Craig Peterson - America's Leading CyberSecurity Strategist: Recent Episodes

Craig Peterson

America’s Leading Fractional Chief Information Security Officer. My team and I usually start with a scan of all devices on your network to determine what needs to be secured. Then we work with you to develop a complete plan to secure what needs to be secured on your networks. In certain cases, my team and I will help businesses source, monitor, and run their cybersecurity. I've been providing Cybersecurity to enterprises of all sizes, and Federal and State agencies since 1991.

View Details

Welcome to today's episode where we dive into the rapidly evolving world of technology and its impact on privacy, history, democracy, and consumer behavior. Join us as we explore the implications of Google FLoC cookies on online privacy, the dangers posed by AI Gemini in altering historical narratives, the role of technology in ensuring election integrity, and the influence of platforms like Temu on the online shopping experience.

  • Google FLoC Cookies: Understand how Google's FLoC technology is reshaping online privacy and targeted advertising.
  • Dangers of AI Gemini Changing History: Discover the risks of AI Gemini's potential to manipulate and rewrite historical events.
  • Election Integrity Technology: Learn about the latest technologies designed to safeguard election integrity and ensure fair democratic processes.
  • Temu and Online Shopping: Explore the impact of Temu and similar platforms on the future of online shopping and consumer habits.

Don't forget to sign up for our Insider Newsletter to stay updated on the latest in technology and its implications for our world!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

Have you ever considered the impact of a powerful solar storm or an unexpected Electromagnetic Pulse (EMP) on our way of life? This article dives deep into the resilience of our electric grid in the face of these potential threats, exploring the concerning "what ifs."

Solar Flares and EMPs: Disrupting Our Connected World

  • Solar Flares: These are massive eruptions of energy from the sun's surface. A powerful enough solar flare can induce electrical currents in our power grids, potentially causing widespread blackouts and damage to transformers.
  • Electromagnetic Pulses (EMPs): These are bursts of electromagnetic energy that can disrupt or damage electronic devices. EMPs can be caused by natural phenomena like solar flares, but also by human actions like nuclear detonations.

The Electric Grid: A Fragile Lifeline

The electric grid is a vast network of interconnected power lines, transformers, and substations that deliver electricity to our homes and businesses. A major disruption to the grid could have a cascading effect, impacting everything from communication networks to critical infrastructure.

Beyond Blackouts: The Looming Threat to Cybersecurity

While a large-scale power outage is certainly a concern, the real danger from EMPs and solar flares lies in their potential to disrupt cybersecurity measures. Critical infrastructure control systems and financial networks could be vulnerable, leading to data breaches and widespread chaos.

Taking Action: Protecting Ourselves and the Grid

The good news is that there are steps we can take to mitigate the risks posed by solar flares and EMPs. These include:

  • Grid Hardening: Upgrading the grid infrastructure with surge protection and other measures to improve resilience.
  • Cybersecurity Measures: Implementing robust cybersecurity protocols to protect critical infrastructure from cyberattacks that could exploit vulnerabilities caused by EMPs.
  • Personal Preparedness: Understanding how to protect electronic devices in your home and developing a plan for surviving a prolonged power outage.

Click to Learn More, Empower, and Protect Yourself

This article just scratches the surface of this complex issue. For a deeper dive into the science behind solar flares and EMPs, practical tips on how to safeguard your devices, and information on how to advocate for grid improvements, click the link below. Together, we can ensure a more resilient future for our electric grid and the way of life it supports.

View Details

Chris's $10,000 smartphone hack is just one instance of a concerning trend of cyberattacks. Today, we're delving deep into eSIM technology, a game-changer in mobile privacy and security.

  • Cybersecurity Concerns: The rise in hacking incidents highlights the urgent need for robust cybersecurity measures, especially in the mobile space.
  • eSIM Technology: Exploring the intricacies of eSIMs reveals both their potential and the security challenges they present.
  • Online Privacy: With eSIMs becoming more prevalent, understanding their impact on online privacy is crucial for users.
  • Combatting Hacking: Strategies for combatting hacking, including tips on how to keep your smartphone safe, are essential knowledge in today's digital landscape.
  • haveibeenpawnd: Tools like Have I Been Pwned can help individuals check if their data has been compromised, adding another layer of security awareness.

If you're intrigued by the intersection of technology, security, and privacy, this article is a must-read. Dive into the world of eSIMs and equip yourself with the knowledge to safeguard your digital life. Click the link below for insightful checklists and actionable advice.

Unmasking the eSIM: A Deep-Dive into Mobile Privacy, Security, and the Combat against Hacking

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

In today's digital age, our online presence can become cluttered and overwhelming, affecting not just our digital identity but also our cybersecurity and privacy. Let's delve into the expert secrets of digital cleansing to ensure a safer and more secure online journey:

  1. Understanding Digital Clutter: Learn how digital clutter impacts your life and why it's essential to tidy up your online presence.
  2. Cybersecurity Concerns: Uncover the risks posed by unchecked emails, unused accounts, and shares, and how they can compromise your cybersecurity.
  3. The Importance of Online Privacy: Explore the elusive asset of online privacy and why it's crucial to respect, value, and protect it.
  4. Digital Detox Strategies: Discover simple steps and checklists to effectively detox your digital life and create a shining, secure digital profile.

By following these expert tips and secrets, you can disappear from the Internet's gaze and enjoy a safer, simplified online experience. Don't miss out on safeguarding your digital identity – click the link to start your journey towards digital cleansing today.

Digital Cleansing 101: Expert Secrets to Disappearing from the Internet’s Gaze

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

Hey there!

Is your home Wi-Fi a potential cyber threat? Let’s bolster your network's defenses!

Here's what you'll find in this guide:

  • Privacy Concerns: Understand the risks associated with a vulnerable home network and the importance of safeguarding your personal information.
  • Wi-Fi Security: Learn how to secure your home Wi-Fi network to prevent unauthorized access and protect your devices.
  • Smart Devices: Explore the security challenges posed by smart devices and how to mitigate these risks effectively.
  • Network Segregation: Delve into the concept of dividing your home network for enhanced safety, ensuring that different devices are isolated from each other.
  • Online Privacy: Discover actionable steps to maintain your online privacy and keep your sensitive data secure from prying eyes.
  • Cybersecurity Measures: Get insights into essential cybersecurity measures to implement for a robust and fortified home network.

This guide is your blueprint for transforming your home into a digital fortress. Don’t wait until it's too late—take proactive steps now to secure your cyberspace!

Read more: Secure Your Cyberspace: A Step-by-Step Blueprint for Dividing Your Digital Domain Between IoT Gadgets and Computers

Hope this helps in making your digital life more secure!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

Have you ever paused mid-message, wondering who might be lurking in the digital shadows? I've delved deep into the realms of online privacy, spam prevention, encryption, and the intricacies of organizing your digital life to keep your conversations secure. Join me on this thrilling journey through cyberspace as we unravel the secrets of safeguarding your chats.

Here's what you'll discover in our expedition:

  • Privacy in the Digital Age: Uncover the nuances of online privacy and learn how to navigate the digital landscape confidently.
  • Combatting Cyber Threats: Dive into the world of cybersecurity and gain insights into protecting your digital identity from prying eyes and malicious actors.
  • The Power of Encryption: Discover how encryption transforms your messages into coded language, ensuring only the intended recipient can decipher your words.
  • Effective Organization Strategies: Streamline your digital interactions with efficient organization techniques, making it easier to manage and safeguard your data.
  • Spam Prevention Tactics: Say goodbye to unwanted messages and learn how to create a spam-free digital environment.

Ready to crack the code and secure your online conversations? Follow the link to my latest guide and equip yourself with essential tools to navigate the digital realm safely. Let's whisper through cyberspace together and keep your chats private, protected, and exclusively yours.

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

Hey there! Ever find yourself drowning in a sea of spam emails? 📧 Fret not! I've got the perfect solution to not only declutter your inbox but also fortify your online privacy and cybersecurity. 🛡️

Introducing the ultimate guide to digital clean up, with a focus on plus addressing for enhanced privacy and organization. No more sifting through unwanted emails – this guide is your ticket to a streamlined and secure email experience. 📥

Here's what you'll find in this comprehensive guide:

  • Privacy Reinforcement: Learn how plus addressing can act as a shield, allowing you to create unique and disposable email addresses on the go, keeping your personal information secure.
  • Say Goodbye to Spam: Explore effective techniques to combat spam and bid farewell to those pesky and intrusive emails once and for all.
  • Email Organization Hacks: Dive deep into the world of inbox management, with tips and tricks on setting up filters, rules, and custom addresses to ensure your messages stay neatly organized.
  • Cybersecurity Boost: Understand the crucial role of plus addressing in enhancing your overall cybersecurity, safeguarding your online presence.

This guide goes beyond the basics, offering practical steps to implement these strategies in your own inbox. Ready to reclaim control over your email? Click the link below to access the secrets of a spam-proof, well-organized digital haven! 🔒

Unlock the Secrets Here

And hey, don't miss out on the awesome checklists included in the article to keep your inbox game strong. 📝 Happy inboxing, my friend!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on TuesdaysWTAG AM 580 - FM 94.9 Talk 1200News Radio 920 & 104.7 FM WHJJNewsRadio 560 WHYNWXTKCraigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - TuesdaysWRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 WednesdaysCraigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7

View Details

Hold onto your hats, tech enthusiasts! 🎩💻 Get ready for a seismic shift in the digital landscape as Google bids farewell to cookies, ushering in a new era where privacy is more than just wishful thinking. Say goodbye to the cookie craze! 🍪🚫 In my latest deep dive, "Digital Clean Up: Navigating Google's Game-Changing Shift in Online Advertising," I'm unraveling the intricacies of this groundbreaking move and what it means for all of us navigating the vast realms of the internet. 🌐🔍

Here's what you can expect in this enlightening journey:

  • Advertising Evolution: Explore the implications of Google's pivot on advertisers desperately seeking new strategies in a cookie-free world.
  • Apple's Impact: Delve into how Apple's stance on privacy has influenced this shift and what it means for the tech giant's ongoing rivalry.
  • Chrome Browser Unveiled: Uncover the role of Chrome Browser in this digital cleanup and how it's reshaping our online experiences.
  • The Lowdown on Cookies: Bid adieu to the cookie era and understand the nitty-gritty details behind this game-changing decision.
  • FLoC Unveiled: Get the inside scoop on FLoC (Federated Learning of Cohorts) and how it's set to revolutionize online advertising.
  • Google vs. Microsoft: Peek into the competition between tech titans Google and Microsoft in the quest for a more private digital space.
  • Privacy Pioneers: Understand the broader implications of this shift in digital privacy and what it means for users worldwide.
  • Tracking Trends: Examine the evolving trends in online tracking and how this shift addresses concerns about user data security.
  • Website Revolution: Explore how websites are adapting to the new normal and reshaping their strategies to align with enhanced privacy standards.
  • Online Privacy Check: Dive into the practical side with tips and checklists to keep your digital footprint secure in this evolving online landscape.

If you're itching to know how these changes will impact your online journey or curious about the future of internet browsing and advertising, this is your go-to resource. Don't stay in the dark—head over to my article, "Digital Clean Up: Navigating Google's Game-Changing Shift in Online Advertising," and equip yourself with the insights you need for this digital evolution.

CLICK HERE TO READ THE ARTICLE

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the fast-paced world of technology, your Windows device needs the ultimate defense against cyber threats. I've revamped the guide, diving deep into the realms of anti-virus protection, cybersecurity, and online privacy. Here's your roadmap to a digitally clean and secure future:

  • Windows Defender vs. Norton vs. Malwarebytes: Uncover the strengths and limitations of each superhero in the battle against cyber villains.
  • The War Against Malware: Arm yourself with knowledge on the latest malware trends and the tools to combat them effectively.
  • Guarding Your Cyber Fortress: Explore the importance of cybersecurity and online privacy in an era where digital threats are omnipresent.
  • Beyond the Basics: McAfee and Bloatware: Navigate the landscape of additional security options and understand the impact of unnecessary software on your system.
  • Securing Your Digital Territory: Wi-Fi, Smart Home, and Routers: Extend your protection beyond your computer by fortifying your Wi-Fi, securing your smart home devices, and understanding router security.
  • Bitcoin and Cybersecurity: Delve into the world of cryptocurrency and how to safeguard your digital assets in the age of Bitcoin.
  • Cisco's Role in Digital Clean Up: Understand the significance of Cisco in ensuring the overall security and integrity of your digital ecosystem.

Click through to embark on a journey towards digital cleanliness and fortify your defenses against cyber threats. Your computer's safety is our top priority, and together, we'll conquer the digital realm! Read the full guide HERE

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Is your digital realm resembling a messy attic? Files overflowing like forgotten knick-knacks, an inbox resembling a confetti blizzard, and social media feeds choked with digital dust bunnies? Fear not, fellow data denizens, for spring cleaning season has arrived – and this year, we're reclaiming our online peace of mind!

But unlike dusting cobwebs and decluttering drawers, taming our digital wilderness requires a different arsenal. Forget brooms and vacuum cleaners – we're talking AI-powered assistants, data-detective hounds, and even a digital shredder for those long-dormant devices whispered goodbye to.

Here's your ultimate digital decluttering toolkit:

  • Microsoft's Power Automate: Think of it as a tech-savvy Mary Poppins, whipping your digital cobwebs with automated file organization, email housekeeping, and seamless backups. Sip your coffee while Power Automate whisks away digital clutter like magic.
  • Duplicate File Hunter: This data sleuth sniffs out file twins hogging precious storage space. Unleash the Hunter and watch gigabytes reappear like spring flowers, leaving your drives feeling light and breezy.
  • Internet Defense Dome: Ditch the tin-foil hat – this digital bouncer, be it OpenDNS or similar shields, filters out online nasties like malware and phishing attempts before they even reach your virtual doorstep. Keep your online castle sparkling clean and data-safe from digital dragons.
  • EV Battery Whisperer: Owning an electric wonder is awesome, but battery health takes some love. This app whispers sweet nothings to your EV, giving it a virtual checkup and ensuring smooth, efficient rides.
  • Password Guardian: Passwords – the kryptonite of digital serenity! Google, your cyber therapist, analyzes your passwords, exposing vulnerabilities and suggesting upgrades. No more sticky notes – lock down your accounts with confidence, a fortress against digital villains.
  • ChatGPT, the Inbox Concierge: Feeling buried in email avalanches? This AI assistant sorts the deluge, prioritizes messages, and even crafts responses. Think of it as a digital butler keeping your inbox zen and your mind focused.

These are just a few of the digital decluttering superpowers at your fingertips. So, say goodbye to the digital dust bunnies, embrace the power of tech, and click here to uncover more tools for building a clutter-free online oasis!

Remember, a tidy digital world is a productive, peaceful one. So grab your virtual dustpan and broom, roll up your sleeves, and prepare to be amazed by the transformative power of a digital spring clean!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Hey there cyber enthusiasts! Ever wondered how to transform your digital space into a fortress of security? Well, buckle up, because we've crafted the ultimate guide to help you declutter, fortify, and defend your digital realm. Our mission: to make cybersecurity engaging and effective, without drowning you in techno-jargon. Check out these key points we've covered:

  • Wi-Fi Wonders: Unveiling the mysteries of Wi-Fi security to ensure your online activities remain secure from prying eyes.
  • Password Power: Dive into the world of password protection, unlocking the secrets to crafting robust and memorable passwords.
  • Software Safeguard: Explore the essential software tools that act as your digital bodyguards, fending off potential cyber threats.
  • Cyber-Consciousness: Elevate your awareness with insights into cyber threats, ensuring you gain confidence while navigating the digital landscape.
  • Privacy Protocols: Delve into the importance of online privacy and learn practical tips to keep your personal information under wraps.
  • Data Defense: Uncover strategies to defend your precious data from the clutches of cyber villains, ensuring it stays in safe hands.
  • Phishing Filters: Equip yourself with the knowledge to recognize and thwart phishing attempts, safeguarding your digital identity.
  • Firewall Fortifications: Understand the role of firewalls in fortifying your digital perimeter against cyber intruders.
  • Antivirus Arsenal: Explore the world of antivirus protection and discover how to choose the right tools to keep your system healthy.
  • Secure Surfing: Decode the mysteries of HTTPS, ensuring your online interactions occur within a secure, encrypted environment.
  • Multi-Layered Security: Embrace the power of 2FA and MFA, adding an extra layer of defense to your digital life.

Ready to embark on a digital detox journey? Our step-by-step guide not only frees up digital space but also ensures your online life is fortified against cyber threats. Say goodbye to data clutter and hello to cyber resilience. Your digital spa retreat awaits—refresh, renew, and revitalize your cyber world! 🚀 #CybersecurityCanBeFun 🌐🔒

Read the full guide here: Data Hoarding: Protecting Your Privacy and Security

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the vast landscape of the digital world, safeguarding your online presence is paramount. Welcome to another episode of TechTalk with Craig Peterson, where today, we unravel the secrets to fortifying your digital realm with "The Ultimate Cybersecurity First-Aid Kit."

Decrypting Wi-Fi Woes Our journey begins with the cornerstone of your digital fortress: Wi-Fi encryption. No secret stays safe forever, and that includes your Wi-Fi password. We delve into the importance of encrypting your Wi-Fi, ensuring that your digital stronghold remains impenetrable.

Password Party Extravaganza "abc123" just won't cut it in the ever-evolving world of cyber threats. Join us for a Password Party Extravaganza, where we explore revolutionary approaches to crafting and managing passwords. Bid farewell to weak links and embrace the new era of digital passcodes.

Software Wardrobe Upgrade Much like updating your wardrobe, keeping your software fresh and secure is essential. We discuss the significance of regular software updates, and adopting a fashion-forward approach to digital safety. It's time to elevate your software game and stay ahead in the cybersecurity-style game.

Data Backup Ballet Our cyber journey gracefully transitions into the realm of data backup. Learn the art of the Data Backup Ballet, where we emphasize the importance of moonwalking through cyber threats with meticulously backed-up data. Your digital performance deserves a standing ovation, not a cyber mishap.

Cyber-Aware Workforce The frontline against phishing invasions is your very own workforce. Discover strategies to keep your staff cyber-aware, creating a formidable defense against phishing scams. After all, in this digital age, knowledge is power, and a well-informed team is your best asset.

MFA Magic Unleashed Two proofs are better than one, especially when it comes to securing your digital kingdom. Unleash the magic of Multi-Factor Authentication (MFA) and elevate your security with a double-proof shield. We explore why MFA is a game-changer in the world of cybersecurity.

Firewall & Antivirus Heroes Firewalls and antivirus tools aren't just buzzwords; they're your digital heroes. Join us in celebrating their crucial roles in safeguarding your online presence. It's time to go beyond the terminology and understand how these digital guardians actively protect your digital realm.

HTTPS Secure Safari Navigating the web should be a secure delight. We dive into the importance of HTTPS and how it enhances your online browsing experience. Secure your digital safari, ensuring each click is a step into a safe and encrypted cyberspace.

Phishing Vigilantes Unleashed Become a phishing vigilante with our insights on spotting scams before they bite. Learn the art of being a Phishing Watchdog, and never fall victim to deceptive online tactics. If it seems phishing, don't be dishin'; empower yourself to recognize and combat these digital threats.

Incident Response Elegance No cybersecurity strategy is complete without a touch of elegance. We discuss the creation of Incident Response Plans, your stylish safety nets for cyber mishaps. It's time to weave a safety net that adds sophistication to your digital defense strategy.

Latte-Fueled Cyber Control Take control of your online presence like never before. Grab a refreshed latte, settle in, and let's navigate the digital landscape with confidence. We wrap up our cybersecurity journey with a well-brewed cyber alert, ensuring that every click is a conscious step towards a secure digital future.

Join us in this episode of Tech Talk with Craig Peterson, where we decode the intricacies of the digital realm, empowerment is protection. Stay secure, stay informed!

Learn more on how to secure your business:

The Cybersecurity First-Aid Kit: Immediate Actions for Small Business Owners

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In today's fast-paced digital age, staying ahead of the curve is not just an advantage; it's a necessity. From the electrifying world of electric vehicles to the intricate web of mobile security, and the visionary influence of Elon Musk, there's a lot to unpack. Join us on this insightful journey as we explore key topics that are shaping the future of technology.

  1. Electric Vehicles (EVs): Paving the Way for a Green Future The surge in popularity of electric vehicles is undeniable. We delve into the latest advancements, innovations, and the environmental impact of EVs, providing you with a front-row seat to the future of transportation.

  2. Mobile Security: Safeguarding Your Digital Playground In an era dominated by smartphones, understanding mobile security is paramount. From protecting your personal data to thwarting ransomware and adware attacks, we share practical insights to ensure your digital world remains secure.

  3. Kochava Chronicles: Navigating the World of Data Brokers Kochava has become a key player in the data ecosystem. Uncover the significance of data brokers and how they impact your online experiences, shedding light on the often opaque world of data trading.

  4. Push Notifications: The Power and Perils Push notifications can be a double-edged sword. We explore their potential benefits and the risks associated with malware attacks through these seemingly harmless alerts, providing tips on how to navigate this digital communication channel safely.

  5. AI and Its Role in Countering Malware Attacks Artificial Intelligence is at the forefront of the battle against cyber threats. Learn how AI is being leveraged to detect and mitigate malware attacks, ensuring a proactive defense in an ever-evolving digital landscape.

  6. BEC Attacks and Elon Musk: Decoding the Phishing Landscape Business Email Compromise (BEC) attacks have become more sophisticated. We uncover the strategies used by cybercriminals, and how the influential figure of Elon Musk is sometimes exploited in these phishing attempts, offering insights to fortify your defenses.

As we embark on this knowledge-rich expedition, we invite you to subscribe to the Insider Mail for an exclusive deep dive into these topics and more. Join our community at craigpeterson.com/subscribe to receive regular updates, expert opinions, and actionable tips straight to your inbox. Stay informed, stay secure, and stay ahead in the ever-evolving world of technology. Subscribe today!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In a world dominated by QR codes, the risk of falling prey to digital tricksters is on the rise. Fear not, fellow entrepreneurs, for we've decoded the secrets to outsmarting these cyber hosers and keeping your digital fortress secure!

QR Code Unveiled: Understanding the Basics Let's kick things off with a deep dive into the world of QR codes. Learn what makes them tick and how scammers exploit these seemingly innocent codes to compromise your cybersecurity.

The Rise of AI and Its Role in QR Code Shenanigans Artificial Intelligence (AI) has ushered in a new era, and unfortunately, cybercriminals are leveraging it to manipulate QR codes. Discover the tricks they use and stay ahead of the curve in this digital arms race.

Nuclear QR Warfare: Protecting Your Digital Existence Uncover the potential dangers of nuclear QR attacks and arm yourself with the knowledge needed to defend against these sophisticated threats. Your digital existence is at stake, and we've got the playbook to keep you one step ahead.

Online Privacy in the QR Age: Navigating the Minefield As our lives become more intertwined with technology, ensuring online privacy is paramount. Explore how QR codes can become a threat to your privacy and what steps you can take to safeguard your digital footprint.

Malware, Phishing, and QR Codes: The Unholy Trinity Delve into the dark side of QR codes as we expose their connection to malware and phishing attempts. Equip yourself with the tools to recognize and thwart these malicious schemes.

Battling Cyber Hosers: Your Ultimate Defense Guide Meet the cyber hosers head-on with our ultimate defense guide. From smartphone security to email protocols, we've got you covered. Stay one step ahead and keep your digital empire secure.

Read the full article here to become a QR code master and fortify your digital defenses against cyber tricksters. Your digital safety is non-negotiable – let's outsmart the hosers together!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the ever-evolving landscape of digital media, the illusion of ownership can be shattered with a single tactical move. Recently, the PlayStation community experienced a rude awakening when paid content was abruptly removed - and no refunds were given. This underscores a widespread issue: do you own the digital shows and movies you 'bought'?

Topics Explored in the Article:

  • Tactical Octopus Unveiled: Delve into the intricate tactics used in the digital realm that challenge the perception of ownership.
  • IRS Alert: Explore the unexpected connection between the IRS and your digital movie purchases, revealing potential vulnerabilities.
  • Cybersecurity Insights: Understand the broader landscape of cybersecurity and its impact on safeguarding your digital trove.
  • Email Threats: Uncover the silent menace posed by email threats and how they can compromise your perceived ownership of digital content.
  • Phishing Schemes Exposed: Navigate through the perilous waters of phishing schemes, shedding light on how they put your digital movies at risk.
  • HaveIBeenPawned: Explore the eye-opening revelations from HaveIBeenPawned.com and how they relate to the security of your digital media.
  • Troy Hunt's Take: Gain insights from Troy Hunt, a renowned expert, as he unveils the reality behind digital content ownership.
  • Password Managers as Shields: Discover how password managers act as shields, protecting your digital movie collection from potential loss.
  • Online Meetings Vulnerability: Zoom in on the vulnerability of digital media during online meetings, revealing potential risks.
  • Antivirus and Antimalware: Explore the role of antivirus and antimalware tools in fortifying your digital ownership.
  • Windows Defender: Assess the effectiveness of Windows Defender in securing your digital content within the Windows ecosystem.

The digital world is full of surprises, and ensuring true ownership of your digital shows and movies requires a strategic approach. From cybersecurity insights to email threats and the role of password managers, this article unravels the layers of complexity surrounding digital ownership. Are you ready to secure what's rightfully yours? Read more on Lifehacker to stay informed and empowered in the digital age.

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Securing your online activities in today’s digital world is a top priority, and the trio of web browsers—Google Chrome, Firefox, and Safari—stand as formidable guardians against cyber threats. Let's embark on a journey into the intricacies of these browsers' advanced protection features to fortify your online experience.

Chrome's Shielding Arsenal Google Chrome takes the lead with robust security measures. From safeguarding against phishing attempts to fortifying defenses against ransomware attacks, Chrome stands tall as a digital fortress. Explore its advanced protection features to ensure a secure online voyage.

Firefox: The Guardian of Virtual Gateways Firefox, known for its commitment to user privacy, offers a suite of advanced security options. Uncover how Firefox acts as a shield against cyber threats, including a detailed look at its capabilities in dealing with phishing and its role in the fight against online vulnerabilities.

Safari's Safari: Navigating the Digital Wilderness As Apple's browser of choice, Safari boasts a unique set of security features. Dive into Safari's advanced protection mechanisms, understanding how it contributes to a secure online environment. From patching vulnerabilities to thwarting phishing attempts, Safari plays a pivotal role in the defense against digital dangers.

Beyond Browsers: A Tech-Savvy Interlude While exploring browser security, it's essential to touch upon broader tech topics. Delve into the world of electric vehicles, with a spotlight on Tesla and hybrid cars. Witness the intersection of technology giants like Google and Microsoft and their roles in shaping the digital landscape.

The Phishing Chronicles: Barracuda vs. Cyber Threats No discussion on online security is complete without addressing phishing threats. Unpack the significance of Barracuda's role in combating phishing attacks, and understanding its strategies in protecting users from falling victim to malicious schemes.

Ransomware Realities: The Digital Extortion Menace Ransomware continues to be a menace in the digital realm. Navigate the landscape of ransomware threats and discover how browsers play a role in preventing and mitigating these attacks. Gain insights into the importance of timely patching to fortify your defenses.

In a world where online security is non-negotiable, understanding the intricate details of browser protection is your armor.

Fortify your digital stronghold and embark on a secure online journey, read more in the article below:

Keep Your Browsers Secure: Advanced Protection in Chrome, Firefox, and Safari

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Unmasking Gift Card Scams: A Growing Online Threat Exposed!

Gift card scams are prowling the digital landscape, targeting unsuspecting online shoppers like never before. In this article, we'll dive deep into the murky waters of online scams involving gift cards, Amazon, credit cards, and more. Buckle up, because the world of online shopping is not as secure as it seems.

Signs You're Being Scammed These online tricksters have mastered the art of deception:

  • Too-good-to-be-true offers
  • Urgent demands for payment via gift cards
  • Threatening legal action if you don't pay up - yikes! (It isn’t the IRS that’s asking for Gift Cards)

Don't let these scammers fluster you with their tactics. Stay vigilant and informed to protect yourself from their sly schemes.

It’s Not the IRS… Contrary to what these scammers claim, the IRS never demands instant payment over the phone or threatens immediate arrest, especially not via gift cards. If you receive a suspicious call, hang up and report it to the IRS using their dedicated hotline for impersonation scams. Keeping a cool head is your best defense against these scammers trying to rustle up trouble.

The Old Switcheroo – What To Do Instead Rather than falling for their bait, let's equip you with some savvy strategies:

  • Ignore requests for payments or donations via gift cards.
  • Always investigate before making any financial moves.

Connect-the-Dots Security Checkups Spread awareness about common scams, especially among elderly family members. Pause if anything feels rushed or odd regarding money or personal information. It's time to connect the dots and ensure everyone stays safe online.

Doing Your Detective Work When playing detective in the digital realm:

  • Verify phone numbers independently; search online rather than relying on potential scammers.
  • Trust verified customer service lines—they should confirm the legitimacy of any requests.

Explore the resources provided by the FTC for comprehensive information and extra help against these cunning lures.

Taking Action Against Gift Card Ghouls If you happen to fall prey to a scam (it can happen to anyone), don't lose hope. Act swiftly:

  • Report scam attempts immediately and inform businesses of the misuse of their names.
  • Remember, knowledge is your sword against gift card scams. Stay sharp and vigilant.

So saddle up on your wisdom steeds—it's time to win the triple crown of online safety! Until next time, partners. Stay savvy and scam-free!

Click here for all the details

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Hey savvy shoppers, gather 'round for a tale as vital as your grandma's pie recipe! Ever felt the sting of an online shopping scam? Fear not, I've got the lowdown on dodging those traps. Let's kick things off with a cautionary yarn and dive into the nitty-gritty.

Spotting a Phony Website: Detective hat on! Check URLs for weird symbols and misspellings. A padlock symbol next to the URL is a good sign.

Evaluating Sellers on eBay and Etsy: eBay and Etsy, our online treasure troves! Check seller ratings, reviews, and authentic photos. Don't fall for smoke and mirrors.

Buying Big Ticket Items: Eyeing a big purchase? Do a reverse image lookup to ensure authenticity. Fish out the real deal from the online sea of possibilities.

Single-Use Credit Cards Magic: Enter the game-changer – single-use credit cards. Use 'em and toss 'em. Bye-bye worries about your main card falling into the wrong hands.

Keeping Your Info Under Lock and Key: Think twice about the info you share online. Use imaginative details for security questions. Be as elusive as a dragon for that added layer of protection.

Why These Steps Matter: Avoid the headache of untangling from online scams. It's easier to prevent than fix.

The 1Password and OpenDNS Shield: Secure your passwords with 1Password and enlist OpenDNS or Cisco Umbrella for a virtual guarddog against ransomware.

Remember, online shopping can be a breeze with a dash of caution. Keep those eyes peeled, use single-use credit cards, and guard your info like the last slice of Thanksgiving pie. Questions or stories to share? I'm all ears!

Ready to master the art of safe online shopping?

Get All the Facts Here

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the dynamic landscape of cyber threats, there are two unsung heroes changing the game for small businesses worldwide. Enter Cisco's OpenDNS and Cloudflare 1.1.1.1, wielding a powerful weapon – a free-tier DNS filtering product! 🛡️

Picture this as having a vigilant bouncer stationed at the entrance of your digital fortress 🏰, meticulously scrutinizing the guest list to ensure no sneaky hackers make it through the gates. 💻🔥

Artificial Intelligence Unleashed: Defending Your Digital Realm Dive into the realm of Artificial Intelligence (AI), where OpenDNS and Cloudflare's 1.1.1.1 leverage cutting-edge technology to block malicious domains before they breach your network defenses.

Beware of the Trojan Horse: The Art of Using Fake Emails Explore the deceptive world of fake emails and how these tools act as a shield, preventing phishing attempts that could compromise your business's sensitive data.

Decoding VPN Risks: Navigating Secure Digital Pathways Uncover the potential risks associated with Virtual Private Networks (VPNs) and learn how these DNS filtering tools provide an additional layer of security beyond traditional VPNs.

Journey into the Dark Web: Unveiling Onion Network TOR Browser Delve into the Onion Network TOR Browser and understand how it plays a pivotal role in fortifying your online privacy against cyber threats.

Guarding Your Virtual Castle: Understanding Online Privacy Explore the concept of online privacy as a crucial aspect of your digital castle's defense strategy, and learn how DNS filtering adds an extra layer of protection.

Gen Z Cyber Skills Alert: Small Businesses, Beware! Highlight the evolving threat landscape, emphasizing the need for businesses to stay ahead of Gen Z's advanced cyber skills, and how these tools provide a defense against such expertise.

Navigating the HiTech Job Market: H1B Visas and Cybersecurity Examine the relationship between the HiTech job market and cybersecurity, addressing how these tools contribute to safeguarding businesses in an ever-changing employment landscape.

Electric Vehicles and The Grid: A Cybersecurity Perspective Explore the impact of electric vehicles on the power grid and the associated cybersecurity challenges, with insights into how DNS filtering tools play a role in mitigating risks.

Ready to fortify your business against cyber threats? Get started in just 15 minutes: Protect Your Business Now

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the fast-paced world of digital threats, safeguarding your home and small business is as crucial as changing the batteries in your smoke detectors. I've compiled a comprehensive Cybersecurity and Privacy Checklist, featuring 10 indispensable tips to fortify your digital haven. Dive into the details on my website [insert link].

  1. Shielding with Two-Factor Authentication: Enhance your defense by adding an extra layer of security. Explore the power of two-factor authentication and how it can thwart unauthorized access.

  2. Fortify with Data Backup: Discover why backing up your data is not just a precautionary measure but a lifeline in the face of digital emergencies. Learn the best practices to ensure your data remains intact.

  3. Power Up with Device and Software Updates: Uncover the importance of regular updates for your devices and software. Stay ahead of vulnerabilities and keep your digital arsenal in top-notch condition.

  4. Fortify Your Digital Perimeter: Secure Your WiFi: Your WiFi is the gateway to your digital kingdom. Learn the ropes of securing it to prevent unauthorized access and protect sensitive information.

  5. Mastering Passwords with Password Managers: Dive into the world of password managers and witness how they can revolutionize how you manage and secure your passwords.

Don't wait until the alarms go off – be proactive in securing your digital space! Head to my website for the complete Cybersecurity and Privacy Checklist that will empower you in the ever-evolving digital landscape.

Get all 10 Tips Here - Read the Full Article Here to Join the Discussion

Get all 10 tips here on my website

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

Listen to this episode

View Details

In the ever-evolving landscape of warfare, the silent revolution of military technology has been steadily reshaping the way conflicts are fought. From electric vehicle charging stations to the notorious Barracuda breach and the enduring threat of phishing, the military is harnessing an array of cutting-edge tools. Here, we delve deeper into this unseen tech revolution, bringing you insights from the frontlines in Ukraine and Gaza.

Tesla's Role in the Unseen Military Tech Revolution

Electric vehicle charging stations may not be the first thing that comes to mind in military operations, but Tesla's involvement is changing that perception. Our troops are increasingly relying on EVs, and the efficiency of charging infrastructure can make all the difference on the battlefield.

Barracuda Breach: Unveiling the Future of Cyber Warfare

The Barracuda breach sent shockwaves through the military world, underscoring the paramount importance of cybersecurity. In a world where data is the new battlefield, understanding the breach's implications is crucial.

Phishing Victims Speak Out: The First-Ever Military Insights

Phishing attacks can cripple military operations, but the victims are now sharing their stories and lessons learned. Discover how these experiences are reshaping the way the military approaches cybersecurity.

Mastering Phishing: Tips for the Modern Military

To counter phishing threats, the military is adopting innovative strategies and sharing valuable insights. Learn how the armed forces are staying one step ahead of these cyber adversaries.

Warfare Takes Flight: The Rise of Drones in Combat

Drones have become indispensable assets on the battlefield, providing critical intelligence and reconnaissance. Explore the role of drones in modern warfare and how they're transforming military strategies.

Russia's Digital Onslaught: Cyber Attacks on the Frontline

Russia's cyber warfare tactics have been making headlines. Gain a comprehensive understanding of how these digital offensives are impacting conflicts in Ukraine and beyond.

From WWII to Now: The Evolution of Military Technologies

The roots of modern military tech can be traced back to World War II. We delve into the historical significance of technological advancements and how they have paved the way for today's innovations.

Unearthing History: The Impact of Technology on Warfare

Understanding the history of technology in warfare is essential to appreciate the current revolution. Discover the lessons learned from the past and their relevance in the context of today's conflicts.

Conflict Zones Revealed: Modern Military Tech in Ukraine and Gaza

The military tech revolution is playing out on the frontlines in Ukraine and Gaza. Gain exclusive insights into how these advancements are changing the face of conflict in these regions.

In a world where innovation is the key to survival, the military's embrace of cutting-edge technology is paramount. This unseen tech revolution, ranging from EV charging to cyber warfare, is shaping the future of warfare, and its effects are palpable in the ongoing conflicts in Ukraine and Gaza. Dive deeper into this uncharted territory by clicking the link below:

Read the Full Article Here and Join the Discussion

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In an era where online threats lurk around every corner, controlling your privacy becomes paramount, whether you're a tech-savvy business magnate or an everyday Internet user. Three words can make all the difference: Control Your Privacy. And where better to start than by exploring the little-known but incredibly potent switches concealed within your Windows system?

Join the ranks of the online safety-first-squad and say a resounding YES to harnessing the hidden switches that will turn your digital life from a potential vulnerability into an impregnable fortress. Your online journey is about to transform, and your peace of mind is set to skyrocket.

Exploring Key Topics within the Article:

First Three Flavors of Mobile Malware Dive deep into the initial three flavors of mobile malware that can put your digital security at risk. Learn how Windows switches can help protect your mobile devices from these insidious threats.

Side Loaded Apps Understand the risks associated with side-loaded apps and how you can utilize Windows switches to maintain control over what gets installed on your device.

Mobile Ransomware, Adware, and More Uncover the menace of mobile ransomware and adware, and explore how hidden Windows switches offer a shield against these malicious entities.

Electric Vehicle Potholes While the focus remains on digital security, consider the unexpected vulnerabilities posed by electric vehicles in the modern world and how they intertwine with the broader cybersecurity landscape.

AI Copyright Problems Delve into the intricacies of AI copyright issues and learn how safeguarding your digital assets is a crucial part of maintaining your online privacy.

Who Owns the Internet Contemplate the intriguing question of internet ownership and its implications for your online presence. Discover how understanding this concept is integral to your privacy.

Unauthorized Derivative Works Unravel the concept of unauthorized derivative works in the digital realm and the implications they can have on your online security.

The Legality Examine the legal aspects of digital privacy and cybersecurity, shedding light on what's within the bounds of the law and what isn't.

By the end of this article, you'll not only have a grasp of the hidden Windows switches that can enhance your online privacy but you'll also be equipped to navigate the complex web of cyber threats and digital privacy concerns. Your decision to take control of your online life will be well-informed, and your digital well-being will thank you for it.

Read the full article here and join the discussion!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In an age dominated by technological advancements, the influence of AI has become increasingly pervasive. But have you ever considered that your beliefs about AI might be influencing the way it responds to you? Recent research conducted by Pat Pataranutaporn at the M.I.T. Media Lab sheds light on the intriguing connection between user bias and AI responses, revealing what has been coined the "AI placebo effect."

This groundbreaking study emphasizes the profound impact of user belief on AI interactions, and it's not just limited to ChatGPT and Claude 2; it extends to various aspects of our digital lives. To illustrate this phenomenon, let's delve into a few pertinent topics.

Passkeys Instead of Passwords: Are your preferences for passkeys or traditional passwords shaped by your AI beliefs?

AI Chatbots and Terrorism: Surprisingly, your perspective on AI may impact how you perceive AI's role in counterterrorism efforts.

Google AI-Powered Search Results: Ever wondered if your AI beliefs influence the information you find online?

Electric Trucks and Power Storage: How do your beliefs about AI-driven innovation affect the development of electric trucks and energy storage solutions?

Payment Delivery Scam: Explore how your outlook on AI may make you more or less susceptible to online scams.

Doxxing - Where Does Data Originate: Investigate the role of AI and user belief in the controversial practice of doxxing.

Doxxing Dilemma - What To Do: Learn how your beliefs can inform your response to doxxing incidents and its ethical implications.

Are You Responsible for Shaping AI's Future: Understand the moral responsibility that comes with influencing AI's responses through your beliefs.

The study conducted by Pat Pataranutaporn involved 300 participants who engaged with an AI program to assess its mental and health support capabilities, revealing the intricate interplay between user belief and AI functionality.

It's an eye-opening revelation that prompts us to ponder: How do our personal beliefs about AI impact its responses, and, in turn, the world we experience through it?

We invite you to share your thoughts below, as we embark on a journey to unravel this captivating relationship between AI and human belief.

Read the full article here and join the discussion!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

With today's digital landscape, safeguarding your online privacy is a non-negotiable priority, regardless of whether you're a tech-savvy business magnate or an everyday Joe. To ensure your digital life remains your own, let's delve into the intriguing world of hidden Windows switches that can revolutionize your online security. Are you ready to master your cyber cloak-and-dagger game? Keep reading as we take a closer look at the hidden features that Windows has to offer.

Is Self-Driving Faster: The race for autonomous vehicles has captured our imagination, promising faster commutes and increased efficiency. But speed isn't the only factor at play in this high-stakes game.

Self-Driving is Not Safer: Contrary to popular belief, the road to self-driving cars may not be paved with safety. We'll uncover the surprising truth about the risks involved.

No Longer About Learn to Code: In this era of rapid technological advancement, learning to code isn't the only path to success. Discover how hidden Windows switches can offer an alternative advantage.

Cyber Sloppiness MGM Ransom CDW Ransom: The threat of cyberattacks is more real than ever, with major players falling victim to ransomware. Learn how these hidden switches can fortify your defenses against attacks like the MGM and CDW incidents.

Tactical Octopus Gang: Explore the tactics employed by cybercriminals like the Tactical Octopus Gang and how hidden Windows switches can foil their schemes.

Global Warming Hoax Princeton and MIT: Moving beyond the digital realm, the debate about global warming continues. Learn how these hidden Windows switches can help you separate fact from fiction, even in the realms of academia with Princeton and MIT's research.

Direct Air Capture Systems: Environmental concerns are paramount, and hidden Windows switches can empower you to take action, such as exploring Direct Air Capture Systems.

In-Person vs Zoom Meetings: As the world adjusts to remote work and virtual meetings, hidden Windows switches can be your ace in the hole for securing your virtual conversations.

Join the online safety-first-squad and embark on a journey to bolster your online privacy with these covert Windows features. Say YES to the concealed, the hidden, and the under-the-radar, and make your online experiences worry-free. Your digital life will thank you for the empowerment and security you'll gain.

Ready to unleash the potential of hidden Windows switches? Explore the secrets of cyber cloak-and-dagger with us, and elevate your online security to new heights. Your digital future begins here!

Click the link below to read the full article: Maximize Your Cyber Cloak-and-Dagger Game with Hidden Windows Switches!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Step into the world of small businesses, the true underdogs, and the relentless cyber threats they face daily.

In the digital age, protecting these economic powerhouses is anything but straightforward! Behind the scenes, malicious attacks and stealthy data breaches lurk, poised to strike. But fret not, champions of small and medium-sized businesses (SMBs)!

To safeguard your empire, you must fortify your network infrastructure, secure point-of-sale systems, and shield your CRM systems. Your most trusted allies in this battle are rock-solid passwords and timely updates.

Don't overlook the defense of your financial systems, remote access tools, websites, e-commerce platforms, and cloud-based services; they should be as impenetrable as Fort Knox. And don't underestimate the importance of protecting those omnipresent mobile devices!

Prepare to be enlightened about the crucial strategies that will keep your SMB safe in the digital wilderness. Dive in here:

Protecting the Underdogs: Safeguarding Your Small Businesses from Your Own High-Tech/High-Risk Systems

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In an era where technology permeates every facet of our lives, concerns about radiation emissions from our beloved gadgets often creep into our thoughts. But before you start picturing yourself mutating into an alien, let's clarify that the radiation we're talking about here is of the "non-ionizing" variety, akin to soaking up the sun's rays on a pleasant day. No need for nuclear energy-level panic.

Recently, the iPhone 12 Pro received a resounding vote of confidence from French regulators, assuring us that it's well within safety limits. So, put your iPhone-related worries on hold. And as for Bluetooth's blue waves, they're not causing any ripples in the danger pond either.

But hold on to your digital seats because this article isn't just about iPhones and radiation; it's a journey through the tech-scape that explores vital topics such as browser security, quishing, underwater mega volcanoes, phishing tips, the first-ever phishing victims, Barracuda breaches, and even the electrifying world of Tesla's electric vehicle charging.

Let's dive in and separate fact from fiction in this fascinating digital age, check out the recent article below: What's With High iPhone Radiation Levels? Cell Phones, Ear Buds, and Radiation ... Just the Facts Man

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In the ever-evolving landscape of cybercrime, the Business Email Compromise (BEC) has emerged as a potent weapon for hackers and scammers to dismantle businesses and siphon off enormous sums of money. A recent incident involving a US hoser operating from Brazil highlights the gravity of this threat.

This individual's audacious $3 million BEC scheme played out like a thriller, involving doppelganger tactics, international wire transfers, and a successful hoodwinking of an oil company that parted with a staggering $651,000, thinking it was headed to Portugal.

However, this story isn't just a remote incident that you can brush aside. BEC, as the name suggests, compromises the very essence of business communication through emails. In this article, we will delve into the world of BEC attacks, exploring how they work and how hackers like the hoser in Brazil use your email to deceive and steal.

But that's not all; we'll also touch upon some surprising connections, including the intersection of BEC with the world of computer-controlled cars, Tesla hacks, and the critical role of patching to defend against these threats.

As if this wasn't intriguing enough, we'll also discuss the implications of ChatGPT and OpenAI's AI models coming under the scrutiny of the Federal Trade Commission (FTC), and how this relates to the broader BEC landscape. Additionally, we'll explore the sobering projection that jobs might be lost by the 2030s due to cyber threats like BEC. Lastly, we'll unveil the unsettling revelation that even our cars may not be immune to spying attempts, further emphasizing the pervasive nature of the BEC threat.

Buckle up as we embark on a journey through the shadowy world of BEC, where the stakes are high, and the perpetrators stop at nothing to live "high on the hog." This is not just a threat to businesses; it's a threat to every individual and entity that relies on email for communication and transactions.

Stay informed, stay vigilant, and protect your business from becoming the next target, subscribing to my Insider Mail, and here's a link to the latest article: The Latest on Business Email Compromise

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Hello, tech-savvy fans!

Today, we're diving into a critical topic that demands your attention - safeguarding your smartphone from stealthy cyber attacks, particularly a notorious one called whaling.

But hold your harpoons, we're not just talking about any aquatic adventure here!

Whaling is a sophisticated form of phishing attack that sets its sights on individuals with substantial savings and senior executives within organizations.

So, what's the catch? Cybercriminals orchestrating whaling attacks are on a mission to obtain valuable credentials and access sensitive bank information. They deploy cunning tactics, often disguising their intentions in emails that resemble legal subpoenas, customer complaints, or other executive-level correspondence.

This comprehensive guide equips you with the essential knowledge and tools to safeguard your smartphone against potential cyber threats.

From tips on recognizing phishing attempts (Barracuda's insights included) to understanding the reasons behind automatic updates and potential pitfalls, we've got you covered.

We'll also explore the real dangers of AI-driven confabulation and its implications for your digital security.

Stay with us as we unveil the secrets to outsmarting these stealthy cyber predators and ensure your smartphone remains an impenetrable fortress in the digital world. Ready to armor up?

Let's get started! 🛡️📱 Click the article to know more

Have Any Assets? You’re a Whale! 🐳 Stay One Step Ahead with These Tips!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

With Jim Polito at 0836 Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In today's digitally driven world, our smartphones are indispensable extensions of ourselves. They hold our deepest secrets, sensitive information, and personal memories. However, this convenience comes at a price, as these prized possessions have also become prime targets for covert cyber attacks. In this article, we embark on a journey to unveil the hidden dangers lurking in the digital shadows and arm you with the knowledge to safeguard your smartphone effectively.

The First Three Flavors of Mobile Malware: Unmasking the Threat

Our exploration begins with the first three flavors of mobile malware – a sinister world where malicious software can infiltrate your smartphone without you even knowing. Learn how these stealthy invaders operate and how to detect and eliminate them before they wreak havoc on your device.

Beware of Side Loaded Apps: The Trojan Horses of the Digital Age

Side-loaded apps, though alluring, can be the Trojan horses that cyber attackers use to breach your smartphone's defenses. We'll delve into the risks associated with these seemingly harmless downloads and provide you with tips on how to distinguish between genuine apps and potential threats.

Mobile Ransomware, Adware, and Beyond: The Silent Saboteurs

Cybercriminals have evolved, and their tactics have become increasingly sophisticated. We'll dissect the world of mobile ransomware and adware, shedding light on how these silent saboteurs can hold your smartphone hostage and compromise your privacy. Discover strategies to thwart these threats and regain control of your device.

Electric Vehicle Potholes: A Surprising Digital Vulnerability

In an era of electric vehicles and smart technology, even your car can pose unexpected digital vulnerabilities. We'll discuss the intersection of electric vehicles and cybersecurity, highlighting potential potholes in your EV's digital infrastructure that you should be aware of.

AI Copyright Problems: Navigating the Ethical Minefield

Artificial Intelligence is reshaping the digital landscape, but it also raises significant ethical concerns, particularly when it comes to copyright. Dive into the complexities of AI-generated content and the legal and ethical challenges it presents.

Who Owns the Internet: A Web of Ownership and Control

The Internet has become an essential part of our lives, but the question of ownership and control looms large. Explore the intricate web of ownership and influence that shapes the digital realm and its potential impact on your online experience.

Unauthorized Derivative Works: The Gray Area of Creativity

The digital age has blurred the lines of creative ownership. We'll navigate the gray area of unauthorized derivative works and their impact on content creators and consumers alike.

The Legality of Cyberspace: Navigating the Digital Legal Landscape

As the digital world expands, so does the realm of digital law. Gain insights into the legal nuances of cyberspace, from data privacy regulations to international treaties that shape the digital legal landscape.

With your smartphone as the gateway to your digital world, defending it from covert cyber attacks is paramount. Join us on this enlightening journey as we delve into these intriguing topics, arm you with knowledge, and empower you to outsmart the unseen threats that lurk in the digital shadows. Your smartphone's security is in your hands.

Are you ready to take the first step in safeguarding your digital life? Read the full article and arm yourself with knowledge: Shielding Your Smartphone from Stealthy Cyber Attacks

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 on Tuesdays WTAG AM 580 - FM 94.9  Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With  Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM  

WGAN  Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday 

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays  Craigs Show Airs 1130 Saturday 

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

[KEYWORDS] AI, EV, electric vehicles, cybersecurity, mobile, malware, apps, ransomware, adware, internet, smartphones

View Details

In an ever-evolving digital landscape, where hackers and spies lurk in the shadows, safeguarding your smartphone has never been more critical.

Cybercriminals are becoming as crafty as cat burglars, slipping through the cracks of our digital defenses, and targeting your most sensitive information. Today, we embark on a journey through the labyrinth of cyber threats, armed with knowledge and a determination to keep your smartphone secure.

1. The Payment Delivery Scam Unmasked
Our first destination is the treacherous realm of payment delivery scams, a cunning ploy orchestrated by cybercriminals to compromise your financial security. Imagine a scenario where you've barely made any recent purchases, yet a seemingly trusted supplier insists on updating your credit card information. Sounds suspicious, right? We'll expose the insidious tactics behind this scam and reveal how you can protect yourself.

2. Doxxing: Tracing the Origins and Defending Your Data
Next, we delve deep into the unsettling world of doxxing. Where does your personal data originate, and how do malicious actors use it against you? Knowledge is your greatest ally in this battle. We'll shed light on the origins of doxxing and provide specific practical steps to fortify your digital fortress.

3. Embrace Digital Responsibility: Back Up Your Smartphone Today
It's time to shoulder your digital responsibility. Discover why backing up your smartphone is not just a suggestion but a necessity. Your data's safety is in your hands, and we'll show you how taking this proactive step can save you from potential disasters.

4. AI in Zoom Meetings: A Double-Edged Sword
As we navigate the digital realm, we can't ignore the role of artificial intelligence in platforms like Zoom meetings. Are these AI tools your friend or foe? We unravel the mysteries behind AI integration and its implications for your privacy and security.

5. Beware of Deceptive Emails: Spotting the Fakes
Emails have become a battleground for cyber deception. We expose the dark secrets of fake emails and equip you with the knowledge to become an expert in identifying phishing attempts. Stay one step ahead of malicious senders.

6. VPN Vulnerabilities: Safeguarding Your Smartphone
Virtual Private Networks (VPNs) often safeguard online privacy, but they are not without risks. Join us as we uncover the vulnerabilities associated with VPNs and provide essential tips to keep your smartphone safe while surfing the web.

7. Navigating the Dark Web with TOR Browser
Venturing into the hidden corners of the internet has its allure and dangers. We take you on a journey through the Onion Network with TOR Browser, exploring its potential for privacy and peril. Brace yourself for a captivating digital expedition.

8. Businesses Under AttackThe Surge in Fake Invoice Scams
Lastly, we examine businesses under siege from a rising tide of fake invoice scams. We shed light on this growing threat and its impact on organizations worldwide. Knowledge is power, and understanding the tactics behind these scams can help businesses defend their financial fortresses.

Get ready to embark on a cybersecurity odyssey as we unravel the mysteries of the digital world and arm you with the knowledge needed to protect your smartphone against hackers and spies. Your digital safety is our top priority, so let's journey together into the heart of the digital underworld.

Click the article to learn more about Fake Invoice Scams Hitting Businesses Hard

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

The digital landscape is a battleground. As the Tactical Octopus Gang orchestrates intricate schemes and the debate over Global Warming Hoax Princeton and MIT rages on, a new threat looms large: hackers and spies targeting your smartphone. In a world where even Direct Air Capture Systems can't purify your device from virtual invaders, it's time to fortify your defenses.

In-person vs. Zoom Meetings are a dilemma, but amid this, hackers seize opportunities. Your smartphone, brimming with personal and sensitive data, becomes their prized possession. The urgency to arm yourself against this modern-day onslaught cannot be overstated. But where to begin?

Start by shattering their tactics. Navigate the maze of catchy email attachments, cleverly named to trick you. "TitleContractDocs.zip" or "JRCLIENTCOPY3122.zip" might seem innocent, but they house sinister intent. Hesitate, and you're already ensnared.

Yet, hope gleams on the horizon. Online Privacy Browsers stand as stalwart guardians, but hackers adapt. This battle demands the best weapons – the finest anti-virus software. Uncover the armor that can repel their assaults, preserving your smartphone's sanctity.

Remember, knowledge is power. Platforms like HaveIBeenPawned unveil the truth, but action rests in your hands. Empower yourself with the twin shields of 2FA and MFA. Become the guardian of your digital realm.

As the Tactical Octopus Gang and their hoser hijinks persist, you hold the key to victory. Don't wait until the hackers' net tightens. The time to act is now! Transform your smartphone into an impregnable fortress against relentless hackers and spies. Your move, digital warrior. Your move.

Click here to embark on your journey to smartphone security: Safeguard Your Small Business Today: The Ultimate Guide to Cloud Protection for Data Loss Liability

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Your smartphone, that tiny marvel of technology, holds the key to your world - your personal information, contacts, photos, and more. But lurking in the digital shadows are hackers and spies, waiting to exploit every chink in your smartphone's armor. In this age of connectivity, safeguarding your micro-computer is no longer just an option – it's a necessity. Join us as we unveil a treasure trove of knowledge to empower you on the digital battlefield.

Phishing Tips: Avoiding the Siren's Call
Ever been lured by a cleverly disguised email or text? You're not alone. Phishing has become a potent weapon in the hacker's arsenal. Learn the art of deciphering suspicious messages and thwarting their attempts to reel you in.

Phishing Victims First Ever: Tales of Triumph and Tragedy
Delve into the gripping narratives of those who fell victim to phishing attacks, revealing the devastating consequences of digital deception. Discover their stories of recovery, resilience, and the lessons they've learned.

Barracuda Breach: Navigating Dangerous Digital Waters
The recent Barracuda breach served as a wake-up call, exposing vulnerabilities in even the most robust systems. Uncover how this breach underscores the urgency of safeguarding your smartphone against evolving cyber threats.

Electric Vehicle Charging Tesla: Charging Up Security
As electric vehicle charging intertwines with our digital lives, the potential risks multiply. Unravel the intricate web of security concerns and discover how Tesla is paving the way for a safer, more connected future.

Automatic Updates: Why Your Smartphone Craves Them
Automatic updates aren't just about new features; they're your smartphone's frontline defense. Explore why these updates are pivotal in repelling hackers and discover how to ensure your device is always armed with the latest protection.

First Reasons for Problems: Peering into Vulnerabilities
What causes smartphone vulnerabilities in the first place? Peel back the layers to uncover the root causes and gain insight into the tactics hackers exploit to gain entry.

Other Potential Update Problems: Navigating the Update Minefield
While updates are crucial, they can sometimes introduce unexpected issues. Navigate the potential pitfalls of updates and learn how to mitigate any problems that may arise.

Confabulation and AI: Unmasking Real Dangers
Artificial Intelligence is a powerful ally, but it also harbors dangers, including the unsettling phenomenon of confabulation. Explore the potential risks AI poses to your smartphone's security and digital well-being.

Your smartphone is more than a device; it's a vault of your digital life.

Click here Protect Your Smartphone Against Hackers and Spies Now! to empower yourself with the knowledge to thwart hackers and safeguard your micro-computer against the ever-evolving threats of the digital age. Your journey to digital security starts now.

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Embark on a riveting cyber adventure like no other, intrepid digital explorers! Brace yourselves for an eye-opening journey into the realm of "Browser Security: Safeguarding Your Online Odyssey." Bid farewell to mundane tech advice – we're about to unveil the secrets of the digital savannah where cyber predators lurk behind unsuspecting links.

Imagine your browser as the valiant Indiana Jones of this sprawling web jungle. But even our trusty explorer needs reinforcements. Learn the art of deciphering its warning signals – a modern-day SOS to steer clear of lurking dangers. And just like precious gold, guard your passwords with unwavering vigilance. Because who wants an embarrassing search history mishap during a crucial meeting? (We've all been there, haven't we? 😳)

Dive into the heart of the matter: share wisely during live chats and shield your sensitive info from data-nappers – those mischievous culprits who misuse your data. And remember, just like leaving a party before the chaos unfolds, always log off when your online shindig concludes. Why? Because in this digital age, paranoia is just your instincts' way of saying, "Guard your data fortress!"

Ready to arm yourself with knowledge? Prepare to fortify your digital armor and emerge victorious against the lurking threats.

Click the article below to empower yourself and fortify your browser against the unseen forces of the web:

Browser Security: Safeguarding Your Online Journey

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Malware, the silent enemy lurking in the digital shadows, has become a formidable threat to our ever-connected lives. With Android users facing an alarming 50 times more attack than their Apple counterparts, it's evident that cyber adversaries have their sights set on the famous 'little green bot.' As we navigate the digital landscape, safeguarding ourselves and our loved ones becomes an urgent necessity.

In this eye-opening article, we delve deep into the world of Android malware and its devastating consequences on your digital life. From the vulnerable digital playgrounds our kids inhabit to the emerging concerns of rapid onset gender dysphoria and the chilling suicide risks stemming from cyber threats, we leave no stone unturned. Moreover, we explore the role of parental control software in protecting the innocence of our children and the importance of patching firewalls and WiFi to ensure our devices remain fortified against potential invasions.

As we unravel the reasons why people neglect essential updates, we address the critical issue of patching and its impact on our overall cybersecurity. Discover the futility of insurance as a safeguard against cyberattacks and the situations when choosing not to patch might be a strategic move.

Don't wait for the invisible invaders to strike; take charge of your digital destiny by empowering yourself with knowledge. Click the link below to read the full article and equip yourself with the tools to protect your business, yourself, and your precious data from the relentless onslaught of Android malware.

Read more about this article by clicking the link below:
Android's Cybersecurity: Protect Your Business, Yourself, and Your Data

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Greetings, fellow guardians of digital security!

Today, we embark on an exhilarating journey to unravel the enigmatic world of Microsoft Windows and the clandestine data-gathering practices it conceals. Windows 11 and Windows 10, cherished by millions worldwide, harbor a well-kept secret—they quietly amass your personal information. Fret not, my dear readers, for I have armed myself with invaluable insights to reinforce your privacy defenses. Let us embark on this adventure, empowering ourselves against the lurking risks!

In this captivating exposé, we'll delve into the lesser-known VPN risks that emerge when using Windows OS. I'll share essential tips on fortifying your online privacy against prying eyes. But that's not all; we'll also uncover the art of using fake emails to keep your identity safe from snoopers.

The intrigue heightens as we venture into the depths of the dark web with the Onion Network TOR Browser and Windows. And for those of you intrigued by the intersection of technology and transportation, we'll explore how Electric Vehicles impact the power grid, raising questions about data security.

To all tech enthusiasts! As we shed light on the Hi-Tech Job Market and H1B Visas, we'll unearth potential security implications for professionals and employers alike.

But that's not where our journey ends. Brace yourselves as we discuss the controversial topic, "Beware of Gen Z kills," and how it relates to digital privacy and cybersecurity.

Finally, we'll delve into the fascinating world of Artificial Intelligence Tools and Zoom Meetings, unearthing both the marvels and risks associated with these innovations.

Dear reader, this is no ordinary article. It's an odyssey that traverses the realms of technology and privacy, unveiling hidden truths and equipping you with the knowledge to safeguard your digital existence. So, join me as we unmask the Windows wardrobe and embark on a quest to preserve our online sanctity. Click the link above, and let's embark on this gripping adventure together!

Click the title link below to delve into our comprehensive guide on "Unmasking the Windows Wardrobe: Your Data is The Show, Microsoft is The Spectator! Secure it Now!" Your digital safety awaits. Let's fortify together!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

In a world where the digital landscape is riddled with potential threats, it's essential to armor up and protect yourself from hidden dangers. The recent controversy surrounding ChatGPT OpenAI's investigation by the FTC serves as a stark reminder of the perils lurking in the shadows. As you navigate the vast sea of information, it's easy to overlook the critical aspects of online security, such as patching and patchware.

Fear not, for there's a beacon of hope amidst this digital labyrinth—patches. Whether you're worried about losing jobs by the 2030s or concerned about your smart devices spying on you, these small but powerful updates hold the key to maintaining your online fortress.
Picture this: your devices, be it your phone, computer, or TV, are all shielded with layers of impenetrable security, thanks to timely patches. But it's not just about waiting for updates to appear magically; it's about arming yourself with knowledge and implementing proven strategies that ensure you never miss a patch.

Are you searching for the best antivirus software that complements your patching efforts? Or perhaps you're curious about online privacy browsers and how they can bolster your defenses. Don't worry; we've got you covered. Along the way, we'll also explore essential tools like HaveIBeenPawned, FA, and MFA, all designed to safeguard your digital identity.

It's time to break free from the clutches of scams and fraudulent activities. Empower yourself with the knowledge you need to navigate the ever-evolving digital world securely. Are you ready to embark on this journey to bulletproof your devices and bid farewell to vulnerability?

Click the link below to delve into our comprehensive guide on "Proven Strategies to Ensure You Never Miss a Patch." Your digital safety awaits. Let's fortify together!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Avast, savvy cyber-citizens! Are you tired of feeling like Captain Ahab, forever chasing the elusive white whale of data security in the vast sea of our hybrid workspaces? Fear not, for we bring you a trove of invaluable tools to help you battle cyber threats like a seasoned digital pirate!

Here are the topics we'll uncover today:

  • Phishing Tips Barracuda
  • Breach Automatic
  • Updates Why First Reasons for Problems
  • Phishing Victims First Ever
  • Electric Vehicle Charging Tesla
  • Other Potential Update Problems
  • Confabulation Real Dangers of AI

Our trusted scribe, Craig Peterson, has charted a course to a secure treasure trove of solutions. X marks the spot where you'll discover the power of Password Manager (1Password), the prowess of Malwarebytes in fending off virtual Krakens, and the reliability of Windows System Utilities in keeping your ship sailing smoothly.

But heed this warning, me hearties! The depths below are treacherous, with human error lurking beneath the waves, waiting to ensnare unsuspecting sailors. Let us remain vigilant and keep a watchful eye on the horizon!

Join me, fellow buccaneers, on an epic quest for cyber security, and you shall never again find yourself shipwrecked on the dangerous digital shoals. Together, we shall conquer the #CyberSecurity challenges of the #HybridWorkplace and uncover priceless #DataTreasures.

Read the full article here:
The Game of 'Spy the Breach' in a Hybrid Office - Catching Data Thieves with Style

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

Welcome to another episode of Tech Talk with Craig Peterson podcast that separates fact from fiction when it comes to keeping your information safe and secure in the digital world. In this episode, we dive deep into the misconceptions surrounding online safety and provide you with the knowledge to navigate the ever-evolving landscape of cybersecurity. Don't miss out on this enlightening discussion!

Main Points:

  1. VPN Risks:
    Unraveling the truth about the risks associated with VPNs and their impact on online privacy.
    Understanding when and how to use VPNs effectively for enhanced security.

  2. Online Privacy:
    Exploring the complexities of online privacy and debunking common myths.
    Practical tips to safeguard your personal information and maintain online privacy.

  3. Using Fake Emails:
    Exposing the dangers of fake emails and the potential risks they pose.
    Educating listeners on how to identify and avoid falling victim to email scams.

  4. Onion Network TOR Browser:
    Demystifying the Onion Network and TOR Browser, providing insights into their benefits and limitations.
    Understanding the role of TOR in enhancing online anonymity and mitigating certain threats.

  5. Electric Vehicles and the Grid:
    Investigating the intersection of electric vehicles and the power grid, debunking misconceptions about their impact on cybersecurity.
    Shedding light on the security measures in place to protect the grid and ensuring the safety of electric vehicles.

  6. Hi-tech Job Market and H1B Visas:
    Navigating the complexities of the HiTech job market and dispelling myths surrounding H1B visas.
    Offering valuable insights for job seekers and employers in the tech industry.

  7. Beware of GenZ Cyber Skills:
    Examining the realities of Gen Z's cyber skills and the potential risks associated with their advanced technological aptitude.
    Guiding how individuals and organizations can protect themselves against emerging threats.

  8. Artificial Intelligence Tools and Zoom Meetings:
    Analyzing the benefits and risks of using artificial intelligence tools in Zoom meetings.
    Highlighting the importance of understanding the security implications and taking necessary precautions.

Conclusion:
It's time to separate fact from fiction and equip yourself with the knowledge to enhance your online safety. Stay informed, proactive, and vigilant in the face of evolving cyber threats. Be sure to subscribe to our podcast for more insightful discussions on cybersecurity and check out the related article for a deeper dive into the topics we covered.

Read the full article here:
10 Myths About Keeping Your Information Safe and Secure Online

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

In this eye-opening episode, we delve into the world of buying and selling scams and equip you with the essential knowledge to safeguard your online transactions. Join us as we explore the best antivirus software and online privacy browsers to fortify your digital defenses. Discover the importance of checking if your personal information has been compromised with "Have I Been Pawned," and learn how two-factor authentication (FA MFA) can add an extra layer of security to your accounts.

We also delve into why it's crucial to exercise caution with specific tools and platforms, uncovering potential pitfalls and red flags. Unravel the mystery of ransomware and learn proactive measures to take if you become a victim. Stay one step ahead of phishing scams by understanding their tactics and how to identify and avoid them. Plus, gain valuable insights into advanced persistent threats (APTs) and their impact on your personal and financial security.

To ensure you're well-informed about the latest scams, we provide an important scam alert, highlighting red flags to watch out for such as requests for ID documents, suspicious payment methods, and emotional tales of military deployment. Arm yourself with knowledge and stay protected!

For additional information and a comprehensive guide on protecting yourself from buying and selling scammers, check out the related article:

Protect Yourself From Falling Victim to Common Buying and Selling Scams

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

In this week's podcast, let's dive deep into the world of cybersecurity, focusing on essential tips to shield yourself from phishing attacks. Discover how to fortify your defenses against these deceptive tactics, safeguard your personal information, and navigate the digital landscape with confidence.

Join us as we explore crucial topics such as automatic updates, the real dangers of confabulation, and the recent Barracuda breach.

With cyber threats becoming increasingly sophisticated, it's crucial to stay one step ahead. Our expert guests share valuable insights and actionable advice to help you strengthen your online security practices. Learn how to identify and avoid phishing scams, understand the importance of automatic updates, and grasp the real risks associated with confabulation. Don't miss out on this opportunity to protect yourself, your data, and your digital life.

To further deepen your knowledge, read the related article on phishing protection below:

Essential Tips to Shield Yourself from Phishing Attacks

Tune in to this episode and fortify your defenses today!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

In this episode, we delve into the world of digital parenting and equip you with the necessary knowledge to navigate your children's social media activities. Join us as we explore Craig's comprehensive guide, which provides cutting-edge strategies for managing and regulating your kids' online presence.

Episode Highlights:

  • Learn how to set up parental controls on popular platforms like Facebook, Instagram, Twitter, and TikTok.
  • Discover reliable third-party apps and tools that can simplify monitoring your children's social media use.
  • Understand the significance of open communication with your kids about their online activities.
  • Gain insights into effective talking points to address with your children regarding responsible social media behavior.
  • Explore additional resources and recommendations to enhance your digital parenting journey further.

Other topics discussed in this podcast:

  • The Threat to Our Kids
  • Rapid Onset of Gender Dysphoria
  • Why People Don't Patch
  • Patching Firewalls and WiFi
  • Futility of Insurance
  • and more!

Don't miss out on the opportunity to become a tech-savvy and empowered parent!

Remember, safeguarding your children in the digital age starts with knowledge. Join us on this transformative journey and subscribe to the podcast today!

Read the related article for an in-depth exploration of Craig's strategies and resources for managing your children's social media use.

Craig’s Comprehensive Guide for Parents on Monitoring and Regulating Children’s Social Media Activity

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays
WTAG AM 580 - FM 94.9
Talk 1200
News Radio 920 & 104.7 FM WHJJ
NewsRadio 560 WHYN
WXTK
Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays
WRVA 96.1 FM, 1140 AM

WGAN
Matt Gagnon 0730 Wednesdays
Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7
Chris Ryan 0730 Mondays
Craigs Show Airs 1130 Saturday

On the Internet:
Tune-In (WGAN)
Radio.com (WRVA)
iHeartRadio (WGIR, WTAG, and other stations)

View Details

In today's digital age, our children face unprecedented risks on social media platforms. As parents, it's crucial to understand these threats and take proactive measures to ensure their safety. In a recent article, I delved into this pressing issue, highlighting key points that every parent should keep in mind.

Join me as I discuss the alarming ease with which children can be exposed to inappropriate content and dangerous individuals online. We'll talk about vigilance, monitoring, and teaching our kids how to be safe online.

Don't miss out on the essential tips and tools I've shared in the article to help shield our little ones from the dark side of the internet. Subscribe now to our podcast and gain valuable insights into protecting our children from the potential pitfalls of social media.

To access the detailed article and embark on this journey of safeguarding our children, visit:

Stopping Children From Becoming Victims Of Social Media

Remember, our kids' safety is in our hands. Let's work together to create a secure digital environment for them. Subscribe today and be part of the solution!

Note: This podcast episode is based on the insightful article by Craig Peterson. For further details and a comprehensive understanding, we encourage you to read the related article provided in the show notes.

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays WTAG AM 580 - FM 94.9  Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With  Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM  

WGAN  Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday 

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays  Craigs Show Airs 1130 Saturday 

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

In this eye-opening podcast episode, we dive into the world of online safety and debunk the top myths that surround it. Join us as we separate fact from fiction and provide practical tips to enhance digital security.

Key Points Discussed:

  1. The Role of Antivirus Software: Separating Fact from Fiction

    • Discover why antivirus software isn't always necessary, as we delve into the capabilities of Windows Defender and its ability to provide adequate protection.
    • Moving Beyond Caution: Preventing Hacking and Breaches

    • Understand why being cautious alone isn't enough to prevent hacking and learn practical steps you can take to enhance your overall online security.

    • Secure Websites: Debunking the Myth of Invincibility

    • Gain a deeper understanding of even seemingly secure websites' vulnerabilities and how cybercriminals can exploit them.

    • Identity Theft: Taking Action to Safeguard Your Information

    • Realize that it's never too late to protect yourself against identity theft, and explore strategies to stay informed and safeguard your valuable personal data.

    • Fraud Reimbursement: Unveiling the Bank's Responsibility

    • Learn about the potential limitations of reimbursement by banks in fraud cases, emphasizing the need for proactive measures to mitigate risks.

    • Online Banking Apps: Vulnerabilities and Countermeasures

    • Explore the truth behind the security of online banking apps, understand that they are not immune to cyberattacks, and discover effective ways to secure your mobile banking experience.

    • Password Strength: Beyond the Basics

    • Recognize the importance of strong passwords, but also be aware of the exploitable vulnerabilities present in websites and apps that can compromise your data.

    • Empowering Yourself: The Importance of Staying Informed

    • Emphasize the significance of staying informed about the latest security measures, emerging threats, and best practices to enhance your online safety.

Join us as we dive deep into these topics and gain access to expert insights provided by renowned cybersecurity expert Craig Peterson. Subscribe to our podcast to stay updated on the latest trends, valuable tips, and practical advice to strengthen your digital defenses.

Related Article: Debunking the Top 10 Myths about Digital Data Security

Protect yourself, stay informed, and subscribe to our podcast today to unlock the secrets of online safety and security!

Note: This podcast episode is based on the insightful article by Craig Peterson. For further details and a comprehensive understanding, we encourage you to read the related article provided in the show notes.

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Are you tired of browsing through endless options for anti-virus software? We've got you covered! In this episode, we're diving into the world of PC protection and revealing our top recommendations to keep your system safe from malware and viruses.

Our first choice, and top pick, is Windows Defender. Not only does it offer exceptional protection against threats, but it comes at an unbeatable price—free! Enable it effortlessly and enjoy the peace of mind you get from knowing your system is safeguarded. Plus, lifetime updates and support are included at no additional cost. It's a win-win!

If Windows Defender doesn't quite meet your requirements or you're looking for additional options, we've got you covered. Tune in as we explore other noteworthy choices, such as Bitdefender, Malwarebytes, and Cisco AMP for Endpoints. Each one has its own strengths, so you can choose the one that is right for you.

To delve deeper into the topic, be sure to check out our related article on our website. There, you'll find further insights, comparisons, and additional information that will guide you in making the best decision for your PC's security.

Access the article below for free, and unlock a wealth of knowledge to enhance your PC protection journey:

Discover the Top Antivirus and Anti-malware Solutions for Total PC Protection!

You can also catch Craig at the following stations and channels:

With Jim Polito at 0836 Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Are you aware of the invisible threat of social engineering that can compromise your personal and professional security?

Cybercriminals are using cunning manipulations to exploit human vulnerabilities and gain access to sensitive information. But don't worry; there are practical ways to protect yourself from these attacks.

We have published a must-read article that provides invaluable insights and guidance on how to avoid social engineering attacks. From phishing scams to physical impersonation, the article delves into the inner workings of these attacks and offers concrete strategies to fortify your defenses.

In this article, you will learn the steps to recognize that you are a potential target, be cautious of unsolicited emails and phone calls, and use multifactor authentication as an extra layer of protection. Additionally, you'll learn how to prevent breaches by not clicking on links in emails.

If you want to stay ahead of the curve and protect yourself from the ever-evolving tactics of cybercriminals, this informative article is a must-read.

Don't wait till it's too late! Take charge of your personal and professional security.

Click on the link and read the article now!

The Hidden Dangers of Social Engineering: Tips to Outsmart Cybercriminals

Craig is also heard on the following:

With Jim Polito at 0836 Tuesdays WTAG AM 580 - FM 94.9 Talk 1200 News Radio 920 & 104.7 FM WHJJ NewsRadio 560 WHYN WXTK Craigs Show Airs 0600 Saturday and Sunday

With Jeff Katz 1630 - Tuesdays WRVA 96.1 FM, 1140 AM

WGAN Matt Gagnon 0730 Wednesdays Craigs Show Airs 1700 Saturday

WGIR 610 & News Radio 96.7 Chris Ryan 0730 Mondays Craigs Show Airs 1130 Saturday

On the Internet: Tune-In (WGAN) Radio.com (WRVA) iHeartRadio (WGIR, WTAG, and other stations)

View Details

Do you ever feel like someone is watching you as you browse the internet? With so much personal data at stake, it's no wonder that online privacy has become a hot-button issue. Luckily, there's a new player in town: privacy-focused search engines.

These search engines are prioritizing user privacy and security by shaking up the online landscape. No longer will your personal information be sold to the highest bidder or your browsing history used against you. With privacy-focused search engines, you can rest easy knowing that your online activities are shielded from prying eyes.

But how do they work, you ask? It's simple. Rather than tracking your every move online, these search engines prioritize your privacy by avoiding invasive tracking techniques. Instead, they focus on providing you with accurate search results without compromising your personal data.

And the benefits don't stop there. Privacy-focused search engines also offer powerful tools for businesses looking to keep their sensitive information under wraps. With features like end-to-end encryption and secure servers, you can trust that your company's data is safe and sound.

So, what are you waiting for? Join the privacy revolution and take control of your online experience. With privacy-focused search engines, you can confidently surf the web, knowing that your personal information is in good hands.

Click the link below to learn more and start your journey toward a safer, more secure digital future.

https://craigpeterson.com/privacy/discover-the-top-privacy-focused-search-engines-protect-your-data-and-boost-your-online-security-today/38765/

View Details

In this episode, we will discuss zero-day vulnerabilities and how they can affect everyone.

A zero-day vulnerability is an exploit that has been discovered but not yet fixed by a software vendor. It's essentially a security hole in software that hasn't been patched yet. These vulnerabilities can range from minor to critical, depending on how long the vendor can patch them.

These are so dangerous because hackers can take advantage of them before they're patched. They can use these vulnerabilities to infect your computer with malware or ransomware, steal your data, or even take control of your entire system without you knowing it's happening!

You need to do a few different things to protect yourself from these attacks, and we will discuss them all step-by-step.

View Details

In today's fast-paced, technology-driven world, it is crucial for computer users to stay informed about the latest updates and security measures for their systems.

For Windows users, automatic updates are a common method of ensuring their devices remain up-to-date and protected against various threats. While these updates are essential for maintaining a secure and smoothly operating system, they can also introduce unexpected problems, such as data loss, system instability, and other unwelcome changes.

This podcast aims to shed light on the hidden dangers of automatic Windows updates and provides a comprehensive guide to help users protect their valuable data and maintain a stable system.

Automatic Windows updates are designed to provide users with the most recent security patches and feature improvements, keeping their systems running optimally. However, these updates can also introduce new bugs and incompatibilities, which can lead to system instability and crashes.

In some cases, the new software components may not be compatible with existing hardware or peripheral devices, causing further issues. Furthermore, unexpected changes to settings or configurations can leave users frustrated and searching for a solution.

One of the most alarming risks associated with automatic updates is the potential for data loss. During the update process, files can become corrupted, overwritten, or even deleted entirely. For users who have not backed up their data, this can result in the loss of important documents, photos, and other irreplaceable files. It is essential for users to be aware of this risk and take the necessary precautions to safeguard their data.

To protect against data loss and maintain a stable system, users should follow a few key steps. First, make sure to create regular backups of important files and store them on external drives or cloud storage services. This ensures that even if something goes wrong during an update, users can quickly and easily recover their lost data.

Second, users should consider adjusting their update settings to have more control over when and how updates occur. By disabling automatic updates and choosing to install them manually, users can determine if there are any known issues or incompatibilities with the new software before installation. This allows them to take a more proactive approach to managing their system and avoiding potential problems.

Third, it is essential for users to stay informed about the latest updates and potential issues. By following technology news outlets and forums, users can learn about any problems associated with particular updates and take appropriate actions to protect their systems. Additionally, users should keep their software and drivers up-to-date, as these can help prevent conflicts and ensure compatibility with new updates.

Finally, users should consider investing in antivirus and security software, which can provide additional protection against malicious software and other threats. These programs can help users identify and address potential security vulnerabilities, keeping their systems safe and secure.

While automatic Windows updates offer essential security patches and improvements, they can also introduce hidden dangers and risks to users' systems. By taking a proactive approach to managing updates, staying informed about potential issues, and implementing a robust data backup and security strategy, users can minimize disruptions and ensure their valuable data remains protected. Don't wait to unlock the full potential of your PC—listen to this podcast to learn more about the secrets to managing your computer updates and maintaining a stable, secure system.

View Details

Which patches are critical? When do they really need to be applied? That’s where our new PatchAware™ features come in. We’re monitoring the thousands of patches that are issued every week, and will tell you which patches are the most critical to install right now.

This week’s tip, 9 years after it was discovered, is the “Heartbleed” bug. It is still one of the most significant threats to online security. It gives the bad guys access to sensitive information from affected systems.

This article highlights the importance of upgrading software and keeping it up-to-date with regular security patches to protect against Heartbleed and other vulnerabilities.

The Need for Upgrading Firewalls and IoT Devices

The need for upgrading firewalls and IoT devices is a clear one. As the number of connected devices continues to grow, so do the risks associated with them. A lack of proper security can lead to a variety of problems:

• Ransomware attacks on hospitals or other critical infrastructure

• Hackers stealing sensitive information from companies and individuals alike

• Cyber criminals compromising payment systems and draining bank accounts

Understanding the Different Types of Patches

There are three types of patches:

• Critical Patches - These are security updates that address vulnerabilities that could allow an attacker to gain access to your system and steal sensitive data. They're important to install as soon as possible.

• Non-Critical Patches - These usually fix minor bugs or add new features, but they don't affect your security. You can wait until you have time to install them later on in the day or week if you want!

• Hotfixes - Hotfixes are temporary fixes for critical issues that arise after a patch has been released; they're only available while the issue is still occurring in the wild, so they may not be available for long periods of time

Best Practices for Upgrading Firewalls and IoT Devices

To ensure that your firewall and IoT devices are kept up-to-date, you should:

• Keep track of patches. Use a patch management tool to monitor for updates, and deploy them as soon as they become available.

• Ensure that all networked devices have an active subscription to the latest version of their operating system or firmware. This will ensure that you're protected against known vulnerabilities in these products' code base. If a vulnerability is discovered after an update has been released but before it has been applied, then users may be at risk until they apply the patch themselves (or their IT departments do so).

The Benefits of Regularly Updating Firewalls and IoT Devices

• Increased security: Updating a firewall's software is a great way to ensure that you're using the latest version of the software. This means that if there are any bugs or vulnerabilities in the old version, they'll be fixed and patched up before they can be exploited by hackers.

• Improved performance: Another benefit of regularly updating your firewall is that it can improve its performance over time. This is because newer versions of firewalls often come with new features and functionality that weren't available in previous releases, so updating allows you access to these improvements without having to buy an entirely new device!

• Reduced downtime: Finally, keeping up-to-date with all the latest patches will help reduce downtime due to hardware failure or other issues associated with older versions of software running on your network equipment (like routers).

What to Do if You Encounter an Unpatched Vulnerability

If you encounter an unpatched vulnerability, it's important to take action immediately. First, identify the affected devices and determine whether they are critical to your organization's operations. If so, consider shutting down those devices until they can be patched; otherwise, continue using them as usual but monitor their activity closely for signs of compromise. If you have any control over the patching process for these devices (for example if they belong to a third party), inform them about the problem and encourage them to prioritize fixing it as soon as possible. If there isn't anything else that can be done at this point besides waiting for patches from vendors or manufacturers before implementing them yourself--which may take weeks or even months--make sure all relevant parties understand how serious this issue is so that everyone knows what steps need taken next time something similar happens again in future!

View Details

First up, I have some sobering news. Almost all of our personal information has likely been stolen at one point or another. This could include our names, addresses, phone numbers, email addresses, and even passwords. Cybercriminals are constantly searching for vulnerabilities in systems where this information is stored, and unfortunately, they often find them.

However, there are steps we can take to protect ourselves. One tool that can help is called "haveibeenpwned." It's a website where you can check if your email address has been compromised in any data breaches. If it has been compromised, you'll want to change the password associated with that account immediately.

Next, let's talk about something more futuristic: artificial intelligence (AI). AI refers to machines that are capable of performing tasks that would typically require human intelligence, such as learning from experience or recognizing speech patterns. 

To give you a live demonstration of AI in action - think about Siri on an iPhone - ask her anything, and she will respond using natural language processing powered by machine learning algorithms running behind the scenes.

Finally, explain two-factor authentication (2FA) and multi-factor authentication (MFA). These methods add an extra layer of security when logging into accounts online. 2FA requires users to enter both their password and a unique code sent via text message or generated by an app on their phone before being allowed access into the system; MFA requires additional credentials beyond just the user's login-password pair – such as biometric identification through facial recognition or fingerprint scans – further reducing risk for unauthorized access attempts.

View Details

Welcome to this week's episode of The AI Revolution! In this episode, join us as we explore the world of Artificial Intelligence and its potential to revolutionize business and life. We'll discuss how to use AI for free, what it can do well, and when and where you should never use it. We'll also talk about how to generate emails, blog posts, and content for Facebook, Twitter, LinkedIn, Instagram, and YouTube live! Tune in now to learn more about how AI is transforming the world.

Discover the Secrets of Internet Anonymity and Protect Your Privacy

https://craigpeterson.com/internet/privacy-internet/discover-the-secrets-of-internet-anonymity-and-protect-your-privacy/38677/

The best way to protect yourself from online theft is to stay anonymous and keep your online activities private. Taking the necessary steps to ensure anonymity can significantly reduce your risk of being targeted by malicious actors.

I’ve put together an Action Guide showing 10 Steps you can take to increase your Anonymity and Protect Your Privacy Online: By following these 10 steps, you can increase your anonymity and protect your privacy online. Be sure to stay informed about the latest threats, and take the necessary steps to stay safe.

https://craigpeterson.com/?p=38677

View Details

Cyber security is no longer an option for small business owners – it's a necessity. Cyber threats are rising, and small businesses must stay ahead of the curve to protect their data and networks from malicious actors.

This show will uncover the most dangerous cyber threats to small businesses and what steps you can take to stay secure.

Ransomware Attacks Ransomware attacks are one of the most dangerous cyber threats to small businesses. Ransomware is malicious software (malware) that's typically delivered via malicious links or email attachments. Once installed on a network, the ransomware will encrypt all of the data and demand a ransom from the victim before releasing the data. To stay safe from ransomware, all small businesses should educate their employees about the dangers of clicking on malicious links or opening unexpected email attachments.

Additionally, businesses should back up their data frequently and ensure that all software is up-to-date.

Phishing Scams Phishing is a type of attack designed to steal sensitive information, such as usernames, passwords, and credit card numbers. In phishing attacks, cybercriminals will send out emails pretending to be from a legitimate source, such as a bank or government agency, asking the recipient to click on a malicious link or provide confidential information. To stay safe from phishing attacks, small businesses should educate their employees about the dangers of clicking on suspicious links and ensure that all emails sent out to customers are legitimate.

Advanced Persistent Threats (APTs) Advanced persistent threats (APTs) are malicious cyber attacks designed to steal data or sabotage systems. APTs are often targeted and can be challenging to detect and remove. To stay safe from APTs, small businesses should use strong passwords, regularly update their software, and perform regular security audits.

Insider Threats Insider threats occur when employees or contractors deliberately or inadvertently exploit the data or resources of a company. To prevent insider threats, small business owners should ensure that all employees and contractors know the company's security policies and procedures.

Additionally, businesses should have clear data access and security policies and implement security measures, such as two-factor authentication.

Distributed Denial of Service (DDoS) Attacks Distributed denial of service (DDoS) attacks are designed to overwhelm a network with traffic, causing it to become unavailable to legitimate users. To stay safe from DDoS attacks, small businesses should ensure adequate network security measures, such as firewalls and intrusion detection systems. Additionally, companies should have the plan to respond to a DDoS attack, such as enlisting the help of a DDoS protection service.

IoT Botnets are networks of Internet-connected devices, such as surveillance cameras and smart thermostats, that are used to send spam or launch denial-of-service attacks. To stay safe from IoT botnets, small business owners should ensure that all Internet-connected devices are up-to-date and properly configured with strong passwords.

Additionally, businesses should take steps to monitor and secure their networks, such as using a virtual private network (VPN) or implementing network access control (NAC) systems. In conclusion, small businesses need to stay ahead of the curve regarding cyber security.

By understanding the most dangerous cyber threats, companies can take the necessary steps to protect themselves from malicious actors. Additionally, businesses should ensure that their employees have educated on cybersecurity best practices, such as avoiding clicking on suspicious links or opening unexpected email attachments. By staying ahead of the curve, small businesses can protect themselves from cyber threats and ensure the safety of their data and networks.

View Details

Artificial Intelligence Search Engines You Can Use For Free Today Robot Kicked Out of Court CNET and BuzzFeed Using AI Biden Signs Go-Ahead to Use Child Labor to Make E-Car Batteries

The Biden administration has issued a 20-year ban on new mining claims in the upper Midwest's famed Iron Range, and it is turning to foreign supply chains as it pushes green energy projects.

The move comes as the U.S. continues to rely on foreign suppliers for critical minerals used in wind turbines and electric vehicles.

The ban is part of a broader effort by the White House to reduce reliance on imported minerals, particularly from China, which is accused of dumping cheap products into the U.S., causing prices to plummet.

The Trump administration has been working on curbing this practice through tariffs imposed on steel and aluminum imports from China and other countries. But critics say those efforts are misguided because they would raise costs for American companies that use those metals in their products — from cars and airplanes to solar panels and wind turbines — while doing little to curb Chinese overcapacity.

In addition, they argue that such tariffs would exacerbate America's trade war with China by driving up prices American consumers and manufacturers paid.

The Biden Administration recently announced a 20-year ban on mining, shifting its focus to foreign supply chains as part of its push for green energy. One significant project affected by this ban was the Twin Metals mining project, which was estimated to contain 88% of the country's cobalt reserves and large amounts of copper, nickel, and platinum-group elements. These critical minerals are crucial for various green energy technologies, including electric vehicle batteries, battery storage systems, solar panels, and wind turbines.

For instance, producing an electric vehicle requires 500% more minerals than a conventional gas-powered car, while a single onshore wind turbine requires 800% more minerals than a typical fossil fuel plant.

Interestingly, just a week before the mining ban, the Biden Administration signed a memorandum of understanding with Zambia and the Democratic Republic of the Congo, two countries that are well-known for their child labor practices in mining rare metals like cobalt and copper. This move raises questions about the administration's commitment to promoting ethical and sustainable practices in its green energy initiatives.

View Details

A Step-by-Step Guide to Clearing Your Browser History and Wipe Away Your Online Footprint The process for clearing your Internet browser history can vary depending on your browser. However, here are the general steps for removing your browser history on some popular browsers…

https://craigpeterson.com/browsers/a-step-by-step-guide-to-clearing-your-browser-history-and-wipe-away-your-online-footprint/38583/

Generation Z is the least cyber secure because they are the most tech-savvy generation but also the least experienced in cyber security. They are likelier to take risks online, such as clicking on suspicious links or downloading unknown files and are less likely to use strong passwords or two-factor authentication. Additionally, they may not be aware of their actions' potential consequences, such as identity theft or data breaches.

https://craigpeterson.com/cyber-breaches/small-business-owners-be-wary-of-relying-on-younger-family-members-or-employees-to-manage-their-cybersecurity/38585/

Electric Cars… Security and the Electric Vehicle Charging Infrastructure Failing US https://www.darkreading.com/attacks-breaches/security-and-the-electric-vehicle-charging-infrastructure

The communications networks that connect chargers with their management system, the personal data that travels across those networks, the charge-point operators collecting payments, and the grid itself are increasingly vulnerable as the EV ecosystem grows and the attack surface expands. The risks include (but are not limited to):

  • Disruption of operations for public charger networks, rendering large numbers of chargers unusable and interfering with transportation
  • A takeover of charger networks to use the chargers as bots in massive distributed denial-of-service (DDoS) attacks
  • Theft of customers’ personal identifiable information (PII), including payment card information
  • Fraudulent payments for electricity used in EV charging
  • Disruption to the power grid, leading to blackouts and equipment damage
  • Damage to the EV charging provider's reputation

Google… Google Pushes Privacy to the Limit in Updated Terms of Service https://www.darkreading.com/edge-articles/google-play-terms-of-service-push-privacy-to-the-limit

Google has a long history of searching the Play Store, its app repository, for programs that contain malware. Less than a year ago, Google removed multiple apps from the Play Store that had the banking Trojan SharkBot hidden inside.

However, while removing troublesome apps from the Play Store would seem prudent, Google takes this one step further into a legal gray area.

Debbie Reynolds says that Google's ToS is ambiguous because it is unclear precisely what it might block or remove that is "known to be harmful to the device, data or users." The ToS also does not commit Google to tell users when it makes such a deletion.

Ransomware… Ransomware Profits Decline as Victims Dig In, Refuse to Pay https://www.darkreading.com/attacks-breaches/ransomware-profits-decline-victims-refuse-pay

In another sign that the tide may finally turn against ransomware actors, ransom payments declined substantially in 2022 as more victims refused to pay their attackers.

"Our findings suggest that a combination of factors and best practices — such as security preparedness, sanctions, more stringent insurance policies, and the continued work of researchers — are effective in curbing payments."

"The businesses that are most inclined not to pay are those that are well prepared for a ransomware attack."

Privacy… Why your data is more valuable than you may realize https://www.welivesecurity.com/2023/01/26/data-more-valuable-you-realize/

The data trail you leave behind whenever you’re online is bigger – and more revealing – than you may think.

Use a GPS map app to find a restaurant that specializes in a particular cuisine, and the search provider can ascertain that you eat out, what day of the week you eat out, possibly how frequently, how far you are prepared to travel, possible food preference, the time of day you eat, etc. In this case, the snippet of data was just the name of the restaurant, yet the resulting information that can be deduced from the action can be significant.

Understanding how data is collected and the conclusions that can be drawn is complicated and likely a topic that is interesting when someone explains it but probably too complex for any actions to avoid collection. I would hazard a guess that even those in the know, so to speak, likely give away more information than they realize.

Dark Web… Business Insiders Pose a Huge Threat – Hunting Insider Threats on the Dark Web

https://www.darkreading.com/threat-intelligence/hunting-insider-threats-on-the-dark-web

According to recent research, malicious employees contribute to 20% of incidents, and the attacks that insiders are involved in are, on average, ten times larger than those conducted by external actors. Further data has shown an increase in insider threat attacks over the past two years, as the risk has been exacerbated by remote working through the pandemic.

To minimize insider threats, all organizations should monitor marketplaces, forums, and social media channels for chatter about their company. This helps them to spot the early warning signs of an imminent attack, such as cybercriminals looking for insider knowledge or disgruntled employees making unsavory comments.

View Details

ChatGPT's Technology Will Be Part of Everything This Year https://craigpeterson.com/artificial-intelligence-2/chatgpt/chatgpts-technol…ything-this-year/38570/

ChatGPT is a new text-generation tool trained on 40GB of Reddit's data. It can generate long passages of text virtually indistinguishable from human-written prose, which could have enormous implications for everything from customer service chatbots to fake social media accounts. The company behind ChatGPT is also working on ways to detect if the text was generated by ChatGPT or a human—though some experts worry about how bad actors could misuse this technology.

The technology has generated random plot descriptions for video games to create plausible-sounding fan fiction about Harry Potter and the Avengers.

The latest development in this field is ChatGPT's ability to generate paragraphs, full-length sentences, and even paragraphs. In addition, the system can produce coherent text up to a certain length (currently between 10 and 15 sentences) that humans can read without difficulty—far superior to previous attempts at doing so.

++++++++

How AI chatbot ChatGPT changes the phishing game https://craigpeterson.com/artificial-intelligence-2/chatgpt/how-ai-chatbot-c…he-phishing-game/38572/

ChatGPT could be used for more than just helping your business get more leads or customers; it could also be used as an effective tool by phishers seeking access to confidential information from unsuspecting victims who are fooled into thinking they're talking with an actual human being through email or SMS messaging apps like WhatsApp or Telegram Messenger (both popular messaging platforms).

We are very excited about ChatGPT and its potential to disrupt the phishing game. If it becomes widespread, it could be a game-changer for cybercriminals. In addition, Microsoft has shown us they are serious about investing in AI technology, so we would not be surprised if they developed their version of this technology in-house or acquired the company behind ChatGPT to ensure their customers stay safe online.

Microsoft Looking to Invest $10 billion More Microsoft, which is rumored to be weighing a $10 billion investment in OpenAI on top of an earlier $1 billion commitment, is betting that the company is worth a lot more—despite the fact neither ChatGPT nor other AI models made by OpenAI are yet raking in vast amounts of cash.

++++++++

LifeLock… Norton LifeLock Password Accounts Hacked https://www.bleepingcomputer.com/news/security/nortonlifelock-warns-that-hackers-breached-password-manager-accounts/

In accessing your account with your username and password, the unauthorized third party may have viewed your first name, last name, phone number, and mailing address — Norton LifeLock

For customers utilizing the Norton Password Manager feature, the notice warns that the attackers might have obtained details stored in the private vaults.

Cars… Millions of Vehicles at Risk: Vulnerabilities found in 16 Major Car Brands https://thehackernews.com/2023/01/millions-of-vehicles-at-risk-api.html

The security vulnerabilities were found in the automotive APIs powering Acura, BMW, Ferrari, Ford, Genesis, Honda, Hyundai, Infiniti, Jaguar, Kia, Land Rover, Mercedes-Benz, Nissan, Porsche, Rolls Royce, Toyota, as well as in software from Reviver, SiriusXM, and Spireon.

The flaws run a wide gamut, ranging from those that give access to internal company systems and user information to weaknesses that allow attackers to send commands to achieve code execution remotely.

Microsoft… Microsoft Ended Windows 7 security updates https://www.bleepingcomputer.com/news/microsoft/microsoft-ends-windows-7-extended-security-updates-on-tuesday/

Windows 7 Professional and Enterprise editions will no longer receive extended security updates for critical vulnerabilities starting Tuesday, January 10, 2023.

The Extended Security Update (ESU) program was the last resort option for customers who still needed to run legacy Microsoft products past their end of support on Windows 7 systems.

All editions of Windows 8.1, launched nine years ago in November 2013, also reached EOS on the same day.

T-Mobile… T-Mobile admits to 37,000,000 customer records stolen by "bad actor." https://nakedsecurity.sophos.com/2023/01/20/t-mobile-admits-to-37000000-customer-records-stolen-by-bad-actor/

In plain English: the crooks found a way in from outside, using simple web-based connections that allowed them to retrieve private customer information without needing a username or password.

T-Mobile first states the sort of data it thinks attackers didn't get, which includes payment card details, social security numbers (SSNs), tax numbers, other personal identifiers such as driving licenses or government-issued IDs, passwords, and PINs, and financial information such as bank account details.

View Details

Google Ads were weaponized in a way that made them appear like any other ad – Allowed hackers to infect computers with malware via a single click.https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-to-spread-malware-in-legit-software/

Hackers have weaponized Google Ads to spread malware to unsuspecting users by disguising them as regular ads. They do this by cloning the official websites of popular software products, such as Grammarly, Audacity, μTorrent, and OBS, and distributing trojanized versions of the software when users click the download button. This tactic allows hackers to infect users' computers with malware through a single click. Google Ads, also known as Google AdWords, is a platform provided by Google that allows businesses and individuals to create and display online advertisements on various websites and platforms across the internet, including Google's own search engine results pages. Advertisers can create and target ads based on keywords, demographics, interests, and other factors to reach potential customers. The ads are typically displayed as text, images, or video and can be tailored to specific audiences. Advertisers pay for the ads on a pay-per-click or pay-per-impression basis, depending on the specific ad format chosen.

++++++++

Identifying People Using Cell Phone Location Data https://www.schneier.com/blog/archives/2023/01/identifying-people-using-cell-phone-location-data.html

The use of cell phone location data is a powerful tool for identifying individuals, as demonstrated in the case of the recent power station attacks. Court documents reveal that investigators were able to quickly identify suspects Greenwood and Crahan by analyzing cell phone data that placed them near the scene of all four attacks. It is important to note that this type of surveillance can be highly effective, as even turning off one's cell phone would likely not be enough to evade detection in this instance. Given the widespread use of cell phones, it is likely that a small number of individuals in the Washington area were in the vicinity of the attacks and had their phones turned off during that time, making them easy to investigate.

++++++++

WhatsApp Was Hacked By an Israeli Company – US Supreme Court Allows WhatsApp to Sue NSO Group https://www.infosecurity-magazine.com/news/us-supreme-court-whatsapp-to-sue/

On Monday, the US Supreme Court cleared the way for WhatsApp to take legal action against NSO Group, an Israeli surveillance firm, for allegedly installing the Pegasus spyware on approximately 1400 devices where the messaging app was also installed. The court's ruling allows WhatsApp to seek damages for the harm caused by the unauthorized installation of the spyware. It is yet to be seen if this case will set a precedent for further litigation regarding "cyber weapons" and outsourced operations, but it raises concerns about private companies being used as a cover for governments that are not necessarily allied with the West, according to Barratt.

++++++++

Identity Thieves Bypassed Experian Security to View Credit Reports https://krebsonsecurity.com/2023/01/identity-thieves-bypassed-experian-security-to-view-credit-reports/

Identity thieves have been taking advantage of a significant vulnerability on the website of Experian, one of the major credit reporting bureaus. Typically, Experian requires individuals requesting a copy of their credit report to answer multiple-choice questions about their financial history. However, until the end of 2022, Experian's website had a vulnerability that allowed anyone to bypass these questions and directly access the consumer's credit report by simply providing their name, address, birthday and Social Security Number. The security weakness was discovered as the crooks figured out they could manipulate Experian's identity verification process by altering the address displayed in the browser's URL bar at a specific point in the process.

View Details

Artificial Intelligence is changing the world. Right Now!

In just a few years, it's possible that you might be chatting with a support agent who doesn't have a human body. You'll be able to ask them anything you want and get an answer immediately. Not only that, but they'll be able to help you with things like scheduling appointments, making payments, and booking flights—without any human intervention necessary.

This is just one of the many ways that Artificial Intelligence will change our lives this year. We will see more businesses using AI technology to make their processes more efficient and effective.

And if you think this is just another boring news story about how artificial intelligence is taking over everything… well, sorry to tell you that most of these "news stories" are probably written by computers anyway!

Cars… Touch Screens on Dashboards Found to be Dangerous Evidence suggests that touch screens in cars may be more distracting than traditional controls such as knobs or buttons. This is because touch screens require drivers to take their eyes off the road and focus on the screen to interact with them, which can increase the risk of a crash.

In contrast, traditional controls such as knobs or buttons can often be operated by feel, allowing drivers to keep their eyes on the road while adjusting settings such as the radio or the climate control.

https://futurism.com/the-byte/study-finds-that-buttons-in-cars-are-safer-and-quicker-to-use-than-touchscreens

Study Finds That Buttons in Cars are Safer and Easier to Use Than Touchscreens. It turns Out That Slapping a Giant iPad Onto Your Dashboard Isn’t An Ideal Way To Control Your Car

+++++++

BMW starts selling heated seat subscriptions for $18 a month https://www.theverge.com/2022/7/12/23204950/bmw-subscriptions-microtransactions-heated-seats-feature

A monthly subscription to heat your BMW’s front seats costs roughly $18, with options to subscribe for a year ($180), three years ($300), or pay for “unlimited” access for $415.

BMW has slowly been putting features behind subscriptions since 2020, and heated seat subscriptions are now available in BMW’s digital stores in countries including the UK, Germany, New Zealand, and South Africa. However, it doesn’t seem to be an option in the US.

For some software features that might lead to ongoing expenses for the carmaker (like automated traffic camera alerts, for example), charging a subscription seems more reasonable. But that’s not an issue for heated seats.

Tesla… I’ve driven more than 1,000 miles in Teslas — and I’ll never buy one https://www.tomsguide.com/opinion/ive-driven-more-than-1000-miles-in-teslas-and-ill-never-buy-one

My biggest problem with the Tesla design is the extreme minimalism employed throughout the cabin. In the Model 3 and Model Y, this means virtually everything is condensed into a single central touchscreen. In fact, only a handful of features don’t employ the touchscreen in some way, and those are relegated to a few levers and dials around the steering column.

The thing that always baffles me most is that Tesla’s two cheapest cars don’t have a dedicated driver display or gauge cluster behind the steering wheel. Instead, you must glance at the central display if you want something as simple and important as your current speed.

The overreliance on the touchscreen is my biggest issue. Not only because of the lack of tactile feedback, ensuring you can’t use the smooth and glossy device without looking, but also because any fault in the screen will render your car completely useless. My Leaf’s infotainment display died recently, taking a bunch of useful car functions with it. But a functional driver display meant I could still drive around safely and know how fast I was going.

Twitter… Hackers leak email addresses of 235 million Twitter users https://nypost.com/2023/01/06/hackers-leak-email-addresses-of-235-million-twitter-users-report/

Hackers obtained the email addresses of more than 235 million Twitter users and published them on an internet forum. The breach “will unfortunately lead to a lot of hacking, targeted phishing and doxxing,” Alon Gal, co-founder of Israeli cybersecurity-monitoring firm Hudson Rock.

“This database is going to be used by hackers, political hacktivists and of course governments to harm our privacy even further.”

Phishing is a tactic used by cybercriminals who send emails or text messages claiming to be from reputable companies. These messages ask their targets to send them personal information, including credit card numbers, passwords, and other sensitive data.

Jobs… Amazon Layoffs to Hit Over 18,000 Workers, the Most in Recent Tech Wave https://www.wsj.com/articles/amazon-to-lay-off-over-17-000-workers-more-than-first-planned-11672874304

Cuts focused on the company’s corporate staff exceed earlier projections and represent about 5% of the company’s corporate workforce. Amazon.com Inc.’s layoffs will affect more than 18,000 employees, the highest reduction tally revealed in the past year at a major technology company as the industry pares back amid economic uncertainty.

View Details

Privacy… Ring Cameras Hacked in 'Swatting' Scheme https://www.entrepreneur.com/business-news/ring-cameras-hacked-in-swatting-scheme/441518

Critics and researchers say the Ring cameras are used to surveil gig economy drivers and delivery people and that they give law enforcement too much power to survey everyday life.

The pair would hack people's Yahoo email accounts, then their Ring accounts, find their addresses, call law enforcement to the home with a bogus story, and then stream police's response to the call. Often, they would harass the first responders at the same time using Ring device capabilities.

++++++++

LastPass finally admits: Those crooks who got in? They did steal your password vaults, after all… https://nakedsecurity.sophos.com/2022/12/23/lastpass-finally-admits-they-did-steal-your-password-vaults-after-all/

…“customers’ information” turns out to include both customer data and password databases. Loosely speaking, the crooks now know who you are, where you live, which computers on the internet are yours, how to contact you electronically, and also have a detailed map of where you go when you’re online.

It’s therefore reasonable to assume that only users who had chosen easy-to-guess or early-to-crack passwords are at serious risk, and that anyone who has taken the trouble to change their passwords since the initial breach announcement has probably kept ahead of the crooks.

++++++++

Researcher Uncovers Potential Wiretapping Bugs in Google Home Smart Speakers https://thehackernews.com/2022/12/researcher-uncovers-potential.html

A security researcher was awarded a bug bounty of $107,500 for identifying security issues in Google Home smart speakers that could be exploited to install backdoors and turn them into wiretapping devices.

The flaws "allowed an attacker within wireless proximity to install a 'backdoor' account on the device, enabling them to send commands to it remotely over the internet, access its microphone feed, and make arbitrary HTTP requests within the victim's LAN," the researcher, who goes by the name Matt, disclosed in a technical write-up published this week.

TikTok… TikTok’s Parent Company Admits Using the Platform’s Data to Track Journalists https://www.infosecurity-magazine.com/news/tiktoks-admits-using-its-data/

What was just a rumor has been confirmed: employees of ByteDance, the China-based company that owns TikTok and its Chinese counterpart Douyin, accessed data from TikTok to track a Financial Times reporter and a former BuzzFeed reporter in a bid to identify the source of leaks to the media.

ByteDance condemned the "misguided initiative that seriously violated the company's code of conduct" and that none of the employees found to have been involved remained employed by the company. The Guardian reported that a person briefed on the matter said four ByteDance employees involved in the incident were fired, including two in China and two in the United States.

Apple… EU forces Apple to Rip a Huge Hole in iPhone security https://www.cultofmac.com/800222/eu-forces-apple-to-rip-huge-hole-in-iphone-security/

Criminals around the world are surely celebrating news that Apple is being forced by the N. The move will allow hackers to release a fresh tidal wave of malware, hoping to slip it onto iOS handsets. iPhone users will be forced to fend off attempts to trick them into installing this malware virtually every day.

Most iPhone users have never had to think much about malware. Because iOS devices get all their applications from the App Store, it’s nearly impossible for hackers to slip spyware or other nasty apps into iPhones.

Expect to see fraudulent pop-up windows crafted to look as much like Apple notices to trick users into installing malware.

Linux… Critical “10-out-of-10” Linux kernel SMB hole – should you worry? https://nakedsecurity.sophos.com/2022/12/27/critical-10-out-of-10-linux-kernel-smb-hole-should-you-worry/

SMB is short for server message block, and it’s the protocol that underpins Windows networking, so almost any Linux server that provides network services to Windows computers will be running software to support SMB.

SMB support is also generally needed in home, and small-business NAS (network-attached storage) devices, which generally run Linux internally, and provide easy-to-use, plug-it-in-and-go file server features for small networks.

View Details

Craig Peterson

Insider Show NotesDecember 5 to December 11, 2022

China… Apple Makes Plans to Move Production Out of China https://www.wsj.com/articles/apple-china-factory-protests-foxconn-manufacturing-production-supply-chain-11670023099

In recent weeks, Apple Inc. has accelerated plans to shift some of its production outside China, long the dominant country in the supply chain that built the world’s most valuable company, say people involved in the discussions. It is telling suppliers to plan more actively for assembling Apple products elsewhere in Asia, particularly India and Vietnam, they say and looking to reduce dependence on Taiwanese assemblers led by Foxconn Technology Group.

After a year of events that weakened China’s status as a stable manufacturing center, the upheaval means Apple no longer feels comfortable having so much of its business tied up in one place, according to analysts and people in the Apple supply chain.

Cybercrime… Spyware posing as VPN apps https://www.welivesecurity.com/videos/spyware-posing-vpn-apps-week-security-tony-anscombe/

Bahamut APT group targets Android users via trojanized versions of two legitimate VPN apps – SoftVPN and OpenVPN. Since January 2022, Bahamut has distributed at least eight malicious apps to pilfer sensitive user data and actively spy on victims’ messaging apps. These apps were never available for download from Google Play; instead, they were distributed through a fake SecureVPN website.

++++++++

Darknet markets generate millions in revenue by selling stolen personal data https://arstechnica.com/tech-policy/2022/12/darknet-markets-generate-millions-in-revenue-selling-stolen-personal-data/

Stolen data products flow through a supply chain consisting of producers, wholesalers, and consumers.

The stolen data supply chain begins with producers—hackers who exploit vulnerable systems and steal sensitive information such as credit card numbers, bank account information, and Social Security numbers. Next, the stolen data is advertised by wholesalers and distributors who sell the data. Finally, the data is purchased by consumers who use it to commit various forms of fraud, including fraudulent credit card transactions, identity theft, and phishing attacks.

++++++++

Voice-scamming site “iSpoof” seized, 100s arrested in a massive crackdown https://nakedsecurity.sophos.com/2022/11/25/voice-scamming-site-ispoof-seized-100s-arrested-in-massive-crackdown/

Whether you call it Caller ID or CLI, it’s no more use in identifying the caller’s actual phone number than the “From:” header in an email is in identifying the sender of an email.

As a cybersecurity measure to help you identify callers you do trust, [Caller-ID] has an extreme false negative problem, meaning that if a call pops up from Dad, or Auntie Gladys, or perhaps more significantly, from Your Bank…

…then there’s a significant risk that it’s a scam call that’s deliberately been manipulated to get past your “do I know the caller?” test.

++++++++

U.S. Govt. Apps Bundled Russian Code With Ties to Mobile Malware Developer https://krebsonsecurity.com/2022/11/u-s-govt-apps-bundled-russian-code-with-ties-to-mobile-malware-developer/

A recent scoop by Reuters revealed that mobile apps for the U.S. Army and the Centers for Disease Control and Prevention (CDC) were integrating software that sends visitor data to a Russian company called Pushwoosh, which claims to be based in the United States. But that story omitted a crucial historical detail about Pushwoosh: In 2013, one of its developers admitted to authoring the Pincer Trojan, malware designed to intercept and forward text messages from Android mobile devices surreptitiously.

Reuters also learned that the company’s address in California does not exist and that two LinkedIn accounts for Pushwoosh employees in Washington, D.C. were fake.

Android… Samsung’s Android app-signing key has leaked and is being used to sign malware https://arstechnica.com/gadgets/2022/12/samsungs-android-app-signing-key-has-leaked-is-being-used-to-sign-malware/

A developer's cryptographic signing key is one of the major linchpins of Android security. Any time Android updates an app, the old app's signing key on your phone must match the key of the update you're installing.

If a developer's signing key leaked, anyone could distribute malicious app updates, and Android would happily install them, thinking they are legit.

On Android, the app-updating process isn't just for apps downloaded from an app store; you can also update bundled-in system apps made by Google, your device manufacturer, and any other bundled apps.

ZeroTrust… Cloud security starts with zero trust https://www.helpnetsecurity.com/2022/11/28/cloud-zero-trust/

Most organizations have outdated security systems that are generally based on-premises. These outdated systems often add an extra layer of complexity to shifting to the cloud, but this complexity does not mean organizations should hold off on this shift.

View Details

It's not your imagination: Shopping on Amazon has gotten worse https://www.washingtonpost.com/technology/interactive/2022/amazon-shopping-ads/

[Amazon founder Jeff Bezos owns The Washington Post]

Sure, Google and Facebook are chock full of ads, too. But on Amazon, we're supposed to be the customers, not the eyeballs for sale. We're paying Amazon to buy a product and probably paying for a membership in its Prime two-day shipping product.

When you search for a product on Amazon, you may not realize that most of what you see at first is advertising. Amazon is betraying your trust in its results to make an extra buck.

I call it the "shill results" business. Even when they contain a tiny disclaimer label — as do Amazon's — these ads can be misleading because they fill up spaces people have every reason to expect to collect trustworthy, independent information.

Privacy… Tor vs. VPN: Which should you choose? https://www.welivesecurity.com/2022/11/18/tor-vs-vpn-which-choose/

Tor and a VPN can significantly help you keep prying eyes away from your online life, but they're also two very different beasts. Which suits your needs better?

Tor is focused on anonymity. It relies on a network of servers, known as Tor nodes, located worldwide. These servers are set up by volunteer individuals and organizations that allocate their resources, computer, and internet bandwidth to support the network operations. Tor connects you to a random network of at least three nodes.

VPN providers rely on a network of dedicated servers. Once you connect to them, your IP address will be hidden from the websites you visit, and only the VPN you're using will know your real identity. Most reputable VPNs claim not to keep records of your online activity but do not provide anonymity.

++++++++

5 Free Tools to Check If Your Browser Is Safe and Private https://www.makeuseof.com/free-tools-test-browser-security/

  1. Privacy Analyzer conducts various tests to help you gauge your browser's safety. To launch it, press the START TEST button. In a few seconds, you will get five detailed reports explaining what the website you visit knows about you.
  2. Qualys BrowserCheck scans a browser for potential vulnerabilities and other security issues and notifies users if they need to remove a plugin, install an update, etc.
  3. Cover Your Tracks is a competent tool that tests if your browser protects you from tracking
  4. AmIUnique determines if your browser is leaving a unique fingerprint online, making it easier for advertisers to target you. In addition, it is more detailed (and technical) than Cover Your Tracks.
  5. Cloudflare's tool will check if you are using a DNS resolver, analyze if you can be attacked via your browser, check if threat actors can see the certificates of websites your browser connects to, and so on.

Also included in the article is what to do if your browser fails, with recommendations on browsers and settings.

++++++++

Thinking about taking your computer to the repair shop? Be very afraid! https://arstechnica.com/information-technology/2022/11/half-of-computer-repairs-result-in-snooping-of-sensitive-data-study-finds/

If you've ever worried about the privacy of your sensitive data when seeking a computer or phone repair, a new study suggests you have a good reason. It found that privacy violations occurred at least 50 percent of the time, not surprisingly, with female customers bearing the brunt.

Researchers recovered logs from laptops after receiving overnight repairs from 12 commercial shops. The records showed that technicians from six locations had accessed personal data and that two shops also copied data onto a personal device. In addition, devices belonging to females were more likely to be snooped on, and snooping tended to seek more sensitive data, including sexually revealing and non-sexual pictures, documents, and financial information.

++++++++

Google Changes Maps URL & Now Can Track You Everywhere - Even When You're Not Using Maps https://www.instapaper.com/read/1556652472

maps.google.com was the defacto domain for Google Maps. Also, for as long as I can remember, I allowed this domain to use the location services of my browser.

Yesterday I was asked to allow the usage of location services for Google Maps seemingly out of nowhere. Of course, I accepted. After all, I just wanted to check a route to a local business and was in a hurry. Back home, I opened Google Maps again and noticed maps.google.com now redirects to google.com/maps. This implies that the permissions I give to Google Maps now apply to all of Google's services hosted under this domain.

Spies… U.S. Bans Chinese Telecom Equipment and Surveillance Cameras Over National Security Risk https://thehackernews.com/2022/11/us-bans-chinese-telecom-equipment-and.html

The U.S. Federal Communications Commission (FCC) formally announced it would no longer authorize electronic equipment from Huawei, ZTE, Hytera, Hikvision, and Dahua, deeming them an "unacceptable" national security threat.

"The FCC is committed to protecting our national security by ensuring that untrustworthy communications equipment is not authorized for use within our borders, and we are continuing that work here," FCC Chairwoman Jessica Rosenworcel said in a Friday order.

OpenSource… Misconfigurations, Vulnerabilities Found in 95% of Applications https://www.darkreading.com/application-security/misconfigurations-vulnerabilities-found-in-95-of-applications

Nearly every application has at least one vulnerability or misconfiguration that affects security, and a quarter of application tests found a highly or critically severe vulnerability, a new study shows.

With open-source software comprising nearly 80% of codebases, it's little surprise that 81% have at least one vulnerability, and another 85% have an open-source component that is four years out of date.

Scams… New extortion scam threatens to damage sites' reputation, leak data https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/

An active extortion scam targets website owners and admins worldwide, claiming to have hacked their servers and demanding $2,500 not to leak data.

The attackers are sending emails with "Your website, databases and emails has been hacked" subjects. The emails appear non-targeted, with ransom demand recipients from all verticals, including personal bloggers, government agencies, and large corporations.

Even though these emails can be scary to those website owners who receive them, it is essential to remember that they are just scams.

View Details

Malware… Authorities Arrest Developer of Malware Service - Was Your Credit Card or Other Personal Information Stolen? And How He Was Captured https://krebsonsecurity.com/2022/10/accused-raccoon-malware-developer-fled-ukraine-after-russian-invasion/

According to the U.S. Justice Department, FBI agents have identified more than 50 million unique credentials and forms of identification (email addresses, bank accounts, cryptocurrency addresses, credit card numbers, etc.) stolen.

Raccoon was essentially a Web-based control Crime-as-a-Service panel, where — for $200 a month — customers could get the latest version of the Raccoon Infostealer malware and interact with infected systems in real-time. Security experts say the passwords and other data stolen by Raccoon malware were often resold to groups engaged in deploying ransomware.

U.S. authorities zeroed in on a mistake that the Raccoon developer made early on in his posts to the crime forums, connecting a Gmail account for a cybercrime forum identity used by the Raccoon developer ("Photix") to an Apple iCloud account belonging to Sokolovsky.

Authorities soon tracked Sokolovsky's phone through Germany and eventually to The Netherlands, with his female companion helpfully documenting every step of the trip on her Instagram account.

Check If You Were Compromised: https://raccoon.ic3.gov/home

++++++++

Former Uber Chief Found Guilty of Hiding Hack From Authorities. https://www.nytimes.com/2022/10/05/technology/uber-security-chief-joe-sullivan-verdict.html

Joe Sullivan, the former Uber security chief, was found guilty by a jury in federal court on charges that he did not disclose a breach of customer and driver records to government regulators.

The case — believed to be the first time a company executive faced criminal prosecution over a hack — could change how security professionals handle data breaches.

Airbnb… Throwing the spotlight on hidden cameras in Airbnb https://www.welivesecurity.com/2022/11/01/spy-who-rented-to-me-hidden-cameras-airbnbs/

In recent years, some travelers have had their dream vacations ruined by one particularly creepy privacy risk – covert cameras in rental properties, which are often booked via platforms such as Airbnb. Ours is also a time when all sorts of surveillance gadgets are increasingly affordable; what's more, these gadgets are often tiny and/or designed to look like everyday objects – they are intended to be challenging to spot.

Airbnb's policy on the matter is pretty unequivocal. Security cameras and noise-monitoring devices are allowed "as long as they are clearly disclosed in the listing description and don't infringe on another person's privacy."

How to Find a Hidden Security Camera:

  • Physically check the room: Look for cameras hiding in plain sight, perhaps in clocks, smoke detectors, speakers, or even light bulbs
  • Use a flashlight: Camera lenses are made of glass, meaning they're reflective. So turn the lights down and shine a flashlight around the property.
  • Check for night vision lights: Turning the lights down or off will also help you spot the tell-tale red or green LEDs, which may illuminate night vision cameras.
  • Use an app: Researchers have been working on a mobile application that uses phones' Time-of-Flight (ToF) sensor to find spy cams hidden in everyday objects.
  • Detect RF signals: A final tell-tale sign of a hidden camera is to monitor for radio frequencies (RF) that the camera may use to connect to a secret network. In addition, a hidden camera may interfere with your phone signal, so stop and investigate.

Baby Monitors… Hacking baby monitors can be child's play: Here's how to stay safe https://www.welivesecurity.com/2022/11/07/hacking-baby-monitors-childs-play-how-stay-safe/

We've probably all read horror stories online: a parent is woken in the middle of the night by strange noises coming from their child's bedroom. They open the door, only to find a stranger "talking" to their baby through the monitor. While rare, such cases do happen from time to time.

How to Stay Safer:

  • Research your options well, and aim to go with a well-regarded manufacturer with a strong emphasis on security and good reviews.
  • Install any updates to the device's software (or firmware)
  • If possible, choose a model that does not allow remote communication via an app. If it does, turn off remote access, especially when not in use.
  • I am setting up a solid and unique password and enabling two-factor authentication if possible.
  • Review monitor logs regularly to check for any suspicious activity, such as individuals accessing it from a unique IP or at strange times.
  • Secure your wireless router with a strong, unique password. Also, disable remote access to it and port forwarding or UPnP. Finally, make sure the router is kept updated with any firmware patches.

Apple… Apple Tracks You Even With Its Own Privacy Protections on, Study Says https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558

For all of Apple's talk about how private your iPhone is, the company vacuums up a lot of data about you. But, of course, iPhones have a privacy setting that is supposed to turn off that tracking. According to a new report by independent researchers, though, Apple collects highly detailed information on you with its apps even when you turn off tracking, an apparent direct contradiction of Apple's own description of how their privacy protection works.

Security researchers at the software company Mysk looked at the data collected by several Apple iPhone apps—the App Store, Apple Music, Apple TV, Books, and Stocks. They found the analytics control and other privacy settings had no noticeable effect on Apple's data collection—the tracking remained the same whether iPhone Analytics was switched on or off.

"The level of detail is shocking for a company like Apple," Mysk told Gizmodo.

++++++++

Apple clarifies security update policy: Only the latest OSes are fully patched. Despite providing security updates for multiple versions of macOS and iOS at any given time, Apple says that only devices running the most recent major operating system versions should expect to be fully protected.

In other words, while Apple will provide security-related updates for older versions of its operating systems, only the most recent upgrades will receive updates for every security problem Apple knows about. For example, apple currently provides security updates to macOS 11 Big Sur and macOS 12 Monterey alongside the newly released macOS Ventura. In addition, in the past, it has released security updates for older iOS versions for devices that can't install the latest upgrades.

Most Macs still receive six or seven years of upgrades, plus another two years of security updates.

View Details

The Semiconductor Industry Is Coming for Your Wallet -
DuckDuckGo Should Be Your Go-To Search Engine -
Which Messaging Apps Are Secure: Signal vs. WhatsApp -
The Upside-Down Logic of Electric SUVs -
Biden Goes Nuclear POWER!
Amazon might own your doctor's office after their latest acquisition.

The Semiconductor Industry Is Coming for Your Wallet. As Usual, Congress Is Complicit https://fee.org/articles/the-semiconductor-industry-is-coming-for-your-wallet-as-usual-congress-is-complicit/

In recent months, the auto and tech sectors have faced unprecedented delays and rising prices. Some used cars are even selling for more than their new counterparts because of the delays, a sure sign that production has slowed dramatically.

To address this, Congress is contemplating bipartisan legislation known as the Chips Act, which would provide $52 billion in grants and $24 billion in tax credits to the US semiconductor industry. Unfortunately, thanks to a last-minute bipartisan amendment, the bill will also put tens of billions of dollars toward various federal agencies, bringing the total price tag to $250 billion.

++++++++

DuckDuckGo Should Be Your Go-To Search Engine. Here's Why https://www.cnet.com/tech/services-and-software/duckduckgo-should-be-your-go-to-search-engine-heres-why/

Since Facebook's Cambridge Analytica scandal, people have become more aware of what information they give companies and advertisers, sometimes without their knowledge or consent. Unfortunately, the data breaches also rose to a record high of 1,862 in 2021. As a result, more people are taking steps to protect their information, and one way some folks do that is by using the search engine DuckDuckGo.

DuckDuckGo has positioned itself as a privacy-focused alternative to search engines like Google. DuckDuckGo has rolled out Android and iOS mobile apps and browser extensions to help keep your information secure, no matter if you use it on your phone or computer.

  • Stop online trackers from spying on you
  • You'll see fewer ads
  • Websites should load faster
  • Your search history isn't stored
  • Your browsing history won't influence your search results.

++++++++

Messaging Apps That Are Secure: Signal vs. WhatsApp https://www.thestreet.com/technology/messaging-apps-that-are-secure-signal-vs-whatsapp

Two messaging apps, Signal and WhatsApp, have become commonplace for people to talk to each other instead of sending a text. The Signal is more secure since the app provides end-to-end encryption by default, and the company does not keep records of your communications. However, while messages on WhatsApp are specific, end-to-end encryption is not on by default, leaving the responsibility up to consumers.

One advantage of Signal is that "all of your messages are stored locally on your device and not Signal's servers," the spokesperson said. "Signal doesn't have access to what you send or with whom you communicate with and does not hinfluencethe content anyone receives. EIn addition, every call and message sent through Signal is encrypted by default."

A hiccup is that, based on the history of Meta, the company keeps data forever.

++++++++

The Upside-Down Logic of Electric SUVs https://www.wsj.com/articles/the-upside-down-logic-of-electric-suvs-vehicles-co2-emissions-ford-subsidies-climate-change-auto-sector-11658524738

The auto industry gambles its finances on big electric vehicles for the rich, like Ford's Mustang Mach-E and GM's Hummer EV, and second-rate cars for everybody else.

If consumers and businesses cared about the CO2 they emit, the last cars they might buy are hot-selling EVs like Ford's Mustang Mach-E or GM's Hummer EV.

These large-battery, long-range vehicles would have to be driven many tens of thousands of miles before they rack up enough mileage and save enough gasoline from compensating for the emissions created to produce their batteries. And that's according to their fans, whose calculations often smell of friendly assumptions about the source of the electricity consumed, whether gasoline driving is being displaced mile for mile, and a presumed lack of progress in reducing the carbon intensity of conventional motor fuels. The most problematic assumption is that EV use causes oil to stay in the ground.

++++++++

Biden goes nuclear https://www.americanthinker.com/blog/2022/07/biden_goes_nuclear.html

Biden wants to turn to nuclear power in his zeal to end the burning of carbon-based fuels. As well, he should. Because nuclear is as carbon-friendly as windmills or solar parks and is a lot more reliable.

President Biden has made several pro-nuclear statements within the past few weeks.

++++++++

Amazon might own your doctor's office after the latest acquisition https://arstechnica.com/tech-policy/2022/07/amazon-might-own-your-doctors-office-after-latest-acquisition/

When Amazon launched Amazon Care to its employees in 2019, the goal was to test the product before rolling it out nationwide. After that rollout happened earlier this year, Amazon CEO Andy Jassy told Insider that the expansion would "fundamentally" change the healthcare game by dramatically enhancing the medical-care process. He predicted that patients in the future would be so used to telehealth and other new conveniences that they'll think that things like long wait times and delays between in-person visits commonly experienced today are actually "insane."

The Wall Street Journal reports that Amazon has gone one step closer to that future by agreeing to a $3.9 billion deal to purchase One Medical, a company that operates a network of health clinics. With this move, Amazon will expand the number of patients it serves by gaining access to "a practice that operates more than 180 medical offices in 25 US markets and works with more than 8,000 companies to provide health benefits to employees, including in-person and virtual care."

View Details

The Semiconductor Industry Is Coming for Your Wallet -
DuckDuckGo Should Be Your Go-To Search Engine -
Which Messaging Apps Are Secure: Signal vs. WhatsApp -
The Upside-Down Logic of Electric SUVs -
Biden Goes Nuclear POWER!
Amazon might own your doctor's office after their latest acquisition.

The Semiconductor Industry Is Coming for Your Wallet. As Usual, Congress Is Complicit https://fee.org/articles/the-semiconductor-industry-is-coming-for-your-wallet-as-usual-congress-is-complicit/

In recent months, the auto and tech sectors have faced unprecedented delays and rising prices. Some used cars are even selling for more than their new counterparts because of the delays, a sure sign that production has slowed dramatically.

To address this, Congress is contemplating bipartisan legislation known as the Chips Act, which would provide $52 billion in grants and $24 billion in tax credits to the US semiconductor industry. Unfortunately, thanks to a last-minute bipartisan amendment, the bill will also put tens of billions of dollars toward various federal agencies, bringing the total price tag to $250 billion.

++++++++

DuckDuckGo Should Be Your Go-To Search Engine. Here's Why https://www.cnet.com/tech/services-and-software/duckduckgo-should-be-your-go-to-search-engine-heres-why/

Since Facebook's Cambridge Analytica scandal, people have become more aware of what information they give companies and advertisers, sometimes without their knowledge or consent. Unfortunately, the data breaches also rose to a record high of 1,862 in 2021. As a result, more people are taking steps to protect their information, and one way some folks do that is by using the search engine DuckDuckGo.

DuckDuckGo has positioned itself as a privacy-focused alternative to search engines like Google. DuckDuckGo has rolled out Android and iOS mobile apps and browser extensions to help keep your information secure, no matter if you use it on your phone or computer.

  • Stop online trackers from spying on you
  • You'll see fewer ads
  • Websites should load faster
  • Your search history isn't stored
  • Your browsing history won't influence your search results.

++++++++

Messaging Apps That Are Secure: Signal vs. WhatsApp https://www.thestreet.com/technology/messaging-apps-that-are-secure-signal-vs-whatsapp

Two messaging apps, Signal and WhatsApp, have become commonplace for people to talk to each other instead of sending a text. The Signal is more secure since the app provides end-to-end encryption by default, and the company does not keep records of your communications. However, while messages on WhatsApp are specific, end-to-end encryption is not on by default, leaving the responsibility up to consumers.

One advantage of Signal is that "all of your messages are stored locally on your device and not Signal's servers," the spokesperson said. "Signal doesn't have access to what you send or with whom you communicate with and does not hinfluencethe content anyone receives. EIn addition, every call and message sent through Signal is encrypted by default."

A hiccup is that, based on the history of Meta, the company keeps data forever.

++++++++

The Upside-Down Logic of Electric SUVs https://www.wsj.com/articles/the-upside-down-logic-of-electric-suvs-vehicles-co2-emissions-ford-subsidies-climate-change-auto-sector-11658524738

The auto industry gambles its finances on big electric vehicles for the rich, like Ford's Mustang Mach-E and GM's Hummer EV, and second-rate cars for everybody else.

If consumers and businesses cared about the CO2 they emit, the last cars they might buy are hot-selling EVs like Ford's Mustang Mach-E or GM's Hummer EV.

These large-battery, long-range vehicles would have to be driven many tens of thousands of miles before they rack up enough mileage and save enough gasoline from compensating for the emissions created to produce their batteries. And that's according to their fans, whose calculations often smell of friendly assumptions about the source of the electricity consumed, whether gasoline driving is being displaced mile for mile, and a presumed lack of progress in reducing the carbon intensity of conventional motor fuels. The most problematic assumption is that EV use causes oil to stay in the ground.

++++++++

Biden goes nuclear https://www.americanthinker.com/blog/2022/07/biden_goes_nuclear.html

Biden wants to turn to nuclear power in his zeal to end the burning of carbon-based fuels. As well, he should. Because nuclear is as carbon-friendly as windmills or solar parks and is a lot more reliable.

President Biden has made several pro-nuclear statements within the past few weeks.

++++++++

Amazon might own your doctor's office after the latest acquisition https://arstechnica.com/tech-policy/2022/07/amazon-might-own-your-doctors-office-after-latest-acquisition/

When Amazon launched Amazon Care to its employees in 2019, the goal was to test the product before rolling it out nationwide. After that rollout happened earlier this year, Amazon CEO Andy Jassy told Insider that the expansion would "fundamentally" change the healthcare game by dramatically enhancing the medical-care process. He predicted that patients in the future would be so used to telehealth and other new conveniences that they'll think that things like long wait times and delays between in-person visits commonly experienced today are actually "insane."

The Wall Street Journal reports that Amazon has gone one step closer to that future by agreeing to a $3.9 billion deal to purchase One Medical, a company that operates a network of health clinics. With this move, Amazon will expand the number of patients it serves by gaining access to "a practice that operates more than 180 medical offices in 25 US markets and works with more than 8,000 companies to provide health benefits to employees, including in-person and virtual care."

View Details

What Happens When a Scammer Has Your Email Address?
Prevention - Signs You're Hacked - Recovery

While your email address might not seem that valuable, scammers can extract a lot of information that they can use against you. Below are some things they can do with your email address information:

  • Scammers Can Impersonate You
  • Send Phishing Emails
  • Scammers Can Access Your Online Accounts

How to Protect Your Email Address from Scammers? * Using Robust Passwords * Set Up Multi-Factor Authentication * Update Your Device’s Security Software * Enable Dark Web Monitoring

Signs Your Email Account Has Been Hacked * You can’t log in to your account * Strange messages pop up on your social media accounts * Your family members or friends are receiving emails you didn’t send * Your sent-message folder contains spammy messages you don’t remember writing

How to Help Recover Your Email Account from a Scammer * If you can still access your account, change your login credentials immediately * Inform your friends and family members about the hack so they don’t fall for the scams sent by the hackers * Contact your banks and credit providers if you have sensitive financial information in your inbox. They can help prevent unauthorized access to your account. * Seek the help of an identity and credit monitoring service like IdentityIQ to help protect you. This service can provide real-time fraud and Social Security number alerts, the dark web and internet monitoring, and even identity theft insurance. Plus, protection plans are affordable. * If you’re completely locked out of your account, contact your email provider for advice on how to recover and protect your account.

View Details

What Happens When a Scammer Has Your Email Address?
Prevention - Signs You're Hacked - Recovery

While your email address might not seem that valuable, scammers can extract a lot of information that they can use against you. Below are some things they can do with your email address information:

  • Scammers Can Impersonate You
  • Send Phishing Emails
  • Scammers Can Access Your Online Accounts

How to Protect Your Email Address from Scammers? * Using Robust Passwords * Set Up Multi-Factor Authentication * Update Your Device’s Security Software * Enable Dark Web Monitoring

Signs Your Email Account Has Been Hacked * You can’t log in to your account * Strange messages pop up on your social media accounts * Your family members or friends are receiving emails you didn’t send * Your sent-message folder contains spammy messages you don’t remember writing

How to Help Recover Your Email Account from a Scammer * If you can still access your account, change your login credentials immediately * Inform your friends and family members about the hack so they don’t fall for the scams sent by the hackers * Contact your banks and credit providers if you have sensitive financial information in your inbox. They can help prevent unauthorized access to your account. * Seek the help of an identity and credit monitoring service like IdentityIQ to help protect you. This service can provide real-time fraud and Social Security number alerts, the dark web and internet monitoring, and even identity theft insurance. Plus, protection plans are affordable. * If you’re completely locked out of your account, contact your email provider for advice on how to recover and protect your account.

View Details

Can You Secure Security Cameras? The Coming Green Energy Nightmare - Email Scams Hitting Businesses and Lonely Hearts Scams… Eight questions to ask yourself before getting a security camera https://www.welivesecurity.com/2022/10/03/8-questions-ask-yourself-getting-home-security-camera/

Security cameras were once the preserve of the rich and famous. Now anyone can get their hands on one thanks to technological advances. The advent of the Internet of Things (IoT) has created a significant new market – for manufacturers of devices like connected doorbells and baby monitors and more sophisticated whole-of-property systems. Connected to home Wi-Fi networks, these devices allow owners to watch live video footage, record video for later, and receive alerts when out of the house.

Yet these same features can also expose households to new risks if the camera is compromised and the footage is leaked. Not all vendors have as big a focus on security and privacy as they should. That means you need to ask the right questions before starting.

++++++++

Romance scammer and BEC fraudster sent to prison for 25 years https://nakedsecurity.sophos.com/2022/10/04/romance-scammer-and-bec-fraudster-sent-to-prison-for-25-years/

Elvis Eghosa Ogiekpolor was jailed for 25 years in Atlanta, Georgia, for running a cybercrime group that scammed close to $10,000,000 in under two years from individuals and businesses caught up in the so-called romance and BEC scams.

BEC is short for business email compromise, an umbrella term for a form of online scam in which the attackers acquire login access to email accounts inside a company so that the fraudulent emails they send don’t just seem to come from the company they’re attacking, but do come from there.

++++++++

How a deepfake Mark Ruffalo scammed half a million dollars from a lonely heart https://grahamcluley.com/how-a-deepfake-mark-ruffalo-scammed-half-a-million-dollars-from-a-lonely-heart/

The Asahi Shimbun reports that 74-year-old Manga artist Chikae Ide received an unsolicited message via Facebook in February 2018 from somebody claiming to be Ruffalo.

With help from some translation software, an initially skeptical Ide responded to the Hollywood actor, attaching a photograph of herself. An American friend of Ide subsequently questioned whether the person claiming to be Ruffalo was genuine, noting that he wrote: “like somebody who has not learned English.”

But, says Ide, a 30-second video call blew away any suspicions.

“I’m sure it was Mark himself behind the screen chatting with me,” Ide said.

Energy… The Coming Green Electricity Nightmare https://wattsupwiththat.com/2022/10/02/the-coming-green-electricity-nightmare/

What this net-zero transition would require:

How many millions of wind turbines, billions of solar panels, billions of EVs, backup batteries, millions of transformers, thousands of miles of transmission lines – sprawling across millions of acres of wildlife habitat, scenic and agricultural lands, and people’s once-placid backyards?

To cite just one example, just the 2,500 wind turbines needed for New York electricity (30,000 megawatts) would require nearly 110,000 tons of copper – which would necessitate mining, crushing, processing, and refining 25 million tons of copper ore … after removing some 40 million tons of overlying rock to reach the ore bodies. Multiply that times 50 states – and the entire world – plus transmission lines.

Spooks… FLASHBACK: CIA Sabotaged Soviet Pipeline to Europe in 1982 - US Software Caused Massive Explosion in Siberian Pipeline Seen From Space https://www.thegatewaypundit.com/2022/10/flashback-cia-sabotaged-soviet-pipeline-europe-1982-us-software-caused-massive-explosion-siberian-pipeline-seen-space/

Back in 1982, the CIA sabotaged a Soviet pipeline in Siberia. US software caused a gas pipeline explosion so large it could be seen in space. The Americans did not want the Europeans to purchase Soviet gas.

In January 1982, President Ronald Reagan approved a CIA plan to sabotage the economy of the Soviet Union through covert transfers of technology that contained hidden malfunctions, including software that later triggered a massive explosion in a Siberian natural gas pipeline, according to a memoir by a Reagan White House official.

++++++++

Former NSA Employee Faces Death Penalty for Selling Secrets https://www.darkreading.com/attacks-breaches/ex--nsa-employee-faces-death-penalty-for-selling-secrets

When he left his job as an information systems security designer with the National Security Agency, Jareh Sebastian Dalke allegedly took a few classified documents with him. Stealing — and then attempting to sell — those secret government documents could land the Colorado Springs man on death row.

Dalke has been charged with trying to sell those government secrets to a foreign government. But, according to a Department of Justice affidavit, the sale went bust when it turned out the potential buyer Dalke believed was an emissary from a foreign nation was an undercover FBI agent.

Hackers… Ransomware 3.0: The Next Frontier https://www.darkreading.com/vulnerabilities-threats/ransomware-3-the-next-frontier

The Federal Bureau of Investigation's Internet Crime Complaint Center received 3,729 complaints identified as ransomware in 2021, up 82% from just two years prior and accelerating. According to the Department of Treasury, the top 10 ransomware gangs raked at least $5.2 billion in extortion payments. Ransomware's growth and sheer scale captured leaders' attention in policy and business, but we must keep our eye on how its operators might adapt and evolve to protect their profits.

++++++++

Russian Hackers Take Aim at Kremlin Targets https://www.infosecurity-magazine.com/news/russian-hackers-take-aim-at/

According to a new report, Russian threat actors have begun launching cyber-attacks at targets inside their country in retaliation for what they see as a needless war with Ukraine.

The Kyiv Post claimed to have spoken to members of the National Republican Army (NRA), a Russian hacking outfit working towards overthrowing the Putin regime.

++++++++

Relentless Russian Cyberattacks on Ukraine Raise Important Policy Questions https://www.darkreading.com/threat-intelligence/russian-cyberattacks-ukraine-raise-important-policy-questions

The cyber picture worsened as the war went on because critical infrastructure and systems used to support the war effort ended up in the crosshairs.

Soon after the onset of the physical invasion, Microsoft found that it could also correlate cyberattacks in the critical infrastructure sector with kinetic events. For example, as the Russian campaign moved around the Donbas region in March, researchers observed coordinated wiper attacks against transportation logistics systems used for military movement and the delivery of humanitarian aid.

And they are targeting nuclear facilities in Ukraine with cyber activity to soften a target before military incursions, which Microsoft researchers have consistently seen throughout the war.

View Details

Can You Secure Security Cameras? The Coming Green Energy Nightmare - Email Scams Hitting Businesses and Lonely Hearts Scams… Eight questions to ask yourself before getting a security camera https://www.welivesecurity.com/2022/10/03/8-questions-ask-yourself-getting-home-security-camera/

Security cameras were once the preserve of the rich and famous. Now anyone can get their hands on one thanks to technological advances. The advent of the Internet of Things (IoT) has created a significant new market – for manufacturers of devices like connected doorbells and baby monitors and more sophisticated whole-of-property systems. Connected to home Wi-Fi networks, these devices allow owners to watch live video footage, record video for later, and receive alerts when out of the house.

Yet these same features can also expose households to new risks if the camera is compromised and the footage is leaked. Not all vendors have as big a focus on security and privacy as they should. That means you need to ask the right questions before starting.

++++++++

Romance scammer and BEC fraudster sent to prison for 25 years https://nakedsecurity.sophos.com/2022/10/04/romance-scammer-and-bec-fraudster-sent-to-prison-for-25-years/

Elvis Eghosa Ogiekpolor was jailed for 25 years in Atlanta, Georgia, for running a cybercrime group that scammed close to $10,000,000 in under two years from individuals and businesses caught up in the so-called romance and BEC scams.

BEC is short for business email compromise, an umbrella term for a form of online scam in which the attackers acquire login access to email accounts inside a company so that the fraudulent emails they send don’t just seem to come from the company they’re attacking, but do come from there.

++++++++

How a deepfake Mark Ruffalo scammed half a million dollars from a lonely heart https://grahamcluley.com/how-a-deepfake-mark-ruffalo-scammed-half-a-million-dollars-from-a-lonely-heart/

The Asahi Shimbun reports that 74-year-old Manga artist Chikae Ide received an unsolicited message via Facebook in February 2018 from somebody claiming to be Ruffalo.

With help from some translation software, an initially skeptical Ide responded to the Hollywood actor, attaching a photograph of herself. An American friend of Ide subsequently questioned whether the person claiming to be Ruffalo was genuine, noting that he wrote: “like somebody who has not learned English.”

But, says Ide, a 30-second video call blew away any suspicions.

“I’m sure it was Mark himself behind the screen chatting with me,” Ide said.

Energy… The Coming Green Electricity Nightmare https://wattsupwiththat.com/2022/10/02/the-coming-green-electricity-nightmare/

What this net-zero transition would require:

How many millions of wind turbines, billions of solar panels, billions of EVs, backup batteries, millions of transformers, thousands of miles of transmission lines – sprawling across millions of acres of wildlife habitat, scenic and agricultural lands, and people’s once-placid backyards?

To cite just one example, just the 2,500 wind turbines needed for New York electricity (30,000 megawatts) would require nearly 110,000 tons of copper – which would necessitate mining, crushing, processing, and refining 25 million tons of copper ore … after removing some 40 million tons of overlying rock to reach the ore bodies. Multiply that times 50 states – and the entire world – plus transmission lines.

Spooks… FLASHBACK: CIA Sabotaged Soviet Pipeline to Europe in 1982 - US Software Caused Massive Explosion in Siberian Pipeline Seen From Space https://www.thegatewaypundit.com/2022/10/flashback-cia-sabotaged-soviet-pipeline-europe-1982-us-software-caused-massive-explosion-siberian-pipeline-seen-space/

Back in 1982, the CIA sabotaged a Soviet pipeline in Siberia. US software caused a gas pipeline explosion so large it could be seen in space. The Americans did not want the Europeans to purchase Soviet gas.

In January 1982, President Ronald Reagan approved a CIA plan to sabotage the economy of the Soviet Union through covert transfers of technology that contained hidden malfunctions, including software that later triggered a massive explosion in a Siberian natural gas pipeline, according to a memoir by a Reagan White House official.

++++++++

Former NSA Employee Faces Death Penalty for Selling Secrets https://www.darkreading.com/attacks-breaches/ex--nsa-employee-faces-death-penalty-for-selling-secrets

When he left his job as an information systems security designer with the National Security Agency, Jareh Sebastian Dalke allegedly took a few classified documents with him. Stealing — and then attempting to sell — those secret government documents could land the Colorado Springs man on death row.

Dalke has been charged with trying to sell those government secrets to a foreign government. But, according to a Department of Justice affidavit, the sale went bust when it turned out the potential buyer Dalke believed was an emissary from a foreign nation was an undercover FBI agent.

Hackers… Ransomware 3.0: The Next Frontier https://www.darkreading.com/vulnerabilities-threats/ransomware-3-the-next-frontier

The Federal Bureau of Investigation's Internet Crime Complaint Center received 3,729 complaints identified as ransomware in 2021, up 82% from just two years prior and accelerating. According to the Department of Treasury, the top 10 ransomware gangs raked at least $5.2 billion in extortion payments. Ransomware's growth and sheer scale captured leaders' attention in policy and business, but we must keep our eye on how its operators might adapt and evolve to protect their profits.

++++++++

Russian Hackers Take Aim at Kremlin Targets https://www.infosecurity-magazine.com/news/russian-hackers-take-aim-at/

According to a new report, Russian threat actors have begun launching cyber-attacks at targets inside their country in retaliation for what they see as a needless war with Ukraine.

The Kyiv Post claimed to have spoken to members of the National Republican Army (NRA), a Russian hacking outfit working towards overthrowing the Putin regime.

++++++++

Relentless Russian Cyberattacks on Ukraine Raise Important Policy Questions https://www.darkreading.com/threat-intelligence/russian-cyberattacks-ukraine-raise-important-policy-questions

The cyber picture worsened as the war went on because critical infrastructure and systems used to support the war effort ended up in the crosshairs.

Soon after the onset of the physical invasion, Microsoft found that it could also correlate cyberattacks in the critical infrastructure sector with kinetic events. For example, as the Russian campaign moved around the Donbas region in March, researchers observed coordinated wiper attacks against transportation logistics systems used for military movement and the delivery of humanitarian aid.

And they are targeting nuclear facilities in Ukraine with cyber activity to soften a target before military incursions, which Microsoft researchers have consistently seen throughout the war.

View Details

How Your iPhone Can Be Hacked -
IRS Warns of “Industrial Scale” Smishing surge -
Crypto Scams Soar -
Morgan Stanley fined millions -
Why Nuclear Power is (quietly) making a big comeback

Cyber… Can your iPhone be hacked? What we know about iOS security https://www.welivesecurity.com/2022/09/19/can-iphone-be-hacked-what-know-ios-security/

How can an iPhone be hacked?

  • Sideloaded apps
  • Fake apps in the App Store
  • Calendar invites
  • Configuration profiles

How can you tell if your iPhone has been hacked?

  • Battery levels
  • Data
  • Strange “things”

++++++++

IRS Warns of “Industrial Scale” Smishing surge https://www.infosecurity-magazine.com/news/irs-warns-of-industrial-scale/

The Internal Revenue Service (IRS) has warned US taxpayers of an “exponential” increase in text-based phishing attempts and urged users to report campaigns to help the government disrupt them.

Spoofed to appear as if sent from the IRS, these text messages often use lures like fake COVID relief, tax credits or help setting up an IRS online account.

++++++++

Crypto Scams Soar https://www.infosecurity-magazine.com/news/crypto-scams-soar-as-domains-surge/

Cryptocurrency scams are set to explode after researchers detected a 335% increase in registered domains in the first half of 2022.

Although most fake sites target English and Spanish speakers, 63% were registered with Russian registrars.

++++++++

Ransomware Affiliates Adopt Data Destruction https://www.infosecurity-magazine.com/news/ransomware-affiliates-adopt-data/

Ransomware affiliates appear to be dabbling with new data destruction capabilities to evade detection, increase their chances of getting paid and minimize the opportunities for developing decrypter tools.

In this tool version, the attacker attempts to corrupt files in the victim’s system following filtration rather than encrypt them as usual.

++++++++

Morgan Stanley fined millions for selling off devices full of customer Personal Information https://nakedsecurity.sophos.com/2022/09/23/morgan-stanley-fined-millions-for-selling-off-devices-full-of-customer-pii/

Morgan Stanley, which bills itself in its website title tag as the “global leader in financial services” and states in the opening sentence of its main page that “clients come first,” has been fined $35,000,000 by the US Securities and Exchange Commission (SEC)…

…for selling off old hardware devices online, including thousands of disk drives still loaded with personally identifiable information (PII) belonging to its clients.

++++++++

Power… Why Nuclear Power is (quietly) making a big comeback all around the world https://fee.org/articles/why-nuclear-power-is-quietly-making-a-big-comeback-all-around-the-world/

In California, France, Japan, Germany, and beyond, nuclear power is suddenly all the rage.

Gov. Gavin Newsom spearheaded an eleventh-hour effort to pass legislation to extend a lifeline to Diablo Canyon. This 2,250-megawatt nuclear plant supplies 8 percent of the energy produced in the Golden State.

Under pressure from lawmakers and environmental activists, the Pacific Gas and Electric Company (PG&E) agreed in 2016 to decommission Diablo when its operating licenses expire in 2024 and 2025. But in light of the recent energy policy environment, California lawmakers had second thoughts.

View Details

How Your iPhone Can Be Hacked -
IRS Warns of “Industrial Scale” Smishing surge -
Crypto Scams Soar -
Morgan Stanley fined millions -
Why Nuclear Power is (quietly) making a big comeback

Cyber… Can your iPhone be hacked? What we know about iOS security https://www.welivesecurity.com/2022/09/19/can-iphone-be-hacked-what-know-ios-security/

How can an iPhone be hacked?

  • Sideloaded apps
  • Fake apps in the App Store
  • Calendar invites
  • Configuration profiles

How can you tell if your iPhone has been hacked?

  • Battery levels
  • Data
  • Strange “things”

++++++++

IRS Warns of “Industrial Scale” Smishing surge https://www.infosecurity-magazine.com/news/irs-warns-of-industrial-scale/

The Internal Revenue Service (IRS) has warned US taxpayers of an “exponential” increase in text-based phishing attempts and urged users to report campaigns to help the government disrupt them.

Spoofed to appear as if sent from the IRS, these text messages often use lures like fake COVID relief, tax credits or help setting up an IRS online account.

++++++++

Crypto Scams Soar https://www.infosecurity-magazine.com/news/crypto-scams-soar-as-domains-surge/

Cryptocurrency scams are set to explode after researchers detected a 335% increase in registered domains in the first half of 2022.

Although most fake sites target English and Spanish speakers, 63% were registered with Russian registrars.

++++++++

Ransomware Affiliates Adopt Data Destruction https://www.infosecurity-magazine.com/news/ransomware-affiliates-adopt-data/

Ransomware affiliates appear to be dabbling with new data destruction capabilities to evade detection, increase their chances of getting paid and minimize the opportunities for developing decrypter tools.

In this tool version, the attacker attempts to corrupt files in the victim’s system following filtration rather than encrypt them as usual.

++++++++

Morgan Stanley fined millions for selling off devices full of customer Personal Information https://nakedsecurity.sophos.com/2022/09/23/morgan-stanley-fined-millions-for-selling-off-devices-full-of-customer-pii/

Morgan Stanley, which bills itself in its website title tag as the “global leader in financial services” and states in the opening sentence of its main page that “clients come first,” has been fined $35,000,000 by the US Securities and Exchange Commission (SEC)…

…for selling off old hardware devices online, including thousands of disk drives still loaded with personally identifiable information (PII) belonging to its clients.

++++++++

Power… Why Nuclear Power is (quietly) making a big comeback all around the world https://fee.org/articles/why-nuclear-power-is-quietly-making-a-big-comeback-all-around-the-world/

In California, France, Japan, Germany, and beyond, nuclear power is suddenly all the rage.

Gov. Gavin Newsom spearheaded an eleventh-hour effort to pass legislation to extend a lifeline to Diablo Canyon. This 2,250-megawatt nuclear plant supplies 8 percent of the energy produced in the Golden State.

Under pressure from lawmakers and environmental activists, the Pacific Gas and Electric Company (PG&E) agreed in 2016 to decommission Diablo when its operating licenses expire in 2024 and 2025. But in light of the recent energy policy environment, California lawmakers had second thoughts.

View Details

America Could Save $Billions$ on Prescriptions -Microsoft 365 users are under attack Business email compromises stealing billions again -
Online privacy getting better thanks to -
Apple Need help? Get my newest punchlists -
Google's huge problem in Russia -
Kill switches in cars -- again

About one-third of Americans are taking a prescription, and this is kind of the scary part. The average person who is on a prescription has four prescriptions, and we're paying dearly for it. But mark Cuban has an answer.

[Automated Transcript Follows]

Well, you know, I do a lot of stuff in cybersecurity, and I've got a few different courses coming up.

[00:13:19] And of course, we do a little bit of weekly training for anybody who's on my email list, you know, on the free list. Absolutely free as well as you get my insider show notes. And if you got my show notes, you probably noticed this on Tuesday when I sent it out. And that is Mark Cuban. Now for those who don't know mark Cuban, he started way back on the internet.

[00:13:44] Boom days. He lucked out. He had a, a company called broadcast.com. and he was able to turn that into, I think it was well over a billion dollars. I don't remember the exact amount, but it, it was a very, very big chunk of money. And then he's gone on to become an investor. You might know him as the owner of a basketball team.

[00:14:07] You might have seen him on a TV show called shark tank. He's been out there and he's a bright guy. He's been helping a lot of people and causing a lot of problems too. Right. But he has a new business that he has started with his billions of dollars only. He has at least 1 billion and it's called. Cost plus drugs.

[00:14:31] Now this is where it comes into affect every American, because I mentioned, you know, how many Americans are on various prescriptions? Well, many of the prescriptions that we could be taking are actually generics. So for instance, if you go to the Walmart pharmacy or Walgreens or wherever it. Be you'll find that they have options for you.

[00:14:56] If the doctor says, yeah, generic's okay. They'll say, Hey, listen, I'll give you the generic and you can save a whole lot of money. I don't know if you've looked at good RX at all. But good RX. I have saved a ton of money with that. And what they do is help you find free coupons. Compare the prices at, at Walmart Walgreen, CVS Rite aid, you know, at the major pharmacies.

[00:15:21] And we'll tell you where you can go to get your best deal. Plus. They also have some really cool discounts. So it, it acts kind of like a discount card. So I'm on their site right now. Good rx.com. And I look, I'm looking up their number one drug, which is Lipitor, apparently it's used for coronary art or coronary disease and high cholesterol.

[00:15:47] So they're saying, well, wait a minute. Now here. You can get a few different, uh, options. I'm looking now, for instance, CVS pharmacy nor normal retail, by the way is $126 at CVS. You can get it using a good rx.com card. 76% off for $30 instead of $126. Walmart, $15. Uh, Walmart neighborhood market, $15 now, Walmart, that's what they consider to be their retail price.

[00:16:24] Although, as I mentioned, some of these other ones have much, much higher retail prices. So you can see that going. For instance, for Lipitor, you might be. Paying a premium for a brand name. Now there, there's a good reason for that. There's a reason why prescription drugs can be expensive and, and they're called patent drugs.

[00:16:45] And the reason they're call patent drugs is they've put a lot of money in. They've put a lot of research time. They've, they've put up with a whole lot of regulation and going back and forth with various government agencies. And they finally were able to come forward with a drug that works. Put all of that together.

[00:17:05] And you've got a very expensive research and development product, right. Or project, frankly. So I don't, I don't really hold it against them. If we're having some of these drugs being rather expensive. You might remember that, uh, epi epinephrine a few years ago, this guy got a hold of the company that made epinephrine and the, um, You know, the, the whole problem with I'm looking it up right now, like EpiPens, they used to be expensive and then they became crazy expensive.

[00:17:41] So let me see here, EpiPens, EpiPens, and who needs it? There's a whole lot of information. It's not telling how much they are, but he raised the price. Like what was it? 2000% or something insane, again, a prescription drug and one that some people really need in order to save their lives. You know, I'm a beekeeper, right.

[00:18:05] And I used to have a really bad reaction to be stings, wasp stings. Now we just. Reaction, right. We thought at the time I was allergic, but no, it was just a bad reaction, which I still have. Right. It gets stung multiple times a year, but, uh, it still swells up. When, when, uh, our friend mark Cuban started looking at this, he said that this is kind of crazy.

[00:18:28] So what he's done now is mark Cuban has built, uh, I think it's all up and running just outside of Dallas. Let's see here. Yeah. Okay. Just outside of Dallas, a huge, huge building. It's a 22,000 square foot plant. Now most of the pharmaceuticals are actually easy to make and. To make. And that's what kind of gets confusing because you've got all of the R and D and the government regulations, everything else that's expensive, but actually making them is pretty cheap, but he's built this $11 million plant near downtown Dallas.

[00:19:10] And he says right now, looking at what the expenses are that Medicare could have saved as much as are you ready for this? 3.6 billion per year. Now that's where we're talking about everybody. Because if you pay taxes, you are paying for some of this Medicare money, 3.6 billion per year in savings. By buying it from cost plus drugs.

[00:19:42] So there's something else I want you to check out. So the first one was good. rx.com. The second one is cost plus drugs. They have over a hundred generic prescription medications right now. And what they're doing is they're taking the actual cost of production. And I'm sure that includes right. The loan on the building, et cetera, but the cost of production, plus a 15% margin because you need to keep the lights on.

[00:20:10] You need to be able to expand. Profit is not a bad word. That's how people save for retirement by investing in companies, buying stocks, and that profit then becomes their money for retirement. I think that's an important thing. So. 15% margin and an $8 pharmacy dispensing and shipping fee. That is absolutely cheap.

[00:20:37] So this is, uh, Hussain Liani who did the research on this? And he published it in the annals of internal medicine. Looking at that just absolutely amazing. And that's something you can do too. One third of Americans, again, we are on prescription drugs and the average person is on four. Wow. So researchers compared the price charge by cost plus drugs for 89, generic medications to the cost of the same drugs paid.

[00:21:13] Medicare in 2020, they found the government program could have saved 37% on 77 generic drugs by buying from Cuban's company cost plus drugs. Once in January drug to consumer bypasses, wholesalers, bypasses, pharmacies, bypasses insurance, all of those are driving up the cost of medicine. So direct to consumer.

[00:21:39] Uh, how easy could that be? And I'm on their website right now, looking at a couple of things here. Let me see, let me go back there. Cost plus drugs, and I'm believing this go to cost plus drugs.com. Yes you can. I am there as we are talking. So he's got, oh, here's one tib. Uh, which is the generic for gleek I'm.

[00:22:04] Now I'm not familiar with that myself retail price, $2,502. cost. Plus, are you ready? $14. Can you believe that that is crazy. Yeah. Wow. And it'll look, it'll look different obviously, cuz it's a generic. So you saved $2,488 for a 30 count supply. That is just amazing. So when I, I, I was talking about the savings here, where.

[00:22:37] Okay. They could have saved 37% on 77 generic drugs. But when you start getting into these really expensive drugs, that's where the 3.6 billion really, really starts to add up in savings. This is something so what you can do once you're on cost plus drugs.com, you can contact your doctor for a prescription.

[00:23:00] They've gotta get started button. They have the strength that you want in this case, a hundred milligrams or 400, the quantity you want. And then all that has to happen is your doctor has to approve it. You pay $14 instead of $2,500 and it gets shipped straight to you. Wow. Now, is that cheaper than Medicare part B right?

[00:23:25] Or your regular insurance? Wow, sure. Is just absolutely amazing. So you can find all of this stuff. This is mark Cuban doing this, and I gotta say, I am impressed. He is going to help a whole lot of people. Yeah, I'm, I'm just looking at this. Wow. Here's another one retail price. $9,600. And at cost plus drugs, you can get it for 39.

[00:23:54] So there you go. Two options, mark Cuban's new venture, which is online now@costplusdrugs.com and good rx.com. Wow. It's just amazing, right? This world. What's it coming to? Great little great little drug company. So we're gonna talk if you are a user of outlook, this is important to you because major tack underway.

[00:24:23] Major scam underway. If you are an outlook customer, you are in the crosshairs of a very successful credential stealing campaign. So I'm gonna tell you about that, what it means, what you can do and, uh, how you can stay safe.

[00:24:41] This is a very big problem for people who are using Microsoft 365, that is really common, used to be called office 365 and you pay a, a flat monthly fee, 20, 25 bucks.

[00:24:56] It kind of depends on what level you get. They have some real cheap ones as well, and it lets you use all of what Microsoft used to call Microsoft office applications. And one of those applications is. And I've never particularly liked. they have gotten better in recent years. And I actually do use it right now, as well as MacMail I use both of them, but there is a hack going on against Microsoft 365 and outlook customers in the us.

[00:25:31] Here's what's happening. They are sending you an email and the email really does look like it's ti voicemail that somebody left. This is called a voicemail fishing attack and it follows, what's kind of a classic fishing flow. If you will, the ways they've been doing fishing here over the years, and what fishing is, is basically.

[00:25:59] Getting you to bite at something that you shouldn't bite on. You, you will respond to an email. You'll click on a link. You might call a phone number. You might click on a text message. That's another one that's going around right now. How do you tell a fake text message from a real text message? And I'm afraid to say nowadays you tell by just not clicking on the links that are in text messages.

[00:26:27] It's, it's so disappointing. I was talking on the radio this week. It, it, it, because it just, it bothers me so much about this very thing. I've been on the internet for decades now. Right? I, I started back in 81. I think it was maybe 80. Two and we had email and it was the best thing ever. If you had somebody's email address, you could send them a note and you'd be pretty darn sure they'd get it.

[00:26:55] In fact, they probably would get it within just a few minutes and respond to you. And there, there wasn't any spam. Back then the idea was, Hey, listen, the internet is for research government research, university research, and that's the way it should stay. And indeed, we were kind of keeping it that way for, for quite a while.

[00:27:18] And then some people who were marketers got on the, in. And they would start to advertise, Hey, we have a special session for you at, uh, UC Berkeley this week only $500. And of course that went be beyond what the internet was for. In fact, at the time you could not use it legally. For any sort of financial purposes.

[00:27:44] So what we would do back then is we would send the script to the Monty Python routine of spam. Remember that spam, spam, and egg spam, and hands spam, spam. Uh, yeah, we would send them the whole. And they, sometimes, if somebody sent out a little thing that was trying to sell something that they should not be selling online because it was illegal to use the internet for business in case you didn't know until about 1991.

[00:28:17] And that's when I started. Putting businesses online and really started focusing in on cyber security because almost immediately the bad guys started getting on there. So this is, uh, this is really what happened. This was the script, right? Uh, well, what have you got waitress? Well, there's egg and bacon, egg, sausage, and bacon, egg, and spam, egg, bacon, and spam, egg, bacon, spam, sausage, and spam spam, bacon sausages, and spam spam eggs, spam spam, bacon spam.

[00:28:48] Do you remember that? So. We would send this to people who kind of broke the rules written or unwritten on the internet. And sometimes somebody would get just a hundred of these things, maybe even more. And what would happen back then of course, is it would fill up your mailbox and it would slow down your check connection.

[00:29:07] Cuz a lot of us were just connected to the internet via dial up modems. So it, it really kind of hurt you to get all kinds of spam. Emails coming in. That's where the term comes from. I remember it well, so I don't care what they say on some of these websites or they're trying to do little research on it and figure it out.

[00:29:28] Well, now things have gotten a lot worse because it isn't just marketers that are trying to solve something. And I don't have a problem with marketers, I guess, in a way I am one myself. Right. I, I have a business and I provide cybersecurity services. For a high net worth individuals and for businesses.

[00:29:47] And if you are a regular person, you have a question. Please ask, just send an email to me, me Craig peterson.com, no matter who you are. And I will try and answer the question for you. And I have a lot of stuff that I've written over the years. That'd be more than glad to forward to you. There are some training courses that I.

[00:30:07] Put together that I will be more than glad to share with you. And you probably know I did all of the training for the FBI's Ingar program for a couple of years. I, I ran that online, all of their webinars. So I've been doing this for a long time and I'm more than glad to help. That's why I am here. Right.

[00:30:28] But now we got bad guys. and the bad guys are trying to get you to do something against your best interest. So in this case, what happens is you get a missed voicemail notification via email, and a lot of times it'll look pretty legitimate. It might even be coming from someone inside your company, whose account they have hacked.

[00:30:54] Now on that email, there is an HTML attach. Now HTML attachments can get past a lot of email gateway filters because they aren't in and of themselves malicious. So they're not raising big red flags for users in a, in a voicemail notification setting because that's how office Microsoft office sends you legitimate notifications.

[00:31:20] Anyways. Now, these from fields are set up specifically using the organization's name. As I said, sometimes even a valid email address. Now, if you go ahead and click on that attachment, it will run a program on your computer using a language called JavaScript and that's embedded in every browser out there nowadays.

[00:31:44] And that JavaScript code is going to redirect you to an attack. Controlled website. Now this website set up to get you to give up your credentials. So, what they'll do now is as you go to the website and the website might look like it's Microsoft office and it might look like it's your business website, and it'll ask you to log in.

[00:32:12] It might ask you for other information as well. It is trying to get your username and password that it can then use to go after other people. You see what's happening here. So each of the URLs, these guys are creating these websites that they're sending you to are created to match the targeted company.

[00:32:36] It's it's incredible how good they're getting, and they even have one of those Google recapture. Pop ups. Now this is a, an increasingly popular technique to evade these auto mail, automated URL analysis tools. So for instance, with my client, an email comes in, it goes through Cisco's. Email filter. We have an advanced email filter from Cisco, but we run our client's emails through.

[00:33:07] And what happens is they look at the URLs, they visit the website that the URL PO points to, they try and verify if it's legit or not. And you you've had captures, you know, it's, um, click every box that has a bicycle in it, sort of a thing. It's kind of a touring test, test puzzle. So once this is solved, We'll tell you what happens next, cuz we're out of time right now.

[00:33:33] Uh, make sure you visit me online. Craig Peter son.com. I'll keep you up to date. You can get my free newsletter and trainings. Craig Peter son.com. And I want to talk too about businesses in the, the big business of email compromise.

[00:33:52] Yeah, I think most of us know what a big business is. Well, how about a business, an industry that has racked in 43 billion, according to the FBI. That's what we're talking about right now and what you can do about it.

[00:34:08] We'll help keep you up to date and make sure you keep an eye out Tuesday mornings for that newsletter that comes your way every Tuesday morning, the insider newsletter you can sign up for for free@craigpeterson.com.

[00:34:29] We were talking about, what's been happening with Microsoft outlook users right now, a major campaign underway that has been extremely successful because these bad guys are using some rather advanced technologies. Absolutely crazy. So they get you to click. HTML link that is there while filed that is there as part of what looks to be a voicemail notification for you.

[00:35:00] And then it takes you to a website that's specially crafted for you and your company. So you work@bigco.com and you click on that HTML and it'll take you to big co.com. Well, at least that's what it looks like, but it distracts you now because it wants to give you this capture as well. So this Google captures, you know, these things, these little mini touring tests, click on all of the trees in the picture, sort of a thing, right?

[00:35:35] And you've got the nine things well with, uh, or maybe it's some blurred or distorted text and you have to type that in. And the whole idea behind that is normally to weed out these bots on eCommerce sites, online account sites. But what they're doing here is. They're making sure that the email, the, the software that checks the emails to make sure they are legitimate, that is going out to the big co dot or big co fake.com website.

[00:36:11] They wanna make sure that that email checker does not find out that it's not the real site that you wanted to go. So the computer that's doing the checking will go to the site and it'll say, oh, there's a capture on there. And then it'll stop because it can't solve the capture. It needs you, it needs a human, right.

[00:36:32] So this is kind of cool here. Uh, Eric. K. He's a security awareness advocate with no before. No. Before is a company that does training for people, for employees here about some of these, uh, these hacks and things are going on. When faced with a login prompt, it looks like a typical. Office 365 login. The person is likely to feel comfortable entering their information without looking at the browser's URL bar to ensure they are at the real login site, this familiarity and the high odds in an attended victim regularly uses office 365 for something in the Workday makes this a great Lu.

[00:37:19] For attackers, this is from an article over on dark reading.com. This isn't, uh, a new technique, but let me tell you, it is B a very successful one. They have seen a resurgent, uh, resurgence of this starting a couple of years ago, back in July, 2020. And it is really targeting human nature. And of course, Microsoft 365 is quite the target.

[00:37:46] So I mentioned. $43 billion industry. I'm looking right now at a public service announcement from the F FBI and they are calling business email compromise the $43 billion. Scam. This is crazy. A sophisticated scam. It targets businesses and individuals who are performing legitimate transfer funds requests.

[00:38:17] It's carried out by people who are compromising legitimate businesses and individuals. Now, what they're trying to do with this business email compromise is get someone who has. Control of funds to do a transfer. What happens is they will do a little research on the business that might go to the website and see on the website.

[00:38:42] Oh, let me see here. Okay. The president's name is Craig Peterson. Uh, the CFO is Mary Jane and, uh, the accounting department head is manly. And, uh, so now they got that information. So they'll go online. And to look at LinkedIn, find out who all else is at the business. Maybe things have changed, you know, maybe try and find an email address by doing an open source search for the email address of people there at the business.

[00:39:15] You see where this is going here? Yeah, it, it gets pretty bad. So, uh, let's say they befriend the CEO on Facebook or on LinkedIn, but Facebook more likely, uh, and now. They're they can see on Facebook or maybe they don't even have to because your Facebook profile and posts are not hidden from the public.

[00:39:37] So they just go there and, oh, let me see. Okay, great. He's gonna be out of town next week. And then what they'll do is they'll get into somebody's email account at the business. And once they're into somebody's email account, they can start looking through the emails and sending emails that look perfectly legitimate to other people within the organization.

[00:40:00] Now, I, I did a whole story on television about this one on news program, and one of the people on staff, one of the talking. received an email like this, and it asked him to, uh, to buy some gift cards. This is very, very common scam right now, the gift card scam, and they try and get you to go ahead and. Buy gift cards for other people in the office are gonna have a little party and we don't want anybody else to know about it.

[00:40:32] It's supposed to be a surprise. And I had some real fun with him. One of these days, I should probably share all of this in one of my newsletters. I think you guys would really appreciate it, enjoy it a little bit, but, uh, we really led them on and sure enough, you know, it was a total scam and we kept playing with them and it, it was something, any.

[00:40:55] That was one thing. This is another because they will eventually get to the CFO, somebody who has the authority to transfer funds and get them to transfer funds to. Them. And then they use mules to move the money around these, uh, useful idiots who will sign up. And yeah. Yeah. It's kinda like the Nigerian scam.

[00:41:22] All I need is access to your bank account and I'm gonna wire in, uh, $10,000. And I, and what I need you to do is transfer 8,000 of it over here to this PayPal account because my grandmother's dying and she needs the. There's similar scams that are going after lonely people and getting them to send money because somebody needs an operation, et cetera.

[00:41:50] So in this case with the business email compromise and the 43. Billion dollars that have been stolen from businesses. They'll usually get to the CFO and send a story like, Hey, uh, we have this new vendor and we've had 'em for three months and we haven't been paying them and we gotta make sure we pay them.

[00:42:11] And, uh, we need to wire 43 million to this account that actually happened. And they did wire the money. It happened to Barbara cran, another person who wa is on shark tank. Uh, it, it happens to a lot of companies out there. And I've got a couple in the last month that we've worked with the FBI on the, these companies hear me on the radio.

[00:42:38] They sent an email to me@craigpeterson.com and they had had their operating account. Emptied. Uh, the latest one is a, a lady 77 years old who had her retirement money stolen from her over $70,000. This stuff's real people. We've got to pay attention. We can't let this continue to happen. Make sure you sign up online.

[00:43:05] Craig peterson.com so that you can get my insider show notes and we can keep you ahead of the bad guys. When we come back, we're gonna talk about this row overturned and what senators are asking the FTC.

[00:43:23] We've got some senators who are saying they were spurred on by the row overturned. And they're asking the FTC to probe, apple and Android, and what's happening with tracking. Now I have a suspicion. That's not really right.

[00:43:40] Well, we've got three Democrat, us senators and a Democrat us representative that asked. The federal trade commission to investigate apple and Google for engaging in unfair and deceptive practices by enabling the collection and sale of hundreds of millions of mobile phones, users, data, the FTC should investigate apple and Google's role in transforming online advertising into an intense system of surveillance that incentivizes and facilitates the UN.

[00:44:16] Train collection and constant sale of Americans' personal data. These companies have failed to inform consumers of the privacy and security dangers involved in using those products. It is beyond time to bring an end to the privacy harms, forced on consumers. Buy these companies. Now I have been talking about this on the radio for 20 years.

[00:44:45] Because do you remember when Congress forced telephone manufacturers and cell phone companies to put GPS coordinates into the receivers, into the phones? Do you remember that you could no longer use your analog phone? You had to use digital phones under federal. right. It, it's just amazing. We can go into all of the reasons that they've given for that in the past, but anyhow, that's what they did.

[00:45:20] So immediately decades ago, now, many years ago, they started collecting data. Now it's okay for the government to collect it, even though it's illegal. For them to collect this data. So what's happening here? Why have the Democrats for so long? Well, and frankly, a lot of Republicans been big on collecting data on all of us.

[00:45:43] Now, I I've gotta say when I've looked at the stats, the biggest. Purveyors of the surveillance society have been president Obama followed by president Biden. Now you could argue that president Bush was won too, because of course they passed an act that allowed for all kinds of changes in surveillance.

[00:46:07] So, okay. So we'll put him in there too. So we got a Republican in there. Obama put that program that president Bush had put in place on steroids and then president Biden did the same thing. President Trump tried to cut it back because he was a victim of some of the surveillance that they were doing. So what's going on here?

[00:46:29] Well, these Democrat senators are saying, uh, we don't want people who are trying to get abortions to be. okay. I can see that. Uh, I can also see that I don't want to be tracked and you don't want to be tracked. And it's one thing to have an advertiser know a little bit about us, you know, Hey, we just visited the Ford dealer and the Chevy dealer and the Honda dealer.

[00:46:57] So maybe he's looking for a car let's let's try and advertise a car. Right. So Honda and Chevy and Ford all start putting ads up for you. Okay. So that's. Thing if I'm in, if I'm interested in buying a truck. Okay, great. Show me ads on a truck, but we've seen already misuses of this data over the years. One of the earliest oness I talked about here on the radio was this guy who went to an emergency room and all of a sudden started seeing ads for what you might call ambulance, chasing lawyers saying, have you been injured?

[00:47:35] right. You've seen those types of ads before, but once he was in the emergency room and he was geolo geolocated in the emergency room, they started selling advertising to lawyers. I, I, I'm not real fond of that one either, but I think there's an ulterior motive here behind what these Democrats are saying.

[00:47:57] If you have seen the movie 2000 mules, you understand what I'm talking about? what ended up happening here is they looked at trillions of data points. You see, they went out and bought databases of smartphone data where these smartphones were located. And then they started doing some serious analysis on it and they were able to say, okay, this smartphone went to.

[00:48:33] Different Dropboxes for the election for ballots. And in between each visit to the Dropbox, they went to a left wing organization where they did something. Right. So they, they go to a Dropbox drop off ballots and they're on video doing this, dropping off ballots. And then they go to a left wing organization and then they go drop off more ballots at a different Dropbox, and then they go back again and then it's on video.

[00:49:07] And some of these people are taking pictures of them, stuffing the ballots into the box, supposedly, so they can get paid. So now there are some criminal investigations that have been started. I don't know how far they've gotten yet over some of this information that was gathered. And that was documented in the film by Danes.

[00:49:28] Dusuza called 2000 mul. And if you haven't seen it, no matter what side of the aisle you want, you need to see it absolutely need to. And whether you believe or not, when president Biden said that we have the best, uh, what was it? Um, election stealing organization that's ever been made? I can't remember his exact words right now.

[00:49:53] Uh, he was serious about it, right? So now all of a sudden, the Democrats are concerned that people who visit abortion clinics might be tracked, cuz they could. Right. You could buy data geotagged with an abortion clinic's location, GPS coordinates. You absolutely could do that, but that's been true for a long time.

[00:50:19] Why now? Well, maybe because of Roe V Wade, but I look, of course it wasn't just that one decision that was overturned, but I, I look at some of this and really, really do wonder because it really looks like some number of people were caught illegally stuffing ballot box. So it's, it's fascinating to me that all of a sudden now out, they come with this.

[00:50:49] Now apple has stopped enabling the tracker identifiers. By default, if you have an apple smartphone, it is much more. Private than the Android phones are by far, right? Google makes its money by selling your information. That's how they make most of their money. Apple makes its money by selling you services and selling you hardware.

[00:51:18] so that should tell you something right there. And the fact that Senator Elizabeth Warren is one of the ones who is proposing this legislation makes you think even more about this. Now, Google, uh, this is an article from ours. Technical apparently responded to this whole concept in an article that ours was writing, saying that it's had all kinds of efforts to block apps and violate Google play policies.

[00:51:47] the bands it's imposed on companies that are apparently sold user data, and they say Google never sells user data in the play at Google, strictly prohibits a sale of user data by developers and, uh, goes into the advertising ID. So it it's fascinating to me that all of a sudden, now the Democrats are interested in stopping the data, collect.

[00:52:12] It really is. I don't like it. As I said, I've talked about this for more than 20 years now on the radio. It, I think it's a real problem. This data collection, because also the federal government, even though it's illegal for them to collect information on American citizens, they do it every. And some of the largest, like the, um, immigration people, Homeland security are the biggest collector.

[00:52:42] They have more information about you than anyone else. Even if you're here legally, you were born in the United States, et cetera, etcetera, because they are buying all of this information from what are called data broker. So, yeah, they say, yeah, we're, we're not collecting it. You we're forbidden by law to collect it, which is absolutely true.

[00:53:04] But what they are doing is buying it from private businesses. So I think we've got to completely. Reconsider how this all works. Apple has been working on it. You can go into your apple phone and make a change, share identifier if you want to, which makes it harder to track apple also. And Google has this, as I believe is an option.

[00:53:30] But apple also will give you a different Mac address every time you're connecting to wifi networks so that you can't be tracked that way. Because just, if, if you connect to the network at target the wifi at target, for instance, they will know when you return because your phone has the same Mac address that's used for the wifi.

[00:53:53] So they know. They know where you go in the store. They know what you're looking at in the store, in some cases, depending on how the tracking works. So it's fascinating to me, this is a, a real privacy issue that could easily turn into something much worse because this data, this same data that's available to marketers is available to government is also available to bad guys.

[00:54:21] and you talk about the ability to potentially frame someone and it, it, it just gets extremely, extremely scary. Right now, last month, more than 40 members of Congress called on Google to stop collecting and retaining customer location data, the prosecutors could use to identify women who obtain abortions.

[00:54:42] Again, tied into this, uh, abortion anytime any day. Uh, and as the governor of Virginia said, even after the baby is born and delivered it, you should be able to abort it. Uh, so wherever you fall in that spectrum, obviously the Democrats in the us want abortions far more than the Europeans that every European country I can think of has much tougher restrictions on abortion than we have here.

[00:55:09] But. Privacy is not an abortion issue. Hey, join me online. Craig peterson.com. Make sure you are on my email list. And, uh, you can ask any question you want. Just email me, me, Craig peterson.com.

[00:55:31] I really appreciate all the emails I get from you guys. And it is driving me to do something I've never done before now. I've always provided all kinds of free information to share on my email list. Great stuff. But now we're talking about cyber punch lists.

[00:55:48] There are a number of stories here.

[00:55:50] They they'll come out, uh, in the newsletter or, or they did, excuse me, come in. The newsletter should have got on Tuesday morning. And that's my insider show notes, which is all of the information that I put together for my radio appearances radio shows. And. Also, of course, I send it off to the host at these various radio stations.

[00:56:12] So they know what's hot because who really, really tracks technology, not too many people. And I get, uh, you know, a little off put by some of these other radio hosts that call themselves tech people, and they're actually marketing people, but. That's me. Right. And that's why, if you are on my list, you've probably noticed I'm not hammering you trying to sell you stuff all of the time.

[00:56:37] It's good, valuable content. And I'm starting something brand new. Never done this before, but this is for you guys. Okay. You know that I do cybersecurity. As a business and I've been doing it now for more than three decades. I don't know if I should admit that. Right. They say, never say more than 17 years.

[00:56:58] Okay. So I've been doing it for more than 17 years and I've been on the internet now for. Oh, 40 years now. Okay. Back before it was even called the internet, I helped to develop the silly thing. So over the years, we've come up with a number of different strategies. We have these things that are called plan of action and milestones, and we have all kinds of other lists of things that we do and that need to be done.

[00:57:29] So what we're doing right now is we're setting it. So that you can just email me, me, Craig peterson.com. And I will go ahead and send you one of these punch lists. Now the punch lists are around one specific topic. You know, we got these massive. Punch lists with hundreds and hundreds of things on them.

[00:57:51] And those are what we use when we go in to help clean up the cybersecurity in a company. So we'll go in, we'll do scans. We will do red team blue team where we're attacking. We do all, all kinds of different types of scans using different software, trying to break in. We use the same tools that the hackers use in order to see if we can.

[00:58:15] Into your systems and if the systems are properly secured, so we do all of this stuff, so, and, and then it goes into all of the paperwork that needs to be done to comply with whatever it might be. Right. It might be, they accept payment cards. It might be that they have hip. Information, which is healthcare information.

[00:58:35] And it might be also that they're a government contractor. So there are hundreds and hundreds of things that they have to comply with. Most of them are procedural. So we have all of this stuff. We do all of this stuff. And I was talking with my wife here this last week about it and said, you. So much of this could be used by small companies that can't afford to hire my team to come in and clean things up.

[00:59:01] Right. And I don't want them to suffer. So here's what we're doing. We're starting this next week. We have a punch list for you on email. So what are the things you can do should do for email? Just very, very narrow on email so that you can recognize a fishing. Email, what you might wanna do to lock down your outlook, if you're on windows or your Mac mail.

[00:59:32] So we're taking these massive spreadsheets that we have and we're breaking them up. So the first one that's available to you guys, absolutely. A hundred percent free. Is the one on email. So just send me an email. Me M E Craig peterson.com. Now, remember I am, my, my business is a business to business business, right.

[00:59:54] But almost everything in these various. Punch lists applies to individuals as well. So I got an email this last week from a guy saying, Hey, I'm 80 years old and, uh, retired and I don't know much about computers and that's kind of what got us thinking about this. You know, we need to be able to help him.

[01:00:16] We need to be able to help you out. Okay. And if you're a small business and we've dealt with a lot of them over the years, and as a small business, you just don't have the funds to bring in an expert, whether it's me or somebody else, although yeah. What you want the best. But anyways, , it, it, uh, it is gonna allow you to do it yourself.

[01:00:39] Okay. So absolutely. All of these punch lists on all of these topics, we're probably gonna end up with more than a hundred of these punch lists. And all you do is email me, me, Craig peterson.com. Just let me know in there what you're interested in. So even if we haven't got that punch list broken down for you yet, we will go ahead and put that on the.

[01:01:06] To do right. We need the priorities. What kind of a priority should we have as we're putting these things together for free for people. Right. Uh, and the only way we know is if you ask, so the first one's on email, you can certainly ask for email. We've got, as I said, more than a hundred others, that we think we're gonna be able to pull out of the exact.

[01:01:27] Plan of action worksheets that we use so that you can go through this yourself, whether you're a home user or you are a small business or even a big business, right? We we're talking with, uh, a gentleman who's probably listening right now, who has a business. They have three offices, they have some requirement because of the military contracts for high level.

[01:01:53] Cyber security and it would work for him too. All right. So they, this is all of the punch list stuff. You probably know what a punch list is, right? It's using the construction industry a lot, but in our case, it's you need to do this. You need to do this, you need to do this. Okay. So that's what that's all about.

[01:02:11] So enough rambling on that. It's gonna take us some time to get 'em all together. I'm also. We're gonna do more video stuff again, training. So just like on the radio show where we're talking about what's in the news, we're gonna talk about what's what's in the news. When it comes to small businesses, what you should be paying attention to with of course, an emphasis on cybersecurity and we're.

[01:02:37] Putting those up on my website@craigpeterson.com. In fact, we've already got some up there already, and then we are going to also be putting them on YouTube and rumble. So if you don't like YouTube and Google, then you can certainly go to rumble. You'll see them there. But if you're on the email list, I'm.

[01:02:57] Starting to put links in the bottom of the emails. So you can go and watch those videos. If you are a video type person that you know, more visual. So it's, I think all good. And it's good news for everybody. And this is what happens, I think, as you get more mature, In the business. Right. Um, as I said, I've been on the internet for more than 40 years, helped develop some of that software that, uh, some of it's still in use today and now it's time to do more give back.

[01:03:29] And I really am trying to give back, okay, there's this isn't. This isn't a joke. So, uh, no joke. Right. So go ahead. Email me at Craig Peterson. Tell me which punch list that you would like. And I can also put you on my email list so that you get my insider show notes, and you can just do that yourself by gonna Craig Peterson dot.

[01:03:52] Com you'll see right up at the top of the page. If you scroll down a little bit, it'll kind of pop up. It's a big red bar that goes across the top. I try not to be too intrusive and you can sign up there for the newsletter. So you'll get some of these trainings automatically. You'll get my insider show notes, all of this stuff.

[01:04:11] It it's absolutely free. Okay. This is my give back to help you out. It really is. Okay. I, as I mentioned at the very beginning, I. Peeve by some of these people that represent themselves as tech experts. And in fact, all they are are marketers. We've got a client that decided that, uh, I was too expensive. My team.

[01:04:31] So they went out and shopped around, tried to find the cheapest company they could. And so now the, the company that they're bringing in is saying, you're saying, uh, Hey, um, uh, so how does this work? How do you do zero trust? Uh, why do you have a firewall here? Uh, why do you bother to have a direct fiber link between the offices?

[01:04:53] All this stuff? Well, because they need it. Okay. I get it. You use. Barracuda spam firewalls and Barracuda firewalls. It, it, yeah, this is a different league. Okay. So you are gonna be getting these punch lists from me that are really gonna help you understand and secure your systems. Right? This isn't your average run of the mill so-called managed security services provider or managed services or break fix shop.

[01:05:24] You are getting it from the guy that the FBI. Ingar program went to, to do their trainings. That was me. Okay. So for two years I set up the program. I ran it. And if we ever are sitting down having a coffee or beer, sometimes I'll tell you why I left. Okay. Uh, but think about FBI and I, I think you might have a clue as to why I decided not to do that anymore, but I trained thousands of businesses, government agencies, state local.

[01:05:56] Federal, you name it. So you are getting what you really need, which is another problem. I keep hearing from people, you do a search for something on YouTube or Google and you get what a million, 5 million pages, right. As supposedly that it says are available and they give you, okay, here's the top one, but what you need is an integrated, single.

[01:06:22] To do things where everything works together. And that's what I'm trying to do for you guys, because there's so many little products, different products that just don't work so well together. So we'll, we'll be covering that as well in these, but you gotta be on that email list. Craig peterson.com. Craig Peterson.

[01:06:43] So n.com/subscribe will take you right to the subscription page. And I'll keep you up to date. This is not my paid newsletter. All right, stick around. We'll be right back. And I promise I'll get to Russia, Russia, Russia.

[01:07:01] Some of the high tech companies and others pulled out of Russia after the Ukraine invasion, but one stayed Google. What is going on with Google? And now they're in big trouble with the Russian government. Wow.

[01:07:18] here's a list of companies according to CNET that have pulled. Out of Russia because you remember Russia invaded Ukraine, February 24, we had Adobe, these are the guys that make Photoshop, Adobe reader. Airbnb, Airbnb has kind of an interesting story too in Ukraine because a number quite a number of Airbnb customers went ahead and rented rooms and homes from Ukrainians, even though they had no intention of going and they told the Ukrainians, Hey.

[01:07:51] I'm not gonna show up, just take this money. I'm sure you need it. Can you, can you imagine that that's fantastic. Good for them, Amazon, they suspended shipments of all retail products of customers in Russia and Bella Russ, and also suspended prime video for users in Russia. Apple stops selling its product in Russia's it's halting online transactions, including limiting apple pay.

[01:08:18] It's also disabled. Some apple map features in Ukraine in order to protect civilians, Amazon web services. They don't have data centers or offices in Russia, but it's stopped allowing new signups for the service in Russia. BMW four GM Honda. Have all scaled back their operations or stopped them. Ford suspended its operations in Russia effective immediately until further notice.

[01:08:47] GM is suspending business in Russia. Honda has suspended exports to Russia, Disney halted, all theatrical releases in Russia, including the new Pixar film, turning red, also paused content DJA. The drone company that's gotten in trouble here in the us for some of its practices of sending GPS information to China while they're not doing it over there.

[01:09:13] Uh, electronic arts. They make a bunch of very popular, uh, games, epic games, another one, Ericsson FIFA body band Russia from this year's world cup formula one canceled its plan planned Russian ground pre Fujitsu, Goldman Sachs. Now Google that's where I want to go. We'll stop at Google here for a minute.

[01:09:38] Google. Suspended their ad network in Russia. And the idea was okay. Uh, we're not sure how payments are gonna work because Russia of course has had this kind of this lockdown by foreign countries on their banking system. We're not sure we can get the money out. Right. Um, uh, that's what they're apparently doing now.

[01:10:03] They're still there. Google's YouTube. It's search engine on and on still running in Russia. Now that is really disturbing. If you ask me, why did they not pull out? It doesn't make sense. So Google did stop accepting new customers for Google cloud. In March. YouTube said it's removing videos at denier trivial trivialize, the Russian invasion, but what finally got Google.

[01:10:37] Out of Russia, Russia seized their bank accounts. They froze, they transferred their money out of the main bank account in Russia. We're talking about a 2 billion per year business, Google Russia, that that really upsets me. So I did a little more research online about all of this, and I was really surprised to see that Ukraine now has given the Ukraine peace prize to Google.

[01:11:08] and it says, uh, quote on the behalf of the Ukrainian people with gratitude for the support during this pivotal moment in our nation's history. So what is it? I, I, I'm not sure. Right? So there, uh, one of their foreign ministers, I guess, and, uh, Koran. Baha I think, uh, said thank you from the beginning of the war, Google has sought to help.

[01:11:33] However, however we can through humanitarian support of our tools will continue to do as long as needed. So I dug in a little more and tried to figure out what's up. Well rush or Google left its Russian search engine online and YouTube online and was using it in Russia in order to. Control the narrative in Russia.

[01:11:58] Now, unlike what they've done here in the us, where Google has been caught, many times controlling the narrative in various elections and taking certain ads and not taking others and taking certain business and not taking others, apparently in Russia, it has been. Blocking a lot of the stuff that Russia itself has been putting out.

[01:12:23] So the, the federal government there in Russia. Interesting. Hey, so they also have helped Ukraine out by providing them with mapping GPS and rumor has it satellite service. Yeah. Interestingly to track Russian troop movements, uh, Al also Ukraine saying the Google news component has also been tremendously valuable.

[01:12:52] Google's also helping to raise money for the cause of Ukraine. Like many companies are doing right now to help people displace due to the war and Poland. Wow. They've been doing Yemen's work and, and bring. People in, by the millions, into Poland from Ukraine. It reminds me when I lived in Calgary, Alberta, my Cub, one of the Cub masters Cub troop leaders was a woman who came from Poland many years ago.

[01:13:20] This was back during Soviet occupation of. Poland. And I, I remember talking to her about what was happening over there. Why did she leave? And it is just so, so impressive. The polls have done so much impressive stuff over the years. So they're also saying that Google's done a lot of other things in order to.

[01:13:41] Help protect Ukraine, including Google's block domains. They've prevented fishing attacks against Ukraine. They've warn targeted individuals that they are being targeted. It's really something what they've done. So my first knee jerk was why is Google? Still doing business in Russia. Well, now it's become clear because they have a special page for Russians that gives correct information, at least, you know, Google's claiming it's correct.

[01:14:15] Uh, I don't know which fact checkers, checkers they're using, but. That gives Russians real information about the war what's going on in Ukraine. What's happening with the Russian soldiers. Did, did you see this just this last week, apparently Russia removed the age limit for volunteers for the military. It used to be, I think it was 40 years old.

[01:14:40] If you were a Russian citizen and 30 years old, if you were foreign national, now the Russian military will take. Any age from anywhere. In other words, Russia is really getting kind of hard up if they want people like me, right. To fight, to fight their wars. I'm sure they don't really well. I don't know.

[01:15:00] Maybe they do want me, right. That every, every war needs cannon fodder. So it is fascinating to see good job Google. I am quite impressed. I did not expect them to be doing that. They've also. Uh, uh, provided over 45 million in donations and grants to various groups. They've done pro bono work for various organizations over there.

[01:15:29] So this is really, really cool. So that's it. That's what's happening over there in you? Crane and Google, you can of course, find out a lot more. Get my insider show notes. So you had all of this on Tuesday morning. You could have digested it all and be ahead of everybody else out there. And then also don't forget about my new offer here.

[01:15:55] Free, absolutely free for anyone. Asks by emailing me Craig peterson.com. I'll go ahead and send them to you, which is I think a pretty cool thing now. What am I gonna send you? Well, you gotta ask first, right? You gotta ask. And what we're gonna be doing is taking what I have been using for years to help secure my customers.

[01:16:22] And we're making available for free my cyber punch lists. Craig peterson.com/subscribe.

[01:16:30] Bit of a hubub here, a B Biden's infrastructure bill $1.2 trillion. And, and it's in there is this thing that Bob BARR is calling an automobile kill switch. Well, I did some more research and we'll tell you the facts right now.

[01:16:47] What are you supposed to do? If you are trying to pass a bill to stop drunk driving deaths, and you've got all of the money in the world, you know, well, I guess 1.2 trillion, isn't all of the money in the world.

[01:17:01] What are you gonna put in there? Well, I did a search on this and I I'm chuckling because this is craziness. This is the AP associated press. And they've got this article claim. President Joe Biden signed a bill that will give law enforcement access to a kill switch that will be attached to all new cars in 2026 APS assessment false.

[01:17:27] Okay, so we've got fact checkers here while the bipartisan infrastructure bill Biden signed last year requires advanced drunk and impaired driving technology to become standard equipment in cars. Experts say. Technology doesn't amount to a kill switch. Hmm. Let me see. So I can't start the car. If the car's computer thinks I might be drunk or impaired in some other way, but that's not a kill switch.

[01:17:58] What, what is that? Then if I can't start the car, because I have a disagreement with the computer. How about these people that I don't know, maybe their eyes can't open all of the way. Maybe they have problems with eyes on nystagmus, the eyes kind of jittering back and forth. Right. And now what are they gonna do?

[01:18:18] Argue with the computer? That's a kill switch. I can't believe these crazy people that are like AP here, coming up with fact checking on things. So, yeah, I'm sure there's some distortions in some articles out there, but they contradicted themselves in two paragraphs. I guess they figure people are just gonna see false.

[01:18:42] Okay. I'm done. They're not gonna bother reading the rest of the article. Yeah. Kind of crazy, isn't it? So according to an article written by remember former us representative Bob BARR in the infrastructure bill, is this kill switch. Now the, the big question is what is the kill switch? How far does it go?

[01:19:07] So I decided, well, let's look up something I remember from years ago and that is GM GM has the OnStar system it's yet another reason I won't buy GM, there are a number of reasons, but this is another one. OnStar system, you know, they've got an advisor, isn't that great. And if your car is in a car accident, a crash that advisor can hop on and ask if you're okay.

[01:19:36] And if you want emergency services coming, they'll come, uh, OnStar will call them for you. And if you are just fine, they won't bother calling. I mean, if there's no answer at all, they'll they'll call emergency services and let them know where the vehicle is. Cuz the vehicle has with OnStar built in GPS.

[01:19:57] Well, one of the features of OnStar is that it can send a signal to disable cars, engines, and gradually slow the vehicle to an idle speed to assist police in recovering the vehicle. Now they will only do that at least right now for vehicles that have been reported stolen and have been confirmed by the police.

[01:20:25] So in, in reality, that's kind of cool, right? It slows down. Hopefully the bad guy, if he's on the highway, makes it over to the side of the road and while the car slows down and eventually stops. So, uh, all of this stuff sounds good. This kill switch. Sounds good. Doesn't it? Because you know, we're gonna keep drunk drivers off the road.

[01:20:52] Now in reality, of course, they're not gonna be able to keep drunk drivers or other impaired drivers off the road. I really don't care what kind of technology they put in. And they're not talking about putting in one of these blow in the tube, things that checks your blood alcohol level. They're talking about having a camera facing you as the driver and probably other occupants of the vehicles and that internally facing camera.

[01:21:21] It's going to evaluate you. It's gonna look at you. It's gonna look at your face. Is something droopy. Are, are you kind of slow to respond? It might have a little test that it has you take right there. The, the law is very loosey goosey on any details. There really aren't any, so it's gonna be up to the manufacturer.

[01:21:42] So they put this in the car step. Just like OnStar, step one, put it in the car and they'll tell you when to turn. Remember how cool that was the GPS with OnStar. And you'd say, yeah, I want to go to this address. And then the, uh, the assistant goes ahead and sense programming to your car. And now you can go and if you lock your keys in the car, they can unlock the car for you.

[01:22:08] All, all kinds of cool stuff. And then next up what happens. Well, but they can stop the vehicle. So there's another technology story related to OnStar. And this is from 2009 from Kelly blue book book, OnStar stolen vehicle, slow down forts its first carjacking. So again, doesn't that sound fantastic. This was a Tahoe OnStar.

[01:22:38] And, uh, the driver and his passenger forced out of the vehicle robbed by a shotgun wielding perp who then drove off in the SUV. And the OnStar dispatcher was able to locate the vehicle using GPS advised police of exact location. And as soon as the police established visual contact, the stolen vehicle slow down system is activated available on a number of GM cars and trucks.

[01:23:03] Right? So this was over a decade. That this happened, but the technology's evolved hasn. so we initially have all of these car companies trying to decide, okay. So we've got this kill switch law, which AP says is not a kill switch law. Cuz they talk to experts just like the, what was it? 52 people, uh, heads of intelligence.

[01:23:29] Committees and agencies said that this wasn't a collusion hoax, right? So they talked to experts who said, no, no, no, this isn't a kill switch, but that's today you can argue, it's not a kill switch. I would completely disagree with you. Day one. It's a kill switch cuz you can't start your car. Right. It's a kill switch.

[01:23:48] A kill switch is often something you hide somewhere on the car so you can kill the engine. So it can't be stolen. It's a kill switch. Come on. People fact checkers aside, but this could potentially allow law enforcement again, to shut down your car, remotely track the car's metrics, location, maybe the passenger load, because remember now cars are tracking all of this.

[01:24:14] There've already been. Tickets issued by police that did not see anyone speeding. The car was not caught on a traffic camera, but they hook up a device to your car's port that talks to its computer. And the computer says, yeah, he was doing 80 miles an hour or, uh, five minutes ago. And all of a sudden you got a ticket, right?

[01:24:35] Massachusetts wants to go ahead now and say, uh, yeah, yeah. Let's charge by the mile that you drive and mask. Because of course they're not getting enough revenue from gasoline because of the electric cars, right. Electric cars are not paying their fair share when it comes to road taxes. So let's do it that way.

[01:24:55] So how are they gonna collect the information? Well, They're gonna hook up to your car's computer. The next thing coming down the road, and it's already in most cars is wireless data connectivity. You might have found already. If you have a Nissan, a Honda, many other cars that. You have to get a major upgrade.

[01:25:17] It varies 600 bucks up to a few grand for an expensive car, but the two G data network, we talked about this on the show already is being completely shut down by the end of the year. So we've gotta replace it and switch you over. To the LTE data network, which of course eventually will go away as well, or at least 3g what happens once it's all hooked up?

[01:25:44] Well, the next easy step is just feed all of that information straight to the government. Craig, Peterson.com.

View Details

America Could Save $Billions$ on Prescriptions -Microsoft 365 users are under attack Business email compromises stealing billions again -
Online privacy getting better thanks to -
Apple Need help? Get my newest punchlists -
Google's huge problem in Russia -
Kill switches in cars -- again

About one-third of Americans are taking a prescription, and this is kind of the scary part. The average person who is on a prescription has four prescriptions, and we're paying dearly for it. But mark Cuban has an answer.

[Automated Transcript Follows]

Well, you know, I do a lot of stuff in cybersecurity, and I've got a few different courses coming up.

[00:13:19] And of course, we do a little bit of weekly training for anybody who's on my email list, you know, on the free list. Absolutely free as well as you get my insider show notes. And if you got my show notes, you probably noticed this on Tuesday when I sent it out. And that is Mark Cuban. Now for those who don't know mark Cuban, he started way back on the internet.

[00:13:44] Boom days. He lucked out. He had a, a company called broadcast.com. and he was able to turn that into, I think it was well over a billion dollars. I don't remember the exact amount, but it, it was a very, very big chunk of money. And then he's gone on to become an investor. You might know him as the owner of a basketball team.

[00:14:07] You might have seen him on a TV show called shark tank. He's been out there and he's a bright guy. He's been helping a lot of people and causing a lot of problems too. Right. But he has a new business that he has started with his billions of dollars only. He has at least 1 billion and it's called. Cost plus drugs.

[00:14:31] Now this is where it comes into affect every American, because I mentioned, you know, how many Americans are on various prescriptions? Well, many of the prescriptions that we could be taking are actually generics. So for instance, if you go to the Walmart pharmacy or Walgreens or wherever it. Be you'll find that they have options for you.

[00:14:56] If the doctor says, yeah, generic's okay. They'll say, Hey, listen, I'll give you the generic and you can save a whole lot of money. I don't know if you've looked at good RX at all. But good RX. I have saved a ton of money with that. And what they do is help you find free coupons. Compare the prices at, at Walmart Walgreen, CVS Rite aid, you know, at the major pharmacies.

[00:15:21] And we'll tell you where you can go to get your best deal. Plus. They also have some really cool discounts. So it, it acts kind of like a discount card. So I'm on their site right now. Good rx.com. And I look, I'm looking up their number one drug, which is Lipitor, apparently it's used for coronary art or coronary disease and high cholesterol.

[00:15:47] So they're saying, well, wait a minute. Now here. You can get a few different, uh, options. I'm looking now, for instance, CVS pharmacy nor normal retail, by the way is $126 at CVS. You can get it using a good rx.com card. 76% off for $30 instead of $126. Walmart, $15. Uh, Walmart neighborhood market, $15 now, Walmart, that's what they consider to be their retail price.

[00:16:24] Although, as I mentioned, some of these other ones have much, much higher retail prices. So you can see that going. For instance, for Lipitor, you might be. Paying a premium for a brand name. Now there, there's a good reason for that. There's a reason why prescription drugs can be expensive and, and they're called patent drugs.

[00:16:45] And the reason they're call patent drugs is they've put a lot of money in. They've put a lot of research time. They've, they've put up with a whole lot of regulation and going back and forth with various government agencies. And they finally were able to come forward with a drug that works. Put all of that together.

[00:17:05] And you've got a very expensive research and development product, right. Or project, frankly. So I don't, I don't really hold it against them. If we're having some of these drugs being rather expensive. You might remember that, uh, epi epinephrine a few years ago, this guy got a hold of the company that made epinephrine and the, um, You know, the, the whole problem with I'm looking it up right now, like EpiPens, they used to be expensive and then they became crazy expensive.

[00:17:41] So let me see here, EpiPens, EpiPens, and who needs it? There's a whole lot of information. It's not telling how much they are, but he raised the price. Like what was it? 2000% or something insane, again, a prescription drug and one that some people really need in order to save their lives. You know, I'm a beekeeper, right.

[00:18:05] And I used to have a really bad reaction to be stings, wasp stings. Now we just. Reaction, right. We thought at the time I was allergic, but no, it was just a bad reaction, which I still have. Right. It gets stung multiple times a year, but, uh, it still swells up. When, when, uh, our friend mark Cuban started looking at this, he said that this is kind of crazy.

[00:18:28] So what he's done now is mark Cuban has built, uh, I think it's all up and running just outside of Dallas. Let's see here. Yeah. Okay. Just outside of Dallas, a huge, huge building. It's a 22,000 square foot plant. Now most of the pharmaceuticals are actually easy to make and. To make. And that's what kind of gets confusing because you've got all of the R and D and the government regulations, everything else that's expensive, but actually making them is pretty cheap, but he's built this $11 million plant near downtown Dallas.

[00:19:10] And he says right now, looking at what the expenses are that Medicare could have saved as much as are you ready for this? 3.6 billion per year. Now that's where we're talking about everybody. Because if you pay taxes, you are paying for some of this Medicare money, 3.6 billion per year in savings. By buying it from cost plus drugs.

[00:19:42] So there's something else I want you to check out. So the first one was good. rx.com. The second one is cost plus drugs. They have over a hundred generic prescription medications right now. And what they're doing is they're taking the actual cost of production. And I'm sure that includes right. The loan on the building, et cetera, but the cost of production, plus a 15% margin because you need to keep the lights on.

[00:20:10] You need to be able to expand. Profit is not a bad word. That's how people save for retirement by investing in companies, buying stocks, and that profit then becomes their money for retirement. I think that's an important thing. So. 15% margin and an $8 pharmacy dispensing and shipping fee. That is absolutely cheap.

[00:20:37] So this is, uh, Hussain Liani who did the research on this? And he published it in the annals of internal medicine. Looking at that just absolutely amazing. And that's something you can do too. One third of Americans, again, we are on prescription drugs and the average person is on four. Wow. So researchers compared the price charge by cost plus drugs for 89, generic medications to the cost of the same drugs paid.

[00:21:13] Medicare in 2020, they found the government program could have saved 37% on 77 generic drugs by buying from Cuban's company cost plus drugs. Once in January drug to consumer bypasses, wholesalers, bypasses, pharmacies, bypasses insurance, all of those are driving up the cost of medicine. So direct to consumer.

[00:21:39] Uh, how easy could that be? And I'm on their website right now, looking at a couple of things here. Let me see, let me go back there. Cost plus drugs, and I'm believing this go to cost plus drugs.com. Yes you can. I am there as we are talking. So he's got, oh, here's one tib. Uh, which is the generic for gleek I'm.

[00:22:04] Now I'm not familiar with that myself retail price, $2,502. cost. Plus, are you ready? $14. Can you believe that that is crazy. Yeah. Wow. And it'll look, it'll look different obviously, cuz it's a generic. So you saved $2,488 for a 30 count supply. That is just amazing. So when I, I, I was talking about the savings here, where.

[00:22:37] Okay. They could have saved 37% on 77 generic drugs. But when you start getting into these really expensive drugs, that's where the 3.6 billion really, really starts to add up in savings. This is something so what you can do once you're on cost plus drugs.com, you can contact your doctor for a prescription.

[00:23:00] They've gotta get started button. They have the strength that you want in this case, a hundred milligrams or 400, the quantity you want. And then all that has to happen is your doctor has to approve it. You pay $14 instead of $2,500 and it gets shipped straight to you. Wow. Now, is that cheaper than Medicare part B right?

[00:23:25] Or your regular insurance? Wow, sure. Is just absolutely amazing. So you can find all of this stuff. This is mark Cuban doing this, and I gotta say, I am impressed. He is going to help a whole lot of people. Yeah, I'm, I'm just looking at this. Wow. Here's another one retail price. $9,600. And at cost plus drugs, you can get it for 39.

[00:23:54] So there you go. Two options, mark Cuban's new venture, which is online now@costplusdrugs.com and good rx.com. Wow. It's just amazing, right? This world. What's it coming to? Great little great little drug company. So we're gonna talk if you are a user of outlook, this is important to you because major tack underway.

[00:24:23] Major scam underway. If you are an outlook customer, you are in the crosshairs of a very successful credential stealing campaign. So I'm gonna tell you about that, what it means, what you can do and, uh, how you can stay safe.

[00:24:41] This is a very big problem for people who are using Microsoft 365, that is really common, used to be called office 365 and you pay a, a flat monthly fee, 20, 25 bucks.

[00:24:56] It kind of depends on what level you get. They have some real cheap ones as well, and it lets you use all of what Microsoft used to call Microsoft office applications. And one of those applications is. And I've never particularly liked. they have gotten better in recent years. And I actually do use it right now, as well as MacMail I use both of them, but there is a hack going on against Microsoft 365 and outlook customers in the us.

[00:25:31] Here's what's happening. They are sending you an email and the email really does look like it's ti voicemail that somebody left. This is called a voicemail fishing attack and it follows, what's kind of a classic fishing flow. If you will, the ways they've been doing fishing here over the years, and what fishing is, is basically.

[00:25:59] Getting you to bite at something that you shouldn't bite on. You, you will respond to an email. You'll click on a link. You might call a phone number. You might click on a text message. That's another one that's going around right now. How do you tell a fake text message from a real text message? And I'm afraid to say nowadays you tell by just not clicking on the links that are in text messages.

[00:26:27] It's, it's so disappointing. I was talking on the radio this week. It, it, it, because it just, it bothers me so much about this very thing. I've been on the internet for decades now. Right? I, I started back in 81. I think it was maybe 80. Two and we had email and it was the best thing ever. If you had somebody's email address, you could send them a note and you'd be pretty darn sure they'd get it.

[00:26:55] In fact, they probably would get it within just a few minutes and respond to you. And there, there wasn't any spam. Back then the idea was, Hey, listen, the internet is for research government research, university research, and that's the way it should stay. And indeed, we were kind of keeping it that way for, for quite a while.

[00:27:18] And then some people who were marketers got on the, in. And they would start to advertise, Hey, we have a special session for you at, uh, UC Berkeley this week only $500. And of course that went be beyond what the internet was for. In fact, at the time you could not use it legally. For any sort of financial purposes.

[00:27:44] So what we would do back then is we would send the script to the Monty Python routine of spam. Remember that spam, spam, and egg spam, and hands spam, spam. Uh, yeah, we would send them the whole. And they, sometimes, if somebody sent out a little thing that was trying to sell something that they should not be selling online because it was illegal to use the internet for business in case you didn't know until about 1991.

[00:28:17] And that's when I started. Putting businesses online and really started focusing in on cyber security because almost immediately the bad guys started getting on there. So this is, uh, this is really what happened. This was the script, right? Uh, well, what have you got waitress? Well, there's egg and bacon, egg, sausage, and bacon, egg, and spam, egg, bacon, and spam, egg, bacon, spam, sausage, and spam spam, bacon sausages, and spam spam eggs, spam spam, bacon spam.

[00:28:48] Do you remember that? So. We would send this to people who kind of broke the rules written or unwritten on the internet. And sometimes somebody would get just a hundred of these things, maybe even more. And what would happen back then of course, is it would fill up your mailbox and it would slow down your check connection.

[00:29:07] Cuz a lot of us were just connected to the internet via dial up modems. So it, it really kind of hurt you to get all kinds of spam. Emails coming in. That's where the term comes from. I remember it well, so I don't care what they say on some of these websites or they're trying to do little research on it and figure it out.

[00:29:28] Well, now things have gotten a lot worse because it isn't just marketers that are trying to solve something. And I don't have a problem with marketers, I guess, in a way I am one myself. Right. I, I have a business and I provide cybersecurity services. For a high net worth individuals and for businesses.

[00:29:47] And if you are a regular person, you have a question. Please ask, just send an email to me, me Craig peterson.com, no matter who you are. And I will try and answer the question for you. And I have a lot of stuff that I've written over the years. That'd be more than glad to forward to you. There are some training courses that I.

[00:30:07] Put together that I will be more than glad to share with you. And you probably know I did all of the training for the FBI's Ingar program for a couple of years. I, I ran that online, all of their webinars. So I've been doing this for a long time and I'm more than glad to help. That's why I am here. Right.

[00:30:28] But now we got bad guys. and the bad guys are trying to get you to do something against your best interest. So in this case, what happens is you get a missed voicemail notification via email, and a lot of times it'll look pretty legitimate. It might even be coming from someone inside your company, whose account they have hacked.

[00:30:54] Now on that email, there is an HTML attach. Now HTML attachments can get past a lot of email gateway filters because they aren't in and of themselves malicious. So they're not raising big red flags for users in a, in a voicemail notification setting because that's how office Microsoft office sends you legitimate notifications.

[00:31:20] Anyways. Now, these from fields are set up specifically using the organization's name. As I said, sometimes even a valid email address. Now, if you go ahead and click on that attachment, it will run a program on your computer using a language called JavaScript and that's embedded in every browser out there nowadays.

[00:31:44] And that JavaScript code is going to redirect you to an attack. Controlled website. Now this website set up to get you to give up your credentials. So, what they'll do now is as you go to the website and the website might look like it's Microsoft office and it might look like it's your business website, and it'll ask you to log in.

[00:32:12] It might ask you for other information as well. It is trying to get your username and password that it can then use to go after other people. You see what's happening here. So each of the URLs, these guys are creating these websites that they're sending you to are created to match the targeted company.

[00:32:36] It's it's incredible how good they're getting, and they even have one of those Google recapture. Pop ups. Now this is a, an increasingly popular technique to evade these auto mail, automated URL analysis tools. So for instance, with my client, an email comes in, it goes through Cisco's. Email filter. We have an advanced email filter from Cisco, but we run our client's emails through.

[00:33:07] And what happens is they look at the URLs, they visit the website that the URL PO points to, they try and verify if it's legit or not. And you you've had captures, you know, it's, um, click every box that has a bicycle in it, sort of a thing. It's kind of a touring test, test puzzle. So once this is solved, We'll tell you what happens next, cuz we're out of time right now.

[00:33:33] Uh, make sure you visit me online. Craig Peter son.com. I'll keep you up to date. You can get my free newsletter and trainings. Craig Peter son.com. And I want to talk too about businesses in the, the big business of email compromise.

[00:33:52] Yeah, I think most of us know what a big business is. Well, how about a business, an industry that has racked in 43 billion, according to the FBI. That's what we're talking about right now and what you can do about it.

[00:34:08] We'll help keep you up to date and make sure you keep an eye out Tuesday mornings for that newsletter that comes your way every Tuesday morning, the insider newsletter you can sign up for for free@craigpeterson.com.

[00:34:29] We were talking about, what's been happening with Microsoft outlook users right now, a major campaign underway that has been extremely successful because these bad guys are using some rather advanced technologies. Absolutely crazy. So they get you to click. HTML link that is there while filed that is there as part of what looks to be a voicemail notification for you.

[00:35:00] And then it takes you to a website that's specially crafted for you and your company. So you work@bigco.com and you click on that HTML and it'll take you to big co.com. Well, at least that's what it looks like, but it distracts you now because it wants to give you this capture as well. So this Google captures, you know, these things, these little mini touring tests, click on all of the trees in the picture, sort of a thing, right?

[00:35:35] And you've got the nine things well with, uh, or maybe it's some blurred or distorted text and you have to type that in. And the whole idea behind that is normally to weed out these bots on eCommerce sites, online account sites. But what they're doing here is. They're making sure that the email, the, the software that checks the emails to make sure they are legitimate, that is going out to the big co dot or big co fake.com website.

[00:36:11] They wanna make sure that that email checker does not find out that it's not the real site that you wanted to go. So the computer that's doing the checking will go to the site and it'll say, oh, there's a capture on there. And then it'll stop because it can't solve the capture. It needs you, it needs a human, right.

[00:36:32] So this is kind of cool here. Uh, Eric. K. He's a security awareness advocate with no before. No. Before is a company that does training for people, for employees here about some of these, uh, these hacks and things are going on. When faced with a login prompt, it looks like a typical. Office 365 login. The person is likely to feel comfortable entering their information without looking at the browser's URL bar to ensure they are at the real login site, this familiarity and the high odds in an attended victim regularly uses office 365 for something in the Workday makes this a great Lu.

[00:37:19] For attackers, this is from an article over on dark reading.com. This isn't, uh, a new technique, but let me tell you, it is B a very successful one. They have seen a resurgent, uh, resurgence of this starting a couple of years ago, back in July, 2020. And it is really targeting human nature. And of course, Microsoft 365 is quite the target.

[00:37:46] So I mentioned. $43 billion industry. I'm looking right now at a public service announcement from the F FBI and they are calling business email compromise the $43 billion. Scam. This is crazy. A sophisticated scam. It targets businesses and individuals who are performing legitimate transfer funds requests.

[00:38:17] It's carried out by people who are compromising legitimate businesses and individuals. Now, what they're trying to do with this business email compromise is get someone who has. Control of funds to do a transfer. What happens is they will do a little research on the business that might go to the website and see on the website.

[00:38:42] Oh, let me see here. Okay. The president's name is Craig Peterson. Uh, the CFO is Mary Jane and, uh, the accounting department head is manly. And, uh, so now they got that information. So they'll go online. And to look at LinkedIn, find out who all else is at the business. Maybe things have changed, you know, maybe try and find an email address by doing an open source search for the email address of people there at the business.

[00:39:15] You see where this is going here? Yeah, it, it gets pretty bad. So, uh, let's say they befriend the CEO on Facebook or on LinkedIn, but Facebook more likely, uh, and now. They're they can see on Facebook or maybe they don't even have to because your Facebook profile and posts are not hidden from the public.

[00:39:37] So they just go there and, oh, let me see. Okay, great. He's gonna be out of town next week. And then what they'll do is they'll get into somebody's email account at the business. And once they're into somebody's email account, they can start looking through the emails and sending emails that look perfectly legitimate to other people within the organization.

[00:40:00] Now, I, I did a whole story on television about this one on news program, and one of the people on staff, one of the talking. received an email like this, and it asked him to, uh, to buy some gift cards. This is very, very common scam right now, the gift card scam, and they try and get you to go ahead and. Buy gift cards for other people in the office are gonna have a little party and we don't want anybody else to know about it.

[00:40:32] It's supposed to be a surprise. And I had some real fun with him. One of these days, I should probably share all of this in one of my newsletters. I think you guys would really appreciate it, enjoy it a little bit, but, uh, we really led them on and sure enough, you know, it was a total scam and we kept playing with them and it, it was something, any.

[00:40:55] That was one thing. This is another because they will eventually get to the CFO, somebody who has the authority to transfer funds and get them to transfer funds to. Them. And then they use mules to move the money around these, uh, useful idiots who will sign up. And yeah. Yeah. It's kinda like the Nigerian scam.

[00:41:22] All I need is access to your bank account and I'm gonna wire in, uh, $10,000. And I, and what I need you to do is transfer 8,000 of it over here to this PayPal account because my grandmother's dying and she needs the. There's similar scams that are going after lonely people and getting them to send money because somebody needs an operation, et cetera.

[00:41:50] So in this case with the business email compromise and the 43. Billion dollars that have been stolen from businesses. They'll usually get to the CFO and send a story like, Hey, uh, we have this new vendor and we've had 'em for three months and we haven't been paying them and we gotta make sure we pay them.

[00:42:11] And, uh, we need to wire 43 million to this account that actually happened. And they did wire the money. It happened to Barbara cran, another person who wa is on shark tank. Uh, it, it happens to a lot of companies out there. And I've got a couple in the last month that we've worked with the FBI on the, these companies hear me on the radio.

[00:42:38] They sent an email to me@craigpeterson.com and they had had their operating account. Emptied. Uh, the latest one is a, a lady 77 years old who had her retirement money stolen from her over $70,000. This stuff's real people. We've got to pay attention. We can't let this continue to happen. Make sure you sign up online.

[00:43:05] Craig peterson.com so that you can get my insider show notes and we can keep you ahead of the bad guys. When we come back, we're gonna talk about this row overturned and what senators are asking the FTC.

[00:43:23] We've got some senators who are saying they were spurred on by the row overturned. And they're asking the FTC to probe, apple and Android, and what's happening with tracking. Now I have a suspicion. That's not really right.

[00:43:40] Well, we've got three Democrat, us senators and a Democrat us representative that asked. The federal trade commission to investigate apple and Google for engaging in unfair and deceptive practices by enabling the collection and sale of hundreds of millions of mobile phones, users, data, the FTC should investigate apple and Google's role in transforming online advertising into an intense system of surveillance that incentivizes and facilitates the UN.

[00:44:16] Train collection and constant sale of Americans' personal data. These companies have failed to inform consumers of the privacy and security dangers involved in using those products. It is beyond time to bring an end to the privacy harms, forced on consumers. Buy these companies. Now I have been talking about this on the radio for 20 years.

[00:44:45] Because do you remember when Congress forced telephone manufacturers and cell phone companies to put GPS coordinates into the receivers, into the phones? Do you remember that you could no longer use your analog phone? You had to use digital phones under federal. right. It, it's just amazing. We can go into all of the reasons that they've given for that in the past, but anyhow, that's what they did.

[00:45:20] So immediately decades ago, now, many years ago, they started collecting data. Now it's okay for the government to collect it, even though it's illegal. For them to collect this data. So what's happening here? Why have the Democrats for so long? Well, and frankly, a lot of Republicans been big on collecting data on all of us.

[00:45:43] Now, I I've gotta say when I've looked at the stats, the biggest. Purveyors of the surveillance society have been president Obama followed by president Biden. Now you could argue that president Bush was won too, because of course they passed an act that allowed for all kinds of changes in surveillance.

[00:46:07] So, okay. So we'll put him in there too. So we got a Republican in there. Obama put that program that president Bush had put in place on steroids and then president Biden did the same thing. President Trump tried to cut it back because he was a victim of some of the surveillance that they were doing. So what's going on here?

[00:46:29] Well, these Democrat senators are saying, uh, we don't want people who are trying to get abortions to be. okay. I can see that. Uh, I can also see that I don't want to be tracked and you don't want to be tracked. And it's one thing to have an advertiser know a little bit about us, you know, Hey, we just visited the Ford dealer and the Chevy dealer and the Honda dealer.

[00:46:57] So maybe he's looking for a car let's let's try and advertise a car. Right. So Honda and Chevy and Ford all start putting ads up for you. Okay. So that's. Thing if I'm in, if I'm interested in buying a truck. Okay, great. Show me ads on a truck, but we've seen already misuses of this data over the years. One of the earliest oness I talked about here on the radio was this guy who went to an emergency room and all of a sudden started seeing ads for what you might call ambulance, chasing lawyers saying, have you been injured?

[00:47:35] right. You've seen those types of ads before, but once he was in the emergency room and he was geolo geolocated in the emergency room, they started selling advertising to lawyers. I, I, I'm not real fond of that one either, but I think there's an ulterior motive here behind what these Democrats are saying.

[00:47:57] If you have seen the movie 2000 mules, you understand what I'm talking about? what ended up happening here is they looked at trillions of data points. You see, they went out and bought databases of smartphone data where these smartphones were located. And then they started doing some serious analysis on it and they were able to say, okay, this smartphone went to.

[00:48:33] Different Dropboxes for the election for ballots. And in between each visit to the Dropbox, they went to a left wing organization where they did something. Right. So they, they go to a Dropbox drop off ballots and they're on video doing this, dropping off ballots. And then they go to a left wing organization and then they go drop off more ballots at a different Dropbox, and then they go back again and then it's on video.

[00:49:07] And some of these people are taking pictures of them, stuffing the ballots into the box, supposedly, so they can get paid. So now there are some criminal investigations that have been started. I don't know how far they've gotten yet over some of this information that was gathered. And that was documented in the film by Danes.

[00:49:28] Dusuza called 2000 mul. And if you haven't seen it, no matter what side of the aisle you want, you need to see it absolutely need to. And whether you believe or not, when president Biden said that we have the best, uh, what was it? Um, election stealing organization that's ever been made? I can't remember his exact words right now.

[00:49:53] Uh, he was serious about it, right? So now all of a sudden, the Democrats are concerned that people who visit abortion clinics might be tracked, cuz they could. Right. You could buy data geotagged with an abortion clinic's location, GPS coordinates. You absolutely could do that, but that's been true for a long time.

[00:50:19] Why now? Well, maybe because of Roe V Wade, but I look, of course it wasn't just that one decision that was overturned, but I, I look at some of this and really, really do wonder because it really looks like some number of people were caught illegally stuffing ballot box. So it's, it's fascinating to me that all of a sudden now out, they come with this.

[00:50:49] Now apple has stopped enabling the tracker identifiers. By default, if you have an apple smartphone, it is much more. Private than the Android phones are by far, right? Google makes its money by selling your information. That's how they make most of their money. Apple makes its money by selling you services and selling you hardware.

[00:51:18] so that should tell you something right there. And the fact that Senator Elizabeth Warren is one of the ones who is proposing this legislation makes you think even more about this. Now, Google, uh, this is an article from ours. Technical apparently responded to this whole concept in an article that ours was writing, saying that it's had all kinds of efforts to block apps and violate Google play policies.

[00:51:47] the bands it's imposed on companies that are apparently sold user data, and they say Google never sells user data in the play at Google, strictly prohibits a sale of user data by developers and, uh, goes into the advertising ID. So it it's fascinating to me that all of a sudden, now the Democrats are interested in stopping the data, collect.

[00:52:12] It really is. I don't like it. As I said, I've talked about this for more than 20 years now on the radio. It, I think it's a real problem. This data collection, because also the federal government, even though it's illegal for them to collect information on American citizens, they do it every. And some of the largest, like the, um, immigration people, Homeland security are the biggest collector.

[00:52:42] They have more information about you than anyone else. Even if you're here legally, you were born in the United States, et cetera, etcetera, because they are buying all of this information from what are called data broker. So, yeah, they say, yeah, we're, we're not collecting it. You we're forbidden by law to collect it, which is absolutely true.

[00:53:04] But what they are doing is buying it from private businesses. So I think we've got to completely. Reconsider how this all works. Apple has been working on it. You can go into your apple phone and make a change, share identifier if you want to, which makes it harder to track apple also. And Google has this, as I believe is an option.

[00:53:30] But apple also will give you a different Mac address every time you're connecting to wifi networks so that you can't be tracked that way. Because just, if, if you connect to the network at target the wifi at target, for instance, they will know when you return because your phone has the same Mac address that's used for the wifi.

[00:53:53] So they know. They know where you go in the store. They know what you're looking at in the store, in some cases, depending on how the tracking works. So it's fascinating to me, this is a, a real privacy issue that could easily turn into something much worse because this data, this same data that's available to marketers is available to government is also available to bad guys.

[00:54:21] and you talk about the ability to potentially frame someone and it, it, it just gets extremely, extremely scary. Right now, last month, more than 40 members of Congress called on Google to stop collecting and retaining customer location data, the prosecutors could use to identify women who obtain abortions.

[00:54:42] Again, tied into this, uh, abortion anytime any day. Uh, and as the governor of Virginia said, even after the baby is born and delivered it, you should be able to abort it. Uh, so wherever you fall in that spectrum, obviously the Democrats in the us want abortions far more than the Europeans that every European country I can think of has much tougher restrictions on abortion than we have here.

[00:55:09] But. Privacy is not an abortion issue. Hey, join me online. Craig peterson.com. Make sure you are on my email list. And, uh, you can ask any question you want. Just email me, me, Craig peterson.com.

[00:55:31] I really appreciate all the emails I get from you guys. And it is driving me to do something I've never done before now. I've always provided all kinds of free information to share on my email list. Great stuff. But now we're talking about cyber punch lists.

[00:55:48] There are a number of stories here.

[00:55:50] They they'll come out, uh, in the newsletter or, or they did, excuse me, come in. The newsletter should have got on Tuesday morning. And that's my insider show notes, which is all of the information that I put together for my radio appearances radio shows. And. Also, of course, I send it off to the host at these various radio stations.

[00:56:12] So they know what's hot because who really, really tracks technology, not too many people. And I get, uh, you know, a little off put by some of these other radio hosts that call themselves tech people, and they're actually marketing people, but. That's me. Right. And that's why, if you are on my list, you've probably noticed I'm not hammering you trying to sell you stuff all of the time.

[00:56:37] It's good, valuable content. And I'm starting something brand new. Never done this before, but this is for you guys. Okay. You know that I do cybersecurity. As a business and I've been doing it now for more than three decades. I don't know if I should admit that. Right. They say, never say more than 17 years.

[00:56:58] Okay. So I've been doing it for more than 17 years and I've been on the internet now for. Oh, 40 years now. Okay. Back before it was even called the internet, I helped to develop the silly thing. So over the years, we've come up with a number of different strategies. We have these things that are called plan of action and milestones, and we have all kinds of other lists of things that we do and that need to be done.

[00:57:29] So what we're doing right now is we're setting it. So that you can just email me, me, Craig peterson.com. And I will go ahead and send you one of these punch lists. Now the punch lists are around one specific topic. You know, we got these massive. Punch lists with hundreds and hundreds of things on them.

[00:57:51] And those are what we use when we go in to help clean up the cybersecurity in a company. So we'll go in, we'll do scans. We will do red team blue team where we're attacking. We do all, all kinds of different types of scans using different software, trying to break in. We use the same tools that the hackers use in order to see if we can.

[00:58:15] Into your systems and if the systems are properly secured, so we do all of this stuff, so, and, and then it goes into all of the paperwork that needs to be done to comply with whatever it might be. Right. It might be, they accept payment cards. It might be that they have hip. Information, which is healthcare information.

[00:58:35] And it might be also that they're a government contractor. So there are hundreds and hundreds of things that they have to comply with. Most of them are procedural. So we have all of this stuff. We do all of this stuff. And I was talking with my wife here this last week about it and said, you. So much of this could be used by small companies that can't afford to hire my team to come in and clean things up.

[00:59:01] Right. And I don't want them to suffer. So here's what we're doing. We're starting this next week. We have a punch list for you on email. So what are the things you can do should do for email? Just very, very narrow on email so that you can recognize a fishing. Email, what you might wanna do to lock down your outlook, if you're on windows or your Mac mail.

[00:59:32] So we're taking these massive spreadsheets that we have and we're breaking them up. So the first one that's available to you guys, absolutely. A hundred percent free. Is the one on email. So just send me an email. Me M E Craig peterson.com. Now, remember I am, my, my business is a business to business business, right.

[00:59:54] But almost everything in these various. Punch lists applies to individuals as well. So I got an email this last week from a guy saying, Hey, I'm 80 years old and, uh, retired and I don't know much about computers and that's kind of what got us thinking about this. You know, we need to be able to help him.

[01:00:16] We need to be able to help you out. Okay. And if you're a small business and we've dealt with a lot of them over the years, and as a small business, you just don't have the funds to bring in an expert, whether it's me or somebody else, although yeah. What you want the best. But anyways, , it, it, uh, it is gonna allow you to do it yourself.

[01:00:39] Okay. So absolutely. All of these punch lists on all of these topics, we're probably gonna end up with more than a hundred of these punch lists. And all you do is email me, me, Craig peterson.com. Just let me know in there what you're interested in. So even if we haven't got that punch list broken down for you yet, we will go ahead and put that on the.

[01:01:06] To do right. We need the priorities. What kind of a priority should we have as we're putting these things together for free for people. Right. Uh, and the only way we know is if you ask, so the first one's on email, you can certainly ask for email. We've got, as I said, more than a hundred others, that we think we're gonna be able to pull out of the exact.

[01:01:27] Plan of action worksheets that we use so that you can go through this yourself, whether you're a home user or you are a small business or even a big business, right? We we're talking with, uh, a gentleman who's probably listening right now, who has a business. They have three offices, they have some requirement because of the military contracts for high level.

[01:01:53] Cyber security and it would work for him too. All right. So they, this is all of the punch list stuff. You probably know what a punch list is, right? It's using the construction industry a lot, but in our case, it's you need to do this. You need to do this, you need to do this. Okay. So that's what that's all about.

[01:02:11] So enough rambling on that. It's gonna take us some time to get 'em all together. I'm also. We're gonna do more video stuff again, training. So just like on the radio show where we're talking about what's in the news, we're gonna talk about what's what's in the news. When it comes to small businesses, what you should be paying attention to with of course, an emphasis on cybersecurity and we're.

[01:02:37] Putting those up on my website@craigpeterson.com. In fact, we've already got some up there already, and then we are going to also be putting them on YouTube and rumble. So if you don't like YouTube and Google, then you can certainly go to rumble. You'll see them there. But if you're on the email list, I'm.

[01:02:57] Starting to put links in the bottom of the emails. So you can go and watch those videos. If you are a video type person that you know, more visual. So it's, I think all good. And it's good news for everybody. And this is what happens, I think, as you get more mature, In the business. Right. Um, as I said, I've been on the internet for more than 40 years, helped develop some of that software that, uh, some of it's still in use today and now it's time to do more give back.

[01:03:29] And I really am trying to give back, okay, there's this isn't. This isn't a joke. So, uh, no joke. Right. So go ahead. Email me at Craig Peterson. Tell me which punch list that you would like. And I can also put you on my email list so that you get my insider show notes, and you can just do that yourself by gonna Craig Peterson dot.

[01:03:52] Com you'll see right up at the top of the page. If you scroll down a little bit, it'll kind of pop up. It's a big red bar that goes across the top. I try not to be too intrusive and you can sign up there for the newsletter. So you'll get some of these trainings automatically. You'll get my insider show notes, all of this stuff.

[01:04:11] It it's absolutely free. Okay. This is my give back to help you out. It really is. Okay. I, as I mentioned at the very beginning, I. Peeve by some of these people that represent themselves as tech experts. And in fact, all they are are marketers. We've got a client that decided that, uh, I was too expensive. My team.

[01:04:31] So they went out and shopped around, tried to find the cheapest company they could. And so now the, the company that they're bringing in is saying, you're saying, uh, Hey, um, uh, so how does this work? How do you do zero trust? Uh, why do you have a firewall here? Uh, why do you bother to have a direct fiber link between the offices?

[01:04:53] All this stuff? Well, because they need it. Okay. I get it. You use. Barracuda spam firewalls and Barracuda firewalls. It, it, yeah, this is a different league. Okay. So you are gonna be getting these punch lists from me that are really gonna help you understand and secure your systems. Right? This isn't your average run of the mill so-called managed security services provider or managed services or break fix shop.

[01:05:24] You are getting it from the guy that the FBI. Ingar program went to, to do their trainings. That was me. Okay. So for two years I set up the program. I ran it. And if we ever are sitting down having a coffee or beer, sometimes I'll tell you why I left. Okay. Uh, but think about FBI and I, I think you might have a clue as to why I decided not to do that anymore, but I trained thousands of businesses, government agencies, state local.

[01:05:56] Federal, you name it. So you are getting what you really need, which is another problem. I keep hearing from people, you do a search for something on YouTube or Google and you get what a million, 5 million pages, right. As supposedly that it says are available and they give you, okay, here's the top one, but what you need is an integrated, single.

[01:06:22] To do things where everything works together. And that's what I'm trying to do for you guys, because there's so many little products, different products that just don't work so well together. So we'll, we'll be covering that as well in these, but you gotta be on that email list. Craig peterson.com. Craig Peterson.

[01:06:43] So n.com/subscribe will take you right to the subscription page. And I'll keep you up to date. This is not my paid newsletter. All right, stick around. We'll be right back. And I promise I'll get to Russia, Russia, Russia.

[01:07:01] Some of the high tech companies and others pulled out of Russia after the Ukraine invasion, but one stayed Google. What is going on with Google? And now they're in big trouble with the Russian government. Wow.

[01:07:18] here's a list of companies according to CNET that have pulled. Out of Russia because you remember Russia invaded Ukraine, February 24, we had Adobe, these are the guys that make Photoshop, Adobe reader. Airbnb, Airbnb has kind of an interesting story too in Ukraine because a number quite a number of Airbnb customers went ahead and rented rooms and homes from Ukrainians, even though they had no intention of going and they told the Ukrainians, Hey.

[01:07:51] I'm not gonna show up, just take this money. I'm sure you need it. Can you, can you imagine that that's fantastic. Good for them, Amazon, they suspended shipments of all retail products of customers in Russia and Bella Russ, and also suspended prime video for users in Russia. Apple stops selling its product in Russia's it's halting online transactions, including limiting apple pay.

[01:08:18] It's also disabled. Some apple map features in Ukraine in order to protect civilians, Amazon web services. They don't have data centers or offices in Russia, but it's stopped allowing new signups for the service in Russia. BMW four GM Honda. Have all scaled back their operations or stopped them. Ford suspended its operations in Russia effective immediately until further notice.

[01:08:47] GM is suspending business in Russia. Honda has suspended exports to Russia, Disney halted, all theatrical releases in Russia, including the new Pixar film, turning red, also paused content DJA. The drone company that's gotten in trouble here in the us for some of its practices of sending GPS information to China while they're not doing it over there.

[01:09:13] Uh, electronic arts. They make a bunch of very popular, uh, games, epic games, another one, Ericsson FIFA body band Russia from this year's world cup formula one canceled its plan planned Russian ground pre Fujitsu, Goldman Sachs. Now Google that's where I want to go. We'll stop at Google here for a minute.

[01:09:38] Google. Suspended their ad network in Russia. And the idea was okay. Uh, we're not sure how payments are gonna work because Russia of course has had this kind of this lockdown by foreign countries on their banking system. We're not sure we can get the money out. Right. Um, uh, that's what they're apparently doing now.

[01:10:03] They're still there. Google's YouTube. It's search engine on and on still running in Russia. Now that is really disturbing. If you ask me, why did they not pull out? It doesn't make sense. So Google did stop accepting new customers for Google cloud. In March. YouTube said it's removing videos at denier trivial trivialize, the Russian invasion, but what finally got Google.

[01:10:37] Out of Russia, Russia seized their bank accounts. They froze, they transferred their money out of the main bank account in Russia. We're talking about a 2 billion per year business, Google Russia, that that really upsets me. So I did a little more research online about all of this, and I was really surprised to see that Ukraine now has given the Ukraine peace prize to Google.

[01:11:08] and it says, uh, quote on the behalf of the Ukrainian people with gratitude for the support during this pivotal moment in our nation's history. So what is it? I, I, I'm not sure. Right? So there, uh, one of their foreign ministers, I guess, and, uh, Koran. Baha I think, uh, said thank you from the beginning of the war, Google has sought to help.

[01:11:33] However, however we can through humanitarian support of our tools will continue to do as long as needed. So I dug in a little more and tried to figure out what's up. Well rush or Google left its Russian search engine online and YouTube online and was using it in Russia in order to. Control the narrative in Russia.

[01:11:58] Now, unlike what they've done here in the us, where Google has been caught, many times controlling the narrative in various elections and taking certain ads and not taking others and taking certain business and not taking others, apparently in Russia, it has been. Blocking a lot of the stuff that Russia itself has been putting out.

[01:12:23] So the, the federal government there in Russia. Interesting. Hey, so they also have helped Ukraine out by providing them with mapping GPS and rumor has it satellite service. Yeah. Interestingly to track Russian troop movements, uh, Al also Ukraine saying the Google news component has also been tremendously valuable.

[01:12:52] Google's also helping to raise money for the cause of Ukraine. Like many companies are doing right now to help people displace due to the war and Poland. Wow. They've been doing Yemen's work and, and bring. People in, by the millions, into Poland from Ukraine. It reminds me when I lived in Calgary, Alberta, my Cub, one of the Cub masters Cub troop leaders was a woman who came from Poland many years ago.

[01:13:20] This was back during Soviet occupation of. Poland. And I, I remember talking to her about what was happening over there. Why did she leave? And it is just so, so impressive. The polls have done so much impressive stuff over the years. So they're also saying that Google's done a lot of other things in order to.

[01:13:41] Help protect Ukraine, including Google's block domains. They've prevented fishing attacks against Ukraine. They've warn targeted individuals that they are being targeted. It's really something what they've done. So my first knee jerk was why is Google? Still doing business in Russia. Well, now it's become clear because they have a special page for Russians that gives correct information, at least, you know, Google's claiming it's correct.

[01:14:15] Uh, I don't know which fact checkers, checkers they're using, but. That gives Russians real information about the war what's going on in Ukraine. What's happening with the Russian soldiers. Did, did you see this just this last week, apparently Russia removed the age limit for volunteers for the military. It used to be, I think it was 40 years old.

[01:14:40] If you were a Russian citizen and 30 years old, if you were foreign national, now the Russian military will take. Any age from anywhere. In other words, Russia is really getting kind of hard up if they want people like me, right. To fight, to fight their wars. I'm sure they don't really well. I don't know.

[01:15:00] Maybe they do want me, right. That every, every war needs cannon fodder. So it is fascinating to see good job Google. I am quite impressed. I did not expect them to be doing that. They've also. Uh, uh, provided over 45 million in donations and grants to various groups. They've done pro bono work for various organizations over there.

[01:15:29] So this is really, really cool. So that's it. That's what's happening over there in you? Crane and Google, you can of course, find out a lot more. Get my insider show notes. So you had all of this on Tuesday morning. You could have digested it all and be ahead of everybody else out there. And then also don't forget about my new offer here.

[01:15:55] Free, absolutely free for anyone. Asks by emailing me Craig peterson.com. I'll go ahead and send them to you, which is I think a pretty cool thing now. What am I gonna send you? Well, you gotta ask first, right? You gotta ask. And what we're gonna be doing is taking what I have been using for years to help secure my customers.

[01:16:22] And we're making available for free my cyber punch lists. Craig peterson.com/subscribe.

[01:16:30] Bit of a hubub here, a B Biden's infrastructure bill $1.2 trillion. And, and it's in there is this thing that Bob BARR is calling an automobile kill switch. Well, I did some more research and we'll tell you the facts right now.

[01:16:47] What are you supposed to do? If you are trying to pass a bill to stop drunk driving deaths, and you've got all of the money in the world, you know, well, I guess 1.2 trillion, isn't all of the money in the world.

[01:17:01] What are you gonna put in there? Well, I did a search on this and I I'm chuckling because this is craziness. This is the AP associated press. And they've got this article claim. President Joe Biden signed a bill that will give law enforcement access to a kill switch that will be attached to all new cars in 2026 APS assessment false.

[01:17:27] Okay, so we've got fact checkers here while the bipartisan infrastructure bill Biden signed last year requires advanced drunk and impaired driving technology to become standard equipment in cars. Experts say. Technology doesn't amount to a kill switch. Hmm. Let me see. So I can't start the car. If the car's computer thinks I might be drunk or impaired in some other way, but that's not a kill switch.

[01:17:58] What, what is that? Then if I can't start the car, because I have a disagreement with the computer. How about these people that I don't know, maybe their eyes can't open all of the way. Maybe they have problems with eyes on nystagmus, the eyes kind of jittering back and forth. Right. And now what are they gonna do?

[01:18:18] Argue with the computer? That's a kill switch. I can't believe these crazy people that are like AP here, coming up with fact checking on things. So, yeah, I'm sure there's some distortions in some articles out there, but they contradicted themselves in two paragraphs. I guess they figure people are just gonna see false.

[01:18:42] Okay. I'm done. They're not gonna bother reading the rest of the article. Yeah. Kind of crazy, isn't it? So according to an article written by remember former us representative Bob BARR in the infrastructure bill, is this kill switch. Now the, the big question is what is the kill switch? How far does it go?

[01:19:07] So I decided, well, let's look up something I remember from years ago and that is GM GM has the OnStar system it's yet another reason I won't buy GM, there are a number of reasons, but this is another one. OnStar system, you know, they've got an advisor, isn't that great. And if your car is in a car accident, a crash that advisor can hop on and ask if you're okay.

[01:19:36] And if you want emergency services coming, they'll come, uh, OnStar will call them for you. And if you are just fine, they won't bother calling. I mean, if there's no answer at all, they'll they'll call emergency services and let them know where the vehicle is. Cuz the vehicle has with OnStar built in GPS.

[01:19:57] Well, one of the features of OnStar is that it can send a signal to disable cars, engines, and gradually slow the vehicle to an idle speed to assist police in recovering the vehicle. Now they will only do that at least right now for vehicles that have been reported stolen and have been confirmed by the police.

[01:20:25] So in, in reality, that's kind of cool, right? It slows down. Hopefully the bad guy, if he's on the highway, makes it over to the side of the road and while the car slows down and eventually stops. So, uh, all of this stuff sounds good. This kill switch. Sounds good. Doesn't it? Because you know, we're gonna keep drunk drivers off the road.

[01:20:52] Now in reality, of course, they're not gonna be able to keep drunk drivers or other impaired drivers off the road. I really don't care what kind of technology they put in. And they're not talking about putting in one of these blow in the tube, things that checks your blood alcohol level. They're talking about having a camera facing you as the driver and probably other occupants of the vehicles and that internally facing camera.

[01:21:21] It's going to evaluate you. It's gonna look at you. It's gonna look at your face. Is something droopy. Are, are you kind of slow to respond? It might have a little test that it has you take right there. The, the law is very loosey goosey on any details. There really aren't any, so it's gonna be up to the manufacturer.

[01:21:42] So they put this in the car step. Just like OnStar, step one, put it in the car and they'll tell you when to turn. Remember how cool that was the GPS with OnStar. And you'd say, yeah, I want to go to this address. And then the, uh, the assistant goes ahead and sense programming to your car. And now you can go and if you lock your keys in the car, they can unlock the car for you.

[01:22:08] All, all kinds of cool stuff. And then next up what happens. Well, but they can stop the vehicle. So there's another technology story related to OnStar. And this is from 2009 from Kelly blue book book, OnStar stolen vehicle, slow down forts its first carjacking. So again, doesn't that sound fantastic. This was a Tahoe OnStar.

[01:22:38] And, uh, the driver and his passenger forced out of the vehicle robbed by a shotgun wielding perp who then drove off in the SUV. And the OnStar dispatcher was able to locate the vehicle using GPS advised police of exact location. And as soon as the police established visual contact, the stolen vehicle slow down system is activated available on a number of GM cars and trucks.

[01:23:03] Right? So this was over a decade. That this happened, but the technology's evolved hasn. so we initially have all of these car companies trying to decide, okay. So we've got this kill switch law, which AP says is not a kill switch law. Cuz they talk to experts just like the, what was it? 52 people, uh, heads of intelligence.

[01:23:29] Committees and agencies said that this wasn't a collusion hoax, right? So they talked to experts who said, no, no, no, this isn't a kill switch, but that's today you can argue, it's not a kill switch. I would completely disagree with you. Day one. It's a kill switch cuz you can't start your car. Right. It's a kill switch.

[01:23:48] A kill switch is often something you hide somewhere on the car so you can kill the engine. So it can't be stolen. It's a kill switch. Come on. People fact checkers aside, but this could potentially allow law enforcement again, to shut down your car, remotely track the car's metrics, location, maybe the passenger load, because remember now cars are tracking all of this.

[01:24:14] There've already been. Tickets issued by police that did not see anyone speeding. The car was not caught on a traffic camera, but they hook up a device to your car's port that talks to its computer. And the computer says, yeah, he was doing 80 miles an hour or, uh, five minutes ago. And all of a sudden you got a ticket, right?

[01:24:35] Massachusetts wants to go ahead now and say, uh, yeah, yeah. Let's charge by the mile that you drive and mask. Because of course they're not getting enough revenue from gasoline because of the electric cars, right. Electric cars are not paying their fair share when it comes to road taxes. So let's do it that way.

[01:24:55] So how are they gonna collect the information? Well, They're gonna hook up to your car's computer. The next thing coming down the road, and it's already in most cars is wireless data connectivity. You might have found already. If you have a Nissan, a Honda, many other cars that. You have to get a major upgrade.

[01:25:17] It varies 600 bucks up to a few grand for an expensive car, but the two G data network, we talked about this on the show already is being completely shut down by the end of the year. So we've gotta replace it and switch you over. To the LTE data network, which of course eventually will go away as well, or at least 3g what happens once it's all hooked up?

[01:25:44] Well, the next easy step is just feed all of that information straight to the government. Craig, Peterson.com.

View Details

American Invents Act Has Destroyed Innovation -
Cops want to keep mass surveillance app secret; privacy advocates refused -
Hackers Hide Malware in Stunning Images Taken by James Webb Space Telescope -
TikShock: Don’t get caught out by these 5 TikTok scams -
Ukrainian Police Bust Crypto Fraud Call Centers

Well, the birds are coming home to roost. Well, not the chickens in this case, but this is called the death warrant for American ingenuity. We'll start by talking through this great article from this week's newsletter.

[Automated transcript follows.]

Well, I hate to say this, but in reality, we are looking at some very, very bad times for inventors, and I've had some of these problems myself before, but last September, there were scores of patent holders who demonstrated in six cities across the US.

[00:00:34] They had on these black t-shirts that said homo sapiens, inventor. Endangered species. They were protesting America's decade of stolen dreams. Great article here in the American thinker. It was in my newsletter this year, or excuse me this week, but, uh, but here here's weirdly what happened here. Back in 2011, president Obama pushed through Congress and signed into law.

[00:01:04] What they called the America invents act. Now just like the inflation reduction act is going to increase inflation, right? It's all double speak. Isn't it? The American invents act turned over the patent process basically to the biggest Democrat party donors. Big business billionaires, right? Because that's who really is funding them, the Hollywood millionaires, these massive billionaires, Zuckerbergs and, and others.

[00:01:35] And what happened here? Is they changed the whole patent law and the basis for it. They flipped the table here, basically. Here's the idea behind the patent law that we've had in place in the United States for well, over a century and patents that are guaranteed in the cons. It used to be that you, if you were first to invent something, if you could show that you were first to invent something, you could file a patent and gain that patent.

[00:02:14] Well, what happened is because of all of the donations that went into the Democrats in 2011, from these big, big companies that were lobbying. A, and this is part of the reason I have a huge problem with all this money going to Washington DC, frankly, because it just attracts rodents like these big companies that want to use the law to control you, to gain profit for them.

[00:02:39] And really in this case, squash. Potential patent holders. You see there have been piracy for years in the patent field. And this happened to me. I spent a year of my life designing some software, writing some software that emulated an older computer system and allowed you to take. Any of that software and run it on the new system.

[00:03:05] And it would run exactly the same way. And a lease on the new hardware was cheaper than just a maintenance contract on the old stuff. Plus it was faster, used less electricity, had more options, et cetera. Right. It was, it was really something, frankly, and I was invited to their headquarters to show them a little bit about.

[00:03:27] Did, and, and I was so excited because they wanted to start selling it, right. So they need to understand a little bit better. So I went to the headquarters and met with them, you know, of course paid my own way. Flew down there, stayed in the hotel, rented a car, you know, all the stuff that you have to do.

[00:03:43] And then nothing happened afterwards. Wouldn't return phone calls. It just, all of a sudden went silent. And then about a year and a half later Tata, they had an alternative product out on the. . Yeah, and they tried to emulate what I had done, but they did a very, very poor job at it. That's patent theft, that's piracy in this particular case, uh, if you are an inventor, you've probably experienced that sort of thing before, you know, you can put employees all of the non-disclosure agreements you want to have in place, but in reality, good luck enforcing those, especially against a big company.

[00:04:25] Well, piracy went on steroids because of president Obama's America and events act. They, as part of that established something, they called the patent trial and appeal board. And it's just gone downhill ever since. So a professor that has more than 40 patents, I'm gonna read a little quote of his, this includes some inventions used in the space shuttles, by the way, which by the way, my invention was used with the space shuttle.

[00:04:57] Um, so Dan brown invented something called the bionic wrench. I have one of those. I bought one of those some years back, this is a one size fits all wrench that does not strip bolt corners like it does if you're trying to use vice scripts or some pair of pliers, right. Because you're just too lazy to go and get the right socket size or box wrench or whatever it is.

[00:05:22] That's the right size. It very, very. And professor brown says that Sears stole his idea for this bionic wrench right down to the marketing pitch. And then Sears, according to him, went out and hired a Chinese company to make it. And all of a sudden now, what kind of invention does he have? How's he gonna battle somebody like that?

[00:05:49] I know a guy who is, uh, completely unethical. You know, I've done many shows from the consumer electronic show and it's really kind of cool, cuz I would get in depth with the inventors and, and explain what they were doing on the air. It was really neat all the way around. It was just a whole lot of fun.

[00:06:08] And I met a guy there who was going to the consumer electronic show to find cool new consumer electronics. He thought might be popular. And then he'd go and talk to the people who were exhibiting that wonderful new electronics and say, Hey, I'm interested in, in selling your stuff. I have, you know, retail space and, uh, you know, kiosks in the mall.

[00:06:33] What can, uh, what kind of deal can we work out here? Well, you know, first I, can I, let me get a, I, I need a copy of, uh, of your device here. I want a copy of it so I can mess with it and see, see if we really wanna follow through on. Oh, and I, I don't want to carry it around the floor of the consumer electronic show.

[00:06:51] So I need you to ship it to me. So they'd ship 'em off. They might be a little speaker. They might be a charger. They might be who knows what? And consumer electronics is pretty broad. And if he liked it, he wouldn't buy it from them. He sent them over to his contacts in China. And had them reverse engineered and make the same thing with his brand label on it.

[00:07:16] And he'd sell it in the stores. Now, when it comes to software and a lot of consumer electronics patents, aren't really a big deal because things. Changed so quickly. Right? And if you're a small guy, it's very hard to file a patent. And that's how president Obama sold this American Bens act to us. I remember this very, very clearly where he said, Hey, listen, this is gonna make the patent process way more streamlined, way easier for the small guys to be able to get patents, uh, not only applied for, but actually get them out to market.

[00:07:52] And it's just gonna be an absolutely wonderful. It, it isn't because what happens now? Is big companies are not investing in research and development. That is true across the board. Now you might say, Hey Craig, well, how about big companies? How about Tesla? That's R and D. How about SpaceX? That's R and D.

[00:08:14] Yes, but they are R and D companies. They're not big companies out there like Facebook, does Facebook try and come up with this or that new invention? Well, yeah, they kind of do from time to time, but most of the time what's been happening is corporate America looks for a winner. And then tries to buy the winner.

[00:08:35] Microsoft has been doing that forever. Microsoft in court has lost cases because of what they did to inventors. And now it's been codified in law for over 10 years. So our American ingenuity, which is what we rely on in order to grow our economy, the ingenuity, the, the brain skills, the science, the true science that we have gives us a major competitive advantage because that particular, uh, type of intellectual property has a much higher profit margin than something like manufacturing a widget.

[00:09:14] When you get right down to it, that's where the real money is. so a very interesting article and I would suggest you take a little bit of time to read it. If you've ever thought about patenting something, if you had a great idea, it used to be, you know, this is kind of the, the, uh, old wives tale. If you will, if you've got a great idea, you think you might wanna patent it, write it all out, take all of your notes, do it in a, a, a workbook that you can.

[00:09:43] Alter right. You can't tear out pages or things. Uh, mail it to yourself in a Manila envelope and make sure you put stamps on it. And then the post office is going to date, stamp it for you or send it to your attorney even better. Right. And your attorney's gonna go ahead and keep that on file. And then when it's time to file the patents, you can say, Hey, look, it here's the proof.

[00:10:06] I invented this in April of 2019. It doesn't matter because if some other company sees what you're doing or comes up with a similar or the same idea, and that company has the money to have the lawyers that know patent law inside out and backwards and can go ahead and file that patent claim. You've lost it.

[00:10:31] you know, as early as the constitutional convention of 18 or 1787, our founding fathers recognize the need to promote innovation and we have to be promoting it. We've gotta get rid of this Obama era law. Absolutely. We've gotta go from first to file, which is what it has been for a decade. The first person to file you.

[00:10:54] And move back to the way it was intended, the way it worked for well over a hundred years where it is a first to invent, it's very, very important for all of us, for economy, et cetera. The, the third law of Congress was a patent act of 1790. It it's just man, have we come a long way, stick around. We'll be right back online.

[00:11:19] Craig peterson.com.

[00:11:22] You know, we've had firewalls in our cars for a very long time for a very good reason. Right? You wanna keep the engine stuff out of the passenger compartment? The same thing is true. When we're talking about our networks, we're using firewalls to keep things out.

[00:11:39] Firewalls are there to keep things out. And we have firewalls in our homes.

[00:11:44] If you've got an internet service provider, you've probably got a firewall right there. Something that you don't even think about, right. It's just, there's gonna protect. You, it might, it's providing some services. You might be familiar with them. It's obviously doing a network address translation for you in this day and age.

[00:12:06] Pretty much everything is especially with the internet transition that's been going on for years now from, um, IP four to IP six, but, uh, the firewall. is critical for every person and every business out there. But when we get into the configurations of firewalls, frankly, they are really a touchy subject.

[00:12:29] You know, every network security professional has their own preferred hardware and software, uh, use Cisco. As a rule, Cisco has some great stuff. What I like the best about the Cisco equipment that we use in software and install at our clients is it is one pane of glass. It's a single vendor that covers everything from endpoint security.

[00:12:54] In other words, security on your desktop, through the network itself, the switches, the firewalls, the email filters Absolut. Everything is there and is taken care of by all of the Cisco gear. It it's really quite something to look. I saw, in fact, a survey just last week at businesses who are trying to consolidate, there's just too many vendors in there selling this piece of endpoint, that piece of endpoint.

[00:13:25] And, you know, that's part of the problem that I see happen pretty frequently, which is people look at Gartner report. Gartner, of course, a research company. They've got a lot of great research out there that I've used before. I've had Gartner on the radio show before, as well as some of their competitors talking about trends.

[00:13:44] Well, There is something known as the upper right quadrant in those Gartner reports where they are rating various vendors for various pieces of software. So there might be for instance, a report on firewalls and the upper right hand cor quadrant is kind of what you want, cuz it's new, it's innovative. It, it innovative.

[00:14:06] It's uh, really cool and wonderful. And it's the best. Since life spread. So they go out and they buy that cuz it's upper, right. Gartner quadrant. And then man, they find out, uh, okay, so now we need desk desktop, desktop. Okay. So they find the or buy actually the Gartner report for five to 10 grand. That's like a page long is crazy how expensive these things are.

[00:14:32] They then look at that and say, okay, so the best desktop is vendor Y so let me see, we got X for the firewall. We've got Y for the endpoint and then, oh, they need switches. So let's go to the Gartner report. Who's in the upper right quadrant here for switches. Oh, it's uh, vendor Z. Okay. So we got Z. So now all of a sudden.

[00:14:51] You end up with all of these different pieces of hardware, different pieces of software that have limited offerability at best interoperability at best. Right? So the, this day and age, when we're talking about cybersecurity, There are so many legitimate attacks every day. I mean, thousands of attacks going on even against a single business.

[00:15:18] And there are hundreds potentially of false alarms every day. So how do you deal with that? That that's a good question. So, uh, a lot of businesses turn to companies like mine now, you know, full disclosure, I've been doing internet security work for businesses since, uh, early 1990s. So whew, 30 years now.

[00:15:40] And I've been doing internet work for even longer than that, helping to develop it. So they'll go and they'll say, Hey, we need a managed security services provider. Uh, there's a big problem with that. And I, I was watching, uh, Yellowstone that TV show and I, it was a great little example of what we're seeing in the world today.

[00:16:05] And Frank, frankly, we've seen forever obviously. And that is if there's a demand for something, all of a sudden, a lot of people will be hanging up shingles. and if they know, if that vendor knows more than you do, or is able to kind of turn, twist your ear and convince you to buy from them, you'll buy from them.

[00:16:26] We saw that man around the year, 2000, all of the people who were trying to sell web services that had no idea what they're doing now, we're seeing all kinds of people trying to sell network services, security services that have little idea of what they're doing. We support. These companies that call themselves manage security services providers, where we actually go in, we design the system, we build the system and we implement the system.

[00:16:53] We run the system and the third party here builds the client. Right. Cuz it's their client. And you know, that's all fine. It's so well and good, but what should you be looking. Particularly if you are a business, if you want to have a managed firewall, which is, I think important again, it's kind of a long tail thing to have a firewall vendor and, uh, this vendor and a managed vendor, and now it can get to be a headache pretty quickly.

[00:17:23] But if you're going to focus on one thing, It's probably the firewall and your end points. Right? So maybe it's two things. So here's what a managed firewall service provider should be able to offer you. First of all, firewall system health and alerting. Software life cycle management, which means your updates, your patches, service, and incident management.

[00:17:48] Whenever there's an alarm, they should know about it and they should be handling it. Security policy implementation your reporting, your analysis, your remediation, some of that is required by these various regulations and laws that are out there. You. To do it, uh, you know, without getting in a lot of detail right now, um, network monitoring, uh, the traffic monitoring, you know, the idea here behind any kind of managed service is to bring in a true expert rather than just completely outsourcing.

[00:18:24] So you're partnering with someone. One of the things I've, I've bated my head against the wall for, for decades now, is that the it department. Thinks that they're up to snuff to be able to do something, or maybe they just want to do it because it's gonna be wonderful for them on the resume for the next job.

[00:18:45] Right. Uh, man, I've seen that a lot of times when, when you are looking at all of this stuff and you've got an it department, maybe you're better off bringing in a very narrow expert to support your it department rather than fight against your it depart. good questions here. Uh, bottom line, they should have better expertise than what you have.

[00:19:11] And you've got to read between the lines between your it staff that are currently doing it and the other vendors reducing the burden on your staff. So that maybe what they can do is. Focus more on things that are, uh, revenue generating that are more important to your business. You'll get faster incident response with any luck here.

[00:19:33] With service level agreement, proactive security from the managed security services providers, or just regular service providers. Your burden on updates is going to be lower, improved manufacturer support. Because a lot of times, like we do my company mainstream, we have direct connections to the manufacturer.

[00:19:56] Our case is usually Cisco because of the volume or services that we have and the equipment that we buy from them, uh, easier to scale there. There's a whole bunch of things, right. Uh, But be careful. One of the things you gotta watch out for too is where are their service people, their support people physically located, and are they us citizens?

[00:20:20] A lot of the regulations. In fact, pretty much everyone. I can't think of an exception require us persons to be the ones in control of your network and data. So lots to consider. But keep that all in mind. I think it's an important thing to understand. Stick around. We'll be right back. And in the meantime, visit me online.

[00:20:42] Craig peterson.com and sign up for my free newsletter.

[00:20:49] The best way to secure a system is something, you know, and something you have, well, many systems have been securing themselves with your phone, right? They send you a text message, but it turns out that that isn't working well.

[00:21:05] Having an SMS message sent to you in order to authenticate who you are, has turned out to be well, a problem we've seen over the last few years, people who have things like cryptocurrency who have a cryptocurrency wallet who are keeping their money, if you will, in this wallet and are using.

[00:21:30] SMS to verify who they are. So here's how that works. You log into a website using a username or perhaps an email address. Again, it should not be asking for an email address for a login because you probably use the same email address or maybe two or three. And. Have for what? 50, a hundred different sites, maybe a thousand, I've got 3000 records, uh, logins on my one password account.

[00:22:02] Okay. So there's a lot of them. They really should be letting you set up your own username so that it can be unique. For every single website that you go to. So, but anyway, that aside, you've got your username, which may be your email address. You've got a password and we've talked about passwords before.

[00:22:21] Hopefully you're following the current guidelines, which are, don't worry about random characters, make sure it is long. And that means. A past phrase. So you string three or four words together. You put some digits, some special characters in between the words, maybe, you know, one word is all upper case. You, you play with it a little bit, but it's easy to remember.

[00:22:48] So if someone then gets your email address and they get your password, they can potentially log into a website. Correct. And that website might be your bank account. It might be your work account. We've had a lot of problems lately. The FBI is saying that about every 12 hours, they're filing a new report of a company that got their intellectual property stolen.

[00:23:22] one of the ways the bad guys steal it is they'll log to your RDP server, your Microsoft remote desktop server, using your credentials that you used at another website. It's that easy. It really is. They might be trying to log in via a VPN again, the same thing. So how do you secure this? How do you secure this?

[00:23:47] Well, how to secure this properly? That's where the something you have comes into play. We all have a smartphone of some sort, even if it's not considered a smartphone, it can still receive text messages. So what a lot of these companies did is they asked their underpaid it people to set it up so that when you enter in your username and your password, it then sends you a text message.

[00:24:16] Usually with a six digit text message and you then have to type that into the website as well. Seems pretty good. Doesn't it? Well, and, and in 30 it is pretty good. There are however, a few problems. Those people I mentioned who have cryptocurrency accounts and have been using this SMS methodology, which is SMS, of course, text messages have found that sometimes their phones have been hijack.

[00:24:48] easy enough to do. And if they know you have a fair amount of cryptocurrency, it's probably worth their effort to spend a few hours to try and get into your account. And they have been getting into your account and people notice, Hey, wait a minute, I'm a kid. They do phone calls or text messages. What's what's with that.

[00:25:07] And you found out that they have dismissed you, they have stolen your. Your, uh, SIM card, basically, even though they don't have to physically have hold of it. And there's a number of ways that they do that there's a new scam or newer scam that's out right now that the fishers are using. And that is they're sending out these SSMS, these text messages that are trying to get people to respond.

[00:25:34] So how do they get people to respond? Well, In this case, they're primarily going after this company called Octo Octo post. And, uh, there's a number of different types of Octos out there, but anyways, they are trying to get you to. Do something you shouldn't do let me just put it that way. Right. So what they're trying to do is get you to, uh, enter in your username and your password.

[00:26:04] Okay. Well, that's been around for a long time. Craig, you're telling me we've had fake bank account, uh, bank website. So they'll send you an email and in it, they'll say, Hey, I need you to go right now. to our bank page and, uh, authorize this $2,000 transaction that wasn't you. And so now you're freaking out, you click on the link, you go to the bank, you try and log in and the login doesn't work well.

[00:26:31] That can be because what the fishers did is a made a webpage that looked like the bank's web page. And when you went there and entered in your username and password, you just gave it to the crooks. That's happened a lot. Well, there's a company called Octa O K T a. That is an authentication company. And what the bad guys have done is they have registered domains similar to a company.

[00:26:59] So for instance, they went after CloudFlare, which is a huge, um, company they're number one, I think they have like 80% of all of the protection for denial of service and caching a business on the internet. It's just amazing. Cloudflare's huge. And I've used them and continue to use them for some customer.

[00:27:19] So, what they did is they found a whole bunch of people that worked for CloudFlare sent them a message. And, and here's what it said. It said alert, your CloudFlare schedule has been updated. Please tap cloudflare-okta.com to view. The changes. So you go there, it looks like a regular Okta login page and they go ahead and ask user name and password, but CloudFlare is smart.

[00:27:47] They're using Okta. So they're sending an SMS message to the user to make sure it's really, them turns out what was really happening is yeah, it was sending that guy a text message and it was using telegram. To relay that his response back to the hackers. So now the hackers have your username, they have your password and they have your six digit login key.

[00:28:15] That's supposedly unique that supposedly went to you. And in this case, they didn't even have to bother a hijacking your SIM card. In this case, they just sent you that text message. So it's been causing some serious problems. They've been going after all kinds of different companies out there, uh, food service company, DoorDash you've heard of them.

[00:28:37] Right? August 25th, they said that there was a sophisticated fishing attack on a third party vendor that allowed a attackers to gain access to some, a door dashes internal company. Tools DoorDash said, intruders stole information on a small percentage of users that have since been notified, big deal, or what a tech crunch, by the way, reported that the incident was linked to the same fishing campaign that targeted Twilio.

[00:29:07] That also, as we just mentioned, targeted cloud. So we have to be careful with this. We cannot be using SMS text messages to authenticate ourselves. Some banks now allow you to use one time passwords from things like one password or others. However, some banks don't turn off the SMS, the text messages for authentication, which they really should be doing.

[00:29:36] And the other thing I wanna let you know is I like UBI. Y U B ico.com. Yubico check them out. I'm not making a dime off of this, but they have a physical token. That you either have to plug in or the connects via Bluetooth. That is something you have that authenticates you to all major popular websites out there, and many of the tools.

[00:30:03] So if you have any questions, just email me, me@craigpeterson.com gimme a few days, but I'll get back to you.

[00:30:12] Have you heard about fog reveal? They it's almost invisible when you search for it online, but it's something that police departments have started using. And they're trying to keep all of this secret. So we're gonna tell you what's happening there and got a few others too.

[00:30:29] Great little article that was in the newsletter this week.

[00:30:32] Hopefully you got my free newsletter, but it is about fog reveal. This is an ours Technica. Often some of these ours Technica stories are carried in multiple places online. It's kind of interesting because we know to some degree what the federal government's doing to collect information on people, they go to open source.

[00:30:57] Sources of information. In other words, things that are put out there publicly online, so they might search you your Facebook information or what you've been saying on Twitter, uh, or more, they go to data brokers that anybody can go to. And those data brokers have more information. They probably. Bought records from the states and they know from each individual state what property you own.

[00:31:25] If you have a car, if there's liens on it, any mortgages that you might have, right. Putting all of the stuff together. It's kind of an interesting problem, frankly, but that's a, again, they say it's legitimate. Now the federal government is not allowed to collect this information. So they just go to third party data aggregators.

[00:31:45] And remember again, If you have apps on your phone, if you have an Android phone, this does not apply to iPhones. Generally it does apply to iPhone apps. However, but, and this is part of the reason I say never, ever, ever use Android. Okay guys, I, I just. Blows my mind. I, I was talking to an old friend of mine.

[00:32:09] Uh, he was the, the CTO in fact for the state of New Hampshire. And he was telling me that, uh, you know, we were talking and telling me, yeah, yeah, I got an Android phone. He says, don't you just love Android? And he knows that I do cybersecurity. He knows I've been in it. He hired my company to do a bunch of different tasks for the state, right over the years, we still do business with the state and he's using Android.

[00:32:41] He's probably listening right now. BU get a little note from him, but, uh, it, it, it's a problem to use Android any. Those free apps that you're using, that Google maps app that you're using. And of course you can use that on iOS as well is tracking you. They know where you live because they know where your smartphone stays at night.

[00:33:04] They know all of this stuff. How do you think the FBI is able to seize a smartphone at a Hardee's drive through. they know where you are. Well, they have some more access to information as it turns out. Uh, one Marilyn based Sergeant, according to the article wrote in a department, email TDY, the benefit of quote, no court paperwork and quote before purchasing the software.

[00:33:37] And the Sergeant said the success lies in secre. interesting. So the electronic frontier foundation, FF, who I have supported over the years and the associated press got together. Now, the associated press won a Pulitzer center for crisis reporting, uh, award, I think. But anyways, the Pulitzer center for crisis reporting also got involved here.

[00:34:05] So she had these three different organizations trying to figure out. what could, or what would be considered local places best kept secret. So they went online. They started doing some searching, trying to figure this out. And according to ours, Technica, the reporting revealed the potentially extreme extent of data surveillance of ordinary people being tracked and made vulnerable just for moving about.

[00:34:38] Small town America. So it isn't just the big cities where you're tracked anymore. Reports showed how police nearly two dozen agencies. One record shows the total figure could possibly be up to 60. Use Google maps, like technology called frog reveal. now this is licensed by fog. I, I keep saying frog it's fog licensed by fog data science, and it gives state and local police a power to surveil.

[00:35:10] Hundreds of billions of records from 250 million mobile devices. And if that doesn't scare you, I don't know what does now FF, the electronic frontier foundation found that fog reveal gets its data from veal. That's the same data source the feds use. neither companies disclosing the nature of their business relationship.

[00:35:33] Okay. They fog, reveal. Didn't say what Tel is providing and vice versa, right? Yeah. But it really appears that fog reveal is getting data location services to local police at its steep discount. So it's making it more affordable for smaller police departments and private security companies to access major amounts of data and trace devices across months or even years.

[00:36:03] isn't that something. So typically FF found that police agencies license the software annually for costs as low as six grand to nine grand. Some agencies spend even more on this tech to track people as they are moving and exactly where they are. Again, think being in a Hardee's drive through having the FBI show up.

[00:36:27] Knowing you're there. Uh, ours reviewed one annual contract in Anaheim, California. That was for more than $40,000. So it took months for these three organizations that are used to digging into this sort of stuff, uh, to figure this out, took more than a hundred public records requests to gather thousands of pages of evidence to trying to compile a picture of how local law enforcement.

[00:36:55] Is using and mining the location data. Now, to me, this is scary because we look at abuses of power. Through the years and I it's happened again and again and again, we are smelling more and more like Venezuela than we are free us. It's frankly scary, scary to me, but I'm talking about it cuz I think it's important.

[00:37:21] That I bring this to light to everybody else out there. Okay. Now fog data science, managing partner, Matthew Brodrick told the associated press that fog reveal has been critical to police to save time and money on investigations, suggesting police who are under-resourced and investigation suffered from reliance on outdated.

[00:37:44] Outdated tech now that's true. Isn't it? But isn't it also true that, uh, that's why we have some of these policies and procedures in place. That's why the Supreme court Miranda decision has some policies and procedures. That's why a warrant, a search warrant is supposed to be specific in what they're looking for and where it is located.

[00:38:11] We don't allow these broad warrants that the king used to issue, but we are doing that nowadays. It seems against political enemies and that's where it starts really, really scaring me. It isn't that I think that the, the current administration it, or even the next administration in Washington, DC, is going to be rounding up its enemies and putting them up against a.

[00:38:38] But when would it happen? Well, it would happen if everything were in place for it to happen. What's one of the most important things for fastest regime. It's to have a citizenry where they know everything about everyone. It, it reminds me of the Soviet era. Show me the man. I'll show you the crime. There's a great book out there right now.

[00:39:04] I think it's called, um, three felonies. a day, I think is what the name of it is. But the, it points out how every last one of the people that call ourselves Americans in the United States of America, every one of us commits at least three felonies a day. Now a lot of these things are just absolutely crazy.

[00:39:26] You know, there's been a lot of jokes about, oh, did you chair the label off of that pillow? Well, you can cuz you're the consumer, right? It's. The people that are selling it that are in distribution chain that cannot tear that off by law. Okay. But in reality, there is a lot of stuff that could be used against you.

[00:39:46] So it it's like when they say, uh, you know, give me this, or why don't you answer that question? It's none of their business. You have a right to be secure in your papers right now, if they have a warrant that's specific, then you need to surrender it. But hopefully the warrant's actually issued by real court.

[00:40:08] Some of these agencies now, uh, like the IRS have their own courts that are paid for by the agency. The judges are working for the agency. So you really think they're gonna be fair. I wonder, I wonder. Okay. Couple more things. Next up these pictures taken by the James web space telescope. Have you seen these?

[00:40:35] It is amazing. I've seen them side by side with our latest or, you know, our previous high tech pictures. And we're seeing what maybe galaxies that we never could see before. It's just absolutely crazy. Well, guess what bad guys have seen them as. And they are embedding malware inside of some of these amazing images taken by the James web space telescope.

[00:41:05] If you can believe this, by the way, they're writing them in go. Uh, so the Phish and emails, they've got a Microsoft office attachment. That's the entry point for the attack chain when you open it, it retrieves and obfuscated, VBA, macro, which in. Auto executed. all of a sudden there is a macro that is de obfuscated and run on your computer.

[00:41:34] So be careful careful with that again. And good news. Microsoft is now turning off the execution of macros by default. Double check your machine, making sure that macros are blocked by default. So, yay. Okay. So they are, by the way, changing campaigns to rogue link and ISO files because of the blocked macros.

[00:41:56] But, uh, it's good that Microsoft is doing that. Thank goodness. And you Ukraine, the police busted a crypto fraud call center. In fact, more than. And they're also shattering two more Russian bot farms. So we shouldn't be getting as many of those, uh, phone messages from the, uh, the bad guys scammers as we used to get.

[00:42:20] Thank you, Ukraine. All right. Online Craig peterson.com. Get that newsletter and stay on top.

[00:42:29] Well, we got some election news here from our friends at Google and at Twitter, they are taking opposite directions about exactly how they're gonna handle news postings about the elections. This is an interesting thing.

[00:42:46] The federal election commission is the branch of the us government that monitors elections.

[00:42:53] It does things like impose fines for misuse of funds. It sets some of the standards for funds and for their use. And. and one of the things it looks at is what are called in kind contributions. This is where someone might, uh, for instance, run a whole bunch of ads on behalf of a candidate. And those ads are coordinated with the campaign and that is illegal.

[00:43:24] You're not supposed to do that. And because it's illegal, you know, they try and stop it. But most of the time they end up finding after the fact. And that's part of the reason they want campaigns to be filing their financial reports fairly frequently so they can catch it quite quickly. Well, There have been many complaints from the G O P about what has happened with some of the campaign finance stuff, where you have someone like Facebook or Twitter or Google, who seems to be meddling with the election.

[00:44:02] They are running ads for your competition. They are really screening the results from people's searches. And from that those results they're, they're benefiting. There was a study down in orange county here a few years back where they looked at. Google results that were related to the elections going on in orange county and found that the Google results were tainted in such a way that it dramatically favored the Democrats that were running in those districts in orange county, California.

[00:44:39] Pretty interesting when you get right down to it. So the GLP says, wait a minute, now that sort of thing is worth millions, tens of millions of dollars, because if they were going to run TV ads, for instance, to get as many eyeballs, to get as much attention to convince people that this is the way they should vote, that would cost them tens of millions of dollars.

[00:45:02] So how much is it worth? Where do you go to really straighten things out in order to ultimately make fairness work and well, you know, that's kind of what the federal election commission's supposed to do. Well, here's, what's happening with the next elections. The federal elections commission has decided that Google.

[00:45:28] Getting rid of their anti spam measures for. Candidates does not violate a ban on contributions on inkind contributions. So this is an interesting approach because Google's saying, Hey, listen, we want to allow pretty much any political message to come right through to Google Gmail users, inboxes, and not filter those.

[00:45:59] Which I frankly think is a smart move on their part. Now some of these campaigns get pretty crazy. They're sending money requests all of the time. It it's been crazy to watch both sides do this and both sides complain about the other side, doing it. But at least by getting rid of these spam rules for the politicians, their messages are gonna get through.

[00:46:24] I think that's ultimately a very good thing. So what kind of messages are gonna get through how and why? Well, ultimately they're saying we're gonna let all of them through. and what that means for you. If you already get some of these messages from the politicians, it means your mailbox. At least if it's a Google Gmail box, you are going to be seen even more during elections.

[00:46:51] And I think this is gonna go on for very long time. Because Google doesn't want to get caught in the middle. When we're talking about these in kind contributions. If this were to be done for the Republicans or were to be done just for the Democrat, can you imagine the noise that would be made? By both sides and in kind contributions where the Republicans tens of millions of dollars Googled get dull tied up in some of these, uh, you know, lawsuits that would really be inevitable.

[00:47:23] Bottom line. Well, Republicans have accused. Google of giving Democrats an advantage in its algorithms. And, and as I said, there have been studies on that that have proved that they have. The big question is why. And there's an article in ours, Technica talking about a meeting that happened in may 20. 22 between Senate Republicans and Google's chief legal officer.

[00:47:52] And he said that the most forceful rebuke came from Senator Marco Rubio from Florida who claimed that not a single email from one of his addresses was reaching inboxes. And the Washington post, which of course is a mouthpiece for the Democrat party reported in late July. That the reason it was getting blocked was that a vendor had not enabled an authentication tool that keeps messages from being marked to spam.

[00:48:21] Now, if that's true, The Washington post accidentally reported the truth here. And it might be true. I had a company call me up this week. They had their Google ads account banned, and they were trying to figure out the details of why and what happened. And I went in and we solved that problem, and I noticed that they had.

[00:48:44] Properly configured their email. There's there's gets technical here. I have a paper we've put together on this, a special report talking about what's called D K I M. These, uh, SPF records DMAR records and how they should all be set up and why I need to use them. So this company was doing marketing.

[00:49:04] Obviously they had a Google, Google ad account. They were sending out emails, but because they had not properly and fully configured their email. They were not getting delivered at the rate that they could get delivered. Now that's kind of a very, very big deal when you get right down to it. And the Washington post is saying, well, that's what happened to center to Rubio.

[00:49:26] Now there's other things that might happen too. There are. Keywords that are used. There's software called spam assassin. That's very, very common. I have used it since it came out decades ago. I can't even remember how long spam Assassin's been out there, but it looks for certain things in the emails. , it looks for a lot of graphical content, a lot of HTML, even a lot of links and it kind of, it gauges, you know, this is likely spam on this scale.

[00:49:56] And typically if the, the score is higher than five or eight, or in some cases, some people said as high as 15, that email is bounced. Well, one of the real big checks as to whether or not this is legitimate email is to check and see. Who is the domain? Does that domain have these special keys that tell us?

[00:50:19] Yes, indeed. This did come from us. In other words, in this case did come from Marco Rubio or in the case of my client, it came from their company.com. And is it signed encrypted so that we know that nobody's kind of playing a man in the middle thing, trying to mess things up on us. And they say, okay, well that's a really good score.

[00:50:40] So we will, we'll lower that spam score. And, and that's how that game is played. So what by Google doing what it. Talking about doing it's really gonna help out because I have of every company I've checked for email, email deliveries, we've got a, a new customer that is a startup and you know, what do they know?

[00:51:02] They they're very narrow. Right? They understand their. Basic technology and their email again, was set up kind of like apparently Senator Rubio's email was set up and, and didn't have these things. And just like this company that I helped this week, they didn't have it set up properly. And, uh, they had experts who supposed experts who had set it up, but both cases, right.

[00:51:26] It was outsourced. Yeah. You know how that goes. Now, some Gmail users submitted comments to the federal elections commission and they were criticizing Google's plan cuz they did not want to get more spam. Okay. And there were more than 2,500 comments. You can find them by the way, online, all of the stuff is a matter.

[00:51:48] Public record and they call it the docket. And so there's a page out for this particular docket and the commissions through Republicans and Democrat commissioner voted for the order appro Google's plan. I think this is a very, very good deal. And it's really kind of the opposite of what Twitter is planning on doing Twitter has.

[00:52:12] essentially announced that it's going to. In the elections. Yeah. So you got Google on the one side saying our hands are clean. We're staying away from this. We don't want anything to do with this. Thank you very much. We love you, but, uh, forget about it. We're just gonna let all the emails. Through, Twitter's saying that it's going to have its wonderful sensors who have been proven right.

[00:52:39] Every time he said with his tongue firmly planted in his cheek, and they're gonna have those wonderful sensors that, you know, they're sitting in the basement and, and eating pizza and drinking Coke or red bull. I, I still kinda understand why somebody that's 30, whatever years old needs, energy drinks, you know, come on, come on.

[00:53:00] Uh, but anyways, They're they're saying that they, Twitter is going to be the determiner as to whether or not something that is posted on Twitter is correct. Or if it should be censored or if it should be blocked entirely. And they're admitting that they're gonna shadow ban conservative content, they don't like isn't that.

[00:53:25] So. Yeah. Uh, that's from the gateway pundit good article. And you'll find it in this week's newsletter. Uh, I think it went out Monday this week and you can follow the link through to these articles on Google and Twitter and the elections or any of the others that we have out there. So stick around, we'll be right back and make sure you sign up.

[00:53:46] If you didn't already get that newsletter. Absolutely free. Craig, Peter son.com/subscribe.

[00:53:59] I'm not sure a week goes by where I don't hear from a listener saying that somehow Facebook is tracking what they're talking about because all of a sudden ad starts showing up. And they're related to things that they've been talking about.

[00:54:16] Meta is the owner of Facebook and Instagram and, and some other things like WhatsApp, which is part of the reason I don't trust WhatsApp, but we've had, I don't know how many complaints from people saying that Facebook is listening in to what they're talking.

[00:54:36] And people are kind of wondering, well, wait a minute. Is it listening in on my phone calls? Is it listening when and how? It's a very, very good question. Now Facebook says in a statement that Facebook does not use your phone's microphone to inform ads or to change what in the newsfeed. Some recent articles have suggested that we must be listening to people's conversations in order to show them.

[00:55:06] Ads. This is not true. We show ads based on people's interests and other profiled information, not what you're talking out loud about. We only access your microphone if you've given our app permission. And if you are actively using a specific feature that requires audio, this might include recording a video or using in an optional feature.

[00:55:30] We introduced two years ago to include music. Or other audio in your status updates. So there it is. There's the official word from our friends over at Facebook. But do you notice there's a little bit of an out in there, right? Facebook does not use your phone microphone to inform ads or change what you see in your news.

[00:55:55] Doesn't use your microphone. So there's a study out right now. That is from an X Google engineer. And this article is in the guardian and they are talking about what he found. So, let me explain the background on some of this technology. First, if you are an app developer, if, if you're a developer of any software of any kind you use libraries and these libraries do things like search for a specific set of characters called a string or in search.

[00:56:31] Them or move things around or open a connection to another machine. So rather than having implement the whole T C P I P stack and ethernet underneath it and, and all of the operating system work that you'd have to do with all of the interrupts and the buffer fills and reading, toggling. As switches in the hardware, doing all of that sort of stuff.

[00:56:52] You just make one library call and say, listen, and you give the port and TA anybody who tries to connect you. It just comes right through. It's all taken care of for you, right? That's what libraries are all about. And they've become much more complex, more recently libraries nowadays can do things like provide you with a full web browser.

[00:57:16] Many of the applications that we use on a daily basis, these apps in our phones, particularly, but it's also true with some of the apps on our computers are actually. Just web browsers. They're web browsers that talk to a server out on the internet and yeah, there might be wrapped in various things, but oftentimes if you're trying to pay within an app, it'll go to a third party site.

[00:57:44] And part of the beauty of that is. Becomes a, a service to them. They don't have to worry about coding it all up. Right. They don't have to worry about taking your money, keeping everything safe. Am I using really good algorithms here to encrypt it can bad guys hack in? No, no, no. There's, they're just calling this routine that spins up a little web browser.

[00:58:07] Inside the application and uses a secure connection to talk to the web server somewhere who cares? Not mine. I'm just the app developer, right? I'm letting you play your farming game or whatever it might be. That makes sense to you guys. So it makes their life much, much easier. Why bother if you've got a website that does everything, why bother coding it all up from scratch in an app?

[00:58:34] They don't people don't. Why would. Well, we've seen that again. And again, for instance, look at Microsoft's latest browser out there, edge, not the original edge, but the latest edge, you know how Microsoft is, right. They call it the same thing, even though it's entirely different. Uh, yeah. How many versions of windows where they're like 20 at one point, right?

[00:58:56] Different ones or different architectures and just crazy. But now the edge browser is. Built on chromium, which is Google Chrome, which is built on Apple's libraries to manipulate, draw things, et cetera. So you're running your edge browser on your Microsoft windows, computer. You're actually running code libraries.

[00:59:21] If you will, from Google and from apple. And that way, if you're developing a browser like edge, you don't have to worry about every little nit bitty thing. That's all taken care of by other programmers who are making a smaller piece of code. Now that's been the whole Unix philosophy forever, by the way.

[00:59:42] Instead of having these monolithic applications. That could be just full of bugs and security problems. You just have nice small, easy to maintain, easy to research applications and let other people worry about the little pieces, which is really kind of cool. It's great. Many browsers in fact are based right there on chromium and they modify it around a little bit.

[01:00:07] Microsoft added all kinds of spyware to it. Well, it turns out. According to this research from an ex Google engineer that both Facebook and Instagram apps have been taking advantage of this in-app browser technology. And what they're doing is users who click on links inside the Facebook app or inside the Instagram at gram act are actually taken to the webpages.

[01:00:39] Using an in-app browser controlled by Facebook or Instagram rather than sending you to your default browser. So if you are using iOS, your default browser might be safari, which is a rather safe. Browser and good for privacy, or you might have decided you wanna use the Chrome browser on iOS or maybe Firefox or brave, or one of dozens of different browsers that are out there.

[01:01:10] No, no, it's not gonna use those. It's not gonna use your default browser. It's going to use the in-app browser. And what it's doing with that in-app browser now is here's a quote from him. The Felix Crouse, he's a privacy researcher founded an app development tool that was acquired by Google in 2017. He says, quote, the Instagram app injects their tracking code into.

[01:01:37] Website shown, including when clicking on AB ads, enabling them to monitor all user interactions. Like every button that you press, every link you taped, every piece of text that you select or highlight any screenshot you take, any forms, you fill out any user forms, things like passwords addresses, credit card numbers.

[01:02:06] Are all seen by the Instagram app? Yes, indeed. So in the statement, of course, uh, medicated that injecting a tracking code, obeyed users preferences on whether or not they allowed apps to follow them. And there was only used to aggregate data before being applied for targeted advertis. Now, this is interesting because according to Crouse, this code injection, uh, was tracked and he was able to look at doing, doing it right for normal browsers.

[01:02:42] His test code detected no changes, but for Facebook and Instagram, it finds up to 18 lines of code added by. App into the webpage. So there you go. JavaScript injection and more from our friends at Facebook and Instagram. So they are tracking you, but apparently. They're not listening to your microphone, but they're watching you as you cruise around the web thinking you're using your browser, but no, no.

[01:03:18] You're using theirs. Hey, stick around Craig peterson.com.

[01:03:24] Cell phone security is something I've talked about for a long time. And you guys know my basics here. If you've been a listener for really any length of time, when it comes to smartphones, we're gonna get into this in more detail, particularly after this raid.

[01:03:41] Well, of course everyone's heard, I'm sure about the rate on Trump's property, Mar Lago.

[01:03:48] There was something else that happened right. About the same time. And that was representative. Perry Scott Perry was traveling with his in-laws, uh, who are described as elderly. They were on vacation. He's a Republican representative in the house of Congress from Pennsylvania. And he told the Fox news people that three FBI agents approached him, issued him a warrant and demanded he hand over his.

[01:04:24] He said they made no attempt to contact my lawyer, who would've made arrangements for them to have my phone, if that was what they wanted. He says I'm outraged. Although not surprised that the FBI. Under the direction of Merrick Garland's DOJ would seize the phone of a sitting member of Congress. My, my phone contains info about my legislative and political activities, personal private discussions with my wife, family constituents, and friends.

[01:04:53] None of this is the government's business. Now that's really an interesting point. And, and it brings up the discussion about our smart devices, you know, what should we be doing with our phones and, and what is it frankly, that our phones have in them. Now, just think about that for a minute. Scott Perry rec he, he not recommended.

[01:05:21] He mentioned that he had all kinds of records. That were in that phone. You do too. You've got your contacts. Of course. The phone contains information about who you called, where you went, cuz it's got a GPS tracker, but even if GPS is turned off, it's still tracking which cell towers you've connected to.

[01:05:43] Uh, we've got all kinds of email in our phones, which are gonna contain business documents, private documents, attorney, client, privilege documents, all kinds of stuff there. And we have the fourth amendment, which protects the right of privacy against unreasonable searches and seizures by the go. Now, in this case, obviously the government got a warrant we could argue about, you know, how legitimate is the warrant and should they have issued it, et cetera.

[01:06:16] Right. That that's not what I'm talking about. This is not a political show. In reality. What we're talking about here is the technology. The technology we're using to store this information, this personal information, what should we be using? What shouldn't we be using? How should we use it? Right. All of that sort of stuff.

[01:06:38] Well, okay, so we've established that there was not apparently a fourth amendment violation here. There, there might have been, we don't know. We may never know. It doesn't really matter, but if someone gets a hold of your smartphone or your tablet or your computer, what information does it have on there?

[01:07:01] And we also have a right under the fifth amendment. against self-incrimination. So if someone's thumbing through our phone, what are they gonna find? People plead the fifth amendment all of the time, because they don't want to get trapped in one of these traps where maybe you don't remember the date.

[01:07:24] Right. And all of a sudden you're in a perjury trap because you said something that wasn't true. Well, you know, our, our memories aren't the best, particularly when we're on vacation, we've been drinking a little bit, right. if someone finds your phone, opens it up, someone steals your phone and opens it up.

[01:07:44] Someone gets a warrant for your phone and opens it up. What's in there. Now some people have in the past said, okay, what I'll do is I'll just go ahead and I'll wipe my phone remotely and they've done it. Right? The police have had the phone in evidence and in evidence locker and somebody remotely went ahead and wiped their phone.

[01:08:04] The police are onto. And what the police have been doing more recently is they put it into a special bag that blocks any sort of signals coming in or out as well as the room. Right. It's kind of a fair date cage anyways, and that way, bad guys, good guys who, if the phones are stolen, they can't remotely wipe them, which is a good thing here, frankly.

[01:08:30] But what are we ultimately trying to protect from? That's the question, right? It it's, who's gonna have your phone and what are you trying to protect it from personally? I'm not someone who truly trusts the government. I'm a firm believer in our constitution and our bill of right. Ultimately governments become corrupt.

[01:08:52] It happens every time. And even if the whole government isn't corrupt, there's guaranteed to be people within the government, within their bureaucracy, the deep state, if you will, who are out there to get you right. makes sense to you. Makes sense to me. I don't know, but our phones, our smartphones, our computers have a lot of stuff in them.

[01:09:14] I've talked on the show before how you should not be taking them to China. If you go to China, because of the evil made. T where they are grabbing your phones. They are duplicating them. Same thing with Russian travelers. Not as much as has been happening in China, but it's happened in Russia, probably a lot now with the whole war thing.

[01:09:36] Right. But you shouldn't be taking them because they can be duplicated just like rep Scott. But Scott Perry's phone was duplicated. Now the, the FBI apparently said, well, we're not gonna look through well, why you're duplicating it then. And you know, maybe it's just to preserve evidence. I really don't know, but the bad guys can get at your phone employers if they own your phone can get at your phone and they can get a lot of data out of that.

[01:10:06] What do you do? Well, bottom line, if you are traveling internationally, you're gonna wanna make sure to wipe your phone and just bring along maybe a, a basic little flip phone. Uh, cetera. Now there is software that we use. For instance, we use one password and duo in order to keep track of all of our stuff, right.

[01:10:31] Our personal information. And. That's the two factor authentication stuff that we use, and we can tell it, Hey, we're traveling out of the country and we will only need these passwords. And it goes ahead and wipes out the password database so that we're not carrying a whole bunch of stuff with us that might be compromised by, uh, a government agency right within what is it?

[01:10:54] The USS 50 miles of the border. They can confiscate and examine anything that you have, even if you're not trying to cross the border. and they'll do that at airports. They'll do that at a whole bunch of places. And then you've got the employer side and then you've got the bad guy side. Look at what happened to Khai with the Saudis right here.

[01:11:16] He was, uh, you know, a journalist. We could argue that I suppose, but he's a journalist. He is abducted and he is murdered by the Saudis. They get their hands on the phone and they decrypt the. this has happened and it'll happen again. So Apple's done something here that I think is a good step in the right direction.

[01:11:40] Apple, of course I've recommended for a long time. Never, ever, ever, ever, ever use Android. Okay. Don't. Use it, Google's using it to track you. You're losing your privacy and the security. Isn't very good. Particularly if your phone's more than three years old, apple has come up with this new lockdown mode on their phones and the lockdown mode is meant for.

[01:12:09] People who are really under thumb, you know, people living in Russia or Ukraine, or you name it, Iran, all of these countries that are really out to get their citizens and it it's coming out in iOS. You'll see it there. You probably don't want to use it as a regular person, cuz it does block some of the things you can do, but it also locks it down against these Israeli based companies that have been selling software and hardware to break into cell phones.

[01:12:44] So consider iPhones. And if you are one of these people, who's at a high risk consider lockdown mode.

[01:12:51] I warned last week about using the ring camera as well as Google's camera. We've got some more news about that today. I was right. A major breakthrough in nuclear fusion and a new toolkit released. Talk about it all now.

[01:13:08] Well, quite, quite a time, you know, I, I remember when I first started doing the radio show, uh, 22 years ago, now it started right there year 2000 Y two K and I, I was, uh, wondering, you know, am I gonna have enough stuff to talk about?

[01:13:27] and my wife, who was just the most amazing person had been helping me and we subscribed to a bunch of newspapers. Yeah. There used to be newspapers back then. And she went through and was clipping articles that we thought might be good, that people might want to, uh, to hear about. And so she had all. Files.

[01:13:49] And we, we subscribe to like four or five different newspapers, including the trashy ones like USA today, just so we knew what was going on out there. We had the financial times and the London times and New York times, and we got just files and files worth of stuff. And didn't take us long to realize, Hey, wait a minute.

[01:14:14] There is so much tech news out there and stuff to talk about, uh, that weren't, we don't have to worry about that. So we canceled our subscriptions to all of these different things. I, I have actually a subscription to the New York times still, cuz they gave me a buck a week, which is not a bad deal for the online version because the old gray lady still does have some good text stories.

[01:14:39] Some of the other stuff obviously is a problem, but, uh, yeah, tech stories anyways. Now we do a lot of this stuff online, the research, and I put it together and send it out in my newsletter every week. And man, did we have a lot of you guys reading it on Monday was the most, most, uh, red newsletter of mine.

[01:15:01] The insider show notes newsletter. Of any of them ever. It was really great. It was like I had a, almost a 50% open rate there within the first day. So that's cool. Thank you guys. And obviously you really value it or you would not have opened that newsletter and click through you. See what I do? Is, uh, you probably know, I appear on radio stations all over the place and I I'm also of course have my own radio show here and elsewhere, and my podcasts, which are on every major podcast platform out there.

[01:15:40] And I've been doing this for so long this week. What am I at here? Show? Number, I think it's like 1700. I'm trying to remember weeks. Okay. That's weeks of shows and, uh, we, we have never hit the same stuff twice, which is really rather cool. One of the things I brought up and this was in, uh, a recent show is about.

[01:16:09] These ring cameras. And I warned everyone not to use ring and went through the whys. So if you have my newsletter from. A few weeks back, you can just probably search your email box for ring camera and you'll find links to a couple articles on that. And there's an article that just came out in the record here talking about ring, which was purchased by Amazon about four years ago.

[01:16:39] And ring was looked at by this cybersecurity firm called check marks. And they found that the ring camera was leaking data like a SIV, the, some of the, uh, web interface stuff. The videos were, were reachable online. And, uh, it was a real problem. So ring is running the Android operating system, which isn't a bad operating system.

[01:17:09] It's just, you know, tends to not get updates. Something like a ring camera. It, the advantage to it is it probably will get updates. And in fact, the Amazon is pushing updates out to it because they were exposing data and camera recording. So this one, this particular article is not in your newsletter, so you can, um, You don't look for this one there, but look for some of the other ones.

[01:17:38] And by the way, if you don't have my newsletter, if you don't get it, this is a free newsletter. I have my insider show notes that come out weekly, and then I also have some little trainings. I do. I try and do it every week or two, uh, just short ones. It takes you just a few minutes to read, to try and bring you up to date.

[01:17:57] But overall, yeah, sometimes you can sometimes, uh, I, I just. Can't get them out, but you do get my is NS because I send those also to the hosts of the radio stations, where I appear as well as the TV stations to let them know what, uh, what topics are kind of hot this week, because it's, you know, I, I follow the tech quite closely for the show and the podcast and the appearances, but they don't follow technology that costly.

[01:18:28] So. Yet another reason to not use ring and a reason to use ring. Uh, I don't use them. I use at, at my house, at my office, we use some really good Cisco security systems that, uh, that I really like, and that do get updates. The things you want to avoid are these Chinese. Firms that have, uh, you know, the security cameras, one in particular that has about 90% of the market, which it's kind of scary things we've seen there.

[01:18:58] All right. Really, really, really good news. I have for a long time been talking about nuclear power and one of my sons is so totally into it. He was actually thinking about trying to get involved with the nuclear Navy program, which is a hard program to get into and ultimately decided. To, but the nuclear power is back on the board.

[01:19:22] The European union has come out and said, yeah, nuclear power is indeed clean. and they green, in fact, they were saying, and they are turning back on some of these nuclear reactors and it, they are green, but I wanna talk about the new nuclear. We've got some amazing new nuclear technology today. That is intrinsically safe, that uses basic physics to make sure that we're not gonna get meltdowns, that we don't have all kinds of nuclear waste.

[01:19:59] It's just amazing what they've been able to do. And that if you look at the failures of the various types of plants in the past, the failures have been related typically to human error, but sometimes you get a stuck valve or a crack pipe, et cetera. And in those cases, The, the humans might again, react inappropriately and cause more problems.

[01:20:24] As in what happened there in Northern Ukraine that we've all heard about many, many times. So what should we do? Well, The power everyone wants is either what's called cold fusion, which is making some progress or the nuclear fusion as opposed to nuclear fission. Fission's what we've been using now for.

[01:20:52] What going on 80 years and it's what goes into nuclear bombs, but it's also, what's used at pretty much every nuclear plant out there. And there's a new company that just got approval. When I say new, I mean, relatively, it took them six years to get the approval from the nuclear regulatory regulatory commission to put this new nuclear power plant into production.

[01:21:18] And it is. I I innovative. So they're using the same basic FIS vision technology that we've you've used for a long time, but a couple of big differences. One it's considered to be safe. And two, these nuclear plants are small. They are made in a factory where everything can be monitored closely and they can easily put together UR.

[01:21:47] You know, Hey, you need to do this. Upgrade that upgrade. And the nuclear plant is shipped out to location. Now consider how we have been doing it in the past where we build a building, we put all the stuff in, everything is made from scratch. We have to get the guys and gals doing the welds and moving this stuff around and.

[01:22:10] every plant is different substantially different in some way, in some regards. So with this new approved nuclear company, everything's exactly the same they're made in a factory. So that's a huge, huge win to get that approved. But here's the really good news, the power of the. In the sun and other stars, you've got heavy hydrogen atoms that are colliding with so much force that they actually fuse together to make a helium at 'em and just like FIS vision.

[01:22:47] Releases a lot of energy by splitting the atom that joining, creating this new atom also releases large amounts of electricity or energy I should say is a byproduct. And that's what's happening in the stars out there, including our sun. Well, we had a major breakthrough in nuclear. It was about a year ago and it was at Lawrence Livermore, national laboratory out in California.

[01:23:17] And this is their national ignition facility. And they have been trying all kinds of ways to make this work. And we've been making, we've had fusion for quite a while, but the problem is it takes more energy for these fusion reactors to get online and stay online than they produce. One year later. Now we're looking at three peer reviewed papers that say yes, indeed.

[01:23:48] They were able to ignite the hydrogen plasma for the first time we have a fusion reaction that is self sustaining. The fusions themself are producing enough power to maintain the temperature, the control systems, et cetera, without any external heating. So this is really, really good news. Of course, it's gonna have to be scaled.

[01:24:18] and it, there are a bunch of things are gonna have to happen, but if they can do this, if they can do the fusion reactor, or even some of these others that are just been improved here, which is more of a standard type of reactor, uh, You can hook these up to your coal power plants that already have all the electrical infrastructure there.

[01:24:40] They already have all the power lines coming in. The transformers that are needed, the steam plants that can take the heat and convert that heat into electricity. All of that stuff is already there. Just replace the cold burning with either, hopefully this fusion. Hopefully they can scale this, but this is really good news or one of these small nuclear power plants that is made in a factory and shipped out.

[01:25:09] Wow, what good news. Hey, visit me online. Make sure you get my newsletters. Craig peterson.com/subscribe. Go there now.

View Details

American Invents Act Has Destroyed Innovation -
Cops want to keep mass surveillance app secret; privacy advocates refused -
Hackers Hide Malware in Stunning Images Taken by James Webb Space Telescope -
TikShock: Don’t get caught out by these 5 TikTok scams -
Ukrainian Police Bust Crypto Fraud Call Centers

Well, the birds are coming home to roost. Well, not the chickens in this case, but this is called the death warrant for American ingenuity. We'll start by talking through this great article from this week's newsletter.

[Automated transcript follows.]

Well, I hate to say this, but in reality, we are looking at some very, very bad times for inventors, and I've had some of these problems myself before, but last September, there were scores of patent holders who demonstrated in six cities across the US.

[00:00:34] They had on these black t-shirts that said homo sapiens, inventor. Endangered species. They were protesting America's decade of stolen dreams. Great article here in the American thinker. It was in my newsletter this year, or excuse me this week, but, uh, but here here's weirdly what happened here. Back in 2011, president Obama pushed through Congress and signed into law.

[00:01:04] What they called the America invents act. Now just like the inflation reduction act is going to increase inflation, right? It's all double speak. Isn't it? The American invents act turned over the patent process basically to the biggest Democrat party donors. Big business billionaires, right? Because that's who really is funding them, the Hollywood millionaires, these massive billionaires, Zuckerbergs and, and others.

[00:01:35] And what happened here? Is they changed the whole patent law and the basis for it. They flipped the table here, basically. Here's the idea behind the patent law that we've had in place in the United States for well, over a century and patents that are guaranteed in the cons. It used to be that you, if you were first to invent something, if you could show that you were first to invent something, you could file a patent and gain that patent.

[00:02:14] Well, what happened is because of all of the donations that went into the Democrats in 2011, from these big, big companies that were lobbying. A, and this is part of the reason I have a huge problem with all this money going to Washington DC, frankly, because it just attracts rodents like these big companies that want to use the law to control you, to gain profit for them.

[00:02:39] And really in this case, squash. Potential patent holders. You see there have been piracy for years in the patent field. And this happened to me. I spent a year of my life designing some software, writing some software that emulated an older computer system and allowed you to take. Any of that software and run it on the new system.

[00:03:05] And it would run exactly the same way. And a lease on the new hardware was cheaper than just a maintenance contract on the old stuff. Plus it was faster, used less electricity, had more options, et cetera. Right. It was, it was really something, frankly, and I was invited to their headquarters to show them a little bit about.

[00:03:27] Did, and, and I was so excited because they wanted to start selling it, right. So they need to understand a little bit better. So I went to the headquarters and met with them, you know, of course paid my own way. Flew down there, stayed in the hotel, rented a car, you know, all the stuff that you have to do.

[00:03:43] And then nothing happened afterwards. Wouldn't return phone calls. It just, all of a sudden went silent. And then about a year and a half later Tata, they had an alternative product out on the. . Yeah, and they tried to emulate what I had done, but they did a very, very poor job at it. That's patent theft, that's piracy in this particular case, uh, if you are an inventor, you've probably experienced that sort of thing before, you know, you can put employees all of the non-disclosure agreements you want to have in place, but in reality, good luck enforcing those, especially against a big company.

[00:04:25] Well, piracy went on steroids because of president Obama's America and events act. They, as part of that established something, they called the patent trial and appeal board. And it's just gone downhill ever since. So a professor that has more than 40 patents, I'm gonna read a little quote of his, this includes some inventions used in the space shuttles, by the way, which by the way, my invention was used with the space shuttle.

[00:04:57] Um, so Dan brown invented something called the bionic wrench. I have one of those. I bought one of those some years back, this is a one size fits all wrench that does not strip bolt corners like it does if you're trying to use vice scripts or some pair of pliers, right. Because you're just too lazy to go and get the right socket size or box wrench or whatever it is.

[00:05:22] That's the right size. It very, very. And professor brown says that Sears stole his idea for this bionic wrench right down to the marketing pitch. And then Sears, according to him, went out and hired a Chinese company to make it. And all of a sudden now, what kind of invention does he have? How's he gonna battle somebody like that?

[00:05:49] I know a guy who is, uh, completely unethical. You know, I've done many shows from the consumer electronic show and it's really kind of cool, cuz I would get in depth with the inventors and, and explain what they were doing on the air. It was really neat all the way around. It was just a whole lot of fun.

[00:06:08] And I met a guy there who was going to the consumer electronic show to find cool new consumer electronics. He thought might be popular. And then he'd go and talk to the people who were exhibiting that wonderful new electronics and say, Hey, I'm interested in, in selling your stuff. I have, you know, retail space and, uh, you know, kiosks in the mall.

[00:06:33] What can, uh, what kind of deal can we work out here? Well, you know, first I, can I, let me get a, I, I need a copy of, uh, of your device here. I want a copy of it so I can mess with it and see, see if we really wanna follow through on. Oh, and I, I don't want to carry it around the floor of the consumer electronic show.

[00:06:51] So I need you to ship it to me. So they'd ship 'em off. They might be a little speaker. They might be a charger. They might be who knows what? And consumer electronics is pretty broad. And if he liked it, he wouldn't buy it from them. He sent them over to his contacts in China. And had them reverse engineered and make the same thing with his brand label on it.

[00:07:16] And he'd sell it in the stores. Now, when it comes to software and a lot of consumer electronics patents, aren't really a big deal because things. Changed so quickly. Right? And if you're a small guy, it's very hard to file a patent. And that's how president Obama sold this American Bens act to us. I remember this very, very clearly where he said, Hey, listen, this is gonna make the patent process way more streamlined, way easier for the small guys to be able to get patents, uh, not only applied for, but actually get them out to market.

[00:07:52] And it's just gonna be an absolutely wonderful. It, it isn't because what happens now? Is big companies are not investing in research and development. That is true across the board. Now you might say, Hey Craig, well, how about big companies? How about Tesla? That's R and D. How about SpaceX? That's R and D.

[00:08:14] Yes, but they are R and D companies. They're not big companies out there like Facebook, does Facebook try and come up with this or that new invention? Well, yeah, they kind of do from time to time, but most of the time what's been happening is corporate America looks for a winner. And then tries to buy the winner.

[00:08:35] Microsoft has been doing that forever. Microsoft in court has lost cases because of what they did to inventors. And now it's been codified in law for over 10 years. So our American ingenuity, which is what we rely on in order to grow our economy, the ingenuity, the, the brain skills, the science, the true science that we have gives us a major competitive advantage because that particular, uh, type of intellectual property has a much higher profit margin than something like manufacturing a widget.

[00:09:14] When you get right down to it, that's where the real money is. so a very interesting article and I would suggest you take a little bit of time to read it. If you've ever thought about patenting something, if you had a great idea, it used to be, you know, this is kind of the, the, uh, old wives tale. If you will, if you've got a great idea, you think you might wanna patent it, write it all out, take all of your notes, do it in a, a, a workbook that you can.

[00:09:43] Alter right. You can't tear out pages or things. Uh, mail it to yourself in a Manila envelope and make sure you put stamps on it. And then the post office is going to date, stamp it for you or send it to your attorney even better. Right. And your attorney's gonna go ahead and keep that on file. And then when it's time to file the patents, you can say, Hey, look, it here's the proof.

[00:10:06] I invented this in April of 2019. It doesn't matter because if some other company sees what you're doing or comes up with a similar or the same idea, and that company has the money to have the lawyers that know patent law inside out and backwards and can go ahead and file that patent claim. You've lost it.

[00:10:31] you know, as early as the constitutional convention of 18 or 1787, our founding fathers recognize the need to promote innovation and we have to be promoting it. We've gotta get rid of this Obama era law. Absolutely. We've gotta go from first to file, which is what it has been for a decade. The first person to file you.

[00:10:54] And move back to the way it was intended, the way it worked for well over a hundred years where it is a first to invent, it's very, very important for all of us, for economy, et cetera. The, the third law of Congress was a patent act of 1790. It it's just man, have we come a long way, stick around. We'll be right back online.

[00:11:19] Craig peterson.com.

[00:11:22] You know, we've had firewalls in our cars for a very long time for a very good reason. Right? You wanna keep the engine stuff out of the passenger compartment? The same thing is true. When we're talking about our networks, we're using firewalls to keep things out.

[00:11:39] Firewalls are there to keep things out. And we have firewalls in our homes.

[00:11:44] If you've got an internet service provider, you've probably got a firewall right there. Something that you don't even think about, right. It's just, there's gonna protect. You, it might, it's providing some services. You might be familiar with them. It's obviously doing a network address translation for you in this day and age.

[00:12:06] Pretty much everything is especially with the internet transition that's been going on for years now from, um, IP four to IP six, but, uh, the firewall. is critical for every person and every business out there. But when we get into the configurations of firewalls, frankly, they are really a touchy subject.

[00:12:29] You know, every network security professional has their own preferred hardware and software, uh, use Cisco. As a rule, Cisco has some great stuff. What I like the best about the Cisco equipment that we use in software and install at our clients is it is one pane of glass. It's a single vendor that covers everything from endpoint security.

[00:12:54] In other words, security on your desktop, through the network itself, the switches, the firewalls, the email filters Absolut. Everything is there and is taken care of by all of the Cisco gear. It it's really quite something to look. I saw, in fact, a survey just last week at businesses who are trying to consolidate, there's just too many vendors in there selling this piece of endpoint, that piece of endpoint.

[00:13:25] And, you know, that's part of the problem that I see happen pretty frequently, which is people look at Gartner report. Gartner, of course, a research company. They've got a lot of great research out there that I've used before. I've had Gartner on the radio show before, as well as some of their competitors talking about trends.

[00:13:44] Well, There is something known as the upper right quadrant in those Gartner reports where they are rating various vendors for various pieces of software. So there might be for instance, a report on firewalls and the upper right hand cor quadrant is kind of what you want, cuz it's new, it's innovative. It, it innovative.

[00:14:06] It's uh, really cool and wonderful. And it's the best. Since life spread. So they go out and they buy that cuz it's upper, right. Gartner quadrant. And then man, they find out, uh, okay, so now we need desk desktop, desktop. Okay. So they find the or buy actually the Gartner report for five to 10 grand. That's like a page long is crazy how expensive these things are.

[00:14:32] They then look at that and say, okay, so the best desktop is vendor Y so let me see, we got X for the firewall. We've got Y for the endpoint and then, oh, they need switches. So let's go to the Gartner report. Who's in the upper right quadrant here for switches. Oh, it's uh, vendor Z. Okay. So we got Z. So now all of a sudden.

[00:14:51] You end up with all of these different pieces of hardware, different pieces of software that have limited offerability at best interoperability at best. Right? So the, this day and age, when we're talking about cybersecurity, There are so many legitimate attacks every day. I mean, thousands of attacks going on even against a single business.

[00:15:18] And there are hundreds potentially of false alarms every day. So how do you deal with that? That that's a good question. So, uh, a lot of businesses turn to companies like mine now, you know, full disclosure, I've been doing internet security work for businesses since, uh, early 1990s. So whew, 30 years now.

[00:15:40] And I've been doing internet work for even longer than that, helping to develop it. So they'll go and they'll say, Hey, we need a managed security services provider. Uh, there's a big problem with that. And I, I was watching, uh, Yellowstone that TV show and I, it was a great little example of what we're seeing in the world today.

[00:16:05] And Frank, frankly, we've seen forever obviously. And that is if there's a demand for something, all of a sudden, a lot of people will be hanging up shingles. and if they know, if that vendor knows more than you do, or is able to kind of turn, twist your ear and convince you to buy from them, you'll buy from them.

[00:16:26] We saw that man around the year, 2000, all of the people who were trying to sell web services that had no idea what they're doing now, we're seeing all kinds of people trying to sell network services, security services that have little idea of what they're doing. We support. These companies that call themselves manage security services providers, where we actually go in, we design the system, we build the system and we implement the system.

[00:16:53] We run the system and the third party here builds the client. Right. Cuz it's their client. And you know, that's all fine. It's so well and good, but what should you be looking. Particularly if you are a business, if you want to have a managed firewall, which is, I think important again, it's kind of a long tail thing to have a firewall vendor and, uh, this vendor and a managed vendor, and now it can get to be a headache pretty quickly.

[00:17:23] But if you're going to focus on one thing, It's probably the firewall and your end points. Right? So maybe it's two things. So here's what a managed firewall service provider should be able to offer you. First of all, firewall system health and alerting. Software life cycle management, which means your updates, your patches, service, and incident management.

[00:17:48] Whenever there's an alarm, they should know about it and they should be handling it. Security policy implementation your reporting, your analysis, your remediation, some of that is required by these various regulations and laws that are out there. You. To do it, uh, you know, without getting in a lot of detail right now, um, network monitoring, uh, the traffic monitoring, you know, the idea here behind any kind of managed service is to bring in a true expert rather than just completely outsourcing.

[00:18:24] So you're partnering with someone. One of the things I've, I've bated my head against the wall for, for decades now, is that the it department. Thinks that they're up to snuff to be able to do something, or maybe they just want to do it because it's gonna be wonderful for them on the resume for the next job.

[00:18:45] Right. Uh, man, I've seen that a lot of times when, when you are looking at all of this stuff and you've got an it department, maybe you're better off bringing in a very narrow expert to support your it department rather than fight against your it depart. good questions here. Uh, bottom line, they should have better expertise than what you have.

[00:19:11] And you've got to read between the lines between your it staff that are currently doing it and the other vendors reducing the burden on your staff. So that maybe what they can do is. Focus more on things that are, uh, revenue generating that are more important to your business. You'll get faster incident response with any luck here.

[00:19:33] With service level agreement, proactive security from the managed security services providers, or just regular service providers. Your burden on updates is going to be lower, improved manufacturer support. Because a lot of times, like we do my company mainstream, we have direct connections to the manufacturer.

[00:19:56] Our case is usually Cisco because of the volume or services that we have and the equipment that we buy from them, uh, easier to scale there. There's a whole bunch of things, right. Uh, But be careful. One of the things you gotta watch out for too is where are their service people, their support people physically located, and are they us citizens?

[00:20:20] A lot of the regulations. In fact, pretty much everyone. I can't think of an exception require us persons to be the ones in control of your network and data. So lots to consider. But keep that all in mind. I think it's an important thing to understand. Stick around. We'll be right back. And in the meantime, visit me online.

[00:20:42] Craig peterson.com and sign up for my free newsletter.

[00:20:49] The best way to secure a system is something, you know, and something you have, well, many systems have been securing themselves with your phone, right? They send you a text message, but it turns out that that isn't working well.

[00:21:05] Having an SMS message sent to you in order to authenticate who you are, has turned out to be well, a problem we've seen over the last few years, people who have things like cryptocurrency who have a cryptocurrency wallet who are keeping their money, if you will, in this wallet and are using.

[00:21:30] SMS to verify who they are. So here's how that works. You log into a website using a username or perhaps an email address. Again, it should not be asking for an email address for a login because you probably use the same email address or maybe two or three. And. Have for what? 50, a hundred different sites, maybe a thousand, I've got 3000 records, uh, logins on my one password account.

[00:22:02] Okay. So there's a lot of them. They really should be letting you set up your own username so that it can be unique. For every single website that you go to. So, but anyway, that aside, you've got your username, which may be your email address. You've got a password and we've talked about passwords before.

[00:22:21] Hopefully you're following the current guidelines, which are, don't worry about random characters, make sure it is long. And that means. A past phrase. So you string three or four words together. You put some digits, some special characters in between the words, maybe, you know, one word is all upper case. You, you play with it a little bit, but it's easy to remember.

[00:22:48] So if someone then gets your email address and they get your password, they can potentially log into a website. Correct. And that website might be your bank account. It might be your work account. We've had a lot of problems lately. The FBI is saying that about every 12 hours, they're filing a new report of a company that got their intellectual property stolen.

[00:23:22] one of the ways the bad guys steal it is they'll log to your RDP server, your Microsoft remote desktop server, using your credentials that you used at another website. It's that easy. It really is. They might be trying to log in via a VPN again, the same thing. So how do you secure this? How do you secure this?

[00:23:47] Well, how to secure this properly? That's where the something you have comes into play. We all have a smartphone of some sort, even if it's not considered a smartphone, it can still receive text messages. So what a lot of these companies did is they asked their underpaid it people to set it up so that when you enter in your username and your password, it then sends you a text message.

[00:24:16] Usually with a six digit text message and you then have to type that into the website as well. Seems pretty good. Doesn't it? Well, and, and in 30 it is pretty good. There are however, a few problems. Those people I mentioned who have cryptocurrency accounts and have been using this SMS methodology, which is SMS, of course, text messages have found that sometimes their phones have been hijack.

[00:24:48] easy enough to do. And if they know you have a fair amount of cryptocurrency, it's probably worth their effort to spend a few hours to try and get into your account. And they have been getting into your account and people notice, Hey, wait a minute, I'm a kid. They do phone calls or text messages. What's what's with that.

[00:25:07] And you found out that they have dismissed you, they have stolen your. Your, uh, SIM card, basically, even though they don't have to physically have hold of it. And there's a number of ways that they do that there's a new scam or newer scam that's out right now that the fishers are using. And that is they're sending out these SSMS, these text messages that are trying to get people to respond.

[00:25:34] So how do they get people to respond? Well, In this case, they're primarily going after this company called Octo Octo post. And, uh, there's a number of different types of Octos out there, but anyways, they are trying to get you to. Do something you shouldn't do let me just put it that way. Right. So what they're trying to do is get you to, uh, enter in your username and your password.

[00:26:04] Okay. Well, that's been around for a long time. Craig, you're telling me we've had fake bank account, uh, bank website. So they'll send you an email and in it, they'll say, Hey, I need you to go right now. to our bank page and, uh, authorize this $2,000 transaction that wasn't you. And so now you're freaking out, you click on the link, you go to the bank, you try and log in and the login doesn't work well.

[00:26:31] That can be because what the fishers did is a made a webpage that looked like the bank's web page. And when you went there and entered in your username and password, you just gave it to the crooks. That's happened a lot. Well, there's a company called Octa O K T a. That is an authentication company. And what the bad guys have done is they have registered domains similar to a company.

[00:26:59] So for instance, they went after CloudFlare, which is a huge, um, company they're number one, I think they have like 80% of all of the protection for denial of service and caching a business on the internet. It's just amazing. Cloudflare's huge. And I've used them and continue to use them for some customer.

[00:27:19] So, what they did is they found a whole bunch of people that worked for CloudFlare sent them a message. And, and here's what it said. It said alert, your CloudFlare schedule has been updated. Please tap cloudflare-okta.com to view. The changes. So you go there, it looks like a regular Okta login page and they go ahead and ask user name and password, but CloudFlare is smart.

[00:27:47] They're using Okta. So they're sending an SMS message to the user to make sure it's really, them turns out what was really happening is yeah, it was sending that guy a text message and it was using telegram. To relay that his response back to the hackers. So now the hackers have your username, they have your password and they have your six digit login key.

[00:28:15] That's supposedly unique that supposedly went to you. And in this case, they didn't even have to bother a hijacking your SIM card. In this case, they just sent you that text message. So it's been causing some serious problems. They've been going after all kinds of different companies out there, uh, food service company, DoorDash you've heard of them.

[00:28:37] Right? August 25th, they said that there was a sophisticated fishing attack on a third party vendor that allowed a attackers to gain access to some, a door dashes internal company. Tools DoorDash said, intruders stole information on a small percentage of users that have since been notified, big deal, or what a tech crunch, by the way, reported that the incident was linked to the same fishing campaign that targeted Twilio.

[00:29:07] That also, as we just mentioned, targeted cloud. So we have to be careful with this. We cannot be using SMS text messages to authenticate ourselves. Some banks now allow you to use one time passwords from things like one password or others. However, some banks don't turn off the SMS, the text messages for authentication, which they really should be doing.

[00:29:36] And the other thing I wanna let you know is I like UBI. Y U B ico.com. Yubico check them out. I'm not making a dime off of this, but they have a physical token. That you either have to plug in or the connects via Bluetooth. That is something you have that authenticates you to all major popular websites out there, and many of the tools.

[00:30:03] So if you have any questions, just email me, me@craigpeterson.com gimme a few days, but I'll get back to you.

[00:30:12] Have you heard about fog reveal? They it's almost invisible when you search for it online, but it's something that police departments have started using. And they're trying to keep all of this secret. So we're gonna tell you what's happening there and got a few others too.

[00:30:29] Great little article that was in the newsletter this week.

[00:30:32] Hopefully you got my free newsletter, but it is about fog reveal. This is an ours Technica. Often some of these ours Technica stories are carried in multiple places online. It's kind of interesting because we know to some degree what the federal government's doing to collect information on people, they go to open source.

[00:30:57] Sources of information. In other words, things that are put out there publicly online, so they might search you your Facebook information or what you've been saying on Twitter, uh, or more, they go to data brokers that anybody can go to. And those data brokers have more information. They probably. Bought records from the states and they know from each individual state what property you own.

[00:31:25] If you have a car, if there's liens on it, any mortgages that you might have, right. Putting all of the stuff together. It's kind of an interesting problem, frankly, but that's a, again, they say it's legitimate. Now the federal government is not allowed to collect this information. So they just go to third party data aggregators.

[00:31:45] And remember again, If you have apps on your phone, if you have an Android phone, this does not apply to iPhones. Generally it does apply to iPhone apps. However, but, and this is part of the reason I say never, ever, ever use Android. Okay guys, I, I just. Blows my mind. I, I was talking to an old friend of mine.

[00:32:09] Uh, he was the, the CTO in fact for the state of New Hampshire. And he was telling me that, uh, you know, we were talking and telling me, yeah, yeah, I got an Android phone. He says, don't you just love Android? And he knows that I do cybersecurity. He knows I've been in it. He hired my company to do a bunch of different tasks for the state, right over the years, we still do business with the state and he's using Android.

[00:32:41] He's probably listening right now. BU get a little note from him, but, uh, it, it, it's a problem to use Android any. Those free apps that you're using, that Google maps app that you're using. And of course you can use that on iOS as well is tracking you. They know where you live because they know where your smartphone stays at night.

[00:33:04] They know all of this stuff. How do you think the FBI is able to seize a smartphone at a Hardee's drive through. they know where you are. Well, they have some more access to information as it turns out. Uh, one Marilyn based Sergeant, according to the article wrote in a department, email TDY, the benefit of quote, no court paperwork and quote before purchasing the software.

[00:33:37] And the Sergeant said the success lies in secre. interesting. So the electronic frontier foundation, FF, who I have supported over the years and the associated press got together. Now, the associated press won a Pulitzer center for crisis reporting, uh, award, I think. But anyways, the Pulitzer center for crisis reporting also got involved here.

[00:34:05] So she had these three different organizations trying to figure out. what could, or what would be considered local places best kept secret. So they went online. They started doing some searching, trying to figure this out. And according to ours, Technica, the reporting revealed the potentially extreme extent of data surveillance of ordinary people being tracked and made vulnerable just for moving about.

[00:34:38] Small town America. So it isn't just the big cities where you're tracked anymore. Reports showed how police nearly two dozen agencies. One record shows the total figure could possibly be up to 60. Use Google maps, like technology called frog reveal. now this is licensed by fog. I, I keep saying frog it's fog licensed by fog data science, and it gives state and local police a power to surveil.

[00:35:10] Hundreds of billions of records from 250 million mobile devices. And if that doesn't scare you, I don't know what does now FF, the electronic frontier foundation found that fog reveal gets its data from veal. That's the same data source the feds use. neither companies disclosing the nature of their business relationship.

[00:35:33] Okay. They fog, reveal. Didn't say what Tel is providing and vice versa, right? Yeah. But it really appears that fog reveal is getting data location services to local police at its steep discount. So it's making it more affordable for smaller police departments and private security companies to access major amounts of data and trace devices across months or even years.

[00:36:03] isn't that something. So typically FF found that police agencies license the software annually for costs as low as six grand to nine grand. Some agencies spend even more on this tech to track people as they are moving and exactly where they are. Again, think being in a Hardee's drive through having the FBI show up.

[00:36:27] Knowing you're there. Uh, ours reviewed one annual contract in Anaheim, California. That was for more than $40,000. So it took months for these three organizations that are used to digging into this sort of stuff, uh, to figure this out, took more than a hundred public records requests to gather thousands of pages of evidence to trying to compile a picture of how local law enforcement.

[00:36:55] Is using and mining the location data. Now, to me, this is scary because we look at abuses of power. Through the years and I it's happened again and again and again, we are smelling more and more like Venezuela than we are free us. It's frankly scary, scary to me, but I'm talking about it cuz I think it's important.

[00:37:21] That I bring this to light to everybody else out there. Okay. Now fog data science, managing partner, Matthew Brodrick told the associated press that fog reveal has been critical to police to save time and money on investigations, suggesting police who are under-resourced and investigation suffered from reliance on outdated.

[00:37:44] Outdated tech now that's true. Isn't it? But isn't it also true that, uh, that's why we have some of these policies and procedures in place. That's why the Supreme court Miranda decision has some policies and procedures. That's why a warrant, a search warrant is supposed to be specific in what they're looking for and where it is located.

[00:38:11] We don't allow these broad warrants that the king used to issue, but we are doing that nowadays. It seems against political enemies and that's where it starts really, really scaring me. It isn't that I think that the, the current administration it, or even the next administration in Washington, DC, is going to be rounding up its enemies and putting them up against a.

[00:38:38] But when would it happen? Well, it would happen if everything were in place for it to happen. What's one of the most important things for fastest regime. It's to have a citizenry where they know everything about everyone. It, it reminds me of the Soviet era. Show me the man. I'll show you the crime. There's a great book out there right now.

[00:39:04] I think it's called, um, three felonies. a day, I think is what the name of it is. But the, it points out how every last one of the people that call ourselves Americans in the United States of America, every one of us commits at least three felonies a day. Now a lot of these things are just absolutely crazy.

[00:39:26] You know, there's been a lot of jokes about, oh, did you chair the label off of that pillow? Well, you can cuz you're the consumer, right? It's. The people that are selling it that are in distribution chain that cannot tear that off by law. Okay. But in reality, there is a lot of stuff that could be used against you.

[00:39:46] So it it's like when they say, uh, you know, give me this, or why don't you answer that question? It's none of their business. You have a right to be secure in your papers right now, if they have a warrant that's specific, then you need to surrender it. But hopefully the warrant's actually issued by real court.

[00:40:08] Some of these agencies now, uh, like the IRS have their own courts that are paid for by the agency. The judges are working for the agency. So you really think they're gonna be fair. I wonder, I wonder. Okay. Couple more things. Next up these pictures taken by the James web space telescope. Have you seen these?

[00:40:35] It is amazing. I've seen them side by side with our latest or, you know, our previous high tech pictures. And we're seeing what maybe galaxies that we never could see before. It's just absolutely crazy. Well, guess what bad guys have seen them as. And they are embedding malware inside of some of these amazing images taken by the James web space telescope.

[00:41:05] If you can believe this, by the way, they're writing them in go. Uh, so the Phish and emails, they've got a Microsoft office attachment. That's the entry point for the attack chain when you open it, it retrieves and obfuscated, VBA, macro, which in. Auto executed. all of a sudden there is a macro that is de obfuscated and run on your computer.

[00:41:34] So be careful careful with that again. And good news. Microsoft is now turning off the execution of macros by default. Double check your machine, making sure that macros are blocked by default. So, yay. Okay. So they are, by the way, changing campaigns to rogue link and ISO files because of the blocked macros.

[00:41:56] But, uh, it's good that Microsoft is doing that. Thank goodness. And you Ukraine, the police busted a crypto fraud call center. In fact, more than. And they're also shattering two more Russian bot farms. So we shouldn't be getting as many of those, uh, phone messages from the, uh, the bad guys scammers as we used to get.

[00:42:20] Thank you, Ukraine. All right. Online Craig peterson.com. Get that newsletter and stay on top.

[00:42:29] Well, we got some election news here from our friends at Google and at Twitter, they are taking opposite directions about exactly how they're gonna handle news postings about the elections. This is an interesting thing.

[00:42:46] The federal election commission is the branch of the us government that monitors elections.

[00:42:53] It does things like impose fines for misuse of funds. It sets some of the standards for funds and for their use. And. and one of the things it looks at is what are called in kind contributions. This is where someone might, uh, for instance, run a whole bunch of ads on behalf of a candidate. And those ads are coordinated with the campaign and that is illegal.

[00:43:24] You're not supposed to do that. And because it's illegal, you know, they try and stop it. But most of the time they end up finding after the fact. And that's part of the reason they want campaigns to be filing their financial reports fairly frequently so they can catch it quite quickly. Well, There have been many complaints from the G O P about what has happened with some of the campaign finance stuff, where you have someone like Facebook or Twitter or Google, who seems to be meddling with the election.

[00:44:02] They are running ads for your competition. They are really screening the results from people's searches. And from that those results they're, they're benefiting. There was a study down in orange county here a few years back where they looked at. Google results that were related to the elections going on in orange county and found that the Google results were tainted in such a way that it dramatically favored the Democrats that were running in those districts in orange county, California.

[00:44:39] Pretty interesting when you get right down to it. So the GLP says, wait a minute, now that sort of thing is worth millions, tens of millions of dollars, because if they were going to run TV ads, for instance, to get as many eyeballs, to get as much attention to convince people that this is the way they should vote, that would cost them tens of millions of dollars.

[00:45:02] So how much is it worth? Where do you go to really straighten things out in order to ultimately make fairness work and well, you know, that's kind of what the federal election commission's supposed to do. Well, here's, what's happening with the next elections. The federal elections commission has decided that Google.

[00:45:28] Getting rid of their anti spam measures for. Candidates does not violate a ban on contributions on inkind contributions. So this is an interesting approach because Google's saying, Hey, listen, we want to allow pretty much any political message to come right through to Google Gmail users, inboxes, and not filter those.

[00:45:59] Which I frankly think is a smart move on their part. Now some of these campaigns get pretty crazy. They're sending money requests all of the time. It it's been crazy to watch both sides do this and both sides complain about the other side, doing it. But at least by getting rid of these spam rules for the politicians, their messages are gonna get through.

[00:46:24] I think that's ultimately a very good thing. So what kind of messages are gonna get through how and why? Well, ultimately they're saying we're gonna let all of them through. and what that means for you. If you already get some of these messages from the politicians, it means your mailbox. At least if it's a Google Gmail box, you are going to be seen even more during elections.

[00:46:51] And I think this is gonna go on for very long time. Because Google doesn't want to get caught in the middle. When we're talking about these in kind contributions. If this were to be done for the Republicans or were to be done just for the Democrat, can you imagine the noise that would be made? By both sides and in kind contributions where the Republicans tens of millions of dollars Googled get dull tied up in some of these, uh, you know, lawsuits that would really be inevitable.

[00:47:23] Bottom line. Well, Republicans have accused. Google of giving Democrats an advantage in its algorithms. And, and as I said, there have been studies on that that have proved that they have. The big question is why. And there's an article in ours, Technica talking about a meeting that happened in may 20. 22 between Senate Republicans and Google's chief legal officer.

[00:47:52] And he said that the most forceful rebuke came from Senator Marco Rubio from Florida who claimed that not a single email from one of his addresses was reaching inboxes. And the Washington post, which of course is a mouthpiece for the Democrat party reported in late July. That the reason it was getting blocked was that a vendor had not enabled an authentication tool that keeps messages from being marked to spam.

[00:48:21] Now, if that's true, The Washington post accidentally reported the truth here. And it might be true. I had a company call me up this week. They had their Google ads account banned, and they were trying to figure out the details of why and what happened. And I went in and we solved that problem, and I noticed that they had.

[00:48:44] Properly configured their email. There's there's gets technical here. I have a paper we've put together on this, a special report talking about what's called D K I M. These, uh, SPF records DMAR records and how they should all be set up and why I need to use them. So this company was doing marketing.

[00:49:04] Obviously they had a Google, Google ad account. They were sending out emails, but because they had not properly and fully configured their email. They were not getting delivered at the rate that they could get delivered. Now that's kind of a very, very big deal when you get right down to it. And the Washington post is saying, well, that's what happened to center to Rubio.

[00:49:26] Now there's other things that might happen too. There are. Keywords that are used. There's software called spam assassin. That's very, very common. I have used it since it came out decades ago. I can't even remember how long spam Assassin's been out there, but it looks for certain things in the emails. , it looks for a lot of graphical content, a lot of HTML, even a lot of links and it kind of, it gauges, you know, this is likely spam on this scale.

[00:49:56] And typically if the, the score is higher than five or eight, or in some cases, some people said as high as 15, that email is bounced. Well, one of the real big checks as to whether or not this is legitimate email is to check and see. Who is the domain? Does that domain have these special keys that tell us?

[00:50:19] Yes, indeed. This did come from us. In other words, in this case did come from Marco Rubio or in the case of my client, it came from their company.com. And is it signed encrypted so that we know that nobody's kind of playing a man in the middle thing, trying to mess things up on us. And they say, okay, well that's a really good score.

[00:50:40] So we will, we'll lower that spam score. And, and that's how that game is played. So what by Google doing what it. Talking about doing it's really gonna help out because I have of every company I've checked for email, email deliveries, we've got a, a new customer that is a startup and you know, what do they know?

[00:51:02] They they're very narrow. Right? They understand their. Basic technology and their email again, was set up kind of like apparently Senator Rubio's email was set up and, and didn't have these things. And just like this company that I helped this week, they didn't have it set up properly. And, uh, they had experts who supposed experts who had set it up, but both cases, right.

[00:51:26] It was outsourced. Yeah. You know how that goes. Now, some Gmail users submitted comments to the federal elections commission and they were criticizing Google's plan cuz they did not want to get more spam. Okay. And there were more than 2,500 comments. You can find them by the way, online, all of the stuff is a matter.

[00:51:48] Public record and they call it the docket. And so there's a page out for this particular docket and the commissions through Republicans and Democrat commissioner voted for the order appro Google's plan. I think this is a very, very good deal. And it's really kind of the opposite of what Twitter is planning on doing Twitter has.

[00:52:12] essentially announced that it's going to. In the elections. Yeah. So you got Google on the one side saying our hands are clean. We're staying away from this. We don't want anything to do with this. Thank you very much. We love you, but, uh, forget about it. We're just gonna let all the emails. Through, Twitter's saying that it's going to have its wonderful sensors who have been proven right.

[00:52:39] Every time he said with his tongue firmly planted in his cheek, and they're gonna have those wonderful sensors that, you know, they're sitting in the basement and, and eating pizza and drinking Coke or red bull. I, I still kinda understand why somebody that's 30, whatever years old needs, energy drinks, you know, come on, come on.

[00:53:00] Uh, but anyways, They're they're saying that they, Twitter is going to be the determiner as to whether or not something that is posted on Twitter is correct. Or if it should be censored or if it should be blocked entirely. And they're admitting that they're gonna shadow ban conservative content, they don't like isn't that.

[00:53:25] So. Yeah. Uh, that's from the gateway pundit good article. And you'll find it in this week's newsletter. Uh, I think it went out Monday this week and you can follow the link through to these articles on Google and Twitter and the elections or any of the others that we have out there. So stick around, we'll be right back and make sure you sign up.

[00:53:46] If you didn't already get that newsletter. Absolutely free. Craig, Peter son.com/subscribe.

[00:53:59] I'm not sure a week goes by where I don't hear from a listener saying that somehow Facebook is tracking what they're talking about because all of a sudden ad starts showing up. And they're related to things that they've been talking about.

[00:54:16] Meta is the owner of Facebook and Instagram and, and some other things like WhatsApp, which is part of the reason I don't trust WhatsApp, but we've had, I don't know how many complaints from people saying that Facebook is listening in to what they're talking.

[00:54:36] And people are kind of wondering, well, wait a minute. Is it listening in on my phone calls? Is it listening when and how? It's a very, very good question. Now Facebook says in a statement that Facebook does not use your phone's microphone to inform ads or to change what in the newsfeed. Some recent articles have suggested that we must be listening to people's conversations in order to show them.

[00:55:06] Ads. This is not true. We show ads based on people's interests and other profiled information, not what you're talking out loud about. We only access your microphone if you've given our app permission. And if you are actively using a specific feature that requires audio, this might include recording a video or using in an optional feature.

[00:55:30] We introduced two years ago to include music. Or other audio in your status updates. So there it is. There's the official word from our friends over at Facebook. But do you notice there's a little bit of an out in there, right? Facebook does not use your phone microphone to inform ads or change what you see in your news.

[00:55:55] Doesn't use your microphone. So there's a study out right now. That is from an X Google engineer. And this article is in the guardian and they are talking about what he found. So, let me explain the background on some of this technology. First, if you are an app developer, if, if you're a developer of any software of any kind you use libraries and these libraries do things like search for a specific set of characters called a string or in search.

[00:56:31] Them or move things around or open a connection to another machine. So rather than having implement the whole T C P I P stack and ethernet underneath it and, and all of the operating system work that you'd have to do with all of the interrupts and the buffer fills and reading, toggling. As switches in the hardware, doing all of that sort of stuff.

[00:56:52] You just make one library call and say, listen, and you give the port and TA anybody who tries to connect you. It just comes right through. It's all taken care of for you, right? That's what libraries are all about. And they've become much more complex, more recently libraries nowadays can do things like provide you with a full web browser.

[00:57:16] Many of the applications that we use on a daily basis, these apps in our phones, particularly, but it's also true with some of the apps on our computers are actually. Just web browsers. They're web browsers that talk to a server out on the internet and yeah, there might be wrapped in various things, but oftentimes if you're trying to pay within an app, it'll go to a third party site.

[00:57:44] And part of the beauty of that is. Becomes a, a service to them. They don't have to worry about coding it all up. Right. They don't have to worry about taking your money, keeping everything safe. Am I using really good algorithms here to encrypt it can bad guys hack in? No, no, no. There's, they're just calling this routine that spins up a little web browser.

[00:58:07] Inside the application and uses a secure connection to talk to the web server somewhere who cares? Not mine. I'm just the app developer, right? I'm letting you play your farming game or whatever it might be. That makes sense to you guys. So it makes their life much, much easier. Why bother if you've got a website that does everything, why bother coding it all up from scratch in an app?

[00:58:34] They don't people don't. Why would. Well, we've seen that again. And again, for instance, look at Microsoft's latest browser out there, edge, not the original edge, but the latest edge, you know how Microsoft is, right. They call it the same thing, even though it's entirely different. Uh, yeah. How many versions of windows where they're like 20 at one point, right?

[00:58:56] Different ones or different architectures and just crazy. But now the edge browser is. Built on chromium, which is Google Chrome, which is built on Apple's libraries to manipulate, draw things, et cetera. So you're running your edge browser on your Microsoft windows, computer. You're actually running code libraries.

[00:59:21] If you will, from Google and from apple. And that way, if you're developing a browser like edge, you don't have to worry about every little nit bitty thing. That's all taken care of by other programmers who are making a smaller piece of code. Now that's been the whole Unix philosophy forever, by the way.

[00:59:42] Instead of having these monolithic applications. That could be just full of bugs and security problems. You just have nice small, easy to maintain, easy to research applications and let other people worry about the little pieces, which is really kind of cool. It's great. Many browsers in fact are based right there on chromium and they modify it around a little bit.

[01:00:07] Microsoft added all kinds of spyware to it. Well, it turns out. According to this research from an ex Google engineer that both Facebook and Instagram apps have been taking advantage of this in-app browser technology. And what they're doing is users who click on links inside the Facebook app or inside the Instagram at gram act are actually taken to the webpages.

[01:00:39] Using an in-app browser controlled by Facebook or Instagram rather than sending you to your default browser. So if you are using iOS, your default browser might be safari, which is a rather safe. Browser and good for privacy, or you might have decided you wanna use the Chrome browser on iOS or maybe Firefox or brave, or one of dozens of different browsers that are out there.

[01:01:10] No, no, it's not gonna use those. It's not gonna use your default browser. It's going to use the in-app browser. And what it's doing with that in-app browser now is here's a quote from him. The Felix Crouse, he's a privacy researcher founded an app development tool that was acquired by Google in 2017. He says, quote, the Instagram app injects their tracking code into.

[01:01:37] Website shown, including when clicking on AB ads, enabling them to monitor all user interactions. Like every button that you press, every link you taped, every piece of text that you select or highlight any screenshot you take, any forms, you fill out any user forms, things like passwords addresses, credit card numbers.

[01:02:06] Are all seen by the Instagram app? Yes, indeed. So in the statement, of course, uh, medicated that injecting a tracking code, obeyed users preferences on whether or not they allowed apps to follow them. And there was only used to aggregate data before being applied for targeted advertis. Now, this is interesting because according to Crouse, this code injection, uh, was tracked and he was able to look at doing, doing it right for normal browsers.

[01:02:42] His test code detected no changes, but for Facebook and Instagram, it finds up to 18 lines of code added by. App into the webpage. So there you go. JavaScript injection and more from our friends at Facebook and Instagram. So they are tracking you, but apparently. They're not listening to your microphone, but they're watching you as you cruise around the web thinking you're using your browser, but no, no.

[01:03:18] You're using theirs. Hey, stick around Craig peterson.com.

[01:03:24] Cell phone security is something I've talked about for a long time. And you guys know my basics here. If you've been a listener for really any length of time, when it comes to smartphones, we're gonna get into this in more detail, particularly after this raid.

[01:03:41] Well, of course everyone's heard, I'm sure about the rate on Trump's property, Mar Lago.

[01:03:48] There was something else that happened right. About the same time. And that was representative. Perry Scott Perry was traveling with his in-laws, uh, who are described as elderly. They were on vacation. He's a Republican representative in the house of Congress from Pennsylvania. And he told the Fox news people that three FBI agents approached him, issued him a warrant and demanded he hand over his.

[01:04:24] He said they made no attempt to contact my lawyer, who would've made arrangements for them to have my phone, if that was what they wanted. He says I'm outraged. Although not surprised that the FBI. Under the direction of Merrick Garland's DOJ would seize the phone of a sitting member of Congress. My, my phone contains info about my legislative and political activities, personal private discussions with my wife, family constituents, and friends.

[01:04:53] None of this is the government's business. Now that's really an interesting point. And, and it brings up the discussion about our smart devices, you know, what should we be doing with our phones and, and what is it frankly, that our phones have in them. Now, just think about that for a minute. Scott Perry rec he, he not recommended.

[01:05:21] He mentioned that he had all kinds of records. That were in that phone. You do too. You've got your contacts. Of course. The phone contains information about who you called, where you went, cuz it's got a GPS tracker, but even if GPS is turned off, it's still tracking which cell towers you've connected to.

[01:05:43] Uh, we've got all kinds of email in our phones, which are gonna contain business documents, private documents, attorney, client, privilege documents, all kinds of stuff there. And we have the fourth amendment, which protects the right of privacy against unreasonable searches and seizures by the go. Now, in this case, obviously the government got a warrant we could argue about, you know, how legitimate is the warrant and should they have issued it, et cetera.

[01:06:16] Right. That that's not what I'm talking about. This is not a political show. In reality. What we're talking about here is the technology. The technology we're using to store this information, this personal information, what should we be using? What shouldn't we be using? How should we use it? Right. All of that sort of stuff.

[01:06:38] Well, okay, so we've established that there was not apparently a fourth amendment violation here. There, there might have been, we don't know. We may never know. It doesn't really matter, but if someone gets a hold of your smartphone or your tablet or your computer, what information does it have on there?

[01:07:01] And we also have a right under the fifth amendment. against self-incrimination. So if someone's thumbing through our phone, what are they gonna find? People plead the fifth amendment all of the time, because they don't want to get trapped in one of these traps where maybe you don't remember the date.

[01:07:24] Right. And all of a sudden you're in a perjury trap because you said something that wasn't true. Well, you know, our, our memories aren't the best, particularly when we're on vacation, we've been drinking a little bit, right. if someone finds your phone, opens it up, someone steals your phone and opens it up.

[01:07:44] Someone gets a warrant for your phone and opens it up. What's in there. Now some people have in the past said, okay, what I'll do is I'll just go ahead and I'll wipe my phone remotely and they've done it. Right? The police have had the phone in evidence and in evidence locker and somebody remotely went ahead and wiped their phone.

[01:08:04] The police are onto. And what the police have been doing more recently is they put it into a special bag that blocks any sort of signals coming in or out as well as the room. Right. It's kind of a fair date cage anyways, and that way, bad guys, good guys who, if the phones are stolen, they can't remotely wipe them, which is a good thing here, frankly.

[01:08:30] But what are we ultimately trying to protect from? That's the question, right? It it's, who's gonna have your phone and what are you trying to protect it from personally? I'm not someone who truly trusts the government. I'm a firm believer in our constitution and our bill of right. Ultimately governments become corrupt.

[01:08:52] It happens every time. And even if the whole government isn't corrupt, there's guaranteed to be people within the government, within their bureaucracy, the deep state, if you will, who are out there to get you right. makes sense to you. Makes sense to me. I don't know, but our phones, our smartphones, our computers have a lot of stuff in them.

[01:09:14] I've talked on the show before how you should not be taking them to China. If you go to China, because of the evil made. T where they are grabbing your phones. They are duplicating them. Same thing with Russian travelers. Not as much as has been happening in China, but it's happened in Russia, probably a lot now with the whole war thing.

[01:09:36] Right. But you shouldn't be taking them because they can be duplicated just like rep Scott. But Scott Perry's phone was duplicated. Now the, the FBI apparently said, well, we're not gonna look through well, why you're duplicating it then. And you know, maybe it's just to preserve evidence. I really don't know, but the bad guys can get at your phone employers if they own your phone can get at your phone and they can get a lot of data out of that.

[01:10:06] What do you do? Well, bottom line, if you are traveling internationally, you're gonna wanna make sure to wipe your phone and just bring along maybe a, a basic little flip phone. Uh, cetera. Now there is software that we use. For instance, we use one password and duo in order to keep track of all of our stuff, right.

[01:10:31] Our personal information. And. That's the two factor authentication stuff that we use, and we can tell it, Hey, we're traveling out of the country and we will only need these passwords. And it goes ahead and wipes out the password database so that we're not carrying a whole bunch of stuff with us that might be compromised by, uh, a government agency right within what is it?

[01:10:54] The USS 50 miles of the border. They can confiscate and examine anything that you have, even if you're not trying to cross the border. and they'll do that at airports. They'll do that at a whole bunch of places. And then you've got the employer side and then you've got the bad guy side. Look at what happened to Khai with the Saudis right here.

[01:11:16] He was, uh, you know, a journalist. We could argue that I suppose, but he's a journalist. He is abducted and he is murdered by the Saudis. They get their hands on the phone and they decrypt the. this has happened and it'll happen again. So Apple's done something here that I think is a good step in the right direction.

[01:11:40] Apple, of course I've recommended for a long time. Never, ever, ever, ever, ever use Android. Okay. Don't. Use it, Google's using it to track you. You're losing your privacy and the security. Isn't very good. Particularly if your phone's more than three years old, apple has come up with this new lockdown mode on their phones and the lockdown mode is meant for.

[01:12:09] People who are really under thumb, you know, people living in Russia or Ukraine, or you name it, Iran, all of these countries that are really out to get their citizens and it it's coming out in iOS. You'll see it there. You probably don't want to use it as a regular person, cuz it does block some of the things you can do, but it also locks it down against these Israeli based companies that have been selling software and hardware to break into cell phones.

[01:12:44] So consider iPhones. And if you are one of these people, who's at a high risk consider lockdown mode.

[01:12:51] I warned last week about using the ring camera as well as Google's camera. We've got some more news about that today. I was right. A major breakthrough in nuclear fusion and a new toolkit released. Talk about it all now.

[01:13:08] Well, quite, quite a time, you know, I, I remember when I first started doing the radio show, uh, 22 years ago, now it started right there year 2000 Y two K and I, I was, uh, wondering, you know, am I gonna have enough stuff to talk about?

[01:13:27] and my wife, who was just the most amazing person had been helping me and we subscribed to a bunch of newspapers. Yeah. There used to be newspapers back then. And she went through and was clipping articles that we thought might be good, that people might want to, uh, to hear about. And so she had all. Files.

[01:13:49] And we, we subscribe to like four or five different newspapers, including the trashy ones like USA today, just so we knew what was going on out there. We had the financial times and the London times and New York times, and we got just files and files worth of stuff. And didn't take us long to realize, Hey, wait a minute.

[01:14:14] There is so much tech news out there and stuff to talk about, uh, that weren't, we don't have to worry about that. So we canceled our subscriptions to all of these different things. I, I have actually a subscription to the New York times still, cuz they gave me a buck a week, which is not a bad deal for the online version because the old gray lady still does have some good text stories.

[01:14:39] Some of the other stuff obviously is a problem, but, uh, yeah, tech stories anyways. Now we do a lot of this stuff online, the research, and I put it together and send it out in my newsletter every week. And man, did we have a lot of you guys reading it on Monday was the most, most, uh, red newsletter of mine.

[01:15:01] The insider show notes newsletter. Of any of them ever. It was really great. It was like I had a, almost a 50% open rate there within the first day. So that's cool. Thank you guys. And obviously you really value it or you would not have opened that newsletter and click through you. See what I do? Is, uh, you probably know, I appear on radio stations all over the place and I I'm also of course have my own radio show here and elsewhere, and my podcasts, which are on every major podcast platform out there.

[01:15:40] And I've been doing this for so long this week. What am I at here? Show? Number, I think it's like 1700. I'm trying to remember weeks. Okay. That's weeks of shows and, uh, we, we have never hit the same stuff twice, which is really rather cool. One of the things I brought up and this was in, uh, a recent show is about.

[01:16:09] These ring cameras. And I warned everyone not to use ring and went through the whys. So if you have my newsletter from. A few weeks back, you can just probably search your email box for ring camera and you'll find links to a couple articles on that. And there's an article that just came out in the record here talking about ring, which was purchased by Amazon about four years ago.

[01:16:39] And ring was looked at by this cybersecurity firm called check marks. And they found that the ring camera was leaking data like a SIV, the, some of the, uh, web interface stuff. The videos were, were reachable online. And, uh, it was a real problem. So ring is running the Android operating system, which isn't a bad operating system.

[01:17:09] It's just, you know, tends to not get updates. Something like a ring camera. It, the advantage to it is it probably will get updates. And in fact, the Amazon is pushing updates out to it because they were exposing data and camera recording. So this one, this particular article is not in your newsletter, so you can, um, You don't look for this one there, but look for some of the other ones.

[01:17:38] And by the way, if you don't have my newsletter, if you don't get it, this is a free newsletter. I have my insider show notes that come out weekly, and then I also have some little trainings. I do. I try and do it every week or two, uh, just short ones. It takes you just a few minutes to read, to try and bring you up to date.

[01:17:57] But overall, yeah, sometimes you can sometimes, uh, I, I just. Can't get them out, but you do get my is NS because I send those also to the hosts of the radio stations, where I appear as well as the TV stations to let them know what, uh, what topics are kind of hot this week, because it's, you know, I, I follow the tech quite closely for the show and the podcast and the appearances, but they don't follow technology that costly.

[01:18:28] So. Yet another reason to not use ring and a reason to use ring. Uh, I don't use them. I use at, at my house, at my office, we use some really good Cisco security systems that, uh, that I really like, and that do get updates. The things you want to avoid are these Chinese. Firms that have, uh, you know, the security cameras, one in particular that has about 90% of the market, which it's kind of scary things we've seen there.

[01:18:58] All right. Really, really, really good news. I have for a long time been talking about nuclear power and one of my sons is so totally into it. He was actually thinking about trying to get involved with the nuclear Navy program, which is a hard program to get into and ultimately decided. To, but the nuclear power is back on the board.

[01:19:22] The European union has come out and said, yeah, nuclear power is indeed clean. and they green, in fact, they were saying, and they are turning back on some of these nuclear reactors and it, they are green, but I wanna talk about the new nuclear. We've got some amazing new nuclear technology today. That is intrinsically safe, that uses basic physics to make sure that we're not gonna get meltdowns, that we don't have all kinds of nuclear waste.

[01:19:59] It's just amazing what they've been able to do. And that if you look at the failures of the various types of plants in the past, the failures have been related typically to human error, but sometimes you get a stuck valve or a crack pipe, et cetera. And in those cases, The, the humans might again, react inappropriately and cause more problems.

[01:20:24] As in what happened there in Northern Ukraine that we've all heard about many, many times. So what should we do? Well, The power everyone wants is either what's called cold fusion, which is making some progress or the nuclear fusion as opposed to nuclear fission. Fission's what we've been using now for.

[01:20:52] What going on 80 years and it's what goes into nuclear bombs, but it's also, what's used at pretty much every nuclear plant out there. And there's a new company that just got approval. When I say new, I mean, relatively, it took them six years to get the approval from the nuclear regulatory regulatory commission to put this new nuclear power plant into production.

[01:21:18] And it is. I I innovative. So they're using the same basic FIS vision technology that we've you've used for a long time, but a couple of big differences. One it's considered to be safe. And two, these nuclear plants are small. They are made in a factory where everything can be monitored closely and they can easily put together UR.

[01:21:47] You know, Hey, you need to do this. Upgrade that upgrade. And the nuclear plant is shipped out to location. Now consider how we have been doing it in the past where we build a building, we put all the stuff in, everything is made from scratch. We have to get the guys and gals doing the welds and moving this stuff around and.

[01:22:10] every plant is different substantially different in some way, in some regards. So with this new approved nuclear company, everything's exactly the same they're made in a factory. So that's a huge, huge win to get that approved. But here's the really good news, the power of the. In the sun and other stars, you've got heavy hydrogen atoms that are colliding with so much force that they actually fuse together to make a helium at 'em and just like FIS vision.

[01:22:47] Releases a lot of energy by splitting the atom that joining, creating this new atom also releases large amounts of electricity or energy I should say is a byproduct. And that's what's happening in the stars out there, including our sun. Well, we had a major breakthrough in nuclear. It was about a year ago and it was at Lawrence Livermore, national laboratory out in California.

[01:23:17] And this is their national ignition facility. And they have been trying all kinds of ways to make this work. And we've been making, we've had fusion for quite a while, but the problem is it takes more energy for these fusion reactors to get online and stay online than they produce. One year later. Now we're looking at three peer reviewed papers that say yes, indeed.

[01:23:48] They were able to ignite the hydrogen plasma for the first time we have a fusion reaction that is self sustaining. The fusions themself are producing enough power to maintain the temperature, the control systems, et cetera, without any external heating. So this is really, really good news. Of course, it's gonna have to be scaled.

[01:24:18] and it, there are a bunch of things are gonna have to happen, but if they can do this, if they can do the fusion reactor, or even some of these others that are just been improved here, which is more of a standard type of reactor, uh, You can hook these up to your coal power plants that already have all the electrical infrastructure there.

[01:24:40] They already have all the power lines coming in. The transformers that are needed, the steam plants that can take the heat and convert that heat into electricity. All of that stuff is already there. Just replace the cold burning with either, hopefully this fusion. Hopefully they can scale this, but this is really good news or one of these small nuclear power plants that is made in a factory and shipped out.

[01:25:09] Wow, what good news. Hey, visit me online. Make sure you get my newsletters. Craig peterson.com/subscribe. Go there now.

View Details

Colorado First State to Take Control of Smart Thermostats - Green Energy Initiatives About to Kill - This Winter Will Be Terrible - We Need 487 New eCar Charging Stations Per Day For Next Eight Years

If you got my newsletter this week, you might have noticed that almost everything is about the power grid. Well, it, it kind of is. And we're going to be talking about some of the implications here...

[Automated transcript follows]

Well, I'm sure you've heard about California and the amazing power shortages that they have out there.

It's terrible, right? On a hot day, they're running out of power and on a cold day, they're running out of power. I remember when I lived in Southern California for a couple of years, well, I'm more than a couple, but I had an apartment in one of my first and the only heat was an electric heater that was on the wall between the bathroom and the living.

[00:00:44] And, and that's it. Right. So everything in the apartment was heated from there. There was a, a bedroom. Okay, great. Isn't that wonderful, but there's no heat in the bedroom. So if it was a cold day and I wanted to heat, I had to turn the temperature way up on without electric heater. In the living room slash bathroom, keep the bathroom door open.

[00:01:07] And then it would allow me to kind of heat up the rest of the apartment. Right. It had a separate kitchen with the door. It had the bedroom with the door and it had the big living room. So think about that for a minute. Think about how much it really can drive. Electrical demands and California has been having some real problems about 30%, just slightly more comes from what California calls, renewable resources.

[00:01:37] and there's a great, great quote here. This is from CBS news saying that governor Newsome signed legislation potentially allowing the state's last remaining nuclear plant to stay opened beyond the plan 2025 closure. In order to provide more power for the energy grid. Again, it kind of makes sense. You might remember back in the summer of 2020, there were some real problems with the grid and they had rolling blackouts.

[00:02:09] They've managed to mostly avoid that, but they're asking people, Hey, don't charge your cars, your electric cars don't charge. 'em the grid's under great stress. And we're seeing in Colorado another problem, right? Yeah. Isn't it great here, Denver residents have been able to just go ahead and yeah. Get a hundred dollars bonus for installing smart thermostats.

[00:02:34] A hundred dollars. Yeah. And also on top of that a hundred dollars, they get $25 after the first year. Now why that what's the advantage to these smart thermostats? You know, you look at it at the surface, it says, well, yeah, that's probably a great idea, right? Some of these smarter thermostats measure who's in the room.

[00:02:56] Well, you know that there's people in the room, there's a heat source in the room. There's movement in the room. So it either turns it up or turns it down. Some of them are, are very simple, like mine, right? They're not connected to the. At all and we'll turn the temperature up and down on certain times of certain days so that I can, you know, have a comfortable temperature, but these ones are interesting because what's happened here in Denver.

[00:03:25] is it the residents have lost control of their thermostats. Yeah. So Colorado's having an energy crisis. Let me see, what are these states have in common? Hmm. I wonder Colorado and California. And they're deciding now that the power grid, the, the guys that run it, you know, they that have the monopoly they get to make, what is it?

[00:03:49] Five or 10% of the gross. Income as profit, which is really kind of cool because you know, what that means is the more expensive electricity is to produce and deliver the more money they make. Right. So they just constantly go to the public utilities commission and say, Hey, we need a rate increase. And isn't that wonderful.

[00:04:11] Cause if it was you, would you rather have 5% of a hundred million dollars or 5% of 200 million? I I'll wait.

[00:04:25] Okay. So you'd rather have 5% of $200 million. So, so would the electric grid companies, so why would they want to invest in increasing the electric power when there's so many reasons? Not. Two, you see, let's talk about this for a minute. To build a new plant is very expensive in New Hampshire. The Seabrook nuclear plant was designed.

[00:04:51] They, they were gonna have two major reactors there. Powering New Hampshire. Putting power into the Northeast grid, which would help to service Maine help to service mass. Right. It, it was gonna be just a wonderful thing. And then Jane Fonda's people got gathered around and said, no, no, you can't do that.

[00:05:11] Right. China syndrome, China syndrome, which isn't true. These types of reactors don't have that problem. And, but the newest reactors really don't, we've talked about those on the show before, because they're intrinsically safe. Doesn't. It, they can submerge them. You can cut out all the power to 'em doesn't matter.

[00:05:30] Well, I'll, um, Let me see, do, do I want to, as a power grid company, go to the expense of a couple of things, right? Do do I want to, first of all, go through the latest, uh, number I saw was about six year process to try and get a basic approval for nuclear power plant. Of course, on top of that, you got way more that you have to worry.

[00:05:54] Approvals from, you know, federal and state and county and city, et cetera, et cetera. And, uh, we, so you gotta put your money into that and then you gotta build the darn thing and Seabrook in, which is the one I just mentioned in New Hampshire is an expensive thing to build. So if you put, build a Seabrook nuclear power plant, right.

[00:06:18] And you've got it sitting there, but you never get to quite finish it, then what. While the construction cost of Seabrook. And this is, uh, right now owned by next era. Next era energy resources, Seabrook cost, $17 billion to build, and it never went fully operational. So let me see if I'm a power provider. Do I want to build a nuclear power plant?

[00:06:49] Well, probably not. Probably not. Well, how about a, a gas, power plant? Well, one of the nice things about gas or coal or wood, or even nuclear is they all have the same basic backend. So you might ask me, well, what is that, Craig? What kind of a backend are you talking about here? Well, we're talking about the back end.

[00:07:14] Steam think steam, locomotive, right? What happened with steam? Well, it's still out there and it's still the back end of all of our electric production, at least almost all of it. Right? So you can take an old coal plant and convert it to nuclear. For instance, there's even some ways to convert them to solar, but that's a more expensive process and a lot of stuff has to be changed.

[00:07:39] So 17 billion. To build Seabrook and it never goes into production. And now the people in New Hampshire are paying 17 billion, right. For a nuclear power plant. That's only partially in use. So let me see what other options do they have? Well, of course they could build a cold plant, you know, maybe. Try to anyways, and then what's gonna happen.

[00:08:03] Well, it's gonna get shut down and it's gonna probably take 20 years nowadays to try and get approval for it. Even though we have some pretty darn good clean coal plant, plant technology out there, uh, other options. Well, we mentioned natural gas if we can get it right, but we can't frack in a lot of areas, which is where we get a lot of our natural gas from so natural gas, even though we have more.

[00:08:27] Any other other country or supplier in the world, we can't really use natural gas can because it's, we don't know what's gonna happen here in the future, solar. Well, you know, it doesn't work at night, uh, wind. Well, it, it doesn't work. If the wind isn't blowing, uh, battery technology distort it. We just don't have it.

[00:08:47] Hm. So if you are a provider of electricity, maybe your best choice is to restrict the production of power. Don't bother investing in new power plants, at least, you know, pretend you are, but don't bother. And then ultimately all you have to do is raise your prices. So you raise your price and wait a minute.

[00:09:09] What was that formula I talked about before? Would you rather have 5% of a hundred million or 5% of 200 million? Hmm. Let's see here. Um, what was the answer to that? Oh, 5% of $200 million wins. So the less efficiency that they can have so that they can charge the higher price means they can pull more to their bottom line and life is good.

[00:09:39] Don't you love these types of government regulations are protecting us. They're keeping the prices under control, making it so everything so much better for us all across the board. So California. is doing a couple of other things that are also absolutely ridiculous. One of the things California is doing and, uh, you know, have, have a look at this is 2035.

[00:10:06] You might have heard of this one too. What's happening in 2035. Well, in 2035, California says they will not allow the sale of any new gasoline or internal combustion engine. Cars, at least maybe trucks as well. So let me see if their electric grid is hurting. They're complaining right now because one of their most reliable sources of energy, uh, nuclear they've been shutting down.

[00:10:37] So I mentioned Gavin, Newsome's bringing nuclear back on the table, keeping that plant running. Uh, the other big one of course is water power, hydro dams, right? Uh, and guess what they're running out of out there is the water. And they're having trouble with keeping hydro plants running. So production of electricity, there is way down and to top it off, they want electric vehicles.

[00:11:04] So we're gonna get into this some more where we get back the insanity. Has just gone way overboard here, way, way overboard. And you haven't even heard the half of it yet. Visit me online. Make sure you get my newsletter. My free insider show notes. Visit Craig peterson.com/subscribe.

[00:11:28] We're talking a little bit about green energy, green quote, unquote. Right? Because a lot of it is anything but green. We've talked about many of those things before, but right now we're gonna start out with Germany. What is up over there? The greenest of green.

[00:11:45] Germany has been a leader over in the EU in a number of ways.

[00:11:49] Right? Well, number one, it's the biggest economy in Europe. It's an incredible economy and it has frankly supported many of the EU. Uh, com countries over there from going broke, right? The, the P I G S the Portugal, uh, Italy crease in Spain have been taking a lot of the money from Germany. That's part of the reason that Britain decided to get out of the EU.

[00:12:18] It's just kind of crazy. Right? So Germany being a major provider of some of the financing for some of these program. Has kind of run the EU, even though it's in Brussels there in Belgium, the headquarters anyways. Right? Well, Germany is facing a complete collapse of its power grid system, complete collapse because of the demand for electric.

[00:12:47] Now I'm gonna get into a little bit more of what's happening here in the us with California. You probably saw all of the stuff in my newsletter this week. Craig peterson.com/subscribe in my free newsletter. Uh, and. Here's what's happening over there right now because the gas was cut off to Germany.

[00:13:11] People are panicking. It's also been cut off to pretty much all of the other European countries, France has been playing footsy with Russia. And, uh, because of that, they haven't been completely cut off yet. I haven't seen the latest numbers, but basically Russia's cutting way back, 80% or more to these major.

[00:13:33] European countries. Well, we're looking at a problem in the us too. I burn home heating oil. Most of that comes from Canada. A lot of people burn natural gas in my neighborhood. There's some people that burn LPG, liquified petroleum gas, which is a blend of waste gas gases for the most part. But because we are competing on an international stage, we got a bit of a different problem that we would have otherwise.

[00:14:04] you might know one of my daughters and sons-in-law son-in-laws sons-in-law yeah, that'd be right. Have been working for an, um, a company that transports various types of natural gas and LP gas. So they'll take that gas. At least I used to work for them. Uh, they've moved on, but they'll take that gas and they'll move it from one place to another, for instance, in Boston.

[00:14:32] A few years ago, her ship was sitting in the Harbor. They pull up this buoy from the bottom of the ocean, pull it into the bottom of the ship. And once it was in the bottom of the ship, now, they were able to take the liquified gas that they had on board reg gasify it, and provide the Northeast natural gas grid with natural gas for the winter.

[00:14:55] So she was sitting there at anchor all winter and. Was providing us with natural gas. So one of the beauties of these regas ships is first of all, mass, that two sets did not want a Rega plant on land. So they built a ship with it right there. And then secondly, if you are doing that, you can fill up your LP.

[00:15:18] Uh, ships, right? Because there's some that just transport the liquified gas and some that, that hold a smaller amount and reify, you can take that anywhere. So one year she was sitting off the coast of Israel and they were filling up of course, from the other ships that would come in with the liquid gas and they would reify it and pump that directly into Israel's.

[00:15:46] Pipelines for natural gas. So natural gas is now a worldwide commodity. You can sell it pretty much anywhere because of these new technology ships that are out there that have Rega plants right on them. So all you have to do is give them access to your main pipeline for natural gas. For the area or for the country and they fill it up and you're off and running.

[00:16:14] So now we've got countries all over the world that are competing for the natural gas that we're selling. The natural gas of Russia was selling, right. That some of the natural gas from some of these other places around the world, that means this winter Europe is going to be buying more and more and more natural gas.

[00:16:38] People are gonna die over there. Don't get me wrong because of the cold. They are gonna have a hard time providing natural gas to enough people because everyone's bidding the value, the price of natural gas. And the same, thing's been true for oil for a long time. Right? It's you, you get a ship, it's got however, million barrels of oil on it.

[00:17:01] I'm not even sure. And they deliver that anywhere you want it delivered. One of the things all of these companies do is they sit off shore, so they get filled up and they just sit there waiting for the value of their cargo to go. Now that's been true forever, right? There's what are called tramp ships.

[00:17:25] And, and they'll just go pick up whatever, and they'll sit around and find out, okay, where do you want me to deliver it? And off they go once the price is high enough. So they're already doing that. They're staging some of these ships with oil, they're staging some of them with natural gas or LPG, and there's watching the markets and waiting for the time that the price goes up.

[00:17:49] So many people in Germany are worried about being able to get any heat. because natural gas, man, it's gonna be rashing something awful. If Russia doesn't turn those pipelines up all of the way. Remember president Trump warned them about that at the UN and the German representatives were sitting there in the UN on camera snickering that president Trump would suggest that buying all of their natural gas from our friends over in Russia was not the best idea possible.

[00:18:20] Right. So they really messed that one. The people in Germany have been going out and doing what. The sales of electric heaters are higher this year than any other year. So far in 2022, Germans have bought more than 600,000 electric heaters. Isn't that something, and that's a 35% increase from usual. Just to let you know, you can put that in some perspective.

[00:18:51] And of course that number keeps going up and their critical infrastructures now facing this massive strain, this 20 million Germans have homes that are dependent on natural gas, 20. Million and are switching to electric heaters. We're gonna be doing the same thing here. I'm sure. And I mentioned earlier about my first apartment down there in California that had electric heater and that was it.

[00:19:20] That's how we heated the whole crazy thing. So think about that. Germany's been having power problems. They had them last year. They've had them for a few years because they've been turning off reliable sources of energy and trying to move to windmills and solar, which are not ready for prime time. So they are expecting some problems here.

[00:19:44] As remix news is reporting. Blackouts who are not just hit private households, but also affect German infrastructure, including cash payment systems, mobile phone networks, street light. Now that's, uh, from a gentleman, from the association of electrical engineering, and he's saying all of these networks would be down for long periods of time.

[00:20:08] You remember the year 2000 Y2K, the world is gonna come to an end. Computers are gonna go down. Yeah. turns out they were off by about 22 years. Right? Meanwhile, This is the daily fetched reporting German. These biggest cities are preparing for an energy crisis as a country prepares to limit heat and shut off warm water and shut off lighting.

[00:20:34] Absolutely amazing. We're gonna pick this up when we come back. So don't go anywhere. Look for my podcast. You'll find it pretty much everywhere. Just search for Craig Peterson and, or go to my website. Craig peterson.com.

[00:20:55] We've talked about the internet of things here before many times and the security problems with it. Well, Denver and California are proving that there are more problems with internet of things as governments taking control.

[00:21:11] I mentioned a little bit earlier about how the guys and gals in Denver, Colorado have succumbed to just, well, it really was a very good deal.

[00:21:23] Succumb is probably the wrong word. You see, they would let you have a smart thermostat and they would pay you a hundred dollars. If you bought a smart thermostat that met their requirements. Of course, and then $25 a year. If you kept that smart thermostat online. Now that's an internet of things. We've talked about, the serious problems we've seen in the past about them.

[00:21:49] So for instance, Google smart thermostat decided that, uh, well it needed a microphone and, um, it didn't tell anybody and nobody knew why Google had put a microphone in there because they weren't using. of course, they kind of make sense to put a, some, our microphone in there, so you can talk to it. Right.

[00:22:09] But none of that was implemented. Then we had some of these smart thermostats being broken into. In fact, some of these, uh, smart thermostats with microphones were not only broken into, but were used to listen the end on what was happening in a. So there's all kinds of problems with them. I OT internet of things is any device that gets hooked up to the internet gets hooked up to your network.

[00:22:35] Nowadays that's things like refrigerators that might remind you that you need to buy some eggs and some of them will even place orders for you for groceries. And they'll just show up. You can expect more of that by the way as time goes. And there are some services that will not only take that order of groceries, but will come into your home and put them in the fridge for you depending on where you live.

[00:23:00] Right. Doesn't that sound absolutely wonderful. But the internet of things here. Is really concerning cuz we're tying more and more of our appliances and other electronic devices into this central control system out there. We've seen issues where they're tied in centrally things like your washer. You're dryer.

[00:23:25] And now they're being controlled by the utilities so that you don't run your wash at a certain time of day when they might need the electricity. Now I can see that, that, that kind of makes sense to me, but I think the best way to incentivize consumers is to do a pricing system that is variable. So if it's peak time, Hey, electricity is cheap.

[00:23:48] If you use it after 10:00 PM or whatever the right time is. And there are some utilities that are doing that, but there are states out there that are again, Democrat controlled. It seems to be the theme, doesn't it, where they are starting to mandate that you have smart appliances and that they be tied into a control system that ultimately the state can.

[00:24:19] So they know when you're washing your clothes, they know when you're ordering your grocer groceries, they know where they're coming from. Now, of course they can get some of that information. Like the groceries from credit cards, cuz most of us were paying for groceries. The credit cards aren't we. But ultimately what we're doing is opening up everything in our homes to external monitoring and potentially to control.

[00:24:44] And that's what's happening right now. It really is external. Control and that's what's happened in Denver where they had a heat wave and people went up to their thermostat to turn it down because man, it was hot and you know what I've had, I've had my temperature turned way up because I didn't wanna waste electricity, but it's really hot today.

[00:25:06] So I'm gonna turn it up and what. What happens. It says right there in the thermostat that you can't change it due to an energy emergency, California is going to mandate these types of smart thermostats that control how much heat you get in the winter and how much cooling you get in the summer. They're also starting to require that your washing machine and dryer, particularly electric dryers are also controlled by this.

[00:25:38] See, it all goes back to what I was talking about before. If you are a power grid. What are you gonna do? Is it better for you to just increase prices or is it better for you to build new sources of electricity? And as I mentioned before, I went through all of this in detail. It's usually much better for you to just go ahead and increase your prices.

[00:26:02] You'll make more money. You don't have that money at risk because man, somebody might pass a law, a rule, a regulation, heck some dictator might sign an executive order cutting off your supply. Right. Might be Putin might be somebody else. You never know. So instead of relying so heavily on things such as our natural gas supply, which president Biden effectively shut down some of the exploration for natural gas because he shut down fracking.

[00:26:35] Uh, we are now burning natural gas to produce electricity. So what happens? Electric prices while in New Hampshire, they doubled doubled from one month to the next. The price of electricity. Now your bill wouldn't have doubled because there's also the delivery costs and other things that are involved, but the price of electricity itself doubled, we've got to get smart about this stuff.

[00:27:03] So I'm, I'm gonna go to another one. We mentioned, and this was in the newsletter that came out. Um, you can find that, uh, on the newsletter subscription online at Craig peterson.com/subscribe, but here's another problem we got California is requiring electric vehicles. By 2035, they want half or not half.

[00:27:30] Excuse me. They want all of the vehicles sold in California. All of them to be electric, no more internal combustion engines in California, at least new cars, right? No, probably be, uh, the gas cars for quite a while. So let's look at this. The federal government wants us to be driving electric cars, all of the car companies, making electric cars.

[00:27:54] Are they making them cuz people want them are demanding them? No. They're not look at the number of cars sold. Look at how some of these electric car lines have been shut down. Nissan Nissan closed one of their cars off a GM closed one of their cars off, right? These electric cars don't make sense, but if you are going to stay in business and you're going to get an executive order or a law coming down from Congress.

[00:28:22] And that law says you're gonna have to produce electric vehicles. You're gonna do it. It's just like the cafe standards. Yeah. Hey, listen, your whole fleet. In other words, all of the cars that you sell, sell half to meet these standards for fuel economy across the board. So what are you gonna do? How are you gonna deal with that?

[00:28:41] Well, you're gonna make the cars less safe by taking some of this deal out of. You're gonna make them less safe because you want to make them lighter. You're gonna get rid of that really great spare tire that was in the back, and you can replace it with one of those stupid little space saver, saver tires, right?

[00:28:57] All, to save weight, all, to meet federal regulations on the mileage the vehicles have to meet. Now, when we're looking at the electricity, we've already established that we don't have the electrical supply to power. These cars. We Don. We don't, we're already having brownouts in the summer and in the winter, in different parts of the country.

[00:29:22] Well, let's also talk about one more thing and that is okay. So how are we gonna charge the cars? And obviously getting the electricity is a very big deal. And there was a new nuclear plant license that finally went through. It started the application process. Back at the pretty much the beginning of the Trump administration and was signed off by the Biden administration for one of these new nuclear plant.

[00:29:53] And the nuclear plant is by the way, intrinsically safe. It's made enough. Factory. It's not custom made on site, whole new world. And then how are we gonna charge the cars? That's another problem. it hasn't been addressed yet. So we'll get into all of that stick around. Of course, listening to Craig Peterson, you can sign up and find out more.

[00:30:19] Craig peterson.com.

[00:30:21] So, how are we going to charge the mall? man, this is gonna be a problem. We're gonna get into that right now. Uh, again, man talking about the cart before the horse, what's the matter with these people? It's crazy.

[00:30:38] You know, I am all for electric cars. I think they are cool.

[00:30:43] Very neat. But they are not green. Okay. Don't fool yourself. They are not green. The manufacturing of the batteries where they're mining, how they're. Processing it we're just outsourcing the pollution to third world countries, making people there sick. Right. Why, why bother you? You remember the Olympics that were held in Beijing and how the air was just so nasty people were wearing face masks?

[00:31:14] Uh, not because of worried about. Disease. They were worried about the particulate matter in the air. So what China did is they shut down all manufacturing. For well over a hundred miles so that the Beijing Olympics would not look like what it normally looks like in that area, which is just horrific, almost unbreathable air, same thing with the water.

[00:31:45] You look at the plastic in our oceans, which people are complaining about. And I get it. I don't want microplastics in me and I certainly don't want that little kid to shove a straw up my nose. Like he did the turtle, but that's really what we're looking at here. We're outsourcing our pollution elsewhere and that pollution.

[00:32:08] Ends up here. It ends up in our aquifers. It ends up in the oceans, obviously. Right. And in the air, which blows around the globe. And some of it settles down to the earth and that gets washed away by the rains and then ends up in all kinds of nasty places. So don't, don't let them convince you that electric cars are.

[00:32:33] they are cool. They're wonderful. They're really neat. They're fast. Uh, we should talk again, some point about the autonomous systems I've been driving, Ford's latest, uh, you know, semi-autonomous system. And we can talk about that. What I like and don't like about those things, but, uh, when we're talking about the electric cars, I, I love what my daughter said.

[00:32:57] Who's living in Norway. They have a Tesla. Uh, I think it's a. What is it? Model three, I think. And they're driving in Norway. Now in Norway, you get a, a 25% price, uh, difference, um, buying electric versus gas. The government gives you 25% off because this tax free and the sales tax is 25%. Can you believe that?

[00:33:21] Right? Oh, but things are cheap. Yeah. Yeah. Yeah. Anyways. What they are saying. Cause I asked my daughter, I said, now, you know, that Tesla is not green. Right. And she said, yeah. And I said, well, how about people in Norway? What are they thinking? Why are they buying it? Why is Norway the most, uh, populated electric vehicle country in the world?

[00:33:46] Per capita, they have more electric cars than any other country. Well, the main reason for that is because of the massive tax incentives, but the other side of that coin here, frankly, is the, how Norway wants to stay green. They wanna be, have fresh air. They wanna be living in a clean environment. And so what she told me was that Norwegian realizes.

[00:34:11] You know, not everybody obviously, but, um, that these cars, these electric cars are not green. They are hard on the environment, but not the environment in nor. Talking about being closed minded. Right? Very narrow minded. All that matters is that we're not polluting Norway by driving those cars. Now, ultimately they may be because in most parts of the world, the electric cars, batteries are being put in storage facilities or are ending up in waste.

[00:34:45] Piles, uh, around the world. It it's really kind of crazy because most of them cannot be recycled. Now there's some work on that right now. Tesla's doing some amazing stuff with changing the battery, not just the chemistry, but it's makeup and in the car. And they think they're gonna be able to have a car out that gets 650 miles, 6, 5 0 on a charge.

[00:35:08] Which is pretty darn cool by changing a whole bunch of stuff. In fact, the batteries become a structural, uh, component of the vehicle. So that's really kind of cool. But if we have all of these electric cars on the road, whether they're polluting or not, how do we charge these things? We've got the problem of how do we generate enough electricity and.

[00:35:33] Again, you've been listening to me long enough, you know, nuclear, nuclear nuclear are the three best options because we need power that's on. When the sun's set, we need power that's on. When the wind isn't blowing, we need power in the Northern realms of Alaska. We need power everywhere. So I really like these new intrinsically safe nuclear plants.

[00:36:00] Germany is turning them back on earlier. I talked about how California has now extended the life on this nuclear plant. They were gonna shut down just so they can keep electricity up. And yet we're talking about millions, more of these electric cars on the. So, what does that mean? Well, it also means that we need to spend 35 billion to meet the demand for an additional 1.2 million public charging stations by 2030.

[00:36:36] And that's not counting the 28 million that are needed in people's home. So the us needs to build 30 million EV charging parts. So let's do the math. Now. We're not gonna do the math up to 2035, which is the Dday for California. Let's do the math to 2030. Okay. The math for up to 2030 means that they need to be installing 478.

[00:37:08] Charging stations per day for the next eight years. And that's of half the drivers switched to electric. I don't think that's gonna happen that quickly, but it is eventually going to happen. So right now we have about 128,000 public electric vehicle charging outlets. And I've shared some articles in the past talking about how so many of them don't work.

[00:37:34] They won't work with your car or, or just plain broken. Uh, there's a lot of those out there. So 128,000 public and at least 4,500 private ones currently in comparison with 150,000 gas stations. Okay. So, although EV sales have climbed a lot each year since 2016, most consumers like myself are really concerned about the batteries.

[00:38:01] How long will they last? How far will they go? And then how long does it take to charge? Where can I charge them? Right. It's uh, very, very big deal. So that's a huge number. Isn't it. Now. And then, then we're talking about putting charging ports into our homes. and you probably have to get an electrician to come into your home to hook up a charging port to charge up your car.

[00:38:27] Right? So it's an interesting set of problems. So when I talked about having the cart before the horse, the obvious problem here is we're pushing electric vehicles and pushing. All out really heavily, the tax incentives have changed recently due to this, this, uh, inflation and increasing act. Right.

[00:38:57] Reduction. I Ugh, crazy. But anyways, I. We are seeing more and more of these vehicles. Some manufacturers such as Tesla are losing their, the federal, uh, chip in other manufacturers like for GM and others, uh, have gone ahead and raised their prices to match or exceed the amount of money that federal government's chipping in.

[00:39:23] Oh boy, I hate it. When that happens, goes down the wrong way. Where are we gonna end up? How is this going to happen? Um, we've got the car before the horse was pushing these cars. The car manufacturers have said, oh, wait a minute. There's gonna be a $5,000, uh, chip in by the federal government, by the taxpayers.

[00:39:44] Yeah. By the, you know, the widows, the people who are working really hard, driving the trucks and everything. Yeah. Those loose guys are gonna pay for electric cars, which by the way, vast majority electric car owners are our wealthy people. Thank you very much. Well, have the poverty line. So we're gonna take money from people at, or below the poverty line and give it to those people.

[00:40:04] And uh, $5,000. No problem. So what do the automakers do? They went ahead and raised their prices by at least the amount of money that the federal government said that they were going to chip in. Is that a surprise to anybody? It shouldn't be it. It's kind of like the student loan problems. Right? Why is tuition so expensive?

[00:40:28] Well, let me see. Government is making it possible for people to borrow more money, to go to college. Government's giving the. Pell grants and others for people to go to college. Uh, they're letting you pay it off over your lifetime. Yeah. It's the same sort of thing. So those, those benefits of thousands of dollars that are in this new bill that was passed, that are there to help you buy electric vehicles won't matter because they have raised their prices of the cars.

[00:41:03] At or above the amount of money the government's going to contribute yet you and me are going to contribute, you know, the small business people that, um, you know, readers, digested a survey of small business people and found out we only have to work a half a day. Did you know that only a half a day? And it doesn't really matter which 12 hours you work, which is true.

[00:41:23] Right. I've had like two vacations in, in my whole adult life. That's it because I care about my customers. Right. I try and make sure everything's going fine for them. So we get to pay for these electric cars they're being bought by people who are in the highest levels of, uh, income in the country. It's absolutely crazy, absolutely crazy.

[00:41:52] And we only have to build about 500 charging stations a day. So there you go. And then, you know, there's this minor problem of the electricity, where's it gonna come from? But you know, don't worry about that. Right? Cuz Bernie natural gas, that's the way to do it. And natural gas prices have gone up, which means electric prices have gone up just like I mentioned before.

[00:42:15] Hey, you know, it, it is probably time to do an upgrade on that computer of yours for windows 11, or maybe you're gonna move over to the Linux world. That's what I did with my older computer, frankly. I it's Linux now much faster, but there's more to it.

[00:42:31] Hey, I send out my newsletter, my insider show notes every Monday morning.

[00:42:37] Usually sometimes it's Tuesday, sometimes it's Wednesday depends on the week. This week I was at a client's site over the weekend, actually, and Monday and Tuesday down in Atlanta. So I, I was busy down there. This is a DOD subcontractor. They just. Parts, but they are required by CMMC these new regulations I've actually been around for a while now to really keep an eye on their cybersecurity.

[00:43:06] And so of course they bring me in and my team cuz you know, that's what we do. But I told you that because of my newsletter this week, I got some comments from a few people that the cybersecurity section in my newsletter was. Two articles from 2015 and , they both pointed it out. I think it's great that everybody's paying that much attention.

[00:43:32] I actually, there's a few people that notice that, and it was my fault for not explaining what I was trying to do. And, and that's because I was in a hotel room and I was getting ready to go to the client site and do. Dates fix a couple of things, check the seals on computers and you know, all of those sorts of maintenance things you have to do clean them out.

[00:43:53] I brought down a, a little blower and stuff. They, they were amazingly clean cuz we put them in a special cabinet that has these big air filters on them and stuff. Anyhow. The two articles this week on cybersecurity in my newsletter. Well, this was even in the free newsletter, talked about two different things.

[00:44:12] Lenovo was installing software and laptops, and they apparently have still kind of done that. This was some years ago. like, uh, seven years ago now, I guess. And they were putting it on there and you had no control over it. Okay. It was a real problem. And then the other one was. About your hard drives and what NSA did for years in modifying the firmware on the hard disk drives of a number of computers, many computers out there.

[00:44:48] And in both cases, Lenovo and the NSA, their national security agency. Put software on the computers so that even if you erased your computers, you would still have their software on it. They would reinstall itself. And Lenovo has been caught again, doing that. Okay. So there there's articles out there talking about.

[00:45:13] Just all of the stuff they've been doing. So here's what I want propose to you guys. And I did not make this clear in the newsletter. And for that, I apologize. I was in a hurry and that was my intention and it just had never happened. Not, but not being in a hurry was my intention. But I, I, I intended to explain this a little bit better and I did on the radio a little bit this week as well.

[00:45:37] And I'm doing it right now. My intention is to let you know that for decades now, bad guys have been able to embed malware into parts of your computer. So instead of just the operating system where they might have re. Placed some sort of a library file. And now when your machine boots up, it's going to pull it in from that library file or one of the many other ways, uh, they, they will go beneath your operating system.

[00:46:12] So they'll put things in the boot blocks of your computer and. As we just mentioned here, they will put things in the hard drive itself, not on the blocks of the hard drive, but in the controller of the hard drive right there on the hard drive's board motherboard, if you will, for the hard drive and they can make it persistent.

[00:46:37] now we've tried to get around some of these problems. Apple came up with the T two chip and what the T two chip does is really lock things down on your apple computer. And that's always a good thing, right? And the apple T two chip keeps track of. Passwords and makes things bootable and everything else.

[00:46:59] And apple has also really kind of spun things out a little bit here with their T2 chip. They had some security problems. Uh they're in all of the newer apple computers. In fact, the one I use a lot is an older computer that doesn't have that T2 chip in it, but what Microsoft has done now, and this isn't really Microsoft, it's really the hardware vendors.

[00:47:25] They have something called a TP. And this TPM is there for security. It's the trusted platform module. You want the version two or better, uh, as they come out, right. Kind of keep it up to date. But the T2, this trusted platform module is kind of like the apple two chip. It is nowhere near as. Complete, if you will, as the apple T two chip is, and it's designed primarily for booting your computer, which is really kind of cool.

[00:48:03] There's a cute article over on medium. And it's saying that the author's, uh, professor bill Buchanan. The author of this article says, uh, the TPM chip in your computer is perhaps a forgotten device. It often sits there not doing much and never quite achieving its full potential. You bought the laptop because it had one, but you just can't find a use for it.

[00:48:25] The chip itself is rather jealous of the apple TTU chip and which does so much more and where people actually buy the computer for the things it bring. Few people actually buy a computer, cuz it has a TPM, but lots of people buy a MacBook and an iPhone because it is trusted to look after your sensitive data.

[00:48:45] And he's absolutely right about that stuff. Now I've got clients who have been buying servers and other computers and the T2 chip has been. Option for them. I think that's probably almost gone nowadays. It is probably added in by default. These things are pretty cheap, cuz again, they don't really do much, but they are now a part of it because of what Microsoft has done.

[00:49:14] Microsoft has made it so that you pretty much have to have one of. T2 chip or TPM chips, I should say the TPM 2.0 cuz you know, it's gotta be as good as apples T2 the TPM 2.0, which is a crypto processor so that you can run windows 11. Now, I don't want you to think that having this TPM chip in your computer, all of a sudden makes it.

[00:49:40] But it does do a few things that are very, very good. First of all, it has a random number generator, which is super important when we're talking about encrypt. And that random number generator is used to generate keys that are used for your disc encryption and potentially other things. So if you are encrypting the disc on your windows machine, you are really moving ahead in a very big way, because now if your computer is stolen and it boots up, they won't be able to.

[00:50:13] at any of that data, it'll all look like random trash. If it's done its job. Right. And it can also of course store the user's password in the chip. It has some what's called persistent memory. I told you all of the stuff cuz of what I want to tell you next. All of this stuff from Lenovo, from the NSA over the years.

[00:50:36] And, and of course the bad guys, whether it's Russia, China, it can be really anywhere. North. Korea's been big on this. Iran's been doing this sort of thing. All of those guys may well have had access to your computer in the past. If you have an older computer. And because some of this software, some of this malware is persistent.

[00:51:00] And because windows now is, as I said, pretty much requiring one of these TPM chips, the TPM 2.0 or better is what you want. I think that it's time to seriously consider buying a new windows computer. Now we're working with a client right now that has an engineer who has been continually upgrading his windows computer since I don't know, windows XP days, I think.

[00:51:29] And every time he gets a new computer, he just goes ahead and migrates everything over. Doesn't upgrade. Doesn't update to the newest operating system. And for him, anyways, life is good. Well, it ain't so good folks because he has all kinds of nastiness, little turds. If you will, that are hiding all around his computer.

[00:51:54] The registry is going to be scattered with these things. Some of them probably installed by some form of malware over the years, his disc is gonna be cluttered, everything. So I'm saying right now, Get a new computer and go ahead and make sure you reinstall windows. That's the first thing we do. In fact, what we do for our clients.

[00:52:17] We have a version of windows that we have updated stream updated and. We don't have any of that bloatware on it, that the manufacturers get their 10 bucks from the various of vendors, you know, to put the Norton antivirus and all this other useless stuff on your computer. So by reinstalling, just the windows.

[00:52:40] And of course, since its windows, you go to install all of the drivers for your computer, too. But by doing that, you're getting rid of all of the bloatware. And then what you wanna do is either copy or restore your files onto the new computer. And then when you're done with that install, Your applications, the newest versions of your applications.

[00:53:05] And I can hear people right now complaining, cuz I hear this all of the time. My gosh, I've had that application for 10 years and you can't even get it anymore. Blah blah. You know what? You should not be using that application. You need to get the newest version or if that vendor's out of. You need to make sure that you go one more step, find a compatible vendor or whatever.

[00:53:29] We have to stop using old computers and old software. Uh, there's options here, but seriously, consider this because of what's been happening to us for years. Hey, visit me online. Sign up for my newsletter, Craig Peter son.com.

[00:53:48] Well, autonomous cars are on the road and there was an accident in Germany. We don't have all of the details yet, but it's really concerning. And it's about the anonymous cars. Yeah. Autonomous cars. And, uh, we gotta study out. I want to talk about as well.

[00:54:05] There are various levels of autonomy, I guess. Yeah.

[00:54:09] That's the right word in these autonomous vehicles that we have and that we're looking forward to level one is kind of the gold standard, right? That's where we want to get. That's where the cars don't even need a churn wheel pedals, your tension, nothing. They just drive themselves. We're not there. And you probably guess that.

[00:54:32] and then there's level two where you're the driver's supposed to pay attention, but the car's pretty much going to drive itself. Well, there is an article here from the associated press talking about what happened in Germany. And, uh, this is a, a few weeks back, and this is the first time I've seen this article, but they're saying that a test car with autonomous steering capability veered into oncoming traffic in Germany, killing one person and seriously injuring nine others.

[00:55:10] A spokesman for police in the Southwestern town of Rogen said the electric BMW. Nine with five people on board, including a young child swerved out of its lane at abandoned the road. Triggering a series of collisions involving four vehicles after brushing an oncoming search, the BMW hit a Mercedes van.

[00:55:37] Head on resulting in the death of a 33 year old passenger in that vehicle, the 70 year old driver, the Sitan lost control of her car and crashed into another vehicle with two people on board, pushing it off the road and causing it to burst into flame. Ruly again, police spokesman. Michael Shaw said four rescue helicopters, and dozens of firefighters responded to the incident and the injured were taken to several hospitals in the region.

[00:56:11] They included the 43 year old driver of the BMW three adults aged 31 42 and 47 and an 18 month old child who are all in the test. The article goes on, uh, is the police said in a statement, the crash vehicle was an autonomous electric test car, whether it was being steered by the 43, 3 year old driver or not is a subject of investigation.

[00:56:40] So this is called a level two driving assistance system. It's already incorporated in production vehicles today. They can support the driver on when the driver turns them on according to BMW with the level two vehicles, the driver always retains responsibility. In other words, if that car gets into.

[00:57:04] Accident while you are behind the wheel and responsible for it, it's your fault. So that solves the problem of whose insurance covers what doesn't it? Yeah, it, it does it pretty well because it's your fault is kind of the bottom line. So we are in the process of investigating the exact circumstances of the crash.

[00:57:25] BMW said, of course we are in close contact with the authorities. It's it's concerning very concerning and I am not ready yet. Autonomous vehicles. Now we've seen, and we've talked about on the show before a number of problems with some of these different vehicles from Tesla and others, and they are on the roads in many states right now, even in the Northeast, not just the Teslas, but these fully autonomous test vehicles.

[00:57:59] There are a number of things to be concerned about here. For instance, how can an autonomous vehicle determine what to do when there's a police officer in the middle of the road or a flagman? Or obviously it really can't determine it because it can't make out. What's what, in fact we might remember, and I'm sure they've made some adjustments here over at Tesla, but a Tesla car went ahead and, uh, struck and I think killed a lady who was crossing the road with her bicycle.

[00:58:36] I think she was walking it across when she was hit. How can they tell, how can they tell the difference between a car that's wrapped and has someone's face on it, maybe a politician full body on the back of a box truck as an advertisement. How can it tell the difference between that and a person that might be standing there?

[00:59:00] It, it gets to be a real problem. We're already seeing that some of these autonomous vehicles go directly rear end fire trucks stopped at the side of the road with their lights on police cars stopped at the side of the road with the lights on. Just completely rear-end them. We're seeing that. So how about when it gets a little more difficult than a fire truck parked on the side of the road?

[00:59:25] Now these cars, apparently autonomous steering and, uh, lane detection and correction, all that sort of stuff. These vehicles are looking at things and trying to determine, well, what should I do here? And oftentimes what they determine is, oh, well, okay. That's just something that's fixed at the side of the road.

[00:59:45] Like, like a sign post, like a speed sign. When in fact it's not. So we've gotta solve that problem. It, it still isn't solved yet. What caused this car to steer directly into oncoming traffic and, and head first into a Mercedes van? I, I don't know. They don't know yet. Anyways. I'm sure they'll find out soon enough, but there are real questions here and then I wanna take it to the next levels.

[01:00:18] If the car is in, let's say level one where it's full autonomous, even if it's not, even if it's a level two, like this car was, or is, uh, what happens when the car is either going to hit a pedestrian or go over a cliff or into a brick wall? That's even better. Cuz the car might not know the cliff is there.

[01:00:43] What decision should the car make? What kind of ethics should it be? You know, executing here, can it even make an ethical decision? And this is the trolley testing in case you're not familiar with the whole trolley test thing. It's, let's say you are. A trolley operator, you're going down a hill and there is a fork in the tracks.

[01:01:09] And all you can do is select tracks at a or track set B you can't stop the trolley. You can't slow the trolley down in tracks at a there's a group of seniors walking across the tracks that you will hit. If you go down tracks at a tracks at B. There's some young kids playing on the tracks and if you choose B, you're gonna kill the kids.

[01:01:35] So ethical dilemma here, who do you kill? Cuz that's what the whole trolley test is about. Look it up online. There's a lot of different variations of this, but what about the car? What decision should the car make? Should the car make the decision to protect you the driver, or should the car be making the decision to protect the pedestrian?

[01:01:59] If it's going to protect the pedestrian by plowing into that brick wall and potentially killing the occupants of the car. How about when there is the decision of the old people or the young people? There is a lot to solve here. And some of these companies, including Mercedes have come out already with their decisions, Mercedes said they will protect the occupants of the vehicle.

[01:02:27] now when you're driving the car yourself, of course, you're making that decision in a, a split second, maybe something you thought about, maybe not, you might make a rational decision. You might not. It's, you know, it's hard to say. And you'll find these articles in my newsletter this week at, uh, Craig peterson.com.

[01:02:49] If you're not on the newsletter list, you can sign up. It's absolutely free. This is the free newsletter and you can see all my insiders show notes every week, but it's an issue. Isn't it. The car veering into traffic hitting another one head first. How about later on when it's completely autonomous, what should it do?

[01:03:14] By now you've seen one of these new cars with that big screen right there in the center of the console. I've got a few problems with this, more than a few problems with you people, right. To quote Seinfeld. Yeah. Let's talk about it.

[01:03:31] You know, it, it's very cool to have that display in the center of the car console.

[01:03:36] One of the major reasons that the automotive manufacturers are putting that console right there in the center is because we are demanding, uh, the apple car play the Android car functions in order to have. Really cool stuff, right. Where we can just run our apps and have all of this, uh, wonderful information.

[01:04:02] What I really like about it and Android auto and, uh, the apple car both provide this. What I really like is you can use the navigation system that you prefer, that you like, that you want that's in your. I have switched over to apple maps. Now I used to use ways. And before that I would use Google maps and way before that map question and others, my wife could tell you some stories of us trying to use some of the very first generation GPS stuff, having a, a lap.

[01:04:38] Top in the car and then having a hockey puck up on the dashboard to try and pick up at least three satellites. And, and, uh, if you went off course at all, went the wrong way, took the wrong. it would just insist on bringing you back to where you were when you went off course, as opposed to taking you from where you are, to where you want to go, which they do nowadays.

[01:05:01] But I like that. Right. And, and I like the new features that are always coming out in these apps that we run on our smartphone. I do not like the fact that the cars have navigation in them. Eh, some of them are pretty cool. They're nice. Like in our car, if you use the incar navigation, it mutes the music or the radio, whatever is playing on the driver's side speaker there in the front of the car.

[01:05:32] And then it gives the driver the direction. So everyone else can just keep listening to whatever they were listening to before on the radio, et. You I'll need features like that. But what I don't like is they wanna get six or 800 bucks out of us in order to get new maps in order to get new software for the mapping system.

[01:05:53] When we can get things like apple maps for free. Where they're not even using our data against us, like Google does right Android. Uh, very, very nice. I, I really like them. And the apple maps now is really good. I don't know if you remember how bad it was when it first came out, but Steve jobs brought all of the mapping, senior management into a room and asked them what happened.

[01:06:20] Why is it so bad? You might remember that it took some people in Australia. Way off the beaten track out in the middle of nowhere with no water, with no fuel and they could have died out there, you know, Australia, everything's out to kill you and they might well have died and they didn't, which is good news.

[01:06:42] But even in the us, it was just messing up. It wasn't very good. Wasn't taking it always to the right place. And certainly not the best route. Now it's just gotten amazingly good. Very, very good. So I can choose, right. If I still want to use ways I can use it. If I wanna use apple, I can use it. Google maps. I can use it some third party.

[01:07:01] I can use it, but if I've got the stuff that's built into the car, I'm stuck with the stuff that's built into the car, and maybe I can pay to upgrade it. A lot of people have found recently, Hey, guess what? That two G data network went. and that means now that your remote control for your card doesn't work anymore, you might have found your navigation doesn't work anymore.

[01:07:28] I remember I had a Garmin that got live traffic updates, but it was using FM carriers on FM radio stations. And many of them dumped that. guess what your garment's no good anymore. At least that part of it isn't any good and garment charging for map updates. And I don't blame 'em for this stuff. Right.

[01:07:48] But I would prefer to have my own device to use. So that's part of the problem. In fact, that's indicative of what I see to be the very big problem with these new in car systems, because that display in the computer behind it. Isn't just handling your navigation. It's controlling your seat, heaters, the radio, the music you're listening to the lights, the dimming, the headlights, almost everything in the car goes through.

[01:08:23] Infotainment system, right? Yeah. Figured out where I'm going next, because that infotainment system just like the maps on my car right now is going to become out outdated. And then what are you gonna do? And when I say out outdated, I don't just mean, oh, well I want the new features. It might be that you want the new maps.

[01:08:48] Yeah. But what happens when it breaks? This leads us to a study that happened here. A Swedish publication had performed a test. They took 11 new cars alongside an older car, a Volvo C 70 from 2005. now that Volvo had buttons and knobs, buttons and knobs. I've always liked that. And those 11 new cars all had these wonderful infotainment systems, all in one touch screens in the center of the console, they tested this whole thing and they timed how long it took people to perform a li list of tasks in each car.

[01:09:35] So. Included things like turning on that seat, heater, turning up the temperature inside the car, the defrost, adjust the radio, reset the trip. Computer. Turn off the screen. Dim the instruments. The old Volvo was the clear winner. Yeah, indeed. So according to this article in ours, Technica, the four tasks were handled within 10 seconds flat using buttons and knobs in the Volvo.

[01:10:06] So in the amount of time it took them to do all of the tasks, the four tasks that they were given out of that selection here. I just read the car, drove a thousand feet at 68 miles per hour. Now most of these other cars with that wonderful infotainment system required twice as long or even more to complete those same.

[01:10:34] Tasks. So some 30 seconds. So you're talking about traveling two or 3000 feet while you're messing around with that display in the central console. Looks cool. Isn't this the neatest thing ever, but the problem is you have to hunt and Peck now, before you say, oh, well, Craig, these people weren't familiar with that console.

[01:10:58] Well, yeah. Okay. I'll give you that. But what they did with this test is. They let all of the participants play with the cars systems before they started the tests. In other words, they knew the menus, they knew where things were and it still took that time. You see what we're really talking about here is muscle memory, the ability for your car or for you to know your.

[01:11:29] so you can reach out and you can turn that volume knob. You might have to glance real quick to make sure you got the volume knob, but you don't have to hunt and Peck through menus. I like that. So as you can tell, I am not all that hot on these new, all touch interfaces. BMW has an interesting solution to this and that is that I drive system that little knob people didn't like it at first, but you get used to it, right?

[01:12:00] So, you know, if you need to turn on their seat heater, you just press a knob up, up right down. And then TA your seat heater and you get to adjust it right there. That is muscle memory as well. So we've got some work to do here. Uh, there are some decent systems out there in Acura, MDX Mazda, CX 50, neither one of them uses a touchscreen infiltration inform attainment system.

[01:12:29] So that's good. We'll see how it all goes. Make sure you're on my newsletter. So you can read this article and more. Craig peterson.com.

[01:12:39] We've had a chip shortage. I'm sure you've heard of it. And it's been a real problem for everybody from car manufacturers through PC makers. Well, now we're seeing a sudden downturn what's happening now. The Congress has funded it.

[01:12:56] Hey, surprisingly enough. Congress comes along to fix the chip problem with the chip bill, billions of dollars, tens of billions actually being spent on our chip plants here to help the chip industry make more chips, cuz we need chips, chips, chips, right?

[01:13:16] Well, ArsTechnica has a great little article. They're actually taking it from the financial time searched waters. Uh, I subscribe the furniture times for quite a while, but I don't anymore. And they're talking about how we went from a boom economy when it came to chips, these microchips, everything from, uh, Intel corporation out through the manufacturers of some of these much more common chip styles nowadays, the arm chips and how this new.

[01:13:51] That's supposed to, uh, boost production is coming at a point where, okay, first of all, these manufacturers put billions of dollars into building new plants here in the us of a. So that's a good thing. And then Congress comes along sometime after the fact and gives him tens of billions more. And by the way, managed, and this apparently was Senator Chuck, Schumer's doing managed to remove a provision in the build that said that none of that money for chip plants could be spent in China.

[01:14:28] So yeah, there you go. China, you get billions more from us, potentially here as we build chip plants over there, but now what do we find out? Well, a bit of a turn here because there is now excess inventory. Dan Hutchinson, who is the chief executive V L S I research. Who's been really watching the whole chip cycle since 1980s came out and said, quote, I have never seen a time when we had excess inventory.

[01:14:59] And we had shortages. Okay. So the immediate cause of this is a rapid buildup and inventory in the chip supply chain since early the year 2022 here. So compared to February, there are enough chips on hand to support about a month and a half of production. Global inventory levels jumped. Even higher and then even higher in July to almost two months.

[01:15:26] So that's been an issue. And then on top of it, PC sales have been tumbling. Smartphone demand has dropped, and those have been the main causes as consumers are slowing their spending, why they slowing spending. Because they don't have the money they used to have because of the non inflation that's happening right now.

[01:15:48] So we've kind of got all of these things happening and to top it all off, as I said, they're taking tens of billions of dollars of our tax money and, uh, going to be spending it, all of this. It's just absolutely amazing. But the suddenness of this turn, again, according to the financial times has, was when in.

[01:16:08] Dun wall street with news that its revenue in the last quarter had fallen 2.6 billion, 15%, which of course was short of what they were expecting on wall street. There. This is really quite amazing. They took an inventory adjustment that only hits like once a decade and video man, they are about to, uh, to really get hit too.

[01:16:34] I don't, I don't think I talked about this. there's the largest maker of these GPS, these graphics, processing boards, and supplemental chips that are on motherboards. And a lot of computers used a lot in video graphics, machine learning, and of course, mining of cryptocurrencies, and they have seen it fall dramatically 44% fall in these GPU that have been used for gaming.

[01:17:06] And. Bitcoin and, and mining and, and other of these cryptocurrencies and micron, one of the largest makers of memory chip said it's free cash flow was likely to turn negative in the next three months after averaging $1 billion in recent quarters. Isn't that amazing? So all of these problems have been.

[01:17:29] Also throughout Asia last, uh, month here over the last month, the chief executive of Chinese ship maker, semiconductor manufacturing, international corporation, SM IC said that demand had slowed from smartphone and other consumer electronics makers. And some of these manufacturers, electronics makers have stopped orders.

[01:17:52] All together. So guess what happens when you do that? Think about what happened with the lockdown, right? That really spurred this whole thing on a month before Taiwan, semiconductor manufacturing company, TSMC, which is like the biggest guy out there for making many of the chips we depend upon said it was expecting an inventory correction that would last until.

[01:18:17] Next year. So this has been a very abrupt slide. Chip makers in the us are trying to manage this decline at the very moment. They're laying the ground for huge increase in production because of the. Tens of billions, they have spent plus the 52 billion bill that was signed into law here. What a month or two ago, uh, government support provided by the chips act.

[01:18:47] So on the same day that Congress passed the law, Intel expected to be the biggest beneficiary of all of these government grants of our tax dollars. Sliced 4 billion permits, capital spending plans for the rest of the. Now isn't that? What happens every time really? Isn't that? What happens every time? For instance, the, uh, build back better plan renamed the inflation causation actor, I think is what they might have called it.

[01:19:17] Um, that particular bill. Put money in for you to buy an electrical car electric car, like four grand, eight grand kind of depends, uh, across the board. So what do electronic electric car makers do? They increase their prices? Yes, indeed buy, you know, six or eight grand as much as 12 grand. Right? Because now we got government money.

[01:19:42] We don't have to have you. Pay for it. So we're gonna take a bigger profit and that profit's gonna come from the tax dollars that were taken from you and from me and from the widow down the. Right. Yeah. That's what happens every time? Why do we have this whole thing about the loans for people who went to college?

[01:20:03] Well, why is college so expensive? Well, it, it continued to go up as government started providing grants and started backing loans. Right? All of the stuff the government was doing was ultimately driving up the cost of your schooling. Now they've driven up the. Of electric cars because of the money they put in.

[01:20:26] And because of the money that they've put in for the chips act the 52 billion to make chips that, Hey, we got a glut right now. Yeah. Um, guess what? The manufacturers of chips, the companies that we're spending the money in order to create. Plants more plants, more chip factories, fabrication plants have decided they're gonna cut their spending.

[01:20:53] Why not? Because they're gonna get money from you at the point of a gun, right? Yeah. That's exactly what's happening. Oh man. So for now, again, according to the financial times, most chip supply chain experts predict a relatively shallow downturn provided that the global economy is headed first off landing something that's obviously not guaranteed, but it has really left them scrambling, trying to figure out what.

[01:21:23] Happened here because it just fell apart so quickly. Gartner group, you might know them. They put together a lot of studies on a lot of different industries had been expecting the growth in ship sales this year to have from 2020 ones, 26%. So it took its forecast down further to 7% and is now predicting a 2.5% contraction in 2023.

[01:21:52] Isn't that something, um, the, the Philadelphia semiconductor index, if you are an investor, you've heard of that before, and that comprises the 30 largest us companies involved in, in chip design, manufacturer and sale. Fell back almost 40% as a stock market corrected this year after rising threefold, after the early lockdown stock market slump, because people were working from home, they couldn't go in to work people.

[01:22:23] The kids were home, people were buying computers so they could play games or get on a video conference with the office, et cetera. It has really, really changed. And I mentioned Nvidia and how NVIDIA's been hurt pretty badly. And you'll find this article by the way, in my newsletter that went out on, um, Monday.

[01:22:45] And if you don't get my free newsletter, definitely get it to just up to date. Craig, Peter son.com/subscribe. It's it's all worth doing, but within NVI. Here's what's happening. One of the biggest cryptocurrencies out there has decided that they don't want to be part of this whole energy problem that we have.

[01:23:09] You know, some of these minors for various types of cryptocurrencies have actually bought power plants, old coal PLA powered power plants that the states don't wanna buy power from anymore because it's, it's. Right. Kohl's evil. But the private sector came in and said, okay, well, if we run our own power company and we put these GPU's and special purpose made mining equipment.

[01:23:38] Into the power plant. We can save a lot of money. That's how much power they need everybody, a whole power plant to run some of these mining operations. And remember the way you mine, the cryptocurrencies. In most cases, you have to solve very complex mathematical problems to prove that you did the. that was needed in order to then, um, be awarded that Bitcoin or whatever it was that you were mining.

[01:24:09] So pretty much all of the major cryptocurrencies are looking at how can we move away from this model? Because in, in some cases, you know, we're talking about electrical consumption, just for mining cryptocurrencies that serve passes, some countries entire need for electricity. That's how bad it is. And supposedly here, we've got one of the major cryptocurrencies that is changing the entire way you.

[01:24:44] Mining, if you will. Very, very big changes. So expect GPUs and companies like Nvidia that make them to go way down in value here over the coming months. Hey, visit me online. Craig peterson.com. Subscribe to my podcast and find me at YouTube. Take care.

View Details

Colorado First State to Take Control of Smart Thermostats - Green Energy Initiatives About to Kill - This Winter Will Be Terrible - We Need 487 New eCar Charging Stations Per Day For Next Eight Years

If you got my newsletter this week, you might have noticed that almost everything is about the power grid. Well, it, it kind of is. And we're going to be talking about some of the implications here...

[Automated transcript follows]

Well, I'm sure you've heard about California and the amazing power shortages that they have out there.

It's terrible, right? On a hot day, they're running out of power and on a cold day, they're running out of power. I remember when I lived in Southern California for a couple of years, well, I'm more than a couple, but I had an apartment in one of my first and the only heat was an electric heater that was on the wall between the bathroom and the living.

[00:00:44] And, and that's it. Right. So everything in the apartment was heated from there. There was a, a bedroom. Okay, great. Isn't that wonderful, but there's no heat in the bedroom. So if it was a cold day and I wanted to heat, I had to turn the temperature way up on without electric heater. In the living room slash bathroom, keep the bathroom door open.

[00:01:07] And then it would allow me to kind of heat up the rest of the apartment. Right. It had a separate kitchen with the door. It had the bedroom with the door and it had the big living room. So think about that for a minute. Think about how much it really can drive. Electrical demands and California has been having some real problems about 30%, just slightly more comes from what California calls, renewable resources.

[00:01:37] and there's a great, great quote here. This is from CBS news saying that governor Newsome signed legislation potentially allowing the state's last remaining nuclear plant to stay opened beyond the plan 2025 closure. In order to provide more power for the energy grid. Again, it kind of makes sense. You might remember back in the summer of 2020, there were some real problems with the grid and they had rolling blackouts.

[00:02:09] They've managed to mostly avoid that, but they're asking people, Hey, don't charge your cars, your electric cars don't charge. 'em the grid's under great stress. And we're seeing in Colorado another problem, right? Yeah. Isn't it great here, Denver residents have been able to just go ahead and yeah. Get a hundred dollars bonus for installing smart thermostats.

[00:02:34] A hundred dollars. Yeah. And also on top of that a hundred dollars, they get $25 after the first year. Now why that what's the advantage to these smart thermostats? You know, you look at it at the surface, it says, well, yeah, that's probably a great idea, right? Some of these smarter thermostats measure who's in the room.

[00:02:56] Well, you know that there's people in the room, there's a heat source in the room. There's movement in the room. So it either turns it up or turns it down. Some of them are, are very simple, like mine, right? They're not connected to the. At all and we'll turn the temperature up and down on certain times of certain days so that I can, you know, have a comfortable temperature, but these ones are interesting because what's happened here in Denver.

[00:03:25] is it the residents have lost control of their thermostats. Yeah. So Colorado's having an energy crisis. Let me see, what are these states have in common? Hmm. I wonder Colorado and California. And they're deciding now that the power grid, the, the guys that run it, you know, they that have the monopoly they get to make, what is it?

[00:03:49] Five or 10% of the gross. Income as profit, which is really kind of cool because you know, what that means is the more expensive electricity is to produce and deliver the more money they make. Right. So they just constantly go to the public utilities commission and say, Hey, we need a rate increase. And isn't that wonderful.

[00:04:11] Cause if it was you, would you rather have 5% of a hundred million dollars or 5% of 200 million? I I'll wait.

[00:04:25] Okay. So you'd rather have 5% of $200 million. So, so would the electric grid companies, so why would they want to invest in increasing the electric power when there's so many reasons? Not. Two, you see, let's talk about this for a minute. To build a new plant is very expensive in New Hampshire. The Seabrook nuclear plant was designed.

[00:04:51] They, they were gonna have two major reactors there. Powering New Hampshire. Putting power into the Northeast grid, which would help to service Maine help to service mass. Right. It, it was gonna be just a wonderful thing. And then Jane Fonda's people got gathered around and said, no, no, you can't do that.

[00:05:11] Right. China syndrome, China syndrome, which isn't true. These types of reactors don't have that problem. And, but the newest reactors really don't, we've talked about those on the show before, because they're intrinsically safe. Doesn't. It, they can submerge them. You can cut out all the power to 'em doesn't matter.

[00:05:30] Well, I'll, um, Let me see, do, do I want to, as a power grid company, go to the expense of a couple of things, right? Do do I want to, first of all, go through the latest, uh, number I saw was about six year process to try and get a basic approval for nuclear power plant. Of course, on top of that, you got way more that you have to worry.

[00:05:54] Approvals from, you know, federal and state and county and city, et cetera, et cetera. And, uh, we, so you gotta put your money into that and then you gotta build the darn thing and Seabrook in, which is the one I just mentioned in New Hampshire is an expensive thing to build. So if you put, build a Seabrook nuclear power plant, right.

[00:06:18] And you've got it sitting there, but you never get to quite finish it, then what. While the construction cost of Seabrook. And this is, uh, right now owned by next era. Next era energy resources, Seabrook cost, $17 billion to build, and it never went fully operational. So let me see if I'm a power provider. Do I want to build a nuclear power plant?

[00:06:49] Well, probably not. Probably not. Well, how about a, a gas, power plant? Well, one of the nice things about gas or coal or wood, or even nuclear is they all have the same basic backend. So you might ask me, well, what is that, Craig? What kind of a backend are you talking about here? Well, we're talking about the back end.

[00:07:14] Steam think steam, locomotive, right? What happened with steam? Well, it's still out there and it's still the back end of all of our electric production, at least almost all of it. Right? So you can take an old coal plant and convert it to nuclear. For instance, there's even some ways to convert them to solar, but that's a more expensive process and a lot of stuff has to be changed.

[00:07:39] So 17 billion. To build Seabrook and it never goes into production. And now the people in New Hampshire are paying 17 billion, right. For a nuclear power plant. That's only partially in use. So let me see what other options do they have? Well, of course they could build a cold plant, you know, maybe. Try to anyways, and then what's gonna happen.

[00:08:03] Well, it's gonna get shut down and it's gonna probably take 20 years nowadays to try and get approval for it. Even though we have some pretty darn good clean coal plant, plant technology out there, uh, other options. Well, we mentioned natural gas if we can get it right, but we can't frack in a lot of areas, which is where we get a lot of our natural gas from so natural gas, even though we have more.

[00:08:27] Any other other country or supplier in the world, we can't really use natural gas can because it's, we don't know what's gonna happen here in the future, solar. Well, you know, it doesn't work at night, uh, wind. Well, it, it doesn't work. If the wind isn't blowing, uh, battery technology distort it. We just don't have it.

[00:08:47] Hm. So if you are a provider of electricity, maybe your best choice is to restrict the production of power. Don't bother investing in new power plants, at least, you know, pretend you are, but don't bother. And then ultimately all you have to do is raise your prices. So you raise your price and wait a minute.

[00:09:09] What was that formula I talked about before? Would you rather have 5% of a hundred million or 5% of 200 million? Hmm. Let's see here. Um, what was the answer to that? Oh, 5% of $200 million wins. So the less efficiency that they can have so that they can charge the higher price means they can pull more to their bottom line and life is good.

[00:09:39] Don't you love these types of government regulations are protecting us. They're keeping the prices under control, making it so everything so much better for us all across the board. So California. is doing a couple of other things that are also absolutely ridiculous. One of the things California is doing and, uh, you know, have, have a look at this is 2035.

[00:10:06] You might have heard of this one too. What's happening in 2035. Well, in 2035, California says they will not allow the sale of any new gasoline or internal combustion engine. Cars, at least maybe trucks as well. So let me see if their electric grid is hurting. They're complaining right now because one of their most reliable sources of energy, uh, nuclear they've been shutting down.

[00:10:37] So I mentioned Gavin, Newsome's bringing nuclear back on the table, keeping that plant running. Uh, the other big one of course is water power, hydro dams, right? Uh, and guess what they're running out of out there is the water. And they're having trouble with keeping hydro plants running. So production of electricity, there is way down and to top it off, they want electric vehicles.

[00:11:04] So we're gonna get into this some more where we get back the insanity. Has just gone way overboard here, way, way overboard. And you haven't even heard the half of it yet. Visit me online. Make sure you get my newsletter. My free insider show notes. Visit Craig peterson.com/subscribe.

[00:11:28] We're talking a little bit about green energy, green quote, unquote. Right? Because a lot of it is anything but green. We've talked about many of those things before, but right now we're gonna start out with Germany. What is up over there? The greenest of green.

[00:11:45] Germany has been a leader over in the EU in a number of ways.

[00:11:49] Right? Well, number one, it's the biggest economy in Europe. It's an incredible economy and it has frankly supported many of the EU. Uh, com countries over there from going broke, right? The, the P I G S the Portugal, uh, Italy crease in Spain have been taking a lot of the money from Germany. That's part of the reason that Britain decided to get out of the EU.

[00:12:18] It's just kind of crazy. Right? So Germany being a major provider of some of the financing for some of these program. Has kind of run the EU, even though it's in Brussels there in Belgium, the headquarters anyways. Right? Well, Germany is facing a complete collapse of its power grid system, complete collapse because of the demand for electric.

[00:12:47] Now I'm gonna get into a little bit more of what's happening here in the us with California. You probably saw all of the stuff in my newsletter this week. Craig peterson.com/subscribe in my free newsletter. Uh, and. Here's what's happening over there right now because the gas was cut off to Germany.

[00:13:11] People are panicking. It's also been cut off to pretty much all of the other European countries, France has been playing footsy with Russia. And, uh, because of that, they haven't been completely cut off yet. I haven't seen the latest numbers, but basically Russia's cutting way back, 80% or more to these major.

[00:13:33] European countries. Well, we're looking at a problem in the us too. I burn home heating oil. Most of that comes from Canada. A lot of people burn natural gas in my neighborhood. There's some people that burn LPG, liquified petroleum gas, which is a blend of waste gas gases for the most part. But because we are competing on an international stage, we got a bit of a different problem that we would have otherwise.

[00:14:04] you might know one of my daughters and sons-in-law son-in-laws sons-in-law yeah, that'd be right. Have been working for an, um, a company that transports various types of natural gas and LP gas. So they'll take that gas. At least I used to work for them. Uh, they've moved on, but they'll take that gas and they'll move it from one place to another, for instance, in Boston.

[00:14:32] A few years ago, her ship was sitting in the Harbor. They pull up this buoy from the bottom of the ocean, pull it into the bottom of the ship. And once it was in the bottom of the ship, now, they were able to take the liquified gas that they had on board reg gasify it, and provide the Northeast natural gas grid with natural gas for the winter.

[00:14:55] So she was sitting there at anchor all winter and. Was providing us with natural gas. So one of the beauties of these regas ships is first of all, mass, that two sets did not want a Rega plant on land. So they built a ship with it right there. And then secondly, if you are doing that, you can fill up your LP.

[00:15:18] Uh, ships, right? Because there's some that just transport the liquified gas and some that, that hold a smaller amount and reify, you can take that anywhere. So one year she was sitting off the coast of Israel and they were filling up of course, from the other ships that would come in with the liquid gas and they would reify it and pump that directly into Israel's.

[00:15:46] Pipelines for natural gas. So natural gas is now a worldwide commodity. You can sell it pretty much anywhere because of these new technology ships that are out there that have Rega plants right on them. So all you have to do is give them access to your main pipeline for natural gas. For the area or for the country and they fill it up and you're off and running.

[00:16:14] So now we've got countries all over the world that are competing for the natural gas that we're selling. The natural gas of Russia was selling, right. That some of the natural gas from some of these other places around the world, that means this winter Europe is going to be buying more and more and more natural gas.

[00:16:38] People are gonna die over there. Don't get me wrong because of the cold. They are gonna have a hard time providing natural gas to enough people because everyone's bidding the value, the price of natural gas. And the same, thing's been true for oil for a long time. Right? It's you, you get a ship, it's got however, million barrels of oil on it.

[00:17:01] I'm not even sure. And they deliver that anywhere you want it delivered. One of the things all of these companies do is they sit off shore, so they get filled up and they just sit there waiting for the value of their cargo to go. Now that's been true forever, right? There's what are called tramp ships.

[00:17:25] And, and they'll just go pick up whatever, and they'll sit around and find out, okay, where do you want me to deliver it? And off they go once the price is high enough. So they're already doing that. They're staging some of these ships with oil, they're staging some of them with natural gas or LPG, and there's watching the markets and waiting for the time that the price goes up.

[00:17:49] So many people in Germany are worried about being able to get any heat. because natural gas, man, it's gonna be rashing something awful. If Russia doesn't turn those pipelines up all of the way. Remember president Trump warned them about that at the UN and the German representatives were sitting there in the UN on camera snickering that president Trump would suggest that buying all of their natural gas from our friends over in Russia was not the best idea possible.

[00:18:20] Right. So they really messed that one. The people in Germany have been going out and doing what. The sales of electric heaters are higher this year than any other year. So far in 2022, Germans have bought more than 600,000 electric heaters. Isn't that something, and that's a 35% increase from usual. Just to let you know, you can put that in some perspective.

[00:18:51] And of course that number keeps going up and their critical infrastructures now facing this massive strain, this 20 million Germans have homes that are dependent on natural gas, 20. Million and are switching to electric heaters. We're gonna be doing the same thing here. I'm sure. And I mentioned earlier about my first apartment down there in California that had electric heater and that was it.

[00:19:20] That's how we heated the whole crazy thing. So think about that. Germany's been having power problems. They had them last year. They've had them for a few years because they've been turning off reliable sources of energy and trying to move to windmills and solar, which are not ready for prime time. So they are expecting some problems here.

[00:19:44] As remix news is reporting. Blackouts who are not just hit private households, but also affect German infrastructure, including cash payment systems, mobile phone networks, street light. Now that's, uh, from a gentleman, from the association of electrical engineering, and he's saying all of these networks would be down for long periods of time.

[00:20:08] You remember the year 2000 Y2K, the world is gonna come to an end. Computers are gonna go down. Yeah. turns out they were off by about 22 years. Right? Meanwhile, This is the daily fetched reporting German. These biggest cities are preparing for an energy crisis as a country prepares to limit heat and shut off warm water and shut off lighting.

[00:20:34] Absolutely amazing. We're gonna pick this up when we come back. So don't go anywhere. Look for my podcast. You'll find it pretty much everywhere. Just search for Craig Peterson and, or go to my website. Craig peterson.com.

[00:20:55] We've talked about the internet of things here before many times and the security problems with it. Well, Denver and California are proving that there are more problems with internet of things as governments taking control.

[00:21:11] I mentioned a little bit earlier about how the guys and gals in Denver, Colorado have succumbed to just, well, it really was a very good deal.

[00:21:23] Succumb is probably the wrong word. You see, they would let you have a smart thermostat and they would pay you a hundred dollars. If you bought a smart thermostat that met their requirements. Of course, and then $25 a year. If you kept that smart thermostat online. Now that's an internet of things. We've talked about, the serious problems we've seen in the past about them.

[00:21:49] So for instance, Google smart thermostat decided that, uh, well it needed a microphone and, um, it didn't tell anybody and nobody knew why Google had put a microphone in there because they weren't using. of course, they kind of make sense to put a, some, our microphone in there, so you can talk to it. Right.

[00:22:09] But none of that was implemented. Then we had some of these smart thermostats being broken into. In fact, some of these, uh, smart thermostats with microphones were not only broken into, but were used to listen the end on what was happening in a. So there's all kinds of problems with them. I OT internet of things is any device that gets hooked up to the internet gets hooked up to your network.

[00:22:35] Nowadays that's things like refrigerators that might remind you that you need to buy some eggs and some of them will even place orders for you for groceries. And they'll just show up. You can expect more of that by the way as time goes. And there are some services that will not only take that order of groceries, but will come into your home and put them in the fridge for you depending on where you live.

[00:23:00] Right. Doesn't that sound absolutely wonderful. But the internet of things here. Is really concerning cuz we're tying more and more of our appliances and other electronic devices into this central control system out there. We've seen issues where they're tied in centrally things like your washer. You're dryer.

[00:23:25] And now they're being controlled by the utilities so that you don't run your wash at a certain time of day when they might need the electricity. Now I can see that, that, that kind of makes sense to me, but I think the best way to incentivize consumers is to do a pricing system that is variable. So if it's peak time, Hey, electricity is cheap.

[00:23:48] If you use it after 10:00 PM or whatever the right time is. And there are some utilities that are doing that, but there are states out there that are again, Democrat controlled. It seems to be the theme, doesn't it, where they are starting to mandate that you have smart appliances and that they be tied into a control system that ultimately the state can.

[00:24:19] So they know when you're washing your clothes, they know when you're ordering your grocer groceries, they know where they're coming from. Now, of course they can get some of that information. Like the groceries from credit cards, cuz most of us were paying for groceries. The credit cards aren't we. But ultimately what we're doing is opening up everything in our homes to external monitoring and potentially to control.

[00:24:44] And that's what's happening right now. It really is external. Control and that's what's happened in Denver where they had a heat wave and people went up to their thermostat to turn it down because man, it was hot and you know what I've had, I've had my temperature turned way up because I didn't wanna waste electricity, but it's really hot today.

[00:25:06] So I'm gonna turn it up and what. What happens. It says right there in the thermostat that you can't change it due to an energy emergency, California is going to mandate these types of smart thermostats that control how much heat you get in the winter and how much cooling you get in the summer. They're also starting to require that your washing machine and dryer, particularly electric dryers are also controlled by this.

[00:25:38] See, it all goes back to what I was talking about before. If you are a power grid. What are you gonna do? Is it better for you to just increase prices or is it better for you to build new sources of electricity? And as I mentioned before, I went through all of this in detail. It's usually much better for you to just go ahead and increase your prices.

[00:26:02] You'll make more money. You don't have that money at risk because man, somebody might pass a law, a rule, a regulation, heck some dictator might sign an executive order cutting off your supply. Right. Might be Putin might be somebody else. You never know. So instead of relying so heavily on things such as our natural gas supply, which president Biden effectively shut down some of the exploration for natural gas because he shut down fracking.

[00:26:35] Uh, we are now burning natural gas to produce electricity. So what happens? Electric prices while in New Hampshire, they doubled doubled from one month to the next. The price of electricity. Now your bill wouldn't have doubled because there's also the delivery costs and other things that are involved, but the price of electricity itself doubled, we've got to get smart about this stuff.

[00:27:03] So I'm, I'm gonna go to another one. We mentioned, and this was in the newsletter that came out. Um, you can find that, uh, on the newsletter subscription online at Craig peterson.com/subscribe, but here's another problem we got California is requiring electric vehicles. By 2035, they want half or not half.

[00:27:30] Excuse me. They want all of the vehicles sold in California. All of them to be electric, no more internal combustion engines in California, at least new cars, right? No, probably be, uh, the gas cars for quite a while. So let's look at this. The federal government wants us to be driving electric cars, all of the car companies, making electric cars.

[00:27:54] Are they making them cuz people want them are demanding them? No. They're not look at the number of cars sold. Look at how some of these electric car lines have been shut down. Nissan Nissan closed one of their cars off a GM closed one of their cars off, right? These electric cars don't make sense, but if you are going to stay in business and you're going to get an executive order or a law coming down from Congress.

[00:28:22] And that law says you're gonna have to produce electric vehicles. You're gonna do it. It's just like the cafe standards. Yeah. Hey, listen, your whole fleet. In other words, all of the cars that you sell, sell half to meet these standards for fuel economy across the board. So what are you gonna do? How are you gonna deal with that?

[00:28:41] Well, you're gonna make the cars less safe by taking some of this deal out of. You're gonna make them less safe because you want to make them lighter. You're gonna get rid of that really great spare tire that was in the back, and you can replace it with one of those stupid little space saver, saver tires, right?

[00:28:57] All, to save weight, all, to meet federal regulations on the mileage the vehicles have to meet. Now, when we're looking at the electricity, we've already established that we don't have the electrical supply to power. These cars. We Don. We don't, we're already having brownouts in the summer and in the winter, in different parts of the country.

[00:29:22] Well, let's also talk about one more thing and that is okay. So how are we gonna charge the cars? And obviously getting the electricity is a very big deal. And there was a new nuclear plant license that finally went through. It started the application process. Back at the pretty much the beginning of the Trump administration and was signed off by the Biden administration for one of these new nuclear plant.

[00:29:53] And the nuclear plant is by the way, intrinsically safe. It's made enough. Factory. It's not custom made on site, whole new world. And then how are we gonna charge the cars? That's another problem. it hasn't been addressed yet. So we'll get into all of that stick around. Of course, listening to Craig Peterson, you can sign up and find out more.

[00:30:19] Craig peterson.com.

[00:30:21] So, how are we going to charge the mall? man, this is gonna be a problem. We're gonna get into that right now. Uh, again, man talking about the cart before the horse, what's the matter with these people? It's crazy.

[00:30:38] You know, I am all for electric cars. I think they are cool.

[00:30:43] Very neat. But they are not green. Okay. Don't fool yourself. They are not green. The manufacturing of the batteries where they're mining, how they're. Processing it we're just outsourcing the pollution to third world countries, making people there sick. Right. Why, why bother you? You remember the Olympics that were held in Beijing and how the air was just so nasty people were wearing face masks?

[00:31:14] Uh, not because of worried about. Disease. They were worried about the particulate matter in the air. So what China did is they shut down all manufacturing. For well over a hundred miles so that the Beijing Olympics would not look like what it normally looks like in that area, which is just horrific, almost unbreathable air, same thing with the water.

[00:31:45] You look at the plastic in our oceans, which people are complaining about. And I get it. I don't want microplastics in me and I certainly don't want that little kid to shove a straw up my nose. Like he did the turtle, but that's really what we're looking at here. We're outsourcing our pollution elsewhere and that pollution.

[00:32:08] Ends up here. It ends up in our aquifers. It ends up in the oceans, obviously. Right. And in the air, which blows around the globe. And some of it settles down to the earth and that gets washed away by the rains and then ends up in all kinds of nasty places. So don't, don't let them convince you that electric cars are.

[00:32:33] they are cool. They're wonderful. They're really neat. They're fast. Uh, we should talk again, some point about the autonomous systems I've been driving, Ford's latest, uh, you know, semi-autonomous system. And we can talk about that. What I like and don't like about those things, but, uh, when we're talking about the electric cars, I, I love what my daughter said.

[00:32:57] Who's living in Norway. They have a Tesla. Uh, I think it's a. What is it? Model three, I think. And they're driving in Norway. Now in Norway, you get a, a 25% price, uh, difference, um, buying electric versus gas. The government gives you 25% off because this tax free and the sales tax is 25%. Can you believe that?

[00:33:21] Right? Oh, but things are cheap. Yeah. Yeah. Yeah. Anyways. What they are saying. Cause I asked my daughter, I said, now, you know, that Tesla is not green. Right. And she said, yeah. And I said, well, how about people in Norway? What are they thinking? Why are they buying it? Why is Norway the most, uh, populated electric vehicle country in the world?

[00:33:46] Per capita, they have more electric cars than any other country. Well, the main reason for that is because of the massive tax incentives, but the other side of that coin here, frankly, is the, how Norway wants to stay green. They wanna be, have fresh air. They wanna be living in a clean environment. And so what she told me was that Norwegian realizes.

[00:34:11] You know, not everybody obviously, but, um, that these cars, these electric cars are not green. They are hard on the environment, but not the environment in nor. Talking about being closed minded. Right? Very narrow minded. All that matters is that we're not polluting Norway by driving those cars. Now, ultimately they may be because in most parts of the world, the electric cars, batteries are being put in storage facilities or are ending up in waste.

[00:34:45] Piles, uh, around the world. It it's really kind of crazy because most of them cannot be recycled. Now there's some work on that right now. Tesla's doing some amazing stuff with changing the battery, not just the chemistry, but it's makeup and in the car. And they think they're gonna be able to have a car out that gets 650 miles, 6, 5 0 on a charge.

[00:35:08] Which is pretty darn cool by changing a whole bunch of stuff. In fact, the batteries become a structural, uh, component of the vehicle. So that's really kind of cool. But if we have all of these electric cars on the road, whether they're polluting or not, how do we charge these things? We've got the problem of how do we generate enough electricity and.

[00:35:33] Again, you've been listening to me long enough, you know, nuclear, nuclear nuclear are the three best options because we need power that's on. When the sun's set, we need power that's on. When the wind isn't blowing, we need power in the Northern realms of Alaska. We need power everywhere. So I really like these new intrinsically safe nuclear plants.

[00:36:00] Germany is turning them back on earlier. I talked about how California has now extended the life on this nuclear plant. They were gonna shut down just so they can keep electricity up. And yet we're talking about millions, more of these electric cars on the. So, what does that mean? Well, it also means that we need to spend 35 billion to meet the demand for an additional 1.2 million public charging stations by 2030.

[00:36:36] And that's not counting the 28 million that are needed in people's home. So the us needs to build 30 million EV charging parts. So let's do the math. Now. We're not gonna do the math up to 2035, which is the Dday for California. Let's do the math to 2030. Okay. The math for up to 2030 means that they need to be installing 478.

[00:37:08] Charging stations per day for the next eight years. And that's of half the drivers switched to electric. I don't think that's gonna happen that quickly, but it is eventually going to happen. So right now we have about 128,000 public electric vehicle charging outlets. And I've shared some articles in the past talking about how so many of them don't work.

[00:37:34] They won't work with your car or, or just plain broken. Uh, there's a lot of those out there. So 128,000 public and at least 4,500 private ones currently in comparison with 150,000 gas stations. Okay. So, although EV sales have climbed a lot each year since 2016, most consumers like myself are really concerned about the batteries.

[00:38:01] How long will they last? How far will they go? And then how long does it take to charge? Where can I charge them? Right. It's uh, very, very big deal. So that's a huge number. Isn't it. Now. And then, then we're talking about putting charging ports into our homes. and you probably have to get an electrician to come into your home to hook up a charging port to charge up your car.

[00:38:27] Right? So it's an interesting set of problems. So when I talked about having the cart before the horse, the obvious problem here is we're pushing electric vehicles and pushing. All out really heavily, the tax incentives have changed recently due to this, this, uh, inflation and increasing act. Right.

[00:38:57] Reduction. I Ugh, crazy. But anyways, I. We are seeing more and more of these vehicles. Some manufacturers such as Tesla are losing their, the federal, uh, chip in other manufacturers like for GM and others, uh, have gone ahead and raised their prices to match or exceed the amount of money that federal government's chipping in.

[00:39:23] Oh boy, I hate it. When that happens, goes down the wrong way. Where are we gonna end up? How is this going to happen? Um, we've got the car before the horse was pushing these cars. The car manufacturers have said, oh, wait a minute. There's gonna be a $5,000, uh, chip in by the federal government, by the taxpayers.

[00:39:44] Yeah. By the, you know, the widows, the people who are working really hard, driving the trucks and everything. Yeah. Those loose guys are gonna pay for electric cars, which by the way, vast majority electric car owners are our wealthy people. Thank you very much. Well, have the poverty line. So we're gonna take money from people at, or below the poverty line and give it to those people.

[00:40:04] And uh, $5,000. No problem. So what do the automakers do? They went ahead and raised their prices by at least the amount of money that the federal government said that they were going to chip in. Is that a surprise to anybody? It shouldn't be it. It's kind of like the student loan problems. Right? Why is tuition so expensive?

[00:40:28] Well, let me see. Government is making it possible for people to borrow more money, to go to college. Government's giving the. Pell grants and others for people to go to college. Uh, they're letting you pay it off over your lifetime. Yeah. It's the same sort of thing. So those, those benefits of thousands of dollars that are in this new bill that was passed, that are there to help you buy electric vehicles won't matter because they have raised their prices of the cars.

[00:41:03] At or above the amount of money the government's going to contribute yet you and me are going to contribute, you know, the small business people that, um, you know, readers, digested a survey of small business people and found out we only have to work a half a day. Did you know that only a half a day? And it doesn't really matter which 12 hours you work, which is true.

[00:41:23] Right. I've had like two vacations in, in my whole adult life. That's it because I care about my customers. Right. I try and make sure everything's going fine for them. So we get to pay for these electric cars they're being bought by people who are in the highest levels of, uh, income in the country. It's absolutely crazy, absolutely crazy.

[00:41:52] And we only have to build about 500 charging stations a day. So there you go. And then, you know, there's this minor problem of the electricity, where's it gonna come from? But you know, don't worry about that. Right? Cuz Bernie natural gas, that's the way to do it. And natural gas prices have gone up, which means electric prices have gone up just like I mentioned before.

[00:42:15] Hey, you know, it, it is probably time to do an upgrade on that computer of yours for windows 11, or maybe you're gonna move over to the Linux world. That's what I did with my older computer, frankly. I it's Linux now much faster, but there's more to it.

[00:42:31] Hey, I send out my newsletter, my insider show notes every Monday morning.

[00:42:37] Usually sometimes it's Tuesday, sometimes it's Wednesday depends on the week. This week I was at a client's site over the weekend, actually, and Monday and Tuesday down in Atlanta. So I, I was busy down there. This is a DOD subcontractor. They just. Parts, but they are required by CMMC these new regulations I've actually been around for a while now to really keep an eye on their cybersecurity.

[00:43:06] And so of course they bring me in and my team cuz you know, that's what we do. But I told you that because of my newsletter this week, I got some comments from a few people that the cybersecurity section in my newsletter was. Two articles from 2015 and , they both pointed it out. I think it's great that everybody's paying that much attention.

[00:43:32] I actually, there's a few people that notice that, and it was my fault for not explaining what I was trying to do. And, and that's because I was in a hotel room and I was getting ready to go to the client site and do. Dates fix a couple of things, check the seals on computers and you know, all of those sorts of maintenance things you have to do clean them out.

[00:43:53] I brought down a, a little blower and stuff. They, they were amazingly clean cuz we put them in a special cabinet that has these big air filters on them and stuff. Anyhow. The two articles this week on cybersecurity in my newsletter. Well, this was even in the free newsletter, talked about two different things.

[00:44:12] Lenovo was installing software and laptops, and they apparently have still kind of done that. This was some years ago. like, uh, seven years ago now, I guess. And they were putting it on there and you had no control over it. Okay. It was a real problem. And then the other one was. About your hard drives and what NSA did for years in modifying the firmware on the hard disk drives of a number of computers, many computers out there.

[00:44:48] And in both cases, Lenovo and the NSA, their national security agency. Put software on the computers so that even if you erased your computers, you would still have their software on it. They would reinstall itself. And Lenovo has been caught again, doing that. Okay. So there there's articles out there talking about.

[00:45:13] Just all of the stuff they've been doing. So here's what I want propose to you guys. And I did not make this clear in the newsletter. And for that, I apologize. I was in a hurry and that was my intention and it just had never happened. Not, but not being in a hurry was my intention. But I, I, I intended to explain this a little bit better and I did on the radio a little bit this week as well.

[00:45:37] And I'm doing it right now. My intention is to let you know that for decades now, bad guys have been able to embed malware into parts of your computer. So instead of just the operating system where they might have re. Placed some sort of a library file. And now when your machine boots up, it's going to pull it in from that library file or one of the many other ways, uh, they, they will go beneath your operating system.

[00:46:12] So they'll put things in the boot blocks of your computer and. As we just mentioned here, they will put things in the hard drive itself, not on the blocks of the hard drive, but in the controller of the hard drive right there on the hard drive's board motherboard, if you will, for the hard drive and they can make it persistent.

[00:46:37] now we've tried to get around some of these problems. Apple came up with the T two chip and what the T two chip does is really lock things down on your apple computer. And that's always a good thing, right? And the apple T two chip keeps track of. Passwords and makes things bootable and everything else.

[00:46:59] And apple has also really kind of spun things out a little bit here with their T2 chip. They had some security problems. Uh they're in all of the newer apple computers. In fact, the one I use a lot is an older computer that doesn't have that T2 chip in it, but what Microsoft has done now, and this isn't really Microsoft, it's really the hardware vendors.

[00:47:25] They have something called a TP. And this TPM is there for security. It's the trusted platform module. You want the version two or better, uh, as they come out, right. Kind of keep it up to date. But the T2, this trusted platform module is kind of like the apple two chip. It is nowhere near as. Complete, if you will, as the apple T two chip is, and it's designed primarily for booting your computer, which is really kind of cool.

[00:48:03] There's a cute article over on medium. And it's saying that the author's, uh, professor bill Buchanan. The author of this article says, uh, the TPM chip in your computer is perhaps a forgotten device. It often sits there not doing much and never quite achieving its full potential. You bought the laptop because it had one, but you just can't find a use for it.

[00:48:25] The chip itself is rather jealous of the apple TTU chip and which does so much more and where people actually buy the computer for the things it bring. Few people actually buy a computer, cuz it has a TPM, but lots of people buy a MacBook and an iPhone because it is trusted to look after your sensitive data.

[00:48:45] And he's absolutely right about that stuff. Now I've got clients who have been buying servers and other computers and the T2 chip has been. Option for them. I think that's probably almost gone nowadays. It is probably added in by default. These things are pretty cheap, cuz again, they don't really do much, but they are now a part of it because of what Microsoft has done.

[00:49:14] Microsoft has made it so that you pretty much have to have one of. T2 chip or TPM chips, I should say the TPM 2.0 cuz you know, it's gotta be as good as apples T2 the TPM 2.0, which is a crypto processor so that you can run windows 11. Now, I don't want you to think that having this TPM chip in your computer, all of a sudden makes it.

[00:49:40] But it does do a few things that are very, very good. First of all, it has a random number generator, which is super important when we're talking about encrypt. And that random number generator is used to generate keys that are used for your disc encryption and potentially other things. So if you are encrypting the disc on your windows machine, you are really moving ahead in a very big way, because now if your computer is stolen and it boots up, they won't be able to.

[00:50:13] at any of that data, it'll all look like random trash. If it's done its job. Right. And it can also of course store the user's password in the chip. It has some what's called persistent memory. I told you all of the stuff cuz of what I want to tell you next. All of this stuff from Lenovo, from the NSA over the years.

[00:50:36] And, and of course the bad guys, whether it's Russia, China, it can be really anywhere. North. Korea's been big on this. Iran's been doing this sort of thing. All of those guys may well have had access to your computer in the past. If you have an older computer. And because some of this software, some of this malware is persistent.

[00:51:00] And because windows now is, as I said, pretty much requiring one of these TPM chips, the TPM 2.0 or better is what you want. I think that it's time to seriously consider buying a new windows computer. Now we're working with a client right now that has an engineer who has been continually upgrading his windows computer since I don't know, windows XP days, I think.

[00:51:29] And every time he gets a new computer, he just goes ahead and migrates everything over. Doesn't upgrade. Doesn't update to the newest operating system. And for him, anyways, life is good. Well, it ain't so good folks because he has all kinds of nastiness, little turds. If you will, that are hiding all around his computer.

[00:51:54] The registry is going to be scattered with these things. Some of them probably installed by some form of malware over the years, his disc is gonna be cluttered, everything. So I'm saying right now, Get a new computer and go ahead and make sure you reinstall windows. That's the first thing we do. In fact, what we do for our clients.

[00:52:17] We have a version of windows that we have updated stream updated and. We don't have any of that bloatware on it, that the manufacturers get their 10 bucks from the various of vendors, you know, to put the Norton antivirus and all this other useless stuff on your computer. So by reinstalling, just the windows.

[00:52:40] And of course, since its windows, you go to install all of the drivers for your computer, too. But by doing that, you're getting rid of all of the bloatware. And then what you wanna do is either copy or restore your files onto the new computer. And then when you're done with that install, Your applications, the newest versions of your applications.

[00:53:05] And I can hear people right now complaining, cuz I hear this all of the time. My gosh, I've had that application for 10 years and you can't even get it anymore. Blah blah. You know what? You should not be using that application. You need to get the newest version or if that vendor's out of. You need to make sure that you go one more step, find a compatible vendor or whatever.

[00:53:29] We have to stop using old computers and old software. Uh, there's options here, but seriously, consider this because of what's been happening to us for years. Hey, visit me online. Sign up for my newsletter, Craig Peter son.com.

[00:53:48] Well, autonomous cars are on the road and there was an accident in Germany. We don't have all of the details yet, but it's really concerning. And it's about the anonymous cars. Yeah. Autonomous cars. And, uh, we gotta study out. I want to talk about as well.

[00:54:05] There are various levels of autonomy, I guess. Yeah.

[00:54:09] That's the right word in these autonomous vehicles that we have and that we're looking forward to level one is kind of the gold standard, right? That's where we want to get. That's where the cars don't even need a churn wheel pedals, your tension, nothing. They just drive themselves. We're not there. And you probably guess that.

[00:54:32] and then there's level two where you're the driver's supposed to pay attention, but the car's pretty much going to drive itself. Well, there is an article here from the associated press talking about what happened in Germany. And, uh, this is a, a few weeks back, and this is the first time I've seen this article, but they're saying that a test car with autonomous steering capability veered into oncoming traffic in Germany, killing one person and seriously injuring nine others.

[00:55:10] A spokesman for police in the Southwestern town of Rogen said the electric BMW. Nine with five people on board, including a young child swerved out of its lane at abandoned the road. Triggering a series of collisions involving four vehicles after brushing an oncoming search, the BMW hit a Mercedes van.

[00:55:37] Head on resulting in the death of a 33 year old passenger in that vehicle, the 70 year old driver, the Sitan lost control of her car and crashed into another vehicle with two people on board, pushing it off the road and causing it to burst into flame. Ruly again, police spokesman. Michael Shaw said four rescue helicopters, and dozens of firefighters responded to the incident and the injured were taken to several hospitals in the region.

[00:56:11] They included the 43 year old driver of the BMW three adults aged 31 42 and 47 and an 18 month old child who are all in the test. The article goes on, uh, is the police said in a statement, the crash vehicle was an autonomous electric test car, whether it was being steered by the 43, 3 year old driver or not is a subject of investigation.

[00:56:40] So this is called a level two driving assistance system. It's already incorporated in production vehicles today. They can support the driver on when the driver turns them on according to BMW with the level two vehicles, the driver always retains responsibility. In other words, if that car gets into.

[00:57:04] Accident while you are behind the wheel and responsible for it, it's your fault. So that solves the problem of whose insurance covers what doesn't it? Yeah, it, it does it pretty well because it's your fault is kind of the bottom line. So we are in the process of investigating the exact circumstances of the crash.

[00:57:25] BMW said, of course we are in close contact with the authorities. It's it's concerning very concerning and I am not ready yet. Autonomous vehicles. Now we've seen, and we've talked about on the show before a number of problems with some of these different vehicles from Tesla and others, and they are on the roads in many states right now, even in the Northeast, not just the Teslas, but these fully autonomous test vehicles.

[00:57:59] There are a number of things to be concerned about here. For instance, how can an autonomous vehicle determine what to do when there's a police officer in the middle of the road or a flagman? Or obviously it really can't determine it because it can't make out. What's what, in fact we might remember, and I'm sure they've made some adjustments here over at Tesla, but a Tesla car went ahead and, uh, struck and I think killed a lady who was crossing the road with her bicycle.

[00:58:36] I think she was walking it across when she was hit. How can they tell, how can they tell the difference between a car that's wrapped and has someone's face on it, maybe a politician full body on the back of a box truck as an advertisement. How can it tell the difference between that and a person that might be standing there?

[00:59:00] It, it gets to be a real problem. We're already seeing that some of these autonomous vehicles go directly rear end fire trucks stopped at the side of the road with their lights on police cars stopped at the side of the road with the lights on. Just completely rear-end them. We're seeing that. So how about when it gets a little more difficult than a fire truck parked on the side of the road?

[00:59:25] Now these cars, apparently autonomous steering and, uh, lane detection and correction, all that sort of stuff. These vehicles are looking at things and trying to determine, well, what should I do here? And oftentimes what they determine is, oh, well, okay. That's just something that's fixed at the side of the road.

[00:59:45] Like, like a sign post, like a speed sign. When in fact it's not. So we've gotta solve that problem. It, it still isn't solved yet. What caused this car to steer directly into oncoming traffic and, and head first into a Mercedes van? I, I don't know. They don't know yet. Anyways. I'm sure they'll find out soon enough, but there are real questions here and then I wanna take it to the next levels.

[01:00:18] If the car is in, let's say level one where it's full autonomous, even if it's not, even if it's a level two, like this car was, or is, uh, what happens when the car is either going to hit a pedestrian or go over a cliff or into a brick wall? That's even better. Cuz the car might not know the cliff is there.

[01:00:43] What decision should the car make? What kind of ethics should it be? You know, executing here, can it even make an ethical decision? And this is the trolley testing in case you're not familiar with the whole trolley test thing. It's, let's say you are. A trolley operator, you're going down a hill and there is a fork in the tracks.

[01:01:09] And all you can do is select tracks at a or track set B you can't stop the trolley. You can't slow the trolley down in tracks at a there's a group of seniors walking across the tracks that you will hit. If you go down tracks at a tracks at B. There's some young kids playing on the tracks and if you choose B, you're gonna kill the kids.

[01:01:35] So ethical dilemma here, who do you kill? Cuz that's what the whole trolley test is about. Look it up online. There's a lot of different variations of this, but what about the car? What decision should the car make? Should the car make the decision to protect you the driver, or should the car be making the decision to protect the pedestrian?

[01:01:59] If it's going to protect the pedestrian by plowing into that brick wall and potentially killing the occupants of the car. How about when there is the decision of the old people or the young people? There is a lot to solve here. And some of these companies, including Mercedes have come out already with their decisions, Mercedes said they will protect the occupants of the vehicle.

[01:02:27] now when you're driving the car yourself, of course, you're making that decision in a, a split second, maybe something you thought about, maybe not, you might make a rational decision. You might not. It's, you know, it's hard to say. And you'll find these articles in my newsletter this week at, uh, Craig peterson.com.

[01:02:49] If you're not on the newsletter list, you can sign up. It's absolutely free. This is the free newsletter and you can see all my insiders show notes every week, but it's an issue. Isn't it. The car veering into traffic hitting another one head first. How about later on when it's completely autonomous, what should it do?

[01:03:14] By now you've seen one of these new cars with that big screen right there in the center of the console. I've got a few problems with this, more than a few problems with you people, right. To quote Seinfeld. Yeah. Let's talk about it.

[01:03:31] You know, it, it's very cool to have that display in the center of the car console.

[01:03:36] One of the major reasons that the automotive manufacturers are putting that console right there in the center is because we are demanding, uh, the apple car play the Android car functions in order to have. Really cool stuff, right. Where we can just run our apps and have all of this, uh, wonderful information.

[01:04:02] What I really like about it and Android auto and, uh, the apple car both provide this. What I really like is you can use the navigation system that you prefer, that you like, that you want that's in your. I have switched over to apple maps. Now I used to use ways. And before that I would use Google maps and way before that map question and others, my wife could tell you some stories of us trying to use some of the very first generation GPS stuff, having a, a lap.

[01:04:38] Top in the car and then having a hockey puck up on the dashboard to try and pick up at least three satellites. And, and, uh, if you went off course at all, went the wrong way, took the wrong. it would just insist on bringing you back to where you were when you went off course, as opposed to taking you from where you are, to where you want to go, which they do nowadays.

[01:05:01] But I like that. Right. And, and I like the new features that are always coming out in these apps that we run on our smartphone. I do not like the fact that the cars have navigation in them. Eh, some of them are pretty cool. They're nice. Like in our car, if you use the incar navigation, it mutes the music or the radio, whatever is playing on the driver's side speaker there in the front of the car.

[01:05:32] And then it gives the driver the direction. So everyone else can just keep listening to whatever they were listening to before on the radio, et. You I'll need features like that. But what I don't like is they wanna get six or 800 bucks out of us in order to get new maps in order to get new software for the mapping system.

[01:05:53] When we can get things like apple maps for free. Where they're not even using our data against us, like Google does right Android. Uh, very, very nice. I, I really like them. And the apple maps now is really good. I don't know if you remember how bad it was when it first came out, but Steve jobs brought all of the mapping, senior management into a room and asked them what happened.

[01:06:20] Why is it so bad? You might remember that it took some people in Australia. Way off the beaten track out in the middle of nowhere with no water, with no fuel and they could have died out there, you know, Australia, everything's out to kill you and they might well have died and they didn't, which is good news.

[01:06:42] But even in the us, it was just messing up. It wasn't very good. Wasn't taking it always to the right place. And certainly not the best route. Now it's just gotten amazingly good. Very, very good. So I can choose, right. If I still want to use ways I can use it. If I wanna use apple, I can use it. Google maps. I can use it some third party.

[01:07:01] I can use it, but if I've got the stuff that's built into the car, I'm stuck with the stuff that's built into the car, and maybe I can pay to upgrade it. A lot of people have found recently, Hey, guess what? That two G data network went. and that means now that your remote control for your card doesn't work anymore, you might have found your navigation doesn't work anymore.

[01:07:28] I remember I had a Garmin that got live traffic updates, but it was using FM carriers on FM radio stations. And many of them dumped that. guess what your garment's no good anymore. At least that part of it isn't any good and garment charging for map updates. And I don't blame 'em for this stuff. Right.

[01:07:48] But I would prefer to have my own device to use. So that's part of the problem. In fact, that's indicative of what I see to be the very big problem with these new in car systems, because that display in the computer behind it. Isn't just handling your navigation. It's controlling your seat, heaters, the radio, the music you're listening to the lights, the dimming, the headlights, almost everything in the car goes through.

[01:08:23] Infotainment system, right? Yeah. Figured out where I'm going next, because that infotainment system just like the maps on my car right now is going to become out outdated. And then what are you gonna do? And when I say out outdated, I don't just mean, oh, well I want the new features. It might be that you want the new maps.

[01:08:48] Yeah. But what happens when it breaks? This leads us to a study that happened here. A Swedish publication had performed a test. They took 11 new cars alongside an older car, a Volvo C 70 from 2005. now that Volvo had buttons and knobs, buttons and knobs. I've always liked that. And those 11 new cars all had these wonderful infotainment systems, all in one touch screens in the center of the console, they tested this whole thing and they timed how long it took people to perform a li list of tasks in each car.

[01:09:35] So. Included things like turning on that seat, heater, turning up the temperature inside the car, the defrost, adjust the radio, reset the trip. Computer. Turn off the screen. Dim the instruments. The old Volvo was the clear winner. Yeah, indeed. So according to this article in ours, Technica, the four tasks were handled within 10 seconds flat using buttons and knobs in the Volvo.

[01:10:06] So in the amount of time it took them to do all of the tasks, the four tasks that they were given out of that selection here. I just read the car, drove a thousand feet at 68 miles per hour. Now most of these other cars with that wonderful infotainment system required twice as long or even more to complete those same.

[01:10:34] Tasks. So some 30 seconds. So you're talking about traveling two or 3000 feet while you're messing around with that display in the central console. Looks cool. Isn't this the neatest thing ever, but the problem is you have to hunt and Peck now, before you say, oh, well, Craig, these people weren't familiar with that console.

[01:10:58] Well, yeah. Okay. I'll give you that. But what they did with this test is. They let all of the participants play with the cars systems before they started the tests. In other words, they knew the menus, they knew where things were and it still took that time. You see what we're really talking about here is muscle memory, the ability for your car or for you to know your.

[01:11:29] so you can reach out and you can turn that volume knob. You might have to glance real quick to make sure you got the volume knob, but you don't have to hunt and Peck through menus. I like that. So as you can tell, I am not all that hot on these new, all touch interfaces. BMW has an interesting solution to this and that is that I drive system that little knob people didn't like it at first, but you get used to it, right?

[01:12:00] So, you know, if you need to turn on their seat heater, you just press a knob up, up right down. And then TA your seat heater and you get to adjust it right there. That is muscle memory as well. So we've got some work to do here. Uh, there are some decent systems out there in Acura, MDX Mazda, CX 50, neither one of them uses a touchscreen infiltration inform attainment system.

[01:12:29] So that's good. We'll see how it all goes. Make sure you're on my newsletter. So you can read this article and more. Craig peterson.com.

[01:12:39] We've had a chip shortage. I'm sure you've heard of it. And it's been a real problem for everybody from car manufacturers through PC makers. Well, now we're seeing a sudden downturn what's happening now. The Congress has funded it.

[01:12:56] Hey, surprisingly enough. Congress comes along to fix the chip problem with the chip bill, billions of dollars, tens of billions actually being spent on our chip plants here to help the chip industry make more chips, cuz we need chips, chips, chips, right?

[01:13:16] Well, ArsTechnica has a great little article. They're actually taking it from the financial time searched waters. Uh, I subscribe the furniture times for quite a while, but I don't anymore. And they're talking about how we went from a boom economy when it came to chips, these microchips, everything from, uh, Intel corporation out through the manufacturers of some of these much more common chip styles nowadays, the arm chips and how this new.

[01:13:51] That's supposed to, uh, boost production is coming at a point where, okay, first of all, these manufacturers put billions of dollars into building new plants here in the us of a. So that's a good thing. And then Congress comes along sometime after the fact and gives him tens of billions more. And by the way, managed, and this apparently was Senator Chuck, Schumer's doing managed to remove a provision in the build that said that none of that money for chip plants could be spent in China.

[01:14:28] So yeah, there you go. China, you get billions more from us, potentially here as we build chip plants over there, but now what do we find out? Well, a bit of a turn here because there is now excess inventory. Dan Hutchinson, who is the chief executive V L S I research. Who's been really watching the whole chip cycle since 1980s came out and said, quote, I have never seen a time when we had excess inventory.

[01:14:59] And we had shortages. Okay. So the immediate cause of this is a rapid buildup and inventory in the chip supply chain since early the year 2022 here. So compared to February, there are enough chips on hand to support about a month and a half of production. Global inventory levels jumped. Even higher and then even higher in July to almost two months.

[01:15:26] So that's been an issue. And then on top of it, PC sales have been tumbling. Smartphone demand has dropped, and those have been the main causes as consumers are slowing their spending, why they slowing spending. Because they don't have the money they used to have because of the non inflation that's happening right now.

[01:15:48] So we've kind of got all of these things happening and to top it all off, as I said, they're taking tens of billions of dollars of our tax money and, uh, going to be spending it, all of this. It's just absolutely amazing. But the suddenness of this turn, again, according to the financial times has, was when in.

[01:16:08] Dun wall street with news that its revenue in the last quarter had fallen 2.6 billion, 15%, which of course was short of what they were expecting on wall street. There. This is really quite amazing. They took an inventory adjustment that only hits like once a decade and video man, they are about to, uh, to really get hit too.

[01:16:34] I don't, I don't think I talked about this. there's the largest maker of these GPS, these graphics, processing boards, and supplemental chips that are on motherboards. And a lot of computers used a lot in video graphics, machine learning, and of course, mining of cryptocurrencies, and they have seen it fall dramatically 44% fall in these GPU that have been used for gaming.

[01:17:06] And. Bitcoin and, and mining and, and other of these cryptocurrencies and micron, one of the largest makers of memory chip said it's free cash flow was likely to turn negative in the next three months after averaging $1 billion in recent quarters. Isn't that amazing? So all of these problems have been.

[01:17:29] Also throughout Asia last, uh, month here over the last month, the chief executive of Chinese ship maker, semiconductor manufacturing, international corporation, SM IC said that demand had slowed from smartphone and other consumer electronics makers. And some of these manufacturers, electronics makers have stopped orders.

[01:17:52] All together. So guess what happens when you do that? Think about what happened with the lockdown, right? That really spurred this whole thing on a month before Taiwan, semiconductor manufacturing company, TSMC, which is like the biggest guy out there for making many of the chips we depend upon said it was expecting an inventory correction that would last until.

[01:18:17] Next year. So this has been a very abrupt slide. Chip makers in the us are trying to manage this decline at the very moment. They're laying the ground for huge increase in production because of the. Tens of billions, they have spent plus the 52 billion bill that was signed into law here. What a month or two ago, uh, government support provided by the chips act.

[01:18:47] So on the same day that Congress passed the law, Intel expected to be the biggest beneficiary of all of these government grants of our tax dollars. Sliced 4 billion permits, capital spending plans for the rest of the. Now isn't that? What happens every time really? Isn't that? What happens every time? For instance, the, uh, build back better plan renamed the inflation causation actor, I think is what they might have called it.

[01:19:17] Um, that particular bill. Put money in for you to buy an electrical car electric car, like four grand, eight grand kind of depends, uh, across the board. So what do electronic electric car makers do? They increase their prices? Yes, indeed buy, you know, six or eight grand as much as 12 grand. Right? Because now we got government money.

[01:19:42] We don't have to have you. Pay for it. So we're gonna take a bigger profit and that profit's gonna come from the tax dollars that were taken from you and from me and from the widow down the. Right. Yeah. That's what happens every time? Why do we have this whole thing about the loans for people who went to college?

[01:20:03] Well, why is college so expensive? Well, it, it continued to go up as government started providing grants and started backing loans. Right? All of the stuff the government was doing was ultimately driving up the cost of your schooling. Now they've driven up the. Of electric cars because of the money they put in.

[01:20:26] And because of the money that they've put in for the chips act the 52 billion to make chips that, Hey, we got a glut right now. Yeah. Um, guess what? The manufacturers of chips, the companies that we're spending the money in order to create. Plants more plants, more chip factories, fabrication plants have decided they're gonna cut their spending.

[01:20:53] Why not? Because they're gonna get money from you at the point of a gun, right? Yeah. That's exactly what's happening. Oh man. So for now, again, according to the financial times, most chip supply chain experts predict a relatively shallow downturn provided that the global economy is headed first off landing something that's obviously not guaranteed, but it has really left them scrambling, trying to figure out what.

[01:21:23] Happened here because it just fell apart so quickly. Gartner group, you might know them. They put together a lot of studies on a lot of different industries had been expecting the growth in ship sales this year to have from 2020 ones, 26%. So it took its forecast down further to 7% and is now predicting a 2.5% contraction in 2023.

[01:21:52] Isn't that something, um, the, the Philadelphia semiconductor index, if you are an investor, you've heard of that before, and that comprises the 30 largest us companies involved in, in chip design, manufacturer and sale. Fell back almost 40% as a stock market corrected this year after rising threefold, after the early lockdown stock market slump, because people were working from home, they couldn't go in to work people.

[01:22:23] The kids were home, people were buying computers so they could play games or get on a video conference with the office, et cetera. It has really, really changed. And I mentioned Nvidia and how NVIDIA's been hurt pretty badly. And you'll find this article by the way, in my newsletter that went out on, um, Monday.

[01:22:45] And if you don't get my free newsletter, definitely get it to just up to date. Craig, Peter son.com/subscribe. It's it's all worth doing, but within NVI. Here's what's happening. One of the biggest cryptocurrencies out there has decided that they don't want to be part of this whole energy problem that we have.

[01:23:09] You know, some of these minors for various types of cryptocurrencies have actually bought power plants, old coal PLA powered power plants that the states don't wanna buy power from anymore because it's, it's. Right. Kohl's evil. But the private sector came in and said, okay, well, if we run our own power company and we put these GPU's and special purpose made mining equipment.

[01:23:38] Into the power plant. We can save a lot of money. That's how much power they need everybody, a whole power plant to run some of these mining operations. And remember the way you mine, the cryptocurrencies. In most cases, you have to solve very complex mathematical problems to prove that you did the. that was needed in order to then, um, be awarded that Bitcoin or whatever it was that you were mining.

[01:24:09] So pretty much all of the major cryptocurrencies are looking at how can we move away from this model? Because in, in some cases, you know, we're talking about electrical consumption, just for mining cryptocurrencies that serve passes, some countries entire need for electricity. That's how bad it is. And supposedly here, we've got one of the major cryptocurrencies that is changing the entire way you.

[01:24:44] Mining, if you will. Very, very big changes. So expect GPUs and companies like Nvidia that make them to go way down in value here over the coming months. Hey, visit me online. Craig peterson.com. Subscribe to my podcast and find me at YouTube. Take care.

View Details

It's Trash Time For Your Computer - Autonomous Car Crash Kills - Which is better for your car? Buttons or a Screen? - Now we have a Chip Backlog! - Facebook tracking Your Hospital Appointments

Hey, you know, it is probably time to do an upgrade on that computer of yours to Windows 11. Or maybe you're going to move over to the Linux world. That's what I did with my older computer. It's running Linux now. Much faster, but there's more to it than that.

[Automated transcript follows]

I send out my newsletter, my insider show notes every Monday morning.

[00:00:22] Usually sometimes it's Tuesday, sometimes it's Wednesday depends on the week. This week I was at a client site over the weekend, actually, and Monday and Tuesday. Down in Atlanta. So I, I was busy down there. This is a DOD subcontractor. They just ship parts, but they are required by CMMC these new regulations I've actually been around for a while now to really.

[00:00:49] Keep an eye on their cybersecurity. And so of course they bring me in and my team cuz you know, that's what we do. But I told you that because of my newsletter this week, I got some comments from a few people that the cybersecurity section in my newsletter was two articles from 2015. And , they both pointed it out.

[00:01:13] I think it's great that everybody's paying that much attention. I actually, there's a few people that notice that, and it was my fault for not explaining what I was trying to do. And, and that's because I was in a hotel room and I was getting ready to go to the client site and do. Dates fix a couple of things, check the seals on computers and you know, all of those sorts of maintenance things you have to do clean them out.

[00:01:38] I brought down a, a little blower and stuff. They, they were amazingly clean cuz we put them in a special cabinet that has these big air filters on them and stuff. Anyhow, the two articles this week on cybersecurity in my newsletter. Well, this is even in the free newsletter. Talked about two different things.

[00:01:57] Lenovo was installing software and laptops and they apparently have still kind of done that. This was some years ago, like how seven years ago now, I guess. And they were putting it on there and you had no control over it. Okay. It was a real problem. And then the other one was. About your hard drives and what NSA did for years in modifying the firmware on the hard disk drives of a number of computers, many computers out there.

[00:02:32] And in both cases, Lenovo and the NSA, the national security agency put software on the computers so that even if you erased your computers, you would still. Have their software on it, they would reinstall itself and Lenovo has been caught again, doing that. Okay. So there there's articles out there talking about just all of the stuff they've been doing.

[00:03:00] So here's what I want to propose to you guys. And I did not make. This clear in the newsletter. And for that, I apologize, I was in a hurry and that was my intention and it just had never happened. Not, but not being in a hurry was my intention. But I, I, I intended to explain this a little bit better and I did on the radio a little bit this week as well.

[00:03:22] And I'm doing it right now. My intention is to let you know that for decades now, bad guys have been able to embed malware into parts of your computer. So instead of just the operating system where they might have a. Replaced some sort of a library file. And now when your machine boots up, it's going to pull it in from that library file or one of the many other ways, uh, they, they will go beneath your operating system.

[00:03:57] So they'll put things in the boot blocks of your computer. And as we just mentioned here, they will put things in the hard drive itself, not on the blocks of the hard drive, but in the control. Of the hard drive right there on the hard drive's board motherboard, if you will, for the hard drive and they can make it persistent.

[00:04:21] Now we've tried to get around some of these problems. Apple came up with the T2 chip and what the T2 chip does is really lock things down on your apple. And that's always a good thing, right? And the apple TTU chip keeps track of passwords and makes things bootable and everything else. And apple has also really kind of spun things out a little bit here with their TTU chip.

[00:04:51] They had some security problems. Uh they're in all of the newer apple computers. In fact, the one I use a lot is an older computer that doesn't. That T2 chip in it, but what Microsoft has done now, and this isn't really Microsoft, it's really the hardware vendors. They have something called a TP. And this TPM is there for security.

[00:05:16] It's the trusted platform module. You want the version two or better, uh, as they come out, right. Kind of keep it up to date. But the T2, this trusted platform module is kind of like the apple T2 chip. It is nowhere near as. Complete, if you will, as the apple T two chip is, and it's designed primarily for booting your computer, which is really kind of cool.

[00:05:47] There's a cute article over a medium. And it's saying that the authors of professor bill Buchanan, the author of this article says, uh, the TPM chip in your computer is perhaps a forgotten device. It often sits there not doing much and never quite achieving its full potential. You bought the laptop because it had one, but you just can't find a use for it.

[00:06:09] The chip itself is rather jealous of the applet two chip and which does so much more and where people actually buy the computer for the things it bring. Few people actually buy a computer, cuz it has a TPM, but lots of people buy a MacBook and an iPhone because it is trusted to look after your sensitive data.

[00:06:29] And he's absolutely right about that stuff. Now I've got clients who have been buying servers and other computers and the T2 chip has been. Option for them. I think that's probably almost gone nowadays. It is probably added in by default. These things are pretty cheap, cuz again, they don't really do much, but they are now a part of it because of what Microsoft has done.

[00:06:58] Microsoft has made it so that you pretty much have to have one of. T2 chip or TPM chips, I should say the TPM 2.0 cuz you know, it's gotta be as good as apples T2 the TPM 2.0, which is a crypto processor so that you can run windows 11. Now, I don't want you to think that having this TPM chip in your computer, all of a sudden makes it safe, but it does do a few things that are very, very.

[00:07:28] First of all, it has a random number generator, which is super important when we're talking about encrypt. And that random number generator is used to generate keys that are used for your disc encryption and potentially other things. So if you are encrypting the disc on your windows machine, you are really moving ahead in a very big way, because now if your computer is stolen and it boots up, they won't be able.

[00:07:57] At any of that data, it'll all look like random trash. If it's done its job. Right. And it can also of course store the user's password in the chip. It has some what's called persistent memory. I told you all of the stuff because of what I want to tell you next. All of this stuff from Lenovo, from the NSA over the years.

[00:08:20] And, and of course the bad guys, whether it's Russia, China, it can be really anywhere. North. Korea's been big on this. Iran's been doing this sort of thing. Uh, All of those guys may well have had access to your computer in the past, if you have an older computer. And because some of this software, some of this malware is persistent.

[00:08:44] And because windows now is, as I said, pretty much requiring one of these TPM chips, the TPM 2.0 were better is what you want. I think that it's time to seriously consider buying a new windows computer. Now we're working with a client right now that has an engineer who has been continually upgrading his windows computer since I don't know, windows XP days, I think.

[00:09:13] And every time he gets a new computer, he just goes ahead and migrates everything over. Doesn't upgrade. Doesn't update to the newest operating system. And for him, anyways, life is good. Well, it ain't so good folks because he has all kinds of nastiness, little turds. If you will, that are hiding all around his computer.

[00:09:37] The registry is going to be scattered with these things. Some of them probably installed by some form of malware over the years, his disc is gonna be cluttered, everything. So I'm saying right now, Get a new computer and go ahead and make sure you reinstall windows. That's the first thing we do. In fact, what we do for our clients.

[00:10:01] We have a version of windows that we have updated stream updated, and we don't have any of that bloatware on it. That the manufacturers get their 10 bucks from the various offenders, you know, to put the Norton antivirus and all this other useless stuff on your computer. So by reinstalling, just the windows.

[00:10:23] And of course, since it's windows, you gotta install all of the drivers for your computer, too. But by doing that, you're getting rid of all of the bloatware. And then what you wanna do is either copy or restore your files onto the new computer. And then when you're done with that install, Your applications, the newest versions of your applications.

[00:10:48] And I can hear people right now complaining, cuz I hear this all of the time. My gosh, I've had that application for 10 years and you can't even get it anymore. Blah blah. You know what? You should not be using that application. You need to get the newest version, or if that vendor's out of business, you need to make sure that you go one more step, find a compatible vendor or whatever.

[00:11:12] We have to stop using old computers and old software. Uh, there's options here, but seriously, consider this because of what's been happening to us for years. Hey, visit me online. Sign up for my newsletter, Craig Peter son.com.

[00:11:31] Well, autonomous cars are on the road and there was an accident in Germany. We don't have all of the details yet, but it's really concerning. And it's about the anonymous cars. Yeah. Autonomous cars. And, uh, we gotta study out. I want to talk about as well.

[00:11:48] There are various levels of autonomy, I guess. Yeah.

[00:11:53] That's the right word in these autonomous vehicles that we have and that we're looking forward to level one is kind of the gold standard, right? That's where we want to get. That's where the cars don't even need a churn pedals, your tension, nothing. They just drive themselves. We're not there. And you probably guess that.

[00:12:15] And then there's level two where you, the driver's supposed to pay attention, but the car's pretty much going to drive itself. Well, there is an article here from the associated press talking about what happened in Germany. And, uh, this is a few weeks back and this is the first time I've seen this article, but they're saying.

[00:12:41] Test car with autonomous steering capability, veered into oncoming traffic in Germany, killing one person and seriously injuring nine others. A spokesman for police in the Southwestern town of Roy. Again said the electric BMW. Nine with five people on board, including a young child swerved out of its lane at abandoned the road, triggering a series of collisions involving four vehicles after brushing an oncoming search, the BMW hit a Mercedes Benz's van head on resulting in the death of a 33 year old passenger in that.

[00:13:27] The 70 year old driver, the Cien lost control of her car and crashed into another vehicle with two people on board, pushing it off the road and causing it to burst into flame Ruly. Again, police spokesman, Michael Shaw said four rescue helicopters and dozens of firefighters. Responded to the incident and the injured were taken to several hospitals in the region.

[00:13:55] They included the 43 year old driver of the BMW three adults aged 31 42 and 47 and an 18 month old child who were all in the test vehicle. The article goes on, uh, is the police said in a statement, the crash vehicle was an autonomous electric test car, whether it was being steered by the 43, 3 year old driver or not is a subject of investigation.

[00:14:24] So this is called a level two driving assistance system. It's already incorporated in production vehicles today. They can support the driver on when the driver turns them on according to BMW with the level two vehicles, the driver. Always retains responsibility. In other words, if that car gets into an accident while you are behind the wheel and responsible for it, it's your fault.

[00:14:54] So that solves the problem of whose insurance covers what doesn't it? Yeah, it, it does it. Pretty well, because it's your fault is kind of the bottom line. So we are in the process of investigating the exact circumstances of the crash. BMW said, of course we are in close contact with the authorities. It's it's concerning very concerning and I am not ready yet.

[00:15:23] Autonomous vehicles. Now we've seen, and we've talked about on the show before a number of problems with some of these different vehicles from Tesla and others, and they are on the roads in many states right now, even in the Northeast, not just the Teslas, but these fully autonomous test vehicles. And.

[00:15:43] There are a number of things to be concerned about here. For instance, how can an autonomous vehicle determine what to do when there's a police officer in the middle of the road or a flagman? Or obviously it really can't determine it because it can't make out. What's what, in fact we might remember, and I'm sure they've made some adjustments here over at Tesla, but a Tesla car went ahead and, uh, struck and I think killed a lady who was crossing the road with her bicycle.

[00:16:20] I think she was walking it across when she was hit. So how can they. How can they tell the difference between a car that's wrapped and has someone's face on it, maybe a politician full body on the back of a box truck as an advertisement. How can it tell the difference between that and a person that might be standing there?

[00:16:44] It, it gets to be a real problem. We're already seeing that some of these autonomous vehicles go directly rear end fire trucks stopped at the side of the road with their lights on police cars stopped at the side of the road with the lights on just completely rear end them. We're seeing that. So how about when it gets a little more difficult than a fire truck parked on the side of the road?

[00:17:10] Now these cars, apparently autonomous steering and, uh, lane detection and correction, all that sort of stuff. These vehicles are looking at things and trying to determine, well, what should I do here? And oftentimes what they determine is, oh, well, okay. That's just something that's fixed at the side of the road.

[00:17:30] Like, like a sign post, like a speed sign. When in fact it's not. So we've gotta solve that problem. It, it still isn't solved yet. What caused this car to steer directly into oncoming traffic and, and head first into a Mercedes van? I, I don't know. They don't know yet. Anyways. I'm sure they'll find out soon enough.

[00:17:57] There are real questions here. And then I wanna take it to the next levels. If the car is in, let's say level one where it's full autonomous, even if it's not, even if it's a level two, like this car was, or is, uh, what happens when the car is either going to hit a pedestrian or go over a cliff or into a brick wall?

[00:18:23] That's even better. Cuz the car might not know the cliff is there. What decision should the car make? What kind of ethics should it be? You know, executing here. Can it even make an ethical decision? And this is the trolley testing in case you're not familiar with the whole trolley test thing. It's, let's say you are.

[00:18:47] A trolley operator, you're going down a hill and there is a fork in the tracks. And all you can do is select track set a or track set B you can't stop the trolley. You can't slow the trolley down in track. Set a there's a group of seniors walking across the tracks that you will hit. If you go down tracks at a tracks at B there's, some young kids playing on the.

[00:19:16] And if you choose B, you're gonna kill the kids. So ethical dilemma here, who do you kill? Cuz that's what the whole trolley test is about. Look it up online. There's a lot of different variations of this, but what about the car? What decision should the car make? Should the car make the decision to protect you the driver, or should the car be making the decision to protect the pedestrian?

[00:19:43] If it's going to protect the pedestrian by plowing into that brick wall and potentially killing the occupants of the car. How about when there is the decision of the old people or the young. There is a lot to solve here. And some of these companies, including Mercedes have come out already with their decisions, Mercedes said they will protect the occupants of the vehicle.

[00:20:11] now when you're driving the car yourself, of course, you're making that decision in a, a split second, maybe something you thought about, maybe not, you might make a rational decision. You might not. It's, you know, it's hard to say. And you'll find these articles in my newsletter this week at, uh, Craig peterson.com.

[00:20:32] If you're not on the newsletter list, you can sign up. It's absolutely free. This is the free newsletter and you can see all my insiders show notes every week. But it's an issue, isn't it? The car veering into traffic hitting another one head first. How about later on when it's completely autonomous, what should it do?

[00:20:58] By now you've seen one of these new cars with that big screen right there in the center of the console. I've got a few problems with this, more than a few problems with you people, right. To quote Seinfeld. Yeah. Let's talk about it.

[00:21:15] Right here, you know, it, it's very cool to have that display in the center of the car console.

[00:21:21] One of the major reasons that the automotive manufacturers are putting that console right there in the center is because we are demanding, uh, the apple car play the Android car functions in order to have some really cool stuff, right. Where we can just run our. And have all of this, uh, wonderful information.

[00:21:47] What I really like about it and Android auto and, uh, the apple car both provide this. What I really like is you can use the navigation system that you prefer, that you like, that you want that's in your. I have switched over to apple maps. Now I used to use ways. And before that I would use Google maps and way before that map quest and, and others, my wife could tell you some stories of us trying to use some of the very first generation GPS stuff, having a, a laptop in the car and then having.

[00:22:25] Keep pup on the dashboard to try and pick up at least three satellites. And, and, uh, if you went off course at all, went the wrong way, took the wrong. It would just insist on bringing you back to where you were when you went off course, as opposed to taking you from where you are, to where you want to go, which they do nowadays.

[00:22:47] But I like that. Right. And, and I like the new features that are always coming out in these apps that we run on our smartphone. I do not like the fact that the cars have navigation in them. Eh, some of them are pretty cool. They're nice. Like in our car, if you use the in-car navigation, it mutes the music or the radio, whatever is playing on the driver's side speaker there in the front of the car.

[00:23:17] And then it gives the driver the direction. So everyone else can just keep listening to whatever they were listening to before on the radio, et. You I'll need features like that. But what I don't like is they wanna get six or 800 bucks out of us in order to get new maps in order to get new software for the mapping system.

[00:23:38] When we can get things like apple maps for free. Where they're not even using our data against us, like Google does right Android. Uh, very, very nice. I, I really like them. And the apple maps now is really good. I don't know if you remember how bad it was when it first came out, but Steve jobs brought all of the mapping, senior management into a room and asked them what happened.

[00:24:05] Why is it so bad? You might remember that it took some people in Australia. Way off the beaten track out in the middle of nowhere with no water, with no fuel and they could have died out there, you know, Australia, everything's out to kill you and they might well have died and they didn't, which is good news.

[00:24:27] But even in the us, it was just messing up. It wasn't very good. Wasn't taking you always to the right place and certainly not the best route. Now it's just gotten amazingly good. Very, very good. So I can choose, right. If I still want to use ways I can use it. If I wanna use apple, I can use it. Google maps.

[00:24:45] I can use it some third party. I can use it, but if I've got the stuff that's built into the car, I'm stuck with the stuff that's built into the car, and maybe I can pay to upgrade it. A lot of people have found recently, Hey, guess what? That two G data network went. And that means now that your remote control for your card doesn't work anymore, you might have found your navigation doesn't work anymore.

[00:25:13] I remember I had a garment that got live traffic updates, but it was using FM carriers on FM radio stations. And many of them dumped that. guess what your garment's no good anymore. At least that part of it isn't any good and garment charging for map updates. And I don't blame 'em for this stuff. Right.

[00:25:33] But I would prefer to have my own device to use. So that's part of the problem. In fact, that's indicative of what I see to be the very big problem with these new in car systems, because that display in the computer behind it. Isn't just handling your navigation. It's controlling your seat, heaters, the radio, the music you're listening to the lights, the dimming, the headlights, almost everything in the car goes through.

[00:26:08] Infotainment system, right? Yeah. Figured out where I'm going next. Cuz that infotainment system just like the maps on my car right now is going to become out outdated. And then what are you gonna do? And when I say out outdated, I don't just mean, oh, well I want the new features. It might be that you want the new maps.

[00:26:34] Yeah. But what happens when it breaks? This leads us to a study that happened here. A Swedish publication had performed a test. They took 11 new cars alongside an older car, a Volvo C 70 from 2005. Now that Volvo had buttons and knobs, buttons and knobs, I've always liked that. And those 11 new cars all had these wonderful infotainment systems, all in one touch screens in the center of the console.

[00:27:11] They tested this whole thing and they timed how long it took people to perform a li list of tasks in each car. So they included things like turning on that seat. Heater, turning up the temperature inside the car, the frost, adjust the radio, reset the trip. Computer, turn off the screen. Dim the instruments.

[00:27:35] The old Volvo was the clear winner. . Yeah, indeed. So according to this article in ours, Technica, the four tasks were handled within 10 seconds, flat using buttons and knobs in the Volvo. So in the amount of time it took them to do all of the tasks, the four tasks that they were given out of that selection here, I just read the car, drove a thousand.

[00:28:06] At 68 miles per hour. Now most of these other cars with that wonderful infotainment system required twice as long, or even more to complete those same four tasks. So some 30 seconds. So you're talking about traveling two or 3000 feet while you're messing around with that display in the central console.

[00:28:34] Looks cool. Isn't this the neatest thing ever, but the problem is you have to hunt and now before you say, oh, well, Craig, these people weren't familiar with that console. Well, yeah. Okay. I'll give you that. But what they did with this test is. They let all of the participants play with the cars systems before they started the tests.

[00:28:57] In other words, they knew the menus, they knew where things were and it still took that time. See, what we're really talking about here is muscle memory, the ability for your car or for you to know your. so you can reach out and you can turn that volume knob. You might have to glance real quick to make sure you got the volume knob, but you don't have to hunt and Peck through menus.

[00:29:26] I like that. So as you can tell, I am not all that hot on these new, all touch interfaces. BMW has an interesting solution to this and that is that I drive system that little knob people didn't like it at first, but you get used to it, right? So, you know, if you need to turn on the seat heater, you just press a knob up, up right down.

[00:29:52] And then TA your seat heater and you get to adjust it right there. That is muscle memory as well. So we've got some work to do here. Uh, there are some decent systems out there in Acura, MDX Mazda, CX 50, neither one of them uses a touchscreen infiltration inform attainment system. So that's good. We'll see how it all goes.

[00:30:18] Make sure you're on my newsletter. So you can read this article and more. Craig peterson.com.

[00:30:26] We've had a chip shortage. I'm sure you've heard of it. And it's been a real problem for everybody from car manufacturers through PC makers. Well, now we're seeing a sudden downturn what's happening now. The Congress has funded it.

[00:30:43] Hey, surprisingly enough. Congress comes along to fix the chip problem with the chip bill, billions of dollars, tens of billions actually being spent on our chip plants here to help the chip industry make more chips, cuz we need chips, chips, chips, right?

[00:31:03] Well, ours Technica has a great little article. They're actually taking it from the financial time searched waters. Uh, I subscribe the France for times for quite a while, but I don't anymore. And they're talking about how we went from a boom economy when it came to chips, these microchips, everything from, uh, Intel corporation out through the manufacturers of some of these much more common chip styles nowadays, the arm chips and how this new.

[00:31:38] That's supposed to, uh, boost production is coming at a point where, okay, first of all, these manufacturers put billions of dollars into building new plants here in the us of a. So that's a good thing. And then Congress comes along sometime after the fact and gives him tens of billions more. And by the way, managed, and this apparently was Senator Chuck, Schumer's doing managed to remove a provision in the bill that said that none of that money for chip.

[00:32:13] Plants could be spent in China. So yeah, there you go. China, you get billions more from us, potentially here as we build chip plants over there. But now what do we find out? Well, a bit of a turn here, because there is now excess inventory. Dan Hutchinson, who is the chief executive V L S I research. Who's been really watching the whole chip cycle since 1980s came out and said, quote, I have never seen a time when we had excess inventory and.

[00:32:46] We had shortages. Okay. So the immediate cause of this is a rapid buildup and inventory in the chip supply chain since early the year 2022 here. So compared to February, there are enough chips on hand to support about a month and a half of production. Global inventory levels jumped up even higher and then even higher in July to almost two months.

[00:33:13] So that's been an issue. And then on top of it, PC sales have been tumbling. Smartphone demand has dropped, and those have been the main causes as consumers are slowing their spending. Why are they slowing spending? Because they don't have the money they used to have because of the non inflation that's have.

[00:33:33] Right now. So we've kind of got all of these things happening and to top it all off, as I said, they're taking tens of billions of dollars of our tax money and, uh, going to be spending it on all of this. It's just absolutely amazing. But the suddenness of this turn, again, according to financial times has, was when Intel stunned wall street with news that its revenue in the last quarter had fallen 2.6 billion.

[00:34:02] 15%, which of course was short of what they were expecting on wall street. There. This is really quite amazing. They took an inventory adjustment that only hits like once a decade and Vidia man. They are about to, uh, to really get hit too. I don't, I don't think I talked about this, but. They're the largest maker of these GPUs, these graphics, processing boards, and supplemental chips that are on motherboards.

[00:34:32] And a lot of computers used a lot in video graphics, machine learning, and of course, mining of cryptocurrencies and they have seen it fall dramatically 44% fall in these GPUs that have been used for gaming. Bitcoin and, and mining and, and other of these cryptocurrencies and micron, one of the largest makers of memory chip said it's free cash flow was likely to turn negative in the next three months after averaging $1 billion in recent quarters.

[00:35:11] Isn't that amazing? So all of these problems have been. Also throughout Asia last, uh, month here over the last month, the chief executive of Chinese ship maker, semiconductor manufacturing, international corporation, S I C said that demand had slowed from smartphone and other consumer electronics makers.

[00:35:32] And some of these manufacturers, electronics makers have stopped orders all together. So guess what happens when you do that? Think about what happened with. Down right. That really spurred this whole thing on a month before Taiwan, semiconductor manufacturing company, TSMC, which is like the biggest guy out there for making many of the chips we depend upon said it was expecting an inventory correction that would last until late next year.

[00:36:05] So this has been a very abrupt slide. Chip makers in the us are trying to manage this decline at the very moment. They're laying the ground for huge increase in production because of the tens of billions they have spent. Plus the $52 billion bill that was signed into law here. What a month or two ago?

[00:36:30] Uh, government support provided by the chips act. So on the same day that Congress passed the law, Intel expected to be the biggest beneficiary of all of these government grants of our tax dollars, sliced 4 billion summits, capital spending plans for the rest of the year. Now isn't that? What happens every.

[00:36:52] Really isn't it. What happens every time? For instance, the, uh, build back better plan renamed the inflation causation actor, I think is what they might have called it. Um, that particular bill. Put money in for you to buy an electrical car electric car, like four grand, eight grand kind of depends, uh, across the board.

[00:37:14] So what electronic electric car makers do they increase their prices? Yes, indeed. Buy, you know, Six or eight grand as much as 12 grand. Right? Because now we got government money. We don't have to have you pay for it. So we're gonna take a bigger profit and that profit's gonna come from the tax dollars that were taken from you and from me and from the widow down the street, right.

[00:37:40] Yeah. That's what happens every time? Why do we have this whole thing about the loans for people who went to college? Well, why is college so expensive? Well, it, it continued to go up as government started providing grants and started backing loans. Right? All of the stuff the government was doing was ultimately driving up the cost of your schooling.

[00:38:05] Now they've driven up the. Of electric cars because of the money they put in. And because of the money that they've put in for the chips act the 52 billion to make chips that, Hey, we got a glut right now. Yeah. Um, guess what. The manufacturers of chips, the companies that were spending the money in order to create plants, more plants, more chip factories, fabrication plants have decided they're gonna cut their spending.

[00:38:38] Why not? Because they're gonna get money from you at the point of a gun, right? That's exactly what's happening. Oh man. So for now, again, according to the financial times, most chip supply chain experts predict a relatively shallow downturn provided that the global economy is headed first off landing something that's obviously not guaranteed, but it has really left them scrambling, trying to figure out what happened here, because it just fell apart so quickly.

[00:39:13] Gartner group, you might know them. They put together a lot of studies on a lot of different industries had been expecting the growth in chip sales this year to have from 2020 ones, 26%. So it took its forecast down further to 7% and is now predicting a 2.5% contraction in 2023. Isn't that something, um, the, the Philadelphia semiconductor index, if you are an investor, you've heard of that before, and that comprises the 30 largest us companies involved in, in chip design manufacturer and sale fell back almost 40% as a stock market corrected this year.

[00:39:57] After rising threefold after the early lockdown stock market slump, because people were working from home, they couldn't go in to work. Peop the kids were home, people were buying computers so they could play games or get on a video conference with the office, et cetera. It has really, really changed. Oh, and I mentioned Nvidia and how Invidia's been.

[00:40:23] Pretty badly. And you'll find this article by the way, in my newsletter that went out on, um, Monday. And if you don't get my free newsletter, definitely get it to just app to date. Craig, Peter son.com/subscribe. It's it's all worth doing, but within video here's what's happening. One of the biggest cryptocurrencies out there has decided that they don't want to be part of this.

[00:40:52] Energy problem that we have, you know, some of these minors for various types of cryptocurrencies have actually bought power plants, old coal PLA powered power plants that the states don't wanna buy power from anymore because it's, it's coal. Right. Kohl's evil. But the private sector came in and said, okay, well, if we run our own power company and we put these GPU's and special purpose made mining equipment into the power plant, we can save a lot of money.

[00:41:27] That's how much power they need every. A whole power plant to run some of these mining operations. And remember the way you mine, the cryptocurrencies. In most cases, you have to solve very complex mathematical problems to prove that you did the work. That was needed in order to then, um, be awarded that Bitcoin or whatever it was that you were mining.

[00:41:54] So pretty much all of the major cryptocurrencies are looking at how can we move away from this model? Because in, in some cases, you know, we're talking about electrical consumption, just for mining cryptocurrencies that serve passes, some countries entire need for electricity. That's how bad it is. And supposedly here, we've got one of the major cryptocurrencies that is changing.

[00:42:24] The entire way you do mining, if you will. Very, very big changes. So expect GPUs and companies like Nvidia that make them to go way down in value here over the coming months. Hey, visit me online. Craig peterson.com. Subscribe to my podcast and find me at YouTube. Take care.

[00:42:50] If Facebook, isn't the only company doing this, but there's an article from the markup. They did a study and caught Facebook. This is absolutely crazy receiving sensitive medical information. We're gonna talk about that right now.

[00:43:06] This is really concerning for a lot of people. And, and for good reason, frankly, I've been talking about this.

[00:43:13] I, I think the first time I talked about it was over a decade ago and it has to do with what are called pixels. Now, marketers obviously want to show you ads and they want show you ads based on your interest. And frankly, as a consumer, if I'm looking for a new F one. I wouldn't mind seeing ads from competing car dealers or, you know, used car places, et cetera, to try and sell me that Ford truck.

[00:43:43] It makes sense, right? If I'm looking for shoes, why not show me ads for shoes, but what happens when we start talking about the medical business about the legal business things get murky and people get very upset. You see the way these pixels work is you'll put a pixel, like for instance, a Facebook pixel.

[00:44:06] If you go to Craig peterson.com, I've got this pixel on there from Facebook. And what it allows me to do now is retarget Facebook user. So you go to my site to go to a page on my site, and this is true for, uh, pretty much every website out there. And. I know that you went and you were looking for this, so I can retarget you in an ads.

[00:44:28] I'll show you an ad. In other words, on Facebook now I've never actually done that ever. Uh, I I'm like the world's worst marketer, frankly. Uh, and, uh, but I do have that on there because it gives me some other numbers, statistics, and, and really helps you to understand how the website's being used, which I think makes a whole lot of sense.

[00:44:49] So there are marketers that are using this for obvious reasons. Now, I think you understand what the pixel is. It is literally a little picture that is one pixel by one pixel, and it tends to blend in, I think even in most cases, now these pixels from different. Places like Facebook are actually transparent.

[00:45:09] So you, you don't even see it on the page, but the idea is now they have a foothold on a website that doesn't belong to them. In this case, Facebook now has access to information about a website that you visited that has nothing to do with Facebook. okay. So that's the basics of how these pixels work and they're almost impossible to get rid of because in reality, many websites, mine included will even grab graphics from other websites just because you know, it it's, I'm quoting another article I pull in their graphic.

[00:45:50] Of course. I'm gonna point to that other site. Why would I take that picture? Put it on my side. I don't own the rights to it. But if he'll let me that other website will, let me go ahead and show that graphic on my website, cuz there's ways to restrict it. If they don't want me doing that, they could stop me from doing it.

[00:46:09] Then I I'm going to just go to the original website so they can get the credit for it's their property still. I'm not violating any copyright laws, et cetera. Does that make sense to. So what's the difference between the Facebook pixel and a picture I'm pulling from another random website? Well, the obvious thing is it's coming from a Facebook domain of some sort.

[00:46:31] So, so there are ways to stop it, but there's just as many ways to get around stopping it, frankly. Well, Let's move on to something a little more sensitive. We have had problems that I reported on years ago of people going to an emergency room in a hospital. Now, when you're in that emergency room, your phone has GPS capabilities still.

[00:46:57] It knows you went in the emergency entrance to the hospital and you are. Opening it up. Maybe you're looking around, maybe you're reading articles, maybe you're plotting your trip home using Google maps. You are being tracked depending on what apps you have on your phone. If you have an Android versus an iPhone, what you've enabled, what you haven't enabled.

[00:47:20] Right? All of that sort of stuff. well, this now has become a problem because as I reported there have been people who went to the hospital, went to the emergency room and started seeing ads from what you might call ambulance, chasing lawyers. Have you been injured? Is it someone else's fault? Call me right now.

[00:47:45] Do he cheat him in. if that sort of thing showed up on your phone, would you get a little upset, a little nervous saying, what are they doing, trying to cash in on, on my pain, maybe literal pain. And it's not as though those ads are just showing up while you are in the emergency room, because now they've tagged you.

[00:48:06] They know that you are in that emergency room. So off they'll. They will go ahead and track you and send you ads even after you leave. Hey, I wanna remind you if you want to get this, uh, this week's list of articles. I, I put out every week, my insider show notes. It has become very popular. Thousands of people get that every week.

[00:48:32] Go right now to Craig peterson.com. I'll also send out a little bit of training. I do that. I have special reports. I send out. I've got more stuff I'm doing, but you gotta be on the email list. Craig peterson.com to get on my free email list now. What's happened here now is markup went ahead and looked at Newsweek's top 100 hospitals in America.

[00:48:56] They went to their websites and they found about a third of the hospitals using what's called the Meel. That is the Facebook pixels referring to earlier. So it sends a little bit of data. Whenever someone clicks a button to let's say, schedule a doctor's appoint. Why does it do that? Well, because the Facebook pixel is on the scheduling page.

[00:49:24] Let's say there's scheduling page for oncology on the website. I guess who knows that you are going to see an oncologist? Facebook? Why? Well, because the hospital has put a Facebook tracking pixel on that page. So Facebook knows, Hey, he was on the oncologist page. Maybe he has cancer. I should start showing him ads from other hospitals and from cancer medications, et cetera.

[00:49:51] Cetera, that is happen. Right now, 33 of these top 100 hospitals in America. Th these are the top 100, according to Newsweek's list. Have that information. Now that data is connected to your internet. Address. So it's kinda like your computer's mailing address and they can link that back to usually to a specific individual or to a household.

[00:50:20] So now they have a receipt of the appointment request. that's gone to Facebook now. They don't have everything you filled out on the page or anything, you know, you added in your social security number, maybe other medical information. Facebook didn't get all of that, but they do know that you visited the hospital's website and which pages you visited on that website.

[00:50:47] So markup went ahead and contacted these hospital. So, for example, John John's Hopkins hospital, they did find a Facebook pixel tracking on the appointment, scheduling page. They informed John's Hopkins of how that is a leak of personal information. And after being contacted by the markup, they did not remove the track.

[00:51:18] also, by the way, when the markup reached out to them, the hospital did not respond UCLA Reagan medical center. They had of course a pixel and they did remove it from the scheduling page. Although they declined to comment, New York Presbyterian hospital, all these hospitals have that pixel and they did not remove it.

[00:51:40] Northwestern Memorial hospital. Again, they got the tracking pixel did not remove it after they were informed about the security problems, duke university hospital, same thing. Most of these, by the way, did not respond to them. University of Pennsylvania, Houston Methodist hospital, the university of Chicago medical center.

[00:52:02] Uh, the last two of those did remove the pixel. Uh, Scripps Memorial hospital out in LA JOA, California. There are many Brigham and women's Faulkner hospital. They were informed that they had the tracking picture pixel on the, on the, uh, scheduling page. They did not remove it, but you know, the time of this article, a Tufts medical center, same thing did not remove it, uh, out in Sanford in San Diego.

[00:52:29] Same problem. John's Hopkins Bayview medical center, John Jefferson health, Thomas Jefferson university, hospitals, Loyola. These are big name hospitals. I'm looking at these that goes on and on sharp Memorial hospital, Henry Ford hospital. Uh, let's see some more, I'm trying to, oh, Massachusetts general hospital.

[00:52:51] They did not have the tracking pixel Brigham in women's hospital, no tracking pixel on the scheduling page. So some of these hospitals were already doing it right. They re they recognized that putting this face. Pixel on may help them with some of the marketing and understanding the market a little better, which is what I do, but it's also giving personal information, personal health information to Facebook and Facebook's advertisers.

[00:53:23] So they didn't put it on so good for them. Again, mass general Brigham and women's, uh, Sanford Mount Sinai, university of Michigan hospital and, and others, of course. So very good news there in general. Again, don't be worried about a pixel on just a random website because it probably is being used to help with stats to know what's being used on the website.

[00:53:49] And maybe, maybe just maybe using it to send a little ad to you on Facebook later. Of course, you're listening to Craig Peter son. You can get my insider show notes for absolutely free. And my little mini trainings. Oh three to five minutes every week@craigpeterson.com. Just sign up on the homepage.

[00:54:14] You know, I've got it on my homeowner's policy. I have a special business policy for it. And it's something that you should seriously consider, but you need to understand first. So we're gonna talk about it. What is cyber insurance? Uh, that's what's up now?

[00:54:31] Cyber insurance is something that many businesses have looked at, not all businesses have, which is kind of crazy. If you ask me according to the industry statistics right now, less than 1% market penetration for cyber insurance and is expected to.

[00:54:52] Into a $20 billion industry by 2025. That is some serious money. So what is this cyber insurance? For instance, there's a rider on my home insurance for, for cyber insurance and I have special cyber insurance from a big company underwritten, but it is for anything that happens. In my business, that's related to cyber security and it also covers my clients because that's what we do for living is cyber security.

[00:55:28] If they are following our guidelines. So it's pretty darn cool when you get right down to it, because these risks that we have in the digital world are really every. So if you're a large organization, if you're a small little enterprise, are you going to get hacked? You know, bottom line, anybody could potentially get hacked because the bad guys have gotten pretty good.

[00:55:56] And most of us in business have gotten pretty lackadaisical because of all of this, but not everybody understands when we're talking about cyber insurance. What does cyber mean? Well, the idea is that cyber insurance is created to protect organizations and individuals against digital risks. So we're talking about things like ransonware malware fishing campaigns.

[00:56:24] So for instance, I got a call just this week from a listener who again, had their operating account, emptied out, hate it. When that happens. And so they lost everything. They lost all of the money in the account and they're trying to get it back. I got an email this week and, uh, from a lady that I, there's not much I can do for her.

[00:56:46] I pointed her in the right direction, but her father, I think it was, had his digital wallet of cryptocurrency completely emptied, completely stolen. Can you believe this sort of stuff, right? It's happening every day. You might have insurance that covers that, but you might not. Traditional insurance policies are only looking at physical risks, so they will take the physical risk things like damage to equipment, or maybe you have livestock or you have stock and inventory, a building different locations.

[00:57:29] That's your standard stuff. But cyber insurance is to allow businesses to transfer the costs associated with recovery from the losses incurred when there's some form of cybersecurity breach. Now that's a pretty big deal. because the losses can be huge. It isn't just ransomware where maybe it, it costs you a million dollars in ransom payments.

[00:57:58] Or if you're an individual, a retiree, maybe it only costs you 25,000 in ransom payments. And I know that's a lot, especially for retiree. But there is loss of reputation. There's loss of business, cuz you couldn't conduct business cuz you couldn't use your computers. Right? All of that sort of stuff. You got people that you have to bring in, you have to bring in a special team to try and recover your data.

[00:58:23] Maybe try and figure out what had happened. Right. All of that sort of stuff. So be careful cyber insurance, a lot of people kind of mistake it for policy that pays off. Attackers to retrieve or unlock data. That's not what it's really for cyber insurance is something that allows you to, I guess the term in, in the industry is transfer risk when your online security controls fail and.

[00:58:52] Basically all of them could fail. It, it, it depends, right? If you're a huge company, you can hire a bigger team for a security operation center, but at the same time, you also have more employees that are causing more problems. So look at it entirely business interruption, payments to experts to recover the data.

[00:59:14] Compensation for bodily injuries, uh, depending obviously on the resulting damage and the particular policy and the rates are gonna vary based on the maturity of your cyber defenses. So this is something that I've been big on for a long time, the cyber security maturity CMMC and what that helps 'em to determine is.

[00:59:39] What are your rates gonna be? So if you went out and you're just using the cable modem that they, that the, uh, company, your cable company provided for you, or you go to a big box retailer, and that's where you bought your firewall and switches, and you've got your wonderful little Lenovo PCs or Dows or whatever, and you're running, uh, Norton antivirus.

[01:00:04] You are not well covered. You are not very mature from a cybersecurity standpoint. The other thing you need to be able to do is make sure you've got your asset management all in line, that you have policies and procedures in place for when things happen. You gotta have it all put together, but the average cyber insurance policy for a small to mid-size company in 2021 was about $1,600.

[01:00:31] For $1 million in cyber liability coverage. Now that's not really bad at all. Now there are limits to what the provider will pay. They will often, if you do get nailed, They'll come in and double check that, everything that you said, all of those boxes that you checked when you were applying for your cyber security insurance, make sure you actually did all of them.

[01:00:59] Okay. Yeah. Kind of a big deal. And you not only will they not pay out, if you didn't do everything that you said you were going to be. but the other problem is you might end up getting sued by. Okay. So expect a counter suit if you decide to soothe them. So don't lie on those fors people. Okay. All right. Um, cyber claims, unlike non-technical events, like again, a fire flood storm damage, the cyber insurance claim might be determined by means of attack and your ability or your effort to prevent it.

[01:01:40] As I was saying, make sure you've got the checklist and this is something I think I, I should probably put a course together on to help you guys with, or maybe even a little bit of consulting for people. Let me know, just send an email to me, me@craigpeterson.com. And uh, if you're interested in more info about cyber insurance, you can either look at this week's newsletter that you can.

[01:02:04] By again, going to Craig peterson.com and a link to this particular article I'm looking at, or you can tell me, Hey, listen, I'd love a little course or little support, a little help. Okay. I think it makes a lot of sense. So does your business qualify for cyber insurance? Well, some do some don't, uh, you might not see yourself as a target.

[01:02:27] For the bad guys, but I'll tell you, my 85 year old father was conned by some of these cyber attack guys. Okay. And he doesn't have much money. He, he's not the bank of, uh, England bank of America. None of these big banks or anything. Oh. Is a retiree living at home trying to make ends meet. So the same, thing's true for you as a business, you as an individual.

[01:02:57] You are vulnerable most likely to a cyber attack, but you've got to really manage your risk posture. You gotta do things, right. So that's the bottom line there. That's what we try and help you do. But you can find information about this again, you can just email me, me, Craig peterson.com and ask for the info on cyber insurance, or if you're already a subscriber to my newsletter.

[01:03:23] That went out Tuesday morning. So just check your mail. Maybe it's in the spam box from Tuesday morning and you'll find a lot more information linked right from there. Craig peterson.com stick around. We'll be right back.

[01:03:41] There are a lot of complaints about how some of these cryptocurrencies are very non green using tons of energy. And now the prices are going down. We're seeing a number of really weird things happening.

[01:03:57] Cryptocurrency, as you probably have heard, has taken a tumble. Now, some of the cryptocurrencies, particularly of course, someone you might know most is Bitcoin use a lot of computing power.

[01:04:11] You see, what they're trying to do is basically solve a very complex mathematical problem. And in order to do that, they need a lot of computing. Now you can certainly run it on your little desktop computer, that program to compute those things. It's called mining. So you're mining for Bitcoin. You're, you're trying to solve these mathematical problems and there's a theoretical limit to how many Bitcoins could actually potentially be mind looking right now.

[01:04:45] They're saying that circulating Bitcoin right now. Is about 19 million Bitcoin that are out there. And Bitcoin is worth about $20,000 right now, down from its huge, huge, huge high. That was, uh, more than two and a half times. What it's worth right now. So, how do you mind? Well, if you take that computer and you run the software, it's gonna do some mining and it is probably going to cost you more in electricity nowadays to mine.

[01:05:21] One Bitcoin than that Bitcoin is worth. In fact, it certainly will cost you more. Now. That's why the people that are professional Bitcoin minors have taken a different tact and what they've done. Is they found places where they can get cheap electricity. For instance, Finland, where they're using geothermal produced electricity.

[01:05:46] They're also using the cold air outside in order to cool down. The computers themselves as they're trying to compute this, but there's another thing that they've been doing. And that is well, how about we buy a coal plant? That's been shut down and that's happened. So they take that coal plant. They bring it back online.

[01:06:08] They burn the coal, they produce electricity at a cheaper rate than they could buy it. but behind all of this is the computing power. And what miners found a long time ago is it's better to have thousands of compute units working on solving these problems than it is just having. I don't know how many CPUs are in your computer.

[01:06:32] Four. Com, um, CPUs. How many? Well, I, how far can you get with those? Yeah, they're fast, but we need thousands of computers. So what they found is that GPU's graphical processing units. Kind of met their goals. You see a GPU is actually composed of thousands of computers, little compute units. Now they can't do real fancy math.

[01:07:01] They can't do anything particularly fancy. They're really designed to move. Pixels around on a screen. In other words, they're designed to help gamers have a nice smooth game while they're playing. They can be used. In fact, they're used all of the time in desktop computers, just for regular display of a webpage, for instance, or if you're watching a video, all of that is part of what they're doing.

[01:07:30] With graphic processing units. And if you've been paying attention, you probably have noticed if you particularly, if you're a gamer that the price for GPUs has gone way up, not only has it gone way up and it isn't just due to the lockdown and the supply chain problems. but they're very, very, very hard to get now.

[01:07:53] Yeah. Some of that is due to supply chain problems. No doubt about it. But most of these GPUs, according to some of the numbers I've seen, have actually been bought by these professional mining companies. In fact, many of them have gone the next step and they have what called custom silicone. These are completely customized process.

[01:08:19] sometimes they're using Asics. Sometimes they're using other things, but these custom processors that are really good at solving that problem that they have to solve in order to mine, a bit Bitcoin or one of these other currencies. So you, you see how that all works. There's a number of GPU manufacturers and something else interesting has happened because of the drop in value of pretty much all of the cryptocurrencies.

[01:08:51] And that is these GPS are going byebye. Right. Do does a company that is now no longer trading. That's no longer operating. Uh, we've seen at least two of these crypto mining companies just completely disappear. So now all of their hardware is going up for sale. You'll find it on EBA. So I, I wanna warn you, if you are looking for a GPU of some sort for your computer, maybe if you're a gamer, be very, very careful.

[01:09:28] We've got a buyer beware situation here because you're not just buying a GPU. A graphics processing card, uh, that has been lightly used. It was sitting in a terminal. Maybe it's a GPU. Like I use them where, when I'm doing video editing, it does use the GPU, even some of the audio editing. It uses the GPU.

[01:09:50] I'm looking at it right now and I've got some, uh, GPU utilization going on. I've got about, uh, 6% of my GPU in use right now on this computer. So. What the problem is is that these minors who are selling their old GPUs have been running them full Bo 24, 7. That's hard on anything. Isn't it. So what, uh, what's happening here is that you are seeing a market getting flooded with GPUs.

[01:10:25] You really don't wanna. All right. Does that make sense? Uh, you know, there we've lost more than 50% this year already in some of these, uh, cryptocurrencies that are out there coin base has had an interesting year Celsius, a major cryptocurrency bank, suspended withdrawals, uh, just here in the last few.

[01:10:52] Coin based crypto exchange announced a round of layoffs. Also here, they paused their hiring a month or two ago. It it's not going very well and prices for new and used graphic cards are continuing to fall. The peak price was late in 2021, a little bit early in 2022, but now you can go to Amazon new egg, best buy and buy current generation GPUs for prices that really would seem like bargain six months ago.

[01:11:26] And pricing for used GPUs has fallen even further, which is the caveat Amour URA thing here that I'm warning everybody about. You need to proceed. With caution. So there's a lot of scams, a lot of bait and switches. You know, that's been kind of normal for some things over the years on eBay. I'm afraid, but I've had pretty good luck with eBay, but any high value eBay purchase CPUs have been mining cryptocurrencies at full tilt for months or years have problems in new GPU.

[01:12:02] Would not have had, you know, this heat that they generate, the dust that gets into them, that the heat is messing with can really degrade the performance and degrade the usage of that GPU here over time. Dust can also, uh, cause problems with the thermal paste that's in them could be dried out thermal paste because of the heat and that causes them to crack and causes other problems.

[01:12:30] So if you buy a used GP that looks dirty or runs hot, removing and cleaning the fan and heat sink, reapplying, fresh thermal paste. Could potentially restore loss performance, and maybe you can even get that new Sony PlayStation because GPS are becoming available. Again. Visit me online Craig peterson.com and get my weekly insider show notes right there.

[01:12:59] Self-driving is relatively new technology. And, uh, our friends at Tesla just fired an employee who posted videos of a full self-driving accident. Uh, he's done it before.

[01:13:15] Tesla has a very interesting background. In fact, Elon Musk has gotten more interesting over time.

[01:13:23] And particularly lately the stuff he's saying, the stuff he's doing, but his companies have really made some amazing progress. Now, one of the things that Elon did pretty well pretty early on was he decided he was going to start selling. A self-driving feature for his cars. And back in the day, you could buy it.

[01:13:49] This was before it was ready at all for, I think it was 5,000 and, uh, it was good for whenever they came out with it. And then it went up to 7,000 and then I think it went to 12,000 and now it's you pay him monthly, but in reality, There are no fully self-driving qualified Teslas on the road today. It will be a little while before that happens.

[01:14:19] So this ex Tesla employee by the name of John Burnell is quoted in ours Technica saying that he was fired for posting YouTube videos about Tesla's full self-driving beta. Now this is called F S D. And if you know, Computers, you know what beta is? Beta means, Hey, you know, should work, could work, probably has some problems.

[01:14:44] And that's exactly what it is. Now. Tesla told California regulators that the full self-driving beta lacks true autonomous features. And that's probably how they got by getting with putting this car on the road, these cars on the road. So this ex employee. Says that Tesla also cut off access to the full self driving beta in the 2021 Tesla model three that he owns.

[01:15:17] Now. He said that he paid for it. He had it legitimately, and yet Tesla cut him off from, and I guess. Anybody can try and sign up for it. I don't know all of the details behind getting that beta code. If you wanted to, you probably could investigate a little bit further, but the video that he posted on February 7th provided a frame by frame analysis of a collision of his Tesla with a Ballard, a a Ballard.

[01:15:48] Those are those stanchions, those, uh, cement pillars. They usually have. Plastic on the outside that you'll see, you know, protecting sidewalks or in this case it was protecting a bike lane in San Jose. So he said, no matter how minor this accident was, it was the first full self-driving beta collision caught on camera.

[01:16:13] That is irrefutable. And he says I was fired from Tesla in February with my U YouTube being cited as the reason why, even though my uploads are for my personal vehicle off company, time or property with software, I paid for. And he has a, um, channel called AI addict that you can find over there on YouTube if it hasn't been taken down yet.

[01:16:38] Right. Uh, he said that he got a notice that his full self-driving beta was disabled be based on his recent driving data, but that didn't seem to fit because the morning I got fired, he says I had zero proper use strikes. On my vehicle. So yeah, I, I can't say as I really would blame him, uh, him being in this case, Elon Musk for firing this guy, but it's an interesting little video to watch.

[01:17:08] It's like two and a half minutes. You'll see. And it, the guy has his hand on the steering. Well, and the car is steering. Itself down the roadway and there's no other traffic really on the road. I don't know when this was like a, a Sunday or something, but you can see on the screen, it is detecting things like the, the little, uh, construction pillars that are on the side of the road.

[01:17:36] And he's in a left. Turn only lane and his Tesla turns, left the steering. Wheel's kind of going a little back and forth, right? As it tries to make up his mind what it's going to do and he's driving down, he just passed a ups truck. Although I would not have passed personally, the way he passed, which is the.

[01:17:56] The car decided it was going to, um, get closer to that ups truck. I, I would've purposely gone further away. And then what happens is he goes around another corner where there's some Ballards. That are in the roadway. And of course the idea behind them is so the cars don't go in and accidentally strike a cyclist.

[01:18:20] But around that corner where there is a crosswalk crossing the street, there's no Ballard. So people don't have to kind of get around them. And then the Ballards start off again. So the Tesla got kind of confused by this and looking at the screen, it doesn't show the, these Ballards. Being recognized. So the driver of the car grabs the stern wheel takes over at the very last second, but did actually hit the Ballard.

[01:18:52] Uh, no two ways about it here. He hit it and the car is stopped and it's just a minor scratch. He's showing it on his, uh, on his screen here. But I gotta say overall, it looks like it performed quite admirably. And the fact that this apparently is the. Uh, the only time it was actually caught on video.

[01:19:16] That's interesting too, but the cars of course have cameras on them too. So I'm sure. In other cases it did record a video of it. So CNBC said it obtained a copy of Tesla's internal social media policy, and it says it makes no direct reference. To criticizing the company's product in public. So we'll see what happens.

[01:19:38] Uh, apparently too, they are saying that this is the first accident in a year of testing this full self-driving. So that is darn good, frankly. And, uh, he's saying, you know, some people are saying I should have reacted sooner, which I should have. But in my year of testing, the full stop driving is usually really good at detecting objects last minute and slowing to avoid.

[01:20:01] So I don't know. We'll see what happens here. Tesla's doing a very good job. Hey, and I got another car story for you. This one, I. Think is totally, totally cool. You might remember Congress passed a law back in the seventies saying that we had to have what these cafe standards for vehicles efficiencies. In other words, you had to have certain fuel efficiency across all of the cars that you manufactured you.

[01:20:29] Okay. It is good enough, whatever. And, uh, they, they weren't able to make. uh, the car manufacturers, they weren't able to hit it until they came up with a whole new ignition technology for the cars. And that of course is fuel injection. You might remember we had car braiders and all of the cars, not very efficient.

[01:20:51] The engines themselves aren't very efficient, but we came up with fuel injection. And that helped the car manufacturers to meet these new cafe standards. Now, unfortunately, car manufacturers have removed weight from the cars in order to gain fuel efficiency in order to meet these federal requirements.

[01:21:13] So they've done things like taking out the full size spare tire, right? You, you had that before and that full size spare tire is now replaced. So. Stupid a little tire, right? That, you know, you can limp down the road a little ways, but not very far, but they've also removed steel and various metals from other parts of the car.

[01:21:32] And many people have said it's made the cars less safe. The same time they've added more safety features like the side impact airbags and, and other things and, and airbags that will Mame. But, but that's a different story entirely. Uh, but this is very, very cool because there's a company called transient plasma systems TPS, and they came up with this new advanced ignition system that uses plasma.

[01:22:02] They've designed it in such a way that it replaces your spark plugs in your. And now they put the ignition module in that uses nanosecond duration, pulses of plasma to ignite that air fuel mixture that's inside the cylinder. So you're still doing the fuel injection, but you're igniting it with a nanosecond worth of.

[01:22:28] Plasma. Isn't that just amazing. So they've tested that technology 2019 is when they came out with it and they did some bench testing, but now it's almost ready for production. So they're doing now with vehicle manufacturers, validation testing. It is frankly very cool. And they don't have to do it on brand new engines either.

[01:22:53] They will come up with retro Kitt fixed fixes. Now, imagine this getting 20% better mileage by basically replacing your spark plugs and a little more firmware changes in your engine controller. No question about that one, right. But this is frankly. Absolutely amazing. Now it's going to take a lot of years before we move to electric vehicles.

[01:23:19] For a lot of reasons. We're not ready. The country isn't ready. The infrastructure isn't ready. People aren't ready. The cars aren't ready. We don't even know what. To do with the batteries. People complain about nuclear waste while there are now huge fields full of these batteries while they're trying to figure out what do we do with the used batteries from these electric or hybrid cars, because man, they it's a huge problem.

[01:23:44] All kinds of toxic stuff in them. And they haven't been good at being able to recycle 'em it's not like the old lead acid batteries. That are very easy to recycle. So it's going to be years before they really stop selling any of these internal combustion engines and even longer before they ban internal combustion engines.

[01:24:06] From the roadways. So this plasma ignition system is going to really, really help 20%. That is darn good. And I am looking at the article right now. They used this Toyota engine. This is a 2.5 liter Toyota Camry cycle, thermal efficiency around 40%, which is absolutely amazing. Good job Toyota. And. Replaced the spark plug with this.

[01:24:38] Ignition system, this new ignition system using of course plasma and they found some amazing, amazing, uh, statistics here improvements. So in some cases they're seeing. The spark plugs and the plasmas getting 6% increase in fuel economy and others are seeing 20% increases. Of course, they've got to do more testing, extreme heat, extreme, cold, wet, dry, but that's gonna be happening.

[01:25:09] And we might see this in our cars in the next couple of years. Make sure you sign up right now. For my newsletter, get my insider show notes for free Craig peterson.com.

View Details

It's Trash Time For Your Computer - Autonomous Car Crash Kills - Which is better for your car? Buttons or a Screen? - Now we have a Chip Backlog! - Facebook tracking Your Hospital Appointments

Hey, you know, it is probably time to do an upgrade on that computer of yours to Windows 11. Or maybe you're going to move over to the Linux world. That's what I did with my older computer. It's running Linux now. Much faster, but there's more to it than that.

[Automated transcript follows]

I send out my newsletter, my insider show notes every Monday morning.

[00:00:22] Usually sometimes it's Tuesday, sometimes it's Wednesday depends on the week. This week I was at a client site over the weekend, actually, and Monday and Tuesday. Down in Atlanta. So I, I was busy down there. This is a DOD subcontractor. They just ship parts, but they are required by CMMC these new regulations I've actually been around for a while now to really.

[00:00:49] Keep an eye on their cybersecurity. And so of course they bring me in and my team cuz you know, that's what we do. But I told you that because of my newsletter this week, I got some comments from a few people that the cybersecurity section in my newsletter was two articles from 2015. And , they both pointed it out.

[00:01:13] I think it's great that everybody's paying that much attention. I actually, there's a few people that notice that, and it was my fault for not explaining what I was trying to do. And, and that's because I was in a hotel room and I was getting ready to go to the client site and do. Dates fix a couple of things, check the seals on computers and you know, all of those sorts of maintenance things you have to do clean them out.

[00:01:38] I brought down a, a little blower and stuff. They, they were amazingly clean cuz we put them in a special cabinet that has these big air filters on them and stuff. Anyhow, the two articles this week on cybersecurity in my newsletter. Well, this is even in the free newsletter. Talked about two different things.

[00:01:57] Lenovo was installing software and laptops and they apparently have still kind of done that. This was some years ago, like how seven years ago now, I guess. And they were putting it on there and you had no control over it. Okay. It was a real problem. And then the other one was. About your hard drives and what NSA did for years in modifying the firmware on the hard disk drives of a number of computers, many computers out there.

[00:02:32] And in both cases, Lenovo and the NSA, the national security agency put software on the computers so that even if you erased your computers, you would still. Have their software on it, they would reinstall itself and Lenovo has been caught again, doing that. Okay. So there there's articles out there talking about just all of the stuff they've been doing.

[00:03:00] So here's what I want to propose to you guys. And I did not make. This clear in the newsletter. And for that, I apologize, I was in a hurry and that was my intention and it just had never happened. Not, but not being in a hurry was my intention. But I, I, I intended to explain this a little bit better and I did on the radio a little bit this week as well.

[00:03:22] And I'm doing it right now. My intention is to let you know that for decades now, bad guys have been able to embed malware into parts of your computer. So instead of just the operating system where they might have a. Replaced some sort of a library file. And now when your machine boots up, it's going to pull it in from that library file or one of the many other ways, uh, they, they will go beneath your operating system.

[00:03:57] So they'll put things in the boot blocks of your computer. And as we just mentioned here, they will put things in the hard drive itself, not on the blocks of the hard drive, but in the control. Of the hard drive right there on the hard drive's board motherboard, if you will, for the hard drive and they can make it persistent.

[00:04:21] Now we've tried to get around some of these problems. Apple came up with the T2 chip and what the T2 chip does is really lock things down on your apple. And that's always a good thing, right? And the apple TTU chip keeps track of passwords and makes things bootable and everything else. And apple has also really kind of spun things out a little bit here with their TTU chip.

[00:04:51] They had some security problems. Uh they're in all of the newer apple computers. In fact, the one I use a lot is an older computer that doesn't. That T2 chip in it, but what Microsoft has done now, and this isn't really Microsoft, it's really the hardware vendors. They have something called a TP. And this TPM is there for security.

[00:05:16] It's the trusted platform module. You want the version two or better, uh, as they come out, right. Kind of keep it up to date. But the T2, this trusted platform module is kind of like the apple T2 chip. It is nowhere near as. Complete, if you will, as the apple T two chip is, and it's designed primarily for booting your computer, which is really kind of cool.

[00:05:47] There's a cute article over a medium. And it's saying that the authors of professor bill Buchanan, the author of this article says, uh, the TPM chip in your computer is perhaps a forgotten device. It often sits there not doing much and never quite achieving its full potential. You bought the laptop because it had one, but you just can't find a use for it.

[00:06:09] The chip itself is rather jealous of the applet two chip and which does so much more and where people actually buy the computer for the things it bring. Few people actually buy a computer, cuz it has a TPM, but lots of people buy a MacBook and an iPhone because it is trusted to look after your sensitive data.

[00:06:29] And he's absolutely right about that stuff. Now I've got clients who have been buying servers and other computers and the T2 chip has been. Option for them. I think that's probably almost gone nowadays. It is probably added in by default. These things are pretty cheap, cuz again, they don't really do much, but they are now a part of it because of what Microsoft has done.

[00:06:58] Microsoft has made it so that you pretty much have to have one of. T2 chip or TPM chips, I should say the TPM 2.0 cuz you know, it's gotta be as good as apples T2 the TPM 2.0, which is a crypto processor so that you can run windows 11. Now, I don't want you to think that having this TPM chip in your computer, all of a sudden makes it safe, but it does do a few things that are very, very.

[00:07:28] First of all, it has a random number generator, which is super important when we're talking about encrypt. And that random number generator is used to generate keys that are used for your disc encryption and potentially other things. So if you are encrypting the disc on your windows machine, you are really moving ahead in a very big way, because now if your computer is stolen and it boots up, they won't be able.

[00:07:57] At any of that data, it'll all look like random trash. If it's done its job. Right. And it can also of course store the user's password in the chip. It has some what's called persistent memory. I told you all of the stuff because of what I want to tell you next. All of this stuff from Lenovo, from the NSA over the years.

[00:08:20] And, and of course the bad guys, whether it's Russia, China, it can be really anywhere. North. Korea's been big on this. Iran's been doing this sort of thing. Uh, All of those guys may well have had access to your computer in the past, if you have an older computer. And because some of this software, some of this malware is persistent.

[00:08:44] And because windows now is, as I said, pretty much requiring one of these TPM chips, the TPM 2.0 were better is what you want. I think that it's time to seriously consider buying a new windows computer. Now we're working with a client right now that has an engineer who has been continually upgrading his windows computer since I don't know, windows XP days, I think.

[00:09:13] And every time he gets a new computer, he just goes ahead and migrates everything over. Doesn't upgrade. Doesn't update to the newest operating system. And for him, anyways, life is good. Well, it ain't so good folks because he has all kinds of nastiness, little turds. If you will, that are hiding all around his computer.

[00:09:37] The registry is going to be scattered with these things. Some of them probably installed by some form of malware over the years, his disc is gonna be cluttered, everything. So I'm saying right now, Get a new computer and go ahead and make sure you reinstall windows. That's the first thing we do. In fact, what we do for our clients.

[00:10:01] We have a version of windows that we have updated stream updated, and we don't have any of that bloatware on it. That the manufacturers get their 10 bucks from the various offenders, you know, to put the Norton antivirus and all this other useless stuff on your computer. So by reinstalling, just the windows.

[00:10:23] And of course, since it's windows, you gotta install all of the drivers for your computer, too. But by doing that, you're getting rid of all of the bloatware. And then what you wanna do is either copy or restore your files onto the new computer. And then when you're done with that install, Your applications, the newest versions of your applications.

[00:10:48] And I can hear people right now complaining, cuz I hear this all of the time. My gosh, I've had that application for 10 years and you can't even get it anymore. Blah blah. You know what? You should not be using that application. You need to get the newest version, or if that vendor's out of business, you need to make sure that you go one more step, find a compatible vendor or whatever.

[00:11:12] We have to stop using old computers and old software. Uh, there's options here, but seriously, consider this because of what's been happening to us for years. Hey, visit me online. Sign up for my newsletter, Craig Peter son.com.

[00:11:31] Well, autonomous cars are on the road and there was an accident in Germany. We don't have all of the details yet, but it's really concerning. And it's about the anonymous cars. Yeah. Autonomous cars. And, uh, we gotta study out. I want to talk about as well.

[00:11:48] There are various levels of autonomy, I guess. Yeah.

[00:11:53] That's the right word in these autonomous vehicles that we have and that we're looking forward to level one is kind of the gold standard, right? That's where we want to get. That's where the cars don't even need a churn pedals, your tension, nothing. They just drive themselves. We're not there. And you probably guess that.

[00:12:15] And then there's level two where you, the driver's supposed to pay attention, but the car's pretty much going to drive itself. Well, there is an article here from the associated press talking about what happened in Germany. And, uh, this is a few weeks back and this is the first time I've seen this article, but they're saying.

[00:12:41] Test car with autonomous steering capability, veered into oncoming traffic in Germany, killing one person and seriously injuring nine others. A spokesman for police in the Southwestern town of Roy. Again said the electric BMW. Nine with five people on board, including a young child swerved out of its lane at abandoned the road, triggering a series of collisions involving four vehicles after brushing an oncoming search, the BMW hit a Mercedes Benz's van head on resulting in the death of a 33 year old passenger in that.

[00:13:27] The 70 year old driver, the Cien lost control of her car and crashed into another vehicle with two people on board, pushing it off the road and causing it to burst into flame Ruly. Again, police spokesman, Michael Shaw said four rescue helicopters and dozens of firefighters. Responded to the incident and the injured were taken to several hospitals in the region.

[00:13:55] They included the 43 year old driver of the BMW three adults aged 31 42 and 47 and an 18 month old child who were all in the test vehicle. The article goes on, uh, is the police said in a statement, the crash vehicle was an autonomous electric test car, whether it was being steered by the 43, 3 year old driver or not is a subject of investigation.

[00:14:24] So this is called a level two driving assistance system. It's already incorporated in production vehicles today. They can support the driver on when the driver turns them on according to BMW with the level two vehicles, the driver. Always retains responsibility. In other words, if that car gets into an accident while you are behind the wheel and responsible for it, it's your fault.

[00:14:54] So that solves the problem of whose insurance covers what doesn't it? Yeah, it, it does it. Pretty well, because it's your fault is kind of the bottom line. So we are in the process of investigating the exact circumstances of the crash. BMW said, of course we are in close contact with the authorities. It's it's concerning very concerning and I am not ready yet.

[00:15:23] Autonomous vehicles. Now we've seen, and we've talked about on the show before a number of problems with some of these different vehicles from Tesla and others, and they are on the roads in many states right now, even in the Northeast, not just the Teslas, but these fully autonomous test vehicles. And.

[00:15:43] There are a number of things to be concerned about here. For instance, how can an autonomous vehicle determine what to do when there's a police officer in the middle of the road or a flagman? Or obviously it really can't determine it because it can't make out. What's what, in fact we might remember, and I'm sure they've made some adjustments here over at Tesla, but a Tesla car went ahead and, uh, struck and I think killed a lady who was crossing the road with her bicycle.

[00:16:20] I think she was walking it across when she was hit. So how can they. How can they tell the difference between a car that's wrapped and has someone's face on it, maybe a politician full body on the back of a box truck as an advertisement. How can it tell the difference between that and a person that might be standing there?

[00:16:44] It, it gets to be a real problem. We're already seeing that some of these autonomous vehicles go directly rear end fire trucks stopped at the side of the road with their lights on police cars stopped at the side of the road with the lights on just completely rear end them. We're seeing that. So how about when it gets a little more difficult than a fire truck parked on the side of the road?

[00:17:10] Now these cars, apparently autonomous steering and, uh, lane detection and correction, all that sort of stuff. These vehicles are looking at things and trying to determine, well, what should I do here? And oftentimes what they determine is, oh, well, okay. That's just something that's fixed at the side of the road.

[00:17:30] Like, like a sign post, like a speed sign. When in fact it's not. So we've gotta solve that problem. It, it still isn't solved yet. What caused this car to steer directly into oncoming traffic and, and head first into a Mercedes van? I, I don't know. They don't know yet. Anyways. I'm sure they'll find out soon enough.

[00:17:57] There are real questions here. And then I wanna take it to the next levels. If the car is in, let's say level one where it's full autonomous, even if it's not, even if it's a level two, like this car was, or is, uh, what happens when the car is either going to hit a pedestrian or go over a cliff or into a brick wall?

[00:18:23] That's even better. Cuz the car might not know the cliff is there. What decision should the car make? What kind of ethics should it be? You know, executing here. Can it even make an ethical decision? And this is the trolley testing in case you're not familiar with the whole trolley test thing. It's, let's say you are.

[00:18:47] A trolley operator, you're going down a hill and there is a fork in the tracks. And all you can do is select track set a or track set B you can't stop the trolley. You can't slow the trolley down in track. Set a there's a group of seniors walking across the tracks that you will hit. If you go down tracks at a tracks at B there's, some young kids playing on the.

[00:19:16] And if you choose B, you're gonna kill the kids. So ethical dilemma here, who do you kill? Cuz that's what the whole trolley test is about. Look it up online. There's a lot of different variations of this, but what about the car? What decision should the car make? Should the car make the decision to protect you the driver, or should the car be making the decision to protect the pedestrian?

[00:19:43] If it's going to protect the pedestrian by plowing into that brick wall and potentially killing the occupants of the car. How about when there is the decision of the old people or the young. There is a lot to solve here. And some of these companies, including Mercedes have come out already with their decisions, Mercedes said they will protect the occupants of the vehicle.

[00:20:11] now when you're driving the car yourself, of course, you're making that decision in a, a split second, maybe something you thought about, maybe not, you might make a rational decision. You might not. It's, you know, it's hard to say. And you'll find these articles in my newsletter this week at, uh, Craig peterson.com.

[00:20:32] If you're not on the newsletter list, you can sign up. It's absolutely free. This is the free newsletter and you can see all my insiders show notes every week. But it's an issue, isn't it? The car veering into traffic hitting another one head first. How about later on when it's completely autonomous, what should it do?

[00:20:58] By now you've seen one of these new cars with that big screen right there in the center of the console. I've got a few problems with this, more than a few problems with you people, right. To quote Seinfeld. Yeah. Let's talk about it.

[00:21:15] Right here, you know, it, it's very cool to have that display in the center of the car console.

[00:21:21] One of the major reasons that the automotive manufacturers are putting that console right there in the center is because we are demanding, uh, the apple car play the Android car functions in order to have some really cool stuff, right. Where we can just run our. And have all of this, uh, wonderful information.

[00:21:47] What I really like about it and Android auto and, uh, the apple car both provide this. What I really like is you can use the navigation system that you prefer, that you like, that you want that's in your. I have switched over to apple maps. Now I used to use ways. And before that I would use Google maps and way before that map quest and, and others, my wife could tell you some stories of us trying to use some of the very first generation GPS stuff, having a, a laptop in the car and then having.

[00:22:25] Keep pup on the dashboard to try and pick up at least three satellites. And, and, uh, if you went off course at all, went the wrong way, took the wrong. It would just insist on bringing you back to where you were when you went off course, as opposed to taking you from where you are, to where you want to go, which they do nowadays.

[00:22:47] But I like that. Right. And, and I like the new features that are always coming out in these apps that we run on our smartphone. I do not like the fact that the cars have navigation in them. Eh, some of them are pretty cool. They're nice. Like in our car, if you use the in-car navigation, it mutes the music or the radio, whatever is playing on the driver's side speaker there in the front of the car.

[00:23:17] And then it gives the driver the direction. So everyone else can just keep listening to whatever they were listening to before on the radio, et. You I'll need features like that. But what I don't like is they wanna get six or 800 bucks out of us in order to get new maps in order to get new software for the mapping system.

[00:23:38] When we can get things like apple maps for free. Where they're not even using our data against us, like Google does right Android. Uh, very, very nice. I, I really like them. And the apple maps now is really good. I don't know if you remember how bad it was when it first came out, but Steve jobs brought all of the mapping, senior management into a room and asked them what happened.

[00:24:05] Why is it so bad? You might remember that it took some people in Australia. Way off the beaten track out in the middle of nowhere with no water, with no fuel and they could have died out there, you know, Australia, everything's out to kill you and they might well have died and they didn't, which is good news.

[00:24:27] But even in the us, it was just messing up. It wasn't very good. Wasn't taking you always to the right place and certainly not the best route. Now it's just gotten amazingly good. Very, very good. So I can choose, right. If I still want to use ways I can use it. If I wanna use apple, I can use it. Google maps.

[00:24:45] I can use it some third party. I can use it, but if I've got the stuff that's built into the car, I'm stuck with the stuff that's built into the car, and maybe I can pay to upgrade it. A lot of people have found recently, Hey, guess what? That two G data network went. And that means now that your remote control for your card doesn't work anymore, you might have found your navigation doesn't work anymore.

[00:25:13] I remember I had a garment that got live traffic updates, but it was using FM carriers on FM radio stations. And many of them dumped that. guess what your garment's no good anymore. At least that part of it isn't any good and garment charging for map updates. And I don't blame 'em for this stuff. Right.

[00:25:33] But I would prefer to have my own device to use. So that's part of the problem. In fact, that's indicative of what I see to be the very big problem with these new in car systems, because that display in the computer behind it. Isn't just handling your navigation. It's controlling your seat, heaters, the radio, the music you're listening to the lights, the dimming, the headlights, almost everything in the car goes through.

[00:26:08] Infotainment system, right? Yeah. Figured out where I'm going next. Cuz that infotainment system just like the maps on my car right now is going to become out outdated. And then what are you gonna do? And when I say out outdated, I don't just mean, oh, well I want the new features. It might be that you want the new maps.

[00:26:34] Yeah. But what happens when it breaks? This leads us to a study that happened here. A Swedish publication had performed a test. They took 11 new cars alongside an older car, a Volvo C 70 from 2005. Now that Volvo had buttons and knobs, buttons and knobs, I've always liked that. And those 11 new cars all had these wonderful infotainment systems, all in one touch screens in the center of the console.

[00:27:11] They tested this whole thing and they timed how long it took people to perform a li list of tasks in each car. So they included things like turning on that seat. Heater, turning up the temperature inside the car, the frost, adjust the radio, reset the trip. Computer, turn off the screen. Dim the instruments.

[00:27:35] The old Volvo was the clear winner. . Yeah, indeed. So according to this article in ours, Technica, the four tasks were handled within 10 seconds, flat using buttons and knobs in the Volvo. So in the amount of time it took them to do all of the tasks, the four tasks that they were given out of that selection here, I just read the car, drove a thousand.

[00:28:06] At 68 miles per hour. Now most of these other cars with that wonderful infotainment system required twice as long, or even more to complete those same four tasks. So some 30 seconds. So you're talking about traveling two or 3000 feet while you're messing around with that display in the central console.

[00:28:34] Looks cool. Isn't this the neatest thing ever, but the problem is you have to hunt and now before you say, oh, well, Craig, these people weren't familiar with that console. Well, yeah. Okay. I'll give you that. But what they did with this test is. They let all of the participants play with the cars systems before they started the tests.

[00:28:57] In other words, they knew the menus, they knew where things were and it still took that time. See, what we're really talking about here is muscle memory, the ability for your car or for you to know your. so you can reach out and you can turn that volume knob. You might have to glance real quick to make sure you got the volume knob, but you don't have to hunt and Peck through menus.

[00:29:26] I like that. So as you can tell, I am not all that hot on these new, all touch interfaces. BMW has an interesting solution to this and that is that I drive system that little knob people didn't like it at first, but you get used to it, right? So, you know, if you need to turn on the seat heater, you just press a knob up, up right down.

[00:29:52] And then TA your seat heater and you get to adjust it right there. That is muscle memory as well. So we've got some work to do here. Uh, there are some decent systems out there in Acura, MDX Mazda, CX 50, neither one of them uses a touchscreen infiltration inform attainment system. So that's good. We'll see how it all goes.

[00:30:18] Make sure you're on my newsletter. So you can read this article and more. Craig peterson.com.

[00:30:26] We've had a chip shortage. I'm sure you've heard of it. And it's been a real problem for everybody from car manufacturers through PC makers. Well, now we're seeing a sudden downturn what's happening now. The Congress has funded it.

[00:30:43] Hey, surprisingly enough. Congress comes along to fix the chip problem with the chip bill, billions of dollars, tens of billions actually being spent on our chip plants here to help the chip industry make more chips, cuz we need chips, chips, chips, right?

[00:31:03] Well, ours Technica has a great little article. They're actually taking it from the financial time searched waters. Uh, I subscribe the France for times for quite a while, but I don't anymore. And they're talking about how we went from a boom economy when it came to chips, these microchips, everything from, uh, Intel corporation out through the manufacturers of some of these much more common chip styles nowadays, the arm chips and how this new.

[00:31:38] That's supposed to, uh, boost production is coming at a point where, okay, first of all, these manufacturers put billions of dollars into building new plants here in the us of a. So that's a good thing. And then Congress comes along sometime after the fact and gives him tens of billions more. And by the way, managed, and this apparently was Senator Chuck, Schumer's doing managed to remove a provision in the bill that said that none of that money for chip.

[00:32:13] Plants could be spent in China. So yeah, there you go. China, you get billions more from us, potentially here as we build chip plants over there. But now what do we find out? Well, a bit of a turn here, because there is now excess inventory. Dan Hutchinson, who is the chief executive V L S I research. Who's been really watching the whole chip cycle since 1980s came out and said, quote, I have never seen a time when we had excess inventory and.

[00:32:46] We had shortages. Okay. So the immediate cause of this is a rapid buildup and inventory in the chip supply chain since early the year 2022 here. So compared to February, there are enough chips on hand to support about a month and a half of production. Global inventory levels jumped up even higher and then even higher in July to almost two months.

[00:33:13] So that's been an issue. And then on top of it, PC sales have been tumbling. Smartphone demand has dropped, and those have been the main causes as consumers are slowing their spending. Why are they slowing spending? Because they don't have the money they used to have because of the non inflation that's have.

[00:33:33] Right now. So we've kind of got all of these things happening and to top it all off, as I said, they're taking tens of billions of dollars of our tax money and, uh, going to be spending it on all of this. It's just absolutely amazing. But the suddenness of this turn, again, according to financial times has, was when Intel stunned wall street with news that its revenue in the last quarter had fallen 2.6 billion.

[00:34:02] 15%, which of course was short of what they were expecting on wall street. There. This is really quite amazing. They took an inventory adjustment that only hits like once a decade and Vidia man. They are about to, uh, to really get hit too. I don't, I don't think I talked about this, but. They're the largest maker of these GPUs, these graphics, processing boards, and supplemental chips that are on motherboards.

[00:34:32] And a lot of computers used a lot in video graphics, machine learning, and of course, mining of cryptocurrencies and they have seen it fall dramatically 44% fall in these GPUs that have been used for gaming. Bitcoin and, and mining and, and other of these cryptocurrencies and micron, one of the largest makers of memory chip said it's free cash flow was likely to turn negative in the next three months after averaging $1 billion in recent quarters.

[00:35:11] Isn't that amazing? So all of these problems have been. Also throughout Asia last, uh, month here over the last month, the chief executive of Chinese ship maker, semiconductor manufacturing, international corporation, S I C said that demand had slowed from smartphone and other consumer electronics makers.

[00:35:32] And some of these manufacturers, electronics makers have stopped orders all together. So guess what happens when you do that? Think about what happened with. Down right. That really spurred this whole thing on a month before Taiwan, semiconductor manufacturing company, TSMC, which is like the biggest guy out there for making many of the chips we depend upon said it was expecting an inventory correction that would last until late next year.

[00:36:05] So this has been a very abrupt slide. Chip makers in the us are trying to manage this decline at the very moment. They're laying the ground for huge increase in production because of the tens of billions they have spent. Plus the $52 billion bill that was signed into law here. What a month or two ago?

[00:36:30] Uh, government support provided by the chips act. So on the same day that Congress passed the law, Intel expected to be the biggest beneficiary of all of these government grants of our tax dollars, sliced 4 billion summits, capital spending plans for the rest of the year. Now isn't that? What happens every.

[00:36:52] Really isn't it. What happens every time? For instance, the, uh, build back better plan renamed the inflation causation actor, I think is what they might have called it. Um, that particular bill. Put money in for you to buy an electrical car electric car, like four grand, eight grand kind of depends, uh, across the board.

[00:37:14] So what electronic electric car makers do they increase their prices? Yes, indeed. Buy, you know, Six or eight grand as much as 12 grand. Right? Because now we got government money. We don't have to have you pay for it. So we're gonna take a bigger profit and that profit's gonna come from the tax dollars that were taken from you and from me and from the widow down the street, right.

[00:37:40] Yeah. That's what happens every time? Why do we have this whole thing about the loans for people who went to college? Well, why is college so expensive? Well, it, it continued to go up as government started providing grants and started backing loans. Right? All of the stuff the government was doing was ultimately driving up the cost of your schooling.

[00:38:05] Now they've driven up the. Of electric cars because of the money they put in. And because of the money that they've put in for the chips act the 52 billion to make chips that, Hey, we got a glut right now. Yeah. Um, guess what. The manufacturers of chips, the companies that were spending the money in order to create plants, more plants, more chip factories, fabrication plants have decided they're gonna cut their spending.

[00:38:38] Why not? Because they're gonna get money from you at the point of a gun, right? That's exactly what's happening. Oh man. So for now, again, according to the financial times, most chip supply chain experts predict a relatively shallow downturn provided that the global economy is headed first off landing something that's obviously not guaranteed, but it has really left them scrambling, trying to figure out what happened here, because it just fell apart so quickly.

[00:39:13] Gartner group, you might know them. They put together a lot of studies on a lot of different industries had been expecting the growth in chip sales this year to have from 2020 ones, 26%. So it took its forecast down further to 7% and is now predicting a 2.5% contraction in 2023. Isn't that something, um, the, the Philadelphia semiconductor index, if you are an investor, you've heard of that before, and that comprises the 30 largest us companies involved in, in chip design manufacturer and sale fell back almost 40% as a stock market corrected this year.

[00:39:57] After rising threefold after the early lockdown stock market slump, because people were working from home, they couldn't go in to work. Peop the kids were home, people were buying computers so they could play games or get on a video conference with the office, et cetera. It has really, really changed. Oh, and I mentioned Nvidia and how Invidia's been.

[00:40:23] Pretty badly. And you'll find this article by the way, in my newsletter that went out on, um, Monday. And if you don't get my free newsletter, definitely get it to just app to date. Craig, Peter son.com/subscribe. It's it's all worth doing, but within video here's what's happening. One of the biggest cryptocurrencies out there has decided that they don't want to be part of this.

[00:40:52] Energy problem that we have, you know, some of these minors for various types of cryptocurrencies have actually bought power plants, old coal PLA powered power plants that the states don't wanna buy power from anymore because it's, it's coal. Right. Kohl's evil. But the private sector came in and said, okay, well, if we run our own power company and we put these GPU's and special purpose made mining equipment into the power plant, we can save a lot of money.

[00:41:27] That's how much power they need every. A whole power plant to run some of these mining operations. And remember the way you mine, the cryptocurrencies. In most cases, you have to solve very complex mathematical problems to prove that you did the work. That was needed in order to then, um, be awarded that Bitcoin or whatever it was that you were mining.

[00:41:54] So pretty much all of the major cryptocurrencies are looking at how can we move away from this model? Because in, in some cases, you know, we're talking about electrical consumption, just for mining cryptocurrencies that serve passes, some countries entire need for electricity. That's how bad it is. And supposedly here, we've got one of the major cryptocurrencies that is changing.

[00:42:24] The entire way you do mining, if you will. Very, very big changes. So expect GPUs and companies like Nvidia that make them to go way down in value here over the coming months. Hey, visit me online. Craig peterson.com. Subscribe to my podcast and find me at YouTube. Take care.

[00:42:50] If Facebook, isn't the only company doing this, but there's an article from the markup. They did a study and caught Facebook. This is absolutely crazy receiving sensitive medical information. We're gonna talk about that right now.

[00:43:06] This is really concerning for a lot of people. And, and for good reason, frankly, I've been talking about this.

[00:43:13] I, I think the first time I talked about it was over a decade ago and it has to do with what are called pixels. Now, marketers obviously want to show you ads and they want show you ads based on your interest. And frankly, as a consumer, if I'm looking for a new F one. I wouldn't mind seeing ads from competing car dealers or, you know, used car places, et cetera, to try and sell me that Ford truck.

[00:43:43] It makes sense, right? If I'm looking for shoes, why not show me ads for shoes, but what happens when we start talking about the medical business about the legal business things get murky and people get very upset. You see the way these pixels work is you'll put a pixel, like for instance, a Facebook pixel.

[00:44:06] If you go to Craig peterson.com, I've got this pixel on there from Facebook. And what it allows me to do now is retarget Facebook user. So you go to my site to go to a page on my site, and this is true for, uh, pretty much every website out there. And. I know that you went and you were looking for this, so I can retarget you in an ads.

[00:44:28] I'll show you an ad. In other words, on Facebook now I've never actually done that ever. Uh, I I'm like the world's worst marketer, frankly. Uh, and, uh, but I do have that on there because it gives me some other numbers, statistics, and, and really helps you to understand how the website's being used, which I think makes a whole lot of sense.

[00:44:49] So there are marketers that are using this for obvious reasons. Now, I think you understand what the pixel is. It is literally a little picture that is one pixel by one pixel, and it tends to blend in, I think even in most cases, now these pixels from different. Places like Facebook are actually transparent.

[00:45:09] So you, you don't even see it on the page, but the idea is now they have a foothold on a website that doesn't belong to them. In this case, Facebook now has access to information about a website that you visited that has nothing to do with Facebook. okay. So that's the basics of how these pixels work and they're almost impossible to get rid of because in reality, many websites, mine included will even grab graphics from other websites just because you know, it it's, I'm quoting another article I pull in their graphic.

[00:45:50] Of course. I'm gonna point to that other site. Why would I take that picture? Put it on my side. I don't own the rights to it. But if he'll let me that other website will, let me go ahead and show that graphic on my website, cuz there's ways to restrict it. If they don't want me doing that, they could stop me from doing it.

[00:46:09] Then I I'm going to just go to the original website so they can get the credit for it's their property still. I'm not violating any copyright laws, et cetera. Does that make sense to. So what's the difference between the Facebook pixel and a picture I'm pulling from another random website? Well, the obvious thing is it's coming from a Facebook domain of some sort.

[00:46:31] So, so there are ways to stop it, but there's just as many ways to get around stopping it, frankly. Well, Let's move on to something a little more sensitive. We have had problems that I reported on years ago of people going to an emergency room in a hospital. Now, when you're in that emergency room, your phone has GPS capabilities still.

[00:46:57] It knows you went in the emergency entrance to the hospital and you are. Opening it up. Maybe you're looking around, maybe you're reading articles, maybe you're plotting your trip home using Google maps. You are being tracked depending on what apps you have on your phone. If you have an Android versus an iPhone, what you've enabled, what you haven't enabled.

[00:47:20] Right? All of that sort of stuff. well, this now has become a problem because as I reported there have been people who went to the hospital, went to the emergency room and started seeing ads from what you might call ambulance, chasing lawyers. Have you been injured? Is it someone else's fault? Call me right now.

[00:47:45] Do he cheat him in. if that sort of thing showed up on your phone, would you get a little upset, a little nervous saying, what are they doing, trying to cash in on, on my pain, maybe literal pain. And it's not as though those ads are just showing up while you are in the emergency room, because now they've tagged you.

[00:48:06] They know that you are in that emergency room. So off they'll. They will go ahead and track you and send you ads even after you leave. Hey, I wanna remind you if you want to get this, uh, this week's list of articles. I, I put out every week, my insider show notes. It has become very popular. Thousands of people get that every week.

[00:48:32] Go right now to Craig peterson.com. I'll also send out a little bit of training. I do that. I have special reports. I send out. I've got more stuff I'm doing, but you gotta be on the email list. Craig peterson.com to get on my free email list now. What's happened here now is markup went ahead and looked at Newsweek's top 100 hospitals in America.

[00:48:56] They went to their websites and they found about a third of the hospitals using what's called the Meel. That is the Facebook pixels referring to earlier. So it sends a little bit of data. Whenever someone clicks a button to let's say, schedule a doctor's appoint. Why does it do that? Well, because the Facebook pixel is on the scheduling page.

[00:49:24] Let's say there's scheduling page for oncology on the website. I guess who knows that you are going to see an oncologist? Facebook? Why? Well, because the hospital has put a Facebook tracking pixel on that page. So Facebook knows, Hey, he was on the oncologist page. Maybe he has cancer. I should start showing him ads from other hospitals and from cancer medications, et cetera.

[00:49:51] Cetera, that is happen. Right now, 33 of these top 100 hospitals in America. Th these are the top 100, according to Newsweek's list. Have that information. Now that data is connected to your internet. Address. So it's kinda like your computer's mailing address and they can link that back to usually to a specific individual or to a household.

[00:50:20] So now they have a receipt of the appointment request. that's gone to Facebook now. They don't have everything you filled out on the page or anything, you know, you added in your social security number, maybe other medical information. Facebook didn't get all of that, but they do know that you visited the hospital's website and which pages you visited on that website.

[00:50:47] So markup went ahead and contacted these hospital. So, for example, John John's Hopkins hospital, they did find a Facebook pixel tracking on the appointment, scheduling page. They informed John's Hopkins of how that is a leak of personal information. And after being contacted by the markup, they did not remove the track.

[00:51:18] also, by the way, when the markup reached out to them, the hospital did not respond UCLA Reagan medical center. They had of course a pixel and they did remove it from the scheduling page. Although they declined to comment, New York Presbyterian hospital, all these hospitals have that pixel and they did not remove it.

[00:51:40] Northwestern Memorial hospital. Again, they got the tracking pixel did not remove it after they were informed about the security problems, duke university hospital, same thing. Most of these, by the way, did not respond to them. University of Pennsylvania, Houston Methodist hospital, the university of Chicago medical center.

[00:52:02] Uh, the last two of those did remove the pixel. Uh, Scripps Memorial hospital out in LA JOA, California. There are many Brigham and women's Faulkner hospital. They were informed that they had the tracking picture pixel on the, on the, uh, scheduling page. They did not remove it, but you know, the time of this article, a Tufts medical center, same thing did not remove it, uh, out in Sanford in San Diego.

[00:52:29] Same problem. John's Hopkins Bayview medical center, John Jefferson health, Thomas Jefferson university, hospitals, Loyola. These are big name hospitals. I'm looking at these that goes on and on sharp Memorial hospital, Henry Ford hospital. Uh, let's see some more, I'm trying to, oh, Massachusetts general hospital.

[00:52:51] They did not have the tracking pixel Brigham in women's hospital, no tracking pixel on the scheduling page. So some of these hospitals were already doing it right. They re they recognized that putting this face. Pixel on may help them with some of the marketing and understanding the market a little better, which is what I do, but it's also giving personal information, personal health information to Facebook and Facebook's advertisers.

[00:53:23] So they didn't put it on so good for them. Again, mass general Brigham and women's, uh, Sanford Mount Sinai, university of Michigan hospital and, and others, of course. So very good news there in general. Again, don't be worried about a pixel on just a random website because it probably is being used to help with stats to know what's being used on the website.

[00:53:49] And maybe, maybe just maybe using it to send a little ad to you on Facebook later. Of course, you're listening to Craig Peter son. You can get my insider show notes for absolutely free. And my little mini trainings. Oh three to five minutes every week@craigpeterson.com. Just sign up on the homepage.

[00:54:14] You know, I've got it on my homeowner's policy. I have a special business policy for it. And it's something that you should seriously consider, but you need to understand first. So we're gonna talk about it. What is cyber insurance? Uh, that's what's up now?

[00:54:31] Cyber insurance is something that many businesses have looked at, not all businesses have, which is kind of crazy. If you ask me according to the industry statistics right now, less than 1% market penetration for cyber insurance and is expected to.

[00:54:52] Into a $20 billion industry by 2025. That is some serious money. So what is this cyber insurance? For instance, there's a rider on my home insurance for, for cyber insurance and I have special cyber insurance from a big company underwritten, but it is for anything that happens. In my business, that's related to cyber security and it also covers my clients because that's what we do for living is cyber security.

[00:55:28] If they are following our guidelines. So it's pretty darn cool when you get right down to it, because these risks that we have in the digital world are really every. So if you're a large organization, if you're a small little enterprise, are you going to get hacked? You know, bottom line, anybody could potentially get hacked because the bad guys have gotten pretty good.

[00:55:56] And most of us in business have gotten pretty lackadaisical because of all of this, but not everybody understands when we're talking about cyber insurance. What does cyber mean? Well, the idea is that cyber insurance is created to protect organizations and individuals against digital risks. So we're talking about things like ransonware malware fishing campaigns.

[00:56:24] So for instance, I got a call just this week from a listener who again, had their operating account, emptied out, hate it. When that happens. And so they lost everything. They lost all of the money in the account and they're trying to get it back. I got an email this week and, uh, from a lady that I, there's not much I can do for her.

[00:56:46] I pointed her in the right direction, but her father, I think it was, had his digital wallet of cryptocurrency completely emptied, completely stolen. Can you believe this sort of stuff, right? It's happening every day. You might have insurance that covers that, but you might not. Traditional insurance policies are only looking at physical risks, so they will take the physical risk things like damage to equipment, or maybe you have livestock or you have stock and inventory, a building different locations.

[00:57:29] That's your standard stuff. But cyber insurance is to allow businesses to transfer the costs associated with recovery from the losses incurred when there's some form of cybersecurity breach. Now that's a pretty big deal. because the losses can be huge. It isn't just ransomware where maybe it, it costs you a million dollars in ransom payments.

[00:57:58] Or if you're an individual, a retiree, maybe it only costs you 25,000 in ransom payments. And I know that's a lot, especially for retiree. But there is loss of reputation. There's loss of business, cuz you couldn't conduct business cuz you couldn't use your computers. Right? All of that sort of stuff. You got people that you have to bring in, you have to bring in a special team to try and recover your data.

[00:58:23] Maybe try and figure out what had happened. Right. All of that sort of stuff. So be careful cyber insurance, a lot of people kind of mistake it for policy that pays off. Attackers to retrieve or unlock data. That's not what it's really for cyber insurance is something that allows you to, I guess the term in, in the industry is transfer risk when your online security controls fail and.

[00:58:52] Basically all of them could fail. It, it, it depends, right? If you're a huge company, you can hire a bigger team for a security operation center, but at the same time, you also have more employees that are causing more problems. So look at it entirely business interruption, payments to experts to recover the data.

[00:59:14] Compensation for bodily injuries, uh, depending obviously on the resulting damage and the particular policy and the rates are gonna vary based on the maturity of your cyber defenses. So this is something that I've been big on for a long time, the cyber security maturity CMMC and what that helps 'em to determine is.

[00:59:39] What are your rates gonna be? So if you went out and you're just using the cable modem that they, that the, uh, company, your cable company provided for you, or you go to a big box retailer, and that's where you bought your firewall and switches, and you've got your wonderful little Lenovo PCs or Dows or whatever, and you're running, uh, Norton antivirus.

[01:00:04] You are not well covered. You are not very mature from a cybersecurity standpoint. The other thing you need to be able to do is make sure you've got your asset management all in line, that you have policies and procedures in place for when things happen. You gotta have it all put together, but the average cyber insurance policy for a small to mid-size company in 2021 was about $1,600.

[01:00:31] For $1 million in cyber liability coverage. Now that's not really bad at all. Now there are limits to what the provider will pay. They will often, if you do get nailed, They'll come in and double check that, everything that you said, all of those boxes that you checked when you were applying for your cyber security insurance, make sure you actually did all of them.

[01:00:59] Okay. Yeah. Kind of a big deal. And you not only will they not pay out, if you didn't do everything that you said you were going to be. but the other problem is you might end up getting sued by. Okay. So expect a counter suit if you decide to soothe them. So don't lie on those fors people. Okay. All right. Um, cyber claims, unlike non-technical events, like again, a fire flood storm damage, the cyber insurance claim might be determined by means of attack and your ability or your effort to prevent it.

[01:01:40] As I was saying, make sure you've got the checklist and this is something I think I, I should probably put a course together on to help you guys with, or maybe even a little bit of consulting for people. Let me know, just send an email to me, me@craigpeterson.com. And uh, if you're interested in more info about cyber insurance, you can either look at this week's newsletter that you can.

[01:02:04] By again, going to Craig peterson.com and a link to this particular article I'm looking at, or you can tell me, Hey, listen, I'd love a little course or little support, a little help. Okay. I think it makes a lot of sense. So does your business qualify for cyber insurance? Well, some do some don't, uh, you might not see yourself as a target.

[01:02:27] For the bad guys, but I'll tell you, my 85 year old father was conned by some of these cyber attack guys. Okay. And he doesn't have much money. He, he's not the bank of, uh, England bank of America. None of these big banks or anything. Oh. Is a retiree living at home trying to make ends meet. So the same, thing's true for you as a business, you as an individual.

[01:02:57] You are vulnerable most likely to a cyber attack, but you've got to really manage your risk posture. You gotta do things, right. So that's the bottom line there. That's what we try and help you do. But you can find information about this again, you can just email me, me, Craig peterson.com and ask for the info on cyber insurance, or if you're already a subscriber to my newsletter.

[01:03:23] That went out Tuesday morning. So just check your mail. Maybe it's in the spam box from Tuesday morning and you'll find a lot more information linked right from there. Craig peterson.com stick around. We'll be right back.

[01:03:41] There are a lot of complaints about how some of these cryptocurrencies are very non green using tons of energy. And now the prices are going down. We're seeing a number of really weird things happening.

[01:03:57] Cryptocurrency, as you probably have heard, has taken a tumble. Now, some of the cryptocurrencies, particularly of course, someone you might know most is Bitcoin use a lot of computing power.

[01:04:11] You see, what they're trying to do is basically solve a very complex mathematical problem. And in order to do that, they need a lot of computing. Now you can certainly run it on your little desktop computer, that program to compute those things. It's called mining. So you're mining for Bitcoin. You're, you're trying to solve these mathematical problems and there's a theoretical limit to how many Bitcoins could actually potentially be mind looking right now.

[01:04:45] They're saying that circulating Bitcoin right now. Is about 19 million Bitcoin that are out there. And Bitcoin is worth about $20,000 right now, down from its huge, huge, huge high. That was, uh, more than two and a half times. What it's worth right now. So, how do you mind? Well, if you take that computer and you run the software, it's gonna do some mining and it is probably going to cost you more in electricity nowadays to mine.

[01:05:21] One Bitcoin than that Bitcoin is worth. In fact, it certainly will cost you more. Now. That's why the people that are professional Bitcoin minors have taken a different tact and what they've done. Is they found places where they can get cheap electricity. For instance, Finland, where they're using geothermal produced electricity.

[01:05:46] They're also using the cold air outside in order to cool down. The computers themselves as they're trying to compute this, but there's another thing that they've been doing. And that is well, how about we buy a coal plant? That's been shut down and that's happened. So they take that coal plant. They bring it back online.

[01:06:08] They burn the coal, they produce electricity at a cheaper rate than they could buy it. but behind all of this is the computing power. And what miners found a long time ago is it's better to have thousands of compute units working on solving these problems than it is just having. I don't know how many CPUs are in your computer.

[01:06:32] Four. Com, um, CPUs. How many? Well, I, how far can you get with those? Yeah, they're fast, but we need thousands of computers. So what they found is that GPU's graphical processing units. Kind of met their goals. You see a GPU is actually composed of thousands of computers, little compute units. Now they can't do real fancy math.

[01:07:01] They can't do anything particularly fancy. They're really designed to move. Pixels around on a screen. In other words, they're designed to help gamers have a nice smooth game while they're playing. They can be used. In fact, they're used all of the time in desktop computers, just for regular display of a webpage, for instance, or if you're watching a video, all of that is part of what they're doing.

[01:07:30] With graphic processing units. And if you've been paying attention, you probably have noticed if you particularly, if you're a gamer that the price for GPUs has gone way up, not only has it gone way up and it isn't just due to the lockdown and the supply chain problems. but they're very, very, very hard to get now.

[01:07:53] Yeah. Some of that is due to supply chain problems. No doubt about it. But most of these GPUs, according to some of the numbers I've seen, have actually been bought by these professional mining companies. In fact, many of them have gone the next step and they have what called custom silicone. These are completely customized process.

[01:08:19] sometimes they're using Asics. Sometimes they're using other things, but these custom processors that are really good at solving that problem that they have to solve in order to mine, a bit Bitcoin or one of these other currencies. So you, you see how that all works. There's a number of GPU manufacturers and something else interesting has happened because of the drop in value of pretty much all of the cryptocurrencies.

[01:08:51] And that is these GPS are going byebye. Right. Do does a company that is now no longer trading. That's no longer operating. Uh, we've seen at least two of these crypto mining companies just completely disappear. So now all of their hardware is going up for sale. You'll find it on EBA. So I, I wanna warn you, if you are looking for a GPU of some sort for your computer, maybe if you're a gamer, be very, very careful.

[01:09:28] We've got a buyer beware situation here because you're not just buying a GPU. A graphics processing card, uh, that has been lightly used. It was sitting in a terminal. Maybe it's a GPU. Like I use them where, when I'm doing video editing, it does use the GPU, even some of the audio editing. It uses the GPU.

[01:09:50] I'm looking at it right now and I've got some, uh, GPU utilization going on. I've got about, uh, 6% of my GPU in use right now on this computer. So. What the problem is is that these minors who are selling their old GPUs have been running them full Bo 24, 7. That's hard on anything. Isn't it. So what, uh, what's happening here is that you are seeing a market getting flooded with GPUs.

[01:10:25] You really don't wanna. All right. Does that make sense? Uh, you know, there we've lost more than 50% this year already in some of these, uh, cryptocurrencies that are out there coin base has had an interesting year Celsius, a major cryptocurrency bank, suspended withdrawals, uh, just here in the last few.

[01:10:52] Coin based crypto exchange announced a round of layoffs. Also here, they paused their hiring a month or two ago. It it's not going very well and prices for new and used graphic cards are continuing to fall. The peak price was late in 2021, a little bit early in 2022, but now you can go to Amazon new egg, best buy and buy current generation GPUs for prices that really would seem like bargain six months ago.

[01:11:26] And pricing for used GPUs has fallen even further, which is the caveat Amour URA thing here that I'm warning everybody about. You need to proceed. With caution. So there's a lot of scams, a lot of bait and switches. You know, that's been kind of normal for some things over the years on eBay. I'm afraid, but I've had pretty good luck with eBay, but any high value eBay purchase CPUs have been mining cryptocurrencies at full tilt for months or years have problems in new GPU.

[01:12:02] Would not have had, you know, this heat that they generate, the dust that gets into them, that the heat is messing with can really degrade the performance and degrade the usage of that GPU here over time. Dust can also, uh, cause problems with the thermal paste that's in them could be dried out thermal paste because of the heat and that causes them to crack and causes other problems.

[01:12:30] So if you buy a used GP that looks dirty or runs hot, removing and cleaning the fan and heat sink, reapplying, fresh thermal paste. Could potentially restore loss performance, and maybe you can even get that new Sony PlayStation because GPS are becoming available. Again. Visit me online Craig peterson.com and get my weekly insider show notes right there.

[01:12:59] Self-driving is relatively new technology. And, uh, our friends at Tesla just fired an employee who posted videos of a full self-driving accident. Uh, he's done it before.

[01:13:15] Tesla has a very interesting background. In fact, Elon Musk has gotten more interesting over time.

[01:13:23] And particularly lately the stuff he's saying, the stuff he's doing, but his companies have really made some amazing progress. Now, one of the things that Elon did pretty well pretty early on was he decided he was going to start selling. A self-driving feature for his cars. And back in the day, you could buy it.

[01:13:49] This was before it was ready at all for, I think it was 5,000 and, uh, it was good for whenever they came out with it. And then it went up to 7,000 and then I think it went to 12,000 and now it's you pay him monthly, but in reality, There are no fully self-driving qualified Teslas on the road today. It will be a little while before that happens.

[01:14:19] So this ex Tesla employee by the name of John Burnell is quoted in ours Technica saying that he was fired for posting YouTube videos about Tesla's full self-driving beta. Now this is called F S D. And if you know, Computers, you know what beta is? Beta means, Hey, you know, should work, could work, probably has some problems.

[01:14:44] And that's exactly what it is. Now. Tesla told California regulators that the full self-driving beta lacks true autonomous features. And that's probably how they got by getting with putting this car on the road, these cars on the road. So this ex employee. Says that Tesla also cut off access to the full self driving beta in the 2021 Tesla model three that he owns.

[01:15:17] Now. He said that he paid for it. He had it legitimately, and yet Tesla cut him off from, and I guess. Anybody can try and sign up for it. I don't know all of the details behind getting that beta code. If you wanted to, you probably could investigate a little bit further, but the video that he posted on February 7th provided a frame by frame analysis of a collision of his Tesla with a Ballard, a a Ballard.

[01:15:48] Those are those stanchions, those, uh, cement pillars. They usually have. Plastic on the outside that you'll see, you know, protecting sidewalks or in this case it was protecting a bike lane in San Jose. So he said, no matter how minor this accident was, it was the first full self-driving beta collision caught on camera.

[01:16:13] That is irrefutable. And he says I was fired from Tesla in February with my U YouTube being cited as the reason why, even though my uploads are for my personal vehicle off company, time or property with software, I paid for. And he has a, um, channel called AI addict that you can find over there on YouTube if it hasn't been taken down yet.

[01:16:38] Right. Uh, he said that he got a notice that his full self-driving beta was disabled be based on his recent driving data, but that didn't seem to fit because the morning I got fired, he says I had zero proper use strikes. On my vehicle. So yeah, I, I can't say as I really would blame him, uh, him being in this case, Elon Musk for firing this guy, but it's an interesting little video to watch.

[01:17:08] It's like two and a half minutes. You'll see. And it, the guy has his hand on the steering. Well, and the car is steering. Itself down the roadway and there's no other traffic really on the road. I don't know when this was like a, a Sunday or something, but you can see on the screen, it is detecting things like the, the little, uh, construction pillars that are on the side of the road.

[01:17:36] And he's in a left. Turn only lane and his Tesla turns, left the steering. Wheel's kind of going a little back and forth, right? As it tries to make up his mind what it's going to do and he's driving down, he just passed a ups truck. Although I would not have passed personally, the way he passed, which is the.

[01:17:56] The car decided it was going to, um, get closer to that ups truck. I, I would've purposely gone further away. And then what happens is he goes around another corner where there's some Ballards. That are in the roadway. And of course the idea behind them is so the cars don't go in and accidentally strike a cyclist.

[01:18:20] But around that corner where there is a crosswalk crossing the street, there's no Ballard. So people don't have to kind of get around them. And then the Ballards start off again. So the Tesla got kind of confused by this and looking at the screen, it doesn't show the, these Ballards. Being recognized. So the driver of the car grabs the stern wheel takes over at the very last second, but did actually hit the Ballard.

[01:18:52] Uh, no two ways about it here. He hit it and the car is stopped and it's just a minor scratch. He's showing it on his, uh, on his screen here. But I gotta say overall, it looks like it performed quite admirably. And the fact that this apparently is the. Uh, the only time it was actually caught on video.

[01:19:16] That's interesting too, but the cars of course have cameras on them too. So I'm sure. In other cases it did record a video of it. So CNBC said it obtained a copy of Tesla's internal social media policy, and it says it makes no direct reference. To criticizing the company's product in public. So we'll see what happens.

[01:19:38] Uh, apparently too, they are saying that this is the first accident in a year of testing this full self-driving. So that is darn good, frankly. And, uh, he's saying, you know, some people are saying I should have reacted sooner, which I should have. But in my year of testing, the full stop driving is usually really good at detecting objects last minute and slowing to avoid.

[01:20:01] So I don't know. We'll see what happens here. Tesla's doing a very good job. Hey, and I got another car story for you. This one, I. Think is totally, totally cool. You might remember Congress passed a law back in the seventies saying that we had to have what these cafe standards for vehicles efficiencies. In other words, you had to have certain fuel efficiency across all of the cars that you manufactured you.

[01:20:29] Okay. It is good enough, whatever. And, uh, they, they weren't able to make. uh, the car manufacturers, they weren't able to hit it until they came up with a whole new ignition technology for the cars. And that of course is fuel injection. You might remember we had car braiders and all of the cars, not very efficient.

[01:20:51] The engines themselves aren't very efficient, but we came up with fuel injection. And that helped the car manufacturers to meet these new cafe standards. Now, unfortunately, car manufacturers have removed weight from the cars in order to gain fuel efficiency in order to meet these federal requirements.

[01:21:13] So they've done things like taking out the full size spare tire, right? You, you had that before and that full size spare tire is now replaced. So. Stupid a little tire, right? That, you know, you can limp down the road a little ways, but not very far, but they've also removed steel and various metals from other parts of the car.

[01:21:32] And many people have said it's made the cars less safe. The same time they've added more safety features like the side impact airbags and, and other things and, and airbags that will Mame. But, but that's a different story entirely. Uh, but this is very, very cool because there's a company called transient plasma systems TPS, and they came up with this new advanced ignition system that uses plasma.

[01:22:02] They've designed it in such a way that it replaces your spark plugs in your. And now they put the ignition module in that uses nanosecond duration, pulses of plasma to ignite that air fuel mixture that's inside the cylinder. So you're still doing the fuel injection, but you're igniting it with a nanosecond worth of.

[01:22:28] Plasma. Isn't that just amazing. So they've tested that technology 2019 is when they came out with it and they did some bench testing, but now it's almost ready for production. So they're doing now with vehicle manufacturers, validation testing. It is frankly very cool. And they don't have to do it on brand new engines either.

[01:22:53] They will come up with retro Kitt fixed fixes. Now, imagine this getting 20% better mileage by basically replacing your spark plugs and a little more firmware changes in your engine controller. No question about that one, right. But this is frankly. Absolutely amazing. Now it's going to take a lot of years before we move to electric vehicles.

[01:23:19] For a lot of reasons. We're not ready. The country isn't ready. The infrastructure isn't ready. People aren't ready. The cars aren't ready. We don't even know what. To do with the batteries. People complain about nuclear waste while there are now huge fields full of these batteries while they're trying to figure out what do we do with the used batteries from these electric or hybrid cars, because man, they it's a huge problem.

[01:23:44] All kinds of toxic stuff in them. And they haven't been good at being able to recycle 'em it's not like the old lead acid batteries. That are very easy to recycle. So it's going to be years before they really stop selling any of these internal combustion engines and even longer before they ban internal combustion engines.

[01:24:06] From the roadways. So this plasma ignition system is going to really, really help 20%. That is darn good. And I am looking at the article right now. They used this Toyota engine. This is a 2.5 liter Toyota Camry cycle, thermal efficiency around 40%, which is absolutely amazing. Good job Toyota. And. Replaced the spark plug with this.

[01:24:38] Ignition system, this new ignition system using of course plasma and they found some amazing, amazing, uh, statistics here improvements. So in some cases they're seeing. The spark plugs and the plasmas getting 6% increase in fuel economy and others are seeing 20% increases. Of course, they've got to do more testing, extreme heat, extreme, cold, wet, dry, but that's gonna be happening.

[01:25:09] And we might see this in our cars in the next couple of years. Make sure you sign up right now. For my newsletter, get my insider show notes for free Craig peterson.com.

View Details

Your Crypto Is Being Tracked - Your Passwordless Future - How Safe is WhatsApp? - Business Email Compromise - Facebook Lost Your Data - Ransomware Prevention Cheaper Than Cure

Cryptocurrencies were thought to be like the gold standard of being secure. Having your information stay private. Maybe if you don't want to use regular currency and transactions. But it's changed.

[Following is an automated transcript]

We have had such volatility over the years when it comes to what are called cryptocurrencies.

[00:00:23] Now I, I get a lot of questions about cryptocurrencies. First of all, let me say, I have never owned any cryptocurrencies and I do not own any crypto, crypto, uh, assets at all. Most people look at crypto currencies and think of a couple of things. First of all, an investment. Well, an investment is something that you can use or sell, right?

[00:00:46] Typically investments you don't really use. It's like a house. Is it an investment? Uh, not so much. Uh, it's more of a liability, but people look at it and say, well, listen, it went from, uh, you know, what was a 10,000. Bitcoins to buy a pizza to, it went up to $50,000 per Bitcoin. There's a pretty big jump there.

[00:01:10] And yeah, it was pretty big. And of course, it's gone way down and it's gone back up and it's gone down. It's gone back up. But the idea of any kind of currency is can you do anything with the currency? You can take a dollar bill and go and try and buy a cup of coffee. Okay. A $10 bill and buy a cup of coffee, um, in most places anyways.

[00:01:33] Well, that sounds like a good idea. uh, I could probably use a cup of coffee right now and get a tickle on my throat. I hate that. But if you have something like Bitcoin, where can you spend it? You might remember Elon Musk was saying, yeah, you can use Bitcoin to buy a Tesla. Also Wikipedia would accept donations.

[00:01:54] Via Bitcoin, there were a number of places online that you could use. Bitcoin. In fact, there's a country right now in south central America that has Bitcoin as its currency. That's kind of cool too. When you think about it, you know, what is, so what are you gonna do? Latin American country? Uh, I'm trying to remember what it is.

[00:02:16] Oh yeah. It's all Salvador. The first country in the world to adopt Bitcoin is an official legal. Now there's a number of reasons they're doing that and he can do it basically. You know, if you got a dictator, you can do almost anything you want to. So in El Salvador, they've got apps that you can use and you can go and buy a tree taco using Bitcoin using their app.

[00:02:42] So there you go. If you have Bitcoin, you can go to El Salvador and you can buy all of the tacos and other basic stuff you might wanna buy. But in general, No, you, you can't just go and take any of these cryptocurrencies and use them anywhere. So what good are they as a currency? we already established that they haven't been good as an investment unless you're paying a lot of attention and you're kind of every day buying and selling based on what the movement is.

[00:03:11] I know a guy that does exactly that it's, he's a day trader basically in some of these cryptocurrencies, you know, good for. But in reality, is that something that makes sense in a long term? Is that going to help him long term? I, I don't know. I, I really don't because again, there's no intrinsic value value.

[00:03:33] So some of the cryptocurrencies have decided, well, let's have some sort of intrinsic value. And what they've done is they've created what are generally known as stable coins. And a stable coin is a type of cryptocurrency that behind it has the ability to be tied to something that's kind of stable. So for instance, one that really hit the news recently is a stable coin that is tied to the us dollar.

[00:04:01] And yet, even though it is tied to the us dollar and the coin is a dollar and the dollar is a coin. They managed to get down into the few pennies worth of value, kinda like penny. so what good was that, you know, it has since come back up, some are tied to other types of assets. Some of them say, well, we have gold behind us.

[00:04:24] Kinda like what the United States used to do back when we were on the gold standard. And we became the petrol dollar where countries were using our currency, our us dollars, no matter which country it was to buy and sell oil. Well, things have changed obviously. And, uh, we're not gonna talk about. The whole Petro dollar thing right now.

[00:04:46] So forget about that. Second benefit. Third benefit is while it's crypto, which means it's encrypted, which means we're safe from anybody's spine on us, anybody stealing it. And of course that's been proven to be false too. We've seen the cryptocurrencies stolen by the billions of dollars. We've seen these cryptocurrencies lost by the billions of dollars as well.

[00:05:14] That's pretty substantial. We get right down to it, lost by the billions because people had them in their crypto wallets, lost the password for the crypto wallet. And all of a sudden, now they are completely out of luck. Right. Does that make sense to you? So the basic. Idea behind currency is to make it easier to use the currency than to say, I'll trade you a chicken for five pounds of nail.

[00:05:41] Does that make sense to you? So you use a currency. So you say the chicken is worth five bucks. Well, actually chicken is nowadays is about $30. If it's a LA hen and those five pounds of nails are probably worth about $30. So we just exchanged dollars back and forth. I think that makes a lot of sense. One of the things that has driven up the value of cryptocurrencies, particularly Bitcoin has been criminal marketplaces.

[00:06:10] As you look at some of the stats of ransoms that are occurring, where people's computers are taken over via ransomware, and then that, uh, person then pays a ransom. And what happens when they pay that ransom while they have to go find an exchange. Pay us dollars to buy cryptocurrency Bitcoin usually. And then they have the Bitcoin and they have to transfer to another wallet, whether or not the bad guys can use the money.

[00:06:42] Is a, again, a separate discussion. They, they certainly can than they do because some of these countries like Russia are going ahead and just exchanging the critical currencies for rubs, which again, kind of makes sense if you're Russia. Now we have a lot of criminals that have been using the Bitcoin for ransoms businesses.

[00:07:07] Publicly traded businesses have been buying Bitcoin by the tens of millions of dollars so that they have it as an asset. In case they get ransom. Well, things have changed. There's a great article in NBC news, by Kevin Collier. And Kevin's talking about this California man who was scammed out of hundreds of thousands of dollars worth of cryptocurrency.

[00:07:33] Now this was a fake scam, which is a fairly common one. It. It tends to target older people who are lonely and a romance starts online and they go ahead and, uh, talk and kind of fall in love. Right. And it turns out she or he has this really almost terminal disease. If only they had an extra, a hundred thousand dollars to pay for the surgery.

[00:08:05] You, you know the story, right. So he was conned out of the. What's interesting to me is how the investigation and investigative ability has changed over the years. Uh, probably about five years ago, I sat through a briefing by the secret service and. In that briefing, they explained how they had gone and very, quite cleverly tracked the money that was being sent to and used by this dark web operator who ran a site known as a silk road.

[00:08:42] And that site was selling illegal things online. Oh, and the currency that they were tracking was Bitcoin. Yes, indeed. So much for cryptocurrency being secure it, five years ago, the secret service was able to do it. The FBI was able to do it and you know, they couldn't do a whole lot about it. But part of the problem is all of your transactions are a matter of public record.

[00:09:13] So if someone sends you a fraction of a Bitcoin. That is now in a ledger and that ledger now can be used because when you then spend. Fraction of a Bitcoin somewhere else, it can be tracked. Well, it is tracked is a hundred percent guaranteed to be tracked. And once it's tracked, well, government can get in.

[00:09:37] Now, in this case, a deputy district attorney in Santa Clara county, California, was able to track the movement of the cryptocurrency. Yeah. So this district attorney, okay. Deputy district attorney, not the FBI, not the secret service, not the, the, uh, national security agency, a local district attorney in Santa Clara county, California, not a particularly huge county, but.

[00:10:07] Uh, she was able to track it. And she said that she thinks that the scammer lives in a country where they can't easily extradite them. And so they're unlikely to be arrested at any time soon. So that includes countries like Russia that do not extradite criminals to the United States. Now getting into the details.

[00:10:26] There's a great quote from her in this NBC news article, our bread and butter these days really is tracing cryptocurrency and trying to seize it and trying to get there faster than the bad guys are moving it elsewhere, where we can't. Grab it. So she said the team tracked the victim's money as it bounced from one digital wallet to another, till it ended up at a major cryptocurrency exchange where it appeared the scammer was planning to launder the money or cash out, they sent a warrant to the exchange.

[00:10:58] Froze the money and she plans to return it to the victim. That is a dramatic reversal from just a few years back when cryptocurrencies were seen as a boon for criminals. Amazing. Isn't it? Well, stick around. We get a lot more to talk about here and of course, sign up online Craig peterson.com and get my free newsletter.

[00:11:24] There have been a lot of efforts by many companies, Microsoft, apple, Google, to try and get rid of passwords. Well, how can you do that? What, what is a password and what are these new technologies? Apple thinks they have the answer.

[00:11:41] Passwords have been kind of the bane of existence for a long while. And, and if you'd like, I have a special report on passwords, or I talk about password managers, things you can do, things you should do in order to help keep your information safe, online things like.

[00:11:59] Bank accounts, et cetera. Just email me, me, Craig peterson.com and ask for the password special report and I'll get it to you. Believe me it it's self-contained it's not trying to get you to buy something. Nothing. It is entirely about passwords and what you can do again, just email me, me@craigpeterson.com and we'll get right back with you.

[00:12:22] Well, you know, give us a couple of days. Passwords are a problem. And over the years, the standards for passwords have changed. I remember way back when some of the passwords might be 2, 3, 4 characters long. and back then, those were kind of hard to crack. Then Unix came along. I started using Unix and, uh, when was that?

[00:12:47] Probably about 81. And as I was messing around with Unix, I. They used to had a couple of changes in how they did passwords. They added assault to it. They used basically the same cipher that the Germans used in world war II, that enigma cipher, which again was okay for the times today, we have much more powerful ciphers and the biggest concern right now, amongst real cybersecurity people.

[00:13:14] Government agencies is okay. So what are we going to do when these new quantum computers come along with their artificial intelligence and other things, that's going to be a bit of a problem because quantum computers are able to problems in fractions of a second. Even that traditional computers cannot solve it.

[00:13:40] It's a whole different thing. I want you to think. Something here. I, if you have a handful of spaghetti, uh, now we're talking about hard spaghetti, not cooked spaghetti and they all dried out and they are a varying links. How could you sort those into the smallest to largest, if you will, how could you find which ones were the longest, perhaps?

[00:14:08] Which ones were the shortest? Well, there's kind of an analog way of doing that and there's a digital way of doing that. So the digital way for the computer would be. To measure them all and compare the measurements and then identify how long the longest one was. And then maybe you'd have to go back and try and find that.

[00:14:27] So you can imagine that would take some time, the analog way of doing that. Cuz there still are analog computers out there and they do an amazing job in certain tasks, but the analog way of doing that is okay. So you take that bundle of various length spaghetti and you slam it on the table. What's gonna happen while those pieces of dried spaghetti are going to self align, right?

[00:14:54] Uh, the shortest ones are going to be down at the bottom and the tallest one's gonna be sticking out from the top. So there you go. There's your tallest, your longest pieces of spaghetti, and it's done. Instantly. So that's just kind of an idea here, quantum, computing's not the same thing, but that's a comparison really of digital and analog computers, but it's the same type of thing.

[00:15:17] Some of these problems that would take thousands of years for digital computer. To work out, can just take a fraction of a second. It's absolutely amazing. So when we're looking at today's algorithms, today's programs for encrypting things like military information, secret telegrams, if you will going back and forth in inside the secretary of state embassies worldwide.

[00:15:43] Today they're considered to be quite secure, but with quantum computing what's gonna happen. So there are a lot of people out there right now who are working on trying to figure out how can we come up with an algorithm that works today with our digital computers and can be easily solved by quantum computer.

[00:16:06] We have a pretty good idea of how quantum computers are going to work in the future, how they kind of work right now, but this really gets us to the next level, which is kind of cool. Franklin. That's a, a little bit here about cybersecurity. Well, how about you and your password? How does this all tie in?

[00:16:26] Well, there are a few standards out there that people have been trying to pass is it's no longer the four character password you might remember. Oh, it needs to be eight to 10 characters, random mix of upper lowercase, special digits, character numbers. Right? You remember those? And you should change it every 30 days.

[00:16:45] And those recommendations changed about three or four years ago when the national Institute of standards and technology said, Hey guys, uh, pass phrase is much better than the, what we've been doing because people are gonna remember it and it can be longer. So if you are using like, I have some pass phrases I use that are 30 characters or more.

[00:17:09] And I mix up the case and I mix up mix ins on special characters and some numbers, but it's a phrase that I can remember and I have different phrases for different websites. Cause I use a password manager right now. I have about 3,100 entries in my password manager. That's a lot. And I bet you have a lot more passwords or at least a lot more websites and accounts than you realize.

[00:17:40] And so that gets to be a real problem. Well, how do you make all of this work and make it easy for people? One of the ways that, uh, that. They're looking at using is something called the Fido alliances, um, technique. And the idea behind Fido is actually similar to what I do right now. Cause I use one password.com.

[00:18:03] I have an app on my phone and the phone goes ahead and gives me the password. In fact, it'll. Put it in. I have plugins in my browsers. It'll put it right into the password form on the website. And then it'll ask me on my phone. Hey, is that really you? And I'll say yes, using duo and TA I'm logged in it's it's really quite cool.

[00:18:28] Well, Fido is a little different than that, but kind of the same, the whole idea behind Fido is you registered a website and the website will send a request to the Fido app. That's on your phone. So now on your phone, you'll use biometrics or maybe, uh, one time pass key, you know, those six digit keys that change every 30 seconds.

[00:18:54] And so now you, you, uh, on your phone, you say, yeah, yeah, yeah. That's me. That's good. That's me. Yeah. Okay. And then the app will exchange with the website using public key cryptography. A public key and it's gonna be unique public key for that website. So it'll generate a private key and a public key for that website.

[00:19:17] And now TA a, the website does not have your password and cannot get your password. And anytime you log in, it's going to ask you on your smartphone. Is this. And there there's ways beyond smartphones. And if you wanna find out more about passwords, I've got, again, that free, special report, just Craig peterson.com.

[00:19:42] Email me, just email me@craigpeterson.com and I'll make sure we send that off to you and explains a lot about passwords and current technology. So Fido is one way of doing this and a few different companies have gone ahead and have invested some. Into final registration, because it requires changes on the websites as well in order to.

[00:20:08] With Fido. Now you might use a pin, you might use the biometrics, et cetera, but apple has decided they've come up with something even better. Now there's still a lot of questions about what apple is doing, but they are rolling it into the next release of iOS and also of Mac operating system. And you'll be able to use that to secure.

[00:20:31] Log into websites. I think Apple's gonna get a lot of traction on this and I think it's gonna be better for all of us involved here. We'll see. There's still a lot of UN unanswered questions, but I'll, I'll keep you up to date on this whole password technology stick around.

[00:20:51] There are ways for us to communicate nowadays easy ways, but are, are the easy ways, the best ways, kind of the question here, frankly. And part of this answer has to do with WhatsApp and we'll talk right now.

[00:21:07] Many people have asked me about secure messaging. You probably know by now that sending text messages is not secure.

[00:21:18] In fact, it could be illegal if you have any personal information about. Patients or maybe employees, you just can't send those over open channels. So what apple has done for instance is they've got their messaging app and if the message is green, it's just reminding you that this is a text message. Now they stuck with green because that was kind of the industry's standard.

[00:21:45] Green does not mean safe in the apple world when it comes to iMessage. Blue does. So they've got end to end encryption. So if the message is blue, that means the encryptions in place from side to side, there are on the other end of the spectrum. There are apps like telegram, which are not. Particularly safe.

[00:22:06] Now, telegram has pulled up it socks a little bit here, but in order to have end to end encryption and telegram, you have to manually turn it on. It is not on by default. I also personally don't trust telegram because of their background, things that they've done in the past. So, you know, avoid that.

[00:22:28] WhatsApp is something I've been asked about. I had a family member of a service member who was overseas, ask if WhatsApp was safe for them to communicate on cuz they didn't want third parties picking. You know, private messages, things you say and do online with friends and family are not necessarily things there are for public consumption.

[00:22:51] So the answer that I gave was, well, yeah, kind of, you might remember Facebook getting, uh, WhatsApp. They bought it and deciding they were going to make some changes to the privacy settings in. now that was really a big mistake. They said we're gonna add advertisements. Well, how are you going to effectively advertise?

[00:23:15] If you don't know what we're talking about, have you noticed advertising platforms? If you look up something or someone else in your house looks up something, if your neighbors are looking up, so. They assume that you might be interested in it as well. So what do they do? They go ahead and show you ads for that brand new pair of socks that you never really cared about, but because the algorithms in the background figured, well, yeah, that's what you've been talking about.

[00:23:45] Well, let's pass out your pair of socks. So if Facebook is going to. Add into WhatsApp, what's going to happen. Are they going to be monitoring what you're saying? And then sending you some of these messages, right? These ads, because of that, a lot of people started looking for a more secure. Platform and that's frankly, where Moxi Marlin spike comes in kind of a fun name, the bloom in this case, but he started a company called signal.

[00:24:21] He didn't just start it. He wrote the code for it, the server code, everything. And the whole idea behind signal was to have a guaranteed safe end to end way to communicate. A a third party with a friend, a relative, et cetera. So signal is something that I've used in the past. And I used from time to time now, as well, depending on who I'm talking to.

[00:24:49] And it does allow you to send messages. It does allow you to talk. You can do all kinds of stuff with it. So now, now there's an issue with signal. It's disappointing. Moxi has stepped down from running signal. There's a company behind it in January, 2022. And he said, you know, the company's begin off. They can run themselves.

[00:25:12] He's still on the board of direct. And the guy who's currently the head of signal is also a very privacy kind of focused guy, which is really good too signal by the way is free. And you can get it for pretty much any platform you would care to have it for a very, very nice piece of software. I like what they've done.

[00:25:34] Now the problem is that some of those people at signal have decided that they should have a way of making payments inside signal. So a few months ago, they went ahead and added into signal, a piece of software that allows you to send. Payments online. Now this is a little concerning, uh, and the let's talk about some of the reasons for the concern.

[00:26:06] Basically what we're seeing is a cryptocurrency that Moxi himself helped to put in place now, you know, I guess that's good cuz he understands it. It's supposedly a cryptocurrency that is privacy. Focused. And that's a good thing. Well, what type of crypto is it? That's privacy focused. And how good is it going to be?

[00:26:33] You know, those are all good questions, but here's the biggest problem. I think that comes from this. We've got our friends at Facebook, again, trying to add crypto payments to their various messenger and, and other products. We're seeing that from a lot of these communication systems, cuz they can skim a little off the top legally, right.

[00:26:55] Charge you a fee and then make their money that way. But. What happens when you put it into an encrypted messaging app? Well, bottom line, a lot of bad things can happen here because now all of a sudden you come under financial regulations, right? Because you are performing a financial. Function. So now potentially here, there could be criminal misuse of the app because you could have ransomware and they say, reach us on signal.

[00:27:34] Here's our signal account. And go ahead and send us crypto. it's called mobile coin by the way, this particular cryptocurrency. Uh, so now all of a sudden you are opening up the possibility of all kinds of bad things happening and your app signal, which was originally great for messaging now being used nefariously.

[00:27:59] I think that's a real problem. Now, when it comes to money transfer functions with cryptocurrencies to say that they're anonymous, I think is a hundred percent a misnomer because it it's really pseudo anonymous. It's never completely anonymous. So now you've increased the legal attack surface here. So now the various regulators and countries around the world can say, Hey.

[00:28:28] This is no longer just a messaging app. You are using it to send money. We wanna track all money transactions. Right. And so what does that mean? Well, that means now we need to be able to break the encryption or need to shut down your app, or you need to stop the ability to send money. So the concern right now with signal is we really could have some legal problems with signal.

[00:28:56] And we could potentially cause some real life harm. On the other side of, this is what Moi Marlin spike has been really driving with signal over the years, which is we don't want anyone to be able to break into signal. So there's a particularly one Israeli based company that sells tools that you can buy that allow you to break into smartphone.

[00:29:24] And they're used by everybody from criminals. You can even buy some of these things on eBay. And they're used also by law enforcement agencies. So he found that there was a bug in one of the libraries that's used by this Israeli soft. To where that causes it to crash. And so he puts some code into signal, at least he threatened to that would cause any of the scanning software that tries to break into your smartphone to fail to crash.

[00:29:56] Yeah. Yeah. Kind of cool. Greg Peterson here on online, Craig peterson.com and really you are not alone.

[00:30:14] I got some good news about ransomware and some bad news about B E C business email compromise. In fact, I got a call just this, uh, just this week from someone who had in fact again, had their operating account emptied.

[00:30:31] Ransomware is a real problem, but it, it's interesting to watch it as it's evolved over the years.

[00:30:40] We're now seeing crackdowns driving down ransomware profits. Yes, indeed. Ransomware's ROI is dropping the return on investment. And so what we're starting to see is a drive towards more. Business email compromise attack. So we'll talk about those, what those are. And I have a couple of clients now that became clients because of the business email compromises that happened to them.

[00:31:15] A great article that was in this week's newsletter. You should have received it Tuesday morning from me. If you are signed up for the free newsletter. Craig peterson.com/subscribe. You'll get these usually Tuesday morning. It's my insider show notes. So you can kind of get up to speed on some of the articles I'm talking about during the week that I talk about on the radio.

[00:31:43] And of course talk about here on the radio show and podcast and everything else as well. So what we're seeing here, according to dark readings, editor, Becky Bracken is some major changes, a pivot by the bad guys, because, uh, at the RSA conference, they're saying that law enforcement crackdowns try cryptocurrency regulations.

[00:32:11] We've been talking about that today and ransomware as a service operator. Downs are driving the return on investment for ransomware operations across the world all the way across the globe. So what is ransomware as a service? I think that's a good place to start because that has really been an Albert Cross Albert Cross around our next for a long time.

[00:32:36] The idea with ransomware is they get you to download some software, run some software that you really should not be running. That makes sense to you. So you get this software on your computer, it exfil trades files. So in other words, it takes files that you have sends them. Off to the bad guys. And then once it's done that, so it'll send like any word files, it finds Excel, other files.

[00:33:06] It might find interesting, uh, once it's done that, then it goes ahead and encrypts those files. So you no longer have access to them and it doesn't just do them on your computer. If you share a drive, let's say you've got a, uh, Gdrive or something else on your computer that is being mounted from either another computer or maybe a server.

[00:33:31] It will go ahead and do the same. With those files. And remember it, isn't just encrypting because if you have a good backup and by the way, most businesses that I've come into do not have a good backup, which is a real problem because their, their backups fail. They haven't run. I, I had one case where we helped the business out and it had been a year and a half since they had a successful backup and they had no.

[00:34:00] They were dutifully carrying home. Uh, these USB drives every day, plug in a new one in, and the backups were not running. Absolutely amazing. So anyhow, ransomware is a service then. Well, so they they've encrypted your files. They've exfiltrated. In other words, they've taken your files and then they demand a.

[00:34:24] So usually it's like this red screen that comes up and says, Hey, uh, you know, all your files are belong to us and you need to contact us. So they have, uh, people who help you buy Bitcoin or whatever they're looking for. Usually it's Bitcoin and send the Bitcoin to them. And then they'll give you, uh, what's hopefully a decryption.

[00:34:50] Now what's particularly interesting about these decryption keys is they work about half of the time. So in other words, about half of the time, you'll get all your data back about half the time. You will not, it's just not good. So if you are a small operator, if you are just a small, bad guy and it's you and maybe somebody else helping you, you got your nephew there helping you out.

[00:35:14] How are you going to. Help these people that you're ransoming by the cryptocurrency. How are you going to threaten them with release of their documents online? Unless you have a staff of people to really help you out here? Well, that's where ransomware's a service comes in. The whole idea behind Raz is.

[00:35:38] You can just be a one man shop. And all you have to do is get someone to open this file. So you go ahead and register with the ransomware service provider and they give you the software and you embed your little key in there, so they know it's you. And then you send it off in an email. You, you might try and mess with those people to get them to do something they shouldn't do.

[00:36:03] And. That's all you have to do because once somebody opens up that file that you sent them, it's in the hand of these service guys and ransomwares the service guys. So the, these ransomwares of service people will do all of the tech support. They'll help people buy the Bitcoin. They'll help them pay the ransom.

[00:36:25] They'll help them recover files, you know, to a certain extent. Right. Does this make sense to you? Yeah, it's kinda crazy. Now I wanna offer you, I I've got this document about the new rules for backup and again, it's free. You can get it. No problem. Just go ahead and email me, me@craigpeterson.com m@craigpeterson.com because the backups are so important and.

[00:36:52] Just like password rules have changed. The rules have changed for backups as well. So just drop me an email me@craigpeterson.com and ask for it and we'll make sure we send it off to you and is not trying to sell you more stuff. Okay. Uh, it's really is explaining the whole thing for you. I'm not holding anything back.

[00:37:11] Well, these ransoms, the service operators, then get the payment from you and then pay a percentage anywhere from 80% to 50%, sometimes even lower to the person who ransom due. Isn't that just wonderful. So our law enforcement people, as well as in other countries have been going after the ransomware as a service providers, because if they can shut down.

[00:37:40] These RAs guys just shutting. One of them down can shut down thousands of small ransomware people. Isn't that cool works really, really well. So they have been shut down. Many of them there's one that just popped its head back up again. After about six months, we'll see how far they get, but it is a very big.

[00:38:06] Uh, blow to the whole industry, you know, ransomware really because of these O as a service operators has become a centralized business. So there's a small number of operators responsible for the majority of these thousands of hundreds of thousands of attacks. Really. It's probably worse. So couple of dis big groups are left the KTI group and lock bit, and they've got more than 50% of the share of ransomware attacks in the first half of 2022.

[00:38:40] But now they're going after them. The feds. And I think that makes a whole lot of sense, right. Because who do you go for while you go for the people who are causing the most harm and that's certainly them. So I expect they'll be shut down sometimes, sometimes soon, too. So. Ransomware had its moment over the last couple of years, still a lot of ransomware out there, still a lot of problems, but now we're seeing B C business, email compromise tactics, and I did a.

[00:39:14] At television appearance, where I was working with the, um, the, the newsmaker or whatever they call them, right. Talking heads on that TV show and explaining what was happening. And the most standard tactic right now is the gift card swindle. I should put together a little video on this one, but it was all, it's all about tricking employees into buying bogus gift cards.

[00:39:43] So this, this good old fashioned Grif is still working. And what happened in our case is it, it was actually one of the newscasters who got an email, supposedly from someone else saying, Hey, Uh, you know, we wanna celebrate everybody. And in order to do that, I wanna give 'em all gift cards. So can you go out and buy gift cards?

[00:40:10] And so we messed around with them. It was really kind of fun and said, okay, uh, you know, what denomination, how many do you think we need? Uh, who do you think we should give them to? And of course we knew what we were doing. Their English grammar was not very good. And it was really obvious that this was not.

[00:40:30] The person they were pretending to be. So that happens and it happens a lot. They got into a business email account, the email account of that newscaster. So they were able to go through their email, figure out who else was in the business, who was a trusted source inside of the business. So they could pretend that, uh, that they were that newscaster and send emails to this trusted source.

[00:41:01] And today these business email compromise attacks are aimed at the financial supply chain. And once these threat actors are inside, they look for opportunities to spoof vendor emails, to send payments to controlled accounts. And the worst case I know of of this is a company that sent $45 million. To a scammer.

[00:41:28] And what happened here is the, this woman pretended to be the CEO who was out of the country at the time and got the CFO to wire the money to her. Uh, an interesting story. We'll have to tell it to you sometime, but it it's a real problem. And we just had another one. We've had them in school districts, look, 'em up online, do a duck dot, go search for them and you'll find them right.

[00:41:56] Left and center because social engineering works. And frankly, business email compromise is a clear threat to businesses everywhere. I, I, as I mentioned, we had one listens to the show, contact us just last week. Again, $40,000 taken out of the operating account. We had another one that had a, I think it was $120,000 taken out of the operating account.

[00:42:25] And another one that had about $80,000 taken out of the operating account. Make sure you're on my newsletter. even the free one. I do weekly free trainings. Craig peterson.com. Make sure you subscribe now.

[00:42:43] Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? You know, did you fall victim for that? Hey, upload your contacts. We'll find your friends. Well, they don't know where your data is.

[00:43:00] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes now, you know, there's always a lot of rumors about different companies and particularly when they're big company and the, the news headlines are kind of grabbing your attention.

[00:43:34] And certainly Facebook can be one of those companies. So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal. well, it came from a leaked document. Yeah, exactly. So I, we find out a lot of stuff like that. Right. I used to follow a, a website about companies that were going to go under and they posted internal memos.

[00:44:08] It basically got sued out of existence, but there's no way that Facebook is gonna be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So of course, if you're older, we used to call those TIAL waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

[00:44:37] So Facebook, internally they're engineers are trying to figure out, okay, so how do we deal? People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

[00:45:01] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How are they all CATA categorized? Now we've got the European union. With their gen general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

[00:45:26] That's not my specialty. My specialty is the cybersecurity side. But in article five, this European law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected and used for a specific purpose and not reused for another purpose.

[00:46:04] So there's an example here that vice is giving in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, you know, feature as well as. Advertisers. Yeah. Interesting. Eh, so Gizmoto with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice.

[00:46:31] Cuz this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now. And most people. Right. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online and nothing.

[00:46:53] Right? I think I probably even uploaded it back then thinking, well, that'd be nice to see if I got friends here. We can start chatting, et cetera. Well, according to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal me, uh, memo, this European regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leak document shows that Facebook may not even have the ability to limit.

[00:47:28] how it handles users data. Now I was on a number of radio stations this week, talking about this and the example I gave, I is just look at an average business from the time it start, you know, Facebook started how right. Well, you scrape in pictures of young women off of Harvard universities. Main catalog, right.

[00:47:52] Contact page, and then asking people, well, what do you think of this rate? This person rate that person and off they go, right. Trying to rate them. Yeah, yeah, yeah. All that matters to a woman, at least according to mark Zuckerberg or all that matters about a woman is how she looks. Right. Do I think she's pretty or not ridiculous what he was doing?

[00:48:13] It just, oh, that's Zuckerberg, right? That's. Who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then opening up even wider and wider.

[00:48:37] And of course, that also created demand because you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certain you're starting to collect data and you're making more money than God. So what do you do? Well, you don't have to worry about inefficiencies.

[00:48:58] I'll tell you that. Right. One thing you don't have to do is worry about, oh, GE we've got a lot of redundant work going on here. We've got a lot of teams working on basically the same. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that, uh, money to this group or that group.

[00:49:20] And they put together all of the basic information, right. That, that they want. They are. Pulling it out of this database and that database, and they're doing some correlation writing some really cool sequel queries with some incredible joins and everything else. Right. And now that becomes part of the main code for Facebook.

[00:49:43] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says, uh, Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And, uh, they, one of the groups inside Facebook says, yeah, yeah, yeah, here, here we go.

[00:50:07] Here's all of the information we have about everybody and it's free. Don't worry about it. Right. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No, no, no, but, but the Obama. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

[00:50:34] And according to this internal memo, they still don't know. They don't even know if they can possibly, uh, comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the us Canada of course, has their own Australia, New Zealand think about all the places Facebook makes a lot of.

[00:50:59] So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water. Okay. And it flows every.

[00:51:22] The document red. Right. So how do you put that ink back in the bottle, in the right bottle? How do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from it? Apparently they don't even know where they got some of this information.

[00:51:43] This data from kind of reminds me of the no fly list. Right. You don't know you're on it and you can't get yourself off of it. Right. It is kind of crazy. So this document that we're talking about was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of a monetization strategy monetization strategy.

[00:52:10] And is the engine that powers Facebook's growth. interesting, interesting problems. And, and I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And I've talked about as well along comes Elon Musk and he says, well, wait a minute now.

[00:52:32] Now I can make Twitter way more profitable. We're gonna get rid of however many people it's well over a thousand, and then we are going to hire more people. We're gonna start charging. We're gonna be more efficient. You can bet all of these redundancies that are in Facebook are also there on. and Twitter also has to comply with all of these regulations that Facebook is kind of freaking out about.

[00:53:00] Well, it, for really a very good reason. So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does, but most companies, right.

[00:53:25] You grow. I, I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be, because it grew organically. Right. You, you started out with a little consumer firewall, router and wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around.

[00:53:48] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian looters.

[00:54:04] Thanks for being with me today. I really appreciate it. And I'm honored, frankly, to be in front of this micro. , this is really something, you know, we, we know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that that looting is kept to an absolute minimum.

[00:54:27] Certainly the Americans, the British, even the Nazis during world war II, the, the, uh, the socialists they're in. Germany, uh, they, they tried to stop some of the looting that was going on. I, I think that's probably a very good thing, right. Because what you end up with is just all of these locals that are just totally upset with you.

[00:54:56] I found a great article on the guardian and there's a village. Had been occupied for about a month by Russian troops and the people came back, they are just shocked to see what happened. They're giving a few examples of different towns. They found that alcohol was stolen and they left empty bottles behind food rappers, cigarette buts, thrown all over the place in apartments and homes.

[00:55:25] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the clothes. This is a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and lingerie. This is really, really something. The SIUs didn't do this, but now Russian.

[00:55:49] Military apparently does. So over the past couple of weeks, there've been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidences suggests looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

[00:56:16] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto Euro trucks, everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioners.

[00:56:41] Being shipped back, just like, you know, you might use ups here, they have their equivalent over there. A lady here who was the head teacher in the school. She came back in, of course, found her home Lood and in the head teacher's office. she found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're gonna destroy it.

[00:57:07] They don't only leave anything behind. They found the Russians had taken most of the computers, the projectors and other electronic equipment. It, it, it's incredible. So let's talk about the turnaround here. A little. You might have heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

[00:57:27] So they get into the apple store. They grab laptops on iPads, no longer iPods, cuz they don't make those anymore. And I phones. And they take them and they run with them. Well, nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is, is they take some parts and use them in stolen equipment.

[00:57:53] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

[00:58:16] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, let's say they put 'em on wifi. They don't get a SIM card. They don't. service from T-Mobile or Verizon or whoever it might be. So now they disconnect to the wifi and it calls home, cuz it's gonna get updates.

[00:58:36] So on download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erased, et cetera.

[00:59:02] Now, police have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're, they're doing things like putting them into Fairday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

[00:59:26] You steal it. It's not gonna do you much. Good. So one of the things the Russian stole when they were in, uh, it's called, uh, I think you pronounce it. Uh, Mela me pole, uh, which is again, a Erian city is they stole all of the equipment from a farm equipment dealership and shipped it to Chenia. Now that's according to a source in, uh, a businessman in the area that CNN is reporting on.

[00:59:59] So they shipped this equipment. We're talking about combines harvesters worth 300 grand a piece. They shipped it 700 miles. and the thieves were ultimately unable to use the equipment, cuz it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

[01:00:26] It's autonomous. It goes up and down the fields. Goes any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, right. Of your property being very, very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

[01:00:52] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a, what not terribly profitable business. It certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? Well, what they do is they. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

[01:01:20] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not gonna come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

[01:01:46] Right? You see where I'm going with this so that they can get their equipment in the hands of more farmers cuz the farmers can lease it. It costs them less. They don't have to have a big cash payment. Right? You see how this all works. So when the Russian forces stole this equipment, that's valued. Total value here is about $5 million.

[01:02:07] They were able to shut it all. And obviously, if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and you know, there's pros and cons to that. I think there's a lot of cons, but, uh, what are you gonna do? How's that gonna work for you? Well, it. Isn't going to work for you.

[01:02:28] And they were able to track it. It had GPS trackers find out exactly where it was. That's how they know it was taken to Chenia and could be controlled remotely. And in this case, how'd they control it. Well, they completely. Shut it off. Even if they sell the harvesters for spare parts, they'll learn some money, but they sure can be able to sell 'em for the 300 grand that they were actually worth.

[01:02:54] Hey, stick around. We'll be right back and visit me online@craigpeterson.com. If you sign up there, you'll be able to get my insider show note. And every week I have a quick five. Training right there in your emails, Craig Peter san.com. That's S O N in case you're wondering.

[01:03:20] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're gonna talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world.

[01:03:36] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

[01:03:47] We had improved all of their systems and their security and one of their. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine, all of a sudden TA, guess what it had ransomware on it. One of those big reds.

[01:04:09] Greens that say pay up is send us this much Bitcoin. And here's our address. Right. All of that sort of stuff. And he called us up and said, what what's going on here? What happened? Well, first of all, don't bring your own machine into the office. Secondly, don't open up particularly encrypted files using the password that they gave.

[01:04:32] and thirdly, we stopped it automatically. It did not spread. We were able to completely restore his computer. Now let's consider here at the consequences of what happened. So he obviously was scared. Uh, and within a matter of a couple of hours, we actually had him back to where he was and it didn't spread.

[01:05:00] So the consequences there, they, they weren't that bad. But how about if it had gotten worse? How about if they ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. Right. Would, do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

[01:05:27] Right? Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. Well, I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

[01:05:54] And if you're interested, I can send you, I I've got something. I wrote up. Be glad to email it back to you. Uh, obviously as usual, no charge. and you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

[01:06:18] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's two, two factor, right. First is they've encrypted your data. You can't get to it. And then the second side of that is okay, well, I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they they'll put it out there.

[01:06:42] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing, uh, you can lose your license for your business. You can U lose your ability to go ahead and frankly, uh, make loans and work with financial companies and financial instruments.

[01:07:06] It could be a very, very big. so there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And we, again, we've got a client that, uh, we picked up afterwards. That, uh, yes, indeed. They lost all of the money in their operating account.

[01:07:31] And, uh, then how do you make payroll? How do you do things? Well, there's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

[01:07:52] Uh, one is by the way, KTI, which is a big ransomware gang that also got hacked after they said we are going to attack anyone that. Uh, that doesn't defend Vlad's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. Uh, first of all, the largest ransom demand is $50 million.

[01:08:20] And that was in 2021 to Acer big computer company. Uh, 37% of businesses were hit by ransomware. In 2021. This is amazing. They're they're expecting by 2031. So in about a decade, ransomware is gonna be costing about $265 billion a year. Now on average, uh, Ransomware costs businesses. 1.8, 5 million to recover from an attack.

[01:08:52] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? Right? If you're a car dealer, you have a license to print money, right? You you're selling car model or cars from manufacturer X. And now you have the right to do that and they can remove that.

[01:09:15] Right? How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, 20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom demand. So about her third paid ransom demand.

[01:09:40] Last. it's it's actually down. Cuz my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it's it's a little, little better than 50%, but 65% of paying victims recovered their data.

[01:10:11] Now isn't that absolutely amazing. Now 57% of companies are able to recover the data using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get backed? Probably took weeks, right?

[01:10:34] For a, a regular computer over a regular internet line. Now restoring from backup's gonna be faster because your down link is usually faster than your uplink. That's not true for businesses that have real internet service, like, uh, ours. It it's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

[01:10:57] So it's very, very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be incredibly expensive for you incredibly. So here you. The number one business types by industry for ransomware tax retail.

[01:11:31] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware, conscious of doing what, of keeping their data secure of having a good it team, a good it department. So there's your bottom line.

[01:11:58] Uh, those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And so, as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

[01:12:24] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to Craig peterson.com. And I'll also send you my special report on how to do passwords stick around will be right back.

[01:12:42] You know, you and I have talked about passwords before the way to generate them and how important they are. And we we'll go over that again a little bit in just a second, but there is a new standard out there that will eliminate the need for passwords.

[01:12:59] I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

[01:13:09] Yeah, 360, you know, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements in, but you had a username.

[01:13:38] You had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang. And, uh, his password was always some sort of a combination of RA Lang. So it was always easy to guess what his, what his password was. Today, it has gotten a lot worse today. We have devices with us all of the time.

[01:14:01] You might be wearing a smart watch. That requires a password. You of course probably have a smart phone. That's also maybe requiring a password, certainly after boots nowadays they use fingerprints or facial recognition, which is handy, but has its own drawbacks. But how about the websites? You're going to the systems you're using when you're at work and logging in, they all require passwords.

[01:14:31] And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for, for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to log. Now that's really kind of an interesting thing, right?

[01:14:59] Just looking at it because we're, we're so used to having this password only authentic. And of course the, the thing to do there is make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe mix.

[01:15:21] Upper lowercase a little bit. In those words, those are the best passwords, you know, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cuz I use a completely different password for every website and right now, Let me pull it up.

[01:15:43] I'm using one password dot com's password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. Entries here in my password manager, 3,100. That is a whole lot of passwords, right? As well as, um, software licenses and a few other things in there.

[01:16:11] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I, I really do like that. Uh, some others that I've liked in the past include last pass, but they really messed. With some of their cybersecurity last year and I lost, lost my faith in it.

[01:16:33] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless sign in. and they're gonna make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

[01:16:56] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're gonna work with the Fido Alliance and they're gonna create this passwordless future. Which I like this idea. So how does this work? Well, basically you need to have a smartphone.

[01:17:16] This is, I'm just gonna go with the most standard way that this is going to work here in the future. And you can then have a, a. Pass key. This is kind of like a multifactor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, I'm giving a password and then it comes up and it asks me for a code.

[01:17:40] So I enter an a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password dot. In order to generate that code. So that's how I log into Microsoft sites and Google sites and all kinds of sites out there. So it's kind of a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

[01:18:08] We have biometrics tied in as. so to log into our systems, I have to have a username. I have to have a password. Uh, I then am sent to a single sign on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

[01:18:33] So, yeah, it there's a lot there, but I have to protect my customer's data. Something that very, very few it's crazy. Um, actual so-called managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list.

[01:18:58] I'll send that to you. That's what we're sending out right now for anyone who signs up new@craigpeterson.com. And if you'd like a copy of it and you're already on the list, just go ahead and email me M E. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing.

[01:19:16] So what will happen with this is you go to a website and it might come up with a QR code. So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again have it set up so that your phone requires, uh, a facial recognition or perhaps it'll require a fingerprint.

[01:19:37] And now you are. Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year. You're going to see this available on apple devices, Google Microsoft platforms. And it really is simple, stronger authentication. That's what Fido calls it. Right. But it is going to make your life a lot easy.

[01:20:03] It easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now I wanna talk about another thing here that has bothered me for a long time. I have a sister-in-law. who is in the medical field and, and, uh, gives prescriptions, you know, doctor thing. And, uh, I think she's not quite a doctor.

[01:20:27] I can't remember what she has or she's an LPN or something. Anyhow. So she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions. And so I warned her about that saying, you know, it is very bad to be using zoom because zoom is not secure.

[01:20:52] Never has been, probably never will be right. If you want secure. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure. So I talked to her about that and said, Hey, listen, you can't do this. You you've really got to go another way here.

[01:21:15] And so she started using one of these mental or. Medical health apps. What I wanna talk about right now specifically are some checks that were just performed some audits on mental health apps. That's why I messed up a second ago, but what they looked at is that things are a serious, serious problem there.

[01:21:42] And then in fact, the threat post is calling it, uh, Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise. So you can get on the horn with, uh, mental health, professional, uh, doctor or otherwise in order to help you here with your psychological or spiritual.

[01:22:05] Well, And people are sharing their personal and sensitive data with third parties and of 32 mental health and prayer mobile apps that were investigated by the open source organization. 28, 28 of the 32 were found to be inherently insecure and were given a privacy, not included label, including, uh, others here.

[01:22:33] So this is a report. uh, that was released here by the open source organization, tied into Mozilla Mozilla. Those are the Firefox people. They have what they call their minimum security standards. So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet.

[01:22:57] Even those minimum security standards. So these apps are dealing with some of the most sensitive men, mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal thoughts, domestic violence, eating disorders. And they are being just terrible with your security Mozilla researchers spent 255 hours or, or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, right.

[01:23:33] Between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed allowed week passwords. That range. One digit one as the password, 2, 1, 1, 1 while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data.

[01:24:02] So be very careful. Um, two of the apps better help a popular app that connects users with therapists and better stop suicide, which is of course a suicide prevention app have vague and messy. According to Mozilla privacy policies, they have little or no effect on actual. User data protection. So be very, very careful.

[01:24:26] And if you are a mental health professional, or a medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini training. They come out most weeks, just go to Craig peterson.com.

[01:24:52] Craig peterson.com. And I'll send you my special report on passwords and more.

View Details

The CHIPS Act
More Billions to China?
What's the Best Private Search Engine?
Private Messengers

Well, they did it. Yeah, it's no longer called "Build Back Better," but it's now the "Inflation Reduction Act." Imagine that. Reducing inflation by causing more inflation through massive spending. And then there's the the "CHIPS" act and, uh, yeah, government's coming for our wallets again. Oh, and this is bound to make things worse.

[Following is an automated transcript.]

The semiconductor industry has been hit hard by the lockdown.

[00:00:21] Of course, it just totally destroyed supply chains all over the world. Makes me wonder if this wasn't intentional, but we are dependent on not just us manufacturers for things like our cars, through our computers, through harvesting machines that farmers need. We are dependent on foreign. Nations to make our chips, our chip sets that that's kind of a bad thing.

[00:00:47] When you consider right now, there is a whole lot of stuff going on over there in the south China sea, which of course is where, what is made. You've probably heard about this before, where in fact, most of our chips are made at least a higher catchups that's a bad. because that means that a place like Taiwan, which has had serious problems with water shortages, and you need a lot of water in order to make chips, it has had all kinds of political instability.

[00:01:21] Of course, they had the same locked. Down messes that the rest of the world had, and that just really messed them up. And then you look at what we did and you had the companies like Ford and GM. These are, I'm mentioning these guys, cuz they're the obvious ones, right? Chrysler, who all said, oh, people aren't gonna buy cars.

[00:01:40] So we're going to cut back our orders. And remember the whole, just in time thing back in the seventies, I remember. Ever so well, it was like, wow, Japan. They are the model of world economies. We've got a. Everything that they do over there in Japan. And the big thing that we took from that was just in time inventory.

[00:02:03] Oh my gosh. I mean, I don't have to have a warehouse with parts and order a train load at a time. I can just order as many as I need and have them arrive just in time. I was watching a documentary on Volkswagen who has, I guess it's the biggest factory in the world. This thing's absolutely amazing. And while they're assembling the cars, the parts that are needed show up just in time, there will be parts that show up that morning from subcontractors, and then they move through their systems there at the factory.

[00:02:39] And then they end up right there at the person who needs to install. Minutes before it's needed. Now that's kind of cool. Cuz it cuts down in your costs. It lets you change a vendor. If you need to change a vendor, if you don't like some parts, you don't have to, you know, get rid of a whole train load or return them all.

[00:02:56] You just have to return that days, but it introduces some very. Serious problems, especially when there are supply chain problems, you know, we've been living in a world that that has just been very, very easy. I'm not gonna say it's too easy, but it's been very easy. We don't have so many of the problems that we used to have way back when, like what 50 years ago really.

[00:03:23] We have these problems where we do a lockdown where a country locks down, let's say Taiwan lockdown, and, and we didn't, and we tried to manufacture things you wouldn't be able to. And part of the theory behind the way we interact with other countries is that it will prevent war. You see if we're a completely separate country and we decide, uh, that, uh, you know, just leave us alone.

[00:03:50] And let's say China decided that they wanted some of our territories or some of their neighbors over there in the south China sea, et cetera. China could just go in and do it. But if we're trading partners, if they rely on us in order to keep their economy going, then we're not going to go to war with them.

[00:04:12] And they're not gonna go to war with us because we both need each other. That's been a, a mantra now for quite a few decades with countries worldwide. Of course, Ukraine and Russia are an interesting combination because Russia needs Ukraine. For quite a number of different supplies, food, and, and other things.

[00:04:32] And Ukraine needs to a lesser extent, Russia, as well as a market, but it, it provides food for a worldwide market. It it's kind of crazy, but that's been the theory. The theory is, well, let's bring. everyone close together. We'll put our hands together, we'll lock them and, and we'll sing, uh, I want the world to buy a Coke, right.

[00:04:56] Or whatever that song was. You you'll probably remember that song, everyone standing around in the circles or whole all the way around the world. Now it's a nice theory. And, and I like it. I like the fact we haven't gone to war, even though we've got a, I guess you could definitely call it a European war going on, but in, in fact, It does cause these types of problem problems, we're seen, we copied the Japanese just in time inventory and that messed things up because those parts are not arriving when they're supposed to be arriving and you no longer have a warehouse full of parts.

[00:05:33] So now you just can't. Can't do anything right now. Now you're in really ultimately big trouble. So what's happening now is Congress decided to pass a, um, I think they're calling it. What was it? A deficit reduction act or something instead of build back better. Because, uh, or no inflation. That's what it was.

[00:05:54] Yeah. This is gonna get rid of inflation because we're increasing taxes and , I, I don't get it. Why would Congress think that increasing taxes would bring more money into their coffers every time it's been done? Yeah. There's a little bit of a bump initially, but. It drops off dramatically. If you want to increase revenue to the federal government, you lower taxes.

[00:06:19] Every time that's been tried pretty much. It's absolutely worked by lowering taxes because now people aren't trying to hide the money. They aren't do doing things. Uh, like moving their businesses out of the country, even Canada and the rest of Europe has lower corporate tax rates and that's part of what they're going for.

[00:06:42] But the manipulation that appears to have happened here is that they wanted to pass this chips act. And the chips act is another example of the federal government helping special interest groups at the expense of you and I, the expense of the taxpayers. So this special interest group came to them and, and they carved out some 50 something dollars.

[00:07:08] I think it was yeah, 52 billion in grant and 24 billion in tax credit. To the us semiconductor industry now at, at first glance, you look at that and say, well, okay, that's, that's actually really good because what can happen here is the semiconductor industry can use that money to build plants here in the us to build fabs chip Fabrica fabrication plants.

[00:07:33] I know I can talk and, and yeah, they probably could. And that could be a very, very good. But the devil is in the details. Yes. What else is new here? Right. So this, uh, last minute by partisan agreement that they agreed, they weren't gonna do build back better because of what mansion had said. Right. I, I'm not gonna support that cuz it's just going to increase inflation and increase our debt.

[00:08:00] And by the way, our federal government. Is barely gonna be enough to discover the interest payments on the debt. You know, no principle at all, which is an incentive for the federal government to cause inflation because then the federal government can pay back that debt with inflated dollars that cost them less.

[00:08:20] And then, uh, there goes the debt, right. And they can talk about how great it was. But if you are retired, if you're looking at your retirement account, With the type of inflation we have, which isn't the nine point, whatever that they've claimed in reality, if you use the same methods and metrics that were used in the 1980s where they're saying, oh, it's been 50 years, 40 years since we had this type of inflation.

[00:08:46] No, no, no. We have never ever had this type of inflation in modern America. Because in fact, the inflation rate of use, again, those same net metrics is supposedly in the 20% range. So what that means is the federal government's able to pay you back 20% less. Then they actually borrowed from you because of that inflation.

[00:09:12] It's it's just incredible. So here we go. Some $77 billion going to the us semiconductor industry, but, um, there's another little trick here that they played on all of us and that is. The lobbyist from the semiconductor industry who, by the way, themselves are spending tens of billions of dollars to build new fabs new plants.

[00:09:35] They're spending it out of their own pockets, not out of our pockets already. Okay. But they lobbied and Chuck Schumer introduced, uh, uh, cute little thing. Cute little thing. It, the bill had said, yeah, we have to use this. For American interest basically. Uh, so he removed that. So now yeah, those tax dollars that are supposed to rebuild our chip industry, they can be used to help China.

[00:10:01] Yes, indeed. They have already penciled in some of that 77 ish billion dollars to go to China. Yeah. Yeah. Isn't that great. I, I thought China was part of what we're trying to protect ourselves from here. Certainly. not, not as a, you know, a hot war sort of a thing, but frankly, as our biggest competitor in the world, it is incredible.

[00:10:29] The us share of chip manufacturing globally has dropped from 12%. From 37%, just 30 years ago. Okay. So we've lost two thirds of our pros. If you will, on the world market in making chips, Hey, you should have received this, uh, on when was it this week? Uh, Wednesday, Tuesday, uh, my weekly insider show notes.

[00:10:56] There's links to a great article in here. From the semiconductor industry, themselves talking about what is going on, what really happened. And, uh, don't worry. It's only more than a trillion dollars. And then this on top of it, it's only another 250 billion. Don't worry about it. You'll be able to pay it back.

[00:11:18] Yeah. Yeah. stick around. We'll be right back.

[00:11:25] I don't know if you've heard of digital exhaust, it's kind of a new term. And it's talking about the things we leave behind the cookie crumbs, if you will, not cookies and browsers, but that's part of it. We're gonna talk about the browser you're using and the search engine.

[00:11:42] We have a lot of choices when it comes to browsers. We've talked about it before, and if you'd like a copy of my browser, special report, of course, this it's free.

[00:11:52] I wouldn't mention it. If it wasn't here and you can just get it by, go by emailing me, me@craigpeterson.com. You actually can't just get it, but I'll be glad to email it to you or we'll have Mary or. Send it on off to you? Me M E Craig peterson.com. Well, people have been worried about their data. Many of us have been worried a very long time, and then remember the whole Cambridge Analytica scandal.

[00:12:23] It's amazing to me, how stuff gets politicized. I'm shaking my head. I just can't. People because bronch Obama got everything on everyone, on Facebook for his campaign. Not, not a beep, nothing. I, nothing. He had everything on everybody and Cambridge Analytica and there was just given to him by the way. And then Cambridge Analytica, uh, decided, okay, well here's what we're gonna do.

[00:12:47] We're gonna make. This little program, people can play it. We'll we will, uh, advertise on Facebook and then we'll gather data on people who are there on Facebook and we'll use it for orange man. Bad Trump. Yeah, this will be great. And so the the exact opposite of what they did with president Obama. When he got all this information on tens of millions, I think it was actually hundreds of million.

[00:13:15] People, uh, they decided this was bad. and they started making a big deal about it. And so a lot of people at that point decided, Hey, uh, what's happening here? What, what is going on? Should, would they have my information? Because remember this is an old adage. You've heard it a million times by now, but it bears repeating.

[00:13:39] If you are not paying for something you or your information are the product. And that's exactly true. Exactly. True. If you are using Google maps, for instance, to get around, to do your GPS navigation, you are the product cuz Google is selling information. They collect information, right? That's what they. Do and you might have noticed recently you probably got an email from Google saying, uh, we're gonna be flushing, uh, your location, or at least some of your location information soon.

[00:14:13] Did you, did you get that email from Google? I, I got it right. And I don't use Google very much, but I, I obviously I need to, I need to know about Google. Google's good for certain things, and I understand what it's doing. But it decided all of a sudden after the, again, left stuff, right. People were all worried that because there was no longer a national law on abortion, uh, by the way, there never has been a national.

[00:14:46] Law on abortion. And in fact, that's what the Supreme court said. You can't make up a law in the court. You can rule on the application of the law in the court. They've gone, they've stepped over that boundary and decided they can rule on whether or not there should be a law. And so the court said, Hey, listen, this is a, at this point, a state's rights issue, right?

[00:15:11] The 10th amendment to the us constitution, uh, the state should decide this. And the Congress didn't act there. There's no federal law about this. So the, these rulings were bad and people say, oh no, that's terrible. It was the first time it's ever no, there've been over 200 times where the Supreme court changed its mind.

[00:15:34] Think of the dread Scott decision. If, if you even know what that is, well, you guys do cuz you're the best and brightest, but these people complaining probably have no clue about any of this stuff, right? None at all. So they're all upset because now, oh my gosh, my golly, um, because Roe V Wade, et cetera, was overturned.

[00:15:55] Now they're going to be tracking me. Because my data is being sold. Cuz you remember that's how they came after these January six protestors, right. That were down in, in Washington, DC by using the GPS data that came from the apps that were there on their phones. Yeah. And, uh, that's also how it was proven that the election.

[00:16:19] Uh, may have been stolen, but certainly had substantial fraud because they were able to buy the data. Look at the data show. What was pretty, obviously the, uh, acts of at least a thousand people that were completely illegal in ballot harvesting and. Box stuffing. Right? So again, GPS data, you can buy it. The federal, government's not allowed to keep data on us.

[00:16:49] It's not allowed to spy on the citizens at all. Right. So what do they do? They go to these same data brokers and they buy the data. I sold it now. Well, we're not tracking, but people are you kidding me? We would never do that. But they're buying the tracking data from third parties. So they are tracking. Oh no, no, it's not us.

[00:17:11] It's it's other people. So now they're worried. Well, if I go to an abortion clinic, are the state's attorneys general. That do not allow abortions in their states where the law does not allow it. Are they going to buy data and see that I went to an abortion clinic, even if I went to an abortion clinic out of state.

[00:17:35] Now you can see their concern on that one. Right? So a again, now all of a sudden they're worried about tracking data. I, I just don't understand why they trust the government on one hand and don't trust it on another hand, I guess, that. People say right. The ability to hold two conflicting thoughts has truth in your mind at the same time, but they're concerned and it's legitimate.

[00:18:00] So what happens. Google decides we're not going to, uh, keep location data on you. And that way none of the attorneys general can ask us forward or subpoena it cuz we just don't have it. And that was all because of the overturn of the court ruling on abortion, the federal court. So it, it, to me, it it's just so disingenuous for these people to only care about privacy when it's about them.

[00:18:36] And I, I, I, again, I, I just don't understand it. My mother is that same way. I know she doesn't listen to this, so , I can say that, but it it's, uh, absolutely absolutely incredible to me that, uh, that, that happens. So what do you use. There there's a number of major search engines, real in the, in the world.

[00:18:59] Really what you're looking at is Google. It's like the, the 800 pound gorilla out there. And then you also have Bing Microsoft search engine. There have been a few that have come and gone. There's some that I liked better. Like I loved Alta Vista much better. Because it had ING algebra operations that you could do much better than Google.

[00:19:23] So I've ended up with Devon, think that I use now for searching if I need to, uh, to get real fancy searches going on, but I gotta mention duck dot go. Now it got a bit of a black eye recently, but the reality is if you want to keep your searches, private duck dot go is a way to go. Well, we talked about the top 100 hospitals in the country and how they were tracking you using Facebook or Google, uh, trackers cookies.

[00:19:59] And they would know, oh, you just registered an appointment with an oncologist or, or whatever it might. B right. Which is private information, duck dot go does not have any tractors on it. They do not keep a history of what you've been searching for and they do not sell that stuff to advertisers. Now behind duck dot go is Bing.

[00:20:23] But Bing does not get access to you. Only duck dot go does, and they don't keep any of that. So check it out online that kid's game used to play duck dot, go.com. Obviously I don't, uh, don't make any money off of that. Oh. And by the way, they have apps for Android and iOS and browser extensions stick around will be right back and visit me online.

[00:20:49] Craig peterson.com.

[00:20:52] I got a question from a parent whose son was serving over in the middle east and they were asking what was a safe messaging app to use. And they asked about what's app. So we're gonna talk about that right now.

[00:21:08] There are a lot of different messaging apps that people are using and they all have different features, right?

[00:21:17] Uh, there have different ways of doing things and the top are WhatsApp. Facebook messenger. Why would anyone use that? Uh, we chat again. Why would anyone use that vibe line telegram and IMO, which I'm not familiar with? This is according to ink magazine, the top seven messenger apps in the world. So why would people use those?

[00:21:47] Okay. So let's, let's just talk about them very briefly. The, the two top ones in my mind that I want to talk about, but WhatsApp has 2 billion active users. It's the number one messaging app followed by WeChat, which is a Chinese messaging app with 1.2 billion. Users and WeChat is also used to make payments.

[00:22:12] And they've got this whole social, social credit system in China, where they are tracking you deciding whether or not you posted something or said something in a chat that, uh, they don't like. And so you, you just, you can't get on the train to get to work and you lose your job, right. Yeah, they, they do that regularly.

[00:22:32] And there are people in the us here that are trying to do very similar things. This Congress has, uh, not been the best. Let me put it that way. So should you use that of. We chat now, obviously, no, the next one is Facebook messenger also called messenger by meta. And it has close to a billion users. And again, they are watching you.

[00:23:01] They are spying on you. They are tracking what you do, WhatsApp. I I use for, uh, one of my masterminds. The whole group is in on what's happened. I'm okay with that. Nothing terribly private that I'm worried about. There, there are things that are said or discussed that, that I'm not, uh, Perhaps happy that they're privy to, but in, in reality, WhatsApp is pretty good.

[00:23:29] Now you have to make sure that when you're using something, something like WhatsApp that you have to turn on their privacy features. For end to end security because that's been a, a historical problem with WhatsApp. Yeah. They can have end to end encryption, but you have to turn it on. So what is end to end encryption and why does it matter?

[00:23:57] Well, end to end encryption means if you are sending a message to someone or someones. They have, obviously have to have the same app that you do. And when it gets to the other side, uh, they can decrypt. So anyone in the middle. We'll just see a whole bunch of encrypted data, which just looks like trash. If, if it's encrypted properly, there's no real distinguishing, uh, portions to it.

[00:24:30] If you will, or identifying factors that it's anything other than just random data, really good, uh, encryption does that, right? It does a, and. compression first and, and then messes with, we're not gonna get into how all of that works. I helped way back when to put PGP together at, uh, Phil. Zimmerman's pretty good privacy.

[00:24:55] I actually still used some of that stuff today. And then PGP became G G, which is the GNU privacy, uh, G G and is well worth it as well. But that. Um, exactly what we're talking about. We're talking about regular messaging apps that regular people can use. I do use G G by the way, those of you who email me@craigpeterson.com, if it's actually me responding to you, it will be.

[00:25:26] A message. That's cryptographically signed by G G so that you can verify that it was me and it wasn't Mary, or it wasn't Karen. So I, I do that on purpose as well. All right. I'm sorry, wander around a little bit here. WhatsApp is pretty commonplace. And is pretty good. Well, WhatsApp, as I mentioned, end end encryption.

[00:25:50] But it's using the encryption from another project that's out there. And this is an open source project called signal. If you want to be secure. End to end if you don't want to leave any digital exhaust around use signal. It's very, very good. Um, Mo what is his name? Um, Moxi Marlin spike is the guy that founded it.

[00:26:15] He ran that company for quite a while. It's a foundation. And, uh, as I recall, early 20, 22, he stepped down as the head of that foundation and other people have taken over, but he's even threatened to, and I assume he actually did build in some things into signal. That will make some of these Israeli programs that are used to crack into cell phones.

[00:26:43] It'll make them fail. They'll crash because of bugs in their it's. Well, again, that's not what we're talking about right now, but signal. Again, if you're gonna send a message just like with WhatsApp, the other person, the receiver has to have signal on their device signals available for smartphones again, Android and iOS, you know?

[00:27:07] What I feel about Android, which is don't use it. You're much better off. If you don't have much of a budget buying an older model iPhone, they're gonna be a lot safer for you. So signal, it will also run on your windows, computer, or your Mac, the same thing with WhatsApp, by the way. So WhatsApp more common, not the worst thing in the world for privacy signal, less common and definitely very good for privacy.

[00:27:37] Now I mentioned apple here. I use max and I have ever, since they switched over to a Unix base, they actually put a mock microkernel and a free BSD user land, if and kernel on top of them. Um, the mock microkernel. So if, if you're total geek, you know what I'm talking about? It's designed to be safe and secure from the beginning.

[00:28:02] Whereas with windows and with Android, it was shoehorned in the security, the privacy, right. It just wasn't there. So what should you do? Well, I, I, as I mentioned, you should be. Apple iOS devices. I'm not the world's apple fan. Okay. Don't get me wrong, but they are a lot more secure and the max are also very secure again.

[00:28:32] Nothing's perfect. Uh, they have not been attacked as much as windows computers because of course, windows is more common, but having worked in the kernel and the network stack on both windows. Uh, the actual kernel, the actual source code of windows and Linux and BSD and system five. So all of the major core, uh, Linux distributions over the decades, I can tell you that.

[00:29:05] The Unix world is far, far more secure. Now you don't have to worry about it. People look at it and say, well, what should I use? Well, if you are a geek, you should probably be using Linux. I do use Linux, but I, I will admit my main workstation is a 10 year old Mac. 10 years old. Uh, how long do your windows machines last?

[00:29:31] Right. And, and it's still working great for me very fast. Still. It's a great little machine and we still have Mac laptops that are, uh, 20 years old. So they, they are designed and made to last same thing with the phones, but they can be more expensive. So look at refurbed, look at older models because it will save you.

[00:29:55] You can be in the same price range as windows. You can be in the same price range as Android, and you can have much, much better privacy and security stick around, cuz we'll be right back. And if you sign up for my email list, you'll get my free insider show notes every Tuesday or Wednesday morning.

[00:30:17] We're gonna talk about electric vehicles right now and what the wall street journal is calling the upside down logic of electric SUVs. And you know what? I agree with them here, but where are electric vehicles today and where are they going?

[00:30:34] Electric vehicles are an interesting topic because in reality, we're not ready for them.

[00:30:43] Our grid is not set up to handle electric vehicles. We are crazy what we're doing right now. Shutting down power plants. Germany is bringing nuclear plants that they had. Down back online. They're not fools. Nuclear is the cleanest right now, uh, source that we can possibly get don't fool yourselves by listening to people that tell you that, for instance, the solar cells you put on your roof are green because they are.

[00:31:14] Not highly toxic, the manufacturing, distribution, and disposal of those things, California, we talked about this a couple of weeks ago has a huge problem now because 90% of those solar panels on people's roofs are ending up in landfills and are leaking toxic metal. into what little, uh, underground water supply California still has left.

[00:31:42] And that's not just true of California. That's everywhere. So we are depending on more electricity, when we actually have less electricity, we're shutting things down. Look at Texas, right? They're oh, we're we're trying to be green, green, green, green, green, and people complain about Texas being conservative.

[00:32:01] It's not, it's just very independent. They have their own electric grid. The only state in the nation that has its own electric grid. That's not tied in. To anybody else. The whole rest of the country is composed of two grids. So if one state isn't producing quite enough, they can potentially buy it from another one here in the Northeast.

[00:32:24] We bring some of the power down from RI Quebec LAA, Leno. Over there in the north, right from the LG projects that they have up there. Of course it's from hydroelectric dams, but we, we exchange it all. We move it back and forth. But we're shutting down some of these relatively clean sources of energy, even cold now with all, all of the scrubbers and stuff.

[00:32:54] But if you look at nuclear, particularly the new nuclear, it is as safe. It's far safer than burning, uh, natural gas that so many grids burn look in New Hampshire, doubling doubled. It doubled the cost of electricity in new H. because we didn't bring on the second nuclear reactor in Seabrook. Right. And we're burning natural gas to generate most of our electricity.

[00:33:27] It doubled, it? It's absolutely crazy. The cost, the things that are happening in Washington and locally, like in New Hampshire, like in Texas, like in so many other states are making our lives much worse and. To top it all off. Now they're pushing electric vehicles, which again are not green. They are not safe.

[00:33:53] They are hazardous to the environment in so many ways, but particularly. By their manufacturing. So if consumers and businesses really cared about the carbon dioxide that they're emitting, right. That greenhouse gas that's, uh, you know, just absolutely terrible. Uh, they might buy what what's selling right now.

[00:34:19] Hmm. Not me. Look. Yeah, EVs electric vehicles like Ford Mustangs, mock E Hummers, EV that's from GM. The, uh, the wonderful new electric pickup. From Ford. Now these are huge vehicles. They are long range electric vehicles, which is what we want. Right. And they can be driven tens of thousands of miles before they rack up enough miles and save enough gasoline to compensate for the emissions created just to produce their batteries.

[00:34:56] And that's according to their fans. And when we're talking about the fans, their, their, uh, predictions, their estimates, their statistics typically are what? A little tainted. Right? We talked about that earlier. Yeah. So it, it, it gets to be a problem doesn't it gets to be real problem. So what are they doing in, instead of making the small electric vehicles, like the Nissan leaf?

[00:35:25] Which was a great little car. I've told the story of my neighbor, who has the, the leaves. He has a couple of them, and he installed a bunch of solar panels and he uses those to charge his leaves and to run around. Cuz most of what driving he does most driving, I do most of the driving, most people do is just short range, right?

[00:35:45] It's less than 30 miles. He just, he loves it. Right, but he's not doing it because it's green. He realizes that it harms the environment to have those solar cells and it harms the environment to drive those electric cars that were very harmful to be made the batteries right now from these electric cars, the outtakes they are storing just like nuclear waste, although there's far more of it than there is.

[00:36:15] The nuclear waste, a separate topic entirely, really? I guess there isn't a whole lot of correlation there, but they, they're not able to recycle so many of these batteries. We just don't have the technology for it. So why would you make these big electric vehicles, these sports utility vehicles, these trucks that have the long ranges.

[00:36:42] And not something that's nice and small th think European, right? Think of the stupid car from Merc. I mean the smart car from Mercedes, uh, that little tiny car that works great in European cities. Where you don't have a lot of space to park the roads. Aren't very wide. You can kind of zoom around zip in and out fine parking.

[00:37:02] And you're not going fast. Not going far makes sense. Right? Same thing with like a Prius with the smaller engines. And yet you see people whipping down the highway passing me. Doing the exact opposite thing that you'd think they'd wanna do. You're driving a small car with a small engine. Maybe it's a hybrid electric gas.

[00:37:24] Maybe it's a plug-in hybrid. To do what to stop CO2, supposedly to save the environment. And yet at the exact same time, you are causing more harm than you need to, to the environment by zooming down the highway. That's not what these things are made for, not what they're designed for, but that is what most people could use.

[00:37:45] And yet G. Ford Chrysler, none of them are making the vehicles that fit into that part of the marketplace. The other nice thing about the smaller vehicles is they don't require as long to charge cuz they don't have to charge up these big battery packs because you're not going that far. So it's less of a demand potentially on the grid.

[00:38:12] Because again, even if you drive that big electric SUV, 30 miles. You are hauling around a thousand pounds, maybe more of batteries that you don't actually need to haul around. See again, it goes back to how so many of us are looking at this stuff. Just like the original Prius poll that I've talked about.

[00:38:39] So many times where the number one reason people said that they drove a Prius. This was some 70% of the people was because of what they thought the purchaser of the Prius thought other people would think about them. , this is, this is a real, real problem. You know, the assumption that electric vehicle stops oil from coming out of the ground stops natural gas from coming out of the ground, stops coal from being mined.

[00:39:08] That assumption is problematic because it is not true. And when it comes to the carbon footprint, again, I obvious. Obviously the, the environment is changing. The temperatures are changing. It it's obvious, right? Climate denier, some might call me, but it's obvious that climate's changing. It has always been changing Mount Saint Helen's eruption, put more carbon dioxide into the atmosphere than mankind has since the beginning of.

[00:39:46] So look at these volcanic eruptions and say, oh, okay. So we've barely scratched the surface as humankind, far less than 1% of global warming is actually caused by humans. but it it's about control, but this isn't a political show. Uh okay. Uh, I guess I am. So let's talk about the next article I had in my newsletter that came out this week again, Tuesday or Wednesday, you can sign up for it.

[00:40:17] It's absolutely free. This is my free newsletter@craigpetersondotcomorjustsendmeanemailmeatcraigpeterson.com and ask to be signed up. It looks like president Biden is maybe thinking about going nuclear. I talked about this on the air earlier this week, cuz there's a couple of really interesting things happening.

[00:40:41] One is the federal government has authorized some of these new nuclear technologies. To go online. So they've got these different plants. There's a number of different types of plants that are out there and different technologies, but all of them hyper safe and they are actually in small production.

[00:41:07] Pretty darn cool. The second thing which I found particularly interesting is that at least. Three times over the last few weeks, president Biden has talked about nuclear power just in passing, right? He, I think he's trying to get his base to get used to the idea because he's been trying to eliminate all forms of energy consumption, but he does seem to maybe favor development of nuclear power or whoever is writing his speeches for him, you know, nuclear.

[00:41:41] Is carbon friendly, very carbon friendly, friendlier than windmills or solar parks. And it's a lot more reliable. So I'm, I'm happy about that new plants coming online, just small ones. And that frankly is the future of nuclear, not these huge, huge, and they, he he's talking about it. We'll see, it's absolutely green.

[00:42:07] Even as I mentioned, Germany is bringing nuclear plants back online and the European union has declared that nuclear is green technology. And. I'm shocked here because apparently I'm agreeing with the European parliament. Oh wow. What's going on? Hey, visit me online. Craig peterson.com. Make sure you get my insider show notes and the trainings that come out.

[00:42:39] Craig peterson.com.

[00:42:41] Hey, it looks like if you did not invest in crypto, you were making a smart move and not moving. Wow. We got a lot to talk about here. Crypto has dived big time. It's incredible. What's happened. We get into that more.

[00:42:58] Crypto currencies. It, it it's a term for all kinds of these basically non-government sanctioned currencies.

[00:43:08] And the idea behind it was I should be able to trade with you and you should be able to trade with me. We should be able to verify the transactions and it's kind of nobody's business as to what's happening behind the scenes. And yet in reality, Everybody's business because all of those transactions are recorded in a very public way.

[00:43:33] So crypto in this case does not mean secret or cryptography. It's actually referring to the way the ledgers work and your wallets and, and fact, the actual coins themselves, a lot of people have bought. I was talking with my friend, Matt earlier this week and Matt was saying, Hey, listen, uh, I made a lot of money off of crypto.

[00:43:59] He's basically a day trader. He watches it. Is it going up? Is it going down? Which coin is doge coin? The way to go? Cuz Elon must just mentioned it. Is it something else? What should I do? And he buys and sell and has made money off of it. However, a lot of people have. And held onto various cryptocurrencies.

[00:44:21] Of course, the most popular one. The one everybody knows about is Bitcoin and Bitcoin is pretty good stuff, you know, kind of bottom line, but 40% right now of Bitcoin investors are underwater. Isn't that incredible because of the major dropoff from the November peak. And this was all started by a problem that was over at something called Tara Luna, which is another cryptocurrency now.

[00:44:53] You know, already that there is a ton of vol a ton of, uh, changes in price in various cryptocurrencies, Bitcoin being of course a real big one where, you know, we've seen 5,000, $10,000 per Bitcoin drops. It, it really is an amazingly, uh, fluid if you will coined. So there's a number of different people that have come out with some plans.

[00:45:21] How about if we do kinda like what the us dollar used to do, which is it's tied to a specific amount of gold or tied to a specific amount of silver. Of course, it's been a while since that was the case. Uh, president Nixon is the one that got us off of those standards, but. Having gold, for instance, back in your currency means that there is going to be far less fluctuation and your currency means something.

[00:45:51] See, the whole idea behind currency markets for government is yeah, you do print money and you do continue to increase the amount of money you print every year. Because what you're trying to do is create money for the. Goods product services that are created as well. So if, if we create another million dollars worth of services in the economy, there should be another million dollars in circulation that that's the basic theory.

[00:46:22] Monetary theory really boiling it. Right. Down now of course, you know, already our government has printed way more than it. Maybe should have. It is certainly causing inflation. There's no doubt about that one. So they're looking at these various cryptocurrencies and saying, well, what can we do? How can we have like a gold standard where the us dollar was the currency of the world used and it all its value was known.

[00:46:48] You see, having a stable currency is incredibly important for consumers and businesses. A business needs to know, Hey, listen, like we sign a three year contract with our vendors and with our customers. And so we need a stable price. So we know what's our cost going to be, what can we charge our customer here?

[00:47:08] Can the customer bear the price increases, et cetera. The answer to most of those questions of course is no, they really, they really can't is particularly in this day and age. So having. Fixed currency. We know how much it's worth. I know in two years from now, I'm not gonna be completely upside down with this customer because I'm having to eat some major increases in prices.

[00:47:33] And as a consumer, you wanna look at it and say, wow, I've got a variable rate interest rate on my mortgage. And man, I remember friends of mine back in the eighties, early eighties, late seventies, who just got nailed by this. They had variable rate interest loan on their home because that's all they could get.

[00:47:52] That's all they could afford. So the variable rate just kept going up. It was higher than credit cards are nowadays. And I remember a friend of mine complaining, they had 25% interest and that's when they lost a house because 25% interest means if you have a a hundred thousand dollars loan, you got $25,000 in interest that year, you know, let alone principal payments.

[00:48:16] So it, it was a really. Thing. It was really hard for people to, to deal with. And I, I can understand that. So the cryptocurrency guys. I said, okay, well let's tie it to something else. So the value has a value and part of what they were trying to tie it to is the us dollar. That's some currencies decided to do that.

[00:48:41] And there were others that tried to tie it to. Assets. So it wasn't just tied to the dollar. It was okay. We have X dollars in this bank account and that's, what's backing the value of our currency, which is quite amazing, right. To think about that. Some of them are backed by gold or other precious metals.

[00:49:04] Nowadays that includes a lot of different metals. Well, this one coin called Tara Luna dropped almost a hundred percent last. Isn't that amazing. And it had a sister token called Tara us D which Tara Luna was tied to. Now, this is all called stablecoin. Right? The idea is the prices will be stable. and in the case of Tara and Tara S D the stability was provided by a computer program.

[00:49:39] So there's nothing really behind it, other than it can be backed by the community currencies themselves. So that'ss something like inter coined, for instance, this is another one of the, there are hundreds of them out there of these, uh, cryptocurrencies. The community backs it. So the goods and services that you can get in some of these communities is what gives value to inter Pointe money system.

[00:50:05] Now that makes sense too, right? Because the dollar is only worth something to you. If it's worth something to someone else, right. If you were the only person in the world that had us dollars, who, who would want. Like, obviously the economy is working without us dollars. So why would they try and trade with you?

[00:50:27] If you had something called a us dollar that nobody else had, or you came up with something, you made something up out of thin air and said, okay, well this is now worth this much. Or it's backed by that et. Because if again, if you can't spend it, it's not worth anything. Anyhow, this is a very, very big deal because on top of these various cryptocurrencies losing incredible amounts of money over the last couple of weeks, We have another problem with cryptocurrencies.

[00:51:01] If you own cryptocurrencies, you have, what's called a wallet and that wallet has a transaction number that's used for you to track and, and others to track the money that you have in the cryptocurrencies. And it it's, um, pretty good. Fun function or feature. It's kind of hard for a lot of people to do so they have these kind of crypto banks.

[00:51:23] So if you have one of these currencies, you can just have your currency on deposit at this bank because there's, there's a whole bunch of reasons, but one of the reasons is if. There is a, a run on a bank, or if there's a run on a cryptocurrency, currencies have built into them incredibly expensive penalties.

[00:51:47] If you try and liquidate that cryptocurrency quickly. And also if there are a lot of people trying to liquidate it. So you had kind of a double whammy and people were paying more than three. Coin in order to sell Bitcoin. And so think about that. Think about much of Bitcoin's worth, which is tens of thousands of dollars.

[00:52:07] So it's overall, this is a problem. It's been a very big problem. So people put it into a bank. So coin base is one of the big one coin coin base had its first quarter Ernie's report. Now, this is the us' largest cryptocurrency exchange and they had a quarterly loss for the first quarter of 2022 of 430 million.

[00:52:37] That's their loss. And they had an almost 20% drop in monthly users of coin. So that's something right. And they put it in their statement, their quarterly statement here as to, you know, what's up. Well, here's the real scary part Coinbase said in its earning earnings report. Last Tuesday that it holds the.

[00:53:03] 256 billion in both Fiat currencies and crypto currencies on behalf of its customers. So Fiat currencies are, are things like the federal reserve notes, our us dollar. Okay. A quarter of a trillion dollars that it's holding for other people kind of think of it like a bank. However, they said in the event, Coinbase we ever declare bankruptcy, quote, the crypto assets.

[00:53:33] We hold in custody on behalf of our customers could be subject to bankruptcy proceedings. Coinbase users would become general unsecured creditors, meaning they have no right to claim any specific property from the exchange in proceedings people's funds would become inaccessible. Very big deal. Very scary for a very, very good reason.

[00:54:00] Hey, when we come back, uh, websites, you know, you go, you type stuff in email address, do you know? You don't even have to hit submit. In most cases, they're stealing it.

[00:54:12] I'm sure you've heard of JavaScript in your browser. This is a programming language that actually runs programs right there in your web browser, whether you like it or not. And we just had a study on this. A hundred thousand websites are collecting your. Information up-front.

[00:54:29] I have a, in my web browser, I have JavaScript turned off for most websites that I go to now, JavaScript is a programming language and it lets them do some pretty cool things on a webpage.

[00:54:43] In fact, that's the whole idea behind Java. Uh, just like cookies on a web browser where they have a great use, which is to help keep track of what you're doing on the website, where you're going, pulling up other information that you care about, right? Part of your navigation can be done with cookies. They go on and on in their usefulness, but.

[00:55:06] Part of the problem is that people are using them to track you online. So like Facebook and many others will go ahead and have their cookies on other websites. So they know where you're going, what you're doing, even when you're not on Facebook, that's by the way, part of. The Firefox browser's been trying to overcome here.

[00:55:30] They have a special fenced in mode that happens automatically when you're using Firefox on Facebook. Pretty good. Pretty cool. The apple iOS devices. Use a different mechanism. And in fact, they're already saying that Facebook and some of these others who sell advertiser, Infor advertisers information about you have really had some major losses in revenue because apple is blocking their access to certain information about you back to Javas.

[00:56:07] It's a programming language that they can use to do almost anything on your web browser. Bad guys have figured out that if they can get you to go to a website or if they can insert and add onto a page that you're visiting, they can then use. Your web browser, because it's basically just a computer to do what well, to mind Bitcoin or other cryptocurrencies.

[00:56:33] So you are paying for the electricity for them as your computer is sitting there crunching on, uh, these algorithms that they need to use to figure out how to find the next Bitcoin or whatever. Be, and you are only noticing that your device is slowing down. For instance, our friends over on the Android platform have found before that sometimes their phones are getting extremely hot, even when they're not using them.

[00:57:00] And we've found that yeah, many times that's just a. Bitcoin minor who has kind of taken over partial control of your phone just enough to mind Bitcoin. And they did that through your web browser and JavaScript. So you can now see some of the reasons that I go ahead and disable JavaScript on most websites I go to now, some websites aren't gonna work.

[00:57:23] I wanna warn you up front. If you go into your browser settings and turn off JavaScript, you are going. Break a number of websites, in fact, many, many websites that are out there. So you gotta kind of figure out which sites you want it on, which sites don't you want it on. But there's another problem that we have found just this week.

[00:57:44] And it is based on a study that was done. It's reported in ours Technica, but they found. A hundred thousand top websites, a hundred thousand top websites. These include signing up for a newsletter making hotel reservation, checking out online. Uh, you, you probably take for granted that you nothing happens until you hit submit, right?

[00:58:10] That used to be the case in web 1.0 days. It isn't anymore. Now I wanna point out we, I have thousands of people who are on my email list. So every week they get my, my, uh, insider show notes. So these are the top articles of the week. They are, you know, usually six to 10 articles, usually eight of them that are talking about cybersecurity, things of importance in.

[00:58:38] The whole radio show and podcast are based on those insider show notes that I also share with the host of all of the different radio shows and television shows that I appear on. Right. It's pretty, pretty cool. So they get that, but I do not use this type of technology. Yeah. There's some JavaScript that'll make a little sign up thing, come up at the top of the screen, but I am not using technology that is in your face or doing.

[00:59:07] What these people are doing, right? So you start filling out a form. You haven't hit cement. And have you noticed all of a sudden you're getting emails from. Right. It's happened to me before. Well, your assumption about hitting submit, isn't always the case. Some researchers from KU LUN university and university of Lue crawled and analyzed the top 100,000 websites.

[00:59:37] So crawling means they have a little robot that goes to visit the webpage, downloads all of the code that's on the page. And then. Analyzed it all right. So what they found was that a user visiting a site, if the, the user is in the European union is treated differently than someone who visits the site from the United States.

[01:00:00] Now there's a good reason for this. We've helped companies with complying with the GDPR, which are these protection rules that are in place in the European union. And that's why you're seeing so many websites. Mine included that say, Hey, listen, we do collect some information on you. You can click here to find out more and some websites let just say no, I don't want you to have any information about me.

[01:00:25] We collect information just so that you can navigate the site properly. Okay. Very basic, but that's why European union users are treated differently than those coming from the United States. So this new research found that over 1800 websites gathered an EU user's email address without their consent. So it's almost 2000 websites out of the top 100,000.

[01:00:54] If you're in the EU and they found. About well, 3000 websites logged a us user's email in some form. Now that's, before you hit submit. So you start typing in your email, you type in your name and you don't hit submit. Many of the sites are apparently grabbing that information, putting it into the database and maybe even starting using it before you gave them explicit permission to do.

[01:01:27] Isn't that a fascinating and the 1800 sites that gathered information on European news union users without their consent are breaking the law. That's why so many us companies decided they had to comply with the GDPR because it's a real big problem. So these guys also crawled websites for password leaks and May, 2021.

[01:01:54] And they found 52 websites where third parties, including Yex Yex is. Big Russian search engine a and more were collecting password data before submission. So since then the group went ahead and let the websites know what was happening, what they found, uh, because it's not necessarily intentional by the website itself.

[01:02:20] It might be a third party, a third party piece of software. That's doing it. They, they informed those sites. Hey, listen, you're collecting user data before there's been explicit consent to collect it. In other words, you, before you hit the submit button and they thought, wow, this is a very surprising, they thought they might find a few hundred website, but.

[01:02:44] Course of a year now they found that there were over 3000 websites really that were doing this stuff. So they presented their findings at Usenet. Well, actually they haven't presented 'em yet. Cuz it's gonna be at use N's. In August and these are what they call leaky forums. So yet another reason to turn off JavaScript when you can.

[01:03:08] But I also gotta add a lot of the forums do not work if JavaScript's not enabled. So we gotta do something about it. Uh, maybe complain, make sure they aren't collecting your. Maybe I should do a little course on that one so you can figure out are they doing it before even giving permission? Anyhow, this is Craig Peter son.

[01:03:29] Visit me online. Craig Peter son.com and sign up for that. No obligation inside your show notes.

[01:03:35] We are shipping all kinds of military equipment over to Ukraine. And right now they're talking about another $30 billion worth of equipment being shipped to what was the world's number one arms dealer Ukraine.

[01:03:52] I'm looking right now at an article that was in the Washington post. And you know, some of their stuff is good.

[01:04:00] Some of their stuff is bad, I guess, kinda like pretty much any media outlet, but they're raising some really good points here. One of them is that we are shipping some pretty advanced equipment and some not so advanced equipment to Ukraine. To help them fight in this war to protect themselves from Russia.

[01:04:24] Now, you know, all of that, that's, that's pretty common. Ultimately looking back in history, there have been a lot of people who've made a lot of money off of wars. Many of the big banks financing, both sides of wars. Going way, way back and coming all the way up through the 20th century. And part of the way people make money in war time is obviously making the equipment, the, and supplies and stuff that the armies need.

[01:04:57] The other way that they do it is by trading in arms. So not just the supplies. The bullets all the way through the advanced missile systems. Now there's been some concerns because of what we have been seen online. We've talked about telegram here before, not the safest web, you know, app to use in order to keep in touch.

[01:05:23] It's really an app for your phone and it's being used. Ukraine to really coordinate some of their hacker activities against Russia. They've also been using it in Russia, te telegram that is in order to kind of communicate with each other. Ukraine has posted pictures of some of the killed soldiers from Russia and people have been reaching out to their mothers in Russia.

[01:05:53] They've done a lot of stuff with telegram it's interest. And hopefully eventually we'll find out what the real truth is, right? Because all sides in the military use a lot of propaganda, right? The first casualty in war is the truth. It always has been. So we're selling to a country, Ukraine that has made a lot of money off of selling.

[01:06:18] Been systems being an inter intermediary. So you're not buying the system from Russia? No, no. You're buying it from Ukraine and it has been of course, just as deadly, but now we are sending. Equipment military great equipment to Ukraine. We could talk about just that a lot. I, I mentioned the whole lend lease program many months ago.

[01:06:44] Now it seems to be in the news. Now takes a while for the mainstream media to catch up with us. I'm usually about six to 12 weeks ahead of what they're talking about. And so when we're talking about Lynn Le, it means. We're not giving it to them. We're not selling it to them. We're just lending them the equipment or perhaps leasing it just like we did for the United Kingdom back in world.

[01:07:10] Wari, not a bad idea. If you want to get weapons into the hands of an adversary and not really, or not an adversary, but an ally or potential ally against an adversary that you have, and they have. But part of the problem is we're talking about Ukraine here. Ukraine was not invited in NATO because it was so corrupt.

[01:07:33] You might remember. they elected a new president over there that president started investigating, hired a prosecutor to go after the corruption in Ukraine. And then you heard president Joe Biden, vice president at the time bragging about how he got this guy shut down. Uh, yeah, he, he got the prosecutor shut down the prosecutor that had his sights on, of course hunter Biden as well as other people.

[01:08:00] So it it's a real problem, but. Let's set that aside for now, we're talking about Ukraine and the weapon systems we've been sending over there. There have been rumors out there. I haven't seen hard evidence, but I have seen things in various papers worldwide talking about telegrams, saying. That the Ukrainians have somehow gotten their hands on these weapons and are selling them on telegram.

[01:08:29] Imagine that, uh, effectively kind of a dark web thing, I guess. So we're, we're saying, well, you know, Biden administration, uh, you know, yeah. Okay. Uh, that, that none of this is going to happen. Why? Well, because we went ahead and we put into the contracts that they could not sell or share or give any of this equipment away without the explicit permission of the United States go.

[01:09:00] Well, okay. That, that kind of sounds like it's not a bad idea. I would certainly put it into any contract like this, no question, but what could happen here? If this equipment falls into the hands of our adversaries or, or other Western countries, NATO countries, how do you keep track of them? It it's very hard to do.

[01:09:22] How do you know who's actually using. Very hard to do so enforcing these types of contracts is very difficult, which makes a contract pretty weak, frankly. And then let's look at Washington DC, the United States, according to the Washington post in mid April, gave Ukraine a fleet of I 17 helicopter. Now these MI 17 helicopters are Russian, originally Soviet designs.

[01:09:55] Okay. And they were bought by the United States. About 10 years ago, we bought them for Afghan's government, which of course now has been deposed, but we still have our hands on some of these helicopters. And when we bought them from Russia, We signed a contract. The United States signed a contract promising not to transfer the helicopters to any third country quote without the approval of the Russian Federation.

[01:10:27] Now that's according to a copy of the certificate that's posted on the website of Russia's federal service on military technical cooperation. So there you. Russia's come out and said that our transfer, those helicopters has grossly violated the foundations of international law. And, and you know, what they, it has, right.

[01:10:48] Arms experts are saying that Russia's aggression Ukraine more than justifies us support, but the violations of the weapons contracts, man, that really hurts our credibility and the, our we're not honoring these contract. How can we expect Ukraine to honor those contracts? That's where the problem really comes in.

[01:11:13] And it's ultimately a very, very big problem. So this emergency spending bill that it, you know, the $30 billion. Makes Ukraine, the world's single largest recipient of us security assistance ever. They've received more in 2022 than United States ever provided to Afghanistan, Iraq, or Israel in a single year.

[01:11:40] So they're adding to the stockpiles of weapons that we've already committed. We've got 1400 stinger anti-aircraft systems, 5,500 anti tank, Mitch missiles, 700 switch blade drones, nine 90. Excuse me, long range Howards. That's our Tillery 7,000 small arms. 50 million rounds of ammunition and other minds, explosives and laser guided rocket systems, according to the Washington post.

[01:12:09] So it's fascinating to look. It's a real problem. And now that we've got the bad guys who are using the dark web, remember the dark web system that we set up, the onion network. Yeah. That one, uh, they can take these, they can sell them, they can move them around. It is a real problem. A very big problem. What are we gonna do when all of those weapons systems come back aimed at us this time?

[01:12:40] You know, it's one thing to leave billions of dollars worth of helicopters, et cetera, back in Afghanistan is the Biden administration did with their crazy withdrawal tactic. Um, but at least those will wear out the bullets, missile systems, Howard, yours, huh? Different deal.

[01:13:00] It seems like the government calls war on everything, the war against drugs or against poverty. Well, now we are looking at a war against end to end encryption by government's worldwide, including our own.

[01:13:17] The European union is following in America's footstep steps, again, only a few years behind this time.

[01:13:26] Uh, but it's not a good thing. In this case, you might remember a few have been following cybersecurity. Like I have back in the Clinton administration, there was a very heavy push for something called the clipper chip. And I think that whole clipper chip. Actually started with the Bush administration and it was a bad, bad thing, uh, because what they were trying to do is force all businesses to use this encryption chip set that was developed and promoted by the national security agency.

[01:14:04] And it was supposed to be an encryption device that is used to secure, uh, voice and data messages. And it had a built in. Back door that allowed federal state, local law enforcement, anybody that had the key, the ability to decode any intercepted voice or data transmissions. It was introduced in 93 and was thank goodness.

[01:14:32] Defunct by 1996. So it used something called skip Jack man. I remember that a lot and it used it to transfer dilly or Diffy excuse me, Hellman key exchange. I've worked with that before crypto keys. It used, it used the, uh, Des algorithm, the data encryption standard, which is still used today. And the Clinton administration argued that the clipper chip.

[01:14:59] Absolutely essential for law enforcement to keep up with a constantly progressing technology in the United States. And a lot of people believe that using this would act as frankly, an additional way for terrorists to receive information and to break into encrypted information. And the Clinton administration argued that it, it would increase national security because terrorists would have to use it to communicate with outsiders, bank, suppliers, contacts, and the government could listen in on those calls.

[01:15:33] Right. Aren't we supposed to in United States have have a right to be secure in our papers and other things, right? The, the federal government has no right to come into any of that stuff unless they get a court order. So they were saying, well, we would take this key. We'll make sure that it's in a, a lock box, just like Al gore social security money.

[01:15:55] And no one would be able to get their hands on it, except anyone that wanted to, unless there was a court order and you know how this stuff goes, right. It, it just continues to progress. And. A lot worse. Well, there was a lot of backlash by it. The electronic privacy information center, electronic frontier foundation boast, both pushed back saying that it would not.

[01:16:20] Only have the effect of, of not, excuse me, have the effect of this is a quote, not only subjecting citizens to increased impossibly illegal government surveillance, but that the strength of the clipper trips encryption could not be evaluated by the public as its design. Was classified secret and that therefore individuals and businesses might be hobbled with an insecure communication system, which is absolutely true.

[01:16:48] And the NSA went on to do some things like pollute, random number generators and other things to make it so that it was almost impossible to have end-to-end encrypted data. So we were able to kill. Many years ago. Now what about 30 years ago? Uh, when they introduced this thing? Well, it took a few years to get rid of it, but now the EU is out there saying they want to stop end, end encryption.

[01:17:15] The United States has already said that, or the new director of Homeland security has, and as well as Trump's, uh, again, Homeland security people said we need to be able to break the. And, and we've talked about some of the stories, real world stories of things that have happened because of the encryption.

[01:17:36] So the EU has now got a proposal forward that would force tech companies to scan private messages for child sexual abuse material called CSAM and evidence of grooming. Even when those messages are, are supposed to be protected by end to end encrypt. So we know how this goes, right? It, it starts at something that's, everybody can agree on, right?

[01:18:04] This child, sexual abuse material, uh, abductions of children, all, you know, there's still a lot of slavery going on in the world. All of that stuff needs to be stopped. And so we say, yeah, yeah. Okay. That makes a whole lot of sense, but where does it end? Online services that receive detection orders. This is from ours Technica under the pending European union legislation would have obligations concerning the detection, the reporting, the removal and blocking of known and new.

[01:18:37] Child sexual abuse material as well as solicitation of children. So what we're starting to see here in the us is some apps, some companies that make smartphones, for instance, looking at pictures that are sent and shared to see if it looks like it might be pornographic in some way. because again, we're seeing younger kids who are sending pictures of each other naked or body parts naked to others.

[01:19:04] If you can believe that. Absolutely incredible. But what happens when you send them using an end-to-end encrypted app? Now, my advice for people who want to keep information private, you're a business person you're working on a deal. You don't go to Twitter like Elon Musk and put it out there for the world to.

[01:19:26] Although, I'm sure he's got some ulterior motives in doing that. You use an app called signal. That's certainly the best one that's out there right now. It provides a whole lot of encryption and privacy, and even has some stuff built in to break the software. That's often used to break into the end end encryption systems.

[01:19:47] So they're trying to get this in place here. They're calling it an important security tool. But it's ordering companies to break that end to end encryption by whatever technological means necessary. It it's gonna be hard because frankly it's gonna be impossible for them to enforce this because you can take encrypted data and make it look like almost.

[01:20:11] Anything, and man has that happened for a long time. Think of the micro dots, way back when Seline world, world war II and on, they were very popular there's techniques to encrypt data and embedded in a photograph and make it almost impossible to detect. So again, they're, they're not going to get to do what they're hoping to do.

[01:20:36] And, and I think that's an important thing for everybody. Pay pay close attention to, so they do want to get rid of end to end there's WhatsApp out there, which I don't really trust cuz is owned by Facebook, but that's supposedly end to end. There's end to end encryption on apple iMessage, although up.

[01:20:56] Apparently, there are some ways to get into that. I think apple is now maintaining a secondary key that they can use to decrypt, but the back doors that the us has called for and other people have called for. Have been pushed back by companies like apple Apple's CEO, Tim cook, opposed government mandated back doors.

[01:21:20] Of course, apple got a major backlash from security experts when unveiled a plan to have iPhones and other devices, scan user photos for child sexual abuse images. That's what I was referring to earlier. And apple put that plan on hold and promised to make changes. But this is apple all over again. And it's hard to say what's the least privacy intrusive way, because if the is S P can read them all, if the company that's providing you with the app that you're using to send the message.

[01:21:52] Can read them all, how much privacy is there and if they can read it, who else can read it and what can be done with it? Blackmail has happened many times in the past because someone got their hands on something. So what happens when a, a Congressman or the military or someone in the military uses that that's another problem.

[01:22:14] Because if we don't know the way the encryption is is, is, uh, being used or is made just like, was true with a clipper chip. And then we move on to the next step, which is okay. So what do we do now with this data that we're storing? Are they going to keep that data confidential? Can they keep it outta the hands of the criminals.

[01:22:38] We've certainly found that they just haven't been able to. And if you're talking about grooming, which is what the European union wants. In other words, someone that's trying to get a child to the point where they're doing something that would be abhorrent. Uh, you've got to. Look at all of the, all of the messages, you have to have them analyzed by some sort of an AI artificial intelligence, and then ultimately analyzed by people.

[01:23:04] It it's just gonna get worse and worse. Right? This is the most sophisticated mass surveillance machinery. That has ever been deployed outside of China in the USSR. It, it's absolutely incredible when you look at it from a cryptographic standpoint. And again, we understand protecting the children. We all want to do that, but how far will this end up going?

[01:23:28] I also wanna point out that my. New, uh, insider show notes that I've been sending out over the last few weeks have had some amazing responses from people. I I've had people saying that this is what they look for in their mailbox. It's the first piece of email they read that it's the most relevant news that they get.

[01:23:49] But you can only get it one way and that's by going to Craig peterson.com, you can sign up there. It's easy enough to do. There's no obligation on your part, right? This is not my paid newsletter. This is absolutely free. And it's incredibly valuable. Plus I'll also be sending you once a week-ish a small training, just, it takes you a few minutes to read.

[01:24:13] I just last week went through the firewall in your windows machine, the firewall in. And gave you step by step instructions. Is it turned on? What is it doing? What should it do? How do you turn it on and how do you use it? So you can only get that one way and that's, if you are on my email list, so it's important to be there.

[01:24:35] And if you have any questions, you can hit reply. Any of those emails, whether it's the training or if it's the insider show notes, just hit re reply. And I'll go ahead and answer your question. You might have to wait a few days cuz I can get pretty busy sometimes, but always answer. So me, me@craigpeterson.com.

[01:24:57] Anybody can send me email and you can also text me at 617-500-3221 with any questions. Well, that's it for right now, there is so much more. Make sure you sign up right now. And of course there's more coming right up. So stick around.

View Details

Solar Cells Are Polluting Our Groundwater
The Resurrection of Coal Plans By MIT
Latest Cyberattacks
Will Elon Musk Beat Twitter?

We all want a green world. I can't think of anybody that doesn't want one, but there are people with ulterior motives. That's a different thing, but California has really caused itself a whole lot of non green. Rooftop solar, right? That's gonna be the solution to all of our problems.

[Automated transcript follows.]

Not the fact that the electric cars, people buy use three times as much electricity as our air conditioners yet. Not the fact that we have rolling blackouts because we don't have enough. Power cuz we've shut down plants before we were actually ready to replace that power. Not that Texas is right now having blackouts as is California having blackouts because of this stupidity.

[00:00:52] Of some of these regulators. It's absolutely crazy. You know, we are the greenest country in the world. All of our plants, our coal plants are cleaner than anybody else's anywhere in the world. And California's. Really got itself into a big problem here, because again of shortsightedness, I just don't get it.

[00:01:16] You know, maybe it is follow the money, maybe, you know, Nancy Pelosi's husband making millions of dollars and, and, uh, using inside information is, is absolutely true. And, uh, maybe it. To do with that, right? It's not really green it's to enrich the politicians. How can you go to Washington DC on the salary?

[00:01:37] Congress has as expensive as it is in Washington, DC and come out a multimillionaire. Uh, there's only one way that can happen. Right. I, I remember the, the trade that Hillary Clinton made, what was it? Beef or something. Right. And she made like $80,000. Well, you know, that sort of tip is a sort of thing.

[00:01:58] That'll put Martha Stewart in jail, but not our politicians. It's absolutely crazy. I don't get it. So California, they have been a pioneer in push. For rooftop, solar panels. Now I get it. They're cool. I get it. It's really nice to have the grid buy electricity back from you when there is plenty of sun and when the grid needs it, but the grids aren't really set up for this sort of stuff.

[00:02:31] But I, I know a few listeners that really love their solar panels. There's one guy. Who has put a whole bunch of panels up solar panels in a field, and he has some cattle and horses and stuff. And so they, they live with these solar panels in the field and he bought himself a couple of Nissan leaves.

[00:02:52] These are these electric cars from Nissan. You might remember them. They've been around for a while and he's just tickled pink that yeah. He had to buy the solar panels. Yeah. He had to install of them. Yeah. He has to keep the snow off of them. Yeah. He has to clean the dust off of them. Yeah. He has to clean, uh, all of the bird stuff off of them, but it's.

[00:03:14] Right. Yeah. Okay. So he gets to drive around and he says, you know, I don't usually go much further than the grocery store or maybe a quick under tractor supply. And it, it, it doesn't cost him anything incrementally. So California decided it was going to go green, green, green, green. Right. And what's one of the best ways to do that.

[00:03:36] Well, we need more electricity. Let's go for rooftop. Solar in. California decided it would go ahead and subsidize these wonderful solar panels on people's roofs all over the place. Not, not like one big central farm, uh, out in the Mohave desert, that's collecting all of the solar. It can possibly collect and then turn it into electricity that can feed into the grid.

[00:04:04] No, it's all decentralizes on all of these rooftops now. We're talking about 20 years later, there are 1.3 million rooftops estimated to have solar cells on them out there in California. And the real bill is coming due. It isn't cleaning the, you know, the bird increment off. Yeah. The real bill in California for the rooftop solar isn't getting the snow off of them.

[00:04:32] Keeping them clean. No, it has to. With completely non-green stuff here. 90% of all of these solar cells that were put onto roofs in California that have been taken down 90% of them have ended up in landfills. Yeah, absolutely. Now the lifetime expectant, uh, lifetime of these solar panels is, uh, 25, maybe 30.

[00:05:05] As long as they're not damaged, or if you really wanna keep up with the technology because solar panels are increasing in efficiency, as time goes on, might be a lot less, right. Might be like a 10 to 15 years cycle. If you have that much money out there. But many of these are now winding up in landfills.

[00:05:25] And the real concern is that they could contam. Groundwater. I've talked about this before. If these solar panels crack, what could happen while they have heavy toxic metals in them such as lead, we know how bad lead is, right. Can't have lead in your house anymore. A selenium cadmium. Right? All things you don't want to have mercury, mercury vapor, you don't want to go anywhere near mercury vapor.

[00:05:54] Uh, except for the fact that the federal government forced us to put them into our homes in the form of purely Q light bulbs. Remember those things? Yeah. Highly toxic breaking. One of those light bulbs, a fluorescent light makes your home a toxic waste site. According to EPA regulations. So I'm sure if you ever had a, a fluorescent light bulb break and that includes the bigger ones, right.

[00:06:21] You might have in the roof, uh, up on the, the top of your office, uh, you know, wherever it might be, you, you, you must have, um, went out and you, you bought, maybe you even had standing by for you some really wonderful. Plastic that you could put up, you know, tape up so that you can isolate the room that has the toxic waste in it, from breaking that light bulb that the federal government made you buy, because you couldn't buy regular incandescent bulbs that you wanted anymore.

[00:06:52] And, uh, they encouraged you and they gave you discounts on it and they subsidize. Yeah. Yeah. Those bulbs. And then, uh, of course you went in with a full respirator and a full suit on that, uh, you know, Tyvec and you taped it up, make sure that tape up around the gloves onto the Tyvec suit so that none of that mercury gets.

[00:07:12] Onto your skin. And, and then you obviously used a specialized vacuum cleaner for toxic hazardous waste and, and vacuumed up like the carpet or the floor, maybe it got onto your couch. Right? You, you did all of that. And then you put it all into a sealed, uh, container of some sort, typically like a glass bottle or something.

[00:07:36] So it's not gonna be able to. Out right. You, you must have done all of that because I I'm sure everyone knew what was going on with those fluorescent bulbs, those little curly Q bulbs. Right. Does that make sense to you? Yeah. Yeah, exactly. So now, California. has 1.3 million rooftops with rooftops, solar power on them.

[00:08:04] Now it isn't like it's out in, as I mentioned a great place, but it out in the Mojave desert, right. They got more sun than they need out there. And so it's all one place and they can take those panels and they can recycle them. No, no, because it's illegal to recycle them in California. Because of the heavy metals, the toxic metals.

[00:08:26] So instead of that, people are just dumping them in their trash and taking them to landfills, et cetera, et C. We're talking about truckloads of waste, some of this stuff badly contaminated, and it really shows how short sight, uh, environmental policy can create incredible problems that were easily foresee right though, the industry's supposed to be green, but in reality, According to Sam Vanderhoff, who is a solar industry expert, chief executive recycled PV solar.

[00:09:01] He says the reality about this industry. is not that it's green, but in reality, it's all about the money. Wait a minute. Isn't no, there's not what I just said earlier. Yeah, yeah. Yeah. So California came early with solar power. They granted $3.3 billion in subsidies for installing solar panels on rooftops.

[00:09:26] And yet, you know, barreling ahead with this renewable energy program, they are now at a point where they have rolling blackouts. They have problems with electricity generation. They have problems with the rooftop, solar, and as it is aged, getting rid of it. Have you seen those pictures of Hawaii with those windmill farm?

[00:09:50] that are just sitting there rusting away. Cuz the windmills aren't turning you'd think Hawaii, right? A lot of wind isn't that a great way to do it, but it takes a lot of space kills some birds and uh, it takes a lot of maintenance. They're very expensive to maintain. So they just let some of these, uh, wind farms just totally rested away.

[00:10:12] We need to elect people, send them to Washington, DC that don't touch things like this with a 5,000 foot pole. The, the reason is that you look at a great investor, a great business investor. That they make money, right? Oh, wouldn't it be great to be mark Cuban or one of the sharks, right? That are making money, investing money.

[00:10:39] Well, yeah, it, it certainly would be, uh, they at best, at best make money out of one out of 10 investments, federal government, it bats pretty close to zero. Zero, right. Oh, oh no, that's not true. Right. Uh, we talked about the millions of dollars that Congress people make. Yeah. Yeah. So they don't bat zero, the Congress and, uh, this political crack class bats, a thousand in their own pocket.

[00:11:13] Let's stop this stuff from Washington DC. It's insanity. Thank goodness California did this so we can see how insane these solar rooftop policies are. At least for the near future.

[00:11:27] Well, we've talked about solar cells. We've talked about the new nuclear, which is incredible stuff. Well, there is a new MIT spinout that's tapping into a million year energy supply right here.

[00:11:44] Government has been terrible about picking winners. It, it kind of reminds me of a quote from Henry Ford where you said, if I had asked people what they wanted, they would've said faster horses, and that's kind of the mentality of government, whatever they're investing in, or their friends, their buddies, their, their voters, their donors are investing in.

[00:12:07] That's what they'll push. So we haven't had a fair shake of some of these technologies, really, you know, the hydrogen who knows what else we could be powering our cars with that hasn't come forward because government's been putting just literally trillions of dollars of support into electric cars. Okay.

[00:12:29] And electric cars. Great. Don't get me wrong. They're the cool technology. I wouldn't mind owning one of them. The government should not be the one who decides the winners and losers. That's the communist way. That's central planning. Central planning does not work. I, I I'm really on a bit of a rampage today.

[00:12:52] It's it? This is just crazy, but this, this is a reason right now. What I'm gonna talk about, why central planning has failed us yet again. Right. Just because it's a big problem. Doesn't mean it's a federal government problem. And the big problem is okay. All of us want green stuff, right? Not this green movement.

[00:13:17] That's all about again, central planning, government control, not that stuff, but we want. Clean environment. We want good, healthy food. We want all of this stuff. That's going to make us healthy. The world healthy, the earth, healthy feed the population of the world. Everything everybody does. I don't get it. I don't know why they, well, anyways, we won't get into that.

[00:13:44] Right. Here's this here's an example. Government has been moving us directly towards solar panels, which we've talked about and, and how they really can and do hurt the environment very, very badly. We talked about the disposal of them. We've talked before about the manufacturing of solar panels and how it is horrific when it comes to the health of our.

[00:14:12] How about this one, this M I T group. These are, it's really kind of cool here. Qua energy is this company that they founded and it is a spin out from MIT. And what they're looking to do is use the power potential that's beneath our feet in order to create a literally a carbon free pollution, free energy source.

[00:14:39] Absolutely amazing. Now we've talked about this for a long time. You, you look at some of these countries in the world that have a lot of volcanic activity. I'm particularly thinking about Iceland right now and how they are taking all of this geothermal thermal potential and turning it into electric.

[00:15:02] Which is fantastic. Right? And when you look at the stability of geothermal, it is dead on it is there, it is always there. If you're looking at the stability of geothermal, for instance, doesn't think of a volcano. How often do the volcanoes move? It it's pretty solid, pretty long term. Certainly there's tectonic activity and the plates move, but it's at, at just an incredibly slow rate.

[00:15:32] You're talking about inches a year. Well, they've looked at a couple of things. One is this abandoned coal power plant in upstate new. And as overall people are looking at it saying, it's just, it's worth nothing. Right? It's a Relic from ages gone by heaven. Forbid we burn coal and I, I would rather not burn coal personally, but get down and think about this.

[00:15:57] Now you've got a cold power plant. What is planned? What does that have in it? That might be useful. It still has transmission lines that run to the grid, the power grid, it's a central producer of electricity, which is exactly how our power grid is set up. We're not set up for having every home or, you know, half of them or whatever it is, generating electricity with solar power or having windmills here and there we're set up for having centralized.

[00:16:32] Power generation Nicola, Tesla aside, right? That's how we're set up. So this old cow coal power plant has transmission lines. It still has a power turbine. How does a coal plant work? How does a nuclear plant work? It generates heat and that heat creates steam. And that steam is used to drive a tur. Much like what happens at a hydroelectric dam, the water drives a turbine, and then that turbine, ultimately of course drives a massive alternator of some sort, some sort of a, a generator, if you will.

[00:17:10] And that's hooked up to our power lines. Now, what's really interesting here. Is their technology. You might have heard about this place. I remember reading about this and all kinds of interesting stories, a about this hole that was drilled in, in Russia. I think it was, and they went down. What was it like 5,000 feet or something?

[00:17:37] Um, Uh, and they abandoned it. Right? Cause they were trying to do the whole thing, but here's the interesting part of what the MIT guys are saying that the crust anywhere in the world about it kind of varies a little bit, but basically about, uh, 10 to 20 kilometers deep has the enough geothermal energy.

[00:18:09] to drive something like this power plant, this old coal power plant in upstate New York. But the problem is how do you drill that deep? The Russians, a Soviet union had a hard time doing it and they didn't, they didn't reach their ultimate goal, uh, and interesting backs stories on all of that, that we don't have time for today.

[00:18:30] what these guys are doing is they have created an approach that vaporizes the rock. So they're not drilling. And if you've ever seen drilling operations, watched it on the discovery channel or something, which I have, it's really cool. You, you realize that when they start hitting hard rock granite bedrock, they stop.

[00:18:55] Cuz it becomes so slow. So they use the diamond. Tip drill heads and, and they drill and it's slow, but what's happening right now is they're using gyro trons to heat the material it's been done for years in nuclear fusion experiments, but they're taking that basic technology and using it for new geothermal drilling technique.

[00:19:23] That is cool. So these gyal trons, haven't been well known in the general science community fusion researchers know about it, but what they're saying is this is going to give them the ability to drill. These massive holes, you know, depth wise. And right now 400 feet is kind of as far as we can usually drill, but this is gonna let them go kilometers into the earth.

[00:19:52] They're gonna be able to tap into that, the energy here, basically, you're talking about what you get out of a volcano, right? That sort of energy, that heat bring it up and then boil the water and run it through that coal power. At least the infrastructure that's in there, the generators and everything else.

[00:20:13] So very, very cool. And this is something that's being done right now. They expect within a few years to have an actual functional demonstration of this blasting its way through melt. Rock and some of the hardest rock on the surface of the earth. Hey, you should have received my insider show notes Tuesday morning.

[00:20:38] If you didn't, you can get 'em for free. Just go to Craig peterson.com. And if you have any questions, just email me, me, Craig peterson.com.

[00:20:53] Do you remember this moment from the fifth element? Old tricks are the best tricks? Eh, yeah. Well, we're talking about attackers right now, cybersecurity and the old tricks are the best tricks. No doubt about that. They're back to the old ways. Yep. Oh, well,

[00:21:10] There are a lot of security firms out there. It's just absolutely amazing to me.

[00:21:16] I get ads all of the time, as you can imagine, from dozens and dozens of startups and big guys, and I'm looking at a page right now and there was what, six different ads on here for cybersecurity stuff. This is a site called dark reading. It's one. Pay some fairly close attention to, because they are talking about cybersecurity stuff.

[00:21:40] So I guess that makes sense. But attackers are doing things every day right now. What are they doing? That's what Robert Lamos is talking about. And he's looking at a report that was produced by yet another security firm called Tetra defense and they analyzed data from the first quarter 2020. Now, when you think about cybersecurity and the problems we have, what do you think about, what do you think of?

[00:22:12] Is it ransomware, fishing, maybe? What, what do you think it is? Well, what this Tetra defense found is that 54% more costs. From compromises caused by user actions comes from drum roll. Pete, please. I, I don't know if I said that very, very well. Let me just do that one more time. Okay. Take two. uh, compromises cost victims 54% more.

[00:22:47] When we're talking about unpatched servers. And vulnerable remote access systems like Microsoft RDP, remote desktop, 54% more. That is huge, absolutely huge. Who would've thought of that by the way, these unpatched vulnerabilities from the first quarter and exposing risky services, such as remote desktop protocol account for 82%.

[00:23:17] Of successful attacks while social engineering employees. And that includes things like fishing accounted for just 18%. Of successful compromises that my friends is a very, very big deal. And as I said, at the very beginning, it is, uh, no trick that they've been up to for a long time. So what I'm trying to get at here, I know I'm kinda wandering a little about a little here mentally, but I'm trying to get at the point that we.

[00:23:50] To patch our systems and we have to apply patches ASAP. We have to make sure those patches are in place because it's, it's an absolutely horrible situation out there. I know a lot of companies that use Microsoft's remote desk. Top. And it has been just a horrific battleground when it comes to hackers because of all of the bugs that have been found in there and major vulnerabilities, uh, the log four shell bug.

[00:24:21] This is the one that's tying into Java has been reported on a whole lot, but it is used in about 22% of breaches. So that's not bad for one vulnerability. And it's a crazy vulnerability. This is a problem with languages like Java, where you have people writing code that don't realize what's happening in all of these libraries are pulling in, you know, in Java you just say, okay, uh, write this out to a file for me.

[00:24:52] And don't realize that the code that's actually doing that is parsing what you send it, and it might have a command in it that you. To it and it'll execute the command and that's the basics of that particular problem. Okay. So we're expecting all of these tactics to continue. There are a finite amount today of vulnerable exchange servers, which is another problem that the attackers have been using to really cause a whole lot of problems for us.

[00:25:24] There will be new problems in the future. There's always new software introduced and the new software always has more problems. And there are a lot of people in the cybersecurity business that say, we should just assume that systems are compromised. So instead of trying to protect them as much, let's look for the compromises, which is an interesting way of doing things.

[00:25:46] Frankly. So cloud misconfiguration, that's another big one that's out there. And I'm seeing that all of the time right now, we're working with a client. That's using a lot of Microsoft Azure stuff and Microsoft Azure, Amazon. But in fact, Amazon S three buckets, which are a way to store files up in the cloud inside.

[00:26:10] Have really been hit hard because of misconfiguration. You see, when it gets very difficult to configure something, people tend to take shortcuts, don't think it through. And in this case they have lost a whole lot, but. It's hard to estimate the damages, but looking at it, we're talking about major cybersecurity in incidents, accounting for about two to 10% of annual revenue cost wise.

[00:26:40] So a company that has maybe a hundred million in annual revenue could be looking at as much as 10% of that. In other words, 10 million as a financial impact of a cybersecurity incident. Now it's probably not gonna cost them 10 million to secure everything, but it might cost them a million a year and they just don't do it.

[00:27:06] It's just, they don't bother doing it. Look at the huge breaches that we've had from some of these, uh, credit reporting agencies. If you will, that keep all this personal information and data on. that have lost data for 200 million Americans. Right. Really? They cared and yet they, they just rake in money.

[00:27:28] They just print money. It's it's absolutely crazy. By the way, there was another report that was released a little earlier this year from crowd strike and it has a report that's based on incident data. And the one they released earlier this year was from 2021. And it's showing the breaches related to ransomware attacks had grown by 82% and the data showed that mal.

[00:27:58] Had only been used in 38% of successful intrusions and 45% of attackers were manually conducting the attacks. So if you thought early on, when we started talking here that ransomware was maybe the biggest problem, you're not entirely wrong because ransomware is the biggest growing problem that we're seeing out there right now.

[00:28:22] So it's absolutely crazy. The average time to move from an initial compromise. Remember, they're doing these things automated up front to try and find vulnerable systems or to try and get the ransomware out into your hands. That might be through a fishing attack, which by the way, fishing attacks increased 29%, that cent, that, that, um, so from the time they get that initial compromise to the time they're attacking other systems on the network.

[00:28:55] It's still about one and a half hours, according to the data that came outta CrowdStrike. Now that is concerning too, because that means you basically have an hour and a half after you've been compromised to detect it and do something about it. And that's why we use automated systems with our clients that really keep a close tab on everything.

[00:29:18] Look for various types of compromises, et cetera, et cetera. And I think it's, uh, an important thing to do because if you can't tell if you've been compromised, you just can't defend yourself. Hey, if you sign up for my newsletter, I will send you my most popular. Special reports that includes password special reports, how to use password managers, what the best ones are absolutely free.

[00:29:44] Right. I got a couple of others that I'll send you and you will get my weekly show notes that come out Tuesday mornings most weeks. And that will allow you to keep up to date on all of this. Be a little bit ahead, in fact of the radio show, because I'm talking about stuff that was in my insider show notes on Tuesday.

[00:30:03] So you get it in. Of everybody else. Just go to Craig peterson.com, sign up right there and you will be well on your way. Hey, stick around, cuz we'll be right back. Any questions me@craigpeterson.com.

[00:30:21] We've got a couple of things to talk about right now. We've got Elon. Mokis gotta be worried about this lawsuit. That's coming up and we'll tell you about that. And then also TikTok is in the news here. We've got two different problems with TikTok that talk about today.

[00:30:42] Hi, you are not alone. At least when it comes to your security and privacy. Hi, I'm Craig Peter son, and you are listening to news radio, w G a N a M five 60 and FM 98.5. I'd like to invite you to join me Wednesday mornings at 7 34 with Mr. Matt, we'll keep you out to. You know, of course about this whole thing.

[00:31:11] Elon Musk said he wanted to buy Twitter for a measly. What was it? 44. Billion dollars, right. Real money. And that's a, you know, a problem, especially when Twitter is alleged to be not worth as much as Twitter appears to be. You see, Twitter has had to file with the securities and exchange commission reports about.

[00:31:39] Their income, obviously writing expenses and management, and they have forward looking statements about what they're gonna be doing in the future. And all of that goes into a pot and kind of gets stirred up. And once it's all stirred up the investors, look at it and say, yeah, okay. I, I wanna invest in Twitter.

[00:31:59] One of the big variables that goes into the pot has to do with advertising revenue, which is based on eyeballs, how many eyeballs can Twitter attract? And of course that means Twitter wants to keep as many eyeballs as possible on this site at once. Right. And for the longest time possible. So that all makes some sense, but Twitter's been reporting in its public reports that less than 5% of the users slash postings there on Twitter, but less than 5% of the users are actually bots.

[00:32:39] These bots are used by. Bad guys, evil companies. And, uh, there are a lot of those out there that are trying to promote themselves. Look at how great we are. Yes. Yes. Look at wow. We're trending on Twitter. You should buy our stuff. And in reality, what they're doing is they are paying people who have bought to post thousands of tweets from different accounts using the company's hashtag it, it makes me ill, frankly, to think about this stuff, but that's what they do.

[00:33:17] So. If Twitter has a lot of these bots that are fake and are just trying to drive up the investors' price for some random product, or maybe it's what happened during the last few election cycles where Russia, China were Medling and getting people to vote for Trump against Trump, for Hillary against Hillary Biden, etcetera.

[00:33:46] Is it worth as much as investors thought. So I've been worried about what's gonna happen here. Elon Musk. He he's got to be worried if he actually ends up buying it, what's gonna happen. Is the securities and exchange commission going to do an investigation? Are they already doing one? Frankly? Probably are.

[00:34:08] And is he going to be liable for it? So Twitter's value has dropped. Now, it, it obviously went up when Musk made that, uh, that generous $44 billion purchase offer, but it has gone down since then. And since there are so many analysts saying, well, there's at least 10% bots, others saying it's 40%, it's 60%.

[00:34:34] And, and that kind of is based on the traffic, right? The amount of traffic, the bots are generating versus the number of accounts that are bought accounts. What, what happens? What should they do? How should they do it? What, how should they account for it? And if, if it's that high and there's questions about how high it is, then Twitter stock value is going to go down.

[00:34:55] So Musk pulled out of this whole thing and yeah, I can see why he did. However Delaware is where a lot of these public companies ha are incorporated. That's where their, you know, corporate headquarters are, if you will. That's where they get their authority to operate as a company. And the reason a lot of them do that in Delaware is Delaware has laws and taxes that are very favorable to publicly traded companies.

[00:35:29] And that says something right there too. Doesn't it? Well, Delaware has this thing called the court of Chancery and the judge that's handling Twitter's lawsuit against Musk. Her name is Kathleen McCormick. She is the chief judge in this case is called the court's chance. Has what Reuters called a no nonsense reputation, as well as the distinction of being one of the few jus who has ever ordered a reluctant buyer to close a us corporate.

[00:36:06] Merger. And specifically she ordered last year, an affiliate of a private equity firm to close its $550 million purchase of a holding company that makes cake decorating products. But because of the lockdown, the value of that cake decorating company drop. Pretty dramatically cuz people just weren't going out and buying this stuff to make cakes.

[00:36:31] They weren't celebrating, they weren't having parties. They didn't have cake cakes. Right. So she forced them to buy. This other company at the original price, even though the value of the company that holding company had dropped. So this is going to be really rather interesting. If you look at her ruling.

[00:36:55] She said the buyers lost their appetite for the deal shortly after signing it as government entities issued, stay at home orders around the country and the weekly sales declined dramatically rather than use reasonable efforts to work around a definitive credit agreement. The buyers called their litigation council and began evaluating ways to get out of the.

[00:37:20] Without input from the management, they prepared a draconian reforecast of the projected sales based on uninformed and largely unexplained assumptions that were inconsistent with real time sales data. That's where Elon Musk may have an out. if he's played his card right now, what really kind of confused me about all of this is that they, the guys at Twitter have a pretty solid case because they were able to negotiate as part of this potential purchase or merger, whatever you might wanna call it really it's a purchase.

[00:38:01] They have a pretty solid case cuz they got some amazing language into this agreement. I, I just can't believe that Elon Musk and his attorneys allowed it to go in there. Now these cases here in the Delaware court of Chancery are decided by the presiding judge and not a jury. Although a judge can get an advers, uh, advisory, excuse me, jury, to help consult, but the judge's decision can be appealed to the state Supreme court.

[00:38:33] And then the decision is final and Twitter proposed a four day trial with a September 19th start. Date and the court, I believe said, we're gonna push it off to October. I'll try and keep an eye on this case, cuz I think it's fascinating to see what happens here as we go forward to our friend, Elon Musk now.

[00:38:57] TikTok, Ugh, man, if you didn't get my newsletter this week, which you should have had my insider show notes on Tuesday morning and follow through and read these two articles on TikTok, you really missed something, but I'll, I'll give you a quick summary here. Right now. We spoke. About TikTok and what they have done here with this blackout challenge.

[00:39:21] Now it's not TikTok. They, they're not the ones promoting the challenge, but they are making money off of it and they're promoting their site. It's just yet another challenge that to has. well, one of the things that's been happening in Ukraine with this Russian invasion is people have been making TikTok videos and they have been posting them and they include all kinds of stuff.

[00:39:47] Uh, I'm sure there's dead soldiers in there. Russian tanks that have been completely blown apart. What a bad design, by the way, and many other things, and TikTok says, Hey, wait, wait a minute. We, we, we, okay. Well, we, we can't keep these, even though they have been asked to preserve the Ukraine content for warm war crime investigations.

[00:40:13] What has come out recently, you remember orange man, bad said that, uh, TikTok needed to be shut down. They, they wanted it out. He wanted it out of the, and not just him, but other people, uh, out of the app stores, because it's being used by Chinese intelligence and they're doing all kinds of stuff. Yeah. Yeah.

[00:40:34] Well, it turns out that our friends at TikTok have been in fact sending. All of the stuff that you are filming to China now, TikTok is illegal to use in China. So they're not sending it to China to show the Chinese because China is smart enough to not allow people to use TikTok. They're using it for ESP espionage TikTok, even just a few weeks ago, changed its usage.

[00:41:06] Uh, document here, right? Terms of use saying, uh, oh, we we're going to use. The video that you submit, uh, we're gonna collect biometric information. We're gonna collect information about things and people in the foreground things and people in the background. In other words, they're now putting together what you might call a social matrix.

[00:41:29] So they know who your friends are or what you're doing. They know about you. They're doing facial recognition of you. It goes on and on and on very, very bad, but because it's so popular with these young Ukrainians and even Russian troops who are posting footage of the war, they've got some stuff that would be great for the war crime investigators.

[00:41:54] And re remember when president Trump said, oh no, we gotta cut out TikTok. And, and the left, his opposition was saying, no, no, you know, TikTok is great. It's wonderful. Oh. And TikTok said, yeah, we have, uh, us based servers, nothing to worry about here. I don't know what Trump is talking about. The guy an idiot.

[00:42:13] Uh, well, as I just mentioned, we found out absolutely that yeah, they're saving it. They're sending it to China. And remember now, The Chinese communist party is a friend of Russia's. They're buying oil for very cheap prices. They're providing Russia with a number of different things. They're being a little cautious about it, but they will not allow war crime investigators to look at TikTok videos that have to do with the war in Ukraine.

[00:42:48] Absolutely amazing. Absolutely amazing. Lot of data pulled from your device sent back to China biometrics, face prints, voice prints, keys, stroke patterns, rhythms, search, and browsing history, location information. Do not let your kids go to TikTok. And this week I got an email from a listener saying that one of her close friends.

[00:43:14] Child died because of the blackout challenge. If that's not enough.

[00:43:20] Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? You know, did you fall victim for that? Hey, upload your contacts. We'll find your friends. Well, they don't know where your data is.

[00:43:36] This whole thing with Facebook has kind of exploded here lately.

[00:43:42] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes now, you know, there's always a lot of rumors about different companies and particularly when they're big company and the, the news headlines are kind of grabbing your attention.

[00:44:16] And certainly Facebook can be one of those companies. So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal data? well, it came from a leaked document. Yeah, exactly. So I, we find out a lot of stuff like that. Right. I used to follow a, a website about companies that were going to go under and they posted internal memos.

[00:44:49] It basically got sued out of existence, but there's no way that Facebook is gonna be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So of course, if you're older, we used to call those TIAL waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

[00:45:19] So Facebook internally, they, their engineers are trying to figure out, okay, so how do we deal? People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

[00:45:42] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How are they all CATA categorized? Now we've got the European union. With their gen general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

[00:46:07] That's not my specialty. My specialty is the cybersecurity side. But in article five, this European law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected and used for a specific purpose and not reused for another purpose.

[00:46:45] So there's an example here that vice is giving in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, you know, feature as well as. Advertisers. Yeah. Interesting. Eh, so Gizmoto with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice.

[00:47:13] Cuz this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now. And most people. Right. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online and nothing.

[00:47:34] Right? I think I probably even uploaded it back then thinking, well, that'd be nice to see if I got friends here. We can start chatting, et cetera. Well, according to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal me, uh, memo, this European regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leak document shows that Facebook may not even have the ability to limit.

[00:48:09] how it handles users data. Now I was on a number of radio stations this week, talking about this and the example I gave, I is just look at an average business from the time it start, you know, Facebook started how right. Well, you scrape in pictures of young women off of Harvard universities. Main catalog, right.

[00:48:34] Contact page, and then asking people, well, what do you think of this rate? This person rate that person and off they go, right. Trying to rate them. Yeah, yeah, yeah. All that matters to a woman, at least according to mark Zuckerberg or all that matters about a woman is how she looks. Right. Do I think she's pretty or not ridiculous what he was doing?

[00:48:54] I, it just, oh, that's Zuckerberg, right? That's. Who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then opening up even wider and wider.

[00:49:19] And of course, that also created demand cuz you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certain you're starting to collect data and you're making more money than God. So what do you do? Well, you don't have to worry about inefficiencies.

[00:49:40] I'll tell you that. Right. One thing you don't have to do is worry about, oh, GE we've got a lot of redundant work going on here. We've got a lot of teams working on basically the same thing. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that, uh, money to this group or that group.

[00:50:02] And they put together all of the basic information, right. That, that they want. They are. Pulling it out of this database and that database, and they're doing some correlation writing some really cool sequel queries with some incredible joins and everything else. Right. And now that becomes part of the main code for Facebook.

[00:50:24] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says, uh, Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And, uh, they, one of the groups inside Facebook says, yeah, yeah, yeah, here, here we go.

[00:50:49] Here's all of the information we have about everybody and it's free. Don't worry about it. Right. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No, no, no, but, but the Obama. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

[00:51:15] And according to this internal memo, they still don't know. They don't even know if they can possibly, uh, comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the us Canada of course, has their own Australia, New Zealand think about all the places.

[00:51:38] Facebook makes a lot of money. So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water.

[00:52:00] Okay. And it flows every. The document red. Right. So how do you put that ink back in the bottle, in the right bottle? How do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from it? Apparently they don't even know where they got some of this information.

[00:52:24] This data from kind of reminds me of the no fly list. Right. You don't know you're on it and you can't get yourself off of it. Right. It is kind of crazy. So this document that we're talking about was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of a monetization strategy monetization strategy.

[00:52:51] And is the engine that powers Facebook's growth. interesting, interesting problems. And, and I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And I've talked about as well along comes Elon Musk and he says, well, wait a minute now.

[00:53:13] Now I can make Twitter way more profitable. We're gonna get rid of however many people it's well over a thousand, and then we are going to hire more people. We're gonna start charging. We're gonna be more efficient. You can bet all of these redundancies that are in Facebook are also there on Twitter. and Twitter also has to comply with all of these regulations that Facebook is kind of freaking out about.

[00:53:42] Well, it, for really a very good reason. So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does, but most companies, right.

[00:54:06] You grow. I, I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be, because it grew organically. Right. You, you started out with a little consumer firewall, router and wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around.

[00:54:29] This is normal. This is not total incompetence on the part of the management, but my gosh, I don't know. Maybe they need an Elon Musk. Just straighten them out as well. Hey, stick around. I'll be right back and sign up online@craigpeterson.com.

[00:54:49] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian looters.

[00:55:06] Thanks for being with me today. I really appreciate it. And I'm honored, frankly, to be in front of this microphone. , this is really something, you know, we, we know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that that looting is kept to an absolute minimum.

[00:55:29] Certainly the Americans, the British, even the Nazis during world war II, the, the, uh, the socialists they're in. Germany, uh, they, they tried to stop some of the looting that was going on. I, I think that's probably a very good thing, right. Because what you end up with is just all of these locals that are just totally upset with you.

[00:55:57] I found a great article on the guardian and there's a village. Had been occupied for about a month by Russian troops and the people came back, they are just shocked to see what happened. They're giving a few examples of different towns. They found that alcohol was stolen and they left empty bottles behind food rappers, cigarette butts, thrown all over the place in apartments and homes.

[00:56:26] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the clothes. This is a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and lingerie. This is really, really something. Uh, it, the Soviets didn't do this, but now Russian.

[00:56:50] Military apparently does. So over the past couple of weeks, there've been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidences suggests looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

[00:57:18] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto Euro trucks, everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioners.

[00:57:42] Being shipped back, just like, you know, you might use ups here, they have their equivalent over there. A lady here who was the head teacher in the school. She came back in, of course, found her home Lood and in the head teacher's office. she found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're gonna destroy it.

[00:58:08] They don't only leave anything behind. They found the Russians had taken most of the computers, the projectors and other electronic equipment. It, it, it's incredible. So let's talk about the turnaround here. A little. You might have heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

[00:58:28] So they get into the apple store. They grab laptops on iPads, no longer iPods, cuz they don't make those anymore. And I phones. And they take them and they run with them. Well, nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is, is they take some parts and use them in stolen equipment.

[00:58:55] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

[00:59:17] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, let's say they put 'em on wifi. They don't get a SIM card. They don't. service from T-Mobile or Verizon or whoever it might be. So now they disconnect to the wifi and it calls home, cuz it's gonna get updates.

[00:59:37] So on download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erased, et cetera.

[01:00:03] Now, police have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're, they're doing things like putting them into Fairday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

[01:00:28] You steal it. It's not gonna do you much. Good. So one of the things the Russian stole when they were in, uh, it's called, uh, I think you pronounce it. Uh, Mela me pole, uh, which is again, a Erian city is they stole all of the equipment from a farm equipment dealership and shipped it to Chenia. Now that's according to a source in, uh, a businessman in the area that CNN is reporting on.

[01:01:01] So they shipped this equipment. We're talking about combines harvesters worth 300 grand a piece. They shipped it 700 miles. and the thieves were ultimately unable to use the equipment, cuz it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

[01:01:27] It's autonomous. It goes up and down the fields. Goes any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, right. Of your property being very, very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

[01:01:54] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a, what not terribly profitable business. It certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? Well, what they do is they lease it. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

[01:02:22] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not gonna come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

[01:02:47] Right? You see where I'm going with this so that they can get their equipment in the hands of more farmers cuz the farmers can lease it. It costs them less. They don't have to have a big cash payment. Right? You see how this all works. So when the Russian forces stole this equipment, that's valued. Total value here is about $5 million.

[01:03:08] They were able to shut it all. And obviously, if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and you know, there's pros and cons to that. I think there's a lot of cons, but, uh, what are you gonna do? How's that gonna work for you? Well, it. Isn't going to work for you.

[01:03:29] And they were able to track it. It had GPS trackers find out exactly where it was. That's how they know it was taken to Chenia and could be controlled remotely. And in this case, how'd they control it. Well, they completely. Shut it off. Even if they sell the harvesters for spare parts, they'll learn some money, but they sure can be able to sell 'em for the 300 grand that they were actually worth.

[01:03:56] Hey, stick around. We'll be right back and visit me online@craigpeterson.com. If you sign up there, you'll be able to get my insider show note. And every week I have a quick five. Training right there in your emails, Craig Peter san.com. That's S O N in case you're wondering.

[01:04:21] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're gonna talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world.

[01:04:37] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

[01:04:48] We had improved all of their systems and their security and one of their. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine, all of a sudden TA, guess what it had ransomware on it. One of those big reds.

[01:05:10] Greens that say pay up is send us this much Bitcoin. And here's our address. Right. All of that sort of stuff. And he called us up and said, what what's going on here? What happened? Well, first of all, don't bring your own machine into the office. Secondly, don't open up particularly encrypted files using the password that they gave.

[01:05:33] and thirdly, we stopped it automatically. It did not spread. We were able to completely restore his computer. Now let's consider here at the consequences of what happened. So he obviously was scared. Uh, and within a matter of a couple of hours, we actually had him back to where he was and it didn't spread.

[01:06:01] So the consequences there, they, they weren't that bad. But how about if it had gotten worse? How about if they ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. Right. Would, do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

[01:06:28] Right? Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. Well, I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

[01:06:55] And if you're interested, I can send you, I I've got something. I wrote up. Be glad to email it back to you. Uh, obviously as usual, no charge. and you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

[01:07:19] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's two, two factor, right. First is they've encrypted your data. You can't get to it. And then the second side of that is okay, well, I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they they'll put it out there.

[01:07:43] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing, uh, you can lose your license for your business. You can U lose your ability to go ahead and frankly, uh, make loans and work with financial companies and financial instruments.

[01:08:08] It could be a very, very big deal. so there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And we, again, we've got a client that, uh, we picked up afterwards. That, uh, yes, indeed. They lost all of the money in their operating account.

[01:08:32] And, uh, then how do you make payroll? How do you do things? Well, there's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

[01:08:53] Uh, one is by the way, KTI, which is a big ransomware gang that also got hacked after they said we are going to attack anyone that. Uh, that doesn't defend Vlad's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. Uh, first of all, the largest ransom demand is $50 million.

[01:09:21] And that was in 2021 to Acer big computer company. Now 37% of businesses were hit by ransomware. In 2021. This is amazing. They're they're expecting by 2031. So in about a decade, ransomware is gonna be costing about $265 billion a year. Now on average, uh, Ransomware costs businesses. 1.8, 5 million to recover from an attack.

[01:09:53] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? Right? If you're a car dealer, you have a to print money, right? You you're selling car model or cars from manufacturer X. And now you have the right to do that and they can remove that.

[01:10:16] Right? How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, 20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom demand. So about her third paid ransom demand.

[01:10:41] Last. it's it's actually down. Cuz my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it's it's a little, little better than 50%, but 65% of pain victims recovered their data.

[01:11:12] Now isn't that absolutely amazing. Now 57% of companies are able to recover the data using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get backed? Probably took weeks, right?

[01:11:35] For a, a regular computer over a regular internet line. Now restoring from backup's gonna be faster because your down link is usually faster than your uplink. That's not true for businesses that have real internet service, like, uh, ours. It it's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

[01:11:58] So it's very, very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be incredibly expensive for you incredibly. So here you. The number one business types by industry for ransomware tax retail.

[01:12:32] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware, conscious of doing what, of keeping their data secure of having a good it team, a good it department. So there's your bottom line.

[01:12:59] Uh, those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And so, as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

[01:13:26] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to Craig peterson.com. And I'll also send you my special report on how to do passwords stick around will be right back.

[01:13:44] You know, you and I have talked about passwords before the way to generate them and how important they are. And we we'll go over that again a little bit in just a second, but there is a new standard out there that will eliminate the need for passwords.

[01:14:00] Passwords are kind of an, a necessary evil, at least they have been forever. I, I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

[01:14:17] Yeah, 360, you know, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements in, but you had a username.

[01:14:47] You had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang. And, uh, his password was always some sort of a combination of RA Lang. So it was always easy to guess what his, what his password was. Today, it has gotten a lot worse today. We have devices with us all of the time.

[01:15:09] You might be wearing a smart watch. That requires a password. You of course probably have a smart phone. That's also maybe requiring a password, certainly after boots nowadays they use fingerprints or facial recognition, which is handy, but has its own drawbacks. But how about the websites? You're going to the systems you're using when you're at work and logging in, they all require passwords.

[01:15:39] And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for, for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to log. Now that's really kind of an interesting thing, right?

[01:16:07] Just looking at it because we're, we're so used to having this password only authentic. And of course the, the thing to do there is make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe mix.

[01:16:29] Upper lowercase a little bit. In those words, those are the best passwords, you know, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cuz I use a completely different password for every website and right now, Let me pull it up.

[01:16:52] I'm using one password dot com's password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. Entries here in my password manager, 3,100. That is a whole lot of passwords, right? As well as, um, software licenses and a few other things in there.

[01:17:19] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I, I really do like that. Uh, some others that I've liked in the past include last pass, but they really messed. With some of their cybersecurity last year and I lost, lost my faith in it.

[01:17:41] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless sign in. and they're gonna make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

[01:18:05] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're gonna work with the Fido Alliance and they're gonna create this passwordless future. Which I like this idea. So how does this work? Well, basically you need to have a smartphone.

[01:18:24] This is, I'm just gonna go with the most standard way that this is going to work here in the future. And you can then have a, a. Pass key. This is kind of like a multifactor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, I'm giving a password and then it comes up and it asks me for a code.

[01:18:48] So I enter an a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password dot. In order to generate that code. So that's how I log into Microsoft sites and Google sites and all kinds of sites out there. So it's kind of a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

[01:19:16] We have biometrics tied in as. so to log into our systems, I have to have a username. I have to have a password. Uh, I then am sent to a single sign on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

[01:19:41] So, yeah, there's a lot there, but I have to protect my customer's data. Something that very, very few it's crazy. Um, actual so-called managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list.

[01:20:07] I'll send that to you. That's what we're sending out right now for anyone who signs up new@craigpeterson.com. And if you'd like a copy of it and you're already on the list, just go ahead and email me M E. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing.

[01:20:25] So what will happen with this is you go to a website and it might come up with a QR code. So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again have it set up so that your phone requires a facial recognition or perhaps it'll require a fingerprint. And now you are in.

[01:20:47] Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year. You're going to see this available on apple devices, Google Microsoft platforms. And it really is simple, stronger authentication. That's what Fido calls it. Right. But it is going to make your life a lot easy.

[01:21:12] It easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now I wanna talk about another thing here that has bothered me for a long time. I have a sister-in-law. who is in the medical field and, and, uh, gives prescriptions, you know, doctor thing. And, uh, I think she's not quite a doctor.

[01:21:35] I can't remember what she has or she's an LPN or something. Anyhow. So she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions. And so I warned her about that saying, you know, it is very bad to be using zoom because zoom is not secure.

[01:22:01] Never has been, probably never will be right. If you want secure, you. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure. So I talked to her about that and said, Hey, listen, you can't do this. You you've really got to go another way here.

[01:22:23] And so she started using one of these mental or. Medical health apps. What I wanna talk about right now specifically are some checks that were just performed some audits on mental health apps. That's why I messed up a second ago, but what they looked at is that things are a serious, serious problem there.

[01:22:50] And then in fact, the threat post is calling it, uh, creepy. Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise. So you can get on the horn with, uh, mental health, professional, uh, doctor or otherwise in order to help you here with your psychological or spiritual wellbeing.

[01:23:15] And people are sharing their personal and sensitive data with third parties and of 32 mental health and prayer mobile apps that were investigated by the open source organization. 28, 28 of the 32 were found to be inherently insecure and were given a privacy, not included label, including, uh, others here.

[01:23:41] So this is a report. uh, that was released here by the open source organization, tied into Mozilla Mozilla. Those are the Firefox people. They have what they call their minimum security standards. So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet.

[01:24:05] Even those minimum security standards. So these apps are dealing with some of the most sensitive men, mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal thoughts, domestic violence, eating disorders. And they are being just terrible with your security Mozilla researchers spent 255 hours or, or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, right.

[01:24:41] Between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed allowed week passwords. That range. One digit one as the password, 2, 1, 1, 1 while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data.

[01:25:11] So be very careful. Um, two of the apps better help a popular app that connects users with therapists and better stop suicide, which is of course a suicide prevention app have vague and messy. According to Mozilla privacy policies, they have little or no effect on actual. User data protection. So be very, very careful.

[01:25:35] And if you are a mental health professional, or a medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini training. They come out most weeks, just go to Craig peterson.com.

[01:26:00] Craig peterson.com. And I'll send you my special report on passwords and more.

View Details

Do You Know Anyone Who Uses TikTok?
Kids Are Dying Because of It!

TikTok has been in the news for a lot of reasons. It is now confirmed. It is used for Chinese spy operations, but the big problem right now is the kids that are dying because of TikTok.

[Automatic transcript follows]

You are not alone. I'm Craig Peterson TikTok has been in the crosshairs for quite a while. This is a Chinese company. Tencent is the Chinese company that started them up and they really kind of got their foundation through what you'd call challenges probably.

[00:00:37] Everybody remembers the ice bucket challenge and that ice bucket challenge was floating around. They were doing it on YouTube, TikTok everywhere, and it was to benefit really ALS. Which is absolutely kind of fantastic. And this was eight years ago, I guess. I don't know, 10 years, 2014, I think actually, uh, a long time ago.

[00:01:03] I remember like it was yesterday and they raised apparently $115 million. The idea was that you would challenge someone else to do this ice bucket challenge and in, so doing, you would donate money to ALS. That is really kind of cool. What a great idea for ALS. So I would, for instance, get challenged by someone who dumped a bucket of ice water over their head.

[00:01:34] To do the same and donate to ALS Lou Gehrig's disease. That's kind of cool. Obviously they're not supporting Lou Gehrigs are supporting the research and due stopping it. Right. And people did it. And as I said, $115 million later, ALS research is probably a little further along. You kind of hope so it's easy in a big organization to chew up $115 million.

[00:02:00] That's for sure. But bill gates did it. Ton of celebrities did it. And ultimately people took that basic idea and, and tried to put it into other types of fundraisers. You know, that's all well and good, you know, it kind of kind of died down, uh, for a while. They did a whole bunch of other things I'm looking right now, by the way.

[00:02:28] Uh, let's see. Yeah, it was ALS association. This is Wikipedia, which is, uh, sometimes to believe be believed most of the time not. And a, the ALS site was where I was quoing from before Wikipedia is saying that. There was over 220 million worldwide raised for ALS research. So it's probably the difference between worldwide and in the us.

[00:02:54] So they wanted to make it kind of an annual event. It just didn't happen. And the cold water challenge. It started really in 1991. So they, they took it and they ran with it. Well, one of the things that TikTok has been doing a lot of is challenges and they they're different kinds of challenges. They have musical challenges where someone will.

[00:03:20] Post, uh, some music usually by a star of some sort. And they'll go ahead and have a, maybe a dance challenge and maybe a, you know, a challenge for your kitty cat or your dog, whatever, what, whatever it might be. But it's been really good for TikTok to grow. And a lot of people are doing it. Different, crazy things that they've done.

[00:03:45] You've got the gorilla glue girl. Do you remember her? she, she decided to use gorilla glue in her hair rather than I guess some sort of, uh, I don't know. Oil or something to hold her hair down. And it definitely held her hair down. She sued, she sued them. It's absolutely crazy what she did. So the gorilla glue girl, probably not really a challenge, but she, uh, this is CRA, this is when the New York post undoubtedly cemented her place on talk's most stupid Mount Rushmore.

[00:04:20] Because she slathered her hair with gorilla glue and she had to go in and get it. Surgically repaired. It took four hours, $20,000 in donations came in hundreds of free air products, even a full-time agent. The DIY vampire fangs. Uh, this is crazy. This is in Halloween a couple of years ago. Super gluing costume vampire fangs to your teeth.

[00:04:50] Uh, 9 million views on that one. Tooth filing. Oh, this is crazy, absolutely crazy. They I'm, I'm looking at a picture of it right now of the video, one of the videos. Anyway, anyways, it was on TikTok and, uh, you know, this is kind of the realm of toothless TikTok challenges, but. They, uh, they were attempting to fix their uneven smiles by using a nail file to sand their teeth down the incisors.

[00:05:24] If they were, were a little bit too big. Oh, man, the dentist got upset about that for very good reason. You're destroying the enamel on the outside of your teeth. Irreparable damage, the face wax challenge. Oh, look at this picture. This is crazy billions of videos in counting. Uh, they they're putting wax, although wax all over people's face.

[00:05:50] Oh, my goodness. So they caked the whole face, including the eyes with wax, like it's, you know, casting mold. Have you seen those things before they even have wax dip Q ticks tips stuck in their noses to get rid of those nasal hairs? Oh man. Very, very traumatic. Um, I'm not gonna talk about this one. It involves a sensitive body part, the corn cob challenge.

[00:06:22] Uh, this is, uh, cons eating corn by attaching the cob. That or to a spinning drill bit. If you can believe that. Oh man, 22 hamburgers. Here's another one. The cereal challenge. Uh, a person pours milk and cereal into the open mouth of a person laying down and eats breakfast from the human bowl. Choking hazards.

[00:06:50] Obviously there, the skull breaker challenge, this apparently started in Venezuela and it depicted three friends jumping next to each other as the book ending, Bud's kick in the middle guy's feet out from under him. So what ends up happening is that person crashes to the ground landing on their back, hitting.

[00:07:12] The head in the process injuries reported Miami, New York, New Jersey, Arizona, uh, Dayton beach, Florida police have charged two high school teens with misdemeanor, battery and cyber bullying, Mexico. The penny challenge. Oh my gosh. Um, This involves. And I talked about this one here on the radio, too, taking a penny and putting it on a plug.

[00:07:41] So you partially plug. A plug into the wall, into the socket and then you stick a penny behind it to shore out the leads. Yeah. So when the, when the penny or whatever coin you're putting in there hits those metal prongs there's sparks electrical system damage, and some cases fire, uh, them fire marshal down in, uh, one of the towns.

[00:08:08] Ostro key, I guess it is in mass. Uh, has a photo of a scorched outlet in Holden. Oh, there you go. Reportedly caused by the viral prank. The Benadryl challenge, Chacha slide, pee your pants. Uh,

[00:08:31] there's another one, the other side, verbal abuse challenge, mom and dads verbally abusing their kids. I color them a mistake in some cases mentioning the word abortion. Oh my goodness. Flash mobs. Uh, dipping challenge. Oh, that'll make you sweet eating and swallowing dip and the blackout challenge. That's the one we're talking about right now.

[00:08:54] There there's so many of these things. If you don't know what's going on on TikTok, this is it, right. I, I just told you a bunch that are dangerous. Absolutely crazy. Nobody should be doing that sort of stuff, but they are, well, parents are saying now the TikTok failed to act after the first reported death in this blackout challenge, as you can guess, the blackout challenge is where kids black out.

[00:09:25] They have to strangle themselves until they pass. This was in my emails this week, this whole thing, I've got a link to some of these articles. You'll find it@craigpeterson.com. If you didn't get it on Tuesday morning, make sure you go to Craig peterson.com and sign up right now. But parents of two girls, these are two of the seven kids that are known to have died from this blackout challenge.

[00:09:53] Are suing these girls, their daughters that died were ages eight and nine nine. They're claiming according to ours, Technica that their kids became addicted to TikTok. They were fed a constant stream of seemingly harmless challenge videos, persuading them to participate and then died after attempting the blackout challenge.

[00:10:22] So they're seeking damages from TikTok for the product design. Now remember TikTok, isn't the one coming up with these challenges. It's the users who are on TikTok that are coming up with them. Now TikTok did respond. He told the New York, they told the New York times the spokesperson that the, the company would not comment on continuing litigation.

[00:10:45] And they also linked a prior company statement to people magazine about a 10 year old girl who also died after attempting the blackout challenge. At that time, TikTok said the disturbing challenge predated their platform and had never become a TikTok. Trend now we know TikTok just a few weeks ago.

[00:11:06] Confirmed has been sending all of the videos, all of the user information, everything to China. So there you have it avoid TikTok and man, don't let your kids on it. Stick around. We'll be right back.

[00:11:25] Hey, Microsoft is giving me nightmares again, and frankly, much of the cybersecurity community because of their change. They just change direction in a way that is much, much less safe. I, I don't know what's going on there.

[00:11:42] We over the years have seen Microsoft be just kind of the bane of our existence. Anybody that's trying to stay secure, it's been terrible.

[00:11:55] There's software, just horrible. It was not designed but frankly, find frankly. All it's just crazy. And then they brought Dave Cutler in and I worked on NT, the pre one, oh, versions, windows, NT, their new technology, which kind of underlines all of the modern versions of Microsoft windows. And what happens well, instead of doing things securely, really following in the footsteps of a.

[00:12:28] Call print system, digital equipment corporation. They decided to just go completely different direction and, uh, rip things out and must make this compatible with anything that's ever been written, kind of the Intel philosophy. And by doing all of that, they lost all of the wonderful security that VMs had.

[00:12:48] This operating system that Dave Cutler had kind of led up over in the deck world. we ended up with a piece of garbage, really? It was just terrible. Oh my goodness. And I I've been absolutely amazed since I got rid of bill gates and got rid of that other guy that was in there running things for a wild bomber, who was just incredibly, just terrible.

[00:13:18] Uh, and they've really come a long way. Their new CEO, the last few years has done some. Wonderful things. Some really amazing things here to increase. Microsoft's not just productivity for the users, but their profitability and their cyber security, which is why now I am so. Puzzled, because one of the things that has been a killer for cybersecurity has been this whole concept that micro has Microsoft has of well had anyways of, well, let let's make it so that you can write programs and put them into this spreadsheet.

[00:13:56] Visual basic visual C plus plus C. We'll make things ever so much better. And of course, what was visual basic used for in some of our word documents and our Excel documents, it was used to hack our computers. Yes, indeed. The bad guys used a programming language to cause. All kinds of havoc, who would've thought a, so Microsoft decided, well, Hey, listen, uh, we are going to turn off macros by default because they are too dangerous.

[00:14:35] Boy, are they too dangerous? Whatever programming language you're using. Come on, look at Java. Java has just been a nightmare as well. Over the years for cybersecurity, it's gotten better. Of course they've tightened it. But I can remember what, 15, 20 years ago, first using Java and seeing all of the problems.

[00:14:57] We still got them. I've got a new client that I've been helping. They're a startup and they are using Java for a lot of the stuff that they are writing. And it's a nightmare trying to get them to. Up to date on the Java engines that they're using and, and they're using some that have massive known vulnerabilities and that's kinda what happens with the macros.

[00:15:23] It, yeah. Great. Look at, you can write files to desk. You can do all kinds of really cool things. Isn't this just wonderful. Yeah. If the whole world was kind and generous and wasn't trying to break into our computer computers. Uh it's. It's incredible. So in February, 2022, Microsoft announced a major change.

[00:15:49] And it put this change in place to, as they said, combat the growing scourge of ransomware and other, uh, really malware attacks. So they're going to block the downloaded macros and office versions, going back to office 20. Team they're gonna be releasing patches for them. And you could still enable macros for these different files, PowerPoint, what, whatever you're doing here, but it's much more difficult to enable it because they are so dangerous.

[00:16:24] Absolutely. Dangerous and, uh, well, we can get into all of the details behind it. You know, the zone identifier tag. And if you have an NTFS volume, it can be in there market, the web it's already used in office. They're kind of emulating what apple has been doing for quite some time in order to really try and focus you saying, Hey, listen, you downloaded that app from the internet.

[00:16:50] Do you really, really. Really want to use it. Uh, you don't think this through a little bit and sure enough, you know, they decided, yeah, this is a bad idea. We can't let people just run macros willy-nilly uh, by the way, why, why were all these things happening? Well, if I was to boil it down, you probably could read between those lines.

[00:17:11] When I was talking earlier really bad. Product management inside Microsoft. Now they've got some great programmers, but, uh, and some great minds there. I, I know a few people, well, I mentioned Cutler who went over there, but I know a lot of other guys that went over there to work for Microsoft, but they just don't have the product management that frankly they need to have.

[00:17:35] And that is caused just all kinds of nightmares. So what's happened. Well, Microsoft made a very big announce. They have decided that they are going to let you know, nevermind. Nevermind. They have reversed course, and they're going to allow untrusted macros to be opened by default in word and other office applications.

[00:18:05] So, uh, they also said here just a few days ago that, Hey, um, Um, you know, the, nevermind. We said that we are gonna allow macros, uh, just by default in everything. Um, yeah, well that that's gonna be temporary, I guess. It's, you know, temporary in passing just like inflation, right? Don't don't worry about it. Uh, nothing is here.

[00:18:28] This is absolutely crazy. Make up your mind. Macros have been the bane of existence for so many. Of us cybersecurity people out there. And another thing too, that's just been really bad is their wonderful little scripting language, their, their power shell, which is being used all the time now by the bad guys to infect machines because your standard malware.

[00:19:00] You know, this antivirus software that you buy, the, you know, not the really good stuff, but the stuff that you buy as a consumer would buy you'd get at staples or Walmart or online does not work against it. And again, it's just like, they're stealing again. This one's from the Unix world. We've had shells in Unix since the seventies.

[00:19:25] and, uh, you know, they, they just, they do it, they do it wrong. They. And they make it, uh, just worse. I'm shaking my head. I, I, you can tell I am no Microsoft fan, right? Uh, people are using it mainly because businesses buy it. And why do businesses buy it? Because the purchasing guy. Looks for check boxes. Oh yes.

[00:19:48] Microsoft windows checks all these boxes and the purchasing guy doesn't care about the user interface. The purchasing guy doesn't really care about how secure it is. It doesn't care about how Des well designed it is. It doesn't care about its network connectivity. So yeah, that's why we have so many copies of windows out there.

[00:20:07] This is a sad decision blocking Microsoft office macros would do infinitely more to actually stop real threats out there than all of the Intel blogs that are out there that are telling us about the problems. I just don't get it. It's absolutely crazy. Everybody is criticizing the move that's in the cybersecurity space.

[00:20:36] Bad decision again from Microsoft. So make sure your macros are turned off. You can find this article. I sent it out my show notes on Tuesday. Craig peterson.com.

[00:20:52] There's been a lot of talked about Elon Musk, this whole Twitter deal. But I think everybody that I have read articles from is missing the boat here. So I'm gonna give you my view of what's happening as a business person, myself.

[00:21:08] Elon Musk made a $44 billion bid to buy Twitter. You've I'm sure you've heard of this.

[00:21:17] It's been talked about now for months and months and months. And I, I want to talk about what happened from my. Perspective with Elon Musk saying, no, um, this deal is over. I'm not gonna follow through on this. And again, this is my opinion. This is me doing a little bit of mind reading here of, of Elon MOS and maybe one or two of the things that.

[00:21:43] That he thought about when he canceled this deal. Now, remember, initially he's put that offer out. And the Twitter board of director said, no, no, no, we're not gonna take it for whatever reason. Right. What's the real reason they might. They, they they'll say what. They want you to hear about what the reason is, but it's not necessarily the reason.

[00:22:06] So initially Twitter said, no, we're not gonna do it. And then Twitter said, yeah. Okay. We'll do it because there was frankly, this is again, me, a lot of. People who were investors in Twitter that were pretty upset that this offer from Musk, that was a very good offer. He was offering more than the stock was trading for would go away.

[00:22:30] They wanted it. They wanted to get out of Twitter. You know is not what you're supposed to be doing. Right. You're making money. Even if you keep your stock, you're, you're gonna be well vested. And that's what you're trying to do is make some money for yourself or your investors. So many of us have retirement money that's in the stock market.

[00:22:52] Yeah. Like you haven't noticed that. Right. There's the, your retirement's gone down by 50% or more it's in the stock market. So you want the people who are running these companies to make good fiscal fiscal decisions so that your money that's invested in there, isn't going away. So you have some money for retirement.

[00:23:15] So that pressure on the Twitter board is really what got them to move and say, yeah, we'll accept the offer. Now Elon Musk made that offer based on the valuation of Twitter and its stock, because really what Musk had to do is buy at least a controlling interest in Twitter stock in order to take it over.

[00:23:42] So Elon's there saying, okay. I'm offering 44 billion and it is based on public information. How does this work? Public companies have to provide stockholders and investors and, and the general community out there in information about their company. So they'll have things you've probably heard terms like forward looking statements.

[00:24:11] They'll say things that Elon Musk has certainly got in trouble before for saying things that weren't done through the securities and exchange commission. So, yeah. Okay, great. Uh, we're not doing, we're not doing as well as we thought we would. Uh, you know, when these companies are making announcements, the, all of these, uh, analysts are looking at what they think they're going to announce and how much of earnings per share they'll have, and whether they're gonna pay dividends.

[00:24:45] You've heard about all of this. Well, one of the things that has to go into those security and exchange commission filings, the S E C is the number of actual eyeballs you have. So you see an advertisers interested in how many people are on Twitter and how many people are seeing the ads, cuz that's how they're paying.

[00:25:10] Right? That's how they justify paying Twitter to run ads. Makes sense. I think, well, the same thing is true for the investors. They wanna know how many eyeballs are on there because that is what the ads are worth and based on what the ads are worth, that is exactly, uh, what we value the company had. Right?

[00:25:35] So, so all of these things and of course more, but those are the core things that go into valuing a business such as Twitter. So Twitter's there, they're putting out the S E C filings and they're telling the securities and exchange commission. Yeah, we have 5% of our Twitter accounts are operated by bots as many as 5%.

[00:26:04] That's what they're saying. Now various experts who have looked for the behavior, that would be a bot have said, the number may be closer to 15%. And I've even, I've heard numbers that are saying that the traffic on Twitter could be. Gen bot generated, uh, at 40 to 60% rates. So obviously you have count accounts that are bots, and then you have the traffic that they generate different numbers in both cases.

[00:26:37] So you've got all of this traffic being generated by bots, and that means it's not legitimate traffic. now what's a bot, a, a bot is, and you know, I've explained this before. Apologize for people that have heard it, but a, a, a bot is a kind of a robot think of it that way. And these robots go ahead and they repost things.

[00:27:06] They post things using hashtags and they're used by evil people. Uh, yeah, I I'm, I'm using that term now. Evil people, people who are trying to get you to do something and are manipulating. so very frequently, we have seen evil people out there who are trying to manipulate the value of a stock by going ahead and using their hashtag their keyword and having bots mention it thousands of times.

[00:27:43] So now that keywords going up and you as a regular user on Twitter, you see that keyword, maybe you're doing some research based on that keyword. And you find that yes, indeed. Uh, these people really have, uh, got a great business and this is gonna be fantastic. So they get eyeballs. And hopefully you're clicking through to their website and maybe they're looking for investors.

[00:28:10] And so you invest in them. You, you see what they're doing. So instead of getting it organically, instead of doing it the way I've done business, and my, I have a friend that says, Hey, Craig, if you were a, as unethical as these other people, like Zuckerberg, like bill gates, like so many others, if you were unethical, you'd be a billionaire too.

[00:28:32] My ethics say that you should not be manipulating people, right? I, if I've got something to offer that you want great, but these bots are used for manipulation purposes only, only. So if it's 5% bots, as much as 5% Twitters has a certain value. And if it's 15%. It has a different value. And that's what Elon Musk has been saying.

[00:29:03] What's the real value of Twitter. Now that it's come out, that the number of bots on Twitter is probably much higher than Twitter's been saying. While now you get the securities and exchange commission upset with you, and I bet you, there are investigations underway, criminal and otherwise against Twitter.

[00:29:29] And more than we've even heard about. So Elon Musk would be a fool to buy Twitter. And when you buy a company, you inherit all of its problems, including its lawsuits and potential lawsuits. So can you imagine the tens hundreds of millions of dollars they're gonna be spent defending Twitter and its board of directors?

[00:29:55] If indeed these things are true. Yeah. Hey, I've got a great article this week from the orange county register, talking about this, explaining. It all out, not as well as I did, but make sure you get my newsletter. My insider show notes, Tuesday mornings, Craig Peter son.com.

[00:30:16] Our technology related businesses. Now this includes everybody from apple, all the way through, um, car manufacturers, like Ford or GM. They have a disaster scenario that we're gonna talk about right now. And hopefully it doesn't happen.

[00:30:33] I have been kind of warning about this for a while. And I definitely been thinking about this for a long while and a great article that came out in nine to five Mac this week that I have a link to in my newsletter.

[00:30:50] This is in my insider show notes newsletter that comes out Tuesday mornings. This is the, the same show notes that I use. For the radio show and for my radio and television appearances. So make sure you are subscribed to keep you up to date. And of course you can subscribe right@craigpeterson.com. So this is a great little article it's titled Apple's disaster scenario is a real possibility.

[00:31:23] Say us and UK security services. What is the disaster scenario? It is the Chinese takeover of Taiwan, which would be very bad. We're about to explain why China, you probably have heard this before. Claims Taiwan is its own and Taiwan claims mainland China as its own, as they. Had, uh, the, the rulers, if you will, of China at the time of the communist takeover fled to Taiwan, basically a government in exile.

[00:32:00] So good luck Taiwan taking over China again, that that just isn't gonna happen. But the other side really. Could happen. So the heads of both the us and UK security services gave an unprecedented warning. This is I five and FBI heads. And, uh, of course that's director Christopher Ray. They're very, very worried.

[00:32:30] This is an unprecedented joint appearance in London. You probably did not hear about this anywhere else. This might be the first time you're hearing about it, but they said that China was quote the biggest long term threat to our economic and national. Security. They talked about how China's interfered in the politics, including recent elections.

[00:32:55] Of course, I've talked about that here. And of course, Russia also does some of that, but China, China, excuse me, is the real threat. I five's had said that they have more than doubled the work against Chinese activity in the last three years. They're going to be doubling it again. I five is now running seven times as many investigations related to China.

[00:33:21] Compared to 2018, uh, FBIs Christopher Ray warn that if China was to forcibly take Taiwan, it would represent one of the most horrific business disruptions the world has ever. Scene. And then China responded and said that the I five was trying to hype up the China threat theory, casting away imagined demon.

[00:33:48] Think about what happened with the lockdown. Have you heard about any sort of shortage shortage in semiconductors in computer chip? Yeah, of course you have. We've got major automobile manufacturers that have had to shut down lines, shut down shifts because they can't get the computers to control the cars.

[00:34:12] Cars are being shipped without seat heaters. They're being shipped without electric windows, even because they cannot get the chips. And that's because of a lock. Not a war, not China invading Taiwan. You see the problem is that Taiwan makes almost all of our chips that are used today in computers. and then China assembles much of the computer technology that we have today now.

[00:34:49] Yes, the, the top quality, the top technology manufacturing devices for chips comes from the

[00:35:01] United States, but it's sitting in Taiwan. So this becomes a very, very big problem. So let's talk about Apple's disaster scenario, cuz it's, it's absolutely horrifying because apple is hugely dependent on Taiwan. You've got the, a series M series S series chips all fabricated by TSMC that's Taiwan, semiconductor manufacturing company.

[00:35:30] Almost all of the apple production takes place in the company's plants. Within Taiwan, an armed conflict would have a devastating impact on Taiwan and its people and would cause massive disruption to manufacturing operations. What kind of manufacturing? Semiconductor who needs semiconductors? Pretty much everybody in the United States.

[00:35:58] Even if you are not reliant on high tech in your manufacturing, uh, you know, to include chips in your designs, which really light bulbs have computer chips in them nowadays, you are reliant on semiconductors for your manufacturing lines themselves, the controllers that are there, the robots that are. So the second point in this nine to five article is that it's inevitable that the us and most of the rest of the world would respond to the Chinese takeover of Taiwan.

[00:36:36] The same way that the world has responded to the Russian invasion of Ukraine. And that is sanction. So think about that. Let's say that China just marches in and takes over. No bloodshed, no buildings destroyed no problem with shipping, but we would all implement sanctions. Now, if the sanctions are as wide ranging as the ones that have been imposed on Russia, apple could no longer give any business to Chinese companies.

[00:37:14] which is where the vast majority of the apple products are manufactured. That's your iPhones, your iPads, your apple watches, your Mac, you name. The greatest volume of every apple product is assembled in China with a lot of the components made there as well and made in Taiwan. So we just cannot overlook the threat that it's posing to apple.

[00:37:40] And the facts that the fact that the, uh, heads of the MI five and FBI have chosen for the first time ever to raise this scenario as a real and present danger. So it's something that's gotta be terrifying, apple senior execs. Now we've been talking about apple here, but we're really talking about every.

[00:38:03] Four GM Chrysler all have parts that are coming using just in time inventory techniques from China and from Taiwan. The same thing is true for our European partners. Look at VW. They're just in time manufacturing. Also relies on Taiwan and on China for the parts to arrive just in time. Now, many parts are coming from different parts of the world.

[00:38:35] Many of our companies are smartening up saying, well, maybe we don't want to make everything in China. A lot of it's moving to different parts of Southeast. and it it's helping a lot of people in Southeast Asia. Some of this stuff is actually moved from China to different countries in Africa, particularly when we're talking about textile operations.

[00:39:01] but you are not gonna be able to get your windows PC either because your windows PC needs those chips, whether it's made by Dell quote unquote made by Dell, right? Who, who gets parts and they're sitting in the parts bins, and they assemble your computer for you or HP or Cisco, or whoever makes your. So this is a huge, huge deal.

[00:39:28] Absolutely crazy deal. The Chinese takeover of Taiwan. And I think that this war in Ukraine that was started by Russia has been a blessing in disguise for every last one of us, because China's ambitions to take over Taiwan, I think have been stalled. because of what they have seen in Ukraine, but also because Russia is a partner with China in so many ways, China and India have been buying oil and gas from Russia at substantially discounted prices because of the Ukraine war.

[00:40:13] So China doesn't want to step on Russia's foot. They have seen what the sanctions have done to Russia. In some ways they've really helped the Russian economy because now they're getting people buying rubles so that they can buy the oil from Russia instead of using the us dollar, the petrol dollar that's been in place for so long.

[00:40:36] So it, you know, sanctions are a two edge sword. Ultimately I think they. Us more than they hurt Russia and they would hurt China more than they hurt us. But what we're looking at is a short period period of time, relatively speaking, transitory, that we would be hurt pretty badly because of the sanctions.

[00:41:00] I mean really badly. Oh, my goodness. The things that these, uh, modern administrations have been doing, right. Oh, I wish it was, was different. Uh, let's talk a bit about the Z. He has made what a ink magazine is calling a huge mistake and ink is predicting. It really could destroy meta and Facebook.

[00:41:26] Zuckerberg came out and said in public, realistically, there are probably a bunch of people at the company who should not be here. Zuckerberg said he's turning up the heat. And he's really adding some unnecessary pressure, making a bad situation, worse and prioritizing ruthlessly. As he said, with stricter management and monitoring of employee performance is moving a lot of.

[00:41:57] People into second place, third place, it's prioritizing the bottom line while forgetting the people who are responsible for the company's success. So expect a real down environment as employees move, frankly, out of meta and Facebook. And then of course the whole thing that happened recently with Carol Sandberg over there a second in command.

[00:42:25] I guess it's kind of a mess. Hey, visit me online. Make sure you get my newsletters. Craig Peter san.com/subscribe.

[00:42:34] Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? You know, did you fall victim for that? Hey, upload your contacts. We'll find your friends. Well, they don't know where your data is.

[00:42:51] This whole thing with Facebook has kind of exploded here lately.

[00:42:56] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes now, you know, there's always a lot of rumors about different companies and particularly when they're big company and the, the news headlines are kind of grabbing your attention.

[00:43:30] And certainly Facebook can be one of those companies. So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal data? well, it came from a leaked document. Yeah, exactly. So I, we find out a lot of stuff like that. Right. I used to follow a, a website about companies that were going to go under and they posted internal memos.

[00:44:04] It basically got sued out of existence, but there's no way that Facebook is gonna be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So of course, if you're older, we used to call those TIAL waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

[00:44:33] So Facebook internally, they, their engineers are trying to figure out, okay, so how do we deal? People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

[00:44:57] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How are they all CATA categorized? Now we've got the European union. With their gen general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

[00:45:22] That's not my specialty. My specialty is the cybersecurity side. But in article five, this European law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected and used for a specific purpose and not reused for another purpose.

[00:46:00] So there's an example here that vice is giving in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, you know, feature as well as. Advertisers. Yeah. Interesting. Eh, so Gizmoto with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice.

[00:46:27] Cuz this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now. And most people. Right. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online and nothing.

[00:46:48] Right? I think I probably even uploaded it back then thinking, well, that'd be nice to see if I got friends here. We can start chatting, et cetera. Well, according to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal me, uh, memo, this European regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leak document shows that Facebook may not even have the ability to limit.

[00:47:24] how it handles users data. Now I was on a number of radio stations this week, talking about this and the example I gave, I is just look at an average business from the time it start, you know, Facebook started how right. Well, you scrape in pictures of young women off of Harvard universities. Main catalog, right.

[00:47:48] Contact page, and then asking people, well, what do you think of this rate? This person rate that person and off they go, right. Trying to rate them. Yeah, yeah, yeah. All that matters to a woman, at least according to mark Zuckerberg or all that matters about a woman is how she looks. Right. Do I think she's pretty or not ridiculous what he was doing?

[00:48:08] I, it just, oh, that's Zuckerberg, right? That's. Who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then opening up even wider and wider.

[00:48:33] And of course, that also created demand cuz you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certain you're starting to collect data and you're making more money than God. So what do you do? Well, you don't have to worry about inefficiencies.

[00:48:54] I'll tell you that. Right. One thing you don't have to do is worry about, oh, GE we've got a lot of redundant work going on here. We've got a lot of teams working on basically the same thing. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that, uh, money to this group or that group.

[00:49:16] And they put together all of the basic information, right. That, that they want. They are. Pulling it out of this database and that database, and they're doing some correlation writing some really cool sequel queries with some incredible joins and everything else. Right. And now that becomes part of the main code for Facebook.

[00:49:38] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says, uh, Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And, uh, they, one of the groups inside Facebook says, yeah, yeah, yeah, here, here we go.

[00:50:03] Here's all of the information we have about everybody and it's free. Don't worry about it. Right. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No, no, no, but, but the Obama. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

[00:50:30] And according to this internal memo, they still don't know. They don't even know if they can possibly, uh, comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the us Canada of course, has their own Australia, New Zealand think about all the places.

[00:50:53] Facebook makes a lot of money. So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water.

[00:51:15] Okay. And it flows every. The document red. Right. So how do you put that ink back in the bottle, in the right bottle? How do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from it? Apparently they don't even know where they got some of this information.

[00:51:39] This data from kind of reminds me of the no fly list. Right. You don't know you're on it and you can't get yourself off of it. Right. It is kind of crazy. So this document that we're talking about was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of a monetization strategy monetization strategy.

[00:52:06] And is the engine that powers Facebook's growth. interesting, interesting problems. And, and I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And I've talked about as well along comes Elon Musk and he says, well, wait a minute now.

[00:52:28] Now I can make Twitter way more profitable. We're gonna get rid of however many people it's well over a thousand, and then we are going to hire more people. We're gonna start charging. We're gonna be more efficient. You can bet all of these redundancies that are in Facebook are also there on Twitter. and Twitter also has to comply with all of these regulations that Facebook is kind of freaking out about.

[00:52:56] Well, it, for really a very good reason. So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does, but most companies, right.

[00:53:21] You grow. I, I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be, because it grew organically. Right. You, you started out with a little consumer firewall, router and wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around.

[00:53:44] This is normal. This is not total incompetence on the part of the management, but my gosh, I don't know. Maybe they need an Elon Musk. Just straighten them out as well. Hey, stick around. I'll be right back and sign up online@craigpeterson.com.

[00:54:03] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian looters.

[00:54:20] Thanks for being with me today. I really appreciate it. And I'm honored, frankly, to be in front of this microphone. , this is really something, you know, we, we know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that that looting is kept to an absolute minimum.

[00:54:43] Certainly the Americans, the British, even the Nazis during world war II, the, the, uh, the socialists they're in. Germany, uh, they, they tried to stop some of the looting that was going on. I, I think that's probably a very good thing, right. Because what you end up with is just all of these locals that are just totally upset with you.

[00:55:12] I found a great article on the guardian and there's a village. Had been occupied for about a month by Russian troops and the people came back, they are just shocked to see what happened. They're giving a few examples of different towns. They found that alcohol was stolen and they left empty bottles behind food rappers, cigarette butts, thrown all over the place in apartments and homes.

[00:55:41] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the clothes. This is a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and lingerie. This is really, really something. Uh, it, the Soviets didn't do this, but now Russian.

[00:56:05] Military apparently does. So over the past couple of weeks, there've been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidences suggests looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

[00:56:32] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto Euro trucks, everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioners.

[00:56:56] Being shipped back, just like, you know, you might use ups here, they have their equivalent over there. A lady here who was the head teacher in the school. She came back in, of course, found her home Lood and in the head teacher's office. she found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're gonna destroy it.

[00:57:22] They don't only leave anything behind. They found the Russians had taken most of the computers, the projectors and other electronic equipment. It, it, it's incredible. So let's talk about the turnaround here. A little. You might have heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

[00:57:42] So they get into the apple store. They grab laptops on iPads, no longer iPods, cuz they don't make those anymore. And I phones. And they take them and they run with them. Well, nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is, is they take some parts and use them in stolen equipment.

[00:58:09] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

[00:58:32] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, let's say they put 'em on wifi. They don't get a SIM card. They don't. service from T-Mobile or Verizon or whoever it might be. So now they disconnect to the wifi and it calls home, cuz it's gonna get updates.

[00:58:52] So on download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erased, et cetera.

[00:59:18] Now, police have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're, they're doing things like putting them into Fairday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

[00:59:42] You steal it. It's not gonna do you much. Good. So one of the things the Russian stole when they were in, uh, it's called, uh, I think you pronounce it. Uh, Mela me pole, uh, which is again, a Erian city is they stole all of the equipment from a farm equipment dealership and shipped it to Chenia. Now that's according to a source in, uh, a businessman in the area that CNN is reporting on.

[01:00:15] So they shipped this equipment. We're talking about combines harvesters worth 300 grand a piece. They shipped it 700 miles. and the thieves were ultimately unable to use the equipment, cuz it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

[01:00:42] It's autonomous. It goes up and down the fields. Goes any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, right. Of your property being very, very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

[01:01:08] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a, what not terribly profitable business. It certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? Well, what they do is they lease it. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

[01:01:36] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not gonna come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

[01:02:02] Right? You see where I'm going with this so that they can get their equipment in the hands of more farmers cuz the farmers can lease it. It costs them less. They don't have to have a big cash payment. Right? You see how this all works. So when the Russian forces stole this equipment, that's valued. Total value here is about $5 million.

[01:02:23] They were able to shut it all. And obviously, if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and you know, there's pros and cons to that. I think there's a lot of cons, but, uh, what are you gonna do? How's that gonna work for you? Well, it. Isn't going to work for you.

[01:02:44] And they were able to track it. It had GPS trackers find out exactly where it was. That's how they know it was taken to Chenia and could be controlled remotely. And in this case, how'd they control it. Well, they completely. Shut it off. Even if they sell the harvesters for spare parts, they'll learn some money, but they sure can be able to sell 'em for the 300 grand that they were actually worth.

[01:03:10] Hey, stick around. We'll be right back and visit me online@craigpeterson.com. If you sign up there, you'll be able to get my insider show note. And every week I have a quick five. Training right there in your emails, Craig Peter san.com. That's S O N in case you're wondering.

[01:03:36] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're gonna talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world.

[01:03:51] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

[01:04:03] We had improved all of their systems and their security and one of their. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine, all of a sudden TA, guess what it had ransomware on it. One of those big reds.

[01:04:25] Greens that say pay up is send us this much Bitcoin. And here's our address. Right. All of that sort of stuff. And he called us up and said, what what's going on here? What happened? Well, first of all, don't bring your own machine into the office. Secondly, don't open up particularly encrypted files using the password that they gave.

[01:04:48] and thirdly, we stopped it automatically. It did not spread. We were able to completely restore his computer. Now let's consider here at the consequences of what happened. So he obviously was scared. Uh, and within a matter of a couple of hours, we actually had him back to where he was and it didn't spread.

[01:05:16] So the consequences there, they, they weren't that bad. But how about if it had gotten worse? How about if they ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. Right. Would, do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

[01:05:43] Right? Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. Well, I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

[01:06:10] And if you're interested, I can send you, I I've got something. I wrote up. Be glad to email it back to you. Uh, obviously as usual, no charge. and you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

[01:06:34] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's two, two factor, right. First is they've encrypted your data. You can't get to it. And then the second side of that is okay, well, I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they they'll put it out there.

[01:06:58] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing, uh, you can lose your license for your business. You can U lose your ability to go ahead and frankly, uh, make loans and work with financial companies and financial instruments.

[01:07:22] It could be a very, very big deal. so there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And we, again, we've got a client that, uh, we picked up afterwards. That, uh, yes, indeed. They lost all of the money in their operating account.

[01:07:47] And, uh, then how do you make payroll? How do you do things? Well, there's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

[01:08:07] Uh, one is by the way, KTI, which is a big ransomware gang that also got hacked after they said we are going to attack anyone that. Uh, that doesn't defend Vlad's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. Uh, first of all, the largest ransom demand is $50 million.

[01:08:36] And that was in 2021 to Acer big computer company. Now 37% of businesses were hit by ransomware. In 2021. This is amazing. They're they're expecting by 2031. So in about a decade, ransomware is gonna be costing about $265 billion a year. Now on average, uh, Ransomware costs businesses. 1.8, 5 million to recover from an attack.

[01:09:08] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? Right? If you're a car dealer, you have a to print money, right? You you're selling car model or cars from manufacturer X. And now you have the right to do that and they can remove that.

[01:09:31] Right? How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, 20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom demand. So about her third paid ransom demand.

[01:09:56] Last. it's it's actually down. Cuz my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it's it's a little, little better than 50%, but 65% of pain victims recovered their data.

[01:10:26] Now isn't that absolutely amazing. Now 57% of companies are able to recover the data using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get backed? Probably took weeks, right?

[01:10:50] For a, a regular computer over a regular internet line. Now restoring from backup's gonna be faster because your down link is usually faster than your uplink. That's not true for businesses that have real internet service, like, uh, ours. It it's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

[01:11:13] So it's very, very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be incredibly expensive for you incredibly. So here you. The number one business types by industry for ransomware tax retail.

[01:11:46] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware, conscious of doing what, of keeping their data secure of having a good it team, a good it department. So there's your bottom line.

[01:12:14] Uh, those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And so, as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

[01:12:40] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to Craig peterson.com. And I'll also send you my special report on how to do passwords stick around will be right back.

[01:12:58] You know, you and I have talked about passwords before the way to generate them and how important they are. And we we'll go over that again a little bit in just a second, but there is a new standard out there that will eliminate the need for passwords.

[01:13:15] Passwords are kind of an, a necessary evil, at least they have been forever. I, I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

[01:13:32] Yeah, 360, you know, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements in, but you had a username.

[01:14:01] You had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang. And, uh, his password was always some sort of a combination of RA Lang. So it was always easy to guess what his, what his password was. Today, it has gotten a lot worse today. We have devices with us all of the time.

[01:14:24] You might be wearing a smart watch. That requires a password. You of course probably have a smart phone. That's also maybe requiring a password, certainly after boots nowadays they use fingerprints or facial recognition, which is handy, but has its own drawbacks. But how about the websites? You're going to the systems you're using when you're at work and logging in, they all require passwords.

[01:14:54] And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for, for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to log. Now that's really kind of an interesting thing, right?

[01:15:22] Just looking at it because we're, we're so used to having this password only authentic. And of course the, the thing to do there is make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe mix.

[01:15:44] Upper lowercase a little bit. In those words, those are the best passwords, you know, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cuz I use a completely different password for every website and right now, Let me pull it up.

[01:16:06] I'm using one password dot com's password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. Entries here in my password manager, 3,100. That is a whole lot of passwords, right? As well as, um, software licenses and a few other things in there.

[01:16:34] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I, I really do like that. Uh, some others that I've liked in the past include last pass, but they really messed. With some of their cybersecurity last year and I lost, lost my faith in it.

[01:16:56] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless sign in. and they're gonna make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

[01:17:20] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're gonna work with the Fido Alliance and they're gonna create this passwordless future. Which I like this idea. So how does this work? Well, basically you need to have a smartphone.

[01:17:39] This is, I'm just gonna go with the most standard way that this is going to work here in the future. And you can then have a, a. Pass key. This is kind of like a multifactor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, I'm giving a password and then it comes up and it asks me for a code.

[01:18:03] So I enter an a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password dot. In order to generate that code. So that's how I log into Microsoft sites and Google sites and all kinds of sites out there. So it's kind of a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

[01:18:31] We have biometrics tied in as. so to log into our systems, I have to have a username. I have to have a password. Uh, I then am sent to a single sign on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

[01:18:56] So, yeah, there's a lot there, but I have to protect my customer's data. Something that very, very few it's crazy. Um, actual so-called managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list.

[01:19:21] I'll send that to you. That's what we're sending out right now for anyone who signs up new@craigpeterson.com. And if you'd like a copy of it and you're already on the list, just go ahead and email me M E. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing.

[01:19:39] So what will happen with this is you go to a website and it might come up with a QR code. So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again have it set up so that your phone requires a facial recognition or perhaps it'll require a fingerprint. And now you are in.

[01:20:02] Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year. You're going to see this available on apple devices, Google Microsoft platforms. And it really is simple, stronger authentication. That's what Fido calls it. Right. But it is going to make your life a lot easy.

[01:20:26] It easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now I wanna talk about another thing here that has bothered me for a long time. I have a sister-in-law. who is in the medical field and, and, uh, gives prescriptions, you know, doctor thing. And, uh, I think she's not quite a doctor.

[01:20:50] I can't remember what she has or she's an LPN or something. Anyhow. So she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions. And so I warned her about that saying, you know, it is very bad to be using zoom because zoom is not secure.

[01:21:15] Never has been, probably never will be right. If you want secure, you. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure. So I talked to her about that and said, Hey, listen, you can't do this. You you've really got to go another way here.

[01:21:38] And so she started using one of these mental or. Medical health apps. What I wanna talk about right now specifically are some checks that were just performed some audits on mental health apps. That's why I messed up a second ago, but what they looked at is that things are a serious, serious problem there.

[01:22:05] And then in fact, the threat post is calling it, uh, creepy. Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise. So you can get on the horn with, uh, mental health, professional, uh, doctor or otherwise in order to help you here with your psychological or spiritual wellbeing.

[01:22:30] And people are sharing their personal and sensitive data with third parties and of 32 mental health and prayer mobile apps that were investigated by the open source organization. 28, 28 of the 32 were found to be inherently insecure and were given a privacy, not included label, including, uh, others here.

[01:22:56] So this is a report. uh, that was released here by the open source organization, tied into Mozilla Mozilla. Those are the Firefox people. They have what they call their minimum security standards. So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet.

[01:23:20] Even those minimum security standards. So these apps are dealing with some of the most sensitive men, mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal thoughts, domestic violence, eating disorders. And they are being just terrible with your security Mozilla researchers spent 255 hours or, or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, right.

[01:23:56] Between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed allowed week passwords. That range. One digit one as the password, 2, 1, 1, 1 while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data.

[01:24:25] So be very careful. Um, two of the apps better help a popular app that connects users with therapists and better stop suicide, which is of course a suicide prevention app have vague and messy. According to Mozilla privacy policies, they have little or no effect on actual. User data protection. So be very, very careful.

[01:24:49] And if you are a mental health professional, or a medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini training. They come out most weeks, just go to Craig peterson.com.

[01:25:15] Craig peterson.com. And I'll send you my special report on passwords and more.

View Details

What's With Those Strange Texts We've Been Getting?

PLUS

  • Hackers Using Deepfakes to Get Jobs
  • Autonomous Taxis Block Intersection
  • This New Law May Make Your Medical Care Cheaper and Better
  • Even the NSA is Being Spied On
  • Do You Use the Best Search Engine?

What's the deal with those weird, wrong number texts. This is kind of a really big deal, frankly, when we get right down to it, because we are getting scammed, there's even a special name for these types of scams. and I don't even know what to start with this, cuz it's absolutely crazy.

[Following is an Automated Transcript]

[00:00:18] This is I'll follow on to a scam. Again, if you've been on the internet for a while, you're familiar with the Nigerian scam. You remember that? where there was a Nigerian prince. And of course there's a lot of variations of this scam, but he needed to get his money out of Nigeria. And the only way he could really do that is by using a us bank account.

[00:00:43] And, you know, if you had a us bank account, you could really help him. And sure enough people would respond because he said, Hey, listen, I I've gotta wire some money out in order to gain access to it. And you can keep some of that money. And that amount kind of varied. And most of us kinda looked at that and with, uh, kind of crossed ice and said, what the heck?

[00:01:08] How could this possibly work with anybody? The grammar was so bad. So much of it was just so out of reality, frankly, And really here here's the bottom line. It worked because it was poorly written. people kind of expected, oh my, this is a foreigner, right? You wouldn't expect someone that doesn't speak English as kind of their native language to be able to write really, really well.

[00:01:36] And then when it comes to the whole concept behind it, again, they were looking for people who were kind of on the gullible side that weren't thinking it through all of the way. Well, we're at that spot again, and this is now using text messages and what's. And it's, it's been a pain, right? Uh it's it's annoying.

[00:01:59] So what are they doing and why are they doing it? Well, they're going after you and me in this case, this isn't, uh, let's get tens of millions of dollars from this huge company. It's what can we get from the little. Quite literally, and you know, maybe some small businesses, because those are the people that are most likely to make some mistakes here.

[00:02:24] So what they're doing is sending a text message, trying to get you to engage. So it, it might be a text message. Hey, uh, remember me? Right? There's an example. And, uh, you know, this is so, and so's, uh, doctor's office and checking up on your appointment. I'm looking right now at my, uh, at my WhatsApp list here.

[00:02:52] I'm I'm not a WhatsApp fan, if you want some private communications use signal, but we use it for one of my masterminds. So here you go. This is, uh, Picture of a very pretty young lady and it says, hello, how are you today? Jason? Long time. No, see how's your family that came to me. Right? Course my name's not Jason.

[00:03:13] I know that you know that, but apparently whoever this is, doesn't know that here's another one. Uh, even pretier girl, uh, Dr. David, my puppy moves very slowly and doesn't eat dog food. Can you make an appointment for me? So here we go. That was from, uh, air code 9 0 1 as though that's legitimate. Here's another one you are invited to join the Bitcoin discussion group.

[00:03:39] Reply with the number one click to join another one. Oh, the same message. Different, different, uh, place. Here's another one. Are you Kevin? these, these are all coming into my WhatsApp and I I've been getting some similar ones on my phone, regular one here's one, it says, hello. And I said, hi there. And he said, hello.

[00:04:06] International one, there it's, uh, going on and on and on. And there's a great article from subs stack that I shared this last week. If you have my insider newsletter, you have a link to this article and you can see some of the text messages in there. Now, this is from max Reed. Hi Tony. Remember me? It's been a long time since our last charity gala ended.

[00:04:30] Mr. Wine, sorry for the traffic jam on the road. I may be 10 minutes late. Jason, my aunt tomorrow, I go to the airport to pick you up. You can tell me notes and flights. I have not been able to contact your phone. Uh, Duran, can you tell me how your handmade meatballs are made? It is so delicious. Hello, which is one of the ones I got here.

[00:04:53] And the, and max said, sorry, who is this? Aren't you Kevin? Sorry. I think I added the wrong person. I'm not Kevin. Yeah. You got the wrong number. I usually have a lot of business partners. Maybe the secretary said Kevin's number wrong. I hope you don't mind. No worries at all. I see he was a kind person.

[00:05:10] Acquaintance is fate. Where are you from? You see what happens? They like engaging another one. Hello. Nice to meet you. Who is this? I don't know why I have your number in my address book. Do we know each other? It is my business partner or broad. Who are you? I love traveling. Maybe we met in a certain city.

[00:05:30] Maybe it is a kind of destiny that makes us similar to each other. now you must be a fan of travel. No look at the blue sky and white clouds behind your head. A good day starts in the morning. Good morning. Good evening. The guy sent a few hours later. This is called pig butchering, which is kind of a sad name for this considering the poor victims.

[00:05:57] Um, I had one, I had a call from a radio station down in, not in a television station down in Florida. because one of their newscasters had received a message kind of similar to this. And it was an email and it was sent by someone else in the TV station and it had a phone number embedded in, it said, Hey, you know, text me here.

[00:06:24] We're gonna have a party. I need you to do something for me. So the email came in, looking like it was from the station manager. So, what are you gonna do at that point? Well, so they figured, Hey, listen, uh, I'm gonna ask a station manager. And he said, no, no, I didn't send that email, know what's going on. And I have seen that a lot lately, uh, people who have been faking my email address.

[00:06:49] They use a reply to header in the email in order to kind of fake that it's me. And so they called me up and said, Hey, Craig, uh, we're having an issue down here at the TV station. And could you help us out a little bit? And maybe we can do a story about it, which they ended up doing a story. So I started talking to this person and I used a throwaway phone number on my part.

[00:07:18] So I wouldn't just get. Hassled all the time. So off we go and I respond and their English again was pretty poor, but they said, Hey, listen, we wanna have a party. And I want to get gifts to everybody. And I said, okay, so what's what you want. They said, oh, I I'm thinking what we'll do is we'll get gift cards for everybody.

[00:07:39] So we went through, there was probably two dozen different messages back and forth, and it was pretty obvious that I was messing with them. If. Spoke English I guess, or spoke it. Well, I don't know how much to script these guys are running off of, but they wanted me. To go down to the late, the nearest drug store and buy a couple of dozen $50 gift cards.

[00:08:05] And the idea was, we'll give those out to the other people in the TV station here as we have a little party. And I, you know, I thought, well, okay, where are these guys going with this? Because, uh, that's weird. So they kept asking if I had picked up the gift card yet and I kept making up excuses. Oh no, I had a hot story.

[00:08:22] Come in. You know, we, we got this thing tonight. We gotta make sure it's on the six o'clock news and we kept going back and forth with them. And I finally said, okay, so I'm, I'm heading on out now, um, to buy them. And then, then what do you want me to do with them? And I said, okay, well, take a picture of the front of the cards, each one of the cards.

[00:08:43] And then on the back, scrape off the number. And take a picture of that as well. So you could immediately see where they're going, right? Yeah. This isn't for any sort of a party. They're not giving them away. They want these gift card numbers so they can use them and cash them in. It, it, to me, it was just amazing that they were doing this.

[00:09:02] It was so obvious. We kept. Playing with them there. There's another one called the romance scam, which is another one that, uh, kind of follows along the same lines it's got. So in this case, what they do is try and romance you, and it could be a lot of, uh, older people, right? They're lonely nowadays, a lot of younger people, a lot of divorces going on.

[00:09:26] So they kind of romance you and it, it can take weeks or months, and then they hit you up that a family member of theirs. Corps or something else has to happen. Hey, I'd love to fly to the United States and meet you, but I just don't have the money. And then ultimately you offer to help a bit and send them a few grand so they can come to the us and you guys can meet.

[00:09:50] And won't it be wonderful or yeah, you wire them the $20,000 for the operation. For their relative, which of course, none of which is really happening. None of it's true. Now this is called Shajuan or pig butcher, and it has been a very big deal in China because they string the victim along for weeks, for months before the swindle actually takes place.

[00:10:19] So the idea behind the. Pig B train is that you, the pig are being fated for slaughter. Isn't that just something. So most of the time it ends with people depositing money into gold trading, four X, right? Uh, fake cryptocurrency platforms, kinda like the one I was reading earlier with the cryptocurrency stuff and the common enough in and around China that there's Chinese language YouTubers who stock in trade is identifying and publicizing.

[00:10:58] The scam. So be very, very careful about this stuff. Look at the newsletter I sent out on Tuesday morning, this week, follow up a little bit, read this article from subs stack and be smart about responding or better yet not responding to these scams.

[00:11:16] It's hard enough to get a job nowadays, even with all of the supposedly open jobs and there's reasons for that, we should discuss it at some point. But right now the FBI is saying that bad guys are using deep fakes to apply for jobs.

[00:11:33] Hey, and thanks for all of your notes guys. FBI. This is quite the little article, this particular one's on Gizmoto again, it was in my insider show notes that you should have received Tuesday morning.

[00:11:47] This is a free service of the Craig Peterson show, and it does keep you up to date. It's all the show notes I send off to the radio stations and I use for my radio show on the weekend and you can get them right there@craigpeterson.com. Just sign. There, and I'll be glad to send them to you. What's happening here is I think very clever.

[00:12:14] Now I've used deep fakes before you've heard me play them here on the radio where I have somebody's voice. And I, I use it in order to, uh, you know, either myself as my voice or it's somebody else. Here's an example. Just so you know, this isn't really me. This is a deep fake that I generated using a special software program.

[00:12:38] So I didn't spend any time editing that, you know, I could fix the tempo, obviously that deep, fake speaks more quickly than I typically do. I used to speak pretty fast like that, but I've slowed down and it is easy to do that. Just took me less than a minute to put. All together that that's how bad it's gotten or, or good it's gotten here.

[00:13:02] Here's another one you've reached the voicemail for Craig Peterson. He's on the road or out of the office right now. So please leave a message and I'll be sure to pass it along. Now that's actually my voicemail. If, if I don't answer the phone or I can't answer the phone and that's not a real person that that's even better than the deep fake of my voice, which I, you know, I had to feed it some audio in order to train it.

[00:13:27] And I had done that a long time ago, but that's just a stock voice that is not a real person. And I can have her say whatever I want. And there are sites out there that'll have, uh, a hundred or more of these. Deep fake voices that you can use. Male voices, female voices, et cetera. So what the FBI is warning about right now is that people are applying for it, positions that are bad guys.

[00:13:58] Real bad guys, like North Korea type bad guys. So the, in in fact I saw an article that said, uh, good luck hiring that new it guy. It might just be somebody from North Korea. So you're used to asking them questions, right? What's your worst quality. Tell me about a problem that you resolved at. Or probably you had with a, a coworker and you know, it's a little bit of a problem here because if you are talking to somebody on nowadays, a lot of people use zoom.

[00:14:31] I try not to. I use WebEx, we have a secure version of WebEx. Uh, we could go into this. I, I talked about it before, how zoom was being routed through China. But I, if the perspective higher kind of sneezes or coughs and doesn't move their lips, or they are not responding the way you'd think they should be responding, it could really be that they're actually not.

[00:14:58] Real. And we've seen stuff like this before. Have you ever seen the movie Simone and it's a simulated woman who was an actress? I, I think we're heading towards that by the way where ultimately the actors and actresses on movies that we watch are just pretty generic. People who are using a face that is owned and copyright copyrighted by the movie studio.

[00:15:25] I, I don't have any doubt about that. That'll be coming at sometime fairly soon right now, but the FBI put up on its internet crime complaint complaint center, just this last week that it's received complaints of people using stolen information and deep faked video and voice to apply for remote. Tech jobs.

[00:15:49] Now that's a pretty big thing to have to say, uh, when you get right down to it here, according to the FBI's announcement, and this is from an article in gizmo. More companies have been reporting people, applying to jobs, using video images or recordings. The are manipulated to look and sound like somebody else.

[00:16:11] These fakers are also using personal identifiable information from other people. In other words, stolen identities to apply for jobs at, in it programming database and software firms. Now many of these companies have access to sensitive information, things like customer data that can be used so they can steal your customers some of your intellectual property.

[00:16:41] it goes on and on. Just think about what they could steal from you. Of course, even cash, frankly. So I it's really not clear how many of these fake attempts at getting a job were successful versus how many were caught and reported. You never really know. Um, But, you know, how far did they get that? They start taking paychecks, et cetera.

[00:17:04] It's uh, it's a fascinating problem. So what do you do? Uh, the FBIs among several federal agencies. That's warning now of. People working for north Korean government who are applying for these remote positions. So be very, very careful about that. And it's not as easy to detect a fake videos as you might think.

[00:17:28] And that's particularly true if you're not looking for it. Artificial intelligence that is designed. To detect fake video. These deep fakes has accuracy from 30 to 97%. They have set up AI that compete with each other. One makes deep fakes. The other one tries to determine if it's a deep, fake or not, and they get better and better and better both sides over time.

[00:17:56] But there's ways that you can detect the fake video. And there are some visual glitches that you can keep an eye out for, like shadows that don't behave like. They should skin texture. That doesn't seem right the hair. Right. You might have noticed that in movies before, it's a kind of a, a, a glitch, if you will.

[00:18:18] Uh, water is a big one, but you're not gonna see that in a, an interview for someone looking for a job, but just like any other. Crime. If you see something like this online, if you are scammed and I'm helping a, a young lady, actually, a couple of different people right now that I think of it. Uh, who are I in the process right now of trying to recovers?

[00:18:44] Monies that were stolen from them. And one of them is actual cash that was stolen. The other one was cryptocurrency that was stolen. And the first thing you should do is go online, which is IC three.gov IC. three.gov. And this is the internet crime complete complete center. And you can file right there. If you think you've been a victim of an internet crime, you can also file on behalf of someone else you think has being a victim.

[00:19:19] And it has a lot of information that's asking from you. It has a whole form online they're they. The name of the victim address, telephone number, email, of course, financial transaction information, et cetera. The reality of it is they are very unlikely to do much about your individual case. If it's over a hundred thousand dollars involved, then they'll probably pay a little bit of attention to it.

[00:19:48] What they'll do is try and see if there's other people that have. Conor had stuff stolen from them in much the same way so that they then use that in order to put together a bit of a bigger case. But there are so many, so many of these things out there. Uh, but anyways, that's the way you want to go. Is I see three.gov.

[00:20:16] Keep that in mind because, uh, right now half of us are likely to become victims this year. That's how bad it's gotten. Make sure you get my weekly newsletter. My insider show notes. The free newsletter has so much great information to help you out. Craig peterson.com. And if you have a question or there's something you'd like me to talk about on the show, email me.

[00:20:42] me@craigpeterson.com.

[00:20:44] I'm sure you know about Tesla and their automated systems for driving assist. Right? Well, cruise Chevy cruises are out there on the roads in San Francisco. And have we got a story for you?

[00:21:00] If you have any questions, drop me an email. me@craigpeterson.com. We have in some states seen a lot of active autonomous vehicles.

[00:21:14] I'm sure you heard about the accident that happened out in New Mexico and a lady with a bicycle was hit and killed a. By one of these autonomous vehicles that are being tested. Yes, they are out on the road and it is really in limited cities and states. No question about that one, as they try and figure out how can they make these things be reliable?

[00:21:39] Cause that's ultimately what we want here. When I'm in my eighties, I would love to have an autonomous vehicle to show for me around heck I'd love it when I'm in my twenties. Right. Uh, it just makes a whole lot. Sense, but that technology is not here yet. It's kinda like all of these government programs that are trying to make our electric vehicles, et cetera, be the wave of the future, which is true.

[00:22:05] They probably will be, but we're talking, uh, I'm really not in my lifetime. If not in any of our lifetimes, this will take decades to get this all done. We gotta build a whole new grid. We've gotta make sure we have reliable sources of electricity. And that might mean we need new battery technology. What some companies have been doing is for instance, out in Las Vegas.

[00:22:30] It's cheaper to get electricity at night, which makes sense because you and I are asleep and businesses for the most part, industrial and otherwise are, are shut down. So here we are at nighttime having a good nap. So what do some of the, uh, casinos other places in Vegas, or are there hot areas around the country?

[00:22:50] Do well, some of them have installed a massive. Pool of water with chillers in it. So at nighttime, they go ahead and freeze all of that water. And then in the daytime, they use that ice in order to cool the air. So they're saving money. It's it's one way of storing energy. Another way that we've seen around the world is they use a.

[00:23:18] Now, you know about that, you know, you've got the water pressure and it drives a turbine that then drives a generator, an alternator, and then that produces electricity. Well at nighttime, they run them in reverse. What they're doing is they take water and they pump it up into the reservoir when the electricity is cheap or the demand isn't as high.

[00:23:43] And then during the daytime, when the demand goes up, they reverse that process. And the water now behind the dam just goes through the normal method of creating electricity behind a dam. So that's another way to store. Electricity or to store power. Neither one of those ways is particularly efficient, but it is efficient enough that it's cheaper than having to buy a peak demand, electricity.

[00:24:13] So we could talk about this for a long, long time, but we're talking right now about this cruise system failure. There were, what was it like four or five cars? I'm looking at an, a, uh, article that was in my weekly insider show notes on Tuesday morning. that you can get for free@craigpeterson.com. Just sign up right there.

[00:24:39] And this one is from the last driver license holder. Dot com kind of a cool name for somebody that follows these autonomous vehicles and these vehicles are all quite amazing cuz they're using the right technology, frankly. I'm not convinced that Elon Musk and Tesla are using the right technology. They are from a cost standpoint, right?

[00:25:04] It's way cheaper to have some cameras and have a couple of high speed computers on board. But it is not as effective as what's happening here, where they're using LIDAR, which is a laser radar, as well as in some cases using radar, they all have cameras on them. You should see the setup on the top of these cars.

[00:25:26] It it's probably 50 grand plus worth of sensors. On the car. So you're more than doubling the, the value, the cost of the car. So crews had a system failure and it is a problem. Now we've been saying Chevy Cruz. I'm looking at it right now. I don't know that it's the same guys. I'm thinking this is not Chevy.

[00:25:51] This is a different company. Okay. Sorry about that. But, uh, there's, there's two vehicles in this family. There's the poppy. And, and, uh, there is another one out there. I'm trying to remember what they called this thing. Uh, let me see if I can find out on the website anyways. A couple of cute names. Oh yeah.

[00:26:11] Poppy and the toda. And they've got others that are ready to roll that are ready to be out there on the streets. okay. There's another one called burrito. So they're out on the streets. They are driving themselves in the they're cabs. There's in fact, uh, lots of them on the streets in San Francisco and a dozen of them just over a dozen robot.

[00:26:36] Cabs that blocked an intersection in San Francisco for two hours before cruise employees were then able to arrive and drive them away manually or remotely in some cases. Uh, so Cruz gave this rather vague information or press release. They said we had an issue earlier this week that caused some of our vehicles to cluster together while it was resolved and, and no passengers were impacted.

[00:27:06] We apologize to anyone who is inconvenience to anybody, trying to get through the intersection. However, in further reports, it's clear, this is not the first time it's happened, nor is this type of behavior by vehicles. Something that's completely unknown. We saw one a couple of weeks ago or a couple of months now actually.

[00:27:28] That I, uh, talked about on the radio, where there was one of these autonomous vehicles, the police were trying to pull it over. It finally decided to pull over in an area, uh, right at the side of the road and the police car, I guess the car was expecting the police car to just pass it. Right. It was trying to get somewhere it wasn't trying to pull me over.

[00:27:51] And so they, it stopped. The police officer did not pass the car. It got right behind it and got, he got out of the car and walked up and looked in. There's no driver. And then all of a sudden the car took off on him again. And then the car was apparently looking for a safe spot by the side of the road. So it drove up the road a little bit.

[00:28:14] To where there was a, a, a nice kind of pull off area and it pulled over and stopped. Now the same type of thing happened here that on the display were the following sentences on. So you looked in the window, these people were looking in the window of these cabs that were pull, blocking this intersection over a dozen of them in San Francisco, and just said, pulling over to a safe stop.

[00:28:40] And then it also said something happened on your trip. A support specialist will explain what to do next. And of course it just didn't show up. There's also a telephone number for emergency responders to call in order to help rectify the situation and the number then also states the self-driving mode has been switched off and I'm, I'm looking at it right now.

[00:29:03] It's got kind of a. Grid and these messages on it, first responders should contact crews at, and it gives a toll free phone number. And it says a crew support specialist is on the way to help in person. And as it turns out they were, but it took a couple hours for them to show up. And it says we parked the car while the issue is resolved.

[00:29:24] So in other words, the cars got kind of confused, trying to figure out what to do. They were at a, an intersection and I don't know if they lost connection to the internet or what, but having a dozen of them failed at the same time makes me think that it was something outside of the cars that made this, uh, happen, frankly.

[00:29:43] So expect this to happen more and more. I'm glad it's happening in San Francisco and not in my hometown, frankly, but there've been cases where the primary and backup services have been down. So there's no way to communicate with the vehicles, get any information. It. Specifically and directly violates the terms granted by the DMV.

[00:30:07] Interesting stuff stick around will be right back a lot more to talk about here, about health insurers and a new law.

[00:30:19] The internet promised us a whole bunch of transparency information access. While as of July 1st health insurers and self-insured employers are now required to do something that should have been around a while.

[00:30:36] This is a moment that is going to be remembered by a lot of people, particularly in the medical healthcare business.

[00:30:45] I've been just shocked sometimes at how much. We get charged for some things. I'm also just amazed at what great medical care we have here. My family, most of them live in Canada and I have horror stories from pretty much every member of my family in Canada, about how terrible socialized medicine in Canada is.

[00:31:13] I mean, Terrible. Now you might know that I was a volunteer EMT. I D P uh, you know, basically a paramedic for about 10 years in my hometown. And we took care of a lot of people. I was, as I said, volunteer, it wasn't a call department. We didn't get paid a dime. We had to provide our own equipment and transportation, everything else.

[00:31:37] Right. So true volunteers. And I got to see some interesting sides of medical care here in the us. And as I kind of an exchange program, got to see some of it in Canada, as well as talking with people and the, the horror stories I can tell you about my family is just incredible. My, my brother was using a table saw and the wood kicked back and ripped off one of his fingers.

[00:32:09] This is in Toronto Brampton to be exact, just one of Toronto's many suburbs. And so here comes the ambulance and he sat in the back of the ambulance. They were driving from hospital to hospital. They couldn't even reach the hospitals beforehand to find out who might take him. And he was holding his severed finger in his hand for three hours, driving around in the back of the hospital before they could find somebody to re a hospital to reattach his finger or do something right.

[00:32:44] He actually says he wishes they hadn't reattached him. You, you wouldn't believe what they did to him and, and his finger. Uh, my father had a heart attack. Right there, Toronto, right? The biggest city in the country. And, uh, he has a heart attack and he's driving around for hours in the back of an ambulance before anybody will bother to have a look at someone who is in the midst of a heart attack.

[00:33:11] Now we're, we're lucky he didn't die. My grandmother, they would not give her medication for her atrial fibrillation. My grandfather. They had called and told his doctor, my mother did this when she was visiting him, that his foot was, uh, looking really bad and she was worried it would get gang ness. So they set up, uh, an appointment six months out.

[00:33:36] She said, no, no, no, no, no. No, it it's go it's gang us. Uh, you know, pretty soon here we gotta do something. So since it was an emergency, they, you know, they set it up for six weeks out and he ended up having to have his whole foot amputated. Um, so don't ask me about socialized medicine, unless you want to hear even more.

[00:33:54] Horror stories it's really, really bad. And just like, uh, schools, public schools in most states costing somewhere around $12,000 a year per student, and yet private education costs a fraction of that, like less than half in almost every case. Uh, You know, which is, which would you rather do send your kid to a private school that, uh, you know, education's probably better.

[00:34:22] I don't know. It's cheaper, so it's probably not as good as public school education. He said with his tongue firmly planted in his cheek, or do you wanna send him to the public schools? Anytime you get government involved or any big organization efficiencies start dropping, but particularly with government cuz they don't have competition and they will point guns at you.

[00:34:47] If you don't do what you're told ultimately right. As you get arrested. So, uh, what's happening here I think is a plus a very, very big plus I am a member of a health share. And so what we do is instead of having health insurance, we help each other pay our medical bills. So one of the things we're supposed to do when we go in there is ask for a self pay discount.

[00:35:16] So, this is a kind of an interesting thing, because what I have found is that the self paid discount shaves off. Typically at least 50% of the cost. If you look at what Medicare will reimburse hospitals, For, or doctor's offices again, it's a fractious way, less than half of what they want to bill you for.

[00:35:40] So they, the hospitals in other places will take people who don't have insurance and you can charge, uh, it'll charge you a whole lot less. It's kind of the bottom line here. So what does that mean to you and me, if you can tell in advance. What the costs might be. And I'm looking@thisarticleherefromkchan.org.

[00:36:08] And they're talking about one of these people who needed to have some, uh, medical care here in x-ray. And you saying that you can see that you can do it for 250 at the hospital, but if you go to the imaging center down the road, it's 75 bucks. or a specialist might be able to do it in their office for 25 bucks.

[00:36:32] What a difference, say a 10th of the cost and that is not abnormal. So what this law is now requiring. As of July 1st is that health insurers and self-insured employers must post on websites pretty much any price they've negotiated with providers for healthcare services item. By item. But the only things that are excluded from these price lists are prescription drugs, except for those that are administered in the hospitals or doctors' offices.

[00:37:09] So this is now federally required data release, and I think it is going to affect future prices because even if you have health, Insurance looking at these numbers is going to ultimately save you money because your monthly health insurance premium could be less. If the health insurance company isn't having to pay as much for all of this stuff, right.

[00:37:32] You, you see how that works. So it's to everyone's advantage. And when you start doing the math. you're talking about trillions of records that are gonna be published. Every physician in network, every hospital, every surgery center, every nursing facility, and every last charge that they have, this is gonna take a little bit of time.

[00:37:57] Isn't it? And the federal government is going to be imposing penalties for non-compliance. And they are going to be Heier than penalties that many hospitals are facing. If you are a small provider, uh, basically insurers self-insured employers could be fined as much as a hundred dollars a day for each violation.

[00:38:23] So let's say you have hundreds of procedures that you could potentially do a hundred dollars a day for each one of those procedures that's not listed or properly priced. Yeah, this could be millions of dollars, very fast for individual organizations, you know, per usual, right. Government is, is just power and they don't consider everything.

[00:38:46] They well, we had a hearing on, well, really you think everybody can attend a hearing that might be affected by this it's it's anyways, I'm not gonna get into that anymore. Right? It's not one of those days. Um, but these databases are gonna be enormous. Most people are gonna find it very hard to use the data in ways that are really going to help them or affect them.

[00:39:09] At least at first here, ultimately I think it's going to be something that we can use certainly is gonna be something that these, uh, PPOs and HMOs are going to be using to figure out where you should go in order to get. Something done or to buy something. And the biggest value of this July data release may well be to shed light on how the different insurers are able to negotiate prices with their providers.

[00:39:46] No. That's interesting. This article on K hn.org is saying that a recent study by the Rand corporation shows that employers that offer job based insurance plans paid on average. I hope you're sitting down here. Okay. This is employers. What do they pay? 224% more than Medicare for the same services.

[00:40:10] Fascinating. Isn't it. Tens of thousands of employers who buy insurance coverage for their workers will get this more complete pricing picture, which I think is really good. There's a whole lot of information here. If you want to find out more about it, just look at this, week's a newsletter, the insider actually show notes.

[00:40:29] I've got a link to this article. There is a lot of detail here. If you are a medical provider of any sort, if you work in a doctor's office, you are going to want to make sure you peruse this. I know most people I've spoken to in the medical business just aren't even aware of this yet. Although I think a lot of the hospital to the bigger organizations are aware of it, but.

[00:40:53] This is, uh, this is gonna be interesting. Uh, the people ultimately you make your medical choices based on money, or maybe it's based on who the doctor is and the bedside manner, and maybe the manner of their staffs. There's a lot of reasons other than price that people choose different medical providers.

[00:41:17] And, uh, and this is going be interesting. So check it out again as in my newsletter this week, uh, K hn.org. Great little thing. Uh, there's also a problem right now with attacks on routers. This is really bad. It's called zero rat. It's a remote access Trojan and it's probably a sophisticated nation state, and it's very, very bad.

[00:41:47] It, it is affecting these routers, these cheaper ones, net gear, SES. There's. Cheaper, Cisco ones, uh, day tech, many others, but what they do is they take over that router, the edge of your network, and then the malware takes full control of connected devices or running windows, Mac OS. And Linux, according to researchers, just within the last couple of weeks, high level of sophistication.

[00:42:18] Hey, make sure you get that insider show notes that I mentioned here a few times today, Craig peterson.org or com, I should say Craig peterson.com. And also if you have any questions, just email me, me, Craig peterson.com. And I will try and get back with you. Take care.

[00:42:39] You're worried about surveillance. Hey, I'm worried about surveillance and it turns out that there's a secretive company out there that to prove their mustard hacked the NSA yeah. Fun thing.

[00:42:56] This is a company that is kind of scary. We've talked before about a couple of these scary guys.

[00:43:03] There's this Israeli company called NSO group. And this is ANSO group is absolutely incredible. What they've been doing, who they'll sell to these. Guys are a company that sells cell phones, smart phone exploits to its customers, and they alleged to have sold their software to a variety of human rights abusers.

[00:43:34] We're talking about NSO group coming up with what we would term kind of a zero day hack against iPhones against Android phones against pretty much anything out there. So in other words, a hack that no one's ever seen before, and then use that in order to get into the phone and find information. They've used things like the, I think it was WhatsApp and video that was sent and use that.

[00:44:03] To hack Saudi Arabian phones. You might remember Khashoggi this, uh, so-called journalist, I guess he kind of was who apparently was murdered by them. Right. Big, big problem. So this Israeli group. Yeah. Yeah. They sell to anybody that's willing to pay. At least that's what the allegations are. I've never tried to buy their stuff, but yeah, they're assisting government with hacks with.

[00:44:32] Ultimate in surveillance. Another one clear view. We've talked about them on the show before this is a company that has done all kinds of illegal stuff. Now, some of it's, uh, technically not illegal. They're against the terms of usage, what clear view has done. And now they've gotten involved in this Russian Ukrainian.

[00:44:56] War that's been going on here. They've gotten involved with a number of legal cases in the us. What they did is they said, okay, well, great. Let's do something. Well, you remember Facebook, right guys. You've heard of that before. And how Facebook got started muck Zuckerberg. muck, uh, went ahead and stole the pictures of the women that were in Harvard's catalog.

[00:45:26] Right now when I say catalog, okay, this isn't like a catalog of women, you know, order one male order type thing. We're talking about their index, their contacts, right. There is a catalog of all of the students that are there in the school. So Zuckerberg goes and grabs those against policy. Okay. Maybe it wasn't strictly against policy at the time.

[00:45:48] And then he puts up something. Called the Facebook where people can look at a picture of a girl and decide whether or not she should get a five or a 10 or a one. Right? Yeah. That sort of stuff, abusing people that that really is abuse. I, I can't imagine. The way people felt had seen their ratings by people that didn't know them, that somehow their Def definition of beauty really defined who they are.

[00:46:18] It's it's crazy what the stuff he did. Right. So he started his business by stealing stuff. Microsoft started his business by what. Well, by going ahead and misrepresenting, some would say lying to IBM about what he had as far as an operating system goes right. A again and again, and again, we're seeing dishonest people getting involved, doing dishonest things to get their companies off of the ground.

[00:46:44] And I have a friend who's an attorney who says, and Craig, that's why you will never be wealthy because you just wouldn't do any of that. So clear view is another example of these types of companies. In this case, clear view, went to Facebook and crawled any page. It could get its little grubby crawlers on.

[00:47:07] So it found your public fab, Facebook page. It went all. Over the internet. There's a number of websites. Some are outta business now, but that you upload your pictures too. You people can rate them, can share them. You can share them. Hey, you got your own photo gallery here that you can share with friends and a million other people, right.

[00:47:29] That that's what ended up happening. That's how those guys made the money. Right? They're selling you on, Hey, you can look at how convenient this. And you can have your own little, uh, photo gather gallery and you can take that full photo gallery and, uh, share it with your friends. And then if you read the fine print, it's Hey, and we'll make money off of showing your pictures and showing ads.

[00:47:51] Well, Clear view went and scanned every website. It could get its grubby little scanners on crawled through the mall, downloaded pictures of any face that it could find. And then went ahead and digitized information about people's face. So it spent years scraping and then it put together its technology, facial recognition technology, and went to the next level, which is, Hey police department, get my app so you can get the clear view app.

[00:48:31] And you encounter someone, you can take a picture of them and upload it, which now gives them another face. Doesn't it. And then once it's uploaded, it'll compare it and it'll say, okay, found the guy here he is. So with the Russia Ukrainian war, what they were doing is taking pictures of, of dead and injured, Russian soldiers, running them through this database online of all of these faces found out who they were and went so far as to use other.

[00:49:04] Stolen data online. Now this is war, right? The whole thing is crazy, but the stolen database online found out who their mothers were, the phone numbers for the mothers and have people all over the world. Sending text messages to mom about their dad's son. . Yeah. Okay. So Clearview sells it to police departments.

[00:49:29] They sell it to, um, pretty much the highest bidder they say, Hey, listen, we don't do that. Come on right now. There's other data brokers. And I've had a few on my show in the past who are using harvested information from phone apps to provide location data. To law enforcement so that they can then circumvent.

[00:49:54] What, what, well, you have a right to privacy. Don't you it's codified right in the bill of rights, those first 10 amendments to the us constitution. And it was also. Uh, defined by the Supreme court's carpenter decision. So we have protections in the constitution, natural rights that were confirmed by the Supreme court that say, Hey, the federal government, you cannot track all of the citizens.

[00:50:26] You can't track what they're doing. You can't harvest their information. And yet at the same time, They go to the data brokers that have put together all of these face pictures, figured out who your friends are, you know, you know, you sign up for Facebook and it says, Hey, you want me to find your friends?

[00:50:45] See if they're already on Facebook, just, just hit. Yes. Here, not blow your contact list. So up goes. Facebook says, oh, look at all your friends. We found isn't this exciting. And in the meantime, in the background, Facebook is looking at all of this data and saying, ha, we now know who your friends are. And so many people have wondered, well, wait a minute.

[00:51:07] I didn't talk about, um, I, I didn't do a search for product X online, and yet I'm getting ads for product X. Well, did you mention it to a friend who might have done a search for it? Because these search engines, these companies like Facebook know who your friends are, what they're interested in, and they'll sell ads to people who are going to promote to you the same items they're promoting to your friends.

[00:51:33] Right? It it's absolutely crazy. So this company. It's called a six and they're very, very quiet, very low key. The website doesn't say anything at all, but they took their software. That's pulling all of this data together and compiling it and. And a six pointed all of this technology towards the national security agency and the C I a and Jews, their own cell phones against them.

[00:52:08] Now, why did they do this? They didn't do it to prove something about how, you know, you shouldn't allow this sort of thing to happen and they didn't do it to prove that man, we gotta have tighter controls because look at what we can do if we can do what other people can do it. No, no, no, no. According to audio, visual presentations and recordings of an Asics presentation reviewed by the intercept and tech inquiry.

[00:52:37] Asics claimed that it can track roughly 3 billion devices in real time. That's equivalent to a fifth of the world population. You're not gonna find anything out about a six it's called anomaly six. Good luck online. If you find it, let me know me@craigpeterson.com. I'd love to know more about these guys.

[00:53:00] The only thing on a website for them is email address and a six anomaly six in that presentation showed the nation spooks. Exactly what a six knew about. All right. Uh, apparently a six is also ignoring questions from journalists and will only respond to emails from people in upper levels of federal agencies, which means, and maybe this is a supposition from our friends over at tech dirt.

[00:53:36] I don't know. But there, what that means is they're looking to sell your information in real time. To the feds to get around the carpenter decision and the constitution just absolutely amazing. Hey, go online right now. Craig peterson.com. I'll send you my special report on passwords and my two other most popular Craig peterson.com.

[00:54:03] Stick around.

[00:54:07] Have you ever wondered about search engines? Which ones should you be using? You're not alone. It's probably the number one question I get from people. What should I use? Well, Google is falling behind, but we're gonna talk about the top engines and the whys.

[00:54:25] Google has been an amazing company moving up. Of course, you know, we were just talking about the cheats.

[00:54:33] So many companies have taken over the years and Google has certainly had its share of cheats. I haven't seen anything about them just doing completely underhanded things to get started. I think. They were pretty straightforward. They had a great idea back in the beginning, where they were just looking at links, how many sites linked into this one particular site?

[00:54:59] And that gave this concept of a page rank. Very simple, very easy to do, of course of problems with that. Because you would end up with pages that are older, having more links to them, et cetera. And they have over the years really improved themselves, but we also have some other problems right now with Google.

[00:55:24] If you do searches on Google for a number of different top. Uh, and you'll, you'll see that really Google search quality has deteriorated in recent years. We've talked before here about some of the problems with Google and elections and how they have obviously gone out of their way to influence elections.

[00:55:47] There a study down in done in orange county, California, or at least about orange county, California, and an election down there showed that Google had a major influence on that election and also tilted it a certain way on purpose. Absolutely amazing. So that's one way Google has kind of fallen behind, but you can.

[00:56:10] at all kinds of searches and hope you're gonna get a great response. And you don't have you noticed that it's gotten worse and then on top of it, you're starting to see more ads squeezed in it is not great. Uh, I have used it. A course for programming. In years past, before that I liked altar Vista, which was a digital equipment corporation product altar Vista was pretty darn good.

[00:56:38] And you could use boo and logic with it. Google says, well, you can use bullying with us, but it it's not the same. It's Google's is very, very simple. But at any rate they have not made any. Leaps here going forward. It it's been absolutely amazing. So let's go through the search engines. I'm gonna give you right now, the pros and cons to some of these search engines out there.

[00:57:04] So we started with Google. It is the 800 pound gorilla. And in case you didn't know this number two overall search engine is YouTube. Okay. But let let's stick with straight searches, not video searches. So what is great about Google? Well, one of the big things is they like fresh content. So if you're looking to do search engine optimization for your business, you are best off having some Keystone pages.

[00:57:37] So having these pages that are. Kept up to date. So you might have a page on whatever it might be hacking VPNs, right? Uh, and you make sure you update it. Cuz Google does favor the fresh content. They rank blogs and. Services, which is really nice and they're accessible in any device. They have apps. They work well on a browser and I'm I'm right now, I'm looking@anarticlebylifewire.com on the best search engine.

[00:58:08] So you'll see some of this information there. What. They don't like about it is the same thing you don't. Right? Which is, it collects all kinds of data on you. They also have hidden content that, that, uh, might damage your ranking as a business or someone who has a website and the search deliver. Too many results, you know, you see millions of results.

[00:58:37] Well, yeah, there probably are millions of results for a single search, but what I want are the really relevant ones and Google learns over time. What kind of results that you want, which is kudos to them, but they are tone deaf sometimes, frankly as well. Okay. Our number two on our list of top eight. Is duck dot go.

[00:59:00] Now I've been talking about them for quite a while, and some people have been kind of disparaging duck dot go lately. And the, the reason is they say, well, those search results maybe are a, a little wrong, right? They are, uh, maybe student little. Cing not as much as Google does, but some, well@firstduckdotgo.com is where you'll find them online named after that kid's game.

[00:59:30] Is a privacy search engine. So it is not tracking or storing any information about you. That's a very big one. Their searches are very fast, but their backed, the actual backend search engine is Bing. Which is Microsoft. We're gonna get to that in a couple minutes here. That means that if Microsoft is deciding to do some waiting on search results, based on their political views, then that's gonna show up in duck dot go.

[01:00:03] But it's nowhere near as bad. And I've talked about it on the show before we've done some examples. So it is also now giving you the option to restrict your searches to the last month worth of results, which is really nice. That keeps a little more up to date. They also aren't graded image searches, no personalized results, and it is free, which is nice.

[01:00:27] You might also wanna look at quant Q w a N T. If you're looking. A private or privacy browser quant is a French company, but it, it does English as well. Okay. English results. They like the older and well-established web pages, they rank home pages. They do not rank blogs. They crawl all kinds of hidden content and non hidden, equally, unlike Google, which is really great.

[01:00:59] Uh, Bing is not great at forums. As I mentioned blogs, they're not as fast as Google. And they have some seriously heavy search results, screened dog pile they've been around for quite a while. You might want to check them out. They have something called fetches and favorite fetches. So you can have a home screen when you go to dog pile and you'll see right there.

[01:01:26] Uh, your favorite searches and they're right there for you. You can just keep going to them. They use multiple databases so they can get broad results, multiple backend search engines, and there's no home screen personalization available with it. And lots of sponsored results, which isn't a real big deal, but you'll find them online@dogpile.com, Google scholar search.

[01:01:50] I've used this a number of times. If you are looking for scholarly articles, it is really good. You can get citations and various styles. If you are working on your master's PhD, whatever it. Be, and they're imposing a style in the document that you're writing, so you can put it into the bibliography. And, uh, they, they got a lot of great stuff.

[01:02:14] Google scholar you'll find online@scholar.google.com. Web EDIA search. It focuses on technical terms and applications, which is kind of good, friendly to non-tech users. And it is only searching weed's 10,000 word and phrase database. So that's pretty good. To, uh, to understand too Yahoo search, they have a home screen has news trending topics I I've used Yahoo of course is not what it used to be, but it does have everything right there.

[01:02:52] Even your horoscope. And the ads are not marked out clearly. And then there's the internet archive search. This is actually a site that I fund. I, I donate money to them every month and you'll find them@archive.org, but it is really, really cool. You can search based on timeframes again, if you are doing papers, if you are a journalist, et C.

[01:03:19] You can find what was the internet like? Or what was this webpage? Like? What was it like around hurricane Katrina in 2005, right there. We'll find it online@archive.org. Hey, stick around. We'll be right back.

[01:03:37] You already know that hackers are coming after you we've talked about how they are out there, scraping web pages, putting together stuff. Well, I wanna bring up again, the Ukraine, Russian war and Russia leaking data like a S.

[01:03:54] Hi, if you've ever wondered who I am. I'm Greg Peterson. We met before. I'm your chief information security officer, well, Russia, Russia, Russia. It, it is of course in the news again, it seems like it's been in the news for how long now, six years, maybe longer in this case, we're gonna talk about what the hackers are doing because they're not just doing it to Russia.

[01:04:22] They're doing it. us. And it's a problem. We're gonna explain why you've heard of doxing before do XX. I N G to docs someone, which is basically to find documentation about people and to release it. That that's really a part of it, frankly. So you've seen some political operatives who have gone online and, and docked people.

[01:04:50] For instance, uh, one of them is libs of TikTok. You might have heard of that one, and this is where they take all of these crazy things, that crazy people, uh, on TikTok, go ahead and publish and just put excerpts of them together. They don't like cut it up to make them look crazy. No, no, no. They let them be crazy.

[01:05:12] All all by themselves and put it online. So some libs decided, Hey, we don't like this. And, uh, a so-called journalist who had been complaining about doxing before that shouldn't be done and it's unethical. It should be illegal. Yeah. What does she do? She goes and docks. The lady that was running libs of TikTok and I, I, it just, it blows my mind here.

[01:05:44] How can these people be so two faced? They really are just crazy, crazy two-faced. So she went ahead and did what she said should never be done. And I'm sure she had some form of justification for it and put it out online. So, uh, online comes this lady's home address her name. Kinds of stuff and that's available online right now.

[01:06:10] Now you might wanna try and do something that I've done before, which is, if you go to one of these data brokers, you see ads for these things, right? Like a, do a search for yourself with us. And have a look at how accurate that information is. When I looked last time I looked cuz I had a few data brokers on the radio show.

[01:06:32] I would say less than a third of the information that they claimed was information about me was actually accurate less than a third, frankly. And I don't think that's a particularly, what's the word I'm looking for, but. unique situation. Let me put it that way. I don't think it's unique at all. I think they get a lot of it wrong because remember, they're trying to piece together this piece together that and put it all together.

[01:07:03] So you, you can't a hundred percent rely on any of that stuff. And as I said, for me, it wasn't particularly accurate. Well, now let's move into war. Ukraine has claimed to have docked Russian troops, as well as FSB spies. You remember them from the Soviet union, they still exist. Right. And activists actually have official scheduled meetings and are leaking private information from various Russian organizations and Russian people.

[01:07:39] So we're talking about things like their names, birth dates, passport numbers, job titles, and the personal information that they have released about these Russian companies. And people goes on for pages here. It looks like frankly, any data breach, you'll find a great article about this that I'm referring to in wired.com, but this particular data.

[01:08:04] Can change personal information on 1600 Russian troops who served in BKA a Ukrainian city, that's been attacked by Russia. And by the way, you've probably seen these things. There were all kinds of, uh, accusations here of multiple potential war crimes. What was going on over there? So this data, set's not the only one.

[01:08:29] There's another one that. Allegedly contains the names and contact details of 620 Russian spies who are registered to work at the Moscow office of the F S B. That is Russia's main security agency. Now this information wasn't released by hackers in North Korea or hackers in the us or Russia, because we already know Russian hackers.

[01:09:02] Don't attack Russia. They're not stupid. Okay. They don't want Booton coming after them, but this was published by Ukraine's intelligence services. So all of these names, all of these personal details, birthdates passport numbers, job titles, where they're from all kinds of stuff. Uh, freely available online to anyone who cares to look now, Ukrainian officials wrote in a Facebook post that as they published the data that every European should know their names.

[01:09:36] So you've got to bet there are a lot of people kind of freaking out over there. Absolutely, absolutely freaking out, uh, in Russia that is. Since the Russians invaded Ukraine, there have been huge amounts of information about Russia itself, the Russian government's activities and companies in Russia. These are all the GARS that are over there and it's all been made public.

[01:10:02] So it's very interesting, cuz these are been closed off private institutions in the us. Yeah, we do do some hacking of potential adversaries, but they don't release it. All right. Uh, not at all, but there's really two types of data here. First of all, you've got the information that the Russian authorities are publishing.

[01:10:25] Their allies are publishing, and then you've got the activists, these companies, these groups, I should say, like, Anonymous hundreds of gigabytes of files and millions of emails have been made public, including some of the largest companies within Russia. I mean the big guys, oil and gas companies, uh, or lumber companies, et cetera, cetera.

[01:10:51] So there's a former British Colonel in the military intelligence. Wired is quoting here, his name's Philip Ingram. And he said, both sides in this conflict are very good at information operations. The Russians are quite blatant about the lies that they'll tell we're used to that aren't we, and much of the Russian disinformation has been debunked, but they.

[01:11:19] They have to make sure that what they're putting out is credible and they're not caught telling outright lies in a way that would embarrass them or embarrass their international partners. So it it's really quite interesting. We've started seeing the stuff coming out in March 20, 22, of course. Right.

[01:11:39] and it's hard to tell how accurate the data is. It looks probably pretty accurate. It has been scooped up. As I mentioned on the show before. uh, some activists, one of whom has put together an app that anyone can download and allows you to send text to this mothers of Russian soldiers, some alive, some dead, and it automatically translated into Russian.

[01:12:08] I, I assume it's kind of a crude translation, but whatever. Right. So you can. Harass some poor, uh, babushka over there in Russia, whose grandson is out there fighting. This is just incredible. We've never seen anything like any of this before, but doxing very toxic online behavior. And when it comes to war, the gloves are off.

[01:12:34] Right. And by the way, these groups that I mentioned, these hacktivists have official meetings, Tuesday mornings on telegram, and they talk about who the next target is. Absolutely amazing. Make sure you visit me online. Craig, Peter son.com. And don't go anywhere because we've got more coming up here about organizations in general, here in the us breaches are up stolen.

[01:13:03] Data are. And the number of bankruptcies are up because of it.

[01:13:10] Hacks are up now, you know that we've, we've known that for a while, but did you know that that is not necessarily the number one reason businesses are suffering breaches? So we're gonna talk about that right now. What else you have.

[01:13:26] We've talked before about some of the websites that I keep an eye on.

[01:13:31] One of them is called dark reading and they've got a lot of good stuff. Some of this stuff I don't really agree with, but you know, who agrees with everybody or another person? Just one, even a hundred percent of the time. Like no one. Okay. So in this case, we're talking. Organization suffering a breach. And the stat that they're quoting here is that more than 66, 0% of organizations have suffered a breach in the last 12 months.

[01:14:04] That's huge. And the breaches have gotten more expensive. Global average breach cost is $2.4 million. And if you are unprepared to respond to a compromise, that price tag increases to 3 million. Yeah. That's how bad it is. That's what's going on out there right now. But the point that really they're trying to make here at dark reading in this article, by Robert Lemo.

[01:14:36] Is that our organizations are focused to narrowly on external attackers when it's insiders third parties and stolen assets that cause many breaches. That's what this new study is showing from Forester research. Now I've had them on the show a few times in the past, you might be familiar with them. They are a research company.

[01:15:02] That charges a lot for very little information, but you know, they've, they've got the research to back it up, right. They're, they're really one of the leading, if not the leading research company out there. So last month they came out. with the 20, 21 state of enterprise breaches report. And they found that the number of breaches and the cost of breaches varied widely, depending on where the organization is based.

[01:15:33] And. The big one that you have control over is whether they were prepared to respond to breaches. Now, companies in north America had the largest disparity between the haves and have nots. Listen to these numbers. They're bad for businesses. These numbers and're worse for individuals. The average organization required 38 days.

[01:16:00] 38 days over a month on average to find eradicate and recover from a breach, but companies that were not prepared for security challenges took 62 days. Now the good news here is that this is down. It used to take nine months on average, and now we're down to two months, but here's the big question for you.

[01:16:30] Can you, or can a company survive 62 days or is it gonna be out of business? Right? Do you have enough money to make payroll for the next two months? That's where the problem. Really starts to come in. That's why small businesses that are hacked small businesses that are using things like Norton or some of the other real basic software without having a, a good firewall and, and good security practices.

[01:17:02] Uh, and same thing with individuals here. Uh, you are going to be out of business odds. Right. That's what they're showing right now. And your insurance policy that you have for cybersecurity insurance will not pay out. I did a presentation for an insurance industry group. Uh, this was in Massachusetts and it was a statewide group.

[01:17:29] And we talked about how. Are not paying out the companies. Aren't right. And why, and if, if you are not prepared, if you are not doing the right things and I can send you a list of what you need to be doing, if you'd like, just email me@craigpeterson.com. Be glad to send it to you. Me, me at Craig Peterson, P E T E R O n.com.

[01:17:54] and just ask for it and I'll, I'll respond to you or we'll get Mary or someone else to forward it to you because I've already got it. Okay. This isn't a big deal for me. Okay. it's ready to go. But, um, that list is an important list because if you don't meet the standards, That the insurance industry has set forward and you are a hack.

[01:18:16] They're not going to pay you a dime, even if you Sue them. And we've seen this with very large companies as well, where they're trying to recover tens of millions of dollars from the insurance policy, and they didn't get a dime. They had to also pay who knows how many millions to lawyers to Sue the insurance companies.

[01:18:36] And they lost. Okay. It's a very, very big deal. So there's of a huge misalignment, according to Forester, between the expectation and the reality of breaches on a global scale, there's a big disparity of about $600,000 between those who are. Prepared to respond to a breach and those who are not. And, uh, we can talk about that as well, because there there's things you need to do obviously backup, but backup means you've got to check the backup.

[01:19:08] You've gotta make sure it's valid. You should be spinning up the backups on, in a virtual environment in order to make sure the backups are good. There's a lot of things you should be doing. Okay. And, uh, that's just a part of it. Plus, do you have your PR people ready? Are you able to respond to the state requirements?

[01:19:29] A lot of states. Now, if you are hacked require you to report it to the state, in some cases in as little as 72 hours. So do you have that paperwork ready? Do you have the phone numbers of all of the people that are on the team? Okay. All of these things now, the threats are not just the external hackers.

[01:19:52] anybody who's trying to protect their data is focused on obviously the external hackers. That's where we tend to focus part one part two is we focus in on the people that are working inside. The company, right? It's kind of a zero trust narrative here. Why is this guy in sales, trying to get into the engineering files?

[01:20:19] Why are they trying to get into payroll? Right? You, you understand where I'm going with this? You buying what I'm selling. You don't want them to have access to stuff that they don't need access. So. Attacks that Forrester found were spread over external attacks, internal incidents, third party, and supply chain attacks, which is really big nowadays and lost or stolen.

[01:20:50] Assets globally. Half of companies consider external attacks to be this top threat, but in reality, only a third of the incidents come from external actors. Nearly a quarter of them are traced back to an internal event while 23% consisted of lost or stolen assets and 21% involved, a third party. Partner, interestingly.

[01:21:15] So we've got to keep an eye on this. These external attacks are a very big deal and that's where they have success with what are called zero day attacks. But your internal people can be a problem. Now I have. Put together 20, uh, 2022. This is something really, really important. A what we call a POA and M it's a plan of action and milestones of what you need to be doing.

[01:21:50] For your cyber security. Okay. This is available absolutely free. You have to email me M E Craig peterson.com. But the idea behind this is it's a spreadsheet that you can use in numbers on a Mac or Excel on windows. And it has all of the key items. Now we follow what's called the. 801 71 standard. This is the national Institute of standards and technology, and they've laid out, uh, all of the different things.

[01:22:23] That you should be doing now. We've broken them down into eight cyber security. Activators is what we called them. And we have, you should have already gotten an email this week from me. If you're on my email list, just talking about cuz we we're starting now getting into those cyber security activators.

[01:22:42] I'm showing you what. To do about each one of them. So you can do it yourself. Right? So many of us are stuck with being the, the CTO or the guy or gal in charge of it just because we like computers or we know more than somebody else. Right. So if you're on my email list, you will be getting these things automatic.

[01:23:03] We're gonna be going through them in the weeks ahead. Little, little quick mini micro trainings, if you will, but you gotta be on the email list in order to get them. These are also appropriate for home users right now. You're gonna have to make your decisions as to what you're going to do, but home users have the same exposure, the same basic problems that they have in bigger organizations out there.

[01:23:30] so I follow the national Institute of standards and technologies. They have broken it down into a number of different sections. They actually require it. And if you are compliant with this with thisness standard, uh, you are going to be able to recover your money from the insurance company. If you are hacked.

[01:23:55] I dunno. I was gonna say if or when, but, um, hopefully you won't get hacked because of this. So it it's an important thing to follow. So make sure you go to Craig peterson.com/subscribe right now and get subscribe a lot of stuff for home users. You know, my business is focused on securing businesses.

[01:24:15] Particularly regulated businesses, right? If you have intellectual property, you don't want to have stolen. If you do government contracts where they're requiring you to be, uh, uh, compliant with thisness standard or some of the others, but it's. Basic stuff that every business should be following. So just email me, me, Craig peterson.com with your questions.

[01:24:40] We've been really good at answering them. We've probably lately been averaging about a dozen a day. Which is quite a few. So it might take us a little bit to get back to you, but we've gotten much better. Mary, her, her number one responsibility right now is making sure that we answer all of your emails.

[01:24:59] We'll send out this plan of action and milestone spreadsheet for you. So you know what to do. This is updated. This is 2022. Everything you need right there. Me at Craig Peterson dot. All right. You'll also find my podcast there. Craig peterson.com. And I wanna point out that I'm not doing the show on video anymore.

[01:25:26] It just wasn't getting enough traction with it and it just takes too long. Anyways, Craig peterson.com.

View Details

Saving 79% on PrescriptionsMicrosoft Outlook Attack in Progress!
Does Your Business Use eMail? FBI Warning

About one-third of Americans are taking a prescription drug -- And this is kind of the scary part. The average person who is on a prescription has four prescriptions and we're paying dearly for it. But mark Cuban has an answer.

[Following is an automated transcript]

Well, you know, I do a lot of stuff in cybersecurity and I've got a few different courses coming up.

[00:00:22] And of course, we do a little bit of weekly training for anybody who's on my email list, you know, on the free list. Absolutely free as well as you get my insider show notes. And if you got my show notes, you probably noticed this. Tidbit here on Tuesday when I sent it out. And that is mark Cuban. Now for those who don't know mark Cuban, he started way back in the internet.

[00:00:48] Boom days he lucked out. He had a, a company called broadcast.com. and he was able to turn that into, I think it was well over a billion dollars. I don't remember the exact amount, but it, it was a very, very big chunk of money. And then he's gone on to become an investor. You might know him as the owner of a basketball team.

[00:01:10] You might have seen him on a TV show called shark tank. He's been out there and he's a bright guy. He's been helping a lot of people and causing a lot of problems too. Right. But he has a new business that he has started with his billions of dollars only. He has at least 1 billion and it's called. Cost plus drugs.

[00:01:35] Now this is where it comes into affect every American, because I mentioned, you know, how many Americans are on various prescriptions? Well, many of the prescriptions that we could be taking are actually generics. So for instance, if you go to the Walmart pharmacy or Walgreens or wherever it. Be you'll find that they have options for you.

[00:02:00] If the doctor says, yeah, generic's okay. They'll say, Hey, listen, I'll give you the generic and you can save a whole lot of money. I don't know if you've looked at good RX at all. But good RX. I have saved a ton of money with that. And what they do is help you find free coupons. Compare the prices at, at Walmart Walgreen, CVS Rite aid, you know, at the major pharmacies.

[00:02:24] And we'll tell you where you can go to get your best deal. Plus. They also have some really cool discounts. So it, it acts kind of like a discount card. So I'm on their site right now. Good rx.com. And I look, I'm looking up their number one drug, which is Lipitor, apparently it's used for coronary art or coronary disease and high cholesterol.

[00:02:51] So they're saying, well, wait a minute. Now here. You can get a few different, uh, options. I'm looking now, for instance, CVS pharmacy nor normal retail, by the way is $126 at CVS. You can get it using a good rx.com card. 76% off for $30 instead of $126. Walmart, $15. Uh, Walmart neighborhood market, $15 now, Walmart, that's what they consider to be their retail price.

[00:03:27] Although, as I mentioned, some of these other ones have much, much higher retail prices. So you can see that going. For instance, for Lipitor, you might be. Paying a premium for a brand name. Now there, there's a good reason for that. There's a reason why prescription drugs can be expensive and, and they're called patent drugs.

[00:03:48] And the reason they're call patent drugs is they've put a lot of money in. They've put a lot of research time. They've, they've put up with a whole lot of regulation and going back and forth with various government agencies. And they finally were able to come forward with a drug that works. Put all of that together.

[00:04:09] And you've got a very expensive research and development product, right. Or project, frankly. So I don't, I don't really hold it against them. If we're having some of these drugs being rather expensive. You might remember that, uh, epi epinephrine a few years ago, this guy got a hold of the company that made epinephrine and the, um, You know, the, the whole problem with I'm looking it up right now, like EpiPens, they used to be expensive and then they became crazy expensive.

[00:04:44] So let me see here, EpiPens, EpiPens, and who needs it? There's a whole lot of information. It's not telling how much they are, but he raised the price. Like what was it? 2000% or something insane, again, a prescription drug and one that some people really need in order to save their lives. You know, I'm a beekeeper, right.

[00:05:08] And I used to have a really bad reaction to be stings, wasp stings. Now we just. Reaction, right. We thought at the time I was allergic, but no, it was just a bad reaction, which I still have. Right. It gets stung multiple times a year, but, uh, it still swells up. When, when, uh, our friend mark Cuban started looking at this, he said that this is kind of crazy.

[00:05:31] So what he's done now is mark Cuban has built, uh, I think it's all up and running just outside of Dallas. Let's see here. Yeah. Okay. Just outside of Dallas, a huge, huge building. It's a 22,000 square foot plant. Now most of the pharmaceuticals are actually easy to make and. To make. And that's what kind of gets confusing because you've got all of the R and D and the government regulations, everything else that's expensive, but actually making them is pretty cheap, but he's built this $11 million plant near downtown Dallas.

[00:06:14] And he says right now, looking at what the expenses are that Medicare could have saved as much as are you ready for this? 3.6 billion per year. Now that's where we're talking about everybody. Because if you pay taxes, you are paying for some of this Medicare money, 3.6 billion per year in savings. By buying it from cost plus drugs.

[00:06:46] So there's something else I want you to check out. So the first one was good. rx.com. The second one is cost plus drugs. They have over a hundred generic prescription medications right now. And what they're doing is they're taking the actual cost of production. And I'm sure that includes right. The loan on the building, et cetera, but the cost of production, plus a 15% margin because you need to keep the lights on.

[00:07:13] You need to be able to expand. Profit is not a bad word. That's how people save for retirement by investing in companies, buying stocks, and that profit then becomes their money for retirement. I think that's an important thing. So. 15% margin and an $8 pharmacy dispensing and shipping fee. That is absolutely cheap.

[00:07:41] So this is, uh, Husain Liani who did the research on this? And he published it in the annals of internal medicine. Looking at that just absolutely amazing. And that's something you can do too. One third of Americans, again, we are on prescription drugs and the average person is on four. Wow. So researchers compared the price charge by cost plus drugs for 89, generic medications to the cost for the same drugs paid.

[00:08:17] Medicare in 2020, they found the government program could have saved 37% on 77 generic drugs by buying from Cuban's company cost plus drugs. Once in January drug to consumer bypasses, wholesalers bypasses, pharmacies bypasses, I PA passes insurance. All of those are driving up the cost of medicine. So direct to consumer.

[00:08:43] Uh, how easy could that be? And I'm on their website right now, looking at a couple of things here. Let me see, let me go back there. Cost plus drugs, and I'm believing this go to cost plus drugs.com. Yes you can. I am there as we are talking. So he's got, oh, here's one tib. Uh, which is the generic for gleek I'm.

[00:09:08] Now I'm not familiar with that myself retail price, $2,502. cost. Plus, are you ready? $14. Can you believe that that is crazy. Yeah. Wow. And it'll look, it'll look different obviously, cuz it's a generic. So you saved $2,488 for a 30 count supply. That is just amazing. So when I, I, I was talking about the savings here, where.

[00:09:41] Okay. They could have saved 37% on 77 generic drugs. But when you start getting into these really expensive drugs, that's where the 3.6 billion really, really starts to add up in savings. This is something so what you can do once you're on cost plus drugs.com, you can contact your doctor for a prescription.

[00:10:04] They've gotta get started button. They have the strength that you want in this case, a hundred milligrams or 400, the quantity you want. And then all that has to happen is your doctor has to approve it. You pay $14 instead of $2,500 and it gets shipped straight to you. Wow. Now, is that cheaper than Medicare part B right?

[00:10:28] Or your regular insurance? Wow, sure. Is just absolutely amazing. So you can find all of this stuff. This is mark Cuban doing this, and I gotta say, I am impressed. He is going to help a whole lot of people. Yeah, I'm, I'm just looking at this. Wow. Here's another one retail price. $9,600. And at cost plus drugs, you can get it for 39.

[00:10:57] So there you go. Two options, mark Cuban's new venture, which is online now at costplusdrugs.com and goodrx.com. Wow. It's just amazing, right? This world. What's it coming to? Great little great little drug company. So we're gonna talk if you are a user of outlook, this is important to you because a major attack is underway.

[00:11:26] Major scam underway. If you are an outlook customer, you are in the crosshairs of a very successful credential stealing campaign. So I'm gonna tell you about that, what it means, what you can do and, uh, how you can stay safe.

[00:11:43] This is a very big problem for people who are using Microsoft 365, that is really common, used to be called office 365 and you pay a, a flat monthly fee, 20, 25 bucks.

[00:11:59] It kind of depends on what level you get. They have some real cheap ones as well, and it lets you use all of what Microsoft used to call Microsoft office applications. And one of those applications is outlook. And I've never particularly liked. they have gotten better in recent years. And I actually do use it right now, as well as MacMail I use both of them, but there is a hack going on against Microsoft 365 and outlook customers in the us.

[00:12:34] Here's what's happening. They are sending you an email and the email really does look like it's ti voicemail that somebody left. This is called a voicemail fishing attack and it follows, what's kind of a classic fishing flow. If you will, the ways they've been doing fishing here over the years, and what fishing is, is basically.

[00:13:02] Getting you to bite at something that you shouldn't bite on. You, you will respond to an email. You'll click on a link. You might call a phone number. You might click on a text message. That's another one that's going around right now. How do you tell a fake text message from a real text message? And I'm afraid to say nowadays you tell by just not clicking on the links that are in text messages.

[00:13:30] It's, it's so disappointing. I was talking on the radio this week. It, it, it, because it just, it bothers me so much about this very thing. I've been on the internet for decades now. Right? I, I started back in 81. I think it was maybe 80. Two and we had email and it was the best thing ever. If you had somebody's email address, you could send them a note and you'd be pretty darn sure they'd get it.

[00:13:58] In fact, they probably would get it within just a few minutes and respond to you. And there, there wasn't any spam. Back then the idea was, Hey, listen, the internet is for research government research, university research, and that's the way it should stay. And indeed, we were kind of keeping it that way for, for quite a while.

[00:14:21] And then some people who were marketers got on the internet. And they would start to advertise, Hey, we have a special session for you at, uh, UC Berkeley this week only $500. And of course that went be beyond what the internet was for. In fact, at the time you could not use it legally. For any sort of financial purposes.

[00:14:47] So what we would do back then is we would send the script to the Monty Python routine of spam. Remember that spam, spam, and egg spam, and hands spam, spam. Uh, yeah, we would send them the whole. And they, sometimes, if somebody sent out a little thing that was trying to sell something that they should not be selling online because it was illegal to use the internet for business in case you didn't know until about 1991.

[00:15:20] And that's when I started. Putting businesses online and really started focusing in on cyber security because almost immediately the bad guys started getting on there. So this is, uh, this is really what happened. This was the script, right? Uh, well, what have you got waitress? Well, there's egg and bacon, egg, sausage, and bacon, egg, and spam, egg, bacon, and spam, egg, bacon, spam, sausage, and spam spam, bacon sausages, and spam spam eggs, spam spam, bacon spam.

[00:15:51] Do you remember that? So. We would send this to people who kind of broke the rules written or unwritten on the internet. And sometimes somebody would get just a hundred of these things, maybe even more. And what would happen back then of course, is it would fill up your mailbox and it would slow down your check connection.

[00:16:10] Cuz a lot of us were just connected to the internet via dial up modems. So it, it really kind of hurt you to get all kinds of spam. Emails coming in. That's where the term comes from. I remember it well, so I don't care what they say on some of these websites or they're trying to do little research on it and figure it out.

[00:16:31] Well, now things have gotten a lot worse because it isn't just marketers that are trying to solve something. And I don't have a problem with marketers, I guess, in a way I am one myself. Right. I, I have a business and I provide cybersecurity services. For a high net worth individuals and for businesses.

[00:16:50] And if you are a regular person, you have a question. Please ask, just send an email to me, me Craig peterson.com, no matter who you are. And I will try and answer the question for you. And I have a lot of stuff that I've written over the years. That'd be more than glad to forward to you. There are some training courses that I.

[00:17:10] Put together that I will be more than glad to share with you. And you probably know I did all of the training for the FBI's Ingar program for a couple of years. I, I ran that online, all of their webinars. So I've been doing this for a long time and I'm more than glad to help. That's why I am here. Right.

[00:17:31] But now we got bad guys. and the bad guys are trying to get you to do something against your best interest. So in this case, what happens is you get a missed voicemail notification via email, and a lot of times it'll look pretty legitimate. It might even be coming from someone inside your company, whose account they have hacked.

[00:17:57] Now on that email, there is an HTML attachment. Now HTML attachments can get past a lot of email gateway filters because they aren't in and of themselves malicious. So they're not raising big red flags for users in a, in a voicemail notification setting because that's how office Microsoft office sends you legitimate notifications.

[00:18:24] Anyways. Now, these from fields are set up specifically using the organization's name. As I said, sometimes even a valid email address. Now, if you go ahead and click on that attachment, it will run a program on your computer using a language called JavaScript and that's embedded in every browser out there nowadays.

[00:18:47] And that JavaScript code is going to redirect you to an attack. Controlled website. Now this website set up to get you to give up your credentials. So, what they'll do now is as you go to the website and the website might look like it's Microsoft office and it might look like it's your business website, and it'll ask you to log in.

[00:19:15] It might ask you for other information as well. It is trying to get your username and password that it can then use to go after other people. You see what's happening here. So each of the URLs, these guys are creating these websites that they're sending you to are created to match the targeted company.

[00:19:39] It's it's incredible how good they're getting, and they even have one of those Google recapture. Pop ups. Now this is a, an increasingly popular technique to evade these auto mail, automated URL analysis tools. So for instance, with my client, an email comes in, it goes through Cisco's. Email filter. We have an advanced email filter from Cisco, but we run our client's emails through.

[00:20:10] And what happens is they look at the URLs, they visit the website that the URL PO points to, they try and verify if it's legit or not. And you you've had captures, you know, it's, um, click every box that has a bicycle in it, sort of a thing. It's kind of a touring test, test puzzle. So once this is solved, We'll tell you what happens next, cuz we're out of time right now.

[00:20:36] Uh, make sure you visit me online. Craig Peter son.com. I'll keep you up to date. You can get my free newsletter and trainings. Craig Peter son.com. And I want to talk too about businesses in the, the big business of email compromise.

[00:20:55] Yeah, I think most of us know what a big business is. Well, how about a business, an industry that has racked in 43 billion, according to the FBI. That's what we're talking about right now and what you can do about it.

[00:21:11] We were talking about, what's been happening with Microsoft outlook users right now, a major campaign underway that has been extremely successful because these bad guys are using some rather advanced technologies. Absolutely crazy. So they get you to click. HTML link that is there while filed that is there as part of what looks to be a voicemail notification for you.

[00:21:43] And then it takes you to a website that's specially crafted for you and your company. So you work@bigco.com and you click on that HTML and it'll take you to big co.com. Well, at least that's what it looks like, but it distracts you now because it wants to give you this capture as well. So this Google captures, you know, these things, these little mini touring tests, click on all of the trees in the picture, sort of a thing, right?

[00:22:18] And you've got the nine things well with, uh, or maybe it's some blurred or distorted text and you have to type that in. And the whole idea behind that is normally to weed out these bots on eCommerce sites, online account sites. But what they're doing here is. They're making sure that the email, the, the software that checks the emails to make sure they are legitimate, that is going out to the big co dot or big co fake.com website.

[00:22:54] They wanna make sure that that email checker does not find out that it's not the real site that you wanted to go. So the computer that's doing the checking will go to the site and it'll say, oh, there's a capture on there. And then it'll stop because it can't solve the capture. It needs you, it needs a human, right.

[00:23:15] So this is kind of cool here. Uh, Eric. K. He's a security awareness advocate with no before. No. Before is a company that does training for people, for employees here about some of these, uh, these hacks and things are going on. When faced with a login prompt, it looks like a typical. Office 365 login. The person is likely to feel comfortable entering their information without looking at the browser's URL bar to ensure they are at the real login site, this familiarity and the high odds in an attended victim regularly uses office 365 for something in the Workday makes this a great Lu.

[00:24:02] For attackers, this is from an article over on dark reading.com. This isn't, uh, a new technique, but let me tell you, it is B a very successful one. They have seen a resurgent, uh, resurgence of this starting a couple of years ago, back in July, 2020. And it is really targeting human nature. And of course, Microsoft 365 is quite the target.

[00:24:29] So I mentioned. $43 billion industry. I'm looking right now at a public service announcement from the F FBI and they are calling business email compromise the $43 billion. Scam. This is crazy. A sophisticated scam. It targets businesses and individuals who are performing legitimate transfer funds requests.

[00:25:00] It's carried out by people who are compromising legitimate businesses and individuals. Now, what they're trying to do with this business email compromise is get someone who has. Control of funds to do a transfer. What happens is they will do a little research on the business that might go to the website and see on the website.

[00:25:25] Oh, let me see here. Okay. The president's name is Craig Peterson. Uh, the CFO is Mary Jane and, uh, the accounting department head is manly. And, uh, so now they got that information. So they'll go online. And to look at LinkedIn, find out who all else is at the business. Maybe things have changed, you know, maybe try and find an email address by doing an open source search for the email address of people there at the business.

[00:25:57] You see where this is going here? Yeah, it, it gets pretty bad. So, uh, let's say they befriend the CEO on Facebook or on LinkedIn, but Facebook more likely, uh, and now. They're they can see on Facebook or maybe they don't even have to because your Facebook profile and posts are not hidden from the public.

[00:26:20] So they just go there and, oh, let me see. Okay, great. He's gonna be out of town next week. And then what they'll do is they'll get into somebody's email account at the business. And once they're into somebody's email account, they can start looking through the emails and sending emails that look perfectly legitimate to other people within the organization.

[00:26:43] Now, I, I did a whole story on television about this one on news program, and one of the people on staff, one of the talking. received an email like this, and it asked him to, uh, to buy some gift cards. This is very, very common scam right now, the gift card scam, and they try and get you to go ahead and. Buy gift cards for other people in the office are gonna have a little party and we don't want anybody else to know about it.

[00:27:15] It's supposed to be a surprise. And I had some real fun with him. One of these days, I should probably share all of this in one of my newsletters. I think you guys would really appreciate it, enjoy it a little bit, but, uh, we really led them on and sure enough, you know, it was a total scam and we kept playing with them and it, it was something, any.

[00:27:38] That was one thing. This is another because they will eventually get to the CFO, somebody who has the authority to transfer funds and get them to transfer funds to. Them. And then they use mules to move the money around these, uh, useful idiots who will sign up. And yeah. Yeah. It's kinda like the Nigerian scam.

[00:28:05] All I need is access to your bank account and I'm gonna wire in, uh, $10,000. And I, and what I need you to do is transfer 8,000 of it over here to this PayPal account because my grandmother's dying and she needs the money. There's similar scams that are going after lonely people and getting them to send money because somebody needs an operation, et cetera.

[00:28:33] So in this case with the business email compromise and the 43. Billion dollars that have been stolen from businesses. They'll usually get to the CFO and send a story like, Hey, uh, we have this new vendor and we've had 'em for three months and we haven't been paying them and we gotta make sure we pay them.

[00:28:54] And, uh, we need to wire 43 million to this account that actually happened. And they did wire the money. It happened to Barbara cran, another person who wa is on shark tank. Uh, it, it happens to a lot of companies out there. And I've got a couple in the last month that we've worked with the FBI on the, these companies hear me on the radio.

[00:29:21] They sent an email to me@craigpeterson.com and they had had their operating account. Emptied. Uh, the latest one is a, a lady 77 years old who had her retirement money stolen from her over $70,000. This stuff's real people. We've got to pay attention. We can't let this continue to happen. Make sure you sign up online.

[00:29:48] Craig peterson.com so that you can get my insider show notes and we can keep you ahead of the bad guys. When we come back, we're gonna talk about this row overturned and what senators are asking the FTC.

[00:30:05] We've got some senators who are saying they were spurred on by the row overturned. And they're asking the FTC to probe, apple and Android, and what's happening with tracking. Now I have a suspicion. That's not really right.

[00:30:21] We've got, of course the recent overturn of Roe. You, you of course heard about that. it was pretty much impossible to miss if you pay any attention to the news.

[00:30:36] Well, we've got three Democrat, us senators and a Democrat us representative that asked. The federal trade commission to investigate apple and Google for engaging in unfair and deceptive practices by enabling the collection and sale of hundreds of millions of mobile phones, users, data, the FTC should investigate apple and Google's role in transforming online advertising into an intense system of surveillance that incentivizes and facilitates the UN.

[00:31:11] Train collection and constant sale of Americans' personal data. These companies have failed to inform consumers of the privacy and security dangers involved in using those products. It is beyond time to bring an end to the privacy harms, forced on consumers. Buy these companies. Now I have been talking about this on the

[00:31:38] radio for 20 years. Because do you remember when Congress forced telephone manufacturers and cell phone companies to put GPS coordinates into the receivers, into the phones? Do you remember that you could no longer use your analog phone? You had to use digital phones under federal law. right. It, it's just amazing.

[00:32:09] We can go into all of the reasons that they've given for that in the past, but anyhow, that's what they did. So immediately decades ago, now, many years ago, they started collecting data. Now it's okay for the government to collect it, even though it's illegal. For them to collect this data. So what's happening here?

[00:32:30] Why have the Democrats for so long? Well, and frankly, a lot of Republicans been big on collecting data on all of us. Now, I I've gotta say when I've looked at the stats, the biggest. Purveyors of the surveillance society have been president Obama followed by president Biden. Now you could argue that president Bush was won too, because of course they passed an act that allowed for all kinds of changes in surveillance.

[00:33:02] So, okay. So we'll put him in there too. So we got a Republican in there. Obama put that program that president Bush had put in place on steroids and then president Biden did the same thing. President Trump tried to cut it back because he was a victim of some of the surveillance that they were doing. So what's going on here?

[00:33:25] Well, these Democrat senators are saying, uh, we don't want people who are trying to get abortions to be. okay. I can see that. Uh, I can also see that I don't want to be tracked and you don't want to be tracked. And it's one thing to have an advertiser know a little bit about us, you know, Hey, we just visited the Ford dealer and the Chevy dealer and the Honda dealer.

[00:33:52] So maybe he's looking for a car let's let's try and advertise a car. Right. So Honda and Chevy and Ford all start putting ads up for you. Okay. So that's. Thing if I'm in, if I'm interested in buying a truck. Okay, great. Show me ads on a truck, but we've seen already misuses of this data over the years, one of the earliest ones I talked about here on the radio was this guy who went to an emergency room and all of a sudden started seeing ads for what you might call ambulance, chasing lawyers saying, have you been injured?

[00:34:30] right. You've seen those types of ads before, but once he was in the emergency room and he was geolo geolocated in the emergency room, they started selling advertising to lawyers. I, I, I'm not real fond of that one either, but I think there's an ulterior motive here behind what these Democrats are saying.

[00:34:52] If you have seen the movie 2000 mules, you understand what I'm talking about here? what ended up happening here is they looked at trillions of data points. You see, they went out and bought databases of smartphone data where these smartphones were located. And then they started doing some serious analysis on it and they were able to say, okay, this smartphone went to.

[00:35:28] Different Dropboxes for the election for ballots. And in between each visit to the Dropbox, they went to a left wing organization where they did something. Right. So they, they go to a Dropbox drop off ballots and they're on video doing this, dropping off ballots. And then they go to a left wing organization and then they go drop off more ballots at a different Dropbox, and then they go back again and then it's on video.

[00:36:02] And some of these people are taking pictures of them, stuffing the ballots into the box, supposedly, so they can get paid. So now there are some criminal investigations that have been started. I don't know how far they've gotten yet over some of this information that was gathered. And that was documented in the film by Danes.

[00:36:24] Dusuza called 2000 mul. And if you haven't seen it, no matter what side of the aisle you want, you need to see it. Absolutely need to see. And whether you believe or not, when president Biden said that we have the best, uh, what was it? Um, election stealing organization that's ever been made? I can't remember his exact words right now.

[00:36:49] Uh, he was serious about it, right? So now all of a sudden, the Democrats are concerned that people who visit abortion clinics might be tracked, cuz they could be. Right. You could buy data geotagged with an abortion clinic's location, GPS coordinates. You absolutely could do that, but that's been true for a long time.

[00:37:15] Why now? Well, maybe because of Roe V Wade, but I look, of course it wasn't just that one decision that was overturned, but I, I look at some of this and really, really do wonder because it really looks like some number of people were caught illegally stuffing ballot box. So it's, it's fascinating to me that all of a sudden now out, they come with this.

[00:37:45] Now apple has stopped enabling the tracker identifiers. By default, if you have an apple smartphone, it is much more. Private than the Android phones are by far, right? Google makes its money by selling your information. That's how they make most of their money. Apple makes its money by selling you services and selling you hardware.

[00:38:13] so that should tell you something right there. And the fact that Senator Elizabeth Warren is one of the ones who is proposing this legislation makes you think even more about this. Now, Google, uh, this is an article from ours. Technical apparently responded to this whole concept in an article that ours was writing, saying that it's had all kinds of efforts to block apps and violate Google play policies.

[00:38:41] And. the bands it's imposed on companies that are apparently sold user data, and they say Google never sells user data in the play at Google, strictly prohibits a sale of user data by developers and, uh, goes into the advertising ID. So it it's fascinating to me that all of a sudden, now the Democrats are interested in stopping the data collection.

[00:39:08] It really is. I don't like it. As I said, I've talked about this for more than 20 years now on the radio. It, I think it's a real problem. This data collection, because also the federal government, even though it's illegal for them to collect information on American citizens, they do it every. And some of the largest, like the, um, immigration people, Homeland security are the biggest collector.

[00:39:37] They have more information about you than anyone else. Even if you're here legally, you were born in the United States, et cetera, etcetera, because they are buying all of this information from what are called data broker. So, yeah, they say, yeah, we're, we're not collecting it. You we're forbidden by law to collect it, which is absolutely true.

[00:39:59] But what they are doing is buying it from private businesses. So I think we've got to completely. Reconsider how this all works. Apple has been working on it. You can go into your apple phone and make a change, share identifier if you want to, which makes it harder to track apple also. And Google has this, as I believe is an option.

[00:40:25] But apple also will give you a different Mac address every time you're connecting to wifi networks so that you can't be tracked that way. Because just, if, if you connect to the network at target the wifi at target, for instance, they will know when you return because your phone has the same Mac address that's used for the wifi.

[00:40:49] So they know. They know where you go in the store. They know what you're looking at in the store, in some cases, depending on how the tracking works. So it's fascinating to me, this is a, a real privacy issue that could easily turn into something much worse because this data, this same data that's available to marketers is available to government is also available to bad guys.

[00:41:17] and you talk about the ability to potentially frame someone and it, it, it just gets extremely, extremely scary. Right now, last month, more than 40 members of Congress called on Google to stop collecting and retaining customer location data, the prosecutors could use to identify women who obtain abortions.

[00:41:37] Again, tied into this, uh, abortion anytime any day. Uh, and as the governor of Virginia said, even after the baby is born and delivered it, you should be able to abort it. Uh, so wherever you fall in that spectrum, obviously the Democrats in the us want abortions far more than the Europeans that every European country I can think of has much tougher restrictions on abortion than we have here.

[00:42:05] But. Privacy is not an abortion issue. Hey, join me online. Craig peterson.com. Make sure you are on my email list. And, uh, you can ask any question you want. Just email me,

[00:42:20] me@CraigPeterson.com.

[00:42:26] I really appreciate all the emails I get from you guys. And it is driving me to do something I've never done before now. I've always provided all kinds of free information to share on my email list. Great stuff. But now we're talking about cyber punch lists.

[00:42:43] So they know what's hot because who really, really tracks technology, not too many people. And I get, uh, you know, a little off put by some of these other radio hosts that call themselves tech people, and they're actually marketing people, but you. That's me. Right. And that's why, if you are on my list, you've probably noticed I'm not hammering you trying to sell you stuff all of the time.

[00:43:09] It's good, valuable content. And I'm starting something brand new. Never done this before, but this is for you guys. Okay. You know that I do cybersecurity. As a business and I've been doing it now for more than three decades. I don't know if I should admit that. Right. They say, never say more than 17 years.

[00:43:30] Okay. So I've been doing it for more than 17 years and I've been on the internet now for. Oh, 40 years now. Okay. Back before it was even called the internet, I helped to develop the silly thing. So over the years, we've come up with a number of different strategies. We have these things that are called plan of action and milestones, and we have all kinds of other lists of things that we do and that need to be done.

[00:44:01] So what we're doing right now is we're setting it. So that you can just email me, me, Craig peterson.com. And I will go ahead and send you one of these punch lists. Now the punch lists are around one specific topic. You know, we got these massive. Punch list with hundreds and hundreds of things on them. And those are what we use when we go in to help clean up the cybersecurity in a company.

[00:44:28] So we'll go in, we'll do scans. We will do red team blue team where we're attacking. We do all, all kinds of different types of scans using different software, trying to break in. We use the same tools that the hackers use in order to see if we can. Into your systems and if the systems are properly secured, so we do all of this stuff, so, and, and then it goes into all of the paperwork that needs to be done to comply with whatever it might be.

[00:45:00] Right. It might be, they accept payment cards. It might be that they have hip. Information, which is healthcare information. And it might be also that they're a government contractor. So there are hundreds and hundreds of things that they have to comply with. Most of them are procedural. So we have all of this stuff.

[00:45:18] We do all of this stuff. And I was talking with my wife here this last week about it and said, you. So much of this could be used by small companies that can't afford to hire my team to come in and clean things up. Right. And I don't want them to suffer. So here's what we're doing. We're starting this next week.

[00:45:42] We have a punch list for you on email. So what are the things you can do should do for email? Just very, very narrow on email so that you can recognize a fishing. Email, what you might wanna do to lock down your outlook, if you're on windows or your Mac mail. So we're taking these massive spreadsheets that we have and we're breaking them up.

[00:46:10] So the first one that's available to you guys, absolutely. A hundred percent free. Is the one on email. So just send me an email. Me M E Craig peterson.com. Now, remember I am, my, my business is a business to business business, right. But almost everything in these various. Punch lists applies to individuals as well.

[00:46:34] So I got an email this last week from a guy saying, Hey, I'm 80 years old and, uh, retired and I don't know much about computers and that's kind of what got us thinking about this. You know, we need to be able to help him. We need to be able to help you out. Okay. And if you're a small business and we've dealt with a lot of them over the years, and as a small business, you just don't have the funds to bring in an expert, whether it's me or somebody else, although yeah.

[00:47:03] What you want the best. But anyways, , it, it, uh, it is gonna allow you to do it yourself. Okay. So absolutely free. All of these punch lists on all of these topics, we're probably gonna end up with more than a hundred of these punch lists. And all you do is email me, me, Craig peterson.com. Just let me know in there what you're interested in.

[00:47:29] So even if we haven't got that punch list broken down for you yet, we will go ahead and put that on the. To do right. We need the priorities. What kind of a priority should we have as we're putting these things together for free for people. Right. Uh, and the only way we know is if you ask, so the first one's on email, you can certainly ask for email.

[00:47:50] We've got, as I said, more than a hundred others, that we think we're gonna be able to pull out of the exact. Plan of action worksheets that we use so that you can go through this yourself, whether you're a home user or you are a small business or even a big business, right? We we're talking with, uh, a gentleman who's probably listening right now, who has a business.

[00:48:17] They have three offices, they have some requirement because of the military contracts for high level. Cyber security and it would work for him too. All right. So they, this is all of the punch list stuff. You probably know what a punch list is, right? It's using the construction industry a lot, but in our case, it's you need to do this.

[00:48:39] You need to do this, you need to do this. Okay. So that's what that's all about. So enough rambling on that. It's gonna take us some time to get 'em all together. I'm also. We're gonna do more video stuff again, training. So just like on the radio show where we're talking about what's in the news, we're gonna talk about what's what's in the news.

[00:49:01] When it comes to small businesses, what you should be paying attention to with of course, an emphasis on cybersecurity and we're. Putting those up on my website@craigpeterson.com. In fact, we've already got some up there already, and then we are going to also be putting them on YouTube and rumble. So if you don't like YouTube and Google, then you can certainly go to rumble.

[00:49:25] You'll see them there. But if you're on the email list, I'm I'm. Starting to put links in the bottom of the emails. So you can go and watch those videos. If you are a video type person that you know, more visual. So it's, I think all good. And it's good news for everybody. And this is what happens, I think, as you get more mature, In the business.

[00:49:48] Right. Um, as I said, I've been on the internet for more than 40 years, helped develop some of that software that, uh, some of it's still in use today and now it's time to do more give back. And I really am trying to give back, okay, there's this isn't. This isn't a joke. So, uh, no joke. Right. So go ahead. Email me at Craig Peterson.

[00:50:12] Tell me which punch list that you would like. And I can also put you on my email list so that you get my insider show notes, and you can just do that yourself by gonna Craig Peterson dot. Com you'll see right up at the top of the page. If you scroll down a little bit, it'll kind of pop up. It's a big red bar that goes across the top.

[00:50:32] I try not to be too intrusive and you can sign up there for the newsletter. So you'll get some of these trainings automatically. You'll get my insider show notes, all of this stuff. It it's absolutely free. Okay. This is my giveback to help you out. It really is. Okay. I, as I mentioned at the very beginning, I, I.

[00:50:52] Peeve by some of these people that represent themselves as tech experts. And in fact, all they are are marketers. We've got a client that decided that, uh, I was too expensive. My team. So they went out and shopped around, tried to find the cheapest company they could. And so now the, the company that they're bringing in is saying, you're saying, uh, Hey, um, uh, so how does this work?

[00:51:15] How do you do zero trust? Uh, why do you have a firewall here? Uh, why do you bother to have a direct fiber link between the offices? All this stuff? Well, because they need it. Okay. I get it. You use. Barracuda spam firewalls and Barracuda firewalls. It, it, yeah, this is a different league. Okay. So you are gonna be getting these punch lists from me that are really gonna help you understand and secure your systems.

[00:51:47] Right? This isn't your average run of the mill so-called managed security services provider or managed services or break fix shop. You are getting it from the guy that the FBI. Ingar program went to, to do their trainings. That was me. Okay. So for two years I set up the program. I ran it. And if we ever are sitting down having a coffee or beer, sometimes I'll tell you why I left.

[00:52:13] Okay. Uh, but think about FBI and I, I think you might have a clue as to why I decided not to do that anymore, but I trained thousands of businesses, government agencies, state local. Federal, you name it. So you are getting what you really need, which is another problem. I keep hearing from people, you do a search for something on YouTube or Google and you get what a million, 5 million pages, right.

[00:52:43] As supposedly that it says are available and they give you, okay, here's the top one, but what you need is an integrated single way. To do things where everything works together. And that's what I'm trying to do for you guys, because there's so many little products, different products that just don't work so well together.

[00:53:06] So we'll, we'll be covering that as well in these, but you gotta be on that email list. Craig peterson.com. Craig Peterson. So n.com/subscribe will take you right to the subscription page. And I'll keep you up to date. This is not my paid newsletter. All right, stick around. We'll be right back. And I promise I'll get to Russia, Russia, Russia.

[00:53:33] Some of the high tech companies and others pulled out of Russia after the Ukraine invasion, but one stayed Google. What is going on with Google? And now they're in big trouble with the Russian government. Wow.

[00:53:50] Here's a list of companies according to CNET that have pulled out of Russia because you remember Russia invaded Ukraine, February 24, we had Adobe, these are the guys that make Photoshop, Adobe reader. Airbnb, Airbnb has kind of an interesting story too in Ukraine because a number quite a number of Airbnb customers went ahead and rented rooms and homes from Ukrainians, even though they had no intention of going and they told the Ukrainians, Hey.

[00:54:23] I'm not gonna show up, just take this money. I'm sure you need it. Can you, can you imagine that that's fantastic. Good for them, Amazon, they suspended shipments of all retail products of customers in Russia and Bella Russ, and also suspended prime video for users in Russia. Apple stops selling its product in Russia's it's halting online transactions, including limiting apple pay.

[00:54:50] It's also disabled. Some apple map features in Ukraine in order to protect civilians, Amazon web services. They don't have data centers or offices in Russia, but it's allowing new signups for the service in Russia. BMW four GM Honda. Have all scaled back their operations or stopped them. Ford suspended its operations in Russia effective immediately until further notice.

[00:55:19] GM is suspending business in Russia. Honda has suspended exports to Russia, Disney halted, all theatrical releases in Russia, including the new Pixar film, turning red, also pause content DJA. The drone company that's gotten in trouble here in the us for some of its practices of sending GPS information to China while they're not doing it over there.

[00:55:45] Uh, electronic arts. They make a bunch of very popular, uh, games, epic games, another one Ericson FIFA body band Russia from this year's world cup formula one canceled its plan planned Russian ground pre Fujitsu, Goldman Sachs. Now Google that's where I want to go. We'll stop at Google here for a minute.

[00:56:10] Google. Suspended their ad network in Russia. And the idea was okay. Uh, we're not sure how payments are gonna work because Russia of course has had this kind of this lockdown by foreign countries on their banking system. We're not sure we can get the money out. Right. Um, uh, that's what they're apparently doing now.

[00:56:36] They're still there. Google's YouTube. It's search engine on and on still running in Russia. Now that is really disturbing. If you ask me, why did they not pull out? It doesn't make sense. So Google did stop accepting new customers for Google cloud. In March. YouTube said it's removing videos at denier trivial trivialize, the Russian invasion, but what finally got Google.

[00:57:09] Out of Russia, Russia seized their bank accounts. They froze, they transferred their money out of the main bank account in Russia. We're talking about a 2 billion per year business, Google Russia, that that really upsets me. So I did a little more research online about all of this, and I was really surprised to see that Ukraine now has given the Ukraine peace prize to Google.

[00:57:40] and it says, uh, quote on the behalf of the Ukrainian people with gratitude for the support during this pivotal moment in our nation's history. So what is it? I, I, I'm not sure. Right? So there, uh, one of their foreign ministers, I guess, and, uh, Koran. Baha I think, uh, said thank you from the beginning of the war, Google has sought to help.

[00:58:05] However, however we can through humanitarian support of our tools will continue to do as long as needed. So I dug in a little more and tried to figure out what's up. Well rush or Google left its Russian search engine online and YouTube online and was using it in Russia in order to. Control the narrative in Russia.

[00:58:31] Now, unlike what they've done here in the us, where Google has been caught, many times controlling the narrative in various elections and taking certain ads and not taking others and taking certain business and not taking others, apparently in Russia, it has been. Blocking a lot of the stuff that Russia itself has been putting out.

[00:58:55] So the, the federal government there in Russia. Interesting. Hey, so they also have helped Ukraine out by providing them with mapping GPS and rumor has it satellite services. Yeah. Interestingly to track Russian troop movements, uh, Al also Ukraine saying the Google news component has also been tremendously valuable.

[00:59:24] Google's also helping to raise money for the cause of Ukraine. Like many companies are doing right now to help people displace due to the war and Poland. Wow. They've been doing Yemen's work and, and bringing. People in, by the millions, into Poland from Ukraine. It reminds me when I lived in Calgary, Alberta, my Cub, one of the Cub masters Cub troop leaders was a woman who came from Poland many years ago.

[00:59:52] This was back during Soviet occupation of. Poland. And I, I remember talking to her about what was happening over there. Why did she leave? And it is just so, so impressive. The polls have done so much impressive stuff over the years. So they're also saying that Google's done a lot of other things in order to.

[01:00:13] Help protect Ukraine, including Google's block domains. They've prevented fishing attacks against Ukraine. They've warn targeted individuals that they are being targeted. It's really something what they've done. So my first knee jerk was why is Google? Still doing business in Russia. Well, now it's become clear because they have a special page for Russians that gives correct information, at least, you know, Google's claiming it's correct.

[01:00:47] Uh, I don't know which fact checkers, checkers they're using, but. That gives Russians real information about the war what's going on in Ukraine. What's happening with the Russian soldiers. Did, did you see this just this last week, apparently Russia removed the age limit for volunteers for the military. It used to be, I think it was 40 years old.

[01:01:12] If you were a Russian citizen and 30 years old, if you were foreign national, now the Russian military will take anybody. Any age from anywhere. In other words, Russia is really getting kind of hard up if they want people like me, right. To fight, to fight their wars. I'm sure they don't really well. I don't know.

[01:01:32] Maybe they do want me, right. That every, every war needs cannon fodder. So it is fascinating to see good job Google. I am quite impressed. I did not expect them to be doing that. They've also. Uh, uh, provided over 45 million in donations and grants to various groups. They've done pro bono work for various organizations over there.

[01:02:01] So this is really, really cool. So that's it. That's what's happening over there in you? Crane and Google, you can of course, find out a lot more. Get my insider show notes. So you had all of this on Tuesday morning. You could have digested it all and be ahead of everybody else out there. And then also don't forget about my new offer here.

[01:02:27] Free, absolutely free for. Asks by emailing me Craig peterson.com. I'll go ahead and send them to you, which is I think a pretty cool thing now. What am I gonna send you? Well, you gotta ask first, right? You gotta ask. And what we're gonna be doing is taking what I have been using for years to help secure my customers.

[01:02:54] And we're making available for free my cyber punch lists. Craig peterson.com/subscribe.

[01:03:02] Bit of a hubub here, a B Biden's infrastructure bill $1.2 trillion. And, and it's in there is this thing that Bob BARR is calling an automobile kill switch. Well, I did some more research and we'll tell you the facts right now.

[01:03:19] What are you supposed to do? If you are trying to pass a bill to stop drunk driving deaths, and you've got all of the money in the world, you know, well, I guess 1.2 trillion, isn't all of the money in the world.

[01:03:33] What are you gonna put in there? Well, I did a search on this and I I'm chuckling because this is craziness. This is the AP associated press. And they've got this article claim. President Joe Biden signed a bill that will give law enforcement access to a kill switch that will be attached to all new cars in 2026 APS assessment false.

[01:03:59] Okay, so we've got fact checkers here while the bipartisan infrastructure bill Biden signed last year requires advanced drunk and impaired driving technology to become standard equipment in cars. Experts say. Technology doesn't amount to a kill switch. Hmm. Let me see. So I can't start the car. If the car's computer thinks I might be drunk or impaired in some other way, but that's not a kill switch.

[01:04:31] What, what is that? Then if I can't start the car, because I have a disagreement with the computer. How about these people that I don't know, maybe their eyes can't open all of the way. Maybe they have problems with eyes on nystagmus, the eyes kind of jittering back and forth. Right. And now what are they gonna do?

[01:04:50] Argue with the computer? That's a kill switch. I can't believe these crazy people that are like AP here, coming up with fact checking on things. So, yeah, I'm sure there's some distortions in some articles out there, but they contradicted themselves in two paragraphs. I guess they figure people are just gonna see false.

[01:05:14] Okay. I'm done. They're not gonna bother reading the rest of the article. Yeah. Kind of crazy, isn't it? So according to an article written by remember former us representative Bob BARR in the infrastructure bill, is this kill switch. Now the, the big question is what is the kill switch? How far does it go?

[01:05:39] So I decided, well, let's look up something I remember from years ago and that is GM GM has the OnStar system it's yet another reason I won't buy GM, there are a number of reasons, but this is another one. OnStar system, you know, they've got an advisor, isn't that great. And if your car is in a car accident, a crash that advisor can hop on and ask if you're okay.

[01:06:08] And if you want emergency services coming, they'll come, uh, OnStar will call them for you. And if you are just fine, they won't bother calling. I mean, if there's no answer at all, they'll they'll call emergency services and let them know where the vehicle is. Cuz the vehicle has with OnStar built in GPS.

[01:06:30] Well, one of the features of OnStar is that it can send a signal to disable cars, engines, and gradually slow the vehicle to an idle speed to assist police in recovering the vehicle. Now they will only do that at least right now for vehicles that have been reported stolen and have been confirmed by the police.

[01:06:58] So in, in reality, that's kind of cool, right? It slows down. Hopefully the bad guy, if he's on the highway, makes it over to the side of the road and while the car slows down and eventually stops. So, uh, all of this stuff sounds good. This kill switch. Sounds good. Doesn't it? Because you know, we're gonna keep drunk drivers off the road.

[01:07:24] Now in reality, of course, they're not gonna be able to keep drunk drivers or other impaired drivers off the road. I really don't care what kind of technology they put in. And they're not talking about putting in one of these blow in the tube, things that checks your blood alcohol level. They're talking about having a camera facing you as the driver and probably other occupants of the vehicles and that internally facing camera.

[01:07:53] It's going to evaluate you. It's gonna look at you. It's gonna look at your face. Is something droopy. Are, are you kind of slow to respond? It might have a little test that it has you take right there. The, the law is very loosey goosey on any details. There really aren't any, so it's gonna be up to the manufacturer.

[01:08:15] So they put this in the car step. Just like OnStar, step one, put it in the car and they'll tell you when to turn. Remember how cool that was the GPS with OnStar. And you'd say, yeah, I want to go to this address. And then the, uh, the assistant goes ahead and sense programming to your car. And now you can go and if you lock your keys in the car, they can unlock the car for you.

[01:08:41] All, all kinds of cool stuff. And then next up what happens. Well, but they can stop the vehicle. So there's another technology story related to OnStar. And this is from 2009 from Kelly blue book book, OnStar stolen vehicle, slow down forts its first carjacking. So again, doesn't that sound fantastic. This was a Tahoe OnStar.

[01:09:10] And, uh, the driver and his passenger forced out of the vehicle robbed by a shotgun wielding perp who then drove off in the SUV. And the OnStar dispatcher was able to locate the vehicle using GPS advised police of exact location. And as soon as the police established visual contact, the stolen vehicle slow down system is activated available on a number of GM cars and trucks.

[01:09:36] Right? So this was over a decade ago. That this happened, but the technology's evolved hasn. so we initially have all of these car companies trying to decide, okay. So we've got this kill switch law, which AP says is not a kill switch law. Cuz they talk to experts just like the, what was it? 52 people, uh, heads of intelligence.

[01:10:01] Committees and agencies said that this wasn't a collusion hoax, right? So they talked to experts who said, no, no, no, this isn't a kill switch, but that's today you can argue, it's not a kill switch. I would completely disagree with you. Day one. It's a kill switch cuz you can't start your car. Right. It's a kill switch.

[01:10:21] A kill switch is often something you hide somewhere on the car so you can kill the engine. So it can't be stolen. It's a kill switch. Come on. People fact checkers aside. This could potentially allow law enforcement again, to shut down your car, remotely track the car's metrics, location, maybe the passenger load, because remember now cars are tracking all of this.

[01:10:46] They've already been. Tickets issued by police that did not see anyone speeding. The car was not caught on a traffic camera, but they hook up a device to your car's port that talks to its computer. And the computer says, yeah, he was doing 80 miles an hour or, uh, five minutes ago. And all of a sudden you got a ticket, right?

[01:11:08] Massachusetts wants to go ahead now and say, uh, yeah, yeah. Let's charge by the mile that you drive and mask. Because of course they're not getting enough revenue from gasoline because of the electric cars, right. Electric cars are not paying their fair share when it comes to road taxes. So let's do it that way.

[01:11:27] So how are they gonna collect the information while. They're gonna hook up to your car's computer. The next thing coming down the road, and it's already in most cars is wireless data connectivity. You might have found already. If you have a Nissan, a Honda, many other cars that. You have to get a major upgrade.

[01:11:49] It varies 600 bucks up to a few grand for an expensive car, but the two G data network, we talked about this on the show already is being completely shut down by the end of the year. So we've gotta replace it and switch you over. To the LTE data network, which of course eventually will go away as well, or at least 3g what happens once it's all hooked up?

[01:12:16] Well, the next easy step is just feed all of that information straight to the government. Craig, Peter son.com.

[01:12:27] If you've been afraid of ransomware before I I've got a good example for you where a whole country now has been ransom. Absolutely crazy. So we'll talk about that. What is the state of ransomware? And the NSA is asking us to trust them again.

[01:12:43] Of course staying up to date means that you get my insider newsletter pretty much every Tuesday morning and, and the only way to get that is to go to Craig peterson.com/subscribe.

[01:12:56] And I will keep you up to date. You'll get even more insight information. The Costa REAN government has declared a state of national emergency. And to the best of my knowledge, this is the first time a government has done this because agencies of the Costa Rican government have been hit so badly by the K ransomware.

[01:13:22] That the new incoming president immediately declared a state of emergency. So now the country has expanded law enforcement powers and they are trying to go after the KTI ransomware group. Now between you and me. Good luck on that one. They are based in Russia. There's a number of different articles out this week.

[01:13:44] This one from ADV Intel at tech target. But according to their research, the Kati ransomware groups attack on Costa Rican government was part of a rebranding effort. So this ransomware gang has seen a lot of their payments, just dry up. Because it's harder to get the money in. Right. And what are you gonna do with cryptocurrency?

[01:14:09] If you are the KTI group, can you turn it into anything useful? Well, it kind of depends on the country you're in, but for most people, no. Okay. Absolutely. No. So we were able to knock the KTI ransomware groups. Offline. And we talked about that before here. The us government did that, but now this is marking a new chapter for the cyber crime landscape.

[01:14:37] Interesting. Isn't it? So there are some investigations that have been going on. They've been trying to figure out what happened. What was the cause of the downfall of the county ransomware group? Are they really gone? Why did they pull their website offline and also. They declared publicly support for Russia in its invasion of Ukraine.

[01:15:00] And so now the Canti ransomware group got hacked and held ransom. They suffered major leaks. As a consequence. So other hackers went after KTI, which is a hacking group and they, they showed here from internal in documents that were stolen, that the KTI ransomware gang's primary Bitcoin address, which was found in the leak, showed that they had taken in over 2 billion in cryptocurrency over the last five years.

[01:15:34] Isn't that just amazing and anonymous leaker has published more of the gangs communications, but you know, that can help that's for sure. But you think with that much money, they'd be able to protect themselves right now on top of it, because of the hack of Costa Rica and the major damage it's caused, the us government has offered a couple of bounties here.

[01:16:00] Against the KTI ransomware group. So there's $10 million available. If you can provide the feds with information about the leaders of the KTI ransomware group and $5 million that you can get leading to the arrest of anyone involved with a cont ransomware attack. Isn't that something. So ransomware has been really outta control for years.

[01:16:25] There's no signs that things are actually slowing down. Definitely been enhanced law enforcement efforts to track them down. But ultimately here, the core members of these groups have been escaping these law enforcement activities. They've been using mules kinda like 2000 mules. Have you seen that movie?

[01:16:46] But the idea is they get people primarily in the us cuz that's where most of the money comes from. They do ran. Of people and businesses information here. In fact, last year, it's estimated that 60%, six, 0% of small businesses were hacked, which is just crazy. Right? Well, no wonder it's got $2 billion, but.

[01:17:09] What are, what are we supposed to do? What are they doing to, to, uh, really come after us? Well, they're doing many of the same things. These mules will, uh, be hired saying, Hey, I just need to, uh, use your PayPal account. And, uh, all you have to do is transfer some money. You can keep. 5%, 10% of the money I put in there.

[01:17:29] And they've always got these excuses, you know, think the Nigerian email scams from years past, and frankly still kind of go around a little bit here, but large bounties are really becoming a part of the toolbox, a law enforcement's been using in the us and abroad to try and track them down. And that's really what they're hoping for down in Costa Rica, because what are they gonna do?

[01:17:57] You know, frankly, really? What are they gonna do? Well, I don't know. And they obviously are relying on the United States to help them out with this. The internal structure of the K group has been highly organized. They've got the same type of structure of a legitimate corporation would have it takes its work that needs to be done.

[01:18:18] They hire contractors that may not even know who they're actually working for to write small pieces of, of, uh, code here that gets tied. so it's not too surprising that a KTI affiliate is going to go far enough to cause a national emergency to be declared. Uh, one of the things that KTI has done in some of these other ransomware companies have done companies, gangs is.

[01:18:47] They have ransomware as a service. So there's all of these people that are affiliated with KTI and all you have to do is get the KTI ransomware onto someone's computer and Taha. They will pay you. It's really that simple. They've got tech support for the people that are ran that got ransom to help them, uh, supposedly pay, right?

[01:19:13] How do I buy Bitcoin? And they'll walk you through. and then they will help you with restoring your files. Hopefully they can be restored. They, they can't always be restored. I think right now the latest number I saw. about 60% of people who have their data encrypted and ransom are in fact able to get that data.

[01:19:39] There's 60% of the data back. So that's not too, too, uh, big a deal, but KTI operates on affiliate model. and this affiliate that went ahead and ransom, our friends in Costa Rica is called UN C 1 7 56, uncle 7 56. They're also suspected in other attacks on government servers, including a theft of intelligence materials from.

[01:20:07] Peru. And this attacker has already leaked information stolen from Costa Rica and it's on the K ransomware dark web portal, which is online. And after the former president of the country refused to pay a $10 million ransom demand, they started leaking the data. So in this case, focus has been on the national government agencies.

[01:20:31] They are potentially looking at what might you might call espionage, but these K ransomware affiliates have become famous for really quickly exploiting new vulnerabilities as they're published and being indiscriminate in who they attack because $2 billion. Right. And then the other part that I think is really kind of interesting here.

[01:20:55] Well, the we're talking about money. We're talking about real money. Obviously KTI deals almost exclusively in Bitcoin, which can be hard to turn into hard currencies, but that our friends in Costa Rica said no, we're, we're not going to pay. Knowing what has been stolen and what they no longer have access to.

[01:21:18] In fact, the president said that the comp the country Costa Rica is effectively at war. Now. They got a foothold KTI did in 27 agencies at different levels of the go. And the, uh, yeah. Okay. So KTI is, see, I'm looking at an article in the register here. KTI is apparently is made more than 150 million from a thousand plus victims while we know it's actually 2 billion, but it depends on the timeframe that they're talking about.

[01:21:50] Uh, And, uh, the, the cont says that they are determined to overthrow the government by means of a cyber attack. We've already shown you all the strength and power. You have introduced an emergency. It it's, it's really quite something. Now I mentioned earlier today that I am now. Taking all of the cybersecurity stuff that we have been using here over the years.

[01:22:14] Things like our plan of action and milestones documents and, and all of this stuff we use to run our projects for our customers. It's the real stuff, people. And remember, I've been doing the cybersecurity. Since the early nineties, so we know what we're doing, I know what I'm doing and I'm making it available for free.

[01:22:40] Okay, guys, you just have to send me an email me@craigpeterson.com. So the first cyber punch list that we have that a available and all you have to do is ask for it again. Me, me, Craig peterson.com is the. Email punch list. So with this punch list, I go through the things that you need to do. In order to secure your email and be more or less secure in your email.

[01:23:14] Now, I don't know about you. I do not like these long diatribes. I, I have a book behind me that is hardening windows 10 and it is in a four inch binder, double. Sided. There are thousands of recommendations in there from Microsoft. There's a lot that needs to be done. So what I've done is boiled it down to the most important things.

[01:23:43] And as I said, it's available for absolutely. Free for you. It really is. If you're a listener, just email me, me, Craig peterson.com. You can ask me to add you to my insider show notes and my little three minute trainings that we do every week. Uh, you can also ask for a cyber punch list that you might need, so it's just, okay.

[01:24:07] Need to do this. You need to do that. You need to do this. You need to do that. So it makes it very straightforward. I'm trying. To be OBT accused about any of this, but we have had amazing feedback on this from companies over the years, and now it's available to you for $0. Okay. So make sure you check it out.

[01:24:28] Craig peterson.com and you can always email me, me@craigpeterson.com as well. Thanks for taking a little time with me today and look for me online. Look for my emails and if you would please give. Thumbs up on your favorite podcasting platform, YouTube or rumble or subscribe. Thanks.

View Details

Been to a Hospital Website Lately?
Facebook May Have Your Personal Information!

Hey, Facebook isn't the only company doing this, but there's an article from the markup. They did a study and caught Facebook. This is absolutely crazy -- receiving sensitive medical information. We're gonna talk about that right now.

[Automated transcript follows]

This is really concerning for a lot of people. And, and for good reason, frankly, I've been talking about this.

[00:00:22] I, I think the first time I talked about it was over a decade ago and it has to do with what are called pixels. Now, marketers obviously want to show you ads and they want show you ads based on your interest. And frankly, as a consumer, if I'm looking for a new F one. I wouldn't mind seeing ads from competing car dealers or, you know, used car places, et cetera, to try and sell me that Ford truck.

[00:00:53] It makes sense, right? If I'm looking for shoes, why not show me ads for shoes, but what happens when we start talking about the medical business about the legal business things get murky and people get very upset. You see the way these pixels work is you'll put a pixel, like for instance, a Facebook pixel.

[00:01:15] If you go to Craig peterson.com, I've got this pixel on there from Facebook. And what it allows me to do now is retarget Facebook user. So you go to my site to go to a page on my site, and this is true for, uh, pretty much every website out there. And. I know that you went and you were looking for this, so I can retarget you in an ads.

[00:01:37] I'll show you an ad. In other words, on Facebook now I've never actually done that ever. Uh, I I'm like the world's worst marketer, frankly. Uh, and, uh, but I do have that on there because it gives me some other numbers, statistics, and, and really helps you to understand how the website's being used, which I think makes a whole lot of sense.

[00:01:58] So there are marketers that are using this for obvious reasons. Now, I think you understand what the pixel is. It is literally a little picture that is one pixel by one pixel, and it tends to blend in, I think even in most cases, now these pixels from different. Places like Facebook are actually transparent.

[00:02:19] So you, you don't even see it on the page, but the idea is now they have a foothold on a website that doesn't belong to them. In this case, Facebook now has access to information about a website that you visited that has nothing to do with Facebook. okay. So that's the basics of how these pixels work and they're almost impossible to get rid of because in reality, many websites, mine included will even grab graphics from other websites just because you know, it it's, I'm quoting another article I pull in their graphic.

[00:03:00] Of course, they'm gonna point to that other site. Why would I take that picture? Put it on my site. I don't own the rights to it. But if he'll let me that other website will, let me go ahead and show that graphic on my website, cuz there's ways to restrict it. If they don't want me doing that, they could stop me from doing it.

[00:03:18] Then I I'm going to just go to the original website so they can get the credit for it's their property still. I'm not violating any copyright laws, et cetera. Does that make sense to. So what's the difference between the Facebook pixel and a picture I'm pulling from another random website? Well, the obvious thing is it's coming from a Facebook domain of some sort.

[00:03:40] So, so there are ways to stop it, but there's just as many ways to get around stopping it, frankly. Well, Let's move on to something a little more sensitive. We have had problems that I reported on years ago of people going to an emergency room in a hospital. Now, when you're in that emergency room, your phone has GPS capabilities still.

[00:04:06] It knows you went in the emergencyentrance to the hospital and you are. Opening it up. Maybe you're looking around, maybe you're reading articles, maybe you're plotting your trip home using Google maps. You are being tracked depending on what apps you have on your phone. If you have an Android versus an iPhone, what you've enabled, what you haven't enabled.

[00:04:29] Right? All of that sort of stuff. well, this now has become a problem because as I reported there have been people who went to the hospital, went to the emergency room and started seeing ads from what you might call ambulance, chasing lawyers. Have you been injured? Is it someone else's fault? Call me right now.

[00:04:54] Do he cheat him in. if that sort of thing showed up on your phone, would you get a little upset, a little nervous saying, what are they doing, trying to cash in on, on my pain, maybe literal pain. And it's not as though those ads are just showing up while you are in the emergency room, because now they've tagged you.

[00:05:15] They know that you are in that emergency room. So off they'll. They will go ahead and track you and send you ads even after you leave. Hey, I wanna remind you if you want to get this, uh, this week's list of articles. I, I put out every week, my insider show notes. It has become very popular. Thousands of people get that every week.

[00:05:41] Go right now to Craig peterson.com. I'll also send out a little bit of training. I do that. I have special reports. I send out. I've got more stuff I'm doing, but you gotta be on the email list. Craig peterson.com to get on my free email list now. What's happened here now is markup went ahead and looked at Newsweek's top 100 hospitals in America.

[00:06:06] They went to their websites and they found about a third of the hospitals using what's called the Meel. That is the Facebook pixel I was referring to earlier. So it sends a little bit of data. Whenever someone clicks a button to let's say, schedule a doctor's appointment. Why does it do that? Well, because the Facebook pixel is on the scheduling page.

[00:06:33] Let's say there's scheduling page for oncology on the website. I guess who knows that you are going to see an oncologist? Facebook? Why? Well, because the hospital has put a Facebook tracking pixel on that page. So Facebook knows, Hey, he was on the oncologist page. Maybe he has cancer. I should start showing him ads from other hospitals and from cancer medications, et cetera, etcetera, that is happening.

[00:07:03] Right now, 33 of these top 100 hospitals in America. Th these are the top 100, according to Newsweek's list. Have that information. Now that data is connected to your internet. Address. So it's kinda like your computer's mailing address and they can link that back to usually to a specific individual or to a household.

[00:07:30] So now they have a receipt of the appointment request. that's gone to Facebook now. They don't have everything you filled out on the page or anything, you know, you added in your social security number, maybe other medical information. Facebook didn't get all of that, but they do know that you visited the hospital's website and which pages you visited on that website.

[00:07:56] So markup went ahead and contacted these hospitals. So, for example, John John's Hopkins hospital, they did find a Facebook pixel tracking on the appointment, scheduling page. They informed John's Hopkins of how that is a leak of personal information. And after being contacted by the markup, they did not remove the track.

[00:08:27] also, by the way, when the markup reached out to them, the hospital did not respond UCLA Reagan medical center. They had of course a pixel and they did remove it from the scheduling page. Although they declined to comment, New York Presbyterian hospital, all these hospitals have that pixel and they did not remove it.

[00:08:49] Northwestern Memorial hospital. Again, they got the tracking pixel did not remove it after they were informed about the security problems, duke university hospital, same thing. Most of these, by the way, did not respond to them. University of Pennsylvania, Houston Methodist hospital, the university of Chicago medical center.

[00:09:11] Uh, the last two of those did remove the pixel. Uh, Scripps Memorial hospital out in LA JOA, California. There are many Brigham and women's Faulkner hospital. They were informed that they had the tracking picture pixel on the, on the, uh, scheduling page. They did not remove it, but you know, the time of this article, a Tufts medical center, same thing did not remove it, uh, out in Sanford in San Diego.

[00:09:39] Same problem. John's Hopkins Bayview medical center, John Jefferson health, Thomas Jefferson university, hospitals, Loyola. These are big name hospitals. I'm looking at these that goes on and on sharp Memorial hospital, Henry Ford hospital. Uh, let's see some more, I'm trying to, oh, Massachusetts general hospital.

[00:10:00] They did not have the tracking pixel Brigham in women's hospital, no tracking pixel on the scheduling page. So some of these hospitals were already doing it right. They re they recognized that putting this Facebook. Pixel on may help them with some of the marketing and understanding the market a little better, which is what I do, but it's also giving personal information, personal health information to Facebook and Facebook's advertisers.

[00:10:32] So they didn't put it on so good for them. Again, mass general Brigham and women's, uh, Sanford Mount Sinai, university of Michigan hospital and, and others, of course. So very good news there in general. Again, don't be worried about a pixel on just a random website because it probably is being used to help with stats to know what's being used on the website.

[00:10:58] And maybe, maybe just maybe using it to send a little ad to you on Facebook later. Of course, you're listening to Craig Peter son. You can get my insider show notes for absolutely free. And my little mini trainings. Oh three to five minutes every week@craigpeterson.com. Just sign up on the homepage.

[00:11:23] You know, I've got it on my homeowner's policy. I have a special business policy for it. And it's something that you should seriously consider, but you need to understand first. So we're gonna talk about it. What is cyber insurance? Uh, that's what's up now?

[00:11:41] Cyber insurance is something that many businesses have looked at, not all businesses have, which is kind of crazy. If you ask me according to the industry statistics right now, less than 1% market penetration for cyber insurance and is expected to.

[00:12:02] Into a $20 billion industry by 2025. That is some serious money. So what is this cyber insurance? For instance, there's a rider on my home insurance for, for cyber insurance and I have special cyber insurance from a, a big company underwritten, but it is for anything that happens. In my business, that's related to cyber security and it also covers my clients because that's what we do for living is cyber security.

[00:12:37] If they are following our guidelines. So it's pretty darn cool when you get right down to it, because these risks that we have in the digital world are really every. So if you're a large organization, if you're a small little enterprise, are you going to get hacked? You know, bottom line, anybody could potentially get hacked because the bad guys have gotten pretty good.

[00:13:06] And most of us in business have gotten pretty lax AADA because of all of this, but not everybody understands when we're talking about cyber insurance. What does cyber mean? Well, the idea is that cyber insurance is created to protect organizations and individuals against digital risks. So we're talking about things like ransonware malware fishing campaigns.

[00:13:34] So for instance, I got a call just this week from a listener who again, had their operating account emptied out, hated when that happens. And so they lost everything. They lost all of the money in the account and they're trying to get it back. I got an email this week and, uh, from a lady that I, there's not much I can do for her.

[00:13:56] I pointed her in the right direction, but her father, I think it was, had his digital wallet of cryptocurrency completely emptied, completely stolen. Can you believe this sort of stuff, right? It's happening every day. You might have insurance that covers that, but you might not. Traditional insurance policies are only looking at physical risks, so they will take the physical risk things like damage to equipment, or maybe you have livestock or you have stock an inventory, a building different locations.

[00:14:38] That's your standard stuff. But cyber insurance is to allow businesses to transfer the costs associated with recovery from the losses incurred when there's some form of cybersecurity breach. Now that's a pretty big deal. because the losses can be huge. It isn't just ransomware where maybe it, it costs you a million dollars in ransom payments.

[00:15:08] Or if you're an individual, a retiree, maybe it only costs you 25,000 in ransom payments. And I know that's a lot, especially for retiree. But there is loss of reputation. There's loss of business, cuz you couldn't conduct business cuz you couldn't use your computers. Right? All of that sort of stuff. You got people that you have to bring in, you have to bring in a special team to try and recover your data.

[00:15:33] Maybe try and figure out what had happened. Right. All of that sort of stuff. So be careful cyber insurance, a lot of people kind of mistake it for policy that pays off. Attackers to retrieve or unlock data. That's not what it's really for cyber insurance is something that allows you to, I guess the term in, in the industry is transfer risk when your online security controls fail and.

[00:16:01] Basically all of them could fail. It, it, it depends, right? If you're a huge company, you can hire a bigger team for a security operation center, but at the same time, you also have more employees that are causing more problems. So look at it entirely business interruption, payments to experts to recover the data.

[00:16:23] Compensation for bodily injuries, uh, depending obviously on the resulting damage and the particular policy and the rates are gonna vary based on the maturity of your cyber defenses. So this is something that I've been big on for a long time, the cyber security maturity CMMC and what that helps 'em to determine is.

[00:16:49] What are your rates gonna be? So if you went out and you're just using the cable modem that they, that the, uh, company, your cable company provided for you, or you go to a big box retailer, and that's where you bought your firewall and switches, and you've got your wonderful little Lenovo PCs or Dows or whatever, and you're running, uh, Norton antivirus.

[00:17:13] You are not well covered. You are not very mature from a cybersecurity standpoint. The other thing you need to be able to do is make sure you've got your asset management all in line, that you have policies and procedures in place for when things happen. You gotta have it all put together, but the average cyber insurance policy for a small to mid-size company in 2021 was about $1,600.

[00:17:41] For $1 million in cyber liability coverage. Now that's not really bad at all. Now there are limits to what the provider will pay. They will often, if you do get nailed, They'll come in and double check that, everything that you said, all of those boxes that you checked when you were applying for your cyber security insurance, make sure you actually did all of them.

[00:18:08] Okay. Yeah. Kind of a big deal. And you not only will they not pay out, if you didn't do everything that you said you were going to be doing. but the other problem is you might end up getting sued by. Okay. So expect a counter suit if you decide to soothe them. So don't lie on those fors people. Okay. All right.

[00:18:32] Um, cyber claims, unlike non-technical events, like again, a fire flood storm damage, the cyber insurance claim might be determined by means of attack and your ability or your effort to prevent it. As I was saying, make sure you've got the checklist and this is something I think I, I should probably put a course together on to help you guys with, or maybe even a little bit of consulting for people.

[00:19:01] Let me know, just send an email to me, me@craigpeterson.com. And uh, if you're interested in more info about cyber insurance, you can either look at this week's newsletter that you can. By again, going to Craig peterson.com and a link to this particular article I'm looking at, or you can tell me, Hey, listen, I'd love a little course or little support, a little help.

[00:19:24] Okay. I think it makes a lot of sense. So does your business qualify for cyber insurance? Well, some do some don't, uh, you might not see yourself as a target. For the bad guys, but I'll tell you, my 85 year old father was conned by some of these cyber attack guys. Okay. And he doesn't have much money. He, he's not the bank of, uh, England bank of America.

[00:19:52] None of these big banks or anything. Oh. Is a retiree living at home trying to make ends meet. So the same, thing's true for you as a business, you as an individual now. You are vulnerable most likely to a cyber attack, but you've got to really manage your risk posture. You gotta do things, right. So that's the bottom line there.

[00:20:16] That's what we try and help you do. But you can find information about this again, you can just email me, me, Craig peterson.com and ask for the info on cyber insurance, or if you're already a subscriber to my newsletter. That went out Tuesday morning. So just check your mail. Maybe it's in the spam box from Tuesday morning and you'll find a lot more information linked right from there.

[00:20:42] Craig peterson.com stick around. We'll be right back.

[00:20:51] There are a lot of complaints about how some of these cryptocurrencies are very non green using tons of energy. And now the prices are going down. We're seeing a number of really weird things happening.

[00:21:07] Cryptocurrency, as you probably have heard, has taken a tumble. Now, some of the cryptocurrencies, particularly of course, someone you might know most is Bitcoin use a lot of computing power.

[00:21:20] You see, what they're trying to do is basically solve a very complex mathematical problem. And in order to do that, they need a lot of computing power. Now you can certainly run it on your little desktop computer, that program to compute those things. It's called mining. So you're mining for Bitcoin.

[00:21:42] You're, you're trying to solve these mathematical problems and there's a theoretical limit to how many Bitcoins could actually potentially be mind looking right now. They're saying that circulating Bitcoin right now. Is about 19 million Bitcoin that are out there. And Bitcoin is worth about $20,000 right now, down from its huge, huge, huge high.

[00:22:11] That was, uh, more than two and a half times. What it's worth right now. So, how do you mind? Well, if you take that computer and you run the software, it's gonna do some mining and it is probably going to cost you more in electricity nowadays to mine. One Bitcoin than that Bitcoin is worth. In fact, it certainly will cost you more now.

[00:22:37] Uh, that's why the people that are professional Bitcoin minors have taken a different tact and what they've done. Is they found places where they can get cheap electricity. For instance, Finland, where they're using geothermal produced electricity. They're also using the cold air outside in order to cool down.

[00:23:00] The computers themselves as they're trying to compute this, but there's another thing that they've been doing. And that is well, how about we buy a coal plant? That's been shut down and that's happened. So they take that coal plant. They bring it back online. They burn the coal, they produce electricity at a cheaper rate than they could buy it.

[00:23:23] but behind all of this is the computing power. And what miners found a long time ago is it's better to have thousands of compute units working on solving these problems than it is just having. I don't know how many CPUs are in your computer for eight. Com, um, CPUs. How many? Well, I, how far can you get with those?

[00:23:48] Yeah, they're fast, but we need thousands of computers. So what they found is that GPU's graphical processing units. Kind of met their goals. You see a GPU is actually composed of thousands of computers, little compute units. Now they can't do real fancy math. They can't do anything particularly fancy.

[00:24:13] They're really designed to move. Pixels around on a screen. In other words, they're designed to help gamers have a nice smooth game while they're playing. They can be used. In fact, they're used all of the time in desktop computers, just for regular display of a webpage, for instance, or if you're watching a video, all of that is part of what they're doing.

[00:24:39] With graphic processing units. And if you've been paying attention, you probably have noticed if you particularly, if you're a gamer that the price for GPUs has gone way up, not only has it gone way up and it isn't just due to the lockdown and the supply chain problems. but they're very, very, very hard to get now.

[00:25:02] Yeah. Some of that is due to supply chain problems. No doubt about it. But most of these GPUs, according to some of the numbers I've seen, have actually been bought by these professional mining companies. In fact, many of them have gone the next step and they have what called custom silicone. These are completely customized process.

[00:25:28] sometimes they're using Asics. Sometimes they're using other things, but these custom processors that are really good at solving that problem that they have to solve in order to mine, a bit Bitcoin or one of these other currencies. So you, you see how that all works. There's a number of GPU manufacturers and something else interesting has happened because of the drop in value of pretty much all of the cryptocurrencies.

[00:26:00] And that is these GPS are going byebye. Right. Do does a company that is now no longer trading. That's no longer operating. Uh, we've seen at least two of these crypto mining companies just completely disappear. So now all of their hardware is going up for sale. You'll find it on EBA. So I, I wanna warn you, if you are looking for a GPU of some sort for your computer, maybe if you're a gamer, be very, very careful.

[00:26:37] We've got a buyer beware situation here because you're not just buying a GPU. A graphics processing card, uh, that has been lightly used. It was sitting in a terminal. Maybe it's a GPU. Like I use them where, when I'm doing video editing, it does use the GPU, even some of the audio editing. It uses the GPU.

[00:26:59] I'm looking at it right now and I've got some, uh, GPU utilization going on. I've got about, uh, 6% of my GPU in use right now on this computer. So. What the problem is is that these minors who are selling their old GPUs have been running them full Bo 24, 7. That's hard on anything. Isn't it. So what, uh, what's happening here is that you are seeing a market getting flooded with GPUs.

[00:27:35] You really don't wanna. All right. Does that make sense? Uh, you know, there we've lost more than 50% this year already in some of these, uh, cryptocurrencies that are out there coin base has had an interesting year Celsius, a major cryptocurrency bank, suspended withdrawals, uh, just here in the last few.

[00:28:01] Coin based crypto exchange announced a round of layoffs. Also here, they paused their hiring a month or two ago. It it's not going very well and prices for new and used graphic cards are continuing to fall. The peak price was late in 2021, a little bit early in 2022, but now you can go to Amazon new egg, best buy and buy current generation GPUs for prices that really would seem like bargain six months ago.

[00:28:35] And pricing for used GPUs has fallen even further, which is the caveat aura URA thing here that I'm warning everybody about. You need to proceed. With caution. So there's a lot of scams, a lot of bait and switches. You know, that's been kind of normal for some things over the years on eBay. I'm afraid, but I've had pretty good luck with eBay, but any high value eBay purchase CPUs have been mining cryptocurrencies at full tilt for months or years have problems in new GPU.

[00:29:12] Would not have had, you know, this heat that they generate, the dust that gets into them, that the heat is messing with can really degrade the performance and degrade the usage of that GPU here over time. Dust can also, uh, cause problems with the thermal paste that's in them could be dried out thermal paste because of the heat and that causes them to crack and causes other problems.

[00:29:40] So if you buy a used GP that looks dirty or runs hot, removing and cleaning the fan and heat sink, reapplying, fresh thermal paste. Could potentially restore loss performance, and maybe you can even get that new Sony PlayStation because GPS are becoming available. Again. Visit me online Craig peterson.com and get my weekly insider show notes right there.

[00:30:07] Craig peterson.com. Sign up now.

[00:30:13] Self-driving is relatively new technology. And, uh, our friends at Tesla just fired an employee who posted videos of a full self-driving accident. Uh, he's done it before.

[00:30:30] Tesla has a very interesting background. In fact, Elon Musk has gotten more interesting over time. And particularly lately the stuff he's saying, the stuff he's doing, but his companies have really made some amazing progress.

[00:30:48] Now, one of the things that Elon did pretty well pretty early on was he decided he was going to start selling. A self-driving feature for his cars. And back in the day, you could buy it. This was before it was ready at all for, I think it was 5,000 and, uh, it was good for whenever they came out with it.

[00:31:15] And then it went up to 7,000 and then I think it went to 12,000 and now it's you pay him monthly, but in reality, There are no fully self-driving qualified Teslas on the road today. It will be a little while before that happens. So this ex Tesla employee by the name of John Burnell is quoted in ours Technica saying that he was fired for posting YouTube videos about Tesla's full self-driving beta.

[00:31:48] Now this is called F S D. And if you know, Computers, you know what beta is? Beta means, Hey, you know, should work, could work, probably has some problems. And that's exactly what it is. Now. Tesla told California regulators that the full self-driving beta lacks true autonomous features. And that's probably how they got by getting with putting this car on the road, these cars on the road.

[00:32:19] So this X employee. Says that Tesla also cut off access to the full self driving beta in the 2021 Tesla model three that he owns. Now. He said that he paid for it. He had it legitimately, and yet Tesla cut him off from, and I guess. Anybody can try and sign up for it. I don't know all of the details behind getting that beta code.

[00:32:46] If you wanted to, you probably could investigate a little bit further, but the video that he posted on February 7th provided a frame by frame analysis of a collision of his Tesla with a Ballard, a a Ballard. Those are those stanchions, those, uh, cement pillars. They usually have. Plastic on the outside that you'll see, you know, protecting sidewalks or in this case it was protecting a bike lane in San Jose.

[00:33:19] So he said, no matter how minor this accident was, it was the first full self-driving beta collision caught on camera. That is irrefutable. And he says I was fired from Tesla in February with my U YouTube being cited as the reason why, even though my uploads are for my personal vehicle off company, time or property with software, I paid for.

[00:33:45] And he has a, um, channel called AI addict that you can find over there on YouTube if it hasn't been taken down yet. Right. Uh, he said that he got a notice that his full self-driving beta was disabled be based on his recent driving data, but that didn't seem to fit because the morning I got fired, he says I had zero proper use strikes.

[00:34:10] On my vehicle. So yeah, I, I can't say as I really would blame him, uh, him being in this case, Elon Musk for firing this guy, but it's an interesting little video to watch. It's like two and a half minutes. You'll see. And it, the guy has his hand on the steering wheel and the car is steering. Itself down the roadway and there's no other traffic really on the road.

[00:34:38] I don't know when this was like a, a Sunday or something, but you can see on the screen, it is detecting things like the, the little, uh, construction pillars that are on the side of the road. And he's in a left. Turn only lane and his Tesla turns, left the steering. Wheel's kind of going a little back and forth, right?

[00:34:58] As it tries to make up his mind what it's going to do and he's driving down, he just passed a ups truck. Although I would not have passed personally, the way he passed, which is the. The car decided it was going to, um, get closer to that ups truck. I, I would've purposely gone further away. And then what happens is he goes around another corner where there's some Ballards.

[00:35:26] That are in the roadway. And of course the idea behind them is so the cars don't go in and accidentally strike a cyclist. But around that corner where there is a crosswalk crossing the street, there's no Ballard. So people don't have to kind of get around them. And then the Ballards start off again. So the Tesla got kind of confused by this and looking at the screen, it doesn't show the, these Ballards.

[00:35:56] Being recognized. So the driver of the car grabs the stern wheel takes over at the very last second, but did actually hit the Ballard. Uh, no two ways about it here. He hit it and the car is stopped and it's just a minor scratch. He's showing it on his, uh, on his screen here. But I gotta say overall, it looks like it performed quite admirably.

[00:36:24] And the fact that this apparently is the. Uh, the only time it was actually caught on video. That's interesting too, but the cars of course have cameras on them too. So I'm sure. In other cases it did record a video of it. So CNBC said it obtained a copy of Tesla's internal social media policy, and it says it makes no direct reference.

[00:36:48] To criticizing the company's product in public. So we'll see what happens. Uh, apparently too, they are saying that this is the first accident in a year of testing this full self-driving. So that is darn good, frankly. And, uh, he's saying, you know, some people are saying I should have reacted sooner, which I should have.

[00:37:09] But in my year of testing, the full stop driving is usually really good at detecting objects last minute and slowing to avoid. So I don't know. We'll see what happens here. Tesla's doing a very good job. Hey, and I got another car story for you. This one, I. Think is totally, totally cool. You might remember Congress passed a law back in the seventies saying that we had to have what these cafe standards for vehicles efficiencies.

[00:37:36] In other words, you had to have certain fuel efficiency across all of the cars that you manufactured, you know? Okay. It is good enough, whatever. And, uh, they, they weren't able to make. uh, the car manufacturers, they weren't able to hit it until they came up with a whole new ignition technology for the cars.

[00:38:00] And that of course is fuel injection. You might remember we had car braiders and all of the cars, not very efficient. The engines themselves aren't very efficient, but we came up with fuel injection. And that helped the car manufacturers to meet these new cafe standards. Now, unfortunately, car manufacturers have removed weight from the cars in order to gain fuel efficiency in order to meet these federal requirements.

[00:38:28] So they've done things like taking out the full size spare tire, right? You, you had that before and that full size spare tire is now replaced with. Stupid a little tire, right? That, you know, you can limp down the road a little ways, but not very far, but they've also removed steel and various metals from other parts of the car.

[00:38:47] And many people have said it's made the cars less safe. The same time they've added more safety features like the side impact airbags and, and other things and, and airbags that will Mame. But, but that's a different story entirely. Uh, but this is very, very cool because there's a company called transient plasma systems TPS, and they came up with this new advanced ignition system that uses plasma.

[00:39:17] They've designed it in such a way that it replaces your spark plugs in your. And now they put the ignition module in that uses nanosecond duration, pulses of plasma to ignite that air fuel mixture that's inside the cylinder. So you're still doing the fuel injection, but you're igniting it with a nanosecond worth of.

[00:39:43] Plasma. Isn't that just amazing. So they've tested that technology 2019 is when they came out with it and they did some bench testing, but now it's almost ready for production. So they're doing now with vehicle manufacturers, validation testing. It is frankly very cool. And they don't have to do it on brand new engines either.

[00:40:08] They will come up with retro Kitt fixed fixes. Now, imagine this getting 20% better mileage by basically replacing your spark plugs and a little more firmware changes in your engine controller. No question about that one, right. But this is frankly. Absolutely amazing. Now it's going to take a lot of years before we move to electric vehicles.

[00:40:34] For a lot of reasons. We're not ready. The country isn't ready. The infrastructure isn't ready. People aren't ready. The cars aren't ready. We don't even know what. To do with the batteries. People complain about nuclear waste while there are now huge fields full of these batteries while they're trying to figure out what do we do with the used batteries from these electric or hybrid cars, because man, they it's a huge problem.

[00:40:59] All kinds of toxic stuff in them. And they haven't been good at being able to recycle 'em it's not like the old lead acid batteries. That are very easy to recycle. So it's going to be years before they really stop selling any of these internal combustion engines and even longer before they ban internal combustion engines.

[00:41:21] From the roadways. So this plasma ignition system is going to really, really help 20%. That is darn good. And I am looking at the article right now. They used this Toyota engine. This is a 2.5 liter Toyota Camry Atkinson cycle, thermal efficiency around 40%, which is absolutely amazing. Good job Toyota. And.

[00:41:48] Replaced the spark plug with this. Ignition system, this new ignition system using of course plasma and they found some amazing, amazing, uh, statistics here improvements. So in some cases they're seeing. The spark plugs and the plasmas getting 6% increase in fuel economy and others are seeing 20% increases.

[00:42:17] Of course, they've got to do more testing, extreme heat, extreme, cold, wet, dry, but that's gonna be happening. And we might see this in our cars in the next couple of years. Make sure you sign up right now. For my newsletter, get my insider show notes for free Craig peterson.com.

[00:42:39] Hey, it looks like if you did not invest in crypto, you were making a smart move and not moving. Wow. We got a lot to talk about here. Crypto has dived big time. It's incredible. What's happened. We get into that more.

[00:42:56] Crypto currencies. It, it it's a term for all kinds of these basically non-government sanctioned currencies.

[00:43:06] And the idea behind it was I should be able to trade with you and you should be able to trade with me. We should be able to verify the transactions and it's kind of nobody's business as to what's happening behind the scenes. And yet in reality, Everybody's business because all of those transactions are recorded in a very public way.

[00:43:30] So crypto in this case does not mean secret or cryptography. It's actually referring to the way the ledgers work and your wallets and, and fact, the actual coins themselves, a lot of people have bought. I was talking with my friend, Matt earlier this week and Matt was saying, Hey, listen, uh, I made a lot of money off of crypto.

[00:43:57] He's basically a day trader. He watches it. Is it going up? Is it going down? Which coin is doge coin? The way to go? Cuz Elon must just mentioned it. Is it something else? What should I do? And he buys and sells and has made money off of it. However, a lot of people have. And held onto various cryptocurrencies.

[00:44:19] Of course, the most popular one. The one everybody knows about is Bitcoin and Bitcoin is pretty good stuff, you know, kind of bottom line, but 40% right now of Bitcoin investors are underwater. Isn't that incredible because of the major dropoff from the November peak. And this was all started by a problem that was over at something called Tara Luna, which is another cryptocurrency now.

[00:44:51] You know, already that there is a ton of vol a ton of, uh, changes in price in various cryptocurrencies, Bitcoin being of course a real big one where, you know, we've seen 5,000, $10,000 per Bitcoin drops. It, it really is an amazingly, uh, fluid if you will coined. So there's a number of different people that have come out with some plans.

[00:45:19] How about if we do kinda like what the us dollar used to do, which is it's tied to a specific amount of gold or tied to a specific amount of silver. Of course, it's been a while since that was the case. Uh, president Nixon is the one that got us off of those standards, but. Having gold, for instance, back in your currency means that there is going to be far less fluctuation and your currency means something.

[00:45:49] See, the whole idea behind currency markets for government is yeah, you do print money and you do continue to increase the amount of money you print every year. Because what you're trying to do is create money for the. Goods product services that are created as well. So if, if we create another million dollars worth of services in the economy, there should be another million dollars in circulation that that's the basic theory.

[00:46:20] Monetary theory really boiling it. Right. Down now of course, you know, already our government has printed way more than it. Maybe should have. It is certainly causing inflation. There's no doubt about that one. So they're looking at these various cryptocurrencies and saying, well, what can we do? How can we have like a gold standard where the us dollar was the currency the world used and it, its value was known.

[00:46:46] You see, having a stable currency is incredibly important for consumers and businesses. A business needs to know, Hey, listen, like we sign a three year contract with our vendors and with our customers. And so we need a stable price. So we know what's our cost going to be, what can we charge our customer here?

[00:47:06] Can the customer bear the price increases, et cetera. The answer to most of those questions of course is no, they really, they really can't is particularly in this day and age. So having a. Fixed currency. We know how much it's worth. I know in two years from now, I'm not gonna be completely upside down with this customer because I'm having to eat some major increases in prices.

[00:47:31] And as a consumer, you wanna look at it and say, wow, I've got a variable rate interest rate on my mortgage. And man, I remember friends of mine back in the eighties, early eighties, late seventies, who just got nailed by this. They had variable rate interest loan on their home because that's all they could get.

[00:47:50] That's all they could afford. So the variable rate just kept going up. It was higher than credit cards are nowadays. And I remember a friend of mine complaining, they had 25% interest and that's when they lost a house because 25% interest means if you have a a hundred thousand dollars loan, you got $25,000 in interest that year, you know, let alone principal payments.

[00:48:14] So it, it was a really. Thing. It was really hard for people to, to deal with. And I, I can understand that. So the cryptocurrency guys. I said, okay, well let's tie it to something else. So the value has a value and part of what they were trying to tie it to is the us dollar. That's some currencies decided to do that.

[00:48:39] And there were others that tried to tie it to actual. Assets. So it wasn't just tied to the dollar. It was okay. We have X dollars in this bank account and that's, what's backing the value of our currency, which is quite amazing, right. To think about that. Some of them are backed by gold or other precious metals.

[00:49:02] Nowadays that includes a lot of different metals. Well, this one coin called Tara Luna dropped almost a hundred percent last week. Isn't that amazing. And it had a sister token called Tara us D which Tara Luna was tied to. Now, this is all called stablecoin. Right? The idea is the prices will be stable. and in the case of Tara and Tara S D the stability was provided by a computer program.

[00:49:37] So there's nothing really behind it, other than it can be backed by the community currencies themselves. So that's something like inter coined, for instance, this is another one of the, there are hundreds of them out there of these, uh, cryptocurrencies. The community backs it. So the goods and services that you can get in some of these communities is what gives value to inter Pointe money system.

[00:50:03] Now that makes sense too, right? Because the dollar is only worth something to you. If it's worth something to someone else, right. If you were the only person in the world that had us dollars, who, who would want. Like, obviously the economy is working without us dollars. So why would they try and trade with you?

[00:50:24] If you had something called a us dollar that nobody else had, or you came up with something, you made something up out of thin air and said, okay, well this is now worth this much. Or it's backed by that, et cetera. Because if again, if you can't spend it, it's not worth anything. Anyhow, this is a very, very big deal because on top of these various cryptocurrencies losing incredible amounts of money over the last couple of weeks, We have another problem with cryptocurrencies.

[00:50:59] If you own cryptocurrencies, you have, what's called a wallet and that wallet has a transaction number that's used for you to track and, and others to track the money that you have in the cryptocurrencies. And it it's, um, pretty good little. Fun function or feature. It's kind of hard for a lot of people to do so they have these kind of crypto banks.

[00:51:21] So if you have one of these currencies, you can just have your currency on deposit at this bank because there's, there's a whole bunch of reasons, but one of the reasons is if. There is a, a run on a bank, or if there's a run on a cryptocurrency, currencies have built into them incredibly expensive penalties.

[00:51:45] If you try and liquidate that cryptocurrency quickly. And also if there are a lot of people trying to liquidate it. So you had kind of a double whammy and people were paying more than three. Coin in order to sell Bitcoin. And so think about that. Think about much of Bitcoin's worth, which is tens of thousands of dollars.

[00:52:05] So it's overall, this is a problem. It's been a very big problem. So people put it into a bank. So coin base is one of the big one coin coin base had its first quarter Ernie's report. Now, this is the us' largest cryptocurrency exchange and they had a quarterly loss for the first quarter of 2022 of 430 million.

[00:52:35] That's their loss. And they had an almost 20% drop in monthly users of coin. So that's something right. And they put it in their statement, their quarterly statement here as to, you know, what's up. Well, here's the real scary part Coinbase said in its earning earnings report. Last Tuesday that it holds the.

[00:53:01] 256 billion in both Fiat currencies and crypto currencies on behalf of its customers. So Fiat currencies are, are things like the federal reserve notes, our us dollar. Okay. A quarter of a trillion dollars that it's holding for other people kind of think of it like a bank. However, they said in the event, Coinbase we ever declare bankruptcy, quote, the crypto assets.

[00:53:31] We hold in custody on behalf of our customers could be subject to bankruptcy proceedings. Coinbase users would become general unsecured creditors, meaning they have no right to claim any specific property from the exchange in proceedings people's funds would become inaccessible. Very big deal. Very scary for a very, very good reason.

[00:53:57] Hey, when we come back, uh, websites, you know, you go, you type stuff in email address, do you know? You don't even have to hit submit. In most cases, they're stealing it.

[00:54:09] I'm sure you've heard of JavaScript in your browser. This is a programming language that actually runs programs right there in your web browser, whether you like it or not. And we just had a study on this. A hundred thousand websites are collecting your information up-front.

[00:54:26] This is not a surprising thing to me. I have a, in my web browser, I have JavaScript turned off for most websites that I go to now, JavaScript is a programming language and it lets them do some pretty cool things on a webpage.

[00:54:44] In fact, that's the whole idea behind Java. Uh, just like cookies on a web browser where they have a great use, which is to help keep track of what you're doing on the website, where you're going, pulling up other information that you care about, right? Part of your navigation can be done with cookies. They go on and on in their usefulness, but.

[00:55:06] Part of the problem is that people are using them to track you online. So like Facebook and many others will go ahead and have their cookies on other websites. So they know where you're going, what you're doing, even when you're not on Facebook, that's by the way, part of. The Firefox browser's been trying to overcome here.

[00:55:31] They have a special fenced in mode that happens automatically when you're using Firefox on Facebook. Pretty good. Pretty cool. The apple iOS devices. Use a different mechanism. And in fact, they're already saying that Facebook and some of these others who sell advertiser, Infor advertisers information about you have really had some major losses in revenue because apple is blocking their access to certain information about you back to Javas.

[00:56:07] It's a programming language that they can use to do almost anything on your web browser. Bad guys have figured out that if they can get you to go to a website or if they can insert and add onto a page that you're visiting, they can then use. Your web browser, because it's basically just a computer to do what well, to mind Bitcoin or other cryptocurrencies.

[00:56:34] So you are paying for the electricity for them as your computer is sitting there crunching on, uh, these algorithms that they need to use to figure out how to find the next Bitcoin or whatever. Be, and you are only noticing that your device is slowing down. For instance, our friends over on the Android platform have found before that sometimes their phones are getting extremely hot, even when they're not using them.

[00:57:01] And we've found that yeah, many times that's just a. Bitcoin minor who has kind of taken over partial control of your phone just enough to mind Bitcoin. And they did that through your web browser and JavaScript. So you can now see some of the reasons that I go ahead and disable JavaScript on most websites I go to now, some websites aren't gonna work.

[00:57:24] I wanna warn you up front. If you go into your browser settings and turn off JavaScript, you are going. Break a number of websites, in fact, many, many websites that are out there. So you gotta kind of figure out which sites you want it on, which sites don't you want it on. But there's another problem that we have found just this week.

[00:57:45] And it is based on a study that was done. It's reported in ours Technica, but they found. A hundred thousand top websites, a hundred thousand top websites. These include signing up for a newsletter making hotel reservation, checking out online. Uh, you, you probably take for granted that you nothing happens until you hit submit, right?

[00:58:11] That used to be the case in web 1.0 days. It isn't anymore. Now I wanna point out we, I have thousands of people who are on my email list. So every week they get my, my, uh, insider show notes. So these are the top articles of the week. They are, you know, usually six to 10 articles, usually eight of them that are talking about cybersecurity, things of importance in.

[00:58:39] The whole radio show and podcast are based on those insider show notes that I also share with the host of all of the different radio shows and television shows that I appear on. Right. It's pretty, pretty cool. So they get that, but I do not use this type of technology. Yeah. There's some JavaScript that'll make a little sign up thing, come up at the top of the screen, but I am not using technology that is in your face or doing.

[00:59:08] What these people are doing, right? So you start filling out a form. You haven't hit cement. And have you noticed all of a sudden you're getting emails from. Right. It's happened to me before. Well, your assumption about hitting submit, isn't always the case. Some researchers from KU LUN university and university of Lue crawled and analyzed the top 100,000 websites.

[00:59:37] So crawling means they have a little robot that goes to visit the webpage, downloads all of the code that's on the page. And then. Analyzed it all right. So what they found was that a user visiting a site, if the, the user is in the European union is treated differently than someone who visits the site from the United States.

[01:00:01] Now there's a good reason for this. We've helped companies with complying with the GDPR, which are these protection rules that are in place in the European union. And that's why you're seeing so many websites. Mine included that say, Hey, listen, we do collect some information on you. You can click here to find out more and some websites let you say no, I don't want you to have any information about me.

[01:00:26] We collect information just so that you can navigate the site properly. Okay. Very basic, but that's why European union users are treated differently than those coming from the United States. So this new research found that over 1800 websites gathered an EU user's email address without their consent. So it's almost 2000 websites out of the top 100,000.

[01:00:54] If you're in the EU and they found. About well, 3000 websites logged a us user's email in some form. Now that's, before you hit submit. So you start typing in your email, you type in your name and you don't hit submit. Many of the sites are apparently grabbing that information, putting it into the database and maybe even started using it before you gave them explicit permission to do.

[01:01:27] Isn't that a fascinating and the 1800 sites that gathered information on European news union users without their consent are breaking the law. That's why so many us companies decided they had to comply with the GDPR because it's a real big problem. So these guys also crawled websites for password leaks and May, 2021.

[01:01:55] And they found 52 websites where third parties, including Yex Yex is. Big Russian search engine a and more were collecting password data before submission. So since then the group went ahead and let the websites know what was happening, what they found, uh, because it's not necessarily intentional by the website itself.

[01:02:21] It might be a third party, a third party piece of software. That's doing it. They, they informed those sites. Hey, listen, you're collecting user data before there's been explicit consent to collect it. In other words, you, before you hit the submit button and they thought, wow, this is a very surprising, they thought they might find a few hundred website, but.

[01:02:45] Course of a year now they found that there were over 3000 websites really that were doing this stuff. So they presented their findings at Usenet. Well, actually they haven't presented 'em yet. Cuz it's gonna be at use N's. In August and these are what they call leaky forums. So yet another reason to turn off JavaScript when you can.

[01:03:09] But I also gotta add a lot of the forums do not work if JavaScript's not enabled. So we gotta do something about it. Uh, maybe complain, make sure they aren't clutching your data. Maybe I should do a little course on that one so you can figure out are they doing it before even giving permission? Anyhow, this is Craig Peter son.

[01:03:29] Visit me online. Craig Peter son.com and sign up for that. No obligation inside your show notes.

[01:03:36] We are shipping all kinds of military equipment over to Ukraine. And right now they're talking about another $30 billion worth of equipment being shipped to what was the world's number one arms dealer - Ukraine.

[01:03:53] I'm looking right now at an article that was in the Washington post. And you know, some of their stuff is good.

[01:04:01] Some of their stuff is bad, I guess, kinda like pretty much any media outlet, but they're raising some really good points here. One of them is that we are shipping some pretty advanced equipment and some not so advanced equipment to Ukraine. To help them fight in this war to protect themselves from Russia.

[01:04:24] Now, you know, all of that, that's, that's pretty common. Ultimately looking back in history, there have been a lot of people who've made a lot of money off of wars. Many of the big banks financing, both sides of wars. Going way, way back and coming all the way up through the 20th century. And part of the way people make money in war time is obviously making the equipment, the, and supplies and stuff that the armies need.

[01:04:57] The other way that they do it is by trading in arms. So not just the supplies. The bullets all the way through the advanced missile systems. Now there's been some concerns because of what we have been seen online. We've talked about telegram here before, not the safest web, you know, app to use in order to keep in touch.

[01:05:24] It's really an app for your phone and it's being used. Ukraine to really coordinate some of their hacker activities against Russia. They've also been using it in Russia, te telegram that is in order to kind of communicate with each other. Ukraine has posted pictures of some of the killed soldiers from Russia and people have been reaching out to their mothers in Russia.

[01:05:53] They've done a lot of stuff with telegram it's interest. And hopefully eventually we'll find out what the real truth is, right? Because all sides in the military use a lot of propaganda, right? The first casualty in war is the truth. It always has been. So we're selling to a country, Ukraine that has made a lot of money off of selling.

[01:06:19] Been systems being an inter intermediary. So you're not buying the system from Russia? No, no. You're buying it from Ukraine and it has been of course, just as deadly, but now we are sending. Equipment military great equipment to Ukraine. We could talk about just that a lot. I, I mentioned the whole lend lease program many months ago.

[01:06:45] Now it seems to be in the news. Now takes a while for the mainstream media to catch up with us. I'm usually about six to 12 weeks ahead of what they're talking about. And so when we're talking about Lynn Le, it means. We're not giving it to them. We're not selling it to them. We're just lending them the equipment or perhaps leasing it just like we did for the United Kingdom back in world.

[01:07:10] Wari, not a bad idea. If you want to get weapons into the hands of an adversary and not really, or not an adversary, but an ally or potential ally against an adversary that you have, and they have. But part of the problem is we're talking about Ukraine here. Ukraine was not invited in NATO because it was so corrupt.

[01:07:33] You might remember. they elected a new president over there that president started investigating, hired a prosecutor to go after the corruption in Ukraine. And then you heard president Joe Biden, vice president at the time bragging about how he got this guy shut down. Uh, yeah, he, he got the prosecutor shut down the prosecutor that had his sights on, of course hunter Biden as well as other people.

[01:08:00] So it it's a real problem, but. Let's set that aside for now, we're talking about Ukraine and the weapon systems we've been sending over there. There have been rumors out there. I haven't seen hard evidence, but I have seen things in various papers worldwide talking about telegrams, saying. That the Ukrainians have somehow gotten their hands on these weapons and are selling them on telegram.

[01:08:30] Imagine that, uh, effectively kind of a dark web thing, I guess. So we're, we're saying, well, you know, Biden administration, uh, you know, yeah. Okay. Uh, that, that none of this is going to happen. Why? Well, because we went ahead and we put into the contracts that they could not sell or share or give any of this equipment away without the explicit permission of the United States government.

[01:09:01] Well, okay. That, that kind of sounds like it's not a bad idea. I would certainly put it into any contract like this, no question, but what could happen here? If this equipment falls into the hands of our adversaries or, or other Western countries, NATO countries, how do you keep track of them? It it's very hard to do.

[01:09:22] How do you know who's actually using them? Very hard to do so enforcing these types of contracts is very difficult, which makes a contract pretty weak, frankly. And then let's look at Washington DC, the United States, according to the Washington post in mid April, gave Ukraine a fleet of I 17 helicopter.

[01:09:49] Now these MI 17 helicopters are Russian, originally Soviet designs. Okay. And they were bought by the United States. About 10 years ago, we bought them for Afghan's government, which of course now has been deposed, but we still have our hands on some of these helicopters. And when we bought them from Russia, We signed a contract.

[01:10:16] The United States signed a contract promising not to transfer the helicopters to any third country quote without the approval of the Russian Federation. Now that's according to a copy of the certificate that's posted on the website of Russia's federal service on military technical cooperation. So there you.

[01:10:38] Russia's come out and said that our transfer, those helicopters has grossly violated the foundations of international law. And, and you know, what they, it has, right. Arms experts are saying that Russia's aggression Ukraine more than justifies us support, but the violations of the weapons contracts, man, that really hurts our credibility and the, our we're not honoring these contracts.

[01:11:06] How can we expect Ukraine to honor those contracts? That's where the problem really comes in. And it's ultimately a very, very big problem. So this emergency spending bill that it, you know, the $30 billion. Makes Ukraine, the world's single largest recipient of us security assistance ever. They've received more in 2022 than United States ever provided to Afghanistan, Iraq, or Israel in a single year.

[01:11:40] So they're adding to the stockpiles of weapons that we've already committed. We've got 1400 stinger anti-aircraft systems, 5,500 anti tank, Mitch missiles, 700 switch blade drones, nine 90. Excuse me, long range Howards. That's our Tillery 7,000 small arms. 50 million rounds of ammunition and other minds, explosives and laser guided rocket systems, according to the Washington post.

[01:12:10] So it's fascinating to look. It's a real problem. And now that we've got the bad guys who are using the dark web, remember the dark web system that we set up, the onion network. Yeah. That one, uh, they can take these, they can sell them, they can move them around. It is a real problem. A very big problem. What are we gonna do when all of those weapons systems come back aimed at us this time?

[01:12:40] You know, it's one thing to leave billions of dollars worth of helicopters, et cetera, back in Afghanistan is the Biden administration did with their crazy withdrawal tactic. Um, but at least those will wear out the bullets, missile systems, Howard, yours, huh? Different deal.

[01:13:01] It seems like the government calls war on everything, the war against drugs or against poverty. Well, now we are looking at a war against end to end encryption by government's worldwide, including our own.

[01:13:18] The European union is following in America's footstep steps, again, only a few years behind this time.

[01:13:27] Uh, but it's not a good thing. In this case, you might remember a few have been following cybersecurity. Like I have back in the Clinton administration, there was a very heavy push for something called the clipper chip. And I think that whole clipper chip. Actually started with the Bush administration and it was a bad, bad thing, uh, because what they were trying to do is force all businesses to use this encryption chip set that was developed and promoted by the national security agency.

[01:14:04] And it's supposed to be an encryption device that is used to secure, uh, voice and data messages. And it had a built in. Back door that allowed federal state, local law enforcement, anybody that had the key, the ability to decode any intercepted voice or data transmissions. It was introduced in 93 and was thank goodness.

[01:14:32] Defunct by 1996. So it used something called skip Jack man. I remember that a lot and it used it to transfer dilly or Diffy excuse me, Hellman key exchange. I've worked with that before crypto keys. It used, it used the, uh, Des algorithm, the data encryption standard, which is still used today. And the Clinton administration argued that the clipper chip was.

[01:14:59] Absolutely essential for law enforcement to keep up with a constantly progressing technology in the United States. And a lot of people believe that using this would act as frankly, an additional way for terrorists to receive information and to break into encrypted information. And the Clinton administration argued that it, it would increase national security because terrorists would have to use it to communicate with outsiders, bank, suppliers, contacts, and the government could listen in on those calls.

[01:15:33] Right. Aren't we supposed to in United States have have a right to be secure in our papers and other things, right? The, the federal government has no right to come into any of that stuff unless they get a court order. So they were saying, well, we would take this key. We'll make sure that it's in a, a lock box, just like Al gore social security money.

[01:15:55] And no one would be able to get their hands on it, except anyone that wanted to, unless there was a court order and you know how this stuff goes, right. It, it just continues to progress. And. A lot worse. Well, there was a lot of backlash by it. The electronic privacy information center, electronic frontier foundation boast, both pushed back saying that it would not.

[01:16:20] Only have the effect of, of not, excuse me, have the effect of this is a quote, not only subjecting citizens to increased impossibly illegal government surveillance, but that the strength of the clipper trips encryption could not be evaluated by the public as its design. Was classified secret and that therefore individuals and businesses might be hobbled with an insecure communication system, which is absolutely true.

[01:16:48] And the NSA went on to do some things like pollute, random number generators and other things to make it so that it was almost impossible to have end-to-end encrypted data. So we were able to kill. Many years ago. Now what about 30 years ago? Uh, when they introduced this thing? Well, it took a few years to get rid of it, but now the EU is out there saying they want to stop end, end encryption.

[01:17:16] The United States has already said that, or the new director of Homeland security has, and as well as Trump's, uh, again, Homeland security people said we need to be able to break the. And, and we've talked about some of the stories, real world stories of things that have happened because of the encryption.

[01:17:37] So the EU has now got a proposal forward that would force tech companies to scan private messages for child sexual abuse material called CSAM and evidence of grooming. Even when those messages are supposed to be protected by end to end encrypt. So we know how this goes, right? It, it starts at something that's, everybody can agree on, right?

[01:18:05] This child, sexual abuse material, uh, abductions of children, all, you know, there's still a lot of slavery going on in the world. All of that stuff needs to be stopped. And so we say, yeah, yeah. Okay. That makes a whole lot of sense, but where does it end? Online services that receive detection orders. This is from ours Technica under the pending European union legislation would have obligations concerning the detection, the reporting, the removal and blocking of known and new.

[01:18:38] Child sexual abuse material as well as solicitation of children. So what we're starting to see here in the us is some apps, some companies that make smartphones, for instance, looking at pictures that are sent and shared to see if it looks like it might be pornographic in some way. because again, we're seeing younger kids who are sending pictures of each other naked or body parts naked to others.

[01:19:04] If you can believe that. Absolutely incredible. But what happens when you send them using an end-to-end encrypted app? Now, my advice for people who want to keep information private, you're a business person you're working on a deal. You don't go to Twitter like Elon Musk and put it out there for the world to.

[01:19:26] Although, I'm sure he's got some ulterior motives in doing that. You use an app called signal. That's certainly the best one that's out there right now. It provides a whole lot of encryption and privacy, and even has some stuff built in to break the software. That's often used to break into the end to end encryption systems.

[01:19:48] So they're trying to get this in place here. They're calling it an important security tool. But it's ordering companies to break that end to end encryption by whatever technological means necessary. It it's gonna be hard because frankly it's gonna be impossible for them to enforce this because you can take encrypted data and make it look like almost.

[01:20:11] Anything, and man has that happened for a long time. Think of the micro dots, way back when Seline world, world war II and on, they were very popular there's techniques to encrypt data and embedded in a photograph and make it almost impossible to detect. So again, they're, they're not going to get to do what they're hoping to do.

[01:20:37] And, and I think that's an important thing for everybody. Pay pay close attention to, so they do want to get rid of end to end there's WhatsApp out there, which I don't really trust cuz is owned by Facebook, but that's supposedly end to end. There's end to end encryption on apple iMessage, although up.

[01:20:57] Apparently, there are some ways to get into that. I think apple is now maintaining a secondary key that they can use to decrypt, but the back doors that the us has called for and other people have called for. Have been pushed back by companies like apple Apple's CEO, Tim cook, opposed government mandated back doors.

[01:21:20] Of course, apple got a major backlash from security experts when unveiled a plan to have iPhones and other devices, scan user photos for child sexual abuse images. That's what I was referring to earlier. And apple put that plan on hold and promised to make changes. But this is apple all over again. And it's hard to say what's the least privacy intrusive way, because if the is S P can read them all, if the company that's providing you with the app that you're using to send the message.

[01:21:53] Can read them all, how much privacy is there and if they can read it, who else can read it and what can be done with it? Blackmail has happened many times in the past because someone got their hands on something. So what happens when a, a Congressman or the military or someone in the military uses that that's another problem.

[01:22:14] Because if we don't know the way the encryption is is, is, uh, being used or is made just like, was true with a clipper chip. And then we move on to the next step, which is okay. So what do we do now with this data that we're storing? Are they going to keep that data confidential? Can they keep it outta the hands of the criminals.

[01:22:38] We've certainly found that they just haven't been able to. And if you're talking about grooming, which is what the European union wants. In other words, someone that's trying to get a child to the point where they're doing something that would be abhorrent. Uh, you've got to. Look at all of the, all of the messages, you have to have them analyzed by some sort of an AI artificial intelligence, and then ultimately analyzed by people.

[01:23:05] It it's just gonna get worse and worse. Right? This is the most sophisticated mass surveillance machinery. That has ever been deployed outside of China in the USSR. It, it's absolutely incredible when you look at it from a cryptographic standpoint. And again, we understand protecting the children. We all want to do that, but how far will this end up going?

[01:23:29] I also wanna point out that my. New, uh, insider show notes that I've been sending out over the last few weeks have had some amazing responses from people. I I've had people saying that this is what they look for in their mailbox. It's the first piece of email they read that it's the most relevant news that they get.

[01:23:49] But you can only get it one way and that's by going to Craig peterson.com, you can sign up there. It's easy enough to do. There's no obligation on your part, right? This is not my paid newsletter. This is absolutely free. And it's incredibly valuable. Plus I'll also be sending you once a week-ish a small training, just, it takes you a few minutes to read.

[01:24:14] I just last week went through the firewall in your windows machine, the firewall in. And gave you step by step instructions. Is it turned on? What is it doing? What should it do? How do you turn it on and how do you use it? So you can only get that one way and that's, if you are on my email list, so it's important to be there.

[01:24:36] And if you have any questions you can hit reply to. Any of those emails, whether it's the training or if it's the insider show notes, just hit re reply. And I'll go ahead and answer your question. You might have to wait a few days cuz I can get pretty busy sometimes, but always answer. So me, me@craigpeterson.com.

[01:24:57] Anybody can send me email and you can also text me at 6 1 7 503 2 2 1 6 1 7 500. 3, 2, 2, 1 with any questions. Well, that's it for right now, there is so much more. Make sure you sign up right now.

View Details

How Private is Crypto? What About WhatsApp and Signal?

Cryptocurrencies were thought to be like the gold standard of security, of having your information stay private. Maybe you don't want to use regular currency and transactions. It's all changed.

[Automated transcript follows.]

[00:00:14] We have had such volatility over the years when it comes to what are called cryptocurrencies.

[00:00:21] Now I get a lot of questions about cryptocurrencies. First of all, let me say, I have never owned any cryptocurrencies and I do not own any crypto assets at all. Most people look at crypto currencies and think of a couple of things. First of all, an investment. An investment is something that you can use or sell, right?

[00:00:42] Typically investments you don't really use. It's like a house. Is it an investment? Not so much. It's more of a liability, but people look at it and say listen, it went from what was a 10,000. Bitcoins to buy a pizza to, it went up to $50,000 per Bitcoin. There's a pretty big jump there.

[00:01:03] And yeah, it was pretty big. And of course, it's gone way down and it's gone back up and it's gone down. It's gone back up. But the idea of any kind of currency is can you do anything with the currency? You can take a dollar bill and go and try and buy a cup of coffee. Okay. A $10 bill and buy a cup of coffee in most places anyways.

[00:01:26] That sounds like a good idea. I could probably use a cup of coffee right now and get a tickle on my throat. I hate that. But if you have something like Bitcoin, where can you spend it? You might remember Elon Musk was saying, yeah, you can use Bitcoin to buy a Tesla. Also Wikipedia would accept donations.

[00:01:45] Via Bitcoin, there were a number of places online that you could use. Bitcoin. In fact, there's a country right now in south central America that has Bitcoin as its currency. That's cool too. When you think about it, what is, so what are you gonna do? Latin American country? I'm trying to remember what it is.

[00:02:05] Oh yeah. It's all Salvador. The first country in the world to adopt Bitcoin is an official legal tender. Now there's a number of reasons they're doing that and he can do it basically. If you got a dictator, you can do almost anything you want to. So in El Salvador, they've got apps that you can use and you can go and buy a tree taco using Bitcoin using their app.

[00:02:31] So there you go. If you have Bitcoin, you can go to El Salvador and you can buy all of the tacos and other basic stuff you might wanna buy. But in general, No you can't just go and take any of these cryptocurrencies and use them anywhere. So what good are they as a currency? we already established that they haven't been good as an investment unless you're paying a lot of attention and you're every day buying and selling based on what the movement is.

[00:02:59] I know a guy that does exactly that it's, he's a day trader basically in some of these cryptocurrencies, good for. But in reality, is that something that makes sense in a long term? Is that going to help him long term? I don't know. I really don't because again, there's no intrinsic value.

[00:03:18] So some of the cryptocurrencies have decided let's have some sort of intrinsic value. And what they've done is they've created what are generally known as stable coins. And a stable coin is a type of cryptocurrency that behind it has the ability to be tied to something that's stable. So for instance, one that really hit the news recently is a stable coin that is tied to the us dollar.

[00:03:46] And yet, even though it is tied to the us dollar and the coin is a dollar and the dollar is a coin. They managed to get down into the few pennies worth of value, kinda like penny. so what good was that, it has since come back up, some are tied to other types of assets. Some of them say we have gold behind us.

[00:04:09] Kinda like what the United States used to do back when we were on the gold standard. And we became the petrol dollar where countries were using our currency are us dollars, no matter which country it was to buy and sell oil. Things have changed obviously. And we're not gonna talk about. The whole Petro dollar thing right now.

[00:04:30] So forget about that. Second benefit. Third benefit is while it's crypto, which means it's encrypted, which means we're safe from anybody's spine on us, anybody stealing it. And of course that's been proven to be false too. We've seen the cryptocurrencies stolen by the billions of dollars. We've seen these cryptocurrencies lost by the billions of dollars as well.

[00:04:58] That's pretty substantial. We get right down to it, lost by the billions because people had them in their crypto wallets, lost the password for the crypto wallet. And all of a sudden, now they are completely out of luck. Does that make sense to you? So the basic. Idea behind currency is to make it easier to use the currency than to say, I'll trade you a chicken for five pounds of nail.

[00:05:25] Does that make sense to you? So you use a currency. So you say the chicken is worth five bucks. Actually chicken is nowadays is about $30. If it's a LA hen and those five pounds of nails are probably worth about $30. So we just exchanged dollars back and forth. I think that makes a lot of sense. One of the things that has driven up the value of cryptocurrencies, particularly Bitcoin has been criminal marketplaces.

[00:05:53] As you look at some of the stats of ransoms that are occurring, where people's computers are taken over via ransomware, and then that person then pays a ransom. And what happens when they pay that ransom while they have to go find an exchange. Pay us dollars to buy cryptocurrency Bitcoin usually. And then they have the Bitcoin and they have to transfer to another wallet, whether or not the bad guys can use the money.

[00:06:25] Is a, again, a separate discussion. They certainly can than they do because some of these countries like Russia are going ahead and just exchanging the critical currencies for rubs, which again, makes sense if you're Russia. Now we have a lot of criminals that have been using the Bitcoin for ransoms businesses.

[00:06:49] Publicly traded businesses have been buying Bitcoin by the tens of millions of dollars so that they have it as an asset. In case they get ransom. Things have changed. There's a great article in NBC news, by Kevin Collier. And Kevin's talking about this California man who was scammed out of hundreds of thousands of dollars worth of cryptocurrency.

[00:07:15] Now this was a fake romance scam, which is a fairly common one. It. It tends to target older people who are lonely and a romance starts online and they go ahead and talk and kind of fall in love. And it turns out she or he has this really almost terminal disease. If only they had an extra, a hundred thousand dollars to pay for the surgery.

[00:07:45] You, you know the story, so he was conned out of the money. What's interesting to me is how the investigation and investigative ability has changed over the years. Probably about five years ago, I sat through a briefing by the secret service and. In that briefing, they explained how they had gone and very, quite cleverly tracked the money that was being sent to and used by this dark web operator who ran a site known as a silk road.

[00:08:22] And that site was selling illegal things online. Oh, and the currency that they were tracking was Bitcoin. Yes, indeed. So much for cryptocurrency being secure it, five years ago, the secret service was able to do it. The FBI was able to do it and they couldn't do a whole lot about it. But part of the problem is all of your transactions are a matter of public record.

[00:08:52] So if someone sends you a fraction of a Bitcoin. That is now in a ledger and that ledger now can be used because when you then spend. Fraction of a Bitcoin somewhere else, it can be tracked. It is tracked is a hundred percent guaranteed to be tracked. And once it's tracked government can get in.

[00:09:15] Now, in this case, a deputy district attorney in Santa Clara county, California, was able to track the movement of the cryptocurrency. Yeah. So this district attorney, okay. Deputy district attorney, not the FBI, not the secret service, not the national security agency, a local district attorney in Santa Clara county, California, not a particularly huge county, but.

[00:09:44] She was able to track it. And she said that she thinks that the scammer lives in a country where they can't easily extradite them. And so they're unlikely to be arrested at any time soon. So that includes countries like Russia that do not extradite criminals to the United States. Now getting into the details.

[00:10:03] There's a great quote from her in this NBC news article, our bread and butter these days really is tracing cryptocurrency and trying to seize it and trying to get there faster than the bad guys are moving it elsewhere, where we can't. Grab it. So she said the team tracked the victim's money as it bounced from one digital wallet to another, till it ended up at a major cryptocurrency exchange where it appeared the scammer was planning to launder the money or cash out, they sent a warrant to the exchange.

[00:10:35] Froze the money and she plans to return it to the victim. That is a dramatic reversal from just a few years back when cryptocurrencies were seen as a boon for criminals. Amazing. Isn't it? Stick around. We get a lot more to talk about here and of course, sign up online Craig peterson.com and get my free newsletter.

[00:11:01] There have been a lot of efforts by many companies, Microsoft, apple, Google, to try and get rid of passwords. How can you do that? What is a password and what are these new technologies? Apple thinks they have the answer.

[00:11:17] Passwords have been the bane of existence for a long while. And if you'd like, I have a special report on passwords, where I talk about password managers, things you can do, things you should do in order to help keep your information safe, online things like.

[00:11:34] Bank accounts, et cetera. Just email me, Craig peterson.com and ask for the password special report and I'll get it to you. Believe me it's self-contained it's not trying to get you to buy something. Nothing. It is entirely about passwords and what you can do again, just email me, me@craigpeterson.com and we'll get right back with you.

[00:11:56] Give us a couple of days, passwords are a problem. And over the years, the standards for passwords have changed. I remember way back when some of the passwords might be 2, 3, 4 characters long. and back then, those were hard to crack. Then Unix came along. I started using Unix and when was that?

[00:12:16] Probably about 81. And as I was messing around with Unix, I. They used to had a couple of changes in how they did passwords. They added assault to it. They used basically the same cipher that the Germans used in world war II, that enigma cipher, which again was okay for the times today, we have much more powerful ciphers and the biggest concern right now, amongst real cybersecurity people.

[00:12:43] Government agencies is okay. So what are we going to do when these new quantum computers come along with their artificial intelligence and other things, that's going to be a bit of a problem because quantum computers are able to solve problems in fractions of a second. Even that traditional computers cannot solve it.

[00:13:10] It's a whole different thing. I want you to think. Something here. I, if you have a handful of spaghetti now we're talking about hard spaghetti, not cooked spaghetti and they all dried out and they are a varying links. How could you sort those into the smallest to largest, if you will, how could you find which ones were the longest, perhaps?

[00:13:37] Which ones were the shortest? There's an analog way of doing that and there's a digital way of doing that. So the digital way for the computer would be. To measure them all and compare the measurements and then identify how long the longest one was. And then maybe you'd have to go back and try and find that.

[00:13:55] So you can imagine that would take some time, the analog way of doing that. Cuz there still are analog computers out there and they do an amazing job in certain tasks, but the analog way of doing that is okay. So you take that bundle of various length spaghetti and you slam it on the table. What's gonna happen while those pieces of dried spaghetti are going to self align, right?

[00:14:22] The shortest ones are going to be down at the bottom and the tallest one's gonna be sticking out from the top. So there you go. There's your tallest, your longest pieces of spaghetti, and it's done. Instantly. So that's just an idea here, quantum, computing's not the same thing, but that's a comparison really of digital and analog computers, but it's the same type of thing.

[00:14:45] Some of these problems that would take thousands of years for digital computer. To work out, can just take a fraction of a second. It's absolutely amazing. So when we're looking at today's algorithms, today's programs for encrypting things like military information, secret telegrams, if you will going back and forth in inside the secretary of state embasies worldwide.

[00:15:10] Today they're considered to be quite secure, but with quantum computing what's gonna happen. So there are a lot of people out there right now who are working on trying to figure out how can we come up with an algorithm that works today with our digital computers and can be easily solved by quantum computer.

[00:15:34] We have a pretty good idea of how quantum computers are going to work in the future, how they work right now, but this really gets us to the next level, which is cool. Franklin. That's a little bit here about cybersecurity. How about you and your password? How does this all tie in?

[00:15:51] There are a few standards out there that people have been trying to pass is it's no longer the four character password you might remember. Oh, it needs to be eight to 10 characters, random mix of upper lowercase, special digits, character numbers. You remember those? And you should change it every 30 days.

[00:16:09] And those recommendations changed about three or four years ago when the national Institute of standards and technology said, Hey guys pass phrase is much better than the, what we've been doing because people are gonna remember it and it can be longer. So if you are using I have some past phrases I use that are 30 characters or more.

[00:16:33] And I mix up the case and I mix up mix ins on special characters and some numbers, but it's a phrase that I can remember and I have different phrases for different websites. Cause I use a password manager right now. I have about 3,100 entries in my password manager. That's a lot. And I bet you have a lot more passwords or at least a lot more websites and accounts than you realize.

[00:17:03] And so that gets to be a real problem. How do you make all of this work and make it easy for people? One of the ways that that. They're looking at using is something called the Fido alliances technique. And the idea behind Fido is actually similar to what I do right now. Cause I use one password.com.

[00:17:24] I have an app on my phone and the phone goes ahead and gives me the password. In fact, it'll. Put it in. I have plugins in my browsers. It'll put it right into the password form on the website. And then it'll ask me on my phone. Hey, is that really you? And I'll say yes, using duo and TA I'm logged in it's really quite cool.

[00:17:48] Fido is a little different than that, but the same, the whole idea behind Fido is you registered a website and the website will send a request to the Fido app. That's on your phone. So now on your phone, you'll use biometrics or maybe one time pass key, those six digit keys that change every 30 seconds.

[00:18:13] And so now you on your phone, you say yeah. That's me. That's good. That's me. Yeah. Okay. And then the app will exchange with the website using public key cryptography. A public key and it's gonna be unique public key for that website. So it'll generate a private key and a public key for that website.

[00:18:35] And now TA a, the website does not have your password and cannot get your password. And anytime you log in, it's going to ask you on your smartphone. Is this. And there's ways beyond smartphones. And if you wanna find out more about passwords, I've got, again, that free, special report, just Craig peterson.com.

[00:18:59] Email me, just email me@craigpeterson.com and I'll make sure we send that off to you and explains a lot about passwords and current technology. So Fido is one way of doing this and a few different companies have gone ahead and have invested some. Into final registration, because it requires changes on the websites as well in order to.

[00:19:25] With Fido. Now you might use a pin, you might use the biometrics, et cetera, but apple has decided they've come up with something even better. Now there's still a lot of questions about what apple is doing, but they are rolling it into the next release of iOS and also of Mac operating system. And you'll be able to use that to secure.

[00:19:48] Log into websites. I think Apple's gonna get a lot of traction on this and I think it's gonna be better for all of us involved here. We'll see. There's still a lot of UN unanswered questions, but I'll keep you up to date on this whole password technology stick around.

[00:20:08] There are ways for us to communicate nowadays easy ways, but are the easy ways, the best ways, the question here, frankly. And part of this answer has to do with WhatsApp and we'll talk right now.

[00:20:23] Many people have asked me about secure messaging. You probably know by now that sending text messages is not secure.

[00:20:34] In fact, it could be illegal if you have any personal information about. Patients or maybe employees, you just can't send those over open channels. So what apple has done for instance is they've got their messaging app and if the message is green, it's just reminding you that this is a text message. Now they stuck with green because that was the industry's standard.

[00:21:01] Green does not mean safe in the apple world when it comes to iMessage. Blue does. So they've got end to end encryption. So if the message is blue, that means the encryptions in place from side to side, there are on the other end of the spectrum. There are apps like telegram, which are not. Particularly safe.

[00:21:22] Now, telegram has pulled up it socks a little bit here, but in order to have end to end encryption and telegram, you have to manually turn it on. It is not on by default. I also personally don't trust telegram because of their background, things that they've done in the past. Avoid that.

[00:21:43] WhatsApp is something I've been asked about. I had a family member of a service member who was overseas, ask if WhatsApp was safe for them to communicate on cuz they didn't want third parties picking. Private messages, things you say and do online with friends and family are not necessarily things there are for public consumption.

[00:22:06] So the answer that I gave was yeah, you might remember Facebook getting WhatsApp. They bought it and deciding they were going to make some changes to the privacy settings in. now that was really a big mistake. They said we're gonna add advertisements. How are you going to effectively advertise?

[00:22:27] If you don't know what we're talking about, have you noticed advertising platforms? If you look up something or someone else in your house looks up something, if your neighbors are looking up, they assume that you might be interested in it as well. So what do they do? They go ahead and show you ads for that brand new pair of socks that you never really cared about, but because the algorithms in the background figured yeah, that's what you've been talking about.

[00:22:55] Let's pass out your pair of socks. So if Facebook is going to. Add into WhatsApp, what's going to happen. Are they going to be monitoring what you're saying? And then sending you some of these messages, right? These ads, because of that, a lot of people started looking for a more secure. Platform and that's frankly, where Moxi Marlin spike comes in a fun name, the bloom in this case, but he started a company called signal.

[00:23:30] He didn't just start it. He wrote the code for it, the server code, everything. And the whole idea behind signal was to have a guaranteed safe end to end way to communicate. A third party with a friend, a relative, et cetera. So signal is something that I've used in the past. And I used from time to time now, as well, depending on who I'm talking to.

[00:23:56] And it does allow you to send messages. It does allow you to talk. You can do all kinds of stuff with it. So now there's an issue with signal. It's disappointing. Moxi has stepped down from running signal. There's a company behind it in January, 2022. And he said, the company's begin off. They can run themselves.

[00:24:19] He's still on the board of direct. And the guy who's currently the head of signal is also a very privacy focused guy, which is really good too signal by the way is free. And you can get it for pretty much any platform you would care to have it for a very nice piece of software. I like what they've done.

[00:24:38] Now the problem is that some of those people at signal have decided that they should have a way of making payments inside signal. So a few months ago, they went ahead and added into signal, a piece of software that allows you to send. Payments online. Now this is a little concerning and the let's talk about some of the reasons for the concern.

[00:25:09] Basically what we're seeing is a cryptocurrency that Moxi himself helped to put in place now, I guess that's good cuz he understands it. It's supposedly a cryptocurrency that is privacy. Focused. And that's a good thing. What type of crypto is it? That's privacy focused. And how good is it going to be?

[00:25:34] Those are all good questions, but here's the biggest problem. I think that comes from this. We've got our friends at Facebook, again, trying to add crypto payments to their various messenger and other products. We're seeing that from a lot of these communication systems, cuz they can skim a little off the top legally, charge you a fee and then make their money that way. But. What happens when you put it into an encrypted messaging app? Bottom line, a lot of bad things can happen here because now all of a sudden you come under financial regulations, right? Because you are performing a financial. Function. So now potentially here, there could be criminal misuse of the app because you could have ransomware and they say, reach us on signal.

[00:26:33] Here's our signal account. And go ahead and send us crypto. it's called mobile coin by the way, this particular cryptocurrency. So now all of a sudden you are opening up the possibility of all kinds of bad things happening and your app signal, which was originally great for messaging now being used nefariously.

[00:26:57] I think that's a real problem. Now, when it comes to money transfer functions with cryptocurrencies to say that they're anonymous, I think is a hundred percent a misnomer because it's really pseudo anonymous. It's never completely anonymous. So now you've increased the legal attack surface here. So now the various regulators and countries around the world can say, Hey.

[00:27:26] This is no longer just a messaging app. You are using it to send money. We wanna track all money transactions. And so what does that mean? That means now we need to be able to break the encryption or need to shut down your app, or you need to stop the ability to send money. So the concern right now with signal is we really could have some legal problems with signal.

[00:27:53] And we could potentially cause some real life harm. On the other side of, this is what Moi Marlin spike has been really driving with signal over the years, which is we don't want anyone to be able to break into signal. So there's a particularly one Israeli based company that sells tools that you can buy that allow you to break into smartphone.

[00:28:20] And they're used by everybody from criminals. You can even buy some of these things on eBay. And they're used also by law enforcement agencies. So he found that there was a bug in one of the libraries that's used by this Israeli soft. To where that causes it to crash. And so he puts some code into signal, at least he threatened to that would cause any of the scanning software that tries to break into your smartphone to fail to crash.

[00:28:53] Yeah. Yeah. Cool. Greg Peterson here, online Craig peterson.com and really you are not alone.

[00:29:09] I got some good news about ransomware and some bad news about B E C business email compromise. In fact, I got a call just this just this week from someone who had in fact again, had their operating account emptied.

[00:29:27] Ransomware is a real problem, but it's interesting to watch it as it's evolved over the years.

[00:29:36] We're now seeing crackdowns driving down ransomware profits. Yes, indeed. Ransomware's ROI is dropping the return on investment. And so what we're starting to see is a drive towards more. Business email compromise attack. So we'll talk about those, what those are. And I have a couple of clients now that became clients because of the business email compromises that happened to them.

[00:30:10] A great article that was in this week's newsletter. You should have received it Tuesday morning from me. If you are signed up for the free newsletter. Craig peterson.com/subscribe. You'll get these usually Tuesday morning. It's my insider show notes. So you can get up to speed on some of the articles I'm talking about during the week that I talk about on the radio.

[00:30:38] And of course talk about here on the radio show and podcast and everything else as well. So what we're seeing here, according to dark readings, editor, Becky Bracken is some major changes, a pivot by the bad guys, because at the RSA conference, they're saying that law enforcement crackdowns try cryptocurrency regulations.

[00:31:05] We've been talking about that today and ransomware as a service operator. Downs are driving the return on investment for ransomware operations across the world all the way across the globe. So what is ransomware as a service? I think that's a good place to start because that has really been an Albert Cross around our next for a long time.

[00:31:30] The idea with ransomware is they get you to download some software, run some software that you really should not be running. That makes sense to you. So you get this software on your computer, it exfil trades files. So in other words, it takes files that you have sends them. Off to the bad guys. And then once it's done that, so it'll send like any word files, it finds Excel, other files.

[00:32:00] It might find interesting once it's done that, then it goes ahead and encrypts those files. So you no longer have access to them and it doesn't just do them on your computer. If you share a drive, let's say you've got a Gdrive or something else on your computer that is being mounted from either another computer or maybe a server.

[00:32:24] It will go ahead and do the same thing. With those files. And remember it, isn't just encrypting because if you have a good backup and by the way, most businesses that I've come into do not have a good backup, which is a real problem because their backups fail. They haven't run. I had one case where we helped the business out and it had been a year and a half since they had a successful backup and they had no.

[00:32:52] They were dutifully carrying home. These USB drives every day, plug in a new one in, and the backups were not running. Absolutely amazing. So anyhow, ransomware is a service then. So they've encrypted your files. They've exfiltrated. In other words, they've taken your files and then they demand a ran.

[00:33:14] So usually it's like this red screen that comes up and says, Hey all your files are belong to us and you need to contact us. So they have people who help you buy Bitcoin or whatever they're looking for. Usually it's Bitcoin and send the Bitcoin to them. And then they'll give you what's hopefully a decryption.

[00:33:38] Now what's particularly interesting about these decryption keys is they work about half of the time. So in other words, about half of the time, you'll get all your data back about half the time. You will not, it's just not good. So if you are a small operator, if you are just a small, bad guy and it's you and maybe somebody else helping you, you got your nephew there helping you out.

[00:34:03] How are you going to. Help these people that you're ransoming by the cryptocurrency. How are you going to threaten them with release of their documents online? Unless you have a staff of people to really help you out here? That's where ransomware's a service comes in. The whole idea behind RA is.

[00:34:25] You can just be a one man shop. And all you have to do is get someone to open this file. So you go ahead and register with the ransomware service provider and they give you the software and you embed your little key in there, so they know it's you. And then you send it off in an email. You might try and mess with those people to get them to do something they shouldn't do.

[00:34:49] And. That's all you have to do because once somebody opens up that file that you sent them, it's in the hand of these service guys and ransomwares the service guys. So the, these ransomwares of service people will do all of the tech support. They'll help people buy the Bitcoin. They'll help them pay the ransom.

[00:35:11] They'll help them recover files, to a certain extent. Does this make sense to you? Yeah, it's kinda crazy. Now I wanna offer you, I've got this document about the new rules for backup and again, it's free. You can get it. No problem. Just go ahead and email me, me@craigpeterson.com m@craigpeterson.com because the backups are so important and.

[00:35:38] Just like password rules have changed. The rules have changed for backups as well. So just drop me an email me@craigpeterson.com and ask for it and we'll make sure we send it off to you and is not trying to sell you more stuff. Okay. It's really is explaining the whole thing for you. I'm not holding anything back.

[00:35:54] These ransoms, the service operators, then get the payment from you and then pay a percentage anywhere from 80% to 50%, sometimes even lower to the person who ransom due. Isn't that just wonderful. So our law enforcement people, as well as in other countries have been going after the ransomware as a service providers, because if they can shut down.

[00:36:21] These RAs guys just shutting. One of them down can shut down thousands of small ransomware people. Isn't that cool works really well. So they have been shut down. Many of them there's one that just popped its head back up again. After about six months, we'll see how far they get, but it is a very big.

[00:36:46] Blow to the whole industry, ransomware really because of these O as a service operators has become a centralized business. So there's a small number of operators responsible for the majority of these thousands of hundreds of thousands of attacks. Really. It's probably worse than. So couple of dis big groups are left the KTI group and lock bit, and they've got more than 50% of the share of ransomware attacks in the first half of 2022.

[00:37:18] But now they're going after them. The feds. And I think that makes a whole lot of sense, because who do you go for while you go for the people who are causing the most harm and that's certainly them. So I expect they'll be shut down sometimes soon, too. Ransomware had its moment over the last couple of years, still a lot of ransomware out there, still a lot of problems, but now we're seeing B C business, email compromise tactics, and I did a.

[00:37:50] At television appearance, where I was working with the the newsmaker or whatever they call them, talking heads on that TV show and explaining what was happening. And the most standard tactic right now is the gift card swindle. I should put together a little video on this one, but it was all, it's all about tricking employees into buying bogus gift cards.

[00:38:18] So this good old fashioned Grif is still working. And what happened in our case is it was actually one of the newscasters who got an email, supposedly from someone else saying, Hey we wanna celebrate everybody. And in order to do that, I wanna give 'em all gift cards. So can you go out and buy gift cards?

[00:38:42] And so we messed around with them. It was really fun and said, okay what denomination, how many do you think we need? Who do you think we should give them to? And of course we knew what we were doing. Their English grammar was not very good. And it was really obvious that this was not.

[00:38:59] The person they were pretending to be. So that happens and it happens a lot. They got into a business email account, the email account of that newscaster. So they were able to go through their email, figure out who else was in the business, who was a trusted source inside of the business. So they could pretend that that they were that newscaster and send emails to this trusted source.

[00:39:31] And today these business email compromise attacks are aimed at the financial supply chain. And once these threat actors are inside, they look for opportunities to spoof vendor emails, to send payments to controlled accounts. And the worst case I know of this is a company that sent $45 million. To a scammer.

[00:39:57] And what happened here is the, this woman pretended to be the CEO who was out of the country at the time and got the CFO to wire the money to her. An interesting story. We'll have to tell it to you sometime, but it's a real problem. And we just had another one. We've had them in school districts, look, 'em up online, do a duck dot, go search for them and you'll find them right.

[00:40:24] Left and center because social engineering works. And frankly, business email compromise is a clear threat to businesses everywhere. I, as I mentioned, we had one listens to the show, contact us just last week. Again, $40,000 taken out of the operating account. We had another one that had a, I think it was $120,000 taken out of the operating account.

[00:40:53] And another one that had about $80,000 taken outta the operating account. Make sure you're on my newsletter. even the free one. I do weekly free trainings. Craig peterson.com. Make sure you subscribe now.

[00:41:10] Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? Did you fall victim for that? Hey, upload your contacts. We'll find your friends. They don't know where your data is.

[00:41:26] It's going to be a great time today because man. This whole thing with Facebook has exploded here lately.

[00:41:35] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes now, there's always a lot of rumors about different companies and particularly when they're big company and the news headlines are grabbing your attention.

[00:42:08] And certainly Facebook can be one of those companies. So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal data? It came from a leaked document. Yeah, exactly. So I, we find out a lot of stuff like that. I used to follow a website about companies that were going to go under and they posted internal memos.

[00:42:38] It basically got sued out of existence, but there's no way that Facebook is gonna be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So of course, if you're older, we used to call those TIAL waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

[00:43:08] So Facebook internally, they, their engineers are trying to figure out, okay, so how do we deal? People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

[00:43:31] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How are they all CATA categorized? Now we've got the European union. With their gen general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

[00:43:56] That's not my specialty. My specialty is the cybersecurity side. But in article five, this European law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected and used for a specific purpose and not reused for another purpose.

[00:44:34] So there's an example here that vice is giving in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, feature as well as. Advertisers. Yeah. Interesting. Eh, so Gizmoto with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice.

[00:45:01] Cuz this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now. And most people. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online and nothing.

[00:45:21] I think I probably even uploaded it back then thinking that'd be nice to see if I got friends here. We can start chatting, et cetera. According to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal me memo, this European regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leak document shows that Facebook may not even have the ability to limit.

[00:45:53] how it handles users data. Now I was on a number of radio stations this week, talking about this and the example I gave, I is just look at an average business from the time it start, Facebook started how right. You scrape in pictures of young women off of Harvard universities. Main catalog, contact page, and then asking people what do you think of this rate? This person rate that person and off they go, trying to rate them. Yeah. All that matters to a woman, at least according to mark Zuckerberg or all that matters about a woman is how she looks. Do I think she's pretty or not ridiculous what he was doing?

[00:46:35] I, it just, oh, that's Zuckerberg, right? That's. Who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then opening up even wider and wider.

[00:47:00] And of course, that also created demand cuz you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certain you're starting to collect data and you're making more money than God. So what do you do? You don't have to worry about inefficiencies.

[00:47:20] I'll tell you that. One thing you don't have to do is worry about, oh, GE we've got a lot of redundant work going on here. We've got a lot of teams working on basically the same thing. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that money to this group or that group.

[00:47:41] And they put together all of the basic information, that, that they want. They are. Pulling it out of this database and that database, and they're doing some correlation writing some really cool sequel queries with some incredible joins and everything else. And now that becomes part of the main code for Facebook.

[00:48:02] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And they, one of the groups inside Facebook says yeah here we go.

[00:48:25] Here's all of the information we have about everybody and it's free. Don't worry about it. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No but the Obama. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

[00:48:50] And according to this internal memo, they still don't know. They don't even know if they can possibly comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the us Canada of course, has their own Australia, New Zealand think about all the places.

[00:49:12] Facebook makes a lot of money. So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water.

[00:49:34] Okay. And it flows every. The document red. So how do you put that ink back in the bottle, in the right bottle? How do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from it? Apparently they don't even know where they got some of this information.

[00:49:58] This data from reminds me of the no fly list. You don't know you're on it and you can't get yourself off of it. It is crazy. So this document that we're talking about was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of a monetization strategy.

[00:50:22] And is the engine that powers Facebook's growth. Interesting problems. And I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And I've talked about as well along comes Elon Musk and he says wait a minute now.

[00:50:41] Now I can make Twitter way more profitable. We're gonna get rid of however many people it's well over a thousand, and then we are going to hire more people. We're gonna start charging. We're gonna be more efficient. You can bet all of these redundancies that are in Facebook are also there on Twitter. and Twitter also has to comply with all of these regulations that Facebook is freaking out about.

[00:51:09] It, for really a very good reason. So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does, but most companies, you grow. I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be, because it grew organically. You started out with a little consumer firewall, router and wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around.

[00:51:54] This is normal. This is not total incompetence on the part of the management, but my gosh, I don't know. Maybe they need an Elon Musk. Just straighten them out as well. Hey, stick around. I'll be right back and sign up online@craigpeterson.com.

[00:52:13] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian looters.

[00:52:30] This is really something, we know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that looting is kept to an absolute minimum.

[00:52:45] Certainly the Americans, the British, even the Nazis during world war II the the socialists they're in. Germany they tried to stop some of the looting that was going on. I think that's probably a very good thing, because what you end up with is just all of these locals that are just totally upset with you.

[00:53:10] I found a great article on the guardian and there's a village. Had been occupied for about a month by Russian troops and the people came back, they are just shocked to see what happened. They're giving a few examples of different towns. They found that alcohol was stolen and they left empty bottles behind food rappers, cigarette butts, thrown all over the place in apartments and homes.

[00:53:39] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the clothes. This is a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and lingerie. This is really something. It, the Soviets didn't do this, but now Russian.

[00:54:02] Military apparently does. So over the past couple of weeks, there've been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidences suggests looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

[00:54:29] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto Euro trucks, everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioners.

[00:54:53] Being shipped back, just you might use ups here, they have their equivalent over there. A lady here who was the head teacher in the school. She came back in, of course, found her home Lood and in the head teacher's office. she found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're gonna destroy it.

[00:55:19] They don't only leave anything behind. They found the Russians had taken most of the computers, the projectors and other electronic equipment. It's incredible. So let's talk about the turnaround here. A little. You might have heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

[00:55:38] So they get into the apple store. They grab laptops on iPads, no longer iPods, cuz they don't make those anymore. And I phones. And they take them and they run with them. Nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is they take some parts and use them in stolen equipment.

[00:56:03] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

[00:56:26] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, let's say they put 'em on wifi. They don't get a SIM card. They don't. service from T-Mobile or Verizon or whoever it might be. So now they disconnect to the wifi and it calls home, cuz it's gonna get updates.

[00:56:45] So on download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erased, et cetera.

[00:57:11] Now, police have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're doing things like putting them into Fairday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

[00:57:36] You steal it. It's not gonna do you much. Good. So one of the things the Russian stole when they were in it's called I think you pronounce it. Mela me pole which is again, a Erian city is they stole all of the equipment from a farm equipment dealership and shipped it to Chenia. Now that's according to a source in a businessman in the area that CNN is reporting on.

[00:58:06] So they shipped this equipment. We're talking about combines harvesters worth 300 grand a piece. They shipped it 700 miles. and the thieves were ultimately unable to use the equipment, cuz it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

[00:58:33] It's autonomous. It goes up and down the fields. Goes any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, of your property being very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

[00:58:58] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a, what not terribly profitable business. It certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? What they do is they lease it. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

[00:59:26] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not gonna come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

[00:59:51] You see where I'm going with this so that they can get their equipment in the hands of more farmers cuz the farmers can lease it. It costs them less. They don't have to have a big cash payment. You see how this all works. So when the Russian forces stole this equipment, that's valued. Total value here is about $5 million.

[01:00:11] They were able to shut it all. And obviously, if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and there's pros and cons to that. I think there's a lot of cons, but what are you gonna do? How's that gonna work for you? It. Isn't going to work for you.

[01:00:32] And they were able to track it. It had GPS trackers find out exactly where it was. That's how they know it was taken to Chenia and could be controlled remotely. And in this case, how'd they control it. They completely. Shut it off. Even if they sell the harvesters for spare parts, they'll learn some money, but they sure can be able to sell 'em for the 300 grand that they were actually worth.

[01:00:57] Hey, stick around. We'll be right back and visit me online@craigpeterson.com. If you sign up there, you'll be able to get my insider show note. And every week I have a quick five. Training right there in your emails, Craig Peter san.com. That's S O N in case you're wondering.

[01:01:22] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're gonna talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world.

[01:01:38] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

[01:01:49] We had improved all of their systems and their security and one of their. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine, all of a sudden TA, guess what it had ransomware on it. One of those big reds.

[01:02:12] Greens that say pay up is send us this much Bitcoin. And here's our address. All of that sort of stuff. And he called us up and said, what's going on here? What happened? First of all, don't bring your own machine into the office. Secondly, don't open up particularly encrypted files using the password that they gave.

[01:02:33] and thirdly, we stopped it automatically. It did not spread. We were able to completely restore his computer. Now let's consider here at the consequences of what happened. So he obviously was scared. And within a matter of a couple of hours, we actually had him back to where he was and it didn't spread.

[01:02:59] So the consequences there they weren't that bad. But how about if it had gotten worse? How about if they ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. Would, do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

[01:03:25] Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

[01:03:52] And if you're interested, I can send you, I've got something. I wrote up. Be glad to email it back to you. Obviously as usual, no charge. and you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

[01:04:15] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's two, two factor, first is they've encrypted your data. You can't get to it. And then the second side of that is okay I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they'll put it out there.

[01:04:38] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing you can lose your license for your business. You can U lose your ability to go ahead and frankly make loans and work with financial companies and financial instruments.

[01:05:00] It could be a very big deal. so there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And we, again, we've got a client that we picked up afterwards. That yes, indeed. They lost all of the money in their operating account.

[01:05:24] And then how do you make payroll? How do you do things? There's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

[01:05:44] One is by the way, KTI, which is a big ransomware gang that also got hacked after they said we are going to attack anyone that. That doesn't defend Vlad's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. First of all, the largest ransom demand is $50 million.

[01:06:11] And that was in 2021 to Acer big computer company. Now 37% of businesses were hit by ransomware. In 2021. This is amazing. They're expecting by 2031. So in about a decade, ransomware is gonna be costing about $265 billion a year. Now on average Ransomware costs businesses. 1.8, 5 million to recover from an attack.

[01:06:41] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? If you're a car dealer, you have a to print money, right? You're selling car model or cars from manufacturer X. And now you have the right to do that and they can remove that.

[01:07:03] How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, 20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom demand. So about her third paid ransom demand.

[01:07:27] Last. It's actually down. Cuz my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it's little better than 50%, but 65% of pain victims recovered their data.

[01:07:55] Now isn't that absolutely amazing. Now 57% of companies are able to recover the data using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get backed? Probably took weeks, right?

[01:08:19] For a regular computer over a regular internet line. Now restoring from backup's gonna be faster because your down link is usually faster than your uplink. That's not true for businesses that have real internet service ours. It's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

[01:08:39] So it's very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be incredibly expensive for you incredibly. So here you. The number one business types by industry for ransomware tax retail.

[01:09:13] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware, conscious of doing what, of keeping their data secure of having a good it team, a good it department. So there's your bottom line.

[01:09:40] Those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

[01:10:06] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to Craig peterson.com. And I'll also send you my special report on how to do passwords stick around will be right back.

[01:10:24] You and I have talked about passwords before the way to generate them and how important they are. And we'll go over that again a little bit in just a second, but there is a new standard out there that will eliminate the need for passwords.

[01:10:40] I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

[01:10:49] Yeah, 360, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements in, but you had a username.

[01:11:18] You had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang. And his password was always some sort of a combination of RA Lang. So it was always easy to guess what his password was. Today, it has gotten a lot worse today. We have devices with us all of the time.

[01:11:40] You might be wearing a smart watch. That requires a password. You of course probably have a smart phone. That's also maybe requiring a password, certainly after boots nowadays they use fingerprints or facial recognition, which is handy, but has its own drawbacks. But how about the websites? You're going to the systems you're using when you're at work and logging in, they all require passwords.

[01:12:10] And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to log. Now that's really an interesting thing, right?

[01:12:37] Just looking at it because we're so used to having this password only authentic. And of course the thing to do there is make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe mix.

[01:12:59] Upper lowercase a little bit. In those words, those are the best passwords, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cuz I use a completely different password for every website and right now, Let me pull it up.

[01:13:21] I'm using one password dot com's password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. Entries here in my password manager, 3,100. That is a whole lot of passwords, right? As well as software licenses and a few other things in there.

[01:13:48] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I really do like that. Some others that I've liked in the past include last pass, but they really messed. With some of their cybersecurity last year and I lost my faith in it.

[01:14:08] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless sign in. and they're gonna make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

[01:14:32] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're gonna work with the Fido Alliance and they're gonna create this passwordless future. Which I like this idea. So how does this work? Basically you need to have a smartphone.

[01:14:50] This is, I'm just gonna go with the most standard way that this is going to work here in the future. And you can then have a, a. Pass key. This is like a multifactor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, I'm giving a password and then it comes up and it asks me for a code.

[01:15:14] So I enter an a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password dot. In order to generate that code. So that's how I log into Microsoft sites and Google sites and all kinds of sites out there. So it's a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

[01:15:41] We have biometrics tied in as. so to log into our systems, I have to have a username. I have to have a password. I then am sent to a single sign on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

[01:16:06] Yeah, there's a lot there, but I have to protect my customer's data. Something that very few it's crazy. Actual managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list.

[01:16:29] I'll send that to you. That's what we're sending out right now for anyone who signs up new@craigpeterson.com. And if you'd like a copy of it and you're already on the list, just go ahead and email me M E. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing.

[01:16:47] So what will happen with this is you go to a website and it might come up with a QR code. So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again have it set up so that your phone requires a facial recognition or perhaps it'll require a fingerprint. And now you are in.

[01:17:09] Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year. You're going to see this available on apple devices, Google Microsoft platforms. And it really is simple, stronger authentication. That's what Fido calls it. But it is going to make your life a lot easy.

[01:17:33] It easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now I wanna talk about another thing here that has bothered me for a long time. I have a sister-in-law. who is in the medical field and gives prescriptions, doctor thing. And I think she's not quite a doctor.

[01:17:55] I can't remember what she has or she's an LPN or something. Anyhow. So she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions. And so I warned her about that saying, it is very bad to be using zoom because zoom is not secure.

[01:18:20] Never has been, probably never will be right. If you want secure, you. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure. So I talked to her about that and said, Hey, listen, you can't do this. You've really got to go another way here.

[01:18:42] And so she started using one of these mental or. Medical health apps. What I wanna talk about right now specifically are some checks that were just performed some audits on mental health apps. That's why I messed up a second ago, but what they looked at is that things are a serious problem there.

[01:19:08] And then in fact, the threat post is calling it creepy. Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise. So you can get on the horn with mental health, professional doctor or otherwise in order to help you here with your psychological or spiritual wellbeing.

[01:19:32] And people are sharing their personal and sensitive data with third parties and of 32 mental health and prayer mobile apps that were investigated by the open source organization. 28, 28 of the 32 were found to be inherently insecure and were given a privacy, not included label, including others here.

[01:19:57] So this is a report. That was released here by the open source organization, tied into Mozilla. Those are the Firefox people. They have what they call their minimum security standards. So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet.

[01:20:19] Even those minimum security standards. So these apps are dealing with some of the most sensitive men, mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal thoughts, domestic violence, eating disorders. And they are being just terrible with your security Mozilla researchers spent 255 hours or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed allowed week passwords. That range. One digit one as the password, 2, 1, 1, 1 while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data.

[01:21:23] So be very careful. Two of the apps better help a popular app that connects users with therapists and better stop suicide, which is of course a suicide prevention app have vague and messy. According to Mozilla privacy policies, they have little or no effect on actual. User data protection. So be very careful.

[01:21:45] And if you are a mental health professional, or a medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini training. They come out most weeks, just go to Craig peterson.com.

[01:22:11] Craig peterson.com. And I'll send you my special report on passwords and more.

View Details

Using Punchlists to Stop Ransomware

I really appreciate all of the emails I get from you guys. And it is driving me to do something I've never done before now. I've always provided all kinds of free information. If you're on my email list, you get great stuff. But now we're talking about cyber punch lists.

[Automated transcript follows]

[00:00:16] Of course, there are a number of stories here that they'll come out in the newsletter or they did, excuse me, go in the newsletters should have got on Tuesday morning.

[00:00:26] And that's my insider show notes, which is all of the information that I put together for my radio appearances radio shows. And. Also, of course, I sent it off to the hosts that these various radio stations. So they know what taught because, oh, who really tracks technology, not too many people. And I get a little off-put by some of these other radio hosts, they call themselves tech people, and they're actually marketing people, but.

[00:00:57] That's me. And that's why, if you are on my list, you've probably noticed I'm not hammering you trying to sell you stuff all the time. It's good. Valuable content. And I'm starting something brand new. Never done this before, but this is for you guys. Okay. You know that I do cybersecurity. As a business and I've been doing it now for more than three decades.

[00:01:22] I dunno if I should admit that right there. Say never say more than 17 years. Okay. So I've been doing it for more than 17 years and I've been on the internet now for. Oh, 40 years now. Okay. Back before it was even called the internet, I helped to develop the silly thing. So over the years, we've come up with a number of different strategies.

[00:01:43] We have these things that are called plan of action and milestones, and we have all kinds of other lists of things that we do and that need to be done. So what we're doing right now is we're setting up. So that you can just email me M e@craigpeterson.com. And I will go ahead and send you one of these punch lists.

[00:02:09] Now the punch lists are around one specific topic. We've got these massive. Punch lists with hundreds and hundreds of things on them. And those are what we use when we go in to help clean up the cybersecurity and accompany. So we'll go in, we'll do scans. We will do red team blue team, or we're attacking.

[00:02:30] We do all kinds of different types of scans using different software, trying to break in. We use the same tools that the hackers use in order to see if we can. Into your systems and if the systems are properly secured, so we do all of this stuff and then it goes into all of the paperwork that needs to be done to comply with whatever might be, it might be, they accept payment cards. It might be that they have. But information, which is healthcare information. And it might be also that they're a government contractor. So there are hundreds and hundreds of things that they have to comply with. Most of them are procedural. So we have all of this stuff.

[00:03:13] We do all of this stuff. And I was talking with my wife here this last week about it and said, yes, That's so much of this could be used by small companies that can't afford to hire my team to come in and clean things up. And I don't want them to suffer. So here's what we're doing. We're starting this next week.

[00:03:36] We have a punch list for you on email. So what are the things you can do should do for email? Just very narrow on email so that you can recognize a Fisher. Email, what you might want to do to lock down your outlook, if you're on windows or your Mac mail. So we're taking these massive spreadsheets that we have and we're breaking them up.

[00:04:03] So the first one that's available to you guys, absolutely. A hundred percent free. Is the one on email. So just send me an email. Me M e@craigpeterson.com. Now, remember I am, my business is a business to business, but almost everything in these various. Punch lists applies to individuals as well.

[00:04:27] So I got an email this last week from a guy saying, Hey, I'm 80 years old and retired and I don't know much about computers. And that's what got us thinking about. No, we need to be able to help him. We need to be able to help you out. Okay. And if you're a small business and we've dealt with a lot of them over the years, and as a small business, you just don't have the funds to bring in an expert, whether it's me or somebody else, although yeah.

[00:04:56] You want the best anyways. It it is going to allow you to do it yourself. Okay. So absolutely free. All of these punch lists on all of these topics. We're probably going to end up with more than a hundred of these punch lists. And all you do is email me M e@craigpeterson.com. Just let me know in there what you're interested in.

[00:05:19] So even if we haven't got that punch list broken down for you yet, we will go ahead and put that on the. To do right. We need the priorities. What kind of a priority should we have as we're putting these things together for free for people. And the only way we know is if you ask, so the first one's on email, you can certainly ask for email.

[00:05:39] We've got, as I said, more than a hundred others, that we think we're going to be able to pull out of the exact. Plan of action worksheets that we use so that you can go through this yourself, whether you're a home user or you are a small business or even a big business, we were talking with a gentleman who's probably listening right now, who has a business.

[00:06:06] They have three offices, they have some requirement because of the military contracts for high level. Cybersecurity. And they would work for him too. All right. So they, this is all of the punch list stuff. He probably know what a punch list is. It's used in the construction industry a lot, but in our case, it's indeed to do this.

[00:06:27] You need to do this, you need to do this. Okay. So that's what that's all about. So enough rambling on that. It's going to take us some time to get them all together. I'm also. And then her do more video stuff again, training. So just like on the radio show where we're talking about what's in the news, we're going to talk about watch what's in the news.

[00:06:49] When it comes to small businesses, what you should be paying attention to with of course, an emphasis on cyber security and. Putting those up on my website@craigpeterson.com. In fact, we've already got some up there already, and then we are going to also be putting them on YouTube and rumble. So if you don't like YouTube and Google, then you can certainly go to rumble.

[00:07:14] You'll see them there. But if you're on the email list, Starting to put links in the bottom of the emails. So you can go and watch those videos. If you're a video type person that you know, more visual. So it's, I think all good. And it's good news for everybody. And this is what happens, I think, as you get more mature, In the business.

[00:07:36] As I said, I've been on the internet for more than 40 years, helped develop some of that software that some of it's still in use today and now it's time to do more give back. And I really am trying to give back, okay, there's this isn't. This isn't a joke. No joke. So go ahead. Email me at Craig Peterson.

[00:07:57] Tell me which punch list that you would like. And I can also put you on my email list so that you get my insider show notes, and you can just do that yourself by going to Craig Peterson. Calm. You'll see right up at the top of the page. If you scroll down a little bit, it'll pop up. It's a big red bar that goes across the top.

[00:08:17] I try not to be too intrusive and you can sign up there for the newsletter. So you'll get some of these trainings automatically. You'll get my insider show notes, all of this stuff. It's absolutely free. Okay. This is my give back to help you out. It really is. Okay. As I mentioned at the very beginning.

[00:08:37] Peeve by some of these people that represent themselves as tech experts. And in fact, all they are marketers. We've got a client that decided that I was too expensive. My team. So they went out and shopped around, tried to find the cheapest company they could. And so now the company that they're bringing in is saying, you're saying Hey so how does this work?

[00:08:59] How do you do zero trust? Why do you have a firewall here? Why do you bother to have a direct fiber link between the offices? All this stuff? Because they need it. Okay. I get it. You use. Barracuda spam firewalls and Barracuda firewall holes it, yeah, this is a different league. Okay. So you're going to be getting these punch lists from me that are really going to help you understand and secure your systems.

[00:09:29] This isn't your average run of the mill, managed security services provider or managed services or break fix shop. You're getting it from the guy that the FBI. InfraGuard program went to, to do their trainings. That was me. Okay. So for two years I set up the program. I ran it. And if we ever sitting down and having a coffee or a beer, sometimes I'll tell you why I left.

[00:09:53] Okay. But think about FBI and I think you might have a clue as to why I decided not to do that anymore. I trained thousands of businesses, government agencies, state local. Federal, you name it. So you're getting what you really need, which is another problem. I keep hearing from people, you do a search for something on YouTube or Google and you get what a million, 5 million pages, as supposedly that it says are available and they give you, okay, then here's the top one. But what you need is an integrated, single. To do things where everything works together. And that's what I'm trying to do for you guys, because there's so many little products, different products that just don't work so well together.

[00:10:46] So we'll be covering that as well in these, but you gotta be on that email list. Craig peterson.com. Craig Peterson, S O n.com/subscribe. We'll take you right to the subscription page and I'll keep you up to date. This is not my paid newsletter. All right, stick around. We'll be right back. And I promise I'll get to Russia.

[00:11:12] Some of the high-tech companies and others pulled out of Russia after the Ukraine invasion, but one stayed Google. What is going on with Google? And now they're in big trouble with the Russian government. Wow

[00:11:28] here's the list of companies according to seeing that, that have. Out of Russia because you remember Russia invaded !Ukraine, February 24, we had Adobe, these are the guys that make Photoshop, Adobe reader. Airbnb has an interesting story too in Ukraine because a number of quite a number of Airbnb customers went ahead and rented rooms and homes from Ukrainians, even though they had no intention of going and they told the Ukrainians, Hey.

[00:11:59] The I'm not going to show up, just take this money. I'm sure you need it. Can you imagine that? But that's fantastic. Good for them, Amazon. They suspended shipments of all retail products at customers in Russia and Bella ruse and also suspended prime video for users. Apple stopped selling its product in rushes.

[00:12:21] It's halting online transactions, including limiting apple pay. It's also disabled. Some apple map features in Ukraine in order to protect civilians, Amazon web services. They don't have data centers or offices in Russia, but it stopped allowing new signups for the service in Russia. BMW for GM, huh? I have all scaled back their operations or stopped them.

[00:12:49] Ford suspended its operations in Russia effective immediately until further notice. GM is suspending business in Russia. Honda has a suspended exports to Russia, Disney halted, all theatrical releases in Russia, including the new Pixar film, turning red, also pause content DJI. The drone company that has gotten in trouble here in the U S for some of its practices of sending GPS information to China while they're not doing it over there.

[00:13:20] Electronic arts. They make a bunch of very popular games, epic games, and other one Erickson, FIFA body band Russia from this year's world cup formula one canceled its plan planned Russian grump, pre Fujitsu, Goldman Sachs. Now Google that's where I want to go. We'll stop at Google here for a minute.

[00:13:44] Google. Suspended their ad network in Russia. And the idea was okay. We're not sure how payments are going to work because Russia of course has had this kind of this lockdown by foreign countries on their banking system. We're not sure we can get the money out. That's what they're apparently doing now.

[00:14:08] They're still there. Google's YouTube it search engine on and on still running in Russia. Now that is really disturbing. If you ask me, why did they not pull out? It doesn't make sense. So Google did stop accepting new customers for Google cloud in March. YouTube said is removing videos at denier trivial trivialize, the Russian invasion, but what finally got.

[00:14:42] Out of Russia, Russia seized their bank accounts. They froze them. They transferred their money out of the main bank account in Russia. We're talking about a $2 billion per year business, Google Russia, that really upsets me. So I did a little more research online about all of this, and I was really surprised to see that you crane now has given the Ukraine peace prize to Google.

[00:15:12] And it says, quote, on the behalf of Ukrainian people with gratitude for the support during this pivotal moment in our nation's history. So what is it? I'm not sure. So they're one of their foreign ministers, and Karen. I think I said, thank you. From the beginning of the war, Google has sought to help power.

[00:15:35] However we can through humanitarian support of our tools, we'll continue to do as long as needed. So I dug in a little more and tried to figure out what's up. Russia or Google left its Russian search engine online and YouTube online and was using it in Russia in order to. Control the narrative in Russia.

[00:15:59] Now, unlike what they've done here in the U S where Google hasn't been caught, many times controlling the narrative in various elections and taking certain ads and not taking others and taking certain business and not taking others, apparently in Russia, it has been. Blocking a lot of the stuff that Russia itself has been putting out.

[00:16:23] So the federal government there in Russia. Interesting. Hey, so they also have helped you crane out by providing them with mapping GPS and rumor has it satellite services. Yeah, interest in it to track Russian troop movements. All also Ukraine saying the Google news component has also been tremendously valuable.

[00:16:51] Google's also helping to raise money for the cause of Ukraine. Like many companies are doing right now to help people displace due to the war and Poland. Wow. They've been doing yeoman's work and bringing. People in, by the millions, into Poland from Ukraine or reminds me when I lived in Calgary, Alberta, my Cub, one of the Cub masters Cub troop leaders was a woman who came from Poland many years ago.

[00:17:18] This was back during Soviet occupation. Poland. And I remember talking to her about what was happening over there. Why did she leave? And it was just so impressive. The polls have done so much impressive stuff over the years. So they're also saying that Google has done a lot of other things in order to.

[00:17:39] Help protect Ukraine, including Google's blocked domains. They've prevented phishing attacks against Ukraine. They warned targeted individuals that they are being targeted. It's really something what they've done. So my first knee jerk was why is Google? Still doing business in Russia while now it's become clear because they have a special page for Russians that gives correct information, at least, Google is claiming it's correct.

[00:18:13] I don't know which fact-check teachers checkers they're using. That gives Russians real information about the war what's going on in Ukraine. What's happening with the Russian soldiers. Did you see this? Just this last week, the apparently Russia removed the age limit for volunteers for the military.

[00:18:35] It used to be, I think it was 40 years old. If you were a Russian citizen and 30 years old, if you are a foreign national, now the Russian military will take any. At any age from anywhere. In other words, Russia has really getting hard up if they want people like me to fight their wars.

[00:18:54] I'm sure they don't really want, I don't know. Maybe they do want me, that every war needs cannon fodder. So it is fascinating to see good job Google. I am quite impressed. I did not expect them to be doing that. They've also. Provided over $45 million in donations and grants to various groups.

[00:19:18] They've done pro bono work for various organizations over there. So this is really cool. So that's it. That's what's happening over there? Yeah. Crane and Googled, you can of course, find out a lot more. Get my insider show notes. So you had all of this on Tuesday morning. You could have digested it all and be ahead of everybody else out there.

[00:19:43] And then also don't forget about my new offer here. Free, absolutely free for anyone. Asks by emailing me@craigpeterson.com. I'll go ahead and send them to you, which is I think a pretty cool thing now. What am I going to send you? You got to ask first, right? You got to ask. And what we're going to be doing is taking what I have been using for years to help secure my customer.

[00:20:14] And we're making available for free my cyber punch lists. Craig peterson.com/subscribe.

[00:20:22] Bit of a hub-bub here. Biden's infrastructure bill $1.2 trillion. And it's in there is this thing that Bob Barr's calling an automobile kill switch. I did some more research and we'll tell you the facts right now.

[00:20:39] What are you supposed to do? If you are trying to pass a bill to stop drunk driving deaths, and you've got all of the money in the world, Joe I guess 1.2 trillion, isn't all of the money in the world. What are you going to put in there? I did a search on this and I'm chuckling because this is craziness.

[00:20:59] This is the AP associated press. And they've got this article claiming. President and Joe Biden signed a bill that will give law enforcement access to a kill switch that will be attached to all new cars in 2026 APS assessment false. Okay. So we've got fact checkers here while the bipartisan infrastructure bill Biden signed last year requires advanced drunk and impaired driving technology to become standard equipment in cars.

[00:21:31] Experts say. Technology doesn't amount to a kill switch. Let me see. So I can't start the car. If the car's computer thinks I might be drunk or impaired in some other way, but that's not a kill switch. What is that? Then if I can't start the car, because I have a disagreement with the computer. How about these people that I don't know, maybe their eyes can't open all of the weight.

[00:21:59] Maybe they have problems with eyes on nystagmus though. Eyes jittering back and forth. And then now what are they going to argue with the computer? That's a kill switch. I can't believe these crazy people that are like AP here, coming up with fact checking on things. So yeah, I'm sure there some distortions in some articles out there, but they contradicted themselves and to bear graphs, I guess they figure people are just going to see false.

[00:22:30] Okay. I'm done. And they're not going to bother reading the rest of the article. Ah, Kind of crazy, isn't it? So according to an article written by member, former us representative Bob BARR in the infrastructure bill, is this kill switch. Now the big question is what is the kill switch? How far does it.

[00:22:55] So I decided let's look up something I remember from years ago and that is GM has the OnStar system it's yet another reason I won't buy GM, there are a number of reasons, but this doesn't, it. OnStar system, they've got an advisors and that grade, and if your car is in a car accident, a crash that advisor can hop on and ask if you're okay.

[00:23:22] And if you want emergency services coming, they'll come OnStar. We'll call them. And if you are just fine, they won't bother calling. If there's no answer at all, they'll call emergency services and let them know where the vehicle is because the vehicle has with OnStar built-in GPS. One of the features of OnStar is that it can send a signal to disable cars, engines, and gradually slow the vehicle to an idle speed to assist police in recovering the vehicle.

[00:23:58] Now they will only do that at least right now for vehicles that have been reported stolen and have been confirmed by the police. So in reality, that's cool, right? It slows down. Hopefully the bad guy, if he's on the highway, makes it over to the side of the road and while the car slows down and eventually stops.

[00:24:22] So all of this stuff sounds good. This kill switch. Sounds good. Doesn't it? Because we're going to keep drunk drivers off the road. Now in reality, of course, they're not going to be able to keep drunk drivers or other impaired drivers off the road. I really don't care what kind of technology they put in.

[00:24:44] And they're not talking about putting in one of these blow in the tube, things that checks your blood alcohol level. They're talking about having a camera facing you as the driver and probably other occupants of the vehicles and that internally facing camera. Is going to evaluate you. It's going to look at you.

[00:25:07] It's going to look at your face. If something droopy, or are you slow to respond? It might have a little test to that. It has you take right there. The law is very loosey goosey on any details. There really aren't any, so it's going to be up to the manufacturer. So they put this in the car step.

[00:25:28] Just like OnStar, step one, put it in the car and they'll tell you when to turn you remember how cool that was the GPS with OnStar. And you tell ya, I want to go to this address. And then the assistant goes ahead and sends programming to your car. And now you can go. And if you lock your keys in the car, they can unlock the car for you.

[00:25:51] All kinds of cool stuff. And then next up what happened. But they can stop the vehicle. So there's another technology story related to OnStar. And this is from 2009 from Kelly blue book, OnStar stolen vehicle slowed down Fort it's first carjacking. So again, doesn't that sound fantastic. And this was a Tahoe OnStar.

[00:26:18] And the driver and his passenger forced out of the vehicle robbed by a shotgun wielding perp who then drove off in the SUV. And the OnStar dispatcher was able to locate the vehicle using GPS advice please, of exact location. And as soon as the police establish visual contact, the stolen vehicle slowdown system is activated available on a number of GM cars and trucks.

[00:26:43] So this was over a decade. That this happened, but the technology's evolved. Yeah. So we initially have all of these car companies trying to decide, okay, so we've got this kill switch law, which AP says is not a kill switch law because they talk to experts just the, what was it? 52 people heads of intelligence.

[00:27:08] Committees and agencies said that this wasn't a collusion hope, right? So they talked to experts who said no, this isn't a kill switch, but that's today you can argue, it's not a kill switch. I would completely disagree with you. Day one. It's a kill switch. Cause you can't start your car. It's a kill switch.

[00:27:25] I kill switch is often something you hide somewhere on the car so you can kill the engine. So it can't be stolen. It's a kill switch. Come on. People fact checkers aside, but this could potentially allow law enforcement again, to shut down your car. Remotely track the cars, metrics, location, maybe the passenger load, because remember now cars are tracking all of this.

[00:27:51] They've already been. Tickets issued by police. The did not see anyone speeding. The car was not caught on a traffic camera, but they hook up a device to your cars port that talks to its computer. And the computer says, yeah, he was doing 80 miles an hour, five minutes. And all of a sudden you got a ticket, right?

[00:28:12] Massachusetts wants to go ahead now and say, ah yeah. Let's charge by the mile that you drive in mass. Because of course you're not getting enough revenue from gasoline because of the electric cars, electric cars are not paying their fair share when it comes to road taxes. So let's do it that way.

[00:28:32] So how are they going to collect the information while. And they're going to hook up to your car's computer. The next thing coming down the road in it's already in most cars is wireless data connectivity, or you might've found already. If you have a Nissan, a Honda, many other cars. You have to get a major, upgrade it very 600 bucks up to a few grand for an expensive car, but the two G data network.

[00:29:02] And we talked about this on the show already is being completely shut down by the end of the year. So they've got to replace it and switch you over. To the L G E data network, which of course eventually will go away as well, or at least three G what happens once it's all hooked up? The next easy step is just feed all of that information straight to the government.

[00:29:26] Craig peterson.com.

[00:29:30] If you've been afraid of ransomware before, I've got a good example for you where a whole country now has been ransomed. Absolutely crazy. So we'll talk about that. What is the state of ransomware? And the NSA is asking us to trust them again.

[00:29:47] Of course staying up to date means that you get my insider newsletter pretty much every Tuesday morning.

[00:29:54] And the only way to get that is to go to Craig Peterson.com/subscribe. And I will keep you up to date. You'll get even more insight information. The Costa Rican government has declared a state of national emergency. And to the best of my knowledge, this is the first time a government has done this because agencies of the Costa Rican government have been hit so badly by the Conti rants.

[00:30:24] That the new incoming president immediately declared a state of emergency. So now the country has expanded law enforcement powers and they are trying to go after the Conti ransomware group. No between you and me. Good luck on that one. They are based in Russia. There's a number of different articles out this week.

[00:30:47] This one from ADV Intel at tech target. But according to their research, the Conti ransomware groups attack on Costa Rican government was part of a rebranding effort. So this ransomware gang has seen a lot of their payments, just dry up. Because it's harder to get the money in. And what are you going to do with cryptocurrency?

[00:31:11] If you're the Conti group, can you turn it into anything useful? It depends on the country you're in, but for most people, no. Okay. Absolutely. No. So we were able to knock the Conti ransomware groups website. Offline. And we talked about that before here. The U S government did that, but now this is marking a new chapter for the cybercrime landscape.

[00:31:38] Interesting. Isn't it? So there are some investigations that have been going on. They've been trying to figure out what happened. What was the cause of the downfall of the Conti ransomware group? Are they really gone? Why did they pull their website offline and. They declared publicly support for Russia in its invasion of Ukraine.

[00:32:02] And so now the Conti ransomware group got hacked and held ransom. They suffered major league. As a consequence. So other hackers went after Conti, which is a hacking group and they showed here from internal documents that were stolen, that the Conti ransomware gangs primary Bitcoin address, which was found in the leak, showed that they had taken in over $2 billion in cryptocurrency over the last five.

[00:32:35] Isn't that just amazing and anonymous leaker has published more of the gangs communications, that can help the mass for sure. But you think with that much money, they'd be able to protect themselves right now on top of it, because of the hack of Costa Rica and the major damages, because the U S government has offered a couple of bounties here.

[00:33:00] Against the Conti ransomware group. So there's $10 million available. If you can provide the feds with information about the leaders of the Conti ransomware group and $5 million that you can get leading to the arrest of anyone involved with a Conti ransomware attack. Isn't that something. So ransomware has been really out of control for years.

[00:33:25] There's no signs that things are actually slowing down. Definitely been enhanced law enforcement efforts to track them down. But I'll ultimately here, the core members of these groups have been escaping these law enforcement activities. They've been using mules like 2000 mules. Have you seen that movie?

[00:33:46] But the idea is they get people primarily in the U S because that's where most of the money comes from. They do rent. Of people and businesses information here. In fact, last year, it's estimated that 60%, six, 0% of small businesses were hacked, which is just crazy. No wonder has got $2 billion. Okay.

[00:34:07] What are we supposed to do? What are they doing to really come after us? They're doing many of the same things. These mules will be hired saying, Hey, I just need to use your PayPal account. And all you have to do is transfer some money. 5%, 10% of the money I put in there. And they've always got these excuses, think that I, Jerry, an email scams from years past, and frankly still go around a little bit here, but large bounties are really becoming a part of the toolbox, a law enforcement's been using in the us and abroad to try and track them down.

[00:34:44] And that's really what they're hoping for down in Costa Rica, because what are they going to do? Frankly, really what are they going to do? I don't know. And they obviously are relying on the United States to help them out with this. And the internal structure of the Conti group has been highly organized.

[00:35:03] They've got the same type of structure of legitimate corporation would have it takes it to work that needs to be done. They hire contractors that may not even know who they're actually working for to write small pieces of a code here that gets tied. So it's not too surprising that a Conti affiliate is going to go far enough to cause a national emergency to be declared.

[00:35:30] One of the things that Conti has done and some of these other ransomware companies have done companies gangs. They have ransomware as a service. So there's all of these people that are affiliated with Conti and all you have to do is get the Conti ransomware onto someone's computer and ta-da, they will pay you.

[00:35:54] It's really that simple. They've got tech support for the people that are ran through there. They got ransomed to help them supposedly pay, right? How do I buy Bitcoin? And they'll walk you through. And then they will help you with restoring your files. Hopefully they can be restored. They are, they can't always be restorative.

[00:36:15] I think right now the latest number I saw. How about 60% of people who have their data encrypted and ransomed are in fact able to get that data, but there's 60% of the data back. So that's not too big a deal, but Conti operates on affiliate. And this affiliate that went ahead and grandson and our friends in Costa Rica is called UNC 1 7 5 6, uncles, 7 56.

[00:36:51] They're also suspected in other attacks on government servers, including a theft of intelligence materials. Peru. And this attacker has already leaked information stolen from Costa Rica and it's on the Conti ransomware dark web portal, which is online. And after the former president of the country refused to pay a $10 million ransom demand, they started leaking the data.

[00:37:17] So in this case, focus has been on the national government agencies. They are potentially looking at what might you might call espionage, but these Conti ransomware affiliates have become famous for really quickly exploiting new vulnerabilities as they're published and being indiscriminate in who they attack, because $2 billion.

[00:37:39] And then the other part that I think is really interesting here. W we're talking about money, we're talking about real money, obviously, Conti deals almost exclusively in Bitcoin, which can be hard to turn into hard currencies, but that our friends in Costa Rica have said, no we're not going to.

[00:37:59] Knowing what has been stolen and what they no longer have access to. In fact, the president said that the company, the country Costa Rica is effectively at war. Now, they got a foothold Conti did in 27 agencies at different levels of the. And the yeah. Okay. So Conti is say, I'm looking at an article in the register here.

[00:38:26] Conti is apparently has made more than 150 million from a thousand plus victims while we know it's actually 2 billion, but it depends on the timeframe that they're talking about. And the Conti says that they are determined to overthrow the government by means of a cyber attack. We've already shown you all the strength and power.

[00:38:45] You have introduced an emergency. It's really quite something. Now I mentioned earlier today that I am. Taking all of the cyber security stuff that we have been using here over the years. Things like our plan of action and milestones documents and all of this stuff we use to run our projects for our customers.

[00:39:11] It's the real stuff, people. And remember, I've been doing the cyber securities. Since the early nineties, so we know what we're doing, I know what I'm doing and I'm making it available for free. Okay, guys, you just have to send me an email me@craigpeterson.com. So the first cyber punch list that we have that available, and all you have to do is ask for it again.

[00:39:37] Me, M e@craigpeterson.com is the. Email punch list. So with this punch list, I go through the things that you need to do. In order to secure your email and be more or less secure in your email. Now, I don't know about you. I do not like these long diatribes. I have a book behind me that is hardening windows 10 and it is in a four inch binder.

[00:40:14] Cited. There are thousands of recommendations in there from Microsoft. There's a lot that needs to be done. So what I've done is boiled it down to the most important things. And as I said, it's available for absolutely. Free for you. It really is. If you're a listener, just email me M e@craigpeterson.com.

[00:40:38] You can ask me to add you to my insider show notes and my little three minute trainings that we do every week. You can also ask for a cyber punch list that you might need. So it's just, okay, we need to do this. You need to do that. You need to do this. You need to do that. So it makes it very straightforward.

[00:40:57] I'm trying to. To be, to see about any of this, but we have had amazing feedback on this from companies over the years, and now it's available to you for $0. Okay. So make sure you check it out. Craig peterson.com and you can always email me M e@gregpeterson.com as well. Thanks for taking a little time with me today and look for me online.

[00:41:24] Look for my emails and if you would please. Thumbs up on your favorite podcasting platform, YouTube or rumble or subscribe. Thanks.

[00:41:37] We're going to talk about the Senate bill that has big tech scared, really scared. I'll talk about a new job site problem for a number of different industries because of hackers and cloud, the cost and reliability.

[00:41:53] This tech bill. It has the Senate really scared.

[00:41:57] He is frankly, quite a big deal for those of you who are watching over on of course, rumble or YouTube. I'm pulling this up on this screen. This is an article. ARS Technica and they got it originally from wired it's it was out in wired earlier in the month. And it's pointing out a real big problem that this isn't just a problem.

[00:42:23] This is a problem for both the legislature. In this case, we're going to talk about the Senate and a problem for our friend. In big tech. So let us define the first problem as the big tech problem. You're Amazon. You are Google. Those are the two big targets here of this particular bill. We're going to talk about, or maybe your Facebook or one of these other Facebook properties, et cetera.

[00:42:50] If you are a small company that wants to compete with any of these big guys, What can you do? Obviously you can do what everyone's been telling us. Oh, you don't like the censorship, just make your own platform. And there've been a lot of places and people that are put a lot of money into trying to make their own platform.

[00:43:12] And some of them have had some mild successes. So for instance, I'm on. You can watch my videos there. And there have been some successes that rumble has had and making it into kind of the competition to YouTube. But YouTube is still the 800 pound gorilla. Everybody wants to be where the cool kids are.

[00:43:32] So for most people. That YouTube. They look at YouTube as being the popular place. Thus, we should be, we are obviously saw the whole thing with Elon Musk and Twitter, and the goings on there. And Twitter really is the public square, although it's died down a lot because of this censorship on Twitter.

[00:43:52] Interesting. So as time goes forward, these various big companies are worried about potential competition. So how do they deal with that? This is where the real problems start coming in because we saw Amazon, for instance, in support of an internet sales tax. You remember that whole big deal. The internet had been set aside saying, Hey, no states can tax the internet and that's going to keep the internet open.

[00:44:21] That's going to help keep it free. And people can start buying online. And that worked out fairly well. A lot of people are out there, why would Amazon support a sales tax on the internet? They are the biggest merchant on the internet, probably the biggest merchant period when it comes to not just consumer goods, but a lot of goods, like a staples might carry for business.

[00:44:45] So they'd have to deal with what they're 9,000 different tax jurisdictions in the United States. And then of course all these other countries, we're not going to talk about them right now, but the United States 9,000 tax jurisdictions. So why would Amazon support an internet sales tax when there's 5,000 tax jurisdictions?

[00:45:10] The reason is it makes life easier for them when it comes to competition. So if you are a little. And do you want to sell your widgets or your service? Whatever it might be online. You now have to deal with 9,000 tax jurisdictions. It's bad enough in the Northeast. If you are in New Hampshire, if you live in New Hampshire and you spend more than, I think it's 15% of your time south of the border and mass, then mass wants you to pay income tax for that 15% that you are spending your time there.

[00:45:48] Now they do that with the. Baseball teams with football teams, hockey, you name it, right? So the big football team comes into town. The Patriots are paying the New York jets or whatever it might be. The Patriots have to pay New York state taxes, income tax now because they stepped foot in New York heaven forbid that they try and do business there and help New York state out.

[00:46:12] And they now have to pay income tax. Now they only have to pay income tax for, or for the amount of time. They're more New York. Various states have various weirdnesses, but if you're only playing 1, 2, 3 dozen games a year, It isn't like your normal work here, which is 2080 hours. We're talking about their plane to New York and they're only spending maybe 10 hours working in New York, but that represents what percentage, 10, 20, 30% of their income, depending on how many games they play and how they're paying.

[00:46:45] And so they got to keep track of all that and figure it out. Okay. We played in New York, we played in New Jersey. We're in mass. We were they weren't in New Hampshire, certainly the Patriots plane, but they got to figure it all out. Guess what? Those big pay. Football players, hockey, baseball.

[00:47:03] They can afford to have a tax accountant, figure it all out and then battle with them. I had a booth one time at a trade show down in Connecticut. Didn't say. Thing it was terrible trade shows, man. They aren't what they used to be. And they haven't been for a long time. This is probably a decade plus ago, maybe even 20 years ago.

[00:47:26] So I had a little booth, we were selling our services for cybersecurity and of course, nobody wanted to bother pain for cybersecurity who needs it. I haven't been hacked yet. Although there's an interesting article. We'll talk about next week based on a study that shows. Small businesses are going out of business at a huge rate because of the hacks because of ransomware.

[00:47:49] And if you're worried about ransomware, I've got a really great little guide that you can get. Just email me, me@craigpeterson.com. I'll send it off to you, right? It's a free thing. Real information, not this cruddy stuff that you get from so many marketers, cause I'm an engineer. They'll go out of business.

[00:48:10] So they figured I haven't got a business yet, not a big deal. And so no body. There's big trade show. And I was so disappointed with the number of people that even showed up for this silly thing. So what happens next while I get back to the office and about a month to two months later, I get this notice from the state of Connecticut they're tax people saying that I haven't paid my Connecticut taxes yet.

[00:48:37] And because I was in connected. I should be paying my income tax for that day that I spent and wasted in Connecticut. Oh. And plus every company in Connecticut that I'm doing business with now, I need to collect their taxes and pay them the taxes that I'm collecting for those Connecticut businesses are resident.

[00:48:59] I didn't sell a thing. You know what it took almost, I think it was three or maybe four years to get the state of Connecticut to finally stop sending me all of these threatening notices because I didn't get a dime from anybody in Connecticut. So I'd love the internet from that standpoint saying you don't have to collect taxes in certain cases, certain states, et cetera, unless you have a legal nexus or a legal presence there in the state. So back to Amazon, Amazon loves the idea of having everything on the internet packs. They love the fact that there's 9,000 plus tax jurisdictions. When you get right down to city, state county Lilian, either local taxes, or you look at those poor residents of New York state, or they're poor residents out in Washington state that have to worry about that, right?

[00:49:52] There's county taxes, state sales tax. City sales tax, and income taxes are much the same, the, all of these crazy cities and states around the country. Yeah. The ones that are in serious trouble right now, they are those same ones. Those particular jurisdictions are hard to deal with. So from Amazon standpoint is just like the Patriots football players.

[00:50:17] We've got plenty of money. We've got teams of lawyers. We have all kinds of accountant. We can handle this and you know why Amazon really loves it because it provides another obstacle for any competitors who want to enter the business. That's the real reason, so many big businesses don't go ahead and charge you serious money so that they can use that money against you.

[00:50:48] Okay. You see where I'm going with this? Because if you want to start a business that competes with Amazon, if you want to have a doilies, you're making doilies. My grandmother used to make them all the time and she had them on the toilet paper in the bathroom, little doily holders. Doilies everywhere.

[00:51:06] And then of course, the seashells shells on top of the toilet paper holders. If you want to do that and sell it, how are you going to deal online with 9,000 tax jurisdictions? All what you're going to do is you're going to go to Etsy, or you may be going to go to Amazon marketplace and sell your product there.

[00:51:25] An Amazon marketplace. So Amazon is taking its cut out of it at is taking it's cut off. And you still ultimately have some of that tax liable. Amazon loves it. It's the same reason you see these groups forums, right? Barbers saying, oh, we've got to be regulated. Really you need to have a regulation in place for barbers.

[00:51:49] You need to have licensing for barbers. Why do they do that? They do that. Not just barbers, right? It's all of these licensures and various states. They do that really to keep people. To keep their prices high. That's why they do it because someone can't just put up a sign and say, Hey, I am now a barber.

[00:52:10] Come get a haircut. And if you don't like the barber, if they do a lousy job, you go elsewhere. We don't need all of the bureaucracy on top of this to enforce licensure. Anyways, when we get back, let's talk about that Senate. It's a big deal. And I am coming down in the middle of this thing. Hey, visit me online.

[00:52:30] Sign up right now. Craig peterson.com and get my special report on passwords.

[00:52:38] We just talked about why big business loves regulation. It helps protect them from up and coming small business, frankly, let's look at this bill, the Klobuchar and Grassley just introduced in the Senate.

[00:52:54] I am coming down in the middle of this bill. And let me tell you why we really do have a problem with some of these big businesses.

[00:53:04] For those of you who were watching here on rumble or YouTube, I'm going to pull this up. This is an article that was originally in wired and is in ARS Technica, great website. They got lots of good information and the title of the bill is a Senate bill that has big texts. So the question is why now are ours technical?

[00:53:27] I'm going to scroll this down so you can see what they are saying. They're claiming that this is really apocalyptic that frankly the people who are pushing against this bill are obviously the wrong people and everything else. But I love this point here. This is from a senior VP of policy at Yelp.

[00:53:50] You can see this on my screen. Luther Lowe. And he's talking about this bill. Actually one of two. Antitrust bills is what they're called in the us. There's voted out of committee by a very strong bi-partisan vote. And the other bill is to regulate app stores and there's issues with that too, that we won't really be talking about today, but they have to do with protecting you the consumer.

[00:54:19] If you can load any app you want from any app store on the internet, on your iPhone, is your iPhone still? Versus having to get it from apple. We're not talking about that one right now. This is Congress's shot here to stop big tech companies from abusing what they're calling a gatekeeper status.

[00:54:42] So we're going to talk about that. What is this gig key keeper status? What does that mean? So Luther low back to him, VP of policy at Yelp long time ago. Antagonist says it, the ball game. That's how these guys stay big and relevant. If they can't put their hand on the scale that it makes them vulnerable to small and medium-sized companies eating their market share.

[00:55:11] Isn't that what I was. Protecting themselves, protecting themselves against the small startups. And if you've got government regulation on your side, you can just hammer them with the fact that, Hey, you guys aren't compliant, right? If you've got some major government regulation to just look at what happened with Elon Musk, when he said I'm going to buy Twitter, all of a sudden his.

[00:55:40] And he, his Twitter account has problem. All of a sudden what w what his money has prompted. All of a sudden when Elon Musk's that I'm going to buy Twitter, the government started investigating Tesla. It's amazing. How these people work and how they think. It's just, it's absolutely amazing.

[00:56:00] So they use these big companies, use government to beat other people over there. It's like my example of the barbers, right? Do we really need licensing for barbers? Do we really need to have a barber board that oversees barbers? If someone harms you, there are laws against that. No. When I was, for 10 years, I was in EMS.

[00:56:26] I was a volunteer EMT. You guys know that emergency medical technician and my wife was. And if we were to cut someone's hair without their consent, that would be considered assault, even battery in some cases. So there's laws on the book to protect your hair. Okay. Need laws about barbers? We don't need laws about so many things.

[00:56:52] The government sticks its fingers in. And so what is it? Stick his fingers in here. What are they trying to do? Let me pull that up on this screen for you. Senators Amy Klobuchar and Chuck Grassley, CR grassy, I should say, who were our, excuse me. So are the top Democrat and Republicans on the Senate judiciary committee are saying, Hey, we need to regulate how Amazon, how Google and these others can use their position in order to.

[00:57:30] Keep their fingers off the scale. So bottom line, that, that sounds like a pretty good idea to me. And that's the thing that fits on the bumpers bumper stickers, stop Google from putting their thumb on the scale. Stop Amazon from putting the thumb on the scale because we have.

[00:57:47] Actual problems with this. We have seen where people who are using Amazon marketplace to sell their stuff. Why would they do that? Obviously they've got to pay a percentage to Amazon plus depending on how your business operates, you have to pay Amazon to warehouse. You're good. Just for you. You have to pay Amazon for all the logistic services for shipping, for moving around between Amazon warehouses and then for selling it, it can get pretty darn expensive.

[00:58:20] Okay. Amazon charges, that seems pretty fair to me, right? The libertarian mindset. Where's the problem. I don't see the problem, Craig. The problem is that Amazon has. Own products that they want to sell more than half of what's on the Amazon store is actually sold by third parties. And we've talked about that before.

[00:58:42] We talked about problems with that before, but that means that what almost half of it is sold by Amazon. So Amazon has a number of brands. Last I checked, it was a few dozen brands that don't look like they're Amazon. There's a home services brand. There's a place that sells couches or Chesterfields depending on where you're from.

[00:59:06] There's a whole bunch of different businesses, clothing, businesses, et cetera, that are actually Amazon who might've bought a company or they saw. That accompany was doing really well in their marketplace by selling item X. So what do they do? They go ahead and say, okay we're going to start making an item X, see where the problem comes in.

[00:59:29] So Amazon is using these small businesses that put everything on the line, right? They might have their house leveraged to the max. They might have sold their house and living with somebody else, apartments are too expensive. The cash to get their business going. They scraped the money together.

[00:59:46] Maybe they had to pay $5,000 to have a mold made injection mold, and then they have the stuff made in the U S or in China, or there they're trying to print it on a 3d printer for the. Concept. And they'd go through a number of different iterations of trying to make that product work and consumers to like it.

[01:00:07] And consumers give them feedback saying, what, if this was a quarter in smaller or moved over there on the product, that would just be so much more useful. So they add that they had the engineering time, they've invested quarter million dollars. Easily to get the product off the floor to get it out there and people start buying it.

[01:00:29] Where are they selling it? They got to really sell it on Amazon marketplace because who else are you going to go to for logistics, sales, support, everything else. And not to mention the tax jurisdictions that want to collect money from you. And then Amazon comes out with a competing. Is that enough to drive you crazy.

[01:00:51] Now we've seen this forever in the software industry. Microsoft has done this for years. Apple does it to I'm looking at a screen right here in front of me. I hooked up to an apple mini. Some of the side card functions and stuff. They were developed by a third party that spent their blood, sweat, tears, and money on developing it.

[01:01:16] And then along comes a big guy and you're out of business. We've got to finish this up. We will do that. When we get back, what's a Senate doing actually here. And what does it mean to you and me? Hey, visit me online. Craig peterson.com. Get my insider information for free.

[01:01:38] We just talked about how big business uses its advantages to crush potential competition. Crush them. And it's a shame and it's happened to me and many people I know, and now the Senate's getting involved and making things worse.

[01:01:55] This happened to me a number of years ago, and I will never forget it.

[01:02:00] It was a really big lesson for me. I had designed and written a computer system that would take the code that it was written for a much older system. And run it for much less money. So bottom line here, this was a system called Cade computer assisted data entry that was made by Sperry way back in the day.

[01:02:25] Yeah. I've been in there for that long and they had little programs, so they would not punch cards, but punch right on two tapes, those big nine track tapes and that information would then be used for processing later on then. People, big businesses grocery stores, you name it. We're using that Sperry system.

[01:02:48] And I designed a system that would take their COBOL is what it was. It was a form of COBOL code from this cage system. And you could use my code to compile it and run it on a Unix system. So the cost involved here was that it would be cheaper to buy a whole new Unix computer and buy new terminals and do some slight training changes.

[01:03:18] But the key punch operators would be exactly the same keystrokes as they were already used to. Okay. So you know how fast they were, so it wouldn't slow than none at all. And their cost would be. Then just the maintenance contract on the old Sperry cage. Very cool stuff. And I worked really well.

[01:03:38] Then I worked with a couple of sales guys at spirit because Barry had a Unix tower system. It was a mini computer that was Unix space. And I had one, I had saved up my money. We bought this thing. It was a lot of money nowadays. It'd be about a hundred thousand dollars I spent on that system and it was really great.

[01:04:00] Cool. So some grocery stores started using it. They used it to build the space shuttle to design it and send it into space. RCA, Astro space used it, my system, which is all really cool. So Sperry was interested in it saying, okay let's do this. Now. I had flown myself across the country too, because I was in California at the time to do some of this work for.

[01:04:25] The for RCA Astro space for the space program and help make sure it was working and get it installed, help them configure it and everything else. So I had a lot of time, a lot of money, a lot of effort into this. It was a big venture. So Sperry invited me down to their headquarters down in blue bell, Pennsylvania to talk about this.

[01:04:50] And I was so excited because their sales guys wanted to sell it. They gave me some free space in a booth in Las Vegas. So I was in the Sperry booth with them and, say, yeah, you can buy this. And you're using the Sperry, the new Sperry hardware. And I went down there and talked with them.

[01:05:10] They never did anything with me, or, here's a huge investment young guy. And all of this stuff just worked and they had proof of concept. They had a couple of customers already using the system and it never materialized. And then about a year and a half later, I found out Sperry had tried to duplicate my system and had messed it up terribly.

[01:05:35] It wasn't keystroke compatible. So anyone using the new Sperry system, they had to learn. Okay. So I got to hit this and I got to go over here and I got to click on this. Are you kidding me using a mouse? Aren't you not? These are data entry operators. They just go all day long, just typing and.

[01:05:52] They had stolen my ideas. They messed it up. They didn't do as good a job as I did, which turns out it's pretty common. And they had stolen it. They stolen years of my life. So I've seen that before with me. I've seen Microsoft do that with friends of mine, and I've seen apple do it with various products that they've decided to release.

[01:06:17] They all do it. Why do you think these businesses can not spend money on research and development, and yet at the same time, stay in business as technology's continuing to move forward? Why? The reason is. They don't have to do, or why would we do T wait a minute. Now, all we have to do is either buy the company or steal the product just re-engineer.

[01:06:44] Oh. And if we want to buy the company, we can do what Microsoft has been accused of doing again and again, which is. We'll just Microsoft. Let's see here. I like that database is pretty darn cool. So here's what we're going to do. So Microsoft announces, Hey, we're going to have a competitor to that in coming out soon.

[01:07:03] And then they sit there and they wait and they say, okay, how many people are going to ask about, oh wow. A lot of people asking for it. In the meantime, that company that had that great little database soft. Trying to sell it. And people are saying, wait, Microsoft is going to come up with a version of this.

[01:07:18] I'm just, I'm going to wait. We can wait a few months. Let's see what Microsoft. So that poor company is now seriously struggling because this big company came out and made the announcement that they're going to do something like this. And then that small company gets a knock on the door. Hey, we're Microsoft or company X.

[01:07:41] And we like your product. Wow. Okay. So we're going to do a buyout. We're going to we're just, oh, this is going to be fantastic. I might have to sign what a two year contract non-compete and help them manage it. Okay. We can deal with this. And then they find out that company X says Your company is not worth that much anymore.

[01:08:02] Your sales look at their sales here, man. They've gone way down. Okay. So let me see let's do a nickel on every dollar evaluation you had a year ago. This happens every day, worldwide in America, it should never happen to anyone. And as you can tell, it upsets me. So what are Klobuchar and Grassley doing here?

[01:08:30] Amy, when she was running for president, she made this big deal. I'm going to pull us up on my screen. Those of you who are watching on rumble or YouTube. And you can find all of that in my website, Craig peterson.com can see here. So they are trying to protect the American consumer, right? Yeah.

[01:08:49] Yeah. That's it. They're gonna protect us. And so what they're doing is saying that. Would a rule ruin Google search results because that's what Google says. Is it going to bar apple from offering new features, useful ones on the iPhone? How about Facebook? Will it stop them from moderating content? So the legislation's core idea is we will just.

[01:09:17] The marketplace take care of things. We're not going to let Amazon put their products in the product listings before third parties, but how are you possibly going to be able to regulate that stuff you can't, you can regulate it talking about a bureaucracy. You'd probably need one about as big as the federal government is right now.

[01:09:41] And the federal government needs to be cut back in a major way. There's this two months. How about the 150 million Americans? This article brings that up to that are currently using Amazon prime, even though the price one hump. And they have it free to prime members. It's this is a big deal.

[01:10:00] The bill doesn't mention prime. Doesn't mention Google by name, Amazon. But this is going to be a nightmare to enforce the bill is not specific enough. It should be voted down. And between you and me, I don't know what can be done about this other than to have additional marketplaces show up online. And you know what the conservative social media sites are starting to win.

[01:10:29] So maybe there's hope.

[01:10:32] We've got two things we're going to talk about right now. One of them is tech jobs. And man, is there a lot of scamming going on there as you might expect in the second is cloud, are you looking at cloud services? Hey, a home or business.

[01:10:48] You can see this. I'm going to pull this up on my screen for those watching on rumble or on YouTube, but this is a big problem.

[01:10:58] And we've seen this again and again right now, they're going after certain workers in the chemical. The sector, but it isn't just the chemical sector. What we've seen is the bad guys going after anyone that's applying for a job. So let me give you a few tips here. First of all, you should not be pain to apply for a job.

[01:11:25] We see that all of the time when it comes to the head hunting firms, what. Is, they will charge the business who is looking to hire someone that makes sense to you. They'll hire they'll charge the business. So oftentimes it's a percentage of the annual salary committee where from usually 20% up to a hundred percent or more, depending on the position.

[01:11:49] And boy can, they make a lot of money, but they don't necessarily place. People, but you know how it is right now, there, there can be quite a few. So people have been applying for jobs to make a lot of money and not realizing that fee that supposedly they have to pay is illegitimate. So remember that.

[01:12:10] Okay. The second thing has to do with this particular scam, because what they're trying to do is. Into some of these companies. So they will send a thing out saying, Hey, on my head hunter, I'm here for you. We're going to get you this job you need to apply. Are you interested in a new job now? I've seen some stats online saying that somewhere around 30 plus percent of people are looking or at least open to.

[01:12:45] Take getting a new job, which means a lot more are looking for jobs. Now I have to add to that, that the people who have jumped ship over the lockdown period really are not happy. The majority of them wish they had stayed where they were at. So keep that in mind too. But what they'll do is they'll say, Hey, listen.

[01:13:07] Oh, there's this new feature on LinkedIn. By the way, you can say y'all are, I'm interested in looking for a job. I forget exactly what it says, but it goes around your picture and I have it up there because I'm a contractor, I go to businesses and I'm. To harden their cybersecurity. And we usually start slowly, especially with some of these startups we're doing work with right now where they won't, they go from a completely flat network and it's all engineers and I don't want anything hindering anything.

[01:13:39] And so you got to work with them and it's just, we had a time sort of a thing. Okay. I just had this one thing this week. And then move on to one thing next week as well. So that's what I do for a living. And a lot of people are looking on LinkedIn and other places to find people who can be a chief information security officer.

[01:14:01] So I'm what you call a fractional chief information security officer. I do this under contract and I've been doing contracts and contract work for. I don't know if I shouldn't be on the air, but my gosh it's been now I guess it's 40 years right now. So I've been doing this for a long time.

[01:14:22] So I'm familiar with some of these scams, so they didn't take my word on some of this stuff. So what they do is they say, Hey, we've got a potential job opening. Are you in interested now? When we talk about 30 plus percent of people polled say that they're looking interested in a new job, the numbers are probably a little higher. Not that everyone's going to jump ship. Some people will, but there are a lot of people that if they get this email, they're going to open it up. And so what'll happen now is this group out of North Korea called the Lazarus group? And we've talked about them before.

[01:15:00] We'll go ahead and say yeah, the here's, what's going to happen here. Let's just send you this thing. You can open it up. You can look at it and see if it's really a fit for you. I love this graphic that they have. This is from dark reading. I have it up on the screen again. Rumble and YouTube.

[01:15:19] What should we do now? Should I open this up? Should I not open it up? It turns out that what's happening is that Symantec and Broadcom, both have noticed this and stated in an advisory a couple of weeks ago. Be very careful because what it's going to do is install a Trojan horse on your computer.

[01:15:40] So let's think about this. You're talking about the chemicals. You have a lot of people who are very technical. And if a company wants to get some new technology, we talked about this earlier in the show, what did they do? Do they just go and say, oh, okay, let's get some R and D going here. Let me research and development.

[01:15:59] Let's hire some scientists and do some pure science here, which are almost never happens anymore. No, what they do is they either buy a company, they steal a company's idea. If you are like the communist, you try and steal the technology directly. And that's exactly what these guys are doing. They put a Trojan on your machine because you open that file and that Trojan then gives you.

[01:16:28] Oh, excuse me, gives them access to your machine. Now this particular Trobe Trojan is a malicious web file. Disguises. This job offer and your machine gets comparable. They attempt to compromise it, right? It's not always successful. They're not as many zero days out there for these lower level actors like North Korea, but they've been able.

[01:16:52] Now, they're not just going after chemical sectors, they're going after it service providers. So companies like mine that provide managed security services for businesses, they are being attacked. So that's a problem too, isn't it? Because if you can compromise. A nine company and we've seen this all the time.

[01:17:14] It's getting reported like crazy. You now have access to all of their customers because the it service company has passwords, et cetera. And they're probably using. Industry is number one or number two products for managing the customer's computers, neither of which are secure. And that's the biggest problem that we've had.

[01:17:38] We use some of these things before, I'm not going to name them right now because it wouldn't mean anything to you anyways, but we had to get. We worked with our, it people inside the software companies that make the software that are used by the managed services providers. And we'd talked with their developers and said, Hey, listen, this is a serious problem.

[01:17:57] That's a serious problem. You've got to change this. You got to change that. And what ended up happening? We left them because they weren't doing what they were supposed to be doing a very big deal. So they're targeting defense, contractors, engineering firms of any sort. They want to steal IP, intellectual property, pharmaceutical companies.

[01:18:18] Yeah. Very big deal. These third hunting teams, including Cisco's, which are the guys that we use. Tallow sets again, an example of a big company buying a smaller company called telos that does threat intelligence and it looks at stuff. They're all reporting to this. So high level jobs in an industry or what you have to watch out.

[01:18:40] It'd be very careful. Now, earlier this year, Lazarus group, again, North Korea went after some of these jobs people 250 that were identified working in the news media, software vendors, internet infrastructure providers, using job offers that appeared to come from. Disney, Google Oracle by the way, that was according to Google who tracked the campaign.

[01:19:06] They know what their employees are doing, where they're going, what emails coming in. It's crazy. We're looking a lot of stuff. Okay. So I want to move on to the next topic here. Last one, this hour, but I'm gonna pull this up right now on my screen. You can have a look at it there. Of course, if you are at home.

[01:19:27] You can or you really can't on the road. You can see this on rumble and also see this on the YouTube site. At least for the time being until I get kicked off right. Kicked off again. That seems to be the word of the hour, but cost reliability are raising concerns in. Again, this is a dark reading article, came out a couple of weeks back here, but the biggest concerns about cloud computing to what is cloud computing.

[01:19:58] Let's talk about that first for a minute. Cloud computing is going online using something like salesforce.com. People don't think of that as cloud computing. But you have in Salesforce, all the communications with all of your customers, et cetera, that's an example of a platform as a service, basically. So they're providing you with everything and it's up in the cloud, nothing to worry about here, folks, but of course you have the same potential problems.

[01:20:28] You do outs where people use what's it called now? Microsoft 365. Which Microsoft disclaimed any liability for any problems they cause for anything customers it's really crazy, but again, what are the problems there? Reliability slash performance, 50% of the people, 50% applaud on the screen.

[01:20:51] Again here worried about reliability and performance, because if your business is relying on cloud computing, What, how is the security any good? That you could use something, as I mentioned Salesforce, and just picking them out of a hat and not, they haven't been like a terrible provider by any stretch.

[01:21:13] But how about if you're going to Azure and you're using a workstation news here? How about if you're going to some other place, right? It could be Amazon web services. Google also has data processing services. Security's huge issue. Cost is a huge issue, reliability, performance, all of those. We're issues with more than 50% of the it professionals.

[01:21:37] I'm surprised that this next one, which is our staff skillset on dealing with cog computing 26%. The reason I'm surprised by that is hardly anybody knows enough about cloud computing. Do we really confident about it? I'm serious about that. There's some companies right now, we're talking with a company called Wiz and they audit Azure configuration.

[01:22:05] So be very careful if you're using. Particularly if you're a business, it may not work out well for you. Hey, make sure you go online right now. Craig peterson.com/subscribe. Sign up. You'll get my newsletters. You'll get all kinds of great information. Absolutely free Craig peterson.com including my special report on passwords.

[01:22:29] Now, if you have any questions, just email me Me@craigpeterson.com.

View Details

Do You Know How Crypto's Nose-dive Will Even Hurt Your 401K?

Hey, it looks like if you did not invest in "Crypto," you were making a smart move! Wow. We got a lot to talk about here. Crypto has dived big time. It's incredible. What's happened? We get into that and more.

[Following is an automated transcript]

Hi everybody. Craig Peterson here. Appreciate your joining me today. Spend a little bit of time with me. It's always a fun thing to do thanks for coming in. And Thanks for sticking around.

[00:00:29] Crypto currencies. It's a term for all kinds of these basically non-government sanctioned currencies.

[00:00:39] And the idea behind it was I should be able to trade with you and you should be able to trade with me. We should be able to verify the transactions and it's nobody's business as to what's happening behind the scenes. And yet in reality, Everybody's business because all of those transactions are recorded in a very public way.

[00:01:03] So crypto in this case does not mean secret or cryptography. It's actually referring to the way the ledgers work and your wallet. And in fact, the actual coins themselves, a lot of people have bought. I was talking with my friend, Matt earlier this week and Matt was saying, Hey, listen I made a lot of money off a crypto.

[00:01:29] He's basically a day trader. He watches it. And is it going up? Is it going down? Which coin is doge coin? The way to go? Because Elon Musk just mentioned it. Is it something else? What should I do? And he buys and sells and has made money off of it. However, a lot of people have. And held on to various cryptocurrencies.

[00:01:51] Of course, the most popular one. The one everybody knows about is Bitcoin and Bitcoin is pretty good stuff, bottom line, but 40% right now of Bitcoin investors are underway. Isn't that incredible because of the major drop-off from the November peak. And this was all started by a problem that was over at something called Terra Luna, which is another cryptocurrency now.

[00:02:22] Already that there is a ton of vulnerable vol a ton of changes in price in various cryptocurrencies, Bitcoin being of course a real big one where, we've seen 5,000, $10,000 per Bitcoin drops. It really is an amazingly fluid if you will coin. So there's a number of different people that have come out with some plans.

[00:02:47] How about if we do like what the us dollar used to do, which is it's tied to a specific amount of gold or tied to a specific amount of silver. And of course, it's been a while since that was the case. President Nixon is the one that got us off of those standards. Having a gold, for instance, back in your currency means that there is going to be far less fluctuation and your currency means something.

[00:03:16] See, the whole idea behind currency markets for government is yeah, you do print money and you do continue to increase the amount of money you print every year. Because what you're trying to do is create money for the. Good product services that are created as well. So if we created another million dollars worth of services in the economy, there should be another million dollars in circulation that's the basic theory.

[00:03:46] Monetary theory, really boiling. Down now of course, already our government is printed way more than it. Maybe should have. It is certainly causing inflation. There's no doubt about that one. So they're looking at these various cryptocurrencies and say what can we do? How can we have a gold standard where the us dollar was the currency the world used and its value was known.

[00:04:10] Having a stable currency is incredibly important for consumers and businesses. The business needs to know, Hey, listen, like we signed a three-year contract with our vendors and with our customers. And so we need a stable price. So we know what's our cost going to be, what can we charge our customer here?

[00:04:30] Can the customer bear the price increases, et cetera. The answer to most of those questions of course is no, they really can't is particularly in this day and age. So having a. Fixed currency. We know how much it's worth. I know in two years from now, I'm not going to be completely upside down with this customer because I'm having to eat some major increases in prices.

[00:04:55] And as a consumer, you want to look at it and say, wow, I've got a variable rate interest rate on my mortgage. And man, I remember friends of mine back in the eighties, early eighties, late seventies, who just got nailed by those. They had variable rate interest loan on their home because that's all they could get.

[00:05:14] That's all they could afford. So the variable rate just kept going up. It was higher than credit cards are nowadays. I remember a friend of mine complaining. They had 25% interest and that's when they lost the house because 25% interest means if you have a hundred thousand dollar loan, you got $25,000 in interest that year, let alone principal payments.

[00:05:36] So it, it was a really. I think it was really hard for people to, to deal with. And I can understand that. So the cryptocurrency guys. I said, okay, let's tie it to something else. So the value has a value and part of what they were trying to tie it to is the us dollar. That's some currencies decided to do that.

[00:06:00] And there were others that tried to tie it to actual. Assets. So it wasn't just tied to the dollar. It was okay. We have X dollars in this bank account and that's, what's backing the value of our currency, which is quite amazing, to think about that. Some of them are backed by gold or other precious metals.

[00:06:24] Nowadays that includes a lot of different metals. This one coin called Terra Luna dropped almost a hundred percent last year. Isn't that amazing. And it had a sister token called Tara USD, which Tara Luna was tied to. Now, this is all called stable coin. The idea is the prices will be staying.

[00:06:46] And in the case of Tara and Tara USD, the stability was provided by a computer program. So there's nothing really behind it, other than it can be backed by the community currencies themselves. So th that's something like inter coin, for instance, this is another one of the, there are hundreds of them out there of these cryptocurrencies.

[00:07:13] Yeah. The community backs it. So goods and services that you can get in some of these communities is what gives value to inter coin money system. Now that makes sense too, right? Because the dollar is only worth something to you. If it's worth something to someone else, if you were the only person in the world that had us dollars, who would want.

[00:07:36] Obviously the economy is working without us dollars. So why would they try and trade with you? If you had something called a us dollar that nobody else had, or you came up with something, you made something up out of thin air and said, okay, this is now worth this much. Or it's backed by that.

[00:07:56] Because if again, if he can't spend it, it's not worth anything. Anyhow, this is a very big deal because on top of these various cryptocurrencies losing incredible amounts of money over the last couple of weeks, We have another problem with cryptocurrencies. If you own cryptocurrencies, you have, what's called a wallet and that wallet has a transaction number that's used for you to track and others to track the money that you have in the cryptocurrencies.

[00:08:29] And it's pretty good. Function or feature it's hard for a lot of people to do so they have these kinds of crypto banks. So if you have one of these currencies, you can just have your currency on deposit at this bank because there's a whole bunch of reasons, but one of the reasons is that.

[00:08:50] There is a run on a bank, or if there's a run on a cryptocurrency, currencies have built into them incredibly expensive penalties. If you try and liquidate that cryptocurrency quickly. And also if there are a lot of people trying to liquidate it. So you had a double whammy and people were paying more than three.

[00:09:13] Coin in order to sell Bitcoin. And so think about that and think about much a Bitcoin's worth, which is tens of thousands of dollars. So it's overall, this is a problem. It's been a very big problem. So people put it into a bank. So Coinbase is one of the big one called Coinbase, had its first quarter earnings report.

[00:09:37] Now, this is the U S is largest cryptocurrency exchange and they had a quarterly loss for the first quarter of 2022 of $430 million. That's their loss. And they had an almost 20% drop in monthly users of coins. So th that's something right. And they put it in their statement. Their quarterly statement here is to, WhatsApp.

[00:10:07] Here's the real scary part Coinbase said in its earnings report. Last Tuesday that it holds. $256 billion in both Fiat currencies and cryptocurrencies on behalf of its customer. So Fiat currencies are things like the federal reserve notes are U S dollar, okay. Quarter of a trillion dollars that it's holding for other people think of it like a bank.

[00:10:36] However, they said in the event, Coinbase we ever declare bankruptcy, quote, the crypto assets. We hold in custody on behalf of our customers could be subject to bankruptcy proceedings. Coinbase users would become general unsecured creditors, meaning they have no right to claim any specific property from the exchange in proceedings people's funds would become in accessible.

[00:11:06] A very big deal. Very scary for a very good reasons. Hey, when we come back a website, no, you go, you type stuff in my email address, do you know? You don't even have to hit submit. In most cases, they're stealing it.

[00:11:23] I'm sure you've heard of JavaScript into your browser. This is a programming language that actually runs programs right there in your web browser, whether you like it or not. And we just had a study on this. A hundred thousand websites are collecting. Information upfront.

[00:11:40] Hi, I'm Craig Peterson, your chief information security officer. This is not a surprising thing to me. I have in my web browser, I have JavaScript turned off for most websites that I go to now, Java script is a programming language and then lets them do some pretty cool things on a webpage.

[00:12:02] In fact, that's the whole idea behind Java. Just like cookies on a web browser, where they have a great use, which is to help keep track of what you're doing on the website, where you're going, pulling up other information that you care about, right? Part of your navigation can be done with cookies. They go on and on in their usefulness.

[00:12:23] Part of the problem is that people are using them to track you online. So like Facebook and many others will go ahead and have their cookies on the other websites. So they know where you're going, what you're doing, even when you're not on Facebook, that's by the way, part of. The Firefox browsers been trying to overcome here.

[00:12:48] They have a special fenced in mode that happens automatically when you're using Firefox on Facebook. Pretty good. Pretty cool. The apple iOS device. Use a different mechanism. And in fact, they're already saying that Facebook and some of these others who sell advertiser in from advertisers information about you have really had some major losses in revenue because apple is blocking their access to certain information about you back to Jarvis.

[00:13:24] It's a programming language that they can use to do almost anything on your web browser. Bad guys have figured out that if they can get you to go to a website or if they can insert an ad onto a page that you're visiting, they can then use. Your web browser, because it's basically just a computer to do what while to mine, Bitcoin or other cryptocurrencies.

[00:13:51] So you're paying for the electricity for them as your computer is sitting there crunching on these algorithms that they need to use to figure out the, how to find the next Bitcoin or whatever. And you are only noticing that your device is slowing down. For instance, our friends over on the Android platform have found before that sometimes their phones are getting extremely hot, even when they're not using them.

[00:14:18] And we found that yeah, many times that's just. Bitcoin miner who has taken over partial control of your phone just enough to mind Bitcoin. And they did that through your web browser and JavaScript. So you can now see some of the reasons that I go ahead and disable JavaScript on most websites I go to now, some websites aren't going to work.

[00:14:40] I want to warn you up front. If you go into your browser settings and turn off JavaScript, you are going. Break a number of websites, in fact many of the websites that are out there. So you got to figure out which sites do you want it on? Which sites don't you want it on? But there's another problem that we have found just this week.

[00:15:00] And it is based on a study that was done as reported in ARS Technica, but they found. A hundred thousand top websites, a hundred thousand top websites. These include signing up for a newsletter or making a hotel reservation, checking out online. You probably take for granted that you nothing happens until you hit submit, right?

[00:15:25] That used to be the case in web one dot O day. It isn't anymore. Now I want to point out we, I have thousands of people who are on my email list. So every week they get my insider show notes. So these are the top articles of the week. They are, usually six to 10 articles, usually eight of them that are talking about cybersecurity, things of importance.

[00:15:51] The whole radio show and podcasts are based on those insider show notes that I also share with the host of all of the different radio shows and television shows that I appear on. It's pretty, pretty cool. So they get that, but I do not use this type of technology. Yeah. There's some Java script.

[00:16:11] That'll make a little signup thing come up at the top of the screen, but I am not using technology that is in your face or doing. What these people are doing, right? So you start filling out a form. You haven't hit cement. And have you noticed all of a sudden you're getting emails from. It's happened to me before.

[00:16:31] Your assumption about hitting submit, isn't always the case. Some researchers from KU Leuven university and university of Lu sane, crawled and analyze the top 100,000 websites. So crawling means they have a little robot that goes to visit the web page, downloads all of the code that's on the page.

[00:16:55] And then. Analyzed it all so what they found was that a user visiting a site, if the user is in the European union is treated differently than someone who visits the site from the United States. Now there's a good reason for it. We've helped companies with complying with the GDPR, which are these protection rules that are in place in the European union.

[00:17:21] And that's why you're seeing so many websites. Mine included that say, Hey, listen, we do collect some information on you. You can click here to find out more and there's some websites let you say no. I don't want you to have any information about me where you collect information, just so that you can navigate the site properly.

[00:17:39] Okay. Very basic, but that's why European union users are treated differently than those coming from the United States. So this new research found that over 1800 websites gathered an EU users' email address without their consent. So it's almost 2000 websites out of the top 100,000. If you're in the EU and they found.

[00:18:07] About well, 3000 website logged a U S users' email in some form. Now that's, before you hit submit. So you start typing in your email, you type in your name and you don't hit cement. Many of the sites are apparently grabbing that information, putting it into the database and maybe even started using it before you gave them explicit permission to do.

[00:18:36] Isn't that a fascinating and the 1800 sites that gathered information on European news union users without their consent are breaking the law. That's why so many us companies decided they had to comply with the GDPR because it's a real big problem. So these guys also crawled websites for password leaks and made 2021, and they found 52 websites where third parties, including Yandex, Yandex is.

[00:19:11] Big Russian search engine and more we're collecting password data before submission. So since then the group went ahead and let the websites know what was happening, what they found because it's not necessarily intentional by the website itself. It might be a third party, but third-party piece of software.

[00:19:33] That's doing it. They w they informed those sites. Hey, listen, you're collecting user data before there's been explicit consent to collect it. In other words, you, before you hit the submit button and they thought, wow, this is very surprising. They thought they might find a few hundred website. In the course of a year now they've found that there were over 3000 websites really that were doing this stuff.

[00:20:01] So they presented their findings that use neck. Oh, actually they haven't presented them yet because it's going to be a useful. In August and these are what the cold leaky forum. So yet another reason to turn off JavaScript when you can. But I also got to add a lot of the forums do not work if JavaScript's not enabled.

[00:20:23] So we got to do something about it. Maybe complain, make sure they aren't collecting your. Maybe I should do a little course on that once you can figure out are they doing it before I even give them permission? Anyhow, this is Greg Peterson. Visit me online, Craig Peter, som.com and sign up for that. No obligation insider show notes.

[00:20:44] We are shipping all kinds of military equipment over to Ukraine. And right now they're talking about another $30 billion worth of equipment being shipped to what was the world's number one arms dealer.

[00:21:00] I'm looking right now at an article that was in the Washington post. And some of their stuff is good.

[00:21:07] Some of their stuff is bad, I guess like pretty much any media outlet, but they're raising some really good points here. One of them is that we are shipping some pretty advanced equipment and some not so advanced equipment to you. To help them fight in this war to protect themselves from Russia.

[00:21:31] Now, all of that's pretty common. Ultimately looking back in history, there have been a lot of people who've made a lot of money off of wars. Many of the big banks financing, both sides of wars. Going way, way back and coming all the way up through the 20th century. And part of the way people make money in war time is obviously making the equipment and supplies and stuff that the armies need.

[00:22:03] The other way that they do it is by trading in arms. So not just the supplies. The bullets all the way through the advanced missile systems. Now there's been some concerns because of what we have been seen online. We've talked about telegram here before, not the safest webs, app to use or to keep in touch.

[00:22:28] It's really an app for your phone. And it's being used by. Ukraine to really coordinate some of their hacker activities against Russia. They've also been using it in Russia to have telegram that is in order to communicate with each other. Ukraine has posted pictures of some of the killed soldiers from Russia and people have been reaching out to their mothers in Russia.

[00:22:57] They've done a lot of stuff with telegram. It's interesting. And hopefully eventually we'll find out what the real truth is, right? Because all of a sudden hides in the military, he uses a lot of propaganda, right? The first casualty in war is the truth. It always has been. So we're selling to a comm country, Ukraine that has made a lot of money off of selling.

[00:23:22] Then systems being an intimate intermediary. So you're not buying the system from Russia? No. You're buying it from Ukraine and it has been of course, just as deadly, but now we are sending. Equipment military grade equipment to Ukraine. We could talk about just that a lot. I mentioned the whole Lend-Lease program many months ago now teams to be in the news.

[00:23:50] Now it takes a while for the mainstream media to catch up with us. I'm usually about six to 12 weeks ahead of what they're talking about. And it's so when we're talking about Lynn Lee sent me. We're not giving it to them. We're not selling it to them. We're just lending them the equipment or perhaps leasing it just like we did for the United Kingdom back in world war two, not a bad idea.

[00:24:16] If you want to get weapons into the hands of an adversary and not really, or not an adversary, but an ally or potential ally against an adversary that you have, and they have. But part of the problem is we're talking about Ukraine here. Ukraine was not invited in Donato because it was so corrupt. You might remember.

[00:24:39] They elected a new president over there that president started investigating, hired a prosecutor to go after the corruption in Ukraine. And then you heard president Joe Biden, vice president at the time bragging about how he got this guy shut down. Yeah, he got the prosecutor shut down the prosecutor that had his sights on, of course hunter Biden as well as other people.

[00:25:03] So it's a real problem, but. Let's set that aside for now, we're talking about Ukraine and the weapon systems who we've been sending over there. There have been rumors out there. I haven't seen hard evidence, but I have seen things in various papers worldwide talking about telegram, saying. The Ukrainians have somehow gotten their hands on these weapons and are selling them on telegram.

[00:25:32] Imagine that a effectively kind of a dark web thing, so we're saying the byte administration okay. There, that none of this is going to happen. Why? Because we went ahead and we put into the contracts that they could not sell or share or give any of this equipment away without the explicit permission of the United States, governor.

[00:25:57] Okay. That kind of sounds like it's not a bad idea. I would certainly put it into any contract like this, no question, but what could, what happened here? If this equipment falls into the hands of our adversaries or our other Western countries, NATO countries, how do you keep track of them? It's very hard to do.

[00:26:18] How do you know who's actually using. Very hard to do so in forcing these types of contracts is very difficult, which makes the contract pretty weak, frankly. And then let's look at Washington DC, the United States, according to the Washington post in mid April, gave Ukraine a fleet of M 17 helicopter. Now, these are my 17 helicopters are Russian, originally Soviet designs.

[00:26:51] Okay. And they were bought by the United States. About 10 years ago, we bought them for Afghans government, which of course now has been deposed, but we still have our hands on some of these helicopters. And when we bought them from Russia, We signed a contract. The United States signed a contract promising not to transfer the helicopters to any third country quote without the approval of the Russian Federation.

[00:27:23] Now that's according to a copy of the certificate that's posted on the website of Russia's federal service on military technical cooperation. Russia has come out and said that our transfer, those helicopters has grossly violated the foundations of international law. And you know what they think it has, right?

[00:27:43] Arms experts are saying the Russia's aggression Ukraine more than justifies you. I support, but the violations of the weapons contracts, man, that really hurts our credibility and our we're not honoring these contracts. How can we expect you crane to honor those contracts? That's where the problem really comes in.

[00:28:07] And it's ultimately a very big problem. So this emergency spending bill that it, the $30 billion. Makes you crane, the world's single largest recipient of us security assistance ever. They've received more in 2022 than United States ever provided to Afghanistan, Iraq, or Israel in a single.

[00:28:33] So they're adding to the stockpiles of weapons that we've already committed. We've got 1400 stinger and the aircraft systems, 5,500 anti-tank missiles, 700 switch blade drones, nine 90. Excuse me, long range Howard. There's that's our Chellora 7,000 small arms. 50 million rounds of ammunition and other minds, explosives and laser guided rocket systems, according to the Washington post.

[00:29:03] So it's fascinating to look. It's a real problem. And now that we've got the bad guys who are using the dark web, remember the dark web system that we set up, the onion network. Yeah. That one they can take these, they can sell them, they can move them around. It is a real problem. A very big problem. What are we going to do when all of those weapons systems come back aimed at us this time?

[00:29:32] It's one thing to leave billions of dollars worth of helicopters, et cetera, back in Afghanistan is the Biden administration did with her crazy withdrawal tactic. But at least those will wear out the bullets, missile systems, Howard, a different deal.

[00:29:51] It seems like the government calls a war on everything, the war against drugs or against poverty. Now we are looking at a war against end-to-end encryption by governments worldwide, including our own.

[00:30:07] The European union is following in America's footsteps steps again, only a few years behind this time.

[00:30:16] But it's not a good thing. In this case, you might remember a few have been following cybersecurity. Like I have back in the Clinton administration, there was a very heavy push for something called the clipper chip. And I think that your whole clipper chip. Actually started with the Bush administration and it was a bad thing because what they were trying to do is force all businesses to use this encryption chip set that was developed and promoted by the national security agency.

[00:30:52] And it was supposed to be an encryption device that is used to secure voice and data messages. And it had a built-in. Back door that allowed federal state, local law enforcement, anybody that had the key, the ability to decode any intercepted voice or data transmissions. It was introduced in 93 and was thank goodness.

[00:31:19] Defunct by 1996. So it used something called skipjack, man. I remember that a lot and use it to transfer Dilley or defi, excuse me, Hellman key exchange. I've worked with that maybe for crypto keys that used it. Use the Dez algorithm, the data encryption standard, which is still used today. And the Clinton administration argued that the clipper chip was.

[00:31:46] Absolutely essential for law enforcement to keep up with a constantly progressing technology in the United States. And a lot of people believe that using this would act as frankly, an additional way for terrorists to receive information and to break into encrypted information. And the Clinton administration argued that it would increase national security because terrorists would have to use it to communicate with outsiders, bank, suppliers, contacts, and the government could listen in on those calls, are we supposed to in the United States have a right to be secure in our papers and other things, right? That the federal government has no right to come into any of that stuff unless they get a court order. So they were saying we would take this key. We'll make sure that it's in a lock box, just like Al gore social security money.

[00:32:41] And no one would be able to get their hands on it, except anyone that wanted to, unless there was a court order and you know how this stuff goes. And it just continues to progress. A lot worse. There was a lot of backlash by it. The electronic privacy information center, electronic frontier foundation boast, both pushed back saying that it would be.

[00:33:05] Only have the effect of have not, excuse me, have the effect of, this is a quote, not only subjecting citizens to increased impossibly illegal government surveillance, but that the strength of the clipper Chip's encryption could not be evaluated by the public as it's designed. It was classified secret and that therefore individuals and businesses might be hobbled with an insecure communication system, which is absolutely true.

[00:33:33] And the NSA went on to do some things like pollute, random number generators and other things to make it so that it was almost impossible to have end-to-end encrypted data. So we were able to kill. Many years ago. Now what about 30 years ago? When they introduced this thing? It took a few years to get rid of it, but now the EU is out there saying they want to stop and end encryption.

[00:34:00] The United States has already said that the new director of Homeland security has, and as well as Trump's again Homeland security people said we need to be able to break the. And we've talked about some of those stories, real world stories of things that have happened because of the encryption.

[00:34:20] So the EU is now got our proposal forward. That would force tech companies to scan private messages for child sexual abuse material called CSM and evidence of grooming. Even when those messages are supposed to be protected by indenting. So we know how this goes, right? It starts at something that everybody can agree on, right?

[00:34:48] This child, sexual abuse material abductions of children, there's still a lot of slavery going on in the world. All of that stuff needs to be stopped. And so we say, yeah. Okay. That makes a whole lot of sense, but where does it end? Online services that receive detection orders. This is from ARS Technica under the pending European union legislation would have obligations concerning the detection, the reporting, the removal, and blocking of known and.

[00:35:20] Child sexual abuse material, as well as the solicitation of children. So what we're starting to see here in the us is some apps, some companies that make smartphones, for instance, looking at pictures that are sent and shared to see if it looks like it might be pornographic in. Because again, we're seeing the younger kids who are sending pictures of each other naked or body parts and they get to others.

[00:35:46] If you can believe that. Absolutely incredible. But what happens when you send them using an end-to-end encrypted app? Now, my advice for people who want to keep information private, you're a business person you're working on a deal. You don't go to Twitter like Elon Musk and put it out there for the world.

[00:36:08] Although, I'm sure he's got some ulterior motives in doing that. You use an app called signal. That's certainly the best one that's out there right now. It provides a whole lot of encryption and privacy, and even has some stuff built in to break the software. That's often used to break into the end to end encryption systems.

[00:36:29] So they're trying to get this in place here. They're calling it an important security tool. But it's ordering companies to break that end to end encryption by whatever technological means necessary. It's going to be hard because it's, frankly, it's going to be impossible for them to enforce this because you can take encrypted data and make it look like.

[00:36:53] Anything, and man has that happened for a long time? Think of the microdots way back when, certainly in rural world war two and on, they were very popular there's techniques to encrypt data and embedded in a photograph and make it almost impossible to detect. So again they're not going to get to do what they're hoping to do.

[00:37:18] And I think that's an important thing for everybody. Please pay close attention to, so they do want to get rid of end-to-end there's WhatsApp out there, which I don't really trust because it's owned by Facebook, but that's supposedly end to end. There's end to end encryption on apple. I message. Although.

[00:37:38] Apparently, there are some ways to get into that. I think apple is now maintaining a secondary key that they can use to decrypt, but the back doors that the us has called for and other people have called for. I have been pushed back by companies like apple CEO, Tim cook, oppose the government mandated back doors.

[00:38:01] Of course, apple got a major backlash from security experts when in veiled, a plan to how I phones and other devices, scan user photos for child sexual abuse images. That's what I was referring to earlier. And apple put that plan on hold and promised to make changes. But this is apple all over again. And it's hard to say what's the least privacy intrusive way, because if the ISP can read them all, if the company that's providing new with the app that you're using to send the message.

[00:38:34] I can read them all, how much privacy is there and if they can read it, who else can read it and what can be done with it? Blackmail has happened many times in the past because someone got their hands on something. So what happens when a Congressman or the military or someone in the military uses that's another problem.

[00:38:54] Because if we don't know the way the encryption is being used or is made just like, was true with a clipper chip. And then we move on to the next step, which is okay. So what do we do now with this data that we're storing? Are they going to keep that data confidential? Can they keep it out of the hands of the criminals.

[00:39:17] We've certainly found that they just haven't been able to. And if you're talking about grooming, which is what the European union wants. In other words, someone that's trying to get a child to the point where they're doing something that would be important. You've got two. Look at all of the messages, you have to have them analyze by some sort of an AI artificial intelligence, and then ultimately analyzed by people.

[00:39:42] It's just going to get worse and worse. This is the most sophisticated mass surveillance machinery. That has ever been deployed outside of China in the USSR. It's absolutely incredible when you look at it from a crypto graphic standpoint. And again, we understand protecting the children. We all want to do that, but how far will this end up going?

[00:40:06] I also want to point out that. Nu insider show notes that I've been sending out over the last few weeks have had some amazing responses from people. I've had people saying that this is what they look for in their mailbox. It's the first piece of email they read that it's the most relevant news. But you can only get it one way and that's by going to Craig peterson.com, you can sign up there.

[00:40:33] It's easy enough to do. There's no obligation on your part, right? This is not my paid newsletter. This is absolutely free. And it's incredibly valuable. Plus I'll also be sending you once a week. Ish, a small training, just, it takes you a few minutes to read. I just last week went through the firewall in your windows machine, the firewall.

[00:40:56] And gave you step-by-step instructions. Is it turned on? What is it doing? What should it do? How do you turn it on and how do you use it? So you can only get that one way and that's, if you are on my email list, so it's important to be there. And if you have any questions, you can hit reply. Any of those emails where there's a training, or if it's the insider show notes, just hit reply.

[00:41:22] And I'll go ahead and answer your question. You might have to wait a few days cause I can get pretty busy sometimes, but always answer. So me M e@craigpeterson.com. Anybody can send me email and you can also text me at 6 1 7 503 2 2 1 6 1 7 5. 3, 2, 2, 1 with any questions? That's it for right now, there is so much more.

[00:41:51] Make sure you sign up right now. And of course there's more coming right up. So stick around. .

[00:42:04] Jam packed today. We're going to start with non fungible tokens. If you don't know what those are, this is a very big deal because so many people are investing in them right now. Are they really investments? I've got a bit of a blow back here. Most people think that Bitcoin is anonymous. We're going to talk about how it absolutely is not.

[00:42:24] We're going to talk about anonymous. In fact, the Russians, Microsoft, what they're doing against the Russians and this little comedic thing about cars.

[00:42:32] NFTs or very big deal.

[00:42:34] I'm going to pull up here on my screen right now. This is a picture of Mr. Jack Dorsey. We'll go full screen, an article from a website called CoinDesk. CoinDesk is one of these sites that really tries to track what's happening out there in the Bitcoin community. Of course, nowadays it's much more than Bitcoin.

[00:42:57] Isn't it? We're talking about all kinds of. Different currencies that have a blockchain backend. They're called cryptocurrencies basically. But the big one was of course, Bitcoin. And there is a whole concept. Now, when we're talking about things like cryptocurrencies and these non fungible tokens. People have been investing them in them.

[00:43:23] Like crazy people are making millions of dollars every week. Now, remember, I am not an investment advisor and particularly I'm not your investment advisor. So take all the. To your investment advisor. I'm not telling you to buy them. I am telling you to be cautious here though, because these non fungible tokens are designed to give you the ability to be able to just, own something in the digital world.

[00:43:52] What might you own in the digital world? We've had a lot of different stuff. We've seen some just crazy monkey things. Have you seen those, these little pictures of monkeys there? Graphic designed and it's all animated. If you will. It's like cartoons and people pay money for them. One of the things that people paid money for was the rights to the first tweet ever on Twitter.

[00:44:20] So that's what you're getting. When we're talking about an NFT on a non fungible transaction, it is now yours. So this particular NFT we're talking about was of our friend here, Jack Dorsey. We'll pull it up again, this article, and he had a tweet that was sold last year for $48 million. That is a lot of money.

[00:44:47] So people look at this as an investment, but it's not the same as hanging art on the wall. You've got a Picasso that has some intrinsic value. It's a painting. It has all the oil paint on that, it was designed by and painted by a crazy man years ago. And you can take that Picasso and you can.

[00:45:11] Turn it around and sell it. It has some real value. If you own the rights to something, let's say it's one of these monkey pictures. It reminds me of a postage stamp and you paid real money for it. Some of these things are going, as I said, for over a million dollars and this Jack Dorsey first tweet went for $48 million.

[00:45:31] So let's say that's what you did, right? You bought this thing for $48 million. Really? What do you have? Because anybody can go online and look at that tweet. Anybody can print it up and stick it on a wall. Anybody can go out and get that picture of the monkeys right there. The guy drew, and you can look at it.

[00:45:54] In fact, I can pull it up right now, if you want to do. But people paid real money for that. So they've got what really? What do they have? You can't take it off the wall, like you're Picasso and salad, right? Or Banksy, if you're into the more modern art, it's just not. What is doable? How do you make this work?

[00:46:15] Only the NFT only gives you bragging rights in reality. That's what it does. You have bragging rights because you could take that digital picture and make a hundred quadrillion copies. Yeah, you'd still own the NFT you would still have in the blockchain for whatever NFT company you're using the rights to it.

[00:46:41] They would say this, you owned it. So let's talk about the blockchain behind it. There are a lot of companies that are trying to give you that. Okay. All right. I get it. Yeah, I get to to own it. But who's running the blockchain behind it. Who's validating that you own it with Bitcoin and many of these other blockchain currencies that are out there.

[00:47:08] There are various. Companies and individuals who are registered, who have all of the paperwork, if you will saying who owns, how much of what, and who paid, who and everything. And that by the way, is why it takes so long for some of these Bitcoin and other transactions to occur. But how about the NFT? There are tons of companies out there that say they will certify the NFT.

[00:47:38] So it gets to be real problem. And when we get into this Jack Dorsey tweet and this article about it, which are let me pull it up again here for you guys. This guy Sina bought the very first tweet ever from Twitter founder, Jack Dorsey for $2.9 million last year. And he decided that he wanted to sell it.

[00:48:07] So he listed it for sale again at $48 million last week. Real. He put it up for open bid and this article and CoinDesk is talking about that. And you can see that if you're watching me on rumble or YouTube, I'm showing you my screen here right now. But this Iranian born crypto entrepreneur named of again.

[00:48:32] As TAVI purchased it for $2.9 million in March, 2021. Last Thursday, he announced on Twitter where out, that he wanted to sell this and Ft. And he said, Hey, listen, I'm going to put 50% of the proceeds to charity while the auction closed. This was an open auction. People could go and bid on it and head auction closed.

[00:49:00] With a, an offer of basically $288, $277 at current prices when this article was written $277 and the lowest bid was $6. And as I recall, this is not in this article, but there were only. I handful of bids. Like when I say handful, I mean a half a dozen beds. Crazy. This is a real problem because the deadline is over.

[00:49:31] He paid how much for it, right? How much did he pay? Pull that up again. $2.9 million last year. And his highest bid was in the neighborhood of $280. Isn't that crazy. So did he get money on this? Did he win money on this? I don't know. I'm looking at those saying is it worth it to buy something like that?

[00:49:59] That you might think, oh, the very first apple computer, an apple. While that's going to be worth some serious money. Yeah, it is. It's something, you can grab onto, you can hold onto it, it's something and you can sell it. You can trade it. You can take a picture of it. You can't make digital copies of it.

[00:50:20] You, you, it's a physical thing. That's worth something. Same thing with that Picasso on the wall, it's really worth something that has some basic intrinsic. Jack's true tweet. The very first tweet. How much is that thing worth? It basically nothing. So the tweet is showing he'll pull it up on the screen again that he's selling ad Jack 2000 6 0 3 21 at eight 50 14:00 PM.

[00:50:50] Just setting up my Twitter. So there you go. There's Jack is very first to. And it's absolutely amazing. Is it worth it? Let me pull up some other stuff here for you guys. I'm going to pull this up here is Coinbase launching an NFT marketplace in hopes of appealing to crypto on mainstream users. So here's some examples from a man and FTEs.

[00:51:16] I'm going to zoom in on this for those of you guys watching on rumble or on Twitter. All right. Mean. Yeah actually you can see it on Twitter too, but YouTube, here you go. Here's some NFTs it's artwork and it's a creature. So you can buy creature number 7, 8 0 6 right now for six Eve. So let me see.

[00:51:39] Value of six. Ethereum is what ether, M two us dollars. So for 3000. And $84. As of right now, you can get a crappy picture that even I could have draw okay. Of this guy and look at all of the work this artist has put in. There's how many of these up here? 1, 2, 3, 4, or five, 10 of them. And it's the same head.

[00:52:08] Each time it looks like this almost the same eyes. He changes colors and he's got different background. It's absolutely not. So that's what they're trying to do right now, trying to sell these NFT. So who's going to buy that. Who's going to pay $3,000 for artwork that hunter Biden could have done with a straw.

[00:52:30] Anchored around. Here's another one. This is from ledger insights. NBA's launching dynamic NFTs for fans, baseball cards for the NBA that are basically just worthless. They're NF. Non fungible tokens. It has taken the crypto world by storm and people are losing millions as you look, but it really is changing the e-commerce world.

[00:52:58] Stick around. We'll be right back.

[00:53:02] Bitcoin blockchain. All of the rage, a lot of people are talking about it, but I got to say most people who are talking. I don't know much about it. And when it comes to anonymity, Bitcoin is probably the worst thing you could possibly do. It's amazing.

[00:53:20] There are a lot of misconceptions out there when it comes to technology, you have almost any kind of technology and blockchain and Bitcoin are examples of a very misunderstood technology.

[00:53:35] Now I'm not talking about how does it work? How are these ledgers maintained? How does this whole mining thing work? Why has Chan. Bandit. Why are a lot of countries going away from it, one country. Now the dictator said, yeah, we're going to use Bitcoin as our we're official currency. In addition to the U S dollar what's going on.

[00:53:57] It is complicated behind the scenes. It's complicated to use. Although there are some entrepreneurs that have made some great strides there. I saw a documentary on what has been happening in that one country. I mentioned. They are able to pay in us dollars using Bitcoin. So they'll go up to a vendor on the street.

[00:54:22] Quite literally they'll have their smartphone with them. The vendor has their smartphone. They type in 15 cents for the taco and a hit send. It goes to the other person and they have 15 cents worth of Bitcoin. By the way, these types of micro-transactions with the way Bitcoin is structured behind the scenes, make things even less manageable in the Bitcoin world than they have been in the past.

[00:54:50] And that's why in case you didn't know, Bitcoin is making some major changes here fairly soon. They've got to change the way all of this ledger stuff works because it takes too long. To record and authorized transactions. And these ledgers just get way too long when it comes to all of these kinds of microtransaction.

[00:55:14] So there's stuff going on, Bitcoin, there, there are many of these types of currencies out there. Theories comes one. You've heard about doge coin because of course that's Elon Musk has been talking about and many others and they're all different somewhat, but the main concepts are the. One of the big concepts, I'm going to pull an article up here on the screen for those watching on YouTube or also on rumble.

[00:55:39] But this is an article from our friends at wired magazine. And now you have subscribed to wired for many years. This particular one is about what wired is calling the crypto. Trap now that's a very big deal. It is a trap and it's a trap and a lot of different ways. And that's what we're going to talk about right now.

[00:56:05] Crypto is not what its name implies. A lot of people look at it and say, oh, crypto that's cryptography. That's like the German enigma machine in world war two and all of this new, great crypto that we have nowadays. And there are some pretty amazing new cryptographic technologies that we've been using, but no, that's not.

[00:56:26] What's really going on. You see the basic premise behind all of these technologies is the concept of having a. And this wallet has a unique identifier. It has a number assigned to it. So if I'm sending money to you, I'm going to have your wallet, ID, your wallet number, and I'm going to now send you some amount of fraction, most likely of a cryptocurrency.

[00:56:55] It's certainly if it's Bitcoin, it's almost certainly a fraction. And so I'm going to send you $100 worth of, let's say. What ends up happening now is these ledgers, which are public, are all going to record the Craig's sent you a hundred dollars worth of Bitcoin. Of course, it's going to be in a fraction of a Bitcoin.

[00:57:16] So sometimes there's rounding errors is not going to be really exactly a hundred dollars. Plus there's the amazing amount of. Tivoli volatility in the cyber currencies. So even though I meant just hitting a hundred dollars, mine ended up being 110 of it goes up. It might be 90. If it goes down you get that.

[00:57:34] You don't understand how that works. So the problem now is I have sent you a hundred dollars. And public ledgers that anyone can gain access to now say wallet number 1, 2, 3, 4 cent, a hundred dollars, two wallet, number 5, 6, 7, 8. Obviously the wallet numbers bruises a lot longer than that. So then it's fine.

[00:57:58] And there's a degree of anonymity there it's really called pseudo anonymity because in reality, it's not completely anonymous because people know the transaction occurred and they know the wallet numbers. Correct. It's like a bank account, and if I'm putting money into your bank account, that bank account number knows that the money came from a check that I wrote.

[00:58:21] Can you imagine that someone writing a check and that check I had a number on it, a bank account number, right? So it can all be tracked while much. The same thing is true when it comes to cryptocurrencies, these cryptocurrencies are in public ledgers and those public ledgers can be used with a little bit of work to figure out.

[00:58:42] Who you are. So this article here from our friends at wired gets really hairy. And it might be of interest to you to read, but this is talking about a take-down that happened, and this is a massive take down. This take down was of a whole group of people who were involved in some really nasty stuff.

[00:59:09] In this particular case, what it was kitty. Just a terrible thing and the abuse surrounding it. So this logical goes into not a lot of detail. I'm not going to read it because here on the air, because I don't want to upset too many people. Cause it's some of the details of this evening to think about them are incredible.

[00:59:29] But. This the police broke into this middle-class suburb home in the outskirts of Atlanta. And he there was Homeland security. It was a guy from the IRS and they came in, they took all of their electronic devices. They separated the family, putting the father who is an assistant principal at the local high school assistant printers.

[00:59:57] And he was the target of this investigation. So they had him in one room, they had his wife and another room and they put the two kids into a third room and they started questioning him. Now, this is part of a takedown of a, as I said, a whole ring of these people, including this assistant. Principal at a school.

[01:00:20] Can you believe that? So this IRS guy had flown in from Washington DC to have a look over what was going on, but this agent from the IRS and his partner whose name is let's see, his name was Jenn S Scouts. I probably got that wrong. And Tigran GAM bar Yan, Cambodian, and they had a small group of investigators and they were at a whole bunch of different federal agencies, not just the IRS.

[01:00:48] What once seemed to be. Untraceable was no longer traceable. Now I've talked on this show before about a lecture I went to by the secret service about how they had tracked down and shut down the world's largest website that was being used to sell illegal materials online. And it's fascinating what they did.

[01:01:12] But frankly, they're calling this particular boss to proof of concept and that's why they are IRS was in on this as well, but it was huge. Here's a quote from the IRS agent in this wired magazine article. He's saying he remembers how the gravity of this whole thing. Let me pull this up on the screen too.

[01:01:32] So you can read along here, but this was a high school administrator, a husband, and a father of two, whether he was guilty or innocent. The accusations, this team of law enforcement agents were leveling against him. There are mere presence in the home would almost certainly ruin his life. And he, as well as these other people were counting on anonymity from Bitcoin.

[01:01:59] Now, obviously I'm glad they got taken down, but listen, folks, if you think that it's safe, that it's anonymous, it ain't Bitcoin just ain't there. Craig peterson.com stick around.

[01:02:15] I've been blamed for really complaining about people not updating their software. And that includes things like firewalls. The FBI has stepped in and they are going ahead and doing updates for you.

[01:02:30] So once you get into this, because this is, I think something that should concern all of us, what should we be doing as a country?

[01:02:40] People are. Updating their software. They're not updating their hardware. And particularly our hardware take a look at what's been happening with the firewalls and the firewall concerns. Everybody has some sort of firewall will almost everybody, but enough people that we can say, everybody has a firewall, you get your internet from you, name it.

[01:03:05] And because of the fact they're using something called Nat network address translation, they've got some sort of firewall in front of you. So for instance, You've got your phone, right? You're using your phone and it's got internet on it. You're going through whoever your carrier is. And that carrier is giving you internet access, right?

[01:03:28] They don't have enough IP addresses, particularly IPV four, in order for you to get your very own unique little address out on the. No they do. When it comes to V6 things a little bit different, but your device is not completely exposed on the internet. Windows comes to the fire. And by default, the windows firewall is turned on.

[01:03:50] Now this gets more than a little concerning because that firewall that's turned on. Isn't really doing anything because I've got a firewall turned on and yet every service is accessible from outside, which is defeating the purpose of the firewall. Again, it's a complaint I've had about Microsoft now for.

[01:04:10] Decades, which is they have features that are just check boxes. Yes. Yes. It's got a firewall. Yeah, it's turned on, but the features don't work. So having a firewall and having everything open defeats the purpose of a firewall max do not have a firewall turned on by default, but they do have their services disabled.

[01:04:33] Which is just as effective if not more effective. So one of the things we advise people to do is go into your windows system, into the firewalls and your security settings, and turn off any services that you're not using. If you're not sharing file systems, then turn that off. In other words, You're mounting the G drive or whatever you might call it from another computer, then you don't need it.

[01:04:59] If you're not as server for what's called SMB, then you don't need to share it. So turn off everything that you don't need. That's going to happen is one of your programs isn't going to work, right? And the, what you did last year, you're going to turn it back on and you can do a lot of research online to find out what they are.

[01:05:18] We have over 200 settings that we change in windows. When we get a customer. Now on the Mac side, you can turn it on. I liked turning it on. I liked turning off the ability to see my machine. So in other words, the ability to be able to. So I turned it on and I enable specific services. And again, you can do some research on that.

[01:05:44] I've got an improving windows security course that people have taken, and we should probably do that again, if not just have some free webinars on how to do this. So you guys can learn how to do it, but not that hard to do. Anyhow, bottom line is. People aren't updating their computers, even the Macs and windows.

[01:06:06] We have a client that would just started a new client and we're tightening things up and we've been finding Mac computers that are major multiple major revisions behind. And that to me is shocking. Apple Macs are just so easy to update. It is extremely rare that an apple update will make your computer break unlike in the windows world, where it's pretty common.

[01:06:32] So windows guys, I can understand, but your even more exposed, your bigger target, you need to keep up to date. So how about all of the other equipment that we. I've had warnings again and again, with you guys about what's happening with our smart devices that are out there, right? Our security cameras we have up in the corner, right?

[01:06:56] We have these smart thermostats, people are using the list goes on and on of all of this equipment that we're using that is exposing us because when was the last time you have. How about the firmware in your router or your wifi, right? Some of the devices that I recommend to people, and if you have any questions, just email me M e@craigpeterson.com.

[01:07:19] I can give you recommendations, even if you're a home user. Although my business obviously is working with businesses on what kind of wifi to buy, what you should get, what you should do. I don't charge for any of that stuff. Okay. You get it. But you have to ask. Me@craigpeterson.com. So you get this information and you go ahead and you buy whatever it is, but you don't keep it up to date, which is why I tend to only recommend stuff that automatically updates.

[01:07:48] But that also means every few years you're going to have to replace it because unless you're using the good Cisco equipment where you can get a seven year life out of it you're not gonna find that in consumer grid. So what's happened here. I'm going to pull this up on my screen for people watching this on YouTube or on rumble.

[01:08:07] But here is a thing that came straight out of our friends here from the FBI. This is from CSO. This is a a magazine that I do follow. But they're talking about what they call psych clock. Blink. So the article says for the second time in a year, the FBI has used search and seizure warrant to clean malware from devices owned by private businesses and users without their explicit approval.

[01:08:40] The FBI used this approach to disrupt a botnet, believed to be the creation of right. Government hackers. So the calling this SYEP clock cycle clubs, blink malware discovered earlier this year. So here's the problem. What do you do if you're the federal government, how do you try and keep your country safe?

[01:09:05] Now we know. We've got these military contractors. They make missiles that take out missiles, right? The provide defensive systems. You've heard of iron dome from years ago, all the way through all of the current stuff. That's what they do, but what do they do? What can they do when there's a botnet? A botnet is where there are multiple computers in this case, probably tens of thousands of computers located in the United States that are acting like sleeper.

[01:09:36] They sit there and they wait for commands as to what they should do. Should they try and attack a machine? Should they try and spread more? Malware, what should they be doing? And the, these things are vicious. They are absolutely nasty. And in this case, we're looking at Russian malware. So Russia effectively like the Americans.

[01:09:59] You might remember that TV show. It was great show, but that. Computers that are owned by you and me and our businesses and government agencies that are under the control of the Russians. Now you don't even know it. You're using your computer or you're playing games. You're going to Facebook, whatever it is you do on your computer.

[01:10:20] Your computer is under command and control of the Russians. So the FBI goes to a court and says, Hey, we've got to go ahead and shut this down. We need a warrant. They get the warrant and the search and seizure warrant lets them now. Get on to these machines that are part of the bot net or the controlling machines for the bot net, and either remove the malware or go ahead and take control of the botnet themselves.

[01:10:49] So it can't be used. And by the way, our friends at Microsoft they've gotten involved in this too, which is really frankly, cool in shutting down some of these botnets, Hey, I want to encourage everyone. Take a couple of minutes, go to Craig peterson.com/subscribe. That's Craig Peterson. CREI G P T R S O N.

[01:11:12] And subscribe, and I'll be sending you a special report on passwords. Plus two more. I send out the most popular special reports that anybody has ever asked for.

[01:11:25] Hey, I've got a little bit more to discuss on what's happening with Russia and Microsoft and more, but I'm also going to talk about QR codes. There is a great explanation. That's in your newsletter from Monday about why you shouldn't trust him.

[01:11:41] Let's finish up this Russian thing. And then we're going to get into why you cannot trust QR codes and a brand new way.

[01:11:51] The bad guys are using QR codes to really mess with us. Now, if you're watching over on either YouTube or on rumble, you'll see this. Let me pull up my screen for you. But here we go. Okay. This is very interesting. Then the last segment, we talked a little bit about what our friends over at the FBI had been doing, which is they have been removing malware from people's computers because people haven't been keeping their computers up-to-date right.

[01:12:26] Part of the botnets. So we explained. At the FBI, isn't the only one out there trying to stop these Russians and the hackers anonymous has been very big at it. In fact, let me pull up this other article. This is from security affairs. And here we go. And it's talking about this whole army of these anonymous hackers.

[01:12:50] Now none of us have been a nightmare for many businesses that they didn't like. I had an anonymous we'll go ahead and they'll do usually pretty basic stuff. They'll do denial of service attacks and some other things, so they don't like you because of. The don't say gay bill in Florida, and, without bothering to do any research, they'll just start attacking organizations that support it, or organizations that don't support it depending on how they want to do it. So this is an interesting article here, because it's talking about these various. Websites that they've hacked. Now, some of them are government site and some of them are private industries. Now, one of the cool things, bad things about hacking private industry and releasing the emails is now the competitors to these businesses know what they're doing.

[01:13:46] And in some cases there's proprietary technology that's being released. Now, when it comes to Russian proprietary technology. The Western world doesn't care a whole lot about some of it, but here's some examples of what these hacktivists of GoDaddy. This is a company called forest 37,000 emails stolen from the company, Russian logging and wood manufacturing firm.

[01:14:09] Again, it would give a little bit of an idea into the whole Russian, what are they doing? In the forest industry. This one, I think is a little more concerning for the Russians Aero gap. This is an engineering company that focuses in the oil and gas industry. Their clients include a whole bunch of Russian companies.

[01:14:30] They've leaked approximately 100,000 emails from Aero gas. That is a huge deal because so much of the country's revenue, the number one industry in Russia is oil and gas. Petro Fort one of the largest office space and business centers in St. Petersburg, the hackers have leaked approximately 300,000 emails from Petro fork.

[01:14:56] Again, you can use that to find out what's happening in your economy. What. Doing how are businesses doing? Are they going to go under so you can see some tweets here. I've got them up on my screen on YouTube and rumble anonymous. What they're saying that they've done and you can follow anonymous directly on Twitter.

[01:15:14] Particularly fond of them. They've done a lot of things that I disagree with. This is really telling us about a whole new approach to warfare, right back in the day, you and I couldn't get involved, we could potentially take up arms and go and fight right there and think about the Spanish American war.

[01:15:33] Think about what's happening now in Ukraine, where Americans have just gone over there. Taken up firearms in order to help them defend Ukraine. People who are maybe of Ukrainian descent, maybe not right. We have never seen this type of involvement by average citizens because anonymous is not like some big fancy company or government agency anonymous is a bunch of people who are trying to be anonymous and do something.

[01:16:05] So they stole 145 gigabytes. Look at this. It's just crazy. So here. The anonymous Twitter thread itself, right? Talking about what. It's absolutely incredible. Incredible. So that's what anonymous is up to. They are hacking Russia and they're hacking Russia in a big way. Now, next stop. We have our friends at Microsoft.

[01:16:30] Microsoft has been seizing Russian domains that they are accusing of having been linked to these Russian hackers that have been going after think tanks and government agencies in the U S and the. He knew, I shouldn't say which I'm sure includes the UK cause UK has gotten involved. So this article from the verge is talking about how Microsoft has seized seven domains, belonging to fancy bear apt 28, which is we've seen them active in a number of companies here, right in the Northeast United States.

[01:17:13] These companies who are. Trying to provide materials, software, hardware for government contracts, right? So they're not even direct government contractors for the feds. They are just a sub contractors. And then we've seen fancy bear in there. We've seen the Chinese in these companies. It's incredible.

[01:17:34] They have no. DIA that all of their intellectual property is being stolen, which is why the federal government has started cracking down on contractors and subcontractors. And there's this whole paragraph 70 12 thing. We're getting geeky here, but companies that have to protect even unclassified information, confidential, classified, and they haven't been so Microsoft.

[01:18:01] Obtained a court order. You can see this on my screen, over at YouTube and at rumble to take control of each domain on April six, that then started redirecting them to a sinkhole. So what they do is they take control of the DNS for the domain. So the root name servers, now, point to a Microsoft name server, and then send them to a sinkhole.

[01:18:24] A sinkhole is basically nowhere you go there. There's nothing on the site, right? Or in this case also servers used by cybersecurity experts to capture and analyze malicious connections. And they'll do this. Oftentimes, when we're talking about these botnets, like we talked about a little earlier today, so apparently they're trying to establish long-term access to the system.

[01:18:48] So the targets, what did we just talk about? Long-term acts. But net, right? That's what button that saw. So Microsoft has gotten involved. They've been doing this now for a little while. It's obviously not their normal business model, but it is something that they've been doing. They were also, by the way, the fancy bear link to these cyber attacks on the DNC in 2016.

[01:19:12] And they also targeted the UFC election in 2020, which is why, part of the reason why anyways, don't use electronic equipment for our elections, have paper ballot, have people count those ballots yet it takes longer. You can't have the instant thing on TV, which is why all of these new services, they all don't do that.

[01:19:34] That's ridiculous. But it's the only thing we can guarantee that these guys, like I got it up on the screen again. Fancy bear the Chinese et cetera. It's the only way they can get in. And if we were doing paper ballots and we had bipartisan people counting the ballots and independence, counting the ballots, observing this, we wouldn't have all of these problems that we had with the last election where people were saying it was stolen.

[01:20:03] It was hacked. How do we know it was stolen? How do we know it? Wasn't stolen? How, go back to paper ballots, get rid of the scanning machines and particularly get rid of these electronic voting machines where you touch the screen to cast your vote. Those things are ridiculous. What if there's a software bug in it?

[01:20:21] How can you go back and change the vote? People that complained about it again, and wait a minute. I voted for this guy and you had to record my vote for the other guy. It's ridiculous. Anyways. Back to QR codes. Okay. I'm going to pull this up on this screen because I think this is a cool article here.

[01:20:40] This is from a, actually a site over in India. It's called scroll.in, and they're talking in here about how hazardous it can be. To use QR codes. Now they're not saying don't use QR codes, we've all had to use them. I've got up on my screen, this picture of being at a table. And you scan the QR code in order to get the menu.

[01:21:03] In order to order, I did that. I was in Vermont and we were riding motorcycles or buddy, and I go into the little tiny. Restaurant, small restaurant and I had a half a dozen tables and they didn't have menus. You scanned it, the QR code that was there on the table and you placed your order. And off it goes a lot of places they've been doing that with menus.

[01:21:27] You've seen that more and more saves them money as well and lets them change their prices more frequently. Yeah. Thanks for that inflation guys. Why shouldn't you use these QR codes? Why should you be extra careful? Here's the answer. QR codes are the URL of a webpage. That's the bottom line. Would you click a random URL that came in an email?

[01:21:53] Would you click on a random URL in an ad or on a web page? We certainly know better than to cook URLs in our email. But that's exactly what the QR code is. And on top of it, the URL in a QR code tends to be what we call a shortened URL. So it might be Bitly, so might be bit.ally/and then some random characters.

[01:22:19] How do you know where it's going to take? You don't all you know, is it's going to take you to Bitly, but that Bitly URL could be sending you to a malicious site. And now your phone could be hacked. It could be using your phone for Bitcoin mining for who knows what. So be very careful and the bad guys are using these in a different way that you might not have seen before, which is they are embedding QR code graphics.

[01:22:50] Into emails. And they're thinking that people are going to hold up their phone to the email and what are they going to do? They're going to scan the QR code that was in their email. And now they're in trouble. Yeah, that's simple. Hey, visit me online. Craig peterson.com. Make sure you sign up for my newsletter.

[01:23:08] Craig peterson.com/subscribe course, Craig Peterson, S O n.com. And I'm going to send you. Top three special reports, absolutely free. We got to take care of these bad guys.

View Details

Facebook Has No Idea Where Your Data Is and What They Do With It?!

Facebook's about 18 years old coming on 20 Facebook has a lot of data. How much stuff have you given Facebook? Did you fall victim for that? Hey, upload your contacts. We'll find your friends. They don't know where your data is.

[Following is an automated transcript]

[00:00:15] This whole thing with Facebook has exploded here lately.

[00:00:20] There is an article that had appeared on a line from our friends over at, I think it was, yeah. Let me see here. Yeah. Yeah. Motherboard. I was right. And motherboards reporting that Facebook doesn't know what it does with your data or. It goes, no, there's always a lot of rumors about different companies and particularly when they're big company and the news headlines are grabbing your attention and certainly Facebook can be one of those companies.

[00:00:57] So where did motherboard get this opinion about Facebook? Just being completely clueless about your personal. It tamed from a leaked document. Yeah, exactly. So we find out a lot of stuff like that. I used to follow a website about companies that were going to go under and they posted internal memos.

[00:01:23] It basically got sued out of existence, but there's no way that Facebook is going to be able to Sue this one out of existence because they are describing this as. Internally as a tsunami of privacy regulations all over the world. So Gores, if you're older, we used to call those tidal waves, but think of what the implication there is of a tsunami coming in and just overwhelming everything.

[00:01:53] So Facebook, internally, their engineers are trying to figure out, okay. So how do we deal with. People's personal data. It's not categorized in ways that regulators want to control it. Now there's a huge problem right there. You've got third party data. You've got first party data. You've got sensitive categories, data.

[00:02:16] They might know what religion you are, what your persuasions are in various different ways. There's a lot of things they might know about you. How were they all cat categorize now we've got the European union. With their general data protection regulation. The GDPR we talked about when it came into effect back in 2018, and I've helped a few companies to comply with that.

[00:02:41] That's not my specialty. My specialty is the cybersecurity. But in article five this year, peon law mandates that personal data must be collected for specified explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. So what that means is that every piece of data, like where you are using Facebook or your religious orientation, Can only be collected in use for a specific purpose and not reused for another purpose.

[00:03:19] As an example here, that vice has given in past Facebook, took the phone number that users provided to protect their accounts with two factor authentication and fed it to its people, feature as well as. Advertisers. Yeah. Interesting. Hey, so Gizmodo with the help of academic researchers caught Facebook doing this, and eventually the company had to stop the practice because, and this goes back to the earlier days where Facebook would say, Hey, find out if your friends are on Facebook, upload your contacts right now.

[00:03:54] And most people. What did you know back then about trying to keep your data private, to try and stop the proliferation of information about you online then nothing. I think I probably even uploaded it back then thinking it'd be nice to see if I got friends here. We can start chatting, et cetera.

[00:04:12] According to legal experts that were interviewed by motherboard who wrote this article and has a copy of the internal memo this year, PN regulation specifically prohibits that kind of repurposing of your phone number of trying to put together the social graph and the leaked document shows that Facebook may not even have the ability to live.

[00:04:37] How it handles user's data. Now I was on a number of radio stations this week, talking about this. And the example I gave is just look at an average business from the time it start, Facebook started how right? Wildly scraping pictures of young women off of Harvard university. Main catalog, contact page, and then asking people what do you think of this? This person, that person. And off they go, trying to rate them. Yeah. Yeah. All that matters to a woman, at least to Courtney, to mark Zuckerberg girl, all the matters about a woman is how she looks. Do I think she's pretty or not?

[00:05:15] It's ridiculous. What he was doing. It just, oh, that's zackerburg who he is not a great guy anyways. So you go from stealing pictures of young ladies asking people to rate them, putting together some class information and stuff there at Harvard, and then moving on to other universities and then open it up even wider and wider.

[00:05:42] And of course, that also created demand because you can't get on. If you're not at one of the universities that we have set it up for. And then you continue to grow. You're adding these universities, certainly starting to collect data and you are making more money than God. So what do you do? You don't have to worry about any efficiencies.

[00:06:02] I'll tell you that. Right? One thing you don't have to do is worry about gee. We've got a lot of redundant work going on here. We've got a lot of teams working on basically the same thing. No, you've got more money than you can possibly shake a stick at. So now you go ahead and send that money to this group or that group.

[00:06:24] And they put together all of the basic information, that they want. Pulling it out of this database and that database in there doing some correlation, writing some really cool CQL queries with mem credible joins and everything else. And now that becomes part of the main code for Facebook.

[00:06:45] And then Facebook goes on to the next little project and they do the same thing. Then the next project, then the next project. And then someone comes along and says, Hey, we. This feature, that feature for advertisers and then in that goes, and then along comes candidate Obama. And they, one of the groups inside Facebook says, yeah here we go.

[00:07:09] Here's all of the information we have about everybody and it's free. Don't worry about it. And then when Trump actually bought it and hired a company to try and process some of that information he got in trouble. No but the. The whole campaign could get access to anything they wanted to, again, because the data wasn't controlled, they had no idea who was doing what with the data.

[00:07:34] And according to this internal memo, they still don't know. They don't even know if they can possibly comply with these regulations, not just in Europe, but we have regulations in pretty much all of the 50 states in the U S Canada of course, has their own Australia and New Zealand think about all the places.

[00:07:57] Facebook makes a lot of. So here's a quote from that we build systems with open borders. The result of these open systems and open culture is well-described with an analogy. Imagine you hold a bottle of ink in your hand, the bottle of ink is a mixture of all kinds of user data. You pour that ink into a lake of water and K and it flows every year.

[00:08:22] The document read. So how do you put that ink back in the bottle? I, in the right bottle, how do you organize it again? So that it only flows to the allowed places in the lake? They're totally right about that. Where did they collect it from? Apparently they don't even know where they got some of this information.

[00:08:43] This data from reminds me of the no fly list. You don't know you're on it and you can't get yourself off of it. It's crazy. So this document that we're talking about, it was written last year by. Privacy engineers on the ad and business product team, whose mission is to make meaningful connections between people and businesses and which quote sits at the center of our monetization strategy.

[00:09:06] And is the engine that powers Facebook's growth. Interesting. Interesting problems. And I see this being a problem well into the future for more and more of these companies, look at Twitter as an example that we've all heard about a lot lately. And then I've talked about as well along comes Elon Musk and he says wait a minute.

[00:09:29] I can make Twitter way more profitable. We're going to get rid of however many people over a thousand, and then we are going to hire more people. We're going to start charging. We're going to be more efficient. You can bet all of these redundancies that are in Facebook are also there. And Twitter also has to comply with all of these regulations that Facebook is freaking out about it for a really a very good reason.

[00:10:00] So this document is available to anybody who wants to look at it. I'm looking at it right now, talking about regulatory landscape and the fundamental problems Facebook's data lake. And this is a problem that most companies have not. As bad as Facebook does the button. Most companies you write, you grow. I have yet to walk into a business that needs help with cybersecurity and find everything in place as it should be because it grew organically.

[00:10:32] Do you started out with a little consumer firewall router, wifi, and then you added to it and you put a switch here and you added another switch behind that and move things around. This is normal. This is not total incompetence on the part of the management, but my gosh, I don't know. Maybe they need an Elon Musk.

[00:10:52] Just straighten them out as well. Hey, stick around. I'll be right back and sign up online@craigpeterson.com.

[00:11:02] Apparently looting is one of the benefits of being a Russian soldier. And according to the reports coming out of Ukraine, they've been doing it a lot, but there's a tech angle on here that is really turning the tables on these Russian Looters.

[00:11:19] We know in wars, there are people that loot and typically the various militaries try and make sure, at least recently that looting is kept to an absolute minimum.

[00:11:32] Certainly the Americans, the British, even the Nazis during world war II the the socialists they're in. Germany they tried to stop some of the looting that was going on. I think that's probably a very good thing, because what you end up with is just all of these locals that are just totally upset with you.

[00:11:57] I found a great article on the guardian and there's a village. I hadn't been occupied for about a month by Russian troops and the people came back. They are just shocked to see what happened in there. Giving a few examples of different towns. They found that the alcohol was stolen and they left empty bottles behind food wrappers, cigarette butts, thrown all over the place in apartments in the home.

[00:12:26] Piles of feces blocking the toilets, family photographs torn, thrown around the house. They took away all of the closes as a code from one of the people, literally everything, male and female coats, boots, shirts, jackets, even my dresses and laundry. This is really something. The Sylvia's didn't do this, but now Russia.

[00:12:49] The military apparently does. So over the past couple of weeks, there have been reporting from numerous places where Russian troops had occupied Ukrainian territory and the guardian, which is this UK newspaper collected evidence to suggest looting by Russian forces was not merely a case of a few way, word soldiers, but a systematic part of Russian military behavior across multiple towns.

[00:13:17] And villages. That's absolutely amazing. Another quote here, people saw the Russian soldiers loading everything onto your old trucks. Everything they could get their hands on a dozen houses on the villages. Main street had been looted as well as the shops. Other villagers reported losing washing machines, food laptops, even as sofa, air conditioner.

[00:13:41] Being shipped back, just you might use ups here or they have their equivalent over there. A lady here who was the head teacher in the school, she came back in, of course, found her home looted and in the head teacher's office. She found an open pair of scissors that had been jammed into a plasma screen that was left behind because if they can't steal it, they're going to destroy it.

[00:14:07] They don't wanna leave anything behind. They found the Russian to take in most of the computers, the projectors and other electronic equipment. It's incredible. So let's talk about the turnaround here. You might've heard stories about some of these bad guys that have smashed and grabbed their way into apple stores.

[00:14:27] So they get into the apple store. They grab laptops on iPads, no longer iPods, because they don't make those anymore. And I phone. And they take them and they run with them. Nowadays there's not a whole lot of use for those. Now what they have been doing, some of these bad guys is they'd take some parts and use them in stolen equipment.

[00:14:52] They sell them on the used market, et cetera. But when you're talking about something specific, like an iPhone that needs specific activation. Completely different problem arises for these guys because that iPhone needs to have a SIM card in order to get onto the cell network. And it also has built in serial numbers.

[00:15:15] So what happens in those cases while apple goes ahead and disables them. So as soon as they connect to the internet, they didn't say they put them on wifi. They don't get a SIM card. They don't. Service from T-Mobile or Verizon or whoever it might be. So now they just connect to the wifi and it calls home.

[00:15:33] Cause it's going to get updates and download stuff from the app store and they find that it's been bricked. Now you can do that with a lot of mobile device managers that are available for. All kinds of equipment nowadays, but certainly apple equipment where if a phone is lost or stolen or a laptop or other pieces of equipment, you can get on the MDM and disable it, have it remotely erase, et cetera.

[00:16:00] Now, please have had some interesting problems with that. Because a bad guy might go ahead and erase a smartphone. That's in the evidence locker at the police station. So they're doing things like putting them into Faraday cages or static bags or other things to try and stop that. So I think we've established here that the higher tech equipment is pretty well protected.

[00:16:25] You steal it. It's not going to do you much. Good. So one of the things the Russian stole when they were in a it's called a, I think you pronounced. Melad Mellott DePaul which is again, a Ukrainian city is they stole all of the equipment from a farm equipment dealership and shipped it to check. Now that's according to a source in a businessman in the area that CNN is reporting on.

[00:16:56] So they shipped this equipment. We're talking about combine harvesters were 300 grand a piece. They shipped it 700 miles. And the thieves were ultimately unable to use the equipment because it had been locked remotely. So think about agriculture equipment that John Deere, in this case, these pieces of equipment, they, they drive themselves.

[00:17:23] It's atonomous it goes up and down the field. Goes to any pattern that you want to it'll bring itself within a foot or an inch of your boundaries, of your property being very efficient the whole time, whether it's planting or harvesting, et cetera. And that's just a phenomenal thing because it saves so much time for the farmer makes it easier to do the companies like John Deere.

[00:17:49] Want to sell as many pieces of this equipment as they possibly can. And farming is known to be a what not terribly profitable business. And certainly isn't like Facebook. So how can they get this expensive equipment into the hands of a lot of farmers? What they do is they use. So you can lease the equipment through leasing company or maybe directly from the manufacturer and now you're off and running.

[00:18:16] But what happens if the lease isn't paid now? It's one thing. If you don't pay your lease on a $2,000 laptop, right? They're probably not going to come hunting for you, but when you're talking about a $300,000 harvester, they're more interested. So the leasing company. Has titled to the equipment and the leasing company can shut it off remotely.

[00:18:41] You see where I'm going with this so that they can get their equipment in the hands of more farmers because the farmers can lease it. It costs them less. They don't have to have a big cash payment. You see how this all works. So when the Russian forces stole this equipment, that's valued, total value here is about $5 million.

[00:19:02] They were able to shut it all off. And th the, obviously if you can't start the engine, because it's all shut off and it's all run by computers nowadays, and there's pros and cons to that. I think there's a lot of cons, but what are you going to do? How's that going to work for? Isn't going to work for you.

[00:19:22] And they were able to track it and had GPS trackers find out exactly where it was. That's how they know it was Tara taken to Chechnya and could be controlled remotely. And in this case, how did they control it? They completely. Shut it off, even if they sell the harvesters for spare parts to learn some money, but they sure aren't gonna be able to sell them for the 300 grand that they were actually worth.

[00:19:48] Hey, stick around. We'll be right back and visit me online@craigpeterson.com. If you sign up there, you'll be able to get my insider show notes. And every week I have a quick. Training right there. New emails, Craig Peterson.com.

[00:20:05] If you've been worried about ransomware, you are right to worry. It's up. It's costly. And we're going to talk about that right now. What are the stats? What can you do? What happens if you do get hacked? Interesting world!

[00:20:20] Ransomware has been a very long running problem. I remember a client of ours, a car dealership who we had gone in.

[00:20:31] We had improved all of their systems and their security, and one of them. People who was actually a senior manager, ended up downloading a piece of ransomware, one of these encrypted ones and opened it up and his machine all of a sudden, guess what it had ransomware on it. One of those big. Green's that say, pay up and send us this much Bitcoin, and here's our address.

[00:21:00] All of that sort of stuff. And he called us up and said, what's going on here? What happened? First of all, don't bring your own machine into the office. Secondly, don't open up as particularly encrypted files using a password that they gave. And thirdly, we stopped it automatically. It did not spread.

[00:21:20] We were able to completely restore his computer. Now let's consider here the consequences of what happened. So he obviously was scared. And within a matter of a couple of hours, we actually had him back to where he was and it didn't spread. So the consequences there, they weren't that bad. But how about if it had gotten worse?

[00:21:47] How about if the ransomware. Also before it started holding his computer ransom, went out and found all of the data about their customers. What do you think an auto dealership would love to hear that all of their customer data was stolen and released all of the personal data of all of their customers?

[00:22:08] Obviously not. So there's a potential cost there. And then how long do you think it would take a normal company? That thinks they have backups to get back online. All I can tell you it'll take quite a while because the biggest problem is most backups don't work. We have yet to go into a business that was actually doing backups that would work to help restore them.

[00:22:35] And if you're interested, I can send you, I've got something I wrote up. Be glad to email it back to you. Obviously as usual, no charge. And you'll be able to go into that and figure out what you should do. Cause I, I break it down into the different types of backups and why you might want to use them or why you might not want to use them, but ransomware.

[00:22:58] Is a kind of a pernicious nasty little thing, particularly nowadays, because it's to two factor, first is they've encrypted your data. You can't get to it. And then the second side of that is okay I can't get to my data and now they're threatening to hold my data ransom or they'll release. So they'll put it out there.

[00:23:22] And of course, if you're in a regulated industry, which actually car dealers are because they deal with financial transactions, leases, loans, that sort of thing you can lose your license for your business. You can, you lose your ability to go ahead and frankly make loans and work with financial companies and financial instruments.

[00:23:45] It could be a very big. So there are a lot of potential things that can happen all the way from losing your reputation as a business or an individual losing all of the money in your operating account. And again, we've got a client that we picked up afterwards. That yes, indeed. That lost all of the money in their operating account.

[00:24:09] And then how do you make payroll? How do you do things? There's a new study that came out from checkpoint. Checkpoint is one of the original firewall companies and they had a look at ransomware. What are the costs of ransomware? Now bottom line, I'm looking at some stats here on a couple of different sites.

[00:24:29] One is by the way, Conti, which is a big ransomware gang that also got hacked after they said we are going to attack anyone. That doesn't defend Plaid's invasion of Ukraine, and then they got hacked and their information was released, but here's ransomware statistics. This is from cloud words. First of all, the largest ransom demand is $50 million.

[00:24:55] And that was in 2021 to Acer big computer company. 37% of businesses were hit by ransomware. In 2021. This is amazing. They're expecting by 2031. So in about a decade, ransomware is going to be costing about $265 billion a year. Now on average. Ransomware costs businesses. 1.8, $5 million to recover from an attack.

[00:25:25] Now that's obviously not a one or two person place, but think of the car dealer again, how much money are they going to make over the year or over the life of the business? If you're a car dealer, you have a license to print money, right? You're selling car model or cars from manufacturers. And now you have the right to do that and they can remove that.

[00:25:48] How many tens, hundreds of millions of dollars might that end up costing you? Yeah. Big deal. Total cost of ransomware last year, $20 billion. Now these are the interesting statistics here right now. So pay closer attention to this 32% of ransomware victims paid a ransom. So about a third Peter ransom demand.

[00:26:12] Lastly. It's actually down because my recollection is it used to be about 50% would pay a ransom. Now on average that one third of victims that paid a ransom only recovered 65% of their data. Now that differs from a number I've been using from the FBI. That's a little bit older that was saying it ends it a little better than 50%, but 65% of pain victims recovered their.

[00:26:41] Now isn't that absolutely amazing. Now 57% of companies were able to recover their data, using a cloud backup. Now think about the different types of backup cloud backup is something that can work pretty well if you're a home user, but how long did it take for your system to get back? Probably took weeks, right?

[00:27:05] For a regular computer over a regular internet line. Now restoring from backups is going to be faster because your downlink is usually faster than your uplink. That's not true for businesses that have real internet service like ours. It's the same bandwidth up as it is down. But it can take again, days or weeks to try and recover your machine.

[00:27:28] So it's very expensive. And I wish I had more time to go into this, but looking at the costs here and the fact that insurance companies are no longer paying out for a lot of these ransomware attacks, it could be credibly expensive for you incredibly. The number one business types by industry for ransomware attacks, retail.

[00:27:59] That makes sense. Doesn't it. Real estate. Electrical contractors, law firms and wholesale building materials. Isn't that interesting? And that's probably because none of these people are really aware or conscious of doing what a, of keeping their data secure of having a good it team, a good it department.

[00:28:24] So there's your bottom line. Those are the guys that are getting hit. The most, the numbers are increasing dramatically and your costs are not just in the money. You might pay as a ransom. And as it turns out in pretty much every case prevention. Is less expensive and much better than the cure of trying to pay ransom or trying to restore from backups.

[00:28:52] Hey, you're listening to Craig Peterson. You can get my weekly show notes by just going to craig peterson.com.

[00:29:00] You and I have talked about passwords before the way to generate them and how important they are. We'll go over that again a little bit in just a second, but there's a new standard out there that will eliminate the need for passwords.

[00:29:16] Passwords are a necessary evil, at least they have been forever. I remember, I think the only system I've ever really used that did not require passwords was the IBM 360.

[00:29:31] Yeah, 360, you punch up the cards, all of the JCL you feed the card deck in and off it goes. And does this little thing that was a different day, a different era. When I started in college in university, we. We had a remote systems, timeshare systems that we could log into. And there weren't much in the line of password requirements.

[00:29:58] And, but you had a username, you had a simple password. And I remember one of our instructors, his name was Robert, Andrew Lang, and his password was always some sort of a combination of RA Lang. So it was always easy to guess what his password was. Today. It has gotten a lot worse today. We have devices with us all the time.

[00:30:22] You might be wearing a smart watch. That requires a password. You course probably have a smartphone that also maybe requiring a password. Certainly after it boots nowadays they use fingerprints or facial recognition, which is handy, but it has its own drawbacks. But how about the websites? You're going to the systems you're using in you're at work and logging in.

[00:30:49] They all require password. And usernames of some sort or another well, apple, Google, and Microsoft have all committed to expanding their support for a standard. That's actually been out there for a few years. It's called the Fido standard. And the idea behind this is that you don't have to have a password in order to.

[00:31:15] Now that's really an interesting thing, right? Just looking at it because we're so used to have in this password only authenticate. And of course the thing to do there is to make sure you have for your password, multiple words in the password, it should really be a pass phrase. And between the words put in special characters or numbers, maybe.

[00:31:41] Upper lower case a little bit. In those words, those are the best passwords, 20 characters, 30 characters long. And then if you have to have a pin, I typically use a 12 digit pin. And how do I remember all of these? Cause I use a completely different password for every website and right now, Let me pull it up.

[00:32:03] I'm using one password dot coms, password manager. And my main password for that is about 25 characters long. And I have thirty one hundred and thirty five. And trees here in my password manager, 3,100, that is a whole lot of passwords, right? As well as software licenses and a few other things in there.

[00:32:30] That's how we remember them is using a password manager. One password.com is my favorite. Now, obviously I don't make any money by referring you there. I really do like that. Some others that I've liked in the past include last pass, but they really meant. With some of their cybersecurity last year and I lost my faith in it.

[00:32:51] So now what they're trying to do is make these websites that we go to as well as some apps to have a consistent, secure, and passwordless. And they're going to make it available to consumers across all kinds of devices and platforms. That's why you've got apple, Google, and Microsoft all committing to it.

[00:33:15] And you can bet everybody else is going to follow along because there's hundreds of other companies that have decided they're going to work with the Fido Alliance and they're going to create this passwordless future. Which I like this idea. So how does this work? Basically you need to have a smartphone.

[00:33:33] This is, I'm just going to go with the most standard way that this is going to work here in the future, and you can then have. Passkey, this is like a multi-factor authentication or two factor authentication. So for instance, right now, when I sign into a website online, I'm giving a username, given a password, and then it comes up and it asks me for a code.

[00:33:57] So I enter in a six digit code and that code changes every 30 seconds. And again, I use my password manager from one password. In order to generate that code. So that's how I log into Microsoft site and Google sites and all kinds of sites out there. So it's a similar thing here now for the sites for my company, because we do cyber security for businesses, including regulated businesses.

[00:34:24] We have biometrics tied in as. So to log into our systems, I have to have a username. I have to have a password. I then am sent to a single sign-on page where I have to have a message sent to my smart device. That then has a special app that uses biometrics either a face ID or a fingerprint to verify who I am.

[00:34:49] Yeah, there's a lot there, but I have to protect my customers. Something that very few it's crazy. Actual managed security services providers do, but it's important, right? By the way, if you want my password. Special report, just go to Craig peterson.com. Sign up for my email list. I'll send that to you.

[00:35:13] That's what we're sending out right now for anyone who signs up new@craigpeterson.com. And if you'd like a copy of it in you're already on the list, just go ahead and email me. At Craig peterson.com and ask for the password special report where I go through a lot of this sort of thing. So what will happen with this is you go to a website and I might come up with a QR code.

[00:35:37] So you then scan that QR code with your phone and verify it, authorize it on your phone. You might again to have it set up so that your phone requires a facial recognition or perhaps it'll require a fingerprint. And now you are. Which is very cool. They fix some security problems in Fido over the last few years, which is great over the coming year.

[00:36:02] You're going to see this available on apple devices, Google Microsoft platforms, and it really is simple, stronger authentication. That's sort of Fido calls it. But it is going to make your life a lot easy, easier. It is a standard and the passwordless future makes a whole lot of sense for all of us. Now, I want to talk about another thing here that just bothered me for a long time.

[00:36:30] I have a sister. Who is in the medical field and gives prescriptions, doctor thing. And I think she's not quite a doctor. I can't remember what she has. She's an LPN or something. And anyhow, so she. We'll get on a zoom call with someone and they'll go through medical history and what's happening right now and she'll make prescriptions.

[00:36:57] And so I warned her about that saying, it is very bad to be using zoom because zoom is not secure. Never has been, probably never will be right. If you want secure. To go and pay for it from one of these providers like WebEx, that's what we use. We have a version of WebEx that is set up to be secure.

[00:37:20] So I talked to her about that and said, Hey, listen, you can't do this. You've really got to go another way here. And so she started using one of these mental or. Medical health apps. What I want to talk about right now specifically are some checks that were just performed some audits on mental health apps.

[00:37:45] That's why I messed up a second ago, but what they looked at is that things are a serious problem there. And then fact, the threat post, just calling it a. Frankly, just plain old creepy. So they've got some good intentions. They want to help with mental health. You've probably seen these or at least heard them advertise.

[00:38:06] So you can get on the horn with a mental health professional, a doctor or otherwise in order to help you here with your psychological or spiritual wellness. And people are sharing their personal and sensitive data with third parties and have 32 mental health and prayer mobile apps that were investigated by the open source organization.

[00:38:32] 28, 28 of the 32 were found to be inherently insecure and were given a privacy not included label, including others here. So this is a report. That was released here by the open source organization, tied into Mozilla. Those are the Firefox people. They have what they call their minimum security standards.

[00:38:56] So things like requiring strong passwords, managing security, updates, and vulnerabilities, et cetera. 25 of the 32 failed to meet. Even those minimum security standards. So these apps are dealing with some of the most sensitive mental health and wellness issues people can possibly have, right? Depression, anxieties, suicidal fonts, domestic violence, eating disorders.

[00:39:23] And they are being just terrible with your security Mozilla researchers spent 255 hours or about eight hours per product pairing under the hood of the security, watching the data that was going back and forth, right between all of these mental health and prayer apps. It was just crazy. So for example, eight of the apps reviewed, allowed weak passwords, that range.

[00:39:52] One digit one as the password to 1, 1, 1, 1, while a mental health app called a mood fit only required one letter or digit as a password. Now that is very concerning for an app that collects mood and symptom data. So be very careful. Two of the apps better help a popular app that connects users with therapists and better stop suicide, which is a course of suicide prevention app have vague and messy, according to Mozilla privacy policies that have little or no effect on actual.

[00:40:30] User data protection. So be very careful. And if you're a mental health, professional or medical professional, don't just go and use these open video calls, et cetera, et cetera, find something good. And there are some standards out there. Again. Visit me online, get my insider show notes every week. Get my little mini trends.

[00:40:56] And they come up most weeks. Just go to Craig peterson.com. And I'll send you my special report on passwords and more.

[00:41:06] We know the Russians have been attacking us. I've talked a lot about it on the radio station, all kinds of stations. In fact, here over the last couple of weeks, and I am doing something special, we are going through the things you can do to keep safe.

[00:41:23] Last week we started doing something I promise we would continue.

[00:41:27] And that is how can you protect yourself when it comes to the Russians, right? When it comes to the bad guys, because the Russians are definitely the bad guys. There's a few things you can do. And there's a few things, frankly, you shouldn't be doing. And that's exactly what we're going to talk about right now.

[00:41:45] So last week he went over some steps, some things that you can look at that you should look at that are going to help protect you. And we are going to go into this a whole lot more today. And so I want you to stick around and if you miss anything, you can go online. You can go to Craig peterson.com, make sure you sign up there for my email.

[00:42:08] And what I'm going to do for you is. Send you a few different documents now where we can chat back and forth about it, but I can send you this. Now I'm recording this on video as well as on audio. So you can follow along if you're watching either on YouTube or. Over on rumble and you can find it also on my website.

[00:42:32] I've been trying to post it up there too, but right now let's talk about what we call passive backend protections. So you've got the front end and the front end of course, is. Stuff coming at you, maybe to the firewall I've mentioned last week about customers of mine. I was just looking at a few customers this week, just so I could have an idea of their firewalls.

[00:42:59] And they were getting about 10 attacks per minute. Yeah. And these were customers who have requirements from the department of defense because they are defense sub subcontractors. So again, Potential bad guys. So I looked up their IP addresses and where the attacks were coming from. Now, remember that doesn't mean where they originated because the bad guys can hop through multiple machines and then get onto your machine.

[00:43:28] What it means is that all, ultimately they ended up. Coming from one machine, right? So there's an IP address of that machine. That's attacking my clients or are attacking my machines. That just happens all the time. A lot of scans, but some definite attacks where they're trying to log in using SSH.

[00:43:48] And what I found is these were coming from Slovakia, Russia, and Iran. Kind of what you were expecting, right? The Iranians, they just haven't given up yet. They keep trying to attack, particularly our military in our industry. One of the things we found out this week from, again, this was an FBI notice is that the Russians have been going after our industrial base.

[00:44:15] And that includes, in fact, it's more specifically our automobile manufacturers we've already got problems, right? Try buying a new car, try buying parts. I was with my friend, just this. I helped them because he had his car right. Need to get picked up. So I took him over to pick up his car and we chatted a little bit with this small independent automotive repair shop.

[00:44:40] And they were telling us that they're getting sometimes six, eight week delays on getting parts and some parts. They just can't. So they're going to everything from junkyards on out, and the worst parts are the parts, the official parts from the car manufacturers. So what's been happening is Russia apparently has been hacking into these various automobile manufacturers and automobile parts manufacturers.

[00:45:10] And once they're inside, they've been putting in. A remote control button net. And those botnets now have the ability to wake up when they want them to wake up. And then once they've woken up, what do they do? Who knows? They've been busy erasing machines causing nothing, but having they've been doing all kinds of stuff in the past today, they're sitting there.

[00:45:31] Which makes you think they're waiting, it's accumulate as much as you possibly can. And then once you've got it all accumulated go ahead and attack. So they could control thousands of machines, but they're not just in the U S it's automobile manufacturers in Japan. That we found out about.

[00:45:50] So that's what they're doing right now. So you've got the kind of that front end and back end protections. So we're going to talk a little bit about the back end. What does that mean? When a cybersecurity guy talks about the backend and the protections. I got it up on my green right now, but here's the things you can do.

[00:46:10] Okay. Remember, small businesses are just getting nailed from these guys, because again, they're fairly easy targets. One change your passwords, right? How many times do we have to say that? And yet about 70% of businesses out there are not using a good password methodology. If you want more information on passwords, two factor authentication, you name it.

[00:46:37] Just email me M e@craigpeterson.com. I want to get the information out now. You got to make sure that all of the passwords on your systems are encrypted are stored in some sort of a good password vault as you really should be looking at 256 bit encryption or better. I have a vendor of. That I use. So if you get my emails every week, when them, there's the little training.

[00:47:06] And so I'll give you a five minute training. It's written usually it's in bullet point for, I'm just trying to help you understand things. That provider of mine has a big database and there's another provider that I use that is for. So the training guys use the database of my provider.

[00:47:27] In using that database, they're storing the passwords and the training providers putting passwords in the clinics. Into the database, which is absolutely crazy. So again, if you're a business, if you're storing any sort of personal information, particularly passwords, make sure that you're using good encryption and your S what's called salting the hash, which means.

[00:47:53] You're not really storing the password, just joining assaulted hash. I can send you more on this. If you are a business and you're developing software that's, this is long tail stuff here. Configure all of the security password settings so that if someone's trying to log in and is failing that, and you block it, many of us that let's say you're a small business.

[00:48:15] I see this all of the time. Okay. You're not to blame. You, but you have a firewall that came from the cable company. Maybe you bought it at a big box retailer. Maybe you bought it online over at Amazon, as hurricane really great for you. Has it got settings on there that lets you say. There's 20 attempts to log in.

[00:48:38] Maybe we should stop them. Now, what we do personally for our customers is typically we'll block them at somewhere around three or four failed attempts and then their passwords block. Now you can configure that sort of thing. If you're using. Email. And that's an important thing to do. Let me tell you, because we've had some huge breaches due to email, like Microsoft email and passwords and people logging in and stealing stuff.

[00:49:06] It was just a total nightmare for the entire industry last year, but limit the number of login retries as well as you're in there. These excessive login attempts or whatever you want to define it as needs to lock the account. And what that means is even if they have the right password, they can't get in and you have to use an administrative password in order to get in.

[00:49:31] You also want to, what's called throttle, the rate of repeated logins. Now you might've gotten caught on this, right? You went to your bank, you went to E-bay, you went to any of these places and all of a sudden. And denied you write it blocked you. That can happen when your account is on these hackers lists.

[00:49:51] You remember last week we talked about password spraying while that's a very big deal and hackers are doing the sprain trick all of the time, and that is causing you to get locked out of your own account. So if you do get locked out, remember it might be because someone's trying to break. Obviously you have to enforce the policies.

[00:50:16] The capture is a very good thing. Again, this is more for software developer. We always recommend that you use multifactor or two factor authentication. Okay. Do not use your SMS, your text messages for that, where they'll send you a text message to verify who you are. If you can avoid that, you're much better off.

[00:50:36] Cause there's some easy ways to get around that for hackers that are determined. Okay. A multi-factor again, installed an intrusion. system. We put right at the network edge and between workstations and servers, even inside the network, we put detection systems that look for intrusion attempts and block intrusion attempts.

[00:51:02] A very important use denied lists to block known attackers. We build them automatically. We use some of the higher end Cisco gates. Cisco is a big network provider. They have some of the best hardware and software out there, and you have to subscribe to a lot of people complain. I ain't going to just go buy a firewall for 200 bucks on Amazon.

[00:51:24] Why would I pay that much a month just to to have a Cisco firewall? And it's like praying pain for the brand. I've got by logo chert on here. Oh, I wouldn't pay for that. No, it's because they are automatically providing block lists that are updated by the minute sometimes. And then make sure you've got an incident response plan in place.

[00:51:50] What are you going to do when they come for you? What are you going to do?

[00:51:55] Now we're going to talk about prevention. What can you do an order to stop some of these attacks that are coming from Russia and from other countries, it is huge. People. Believe me, this is a very big problem. And I'm here to help.

[00:52:12] We've reviewed a number of things that are important when it comes to your cyber security and your protection.

[00:52:20] We talked about the front end. We talked about the backend. Now we're going to talk about pure prevention and if you're watching. Online. You'll be able to see my slides as they come up, as we talk about some of this stuff and you'll find me on YouTube and you'll also find me on rumble, a fairly new platform out there platform that doesn't censor you for the things you say.

[00:52:44] Okay. So here we go. First of all, enabling your active directory password protection is going to. Four's password protection all the way through your business. Now I've had some discussions with people over the months, over the years about this whole thing and what should be done, what can be done, what cannot be done.

[00:53:09] Hey, it's a very big deal when it comes to password protection and actor directory, believe it or not, even though it's a Microsoft product is pretty darn good at a few things. One of them is. Controlling all the machines and the devices. One of the things we do is we use an MDM or what used to be a mobile device manager called mass 360.

[00:53:34] It's available from IBM. We have a special version of that allows us as a managed security services provider to be able to control everything on people's machines. Active directory is something you should seriously consider. If you are a Mac based shop. Like I am. In fact, I'm sitting right now in front of two max that I'm using right now, you'll find that active directory is a little bit iffy.

[00:54:04] Sometimes for max, there are some work around and it's gotten better mastery. 60 is absolutely the way to go, but make sure you've got really good. Passwords and the types of passwords that are most prone to sprain the attacks are the ones you should be banning specifically. Remember the website? Have I been poned?

[00:54:28] Yeah. It's something that you should go to pretty frequently. And again, if you miss anything today, just email me M e@craigpeterson.com. Believe me, I am not going to harass you at all. Okay. Now, the next thing that you should be doing is what's called red team blue team. Now the red team is a group of people, usually outside of your organization.

[00:54:54] If you're a big company they're probably inside, but the red team is the team that attacks you. They're white hat hackers, who are attacking you, looking for vulnerabilities, looking for things that you should or shouldn't be doing. And then the blue team is the side that's trying to defend. So think of, like war games.

[00:55:12] Remember that movie with Matthew Broderick all of those decades ago and how the, he was trying to defend that computer was trying to defend that it moved into an attack mode, right? Red team's attack, blue team is defend. So you want. To conduct simulated attacks. Now w conducting these attacks include saying, oh my let's now put in place and execute our plan here for what are we going to do once we have a.

[00:55:44] And you darn well better have a breach plan in place. So that's one of the things that we help as a fractional chief information security officer for companies, right? You've got to get that in place and you have to conduct these simulated attacks and you have to do penetration testing, including password spraying attacks.

[00:56:04] There's so many things you can do. The one of the things that we like to do and that you might want to do, whether you're a home user, retiree or a business is go and look online, you can just use Google. I use far more advanced tools, but you can use Google and look for your email address right there.

[00:56:23] Look for the names of people inside your organization. And then say wait a minute, does that data actually need to be there? Or am I really exposing the company exposing people's information that shouldn't be out there because you remember the hackers. One of the things they do is they fish you fish as in pH.

[00:56:47] So they'll send you an email that looks like. Hey let me see. I know that Mary is the CFO, and I know that Joe's going to be out of town for two weeks in The Bahamas, not a touch. So while he's got. I'm going to send an email to Mary, to get her to do something, to transfer the company's funds to me.

[00:57:06] Okay. So that's what that's all about. You've got to make sure, where is our information? And if you go to my company's page, mainstream.net, you'll see on there that I don't list any of the officers or any of the people that are in the company, because that again is a security problem.

[00:57:24] We're letting them know. I go to some of these sites, like professional sites lawyers, doctors, countenance, and I find right there all, are there people right there top people or sometimes all of them. And then we'll say, yeah, I went to McGill university, went to Harvard, whatever my B. It's all there. So now they've got great information to fish you, to fish that company, because all they have to do is send an email to say, Hey, you remember me?

[00:57:56] We're in Harvard when this class together. And did you have as a professor to see how that works? Okay. You also want to make. That you implement, what's called a passwordless user agent, and this is just so solely effective. If they cannot get into your count, what's going to, what could possibly go wrong, but one of the ways to not allow them into the count is to use.

[00:58:24] Biometrics. We use something called duo and we have that tied into the single sign-on and the duo single sign-on works great because what it does now is I put in, I go to a site, I put it into my username and. Pulls up a special splash page that is running on one of our servers. That again asks me for my duo username.

[00:58:48] So I've got my username for the site then to my dual username and my duo password single sign on. And then it sends me. To an app on my smart device, a request saying, Hey, are you trying to log into Microsoft? And w whatever it might be at Microsoft, and you can say yes or no, and it uses biometric.

[00:59:11] So those biometrics now are great because it says, oh, okay, I need a face ID or I need a thumb print, whatever it might be that allows a generalized, a password, less access. Okay. Password less. Meaning no pass. So those are some of the top things you can do when it comes to prevention. And if you use those, they're never going to be able to get at your data because it's something you have along with something, it works great.

[00:59:45] And we like to do this. Some customers. I don't like to go through those hoops of the single sign-on and using duo and making that all work right where we're fine with it. We've got to keep ourselves, at least as secure as the DOD regulations require unlike almost anybody else in industry, I'm not going to brag about it.

[01:00:09] But some of our clients don't like to meet the tightest of controls. And so sometimes they don't. I hate to say that, but they just don't and it's a fine line between. Getting your work done and being secure, but I think there's some compromises it can be readily made. We're going to talk next about saving your data from ransomware and the newest ransomware.

[01:00:36] We're going to talk about the third generation. That's out there right now. Ransomware, it's getting crazy. Let me tell ya and what it's doing to us and what you can do. What is a good backup that has changed over the last 12 months? It's changed a lot. I used to preach 3, 2, 1. There's a new sheriff in town.

[01:00:58] Stick around Craig peterson.com.

[01:01:02] 3, 2, 1 that used to be the standard, the gold standard for backing up. It is no longer the case with now the third generation of ransomware. You should be doing something even better. And we'll talk about it now.

[01:01:19] We're doing this as a simulcast here. It's on YouTube. It is also on rumble.

[01:01:27] It's on my website@craigpeterson.com because we're going through the things that you can do, particularly if you're a business. To stop the Russian invasion because as we've been warned again and again, the Russians are after us and our data. So if you missed part of what we're talking about today, or.

[01:01:50] Last week show, make sure you send me an email. me@craigpeterson.com. This is the information you need. If you are responsible in any way for computers, that means in your home, right? Certainly in businesses, because what I'm trying to do is help and save those small businesses that just can't afford to have full-time.

[01:02:15] True cyber security personnel on site. So that's what the whole fractional chief information security officer thing is about. Because you just, you can't possibly afford it. And believe me, that guy that comes in to fix your computers is no cyber security expert. These people that are attacking our full time cybersecurity experts in the coming from every country in the world, including the coming from the us.

[01:02:44] We just had more arrests last week. So let's talk about ransomware correctly. Ransomware, very big problem. Been around a long time. The first version of ransomware was software got onto your computer through some mechanism, and then you had that red screen. We've all seen that red screen and it says, Hey, pay up buddy.

[01:03:07] It says here you need to send so many Bitcoin or a fraction of a Bitcoin or so many dollars worth of Bitcoin. To this Bitcoin wallet. And if you need any help, you can send email here or do a live chat. They're very sophisticated. We should talk about it some more. At some point that was one generation.

[01:03:29] One generation two was not everybody was paying the ransoms. So what did they do at that point? They said let me see if they, we can ransom the data by encrypting it and having them pay us to get it back. 50% of the time issue got all your data back. Okay. Not very often. Not often enough that's for sure.

[01:03:49] Or what we could do is let's steal some of their intellectual property. Let's steal some of their data, their social security number, their bank, account numbers, et cetera. They're in a, in an Excel spreadsheet on their company. And then we'll, if they don't pay that first ransom, we'll tell them if they don't pay up, we'll release their information.

[01:04:10] Sometimes you'll pay that first ransom and then they will hold you ransom a second time, pretending to be a different group of cyber terrorists. Okay. Number three, round three is what we're seeing right now. And this is what's coming from Russia, nears, everything we can tell. And that is. They are erasing our machines.

[01:04:31] Totally erasing them are pretty sophisticated ways of erasing it as well, so that it sinks in really, it's impossible to recover. It's sophisticated in that it, it doesn't delete some key registry entries until right at the very end and then reboots and computer. And of course, there's. Computer left to reboot, right?

[01:04:55] It's lost everything off of that hard drive or SSD, whatever your boot devices. So let's talk about the best ways here to do some of this backup and saving your data from ransomware. Now you need to use offsite disconnected. Backups, no question about it. So let's talk about what's been happening.

[01:05:17] Hospitals, businesses, police departments, schools, they've all been hit, right? And these ransomware attacks are usually started by a person. I'll link in an email. Now this is a poison link. Most of the time, it used to be a little bit more where it was a word document, an Excel document that had something nasty inside Microsoft, as I've said, many times has truly pulled up their socks.

[01:05:45] Okay. So it doesn't happen as much as it used to. Plus with malware defender turned on in your windows operating system. You're going to be a little bit safer next step. A program tries to run. Okay. And it effectively denies access to all of that data. Because it's encrypted it. And then usually what it does so that your computer still works.

[01:06:09] Is it encrypts all of you, like your word docs, your Excel docs, your databases, right? Oh, the stuff that matters. And once they've got all of that encrypted, you can't really access it. Yeah. The files there, but it looks like trash now. There's new disturbing trends. It has really developed over the last few months.

[01:06:31] So in addition to encrypting your PC, it can now encrypt an entire network and all mounted drives, even drives that are marrying cloud services. Remember this, everybody, this is really a big deal because what will happen here is if you have let's say you've got an old driver G drive or some drive mounted off of your network.

[01:06:57] You have access to it from your computer, right? Yeah. You click on that drive. And now you're in there and in the windows side Unix and max are a little different, but the same general idea you have access to you have right. Access to it. So what they'll do is any mounted drive, like those network drives is going to get encrypted, but the same thing is true.

[01:07:20] If you are attaching a U S B drive to your company, So that USB drive, now that has your backup on it gets encrypted. So if your network is being used to back up, and if you have a thumb drive a USB drive, it's not really a thumb drive, right? There's external drive, but countered by USP hooked up.

[01:07:45] And that's where your backup lives. Your. Because you have lost it. And there have been some pieces of software that have done that for awhile. Yeah. When they can encrypt your network drive, it is really going after all whole bunch of people, because everyone that's using that network drive is now effective, and it is absolutely.

[01:08:10] Devastating. So the best way to do this is you. Obviously you do a bit of a local backup. We will usually put a server at the client's site that is used as a backup destiny. Okay. So that servers, the destination, all of the stuff gets backed up there. It's encrypted. It's not on the network per se. It's using a special encrypted protocol between each machine and the backup server. And then that backup servers data gets pushed off site. Some of our clients, we even go so far as to push it. To a tape drive, which is really important too, because now you have something physical that is by the way, encrypted that cannot be accessed by the attacker.

[01:09:03] It's offsite. So we have our own data center. The, we run the, we manage the no one else has access to it is ours. And we push all of those backups offsite to our data center, which gives us another advantage. If a machine crashes badly, right? The hard disk fails heaven forbid they get ransomware. We've never had that happen to one of our clients.

[01:09:29] Just we've had it happen prior to them becoming clients, is that we can now restore. That machine either virtually in the cloud, or we can restore it right onto a piece of hardware and have them up and running in four hours. It can really be that fast, but it's obviously more expensive than in some.

[01:09:51] Are looking to pay. All right, stick around. We've got more to talk about when we come back and what are the Russians doing? How can you protect your small business? If you're a one, man, one woman operation, believe it. You've got to do this as well. Or you could lose everything. In fact, I think our small guys have even more to lose Craig peterson.com.

[01:10:16] Backups are important. And we're going to talk about the different types of backups right now, what you should be doing, whether you're a one person, little business, or you are a, multi-national obviously a scale matters.

[01:10:32] Protecting your data is one of the most important things you can possibly do.

[01:10:36] I have clients who had their entire operating account emptied out, completely emptied. It's just amazing. I've had people pay. A lot of money to hackers to try and get data back. And I go back to this one lady over in Eastern Europe who built a company out of $45 million. By herself. And of course you probably heard about the shark tank people, right?

[01:11:07] Barbara Cochran, how she almost lost $400,000 to a hacker. In fact, the money was on its way when she noticed what was going on and was able to stop it. So thank goodness she was able to stop it. But she was aware of these problems was looking for the potential and was able to catch it. How many of us are paying that much attention?

[01:11:34] And now one of the things you can do that will usually kind of protect you from some of the worst outcomes. And when it comes to ransomware is to backup. And I know everybody says, yeah, I'm backing up. It's really rare. When we go in and we find a company has been backing up properly, it even happens to us sometimes.

[01:11:59] We put them back up regimen in place and things seem to be going well, but then when you need the backup, oh my gosh, we just had this happen a couple of weeks ago. Actually this last week, this is what happened. We have. Something called an FMC, which is a controller from Cisco that actually controls firewalls in our customer's locations.

[01:12:26] This is a big machine. It monitors stuff. It's tied into this ice server, which is. Looking for nastiness and we're bad guys trying to break in, right? It's intrusion detection and prevention and tying it into this massive network of a billion data points a day that Cisco manages. Okay. It's absolutely huge.

[01:12:48] And we're running it in a virtual machine network. So we. Two big blade. Chassies full of blades and blades are each blade is a computer. So it has multiple CPU's and has a whole bunch of memory. It also has in there storage and we're using something that VMware calls visa. So it's a little virtual storage area network.

[01:13:15] That's located inside this chassis and there are multiple copies of everything. So if a storage unit fails, you're still, okay. Everything stays up, it keeps running. And we have it set up so that there's redundancy on pond redundancy. One of the redundancies was to back it up to a file server that we have that's running ZFS, which is phenomenal.

[01:13:40] Let me tell you, it is the best file system out there I've never ever had a problem with it. It's just crazy. I can send you more information. If you ever interested, just email me@craigpeterson.com. Anytime. Be glad to send you the open source information, whatever you need. But what had happened is.

[01:13:57] Somehow the boot disk of that FMC, that, that firewall controller had been corrupted. So we thought, oh, okay, no problem. Let's look at our backups. Yeah, hadn't backed up since October, 2019. Yeah, and we didn't know it had been silently failing. Obviously we're putting stuff in place to stop that from ever happening again.

[01:14:27] So we are monitoring the backups, the, that network. Of desks that was making up that storage area network that had the redundancy failed because the machine itself, somehow corrupted its file system, ext four file system right then are supposed to be corruptible, but the journal was messed up and it was man, what a headache.

[01:14:51] And so they thought, okay, you're going to have to re-install. And we were sitting there saying, oh, you're kidding me. Reinstalling this FMC controller means we've got to configure our clients, firewalls that are being controlled from this FMC, all of their networks, all of their devices. We had to put it out.

[01:15:07] This is going to take a couple of weeks. So because I've been doing this for so long. I was able to boot up an optics desk and Mount the file system and go in manually underneath the whole FMC, this whole firewall controller and make repairs to it. Got it repaired, and then got it back online. So thank goodness for that.

[01:15:33] It happens to the best of us, but I have to say I have never had a new client where they had good backups. Ever. Okay. That, and now that should tell you something. So if you are a business, a small business, whatever it might be, check your backups, double check them. Now, when we're running backups, we do a couple of things.

[01:15:57] We go ahead and make sure the backup is good. So remember I mentioned that we have. Backup server that sits onsite. Usually it depends on the size of the client. But sits onsite at the client's site. So it will perform the backup and then tries to actual restore of that backup to make sure it's good.

[01:16:18] And we can even. Client, depending on what they want. So a higher level, if a machine goes down, let's say it catches fire, or disk explodes in it, or completely fails. We can actually bring that machine online inside our backup server or the customer. Yeah, how's that for fancy and bring it back online in just a matter of minutes instead of days or weeks.

[01:16:48] So that's true too. If that machine had been a ransom had this data, you raised whatever might've happened to it. We can restore it now. We've never had to knock on wood, except when there was a physical problem with the machine and as. Starting from scratching it, that machine, the new machine online in four hours or less.

[01:17:12] And it's really cool the way it works. If you like this stuff, man, it is great. Okay. Protecting your data. I'm rambling a little bit here. You need an archival service there's companies out there like iron mountain, you can at your local bank, depending on the bank. It ain't like it used to be, get a box, right?

[01:17:33] A special box in the vault that you. The tapes and other things in nowadays there's cloud options, virtual tape backup options, which is a lot of what we use and we do. Okay. We also use straight cloud at the very bottom end again. It's not located on the network. It's up in the cloud. It's double encrypted.

[01:17:57] It's absolutely the way to do now if you're going to have a backup and if that backup, you want to be secure, it must not be accessible. To the attacker, you've got to put some literal air space between your backups and the cyber criminals. It's called an air gap. So there's no way for them to get to it.

[01:18:21] Okay. Now I want you to consider seriously using tape these a LTO. These linear tape drives. They've been around for a long time, but their cartridges you can pull in and out. And they're huge. They they're physically small, but they can hold terabytes worth of data. They're absolutely amazing. There's some great disk based backup systems as what we do.

[01:18:46] Some of them are been around a long time and they can be quite reasonably. Price. All right. So it's something for you to consider, but you've got to have at least that air gap in order to make sure that you're going to be protected. What should you be looking for in a backup system? This is called 3, 2, 2 1, which means maintain at least three copies of your data store the backups on two different meters.

[01:19:15] Store at least one of the copies at an offsite location store, at least one of the copies offline, and be sure to have verified backups without air. Okay. Does that sound a little complicated? 3, 2, 1, 1 0 is what it's called. Just to be 3, 2, 1. Now it's 3, 2, 1, 1 0. I can send you Karen put together a special report on this based on our research.

[01:19:41] And I can share that with you. Absolutely free. Hey guys, if you want it, you got it. But you got to ask me, just email me M e@craigpeterson.com. This is absolutely essential. If you're a small business, a tiny business to do it this way. Let me tell you, okay, this is just huge. Physical backups should be stored off site.

[01:20:02] I mentioned the bank fault. A lot of people just go ahead and take them home with. That might be a desk. It might be a tape. It can be a little bit complicated to do. And I've picked up customers that thought they were backing up. They were using a USB drive. They were putting it in due to flee every Monday.

[01:20:24] And then every Wednesday, what happened? Every Wednesday they bring in Wednesdays desk and then they bring that disc home and then Thursday, they bring in the Thursday disc. And none of them had been working. Okay. So be very careful. All of your backups should be encrypted. We encrypted at the customer site and then we reencrypt it when we bring it over to us.

[01:20:50] Okay. Keys are essential. Particularly if you're using a cloud-based backup, don't use the same keys across multiple backups. Very important there. You should have some good procedures that are well-documented test, test your restores because very frequently. We find they don't work. In fact, that's the number one problem, right?

[01:21:14] If they had just tried to restore, even once from their backup, they would've known they had problems. And get those backups scheduled on a regular schedule. Okay. So there's a lot more offline backups and more that we can talk about another time, but this is important. If you want any help, send me an email, just put backups in the subject line.

[01:21:39] I'll send you some stuff. Email me, M e@craigpeterson.com. Now I am more than glad to help. Pretty much anybody out there. I'm not going to help. What about blah, blah, Amir Putin. But anybody else I'll help, but you got to reach out. Okay. You listen here. And I know some of this stuff is over some of our heads, some of your heads, you're the best and brightest.

[01:22:04] That's why you're listening and I'll help you out. I'll send you some information. That's going to get you on the right track. Me Me@craigpeterson.com. That's Craig Peterson, S O N have a great day.

View Details

Did You Hear How the FBI, NSA, and CIA Got Tracked Because of Their Smartphones? How About You?

You're worried about surveillance. Hey, I'm worried about surveillance. And it turns out that there's a secretive company out there that to prove their mustard tracked the CIA, and NSA yeah. Fun thing.

[Following is an automated transcript.]

[00:00:16] This is a company that is scary. We've talked before about a couple of these scary guys.

[00:00:22] There's this Israeli company called NSO group. And this it is, so group is absolutely incredible. What they've been doing, who they'll sell to these. Guys are a company that sells cell phones, smart phone exploits to its customers. And there are alleged to have sold their software to a variety of human rights abusers.

[00:00:53] We're talking about NSO group coming up with what we would term a zero day hack against I-phones against Android phones against pretty much anything out. So in other words, I hacked that no one ever seen before and then use that in order to get into the phone and find information, they views things like the, I think it was what's app and video that was sent and usually.

[00:01:22] To hack Saudi Arabian phones. You might remember Chris Shogi this journalist. I guess he was who apparently was murdered by them. Big problem. So this Israeli group. Yeah. Yeah. They sell to anybody that's willing to pay. At least that's what the allegations are. I've never tried to buy their stuff, but yeah, they're assisting government with hacks with.

[00:01:48] Ultimate in surveillance. Another one clear view. We've talked about them on the show before this is a company that has done all kinds of illegal stuff. Now some of it's technically not illegal. They're against the terms of usage, what Clearview has done. And now they've gotten involved in this Russian Ukrainian.

[00:02:12] War that's been going on here and they've gotten involved with a number of legal cases in the us. What they did is they said, okay great. Let's do something. You remember Facebook, right guys. So you've heard of that before. And how Facebook got started. Mike Zuckerberg. MK went ahead and stole the pictures of the women that were in Harvard's cattle.

[00:02:41] And I will, when I'm, when I say catalog, okay, this isn't like a catalog of women, order one mail order type thing. We're talking about their index, their contacts, there is a catalog of all of the students that are there in the school. So Zuckerberg goes and grabs those against policy.

[00:03:00] Okay. Maybe it wasn't strictly against policy at the time. And then he puts up some. Called the Facebook where people can look at a picture of a girl and decide whether or not she should get a five or a 10 or a one. Yeah. That sort of stuff, abusing people that really is abuse. I can't imagine.

[00:03:19] The way people felt, I had seen their ratings by people that didn't know them, that somehow their Def definition of beauty really defined who they are. It's crazy what the stuff he did. So he started his business by stealing stuff. Microsoft started his business by. By going ahead and misrepresenting, some would say lying to IBM about what he had as far as an operative system goes right, again and again, we're seeing dishonest people getting involved, doing dishonest things to get their companies off of the ground.

[00:03:54] And I have a friend who's an attorney who says, and Craig, that's why you will never be wealthy because you just wouldn't do any of that. So Clearview is another example of these types of companies. In this case, clear view, went to Facebook and crawled any page. It could get its little grubby crawlers on.

[00:04:18] So it found your public fake Facebook page. It went. Over the internet. There's a number of websites. Some are out of business now, but the, you upload your pictures to you. People can rate them, can share them. You can share them. Hey, you got your own photo gallery here that you can share with friends and a million other people.

[00:04:39] I'm right. That's what ended up happening. That's how those guys made the money. They're selling you on, Hey, you can look at how convenient this. And you can have your own little photo gathered at gallery and you can take that full load photo gallery and share it with your friends. And then if you read the fine print at T and we'll make money off of showing your pictures and showing ads well, Ah, Clearview went and scanned every website.

[00:05:08] It could get its grubby little scanners on crawled through the mall, downloaded pictures of any face that it could find. And then went ahead and digitized information about people's faces. So it spent years scraping and then it put together its technology, facial recognition technology, and went to the next level, which is, Hey, please department, get my app so you can get the clear view.

[00:05:41] And do you encounter someone? You can take a picture of them and upload it, which now gives them another face. Doesn't it. And then once it's uploaded, it'll compare it. It'll say, okay. Found the guy here. So with the Russia Ukrainian war, what they were doing is taking pictures of dead and injured, Russian soldiers, running them through this database online of all of these spaces, found out who they were and went so far as to use.

[00:06:14] Stolen data online. Now this is war, right? The whole thing is crazy, but the stolen database online find out who their mothers were, the phone numbers for the mothers, and to have people all over the world, sending text messages to mom about their dads. Yeah. Okay. So Clearview sells it to police departments.

[00:06:38] They sell it to pretty much the highest bidder they say, Hey, listen, we don't do that. Come on right now. There's other data brokers. And I've had a few on my show in the past who are using harvested information from phone apps to provide location data. To law enforcement so that they can then circumvent.

[00:07:03] What you have a right to privacy. Don't you it's codified right in the bill of rights. I was first 10 amendments to the U S constitution and it was all defined by the Supreme court's carpenter decision. So we have protections in the constitution, natural, right? That were confirmed by the Supreme court that say, Hey, the federal government, you cannot track all of the citizens.

[00:07:31] You can't track what they're doing. You can't harvest their information. And yet at the same time, They go to the data brokers that have put together all of these face pictures, figured out who your friends are, you sign up for Facebook and it says, Hey, you want me to find your friends?

[00:07:49] See if they're already on Facebook. Just hit. Yes. Here, not blowed your contact list. So I'll go. Facebook says, oh, look at all your friends. Or we found isn't this exciting. And in the meantime, in the background, Facebook is looking at all of this data and saying, we now know who your friends are. And so many people have wondered I wait a minute.

[00:08:10] I didn't talk about. I didn't do a search for product X online, and yet I'm getting ads for product X. Well, did you mention it to a friend who might've done a search for it? Because these search engines, these companies like Facebook know who your friends are, what they're interested in, and they'll sell ads to people who are going to promote to you the same items they're promoting to your friends.

[00:08:35] It's absolutely crazy. So this company. It's called and they're very quiet, very low key. The website doesn't say anything at all, but they took their software. That's pulling all of this data together and compiling it. Yeah. And ASX pointed all of this technology towards the national security agency and the C I a and Jews, their own cell phones against them.

[00:09:08] Now, why did they do this? They didn't do it to prove something about how, you shouldn't allow this sort of thing to happen and they didn't do it to prove that man, we've got to have tighter controls because look at what we can do. If we can do it, other people can do it. No. According to audio, visual presentations and recordings of an ACX presentation reviewed by the intercept and tech inquiry.

[00:09:36] claimed that it can track roughly 3 billion devices in real time. That's equivalent to a fifth of the world population. You're not going to find anything out about Asics it's called anomaly six. Good luck online. If you find it, let me know me@craigpeterson.com. I'd love to know more about these guys. The only thing on a website for them as an email address and a six anomalies six in that presentation showed the nation spooks.

[00:10:13] Exactly what knew about. All right. Apparently is also ignoring questions from journalists and will only respond to emails from people in upper levels of federal agencies, which means, and maybe this is a supposition from our friends over at tech dirt. I don't know. But then what that means is they're looking to sell your information in real time.

[00:10:43] To the feds to get around the carpenter decision and the constitution just absolutely amazing. Hey, go online right now. Craig peterson.com. I'll send you my special report on passwords and my two other most popular Craig peterson.com. Stick around.

[00:11:06] Have you ever wondered about search engines? Which one should you be using? You're not alone. It's probably the number one question I get from people. What should I use? Google is falling behind, but we're going to talk about the top engines and the why.

[00:11:23] Google has been an amazing company moving up. Of course, we're just talking about the cheats.

[00:11:31] So many companies have taken over the years and Google has certainly had its share of cheat. I haven't seen anything about them just doing completely underhanded things to get started. I think. They were pretty straightforward. They had a great idea back in the beginning, where they were just looking at links, how many sites linked into this one particular site?

[00:11:57] And that gave this concept of a page rank. Very simple, very easy to do. Of course, are problems with. Because you would end up with pages that are older, having more links to them, et cetera. And they have over the years really improved themselves, but we also have some other problems right now with Google.

[00:12:22] If you do searches on Google for a number of different. And you'll see that really Google search quality has deteriorated in recent years. We've talked before here about some of the problems with Google and elections and how they have obviously gone out of their way to influence the election.

[00:12:43] There is study down in, done in orange county, California, or at least about orange county, California, and an election down there showed that Google had a major influence on that election and also tilted it a certain way on purpose. Absolutely amazing. So that's one way Google has fallen behind, but you can.

[00:13:06] At all kinds of searches and hope you're going to get a great response. And you don't have you noticed that it's gotten worse and then on top of it, you're starting to see more ads squeezed in it is not great. I have used. Of course for programming in years past, before that I liked alter Vista, which was a digital equipment corporation product out there.

[00:13:32] Vista was pretty darn good. And you could use Boolean logic with it. Google says you can use Boolean with us, but it's not the same as Google's is very simple. But at any rate they have not made any. Leaps here going forward. It's been absolutely amazing. So let's go through the search engines.

[00:13:53] I'm going to give you right now, the pros and cons to some of these search engines out there. So we started with. It is 800 pound gorilla. And in case you didn't know the number two overall search engine is YouTube. Okay. But let's stick with straight searches, not video searches. So what is great about Google?

[00:14:19] One of the big things is they like fresh content. So if you're looking to do search engine optimization for your business, you are best off having some Keystone pages. So having these pages that are. Kept up to date. So you might have a page on whatever it might be hacking VPNs, right? And you make sure you update it because Google does favor the fresh content.

[00:14:45] They rank blogs and. Services, which is really nice and they're accessible in any device. They have apps that work well on a browser. And I'm right now, I'm looking@anarticlebylifewire.com on the best search engine. So you'll see some of this information there. They don't like about it is the same thing you don't.

[00:15:09] Right? Which is, it collects all kinds of data on you. They also have hidden content that, that might damage your ranking as a business or someone who has a website and the search delivers. Too many results, millions of results. Yeah, there probably are millions of results for a single search, but what I want are the really relevant ones and Google learns over time.

[00:15:38] What kind of results that you want, which is kudos to them, but they are tone deaf sometimes, frankly as well. Okay. Our number two on our list of topics. Is duck go. Now I've been talking about them for quite a while and some people have been disparaging talk, talk, go lately. And the reason is they say, what.

[00:16:03] And those search results maybe are a little wrong, right? They are maybe student little sensory, not as much as Google does, but some, at first duck go.com is where you'll find them online named after that kids game. Is a privacy search engine. So it is not tracking or storing any information about you.

[00:16:29] That's a very big one. There are searches are very fast, but they're backed. The actual backend search engine is. Which is Microsoft. We're going to get to that in a couple of minutes here. That means that if Microsoft is deciding to do some weighting on search results, based on their political views, then that's going to show up in duck go, but it's nowhere near as bad.

[00:16:54] And I've talked about it on the show before we'd done some examples. So it is also now giving you the option to restrict your searches to the last month worth of results, which is really nice. That keeps a little more up to date. They also aren't great at image searches, no personalized results, and it is free, which is nice.

[00:17:17] You might also want to look at quant Q w a N T. If you look at. A private or privacy browser. Quanta's a French company, but it does leave English as well. Okay. English results. They like the older and well-established web pages, they rank home pages. They do not rank blogs. They crawl all kinds of hidden content and non hidden, equally, unlike Google, which is really great being as not great at forums.

[00:17:50] As I mentioned, blogs, they're not as fast as Google. And they have some seriously heavy search results screened. Dogpile they've been around for quite a while. You might want to check them out. They have something called fetches and favorite fetches. So you can have a home screen when you go to dog pile and you'll see right there.

[00:18:14] Your favorite searches and they're right there for you. You can just keep going to them. They use multiple databases so they can get broad results, multiple backend search engines, and there's no home screen personalization available. And lots of sponsored results, which isn't a real big deal, but you'll find them online@dogpile.com, Google scholar search.

[00:18:38] I've used this a number of times. If you're looking for scholarly articles, it is really good. You can get citations in various styles. If you are working on your master's PhD, whatever. B and they're imposing a style in the document that you're writing. So you can put it into the bibliography and a, they got a lot of great stuff.

[00:19:02] Google scholar you'll find online at scholar dot, google.com. Wearable PDs, sir. It focuses on technical terms and applications, which is good, friendly to non-tech users. And it is only searching the web well, PD is 10,000 word and phrase database. So that's pretty. To to understand to Yahoo search, they have a home screen, has news trending topics.

[00:19:33] I've used y'all who? Of course it's not what it used to be, but it does have everything right there. Even your horoscope. And the ads are not marked out clearly. And then there's the internet archive search. This is actually a site that I fund. I donate money to them every month and you'll find them@archive.org, but it is really cool.

[00:19:58] You can search based on timeframes again, if you are doing papers, if you're a journalist. You can find what was the internet like? Or was this webpage? What was it like around a hurricane Katrina in 2005, right there. We will find it online@archive.org. Hey, stick around. We'll be right back.

[00:20:23] You already know that hackers are coming after you we've talked about how they are out there, scraping web pages, putting together stuff. I want to bring up again, the Ukraine, Russian war and Russia leaking data like a sieve .

[00:20:39] It is, of course in the news again, it seems like it has been in the news for how long now, six years, maybe longer in this case, we're going to talk about what the hackers are doing because they're not just doing it to Russia.

[00:20:56] They're doing. Us. And it's a problem. We're going to explain why you've heard of doxing before D O X I N G two docs, someone which is basically to find documentation about people and to release it. That's really a part of it. So you've seen some political operatives who have gone online and doxed people.

[00:21:22] For instance one of them is libs of tick talk. You might've heard of that one, and this is where they take all of these crazy things that crazy people on tick talk, go ahead and publish and just put excerpts of them together. They don't cut it up to make them look crazy. No. They let them be crazy.

[00:21:42] All by themselves and put it online. So some libs decided, Hey, we don't like this. And journalists who had been complaining about doxing before that shouldn't be done and it's unethical. It should be illegal. Yeah. What does she do? She goes and docks. The lady that was running libs of tick talk.

[00:22:07] And I, it just blows my mind here. How can these people be so two faced, they really are just crazy to face. So she went ahead and did what she said should never be done. And I'm sure she had some form of justification for it and put it out online. So I went online, comes this lady's home. Address her name.

[00:22:31] Kinds of stuff and that's available online right now. Now you might want to try and do something that I've done before, which is, if you go to one of these data brokers, ads for these things, right? Do a search for yourself with us. And have a look at how accurate that information is. When I looked last time I looked cause I had a few data brokers on the radio show.

[00:22:58] I would say less than a third of the information that they claimed was information about me was actually accurate less than a third, frankly. And I don't think that's a particularly, what's the word I'm looking for, but Unique situation. Let me put it that way. I don't think it's unique at all. I think they get a lot of it wrong because remember, they're trying to piece together this piece together that and put it all together.

[00:23:27] So you can't a hundred percent rely on any of that stuff. And as I said, for me, it wasn't particularly accurate. Now let's move into. Ukraine has claimed to have doxed Russian troops as well as FSB spies. Do you remember them from the Soviet union? They still exist, and hacktivists actually have official scheduled meetings and are leaking private information from various Russian organizations in Russia.

[00:23:59] So we're talking about things like their names, birth dates, passport numbers, job titles, and the personal information that they have released about these Russian companies. And people goes on for pages here. It looks like frankly, any data breach, you'll find a great article about this that I'm referring to in wired.com, but this particular data.

[00:24:25] Can change personal information on 1600 Russian troops who served in bootcamp, a Ukrainian city, that's been attacked by Russia. And by the way, you've probably seen these things. There were all kinds of accusations here of multiple potential war crimes. What was going on over there? So this data sets not the only one.

[00:24:50] There's another one that legislature legislation. Allegedly contains the names and contact details of 620 Russian spies who are registered to work at the Moscow office of the F S B. That is Russia's main security agents. Now this information wasn't released by hackers in North Korea or hackers in the us or Russia, because we already know Russian hackers.

[00:25:22] Don't attack Russia. They're not stupid. Okay. They don't want boudin coming after them, but this was published by Ukraine's intelligence service. So all of these names, all of these personal details, birth dates, passport numbers, job titles, where they're from all kinds of stuff. I'm freely available online to anyone who cares to look now, Ukrainian officials wrote in a Facebook post as they publish the data that every year peon should know their names.

[00:25:56] So you got to bet, there are a lot of people freaking out over there. Absolutely freaking out in Russia that is. Since the Russians invaded Ukraine, there have been huge amounts of information about Russia itself, the Russian government activities and companies in Russia. These, all the guards that are over there and it's all been made public.

[00:26:21] So it's very interesting because these are been closed off private institutions in the us. Yeah, we do some hacking of potential adversaries, but they don't release. All right. Not at all, but there's really two types of data here. First of all, you've got the information that the Russian authorities are publishing.

[00:26:42] Their allies are publishing, and then you've got the hacktivists, these companies, these groups, I should say. Anonymous hundreds of gigabytes of files and millions of emails have been made public, including some of the largest companies within Russia. The big guys, oil and gas companies or lumber companies, et cetera, et cetera.

[00:27:08] So there's a former British Colonel in the military intelligence. Wired is quoting here, his name's Phillip Ingram. And he said, both sides in this conflict are very good at information operations. The Russians are quite blatant about the lies that they'll tell we're used to that aren't we, and much of the Russian disinformation has been debunked, but they say.

[00:27:36] They have to make sure that what they're putting out is credible and they're not caught telling out right. Lies in a way that would embarrass them or embarrass their international partners. So it's really quite interesting. We've started seeing the stuff coming out in March 20, 22. Of course. And it's hard to tell how accurate the data is.

[00:28:00] Looks probably pretty accurate. It has been scooped up as I mentioned on the show before, but. Some activists, one of whom has put together an app that anyone can download. And that allows you to send texts to the mothers of Russian soldiers, some alive, some dead, and it automatically translated into Russian.

[00:28:24] I assume it's a crude translation, but whatever. So you can. Harass some bore a babushka over there in Russia, whose grandson is out there fighting. This is just incredible. We've never seen anything like any of this before, but doxing very toxic online behavior. And when it comes to war, the gloves are off.

[00:28:48] And by the way, these groups that I mentioned, these hacktivists have official meetings, Tuesday mornings on telegram, and they talk about who the next target is. Absolutely amazing. Make sure you visit me online. Craig Peter sawn.com and don't go anywhere because we've got more coming up here about organizations in general, here in the us breaches are up stolen data or.

[00:29:17] And the number of bankruptcies are up because of it.

[00:29:23] Hacks or up no, you know that we've known that for awhile, but did you know that is not necessarily the number one reason businesses are suffering breaches. So we're going to talk about that right now. What else you have.

[00:29:39] We've talked before about some of the websites that I keep an eye on.

[00:29:44] One of them is called dark reading and they've got a lot of good stuff. Some of the stuff I don't really agree with, who agrees with everybody or another person, just one, even a hundred percent of the time. Like no one. Okay. So in this case, we're talking to. Organization suffering a breach.

[00:30:03] And the stat that they're quoting here is that more than 66, 0% of organizations have suffered a breach in the last 12 months. That's huge. And the breaches have gotten more expensive. Global average breach cost is $2.4 million. And if you are unprepared to respond to a compromise, that price tag increases to $3 million.

[00:30:36] Yeah. That's how bad it is. That's what's going on out there right now. But the point that really they're trying to make here, a dark reading in this article by Robert Lim. Is that organizations are focused too narrowly on external attackers when it's insiders third parties and stolen assets that cause many breaches.

[00:31:02] That's what this new study is showing from Forrester research. Now I had them on the show a few times in the past, you might be familiar with them. They are a research company. The charges a lot for very little information, they've got the research to back it up right there. They're really one of the leading, if not the leading research company out there.

[00:31:26] So last month they came in. With the 20, 21 state of enterprise breaches report. And they found that the number of breaches in the cost of breaches varied widely, depending on where the organization is based. And. The big one that you have control over is whether they were prepared to respond to breaches.

[00:31:53] Now, companies in north America had the largest disparity between the haves and have not listened to these numbers. They're bad for businesses, these numbers, and they're worse for individuals. The average organization required 38 days. 38 days over a month on average to find eradicate and recover from a breach, but companies that were not prepared for security challenges took 62 days.

[00:32:28] Now the good news here is that this is down. It used to take nine months on average, and now we're down to two months, but here's the big question. Can you, or can a company survive 62 days or is it going to be out of business? Do you have enough money to make payroll for the next two months? That's where the problem.

[00:32:55] Really starts to come in. That's why small businesses that are hacked small businesses that are using things like Norton or some of the other real basic software without having a good firewall and good security practices. And same thing with individuals here. You are going to be out of business.

[00:33:17] That's of the showing right now. And your insurance policy that you have for cybersecurity insurance will not pay out. I did a presentation for an insurance industry group. This was in Massachusetts and it was a statewide group. And we'd talked about how the. Are not paying out the companies.

[00:33:41] Aren't right. And why, and if you are not prepared, if you are not doing the right things and I can send you a list of what you need to be doing, if you'd like, just email me@craigpeterson.com. Be glad to send it to me. M E at Craig Peterson, P E T E R. So when Dr. And just to ask for it and I'll respond to you or we'll get married or someone else to forward it to you because I've already got it.

[00:34:07] Okay. This isn't a big deal for me. Okay. It's ready to go. But that list is an important list because if you don't meet the standard. That the insurance industry has set forward and you are a hack. They're not going to pay you a dime, even if you Sue them. And we've seen this with very large companies as well, where they're trying to recover tens of millions of dollars from the insurance policy, and they didn't get a dime.

[00:34:36] They had to also pay who knows how many millions to lawyers to Sue the insurance companies. And they lost. Okay. It's a very big deal. So there's a huge misalignment, according to Forrester, between the expectation and the reality of breaches on a global scale, there's a big disparity of above $600,000 between those.

[00:34:59] Paired to respond to a breach and those who are not. And we can talk about that as well, because there's things you need to do obviously backup, but backup means you've got to check the backup. You've got to make sure it's valid. You should be spinning up the backups on, in a virtual environment in order to make sure the backups are good.

[00:35:22] There's a lot of things you should be doing. Okay. And that's just a part of it. Plus, do you have your PR people ready? Are you able to respond to the state requirements? A lot of states. Now, if you are hacked require you to report it to the state, in some cases in as little as 72 hours. So do you have that paperwork ready?

[00:35:46] Do you have the phone numbers of all of the people that are on the team? Okay. All of these things now, the threats are not just the external hack. Anybody who's trying to protect their data is focused on obviously the external hackers. That's where we tend to focus part one part two is we focus in on the people that are working inside.

[00:36:13] The company, right? It's a zero trust narrative here. Why is this guy in sales, trying to get into the engineering files? Why are they trying to get into payroll? You understand where I'm going with this, you buy and what I'm selling. You don't want them to have access to stuff that they don't need access.

[00:36:37] Attacks that Forrester found were spread over external attacks, internal incidents, third party, and supply chain attacks, which is really big nowadays and lost or stolen. Assets globally. Half of companies consider external attacks to be this top threat, but in reality, only a third of the incidents come from external actors.

[00:37:04] Nearly a quarter of them are traced back to an internal event. 23% consisted of lost or stolen assets and 21% involved with third. Partner. Interesting. Hey, so we've got to keep an eye on this. These external attacks are a very big deal and that's where they have success with what are called zero day attacks.

[00:37:31] But your internal people can be a problem. Now I have. Put together in 2022, this is something really important. What we call a POA and M it's a plan of action and milestones of what you need to be doing. For your cybersecurity. Okay. This is available absolutely free. You have to email me M e@craigpeterson.com.

[00:38:00] But the idea behind this is it's a spreadsheet that you can use in numbers on a Mac or Excel on windows. And it has all of the key items. Now we follow what's called the. 801 71 standard. This is the national Institute of standards and technology, and they've laid out all of the different things. That you should be doing now.

[00:38:26] We've broken them down into eight cybersecurity activators as what we called them. And we have, you should have already gotten an email this week from me. If you're on my email list, just talking about, cause we're starting now getting into those cybersecurity activators. I'm showing you. To do about each one of them.

[00:38:46] So you can do it yourself. So many of us are stuck with being the CTO or the guy or gal in charge of it just because we like computers or we know more than somebody else. So if you're on my email list, you will be getting these things off. We're going to be going through them in the weeks. I had little quick mini micro trainings, if you will, but you gotta be on the email list in order to get them.

[00:39:12] These are also appropriate for home users right now. You're going to have to make your decisions as to what you're going to do, but home users have the same exposure, the same basic problems that they have in bigger organizations out. So I follow the national Institute of standards and technologies.

[00:39:34] They have broken it down into a number of different sections. They actually require it. And if you are compliant with this new standard you are going to be able to recover your money from the insurance company. If you are hacked, I don't know. I was going to say it for a win, but hopefully you won't get hacked because of this.

[00:39:58] So it's an important thing to follow. So make sure you go to Craig peterson.com/subscribe right now and get subscribed. A lot of stuff for home users. My business is focused on securing businesses. Particularly regulated businesses, right? If you have intellectual property, you don't want to have stolen a few do government contracts where they're requiring you to be compliant with this new standard or some of the others, but it's.

[00:40:27] Basic stuff that every business should be following. So just email me, M e@craigpeterson.com with your questions. We've been really good at answering them. We've probably lately been averaging about a dozen a day. Which is quite a few, but so it might take us a little bit to get back to, but we've gotten much better.

[00:40:48] Mary her number one responsibility right now is making sure that we answer all of your emails. We'll send out this plan of action and milestone spreadsheet for you. So you know what to do. This is updated. This is 2022. Everything you need right there. Me at Craig Peterson dot. Alright, you'll also find my podcast there.

[00:41:14] Craig peterson.com. And I want to point out that I'm not doing the show on video anymore. Just wasn't getting enough traction with, if it just takes too long. Anyways, Craig peterson.com.

[00:41:29] This is one of the top topics I've had people ask about lately, and that is protecting yourself and your business against Russian hacker. So I've got a presentation. We're going to run through it. We're going to talk about what you can do.

[00:41:46] This has been a long time coming. I have been doing a lot over the years of webinars of online meetings, trying to help people understand what's going on, what can be done.

[00:41:58] And I got a great email this week from one of the listeners. Who's been man on my email list now for years, I'm not even sure how many years. And he was saying, Hey, thanks for giving all of this information for free for small businesses. I can't afford it. And I got to thinking, because there've been a lot of requests lately, for instance, backups how should I be doing them?

[00:42:22] What should I be doing? And a number of other topics that really all go together into the, how do I protect myself? My business. From ransomware from these Russian hackers. So that's what we're going to be talking about today. We're going to go through a few of these. This is going to be a series.

[00:42:41] We're going to continue this here and weeks ahead, and I appreciate all your feedback. And if you miss part of it, make sure you email me just M. Craig peterson.com. Let me know, and I'll be glad to send some of it to you. Now I'm recording this on video as well. So it's great when you're driving around and listening in picking up some tidbits.

[00:43:04] And if you do want to see the recorded version again, dropping them in an email to me@craigpeterson.com or search for me on YouTube or on one of the other sites that are out there like grumble and you'll. This as I release it. Cause this is going to take a few weeks to really get into the whole thing.

[00:43:26] So let's get started. I'm going to pull this up here. Full screen. For those watching at home and what this is called today, we're talking about protecting your business and your self from Russian hackers because they have been out there. They have been causing just all kinds of problems, but there's a few things that you can do.

[00:43:48] And I have them up on the screen here. Let me pull them up, but I want to get into the background first. Russian ransomware group. They're a bunch of bad guys and it's called Conti. Now. Conti has been around for a long time. These are the guys that have been ransoming us. They're the guys who in rants. The businesses they've been rants.

[00:44:10] Government, you might've heard them. They've got into hospitals. They have been all over the place and they've raised a whole lot of. For the Russians. I'm also going to tell you about a couple of things you can do here. Cause there's a real neat trick when it comes to keeping Russians out of your computers, but Conti decided, Hey, listen, we are all for Russia and president and Putin.

[00:44:34] So they came out with an official warning, oh, I want to read this to it says if anybody. We'll decide to organize a cyber attack or any war activities against Russia. We are going to use our all possible resources to strike back at the critical infrastructures of an enemy. Yeah, no, not the best English, but much better than my Russian.

[00:44:55] I got to say that I know two words or so in Russian, but they said that they were announcing full support for president. That's a pretty bad thing. If you asked me, they also have ties to Russian intelligence intelligence, but what are we talking about really? Think of the KGB.

[00:45:13] The FSB is what they're called nowadays, but directly tie. China and North Korea, Iran, or also now tied in with Russia to varying degrees, but all of them are a little bit concerned about getting into it a little too much, but we're going to talk about their tactics. That's what's important today. What are they doing?

[00:45:35] Why are they doing it? What can you do about. So the first thing is password sprain. This is big deal. I've got a nice big slide up here. I like that color blue. I don't know about you, but I think it's pretty, but password sprain is something we all need to understand a little bit better. It's a brute force attack that has been really hurting.

[00:46:00] Many of us. Let me see if I can get this to work. For some reason it has decided it just doesn't want. Let me see here. What is up? Oh, is something isn't it's just, I'm getting a white screen, but it's a brute force attack targets users who have common passwords. Now this is a problem. When we're talking about passwords.

[00:46:25] If you have a password that has been breached in any of these breaches that have gone on over the last, however long, right? 30 years plus now that password is known to the bad guy. So what they'll do is they'll take that common password and they'll start to try it. So password sprain is where they will go to a bank site or they'll go to Google.

[00:46:51] The, oftentimes they're trying to get at your email accounts. So if you have Google email or Yahoo or Hotmail, they'll try it. Use passwords that they have found against accounts that they have found on those various sites that ends up being quite a big problem for everybody out there. Okay. I got that screen back here.

[00:47:12] So I'll put that up for those people who are well. But they will send multiple times attacks using variations of these passwords. And it's known as a low and slow method of password hacking because if they were to go bam, and send all of these passwords and login attempts.

[00:47:35] They'd get caught. The automated systems would say, Hey, wait a minute. This is not good. We're going to cut you off. In fact, that's what I do for my client. We have remote access using SSH, which is a an encryption session so that we can have a terminal session. And if you try and log in three times, We automatically zap you, right?

[00:47:58] We shut you down. So they take a very slow approach to this password sprain technique. And they're also going after volume, which makes a whole lot of sense. And there are right now, billions of passwords usernames, email addresses that have been stolen that are sitting out in the dark. So you've got to make sure that you are not reusing passwords.

[00:48:24] How many times have we talked about that? You've got one common password that you're using over and again, while that's a problem, but they're not going to keep hacking your account. They're going to switch from one account to another because they don't want to get locked out.

[00:48:39] Just like I lock out somebody who's trying to get in. So if someone's coming from that same. IP address that same internet site. And they're trying to log into that same account multiple times. Bam. They are gone. So with path's word sprain, they're trying to get around the problem of you noticing they're trying to get into a bunch of different accounts and they try and leverage it.

[00:49:04] So they'll oftentimes use multiple computers that they've stolen access to. We've talked about that before too. It gets to be a real big. Now they're also targeting these single sign-on and cloud-based applications, because once they're on. Using one of these federated authenticated authentication protocols, they can mask the malicious traffic.

[00:49:30] We've heard some of these hacks lately where they're using a token that they managed to pick up from somebody's email, I account, or they got onto Microsoft and they got into the email account on Microsoft. That happened recently. In a supply chain attack, solar winds. You heard about that 20, 21, right?

[00:49:52] So they're going after these email applications, including Microsoft or Microsoft has done they're going after routers and internet of things, devices for a very good reason, those IOT devices, which are things like your smart lights, they can be. Controlling the cameras outside, they go on and on there's thousands, millions of them.

[00:50:14] Now I actually all the way through your microwave, they tend to not be very well protected. So that's a real big target for them. So step. They want to acquire a list of usernames. Step two, they're going to spray the passwords. Where do they get those passwords in those usernames? Or they get them from breaches.

[00:50:36] So again, if you have an account that's breached at some online shopping site, a big one, a small one, it doesn't really mean. That particular breach is now well known and they can, will and do gain access to your account which is step three, gain access to it. It gets to be a serious problem.

[00:50:57] Okay. How do you know if you are under attack? Number one? There is a spike in failed. Log-ins this is where having a system and there's technical terms is tough for this. I'm trying to avoid a lot of those terms, but this is where the system is watching logins, noticing that there's a problem and going ahead and stopping it, not just noticing it, but stop. Very important to do. There are a high number of locked accounts, which means what it means that again, someone's been trying to log in. You should make sure that your account, if there are invalid, lock-ins automatic. Locks it out after some number of attempts and five attempts is usually considered to be okay.

[00:51:44] I know on my phone, for instance, I have a higher number of the neck, cause sometimes the grandkids get at it. But when it comes to your business account, when it comes to your bank account, you probably don't want to have a whole bunch of attempts, and then in known or valid or invalid, I should say use.

[00:52:04] Attempt again, why are they trying to log in with a username that just doesn't exist? Yeah, it can be a problem. Hey, when we come back. We're going to talk about some steps. Like you can take here to really remediate, maybe even stop a password spraying attack. I've already given you a few ideas here, but what are some act of things that you can do, particularly for a small business to really protect yourself?

[00:52:33] Hey, stick around. We'll be right back. Craig peterson.com.

[00:52:39] Russia has, been hacking our computers, Russia's continuing to hack our computers and this is a real problem. So we are going to talk right now about how to stop some of these things. We already talked about password sprain. How do you stop it?

[00:52:56] There are a lot of things we have to pay attention to, and that's what I'm going to be doing in the weeks ahead.

[00:53:03] We're going to be going through some of the things you need to do to keep yourself safe. Keep your business safe in this really dangerous online. There are so many things going on. So many people that are losing their retirement businesses, losing their operating accounts. We've seen it before with clients of ours while you know their clients now.

[00:53:29] And it was just a devastating thing to them. So I don't want that to happen to you now, if you are interested. All of this is recorded and I am doing this as video as well. We've got slides and you can find out more about it. Just email me M e@craigpeterson.com. It's really that simple. And I didn't let me know.

[00:53:54] And I'll be glad to send it off to you. Okay. This is available to anybody I'm trying to help. And we've had a lot of emails recently about some of these things. So th this is covering everything from the password spraying we're talking about right now through backups and other things that you need to do.

[00:54:14] Let's get going on our sprain problem. So w what are the steps that we need to take in order to really remediate against one of these password spraying attacks? And frankly, it is. Oh, a lot to do. It has a lot to do with our users and what we do, if you're a business, if you are an individual, we need to be using longer passwords.

[00:54:43] Now we're not talking about all of these random characters that we used to have. I remember having to have my password be at least four characters, long APAC, when didn't even have to have a username, it was just all based on the password. And things changed over the years, the latest standards that are out there right now come from this too, which is the national Institute for science and technology.

[00:55:07] They are the guys that put together, all of the guidelines said federal government and businesses need to follow. And they're telling us that a longer passwords means elaborate pass phrase. So you should use 15 character passwords. I had an article just a couple of weeks ago saying that an eight character password can be cracked almost instantly, certainly within an hour, any eight character password.

[00:55:39] So if you're still using that, you've got to make a change. And obviously nine characters is a lot more possibilities, takes a lot longer to crack. I don't have those numbers right in front of me, but 15 is the ideal. So use pass phrases instead of single words. So phrases like I don't know secretary of one, the Kentucky.

[00:56:04] There you go. There's a phrase. So what you would do is put, maybe dashes between each one of the words. Maybe you would go ahead and use a comma, put some numbers in there, put some special characters in upper lowercase, right? So it's basically on uncrackable at that point. And that's what you want.

[00:56:24] Next one. When we're talking about rules for your passwords, the best passwords are the passwords that you can remember without writing them down and words that don't make sense to anyone else's. I remember taking a memory course a few years back and they had random words and you had to remember them.

[00:56:49] And the whole idea was okay, visualize this happening. And as I recall, man, it's been a lot of years I won't say decades, but it hasn't been. Since I did this, I still remember a part of it, it was first word was airplane. Next was all envelope. The next one was paper clip. Next one was pencil.

[00:57:08] So I visualized an airplane flying into an all envelope and that all envelope then goes into a paper clip and a pencil writes on the outside. Like it's addressing it to someone. That is a good little password, actually airplane or envelope, paperclip, a pencil with a mixed case and maybe a number two or special symbol thrown in.

[00:57:35] Those are the types of rules that we're talking about. The types of rules that really. Next up here. Oops. Wrong keyboard. Stay away from frequently used passwords. We've talked about this many times. If you're using one of the better password managers, like for instance, one password, you will automatically have any passwords that you are there in Shirin or that it creates you'll have them checked via a website out there.

[00:58:07] It's called. Yeah. Okay. It's called. Have I been poned I, and I hated to say this because how do you spell it? It's all one big, long word. Have I been poned to.com and poned is P w N E d.com. It will tell you if a password that you're trying to use is a known password. If it has been found out in the wild, okay.

[00:58:32] Use unique passwords for every site you visit, I can't stress this enough. We were talking about password sprain. If you use the same password and email address on multiple sites, you're in. Because all they have to do is try your email address and your password for whichever site it is that they might want to try out.

[00:58:58] Remember, many of them are trying to get into your email and they have done that successfully. With Microsoft email, if you have their Microsoft 365 service and you might want to read the fine print there very carefully, because Microsoft does not guarantee much of anything. You make sure you back it up yourself.

[00:59:20] Make sure you do all of these things because Microsoft just plain, isn't doing them for you. Next one here. Next up is our password manager. And I mentioned this before installing and using a password manager is phenomenal. It automates the generation of passwords. If you have. Integrated with your web browser.

[00:59:45] It now allows your web browser to work with your password manager. So when you go to a site, you can have it pull up your passwords. How could it be much easier than that? It's really rather simple. That way it's keeping track of your logins. And again, One password.com is the one I recommend and people get confused.

[01:00:06] When I say that, when I'm saying one password, I don't mean only have one password used for everything. One password is a name of a company. Okay. So it Talking about only having a single password, but use a password manager. And I've got all of these up on the screen right now. If you're interested in getting copies of these, you can go ahead and just email me M e@craigpeterson.com.

[01:00:35] And I'll make sure I send you a copy of the slide deck of this presentation as well. Cause this is just so important, frankly, but having these points is going to be huge for you. Now strange activity. That's another very big deal. And we're going to talk about this when we get back, what is it?

[01:00:55] What does it mean? But I'm going to hold off the rest of this, I think for another week. But right now, what let's hit this, we're talking about odd log-in attacks. A lot of login attempts, the excessive login attempts trends in unusual activities take any, you need to basically take measures to block it and determine if this activity is legitimate.

[01:01:20] Is someone just for forgetting their password and spraying themselves or what's going on? Okay. There you go. Simple. Hey, everybody, you can find out a lot more and you'll be getting links to this automatically to these videos, et cetera. If you're on my email list, Craig peterson.com and you can email me M e@craigpeterson.com.

[01:01:45] We'd be glad to send you this or any other information I might have. All right. Take care. We'll be right back.

[01:01:54] Putin has been working for a while. In fact, it looks like as early as September in 2021, Putin started going after major us corporation. So we're going to talk about that. And what does it mean?

[01:02:10] Putin has been going crazy for a while. I'm going to put this up on the screen for those of you who are watching either on rumble or YouTube, but Putin planned this whole invasion apparently quite a while ago.

[01:02:27] And I got an article from the Washington post up on MSN talking about what Putin did at least a little bit about what he did. And you can see right here if you're following. That Russian agents came to the home of Google's top executive and Moscow. And what they did is gave an ultimatum. They told that Google, a senior executive that they needed.

[01:02:55] Pull down an app that was in use in Russia. And this app was polling. It was for people to do polls and say, Hey what do you think about Putin's garden performance, et cetera. We do them in the U S all of the time you hear about the polls right left and center. Poland, which is a small country next to another small country called Ukraine next to a large country called Russia.

[01:03:21] But we're talking about Paul's favoribility polls. What do you think they should be doing? What do you think that the government should be doing and maybe what they should not be. So Putin didn't like this. He didn't like this at all. And so what he did is he sent a couple of guys ex KGB, FSB, the secret police over in Russia by to visit this Google executive.

[01:03:47] If you're the Google executive, what are you going to do? If you Google. Yeah, you're going to say, oh my gosh, I'm out of here. So I'm not sure if she, if this executive was an American or Russian, this article doesn't seem to be clear about it, but what happened is they said, okay let's go hide.

[01:04:12] So they rented a hotel room for the. They put her in it and they rented the room under an assumed name. So it wasn't the real name of the executive. It wasn't tied into Google and they thought, okay, now we're pretty safe. Cause you got a hotel security, I guess there are a couple of Google people hanging out with her and they felt pretty safe.

[01:04:35] What happens next? There is a knock on the door. These same agents, again, that are believed to be Russian secret. Police showed up at her room and told her that the cock was still ticking because they had given her 24 hours for Google to take down the app because Putin, dental. People weren't particularly pleased with Putin.

[01:05:02] So at that point, of course it was forget about it. And within hours, Google had pulled down the app. Now you might complain, right? A lot of people might complain about it. It's one thing for a company like Google or apple to capitulate, to a government to do maybe some censorship, like the great firewall of China.

[01:05:25] You might've heard of that where the Chinese citizens can't get certain information. Russia has something pretty similar and us companies have gone ahead and helped build it, provided the technology for it and put it in place. They sold it to them. I don't like that in case you didn't guess, right?

[01:05:43] I'm all for free speech. I think it's very important for any form of a democracy. No question about it, but these companies apparently don't have a problem with that. However, now this is something, a little different. If you have employees who are being threatened and I mean threatened to serve 15 years in a Russian prison, what are you going?

[01:06:10] Are you going to say no, I'm going to leave that app up. And then now all of a sudden your executives, or even a coder, somebody a programmer, like the guy that sweeps the floors, whatever are you going to let them be arrested so that you can have this app up on your Google play store or your app store over the apple side?

[01:06:29] Probably not because frankly, this is something that is not worth it. So what are you. I think the only answer is what we've seen company after company do, and that is get out of Russia completely. And there was an interesting story. I read this recently about McDonald's you might remember back in the Soviet days, McDonald's worked out this deal with the Soviet union to open a McDonald's right there in downtown Moscow.

[01:07:03] I guess it was pretty prominent. I don't know if it was, I think I might've been even on red square and there were people like. To have an American hamburger and it's been pretty popular the whole time. McDonald's closed that store and pulled out of the country. Starbucks has pulled out, are they going to reopen?

[01:07:21] Cause I don't think either one of them said, forget about it. We're not coming back, but I know both of them have closed on operations. Automobile manufacturers from the U S have closed on operations. What is their choice? You can't just go ahead and say, okay yeah. Okay. Yeah. You're just going to arrest people or, we'll keep quiet for now and come back later.

[01:07:42] What are you supposed to do? That's part of the problem with these oligarchies, with these people who are basically all powerful. Now we actually see some of that here in the us, which is just as shame, just a shame because we see these companies going ahead and cutting out free speech saying, oh, you can't say that there was a time where if you said masks work, that you would have been censored. And then there was a time where if you said masks don't work. You cloth mass don't work, you would have been censored. There was a time when you said masks aren't necessary. You would have been censored right now, but the science is settled.

[01:08:27] It was just crazy. Science has never settled and oh, we could go on with this for hours and hours, but potent is not a good guy. And this article, I'm going to bring it up on the screen here again. But this article talks about. And a single year. And again, this is MSN. Potent had his political nemesis, Aloxi Novolin novel ne yeah, I got it right.

[01:08:54] He had him in prison after a poisoning attempt, felled to kill him. Do you remember that whole poison in attempt? Where they gave him this really nasty radioactive bride product, as I recall, and potent went ahead and basically shut down. They pushed all of these independent news organizations to the brink of extinction.

[01:09:17] Look at what happened with Russia today. The entire staff walked off on the. Saying, we're not going to report on any of these lies that are coming out of Moscow. It's happened again and again, Putin orchestrated a Kremlin controlled takeover of Russia's Facebook equivalent, and he's also issued liquidation orders against human rights organizations.

[01:09:43] And so all this is going on. What are you going to do if you're. If you're a Google, right? I can see the criticism of those countries or companies should say when they're cooperating with the regimes, putting in place, things like facial recognition to, to spy on people, to have a social credit system, these great firewalls in these countries.

[01:10:05] But when you have something like this happen, I forget about it. There's nothing you can do. And the crackdown is accelerated Facebook and Twitter were knocked offline by the government for millions of Russians news outlets had survived the state harassment for years, shut down in the face of a new law impose.

[01:10:26] 15 year prison sentences for spreading fake news. It's incredible what has happened. And we've got to be careful here in the U S too, because we see this censorship, there's a lot of complaints about what was happening under Donald Trump president and old Biden, both Obama and Biden.

[01:10:45] Both of those have done some of these same things to a lesser extent. Stick around. We'll be right back.

[01:10:53] This whole war with the crane, Ukraine and Russia has brought a few things to light here over the months, and really the more than year that it's been leading up to the beginning of that war even, but we've got clear view in the news again.

[01:11:09] So you can always follow along at rumble or at YouTube, but there's a great article here.

[01:11:16] I have up on my screen for you to see. And this is from writer. Para carried over on MSN. And it is an exclusive story talking about Ukraine, using something called clear views. AI facial recognition. This to me is absolutely fascinating because what is happening. Is the technology that Clearview develop and has it been selling to police forces in the United States is being used on the battlefield and.

[01:11:51] How here's what the technology did. And does Clearview illegally went on websites, major websites all over the world and did what we call scraping. Now, scraping is where they go to the site and they grab the pictures. So they scraped Facebook. They scraped you tube. They scraped. Dan and many more.

[01:12:18] And then they put it all into a big database that told them where they found it, who that person was. And then they also took that biometric information from that image of the face and came up with some unique codes, a hash basically is what they did. And. Now what Clearview is doing is if you are a police organization, you can get a little app that runs right there on your.

[01:12:46] And you have an encounter with someone you're a policeman, right? Let's say, and you just hold the camera up and it gets a picture of that person. It now finds the background information on them. And then you can use that tied into the police databases to check and see if there's any record of this person.

[01:13:06] If they've been doing anything illegal. It's really quite cool. What they're able to do and scary at the same time, we use the same basic technology over in Afghanistan. So literary troops as they're out, and they're having encounters with civilians, people in the street fighters, et cetera. They could hold the device up.

[01:13:29] It would identify them. It went further than just the face that actually did retinal scans and things, all kinds of cool stuff, but basically recognize the face. And they were able to tell if this was a friend of foe or. So a friend might be someone who worked as a translator who has been known to be helping the us troops in Afghanistan, et cetera.

[01:13:53] So we built this huge database of hundreds, of thousands of people's biometrics person, very personal information in it. And if they were getting paid even how much they're getting paid, all of that was in the database, in the backend. And then we abruptly. And we left that equipment behind. I hope the database was destroyed.

[01:14:16] I haven't found anything. Absolutely conclusive on it. That the withdrawal from Afghanistan was frankly unforgivable. It just I can't believe they did what they did at any rate. This is Clearview. This is this company. So now that same technology has moved to Ukraine. What's interesting. About this whole Ukrainian thing to me was okay, great.

[01:14:42] Now they can identify people. Can they really identify a pretty much everybody? Who are they going to identify? As it turns out clear Clearview also illegally stole photos of people over in Russia and in Ukraine. So the clear view founder said that they had more than 2 billion images from. How's that right from this social media service called V contact a or somebody like that out of a database of 10 billion photos total.

[01:15:16] So one out of five of the pictures they scraped was Russian, which surprised me. So the Ukrainians have been using it to identify dead Russian. And it's, they're saying it's much easier than matching fingerprints even works. If there's facial damage, it's scary to think about right. Wars, terrible.

[01:15:38] Who wants to go to war? I can't believe all of the people that want to jump in there. I really feel for these people in Ukraine, what can we do? I'll start proximal interest. Research for the department of energy, found the decomposition, reduce the technology's effectiveness while a paper from 2021 showed some promising results.

[01:16:01] Now, this again is an example of technology being used in a way it's never been used before. And having that ability to identify dead or living combined combatants on a field like this is just amazing. So this is the most comprehensive data set. There's critics, of course, they're saying that the facial recognition could misidentify people at checkpoints, obviously.

[01:16:29] Could miss identify people in a battle mismatch could lead to civilians. Just like unfair arrests have risen from police use. And that's from Albert Kahn, executive director of surveillance, technology oversight, product project in New York. So as usual, these things can backfire and I think they probably will given a little bit of time and that's a sad.

[01:16:56] Now I also want to talk about this. This is cool. Another article here, I'm pulling up on the screen right now, and this is about some hackers. Now we know that the Kremlin has been lying. Do we know that if a politician's lips are moving their line, right? Isn't that the old standby, but Russians apparently don't know this.

[01:17:22] And the average Russian on the street is thinking that, okay, we're rescuing Ukraine. Isn't that just a wonderful thing? There's a couple of ways that the hackers have been getting around it. It's called a squad 3 0 3. They have this tool that's hosted at the domain. 1920 dot I N. There's an Indian domain and it loads a pre-written statement in Russian into your native SMS app.

[01:17:54] In other words, the app that you use for texting and the idea is they that they've taken, oh, let's see here. Tens of thousands of trying to remember the exact number of stolen phone numbers from Russia. So all of those hacks that we've talked about for all of these years, those hacks have many of them phone numbers in them.

[01:18:18] And they've been taking those phone numbers from some of those hacks and using them to send out about 6.5. Million text messages. So what happens is you, your phone, your actual phone ends up sending a text in Russia saying something to the effect of dear Russians. Your media is being censored. The Kremlin is lying.

[01:18:43] Find out the truth about Ukraine on the free internet, and then the telegram app time to overthrow dictator. Yeah, that's not going to cause any problems, is it right? I'll put that up on the screen again for people who might read Russian. Cause it's got it in Cyrillic. Okay. And then you have the option to get an, another set of text and figure it out.

[01:19:05] So the phone number, you can see there, you can copy it and paste it into your app and off the message goes. It's very cool. And in the daily dog, They're quoting a member of this squad 3 0 3 saying that this is a non-violent communications project. It's bypassing Russia's crackdown on the news.

[01:19:26] They're sensitive. They're censorship of the news. And by the way, the domain 1920 dot. Refers to Poland's surprise victory against Russian forces just after world war one and the Bolshevik Menshevik revolution. You might remember all that stuff, that you studied all those years ago. So it's interesting.

[01:19:47] We'll see what happens. But this hacking group also claimed that they were attacked probably again by Russian hackers, the FSB ex. Using a distributed denial of service attack shortly after launch. And they put CloudFlare in front of their domain. Now we use CloudFlare for one of our, something, not one, but some of our customers.

[01:20:15] What CloudFlare is a website that's designed to basically buffer your website when it's been served. So if all of a sudden you get a ton of legitimate request, your site's going to stay up. It's going to be able to respond to people. The other big advantage to CloudFlare is what's happening here with 1920, Diane CloudFlare goes ahead and will block some of these denial of service attack.

[01:20:43] So I think that's pretty darn cool. Many texts apparently are met with silence. Some say they've been able to converse with Russian citizens. One user who remained anonymous said they had made. The text messages they'd made using the tool really worked it says, I want the people of Russia to know the truth.

[01:21:03] The government is doing to the people of Ukraine. This is a quote from the daily dot going to pull this up too. This is a a tweet here on Twitter and. Yeah, it's from anonymous. That hacker group, you've probably heard of them before. Cause they've done a lot of nasty stuff over the years, but he says it's been doing just absolutely amazing things for him.

[01:21:27] Let's see here. Can we hear this? Here we go. Ah, I got to unmute it. Let's see. Where is my mute? There it is. So this guy's name is Rodney. He is. D Jang, oh my dog. Get to Django my dog. And he's got a really great little testimonial there about that. It works and his tweet has had 4,300 views and it's good.

[01:21:54] Again, another way around censorship now, Twitter, of course could decide they're going to sensor and that could be a problem too, but that's also why we now have alternatives to Twitter. And some of these other sites that are out there that are doing a whole bunch of blocking really, they don't like you.

[01:22:15] And by the way, the reference to Telegraph was fascinating because they are using. In order to get around censorship. Again, many people are using it to to send information about what is really, truly happening in Ukraine. So a lot of stuff from the beginning of the war here, visit me online. Craig peterson.com.

[01:22:38] Get my newsletter and get the free up-to-date trainings.

View Details

How Does Big Government Collaboration With Big Tech Raise the Costs of Everything?

We're going to talk about the Senate bill that has big tech scared, really scared. I'll talk about a new job site problem for a number of different industries because of hackers, the cloud, the cost and reliability.

[Following is an automated transcript]

This tech bill. It has the Senate really scared.

He is frankly, quite a big deal for those of you who are watching over on of course, rumble or YouTube. I'm pulling this up on this screen. This is an article. ARS Technica and they got it originally from wired it's it was out in wired earlier in the month. And it's pointing out a real big problem that this isn't just a problem.

This is a problem for both the legislature. In this case, we're going to talk about the Senate and a problem for our friend. In big tech. So let us define the first problem as the big tech problem. [00:01:00] You're Amazon. You are Google. Those are the two big targets here of this particular bill. We're going to talk about, or maybe your Facebook or one of these other Facebook properties, et cetera.

If you are a small company that wants to compete with any of these big guys, What can you do? Obviously you can do what everyone's been telling us. Oh, you don't like the censorship, just make your own platform. And there've been a lot of places and people that are put a lot of money into trying to make their own platform.

And some of them have had some mild successes. So for instance, I'm on. You can watch my videos there. And there have been some successes that rumble has had and making it into kind of the competition to YouTube. But YouTube is still the 800 pound gorilla. Everybody wants to be where the cool kids are.

So for most people. That YouTube. They look at YouTube as being the [00:02:00] popular place. Thus, we should be, we are obviously saw the whole thing with Elon Musk and Twitter, and the goings on there. And Twitter really is the public square, although it's died down a lot because of this censorship on Twitter.

Interesting. So as time goes forward, these various big companies are worried about potential competition. So how do they deal with that? This is where the real problems start coming in because we saw Amazon, for instance, in support of an internet sales tax. You remember that whole big deal. The internet had been set aside saying, Hey, no states can tax the internet and that's going to keep the internet open.

That's going to help keep it free. And people can start buying online. And that worked out fairly well. A lot of people are out there, why would Amazon support a sales tax on the internet? They are the biggest merchant on the internet, probably the biggest [00:03:00] merchant period when it comes to not just consumer goods, but a lot of goods, like a staples might carry for business.

So they'd have to deal with what they're 9,000 different tax jurisdictions in the United States. And then of course all these other countries, we're not going to talk about them right now, but the United States 9,000 tax jurisdictions. So why would Amazon support an internet sales tax when there's 5,000 tax jurisdictions?

The reason is it makes life easier for them when it comes to competition. So if you are a little. And do you want to sell your widgets or your service? Whatever it might be online. You now have to deal with 9,000 tax jurisdictions. It's bad enough in the Northeast. If you are in New Hampshire, if you live in New Hampshire and you spend more than, I think [00:04:00] it's 15% of your time south of the border and mass, then mass wants you to pay income tax for that 15% that you are spending your time there.

Now they do that with the. Baseball teams with football teams, hockey, you name it, right? So the big football team comes into town. The Patriots are paying the New York jets or whatever it might be. The Patriots have to pay New York state taxes, income tax now because they stepped foot in New York heaven forbid that they try and do business there and help New York state out.

And they now have to pay income tax. Now they only have to pay income tax for, or for the amount of time. They're more New York. Various states have various weirdnesses, but if you're only playing 1, 2, 3 dozen games a year, It isn't like your normal work here, which is 2080 hours. We're talking about their plane to New York and they're only spending maybe 10 hours working in New York, but that [00:05:00] represents what percentage, 10, 20, 30% of their income, depending on how many games they play and how they're paying.

And so they got to keep track of all that and figure it out. Okay. We played in New York, we played in New Jersey. We're in mass. We were they weren't in New Hampshire, certainly the Patriots plane, but they got to figure it all out. Guess what? Those big pay. Football players, hockey, baseball.

They can afford to have a tax accountant, figure it all out and then battle with them. I had a booth one time at a trade show down in Connecticut. Didn't say. Thing it was terrible trade shows, man. They aren't what they used to be. And they haven't been for a long time. This is probably a decade plus ago, maybe even 20 years ago.

So I had a little booth, we were selling our services for cybersecurity and of course, nobody wanted to bother pain for cybersecurity who needs it. I haven't been hacked yet. [00:06:00] Although there's an interesting article. We'll talk about next week based on a study that shows. Small businesses are going out of business at a huge rate because of the hacks because of ransomware.

And if you're worried about ransomware, I've got a really great little guide that you can get. Just email me, me@craigpeterson.com. I'll send it off to you, right? It's a free thing. Real information, not this cruddy stuff that you get from so many marketers, cause I'm an engineer. They'll go out of business.

So they figured I haven't got a business yet, not a big deal. And so no body. There's big trade show. And I was so disappointed with the number of people that even showed up for this silly thing. So what happens next while I get back to the office and about a month to two months later, I get this notice from the state of Connecticut they're tax people saying that I haven't paid my Connecticut taxes yet.

[00:07:00] And because I was in connected. I should be paying my income tax for that day that I spent and wasted in Connecticut. Oh. And plus every company in Connecticut that I'm doing business with now, I need to collect their taxes and pay them the taxes that I'm collecting for those Connecticut businesses are resident.

I didn't sell a thing. You know what it took almost, I think it was three or maybe four years to get the state of Connecticut to finally stop sending me all of these threatening notices because I didn't get a dime from anybody in Connecticut. So I'd love the internet from that standpoint saying you don't have to collect taxes in certain cases, certain states, et cetera, unless you have a legal nexus or a legal presence there in the state. So back to Amazon, Amazon loves the idea of having everything on the internet packs. They love the fact that there's 9,000 plus [00:08:00] tax jurisdictions. When you get right down to city, state county Lilian, either local taxes, or you look at those poor residents of New York state, or they're poor residents out in Washington state that have to worry about that, right?

There's county taxes, state sales tax. City sales tax, and income taxes are much the same, the, all of these crazy cities and states around the country. Yeah. The ones that are in serious trouble right now, they are those same ones. Those particular jurisdictions are hard to deal with. So from Amazon standpoint is just like the Patriots football players.

We've got plenty of money. We've got teams of lawyers. We have all kinds of accountant. We can handle this and you know why Amazon really loves it because it provides another obstacle for any competitors who want to enter the business. That's the [00:09:00] real reason, so many big businesses don't go ahead and charge you serious money so that they can use that money against you.

Okay. You see where I'm going with this? Because if you want to start a business that competes with Amazon, if you want to have a doilies, you're making doilies. My grandmother used to make them all the time and she had them on the toilet paper in the bathroom, little doily holders. Doilies everywhere.

And then of course, the seashells shells on top of the toilet paper holders. If you want to do that and sell it, how are you going to deal online with 9,000 tax jurisdictions? All what you're going to do is you're going to go to Etsy, or you may be going to go to Amazon marketplace and sell your product there.

An Amazon marketplace. So Amazon is taking its cut out of it at is taking it's cut off. And you still ultimately have some of that tax liable. [00:10:00] Amazon loves it. It's the same reason you see these groups forums, right? Barbers saying, oh, we've got to be regulated. Really you need to have a regulation in place for barbers.

You need to have licensing for barbers. Why do they do that? They do that. Not just barbers, right? It's all of these licensures and various states. They do that really to keep people. To keep their prices high. That's why they do it because someone can't just put up a sign and say, Hey, I am now a barber.

Come get a haircut. And if you don't like the barber, if they do a lousy job, you go elsewhere. We don't need all of the bureaucracy on top of this to enforce licensure. Anyways, when we get back, let's talk about that Senate. It's a big deal. And I am coming down in the middle of this thing. Hey, visit me online.

Sign up right now. Craig peterson.com and get my special report on passwords.[00:11:00]

We just talked about how big business uses its advantages to crush potential competition. Crush them. And it's a shame and it's happened to me and many people I know, and now the Senate's getting involved and making things worse.

This is a huge problem. This happened to me a number of years ago, and I will never forget it.

It was a really big lesson for me. I had designed and written a computer system that would take the code that it was written for a much older system. And run it for much less money. So bottom line here, this was a system called Cade computer assisted data entry that was made by Sperry way back in the day.

Yeah. I've been in there for that long and they had little programs, so they would not punch cards, but punch right on two tapes, those big [00:12:00] nine track tapes and that information would then be used for processing later on then. People, big businesses grocery stores, you name it. We're using that Sperry system.

And I designed a system that would take their COBOL is what it was. It was a form of COBOL code from this cage system. And you could use my code to compile it and run it on a Unix system. So the cost involved here was that it would be cheaper to buy a whole new Unix computer and buy new terminals and do some slight training changes.

But the key punch operators would be exactly the same keystrokes as they were already used to. Okay. So you know how fast they were, so it wouldn't slow than none at all. And their cost would be. Then just the maintenance contract on the old Sperry cage. Very [00:13:00] cool stuff. And I worked really well.

Then I worked with a couple of sales guys at spirit because Barry had a Unix tower system. It was a mini computer that was Unix space. And I had one, I had saved up my money. We bought this thing. It was a lot of money nowadays. It'd be about a hundred thousand dollars I spent on that system and it was really great.

Cool. So some grocery stores started using it. They used it to build the space shuttle to design it and send it into space. RCA, Astro space used it, my system, which is all really cool. So Sperry was interested in it saying, okay let's do this. Now. I had flown myself across the country too, because I was in California at the time to do some of this work for.

The for RCA Astro space for the space program and help make sure it was working and get it installed, help them configure it and everything else. So [00:14:00] I had a lot of time, a lot of money, a lot of effort into this. It was a big venture. So Sperry invited me down to their headquarters down in blue bell, Pennsylvania to talk about this.

And I was so excited because their sales guys wanted to sell it. They gave me some free space in a booth in Las Vegas. So I was in the Sperry booth with them and, say, yeah, you can buy this. And you're using the Sperry, the new Sperry hardware. And I went down there and talked with them.

They never did anything with me, or, here's a huge investment young guy. And all of this stuff just worked and they had proof of concept. They had a couple of customers already using the system and it never materialized. And then about a year and a half later, I found out Sperry had tried to duplicate my system and had messed it up terribly.

It [00:15:00] wasn't keystroke compatible. So anyone using the new Sperry system, they had to learn. Okay. So I got to hit this and I got to go over here and I got to click on this. Are you kidding me using a mouse? Aren't you not? These are data entry operators. They just go all day long, just typing and.

They had stolen my ideas. They messed it up. They didn't do as good a job as I did, which turns out it's pretty common. And they had stolen it. They stolen years of my life. So I've seen that before with me. I've seen Microsoft do that with friends of mine, and I've seen apple do it with various products that they've decided to release.

They all do it. Why do you think these businesses can not spend money on research and development, and yet at the same time, stay in business as technology's continuing to move forward? Why? The reason is. They don't have to do, or why [00:16:00] would we do T wait a minute. Now, all we have to do is either buy the company or steal the product just re-engineer.

Oh. And if we want to buy the company, we can do what Microsoft has been accused of doing again and again, which is. We'll just Microsoft. Let's see here. I like that database is pretty darn cool. So here's what we're going to do. So Microsoft announces, Hey, we're going to have a competitor to that in coming out soon.

And then they sit there and they wait and they say, okay, how many people are going to ask about, oh wow. A lot of people asking for it. In the meantime, that company that had that great little database soft. Trying to sell it. And people are saying, wait, Microsoft is going to come up with a version of this.

I'm just, I'm going to wait. We can wait a few months. Let's see what Microsoft. So that poor company is now seriously struggling because this big company came out and made the announcement that they're going to do something like this. And then that small company gets a [00:17:00] knock on the door. Hey, we're Microsoft or company X.

And we like your product. Wow. Okay. So we're going to do a buyout. We're going to we're just, oh, this is going to be fantastic. I might have to sign what a two year contract non-compete and help them manage it. Okay. We can deal with this. And then they find out that company X says Your company is not worth that much anymore.

Your sales look at their sales here, man. They've gone way down. Okay. So let me see let's do a nickel on every dollar evaluation you had a year ago. This happens every day, worldwide in America, it should never happen to anyone. And as you can tell, it upsets me. So what are Klobuchar and Grassley doing here?

Amy, when she was running for president, she made this big deal. I'm going to pull us up on my screen. Those of you who are watching [00:18:00] on rumble or YouTube. And you can find all of that in my website, Craig peterson.com can see here. So they are trying to protect the American consumer, right? Yeah.

Yeah. That's it. They're gonna protect us. And so what they're doing is saying that. Would a rule ruin Google search results because that's what Google says. Is it going to bar apple from offering new features, useful ones on the iPhone? How about Facebook? Will it stop them from moderating content? So the legislation's core idea is we will just.

The marketplace take care of things. We're not going to let Amazon put their products in the product listings before third parties, but how are you possibly going to be able to regulate that stuff you can't, you can regulate it [00:19:00] talking about a bureaucracy. You'd probably need one about as big as the federal government is right now.

And the federal government needs to be cut back in a major way. There's this two months. How about the 150 million Americans? This article brings that up to that are currently using Amazon prime, even though the price one hump. And they have it free to prime members. It's this is a big deal.

The bill doesn't mention prime. Doesn't mention Google by name, Amazon. But this is going to be a nightmare to enforce the bill is not specific enough. It should be voted down. And between you and me, I don't know what can be done about this other than to have additional marketplaces show up online. And you know what the conservative social media sites are starting to win.

So maybe there's hope.

We've got two things we're going to talk about right now. One of them [00:20:00] is tech jobs. And man, is there a lot of scamming going on there as you might expect in the second is cloud, are you looking at cloud services? Hey, a home or business.

You can see this. I'm going to pull this up on my screen for those watching on rumble or on YouTube, but this is a big problem.

And we've seen this again and again right now, they're going after certain workers in the chemical. The sector, but it isn't just the chemical sector. What we've seen is the bad guys going after anyone that's applying for a job. So let me give you a few tips here. First of all, you should not be pain to apply for a job.

We see that all of the time when it comes to the head hunting firms, what. Is, they will charge the business who is looking to hire someone [00:21:00] that makes sense to you. They'll hire they'll charge the business. So oftentimes it's a percentage of the annual salary committee where from usually 20% up to a hundred percent or more, depending on the position.

And boy can, they make a lot of money, but they don't necessarily place. People, but you know how it is right now, there, there can be quite a few. So people have been applying for jobs to make a lot of money and not realizing that fee that supposedly they have to pay is illegitimate. So remember that.

Okay. The second thing has to do with this particular scam, because what they're trying to do is. Into some of these companies. So they will send a thing out saying, Hey, on my head hunter, I'm here for you. We're going to get you this job you need to apply. Are you interested in a new job now? I've seen some stats online saying [00:22:00] that somewhere around 30 plus percent of people are looking or at least open to.

Take getting a new job, which means a lot more are looking for jobs. Now I have to add to that, that the people who have jumped ship over the lockdown period really are not happy. The majority of them wish they had stayed where they were at. So keep that in mind too. But what they'll do is they'll say, Hey, listen.

Oh, there's this new feature on LinkedIn. By the way, you can say y'all are, I'm interested in looking for a job. I forget exactly what it says, but it goes around your picture and I have it up there because I'm a contractor, I go to businesses and I'm. To harden their cybersecurity. And we usually start slowly, especially with some of these startups we're doing work with right now where they won't, they go from a completely flat network and [00:23:00] it's all engineers and I don't want anything hindering anything.

And so you got to work with them and it's just, we had a time sort of a thing. Okay. I just had this one thing this week. And then move on to one thing next week as well. So that's what I do for a living. And a lot of people are looking on LinkedIn and other places to find people who can be a chief information security officer.

So I'm what you call a fractional chief information security officer. I do this under contract and I've been doing contracts and contract work for. I don't know if I shouldn't be on the air, but my gosh it's been now I guess it's 40 years right now. So I've been doing this for a long time.

So I'm familiar with some of these scams, so they didn't take my word on some of this stuff. So what they do is they say, Hey, we've got a potential job opening. Are you in interested now? When we talk about 30 plus percent of people polled [00:24:00] say that they're looking interested in a new job, the numbers are probably a little higher. Not that everyone's going to jump ship. Some people will, but there are a lot of people that if they get this email, they're going to open it up. And so what'll happen now is this group out of North Korea called the Lazarus group? And we've talked about them before.

We'll go ahead and say yeah, the here's, what's going to happen here. Let's just send you this thing. You can open it up. You can look at it and see if it's really a fit for you. I love this graphic that they have. This is from dark reading. I have it up on the screen again. Rumble and YouTube.

What should we do now? Should I open this up? Should I not open it up? It turns out that what's happening is that Symantec and Broadcom, both have noticed this and stated in an advisory a couple of weeks ago. Be very careful [00:25:00] because what it's going to do is install a Trojan horse on your computer.

So let's think about this. You're talking about the chemicals. You have a lot of people who are very technical. And if a company wants to get some new technology, we talked about this earlier in the show, what did they do? Do they just go and say, oh, okay, let's get some R and D going here. Let me research and development.

Let's hire some scientists and do some pure science here, which are almost never happens anymore. No, what they do is they either buy a company, they steal a company's idea. If you are like the communist, you try and steal the technology directly. And that's exactly what these guys are doing. They put a Trojan on your machine because you open that file and that Trojan then gives you.

Oh, excuse me, gives them access to your machine. Now this particular Trobe Trojan is a malicious [00:26:00] web file. Disguises. This job offer and your machine gets comparable. They attempt to compromise it, right? It's not always successful. They're not as many zero days out there for these lower level actors like North Korea, but they've been able.

Now, they're not just going after chemical sectors, they're going after it service providers. So companies like mine that provide managed security services for businesses, they are being attacked. So that's a problem too, isn't it? Because if you can compromise. A nine company and we've seen this all the time.

It's getting reported like crazy. You now have access to all of their customers because the it service company has passwords, et cetera. And they're probably using. Industry is number one or number two products for managing the customer's computers, neither of which are secure. [00:27:00] And that's the biggest problem that we've had.

We use some of these things before, I'm not going to name them right now because it wouldn't mean anything to you anyways, but we had to get. We worked with our, it people inside the software companies that make the software that are used by the managed services providers. And we'd talked with their developers and said, Hey, listen, this is a serious problem.

That's a serious problem. You've got to change this. You got to change that. And what ended up happening? We left them because they weren't doing what they were supposed to be doing a very big deal. So they're targeting defense, contractors, engineering firms of any sort. They want to steal IP, intellectual property, pharmaceutical companies.

Yeah. Very big deal. These third hunting teams, including Cisco's, which are the guys that we use. Tallow sets again, an example of a big company buying a smaller company called telos that does threat intelligence and it looks at stuff. They're all reporting to this. [00:28:00] So high level jobs in an industry or what you have to watch out.

It'd be very careful. Now, earlier this year, Lazarus group, again, North Korea went after some of these jobs people 250 that were identified working in the news media, software vendors, internet infrastructure providers, using job offers that appeared to come from. Disney, Google Oracle by the way, that was according to Google who tracked the campaign.

They know what their employees are doing, where they're going, what emails coming in. It's crazy. We're looking a lot of stuff. Okay. So I want to move on to the next topic here. Last one, this hour, but I'm gonna pull this up right now on my screen. You can have a look at it there. Of course, if you are at home.

You can or you really can't on the road. You can see this on rumble and also see this on the YouTube [00:29:00] site. At least for the time being until I get kicked off right. Kicked off again. That seems to be the word of the hour, but cost reliability are raising concerns in. Again, this is a dark reading article, came out a couple of weeks back here, but the biggest concerns about cloud computing to what is cloud computing.

Let's talk about that first for a minute. Cloud computing is going online using something like salesforce.com. People don't think of that as cloud computing. But you have in Salesforce, all the communications with all of your customers, et cetera, that's an example of a platform as a service, basically. So they're providing you with everything and it's up in the cloud, nothing to worry about here, folks, but of course you have the same potential problems.

You do outs where people use what's it called now? Microsoft 365. Which Microsoft disclaimed [00:30:00] any liability for any problems they cause for anything customers it's really crazy, but again, what are the problems there? Reliability slash performance, 50% of the people, 50% applaud on the screen.

Again here worried about reliability and performance, because if your business is relying on cloud computing, What, how is the security any good? That you could use something, as I mentioned Salesforce, and just picking them out of a hat and not, they haven't been like a terrible provider by any stretch.

But how about if you're going to Azure and you're using a workstation news here? How about if you're going to some other place, right? It could be Amazon web services. Google also has data processing services. Security's huge issue. Cost is a huge issue, reliability, performance, all of those. We're issues with more than 50% of the it [00:31:00] professionals.

I'm surprised that this next one, which is our staff skillset on dealing with cog computing 26%. The reason I'm surprised by that is hardly anybody knows enough about cloud computing. Do we really confident about it? I'm serious about that. There's some companies right now, we're talking with a company called Wiz and they audit Azure configuration.

So be very careful if you're using. Particularly if you're a business, it may not work out well for you. Hey, make sure you go online right now. Craig peterson.com/subscribe. Sign up. You'll get my newsletters. You'll get all kinds of great information. Absolutely free Craig peterson.com including my special report on passwords.

Now, if you have any questions, just email me M e@craigpeterson.com.

[00:32:00] There is a whole bunch going on when it comes to Russia, of course, invasion of Ukraine. We're going to talk about that. And what is I can, how does this domain system work and why are people calling to have dot R U deleted?

This is really a big deal. And if you're watching from home, I'm going to go full screen on this article.

This is an article from ARS Technica, and I've been talking about it all week, which is that I can won't revoke Russian in Jeanette domains, says the effect. Devastating. This is frankly pretty darn fascinating to me because I can, as this international organization, it was put together in order to help make the internet international.

And I'm not talking about the data international, but control of it. A lot of countries work. Because of [00:33:00] course the internet was created in that states. It was created by us tax payers, money for the DOD. And it was designed to be very resilient, in fact, so resilient that there could be a nuclear blast and that nuclear blast and.

Causing problems, but yeah. Yeah, the internet is still going to work. And the whole idea behind it was you could have multiple routers. They're all talking to each other nowadays. They're talking BGP four and they can say, how can I get from here? To there. And so the idea behind BGP is they all share this information once the least cost way.

What's the easiest way to post way. If you will, for me to get from point a to point B and it changes all the time. So you might be on a phone conversation. You might be listening to me right now, online streaming or watching the video you might be doing, who knows what [00:34:00] out there with digital communications.

But the communications channel that you think you're using, where the data is going from, let's say my microphone, ultimately to your device, your ears, that data path, once it becomes dated. Can be changing multiple times a second. Now it actually changes quite a bit. Initially as these internet backbone routers, send the least cost, routing information back and forth to, and fro a very good thing, frankly, because it helps to speed everything up.

And there's other tricks that we're using you. Might've seen. For instance, Akamai and some of the URLs before have sites that you've gone to, and that's called a content delivery network and that helps get the content to be closer to you. So if you're on a website in California and you're in New Hampshire, that website video, that website graphic, et cetera, is going to be coming from [00:35:00] a server local to me here in New Hampshire.

All right. That's how that all is supposed to work. So we have names you guys know about that internet, domain names and those domain names. You already know those are turned into internet addresses, and those addresses are then used by the routers to figure out where to go, how to get the data. The problem that we're having right now, of course, is Russia seems to be substantially abusing the intranet Putin, put a kill switch on to the Russian internet sometime ago.

And the idea behind the skills, which was, Hey, listen, if we don't want the world to be talking to us, we'll just cut it. Now he's tested it a couple of times, but what he has not done is shut it down and he hasn't shut it down. As part of this Ukraine, more, what they did is they passed laws saying, Hey, if you publish something that [00:36:00] disagrees with what we're saying, you get 15 years.

And even these people who've been protesting on the streets, they're getting a bound 60 days, 30 to 60 days in jail, just for protesting what's going on. So a lot of people have been saying why don't we just, we turn off the Russian internet now we're not going to use Putin's kill switch in order to shut it all off.

We're not going to do a well, a few things. She decided not to do, denial of service attacks, et cetera. Although there are hackers doing that and we are going to talk about that today, but they're saying what? Let's just go ahead and let's kill their dot R E. The country domain. And I can, the guy who heads it up said, Hey, listen our mission is just to make sure that the internet works.

So shutting off the dot R U domain so that no one can go ahead and. We send right. A [00:37:00] request out to the domain name servers and get a resolution to an IP address. So if you try and go to Kremlin dot REU or something, you will get blocked and you will get blocked. Not blocked. No, I like the great firewall of China or of Russia.

Now they've got one going pretty good. Yeah. Thank you. You ain't using us technology. It's crazy. What we've. But what it does is it says, oh, I hide dot, are you, I don't know. What are you talking about? So there have been a lot of people who have been pushing for it. And you'll see, on my screen here, that Ukraine is requested to cut Russia off from some of these core parts of the internet.

And I can, which is the internet corporation for assigned names and numbers. I couldn't remember what that was earlier said that I can must remain neutral and their mission they say is not to take punitive actions. It's to make sure the internet works. So are they really taking punitive actions [00:38:00] of the cat Russia off?

It's really interesting to me because look at what has been going on. You've got companies like Facebook as the great example who has gone ahead and just shut off people. They didn't like what they were saying. My goodness. At one point of you said you should wear a mask during this pandemic.

You would be cut off from Facebook. And then of course, if you said, no, you don't, you shouldn't don't need you, you shouldn't wear a mask that at that point you would be cut off, because science right. Sciences, we know exactly what we're doing now. It goes on and on. If you said that it came from a lab in China, you would have your account suspended.

Now of course their whole tune has changed and yeah probably came from a lab in China. It's crazy what these people have been doing. So we have arbiters of truth, who are some contractors sitting in their home or wherever it is the contractors for Facebook [00:39:00] that are going through posts that people are flagging as Incorrect as fake news.

So what happens is people say fake news and then that goes off to their team that then looks at it and says okay. Yeah, fake news because we disagree with it. It just blows my mind. We have to have free and fair and open discussions. Don't we. You have that line at Facebook and Google does some of the same.

A lot of these sites do a lot of the same. You get our major media outlets that are all deciding what they want to report on and what they want to label as fake and fake news. I'm just shaking my head because it's hard. It's hard to believe. What about. Russia is putting out fake news, as I've said many times before the first casualty in war, this isn't my quote. The first casualty in war is what, it's the truth. So if [00:40:00] truth is the first casualty, then that means we've got a lot of propaganda going on. We had propaganda coming out of Ukraine. We've caught some of those, like the, what was it? The. Chat goes, fighter, pilot, whatever it was who had killed, what was it?

Five Soviet or Russian jets, Soviet era using silver deer, techno era technology on the part of the Ukrainian turns out well. Okay, that, that was false news. That was fake news. The whole thing about snake island, where you had that Russian military. I know what it was a frigging but anyways boat sitting there saying we are a Russia.

Warship, you will surrender or, whatever. Do you remember that snake on just the small place, 13 guys and supposedly they shelled it and they killed all 13 turns out that was probably fake news as well. So that's from the Ukrainian side and on the Russian side they hardly reported I as to how many.[00:41:00]

The we're in fact, initially for quite a while, they were saying there are no desks. Then at the same time, the Ukrainians are saying they're 2,500 Russians dead. And that number keeps going up, who knows what it is today. It gets really crazy in the time of war. So if Facebook is going to stop someone from saying don't wear masks or do wear masks, depending on what day of the week it is basically right.

Wednesday. It's okay to say that Thursday is not okay to say that we're back. No it's not. Or then why can't that type of censorship? Move on to the next. I that's a big question I have now. Should we be shutting it off? I'll pull this back up on the screen again. And it, this article from ARS, Technica is saying that experts have warned, whoever they are that shutting down the dot R U domain.

Is going to cause just incredible problems [00:42:00] for Russians, which man would it ever talking about a major blow to the economy. And it would also cause problems for people who are trying to find out more truth about. Russia cause you couldn't get to their site. Now we've seen some amazing things in Russia.

We had the Russian, one of the Russian news agencies T, which is broadcasting and here in the U S that their entire staff just walked out saying, forget about it. We're not going to promote this fake news, but this is a little bit different question. Me personally. I don't think anybody should be censoring any.

For almost anything. Yo, there are some limits, but they're pretty extreme in my book. I'd rather know someone is an idiot because they're allowed to say stupid things, and counter, counter it, counter their arguments. You've got to have discussions anyways, stick around. We'll be [00:43:00] right back.

Microsoft. Yeah, they've been around a long time. They've been helping us. They've had lots of cybersecurity problems. People use Microsoft software on their desktop. Some people use it for servers, which is crazy, but listen to what they're doing now.

This is a little concerning. I'm going to pull this article up on the screen.

For those of you who are watching a long, either on rumble or YouTube ARS, Technica article, they have some really great articles. This particular one is about our friends at Microsoft. This is cool. Microsoft announced today? This was like a week or so ago that Microsoft would be suspending all new sales of Microsoft products and services in Russia.

Following the countries, unjustified, unprovoked, and unlawful invasion of. Now Microsoft [00:44:00] didn't give any specifics about the products, but it really is likely to be a blanket ban of all of the Microsoft products. This is very cool because Microsoft has taken an approach I've never seen them do before, which is okay.

When. Gets hacked. You get our friends at apple, putting together patches and getting them out. They get them up pretty quick. Microsoft had been doing much the same. The problem was some months there were patches every day that you had to apply. That's how bad this software is. And they decided that man, let's be like politicians here.

Let's release some very damning news Friday. At about 4:30 PM before a long weekend. So no one will notice. Yeah. Y'all are friends of politicians do that all the time. What Microsoft decided they do is, Hey, wait a minute. We know we're going to have patches. [00:45:00] It's not going to slow down. And because our code is terrible.

So what we're going to do, let me see here. How about we just release all of them at once and we'll just call it patch Tuesday, right? Because people were complaining about how much work it was, how much effort was effort. It was to try. They hate them. These machines apply these patches every day. Huge problem for everybody from home users to big companies out there.

So Microsoft has said, okay let's do that. Let's burry it. So nobody will notice okay that's what Microsoft does. And now we've gotten used to that. Now we have. We remember two guys, right? Bill gates followed by Steve Ballmer. Steve Bohmer was a nut job. Bill gates was a bad man.

I think he's just been trying extra hard to compensate for all of the evil he did over the years. But what we're looking at now is new management and that he's been in [00:46:00] there now for a few years, doing a great job, cleaning up Microsoft, making it a very competitive company. He has done some amazing things.

One of the things that he has decided to do, that's been very effective is how about this? How about we go ahead. And we work with various governments to help stop these Russian hackers. And I mentioned this a couple of weeks ago, what was happening and the Microsoft had reached out to the white house and said, Hey, listen.

What we have been looking at the hacks that have been coming from the Russian hackers, and we've been preparing fixes for some of those hacks. How about we work directly with some of these other countries? This reminds me a whole lot of the lend lease program in world war two. You might remember this thing, but the [00:47:00] us of course, initially was not involved in the war and they decided, okay we've got to help the United Kingdom.

How are we going to help them? The UK doesn't have the money to buy ships, to have us make weapons, bullets know. What they did is they had people donate the rifles, the guns ammo from home. Plus they made them the government, instead of selling them to the UK, they lent them to the UK because the UK could not afford everything that it needed in order to fight a war against the national socialist in Germany.

So what did they do? We just shipped the stuff over there and called it a lend slash lease. I think that's a great idea. And what Microsoft is doing is also great idea. They have been decoding, reverse compiling, if you will, and interpreting the code, looking at what some of the ransomware and other malicious code the Russia has [00:48:00] been using against Ukraine, and they have been providing.

All kinds of insight information to these other countries. Now, this is a great idea for a few reasons, one of the reasons, and I think maybe the biggest reason is that the ransomware, the viruses, all of this malware that they're producing is. Not particularly discriminating. Do you guys remember maybe I dunno, what was it?

Six months ago, I taught, told you how to avoid getting most of this Russian ransomware. And it was as easy as just installing. Yeah, installing a keyboard on your computer windows or Mac, windows. Those are the machines are always getting attacked quite successfully most of the time, but the windows keyboard.

Russian language. Now you didn't even have to use it. [00:49:00] You don't have to have a keyboard, right? This isn't a Russian keyboard that I'm holding up here on camera. This is just a regular us keyboard. You can just install a virtual, Russian keyboard. And once that keyboard was installed, you're pretty safe.

Why? Because Vladimir poop. Dictator for life of Russia decided he would just go ahead and stop anybody that was trying to hack Russian. Companies businesses, government agencies and what's the best way for the hackers to do that. Cause they didn't want to end up in Siberia for the rest of their lives because of a hack.

Now they went ahead and said, okay if there's a Russian Cyrillic keyboard on the machine, we're not going to activate. So if the software, the malware on your computer, all you need to do is have a Russian keyboard. Yeah, that's it pretty simple. I told you that months ago, now what we're seeing is these indiscriminant [00:50:00] types of software that are being used in Ukraine.

Why doesn't the keyboard trick work while some of Ukrainians peak Russian, we could go in. To the background on that of the massacre, the starvation purposeful starvation of Ukrainians by the Soviet union over many years ago. And how they then gave their property, their homes to Russians to move into in order to occupy Ukraine.

So there's people in Ukraine who are Russian speaking of course. Now we're talking two or three generations, four, maybe down the road from when the Soviet union killed all of those millions of people. But there are some fights that to say, there's Russians, Russian speaking people there. Let me put it that way.

Perfectly. In Southeastern Ukraine anyways I'm going on and on I, this is not an education on war or history. This we're talking about [00:51:00] cyber security. So the, they have, they been, Microsoft found many cases of Russians putting destructive. And disruptive or even more than that data wiping malware onto computers, it spreads indiscriminately.

So Microsoft looking at what's happening, you crane, trying to get patches together for all of us, letting other countries know about what's going on is going to be. Amazing because this malware, which is wiping computers, primarily, it's not really just straight up ransomware give us money and we'll give you your data back.

This is just showing your data, that malware is going to leak outside of Ukraine. Yeah. Cause us all kinds of book tension, probably. When we get back, I want to talk about this here. This is our friend Ilan Musk, and we've been following [00:52:00] along with some of the stuff been going on with his new satellite system in Ukraine.

Stick around.

The whole concept of these satellites and circling the earth, providing us with internet, just regular guides. It's going to be in our smartphones is changing everything. We're going to talk about Elon Musk and what's happened over in Ukraine.

Our friend Elon Musk has done a lot of things over the years. He has really helped us for frankly, the Tesla and what's been happening there.

SpaceX, his main concern being let's get off of a single planet on to multiple planets, right? The movement to Mars, NASA's working on a serious moon base. I reminded him of space 1999. You guys remember that show, but yeah, we're going to have a moon base by then [00:53:00] and it makes a lot of sense. So who's going to go to these well, there's some interesting lotteries people have to apply and everything else, but he's done so much, right?

He's got the boring company you'd already know about Tesla and boring company in case you didn't know makes underground tunnels. He has also. A few other things has got a huge battery manufacturing facility. They're working on new battery technologies to make all of our lives a little bit better, particularly if we have an electric house or electric car, because this is what good is it to have electricity that you can't use.

And that's really what they're trying to do is make it so that electricity is available 24 7 for you. And. Those space X, which is what I mentioned as well as what we're going to talk about right now. I'm going to pull this up on my screen. For those of you who are watching over on rumble, or of course, YouTube, this is fascinating.

He [00:54:00] said there's a high probability of Russian attacks on Starlink in Ukraine. Now that is fascinating because what he's done is he has sent over truckloads. I'm showing a picture of a truck. In fact, with these Starling terminals in it, that's from ARS Technica. Just double-checking it here, but this is very cool.

This is posted by the vice prime minister over there in Ukraine. And they are talking about these terminals. Now a terminal in this case is something that allows your devices to talk to the Starlink satellites, or there's going to be a huge constellation. They've got 2000 satellites up and they're putting another 12,000.

These types of satellites are much different than what we've been used to over the years. We were typically, we've had these massive things sitting up in space. [00:55:00] I worked with RCA Astro space many years ago and I saw. They're testing facilities, which are just incredible. They had this huge vacuum chamber that they brought me in to see as we were working on space shuttle software.

Yeah. I wrote software that they used to put the space shuttle together yeah. Way back in the day. So that was a pretty proud moment. Anyways. It's we're not talking about these huge satellites, like they used to launch, we're talking about very small cell. And they're not just sitting way, way up there.

These are in basically in low orbit around the earth and they're geostationary. In other words, they stay in one spot. I believe this is the way they've got these things set up. So these satellites then allow because they're so close to the earth, allow them to use less power. And also the other advantage to that is.[00:56:00]

The delay, right? The delay between having to send it all the way up and back down, because electricity takes time, right? Yeah. Travels at the speed of light. But nowadays you might've noticed it can take your quarter second, half a second. When you're talking to someone, when I'm on the radio with some of these radio stations or the delay can be absolutely incredible.

Like I half second to a second sometimes. And that's just because they're being cheap. This type of technology where you have these constellations and it isn't just Elon Musk. It isn't just Starling, but constellations with will ultimately we'll have tens of thousands of satellites up there. Not, there's all kinds of other potential problems not getting into that right now.

But what it does mean is yes. Can communicate and we've never had this sort of thing before we had the us military, the Navy in fact, put together a communication system that [00:57:00] lives on top of the internet and called nowadays. Generically the dark web. And it was set up to allow our military, our state department to be able to communicate with people in countries that are back in the day under Soviet control, all kinds of potential problems.

So whenever those problems existed, they just went ahead and used this onion network, which is a part of the dark web, et cetera, et cetera. So let's say we had before. Now what happens if you're a country like Ukraine, where 100% of your internet comes from Russia, Russia obviously can sit there and listen in.

Hopefully your encryptions. Good. A lot of Russians have been using telegram and already get real news about what's happening in their country and other places. And Della Graham is not that secure, frankly. WhatsApp pretty secure signal is the [00:58:00] one you want to pay close. Attention to signal is considered to be the most secure of all of these secure communications apps.

But there's a level above all of that, because if they can tell that you're communicating, even that is enough to give them some information. So they might not know what was in that transmission, but if the transmission is all of a sudden, a tons of activity coming over, lots of data, lots of messages going back and forth, they can say maybe there's something about to happen.

That came out. You might remember the old orange book for security way back in the eighties, I think is when it came out. But part of what you had to do was cover up your. Actual real communication. So it's one thing to have the communications encrypted, but you wanted to always have about the same amount of communications going back and forth.

So people couldn't figure out what you're doing now with these types of devices. That [00:59:00] kind of problem still exists. And this is part of what Elon Musk is warning about here. Pull it up on my screen again, for those people who are watching Elon Musk is urging users of his satellite system to put their Starlink antennas as far as.

From people as possible. Now, why would he be doing that? Because frankly, that terminal is transmitting to the satellite as well as receiving from the satellite. And it is entirely possible that there could be some evil software that is listening in for the satellite transmissions and sends a little missile your way.

Also, of course the Russians have satellites in space that can look down on the ground. Now it's something as small as a terminal four Starlink, little hard to see, but Elon Musk is saying, Hey, listen guys, [01:00:00] go ahead and camouflage it. You might want to spray paint. It just don't use metallic paint so that they can't see it and place it as far away from where people are as post.

So you can still use it and only use it when you need to use it. Don't keep it up and running all the time. But this is the start of something great. Something where you can't easily block people's communication. So Russia has tried to do. And they have been jamming the Starlink satellites. So what did must do?

He delivered all of his engineers to working on how can we get around the Russian Jack? And according to Elon Musk, they have gotten around it and they now have their satellite systems completely jammed free from the Russians. I think that's fascinating. They're probably using some good spread spectrum technology that was actually known about it and world war II.

And then we can talk [01:01:00] about that for a long time. Heady, you might remember her anyways, skip that for now. Stick her out. We got more when we. A whole bunch of pandemonium out there because of what Russia's been doing in Ukraine and how it's flowing over to us as well. Hey, this is not great news.

Pandemonium is the name of the game over there in Russia. And they are being very successful. We're going to talk about what happened in Bella ruse. We'll talk a little bit about what happened in Ukraine with cybersecurity and what's happening right here right now.

I'd also like to invite you guys to listen to me on all kinds of apps out there, including the tune-in app and many others. Let me get my screen set up because now you can also catch me on. And on YouTube, this is almost [01:02:00] a complete, let me pull this up for you.

There we go. Complete ARS Technica today. They've got some great articles this week, looking into the Russians. What are they doing? What kind of problems is that causing us? But we are seeing some interesting attacks back on. And back in very big way. Russia has been going after you crane in the cyberspace for a long time, we spoke a few years ago about what Russia had been doing with the tax software for Ukraine.

We don't do this in the us or in Canada, but my number of European countries do you, where you have to have. The old official tax preparation software put together by the government for your business or for your person, depending on the country you're living in [01:03:00] France is a great example of this. And Ukraine is another one.

So Ukraine says, Hey guys, you got to go ahead and use our software. That means every business in Ukraine is using their software. To manage their tax payments and their accounts, frankly. And that wonderful little piece of software was hijacked by our friends in Russia. So they grabbed a hold of it. They in.

Did some code into it that added rent somewhere to the software. So now all of the businesses in Ukraine are pretty much guaranteed to be using this hacked software. We have a client who has offices over in France, and we found a really interesting problem with them because. The French software that was being used for taxes for French businesses had an extra little [01:04:00] problem.

And that extra problem was, it was insecure as can be whoever wrote this, must've taken a Microsoft programming course and had no idea DIA about the consequences of what they were. So it was very insecure. The, it was using a version of SSL, which is an encryption that's based on another type of increase.

I don't want to get too wonky here, but that was just one of its many problems and bad keys, et cetera, et cetera. And keys by the way, was using keys that had been revoked, which you should never do. Bottom line. Oh my gosh. Hey, if you want more information on this, just drop me a note.

me@craigpetersohndotcomandyoucanalsogetmynewsletterwithallkindsofgreatlittletipsmeatcraigpeterson.com. Just let me know. So in this case, we had to help that company in [01:05:00] France. Ignore the security restrictions that were on their systems so they could use the French tax system. So anyways, I told you that, so I could tell you that the same thing happened to Ukraine.

In a different way, their software was pre infected. So when they downloaded it, ta-da. They got that piece of ransomware that virus had spread. It was just a nightmare. And of course it robbed. If you will, Ukraine, government of funds, that would have been. So we had now a bit of a shift. I'm going to pull this up on the screen again, this article, because what this shift has shown is that the hackers are now operating on the side of you.

Crazy. Which is just fascinating. So the group called anonymous, you might be familiar with them. Of course, they've been doing a lot of hacking for a [01:06:00] lot of years, releasing private information, government and information. All of that sort of stuff. And they have a mast what they're calling a volunteer.

It. And this it army has been going and doing what well hacking Russian sites apparently. So this article is just absolutely fascinating and they pulled some of from wired as well, but the Russian space research Institute, their website was hacked, leaked files that were stolen from the Russian space agency, made it all the way on to the.

The space agency was hacked in their website said, leave Ukraine alone, Alto anonymous. Will you up even more? They also did. What's called a D O S. Which is a distributed denial of service attack. Those can be [01:07:00] very difficult to protect against unless you're set up in advance to help protect yourself.

And that pretty much destroyed Russia's dot are you top level domain? So we've talked about how domain services work, right? So Doug are, you is like.com except dot R U is for running. And so the domain name servers that handled our, you were knocked off the air because no one could really get to them.

They used amplifying attacks and stuff without getting into all of the details. So basically they were trying to cut off access and they did for a lot of people to any. That ended in, are you? It's great. These are just some of the latest in this surge of hacktivism. That's been going on one of the ones I mentioned a couple of weeks ago with the Belarusians deciding they were going to hack the Belarus railroad, which was being used.

To bring Russian [01:08:00] troops, supplies, tanks, et cetera, all on rail, right on down right to the border of Ukraine. So that was hacked so that they couldn't use it in order to go after. Of course Russia was able to get to Ukraine, but there's also been protests around the world. 48 Russian cities raise millions of dollars through cryptocurrency donations.

Now, I'm not a big cryptocurrency guy and I'm not a big crypto currency guy because while. Cryptocurrency is likely to be outlawed by most, if not all governments. And they certainly could shut it down and it is not anonymous. All right. So using cryptocurrency does not mean it does not equate to completely anonymous.

They have done a lot of donations. They're big companies including, we [01:09:00] just talked earlier about Microsoft, but also apple shell, BP, a McDonald's Starbucks. And these hacktivists have really joined in. And w we talked about a couple of other things, so this is messy. Because even more than in peace time, these active combat that are really hacking happening right now, rendering, hacktivism, any effectual and largely just distracting because we are now in a hot war right now.

Maybe we don't have our. Eric planes bombing Russian movements or other things, but there is a kinetic war going on over there. There are bullets, et cetera, mean exchanged. So the hacktivist efforts have been, visible. There's no question about that. But what have they done? See, [01:10:00] that's an advantage to being a country like Russia, or like the Ukraine, or excuse me, Ukraine, because both of those countries there, their industrial base, the military industrial base is not heavily automated unlike ours.

What could you do? What can you shut down? So what you shut down the Russian space agency's website, how far did you get into it? Probably not very far. We also have a couple of groups and we talked about these guys many times the Conti group, which has been.

Terrible and hurting us businesses, individuals, government agencies, and stuff, the Cuming project, both of them have declared their allegiance to Russia. You might remember a few weeks ago, we talked here about how we have had some researchers track down most of these Russian hacker groups and their money.

And they all ended up in one building in Moscow. [01:11:00] No, that should tell you something, right? In fact, the most expensive real estate right there in downtown Los gal, the tallest building, et cetera. So these groups getting together in order to protect the father land there in Russia. Ah interesting problem.

How much of this is really controlled by the Kremlin? It's a very good question. Context. Was dismantling its infrastructure. It, some of their top people were arrested by Putins military. Not military, but police state over there. And that was interesting too. That was again before the invasion, but why would Putin be shutting them down at all?

Apparently they said some things. That they shouldn't have said. So now they've come out and have decided they're going to support Russia in its entirety. Now we mentioned Microsoft and how [01:12:00] Microsoft has decided they are going to protect other countries. As well as you crane, at least as far as the Russian malware goes, and they've been very active in that.

And there are a number of cybersecurity companies and other organizations that have released free versions of some of their software, these digital defense tools. Free offerings. Our big cranes defend the networks. Google says it's human rights focus de dos protection service project shield is now in use by more than 150 Ukrainian websites.

So it's very good. Bottom line propped up by the way, published this massive trove of personal data. Allegedly identifying 120,000 Russian soldiers deploy. In Ukraine that was Ukrainian prov, not the old good old Russian Sophia Pramata man. I [01:13:00] remember I bought one of those on new standing Canada once.

And I had a friend who was from Yugoslavia and he said, oh, can I show that to my wife? He showed it to his wife. She tore it up. I said, I want my Pramata, Craig Peterson got calm.

View Details

Did You Hear About the Latest Rip-Off? Non-Fungible Tokens (NFTs) Are Already Losing Steam!

[10:54] How Law Enforcement Tracks Bitcoin! It is Absolutely NOT Anonymous

[20:05] The FBI Is Actively Removing Malware From Private Machines -- Without The Owner's Permission

[29:10] Why and When You Shouldn't Trust QR Codes

[41:08] Cybercrime in Russia Tracked to a Single Office Building in Moscow!

[52:29] The Newest Phishing Scams

[01:01:32] Using Wordpress? How Supply Chain Attacks are Hurting Your Business Website

[01:10:43] Cybersecurity Tools You Should Be Using!

Jam packed today. We're going to start with non fungible tokens. If you don't know what those are, this is a very big deal because so many people are investing in them right now. Are they really investments? I've got a bit of a blow back here. Most people think that Bitcoin is anonymous. We're going to talk about how it absolutely is not.

[00:00:20] We're going to talk about anonymous. In fact, the Russians, Microsoft, what they're doing against the Russians and this little comedic thing about cars.

[00:00:28] NFTs are very big deal.

[00:00:31] I'm going to pull up here on my screen right now. This is a picture of Mr. Jack Dorsey. We'll go full screen, an article from a website called CoinDesk. CoinDesk is one of these sites that really tries to track what's happening out there in the Bitcoin community. Of course, nowadays it's much more than Bitcoin.

[00:00:53] Isn't it? We're talking about all kinds of. Different currencies that have a blockchain backend. They're called cryptocurrencies basically. But the big one was of course, Bitcoin. And there is a whole concept. Now, when we're talking about things like cryptocurrencies and these non fungible tokens. People have been investing them in them.

[00:01:19] Like crazy people are making millions of dollars every week. Now, remember, I am not an investment advisor and particularly I'm not your investment advisor. So take all the. To your investment advisor. I'm not telling you to buy them. I am telling you to be cautious here though, because these non fungible tokens are designed to give you the ability to be able to just, own something in the digital world.

[00:01:48] What might you own in the digital world? We've had a lot of different stuff. We've seen some just crazy monkey things. Have you seen those? These little pictures of monkeys are. Graphic designed and it's all animated. If you will. It's like cartoons and people pay money for them. One of the things that people paid money for was the rights to the first tweet ever on Twitter.

[00:02:16] So that's what you're getting. When we're talking about an NFT on a non fungible transaction, it is now yours. So this particular NFT we're talking about was of our friend here, Jack Dorsey. We'll pull it up again, this article, and he had a tweet that was sold last year for $48 million. That is a lot of money.

[00:02:43] So people look at this as an investment, but it's not the same as hanging art on the wall. You've got a Picasso that has some intrinsic value. It's a painting. It has all the oil paint on that, it was designed by and painted by a crazy man years ago. And you can take that Picasso and you can.

[00:03:07] Turn it around and sell it. It has some real value. If you own the rights to something, let's say it's one of these monkey pictures. It reminds me of a postage stamp and you paid real money for it. Some of these things are going, as I said, for over a million dollars and this Jack Dorsey first tweet went for $48 million.

[00:03:27] So let's say that's what you did, right? You bought this thing for $48 million. Really? What do you have? Because anybody can go online and look at that tweet. Anybody can print it up and stick it on a wall. Anybody can go out and get that picture of the monkeys right there. The guy drew, and you can look at it.

[00:03:51] In fact, I can pull it up right now, if you want to do. But people paid real money for that. So they've got what really? What do they have? You can't take it off the wall, like you're Picasso and salad, right? Or Banksy, if you're into the more modern art, it's just not. What is doable? How do you make this work?

[00:04:12] Only the NFT only gives you bragging rights in reality. That's what it does. You have bragging rights because you could take that digital picture and make a hundred quadrillion copies. Yeah, you'd still own the NFT you would still have in the blockchain for whatever NFT company you're using the rights to it.

[00:04:37] They would say this, you owned it. So let's talk about the blockchain behind it. There are a lot of companies that are trying to give you that. Okay. All right. I get it. Yeah, I get to to own it. But who's running the blockchain behind it. Who's validating that you own it with Bitcoin and many of these other blockchain currencies that are out there.

[00:05:04] There are various. Companies and individuals who are registered, who have all of the paperwork, if you will saying who owns, how much of what, and who paid, who and everything. And that by the way, is why it takes so long for some of these Bitcoin and other transactions to occur. But how about the NFT? There are tons of companies out there that say they will certify the NFT.

[00:05:34] So it gets to be real problem. And when we get into this Jack Dorsey tweet and this article about it, which are will, let me pull it up again here for you guys. This guy, Sina S bought the very first tweet ever from Twitter founder, Jack Dorsey for $2.9 million last year. And he decided that he wanted to sell it.

[00:06:03] So he listed it for sale again at $48 million last week. Real. He put it up for open bid and this article and CoinDesk is talking about that. And you can see that if you're watching me on rumble or YouTube, I'm showing you my screen here right now. But this Iranian born crypto entrepreneur named of again.

[00:06:28] As TAVI purchased it for $2.9 million in March, 2021. Last Thursday, he announced on Twitter where out, that he wanted to sell this and Ft. And he said, Hey, listen, I'm going to put 50% of the proceeds to charity. The auction closed, this was an open auction. People could go and bid on it and head auction closed.

[00:06:55] With an offer of basically $288, $277 at current prices when this article was written $277 and the lowest bid was $6. And as I recall, this is not in this article, but there were only. I handful of bids. Like when I say handful, I mean a half a dozen beds. Crazy. This is a real problem because the deadline is over.

[00:07:27] He paid how much for it, right? How much did he pay? Pull that up again. $2.9 million last year. And his highest bid was in the neighborhood of $280. Isn't that crazy. So did he get money on this? Did he win money on this? I don't know. I'm looking at those saying is it worth it to buy something like that?

[00:07:54] That you might think, oh, the very first apple computer, an apple. While that's going to be worth some serious money. Yeah, it is. It's something, you can grab onto, you can hold onto it, it's something and you can sell it. You can trade it. You can take a picture of it. You can't make digital copies of it.

[00:08:15] You, you, it's a physical thing. That's worth something. Same thing with that Picasso on the wall, it's really worth something that has some basic intrinsic value. Jack's true tweet. The very first tweet. How much is that thing worth? It basically nothing. So the tweet is showing he'll pull it up on the screen again that he's selling ad Jack 2000 6 0 3 21 at eight 50 14:00 PM.

[00:08:46] Just setting up my Twitter. So there you go. There's Jack is very first to. And it's absolutely amazing. Is it worth it? Let me pull up some other stuff here for you guys. I'm going to pull this up here is Coinbase launching an NFT marketplace in hopes of appealing to crypto on mainstream users. So here's some examples from a man and FTEs.

[00:09:11] I'm going to zoom in on this for those of you guys watching on rumble or on Twitter. All right. Mean. Yeah actually you can see it on Twitter too, but YouTube, here you go. Here's some NFTs it's artwork and it's a creature. So you can buy creature number 7, 8 0 6 right now for six Eve. So let me see.

[00:09:34] Value of six. Ethereum is what ether, M two us dollars. So for 3000. And $84. As of right now, you can get a crappy picture that even I could have draw okay. Of this guy and look at all of the work this artist has put in. There's how many of these up here? 1, 2, 3, 4, or five, 10 of them. And it's the same head.

[00:10:03] Each time it looks like this almost the same eyes. He changes colors and he's got different background. It's absolutely not. So that's what they're trying to do right now, trying to sell these NFT. So who's going to buy that. Who's going to pay $3,000 for artwork that hunter Biden could have done with a straw.

[00:10:25] Anchored around. Here's another one. This is from ledger insights. NBA's launching dynamic NFTs for fans, baseball cards for the NBA that are basically just worthless. They're NF. Non fungible tokens. It has taken the crypto world by storm and people are losing millions as you look, but it really is changing the e-commerce world.

[00:10:54] Bitcoin blockchain. All of the rage, a lot of people are talking about it, but I got to say most people who are talking. I don't know much about it. And when it comes to anonymity, Bitcoin is probably the worst thing you could possibly do. It's amazing.

[00:11:12] There are a lot of misconceptions out there when it comes to technology, you have almost any kind of technology and blockchain and Bitcoin are examples of a very misunderstood technology.

[00:11:25] Now I'm not talking about how does it work? How are these ledgers maintained? How does this whole mining thing work? Why has Chan. Bandit. Why are a lot of countries going away from it, one country. Now the dictator said, yeah, we're going to use Bitcoin as our we're official currency. In addition to the U S dollar what's going on.

[00:11:48] It is complicated behind the scenes. It's complicated to use. Although there are some entrepreneurs that have made some great strides there. I saw a documentary on what has been happening in that one country. I mentioned. They are able to pay in us dollars using Bitcoin. So they'll go up to a vendor on the street.

[00:12:13] Quite literally they'll have their smartphone with them. The vendor has their smartphone. They type in 15 cents for the taco and a hit send. It goes to the other person and they have 15 cents worth of Bitcoin. By the way, these types of micro-transactions with the way Bitcoin is structured behind the scenes, make things even less manageable in the Bitcoin world than they have been in the past.

[00:12:40] And that's why in case you didn't know, Bitcoin is making some major changes here fairly soon. They've got to change the way all of this ledger stuff works because it takes too long. To record and authorized transactions. And these ledgers just get way too long when it comes to all of these kinds of microtransaction.

[00:13:04] So there's stuff going on, Bitcoin, there, there are many of these types of currencies out there. Theories comes one. You've heard about doge coin because of course that's Elon Musk has been talking about and many others and they're all different somewhat, but the main concepts are the. One of the big concepts, I'm going to pull an article up here on the screen for those watching on YouTube or also on rumble.

[00:13:30] But this is an article from our friends at wired magazine. And now you have subscribed to wired for many years. This particular one is about what wired is calling the crypto. Trap now that's a very big deal. It is a trap and it's a trap and a lot of different ways. And that's what we're going to talk about right now.

[00:13:56] Crypto is not what its name implies. A lot of people look at it and say, oh, crypto that's cryptography. That's like the German enigma machine in world war two and all of this new, great crypto that we have nowadays. And there are some pretty amazing new cryptographic technologies that we've been using, but no, that's not.

[00:14:17] What's really going on. You see the basic premise behind all of these technologies is the concept of having a. And this wallet has a unique identifier. It has a number assigned to it. So if I'm sending money to you, I'm going to have your wallet, ID, your wallet number, and I'm going to now send you some amount of fraction, most likely of a cryptocurrency and it's certainly if it's Bitcoin, it's almost certainly a fraction.

[00:14:49] And so I'm going to send you $100 worth of, let's say. What ends up happening now is these ledgers, which are public, are all going to record the Craig's sent you a hundred dollars worth of Bitcoin. Of course, it's going to be in a fraction of a Bitcoin. So sometimes there's rounding errors is not going to be really exactly a hundred dollars.

[00:15:12] Plus there's the amazing amount of. Tivoli volatility in the cyber currencies. So even though I meant just hitting a hundred dollars, mine ended up being 110 of it goes up. It might be 90. If it goes down you get that. You don't understand how that works. So the problem now is I have sent you a hundred dollars.

[00:15:33] And public ledgers that anyone can gain access to now say wallet number 1, 2, 3, 4 cent, a hundred dollars, two wallet, number 5, 6, 7, 8. Obviously the wallet, our bruises, a lot longer than that. So then it's fine. And there's a degree of anonymity there it's really called pseudo anonymity because in reality, it's not completely anonymous because people know the transaction occurred and they know the wallet numbers.

[00:16:03] Correct. It's like a bank account, and if I'm putting money into your bank account, that bank account number knows that the money came from a check that I wrote. Can you imagine that someone writing a check and that check I had a number on it, a bank account number, right? So it can all be tracked while much.

[00:16:19] The same thing is true when it comes to cryptocurrencies, these cryptocurrencies are in public ledgers and those public ledgers can be used with a little bit of work to figure out. Who you are. So this article here from our friends at wired gets really hairy. And it might be of interest to you to read, but this is talking about a take-down that happened, and this is a massive take down.

[00:16:51] This take down was of a whole group of people who were involved in some really nasty stuff. In this particular case, what it was kitty. Just a terrible thing and the abuse surrounding it. So this logical goes into not a lot of detail. I'm not going to read it because here on the air, because I don't want to upset too many people.

[00:17:15] Cause it's some of the details of this evening to think about them are incredible. But. This the police broke into this middle-class suburb home in the outskirts of Atlanta. And he there was Homeland security. It was a guy from the IRS and they came in, they took all of their electronic devices.

[00:17:38] They separated the family, putting the father who is an assistant principal at the local high school assistant printers. And he was the target of this investigation. So they had him in one room, they had his wife and another room and they put the two kids into a third room and they started questioning him.

[00:18:00] Now, this is part of a takedown of a, as I said, a whole ring of these people, including this assistant. Principal at a school. Can you believe that? So this IRS guy had flown in from Washington DC to have a look over what was going on, but this agent from the IRS and his partner whose name is let's see, his name was Jenn S Scouts.

[00:18:26] I probably got that wrong. And Tigran GAM bar Yan, Cambodian, and they had a small group of investigators and they were at a whole bunch of different federal agencies, not just the IRS. What once seemed to be. Untraceable was no longer untraceable. Now I've talked on this show before about a lecture I went to by the secret service about how they had tracked down and shut down the world's largest website that was being used to sell illegal materials online.

[00:19:01] And it's fascinating what they did. But frankly, they're calling this particular boss to proof of concept and that's why they are IRS was in on this as well, but it was huge. Here's a quote from the IRS agent in this wired magazine article. He's saying he remembers how the gravity of this whole thing.

[00:19:21] Let me pull this up on the screen too. So you can read along here, but this was a high school administrator, a husband, and a father of two, whether he was guilty or innocent. The accusations, this team of law enforcement agents were leveling against. There are mere presence in the home would almost certainly ruin his life.

[00:19:44] And he, as well as these other people were counting on anonymity from Bitcoin. Now, obviously I'm glad they got taken down, but listen, folks, if you think that it's safe, that it's anonymous, it ain't Bitcoin just ain't there. Craig peterson.com stick around.

[00:20:05] I've been blamed for really complaining about people not updating their software. And that includes things like firewalls. The FBI has stepped in and they are going ahead and doing updates for you.

[00:20:21] What should we be doing as a country?

[00:20:26] People are. Updating their software. They're not updating their hardware. And particularly our hardware take a look at what's been happening with the firewalls and the firewall concerns. Everybody has some sort of firewall will almost everybody, but enough people that we can say, everybody has a firewall, you get your internet from you, name it.

[00:20:50] And because of the fact they're using something called Nat network address translation, they've got some sort of firewall in front of you. So for instance, You've got your phone, right? You're using your phone and it's got internet on it. You're going through whoever your carrier is. And that carrier is giving you internet access, right?

[00:21:14] They don't have enough IP addresses, particularly IPV four, in order for you to get your very own unique little address out on the. No they do. When it comes to V6 things a little bit different, but your device is not completely exposed on the internet. Windows comes to the fire. And by default, the windows firewall is turned on.

[00:21:35] Now this gets more than a little concerning because that firewall that's turned on. Isn't really doing anything because I've got a firewall turned on and yet every service is accessible from outside, which is defeating the purpose of the firewall. Again, it's a complaint I've had about Microsoft now for.

[00:21:55] Decades, which is they have features that are just check boxes. Yes. Yes. It's got a firewall. Yeah, it's turned on, but the features don't work. So having a firewall and having everything open defeats the purpose of a firewall max do not have a firewall turned on by default, but they do have their services to say.

[00:22:18] Which is just as effective if not more effective. So one of the things we advise people to do is go into your windows system, into the firewalls and your security settings, and turn off any services that you're not using. If you're not sharing file systems, then turn that off. In other words, You're mounting the G drive or whatever you might call it from another computer, then you don't need it.

[00:22:44] If you're not as server for what's called SMB, then you don't need to share it. So turn off everything that you don't need. That's going to happen is one of your programs isn't going to work, right? And the, what you did last year, you're going to turn it back on and you can do a lot of research online to find out what they are.

[00:23:04] We have over 200 settings that we change in windows. When we get a customer. Now on the Mac side, you can turn it on. I liked turning it on. I liked turning off the ability to see my machine. So in other words, the ability to be able to. So I turned it on and I enable specific services. And again, you can do some research on that.

[00:23:30] I've got an improving windows security course that people have taken, and we should probably do that again, if not just have some free webinars on how to do this. So you guys can learn how to do it, but not that hard to do. Anyhow, bottom line is. People aren't updating their computers, even the Macs and windows.

[00:23:51] We have a client that would just started a new client and we're tightening things up and we've been finding Mac computers that are major multiple major revisions behind. And that to me is shocking. Apple Macs are just so easy to update. It is extremely rare that an apple update will make your computer break unlike in the windows world, where it's pretty common.

[00:24:17] So windows guys, I can understand, but your even more exposed, your bigger target, you need to keep up to date. So how about all of the other equipment that we. I've had warnings again and again, with you guys about what's happening with our smart devices that are out there, right? Our security cameras we have up in the corner, right?

[00:24:41] We have these smart thermostats, people are using the list goes on and on of all of this equipment that we're using that is exposing us because when was the last time you have. How about the firmware in your router or your wifi, right? Some of the devices that I recommend to people, and if you have any questions, just email me and e@craigpeterson.com.

[00:25:05] I can give you recommendations, even if you're a home user. Although my business obviously is working with businesses on what kind of wifi to buy, what you should get, what you should do. I don't charge for any of that stuff. Okay. You get it. But you have to ask. Me@craigpeterson.com. So you get this information and you go ahead and you buy whatever it is, but you don't keep it up to date, which is why I tend to only recommend stuff that automatically updates.

[00:25:33] But that also means every few years you're going to have to replace it because unless you're using the good Cisco equipment where you can get a seven year life out of it you're not going to find that in consumer grid. So what's happened here. I'm going to pull this up on my screen for people watching this on YouTube or on rumble.

[00:25:52] But here is a thing that came straight out of our friends here from the FBI. This is from CSO. This is a a magazine that I do follow. But they're talking about what they call psych clock. Blink. So the article says for the second time in a year, the FBI has used search and seizure warrant to clean malware from devices owned by private businesses and users without their explicit approval.

[00:26:25] The FBI used this approach to disrupt a botnet, believed to be the creation of right. Government hackers. So the calling this SYEP clock cycle clubs, blink malware discovered earlier this year. So here's the problem. What do you do if you're the federal government, how do you try and keep your country safe?

[00:26:51] Now we know. We've got these military contractors. They make missiles that take out missiles, right? The provide defensive systems. You've heard of iron dome from years ago, all the way through all of the current stuff. That's what they do, but what do they do? What can they do when there's a botnet? A botnet is where there are multiple computers in this case, probably tens of thousands of computers located in the United States that are acting like sleeper.

[00:27:21] They sit there and they wait for commands as to what they should do. Should they try and attack a machine? Should they try and spread more? Malware, what should they be doing? And the, these things are vicious. They are absolutely nasty. And in this case, we're looking at Russian malware. So Russia effectively like the Americans.

[00:27:44] You might remember that TV show. It was great show, but that. Computers that are owned by you and me and our businesses and government agencies that are under the control of the Russians. Now you don't even know it. You're using your computer. You're playing games. You're going to Facebook, whatever it is you do on your computer.

[00:28:06] Your computer is under command and control of the Russians. So the FBI goes to a court and says, Hey, we've got to go ahead and shut this down. We need a warrant. They get the warrant and the search and seizure warrant lets them now. Get on to these machines that are part of the bot net or the controlling machines for the bot net, and either remove the malware or go ahead and take control of the botnet themselves.

[00:28:34] So it can't be used. And by the way, our friends at Microsoft they've gotten involved in this too, which is really frankly, cool in shutting down some of these botnets, Hey, I want to encourage everyone. Take a couple of minutes, go to Craig peterson.com/subscribe. That's Craig Peterson. CREI G P T R S O N.

[00:28:57] And subscribe, and I'll be sending you a special report on passwords. Plus two more. I send out the most popular special reports that anybody has ever asked for.

[00:29:10] Hey, I've got a little bit more to discuss on what's happening with Russia and Microsoft and more, but I'm also going to talk about QR codes. There is a great explanation. That's in your newsletter from Monday about why you shouldn't trust 'em.

[00:29:26] Let's finish up this Russian thing. And then we're going to get into why you cannot trust QR codes and a brand new way.

[00:29:36] The bad guys are using QR codes to really mess with us. Now, if you're watching over on either YouTube or on rumble, you'll see this. Let me pull up my screen for you. But here we go. Okay. This is very interesting. Then the last segment, we talked a little bit about what our friends over at the FBI had been doing, which is they have been removing malware from people's computers because people haven't been keeping their computers up-to-date right.

[00:30:11] Part of the botnets. So we explained. At the FBI, isn't the only one out there trying to stop these Russians and the hackers anonymous has been very big at it. In fact, let me pull up this other article. This is from security affairs. And here we go. And it's talking about this whole army of these anonymous hackers.

[00:30:35] Now none of us have been a nightmare for many businesses that they didn't like. I had an anonymous we'll go ahead and they'll do usually pretty basic stuff. They'll do denial of service attacks and some other things, so they don't like you because of. The don't say gay bill in Florida, and, without bothering to do any research, they'll just start attacking organizations that support it, or organizations that don't support it depending on how they want to do it. So this is an interesting article here, because it's talking about these various. Websites that they've hacked. Now, some of them are government site and some of them are private industries. Now, one of the cool things, bad things about hacking private industry and releasing the emails is now the competitors to these businesses know what they're doing.

[00:31:31] And in some cases there's proprietary technology that's being released. Now, when it comes to Russian proprietary technology. The Western world doesn't care a whole lot about some of it, but here's some examples of what these hacktivists of GoDaddy. This is a company called forest 37,000 emails stolen from the company, Russian logging and wood manufacturing firm.

[00:31:55] Again, it would give a little bit of an idea into the whole Russian, what are they doing? In the forest industry. This one, I think is a little more concerning for the Russians Aero gap. This is an engineering company that focuses in the oil and gas industry. Their clients include a whole bunch of Russian companies.

[00:32:15] They've leaked approximately 100,000 emails from Aero gas. That is a huge deal because so much of the country's revenue, the number one industry in Russia is oil and gas. Petro Fort one of the largest office space and business centers in St. Petersburg, the hackers have leaked approximately 300,000 emails from Petro fork.

[00:32:41] Again, you can use that to find out what's happening in your economy. What. Doing how are businesses doing? Are they going to go under so you can see some tweets here. I've got them up on my screen on YouTube and rumble anonymous. What they're saying that they've done and you can follow anonymous directly on Twitter.

[00:32:59] Particularly fond of them. They've done a lot of things that I disagree with. This is really telling us about a whole new approach to warfare, right back in the day, you and I couldn't get involved, we could potentially take up arms and go and fight right there and think about the Spanish American war.

[00:33:18] Think about what's happening now in Ukraine, where Americans have just gone over there. Taken up firearms in order to help them defend Ukraine. People who are maybe of Ukrainian descent, maybe not right. We have never seen this type of involvement by average citizens because anonymous is not like some big fancy company or government agency anonymous is a bunch of people who are trying to be anonymous and do something.

[00:33:50] So they stole 145 gigabytes. Look at this. It's just crazy. So he. The anonymous Twitter thread itself, right? Talking about what. It's absolutely incredible. Incredible. So that's what anonymous is up to. They are hacking Russia and they're hacking Russia in a big way. Now, next stop. We have our friends at Microsoft.

[00:34:15] Microsoft has been seizing Russian domains that they are accusing of having been linked to these Russian hackers that have been going after think tanks and government agencies in the U S and the. He knew, I shouldn't say which I'm sure includes the UK cause UK has gotten involved. So this article from the verge is talking about how Microsoft has seized seven domains, belonging to fancy bear apt 28 which is we've seen them active in a number of companies here, right in the Northeast United States.

[00:34:57] These companies who are. Trying to provide materials, software, hardware for government contracts, right? So they're not even direct government contractors for the feds. They are just a sub contractors. And then we've seen fancy bear in there. We've seen the Chinese in these companies. It's incredible.

[00:35:19] They have no. DIA that all of their intellectual property is being stolen, which is why the federal government has started cracking down on contractors and subcontractors and the, this whole paragraph 70 12 thing. We're getting geeky here, but companies that have to protect even unclassified information, confidential, classified, and they haven't been so Microsoft.

[00:35:46] Obtained a court order. You can see this on my screen, over at YouTube and at rumble to take control of each domain on April six, that then started redirecting them to a sinkhole. So what they do is they take control of the DNS for the domain. So the root name servers, now, point to a Microsoft name server, and then send them to a sinkhole.

[00:36:09] A sinkhole is basically nowhere you go there. There's nothing on the site, right? Or in this case also servers used by cybersecurity experts to capture and analyze malicious connections. And they'll do this. Oftentimes, when we're talking about these botnets, like we talked about a little earlier today, so apparently they're trying to establish long-term access to the system.

[00:36:33] So the targets, what did we just talk about? Long-term acts. But net, right? That's what button that saw. So Microsoft has gotten involved. They've been doing this now for a little while. It's obviously not their normal business model, but it is something that they've been doing. They were also, by the way, the fancy bear link to these cyber attacks on the DNC in 2016.

[00:36:57] And they also targeted the UFC election in 2020, which is why, part of the reason why anyways, don't use electronic equipment for our elections, have paper ballot, have people count those ballots yet it takes longer. You can't have the instant thing on TV, which is why all of these new services, they all don't do that.

[00:37:18] That's ridiculous. But it's the only thing we can guarantee that these guys, like I got it up on the screen again. Fancy bear the Chinese et cetera. It's the only way they can get in. And if we were doing paper ballots and we had bipartisan people counting the ballots and independence, counting the ballots, observing this, we wouldn't have all of these problems that we had with the last election where people were saying it was stolen.

[00:37:48] It was hacked. How do we know it was stolen? How do we know it? Wasn't stolen? How, go back to paper ballots, get rid of the scanning machines and particularly get rid of these electronic voting machines where you touch the screen to cast your vote. Those things are ridiculous. What if there's a software bug in it?

[00:38:06] How can you go back and change the vote? People that complained about it again, and wait a minute. I voted for this guy and you had to record my vote for the other guy. It's ridiculous. Anyways. Back to QR codes. Okay. I'm going to pull this up on this screen because I think this is a cool article here.

[00:38:25] This is from a, actually a site over in India. It's called scroll.in, and they're talking in here about how hazardous it can be. To use QR codes. Now they're not saying don't use QR codes, we've all had to use them. I've got up on my screen, this picture of being at a table. And you scan the QR code in order to get the menu.

[00:38:48] In order to order, I did that. I was in Vermont and we were riding motorcycles or buddy, and I go into the little tiny. Restaurant, small restaurant and I had a half a dozen tables and they didn't have menus. You scanned it, the QR code that was there on the table and you placed your order. And off it goes a lot of places they've been doing that with menus.

[00:39:11] You've seen that more and more saves them money as well and lets them change their prices more frequently. Yeah. Thanks for that inflation guys. Why shouldn't you use these QR codes? Why should you be extra careful? Here's the answer. QR codes are the URL of a webpage. That's the bottom line. Would you click a random URL that came in an email?

[00:39:37] Would you click on a random URL in an ad or on a web page? We certainly know better than to cook URLs in our email. But that's exactly what the QR code is. And on top of it, the URL in a QR code tends to be what we call a shortened URL. So it might be Bitly, so might be bit.ally/and then some random characters.

[00:40:04] How do you know where it's going to take? You don't all you know, is it's going to take you to Bitly, but that Bitly URL could be sending you to a malicious site. And now your phone could be hacked. It could be using your phone for Bitcoin mining for who knows what. So be very careful and the bad guys are using these in a different way that you might not have seen before, which is they are embedding QR code graphics.

[00:40:34] Into emails. And they're thinking that people are going to hold up their phone to the email and what are they going to do? They're going to scan the QR code that was in their email. And now they're in trouble. Yeah, that's simple. Hey, visit me online. Craig peterson.com. Make sure you sign up for my newsletter.

[00:40:53] Craig peterson.com/subscribe course, Craig Peterson, S O n.com. And I'm going to send you. Top three special reports, absolutely free. We got to take care of these bad guys.

[00:41:08] This is a big deal, quite literally a big deal. Russian malware. We have been able to track it down now, track it down to a single site. Yeah. All of these bad guys are in one building in Moscow.

[00:41:25] Hi everybody. Of course, you're listening to Craig Peterson. Thanks for taking a little bit out of your day today. As we continue to really talk about the stuff that's most important in the world, and there could be nothing more important, I think, than some of our cyber security, our lives, our fortunes, et cetera.

[00:41:44] Last year we have to pay attention to well, This is a very big story and it's a bit of a scary one as well. We've had a lot of ransomware over the years and a lot of ransomware. Have you had it yourself? I bet you, if you haven't, someone who has had ransomware because frankly it is pervasive in every aspect of pretty much everybody's life out there.

[00:42:12] So when you get hit with ransomware, Lately something a little different has happened. It's really gone through three phases. The first phase was the ransomware would get on to your system. Usually it came as an attachment, probably embedded in like a word file it's been embedded in PDFs, embedded in all kinds of stuff.

[00:42:35] Even drive by downloads on websites, have brought malware. But in this case yeah, it was annoying. It was a problem. It would give you a red screen. You've probably seen it before warning about the ransomware and it told you, okay, here's what you can do to get your files back. And in order to get your files back, you usually.

[00:42:57] To go to some exchange online, take dollars, buy of course, Bitcoin, or some other cryptocurrency. And then that cryptocurrency would be used in exchange now for you to get a key that would hopefully decrypt everything. And in reality, it often didn't encrypt hardly anything. So it's been a problem and a problem for a lot of people.

[00:43:23] The FBI said that at the time. So this is a gen one of ransomware. You were lucky if 50% of the time you got all your data back, gen two of ransomware is when the bad guys started getting a little bit smarter. They didn't just take your files. Thumb and then say, Hey, pay up buddy. What they did at this point is that got onto your systems and they poked around.

[00:43:46] They went we call in the industry, east west on the network. So they got onto you, maybe your kid's computer may, maybe you were hooked up via VPN to the office to do work. And it wasn't a great VPN. And the kid's computer had that virus and that virus weaseled his way all the way over the VPN, directly to the office, because remember.

[00:44:09] VPNs are. A network private in that. Yeah. Okay. It's encrypted. And so someone who's got a wire tap isn't necessarily going to get anything, but it's a VPN, it's a tunnel. And that tunnel was used a many times for malware, like brand summer to creep over to the office network. That's an east west is going from.

[00:44:30] One machine to another machine. And in businesses, man, you saw that one a lot as that ransomware moved around. So that was the second one. So the rents were going on the machine. It would then look for files that is. You might not want to have exposed. So it looked for files with bank account numbers in them, social security numbers, maybe intellectual property.

[00:44:57] We saw a lot of that. Theft is continuing to go on primarily from the Chinese and then an intellectual property theft. And what happened next? While of course it ended up moving the data, the files, and then what they would do. It's encrypt your desk. So before they gripped your desk, they got copies of all of the stuff they thought might be important to you.

[00:45:20] So now the threat was in version two of ransomware pay up, or if you don't pay up, you are going to have to pay us to not release your files. If you didn't want all of that client information online, if by law, you would get nailed for having that client information out online. And that's true in most states now, and the federal government's from putting some teeth on some of their laws as well, then what are you going to do?

[00:45:49] Yeah, you paid the. So that was version two version three that we're seeing right now of ransomware is simply destructive. And if you go way back in history, you may remember I got hit with the Morris worm, which was one of the first pieces of nastiness out on the internet. And that was early nineties.

[00:46:13] My business that I owned and was running, got hit with this thing. Even before that, There was ran. There was a nasty where viruses, if you will, that would get on the computer and destroy everything. It was just a malicious, as I remember, somebody at UC Berkeley, some researcher in it. And he didn't like what that of the researchers were saying about him.

[00:46:35] So he put some floppy disk together and on them, he put. Erasing malware and shared all of the stats with anybody. And of course, you plugged that disc into your, that little floppy disc into your windows computer. And it says, okay, I'm going to go ahead and open it up. And, oh, look at this, a virus.

[00:46:56] And so he then wiped out the computer of everybody else. That was a competitor of his out there in the industry. Yeah, a little bit of a problem if he asked me, so how did that end up getting around? What ended up happening while everybody got really upset with him, nobody really found out what was happening, who did it, et cetera.

[00:47:19] That's what's happened. Now, so version three of malware is like some of the very first malware we ever saw version three of ransomware. So some, again, some of that very first ransomware was pretty nasty is not the sort of stuff you want to see running destroying files, but at least you could get back from a.

[00:47:40] Nowadays, a lot of people are doing backups by attaching a disc directly to their machine, or they're backing up to another machine on the same network. Remember that whole east west thing, you didn't want the data going back and forth, it causes problems. Yeah. So what happens now? The Russians apparently are just trying to cause havoc with businesses, anybody who has decided that they're going to be anti-Russian in any way there they're attacking.

[00:48:13] So they'll, reraise your desks. They'll erase all of your data. If you have backups on that thumb drive or that USB external. The good news erase that if you have backups on another machine, on the network, hopefully from their standpoint, there'll be able to get onto that machine and erase all of your backups, which is again, why we'd like 3, 2, 1 backups.

[00:48:34] At the very least, there's some others that are even better. And if you're interested, send me an email me@craigpeterson.com. I'll send you a webinar that I did on this. I'm not charging you for. But it was a free webinar to begin with what a webinar on backup and how to backup properly and why to do it this way.

[00:48:54] Again, me, M E Craig peterson.com. Be glad to do that. What we're seeing now is a huge problem. Let me see if this is going to work for us. Yeah. Okay. It is. I am, by the way, live here we go on my computer. So people who are watching. I can see my desktop. So here we go. This is Russian companies who are linked to this Russian malware.

[00:49:24] Ransomware are hiding in plain sight is what they're calling it. So what does it mean. To hide in plain sight. While in this case, what it means is money that's been paid by American businesses to these Russian ransomware gangs, some of who by the way, are actively going after anyone that criticizes Russia found these American researchers.

[00:49:50] Yeah. Led to one of Moscow's most prestigious addresses. You can see it up here on my screen. This is a New York times article. It's just a random actor, journalism people, sometimes even the New York times gets it. And they're saying millions of dollars have gone through this. So they've been tracing.

[00:50:10] Where did they go? The Biden administration has also apparently zeroed in on the building is called Federation tower east. It's the tallest skyscraper in the Russian Capitol. How would that be to have a business and just this beautiful tall skyscraper and have a view that would be really cool. So they have targeted some companies in the tower.

[00:50:32] As what it's trying to do is stop the ransomware guy gang. Maiden cryptocurrencies. Russian law enforcement usually has an answer to why don't you just shut down these bad guys that are out there trying to steal all of our money. They say there is no case open in Russian jurisdiction. There are no victims.

[00:50:51] How do you expect us to prosecute these honorable people? That apparently is a quote from this Massachusetts based secure cybersecurity. Called recorded future, but I'm looking at a picture it's up on my screen right now. You guys can see it, but this is the Moscow financial district called Moscow city.

[00:51:10] 97 floor Federation tower east. This is really pretty, you wouldn't know this isn't like London or any other major European capital. There's some cranes in the background building up new buildings. The cyber crime is really fueling some growth there in Moscow, which is, if you ask me the exact reason why lad is happy as a clam to just go ahead and have these Russian cyber crime guys.

[00:51:43] Just go and bring money in right. Money is bringing in great money for them. The treasury department, by the way, it's estimated the Americans have paid $1.6 billion in ransom since 2011. Huge one ransomware strain called RIAA committed an estimated $162 million. Last year. It is really something.

[00:52:07] So when we come back, we've got a lot more to talk about. We're going to talk about the cloud. If it's more secure or why is it calm, broken, give masks work. Why aren't they working right. Anyways, we'll talk about that. When we get back and visit me online, Craig Peter sohn.com.

[00:52:26] Stick around.

[00:52:29] I hate to say it, but there's another big scam out there right now. And it is hitting many of us, particularly the elderly quite hard. We're going to talk about that right now, what you can do about it and how you can recognize when it's happening.

[00:52:45] Interesting article that came out this week in wired.

[00:52:49] It's actually in Wired's. Let's see, what is a March 2022 issue. It wasn't this week. Nevermind. And it's talking about a serious problem. I'm going to show you guys who are watching I have this on rumble, YouTube, Facebook as well. So you guys can see along and of course, right here, too.

[00:53:11] Now let's not forget about that, but this is an article that says we were calling or excuse me, they were calling for help. Then they stole. Thousands of dollars. I'm going to read parts of this article. It's just amazing. It's by Becca, Andrew's a back channel. What is that? Okay, so that's just a cat.

[00:53:33] On December more one December morning, my mother's phone rang. She tugged the iPhone from the holster. She kept clipped to the waist, her blue jeans and wondered who might be calling perhaps somebody from the church who was checking in on her recovery from Corona virus. Hello. She said the voice that greeted her was masculine.

[00:53:53] This is just great writing. The color sounded concerned and he told her something was. With her Amazon account, somebody has access to your bank accounts through Amazon and they can take all your money. I'm calling to it. Her mind raced or Lord, she prayed silently. The voice was warm and reassuring them.

[00:54:15] My mom tried to focus closely on his words. My dad was driving to work in his truck and she was home alone. She'd been cooped up in the house for weeks with COVID isolated from her community and she missed the bomb. Friendly voice. I D I just love her language here. It's just phenomenal. She tried to steady herself.

[00:54:36] The man said he needed to make sure the money was safe. He transferred her to a different male voice. Soothing reassuring, calm. She promised not to hang up a brain injury decades earlier, made it hard for her to follow his instructions, but she stuck with it. The voice explained slowly, carefully, how to swipe and tap her phone until she had installed an app that allowed him to see what was happening on her screen.

[00:55:07] Now. You followed her every move. After some hour, she mentioned she had to relieve herself hours. It's okay. I'll stay on the line. He said she parked the phone, outside the bathroom and picked it back up. When she was done as Nooner approached, she told him I have to eat. I'll wait. It's okay. Don't hang up.

[00:55:28] We'll lose all our progress. She set the phone down on the counter to make a sandwich, then pulled some chips from the cabinet and padded over to the kitchen. The phone buzz with the text. It was my father checking in. She typed back that there was a problem, but she was fixing it. She had it all taken care of.

[00:55:48] She tapped the tiny white arrow next to the message field to send her reply. And then she heard the voice, its volume elevated as sounded angry. She frowned and brought the phone back up to her ear. Why would you do that? You can't tell anyone what if he's in. She felt confused that didn't make any sense, but she also didn't fully trust herself.

[00:56:10] She was worn. From her slow recovery and the steroid, she was taken as a treatment, gave her a hollow buzz of energy. Now I want you guys to go have a look at this over on wired site. Read the whole article. It is a phenomenal. Absolutely phenomenal. But what it's doing is telling the story of this woman who was trying to, do the right thing, trusting other people, which many of us do?

[00:56:40] I have a default trust with a little trepidation. I will admit that, but with the whole. Down the thing that happened, many of us have just been longing for a little bit of companionship and to hear a stranger who's trying to help out. That's a huge plus it goes on in this article and talks about how reassuring these guys were and what they did.

[00:57:06] She installed this cash app and opened up PayPal downloaded. Coinbase set up Zelle so she could send money directly from her bank account. She doesn't know about any of these things. It's just incredible. So the afternoon wore on and the guy said Hey, we're almost done. And her husband of course, was on his way back.

[00:57:30] And the sun was down. Father got home. He noticed right away that something was off. And she said she took care of it. And you said you took care of what I'm not supposed to tell you. It said, so the scammer had siphoned away. All of her personal information, the scammers had your social security number, date of birth driver's license number, and about $11,000.

[00:57:55] These new financial apps like Zelle and others that are legitimate PayPal apps, right? Zell, you can use to send money legitimately to someone else. But it links into your bank account. That's why I don't like them. I have a friend that's been pushing me. Oh, this happens. Great. It saves you so much money on gas.

[00:58:15] Look at how much money I've saved any. He sent a screenshot of it and I re I went online and had a look. And guess what? I read, reviews it again, like this tied into her bank account directly. And. What can happen? Like here, everything was emptied. So in the next few months this author of the story and her father tried to undo the damage.

[00:58:40] Very frustrating, getting scanned of course, is really dehumanizing and it just breaks your trust and other people. How could someone do something like that? It's just incredible. Got to go through the stages of grief and everything. She got a, she talked to people, she said she got chili half replies, or just as often silence.

[00:59:05] And she was calling around trying to find someone for some empathy. Okay. It's just incredible. Great article. If you can still find it, the March issue of wired, I'm sure it's available online. This goes on. And talks about her mother's seizures getting worse. And of course now they don't have the cash that they had been saving.

[00:59:27] And it just very depressing. Now I have this, you might remember about a year ago, I talked about it. I had something like this happen to a friend of mine and I'm still not quite sure what happened, but it looks like it was a password sprain or password stuffing. And they got into his, the app that his company uses to pay people and sure enough, they got in and they directed his next two paychecks to their own account, which went right out of the country like that.

[01:00:05] These are bad people. And how do you deal with this? It's incredible because if you've got someone like her mother who has mental problems due to no fault of her own and is a very trusting woman, what do you do? She's walking around all day with her phone on her hip. That's how we started this out.

[01:00:27] Do you take that phone away from him? Th that would be dangerous, frankly. So this is a very problem. They had a USAA account was her bank account. USAA is usually good about this sort of stuff. In fact, my other friend had USAA as well. But they did help deactivate Zelle, but they didn't do anything about the $999 that were transferred through it.

[01:00:51] Very bad. So they figured out maybe we should change our passwords. She had them change them. And if you would like information about password managers, again, I'm not selling anything. I'd be glad to send them to you. If you sign up for my email list, you're going to get them automatically. Craig peterson.com.

[01:01:11] I've got a bunch of data information I want in your hands. It talks about the free stuff, talks about the paid stuff. None of which I'm selling you. Craig Peter sohn.com. Sign up right there on the top of the page. Thanks. Stick around.

[01:01:32] We've had some serious supply chain attacks over the last couple of years. And they have caused all kinds of problems for tens of thousands of businesses. If you use WordPress, there was one of those this week.

[01:01:47] We have had supply chain problems. Like you wouldn't believe. So let's start out by explaining what is a supply chain problem?

[01:01:58] In this case, we're narrowing it down to cybersecurity because we've had supply chain problems from everything from our toilet paper to the food we eat. But what I'm talking about right now is. Supply chains when it comes to cyber security. And one of the biggest problems we had was a company that's supposedly providing cyber security for businesses, right?

[01:02:29] Some of the biggest businesses in the world. And I'm looking at an article right now from security Boulevard, say saying how to protect the supply chain from vulnerable third party code. It can be a script that's downloaded online. It can be an open source library. We've seen big problems with get hub lately and pulling in libraries.

[01:02:51] We've seen big problems with what are called containers lately, which are little mini versions of computers with all of the software. They're all ready to go. Ready and raring to go. All kinds of supply chain issues for a very long time now. And these supply chain, cyber attacks have been hitting some of our cybersecurity companies, really the hardest I'm pulling this up on my screen right now, if you're watching this on rumble or on YouTube, and you can see links to those, by the way, in my emails, I send out every week.

[01:03:28] Craig peterson.com. Craig peterson.com. But you can see here, supply chain hits cybersecurity hard supply chain security is not a problem. It's a predicament. That's uninteresting look because we have to use some of the supply chain stuff. Seesaw the FBI or a sheer wean cybersecurity advisories because of the Russian attack over on Ukraine.

[01:03:55] And then the U S the weakest link in supply chain security fears of rising fuel SISA FBI NSA and gestural partners. Issue is advisories Toyota stops production after possible cyber attack at a supplier. Isn't that something this goes on and on. What's a guy to do, right? Many of us are using websites to, in order to run our businesses.

[01:04:24] Heck we got websites for our soccer team, for the kids, we got websites for pretty much everything that's out there today and those websites need software in order to run. So the basic idea of the website is nowadays. Content management system, they called CMS CMSs and there have been a lot over the years.

[01:04:46] I've used quite a few myself off and on. This is very interesting though, because this particular piece of. Is code that runs a website. I'm going to show you this article from ARS Technica here on the screen, but it's talking about millions of WordPress sites that got a forced update to patch critical plugin flaws.

[01:05:13] So when we're talking about supply chain, in this case, we're talking about something. WordPress right. And this WordPress software as good as it is, can have bugs. So WordPress is the content management system. So you load stuff up into, in fact, I'll bring up my site right now. So I'm going to bring up the Craig peterson.com.

[01:05:37] And on my site, I have all kinds of stuff, which is why it's so slow to load. I've got to fix that one of these days, but this is an example of a WordPress site. So you can see right at the top of the site, I've got watch this week, show jobs, or top, of course, that was last week. You can watch it on rumble or a new tube, and then it's got my latest show.

[01:05:59] So if you click on one of these, here you go. And you can listen to it. Starts right out here. C ta-da. So there, you can listen to my podcast right there on the site, and I've got an automated transcript of it. It's for you, depending on what you want. It's got links over here to take you to iTunes or YouTube or Spotify or SoundCloud or iHeart or Google player audible.

[01:06:26] All of these links take you to different places. And this site in survey, Program a site in HTML. What we're doing is we're working. Putting some data in, so we say, okay, I want a default page. Somebody else has already set it up. Somebody else has already got an old program. It just works. And it's all right there for me.

[01:06:49] Here's some related posts on the side. Here's the most popular ones that we have right now. This is a content management system. And specifically this of course is WordPress. So what happened. If I had a, yeah. And here's what it looks like over an audible, you can listen for free on. This is what happened this last week, WordPress, which has this great software that I use and tens of thousands of others use out there very popular.

[01:07:27] And in order to make it easy for me to have my website, probably your business, probably your kids' soccer club, you name it is using WordPress. It's just over the top hop healer. It is using code that was written by other people. The reason we can make programs so quickly nowadays is we're relying on other programs.

[01:07:51] So we'll go ahead and we'll grab this program that does this part of what we need to have done, and ta-da we're up and we're running. I just have to write the glue right? To put it together. The API calls, whatever it might be, because the idea is let's make it easier for programmers. So you've got something called get hub here.

[01:08:11] Let me pull it up so you can see that you can go online if you're following along. To get hub.com. And as it says right there on their front page where the world builds software as a beautiful world, isn't it? That blue, you can see the air around it. And that's what it's doing is where the world builds software.

[01:08:33] So let's say we want something. What do we want? What's a, let's say we want something to make a chess program. We can talk about chess and let's say, oh, you have to. I Dan didn't want to do this, so I'm just going to skip that for now. But it would come up and tell me, okay here's all of the chess programs that are out there and I find one, that's close to what I want to do.

[01:08:54] So what do I do? Point while I go ahead and have a look at the license, a lot of the programs up there have a very open license, so I can just take that code, modify it. And I have a chess program without having to write a chess. It's really that simple that's part of the supply chain. If you bought my chest program, you would actually not just be getting the code that I wrote, which is typically just glue code with maybe some API APIs or application programming interfaces.

[01:09:25] In other words, you're using someone else's code would now make it who's program. It's like the Pharaoh's barge. It would make it other people's programs. Not my. So you got to figure out what's in my supply chain. I've got a new client. I do work as a virtual chief information security officer.

[01:09:46] Actually, it's a fractional Cecil. And as a fractional Cecil, one of the things I have to do is look at the whole supply chain. Who are they buying even physical things from. And could there be. Did it into their software, into their systems, something that might be coming from yet another supplier. Man, does this get complicated?

[01:10:09] Very fast, but this week, our friends at WordPress, they went ahead and forced all WordPress sites to update. Very good. Okay. Otherwise, people could have downloaded a full backup of the sites that are out there, something you really just don't want to happen. Anyways. Go right now, Craig Peter sohn.com while the bits are still hot and sign up right there.

[01:10:36] Craig peterson.com for the newsletter and get those special reports that are going to get you started.

[01:10:43] This is the moment you've been waiting for. We're going to talk about free cybersecurity services and tools that you can use. Now you have to be a little bit of a cybersecurity expert to use them, but not much. This is from the government.

[01:10:59] This is I think an amazing thing. This only came out within the last few weeks.

[01:11:07] I have it up on my screen. There we go right now, for those of you who are watching on rumble or YouTube, you can see it right there, free cybersecurity services and tools from. The cybersecurity and infrastructure security agency SISA reminds me of Marvel was shield, that really long name that came up with an acronym for as though they weren't aiming for that acronym in the first place, but there are some tools that you can use there's tools that I use as a cybersecurity professional.

[01:11:42] And some of them are obviously going to be pretty darn. Complex. And if you're looking at my screen right now, or if you want to go online at csun.gov/free-cybersecurity-services, dash, and the as tools, or just look it up online, you'll find this on my website as well. I'm going to try and make sure I get that up.

[01:12:07] But what they have done is they're showing you what they call their key or the known exploited vulnerabilities. Okay. And this is where they are showing the CVEs, which are. The frankly, these are the ones that I use. It is published by nest, which is the national institutes of standard and Sanders and technology.

[01:12:31] And this gives all of the details. So this is CVE 20 21, 27. Okay, and this is detail, and of course I would be using detail. And it's telling you, here's the advisories, there's one from get hub Excel. Leon has one. Here's the weaknesses, the SA the known soccer configurations. So you can find where they all are at and everything.

[01:12:56] So all of the details. So they're telling you about that. These are the ones, this was in the vendor product. Project, I should say. So we'll look at the data added to catalog. Here are a few in Cisco right now. So this is their small business series of routers, which we do not use for anyone because they don't provide the type of security you want, but Cisco is taking care of the problems, right?

[01:13:23] Many of these update themselves, here's Microsoft windows. And installer contains an unexpected unspecified vulnerability, which allows for privilege escalation, a lot of stuff this week, this is crazy Apache Tomcat, which I am never been a fan of and problems. So all of these came out. On March 3rd and more rights.

[01:13:47] This is just page one. So let's look at page two here. Oh wow. More Microsoft Excel exchange server, some more Cisco vulnerabilities. Why Cisco? Why Microsoft? Because they are frankly. The big boys on the block, that why do you Rob the bank? Because that's where the money is. So they list all of those right here, as he said, does the warning you do use multifactor authentication?

[01:14:16] I don't want to sound like a broken record, so I'm not going to say use multifactor authentication today. Okay. I just refuse to say use multi-factor authentication. And this one talks about what it is, right? Many names. Now they're trying to make this. But really a Fido key fast at any online considered the gold standard or multi-factor authentication Walt for online.

[01:14:40] It is websites, but not for authors. So how would you know that if you weren't an expert? So yeah, this is the government talking, right? So they have the service. So what does, what do I do right? Me, Mr. Idiot. I click on this and they are talking about the service that they've got them showing it up on the screen.

[01:15:02] It's called SISA insight. And they're talking about website, defacement, destructive malware, or not Petya want to cry, right? All these things. What can you do to prevent it? And. They make it sound easy. Now I want to say something here because I, I have a couple of mastermind groups and in one of my groups, I rescued a group member from a 40 something thousand dollar loss.

[01:15:31] And so I was explaining it in our next mastermind meeting. Cause everyone wanted to know. What should I do? How should I do it? And they all tuned out and I thought I was trying to, I was being simple enough. I was trying to be simple, not like simple Kamala Harris explaining that Ukraine is a country beside right next to another country called Russia.

[01:15:55] And that's why there's an invasion. Okay. I couldn't believe that. Did you guys hear that? It was just incredible, but I didn't get that simple. And I know you guys are the best and brightest, and you're trying to figure this, all this stuff all out, and that's why you need to make sure you sign up for my email list right now, because I do have simple step-by-step stuff.

[01:16:17] And these tools that they're talking about and services are supposedly available. Now, I went to a bunch of these. And I tried to get some services. So they said they'll do a free scan over the network. So I filled it all out and according to their standards, my company, because I do cybersecurity for everything from government contractors, through dentists and manufacturers and distribution companies.

[01:16:50] So I, I. The critical infrastructure definition. And I have never heard back from them. I check my spam box at least once a week looking for their reply. So I don't hold up a whole lot of hope, but there is some good information here that you can get email via social media via just all of these different types of things that.

[01:17:15] You could use for it. And again, I want you to look for it online. It's on csun.gov. If you go to their homepage, you'll see their tools, they've got a shields up a warning right now on their homepage because there have been so many attacks coming from China and coming from Russia, but particularly Russia.

[01:17:34] And you can see there. Stop ransomware.gov, which has some great tips, particularly for home users and small businesses. The Seesaw culture, height, hygiene services. That they have doing business with CSUN and careers they're looking forward to is okay. It's part of Homeland security. So there's a whole lot that you can do and you can find, but I wanted to let you guys know that this is out there.

[01:18:04] A lot of the stuff guaranteed is going to be. Above 98% of people's heads out there. Just in general, even it professionals. So look for information, that's going to help you. That's on your level. And to that end we have right now, three things. If you sign up for the email list, or if you're already on my email list, you can just email.

[01:18:30] Me@craigpeterson.com or just hit reply to any of my emails and I'll see it and ask for them. But we've got stuff on your computer, keeping it secure, keeping your password secure comparison between using a one password manager or using last pass, which I am not advising to use right now, but that's in there.

[01:18:54] There are a lot of different things that are there that are ready for you to get right away. And then if you have other questions, I've got dozens of little special reports that I've written in response to people's questions. Don't be afraid to send them to me. I'd you know me@craigpeterson.com and I'll make sure I get you an answer because it's that important.

[01:19:20] Okay. I'm not here trying to sell you something. I am here because most of you guys can could never get my services. You don't need them. You can't afford them, whatever. I'm a fractional Cecil. I'm one of the guys that keep. It was a cyber security working in a live for businesses. Like it's not going to be everybody, but it's, it is there is, I should say a lot of information you guys need and need to understand, and I want to help you. Okay. I think I've beaten that horse enough and it was probably past dead, but you'll find some of this stuff on my website@craigpeterson.com.

[01:19:58] I've been working on some other changes to it. I would also ask you guys. If you're hearing part of the show today, I know a lot of people who are listening on the radio are tend to be out and about in their cars, listening, on the weekend, I listened to a lot of radio then, but go ahead and subscribe to either my podcast.

[01:20:19] And there are a lot of ways to do that. And I showed those people who are watching on video, how to do that. And if you would give me a five star. On whatever platform you're using, hopefully I've earned that. And then also if you'd like video, I have my whole show up. It's like about an hour and a half long on multiple platforms.

[01:20:44] So rumble.com rumble, R U M B L E. Is a competitor to YouTube. So if you don't like censorship, if you want a site that is trying to keep that information out there, get it out there for you. A rumble is your place. You'll find all kinds of interesting characters there other than myself, right? A lot of conservative people go there to rumble.com.

[01:21:09] I have it up on YouTube. Because YouTube, isn't the worst platform in the world. They're also not the best, but they are the biggest. Did you know, YouTube is the second largest search engine in the world. Okay. They have a lot of people on YouTube and then on Facebook as well. You'll find me there on Facebook.

[01:21:28] Of course, Craig Peterson, I had. I excuse me at facebook.com/craig Peterson. And I didn't use it for a long time cause I hated Facebook. Just, I looked at it as a time sink that I just didn't need. I got a lot of stuff. I got a lot of people help and so I didn't really do anything with it. And so somebody else got the slash Craig Peterson, but I do have a trick for you.

[01:21:52] If you go online with your web browser to Craig peterson.com. That's my website slash. YouTube. It'll take you right to my YouTube page. Ores Craig peterson.com/facebook. Yes. What do your Facebook page? Craig peterson.com/itunes. Good slash sound cloud, et cetera. It'll take you right to my page on all of those sites and have a look at the video.

[01:22:21] Let me know what you think. I would appreciate that feedback and make sure you tune in on the radio too. It's great. Don't watch this while you're driving to taking the kids to school, a lot of people listen to this while they're taking the kids to school on podcast. Anyways, take care. Thanks for being with us.

View Details

Are You Ready For Data Wiping Attacks?

Yet another warning coming out from the federal government about cyber security. And this one is based on what's been happening in Ukraine. So we're going to talk about that situation, the whole cyber security over there and why it's coming here.

[Automated transcript follows]

CISA is the cybersecurity and infrastructure security agency. How's that for a name it's not as bad as what does that shield right over from the Marvel universe, but the cybersecurity and infrastructure security agency is the agency that was created to not just protect federal government systems, although they are providing information for.

[00:00:41] People who protect those systems, but also for businesses and you and me and our homes. So they keep an eye on what's happening, what the various companies out there are finding, because most of the cybersecurity information that we get is from private companies and they. But it altogether, put it in a nice little wrapping paper.

[00:01:05] In fact, you can go onto their website anytime that you'd like to, and find all kinds of stuff that is going to help you out. They've got a ton of documents that you can download for free little steps that you can take. It's at csun.gov, C I S a.gov. And they've got the known exploited vulnerabilities catalog.

[00:01:30] That's something that we keep up to date on to help make sure our clients are staying ahead of the game. They've also got their review board securing public gatherings. They also run the stop ransomware.gov site that you might want to check out. And we'll be talking a little bit more about ransomware and the ways to protect yourself a little later today.

[00:01:52] Now Seesaw is interesting too, because when they are releasing information, most Americans really aren't aware that they even exist. They do. And they've got a big warning for us this week. There's a site that I follow called bleeping computer that you might want to keep an eye on and they have.

[00:02:15] I'll report just out this week that you, crane government agencies and corporate entities were being attacked. This was a coordinated cyber attack last Friday, a week ago, where websites were defaced data wiping malware was deployed and causing all of these systems to become not just a corrupt, but some of these windows devices to be completely.

[00:02:45] Operable now that is a bad thing. The reason for this, this is speculation, but it isn't a whole lot of speculation. Right? Am I getting out of, on a limb here particularly, but the whole idea behind this is a cyber war, that Russia's got, what is it now? 130,000 troops, whatever it is over a hundred thousand.

[00:03:08] On the border of Ukraine, they invaded Ukraine a few years ago. Russians shot down a passenger airline in Ukrainian air space. This that was a few years back. They've been doing all kinds of nastiness to those poor Ukrainians. They also had a massive ransomware attack in Ukraine. That was aimed at their tax software.

[00:03:35] Some countries do the electronic filing thing a lot differently than the us does. A couple of examples are Ukraine. France is another one that comes to mind. We have clients in France that we've had to help with cyber safety. And we're always getting popups about major security problems in the tax software, because they have to use this software that's provided by the French government.

[00:04:03] Ukraine's kind of the same way. The biggest. Company providing and the tax filing software for Ukraine was hacked and they use that hack to then get into the tech software and make it so that when that software was run by these Ukrainian companies, they would get ransomware. It was really rather nasty.

[00:04:30] So the Russians had been playing games over in Ukraine for quite a while. But what's apparently happened now, is that a thing? Those things, same things are coming our way now. It's not just because of the fact that a Ukraine is being threatened, maybe they're going to encroach even more, take more than Crimea, which they did last time.

[00:04:56] We're in the U S and what are we doing? President? Biden's been sending troops to Europe, troops to Poland, Germany, and also advisors to the Ukraine. He's removed the embassy staff, at least the vast majority of it from Ukraine. And I just I think. To what happened with his completely unplanned withdrawal that we did in Afghanistan and how things just got really bad there.

[00:05:28] And I'm not worried about what's going to happen in Ukraine because the Russians aren't particularly fond of the idea that we are sending aid and support to. Yeah, it's a bad thing. President Obama sent them blankets, but Biden is sending them military weapons and ordinance, which is what they'd need to fight.

[00:05:53] So Russia has shown that they will attack a country via electronic means cyber means, right? Cyber attacks. And so what's happening now is the bad guys from. That have been the facing websites and who have been doing more than that, wiping computers and making them completely unusable could well come after us because they're really going to be upset with what's happening now.

[00:06:27] And that was CNN has reported the Ukrainian it services company that helped develop many of these sites was also a big. And of course that means bottom line, that this is what's called a supply chain attack. What I mentioned earlier with the Ukrainian tax software, that's a supply chain attack where you are buying that software, or you're mandated to use the software to file your taxes by the government.

[00:06:57] And what happens while it turns out that software is contaminated, that's called a supply chain attack. Now crane issued a press release about a week ago, saying that the entities were hit by both attacks, leading them to believe that they were coordinated. This is a quote here. Thus, it can be argued with high probability that the interface.

[00:07:24] Of websites have attacked government agencies and destruction of data by Viper are part of a cyber attacking, but causing as much damage to the infrastructure of state electronic resource that's from the Ukrainian government, not the best English, but their English is much better than my Ukrainian or Russian.

[00:07:44] So you, crane is blaming these attacks on Russia, incomes, CS. So you says now urgent. Business people in the us and other organizations to take some specific steps. So quote, here from the Seesaw insights bulletin, the CSO insights is intended to ensure that senior leaders at the top of every organizational where the cyber risks and take urgent near term steps to reduce the likelihood and impact of a potentially damaging compromise.

[00:08:19] All organizations, regardless of the sector or side should immediately implement the steps outlined below. So here's the steps and there are a lot of them. One I'm going to do these, you should find in your newsletter today. Hopefully that all made it in. But three basic things. One reduce the likelihood of a damaging cyber intrusion.

[00:08:46] And we're going to talk about the best way to do backups here a little later on today. Make sure your software is up to date. Make sure your organization's it personnel disabled, all ports and protocols, not essential for business purposes. This is all basic stuff, but I got to say. I bet you, 98% of businesses and organizations, haven't done these things.

[00:09:07] The next major category here, take steps to quickly detect a potential intrusion, and then ultimately maximize the organizations resilient to destructive. Incident. So that means doing things like testing your backup procedure, make sure your data can be restored rapidly, or you have a way to get your business back online quickly.

[00:09:31] What we tend to do is in our backup strategy, depending on how much the company can afford, to be down. To be out of business if they lose all of their stock versus what it costs to do this, but we will put a server on site at the company and that server then does some of the backups, right? It does all of the initial backups.

[00:09:55] And then what happens is it gets relayed to us. It gets pushed to tape and tape is really good. We'll talk about that in just a few minutes, but the other big thing is. The backup that we have local to their business also has what's called a virtual machine infrastructure built on it. So if a machine goes down, If it gets wiped or if it just crashes and can't be recovered easily, we can spin up that machine.

[00:10:27] A copy of it in our little virtual environment in just a matter of minutes. So these are all things you should be considering. If you're interested, you can send an email to me@craigpeterson.com. I can send you a checklist that a little more extensive than this, or I can help you with any other questions you have.

[00:10:47] I get lots of questions every week from everything for on retirees, wondering what they should do all the way through businesses that we help government contractors and others. This isn't good. Russia is likely coming after us. Based on this. Visit me online. Craig peterson.com or email me@craigpeterson.com with your questions.

[00:11:14] With all of this talk about hackers, ransomware data, wiping systems. What's the best way to protect yourself, but what do you do to really protect against ransomware? I can tell you, it's not just plugging another hard disk into do backup.

[00:11:31] We've got so many hackers out there. We're talking about a multi-billion dollar industry to go after us.

[00:11:39] It's just depressing. Really. When you think about it, I think about the old days where security, wasn't a huge concern, right? Physical security. I had one of my first jobs was at a bank and I was, this was back way back in the a G it would have been the mid seventies and I was one of the operators of the main.

[00:12:05] And so as a mainframe operator, we'd load up the tapes and we would ship them places. We'd also go ahead and put them in the vault so that they were in a fireproof vault, and we could recover anything we needed to recover. It worked out pretty darn well, and it was a fun job, but most of the time it was cleaning the tape drive heads and taking those tapes, those big round tapes, you might remember those.

[00:12:33] Nine track tapes and maybe the fancy stuff, 52 50 BPI or 800 BPI of one end or the other, or the spectrum. And we just had to make sure they were physically safe nowadays of course, mainframes are still around and are still absolutely fantastic. They're just phenomenal. Some of the technology IBM has in their mainframes.

[00:12:59] Most of us, aren't using those. Most of us are using a regular computer or I'm sitting in front of a Mac right now that I use for the radio show. We have windows, computers, Linux machines, right? All of those things that we have in our business and that we maintain securely for our clients. But what do you do when we're talking about random?

[00:13:23] You can cross your fingers and hope that you'd hope you don't get ransomed. That sort of a practice doesn't usually work out too well for people, but you can do backups and many people do. So let's talk about the backups. Let's say that you have your computer and you're doing a backup and you have one or two generations worth of backups for your company.

[00:13:47] Ransomware nowadays does not just typically destroy your whole disk. Usually what it does is it encrypts files like doc files, doc X, right? Excel files, all kinds of files that thinks might be useful to you. And then of course, the rest, it pops up says, pay me. And off you go. The reason for that is so your computer still works so that you can enter in the decryption code.

[00:14:18] Once you've paid the ransom, hopefully it works for you give or take 50% of the time. You will get your data back. If you pay the ransom much of the time. But let's go back to that one or two generations of backup. You're using a cloud service, let's say, and your computer gets ransomware. That cloud service backup software will still work.

[00:14:43] What if it's working? So you're now backing up your encrypted files to the backup site in the cloud. Do you see where I'm going with this? Your backups? No. Same thing is true. If you're backing up to a local hard disk, many people do it and it's handy. I recommend that you do that, but it's not all you should do.

[00:15:08] So that disc is attached. We had a. Boy, who was it here? Yeah, we have a client in Maine and they have a really smart system administrator and he designed these disk drives that would physically disconnect themselves from a machine when the backup was not running and would physically connect themselves when the backup.

[00:15:34] Was running. So the idea there was okay, great. We've got a local backup on a local disk and if the bad guys managed to get a hold of the machine, they're not going to be able to encrypt the. And, as long as the backup isn't running, I thought that was a brilliant solution. Doesn't solve some problems, but it certainly takes care of some others.

[00:15:58] So if you are doing a backup, you've got to make sure you've got multi generations. I tend to keep a year's worth. Now there's other considerations. There's the federal rules of. Procedures that say you have to have bad cops. They have to go back years. And there are also other things the payment card industry requires certain types of backups.

[00:16:25] If you are a government contract, We have them as clients and they have certain data retention policies based on the length of the contract. They have keep it for some years afterwards. It goes on and on. So if your data is lost or stolen or encrypted, and your backup is encrypted or deleted, You are in real trouble depending on the type of business you're in.

[00:16:56] So what's the right answer to this. I've talked about 3, 2, 1 backup for a long time, and it's still a very good methodology for doing backups, but nowadays they're talking about 3, 2, 1, 1 backup, which is again, that's a bit of a different methodology. In doing backups, but the idea is you've got multiple copies of your data on multiple types of media in multiple places.

[00:17:29] That's the bottom line. What is the gold standard for this? I it's something that gets to be a little expensive. Again, we have another client that we've had for years, and they are looking for a replacement for the backup system. Now. And so we proposed something that's based on what's called LTO technology, which is a type of a tape drive.

[00:17:55] It's a small cassette, right? It's not those big 12 inch reels of tape that we used to lug around and it's amazingly dance. The new LTO tape drives have space on them for as much as 45. Terabytes of information. It's also great because it's encrypted by hardware, government level encryption automatically, and those tapes can be taken offline.

[00:18:25] You can take the tape. Now we picked up a client who had been doing backups and they were using little USB drives and every day he'd take the drive home and bring in the next drive. So he had five drives, right? So he had the drive for Monday, Tuesday, Wednesday, Thursday, Friday. And he was taking them home, but he missed one of the key things to check the back.

[00:18:53] He hadn't checked the backup and their backup had not been running for more than a year and a half. So that's the other thing you have to do? The LTO tapes are really the gold standard. It goes back to that for one of the first jobs of mine, right? The job I mentioned, where I was mounting tapes and filing them and moving them around and mountain disc packs and pulling them out and everything.

[00:19:19] It still makes sense. They'll last for decades, they cannot be hacked because they are literally offline. You can ship them to places to have them stored. I have a course on backups and if you're really interested, send me a an email to me@craigpeterson.com. And I'll go ahead and. Send you a link to the course, you can watch it.

[00:19:48] But yeah, I think this is really important. Of course, I'm not going to charge you for that, but magnetic tape it's established. It's understood. It's proven it's been around for many decades and LTO tape is unique. It needs all five best practices for addressing ransomware. Even be able to recover.

[00:20:12] If you want more information, just email me@craigpeterson.com or sign up for my free newsletter. Craig peterson.com.

[00:20:22] Switching from gasoline powered engines to these new electric cars is no environmental panacea. At least that's what West Virginia university is saying. And the E. Just changed its mind as well.

[00:20:38] Ford of course, about a year ago, unveiled its new electric.

[00:20:43] F-150 the lightning and Ford has stopped taking orders for them because they are going to have to make double what they thought they would have to make. Ford also has a similar problem with yet another electric vehicle. The Mustang GM is doing a few different electric. Coles. And so is everybody else, frankly, Porsche even now has an electric car out.

[00:21:11] That is all well and good. Isn't it. And there's certainly problems, particularly with manufacturing nowadays, trying to get the CPU's and other electronic components you need. They're even having trouble getting electric motors for electric windows in vehicles. Now they're coming. Crank window with a little coupon saying later on, we'll convert it to electric for you all kinds of problems, but there's one that I haven't heard anybody but myself talk about.

[00:21:44] And so I was online looking around, doing some searches, seeing if I was, like the only one there's no way right now, I'm not the smartest person in the world. I don't pay the most attention to everything. And I found that. Virginia university is in total agreement with that with me, it's just amazing.

[00:22:06] They looked at recent trends and they're cautioning as I have been for years, at least a decade. Now they're cautioning about what seems to be a race to put more electric vehicles. On the road. And the problem is that these electric vehicles in their demand for electricity may well out, run what's needed to keep the vehicles on the road.

[00:22:35] So here's a quote from them. The electric grid will struggle to handle the quick charging of very many electric vehicles at the same time. Okay yeah, by the way, like hardly any quick charging is generally what everyone thinks about, like going to the gas station, getting a full charge in 10 to 15 minutes, which would be a tremendous instantaneous load on the local distribution center.

[00:23:03] My concern is the huge power dumps required at quick charging stations along the interstate. It sounds good, but it'll require a lot of new infrastructure to get the power to the charging stations, as well as building those charging stations. So where does the power come from? Power storage is going to be required if we're going to also move towards fixing.

[00:23:28] Power sources such as solar and wind. We do not have power storage capability yet in large enough quantities to do this on a large scale. Solar does not work at night. The wind doesn't blow all the time. Also, we do not have the distribution on the streets to move fast charging into residential neighborhoods on mass.

[00:23:52] Electric vehicles are great, but we have not fully considered the impact it'll have on our electrical grid infrastructure. It will require a lot of expansion of our electrical distribution and charging facilities. Remember, electric power comes from the power company. I heard an interview with a lady the other day, and they asked her, where does the electricity come?

[00:24:15] She said, From the plugin, the wall, right? We must consider this when considering wide-scale electric vehicle adoption, much as there is to gain from electric vehicles. I don't believe we're ready yet as a society for completely electrical vehicle transportation system. With time and infrastructure development, we can be.

[00:24:37] I totally agree. This is Rory Nutter, professor lane, department of computer science, electrical engineering, Benjamin M. Slater, college of engineering and mineral resources. I totally agree with that. We don't have the ability to generate the electricity. We don't have the ability to store the excess electricity.

[00:25:01] So in other words, if we're using solar at nighttime, we don't have the sun, we can't run solar. So we got to store the solar. And in fact, we have to make about twice as much electricity as we need during the day so that if we can store it, we can then use it in. The same thing with wind, right? It's fickle.

[00:25:24] It just doesn't work that well. So what do we need? Basically right now, we need to stop turning off our coal powered plants, our natural gas plans and our nuclear plant. Because we need to still have electricity. Look at what's happened last year. And this year over in Europe with the crazy cutbacks that they've been doing on some of these plants, coal nowadays with the scrubbers that are on our cold powered, flat plant is clean energy.

[00:25:58] It's not like the old days where you lived on the south side of the tracks and you got all of the wind blowing towards you that had all of that nasty cold ass. You ever seen any of those pictures? It was just terrible. All of that nasty sitcom. It's not something we need to worry about nowadays.

[00:26:16] The other big thing that ties into all of this is so how do we generate our electricity cleanly? A hundred percent cleanly? Nothing. Per cent, but just a couple of weeks ago, the European commission presented their 27 members states with new draft rules that classified natural gas and nuclear power as green fuels for electricity generation.

[00:26:47] Listen, if we want electric cars, which as we've talked about before are highly polluting. Yes. Because of the materials in them, because of the materials that go into the batteries, having to mine it, having to ship it, having to process it and then having to change out those battery packs after 80,000 or a hundred thousand miles.

[00:27:09] Did you see this guy? There was a meme in the video about this online a few weeks ago. How to test. His Tesla needed a battery replacement. It would cost him, I can't remember what it was. 20, $30,000. A lot of money. So he decided to just blow up the car. That's all it took. I saw another Tesla that had water damage.

[00:27:33] From, being down in new Orleans or somewhere, the flooding occurred. And the guy bought that Tesla because Tesla won't sell the parts to fix the car after the water damage. And so he ripped out the batteries, ripped out the electric motors and he bought a high power engine. And gasoline and put it into the Tesla and made really, quite a very cool car.

[00:28:00] You can find it online if you want to look for that, it's quite cool. What they ended up doing. It took us quite a while to do it, but they did it. So now that we're seeing. That nuclear is green. Let's talk about why we've been so afraid of nuclear. One of the biggest problems of course is so what do you do with all of the waste?

[00:28:20] And that's a legitimate question, but what you're really talking about when you ask that question are the reactors that went online 50 years ago, or that were approved 50 years ago because of the regulations. There are. These nuclear plants that have been provisioned in the last 20 years that are still using that old technology.

[00:28:43] So when we get back, we're going to talk about this more. What about the waste? What our fourth generation nuclear power plants, how safe are they when they say they're intrinsically safe? What does that mean? And how and why? Because I'm predicting to this point that we're going to have to switch back to nuclear and even the European union, if you can believe it agrees with.

[00:29:13] Hey, make sure you take a minute. Go online. Craig peterson.com. Subscribe to my free newsletter. You can get it right there. I send you out stuff every week. And this week is no exception. We've got a bunch of bullet points that if you are in a business position, you got to protect yourself immediately. So I tell you how Craig peterson.com.

[00:29:38] So what are these new rules for nuclear energy? And why is it absolutely necessary that we do something like this? Get fourth generation nuclear online. If we can even consider electric vehicles on our roads.

[00:29:55] Things have changed in the European union. They've been trying to figure out how they're gonna handle all of these electric vehicles, how they're going to properly handle all of the solar cells and the wind turbines.

[00:30:09] And there's even some work over in the EU. To get the tide to generate electricity, some very cool stuff. Actually, that's been done, I love tech and I'm into all of this stuff, frankly. I think we should be doing a lot of it. What I don't think we should be doing. Is getting ahead of ourselves. And unfortunately that's really what's being going on.

[00:30:35] We don't have a grid that can really use the electricity that we can generate from our windmills, from our solar cells, from anything, frankly. And we cannot. All of that electricity that we might be generating and somehow have that electricity be stored and used distributed appropriately to our charging station.

[00:31:03] And our grid was built and designed to have a few central point where the electricity is made, where it's generated and then distributed to some pretty specific types of things like housing, development, businesses, et cetera. You can't just go ahead and open a big business man. in a residential area.

[00:31:25] And part of the reason for that is the grid isn't set up for it. You don't have three phase power going into residential areas or even more than that, you don't have the high voltage, the high current, et cetera. So how are you going to be able to quick charge electric cars in the regular residential neighborhoods?

[00:31:47] I w how about at a hotel? Yeah. Okay. A hotel is probably. Multiple phases and has a fair amount of power there, but the amount of strain that's put on the grid by trying to just rapid charge a single car is huge. So how can we deal with that as well? The quickest and easiest way to deal with it is just put more large power plants online.

[00:32:13] Some people don't like that. Don't like that idea at all, frankly, but we're not ready. What are we going to do? Look at what happened in Texas with a fairly minor reliability or re reliance, I should say, on these windmills last winter and things with this winter, as cold as it's been, that could really cause some just incredible problems.

[00:32:40] Nuclear is being reconsidered, particularly fourth generation nuclear power plants. The greenhouse gas emissions from nuclear power are one 700th of those of coal. The nuclear power plants produce one, 400th greenhouse gas emissions of a gas plant, and they produce a quarter of the greenhouse gas emissions from solar.

[00:33:09] Now you're saying, Hey Craig, come on, I get it. Wait a minute, solar, how can solar produce greenhouse gas? It does. And it produces greenhouse gases because of the manufacturing processes, as well as of course it off gases. So how do we make all of this stuff work? We all saw the China syndrome and we heard from experts like Jane Fonda, how we would all die.

[00:33:34] If we put a nuclear power plant. These are intrinsically safe, power plants much different than they used to be. Nuclear power frankly is a much safer business than most people think it is. They no longer these new plants produce. The the nastiest what's called high level nuclear waste.

[00:34:00] They can reprocess it right there in the plant. They can start in fact where some of the nuclear waste though has been generated from the older nuclear plants and get rid of that. It's amazing. So people are asking okay. Plutonium might have a half-life of 24,000 years, but it doesn't emit much radiation.

[00:34:23] We get that. How about the higher levels of radiation? Because some of it can last for hundreds of thousands of years. According to the U S radiation expert, Robert Gale for every terawatt hour of electricity produced nuclear energy is 10. To 100 times safer than coal or gas. What it does emit are alpha particles, which do not even penetrate human skin.

[00:34:54] They've done all kinds of risk assessments and tried to figure out what's going to happen. What can we do? And I'm not going get into all the details here, but it is intrinsically safe because. What really happens is that the, these new plants he's fourth generation, a newer plant are instead of using water, for instance, that can do reactors out of Canada, use heavy water in order to cool those rods.

[00:35:25] It was same sort of thing we've had in the meltdowns before they're using a liquid silica inside. They're set up in such a way that they do not need to have pumps running. So the Fukushima reactor that you might remember in Japan that failed because of the tsunami and the fact that one fact, this is what was their killer that their electrical generation from the diesel generators went offline.

[00:35:56] Why did it go offline? Oh, I can see the grid going offline, but how about a diesel generator? If you have a below sealer, And the water comes in. You're in big trouble now. They didn't have it like below, permanently below sea level and Fukushima. But when that tsunami wave came in, it was below sea level.

[00:36:16] They just, man, we could talk for a long time about the problems that they had over there. The nepotism, the line on the forums. They fact they did not do the upgrades that the manufacturer has suggested on and on. So these new reactors can lose all power and you won't have a China store. They won't go through a meltdown and they're even designed in such a way, the way using physics things called the law of gravity, who would have thought, right?

[00:36:51] So that what happens in the worst case scenario is no one gets hurt. It just eats in on itself and then stops runs out of. So we've got to remember all of this stuff. Okay. The nuclear power of yesteryear is not the nuclear power of today. And the nuclear power of today is so green and so safe that even the European commission presented new draft rules that said to the natural gas, nuclear power, our agreement.

[00:37:29] Fuels for electricity generation. So assuming the rules are approved and Francis in favor, Germany isn't as into nuclear power. In fact, they plan on having all of their plants shut off by the end of 2025, which is crazy because they're already having serious problems with their solar and wind.

[00:37:53] And that's why they're buying so much natural gas now for. Yeah, American influence dropping over there. Thank you again, president Biden for allowing that pipeline to go through. All right. Anyhow. They're assuming they're approved Germany. Apparently isn't likely to try and block these rules. It means that nuclear, the new nuclear force generation or newer is going to be right there alongside renewables, like wind and solar on the list of the EUS technology that are approved for financial support.

[00:38:30] Now, this is very good news because as I mentioned earlier, What happens when it comes to solar at nighttime doesn't work solar. When it's raining, doesn't work solar. When it's snowing, doesn't work solar. When it's cloudy, doesn't work. Ryan, how about the windmills? When the wind is. They don't work when they break down, which happens a lot due to mechanical failures, they don't work.

[00:39:02] So having the. New nuclear plants that are intrinsically safe, that don't generate this really nasty radiation, and stuff that we have to store for a thousand years, et cetera. The high level nuclear waste makes a lot of sense because unlike the. Solar plants or other things that might be on someone's house that cannot be easily controlled by the central grid.

[00:39:32] In other words, Hey, stop generating electricity because I got enough right now. And what Germany has been doing is putting it into heat sinks, heating up lakes and other things, to get rid of that extra solar energy people are generating on their homes and businesses. What you can do is, Hey, we are at the point where we don't have enough sun.

[00:39:54] It's really cold. People are trying to heat their homes, or it's really hot. People are trying to cool to their homes. And yet it's raining heavily or there's a lot of clouds. So all you have to do at that point is turn off. That nuclear power plant or multiple plants. You see the way it's going.

[00:40:12] You're not going to have some massive plant with a bunch of reactors. No. Where they're going with this is to have community reactors in the multi megawatt range that can be put into communities and the power distributed directly. Into the community and these power plants are good for 20 years and these new ones, they are typically going to be buried in the.

[00:40:41] And then every 20 years they get dug up, put onto a truck, shipped off, they get recharged, brought back and you're off and running again, a whole different concept. And I love it. We're starting to do this in the United States. We've got some early approvals for some of these, and I was shocked and amazed and happy that the Biden administration has decided.

[00:41:06] To approve the new nuclear here in the United States. So there'll be some test plants going online relatively soon. That just makes so much sense. These 50 year old nuclear red regulations and plants, they just don't work. Make sure you visit me online. Craig peterson.com. I'm going to have a lot of stuff for you every week.

[00:41:32] Craig peterson.com.

[00:41:37] The hacker world got turned upside down this past week as Russian president Putin decided to crack down on the hackers. Now, this is a very big change for Russia. We're going to talk about my theories. Why did this happen?

[00:41:54] As we keep you up to date, russian hackers have long been known to go after basically whoever they want. They have really gone after the United States and other Western company countries.

[00:42:10] And as part of what they've been doing, they have been making a lot of money and keeping Vladimir Putin pretty darn happy. He's been a happy because they're bringing more. Into mother Russia, he's happy because they are causing confusion amongst Russia's competitors out there, particularly the United States.

[00:42:35] But there's one thing that Putin has been absolutely steadfast. And that is not allowing any of the hackers to go and hack any of the countries that are part of their little pact over there. Think of the old Warsaw pack they got that band back together. So as long as they didn't harm any Russian or, a affiliated country, They could do basically whatever they wanted and they did.

[00:43:09] And they have caused a lot of trouble all over the world. So Friday Russia. As security agency announced that it had arrested members of the cyber gang called reveal. Now we have talked about them for a long time. They have come and gone. The FBI and other countries have shut down their servers.

[00:43:37] So reveal disappears for awhile. Then pops his head up again. And Russia said that they arrested members of revival who were responsible for massive ransomware crimes against us companies the last year. So why would they do that? I'm looking right now at the Russian website here, that's part of the FSB.

[00:44:06] And it's saying that the Russian federal security service in cooperation, the investigation department of the ministry of internal affairs of Russia in the cities of Moscow St. Petersburg, Leningrad lips. As, I guess it is regions. They stop the illegal activities, a members of an organized criminal community and the basis for the search activities was the appeal of competent U S authorities who reported on the leader of the criminal community and his involvement in an encroachment on the information, sir, resources of foreign high tech companies by drusen militia software, encrypting information and extorting money for its decreased.

[00:44:52] Now that all sounds like the stuff that Vlad has been just a happy about in years past. So why did this happen? What brought this about nowadays in this day and age? What is he doing? I've got a little bit of a theory on that one because there have been some interesting development. One of them is this hacker.

[00:45:19] In Belarus. Now, Belarus is one of those countries that's closely affiliated with Russia friend of Russia, right? Part of the old Warsaw pact. And you might remember that Bella ruse is right there by you. And of course, we've got this whole issue with Ukraine and whether or not Russia is going to invade president and Biden said something incredibly stupid where he said, yeah a moral response is going to depend upon what Russia does, if it's just a minor invasion.

[00:45:57] You're you remember? The president Biden's saying that just absolutely ridiculous. And then of course, the white house press secretary and various Democrat operatives tried to walk the whole thing back, but it's a problem because Russia has, what is it now like 120,000 troops on the border.

[00:46:17] Now, if you know anything about history, you know that the military army. March on their stomachs, right? Isn't that the expression you've got to feed them. You have to have a lot of logistics in place. In fact, that's what really got a lot of the German military in world war two. Very nervous because they saw how good our logistics were, how good our supply chain was.

[00:46:43] We were even sending them. They cakes to men in the field that they discovered these cakes in great shape. And some of the German armies, particularly later in the war, didn't even have adequate food to eat. What do you think is happening with the Russian troops that are sitting there?

[00:47:01] They need food. They need supplies, including things like tanks, heavy artillery, ammunition. All of that sort of stuff. So how do they do that? They're moving it on rail, which they have done in Russia for a very long time. You might remember as well in world war II, the problems with the in compatibility between the German rail gauge and the Russian rail gauge as Germany tried to move their supplies on Russian rails and Soviet rails, ultimately, but on Russian rails and just wasn't able to do.

[00:47:37] So hacktivists in Bella ruse right there next to Ukraine said that they had infected the network of Bella Russa's state run railroad system with ransomware and would provide the decryption key. Only if Bella Reuss president stopped. Russian troops ahead of a possible invasion of Ukraine. So this group, they call themselves cyber partisans wrote on telegram.

[00:48:11] Now I got to warn everybody. Telegram is one of the worst places to post something. If you want some privacy, excuse me, some privacy, some security it's really bad. Okay. No two questions. So they have, apparently this is according to what they wrote on telegram. They have destroyed the backups as part of the pec low cyber campaign.

[00:48:36] They've encrypted the bulk of the servers, databases and work station. Of the Belarus railroad, dozens of databases have been attacked, including, and they name a bunch of the databases. Automation and security systems were deliberately not affected by a cyber attack in order to avoid emergency situations.

[00:49:00] They also said in a direct message that this campaign is targeting specific entities and government run companies with the goal of pressuring the Belarus government to release political prisoners. And stop Russian troops from entering Bellaruse to use its ground for the attacks on Ukraine. Now, this is frankly fascinating from a number of different angles.

[00:49:26] One is, it is very easy nowadays to become a cyber hacker. And in fact, it's so easy. You don't even have to do anything other than send N E. And it's been done, frankly. It's been done people who are upset with a, an ax, for instance upset with a particular company, you can go onto the dark web and you can find companies.

[00:49:53] And this revival company was one. That will provide you with the ransomware and they will do everything for you except get that ransomware onto a computer. So you could bring it in to an employer. You can send it by email to the ax. As I mentioned, you can do a lot of stuff. And then the. Ms. Cyber hacker guys, the bad guys will go ahead now and they will collect the ransom.

[00:50:24] They'll even do tech support to help the people buy Bitcoin or whatever currency they want to have used. And then they take a percentage. So they might take 30% of it. There's a whole lot. We can talk about here too, including trust among thieves and everything else. It is easy to do this. So to see an organization like these cyber partisans, which I'm assuming is an organization, it could be as little as one person taking ransomware, going into specific computer systems breaking in.

[00:50:58] Because again, even here in the U S how many of us have actually got their computer systems all patched up to date? The answer to that is pretty close to zero. And they can now go after a government, they can protect their friends. It's really something. When you start thinking about it, right? No longer do you have to be North Korea or China or Russia in order to hack someone to the point where they commit.

[00:51:31] And in this case, they're not even after the money, they just want these political prisoners freed and they want Russia to stop shipping in troops supplies, into the area in Belarus next to or close to. Very fascinating. There, there is a whole lot of information about this online. If you're interested, you can read more about it.

[00:51:55] It's in my newsletter, my show notes. I have links to some articles in there, but it really is a tool for the under. We've never really seen this before. It's quite an interesting turn in the whole ransomware narrative. It's just in crazy. That's a quote from a guy over at Sentinel one. Alright.

[00:52:21] Lots to consider and lots to know and do, and you can find out about all of the. One way, subscribe right now@craigpeterson.com. I promise. I'm not going to her Hess. You stick around.

[00:52:38] We've heard a lot about automated cars. And of course we talked about them a lot here too, but that original vision of what we would have, it's gone now. It's fascinating. We're going to talk about that journey of automated car.

[00:52:55] To date on technology for years, automakers have been telling this story about how these automated cars are going to drive themselves around and do just wonderful things for us.

[00:53:10] And as part of that, they've decided that. The way it's going to work. And I remember talking about this, cause I think it's a cool idea is that there will be fleet of these vehicles think about maybe an Uber or Lyft where you get on the phone and you order up a card and it says, Hey that driver will be here.

[00:53:30] Here's the license plate, the driver's name and picture. It's really cool, but general motors and Lyft haven't gotten there. They signed in agreement. To have electric autonomous cars as part of Lyft's fleet of drivers. They did a back in 2016, a long time ago. Ford promised what it called robo taxis and that they would debut by 2021 Dimeler of course, the company that makes Mercedes-Benz said it would work with Uber to deploy fleets of their car.

[00:54:12] And the logic was really financial and it made a lot of sense to me, which is why I was so excited. I have car outside. You know about my Mercedes, you. How often do I drive that 40 year old car? Most of the time it's sitting there parked, most of the time, because I don't go very many places very often.

[00:54:35] What would it be like then to just be able to have an Uber or Lyft type app on my phone that says, okay, tomorrow I have a 10 o'clock meeting in Boston and I want a car to take me there. So the. Checks with the servers and figures out. Okay. At 10 o'clock meaning, that means you're going to have to leave at eight 30 in order to get around the traffic that's normally happening.

[00:55:03] And so we'll have a car there for you. So all I have to do is walk out the apple, probably remind me, my butt out of bed and get outside. Cause the car is about to arrive. So the car pulls into my driveway or maybe just stops on the road and the app reminds me, Hey, the car's there I go out. I get in.

[00:55:22] And on the way down, I can work on getting ready for the meeting, getting some things done, just really kicking back, maybe having a nap as we go. And I'm there on time for my 10 o'clock. Just phenomenal. And from a financial standpoint, nowadays, how much is a car costing you? Have you ever done the math on that?

[00:55:44] How much does a typical car loan run you per month? And I also want to put in how about these leases? How many of us are leasing cars? My daughter leaves to Gargan believe she did that. Didn't leave to me. It didn't make financial sense, but maybe that's just because I've been around a while. But looking right now at some statistics from credit karma, they're saying us auto loans, new cars, your average monthly payment is $568.

[00:56:17] For an average loan term of 71 months. Good grief used cars, about $400. A month payment and average loan term, 65 months. I can't believe that I've never had a car loan for more than three years. Wow. That's incredible. So we're talking about six year notes on a new car. Wow. I guess that's because people buy cars based on the monthly payment, right?

[00:56:49] So figure that out. If you're paying $500 a month, how about just paying a subscription service? $500. You can get so many rides a month and you don't have to maintain the car. You don't have to buy insurance. You don't have to make any fixes. You don't have to do anything. And the car will just show up.

[00:57:08] That's what I was excited about. And it had some just amazing implications. If you think about it, it city dwell over dwellers and people who were directly in the suburbs, it'd be just phenomenal. And you could also have the robo taxis for longer trips. You can abandon that personal car. Really alternate.

[00:57:31] So now it's been about a decade into this self-driving car thing that was started. And, we were promised all of these cars, it reminds me of the fifties, we're all going to be driving, flying cars by. George Jetson one, when was he flying around the cities, but that's not happening.

[00:57:52] Okay. The progress on these automated vehicles has really slowed automakers and tech companies have missed all kinds of self-imposed deadlines for the autonomy. Look at what Elon Musk has promised again and again, it's. Basically in 2020, late 2020, it was going to have fully autonomous cars even calls itself dry.

[00:58:15] When it isn't really self-driving, it certainly isn't fully autonomous it more or less drives. It stays in the lane as it's driving down the highway. But the tech companies are looking for other ways to make money off of self-driving tech. Some of them have completely abandoned. There's self-driving cars, the sensors like the LIDAR, and I've had the LIDAR people on my show before they've all gotten cheaper.

[00:58:40] It doesn't cost you $50,000. Now just for one LIDAR sensor, think about what that means to these cars. So some of these manufacturers of these future autonomous cars are shifting to a new business strategy. And that is selling automated features directly to customers. In other words, you're going to buy a car, but that car isn't going to do much.

[00:59:09] Think about the golden key that the tech companies have used for years, right? IBM well-known for that, you buy a mainframe or from IBM or a mini computer from digital equipment corporation, and you have the same computer as someone that has this massive computer. But in fact the difference is that they turn off features and we're seeing that right now.

[00:59:34] I'm, I've mentioned that Subaru before where they are charging people for upgrades, but some of the companies are charging you monthly to use a remote start feature for instance, and many others. So what's happening is a major change. We have the consumer electronic show, right? January 20, 20 and general motors CEO, Mary Barra said that they would quote, aim to deliver our first personal autonomous vehicles as soon as the middle of this decade.

[01:00:07] So again, it slipped, right? I'm looking at it, a picture of what they're considering to be. The new Cadillac car that should be out next year. Maybe thereafter. It is gorgeous. Absolutely gorgeous. But this announcement, right? Yeah. We're going to have autonomous vehicles, middle of the 2020s. She had no specific details at all.

[01:00:33] And apparently this personal robo car project is completely separate from this robo taxi fleet that's been developed by GM's cruise subsidiary. And cruise said it has plans to launch a commercial service in San Francisco this year. So they're going after multiple paths. The logic here is financial.

[01:00:56] The reasoning has changed and they're offering autonomy as a feature for the consumer market. Tesla, Elon Musk, they've been charging $10,000 now for the autopilot driver assistance feature. They're planning on raising it to $12,000 here early 2022 Tesla technology. Can't drive a car by itself.

[01:01:22] But he's going to charge you if you want it. And I expect that's going to be true of all of the major manufacturer that's out there. And by the way, they're also looking at customization, like color changing cars and things. They're going to charge them as features. Hey, stick around. Visit me online.

[01:01:43] Craig peterson.com.

[01:01:46] Just how secure are our smartphones. We've got the iPhones, we've got Android out there. We've talked a little bit about this before, but new research is showing something I didn't really expect, frankly.

[01:02:02] We've got some new research that wired had a great article about last week that is talking about the openings that iOS and Android security provide for anyone with the right tools. You're probably familiar at least vaguely with some cases where the FBI or other law enforcement agencies have gone to apple and tried to have.

[01:02:29] Old break into iPhones. Apples, refuse to do that one in particular, down in Southern California, where they tried to get apple to open up this I phone and tell them who was this person talking to after a shooting of foul of fellow employees at a. It was really something, there was a lot of tense times and we've seen for decades now, the federal government trying to gain access to our devices.

[01:03:04] They wanted a back door. And whenever you have a back door, there's a potential that someone's going to get in. So let's say you've got a. And your house has a front door. It has a backdoor, probably has some windows, but we'll ignore those for now. Okay. And you have guards posted at that front. All in someone needs to do is figure out to how to get into that back door.

[01:03:31] If they want to get into your house, it might be easy. It might be difficult, but they know there's a back door and they're going to figure out a way to get in. And maybe what they're going to do is find a friend that works for that security company, that post of the guards out front. And see if that friend can get a copy of the.

[01:03:51] That'll let them in the back door. And that's where we've had some real concerns over the year years here, a decades, frankly, our first, I remember this coming up during the Clinton administration, very big deal with the. That they were pushing. This was a cryptographic chip that they wanted every manufacturer to use if they wanted to have encryption and the white house and every gov federal government agency, and probably ultimately every local agency had the ability to break any encryption that was created by the clipper.

[01:04:30] In fact, we were able to track Saddam Hussein and his sons and his inner circle. Because he was using some encrypted phones that were being made by a company in England. And that company in England did have a back door into those encrypted phones. And so we were able to track them and we could listen in, on all of their communications back and forth.

[01:04:56] And it's really frankly, oppressed. When that sort of thing happens. So what do you do? What are you supposed to do? How can you make it so that your devices are safe? There are some ways to be relatively safe, but these cryptographers over Johns Hopkins university, Use some publicly available documentation that was available from apple and Google, as well as their own analysis.

[01:05:26] And they looked into Android and iOS encryption and they founded lacking. So they studied more than a decades worth of reports. How about which mobile security features had been bypassed had been a hack. I had been used by law enforcement and criminals in order to get into these phones. They got some of these hacking tools off of the dark web and other places, and they tried to figure.

[01:05:59] So we've got a quote here from Johns Hopkins, cryptographer, Matthew Green, who oversaw the research. It just really shocked me because I came into this project thinking that these phones are really protecting user data. Now I've come out of the project, thinking almost nothing is protected as much as it could be.

[01:06:22] So why do we need a backdoor for law enforcement? When the protections that these phones actually offer are so bad. Now there's some real interesting details of if you like this stuff, I followed cryptography for many decades. Now I've always found it. Fascinating. There are some lightweight things I'm going to touch on here.

[01:06:46] We won't get too deep in this, but here's another quote. Again, Johns Hopkins university on Android. You can not only attack the operating system level, but other different layers of software that can be vulnerable in different ways. Another quote here on iOS in particular, the infrastructure is in place for hierarchal encrypted.

[01:07:10] Now higher are hierarchical. Encryption is various layers of encryption. If you have an iPhone or an iPad, or if you have most Android phones nowadays, if you use a passcode in order to unlock the phone or even a fingerprint or a face. Your method of authentication is used to encrypt everything on the phone, but in reality, everything on the phone is only fully encrypted when the phone is powered off.

[01:07:49] Now that's a real, interesting thing to think about because obviously the phone can't work. If everything's encrypted. It needs access to the programs. It needs access to your data. So what they found bottom line was the only way to have a truly safe machine or a smartphone in this case is to turn it off because when you turn it on and it boots up on first boot, now it gets.

[01:08:20] Either by bio medical information, like your fingerprint or your face sprint or your passcode, it then has a key that it can use to decrypt things. So apple has on the iPhone, something, they call complete protection and that's again, when the iPhone has been turned off on boots up because the user has to unlock the device before anything can happen on the phone.

[01:08:45] And the is protections are very. Now you could be forced to unlock the phone by a bad guy, for instance, or in some cases, a warrant or an order from a judge, but forensic tools that, that they are using the police and the criminals really would have almost no luck at pulling information off of your phone.

[01:09:11] That would be useful at all because it would all be encrypted, right? If they could. So once you've unlocked your phone after that first reboot molt, after that reboot, right? You unlocked it after power up. A lot of the data moves into a different mode that apple calls protected until first user authentication.

[01:09:32] But it's what I call after first unlock. So when you think about it, your phone is almost always in the after first unlocks. Because how often do you reboot your phone? No, it's pretty rare that your phone might do on. And this is particularly true for I-phones might do updates and boot and reboot. And then of course you have to unlock that phone, but it doesn't go much further.

[01:10:01] The net and that's, what's interesting. That's how law enforcement and the bad guys, these Israeli companies and others have been able to get into iPhones and get into Android devices because ultimately if that computer is turned on and you've logged in, there's a lot of data. That's no longer encrypted.

[01:10:22] Oh. And by the way, that's also how some of these attacks occur on our laptops. Particularly if you traveled to. In the memory on that laptop that you close the lid on, you have to re log into is the key to UNHCR, unencrypt, everything, right? Because you logged in once. So all they have to do is freeze the memory, duplicate the memory and put it back in part of the reason, by the way that apple laptops have their memory soldered in you can't do that kind of attack.

[01:10:56] Stick around. We'll be right back.

[01:11:00] VPNs are good and they are bad. It depends on the type of VPN. Many of these commercial VPNs of people are using are actually very bad for you when it comes to your security.

[01:11:17] VPNs are Trump problematic. I did a couple of boot camps on VPNs. Probably I think it was about last year.

[01:11:26] Yeah, it was last spring. And I went through and explained and showed exactly why commercial VPNs are one of the worst things you could possibly do if you want. To stay secure. Now I lemme just give you the high level here. I have given people copies of this, if you're interested in a link to that VPN webinar that I did, I'd be glad to send it to you.

[01:11:57] Just email me Emmy at Craig Peterson, doc. And ask me for the VPN information and I'll send that all off to you. I also wrote something up that I've been sending out to people that have asked about VPNs. Cause it's one of the most common questions we have Franklin, but here's your problem with commercial VPNs?

[01:12:18] Most all of them say, oh, your information safe at zero logging, et cetera. And yet we have found again and again that's not. In fact, it can't possibly be true in almost every case because most of these VPN services are running out of other people's data centers. So they might be in an Amazon data center or IBM or Microsoft.

[01:12:45] And inside that data center, your data is coming in and then it's going to. So let's say you're using a VPN and you're connecting to a website. I don't care. Go to google.com via a VPN. So you're using one of these services. That's advertised all over creation. And what happens now is. Your web request to get to Google passes over that encrypted VPN and comes to an exit point because at some point it has to get onto the regular internet.

[01:13:20] How else are you going to get to that website? On the other side? You can't, unless you get to the regular internet. So at the other side, now the server is that's receiving the end point of view. VPN is going to send the request to Google. Google is going to respond to that VPN server. It's going to be encrypted and sent back to you.

[01:13:43] So what's the problem with that? There's multiple problems. One is the data center can see. That there is the request going up to Google. Now he might not be able to tell who it was. But if that VPN server has been hacked. And let me tell you, it is a big target for hackers, government hackers, as well as bad guys.

[01:14:06] Then they do know who went out there and depending on how it was hacked and how the VPN was set up, they may even be able to see all of the data that you're sending back and forth. It's called a man in the middle of. And some of these VPN services do it by having you install some software on your computer.

[01:14:28] And as part of that installation, they provide you with a master key that they then use to spoon. The keys for the websites. You're going to some, explain that what happens is if you were to go right now on your web browser, go to Craig peterson.com as an example. So Craig peterson.com. I'm typing it in right now in the browser.

[01:14:55] That's directly in front of me. Now you'll see a little lock up in the URL. What does that mean? If you click on that lock, it says something about the connection being secure. Are you familiar with that? What's actually happening is it's using SSL TLS keys, but it's using encryption now to send the data from your computer.

[01:15:24] To my server, that's hosting Craig peterson.com. And then my server is sending all of the webpage back to you. Encrypted. Any fact, a VPN has been established between your web browser and my web server. So why use a third-party VB? Because your data is encrypted already, right? Could it be more simple than that?

[01:15:59] Now, remember again, that the server on the VPM service that you're using is a prime attack target for everybody else. As I said from government agencies through hackers. So your data is likely less safe because if they get a hold of it, they can do all kinds of things to your data and to. And then on top of it, all the VPN service may well be selling your data in order to make money, to support the VPN service because free VPNs, inexpensive VPN sees the ones that are charging you five or 10 bucks a month cannot possibly afford to provide you with that service.

[01:16:51] And in the bootcamp, I go through all of the numbers here, the costs involved. With a VPN service it's not possible to do. They can't make any money off of it. So it is a very big problem for you to use one of these public VPN services. Now, I want to talk about an arc article that was on Z.

[01:17:19] Apparently your old pole, which is of course the police over there in the European nations has seized servers. What servers, VPN servers in Europe. Now they seized the servers because they were used by who was it? Grandma looking at pictures of the grandkids. Was it people watching cat videos who was using the VPN server?

[01:17:45] The paid VPN service. Wow. It was criminals. And when they seized these VPN servers that were also being used by criminals, they found more than a hundred businesses that had fallen victims to attacks. So who uses VPN services? People who want to hide something as well as people who just want to have their data secure.

[01:18:14] Another reason not to use VPN services. So as a part of the joint action by Europol Germany's police Hanover police department, the FBI, UK national crime agency, and others seized 15 servers used by VPN lab dot. Okay. So VPN lab.net net, obviously no longer usable. And they started looking at all of the records that were being kept in these servers and use that to find the criminal.

[01:18:48] Does that make sense to you? So VPN lab.net was according to these charges, facilitating illicit activities, such as malware distribution. Other cases showed the services use in setting up infrastructure and communications behind ransomware campaigns, as well as the actual deployment of ransomware. You like that.

[01:19:12] Now they were using open VPN technology, which is actually very good. As part of that VPN information, I can send you if you're interested, just email me M e@craigpeterson.com. Let me know what you're interested in, and I'll whoop you off an email. Give me a few days I can get behind sometimes, but you can set up your own private VPN server if that's what you want to do.

[01:19:38] And I've gotten instructions on how to do that in that little special report in that email, but They were providing what they called online anonymity, this VPN lab.net service for as little as $60 a year. Okay. You like that? So they provided what they call double VPN servers and a lot of different countries and made it a popular choice for cyber criminals.

[01:20:04] Very big deal. Okay. So be very careful with VPNs. Also be careful of the VPN you might be using for your business. Let's say you've got something that isn't terribly secure or not secure at all as your firewall, right? So you buy a nice little firewall or this is so great. It's not expensive. And I got it online from a big box retailer.

[01:20:27] Most of them out there do not meet. The minimum standards you really need in order to keep your business. And there's only two companies that do one of them, Cisco, and one of them's Juniper, that's it? None of the other firewalls with VPNs meet the minimal standards you need to have, but those be glad to sell it to you.

[01:20:49] They'll be glad to tell you that it's perfectly secure, but it is not okay. Just went through that again with a company this week an engineering firm and at least they understand some of the stuff, but they were trying to do the right thing and they were being misled by these various vendors. So this action against VPN lab took place in January involved with authorities from Germany.

[01:21:15] The Netherlands Canada, Czech Republic, France, Hungary, Latvia, Ukraine, us UK, as well as your old pole. So there you go. You've gotta be careful don't trust VPNs, right? I've been saying that for a very long time. And then the other thing I want to. Is hopefully this summer we're going to be traveling.

[01:21:40] And when you're traveling, the temptation is to use public wifi might be at the hotel. It might be at a restaurant coffee shop, whatever. Okay. I admit to doing that myself. But here's two things you need to be careful with. One use, good DNS filtering. Now we sell and provide umbrella, which is a Cisco product, which is extremely good.

[01:22:08] DNS filtering. You can get free DNS filtering that isn't configurable, doesn't have the options, but is fantastic called open DNS. I've got, again, I did a bootcamp on that. I can send you information on it if you want. It doesn't cost you a dime for any of this stuff, but open DNS. And then the other thing I do, I have a high-end Cisco firewall and VPN.

[01:22:34] So when I'm on the road, even when I'm using data from the phone company, I have my secure VPN turned on FIPs compliant, by the way, for those who know what that means. Hey, visit me online. Craig peterson.com. Get my show notes. Get my Wednesday, wisdoms everything. Craig peterson.com. It's easy to sign up right there on any page.

View Details

Weekly Show #1158

We know the Russians have been attacking us. I've talked a lot about it on the radio and TV over the last couple of weeks. So I am doing something special; we are going through the things you can do to stay safe from the latest Russian attacks.

Last week, we started doing something I promised we would continue -- how can you protect yourself when it comes to the Russians? The Russians are the bad guys when it comes to bad guys. So there are a few things you can do. And there are a few things; frankly, you shouldn't be doing. And that's precisely what we're going to talk about right now.

Today, I explain:

  • How to protect your back-end
  • Preventative measures
  • The new rules of backing up your computer

As usual, we'll cover the What, Why, and How's.

[Automated transcript follows]

[00:00:39] So last week he went over some steps, some things that you can look at that you should look at that are going to help protect you. And we are going to go into this a whole lot more today. And so I want you to stick around and if you miss anything, you can go online. You can go to Craig peterson.com, make sure you sign up there for my email.

[00:01:01] And what I'm going to do for you is. Send you a few different documents now where we can chat back and forth about it, but I can send you this. Now I'm recording this on video as well as on audio. So you can follow along if you're watching either on YouTube or. Over on rumble and you can find it also on my website.

[00:01:26] I've been trying to post it up there too, but right now let's talk about what we call passive backend protections. So you've got the front end and the front end of course, is. Stuff coming at you, maybe to the firewall I've mentioned last week about customers of mine. I was just looking at a few customers this week, just so I could have an idea of their firewalls.

[00:01:52] And they were getting about 10 attacks per minute. Yeah. And these were customers who have requirements from the department of defense because they are defense sub subcontractors. So again, Potential bad guys. So I looked up their IP addresses and where the attacks were coming from. Now, remember that doesn't mean where they originated because the bad guys can hop through multiple machines and then get onto your machine.

[00:02:22] What it means is that all, ultimately they ended up. Coming from one machine, right? So there's an IP address of that machine. That's attacking my clients or are attacking my machines. That just happens all the time. A lot of scans, but some definite attacks where they're trying to log in using SSH.

[00:02:42] And what I found is these were coming from Slovakia, Russia, and Iran. Kind of what you were expecting, right? The Iranians, they just haven't given up yet. They keep trying to attack, particularly our military in our industry. One of the things we found out this week from, again, this was an FBI notice is that the Russians have been going after our industrial base.

[00:03:09] And that includes, in fact, it's more specifically our automobile manufacturers we've already got problems, right? Try buying a new car, try buying parts. I was with my friend, just this. I helped them because he had his car right. Need to get picked up. So I took him over to pick up his car and we chatted a little bit with this small independent automotive repair shop.

[00:03:34] And they were telling us that they're getting sometimes six, eight week delays on getting parts and some parts. They just can't. So they're going to everything from junkyards on out, and the worst parts are the parts, the official parts from the car manufacturers. So what's been happening is Russia apparently has been hacking into these various automobile manufacturers and automobile parts manufacturers.

[00:04:03] And once they're inside, they've been putting in. A remote control button net. And those botnets now have the ability to wake up when they want them to wake up. And then once they've woken up, what do they do? Who knows? They've been busy erasing machines causing nothing, but having they've been doing all kinds of stuff in the past today, they're sitting there.

[00:04:24] Which makes you think they're waiting, it's accumulate as much as you possibly can. And then once you've got it all accumulated go ahead and attack. So they could control thousands of machines, but they're not just in the U S it's automobile manufacturers in Japan. That we found out about.

[00:04:44] So that's what they're doing right now. So you've got the kind of that front end and back end protections. So we're going to talk a little bit about the back end. What does that mean? When a cybersecurity guy talks about the backend and the protections. I got it up on my green right now, but here's the things you can do.

[00:05:03] Okay. Remember, small businesses are just getting nailed from these guys, because again, they're fairly easy targets. One change your passwords, right? How many times do we have to say that? And yet about 70% of businesses out there are not using a good password methodology. If you want more information on passwords, two factor authentication, you name it.

[00:05:30] Just email me M e@craigpeterson.com. I want to get the information out now. You got to make sure that all of the passwords on your systems are encrypted are stored in some sort of a good password vault as you really should be looking at 256 bit encryption or better. I have a vendor of. That I use. So if you get my emails every week, when them, there's the little training.

[00:05:59] And so I'll give you a five minute training. It's written usually it's in bullet point for, I'm just trying to help you understand things. That provider of mine has a big database and there's another provider that I use that is for. So the training guys use the database of my provider.

[00:06:20] In using that database, they're storing the passwords and the training providers putting passwords in the clinics. Into the database, which is absolutely crazy. So again, if you're a business, if you're storing any sort of personal information, particularly passwords, make sure that you're using good encryption and your S what's called salting the hash, which means.

[00:06:46] You're not really storing the password, just joining assaulted hash. I can send you more on this. If you are a business and you're developing software that's, this is long tail stuff here. Configure all of the security password settings so that if someone's trying to log in and is failing that, and you block it, many of us that let's say you're a small business.

[00:07:08] I see this all of the time. Okay. You're not to blame. You, but you have a firewall that came from the cable company. Maybe you bought it at a big box retailer. Maybe you bought it online over at Amazon, as hurricane really great for you. Has it got settings on there that lets you say. There's 20 attempts to log in.

[00:07:31] Maybe we should stop them. Now, what we do personally for our customers is typically we'll block them at somewhere around three or four failed attempts and then their passwords block. Now you can configure that sort of thing. If you're using. Email. And that's an important thing to do. Let me tell you, because we've had some huge breaches due to email, like Microsoft email and passwords and people logging in and stealing stuff.

[00:07:59] It was just a total nightmare for the entire industry last year, but limit the number of login retries as well as you're in there. These excessive login attempts or whatever you want to define it as needs to lock the account. And what that means is even if they have the right password, they can't get in and you have to use an administrative password in order to get in.

[00:08:25] You also want to, what's called throttle, the rate of repeated logins. Now you might've gotten caught on this, right? You went to your bank, you went to E-bay, you went to any of these places and all of a sudden. And denied you write it blocked you. That can happen when your account is on these hackers lists.

[00:08:45] You remember last week we talked about password spraying while that's a very big deal and hackers are doing the sprain trick all of the time, and that is causing you to get locked out of your own account. So if you do get locked out, remember it might be because someone's trying to break. Obviously you have to enforce the policies.

[00:09:09] The capture is a very good thing. Again, this is more for software developer. We always recommend that you use multifactor or two factor authentication. Okay. Do not use your SMS, your text messages for that, where they'll send you a text message to verify who you are. If you can avoid that, you're much better off.

[00:09:30] Cause there's some easy ways to get around that for hackers that are determined. Okay. A multi-factor again, installed an intrusion. system. We put right at the network edge and between workstations and servers, even inside the network, we put detection systems that look for intrusion attempts and block intrusion attempts.

[00:09:56] A very important use denied lists to block known attackers. We build them automatically. We use some of the higher end Cisco gates. Cisco is a big network provider. They have some of the best hardware and software out there, and you have to subscribe to a lot of people complain. I ain't going to just go buy a firewall for 200 bucks on Amazon.

[00:10:18] Why would I pay that much a month just to to have a Cisco firewall? And it's like praying pain for the brand. I've got by logo chert on here. Oh, I wouldn't pay for that. No, it's because they are automatically providing block lists that are updated by the minute sometimes. And then make sure you've got an incident response plan in place.

[00:10:44] What are you going to do when they come for you? What are you going to do? Bad boys. Bad. Stick around. We've got a lot more to talk about here as we go. I am explaining the hacks that are going on right now and what you can do as a business and an individual doubt. Protect yourself. Don't go anywhere.

[00:11:07] Now we're going to talk about prevention. What can you do an order to stop some of these attacks that are coming from Russia and from other countries, it is huge. People. Believe me, this is a very big problem. And I'm here to help.

[00:11:23] hi, I'm Craig Peter Sohn, your chief information security officer. We've reviewed a number of things that are important when it comes to your cyber security and your protection.

[00:11:37] We talked about the front end. We talked about the backend. Now we're going to talk about pure prevention and if you're watching. Online. You'll be able to see my slides as they come up, as we talk about some of this stuff and you'll find me on YouTube and you'll also find me on rumble, a fairly new platform out there platform that doesn't censor you for the things you say.

[00:12:01] Okay. So here we go. First of all, enabling your active directory password protection is going to. Four's password protection all the way through your business. Now I've had some discussions with people over the months, over the years about this whole thing and what should be done, what can be done, what cannot be done.

[00:12:26] Hey, it's a very big deal when it comes to password protection and actor directory, believe it or not, even though it's a Microsoft product is pretty darn good at a few things. One of them is. Controlling all the machines and the devices. One of the things we do is we use an MDM or what used to be a mobile device manager called mass 360.

[00:12:51] It's available from IBM. We have a special version of that allows us as a managed security services provider to be able to control everything on people's machines. Active directory is something you should seriously consider. If you are a Mac based shop. Like I am. In fact, I'm sitting right now in front of two max that I'm using right now, you'll find that active directory is a little bit iffy.

[00:13:21] Sometimes for max, there are some work around and it's gotten better mastery. 60 is absolutely the way to go, but make sure you've got really good. Passwords and the types of passwords that are most prone to sprain the attacks are the ones you should be banning specifically. Remember the website? Have I been poned?

[00:13:45] Yeah. It's something that you should go to pretty frequently. And again, if you miss anything today, just email me M e@craigpeterson.com. Believe me, I am not going to harass you at all. Okay. Now, the next thing that you should be doing is what's called red team blue team. Now the red team is a group of people, usually outside of your organization.

[00:14:11] If you're a big company they're probably inside, but the red team is the team that attacks you. They're white hat hackers, who are attacking you, looking for vulnerabilities, looking for things that you should or shouldn't be doing. And then the blue team is the side that's trying to defend. So think of, like war games.

[00:14:29] Remember that movie with Matthew Broderick all of those decades ago and how the, he was trying to defend that computer was trying to defend that it moved into an attack mode, right? Red team's attack, blue team is defend. So you want. To conduct simulated attacks. Now w conducting these attacks include saying, oh my let's now put in place and execute our plan here for what are we going to do once we have a.

[00:15:01] And you darn well better have a breach plan in place. So that's one of the things that we help as a fractional chief information security officer for companies, right? You've got to get that in place and you have to conduct these simulated attacks and you have to do penetration testing, including password spraying attacks.

[00:15:21] There's so many things you can do. The one of the things that we like to do and that you might want to do, whether you're a home user, retiree or a business is go and look online, you can just use Google. I use far more advanced tools, but you can use Google and look for your email address right there.

[00:15:40] Look for the names of people inside your organization. And then say wait a minute, does that data actually need to be there? Or am I really exposing the company exposing people's information that shouldn't be out there because you remember the hackers. One of the things they do is they fish you fish as in pH.

[00:16:04] So they'll send you an email that looks like. Hey let me see. I know that Mary is the CFO, and I know that Joe's going to be out of town for two weeks in The Bahamas, not a touch. So while he's got. I'm going to send an email to Mary, to get her to do something, to transfer the company's funds to me.

[00:16:23] Okay. So that's what that's all about. You've got to make sure, where is our information? And if you go to my company's page, mainstream.net, you'll see on there that I don't list any of the officers or any of the people that are in the company, because that again is a security problem.

[00:16:41] We're letting them know. I go to some of these sites, like professional sites lawyers, doctors, countenance, and I find right there all, are there people right there top people or sometimes all of them. And then we'll say, yeah, I went to McGill university, went to Harvard, whatever my B. It's all there. So now they've got great information to fish you, to fish that company, because all they have to do is send an email to say, Hey, you remember me?

[00:17:13] We're in Harvard when this class together. And did you have as a professor to see how that works? Okay. You also want to make. That you implement, what's called a passwordless user agent, and this is just so solely effective. If they cannot get into your count, what's going to, what could possibly go wrong, but one of the ways to not allow them into the count is to use.

[00:17:41] Biometrics. We use something called duo and we have that tied into the single sign-on and the duo single sign-on works great because what it does now is I put in, I go to a site, I put it into my username and. Pulls up a special splash page that is running on one of our servers. That again asks me for my duo username.

[00:18:04] So I've got my username for the site then to my dual username and my duo password single sign on. And then it sends me. To an app on my smart device, a request saying, Hey, are you trying to log into Microsoft? And w whatever it might be at Microsoft, and you can say yes or no, and it uses biometric.

[00:18:27] So those biometrics now are great because it says, oh, okay, I need a face ID or I need a thumb print, whatever it might be that allows a generalized, a password, less access. Okay. Password less. Meaning no pass. So those are some of the top things you can do when it comes to prevention. And if you use those, they're never going to be able to get at your data because it's something you have along with something, it works great.

[00:19:02] And we like to do this. Some customers. I don't like to go through those hoops of the single sign-on and using duo and making that all work right where we're fine with it. We've got to keep ourselves, at least as secure as the DOD regulations require unlike almost anybody else in industry, I'm not going to brag about it.

[00:19:26] But some of our clients don't like to meet the tightest of controls. And so sometimes they don't. I hate to say that, but they just don't and it's a fine line between. Getting your work done and being secure, but I think there's some compromises it can be readily made. We're going to talk next about saving your data from ransomware and the newest ransomware.

[00:19:53] We're going to talk about the third generation. That's out there right now. Ransomware, it's getting crazy. Let me tell ya and what it's doing to us and what you can do. What is a good backup that has changed over the last 12 months? It's changed a lot. I used to preach 3, 2, 1. There's a new sheriff in town.

[00:20:15] Stick around Craig peterson.com.

[00:20:19] 3, 2, 1 that used to be the standard, the gold standard for backing up. It is no longer the case with now the third generation of ransomware. You should be doing something even better. And we'll talk about it now.

[00:20:36] We're doing this as a simulcast here. It's on YouTube. It is also on rumble.

[00:20:43] It's on my website@craigpeterson.com because we're going through the things that you can do, particularly if you're a business. To stop the Russian invasion because as we've been warned again and again, the Russians are after us and our data. So if you missed part of what we're talking about today, or.

[00:21:07] Last week show, make sure you send me an email. me@craigpeterson.com. This is the information you need. If you are responsible in any way for computers, that means in your home, right? Certainly in businesses, because what I'm trying to do is help and save those small businesses that just can't afford to have full-time.

[00:21:31] True cyber security personnel on site. So that's what the whole fractional chief information security officer thing is about. Because you just, you can't possibly afford it. And believe me, that guy that comes in to fix your computers is no cyber security expert. These people that are attacking our full time cybersecurity experts in the coming from every country in the world, including the coming from the us.

[00:22:01] We just had more arrests last week. So let's talk about ransomware correctly. Ransomware, very big problem. Been around a long time. The first version of ransomware was software got onto your computer through some mechanism, and then you had that red screen. We've all seen that red screen and it says, Hey, pay up buddy.

[00:22:23] It says here you need to send so many Bitcoin or a fraction of a Bitcoin or so many dollars worth of Bitcoin. To this Bitcoin wallet. And if you need any help, you can send email here or do a live chat. They're very sophisticated. We should talk about it some more. At some point that was one generation.

[00:22:45] One generation two was not everybody was paying the ransoms. So what did they do at that point? They said let me see if they, we can ransom the data by encrypting it and having them pay us to get it back. 50% of the time issue got all your data back. Okay. Not very often. Not often enough that's for sure.

[00:23:05] Or what we could do is let's steal some of their intellectual property. Let's steal some of their data, their social security number, their bank, account numbers, et cetera. They're in a, in an Excel spreadsheet on their company. And then we'll, if they don't pay that first ransom, we'll tell them if they don't pay up, we'll release their information.

[00:23:26] Sometimes you'll pay that first ransom and then they will hold you ransom a second time, pretending to be a different group of cyber terrorists. Okay. Number three, round three is what we're seeing right now. And this is what's coming from Russia, nears, everything we can tell. And that is. They are erasing our machines.

[00:23:48] Totally erasing them are pretty sophisticated ways of erasing it as well, so that it sinks in really, it's impossible to recover. It's sophisticated in that it, it doesn't delete some key registry entries until right at the very end and then reboots and computer. And of course, there's. Computer left to reboot, right?

[00:24:11] It's lost everything off of that hard drive or SSD, whatever your boot devices. So let's talk about the best ways here to do some of this backup and saving your data from ransomware. Now you need to use offsite disconnected. Backups, no question about it. So let's talk about what's been happening.

[00:24:34] Hospitals, businesses, police departments, schools, they've all been hit, right? And these ransomware attacks are usually started by a person. I'll link in an email. Now this is a poison link. Most of the time, it used to be a little bit more where it was a word document, an Excel document that had something nasty inside Microsoft, as I've said, many times has truly pulled up their socks.

[00:25:02] Okay. So it doesn't happen as much as it used to. Plus with malware defender turned on in your windows operating system. You're going to be a little bit safer next step. A program tries to run. Okay. And it effectively denies access to all of that data. Because it's encrypted it. And then usually what it does so that your computer still works.

[00:25:26] Is it encrypts all of you, like your word docs, your Excel docs, your databases, right? Oh, the stuff that matters. And once they've got all of that encrypted, you can't really access it. Yeah. The files there, but it looks like trash now. There's new disturbing trends. It has really developed over the last few months.

[00:25:48] So in addition to encrypting your PC, it can now encrypt an entire network and all mounted drives, even drives that are marrying cloud services. Remember this, everybody, this is really a big deal because what will happen here is if you have let's say you've got an old driver G drive or some drive mounted off of your network.

[00:26:14] You have access to it from your computer, right? Yeah. You click on that drive. And now you're in there and in the windows side Unix and max are a little different, but the same general idea you have access to you have right. Access to it. So what they'll do is any mounted drive, like those network drives is going to get encrypted, but the same thing is true.

[00:26:36] If you are attaching a U S B drive to your company, So that USB drive, now that has your backup on it gets encrypted. So if your network is being used to back up, and if you have a thumb drive a USB drive, it's not really a thumb drive, right? There's external drive, but countered by USP hooked up.

[00:27:02] And that's where your backup lives. Your. Because you have lost it. And there have been some pieces of software that have done that for awhile. Yeah. When they can encrypt your network drive, it is really going after all whole bunch of people, because everyone that's using that network drive is now effective, and it is absolutely.

[00:27:27] Devastating. So the best way to do this is you. Obviously you do a bit of a local backup. We will usually put a server at the client's site that is used as a backup destiny. Okay. So that servers, the destination, all of the stuff gets backed up there. It's encrypted. It's not on the network per se. It's using a special encrypted protocol between each machine and the backup server. And then that backup servers data gets pushed off site. Some of our clients, we even go so far as to push it. To a tape drive, which is really important too, because now you have something physical that is by the way, encrypted that cannot be accessed by the attacker.

[00:28:20] It's offsite. So we have our own data center. The, we run the, we manage the no one else has access to it is ours. And we push all of those backups offsite to our data center, which gives us another advantage. If a machine crashes badly, right? The hard disk fails heaven forbid they get ransomware. We've never had that happen to one of our clients.

[00:28:46] Just we've had it happen prior to them becoming clients, is that we can now restore. That machine either virtually in the cloud, or we can restore it right onto a piece of hardware and have them up and running in four hours. It can really be that fast, but it's obviously more expensive than in some.

[00:29:08] Are looking to pay. All right, stick around. We've got more to talk about when we come back and what are the Russians doing? How can you protect your small business? If you're a one, man, one woman operation, believe it. You've got to do this as well. Or you could lose everything. In fact, I think our small guys have even more to lose Craig peterson.com.

[00:29:32] Backups are important. And we're going to talk about the different types of backups right now, what you should be doing, whether you're a one person, little business, or you are a, multi-national obviously a scale matters.

[00:29:47] Protecting your data is one of the most important things you can possibly do.

[00:29:53] I have clients who had their entire operating account emptied out, completely emptied. It's just amazing. I've had people pay. A lot of money to hackers to try and get data back. And I go back to this one lady over in Eastern Europe who built a company out of $45 million. By herself. And of course you probably heard about the shark tank people, right?

[00:30:23] Barbara Cochran, how she almost lost $400,000 to a hacker. In fact, the money was on its way when she noticed what was going on and was able to stop it. So thank goodness she was able to stop it. But she was aware of these problems was looking for the potential and was able to catch it. How many of us are paying that much attention?

[00:30:50] And now one of the things you can do that will usually kind of protect you from some of the worst outcomes. And when it comes to ransomware is to backup. And I know everybody says, yeah, I'm backing up. It's really rare. When we go in and we find a company has been backing up properly, it even happens to us sometimes.

[00:31:15] We put them back up regimen in place and things seem to be going well, but then when you need the backup, oh my gosh, we just had this happen a couple of weeks ago. Actually this last week, this is what happened. We have. Something called an FMC, which is a controller from Cisco that actually controls firewalls in our customer's locations.

[00:31:42] This is a big machine. It monitors stuff. It's tied into this ice server, which is. Looking for nastiness and we're bad guys trying to break in, right? It's intrusion detection and prevention and tying it into this massive network of a billion data points a day that Cisco manages. Okay. It's absolutely huge.

[00:32:05] And we're running it in a virtual machine network. So we. Two big blade. Chassies full of blades and blades are each blade is a computer. So it has multiple CPU's and has a whole bunch of memory. It also has in there storage and we're using something that VMware calls visa. So it's a little virtual storage area network.

[00:32:32] That's located inside this chassis and there are multiple copies of everything. So if a storage unit fails, you're still, okay. Everything stays up, it keeps running. And we have it set up so that there's redundancy on pond redundancy. One of the redundancies was to back it up to a file server that we have that's running ZFS, which is phenomenal.

[00:32:56] Let me tell you, it is the best file system out there I've never ever had a problem with it. It's just crazy. I can send you more information. If you ever interested, just email me@craigpeterson.com. Anytime. Be glad to send you the open source information, whatever you need. But what had happened is.

[00:33:13] Somehow the boot disk of that FMC, that, that firewall controller had been corrupted. So we thought, oh, okay, no problem. Let's look at our backups. Yeah, hadn't backed up since October, 2019. Yeah, and we didn't know it had been silently failing. Obviously we're putting stuff in place to stop that from ever happening again.

[00:33:43] So we are monitoring the backups, the, that network. Of desks that was making up that storage area network that had the redundancy failed because the machine itself, somehow corrupted its file system, ext four file system right then are supposed to be corruptible, but the journal was messed up and it was man, what a headache.

[00:34:07] And so they thought, okay, you're going to have to re-install. And we were sitting there saying, oh, you're kidding me. Reinstalling this FMC controller means we've got to configure our clients, firewalls that are being controlled from this FMC, all of their networks, all of their devices. We had to put it out.

[00:34:23] This is going to take a couple of weeks. So because I've been doing this for so long. I was able to boot up an optics desk and Mount the file system and go in manually underneath the whole FMC, this whole firewall controller and make repairs to it. Got it repaired, and then got it back online. So thank goodness for that.

[00:34:49] It happens to the best of us, but I have to say I have never had a new client where they had good backups. Ever. Okay. That, and now that should tell you something. So if you are a business, a small business, whatever it might be, check your backups, double check them. Now, when we're running backups, we do a couple of things.

[00:35:14] We go ahead and make sure the backup is good. So remember I mentioned that we have. Backup server that sits onsite. Usually it depends on the size of the client. But sits onsite at the client's site. So it will perform the backup and then tries to actual restore of that backup to make sure it's good.

[00:35:35] And we can even. Client, depending on what they want. So a higher level, if a machine goes down, let's say it catches fire, or disk explodes in it, or completely fails. We can actually bring that machine online inside our backup server or the customer. Yeah, how's that for fancy and bring it back online in just a matter of minutes instead of days or weeks.

[00:36:04] So that's true too. If that machine had been a ransom had this data, you raised whatever might've happened to it. We can restore it now. We've never had to knock on wood, except when there was a physical problem with the machine and as. Starting from scratching it, that machine, the new machine online in four hours or less.

[00:36:28] And it's really cool the way it works. If you like this stuff, man, it is great. Okay. Protecting your data. I'm rambling a little bit here. You need an archival service there's companies out there like iron mountain, you can at your local bank, depending on the bank. It ain't like it used to be, get a box, right?

[00:36:50] A special box in the vault that you. The tapes and other things in nowadays there's cloud options, virtual tape backup options, which is a lot of what we use and we do. Okay. We also use straight cloud at the very bottom end again. It's not located on the network. It's up in the cloud. It's double encrypted.

[00:37:13] It's absolutely the way to do now if you're going to have a backup and if that backup, you want to be secure, it must not be accessible. To the attacker, you've got to put some literal air space between your backups and the cyber criminals. It's called an air gap. So there's no way for them to get to it.

[00:37:37] Okay. Now I want you to consider seriously using tape these a LTO. These linear tape drives. They've been around for a long time, but their cartridges you can pull in and out. And they're huge. They they're physically small, but they can hold terabytes worth of data. They're absolutely amazing. There's some great disk based backup systems as what we do.

[00:38:02] Some of them are been around a long time and they can be quite reasonably. Price. All right. So it's something for you to consider, but you've got to have at least that air gap in order to make sure that you're going to be protected. What should you be looking for in a backup system? This is called 3, 2, 2 1, which means maintain at least three copies of your data store the backups on two different meters.

[00:38:31] Store at least one of the copies at an offsite location store, at least one of the copies offline, and be sure to have verified backups without air. Okay. Does that sound a little complicated? 3, 2, 1, 1 0 is what it's called. Just to be 3, 2, 1. Now it's 3, 2, 1, 1 0. I can send you Karen put together a special report on this based on our research.

[00:38:57] And I can share that with you. Absolutely free. Hey guys, if you want it, you got it. But you got to ask me, just email me M e@craigpeterson.com. This is absolutely essential. If you're a small business, a tiny business to do it this way. Let me tell you, okay, this is just huge. Physical backups should be stored off site.

[00:39:19] I mentioned the bank fault. A lot of people just go ahead and take them home with. That might be a desk. It might be a tape. It can be a little bit complicated to do. And I've picked up customers that thought they were backing up. They were using a USB drive. They were putting it in due to flee every Monday.

[00:39:41] And then every Wednesday, what happened? Every Wednesday they bring in Wednesdays desk and then they bring that disc home and then Thursday, they bring in the Thursday disc. And none of them had been working. Okay. So be very careful. All of your backups should be encrypted. We encrypted at the customer site and then we reencrypt it when we bring it over to us.

[00:40:06] Okay. Keys are essential. Particularly if you're using a cloud-based backup, don't use the same keys across multiple backups. Very important there. You should have some good procedures that are well-documented test, test your restores because very frequently. We find they don't work. In fact, that's the number one problem, right?

[00:40:30] If they had just tried to restore, even once from their backup, they would've known they had problems. And get those backups scheduled on a regular schedule. Okay. So there's a lot more offline backups and more that we can talk about another time, but this is important. If you want any help, send me an email, just put backups in the subject line.

[00:40:55] I'll send you some stuff. Email me, M e@craigpeterson.com. Now I am more than glad to help. Pretty much anybody out there. I'm not going to help. What about blah, blah, Amir Putin. But anybody else I'll help, but you got to reach out. Okay. You listen here. And I know some of this stuff is over some of our heads, some of your heads, you're the best and brightest.

[00:41:20] That's why you're listening and I'll help you out. I'll send you some information. That's going to get you on the right track. Me M e@craigpeterson.com. That's Craig Peterson, S O N have a great day.

[00:41:35] We just got an email this week from a customer and they're saying, oh no, my email has been hacked. What does that mean was a really hacked, we're going to talk right now about email spoofing, which is a very big deal.

[00:41:51] Emails spoofing is being a problem for a long time, really? Since the 1970s. I remember when I got my first spoofed email back in the eighties and they was really a little bit confusing.

[00:42:05] I went into it more detail, of course, being a very technical kind of guy and looked behind the curtains, figured out what was going on. Just shook my head. I marveled at some people. Why would you do this sort of thing? The whole idea behind email spoofing is for you to receive an email, looks like it's from someone that it's not now, you've all seen examples of this.

[00:42:30] Everybody has. And those emails that are supposedly from the bank, or maybe from Amazon or some other type of business or family friend, this is part of what we call social engineering, where the bad guys are using a little bit about what they know about you, or maybe another person in order to. Frankly, fool you.

[00:42:54] That's what spoofing really is. There were a lot of email accounts that were hacked over the last what, 30, 40 years. And you might remember this people sending out an email saying, oh, my account got hacked because you just got emails. Back in the day, what people were trying to do is break into people's email accounts and then the bad guys after having broken in now knew everybody that was in the contact list from the account that was just broken into.

[00:43:29] Now they know, Hey, listen, this person sends an email. Maybe I can just pretend I'm them. Days it, the same thing still happens. But now typically what you're seeing is a more directed attack. So a person might even look in that email account that they've broken into and poke around a little bit and find out, oh, okay.

[00:43:52] So this person's account I just broken to is a purchasing manager at a big. So then they take the next step or maybe this tab after that and try and figure out. Okay, so now what do I do? Oh, okay. So really what I can do now is send fake purchase orders or send fake requests for money. I've seen in the past with clients that we've picked up because the email was acting strangely where a bad guy went ahead, found.

[00:44:25] Invoices that have been sent out by the purchasing person and the send the invoices out and changed the pay to information on the invoice. So they took the PDFs that they found on the file server of the invoices went in and changed them, change the account that they wanted, the funds ACH into. And once they had that happen, they just sent the invoice out again saying overdue.

[00:44:54] Off goes in the email and the company receives it and says, oh okay, I need to pay this invoice. Now. Sometimes it marked them overdue. Sometimes they didn't mark them overdue. I've seen both cases and now the money gets sent off and that invoice gets paid and then gets paid to the wrong person.

[00:45:13] Or maybe they go ahead and they don't send the invoice out, but they just send a little notification saying, Hey, our account has changed. Make sure you. Direct all future payments to this account. Instead. Now you might be thinking wait a second here. Now they send this email out. It's going to go into a bank account.

[00:45:33] I can recover the money while no, you can't. Because what they're doing is they are using mules. Now you've heard of meals before. He might've even seen that recent Clint Eastwood movie. I think it was called. But typically when we think of mules, as people we're thinking about people who are running drugs well, in this case, the bad guys use mules in order to move money around.

[00:45:59] And now sometimes the people know what they're doing. The FBI has had some really great arrests of some people who were doing this, particularly out in California, some of them cleaned. Yeah. I didn't know what was happening. It was just somebody, asked me to send money. It's like the Nigerian scam where the Nigeria in the Nigerian scam, they say, Hey I'm, I'm Nigerian prince, you've heard of these things before. And I need to get my money out of the country. I need to place to put them. And so if you have a us account, I'm going to transfer money into it. You can keep a thousand dollars of that 5,000 and I'm going to wire in just as a fee. Thanks for doing this. I, this is so important and it's such a hurry and I'm going to send you the.

[00:46:46] What they'll often do is send you a money order. It couldn't be a bank check, could be a lot of things, and then you go ahead and you cash it and oh, okay. Or cash just fine. And then you wire the $4,000 off to the bad guy. The bad guy gets the money and is off. Running in the meantime, your bank is trying to clear that bank check or that money order.

[00:47:14] And they find out that there is no money there because frankly what might've happened? I, this is one I've seen, I'm telling you about a story w we helped to solve this problem, but I had taken out a real money order from a bank, and then they made copies of it. Basically, they just forged it. And so they forged a hundred copies of it.

[00:47:36] So people thought they were getting a legitimate money order. And in some cases, the banks where the money order was, you mean deposited, did conf confirm it? They called up the source bank. Oh yeah. Yeah. That's a legit money order and then they all hit within a week or two. And now the, you are left holding the bag.

[00:47:58] So that's one thing that happens. But typically with these mules, the money comes to them in that account. They are supposed to then take that money and put it in their PayPal account and send it off to the next. And it might try jump to through two or three different people, and then it ends up overseas and the bad guys have gotten so good at this and have the cooperation of some small countries, sometimes bigger countries that they actually own.

[00:48:30] The bank overseas of the money ultimately gets transferred into. And of course there's no way to get the money back. It's a real. So with spoofing, they're trying to trick you into believing the emails from someone that you know, or someone that you can trust. Or as I said, maybe a business partner of some sort in most cases, it's some sort of a colleague, a vendor or a trusted brand.

[00:48:58] And so they exploit the trust that you have, and they ask you to do something or divulge information. They'll try and get you to do something. So there's more complexity tax. Like the ones that I just explained here that are going after financial employees, there might be some, an accountant, a bookkeeper, or bill payer and receivables payables.

[00:49:24] I've seen CFO attacks, but the really the spoofed email message looks legitimate on the surface. They'll use the legitimate logo of the company that they're trying to pretend that they're from. For instance, PayPal. Phishing attack. They have a spoofed email sender and typical email clients like you might be using for instance, on Microsoft outlook.

[00:49:48] The sender address is shown on the message, but most of the time nowadays the mail clients hide the actual email address, or if you just glance at it, it looks legit. You've seen those before these forged email headers. Yeah, it gets to be a problem. Now we use some software from Cisco that we buy.

[00:50:13] You have to buy. I think it's a thousand licenses at a time, but there were some others out there, Cisco again, by far the best and this, the software. Receives the email. So before it even ends up in the exchange server or somewhere else online, that email then goes through that Cisco server. They are comparing it to billions of other emails that they've seen, including in real time emails that are.

[00:50:41] Right now. And they'll look at the header of the email message. You can do that as well. With any email client, you can look at the header, Microsoft and outlook calls, it view source. But if you look at the email header, you'll see received. Headers that are in there. So say, receive colon from, and they'll give a name of a domain and then you'll see another received header and give another name of a machine.

[00:51:08] And it'll include the IP address might be IVF IPV four of your six, and you can then follow it all the way through. So what'll happen is partway through. You'll see, it took a hop that is. Not legitimate. That's where it comes in. Nowadays, if you have an email address for your business, man, a domain, you need to be publishing what are called SPF records.

[00:51:37] And those SPF records are looked at there compared to make sure that the email is properly signed and is from. The correct sender. There's a SPF records. There's a mother's too, that you should have in place, but you'll see that in the headers, if you're looking in the header. So it gets pretty complicated.

[00:51:59] The SPF, which is the sender policy framework is a security protocol standard. It's been around now for almost a decade. It's working in conjunction with what are called domain based message, authentication, reporting, and conformance. Heather's D mark headers to stop malware and phishing attacks. And they are very good if you use them properly, but unfortunately when I look, I would say it's still 95% of emails that are being sent by businesses are not using this email spoofing and protection.

[00:52:35] So have a look at that and I can send you a couple articles on it. If you're in trusted Craig Peter sohn.com.

[00:52:46] So we've established that email spoofing happens. What are the stats to this? And how can you further protect yourself from email spoofing? Particularly if you're not the technical type controlling DNS records, that's what's up right.

[00:53:02] Everybody Craig Peter sawn here, your cybersecurity strategist. And you're listening to news radio, w G a N a M five 60 and 98.5 FM. Join me on the morning. Drive Wednesday mornings at 7 34. Of course in the am. There's so much going on in the cybersecurity world. It affects all of us. Now, I think back to the good old days 40 years ago where we weren't worried about a lot of this stuff, spoofing, et cetera.

[00:53:36] But what we're talking about right now is 3.1 billion domain spoof. Emails sent every day. That's a huge thing. More than 90% of cyber attacks. Start with an email message. Email spoofing and phishing have had a worldwide impact costing probably $26 billion over the last five years. A couple of years ago, the FBI, this is 2019.

[00:54:07] Reported that about a house. A million cyber attacks were successful. 24% of them were email-based and the average scam tricked users out of $75,000. Yeah. So it's no wonder so many people are concerned about their email and whether or not those pieces of email are really a problem for them. And then anybody else.

[00:54:34] So a common attack that uses spoofing is CEO fraud, also known as business, email compromise. So this is where the attacker is spoofing or modifying, pretending to be a certain person that they're not they're impersonating an executive or owner, maybe of a business. And it targets. People in the financial accounting or accounts payable departments or even the engineering department.

[00:55:01] And that's what happened with one of our clients this week. They got a very interesting spoofed email. So even when you're smart and you're paying attention, you can be tricked the Canadian city treasurer. Tricked into transferring a hundred grand from taxpayer funds, Mattel tricked into sending 3 million to an accountant, China, a bank in Belgium, tricked into sending the attackers 70 million Euro.

[00:55:31] It happens and I have seen it personally with many businesses out there. So how do you protect yourself from email? Spoofing now, even with email security in place, there's some malicious email messages that are still going to get through to the inboxes. Now we're able to stop better than 96% of them just based on our stats.

[00:55:54] In fact, it's very rare that one gets through, but here are some things you can do and watch out for whether you're an employee responsible for financial decisions, or maybe you're someone who is. Personal email at work. Here's some tricks here. So get your pencil ready. Number one, never click links to access a web.

[00:56:19] Where you're asked to log in, always type in the official URL into your browser and authenticate on the browser. In other words, if you get an email from your bank or someone else, and there's a link in there to click that says, Hey oh man, here's some real problems. You got to respond right away.

[00:56:42] Don't do that go to paypal.com or your bank or your vendor's site, just type it into your browser, even though you can hover over the email link and see what it is. Sometimes it can be perfectly legitimate and yet it looks weird. For instance, when I send out my emails that people subscribe to that right there on Craig peterson.com, the links are going to come from the people that handle my email lists for me, because I send out thousands of emails at a time to people that have asked to get those emails.

[00:57:22] So I use a service and the services taking those links, modifying them somewhat in fact dramatically. And using that to make sure the delivery happened, people are opening it and that I'm not bothering you. So you can unsubscribe next step. You can, if you want to dig in more, look at the email headers.

[00:57:45] Now they're different for every email client. If you're using outlook, you have to select the email, basically in the left-hand side. Okay. You're going to control, click on that email and we'll come up and you'll see something that says view source. So in the outlook world, they hide it from you.

[00:58:06] If you're using a Mac and Mac mail, all you have to do is go to up in the menu bar email and view, header and cut off. There it is. I have many times in the past just left that turned on. So I'm always seeing the headers that reminds me to keep a look at those headers. So if you look in the header, And if the email sender is let me put it this way.

[00:58:31] If the person who is supposed to have sent it to you is doing headers proper, properly. You're going to see. A received SPF section of the headers and right in there, you can look for a pass or fail and response, and that'll tell you if it's legit. So in other words, let's use PayPal as an example, PayPal has these records that it publishes that say all of our emails are going to come from this server or that server of.

[00:59:04] And I do the same thing for my domains and we do the same thing for our clients domains. So it's something that you can really count on if you're doing it right, that this section of the headers. And that's why I was talking about earlier. If you have an email that your sending out from your domain and you don't have those proper headers in it, there's no way.

[00:59:31] To truly authenticate it. Now I go a step further and I use GPG in order to sign most of my emails. Now I don't do this for the trainings and other things, but direct personal emails from me will usually be cryptographically signed. So you can verify that it was me that sent it. Another thing you can do is copy and paste the text, the body of that email into a search engine.

[01:00:03] Of course I recommend duck go in most cases. And the chances are that frankly they've sent it to multiple people. That's why I was saying our Cisco based email filter. That's what it does, it looks for common portions of the body for emails that are known to be bad, be suspicious of email from official sources like the IRS, they're not going to be sending you email out of the blue most places. Aren't obviously don't open attachments from people that you don't. Special suspicious ones, particularly people we'll send PDFs that are infected. It's been a real problem. They'll send of course word docs, Excel docs, et cetera, as well.

[01:00:54] And the more. I have a sense of urgency or danger. That's a part of the email should really get your suspicions up, frankly, because suggesting something bad is going to happen. If you don't act quickly, that kind of gets around part of your brain and it's the fight or flight, right? Hey, I gotta take care of this.

[01:01:17] I gotta take care of this right away. Ah, and maybe you. So those are the main things that you can pay attention to. In the emails, if you are a tech person, and you're trying to figure this out, how can I make the emails safer for our company? You can always drop me an email as well. Me, M e@craigpeterson.com.

[01:01:43] I can send you to a couple of good sources. I'll have to put together a training as well on how to do this, but as individually. At least from my standpoint, a lot of this is common sense and unfortunately the bad guys have made it. So email is something we can no longer completely trust. Spoofing is a problem.

[01:02:05] As I said, we just saw it again this week. Thank goodness. It was all caught and stopped. The account was not. It was just a spoofed email from an account outside the organization that was act Craig peterson.com. Stick around.

[01:02:24] The value of crypto coins has been going down lately quite a bit across the board, not just Bitcoin, but the amount of crypto mining and crypto jacking going on. That hasn't gone down much at all.

[01:02:48] hi, I'm Craig Peter Sohn, your cyber security strategist. And you're listening to news radio, w G a N a M five 60 and FM nine. Point five, you can join me on the morning drive every Wednesday morning at 7 34, Matt and I go over some of the latest in news. You know about crypto coins, at least a little bit, right?

[01:03:15] These are the things like Bitcoin and others that are obstensively private, but in reality, aren't that private. If you receive coins and you spend coins, you are probably trackable. And if you can't spend that, the crypto currencies, why even bother getting it in the first place. One of the big drivers behind the price of these crypto currencies has been criminal activity.

[01:03:48] We've talked about that before. Here's the problem we're seeing more and more nowadays, even though the price of Bitcoin might go down 30%, which it has, and it's gone down in bigger chunks before. It does not mean that the bad guys don't want more of it. And what better way to mine, cryptocurrency then to not have to pay for.

[01:04:15] So the bad guys have been doing something called crypto jacking. This is where criminals are using really ransomware like tactics and poisoned website to get your computer, even your smartphone to mine, cryptocurrencies for. No mining, a Bitcoin can cost as much in electric bills that are in fact more in electric bills.

[01:04:43] Then you get from the value of the Bitcoin itself. So it's expensive for them to run it. Some countries like China have said, no, you're not doing it anymore because they're using so much electricity here in the U S we've even got crypto mining companies that are buying. Old power plant coal-fired or otherwise, and are generating their own electricity there locally in order to be able to mine cryptocurrencies efficiently, effectively so that they can make some profit from it.

[01:05:18] It's really quite the world out there. Some people have complained about their smartphone getting really hot. Their battery only lasts maybe an hour and it's supposed to last all day. Sometimes what's happened is your smartphone has been hijacked. It's been crypto jacked. So your smartphone, they're not designed to sit there and do heavy computing all day long.

[01:05:45] Like a workstation is even your regular desktop computer. Probably isn't. To be able to handle day long mining that has to happen. In fact, the most efficient way to do crypto mining of course is using specialized hardware, but that costs them money. So why not just crypto Jack? All right. There are two primary ways.

[01:06:09] Hackers have been getting victims, computers to secretly mine. Cryptocurrencies one is to trick them into loading. Crypto mining code onto their computers. So that's done through various types of fishing, light tactics. They get a legitimate looking email that tricks people into clicking on a link and the link runs code.

[01:06:30] Now what's interesting is you don't, even for cryptocurrency crypto jacket, you don't even have to download a program in. To have your computer start mining cryptocurrencies for the bad guys. They can use your browser to run a crypto mining script. And it runs in the background. As you work right, using up electricity, using up the CPU on your computer.

[01:06:58] They also will put it into ads. They'll put it on a website and your browser goes ahead and runs the code beautifully. So they're really trying to maximize their returns. That's the basics of crypto jacking what's been particularly bad lately has been the hackers breaking into cloud account. And then using those accounts to mine cryptocurrency, one of the trainings that I had on my Wednesday wisdoms has to do with password stuffing and my Wednesday wisdoms, you can get by just subscribing to my email over there@craigpeterson.com.

[01:07:44] But what happens here is they find your email address. They find. Password on one of these hacks that is occurred on the dark web. You weren't on the dark web, but your username or email address and password are there on the dark web. And then they just try it. So a big site like Amazon, or maybe it was your IBM also has cloud services can be sitting there running along very well, having fun.

[01:08:16] Life's good. And. Then they go ahead and try your email address and password to try and break in. Now, you know how I keep telling everybody use a good password manager and this week I actually changed my opinion on password managers. So you know, that I really like the password manager that you can get from one password.com.

[01:08:44] It really is fantastic. Particularly for businesses, various types of enterprises, one password.com. However, where I have changed is that some of these browsers nowadays, particularly thinking about Firefox Google Chrome safari, if you're particularly, if you're on a Mac, all have built in password managers that are actually.

[01:09:09] Good. Now they check. Have I been poned, which is a site I've talked to you guys about for years. To make sure that your accounts are reasonably safe than not being found on the dark web, the new password that it came up with or that you want to use. They check that as well. Make sure it's not in use. So here's an example here.

[01:09:32] This is a guy by the name of Chris. He lives out in Seattle, Washington, and he makes mobile apps for local publishers. Just this year, new year's day, he got an alert from Amazon web services. Now Amazon web services, of course, cloud service. They've got some really nice stuff, starting with light ship and going up from there, I've used various services from them for well, since they started offering the services over very many years and.

[01:10:04] They allow you to have a computer and you can get whatever size computer you want to, or fraction of a computer. You want to, he got this alert because it said that he owed more than $53,000 for a month's worth of hosts. Now his typical Amazon bill is between a hundred and 150 bucks a month. My typical Amazon bell is now 50 to maybe $80 a month.

[01:10:34] I cannot imagine getting a $53,000 bill from our friends at Amazon. So the poor guy was just totally freaking out, which is a very big deal. So I'm looking at an article from insider that you can find a business insider.com. They were able to confirm that, yes, indeed. He got this $53,000 bill from Amazon and yes, indeed.

[01:11:00] It looks like his account had been hacked by cryptocurrency miners. So these guys can run up just incredibly large charges for the raw computing power. They need to produce some of these digital cryptocurrencies, like Bitcoin there's many others out there. But this isn't new. This is happening all of the time.

[01:11:23] Google reported late last year, that 86% of account breaches on its Google cloud platform were used to perform cryptocurrency mining. So make sure you are using a good password manager that generates good passwords. And I have a special report on passwords. You can download it immediately when you sign up for.

[01:11:48] My email, my weekly email newsletter@craigpeterson.com and it tells you what to do, how to do it. What is a good password? What the thinking is because it's changed on passwords, but do that and use two factor authentication. Multi-factor authentication as well. And I talk about that in that special report too.

[01:12:11] And visit me online. Sign up right now. Craig Peter sohn.com.

[01:12:17] We're moving closer and closer to completely automated cars, but we want to talk right now about car hacks, because there was an interesting one this week that has to do with Tesla. And we'll talk about some of the other hacks on car.

[01:12:33] Connected cars are coming our way in a very big way.

[01:12:38] We just talked about the shutdown of two G and 3g in our cars. We, it wasn't really our cars, right? Two G 3g. That was for our cell phones. That was. Years ago course now for four GLTE 5g, even 10 G is being used in the labs. Right now. It's hard to think about some of those older technologies, but they were being used and they were being used by cars, primarily for the navigation features.

[01:13:13] Some cars use these data links, if you will, that are really on the cell phone network in order to do remote things like remote start. For instance, I have a friend who's Subaru. Of course was using that. And now she's got to do an upgrade on her car because that 3g technology is going away depending on the carrier, by the way, some of it's going away sooner.

[01:13:40] Some of it's going away later, but it'll all be gone at the end of 2020. What are we looking at? As we look into the future, I'm really concerned. I don't want to buy one of these new cars at the same time as I do, because they are cool, but I don't want to buy one of those because of the real problem that we could have of what well of having that car.

[01:14:07] I need an upgrade and not been able to do it. I watched a video of a guy who took a Tesla that hadn't been damaged badly in a flood, and it was able to buy it for cheap. Why? Because Tesla will not sell you new motors and a new batteries for a car like that. So he got the car for cheap. He found a Chevy Camaro that had been wrecked, but its engine and transmission were just fine.

[01:14:37] He ripped everything out of the Tesla and went ahead after that, cause you got to clean that out, and water damage. You spray wash all to the inside. He got right down to the aluminum, everything that wasn't part of the core aluminum chassis was gone. And then he built it back up again. He managed to keep all of those Tesla systems working, that, that screen that you have upfront that does the temperature control, cruise maps, everything out.

[01:15:09] He kept that it was able to work. The, automated stuff, cruise control type stuff. And now he had a very hot car that looked like a Tesla. He took it out to SEMA, which is pretty cool. I'd love to see that, but it was a Tesla with a big V8 gasoline engine in it. He's done a, quite a good job on it.

[01:15:33] It was quite amazing to see it took them months. It was him and some of his buddies. These new cars are even more connected than my friend Subaru is they get downloads from the. Some of them are using Wi-Fi and 5g. Really one of the big promises of 5g is, Hey, our cars can talk to each other because now you can get a millisecond delay in going from one car to another versus what you have today, which can be a half a second or more, which can be the difference between having a rear end collision and being able to stop in time when it comes to these automated system.

[01:16:15] So they are more connected. They connect to the wifi in your homes. They connect to obviously the 5g network, which is where things are going right now. But what's happening with the hackers because really what we're talking about, isn't a computer on wheels. Oh no. Dozens of computers inside that car and your car has a network inside of it and has had for many years, this can bus network and even fancier ones nowadays that connect all of your systems together.

[01:16:50] So your entertainment system, for instance, is connected to this network. And that was used. You might remember a couple of years ago on a Chrysler product where the bad guy installed. Or using the thumb drive onto that entertainment system and had a reporter drive that car down the road. This is all known.

[01:17:13] It was all controlled. And was able to the bad guy right there, the demonstration in this case, I guess you'd call them a white hat hacker. He drove that car right off the road while the reporter was trying to steer otherwise because cars nowadays don't have a direct linkage between anything in any.

[01:17:36] That's why I love my 1980 Mercedes TESOL. You turn the steering wheel. It isn't actually connected to the wheels to that front end of the car. All it's doing is telling the computer you want to turn and how much you want to turn that brake pedal. Doesn't actually. Compress hydraulics and cause the brakes to engage that fuel pedal doesn't actually move the throttle on the car.

[01:18:01] The throttle is really being controlled and moved by the computers. So the car is completely electronic. It feels like a regular car, right? We're not talking about the Tesla's of today or tomorrow. We're talking about Volvos that have been sold for more than a decade. We're talking about a lot of different cars.

[01:18:22] So now you have a platform on wheels that can be dangerous because it can be, in some cases, remotely controlled, it can have software that may be crashes. We know that part of the infrastructure quote, unquote bill, which contains almost no infrastructure. It's amazing how they named these things. Isn't it.

[01:18:43] And what is it like 6% it actual infrastructure and the infrastructure bill? One of the things in there that is not infrastru. Is a demand, a law that says the car manufacturers have to include a remote. Button, if you will, so that a police officer could go ahead and say, okay, I'm pursuing this car and they're not stomping.

[01:19:09] I don't want to risk people's lives. As this bad guy tries to elude me here in backstreets. Kids can get hit, et cetera. So they push the button and the car stops that all sounds great. The problem is that you could potentially be opening some security problems by having this remote stop button that can be used by anybody really right.

[01:19:38] Since when is it going to be limited to just law enforcement? Isn't that a problem? According to Caren driver, I'm looking at their magazine right now. They're saying that there were at least 150 automotive cybersecurity incidents in twenty nineteen, a hundred and fifty incidents, part of a 94% year over year increase since 2016.

[01:20:03] In other words, every year. The number of automotive, cybersecurity and incidences has doubled. And that's according to report from a company called upstream security. So we're lost. So looking at what w maybe ransomware for a car. So that your car gets hacked. You can't hack my 1980 Mercedes diesel.

[01:20:26] It is impossible to hack into an unconnected car, but if you are driving a vehicle it's likely at risk from some sort of digital true. We've even seen from some of the bugs. We've seen cars from Japan that have decided to drive into the Jersey barrier because it misunderstands exactly what it is. We've seen cars from Tesla.

[01:20:55] Drive right into the back of a parked fire truck mentioned doing that at speed, right? And cause a fire truck full of water, et cetera. I've actually seen that one happened personally. So the more sophisticated the system is, the more connected your vehicle is. The more exposed you are in Detroit free press has a great little article on that right now.

[01:21:21] And in there he's saying we have taken. Whatever model car you think of. And we hack them through various places. I can control your steering. I can shut down and start your engine. Control your brakes, your doors, your wipers, open and close your. There's a lot of people who are trying to break into these cars.

[01:21:44] And there's a lot of people who are trying to protect them. That hacker duo back in 2015, who took control of that Jeep Cherokee, just think about that sort of. There's an Israeli based automotive cybersecurity company who told the free press that he expects the current trend of hackers, holding digital data on computers for ransom to also move to cars.

[01:22:10] So when this happens, the driver will not be able to start the vehicle until they pay off the rant. Or suffer the consequences, which could be wiping the cars systems operating systems could be Kenning the car to catch on fire. Think of what can happen with each generation with those batteries.

[01:22:30] There's no way around it. You're going to have to get it towed and get all of the software reloaded in the company. And now this week, it comes out that in 19 year old kid said that he was able to hack into over 25 Teslas that he tried via a bug in a popular. It's an open source tool that people are using to link into their Teslas to do various types of remote control.

[01:22:59] And he posted a tweet on this guy's name's David Colombo. You'll find them on Twitter, went viral and he reported the vulnerability to the people who are maintaining the software and they fixed it. In fact, the very same day and Tesla also pushed updates to their vehicle. That invalidated the signatures and the key exchanges that we're having.

[01:23:26] So this is a 19 year old researcher. He's able to hack into cars in 13 countries, 38, 13 countries. Yeah. Worth of Teslas without the owner's knowledge. No, he says I, I can not. Doors, I can turn off the security system. I can open windows. I keyless start and things turn on the stereo, honk the horn view, the cars location, and if the driver was present, but he doesn't think he could actually move the vehicle remotely, but that's a 19 year old.

[01:24:00] What's going to happen when we implement the law that was just passed that says our cars have to be remotely controllable by anybody basically. Yeah. It's scary. Hey, I want to invite you guys to take a minute, go to Craig peterson.com. Make sure you sign up for my newsletter there, and I'll keep you up to date on all of this stuff and you'll even get my show notes.

[01:24:26] Craig peterson.com.

View Details

Why Is Russia Password Spraying Hurting You?
What Are They Trying to Do?
And What Is It?

This is one of the top topics I've had people ask about lately: How can you protect yourself and your business against Russian hackers? So I've got a presentation. We're going to run through it. We're going to talk about what you can do about it.

[Automated transcript follows]

This has been a long time coming. I have been doing a lot over the years of webinars of online meetings, trying to help people understand what's going on, what can be done.

[00:00:28] And I got a great email this week from one of the listeners. Who's been a man on my email list now for years, I'm not even sure how many years. And he was saying, Hey, thanks for giving all of this information for free for small businesses. And afford it. And I got to thinking because there've been a lot of requests lately, for instance, backups how should I be doing them?

[00:00:52] What should I be doing? And a number of other topics that really all go together into the, how do I protect myself, my business. From ransomware from these Russian hackers. So that's what we're going to be talking about today. We're going to go through a few of these. This is going to be a series.

[00:01:10] We're going to continue this here and weeks ahead, and I appreciate all your feedback. And if you miss part of it, make sure you email me just M. Craig peterson.com. Let me know, and I'll be glad to send some of it to you. Now I'm recording this on video as well. So it's great when you're driving around and listening in picking up some tidbits.

[00:01:34] And if you do want to see the recorded version again, dropping them in an email to me@craigpeterson.com or search for me on YouTube or on one of the other sites that are out there like grumble and you'll. This as I release it. Cause this is going to take a few weeks to really get into the whole thing.

[00:01:55] So let's get started. I'm going to pull this up here. Full screen. For those watching at home and what this is called today, we're talking about protecting your business and your self from Russian hackers because they have been out there. They have been causing just all kinds of problems, but there's a few things that you can do.

[00:02:18] And I have them up on the screen here. Let me pull them up, but I want to get into the background first. Russian ransomware group. They're a bunch of bad guys and it's called Conti. Now. Conti has been around for a long time. These are the guys that have been ransoming us. They're the guys who ran to mean the businesses they've been rants.

[00:02:40] Government, you might've heard them. They've got into hospitals. They have been all over the place and they've raised a whole lot of. For the Russians. I'm also going to tell you about a couple of things you can do here. Cause there's a real neat trick when it comes to keeping Russians out of your computers, but Conti decided, Hey, listen, we are all for Russia and president and Putin.

[00:03:03] So they came out with an official warning, oh, I want to read this to it says if anybody. We'll decide to organize a cyber attack or any war activities against Russia. We are going to use our all possible resources to strike back at the critical infrastructures of an enemy. Yeah, no, not the best English, but much better than my Russian.

[00:03:25] I got to say that I know two words or so in Russian, but they said that they were announcing full support for president. That's a pretty bad thing. If you asked me, they also have ties to Russian intelligence intelligence, but what are we talking about really? Think of the KGB.

[00:03:43] The FSB is what they're called nowadays, but directly tie. China and North Korea, Iran, or also now tied in with Russia to varying degrees, but all of them are a little bit concerned about getting into it a little too much, but we're going to talk about their tactics. That's what's important today. What are they doing?

[00:04:05] Why are they doing it? What can you do about. So the first thing is password sprain. This is big deal. I've got a nice big slide up here. I like that color blue. I don't know about you, but I think it's pretty, but password sprain is something we all need to understand a little bit better. It's a brute force attack that has been really hurting.

[00:04:30] Many of us. Let me see if I can get this to work. For some reason it has decided it just doesn't want. Let me see here. What is up? Oh, is something isn't it's just, I'm getting a white screen, but it's a brute force attack targets users who have common passwords. Now this is a problem. When we're talking about passwords.

[00:04:55] If you have a password that has been breached in any of these breaches that have gone on over the last, however long, right? 30 years plus now that password is known to the bad guy. So what they'll do is they'll take that common password and they'll start to try it. So password sprain is where they will go to a bank site or they'll go to Google.

[00:05:21] The, oftentimes they're trying to get at your email accounts. So if you have Google email or Yahoo or Hotmail, they'll try it. Use passwords that they have found against accounts that they have found on those various sites that ends up being quite a big problem for everybody out there. Okay. I got that screen back here.

[00:05:42] So I'll put that up for those people who are well. But they will send multiple times attacks using variations of these passwords. And it's known as a low and slow method of password hacking because if they were to go bam, and send all of these passwords and login attempts. They get caught.

[00:06:06] The automated systems would say, Hey, wait a minute. This is not good. We're going to cut you off. In fact, that's what I do for my client. We have remote access using SSH, which is a an encryption session so that we can have a terminal session. And if you try and log in three times, We automatically zap you, right?

[00:06:28] We shut you down. So they take a very slow approach to this password sprain technique. And they're also going after volume, which makes a whole lot of sense. And there are right now, billions of passwords usernames, email addresses that have been stolen that are sitting out in the dark. So you've got to make sure that you are not reusing passwords.

[00:06:54] How many times have we talked about that? You've got one common password that you're using over and again, while that's a problem, but they're not going to keep hacking your account. They're going to switch from one account to another because they don't want to get locked out.

[00:07:09] Just like I lock out somebody who's trying to get in. So if someone's coming from that same. IP address that same internet site. And they're trying to log into that same account multiple times. Bam. They are gone. So with path's word sprain, they're trying to get around the problem of you noticing they're trying to get into a bunch of different accounts and they try and leverage it.

[00:07:34] So they'll oftentimes use multiple computers that they've stolen access to. We've talked about that before too. It gets to be a real big. Now they're also targeting these single sign-on and cloud-based applications, because once they're on. Using one of these federated authenticated authentication protocols, they can mask the malicious traffic.

[00:08:00] We've heard some of these hacks lately where they're using a token that they managed to pick up from somebody's email, I account, or they got onto Microsoft and they got into the email account on Microsoft. That happened recently. In a supply chain attack, solar winds. You heard about that 20, 21, right?

[00:08:21] So they're going after these email applications, including Microsoft or Microsoft has done they're going after routers and internet of things, devices for a very good reason, those IOT devices, which are things like your smart lights, they can be. Controlling the cameras outside, they go on and on there's thousands, millions of them.

[00:08:44] Now I actually all the way through your microwave, they tend to not be very well protected. So that's a real big target for them. So step. They want to acquire a list of usernames. Step two, they're going to spray the passwords. Where do they get those passwords in those usernames? Or they get them from breaches.

[00:09:06] So again, if you have an account that's breached at some online shopping site, a big one, a small one, it doesn't really mean. That particular breach is now well known and they can, will and do gain access to your account which is step three, gain access to it. It gets to be a serious problem.

[00:09:26] Okay. How do you know if you are under attack? Number one? There is a spike in failed. Log-ins this is where having a system and there's technical terms is tough for this. I'm trying to avoid a lot of those terms, but this is where the system is watching logins, noticing that there's a problem and going ahead and stopping it, not just noticing that, but stop. Very important to do. There are a high number of locked accounts, which means what it means that again, someone's been trying to log in. You should make sure that your account, if there are invalid, lock-ins automatic. Locks it out after some number of attempts and five attempts is usually considered to be okay.

[00:10:14] I know on my phone, for instance, I have a higher number of the neck, cause sometimes the grandkids get at it. But when it comes to your business account, when it comes to your bank account, you probably don't want to have a whole bunch of. Of a attempts, and then in known or valid or invalid, I should say user attempts again.

[00:10:36] Why are they trying to log in with a username that just doesn't exist? Yeah, it can be a problem. Hey, when we come back. We're going to talk about some steps. Like you can take here to really remediate, maybe even stop a password spraying attack. I've already given you a few ideas here, but what are some act of things that you can do, particularly for a small business to really protect yourself?

[00:11:04] Hey, stick around. We'll be right back. Craig peterson.com.

[00:11:10] Russia has, hacking our computers, Russia's continuing to hack our computers and this is a real problem. So we are going to talk right now about how to stop some of these things. We already talked about password sprain. How do you start?

[00:11:26] There are a lot of things we have to pay attention to, and that's what I'm going to be doing in the weeks ahead.

[00:11:33] We're going to be going through some of the things you need to do to keep yourself safe. Keep your business safe in this really dangerous online. There are so many things going on. So many people that are losing their retirement businesses, losing their operating accounts. We've seen it before with clients of ours while you know their clients now.

[00:11:59] And it was just a devastating thing to them. So I don't want that to happen to you now, if you are interested. All of this is recorded and I am doing this as video as well. We've got slides and you can find out more about it. Just email me M e@craigpeterson.com. It's really that simple. And I didn't let me know.

[00:12:24] And I'll be glad to send it off to you. Okay. This is available to anybody I'm trying to help. And we've had a lot of emails recently about some of these things. So th this is covering everything from the password spraying we're talking about right now through backups and other things that you need to do.

[00:12:43] Let's get going on our sprain problem. So w what are the steps that we need to take an order to really remediate against one of these password spraying attacks? And frankly, it is. Oh, a lot to do. It has a lot to do with our users and what we do, if you're a business, if you are an individual, we need to be using longer passwords.

[00:13:12] Now we're not talking about all of these random characters that we used to have. I remember having to have my password be at least four characters, long APAC, when didn't even have to have a username, it was just all based on the password. And things changed over the years, the latest standards that are out there right now come from this too, which is the national Institute for science and technology.

[00:13:37] They are the guys that put together, all of the guidelines said federal government and businesses need to follow. And they're telling us that a longer passwords means elaborate pass phrase. So you should use 15 character passwords. I had an article just a couple of weeks ago saying that an eight character password can be cracked almost instantly, certainly within an hour, any eight character password.

[00:14:08] So if you're still using that, you've got to make a change. And obviously nine characters is a lot more possibilities, takes a lot longer to crack. I don't have those numbers right in front of me, but 15 is the ideal. So use pass phrases instead of single words. So phrases like I don't know secretary of one, the Kentucky.

[00:14:34] There you go. There's a phrase. So what you would do is put, maybe dashes between each one of the words. Maybe you would go ahead and use a comma, put some numbers in there, put some special characters in upper lowercase, right? So it's basically on uncrackable at that point. And that's what you want.

[00:14:53] Next one. When we're talking about rules for your passwords, the best passwords are the passwords that you can remember without writing them down and words that don't make sense to anyone else's. I remember taking a memory course a few years back and they had random words and you had to remember them.

[00:15:18] And the whole idea was okay, visualize this happening. And as I recall, man, it's been a lot of years I won't say decades, but it hasn't been. Since I did this, I still remember a part of it, it was first word was airplane. Next was all envelope. The next one was paper clip. Next one was pencil.

[00:15:38] So I visualized an airplane flying into an all envelope and that all envelope then goes into a paper clip and a pencil writes on the outside. Like it's addressing it to someone. That is a good little password, actually airplane or envelope, paperclip, a pencil with a mixed case and maybe a number two or special symbol thrown in.

[00:16:05] Those are the types of rules that we're talking about. The types of rules that really. Next up here. Oops. Wrong keyboard. Stay away from frequently used passwords. We've talked about this many times. If you're using one of the better password managers, like for instance, one password, you will automatically have any passwords that you are there in Shirin or that it creates you'll have them checked via a website out there.

[00:16:37] It's called. Yeah. Okay. It's called. Have I been poned I, and I hated to say this because how do you spell it? It's all one big, long word. Have I been poned to.com and poned is P w N E d.com. It will tell you if a password that you're trying to use is a known password. If it has been found out in the wild, okay.

[00:17:02] Use unique passwords for every site you visit, I can't stress this enough. We were talking about password sprain. If you use the same password and email address on multiple sites, you're in. Because all they have to do is try your email address and your password for whichever site it is that they might want to try out.

[00:17:27] Remember, many of them are trying to get into your email and they have done that successfully. With Microsoft email, if you have their Microsoft 365 service and you might want to read the fine print there very carefully, because Microsoft does not guarantee much of anything. You make sure you back it up yourself.

[00:17:50] Make sure you do all of these things because Microsoft just plain, isn't doing them for you. Next one here. Next up is our password manager. And I mentioned this before installing and using a password manager is phenomenal. It automates the generation of passwords. If you have. Integrated with your web browser.

[00:18:15] It now allows your web browser to work with your password manager. So when you go to a site, you can have it pull up your passwords. How could it be much easier than that? It's really rather simple. That way it's keeping track of your logins. And again, One password.com is the one I recommend and people get confused.

[00:18:36] When I say that, when I'm saying one password, I don't mean only have one password used for everything. One password is a name of a company. Okay. So it Talking about only having a single password, but use a password manager. And I've got all of these up on the screen right now. If you're interested in getting copies of these, you can go ahead and just email me M e@craigpeterson.com.

[00:19:04] And I'll make sure I send you a copy of the slide deck of this presentation as well. Cause this is just so important, frankly, but having these points is going to be huge for you. Now strange activity. That's another very big deal. And we're going to talk about this when we get back, what is it?

[00:19:25] What does it mean? But I'm going to hold off the rest of this, I think for another week. But right now, what let's hit this, we're talking about odd log-in attacks. A lot of login attempts, the excessive login attempts trends in unusual activities take any, you need to basically take measures to block it and determine if this activity is legitimate.

[00:19:50] Is someone just for forgetting their password and spraying themselves or what's going on? Okay. There you go. Simple. Hey, everybody, you can find out a lot more and you'll be getting links to this automatically to these videos, et cetera. If you're on my email list, Craig peterson.com and you can email me M e@craigpeterson.com.

[00:20:15] We'd be glad to send you this or any other information I might have. All right. Take care. We'll be right back.

[00:20:23] Putin has been working for a while. In fact, it looks like as early as September in 2021, Putin started going after major us corporation. So we're going to talk about that. And what does it mean.

[00:20:39] Putin has been going crazy for a while. I'm going to put this up on the screen for those of you who are watching either on rumble or YouTube, but Putin planned this whole invasion apparently quite a while ago.

[00:20:56] And I got an article from the Washington post up on MSN talking about what Putin did at least a little bit about what he did. And you can see right here if you're following. That Russian agents came to the home of Google's top executive and Moscow. And what they did is gave an ultimatum. They told that Google, a senior executive that they needed.

[00:21:24] Pull down an app that was in use in Russia. And this app was polling. It was for people to do polls and say, Hey what do you think about Putin's garden performance, et cetera. We do them in the U S all of the time you hear about the polls right left and center. Poland, which is a small country next to another small country called Ukraine next to a large country called Russia.

[00:21:50] But we're talking about Paul's favoribility polls. What do you think they should be doing? What do you think that the government should be doing and maybe what they should not be. So Putin didn't like this. He didn't like this at all. And so what he did is he sent a couple of guys ex KGB, FSB, the secret police over in Russia by to visit this Google executive.

[00:22:16] If you're the Google executive, what are you going to do? If you Google. Yeah, you're going to say, oh my gosh, I'm out of here. So I'm not sure if she, if this executive was an American or Russian, this article doesn't seem to be clear about it, but what happened is they said, okay let's go hide.

[00:22:41] So they rented a hotel room for the. They put her in it and they rented the room under an assumed name. So it wasn't the real name of the executive. It wasn't tied into Google and they thought, okay, now we're pretty safe. Cause you got a hotel security, I guess there are a couple of Google people hanging out with her and they felt pretty safe.

[00:23:04] What happens next? There is a knock on the door. These same agents, again, that are believed to be Russian secret. Police showed up at her room and told her that the cock was still ticking because they had given her 24 hours for Google to take down the app because Putin, dental. People weren't particularly pleased with Putin.

[00:23:31] So at that point, of course it was forget about it. And within hours, Google had pulled down the app. Now you might complain, right? A lot of people might complain about it. It's one thing for a company like Google or apple to capitulate, to a government to do maybe some censorship, like the great firewall of China.

[00:23:54] You might've heard of that where the Chinese citizens can't get certain information. Russia has something pretty similar and us companies have gone ahead and helped build it, provided the technology for it and put it in place. They sold it to them. I don't like that in case you didn't guess, right?

[00:24:12] I'm all for free speech. I think it's very important for any form of a democracy. No question about it, but these companies apparently don't have a problem with that. However, now this is something, a little different. If you have employees who are being threatened and I mean threatened to serve 15 years in a Russian prison, what are you going?

[00:24:39] Are you going to say no, I'm going to leave that app up. And then now all of a sudden your executives, or even a coder, somebody a programmer, like the guy that sweeps the floors, whatever are you going to let them be arrested so that you can have this app up on your Google play store or your app store over the apple side?

[00:24:59] Probably not because frankly, this is something that is not worth it. So what are you. I think the only answer is what we've seen company after company do, and that is get out of Russia completely. And there was an interesting story. I read this recently about McDonald's you might remember back in the Soviet days, McDonald's worked out this deal with the Soviet union to open a McDonald's right there in downtown Moscow.

[00:25:32] I guess it was pretty prominent. I don't know if it was, I think I might've been even on red square and there were people like. To have an American hamburger and it's been pretty popular the whole time. McDonald's closed that store and pulled out of the country. Starbucks has pulled out, are they going to reopen?

[00:25:50] Cause I don't think either one of them said, forget about it. We're not coming back, but I know both of them have closed on operations. Automobile manufacturers from the U S have closed on operations. What is their choice? You can't just go ahead and say, okay yeah. Okay. Yeah. You're just going to arrest people or, we'll keep quiet for now and come back later.

[00:26:12] What are you supposed to do? That's part of the problem with these oligarchies, with these people who are basically all powerful. Now we actually see some of that here in the us, which is just as shame, just a shame because we see these companies going ahead and cutting out free speech saying, oh, you can't say that there was a time where if you said masks work, that you would have been censored. And then there was a time where if you said masks don't work. You cloth mass don't work, you would have been censored. There was a time when you said masks aren't necessary. You would have been censored right now, but the science is settled.

[00:26:56] It was just crazy. Science has never settled and oh, we could go on with this for hours and hours, but potent is not a good guy. And this article, I'm going to bring it up on the screen here again. But this article talks about. And a single year. And again, this is MSN. Potent had his political nemesis, Aloxi Novolin novel ne yeah, I got it right.

[00:27:23] He had him in prison after a poisoning attempt, felled to kill him. Do you remember that whole poison attempt? Where they gave him this really nasty radioactive bride product, as I recall, and potent went ahead and basically shut down. They pushed all of these independent news organizations to the brink of extinction.

[00:27:46] Look at what happened with Russia today. The entire staff walked off on the. Saying, we're not going to report on any of these lies that are coming out of Moscow. It's happened again and again, Putin orchestrated a Kremlin controlled takeover of Russia's Facebook equivalent, and he's also issued liquidation orders against human rights organizations.

[00:28:12] And so all this is going on. What are you going to do if you're. If you're a Google, right? I can see the criticism of those countries or companies should say when they're cooperating with the regimes, putting in place, things like facial recognition to, to spy on people, to have a social credit system, these great firewalls in these countries.

[00:28:34] But when you have something like this happen, I forget about it. There's nothing you can do. And the crackdown is accelerated Facebook and Twitter were knocked offline by the government for millions of Russians news outlets had survived the state harassment for years, shut down in the face of a new law impose.

[00:28:55] 15 year prison sentences for spreading fake news. It's incredible what has happened. And we've got to be careful here in the U S too, because we see this censorship, there's a lot of complaints about what was happening under Donald Trump president and old Biden, both Obama and Biden.

[00:29:15] Both of those have done some of these same things to a lesser extent. Stick around. We'll be right back.

[00:29:23] This whole war with the crane, Ukraine and Russia has brought a few things to light here over the months, and really the more than year that it's been leading up to the beginning of that war even, but we've got clear view in the news again. Yeah.

[00:29:39] am also besides broadcasting this on the radio, we're doing it in video two. So you can always follow along at rumble or at YouTube, but there's a great article here.

[00:29:52] I have up on my screen for you to see. And this is from writer. Para carried over on MSN. And it is an exclusive story talking about Ukraine, using something called clear views. AI facial recognition. This to me is absolutely fascinating because what is happening. Is the technology that Clearview develop and has it been selling to police forces in the United States is being used on the battlefield and.

[00:30:27] How here's what the technology did. And does Clearview illegally went on websites, major websites all over the world and did what we call scraping. Now, scraping is where they go to the site and they grab the pictures. So they scraped Facebook. They scraped you tube. They scraped. Dan and many more.

[00:30:54] And then they put it all into a big database that told them where they found it, who that person was. And then they also took that biometric information from that image of the face and came up with some unique codes, a hash basically is what they did. And. Now what Clearview is doing is if you are a police organization, you can get a little app that runs right there on your.

[00:31:22] And you have an encounter with someone you're a policeman, right? Let's say, and you just hold the camera up and it gets a picture of that person. It now finds the background information on them. And then you can use that tied into the police databases to check and see if there's any record of this person.

[00:31:42] If they've been doing anything illegal. It's really quite cool. What they're able to do and scary at the same time, we use the same basic technology over in Afghanistan. So literary troops as they're out, and they're having encounters with civilians, people in the streets, fighters, et cetera. They could hold the device up.

[00:32:04] It would identify them. It went further than just the face that actually did retinal scans and things, all kinds of cool stuff, but basically recognize the face. And they were able to tell if this was a friend of foe or. So a friend might be someone who worked as a translator who has been known to be helping the us troops in Afghanistan, et cetera.

[00:32:29] So we built this huge database of hundreds, of thousands of people's biometrics person, very personal information in it. And if they were getting paid even how much they're getting paid, all of that was in the database, in the backend. And then we abruptly. And we left that equipment behind. I hope the database was destroyed.

[00:32:52] I haven't found anything. Absolutely conclusive on it. That the withdrawal from Afghanistan was frankly unforgivable. It just I can't believe they did what they did at any rate. This is Clearview. This is this company. So now that same technology has moved to Ukraine. What's interesting. About this whole Ukrainian thing to me was okay, great.

[00:33:18] Now they can identify people. Can they really identify a pretty much everybody? Who are they going to identify? As it turns out clear Clearview also illegally stole photos of people over in Russia and in Ukraine. So the clear view founder said that they had more than 2 billion images from. How's that right from this social media service called V contact a or somebody like that out of a database of 10 billion photos total.

[00:33:52] So one out of five of the pictures they scraped was Russian, which surprised me. So the Ukrainians have been using it to identify dead Russian. And it's, they're saying it's much easier than matching fingerprints even works. If there's facial damage, it's scary to think about right. Wars, terrible.

[00:34:14] Who wants to go to war? I can't believe all of the people that want to jump in there. I really feel for these people in Ukraine, what can we do? I'll start approximately. Research for the department of energy, found the decomposition, reduce the technology's effectiveness while a paper from 2021 showed some promising results.

[00:34:36] Now, this again is an example of technology being used in a way it's never been used before. And having that ability to identify dead or living combat combatants on a field like this is just amazing. So this is the most comprehensive data set. There's critics, of course, they're saying that the facial recognition could misidentify people at checkpoints, obviously, right?

[00:35:04] Could miss identify people in a battle mismatch could lead to civilian deaths, just like unfair arrests have risen from police use. And that's from Albert Kahn, executive director of surveillance, technology oversight, product, project, and new. So as usual, these things can backfire and I think they probably will given a little bit of time and that's a sad thing.

[00:35:31] Now I also want to talk about this. This is cool. Another article here, I'm pulling up on the screen right now. And this is about some hackers. Now we know that the Kremlin's been lying. We know that if a politician's lips are moving their line, isn't that the old standby, but Russians apparently don't know this.

[00:35:56] And the average Russian on the street is thinking that, okay, we're rescuing Ukraine. Isn't that just a wonderful thing. There's a couple of ways that the hackers have been getting around it. It's called a squad 3 0 3. They have this tool that's hosted at the domain. 1920 dot. There's an Indian domain and it loads a pre-written statement in Russian into your native SMS app.

[00:36:29] In other words, the app that you use for texting and the idea is they that they've taken, oh, let's see here. Tens of thousands of trying to remember the exact number of stolen phone numbers from Russia. So all of those hacks that we've talked about for all of these years, those hacks have many of them phone numbers in them.

[00:36:54] And they've been taking those phone numbers from some of those hacks and using them to send out about 6.5. Million text messages. So what happens is you, your phone, your actual phone ends up sending a text in Russia saying something to the effect of dear Russians. Your media is being censored. The Kremlin is lying.

[00:37:18] Find out the truth about Ukraine on the free internet, and then the telegram app time to overthrow dictator. Yeah, that's not going to cause any problems, is it right? I'll put that up on the screen again for people who might read Russian. Cause it's got it in Cyrillic. Okay. And then you have the option to get an, another set of text and figure it out.

[00:37:40] So the phone number, you can see there, you can copy it and paste it into your app and off the message goes. It's very cool. And in the daily dog, They're quoting a member of this squad 3 0 3 saying that this is a non-violent communications project. It's bypassing Russia's crackdown on the news.

[00:38:02] They're sensitive. They're censorship of the news. And by the way, the domain 1920 dot. Refers to Poland's surprise victory against Russian forces just after world war one and the Bolshevik Menshevik revolution. You might remember all that stuff, that you studied all those years ago. So it's interesting.

[00:38:23] We'll see what happens. But this hacking group also claimed that they were attacked probably again by Russian hackers, the FSB ex. Using a distributed denial of service attack shortly after launch. And they put CloudFlare in front of their domain. Now we use CloudFlare for one of our, something, not one, but some of our customers.

[00:38:50] What CloudFlare is a website that's designed to basically buffer your website when it's been served. So if all of a sudden you get a ton of legitimate request, your site's going to stay up. It's going to be able to respond to people. The other big advantage to CloudFlare is what's happening here with 1920, Diane CloudFlare goes ahead and will block some of these denial of service attack.

[00:39:19] So I think that's pretty darn cool. Many texts apparently are met with silence. Some say they've been able to converse with Russian citizens. One user who remained anonymous said they had made. The text messages they'd made using the tool really worked it says, I want the people of Russia to know the truth.

[00:39:38] The government is doing to the people of Ukraine. This is a quote from the daily dot going to pull this up too. This is a a tweet here on Twitter and. Yeah. It's from the anonymous, that hacker group, you've probably heard of them before. Cause they've done a lot of nasty stuff over the years, but he says it's been doing just absolutely amazing things for him.

[00:40:02] Let's see here. Can we hear this? Here we go. Ah, I got to unmute it. Let's see. Where is my mute? There it is. So this guy's name is Rodney. He is. D Jang, oh my dog. Get to Django my dog. And he's got a really great little testimonial there about that. It works and his tweet has had 4,300 views and it's good.

[00:40:30] Again, another way around censorship now, Twitter, of course could decide they're going to sensor and that could be a problem too, but that's also why we now have alternatives to Twitter. And some of these other sites that are out there that are doing a whole bunch of blocking really, they don't like you.

[00:40:51] And by the way, the reference to Telegraph was fascinating because they are using. In order to get around censorship. Again, many people are using it to to send information about what is really, truly happening in Ukraine. So a lot of stuff from the beginning of the war here, visit me online. Craig peterson.com.

[00:41:14] Get my newsletter and get the free up-to-date trainings.

[00:41:20] They pass the infrastructure bill, which means now it's time to figure out what is in the infrastructure bill. And we're going to talk about the technology that they decided to fund the technology. That's going to win the game because it has billions of dollars of federal money behind it.

[00:41:36] This is disappointing bully it's normal, right?

[00:41:40] It's absolutely normal because the federal government has always been one that picks winners and losers. If you're old enough, you remember, of course, VHS. Tapes right too. Do you remember beta tapes? Beta max tapes. Beta max was really quite the standard for professional production for the longest time, a better technology, frankly, a lot better than VHS.

[00:42:06] Same. Thing's true with beta, but beta lost. And of course we ended up with VHS tapes. That's an example of technologies that were backed by investors. And we've seen a lot of that. Look at what's happened with the Serono trial, again, technology backed by investors. And it turned out to not work and in quite a dramatic way, frankly.

[00:42:33] We've seen that again and again, and keep hitting my mic here and the problem that we really have, isn't so much that investors get things wrong because they. I was talking with a friend of mine. Who's has been an angel investor and part of VC partnerships for a long time. And he was saying, we're lucky if we get maybe one out of 20 times, we get.

[00:42:57] Now, these are professionals and my friend, he's a technology guy. He and I contracted together at the same time over at digital equipment corporation. And he came to me for a lot of advice about business. Now, I look back and think my gosh, the way he did it. You can have all kinds of decisions in life.

[00:43:18] Some are going to bring you closer to family. Some are going to bring you more peace and joy and happiness, and some are going to give you very gray hair that you're going to lose very quickly. And he chose the kind of the gray hair. But he was really clear about that. Cause I had said to him, what is a one-time out of 10 VCs make money.

[00:43:39] And that's when he corrected me. He said, no, it's really one out of 20, if they're lucky, because that doesn't even happen all of the time. Now think about him. He was working on the scuzzy subsystem, which is. Complicated topic, but basically the ability for a computer to be able to talk to its hard desks.

[00:43:58] Okay. Let's just keep it simple. And I was working in the kernel, which is the core of the operating system and was rewriting kernel modules and routines. To work with a few different types of features and functions. I was in very deep very complicated. He was in rather deep, rather complicated.

[00:44:19] There's always a battle by the way, between compiler people and kernel people as to who has the more complicated job, but he wasn't either. So he just a Colonel guy guess. So he went on. He started a company. He got VC angel funding and VC funding. He made a card for your computer that you could plug in that would provide not just scuzzy support, but he moved the file system out of the operating system onto the card.

[00:44:50] I that's something I had actually done a decade earlier with the network moving it out. But anyways, that's a different story entirely. So many things I've done all my life that I wish I'd been able to monetize. But anyways, w he doesn't, he's not a slacker. Let me put it that way. When it comes to technology and neither are his partners, and yet one time out of 20 and along comes the infrastructure.

[00:45:14] They call it the infrastructure, but it really bothers me to call bills things that they're not the infrastructure bill that had. What was it? About five, 6% actually going to infrastructure. It's like the Democrats under president, the last president Obama they, he had this shovel-ready jobs, which of course wasn't true.

[00:45:35] And most of the money didn't go to building infrastructure. It just got worse. It's just crazy and we're not paying attention. So I'm going to help you right now. Enough ranting and raving. The infrastructure bill contains money for some things. We'll talk about a few of them here in a minute and also has new regulations.

[00:45:56] And one of those regulations that I've been talking about on the radio this week is this requirement to put kill switches in all new cars. That is really a big deal. Now a kill switch of course, is something that will stop the engine and it'll stop the car. That's the whole idea. And there's various types that have been bantered bandied about including pulling the car over to the side of the road.

[00:46:25] If the driver stops responding as a driver might have a heart attack, or maybe they fell asleep, maybe something happened in that car should probably pull over and get out of traffic, turn on the flashers which then makes it a target. Apparently for some of these Teslas, we've seen articles about that in the new.

[00:46:44] Yeah, don't park on the side of the road. They, I was in emergency medical for a long time. And one of the things I can pass along to that may save your life is if you have to pull over, do not stay in the car, do not stand in front of the. And particularly in the evening or at night because the flashing lights and the car at the side of the road is a beacon for drunk drivers to come and hit you as well as some of these autonomous vehicles, apparently just get out of the car.

[00:47:16] Behind the car off the road. Okay. Go off the road behind the car, not next to the car off the road, not in front of the car, off the road, behind the car. So if it does get hit, you are less likely to suffer severe damage yourself, but this kills switch. That's part of this bill that was passed in sign, of course, a hidden part requires all manufacturers to include the ability.

[00:47:44] For police departments and potentially others. And this is where some of the problem comes in to be able to stop the. Now you might remember back in 98, there's a Saifai series called the X-Files. It was very cool series. And there's an episode called kill switch about an artificial intelligence gone wild.

[00:48:07] And that, that is of course a while ago back when most people were still using dial up modem. But this was a tale of technology, run a muck, and it was warning about handing too much of your life over to technology. Oh, that's one thing. But in this case, isn't it safer, right? Because somebody is whipping through neighborhoods at 80 miles an hour in their car, trying to avoid police.

[00:48:37] Shouldn't have, please be able to stop that car and pull it. The problem is multifold frankly, and having this kill switch one is what constitutes law abiding. There's a great article in motorists.com and it shows a picture of this down in New Zealand. Our car was pulled over. And the police found the trunk was full of contraband.

[00:49:02] Now we've seen this before, right? And movies, Miami vice and others, where they pull over the car. It's got all this contraband in the trunk. It's cocaine and various other things. No. This isn't Auckland New Zealand and the trunk was full of Kentucky fried chicken meat. They were running Kentucky fried chicken, just like the Kennedys, running illegal booze back in the day. Yeah. That's how they made their millions. They were running Kentucky fried chicken. Now this bill that was signed into law by president Biden states that this kills switch, which uses referred to as a safety device, must passively monitor the performance of a driver of a motor vehicle to accurately identify whether that driver may be impaired.

[00:49:54] In other words, big brother will be constantly monitoring how you drive. If you do something that the system has been programmed to recognize as driver impairment or unsafe driving your car could just shut off, which could be incredibly dangerous. I want to point out this week too. There's another article I read about Teslas and how Tesla had introduced last fall, a feature.

[00:50:23] So you could set how the car was going to drive. Do you want to drive? Real cool, laid back fashion. Do you want the car to drive an average way or do you want it to be aggressive? Just weave in and out of traffic a bit and tailgate and do all of those sorts of things and you could set it and there is a public backlash and Tesla got rid of it.

[00:50:42] It is back now. How do you tell if a driver's being unsafe? When a car in its autonomous mode will do the same things that a human drivers shouldn't be doing? Or what if you're hauling contraband, Kentucky fried chicken? How is the driving going to be measured as impaired? Now I know in many states you have these breathalyzers that are court ordered, installed in cars.

[00:51:13] Okay, so that makes sense. Somebody has been drunk driving many times. You don't want them drunk driving ever again, please. And thank you. But how about having that system in every car? Because it fails. It doesn't work sometimes. And how about the back door? Because that's essentially what we're talking about.

[00:51:34] These cars are going to have a back door that allows someone named government authorities to access it whenever they want. Would they need a warrant to do it? Probably not. Even as hackers could access the back door and shut down your vehicle, think about lad having a kill switch that would kill all of the cars and trucks in the United States.

[00:52:02] Right? There are so many potential problems here and they haven't been thought about. Oh, obviously it's government, but we're going to talk or we'd get back about the investment that are part of this multi-trillion dollar bill that you and your kids and grandkids are paying for.

[00:52:23] We know they snuck a backdoor kill, switch into all cars manufactured after 2026 into this infrastructure belt. What else is in there? That's going to affect technology. That's what we're going to talk about right now.

[00:52:38] We know about this now. After it passed, finally, people had a chance to read it because this provision on the kill switch was not debated in the house.

[00:52:50] It was not debated in this. Just like they've been doing was so many other things for so long now they just bundle them all together in a bill. They gave it a cute little cuddly title, and then they go ahead and put whatever it is they want into it. These are these omnibus bills that they should have gotten rid of decades ago.

[00:53:16] It is absolutely crazy to me. I just. Get it. Why are we putting up with this? So now the next step here is the investments that are being made. Now I'm going to type in right now, how successful are angel investments? Okay. So here we go. Bunch of ads for angel investing says you can have an average return of 1.1 X cap.

[00:53:48] All right. And it goes on and on. This is a company called core associates. The success rate of angel investors. This is from Investopedia, the effective internal rate out return for a successful portfolio for angel investors is approximately 22%. Now, remember that over. So that's pretty amazing. Those numbers are much higher than what my friends said that they can expect absolutely much, much.

[00:54:19] But I can tell you one thing for sure. Government quote, investments, end quote, rarely ever actually pay out because you've got political motivations in there. It's one thing to be a smart technology guy investing in technology. But how about those people in Congress? That aren't smart technology guys.

[00:54:44] How about the doctors in Congress? Look at what Senator Paul ran. Paul has been saying he is a doctor and what he's been saying about the whole COVID thing and the way the government has handled it. We are really going down the wrong road to here because government. Taking the money from us at the point of a gun.

[00:55:06] Try not paying your taxes and see what happens rarely ends up. Okay. So the us Congress passed November six. Biden's trillion. Plus infrastructure bill that includes 65 billion of investments in the power grid to accommodate rising, renewable energy capacity and demonstration clean tech project. So what's that one about?

[00:55:32] That particular one is because our grid cannot handle solar and also the windmill power. The rates, we would need to have it, our grid set up so that you have a few centralized power stations, and then that power is distributed to the area. It's not set up for having tens of thousands of power stations.

[00:55:56] So there you go, president Biden, put money into try and figure out well, Hey, how do we accomplish? How do we accommodate them? Noma, Germany has done. Is they've gone ahead and they're using a massive lake as a heat sink to get rid of the extra electricity that's being generated. When it comes to a regular power plant, you can turn it up.

[00:56:21] You can turn it down the same. Thing's true for every type of power plant, whether it's powered by water or nuclear or cold, you can turn it up. But when it comes to wind and solar you can't turn it down. If it's a nice sunny day, you're not going to be able to turn that power down. It's still coming out.

[00:56:40] You got to do something with it. You can cut it. Open the circuit. But the power companies that run the grid don't have that kind of fine grain control over the electricity that you're generating in your house or in your business. There's so many problems that start to open up here. So they're spending $65 billion.

[00:57:02] That is a lot of money to figure this out. Okay. Personally, I'd rather see the private sector do it because they're going to have a better chance of coming up with something that's really going to work next part here. Okay. And by the way, Colin it or trillion dollar plus is being favorable because they played all kinds of gimmicks with this money.

[00:57:25] Just, I just found out. In fact, I think it was a couple of weeks ago, June. Do you remember. President Biden moved all of the college loans from private sources into the white house. Do you remember that? So the white house is controlling all college loans at the time I thought, okay, it's just them paying back the unions, the teachers unions, right?

[00:57:49] Because it also included provisions that you cannot have be bankrupt and get rid of your college. Th that's just mind boggling to me, but as it turns out what he was doing. Okay. All of that's true. But what he was actually doing is saying, oh, there's over a trillion dollars in college loans. So we're going to move them into the white house and call those assets to offset all of the money we're spending.

[00:58:19] You see what we're talking about here? It's just not. Electric vehicles, clean energy, public transit are all part of this trillion dollar plus legislation. It's got $550 billion, a half, a trillion dollars to fund advancements in public transit, clean energy electric vehicles, roads, and bridges. Okay. It's always electric.

[00:58:48] Really? The right winner here is electric. The beta max that should have won out over VHS. How about hydrogen? How about some other way? How about natural gas or LP gas? What we'll never know because some of that is not going to get funding. However, there is going to be some funding. For nuclear development?

[00:59:12] No, I've talked a lot about this on the radio before, but the bottom line is nuclear is the only green energy that we can really get. And I can hear some people saying, oh, you're not sure not to know. Look at the current generations of nuclear power. Now, unfortunately, the regulations around nuclear power were written what, 70, 60 years ago, right?

[00:59:38] When nuclear power was nasty stuff, it came out of the projects that we had in world war II to build nuclear bomb. Now these six generation nuclear power plants are as clean as can be. They only need to be refueled every 10 to 20 years, and they're small enough to fit into a small building smaller than your average home.

[01:00:02] And you can put one of these in the neighborhood in a small town, and that will power the whole. Thing. Okay. So we're already getting 27%, according to president Biden of our power from these decades, old nuclear and hydro power facilities, they've got 21 and a half billion dollars in this for clean energy demonstrations and research hubs focused on next generation technologies, helping to get us to that net zero by 2050 that they're looking at.

[01:00:35] To get to, so this will be interesting because there they've got 8 billion earmarked for hydrogen and carbon capture. Guess what's going to get more, yeah. Carbon capture, direct air capture, and we don't know what's going to happen with this. We're turning cow, carbon into stone, basically with some of these plans and experiments are underway.

[01:00:56] So what happened. When we need that carbon again. But 8 billion is earmarked for hydrogen and carbon capture direct capture, 10 billion, two and a half billion earmarked for advanced nuclear. So I'm happy with that. Not that they're spending the money, not at all, but that they're actually putting it into something that might make a difference.

[01:01:22] And hydrogen funding in this, by the way, it looks like it's a big win for oil and the whole oil industry stick around.

[01:01:31] You've heard of this shortage of Silicon, of semiconductors CPU's et cetera. I don't know if you tried to buy a computer lately, order a computer, et cetera, but there is another part of the computer that's really hard to get. And that's what we're going to talk about.

[01:01:56] CPU is the central processing unit in your computer.

[01:02:01] And that nowadays might actually not just be on a chip by itself, back in the day. I'm thinking about the, some of the first microchips microcomputers I worked with such as the 65 0 2, that original. Apple chip that they use great little chip, by the way, he was just so clever how they got around some of the problems eight-bit problems or the day that computer with its CPU was a standalone CPU.

[01:02:30] That in other words, the CPU only did CPU thinks, it went out and grabbed stuff from memory and then did the computing and then. Push the results back to memory. Just simplifying it there today. You look at a CPU like what apple is putting into their iPhones and the iPads, and particularly their desktops with , the M family, really whole family of chips.

[01:02:56] It is no longer just a CPU on that chip. That chip has all of them. It has, of course, all of the memory controllers on it, the processors, it has low power processors. It has high power processors and it has GPU's that's what I want to talk about right now are the GPU's cause in the apple case, you. One of these M series computers and your stuck with what you buy, which is why you should always be buying the biggest, best just computer you can so that it will last you longer.

[01:03:32] And I'm not talking about the fact of that study that said your average laptop, nowadays windows, laptop is going to last about seven months. I'm talking about the it's going to last, not because it breaks down or doesn't break down, but it's going to last because it has enough memory to handle future operating systems, et cetera.

[01:03:53] Now we've got a problem today with TPMS. These are trusted platform modules and apple has actually been using something very similar to that for a long time. TPMS are in the window's case, very simplistic and don't actually provide very much security. They're basically going to help prevent someone putting some malicious code into the boot blocks on your computer.

[01:04:23] So it's going to do some good, but it's not going to do a lot of good and windows. Now, Microsoft is requiring pretty much TPMS for windows either. Across the board. Now there's some ways around it sometimes depending on what you're doing, how you're doing it, but as a whole, yeah. You gotta have that TPM in order for things to work for you and even installed windows 11.

[01:04:50] That's a good step, frankly that they made apple is many steps ahead of Microsoft in this case, mainly because they can make their own hardware. Microsoft can't. So when you buy a Microsoft computer inside, it's going to have what we're still calling a CPU, but it's much more than that.

[01:05:11] Nowadays their CPU might be from Intel. It might be from AMD. Those are the two most likely Microsoft with their surface tablets does support similar chips to what apple is making. So you don't have to use an Intel type of chip in order to run windows anymore, depending on the hardware you're using.

[01:05:32] But as part of these chips, you have to move graphics around. So the modern chips, like the Intel chips and AMD chips have some GPU capabilities built into. But in most cases, you're going to add a GPU card to your machine. So what is this GPU? What are we talking about here? A GPU is a really interesting piece of hardware because it is designed specifically to move.

[01:06:05] Bits of information around very efficiently versus a CPU, which is designed to do mathematics on words of data. So in other words, 64 bits at a time. So if you're moving stuff around the memory buses on the CPU, et cetera, are optimized for maybe 128 bits of data all at once. So why would you want something that only handles.

[01:06:33] A bit at a time. Of course it can do more than that, but we're keeping things simple. You want that because it's efficient at it. And if you think about the graphics processing unit, as the thing that handles the graphics, and you look at a screen, that screen is composed of most likely millions of dots, even on our little smartphone device.

[01:06:55] Millions of dots. And so you've got to flip those dots around. Sometimes you need to move them as something most, or the most efficient way. For instance, to show a video is not to update that whole screen, because if you look at a screen with video, most of that screen, isn't moving nothing. Tap. What you want to update is just the parts that are moving and that's where compression comes into place.

[01:07:21] And also where decompression comes into play. So all of this stuff that is part of moving things around on your screen, even if you're dragging a window around on your display, that is most optimally handled by the graphics processing unit, the. So Apple's putting their memory on chip. It's putting the GPU's, CPU's the high power, low power.

[01:07:45] CPU's everything it can. And then all the memory management and stuff on one chip. And that gives some huge advantages because when you're talking about the speeds that we're using today the less space that electrons have to travel the faster it will be. I know you think about that for a minute, right?

[01:08:03] You turn on a light switch and lights are on instantly. In reality, it takes a little bit because the electrons have to, first of all, get to the light and then they have to somehow excite something in the light in order to make the light. But electrons, distance traveled matters in. So why are we having such a huge shortage of GPU's while it has to do with their ability to mine, crypto current?

[01:08:34] Now the best way to mine. Cryptocurrency is using specially made and designed hardware that is designed for that one particular cryptocurrency. So it makes sense to you. That's the best way to do. But in most cases you don't have that specially designed hardware. And in many cases, that hardware is only really viable for a few months, but people are still buying GPU specifically to mine, cryptocurrencies, by the way.

[01:09:09] It's usually cheaper to buy cryptocurrencies and to mine them because the average electric bill in the United States makes it so that it is impossible to mine. These cryptocurrencies like Bitcoin effectively enough. So the electricity is cheaper than the pit coins worth. So think about that. If a Bitcoin is worth $50,000, Frank.

[01:09:34] The electricity to mine. Another Bitcoin is more than likely going to cost you more than 50 grand and take a long time. So people are still buying GPU's these high-end GPU's, they're using them to build machines that have a bunch of these cards in them. And that is causing shortages for you and me who might want to make videos efficiently or who might want to do just.

[01:10:01] Computing and buy a high-end computer. So it's good for you for the next five to 10 years. Oh, and Radian, who makes some of these high-end GPU's just came out with one that is specifically designed to be bad at mining cryptocurrency. So who knows? Maybe there is a little bit of hope here. You can visit me online.

[01:10:23] I'd appreciate it. If you would, Craig peterson.com, you'll find all kinds of great information there. And if you sign up, I'm going to send you absolutely free. My three most popular, special reports, including. The one-on passwords, Craig peterson.com. Visit me online and stick around because we'll be right back.

[01:10:49] There are a lot of programs claiming that they are secure. That's what we're going to talk about right now for secure communications. What about telegram? What about signal? What about WhatsApp and WhatsApp? You remember started 20, 21 with a real blackout.

[01:11:05] Signal is probably the best software that you can use the best app. They've got a desktop version as well in order to keep your communications safe. And that's what you want to do. You don't want. People listening in. You don't want people spying on you. You just want to have a conversation.

[01:11:27] And there's many things that you'd say in a private conversation that you would not say, if you were sitting here on the radio or standing on the top of a building with a thousand people below you, private conversations are meant to be. What signal is doing to play with fire is they are talking about trying to pull in cryptocurrency payments into part of signals, platinum.

[01:11:55] It all started with something called mobile calling and signals CEO. And his name is mark C Marlin spike. We've talked to him about him a few times, but he was an advisor to the mobile coin, current cryptocurrency. And it's been built on this stellar blockchains designed to use a view, be used to make anonymous payments that are basically the same mistakes.

[01:12:20] So it's designed to hide everything from ha from every one. That's the whole idea behind mobile coin. So the problem is if you start to integrate advertising systems into supposedly secure communication channels, what's going to have. If you start to take things like a cryptocurrency and put it into a secure communications channel, then what's going to happen.

[01:12:48] You can bet that what's going to happen is governments are going to step in saying, Hey, wait a minute. Now you can have money flowing. I remember buying a car. And this was back in I think the early eighties and I went to the bank and I got a loan from the bank in order to buy the car. And they gave me eight, $1,000 bills.

[01:13:11] Cause I was going down to the auction car auction and I was going to buy a car and I set myself an $8,000. So the idea was like buy the car and I come back, I pay them back the difference, and then they write the rest stop as alone, man. Weren't those the days, right? When a banker knew you, the banker made decisions on things like an $8,000 loan, I don't know.

[01:13:37] What would that be worth in today's money? 10,020 probably goes to the $15,000 just based on my word. And I walked out of there with thousand dollar bills and. I also had $500 bills. And back then, you used them to pay bills and of course they're worth more today than they were then. Let me put it the other way is actually worth less, right?

[01:14:03] Because of the, in crazy amounts of inflation that we've had. But the bottom line is you could have. Get thousand dollar bills and put eight of them in your pocket. So it doesn't look like you're walking around with a huge water cash that someone's going to steal from you. And then the government decided that, oh my gosh, that's terrible.

[01:14:25] Oh no. Wow. Drug dealers might be using those thousand dollar bills. Oh, yeah, this is true. They might be using them and we all want to start off, stop the sale of illegal illicit drugs. That makes sense. But the war on drugs, we're not going to get into that has been an abject failure and it has resulted in things like the fiscal or w you're not even charged criminally or civilly, and they seize the money.

[01:14:55] You. So they got rid of thousand dollar bills because of course they were only used by drug dealers and people like me, they got rid of $500 bills because of course it was still the drug dealers. And to me who were using them now, the biggest denomination that you can get is a hundred dollar bill.

[01:15:14] Although the treasury is talking about making minting a 1000, excuse me. $1 trillion coin that they would use in order to make payments, right? Yeah. So that, that balances their budget. Cause yeah, they just printed a trillion dollar coin. Anyhow. The problem is that the government wants its fingers in every transaction, whether or not there are drug dealers involved and that is causing us nothing but headaches and heartaches, frankly, it's a real.

[01:15:49] Problem. So when you get Marlin spike, tallying people, that signal is going to include a cryptocurrency called mobile calling that is designed to be absolutely private. That's when they government starts freaking. China already has a cryptocurrency. In fact, they've been trying to peddle their cryptocurrency for use by governments around the world to trade for oil.

[01:16:21] Remember the United States time was when our currency was supposed to be the standard. Remember that the standard for. Doing transactions worldwide crypto type transactions is where China wants to delete it. And what they're trying to do when they lead it over there is get the U S dollar out of the way.

[01:16:43] He can't say as I blame them lately, but they have been testing it already here. This coin, mobile coin cryptocurrency. What do you do now, if you're trying to have a private conversation, I started out by mentioning telegram, WhatsApp and signal. Now we just talked about the biggest problem with signal right now.

[01:17:06] We'll talk about it. Security in just a minute. Let's talk about WhatsApp. WhatsApp's biggest problem is that it was bought by Facebook. Should they have been allowed to buy them? It depends on how much of a free market person you are, should the government have stepped in and said, no, you can't do that because frankly, WhatsApp was a competitor to Facebook and Facebook just bought them because they have so much cash.

[01:17:28] So WhatsApp's problem is Facebook. And remember last year, January, 2021, I think it was. Facebook said from now on, we are going to be inserting ads into your WhatsApp communications. Yeah. That kind of got people a little upset for very good reason. How about telegram? Telegram is not secure. It has never been secure.

[01:17:55] And a lot of people switched over to telegram because of what happened with WhatsApp and Facebook saying we are going to be putting ads into your WhatsApp channel. So tens of millions of users switched to Della gram. Yeah, it was a nightmare for WhatsApp last year, but frankly, the, it changed. WhatsApp changed Facebook backed off because some people were upset, but they're ultimately going to go that direction.

[01:18:26] That's who Facebook is, they make their money off of us. Now signal is even more secure than WhatsApp. Telegram is not secure at all. Okay. So forget about it. Don't use telegram. They've got this cloud-based architecture. That's truly, it's a serious risk when compared to end default encryption, that's used by signal.

[01:18:48] Why? So right off telegram, if you want a secure private conversation, but one tap and signal both have end to end default encryption. So why would I say that signal is more secure than WhatsApp? The bottom line is that WhatsApp keeps some of your data in. Okay. And that's where the problem really comes in with signal.

[01:19:17] Everything is encrypted. Everything is obfuscated. Okay. Telegram, you can delete messages, chats, call histories, groups, any time that you create them in afterwards deleted items, completely disappear for all participants without our trace. There, there's just all kinds of problems, but now I'm concerned about signal.

[01:19:36] That signal has been doing a lot of stuff in order to keep the bad guys and snoops out of their streams. And that includes even putting in codes that are known to crash some of the devices, the criminals and law enforcement, even you. Build it right into signal, which I thought was just hilarious because there's this tool that I'm referring to terminate Israeli company is using some open source software that they have not patched in years solely.

[01:20:10] It's it's absolutely fun. So keep all of that in mind. In reality signal is. Everything it possibly can to keep your data safe. I am concerned about the fact that they're going after this coin mobile thing, trying to integrate it. I can see why they'd try and do that. Facebook has released its own cryptocurrency last year.

[01:20:36] I didn't really go anywhere. They've relabeled it a couple of times, and Facebook wants to become your payment centers as well. So you can use Facebook messages in order to send money and potentially use WhatsApp as well. Apple, by the way, is using encryption end to end for I message. But there is some concern about iron message particularly lately because apple has been using its own backdoor keys for some of the data that you store.

[01:21:10] And I'm a little unclear as to how I message fits into that whole. But WhatsApp is free. Signal is free. Telegram is free, but it's becoming clear the price you need to pay for it because Facebook basically broke WhatsApp. And because of that radical change and you can consider it to come out further.

[01:21:36] And we know that Telegraph is just not there and hopefully signal's going to smarten up here and not try and get the re federal regulators involved because of monetary transactions. Although, technically it's not money, right? It's a cryptocurrency. Should you stop using WhatsApp? The short answer's probably, no, I do use it with one of my mastermind groups.

[01:22:01] Nothing's really changed after the pushback from people who've been using it. That's the short app answer, but your signal whenever you can, it just makes. Hey, thanks for joining me today. Spend a little time over your weekend and I'd invite you to also go online. Go to Craig peterson.com. Make sure you sign up for the newsletter.

[01:22:24] I've got a special report on passwords this week.

View Details

What Can Be done About Russia?
What Can You Do?

There is a whole bunch going on when it comes to Russia, of course, the invasion of Ukraine. Why are people calling to have dot RU deleted?

This is really a big deal. And if you're watching from home, I'm going to go full screen on this article.

[Automated transcript follows.]

[00:00:23] This is an article from ARS Technica, and I've been talking about it all week, which is that I can won't revoke Russian in Jeanette domains, says the effect. Devastating. This is frankly pretty darn fascinating to me because I can, as this international organization, it was put together in order to help make the internet international.

[00:00:49] And I'm not talking about the data international, but control of it. A lot of countries work. Because of course the internet was created in nodded states. It was created by us tax payers, money for the DOD. And it was designed to be very resilient, in fact, so resilient that there could be a nuclear blast and that nuclear blast and.

[00:01:13] Causing problems, but yeah. Yeah, the internet is still going to work. And the whole idea behind it was you could have multiple routers. They're all talking to each other nowadays. They're talking BGP four and they can say, how can I get from here? To there. And so the idea behind BGP is they all share this information once the least cost way.

[00:01:36] What's the easiest way to post way. If you will, for me to get from point a to point B and it changes all the time. So you might be on a phone conversation. You might be listening to me right now, online streaming or watching the video you might be doing, who knows what out there with digital communications.

[00:01:57] But the communications channel that you think you're using, where the data is going from, let's say my microphone, ultimately to your device, your ears, that data path, once it becomes dated. Can be changing multiple times a second. Now it actually changes quite a bit. Initially as these internet backbone routers, send the least cost, routing information back and forth to, and fro a very good thing, frankly, because it helps to speed everything up.

[00:02:28] And there's other tricks that we're using you. Might've seen. For instance, Akamai and some of the URLs before have sites that you've gone to, and that's called a content delivery network and that helps get the content to be closer to you. So if you're on a website in California and you're in New Hampshire, that website video, that website graphic, et cetera, is going to be coming from a server local to me here in New Hampshire.

[00:02:59] All right. That's how that all is supposed to work. So we have names you guys know about that internet, domain names and those domain names. You already know those are turned into internet addresses, and those addresses are then used by the routers to figure out where to go, how to get the data. The problem that we're having right now, of course, is Russia seems to be substantially abusing the intranet Putin, put a kill switch on to the Russian internet sometime ago.

[00:03:31] And the idea behind the skills, which was, Hey, listen, if we don't want the world to be talking to us, we'll just cut it. Now he's tested it a couple of times, but what he has not done is shut it down and he hasn't shut it down. As part of this Ukraine, more, what they did is they passed laws saying, Hey, if you publish something that disagrees with what we're saying, you get 15 years.

[00:03:59] And even these people who've been protesting on the streets, they're getting a bound 60 days, 30 to 60 days in jail, just for protesting what's going on. So a lot of people have been saying why don't we just, we turn off the Russian internet now we're not going to use Putin's kill switch in order to shut it all off.

[00:04:19] We're not going to do a well, a few things. She decided not to do, denial of service attacks, et cetera. Although there are hackers doing that and we are going to talk about that today, but they're saying what? Let's just go ahead and let's kill their dot R E. The country domain. And I can, the guy who heads it up said, Hey, listen our mission is just to make sure that the internet works.

[00:04:46] So shutting off the dot R U domain so that no one can go ahead and. We send right. A request out to the domain name servers and get a resolution to an IP address. So if you try and go to Kremlin dot REU or something, you will get blocked and you will get blocked. Not blocked. No, I like the great firewall of China or of Russia.

[00:05:10] Now they've got one going pretty good. Yeah. Thank you. You ain't using us technology. It's crazy. What we've got. But what it does is it says, oh, I hide dot, are you, I don't know. What are you talking about? So there have been a lot of people who have been pushing for it. And you'll see on my screen here that you cranes requested to cut Russia off from some of these core parts of the internet.

[00:05:35] And I can, which is the internet corporation for assigned names and numbers. I couldn't remember what that was earlier said that I can must remain neutral and their mission they say is not to take punitive actions. It's to make sure the internet works. So are they really taking punitive actions of the cat Russia off?

[00:05:56] It's really interesting to me because look at what has been going on. You've got companies like Facebook as the great example who has gone ahead and just shut off people. They didn't like what they were saying. My goodness. At one point of you said you should wear a mask during this pandemic.

[00:06:15] You would be cut off from Facebook. And then of course, if you said, no, you don't, you shouldn't don't need you, you shouldn't wear a mask that at that point you would be cut off, because science right. Sciences, we know exactly what we're doing now. It goes on and on. If you said that it came from a lab in China, you would have your account suspended.

[00:06:35] Now of course their whole tune has changed and yeah probably came from a lab in China. It's crazy what these people have been doing. So we have arbiters of truth, who are some contractors sitting in their home or wherever it is the contractors for Facebook that are going through posts that people are flagging as Incorrect as fake news.

[00:07:02] So what happens is people say fake news and then that goes off to their team that then looks at it and says okay. Yeah, fake news because we disagree with it. It just blows my mind. We have to have free and fair and open discussions. Don't we. You have that line at Facebook and Google does some of the same.

[00:07:22] A lot of these sites do a lot of the same. You get our major media outlets that are all deciding what they want to report on and what they want to label as fake and fake news. I'm just shaking my head because it's hard. It's hard to believe. What about. Russia is putting out fake news, as I've said many times before the E the first casualty in war, this isn't my quote. The first casualty in war is what, it's the truth. So if truth is the first casualty, then that means we've got a lot of propaganda going on. We had propaganda coming out of Ukraine. We've caught some of those, like the, what was it? The. Chat goes, fighter, pilot, whatever it was who had killed, what was it?

[00:08:12] Five Soviet or Russian jets, Soviet era using silver deer, techno era technology on the part of the Ukrainians turns out well. Okay, that, that was false news. That was fake news. The whole thing about snake island, where you had that Russian military. I know what it was a frigging but anyways boat sitting there saying we are a Russia.

[00:08:33] Warship, you will surrender or, whatever. Do you remember that snake on just the small place, 13 guys and supposedly they shelled it and they killed all 13 turns out that was probably fake news as well. So that's from the Ukrainian side and on the Russian side they hardly reported I as to how many.

[00:08:57] The we're in fact, initially for quite a while, they were saying there are no desks. Then at the same time, the Ukrainians are saying they're 2,500 Russians dead. And that number keeps going up, who knows what it is today. It gets really crazy in the time of war. So if Facebook is going to stop someone from saying don't wear masks or do wear masks, depending on what day of the week it is basically right.

[00:09:20] Wednesday. It's okay to say that Thursday is not okay to say that we're back. No it's not. Or then why can't that type of censorship? Move on to the next. I that's a big question I have now. Should we be shutting it off? I'll pull this back up on the screen again. And it, this article from ARS, Technica is saying that experts have warned, whoever they are that shutting down the dot R U domain.

[00:09:53] Is going to cause just incredible problems for Russians, which man would it ever talking about a major blow to the economy. And it would also cause problems for people who are trying to find out more truth about. Russia cause you couldn't get to their site. Now we've seen some amazing things in Russia.

[00:10:15] We had the Russian, one of the Russian news agencies are T which is broadcasting and here in the U S that their entire staff just walked out saying, forget about it. We're not going to promote this fake news, but this is a little to do trip question me personally. I don't think anybody should be censoring any.

[00:10:38] For almost anything. Yo, there are some limits, but they're pretty extreme in my book. I'd rather know someone is an idiot because they're allowed to say stupid things, and counter, counter it, counter their arguments. You've got to have discussions

[00:10:54] Microsoft. Yeah, they've been around a long time. They've been helping us. They've had lots of cybersecurity problems. People use Microsoft software on their desktop. Some people use it for servers, which is crazy, but listen to what they're doing now.

[00:11:10] This is a little concerning. I'm going to pull this article up on the screen.

[00:11:15] For those of you who are watching a long, either on rumble or YouTube ARS, Technica article, they have some really great articles. This particular one is about our friends at Microsoft. This is cool. Microsoft announced today? This was like a week or so ago that Microsoft would be suspending all new sales of Microsoft products and services in Russia.

[00:11:45] Following the countries, unjustified, unprovoked, and unlawful invasion of. Now Microsoft didn't give any specifics about the products, but it really is likely to be a blanket ban of all of the Microsoft products. This is very cool because Microsoft has taken an approach I've never seen them do before, which is okay.

[00:12:10] When. Gets hacked. You get our friends at apple, putting together patches and getting them out. They get them up pretty quick. Microsoft had been doing much the same. The problem was some months there were patches every day that you had to apply. That's how bad this software is. And they decided that man, let's be like politicians here.

[00:12:34] Let's release some very damning news Friday. At about 4:30 PM before a long weekend. So no one will notice. Yeah. Y'all are friends of politicians do that all the time. What Microsoft decided they do is, Hey, wait a minute. We're going to have patches. It's not going to slow down. And because our code is terrible.

[00:12:56] So what we're going to do, let me see here. How about we just release all of them at once and we'll just call it patch Tuesday, right? Because people were complaining about how much work it was, how much effort was effort. It was to try. They hate them. These machines apply these patches every day. Huge problem for everybody from home users to big companies out there.

[00:13:21] So Microsoft has said, okay let's do that. Let's burry it. So nobody will notice okay that's what Microsoft does. And now we've gotten used to that. Now we have. We remember two guys, right? Bill gates followed by Steve Ballmer. Steve Ballmer was a nut job. Bill gates was a bad man.

[00:13:40] I think he's just been trying extra hard to compensate for all of the evil he did over the years. But what we're looking at now is new management and that he's been in there now for a few years, doing a great job, cleaning up Microsoft, making it a very competitive company. He has done some amazing things.

[00:14:02] One of the things that he has decided to do, that's been very effective is how about this? How about we go ahead. And we work with various governments to help stop these Russian hackers. And I mentioned this a couple of weeks ago, what was happening and the Microsoft had reached out to the white house and said, Hey, listen.

[00:14:27] What we have been looking at the hacks that have been coming from the Russian hackers, and we've been preparing fixes for some of those hacks. How about we work directly with some of these other countries? This reminds me a whole lot of the lend lease program in world war two. You might remember this thing, but the us of course, initially was not involved in the war and they decided, okay we've got to help the United Kingdom.

[00:15:00] How are we going to help them? The UK doesn't have the money to buy ships, to have us make weapons, bullets know. What they did is they had people donate the rifles, the guns, AML from home. Plus they made them the government, instead of selling them to the UK, they lent them to the UK because the UK could not afford everything that it needed in order to fight a war against the national socialist in Germany.

[00:15:28] So what did they do? We just shipped the stuff over there and called it a lend slash lease. I think that's a great idea. And what Microsoft is doing is also great idea. They have been decoding, reverse compiling, if you will, and interpreting the code, looking at what some of the ransomware and other malicious code the Russia has been using against Ukraine, and they have been providing.

[00:15:57] All kinds of insight information to these other countries. Now, this is a great idea for a few reasons, one of the reasons, and I think maybe the biggest reason is that the ransomware, the viruses, all of this malware that they're producing is. Not particularly discriminating. Do you guys remember maybe I dunno, what was it?

[00:16:22] Six months ago, I taught, told you how to avoid getting most of this Russian ransomware. And it was as easy as just installing. Yeah, installing a keyboard on your computer windows or Mac, windows. Those are the machines are always getting attacked quite successfully most of the time, but the windows keyboard.

[00:16:49] Russian language. Now you didn't even have to use it. You don't have to have a keyboard, right? This isn't a Russian keyboard that I'm holding up here on camera. This is just a regular us keyboard. You can just install a virtual, Russian keyboard. And once that keyboard was installed, you're pretty safe.

[00:17:06] Why? Because Vladimir poop. Dictator for life of Russia decided he would just go ahead and stop anybody that was trying to hack Russian. Companies businesses, government agencies and what's the best way for the hackers to do that. Cause they didn't want to end up in Siberia for the rest of their lives because of a hack.

[00:17:29] Now they went ahead and said, okay if there's a Russian Cyrillic keyboard on the machine, we're not going to activate. So if the software, the malware on your computer, all you need to do is have a Russian keyboard. Yeah, that's it pretty simple. I told you that months ago, now what we're seeing is these indiscriminant types of software that are being used in Ukraine.

[00:17:57] Why doesn't the keyboard trick work while some of Ukrainians peak Russian, we could go in. To the background on that of the massacre, the starvation purposeful starvation of Ukrainians by the Soviet union over many years ago. And how they then gave their property, their homes to Russians to move into in order to occupy Ukraine.

[00:18:23] So there's people in Ukraine who are Russian speaking of course. Now we're talking two or three generations, four, maybe down the road from when the Soviet union killed all of those millions of people. But there are some fights that to say, there's Russians, Russian speaking people there. Let me put it that way.

[00:18:41] Perfect. In Southeastern Ukraine anyways I'm going on and on I, this is not an education on war or history. This we're talking about cyber security. So the, they have, they been, Microsoft found many cases of Russians putting destructive. And disruptive or even more than that data wiping malware onto computers, it spreads indiscriminately.

[00:19:13] So Microsoft looking at what's happening, you crane, trying to get patches together for all of us, letting other countries know about what's going on is going to be. Amazing because this malware, which is wiping computers, primarily, it's not really just straight up ransomware give us money and we'll give you your data back.

[00:19:35] This is just showing your data, that malware is going to leak outside of Ukraine. Yeah. Cause us all kinds of book tension, probably. When we get back, I want to talk about this here. This is our friend Ilan Musk, and we've been following along with some of the stuff been going on with his new satellite system in Ukraine.

[00:19:58] The whole concept of these satellites and circling the earth, providing us with internet, just regular guides. It's going to be in our smartphones is changing everything. We're going to talk about Elon Musk and what's happened over in Ukraine.

[00:20:15] Our friend Elon Musk has done a lot of things over the years. He has really helped us for frankly, the Tesla and what's been happening there.

[00:20:26] Space sex, his main concern being let's get. Off of a single planet on to multiple planets, right? The movement to Mars, NASA's working on a serious moon base. I reminded him of space 1999. You guys remember that show, but yeah, we're going to have a moon base by then and it makes a lot of sense. So who's going to go to these well, there's some interesting lotteries people have to apply and everything else, but he's done so much, right?

[00:21:00] He's got the boring company you'd already know about Tesla and boring company in case you didn't know makes underground tunnels. He has also. A few other things has got a huge battery manufacturing facility. They're working on new battery technologies to make all of our lives a little bit better, particularly if we have an electric house or electric car, because this is what good is it to have electricity that you can't use.

[00:21:25] And that's really what they're trying to do is make it so that electricity is available 24 7 for you. And. Those space X, which is what I mentioned as well as what we're going to talk about right now. I'm going to pull this up on my screen. For those of you who are watching over on rumble, or of course, YouTube, this is fascinating.

[00:21:49] He said there's a high probability of Russian attacks on Starlink in Ukraine. Now that is fascinating because what he's done is he has sent over truckloads. I'm showing a picture of a truck. In fact, with these Starling terminals in it, that's from ARS Technica. Just double-checking it here, but this is very cool.

[00:22:12] This is posted by the vice prime minister over there in Ukraine. And they are talking about these terminals. Now a terminal in this case is something that allows your devices to talk to the Starlink satellites, or there's going to be a huge constellation. They've got 2000 satellites up and they're putting another 12,000.

[00:22:38] These types of satellites are much different than what we've been used to over the years. We typically we've had these massive things sitting up in space. I worked with RCA Astro space many years ago and I saw. They're testing facilities, which are just incredible. They had this huge vacuum chamber that they brought me in to see as we were working on space shuttle software.

[00:23:05] Yeah. I wrote software that they used to put the space shuttle together yeah. Way back in the day. So that was a pretty proud moment. Anyways. It's we're not talking about these huge satellites, like they used to launch, we're talking about very small cell. And they're not just sitting way, way up there.

[00:23:26] These are in basically in low orbit around the earth and they're geostationary. In other words, they stay in one spot. I believe this is the way they've got these things set up. So these satellites then allow because they're so close to the earth, allow them to use less power. And also the other advantage to that is.

[00:23:49] The delay, right? The delay between having to send it all the way up and back down, because electricity takes time, right? Yeah. Travels at the speed of light. But nowadays you might've noticed it can take your quarter second, half a second. When you're talking to someone, when I'm on the radio with some of these radio stations or the delay can be absolutely incredible.

[00:24:11] Like I half second to a second sometimes. And that's just because they're being cheap. This type of technology where you have these constellations and it isn't just Elon Musk. It isn't just Starling, but constellations with will ultimately we'll have tens of thousands of satellites up there. Not, there's all kinds of other potential problems not getting into that right now.

[00:24:34] But what it does mean is. Can communicate and we've never had this sort of thing before we had the us military, the Navy in fact, put together a communication system that lives on top of the internet and called nowadays. Generically the dark web. And it was set up to allow our military, our state department to be able to communicate with people in countries that are back in the day under Soviet control, all kinds of potential problems.

[00:25:10] So whenever those problems existed, they just went ahead and used this onion network, which is a part of the dark web, et cetera, et cetera. So let's say we had before. Now what happens if you're a country like Ukraine, where 100% of your internet comes from Russia, Russia obviously can sit there and listen in.

[00:25:32] Hopefully your encryptions. Good. A lot of Russians have been using telegram and already get real news about what's happening in their country and other places. And Della Graham is not that secure, frankly. WhatsApp pretty secure signal is the one you want to pay close. Attention to signal is considered to be the most secure of all of these secure communications apps.

[00:25:57] But there's a level above all of that, because if they can tell that you're communicating, even that is enough to give them some information. So they might not know what was in that transmission, but if the transmission is all of a sudden, a tons of activity coming over, lots of data, lots of messages going back and forth, they can say maybe there's something about to happen.

[00:26:21] That came out. You might remember the old orange book for security way back in the eighties, I think is when it came out. But part of what you had to do was cover up your. Actual real communication. So it's one thing to have the communications encrypted, but you wanted to always have about the same amount of communications going back and forth.

[00:26:42] So people couldn't figure out what you're doing now with these types of devices. That kind of problem still exists. And this is part of what Elon Musk is warning about here. Pull it up on my screen again, for those people who are watching Elon Musk is urging users of his satellite system to put their Starlink antennas as far as.

[00:27:08] From people as possible. Now, why would he be doing that? Because frankly, that terminal is transmitting to the satellite as well as receiving from the satellite. And it is entirely possible that there could be some evil software that is listening in for the satellite transmissions and sends a little missile your way.

[00:27:36] Also, of course the Russians have satellites in space that can look down on the ground. Now it's something as small as a terminal four Starlink, little hard to see, but Elon Musk is saying, Hey, listen guys, go ahead and camouflage it. You might want to spray paint. It just don't use metallic paint so that they can't see it and place it as far away from where people are as post.

[00:27:59] So you can still use it and only use it when you need to use it. Don't keep it up and running all the time. But this is the start of something great. Something where you can't easily block people's communication. So Russia has tried to do. And they have been jamming the Starlink satellites. So what did must do?

[00:28:23] He delivered all of his engineers to working on how can we get around the Russian Jack? And according to Elon Musk, they have gotten around it and they now have their satellite systems completely jammed free from the Russians. I think that's fascinating. They're probably using some good spread spectrum technology that was actually known about it and world war II.

[00:28:47] And then we can talk about that for a long time. Heady, you might remember her anyways, skip that for now. Stick her out. We got more when we. A whole bunch of pandemonium out there because of what Russia's been doing in Ukraine and how it's flowing over to us as well. Hey, this is not great news.

[00:29:15] Pandemonium is the name of the game over there in Russia. And they are being very successful. We're going to talk about what happened in Bella ruse. We'll talk a little bit about what happened in Ukraine with cybersecurity and what's happening right here right now.

[00:29:36] Complete ARS Technica today. They've got some great articles this week, looking into the Russians. What are they doing? What kind of problems is that causing us? But we are seeing some interesting attacks back on. And back in very big way. Russia has been going after you crane in the cyberspace for a long time, we spoke a few years ago about what Russia had been doing with the tax software for Ukraine.

[00:30:12] We don't do this in the U.S. Or in Canada, but my number of European countries do you, where you have to have. The old official tax preparation software put together by the government for your business or for your person, depending on the country you're living in France is a great example of this. And Ukraine is another one.

[00:30:36] So Ukraine says, Hey guys, you got to go ahead and use our software. That means every business in Ukraine is using their software. To manage their tax payments and their accounts, frankly. And that wonderful little piece of software was hijacked by our friends in Russia. So they grabbed a hold of it. They in.

[00:31:02] Did some code into it that added rent somewhere to the software. So now all of the businesses in Ukraine are pretty much guaranteed to be using this hacked software. We have a client who has offices over in France, and we found a really interesting problem with them because. The French software that was being used for taxes for French businesses had an extra little problem.

[00:31:33] And that extra problem was, it was insecure as can be whoever wrote this, must've taken a Microsoft programming course and had no idea DIA about the consequences of what they were. So it was very insecure. The, it was using a version of SSL, which is an encryption that's based on another type of increase.

[00:31:57] I don't want to get too wonky here, but that was just one of its many problems and bad keys, et cetera, et cetera. And keys by the way, was using keys that have been revoked, which you should never do. Bottom line. Oh my gosh. Hey, if you want more information on this, just drop me a note.

[00:32:16] me@craigpetersohndotcomandyoucanalsogetmynewsletterwithallkindsofgreatlittletipsmeatcraigpeterson.com. Just let me know. So in this case, we had to help that company in France. Ignore the security restrictions that were on their systems so they could use the French tax system. So anyways, I told you that, so I could tell you that the same thing happened to Ukraine.

[00:32:45] In a different way, their software was pre infected. So when they downloaded it, ta-da. They got that piece of ransomware that virus had spread. It was just a nightmare. And of course it robbed. If you will, Ukraine, government of funds, that would have been. So we had now a bit of a shift. I'm going to pull this up on the screen again, this article, because what this shift has shown is that the hackers are now operating on the side of you.

[00:33:21] Crazy. Which is just fascinating. So the group called anonymous, you might be familiar with them. Of course, they've been doing a lot of hacking for a lot of years, releasing private information, government and information, all that sort of stuff. And they have a mast what they're calling a volunteer.

[00:33:44] It. And this it army has been going and doing what well hacking Russian sites apparently. So this article is just absolutely fascinating and they pulled some of from wired as well, but the Russian space research Institute, their website was hacked, leaked files that were stolen from the Russian space agency, made it all the way on to the.

[00:34:13] The space agency was hacked in their website said, leave Ukraine alone, Alto anonymous. Will you up even more? They also did. What's called a D O S. Which is a distributed denial of service attack. Those can be very difficult to protect against unless you're set up in advance to help protect yourself.

[00:34:39] And that pretty much destroyed Russia's dot are you top level domain? So we've talked about how domain services work, right? So Doug are, you is like.com except dot R U is for running. And so the domain name servers that handled our, you were knocked off the air because no one could really get to them.

[00:35:02] They used amplifying attacks and stuff without getting into all of the details. So basically they were trying to cut off access and they did for a lot of people to any. That ended in, are you? It's great. These are just some of the latest in this surge of hacktivism. That's been going on one of the ones I mentioned a couple of weeks ago with the Belarusians deciding they were going to hack the Belarus railroad, which was being used.

[00:35:31] To bring Russian troops, supplies, tanks, et cetera, all on rail, right on down right to the border of Ukraine. So that was hacked so that they couldn't use it in order to go after. Of course Russia was able to get to Ukraine, but there's also been protests around the world. 48 Russian cities raise millions of dollars through cryptocurrency donations.

[00:36:01] Now, I'm not a big cryptocurrency guy and I'm not a big crypto currency guy because while. Cryptocurrency is likely to be outlawed by most, if not all governments. And they certainly could shut it down and it is not anonymous. All right. So using cryptocurrency does not mean it does not equate to completely anonymous.

[00:36:28] They have done a lot of donations. They're big companies including, we just talked earlier about Microsoft, but also apple shell, BP, a McDonald's Starbucks. And these hacktivists have really joined in. And w we talked about a couple of other things, so this is messy. Because even more than in peace time, these active combat that are really hacking happening right now, rendering, hacktivism, any effectual and largely just distracting because we are now in a hot war right now.

[00:37:10] Maybe we don't have our. Eric planes bombing Russian movements or other things, but there is a kinetic war going on over there. There are bullets, et cetera, mean exchanged. So the hacktivist efforts have been, visible. There's no question about that. But what have they done? See, that's an advantage to being a country like Russia, or like the Ukraine, or excuse me, Ukraine, because both of those countries there, their industrial base, the military industrial base is not heavily automated unlike ours.

[00:37:50] What could you do? What can you shut down? So what you shut down the Russian space agency's website, how far did you get into it? Probably not very far. We also have a couple of groups and we talked about these guys many times the Conti group, which has been.

[00:38:07] Terrible and hurting us businesses, individuals, government agencies, and stuff, the Cuming project, both of them have declared their allegiance to Russia. You might remember a few weeks ago, we talked here about how we have had some researchers track down most of these Russian hacker groups and their money.

[00:38:30] And they all ended up in one building in Moscow. No, that should tell you something, right? In fact, the most expensive real estate right there in downtown Los gal, the tallest building, et cetera. So these groups getting together in order to protect the father land there in Russia. Ah interesting problem.

[00:38:52] How much of this is really controlled by the Kremlin? It's a very good question. Context. Was dismantling its infrastructure. It, some of their top people were arrested by Putins military. Not military, but police state over there. And that was interesting too. That was again before the invasion, but why would Putin be shutting them down at all?

[00:39:20] Apparently they said some things. That they shouldn't have said. So now they've come out and have decided they're going to support Russia in its entirety. Now we mentioned Microsoft and how Microsoft has decided they are going to protect other countries. As well as you crane, at least as far as the Russian malware goes, and they've been very active in that.

[00:39:46] And there are a number of cybersecurity companies and other organizations that have released free versions of some of their software, these digital defense tools. Free offerings. Our big cranes defend the networks. Google says it's human rights focus de dos protection service project shield is now in use by more than 150 Ukrainian websites.

[00:40:12] So it's very good. Bottom line propped up by the way, published this massive trove of personal data. Allegedly identifying 120,000 Russian soldiers deploy. In Ukraine that was Ukrainian prov, not the old good old Russian Sophia Pramata man. I remember I bought one of those on new standing Canada once.

[00:40:36] And I had a friend who was from Yugoslavia and he said, oh, can I show that to my wife? He showed it to his wife. She tore it up. I said, I want my Pravda, Craig Peterson dot com.

[00:40:47] The tech world is all a buzz with this log for J or log for shell. However you want to call it because we are looking at what is probably the biggest security vulnerability the internet has had in a long time. I don't know how to express it anymore, but there are multiple problems here. And even the patch that was released to fix this problem was broken as being exploited in the last 24 hours. There've been no less than 30 different new. Variations of the exploit. So what is going on? There is a computer language that's used by many programmers, particularly in larger businesses called Java.

[00:41:37] You might remember this, I've been following it and using it now, since it first came out very long time ago from sun Microsystems. Java is a language that's designed to have kind of an intimate. CPU processor. So think about it. If you have an Intel chip that is an x86 type chip, what can you use instead of that Intel chip to run that code?

[00:42:03] There are some compatible chips made mainly by AMD advanced micro devices, but you're really rather limited. You have problems. Power. Guess what you're stuck. You're stuck in that architecture. And then on the other end of the spectrum, you have some of these devices that are designed by companies like apple, Google has their own.

[00:42:24] Now that our CPU's their graphics processing units as well. And they completely replaced the Intel architecture. But the Intel code, the programs that are written for the Intel architecture that are compiled for Intel are not going to work on the apple chips and vice versa. So what did apple do? Apple, for instance, just moved from Intel over to.

[00:42:51] Own chipsets and these chips don't run Intel code. So how can you run your old apple apps? Apple has a little translator. They call Rosetta. It sits in the middle and it pretends it's an Intel processor. This really rather simple. And they've done an amazing job on this. And w Rosetta is actually a third party company and they helped apple as well with the transition from the IBM power series chips to the Intel chips.

[00:43:23] So how do you move the code around while you either have. Recompile it, you may have to redesign it, rearchitect it for the new type of processor and the new types of computers that are supported by that processor. Or you may do what Apple's done here a couple of times now, and that is having an interpreter in the middle that pretends it's something else pretends as an Intel chip.

[00:43:49] And then you can still run your in. Code because it knows, okay. It was designed originally for this apple Intel architecture. So I know how to make all of this work Java steps in and says why are you doing all of that? That's crazy. Isn't it moving all of your code around all of the time. So Java's original claim to fame was what will make life easy for?

[00:44:14] What you do is you write your code. Using Java in Java is very similar to C plus in some of these other languages that are out there. And that language, when you're writing your source code will be compiled into an intermediate. Code. So what happened is sun Microsystems designed this virtual machine?

[00:44:36] Now don't think of it like a normal VM, but we're talking about a CPU architecture and CPU instructions. And so what it did for those CPU instructions. Which is really quite clever, as I said we'll come up with what we think are the most useful. And it's a Cisco architecture for those of you who are ultra geeks like myself.

[00:44:59] And we will go ahead and implement that. And so the compiler spits out code for this CPU that doesn't actually exist anywhere in the known universe. And then what happened is sun went out and said, okay we'll make an interpreter for. Artificial CPU that'll run on Intel chips and we'll make another one that runs on these chips, that chips and the other chips, beautiful concept, because basically you could write your code once debug it and run it off.

[00:45:32] Anything that was one of the original claims to fame for Unix, not so the run at anywhere part of it, but the part that says it doesn't take much work to move your code to different machine, and we're not going to get into Unix and its root I've been around the whole time. It's crazy.

[00:45:51] I just finished reading a book and saying, I remember that. And they were going through all of the history of everything I was in the middle of that. I did that. That was the first one to do this. It was fun. Anyhow, what Java has done now is it's really solidified itself in the larger enterprises.

[00:46:11] So basically any software that you might be using, like our website that is particularly with a larger business. Is going to be using Java and that Java language is using libraries. So in programmers, instead of doing what I used to do way back when which is write in assembly code, or even in COBOL, and basically you had to write everything, every part of every program, anything you wanted to have done, you had to write, or maybe you borrowed somebody else's code and you embedded it in.

[00:46:45] And mind you, we only had 32 kilobytes of memory in the mainframe back then the 360 30, for those of you who remember those things, but here is where things really changed. You now had the ability to take that code that you wrote and put it on a smart. You could take that exact same code, no recompiling or anything, and take that code and run it on a mainframe on our super computer in a car.

[00:47:15] So Java became very popular for that. Very reason in these libraries that Java provided, made it even quicker to program and easier to program. Now there's some problems with languages. Java, which are these object oriented languages where you can, for instance, say one plus one equals two. That will make sense.

[00:47:38] But what does it mean when you use a plus sign? When you're talking about words? So you say apple plus oranges, what's that going to eat? That's called overloading an operator, and this is not a course on programming languages, but what happens is a person can write the library and says, oh if the programmer says a non-Apple plus an orange or string plus a string, what I want you to do is concatenate the strings.

[00:48:06] Now that programmer who wrote that has to figure out a couple of things, make some assumptions. Oh I should I put a space between apple and. Or not. And what do they really mean? Okay. So this is how I'm going to interpret it. So that, it's a very simple example. But the concept is that now with these overloaded opera operations and these libraries that can go deep deep, you now have the additional problem of people designing and writing the libraries, making assumptions about what the programmer wants and what the programmer needs.

[00:48:43] Enter the problem with the log for J vulnerability. This is a very big deal because we're talking about a library function that is being used in Java by programmers. Now, you know that I have been warning everybody. Android for years, the biggest problem with Android isn't its user interface. It isn't that it's made by somebody else.

[00:49:10] The biggest problem. And of course, this is my opinion is that Android software is provided by Google and. It is given basically to any manufacturer that wants to license it. And then that manufacturer can't just take Google and run it. Have you ever tried to install windows or Linux or free BSD?

[00:49:36] It's mainly a windows problem, frankly, but you go on ahead and install that. And what do you need in windows? You're going to need driver. Oh wait a minute. This laptop is three years old. So how can I find them? And then you go around and you work on it and takes you a day and you finally find everything you need.

[00:49:53] And you've got all of the drivers and now it works. But Microsoft provided you with the base operating system. Why do you need drivers? You know the answer to that and it's because every piece of equipment out there is different. Think about this in the smartphone market. Think about it in the more general.

[00:50:10] Android market. There are thousands of these devices that are out there and those different devices are using different hardware, which require different drivers. So when Google comes up with a software patch, how well we just fix the log for J issue that patch. Has to be given to the devices manufacturer who then has to talk to the manufacturers of the various components and make sure that the device drivers that they're using by the manufacturer are actually compatible.

[00:50:50] They're going to. Got the upgrades, wire it all together, and then test it on all of the different phones that they have and cars because the cars are running it. Now you see how complicated this get. And most Android devices will never. Get another update. They will never get a security patch versus apple.

[00:51:14] Right now. They're still supporting the apple six S that came out in 2015. If I remember right, it's five or six years old. Now you don't find that in the Android space. You're lucky if you get two years worth of support, we're going to continue this. But this is this is really important. I'm going to talk more about the actual problem.

[00:51:36] What is being done about it? What you can do about it as an individual, a home user, and as a business, in fact, keep an eye on your mailboxes. Cause I've got some more links to some sites about what you can do and how to do it and how to test for it.

[00:51:53] We're talking about what is likely to be the biggest set of hacks in internet history right now. It's absolutely incredible what's going on. So we're going to talk about what it means to you and what's really going on. This whole problem is probably bigger than anybody really realizes because Java, as I explained is a very common computer programming language.

[00:52:23] And it has a lot of features that bigger businesses love. They love the ability to have multiple programmers working on something at the same time. They love the inheritance and multiple inheritance and all of these wonderful features of Java. One of the really cool features is that you can, while your program is running, have the program change.

[00:52:48] It's. That's effectively what it's doing. It's pulling in libraries and functions in real time. And that's where this particular problem comes in. This has been a nightmare for Java forever. It's one of the reasons I have never migrated to Java for any of the projects that I have. Don, it just gets to be a nightmare.

[00:53:12] It reminds me of Adobe flash. It was the biggest security problem that has ever been. And the number two Java and Java is running in the Android operating system. It is the core of the operating system. All of the programs are almost certainly written into. And now we're seeing Java up in the, not just entertainment systems in our cars, but in the actual computers that are driving the cars, running the cars.

[00:53:45] And I get very concerned about this. We had two major outages just this week before this log for J thing came about over at Amazon. And those two Amazon outages knocked thousands of businesses. Off the air out of business. You couldn't get to them. You remember the big problem with Facebook that we talked about a little while back and in both cases, it looks like they were using some automatic distribution of software sent out the wrong stuff.

[00:54:15] And now you are effected. What happens? What happens with the cars? If they push out a bad patch, how are we going to know. What's that going to mean? And if your car has Java in it, are you going to be vulnerable to this? You wouldn't be vulnerable to log for J if your computer wasn't hooked up to anything, but nowadays the cars are hooked up to the net.

[00:54:39] We've had a couple of car dealers for our clients. Who've had the Mercedes we've had Acura Honda and others over the years. And it's interesting going in there now and working with them because they are doing massive downloads of firmware whenever a car comes in. So that car, if they don't have the right kind of networks, that car can take hours to do.

[00:55:07] Dates. And I got to tell you, man, I'm just shocked by so many businesses, not willing to spend the money that it really takes. So the poor technician is sitting there waiting for it to happen. We could make it happen in 15 minutes, but they're stuck there waiting for three or four hours sometimes for some of these downloads, no it's called cash them locally.

[00:55:26] These cars, some of them need new and different firmware. Some of them use the same and have. A reliable, fast internet connection. And we've done that for many companies. Anyways, I'm going off on a bit of a tangent here. So forget that let's get back into this with Java. You can have a routine.

[00:55:48] Call another routine that was not even necessarily thought of by the programmer. Now, can you imagine that? So you're programming and you're not considering adding something that's going to send email out and yet you could have a log in. That's part of the DNS and it gets logged that actually causes an email to be sent or causes anything else to happen.

[00:56:17] That the exact problem we're seeing right now, it's absolutely crazy patterns in text fields, things like you can put a user desk agent. Which is normal for nature. UDP connection. You say, this is usually a guy who using Chrome version bar or Firefox or safari, but you put the user agent field.

[00:56:40] And then after that, you've put in some, a little bit of code that tells Java, Hey, what I want you to do is this. This is a problem because we're finding now that I'm, again, I said the last 24 hours, 30 different exploits over a million companies have been attacked on this. And we're talking about 10.

[00:57:05] Companies, absolutely hacked every minute right now. Can you think of, let's just think about that. And we're in the middle of what, right? The big holiday season, we've had some holidays, there's people online, shopping there's businesses that are trying to buy stuff, business stuff, almost every one of those sites is likely to be compromised.

[00:57:31] It's that bad. It's absolutely nuts. What's happening here. This is a huge flaw. And by the way, it is flaw. Number this you ready for? This 44,228. In the year 2021. So the written 44,000 flaws that have been discovered and reported, this is the CVE system for those of you who are interested, but this really is a worst case scenario.

[00:58:02] Because this log for J library is being pulled in to so many pieces of software out there on so many different platforms. The paths to to exploit this vulnerability are almost unlimited. And because there's so many dependencies on this particular log for J library, it's going to make it very difficult to patch without breaking other things.

[00:58:32] And the fact the exploit itself fits in. Tweet come injected almost anywhere. So it's going to be a very long weekend for a lot of people, but let me tell you this. It is not going to be solved in a few days, a week, a month. We're going to be seen this. Years, because you have to be the person that wrote the program that has the source code to link in the new libraries, distributed out to your customers.

[00:59:03] Do you see what a nightmare? This is now? Some people are saying let's blame this on open source. This is an open source product. Yeah, it is an open source project and it turns out that even though anyone can grab this, these, this library routine or any of these pieces of code, anybody can grab it.

[00:59:21] Anybody can look at it. It turns out it's one guy. Who actually maintained this, who has a budget of $2,000 a year to maintain it. Nobody else pitched in. And all of these big companies are all out there grabbing this code that this guy has been working on and not paying much attention to it. Not donating to the project.

[00:59:46] Which is saving them millions of dollars, not that one project, but all of these projects collectively in the open source community, it's it is more far reaching than this stretch vulnerability. You might remember this drug vulnerability that's was, that was the root cause of the massive breach at Equifax that Explo exposed all of our personal information.

[01:00:14] To the dark web. That's how bad this is. Oh my gosh. So Hey, if you want information, I've got a links, a bunch of links set up here on what to do while you're waiting for the log for J updates from your vendors, how you can find on your servers. If they have the log for J vulnerability, I've got a bunch of information that I've stored up on that.

[01:00:41] And some others just email me. M e@craigpeterson.com asked for the list of the log for Jay's stuff or the Java's stuff. I'll figure it out. Be glad to send it to anyone that's interested. And if you need to scan to find out yourself and your business, let me know to me@craigpeterson.com.

[01:01:03] Wow. I was just going through a list published by Seesaw, this federal government agency that tracks some of these types of vulnerabilities. And wow, this list is daunting of all of these pieces of software that are vulnerable to this huge hack.

[01:01:19] This is now a problem for each and every one of us.

[01:01:23] I think I've established the man. This is nasty. So what do you do? First of all, I sent out. Email a list of things have in fact, a few different lists of things that you can do. So I had one for consumers, one for businesses and a general thing as well. And then a bunch of references.

[01:01:47] Of course there's even more references and more great information now because I got that email. Pretty early. So I hope hopefully you had a chance to really look through that, but here let's just talk a little bit about this, what to do thing you already know because you guys really are the best and brightest that you need to be careful when you're on.

[01:02:11] You cannot be online, Willy nilly, clicking on things. And that includes emails and links. And this time of year in fact, all year long, we're looking for. Wow, let's see. Is there a great bonus here? Look at they're having a sale, a discount. Oh no. I've only got three hours to respond or the deal's going to go away.

[01:02:33] I've usually been of the sort that I just am, not that influenced by some of these deals, but. I do sometimes want to find out what it is. So I find myself this week clicking through on. I'm on a lot of marketing lists because I like to follow what different marketers are doing, that's technology.

[01:02:55] And it's something I want to keep you guys informed about. And I found myself just crazy amount of double checking to make sure the link was valid. Now I'm sure you guys have, if you're on my email list, you might notice that the from address is not the me at Craig Peterson. Calm email address. You can always send email to me@craigpeterson.com and it ends up in my email box.

[01:03:21] And it might take me a few days, or even as much as a week or two to get back to you. If it's something there's an emergency, you really need to fill out the form on my website, but I will get back with you. But the problem that some people have noticed lately is. It doesn't say return address or sent from me@craigpeterson.com.

[01:03:45] It's got this rather long convoluted convoluted URL that has nothing to do with Craig peterson.com, sows a number of people question it, it is a tracking. When can the idea is if I am going to be able to get back to people and if Karen is going to be able to nudge. I have to have these things tracked.

[01:04:09] So the email from address, when you hit reply, it is going to go to the, again, my email list server guys, and it is going to get tracked so I know. Okay. Okay. So now I've got a few minutes or an hour. Let's sit down and go through a lot of these emails so I can get back to people. That's a problem for many people, that's even more of a problem today than it ever has been in the past.

[01:04:38] Now there's been a few sites that have done something about tracking because many people don't like to be tracked. My self included, although, as I've always explained on the show, it's a double-edged sword because I would rather see commercials or ads for a Ford F-150 pickup truck. When I'm looking to buy.

[01:05:00] Car or certainly a truck. I don't want to see ads for things I don't care about. And you probably don't either. So the tracking, I don't think is a huge deal. The statistics that have come out from apple recently are very interesting because what apple ended up doing is they put some new technology and to stop tracking.

[01:05:25] And to stop you from being tracked. And basically what they're doing is a couple of things. One, they've got this new feature where they will download images and emails from their website, so that it's not they're not being able to localize where you are and then they're also doing something where you.

[01:05:49] Are you are, you can't be tracked like you used to be able to be tracked. Let me just put it simply like that applications now have to have that little label warning label in the app store to let you know what they might be tracking, et cetera. So they've been accepting anti tracking behavior that came from our friends from.

[01:06:13] Apple now Google, Facebook and others have been very upset about this thinking that they were going to lose a lot of business here in the advertising side, because you wouldn't be able to track them. So if you've got an apple iOS device, you probably noticed, it says, allow app to track your activity across other companies.

[01:06:36] And websites, your data will be used to measure advertising efficiency. I don't know that's such a bad thing. And looking at the stats right now, I'm looking at Google's income. And a lot of that comes from YouTube after. Apple launched its new privacy initiative and it looks like Google really wasn't hit very badly.

[01:07:00] What Facebook was worried about that they would just be losing all kinds of revenue. Also didn't turn out to be true. So it's an interesting thing to see and I've got to really compliment apple again. At this time on trying to keep our information private, I read a really great book this, so this is how the world ends talking about the whole cyber race and where things are likely going.

[01:07:30] And it's frankly impressive. To see what Google has done to try and keep out our government from their networks, as well as foreign government and the whole thing with the Chinese hackers we've talked about before, where I've found them. Active inside our customer's network before. And this is where we get called in because there's a problem.

[01:07:57] We look around, we find indications of compromise. We find the Chinese inside. Okay. So it isn't something that we were protecting them, the Chinese got in, but we come in after the fact and have to clean up the mess. But what we have really seen happen here is the largest transfer in. Of wealth, I should say, in history, the largest transfer of wealth in history to.

[01:08:25] From us and from other countries, but primarily from us because of what they've stolen. And so Google really has fought hard against it. The Chinese have been in their systems have stolen a lot of stuff. Apple has fire fought hard against it, but we know about the apple stuff. Google's seems to be a little quieter about some of it.

[01:08:45] So they may be selling our information to advertisers, but there certainly are trying to keep nation states out. I'm really wondering too, what is Google doing? Moving that artificial intelligence lab to China. It just it's insane. We know we, if we're going to get out of this financial position, we're in as a country, we need to have an amazing new technology.

[01:09:09] So people are coming to the United States and we're certainly not seeing that. At least not yet. It's all been stolen. So what to do, man. I started talking about that and we got a little sidetracked. So I will talk about that a little bit more here coming right up and what to do if you're a consumer, if you're a business person.

[01:09:32] And of course, as I mentioned earlier, I have. Quite a list. I'm more than glad to send you. If you go ahead and just email me, M e@craigpeterson.com. I'll keep you up to date, let you know what's happening and give you those links that you can follow to find out exactly what is happening and what you can do.

[01:09:53] Including some tools. There are some tools out there to check to see if that vulnerability exists inside your networks or systems MI. Ed Craig peterson.com. And I'll be glad to reach out, reach back to you.

[01:10:09] I'm gonna tell you what to do as a consumer because of this massive internet hack that is underway. It is huge. Also going to talk a little bit about apple and what they're doing with their tracker detect app on Android devices.

[01:10:24] This will be going on for months and probably years in some cases, because there are many systems that will never.

[01:10:35] Patched for this vulnerability. So from now on, you need to be doubly cautious about almost everything, the big targets for this. Then people who tend to be the most valuable. Big businesses. And I can send you a list of devices that are known to be either immune to this they've been fixed or patched and devices that are known to have this problem.

[01:11:03] You send me an email. Excuse me. If you have any questions about it. So it's me M e@craigpeterson.com. I'd be glad to send you that list. Seesaw has it online. You can certainly search for it yourself. If you're interested in. So for you as an individual, it's just extra caution, use these one time, use credit card numbers.

[01:11:31] I have talked about this before. And that is, I use fake identities as much as I possibly can online. And I'm not trying to defraud anyone. Of course, that would be legal. What I'm trying to do is not make myself as easy at target. As is frankly pretty much anybody who uses a computer out there, because if you're always using your, in the same name and email address and having forbid password, then you are a bigger target than you have to be.

[01:12:07] And I have a whole index file. I have a spreadsheet that I put together with 5,000 different identities, different names, of course, different sexes, races, origin stories, everything. And the whole idea behind that is why does some company that's providing me with some little website thing, need my real info.

[01:12:31] They don't obviously you give you real info to the banks or. Counts, but you don't need to give it to anybody else. And that's what I do. That's my goal. So if you can do that, do that. Apple also has a way for you to use random. Email address a suit can set up a different email address for every website you visit.

[01:12:57] There are a few services out there that can do it. If you're interested, drop me an email. me@craigpeterson.com. I'll send you a list of some of them. I think they're all paid except for the app. But you have to have an apple account in order to use it. One of the things that businesses really need to do is do a scan.

[01:13:19] Again, I can send you a list of scanners so that you can look at your network, see if there's any. Obvious that might have huge implications for your business. Again, me@craigpeterson.com, one of the things apple has come up with that I really have turned out to and I think I mentioned them before on the air, but it's these news.

[01:13:41] Trackers that apple has, that you can put on things. And we spoke a little bit last week about the problem with these trackers being put on to high-end cars, and then being used to track the car. Now apple got around that problem a while ago, by letting you know, Hey, there is a tracker following you isn't that handy.

[01:14:04] Wait a minute, somebody dropped one of these little tags into my purse. Coat my car or whatever it might be. And so now you can have a look and see where is this thing that's following me and get rid of it. Of course, in order to know that there's one of these apple tags tracking, you've needed to have an apple phone.

[01:14:26] Because it'll warn you. Apple now has something called tracker detect. If you are using an Android phone, I would highly advise you to get this app tracker detect app on Android. And it's designed to help you Android users from being tracked by apple airtight. 'cause if you don't know you're being tracked right, then you can't know if you're being tracked.

[01:14:55] If you don't have an iPhone, unless you get this app so good for them, apple has it up now on the Google play store. That's just in the last week or so, and it lets you locate nearby air tags. So let's I think a very good thing kind of wonder if apple isn't using the Androids also for part of the.

[01:15:16] Crowdsourcing for the air tags, but that's a different conversation. Great article in vice this week by Aaron Gordon, about how car companies want you to keep paying. Features you already have, and they specifically made a call out about a car manufacturer. Toyota. Who's now charging $80 a year for people who bought their car years ago, six years ago, $80 a year.

[01:15:51] If you want to keep using the remote start function on your key. Yeah, so you paid for it and life was good. You went a few years, really nice on a cold winter day or a hot summer day, warm up the car or cool it down all automatically. But now Toyota is charging. $80 a year. So people are saying why I bought it?

[01:16:16] Why would I pay for that? Apple's now claiming that the several first years were merely a free trial period, but this isn't even the big play for these car companies, this $80 a year for marginal features like remote start instead. Is probably going to happen. And I agree with this author as well is we're going to see a, an approach that Elon Musk has used with his Teslas.

[01:16:47] They're going to charge extra for performance, for range, for safety upgrades, for electric vehicles that actually make the car better car, a better car. So upgrades used to be difficult or impossible with gas cars. A lot of these are trivial for the electric cars, with the dashboards that have games that you can play while you are charging.

[01:17:13] Some of them were complaining about it being for when they're on the road. Of course that's going to happen because frankly, when, once we get a full autonomous car, what are outs are you going to do? I should also mention this isn't really a, but Mercedes-Benz has been awarded the very first license for the manufacturer sale and distribution of a fully autonomous vehicle.

[01:17:39] The very first they are licensed for up to, I think it was 37 miles per hour. On their car and anything beyond that, you still have to retain control, but that's an amazing thing. And it only works on roads that are mapped. And what Mercedes is doing is they have these super high definition maps. So the car knows exactly where it is.

[01:18:08] If you are a Tesla owner, you know that a few years ago, Paid, I think it was $2,000 for your Tesla to be able to drive itself. And of course they haven't been able to drive themselves. They, yeah, there's been features here and there, but how were you getting those features? How will you going to get that self-driving mode?

[01:18:30] We'll test those, calling them over the air upgrades. And they're also saying. Th this is part of the Tesla ownership experience to quote their website. All right. So they've had all kinds of over the air upgrade. They've had some free software. They've had paid ones, Tesla charges, thousands of dollars for its autopilot.

[01:18:54] Now a lot of money, I think it was five grand. Now they've got this beta driver assist system as well, and they also have. To others. You might remember the ludicrous speed. Long range model three would dual motors is capable of accelerating from zero to 60 in 3.9 seconds. But when you buy the car, the zero to 60 time is a half a second longer.

[01:19:25] So pay an extra $2,000 and you get that extra half second and accelerate. Yeah, there's nothing different. They don't even have to change. Really changed the software. There's no hardware differences. It's just, you pay them two grand and they, your cars catheter to the internet and they just unlock a key is not something.

[01:19:48] Now there some people that hack the way around that paywall, but then Tesla blocked it and reversed the hack as well. Tesla has sold their cars now for years with the same 75 kilowatt hour battery. But software locked them to 60 and 70 kilowatt hours might remember. We talked about this with a hurricane that came ashore down in Texas, where Tesla, anyone in that area provided them with an automatic upgrade for extra batteries.

[01:20:19] So they could go further in order to get out of the zone of their herd. Before them in software lock-in and a 60 and 70 kilowatt hours, unless you paid an additional $3,000 for that extra 30 or 40 miles of range. Isn't that something. Yeah. So Tesla has temporarily unlocked them, but this is where we're going.

[01:20:43] You're going to be going into the car dealership while in Tesla's case. It's on the internet, which I think is better. Frankly, dealerships are handy in order to get a repair, but. You can get a repair at some of these little specialty shops it's often better and certainly cheaper than what the dealership sells, but you're not only going to be haggling over the price of the vehicle and delivery times.

[01:21:08] You're going to be haggling over all of these different features. And it's never going to end because they're going to keep having software upgrades that you're going to have to pay for. Pollstar star. This is an electric vehicle company spun off from Volvo new member. Volvo is now Chinese company.

[01:21:25] Yeah. Chinese. Yeah. So much for safety, right? They're going to charge an extra thousand dollars for a slight increase in horsepower and torque, just like Tesla does. So this is the future. Of car companies. Hey, I want to remind everyone, if you go to my website, Craig peterson.com. Right now you can sign up for my weekly newsletter.

[01:21:48] It is packed full of great information for you. Every week. We've got some free boot camps coming up after the first of the year, and you need to be on my email list to find out about it. CraigPeterson.com/subscribe.

View Details

Did You Hear About the Latest Phishing Scams to Hit?
Get the Latest Free Cybersecurity Tools

This is a big deal, quite literally a big deal. Russian malware. We have been able to track it down now, track it down to a single site. All of these bad guys are in one building in Moscow.

[Following is an automatic transcript]

This is a very big story and it's a bit of a scary one as well. We've had a lot of ransomware over the years and a lot of ransomware. Have you had it yourself? I bet you, if you haven't, someone who has had ransomware because frankly it is pervasive in every aspect of pretty much everybody's life out there.

[00:00:40] So when you get hit with ransomware, Lately something a little different has happened. It's really gone through three phases. The first phase was the ransomware would get on to your system. Usually it came as an attachment, probably embedded in like a word file it's been embedded in PDFs, embedded in all kinds of stuff.

[00:01:03] Even drive by downloads on websites, have brought malware. But in this case yeah, it was annoying. It was a problem. It would give you a red screen. You've probably seen it before warning about the ransomware and it told you, okay, here's what you can do to get your files back. And in order to get your files back, you usually.

[00:01:25] To go to some exchange online, take dollars, buy of course, Bitcoin, or some other cryptocurrency. And then that cryptocurrency would be used in exchange now for you to get a key that would hopefully decrypt everything. And in reality, it often didn't encrypt hardly anything. So it's been a problem and a problem for a lot of people.

[00:01:51] The FBI said that at the time. So this is a gen one of ransomware. You were lucky if 50% of the time you got all your data back, gen two of ransomware is when the bad guys started getting a little bit smarter. They didn't just take your files. Thumb and then say, Hey, pay up buddy. What they did at this point is that got onto your systems and they poked around.

[00:02:14] They went we call in the industry, east west on the network. So they got onto you, maybe your kid's computer may, maybe you were hooked up via VPN to the office to do work. And it wasn't a great VPN. And the kid's computer had that virus and that virus weaseled his way all the way over the VPN, directly to the office, because remember.

[00:02:37] VPNs are. A network private in that. Yeah. Okay. It's encrypted. And so someone who's got a wire tap isn't necessarily going to get anything, but it's a VPN, it's a tunnel. And that tunnel was used a many times for malware, like brand summer to creep over to the office network. That's an east west is going from.

[00:02:57] One machine to another machine. And in businesses, man, you saw that one a lot as that ransomware moved around. So that was the second one. So the rents were going on the machine. It would then look for files that is. You might not want to have exposed. So it looked for files with bank account numbers in them, social security numbers, maybe intellectual property.

[00:03:25] We saw a lot of that. Theft is continuing to go on primarily from the Chinese and then an intellectual property theft. And what happened next? While of course it ended up moving the data, the files, and then what they would do. It's encrypt your desk. So before they gripped your desk, they got copies of all of the stuff they thought might be important to you.

[00:03:48] So now the threat was in version two of ransomware pay up, or if you don't pay up, you are going to have to pay us to not release your files. If you didn't want all of that client information online, if by law, you would get nailed for having that client information out online. And that's true in most states now, and the federal government's from putting some teeth on some of their laws as well, then what are you going to do?

[00:04:17] Yeah, you paid the. So that was version two version three that we're seeing right now of ransomware is simply destructive. And if you go way back in history, you may remember I got hit with the Morris worm, which was one of the first pieces of nastiness out on the internet. And that was early nineties.

[00:04:41] My business that I owned and was running, got hit with this thing. Even before that, There was ran. There was a nasty where viruses, if you will, that would get on the computer and destroy everything. It was just a malicious, as I remember, somebody at UC Berkeley, some researcher in it. And he didn't like what that of the researchers were saying about him.

[00:05:03] So he put some floppy disk together and on them, he put. Erasing malware and shared all of the stats with anybody. And of course, you plugged that disc into your, that little floppy disc into your windows computer. And it says, okay, I'm going to go ahead and open it up. And, oh, look at this, a virus.

[00:05:24] And so he then wiped out the computer of everybody else. That was a competitor of his out there in the industry. Yeah, a little bit of a problem if he asked me, so how did that end up getting around? What ended up happening while everybody got really upset with him, nobody really found out what was happening, who did it, et cetera.

[00:05:47] That's what's happened. Now, so version three of malware is like some of the very first malware we ever saw version three of ransomware. So some, again, some of that very first ransomware was pretty nasty is not the sort of stuff you want to see running destroying files, but at least you could get back from a.

[00:06:08] Nowadays, a lot of people are doing backups by attaching a disc directly to their machine, or they're backing up to another machine on the same network. Remember that whole east west thing, you didn't want the data going back and forth, it causes problems. Yeah. So what happens now? The Russians apparently are just trying to cause havoc with businesses, anybody who has decided that they're going to be anti-Russian in any way there they're attacking.

[00:06:41] So they'll, reraise your desks. They'll erase all of your data. If you have backups on that thumb drive or that USB external. The good news erase that if you have backups on another machine, on the network, hopefully from their standpoint, there'll be able to get onto that machine and erase all of your backups, which is again, why we'd like 3, 2, 1 backups.

[00:07:02] At the very least, there's some others that are even better. And if you're interested, send me an email me@craigpeterson.com. I'll send you a webinar that I did on this. I'm not charging you for. But it was a free webinar to begin with what a webinar on backup and how to backup properly and why to do it this way.

[00:07:22] Again, me, M E Craig peterson.com. Be glad to do that. What we're seeing now is a huge problem. Let me see if this is going to work for us. Yeah. Okay. It is. I am, by the way, live here we go on my computer. So people who are watching. I can see my desktop. So here we go. This is Russian companies who are linked to this Russian malware.

[00:07:52] Ransomware are hiding in plain sight is what they're calling it. So what does it mean. To hide in plain sight. While in this case, what it means is money that's been paid by American businesses to these Russian ransomware gangs, some of who by the way, are actively going after anyone that criticizes Russia found these American researchers.

[00:08:18] Yeah. Led to one of Moscow's most prestigious addresses. You can see it up here on my screen. This is a New York times article. It's just a random actor, journalism people, sometimes even the New York times gets it. And they're saying millions of dollars have gone through this. So they've been tracing.

[00:08:38] Where did they go? The Biden administration has also apparently zeroed in on the building is called Federation tower east. It's the tallest skyscraper in the Russian Capitol. How would that be to have a business and just this beautiful tall skyscraper and have a view that would be really cool. So they have targeted some companies in the tower.

[00:09:00] As what it's trying to do is stop the ransomware guy gang. Maiden cryptocurrencies. Russian law enforcement usually has an answer to why don't you just shut down these bad guys that are out there trying to steal all of our money. They say there is no case open in Russian jurisdiction. There are no victims.

[00:09:19] How do you expect us to prosecute these honorable people? That apparently is a quote from this Massachusetts based secure cybersecurity. Called recorded future, but I'm looking at a picture it's up on my screen right now. You guys can see it, but this is the Moscow financial district called Moscow city.

[00:09:38] 97 floor Federation tower east. This is really pretty, you wouldn't know this isn't like London or any other major European capital. There's some cranes in the background building up new buildings. Cyber crime is really fueling some growth there in Moscow, which is, if you ask me the exact reason why lad is happy as a clam to just go ahead and have these Russian cyber crime guys.

[00:10:11] Just go and bring money in right. Money is bringing in great money for them. The treasury department, by the way, it's estimated the Americans have paid $1.6 billion in ransom since 2011. Huge one ransomware strain called RIAA committed an estimated $162 million. Last year. It is really something.

[00:10:35] So when we come back, we've got a lot more to talk about. We're going to talk about the cloud. If it's more secure or why is it calm, broken, give masks work. Why aren't they working right. Anyways, we'll talk about that. When we get back and visit me online, Craig Peter sohn.com.

[00:10:54] Stick around.

[00:10:57] I hate to say it, but there's another big scam out there right now. And it is hitting many of us, particularly the elderly quite hard. We're going to talk about that right now, what you can do about it and how you can recognize when it's happening.

[00:11:13] Interesting article that came out in Wired.

[00:11:16] And it's talking about a serious problem. I'm going to show you guys who are watching I have this on Rumble, YouTube, Facebook as well. So you guys can see a long and of course, right here, a two.

[00:11:30] Now let's not forget about that, but this is an article that says we were calling or excuse me, they were calling for help. Then they stole. Thousands of dollars. I'm going to read parts of this article. It's just amazing. It's by Becca, Andrew's a back channel. What is that? Okay, so that's just a cat.

[00:11:52] On December more one December morning, my mother's phone rang. She tugged the iPhone from the holster. She kept clipped to the waist, her blue jeans and wondered who might be calling perhaps somebody from the church who was checking in on her recovery from coronavirus. Hello. She said the voice that greeted her was masculine.

[00:12:12] This is just great writing. The color sounded concerned and he told her something was. With her Amazon account, somebody has access to your bank accounts through Amazon and they can take all your money. I'm calling to them. Her mind raced or Lord, she prayed silently. The voice was warm and reassuring them.

[00:12:34] My mom tried to focus closely on his words. My dad was driving to work in his truck and she was home alone. She'd been cooped up in the house for weeks with COVID isolated from her community and she missed the bomb. Friendly voice. I just love her language here. It's just phenomenal. She tried to steady herself.

[00:12:55] The man said he needed to make sure the money was safe. He transferred her to a different male voice. Soothing reassuring, calm. She promised not to hang up a brain injury decades earlier, made it hard for her to follow his instructions, but she stuck with it. The voice explained slowly, carefully, how to swipe and tap her phone until she had installed an app that allowed him to see what was happening on her screen.

[00:13:26] Now. You followed her every move. After some hour, she mentioned she had to relieve herself hours. It's okay. I'll stay on the line. He said she parked the phone, outside the bathroom and picked it back up. When she was done, as noon approached, she told him I have to eat. I'll wait. It's okay. Don't hang up.

[00:13:47] We'll lose all our progress. She set the phone down on the counter to make a sandwich, then pulled some chips from the cabinet and padded over to the kitchen. The phone buzz with the text. It was my father checking in. She typed back that there was a problem, but she was fixing it. She had it all taken care of.

[00:14:07] She tapped the tiny white arrow next to the message field to send her reply. And then she heard the voice, its volume elevated as sounded angry. She frowned and brought the phone back up to her ear. Why would you do that? You can't tell anyone what if he's in. She felt confused that didn't make any sense, but she also didn't fully trust herself.

[00:14:29] She was worn. From her slow recovery and the steroid, she was taken as a treatment, gave her a hollow buzz of energy. Now I want you guys to go have a look at this over on wired site. Read the whole article. It is a phenomenal. Absolutely phenomenal. But what it's doing is telling the story of this woman who was trying to, do the right thing, trusting other people, which many of us do?

[00:14:59] I have a default trust with a little trepidation. I will admit that, but with the whole. Down the thing that happened, many of us have just been longing for a little bit of companionship and to hear a stranger who's trying to help out. That's a huge plus it goes on in this article and talks about how reassuring these guys were and what they did.

[00:15:25] She installed this cash app and opened up PayPal downloaded. Coinbase set up Zelle so she could send money directly from her bank account. She doesn't know about any of these things. It's just incredible. So the afternoon wore on and the guy said Hey, we're almost done. And her husband of course, was on his way back.

[00:15:49] And the sun was down. Father got home. He noticed right away that something was off. And she said she took care of it. And you said you took care of what I'm not supposed to tell you. It said, so this scammer had siphoned away. All of her personal information, the scammers had your social security number, date of birth driver's license number, and about $11,000.

[00:16:14] These new financial apps like Zell and others that are legitimate PayPal apps, right? Zell, you can use to send money legitimately to someone else. But it links into your bank account. That's why I don't like them. I have a friend that's been pushing me. Oh, this happens. Great. It saves you so much money on gas.

[00:16:34] Look at how much money I've saved any. He sent a screenshot of it and I re I went online and had a look. And guess what? I read, reviews it again, like this tied into her bank account directly. And. What can happen? Like here, everything was emptied. So in the next few months this author of the story and her father tried to undo the damage.

[00:16:59] Very frustrating, getting scanned of course, is really dehumanizing and it just breaks your trust and other people. How could someone do something like that? It's just incredible. Got to go through the stages of grief and everything. She got a, she talked to people, she said she got chili half replies, or just as often silence.

[00:17:24] And she was calling around trying to find someone with some empathy. Okay. It's just incredible. Great article. If you can still find it, the March issue of wired, I'm sure it's available online. This goes on. And talks about her mother's seizures getting worse. And of course now they don't have the cash that they had been saving.

[00:17:46] And it just very depressing. Now I have this, you might remember about a year ago, I talked about it. I had something like this happen to a friend of mine and I'm still not quite sure what happened, but it looks like it was a password sprain or password stuffing. And they got into his, the app that his company uses to pay people and sure enough, they got in and they directed his next two paychecks to their own account, which went right out of the country like that.

[00:18:24] These are bad people. And how do you deal with this? It's incredible because if you've got someone like her mother who has mental problems due to no fault of her own and is a very trusting woman, what do you do? She's walking around all day with her phone on her hip. That's how we started this out.

[00:18:46] Do you take that phone away from him? Th that would be dangerous, frankly. So this is a very problem. They had a USAA account was her bank account. USAA is usually good about this sort of stuff. In fact, my other friend had USAA as well. But they did help deactivate Zelle, but they didn't do anything about the $999 that were transferred through it.

[00:19:10] Very bad. So they figured out maybe we should change our passwords. She had them change them. And if you would like information about password managers, again, I'm not selling anything. I'd be glad to send them to you. If you sign up for my email list, you're going to get them automatically. Craig peterson.com.

[00:19:30] I've got a bunch of data information I want in your hands. It talks about the free stuff, talks about the paid stuff. None of which I'm selling you. Craig Peter sohn.com. Sign up right there on the top of the page. Thanks. Stick around.

[00:19:51] We've had some serious supply chain attacks over the last couple of years. And they have caused all kinds of problems for tens of thousands of businesses. If you use WordPress, there was one of those this week.

[00:20:06] We have had supply chain problems. Like you wouldn't believe. So let's start out by explaining what is a supply chain problem?

[00:20:17] In this case, we're narrowing it down to cybersecurity because we've had supply chain problems from everything from our toilet paper to the food we eat. But what I'm talking about right now is. Supply chains when it comes to cyber security. And one of the biggest problems we had was a company that's supposedly providing cyber security for businesses, right?

[00:20:48] Some of the biggest businesses in the world. And I'm looking at an article right now from security Boulevard, say saying how to protect the supply chain from vulnerable third party code. It can be a script that's downloaded online. It can be an open source library. We've seen big problems with get hub lately and pulling in libraries.

[00:21:10] We've seen big problems with what are called containers lately, which are little mini versions of computers with all of the software. They're all ready to go. Ready and raring to go. All kinds of supply chain issues for a very long time now. And these supply chain, cyber attacks have been hitting some of our cybersecurity companies, really the hardest I'm pulling this up on my screen right now, if you're watching this on rumble or on YouTube, and you can see links to those, by the way, in my emails, I send out every week.

[00:21:47] Craig peterson.com. Craig peterson.com. But you can see here, supply chain hits cybersecurity hard supply chain security is not a problem. It's a predicament. That's uninteresting look because we have to use some of the supply chain stuff. Seesaw the FBI or a sheer wean cybersecurity advisories because of the Russian attack over on Ukraine.

[00:22:14] And then the U S the weakest link in supply chain security fears of rising fuel SISA FBI NSA and gestural partners. Issue is advisories Toyota stops production after possible cyber attack at a supplier. Isn't that something this goes on and on. What's a guy to do, right? Many of us are using websites to, in order to run our businesses.

[00:22:43] Heck we got websites for our soccer team, for the kids, we got websites for pretty much everything that's out there today and those websites need software in order to run. So the basic idea of the website is nowadays. Content management system, they called CMS CMSs and there have been a lot over the years.

[00:23:05] I've used quite a few myself off and on. This is very interesting though, because this particular piece of. Is code that runs a website. I'm going to show you this article from ARS Technica here on the screen, but it's talking about millions of WordPress sites that got a forced update to patch critical plugin flaws.

[00:23:32] So when we're talking about supply chain, in this case, we're talking about something. WordPress right. And this WordPress software as good as it is, can have bugs. So WordPress is the content management system. So you load stuff up into, in fact, I'll bring up my site right now. So I'm going to bring up the Craig peterson.com.

[00:23:55] And on my site, I have all kinds of stuff, which is why it's so slow to load. I've got to fix that one of these days, but this is an example of a WordPress site. So you can see right at the top of the site, I've got watch this week, show jobs, or top, of course, that was last week. You can watch it on rumble or a new tube, and then it's got my latest show.

[00:24:18] So if you click on one of these, here you go. And you can listen to it. Starts right out here. C ta-da. So there, you can listen to my podcast right there on the site, and I've got an automated transcript of it. It's for you, depending on what you want. It's got links over here to take you to iTunes or YouTube or Spotify or SoundCloud or iHeart or Google player audible.

[00:24:45] All of these links take you to different places. And this site in survey, Program a site in HTML. What we're doing is we're working. Putting some data in, so we say, okay, I want a default page. Somebody else has already set it up. Somebody else has already got an old program. It just works. And it's all right there for me.

[00:25:08] Here's some related posts on the side. Here's the most popular ones that we have right now. This is a content management system. And specifically this of course is WordPress. So what happened. If I had a, yeah. And here's what it looks like over an audible, you can listen for free on. This is what happened this last week, WordPress, which has this great software that I use and tens of thousands of others use out there very popular.

[00:25:46] And in order to make it easy for me to have my website, probably your business, probably your kids' soccer club, you name it is using WordPress. It's just over the top hop healer. It is using code that was written by other people. The reason we can make programs so quickly nowadays is we're relying on other programs.

[00:26:10] So we'll go ahead and we'll grab this program that does this part of what we need to have done, and ta-da we're up and we're running. I just have to write the glue right? To put it together. The API calls, whatever it might be, because the idea is let's make it easier for programmers. So you've got something called get hub here.

[00:26:30] Let me pull it up so you can see that you can go online if you're following along. To get hub.com. And as it says right there on their front page where the world builds software as a beautiful world, isn't it? That blue, you can see the air around it. And that's what it's doing is where the world builds software.

[00:26:51] So let's say we want something. What do we want? What's a, let's say we want something to make a chess program. We can talk about chess and let's say, oh, you have to. Dan didn't want to do this, so I'm just going to skip that for now. But it would come up and tell me, okay here's all of the chess programs that are out there and I find one, that's close to what I want to do.

[00:27:13] So what do I do? Point while I go ahead and have a look at the license, a lot of the programs up there have a very open license, so I can just take that code, modify it. And I have a chess program without having to write a chess. It's really that simple that's part of the supply chain. If you bought my chest program, you would actually not just be getting the code that I wrote, which is typically just glue code with maybe some API APIs or application programming interfaces.

[00:27:44] In other words, you're using someone else's code would now make it who's program. It's like the Pharaoh's barge. It would make it other people's programs. Not my. So you got to figure out what's in my supply chain. I've got a new client. I do work as a virtual chief information security officer.

[00:28:05] Actually, it's a fractional Cecil. And as a fractional Cecil, one of the things I have to do is look at the whole supply chain. Who are they buying even physical things from. And could there be. Did it into their software, into their systems, something that might be coming from yet another supplier. Man, does this get complicated?

[00:28:28] Very fast, but this week, our friends at WordPress, they went ahead and forced all WordPress sites to update. Very good. Okay. Otherwise, people could have downloaded a full backup of the sites that are out there, something you really just don't want to happen. Anyways. Go right now, Craig Peter sohn.com while the bits are still hot and sign up right there.

[00:28:55] Craig peterson.com for the newsletter and get those special reports that are going to get you started.

[00:29:02] This is the moment you've been waiting for. We're going to talk about free cybersecurity services and tools that you can use. Now you have to be a little bit of a cybersecurity expert to use them, but not much. This is from the government.

[00:29:18] This is I think an amazing thing. This only came out within the last few weeks.

[00:29:26] I have it up on my screen. There we go right now, for those of you who are watching on Rumble or YouTube, you can see it right there, free cybersecurity services and tools from. The cybersecurity and infrastructure security agency SISA reminds me of Marvel was shield, that really long name that came up with an acronym for as though they weren't aiming for that acronym in the first place, but there are some tools that you can use there's tools that I use as a cybersecurity professional.

[00:30:01] And some of them are obviously going to be pretty darn. Complex. And if you're looking at my screen right now, or if you want to go online at csun.gov/free-cybersecurity-services, dash, and the as tools, or just look it up online, you'll find this on my website as well. I'm going to try and make sure I get that up.

[00:30:26] But what they have done is they're showing you what they call their key or the known exploited vulnerabilities. Okay. And this is where they are showing the CVEs, which are. The frankly, these are the ones that I use. It is published by nest, which is the national institutes of standard and Sanders and technology.

[00:30:50] And this gives all of the details. So this is CVE 20 21, 27. Okay, and this is detail, and of course I would be using detail. And it's telling you, here's the advisories, there's one from get hub Excel. Leon has one. Here's the weaknesses, the SA the known soccer configurations. So you can find where they all are at and everything.

[00:31:15] So all of the details. So they're telling you about that. These are the ones, this was in the vendor product. Project, I should say. So we'll look at the data added to catalog. Here are a few in Cisco right now. So this is their small business series of routers, which we do not use for anyone because they don't provide the type of security you want, but Cisco is taking care of the problems, right?

[00:31:41] Many of these update themselves, here's Microsoft windows. And installer contains an unexpected unspecified vulnerability, which allows for privilege escalation, a lot of stuff this week, this is crazy Apache Tomcat, which I am never been a fan of and problems. So all of these came out. On March 3rd and more rights.

[00:32:05] This is just page one. So let's look at page two here. Oh wow. More Microsoft Excel exchange server, some more Cisco vulnerabilities. Why Cisco? Why Microsoft? Because they are frankly. The big boys on the block, that why do you Rob the bank? Because that's where the money is. So they list all of those right here, as he said, does the warning you do use multifactor authentication?

[00:32:34] I don't want to sound like a broken record, so I'm not going to say use multifactor authentication today. Okay. I just refuse to say use multi-factor authentication. And this one talks about what it is, right? Many names. Now they're trying to make this. But really a Fido key, fast identity online considered the gold standard or multi-factor authentication Walt for online.

[00:32:58] It is websites, but not for authors. So how would you know that if you weren't an expert? So yeah, this is the government talking, right? So they have the service. So what does, what do I do right? Me, Mr. Idiot. I click on this and they are talking about the service that they've got them showing it up on the screen.

[00:33:20] It's called SISA insight. And they're talking about website, defacement, destructive malware, or not Petya want to cry, right? All these things. What can you do to prevent it? And. They make it sound easy. Now I want to say something here because I, I have a couple of mastermind groups and in one of my groups, I rescued a group member from a 40 something thousand dollar loss.

[00:33:50] And so I was explaining it in our next mastermind meeting. Cause everyone wanted to know. What should I do? How should I do it? And they all tuned out and I thought I was trying to, I was being simple enough. I was trying to be simple, not like simple, like Kamala Harris explaining that Ukraine is a country beside right next to another country called Russia.

[00:34:14] And that's why there's an invasion. Okay. I couldn't believe that. Did you guys hear that? It was just incredible, but I didn't get that simple. And I know you guys are the best and brightest, and you're trying to figure this, all this stuff all out, and that's why you need to make sure you sign up for my email list right now, because I do have simple step-by-step stuff.

[00:34:36] And these tools that they're talking about and services are supposedly available. Now, I went to a bunch of these. And I tried to get some services. So they said they'll do a free scan over the network. So I filled it all out and according to their standards, my company, because I do cybersecurity for everything from government contractors, through dentists and manufacturers and distribution companies.

[00:35:09] So I, I. The critical infrastructure definition. And I have never heard back from them. I check my spam box at least once a week looking for their reply. So I don't hold up a whole lot of hope, but there is some good information here that you can get email via social media via just all of these different types of things that you.

[00:35:34] You could use for it. And again, I want you to look for it online. It's on csun.gov. If you go to their homepage, you'll see their tools, they've got a shields up a warning right now on their homepage because there have been so many attacks coming from China and coming from Russia, but particularly Russia.

[00:35:54] And you can see there. Stop ransomware.gov, which has some great tips, particularly for home users and small businesses. The Seesaw culture, height, hygiene services. That they have doing business with CSUN and careers they're looking forward to is okay. It's part of Homeland security. So there's a whole lot that you can do and you can find, but I wanted to let you guys know that this is out there.

[00:36:24] A lot of the stuff guaranteed is going to be. Above 98% of people's heads out there. Just in general, even it professionals. So look for information, that's going to help you. That's on your level. And to that end we have right now, three things. If you sign up for the email list, or if you're already on my email list, you can just email.

[00:36:50] Me@craigpeterson.com or just hit reply to any of my emails and I'll see it and ask for them. But we've got stuff on your computer, keeping it secure, keeping your password secure comparison between using a one password manager or using last pass, which I am not advising to use right now, but that's in there.

[00:37:14] There are a lot of different things that are there that are ready for you to get right away. And then if you have other questions, I've got dozens of little special reports that I've written in response to people's questions. Don't be afraid to send them to me. I'd you know me@craigpeterson.com and I'll make sure I get you an answer because it's that important.

[00:37:39] Okay. I'm not here trying to sell you something. I am here because most of you guys can could never get my services. You don't need them. You can't afford them, whatever. I'm a fractional Cecil. I'm one of the guys that keep. It was a cyber security working in a live for businesses. Like it's not going to be everybody, but it's, it is there is, I shouldn't say a lot of information you guys need and need to understand that I want to help you. Okay. I think I've beaten that horse enough and it was probably past dead, but you'll find some of this stuff on my website@craigpeterson.com.

[00:38:17] I've been working on some other changes to it. I would also ask you guys. If you're hearing part of the show today, I know a lot of people who are listening on the radio are tend to be out and about in their cars, listening, on the weekend, I listened to a lot of radio then, but go ahead and subscribe to either my podcast.

[00:38:38] And there are a lot of ways to do that. And I showed those people who are watching on video, how to do that. And if you would give me a five star. On whatever platform you're using, hopefully I've earned that. And then also if you'd like video, I have my whole show up. It's like about an hour and a half long on multiple platforms.

[00:39:04] So rumble.com rumble, R U M B L E. Is a competitor to YouTube. So if you don't like censorship, if you want a site that is trying to keep that information out there, get it out there for you. A rumble is your place. You'll find all kinds of interesting characters there other than myself, right? A lot of conservative people go there to rumble.com.

[00:39:28] I have it up on YouTube. Because YouTube, isn't the worst platform in the world. They're also not the best, but they are the biggest. Did you know, YouTube is the second largest search engine in the world. Okay. They have a lot of people on YouTube and then on Facebook as well. You'll find me there on Facebook.

[00:39:48] Of course, Craig Peterson, I had. I excuse me at facebook.com/craig Peterson. And I didn't use it for a long time cause I hated Facebook. Just, I looked at it as a time sink that I just didn't need. I got a lot of stuff. I got a lot of people help and so I didn't really do anything with it. And so somebody else got the slash Craig Peterson, but I do have a trick for you.

[00:40:12] If you go online with your web browser to Craig peterson.com. That's my website slash. YouTube. It'll take you right to my YouTube page. Ores Craig peterson.com/facebook. Yes. What do your Facebook page? Craig peterson.com/itunes. Good slash sound cloud, et cetera. It'll take you right to my page on all of those sites and have a look at the video.

[00:40:41] Let me know what you think. I would appreciate that feedback and make sure you tune in on the radio too. It's great. Don't watch this while you're driving to taking the kids to school, a lot of people listen to this while they're taking the kids to school on podcast. Anyways, take care. Thanks for being with us.

[00:41:01] By now you've heard of tick talk. You might use Tik TOK. A lot of people do. It's their go-to site online, especially if you're a little on the younger side. Here is a danger of some of these tick talk challenges and combine that with Alexa. Oh my

[00:41:17] This is a little bit on the scary side. We built our house some 25 years ago, we contacted a builder and I put together all of the specs and I made sure that the wood he used was better than average.

[00:41:33] It's all plywood, it's not particle board or the composite boards. And I made sure they were thicker than need be that all of the rules. Struts were were closer together than code required. And we had bigger plumbing than what was required all the way through the house. And one of the things I did is I had him wire the house, actually the electrical contractor with a heavier gauge wire than usually.

[00:42:05] So that I had 20 amp sockets at every socket in the house. Now we put the special 20 amp sockets on some of them, like in the kitchen, we have a commercial toaster, as a sort of thing you need, when you got eight kids and a half of our married life, we had other families living with us too, that we were helping out everything from training through just getting them through.

[00:42:29] Bot. So there were times when we had 20 plus people living in my house, it got gotten it crowded, but I wanted to make sure everything was above code so that it would work well and work well for us and knowing how much juice we tend to use. Yeah, you don't want to see my electric bill. I decided yeah, let's do the heavier gauge wire and let's put the sockets in one of the things I had the electrician do in order to make the sockets a little bit safer.

[00:42:59] This was back before you had these. I, frankly, I hate them, but these safety sockets where you push in the plug in Erie really gotta push it in order for something to get plugged in. There are ways to defeat those safety sockets and that's where this problem comes in. I had him install the sockets.

[00:43:21] You might consider them to be upside down. So the top of the socket had the little grounding. And then underneath that you had the hot and the neutral lines. So the idea there was, while if something fell onto a plug that wasn't plugged in all the way, or if the kids decided they'd stick something on it, it would go to ground or made sense to be.

[00:43:47] And apparently it's worked because none of my kids are dead yet. So that's a good thing, there's these challenges on Tik TOK. You've probably heard of them. In fact, that's how they really got themselves going. They had that, that ice bucket challenge and many others that people were doing and they continue to this day.

[00:44:09] One of the tick tock challenges is very stupid and dangerous. And that's where this article from ARS Technica comes. Eric Bankman wrote. The when was this? Oh my gosh, this is right at the beginning of the year, apparently a 10 year old girl and her mother used Amazon Alexa. And what was happening is the kid wanted some challenges.

[00:44:34] Mom wanted some challenges and they were doing a whole bunch of things. Physical challenges, like laying down. Rolling over a holding a shot on your foot from a phys ed teacher on YouTube. And the girl just wanted another one. So for those of you who are uninitiated, the plug challenge consists of.

[00:44:57] Partially plugging a phone charger into an electrical outlet. Now the phone chargers usually do not have a grounding pin. So my little work around of mounting, all of the sockets upside down wouldn't matter. Cause if you look at that a little charger plug, it's usually just two pins and it actually usually doesn't care about the polarity.

[00:45:19] It doesn't have the bigger the side and the smaller side, the. Yeah. I can't remember what they call now, but if they're both the same size, so you can put it in either direction, the spades that you put in. So if you put it in part way, you have defeated the safety mechanism, that's in all of these modern plus.

[00:45:41] So you put it in part way, you have to push hard and in it goes, and then you pull it out part way. So that's part one. Can you plug this phone charger intellectual outlet part way so that those two conductors are exposed and then yeah. Then they ask you the challenge is to drop a penny onto the exposed prongs.

[00:46:11] So you can get anything from a small spark. That little coin may jump off to a full-blown electrical fire. Now mom was there and she yelled. No Alexa, no. And the daughter said she's too smart to do something. Anyway, and I'm looking at a picture here that ARS Technica published of a wall socket, where a short had happened.

[00:46:37] This wall socket is mounted sideways. I don't get that. And the hot side is up. So anything falling against the sock and by the way, the faceplate is metal. And grounded, obviously. So anything falling onto a plug that's only partially plugged in because the sock gets sideways. It falls onto it. It touches the metal face plate, and you've got a fire Bruin.

[00:47:08] So they've got a picture of one of these in a house and you can see where the smoke went up. Now. I don't think the whole house caught on fire here, but it was a major zap. It reminds me of the days when we had. The fuses in the basement. And if a fuse blew, all you really needed to do is go down there and stick a quarter in it.

[00:47:28] And you're fine, which means it's defeated the purpose. Anyways, you gotta be careful. At Amazon confirmed in a statement to the BBC that it has removed that particular challenge from Alex's database. Obviously these are computer generated and they're based on Tik TOK, idiots. You shouldn't be using Tik TOK for a lot of reasons.

[00:47:55] One of them is it has been alleged that they have been spying for the Chinese. It is a Chinese company. It's part of 10 cent. And the, there's just a little stupid thing. So Amazon said, as soon as you became aware of this error, We took action to fix it. So again, you can't necessarily trust your kid at home with a, an Alexa doing challenges.

[00:48:20] I just can't believe it. It's just incredible exactly what happened here. Hey, I want to give you a real quick tip. Last week, we went over how you can find out. If your computer has been hacked, basically. In fact, we were a little bit more specific. We said, okay, what I want to do here is know if not just the computers have been hacked, but as someone's stolen my.

[00:48:50] Email and or my password. And we explained why and everything else. Then if you missed it last week, you can just go right ahead, online to to oh my I'm just having man's beginning of the year, right? That's what happened. Go online to Craig peterson.com/itunes or slash your favorite podcast player.

[00:49:11] And you can listen to it there. So really good little article from. And make use of technology. And they're talking about what are some of the things you can do? You should do. You shouldn't do when it comes to external GPU's and now if you are a regular computer user, you don't even need one of these things and people might've tried to talk you into it.

[00:49:38] Now, also that GPU is these graphical processing units are built into all of our computers nowadays. All of these new computers that our friends at apple have come up with, have some amazing GPS built into them. Those are great. They're used to update your actual windows screen that you're looking at hate Microsoft for stealing words like windows, mean things anyways.

[00:50:05] But the external GPU is something I use on my main production workstation. So I've got GPU's they work great. And when I'm processing video and doing the edits, and then the final renders, that's when an external GPU comes in. So I can guarantee you if you don't know what I'm talking about here, I guarantee you.

[00:50:31] I need an external GPU. Now the couple of other things to know, if you are looking for an, a GPO of any sort to build and put in your existing computer to build in somewhere else, the GPU's are difficult to get right now. And part of the reason for that is so many people have been using them for mining cryptocurrencies, because they're quite good at that.

[00:50:57] Now there's special hardware that's being made. To mine, cryptocurrencies, but GPU's frankly are great little work around for anybody that just has a basic computer and wants to try and do a little crypto mining. So you're going to have a hard time getting a hold of these. GPU's just like many other chip sets out there and my own personal experiences.

[00:51:21] I don't need the top end one because of it takes a few extra minutes to render something. When I'm making a video, it's not a big deal, cause I'm not making videos all day long. So a little tip for you on GPU's and external GPU's. And do you need them, what should do. Use them for, Hey, I am doing some training every week.

[00:51:45] Kind what we just did just now, but about cybersecurity and other things in my weekly newsletter. So make sure you sign up Craig peterson.com AU. And if you could, and if you are a podcast listener, like to invite you to subscribe to my podcast, you can find it at Craig peterson.com/itunes.

[00:52:08] We've got the end of a era for a device that was considered to be quite secure. In fact, some of our presidents, particularly the one that comes to mind is president Obama used it extensively, and it isn't what it was.

[00:52:25] This device that I'm thinking of right now, and we'll see if you can guess what it is, but it was extremely popular.

[00:52:33] It was for sending and receiving messages that even had some other functions, but it was mainly an email thing. I remember having a couple of those back in the day that was strictly email. They were, they actually nice. And then of course texting came along and they kept up with the times a little bit.

[00:52:51] What we're talking about is the end of the line. This was a Canadian company, a company that was well-known worldwide by the name of rim. They were providing the Blackberry operating system. They had servers that were designed and built to be secure. So you could rest assured that all of your data was safe, no loud you to send and receive emails.

[00:53:25] And it had that wonderful little click keyboard on it. Something that went the way of all the world. That keyboard is now gone and it's gone for good as has the ability to use some of those blackberries that you bought over the years to keep yourself. I just had to play taps underneath that, but it's just incredible.

[00:53:53] It is the end of the day for the company, the once dominated the entire smartphone business. If you didn't have a Blackberry, you weren't cool and you weren't secure or secure. And you weren't able to communicate as easily. They were actually. Excellent little devices in their day. I want to add another note here when we're talking about secure, because Blackberry was very big and saying, Hey, listen, it's very secure.

[00:54:23] It's all encrypted. We keep all your emails, encrypted, all your communications and gripped and what we found out by the way, is it turned out that the Canadian government, basically the equivalent of the FBI, CIA NSA had the master key for all Blackberry messages. And not only did it have the master key, it shared the master key with the United States secret agencies, the end of the.

[00:54:55] CIA, et cetera. So if you were thinking you could use your Blackberry and keep your information safe, you are wrong. You remember when president Obama was elected? One of the first things they scrambled for in the tech business was how do we secure our. Mary. And of course all kinds are not our Blackberry, his Blackberry, all kinds of rumors erupted that, it was people controlling president Obama and they were using the Blackberry and they're using it because it was secure.

[00:55:24] You, do you remember the whole uproar around. And the biggest problem was obviously our intelligence knew that they weren't secure and they could read any message they wanted to, as well as the Canadian government. And remember the whole five eyes thing back in the day, these five different governments that shared information on their own citizens.

[00:55:47] So it was a real windfall for the United States because Canada was. EV all of this shop software was developed for the Blackberry. It's where all of the servers were located and data could easily be routed to Canadian servers away from us servers if they wanted to monitor somebody. And so Canada was the one spying on you, technically not your government.

[00:56:10] They'd never do that. So it was an interesting time, frankly. As of January 4th, 2020, These Blackberry phones will no longer be provided with provisioning services, which means they are going to gradually lose the ability to join networks, including the cellular network, by the way. So it's man, it's something that many kids.

[00:56:41] I have never even seen. And I look at it and just think, I remember envied some of the guys that had the blackberries at the time. And I had a couple of other little devices, keyboard driven that were from people who have been guests on my radio show. And I really liked those, but in the Blackberry was just crazy expensive as far as I was concerned.

[00:57:04] But Blackberry's leadership really messed up. The guys who are developing Android at the time realized, oh, wait a minute. The iPhone is a pretty popular. It's going to be extremely popular. So Android then they mimic the Blackberry at first, made it look like a Blackberry. And then they switched over and made the Android operating system be like an iPad.

[00:57:33] So they can pick, can beat with it, but Blackberry didn't see any of this coming. And it took over a year after the iPhone came out for Blackberry, for rim research and motion to come up with its own touchscreen phone. And the software was really quite a mass where they tried to. Basically crowbar in some new features and they had the old features.

[00:57:58] They're still incorporate users during this whole time were falling into love with their apple phones and then eventually the Android phone. Told their IP department, it departments that they needed to support the iPhone and the Android phones. And so they did, and Blackberry eventually gave up on its own phones and they started releasing Android versions.

[00:58:23] Do you remember those, the Android phones from. Mary, they got out of the hardware business entirely. And now what they're doing is they're trying to promote corporate security services. And that's really what they're trying to do. It's a new claim to fame. Yeah. Remember I just told you last time they were promoting that they were secure.

[00:58:44] They weren't at all. No, they were to some extent, but so the last version of Blackberry opera and he said, The very last release that they had was in 2013. Yeah. 2013 year that hold. So the devices affected here by this shutdown are by all standards, extremely low old. And remember you got to get security updates.

[00:59:09] So these machines, I can't even believe this still online when Blackberry hasn't given an update to them since 2013, that's almost a decade now, nine years. So if you're still using it stop, and if you're trying to figure out what to use, get an iPhone. And if you say, oh, Hey, films are too expensive. Don't get the latest, greatest iPhone.

[00:59:33] Get a slightly older one because they are supported for five or more years out, unlike everything else out there now, although. We now have Samsung promising some longer support, like five-year support for some of the devices. So we'll see how that ends up going. But frankly, Blackberry, they're done for.

[00:59:55] It's a shame. So there's a handful of software services that relied on the Blackberry servers to function. So if you were using Blackberry world or Blackberry link, those also stopped functioning on the 4th of January and the number of people still using it. I don't know. When was the last time you saw a Blackberry and have you used one I'd love to hear from you go ahead and drop me into the.

[01:00:23] Craig. Yeah, exactly. me@craigpetersawn.com. Let me know, did you have a Blackberry or were you still using one? And did they bother telling you about the shutdown that was coming up, but this is it. This is the end of what was a very significant technology. So here's to blackberries. All right, stick around everybody.

[01:00:52] Make sure you are on my email list. I'm going to do something new too, with the list. I'm going to start sending you my show notes. Now you can opt out of the show notes, just the show notes, if you want to, but expect to start seeing them show up in your email box. And this is the same show notes I send out to all of the radio and television stations I appear on because it's the most important news of the week.

[01:01:20] Artificial intelligence is making its way into all kinds of aspects of our lives. And one of them that concerns me maybe the most, in some ways it's a benefit and others is AI in the criminal justice system.

[01:01:36] China has developed what it's calls an AI. Or artificial intelligence prosecutor.

[01:01:44] And they're saying that they can identify dissident and press charges for common crimes with 97% accurate. Now that is a very big claim. And the whole idea behind this is their servers services. If you will, in the court system are overloaded. We have the same problem. Most countries have the same problem.

[01:02:11] I was just looking at India. They've got some 37 million backlog court cases. Absolutely. Phenomenal. So the system now in China can press charges for Shanghai's eight most common crimes. There runs on a standard PC and it takes part in the decision-making process. They say, although apparently it's actually making their decisions, but there are fears.

[01:02:40] The machine could be weaponized by the state. Now it's interesting. Looking at the actual charges that it's designed to press right now, they're saying that it was trained using 17,000 real life cases. And it's able to identify and press charges for the eight most common crimes in Shanghai. These include provoking.

[01:03:08] Now that's a term used to stifle dissent in China credit card, fraud, gambling crimes, dangerous driving theft, fraud, intentional injury, and obstructing official duties. In other words pretty much everything, right? You go against the government. It's just going to charge you. And that's what they say high prosecutor's going to do.

[01:03:31] Now I'm looking to it. Some more details. From the management review journal. And they're saying that the system can replace prosecutors in the decision-making process to a certain extent. Now let's look at some other countries we've got, for instance, Germany, and they're using image recognition and digital forensics to help with their case loads.

[01:03:58] China's using a system. No. System 2 0 6 to evaluate evidence a suspect's potential danger and conditions for arrest. Now, we've had some really weird things happening here in the U S with our criminal justice system. Some of them are absolutely idiotic. But things like just letting people out the same day that really should be held because they committed a moderately serious crime.

[01:04:23] And we just had cases just at the end of 2021, where we had people. Who had been arrested and got out that same day and then went on to commit serious crimes, rape, murder, and other things. So what are we doing here in the U S unfortunately we have found out that in the us, we are monitoring the.

[01:04:52] The funds that people need to put up that are called bail in order to be released from jail. So normally you'd go in front of a justice of the peace and maybe a court clerk, and they would look at what the charges are or what your background is, how sticky you are in the community, family, business ties, et cetera, and then set up.

[01:05:18] So you now put up the bail cash or otherwise, and you are released on basically usually your own recognizance. They're very somewhat, so we are all ready in many areas using artificial intelligence for that entire. Process, there's no pleading with the computer's saying I can't afford a $200,000 bail.

[01:05:42] There's no pleading with the computer saying, listen, I've been a member of the rotary club for 20 years and I own a business here. I have tight ties to the community that bail is just way too high because in many communities they are using artificial intelligence and relying on it a hundred percent.

[01:06:00] That's one of the big problems with computers. People because they don't really understand them. Just say fine. Just yeah, go. The computers is almost always right. Yeah. The other problem is we don't know how it was programmed. Now in the case of this Chinese computer, that acts as a prosecutor for charging.

[01:06:23] They fed it 17,000 cases. Do we know what those cases are? Do we know what the computer weighs when it's making its decisions? And we've seen this already, in some cases here in the U S where normally you can face your accuser. Normally you can go to the court and say, this decision by the justice of the peace was not quite right.

[01:06:46] It needs to be fixed right now. They did and all well and good. And so if they had someone or they'd come in and testify to say, yeah, you're not a flight risk, et cetera, you're fine. But when it comes to the computers, people tend to just believe them. What were those 17,000 cases? Were they all nasty dissidents?

[01:07:09] What did the computer learned from it? And some of these cases that we've had in the us we've found. That even the people that provided the software, that AI software, they don't know what the decision-making process actually was because the computer learned how to do it. And you need to understand AI models and how they're fed data and how they work.

[01:07:35] But basically the computers come up with their own way of thinking through things. Just to make this simple. So it's not necessarily totally logic. It's not like back in the day, you'd write software that says, okay, if they have lived in that same home for over twenty-five years, they have kids in school, they own a business, et cetera, et cetera.

[01:07:55] So you set up all of the explicit parameters. And from that, now you can say okay, fine. So you've got, went down this path based on. Person was and what their background was. Therefore, you came to this conclusion. That's not what's happening with this newer AI, not at all. And then you also have the question.

[01:08:16] Okay. What does 97% accurate? Who's going to take responsibility when there is a mistake. Now I'm not talking about the 3% that they're admitting could be mistakes. I'm talking about the 97% of the time. And then if you now move up to the courts, who are they going to talk to? The prosecutor, the machine, the designer of the algorithm.

[01:08:42] Are they going to examine all 17,000 cases that were fed into this? I goes back to what I said before about airplanes. People are not good at monitoring computers, but computers can be good at monitoring people. In other words, in this case, the artificial intelligence may help detect a mistake, but it really cannot replace humans in making a decision.

[01:09:09] It's very true. China's relying more and more on AI to boost productivity. They're using AI with facial recognition systems for their social credit score that allows people to get on. Train you can't get on a train unless you have a high enough social credit score. And if you J rock walk, you have now lost points.

[01:09:32] So it's it's really crazy. So I'm very concerned about this. I found some great information by the way, online from the justice department about what they are looking to have AI do. And it's basically everything making decisions and informing. What should happen? They're looking at using chat chatbox to provide legal advice for pro se litigants.

[01:10:00] In other words, people that are trying to defend themselves can go to a chat box that will give them some direction. That's all in the works. I'm looking at the official documents right now, criminal justice testing and evaluation consortium, looking at artificial intelligence. Hey, make sure you subscribe to my podcast.

[01:10:21] Craig peterson.com/itunes, and I hope I've earned a five star review. And if you could take a minute, just give it right there.

[01:10:31] We all know the children online suffer some pretty serious consequences in certain cases. The federal trade commission has now won a case against Google. We're going to talk about what's going on. With ads.

[01:10:47] The FTC has now been enforcing what's called CAPA, which is the children's online privacy protection rule.

[01:10:58] And they have find. In fact they find them. What was it? Almost 200. Yeah, exactly. Let me just find it here. Sorry about that. They have find Google to the sum total of. 170 million. That's what I thought it was almost $200 million penalty. So what had happened here is YouTube. Now YouTube is owned by Google has been for quite a while.

[01:11:28] And in fact, YouTube. Advertising to advertisers that quote YouTube is today's leader in reaching children age six to 11 against top TV channels. They also said that YouTube is the number one website regularly visited by kids. Now we know that they are not supposed to be directing any content to children under 13.

[01:11:58] Now you could argue, all right, they're not directing content to them, but the facts are the facts of kids are on the site. They're on the site. Yeah. But why would you promote that to advertisers and. You were exactly promoting to children. And that's what the federal trade commission said. Hey, Google, here you are promoting your ability to target these kids by saying you are the number one platform for them.

[01:12:30] So you shouldn't be doing that. So this settlement they came up with Google required you tube to pay $170 million penalty. They were also required to implement a system. That permits channel owners to identify content is child directed. So YouTube can ensure it's complying with the rule going forward.

[01:12:53] So remember YouTube doesn't make the content that's up on their site. They steal it from you. They don't exact this dealer from you, but anything that you're uploading, they may try and monetize. If enough people watch it and stay on their site longer. Which is the goal, by the way, for your content.

[01:13:11] If you put it up, really Facebook's the same way. LinkedIn, everybody, they want eyeballs. They want them to stay on the site so they can show them advertising. The people who are making the content are these content creators, just you and me uploading stuff to YouTube. As well as these people that have somehow become very popular that I just don't understand.

[01:13:32] So here are also some things from our dark reading website here. Alison LeFrak, she's senior vice president of public policy. Ads privacy and children's online privacy protection act compliance at pixelate. So she's come up with five things she thinks should be adopted by the industry. First of all, improve transparency ad networks platforms should consider implementing their system that lets online services, identity.

[01:14:05] To the ad network or platform that their content is child directed, which is something that the courts are demanding here now. The FTC settlement is I should say, number two, stop collecting children's data once an ad network or a platform like YouTube sets up a system where developers can signal that their app or their software or their.

[01:14:30] Oh, the video is directed at children. That ad network needs to take steps to not collect personal information through those websites. Make sense apps or channels. Number three, involve parents when required, even if an ad network is not collecting precise geolocation information from children. If it collects wireless network identifiers to infer precise location, it is required to provide notice.

[01:14:56] Teen consent from the parents. I'm loving all of these number four. Protect sensitive data. If an ad network decides to collect children's data, it must maintain the confidentiality, security and integrity of the information. It should only retain the data as long as necessary to fulfill the purpose for which it was collected.

[01:15:19] And the ad networks should delete the data in a way that protects against its own authorized use. And number five remained stringent on protecting children. So I think all of those make quite a bit of sense. They're all things that ad networks and these platforms should be doing, but they're not required to do it.

[01:15:38] And I, I go back and forth here. My dad and mumble both used to say there ought to be a law. No, that's not how my mom said it, you get the idea. And I'm at the point where I say, man, we got to get rid of most of these laws, rules and regulations, because they are hampering us something.

[01:15:57] If you look at the Scandinavian countries, some people say, oh, there are socialists over that. No, they're not. They have very high taxes and they have a lot of community services, but Switz, they're not Switzerland, Sweden, for instance. They know that they have to keep their businesses healthy so that they can collect taxes.

[01:16:18] So they stay out of the way versus here, where we already have a socialist system. We have all of these rules and regulations that effectively provide the government complete control over businesses. It's absolutely crazy what we've been doing. So I don't know what to do here. I'd like to see the advertisers adopt something like this, but keep an eye out.

[01:16:43] If you have kids, they are targeting them. Now they've been targeted. Kids have been targeted since the early days on radio and television. Remember the Buckaroo, Bonzai and all these other things that were really cooled and some adults listened to them, but. Kids listen to film a lot and watch cartoons as kids and how the cartoons were again, aimed at the kids.

[01:17:08] Right? Saturday morning cartoons it's really don't exist anymore. Nowadays they're doing it online. So have they crossed the line? I don't think they've crossed the line any more than advertisers did all of those decades ago, but yeah it is a bit of an issue and something that we should pay attention to, particularly as parents.

[01:17:30] So the next question I have here, and I'm sighing because it's just a shame that things aren't. A little better. Aren't more open government and everything else. It's just everywhere you turn. Even in my industry, there's a, I'm working on this bootcamp right now that we're going to be doing, and it's going to be a free bootcamp for anyone who wants to attend.

[01:17:53] And we're really going to teach you stuff. We're going to walk through it on, and it's the, on the basics of some of the security stuff you need to do in business and in home. And. When I came across and what really bothered me was this whole concept of the cyber security industry, lying to people.

[01:18:14] And they've been lying to you for years. They are selling antivirus software. That's based on designs that are 20 years old. The stats that really upset me are the antivirus software that you're buying that you're paying good money for. It doesn't work in 70% of the hacks that occurred last year, 70% of the time, it doesn't work.

[01:18:42] Obviously it doesn't work again. Zero day attacks, which are attacks that have a bug that nobody knows about. But so much of even the ransomware, the viruses we had of years past hides itself very well from the antivirus software very well. And that gets to be just a huge problem because it, every time it spread.

[01:19:06] Changes its digital signature, if you will. So now when the antivirus software looks for a specific strings that are in there, when it looks for specific checks, it's not going to find them because the software morphed itself, it changed it. very big deal. And these companies are out there selling their software as though it's a panacea.

[01:19:30] So I'm looking right now and I can send this to you. If you are interested, just drop an email to me. M e@craigpeterson.com. And I'll send you a link to this, but there's a website out there called AAV comparative. And they are testing different types of software. So in 2021, between August and November, they looked at real-world protection, malware protection, performance, and product review information.

[01:20:02] So they put it all together. And they tested, what is this about a little over a dozen different products, very popular products that are out there. And like a vast business anti-virus pro plus bit defender gravity zone, elite Kaspersky, which you probably shouldn't be using Microsoft defender, antivirus virus with Microsoft endpoint manager.

[01:20:27] Okay. So what are the good ones? Bottom line. What I'm recommending nowadays is that you just use the Microsoft software, Microsoft defender. It is, I'm looking at the chart right now. It is pretty much as good as anything else. Out there. They, the better one is bit defender, which I really like. And I recommended to a lot of people.

[01:20:53] Some of you guys have been writing me the last couple of weeks. I'm guessing because you just got new computers about what antivirus to use and bit defenders. Very good. And there's versions for Mac as well as windows. And remember if you have a Mac and you send something to someone that has windows or you're on a network with windows that the files.

[01:21:14] Affect the Mac at all. If they are exchanged with somebody on windows, could knock that windows and machine completely off the air. So be careful with that. So those are the big guys. Those are the ones that worked really well. And I've got to say most I'm looking right now across These some good ones CrowdStrike's listed really well.

[01:21:39] They're using a low end, Cisco for comparison here, and it did better than cyber reason for instance, or a Cronus or some of these others. But. Yeah, it looks like you're best off sticking with the Microsoft and bit defender. And if you want something that's more professional than get the advanced malware protection from Cisco, which is it's combining a bunch of things and it's really the gold standard.

[01:22:08] It's something that we use with our clients. You cannot buy it directly. To get it from a managed security services provider like us. Anyways, any questions? Email me emmy@craigpeterson.com and make sure you're on my email list. Craig peterson.com/subscribe to get all of this stuff for free.

View Details

Considering a change in employment? Apple/China/Green Army/Bitcoin seizure and Cybersecurity Jobs!

Apple has upended a lot of industries over the years, and it is about to upend yet another one. Square is a company that has been making a lot of money and its run by same guy that ran Twitter. You know that Rasputen-looking guy? What's Apple doing to the finance industry?

[Following is an automated transcript]

This is a real big deal. Apple has been for a long time upending industries.

[00:00:23] You might remember, of course, the music player. In fact, I still have an old MP3 player. You can't really see it very well from this angle, but it was right over there. And then. And it was a five gigabyte player. Just amazing thing was huge. It was actually designed by digital equipment corporation, licensed by this other manufacturer, put them together.

[00:00:44] Great audio quality. They had these little costs, headphones that came along. I loved the thing. Absolutely loved it. And apple came along, they weren't the first and they introduced their own MP3 player. That was called an iPod. And it did very well. It just slaughtered everybody else. You might remember the Microsoft came out with their zoon and many others came out with their own little MP3 players.

[00:01:12] No, nobody could touch our friends over at apple with their iPod. And then what happened? Around 2010, think for a minute. What new product did apple introduce around 2010? Of course it was this right. It was the I phone now the iPhone cut dramatically into Apple's market and for a good reason. It was a phone.

[00:01:38] It was a smart phone. It could play all of your music. I still have and still use 120 gigabyte. I iPod. At the kind of the classic I think is what they had called it. And 120, it was just amazing. Just that much music. Of course, me, I have a lot of lectures, a lot of audio books and other things I listened to on that, on those iPods and what happened.

[00:02:05] Of course. Now you can get these I-phones with a terabyte of memory in them, just incredible amount of space. And that's a pretty good thing, frankly, because you can store everything. But at the same time, our networks are getting faster. Aren't they? So our networks, like what we have for our cellular phones and stuff are faster than they have ever been.

[00:02:29] So you don't really need as much storage do you, as you used to have. On your phone or your iPod or your MP3 player. So it's an interesting game. How much space do you need? And I'm asked that all of the time and the newest iPhone is coming out, have a lot more memory. I think they have eight gigabytes of Ram in them.

[00:02:48] And as I said, a terabyte of storage. But what apple was doing is saying, Hey, we own this iPod market, the MP3 player market. And of course it's more than just MP3s, lot of other formats out there for the music or audio books, but they owned it. But they knew that if they were going to survive in the industry, they had to do something else.

[00:03:13] Came out with a product that competed with their award winning and just top of the line product, the iPhone and your iPhone works every bit as well as an iPod ever did. And of course ever so much better because now you don't have to download the music on your iPhone to listen to it, to you. You can stream it over the internet, over wifi, right over the cellular data connection, those things we've gotten fast.

[00:03:38] Two great option for. What Apple's doing now is saying we need to append another market. Have you ever had, again, like you, you got your phone, right? And let's say you're a small merchant, maybe your coffee shop, or maybe you're even smaller. Maybe you're just out at a flea market selling stuff that you might want to peddle.

[00:03:59] You have to get an, a credit card. Don't you. And back in the day that credit card reader would plug right into the headphone Jack and with a headphone Jack, you'd be able to go online. No problem. Life is good. And once you're online, then you can take the credit. Now you didn't just have to go online with your iPhone, but you had to be able to go on line with your phone and the reader, because when they got rid of that wonderful little headphone port, you now had to use Bluetooth, didn't you and you still.

[00:04:37] So you get that reader from square or that reader from PayPal or somewhere else it's acting as your merchant account. And that reader then uses Bluetooth to talk to the phone and then it can read the credit card or the chip. And of course, with the chip it's by directional, it has to get the information to, and from that trip, And then you've got the credit card that you can process all well, and good.

[00:05:04] We're all happy about that, but here's your next problem? Bluetooth. Isn't always working. That reader has to be charged. Did you charge it before you brought it before you started using it? So apple said wait a minute. In our I-phones we have built in a few different things. Do you ever used apple pay?

[00:05:25] It's probably the safest way to pay online bar? None. It doesn't actually give the merchant the credit card. And it gives them a code that they can read Dean in order to go ahead and get the money from the transaction so that transaction can then be redeemed by the merchant. And that's all stuff handled by your merchant account.

[00:05:48] You don't have to worry about it makes life. However now what they've done is they've said let's reverse this. You can use your iPhone with apple pay in order to pay for things. And it has, what's called near field technology in it that allows it to act like those tap and go credit cards I've ever used.

[00:06:08] One of those where you can just tap it and it makes the transaction happen. Pretty simple. So it has that in there, but it also has the ability. To read those tap and go transactions. So it's going to be interesting to see exactly what happens here. This is a very big industry. There is a whole lot of money in it, and there's an article this week from our friends over in ink magazine.

[00:06:36] I got up on my screen for those who are watching a video here on rumble or YouTube. And it's talking about this feature that they introduced quite quietly. Because this new capability is going to change things. Now you are still going to have your merchant account. So you still might have to have a Stripe or a PayPal or direct merchant account with your bank.

[00:07:02] But this is allowing contactless credit and debit cards and other digital wallets to be able to be read from any one's iPhone, which is really quite. Now there's things like Venmo and others out there that people use. My kids use a lot more than I do, but they use it to send money back and forth to each other.

[00:07:23] It's a pretty good little thing that they've got going, but with something like this, you wouldn't even need to use a Venmo. So those are the guys that are going to get really nailed by it. And Stripe really is phenomenal. It's so easy to use and I use it as well. I use. For my courses. If you sign up, for course, to almost always going through Stripe, I know there's some other alternatives out there right now that are a little more friendly to the non-mainstream, but I haven't been able to integrate those yet in Vermont payment processors, but there's still going to need it.

[00:08:01] You can use cash app, Venmo. It's not going to stop you from doing any of that, but it does stop you from having to have another. Piece of equipment with you, which is just something else to go bad, or dig to have, get dirty to, to not be able to work for you. So we'll see what happens. This is cutting out.

[00:08:22] These companies like square. They'll no longer be able to. Have from the front to the back, they'll still have the back, frankly, but they'd be able to accept payments from pretty much anything that's contactless, which is I think a very good deal. We'll see what happens. But again, this is not apple going after Apple's existing customer base, like it did with the I Paul.

[00:08:50] Transition to the I phone. This is apple going after another piece of the retail space. And remember what I said earlier, it's not even just that app. Has the ability to enter market, but we've seen time and again, where apple enters a market that's already established. It's not quite mature, right? You haven't had all of those acquisitions going where the companies are buying each other up, but it is going to make a huge difference because again, apple up.

[00:09:23] And apple has ties in to a couple of banks that they use for processing their apple cards. Think it's Goldman Sachs, and they could potentially provide you with the merchant account stuff on the backend. So I think that's pretty cool. And it's going to allow us all to have a cashless. The yeah, if this was a political show, that's probably what we'd be talking about.

[00:09:50] Wouldn't it? Because there's certain problems with doing that as well. Hey, I want to invite everybody to take a few minutes right now. I am making some changes. I've been working on some of these for weeks, but I've got a lot of clients. I've got two. Take care of first, right? I've been doing a lot of CSO work, CIS, so chief information security officer, just on a fractional or part-time basis as a contractor for a few different companies to try and keep them up-to-date with all of the latest in technology.

[00:10:22] So it's been really fun, but I haven't been able to do everything I want to do yet on the radio show. So my wife and I are reaching into our pockets and we're going to be hopefully pulling out somebody to help us with some of this, because what I want to do is send. My show notes to you guys every week.

[00:10:41] So you can see what I'm talking about. You have the direct links, as well as my newsletter, and I want to start doing my Wednesday wisdoms trainings more regularly. It's really hit or miss. So trying to do all of that, and I'd really appreciate it. If you would go right now to Craig peterson.com and make sure you sign up right there for my email list, Craig peterson.com.

[00:11:07] Get it. All right.

[00:11:10] We've been very worried about China for quite a few years, for more than one reason. But one of the biggest is they have dominated some of the most critical markets in the world, including some of these mineral resources that we need.

[00:11:27] China has been a big worry for many countries around the world.

[00:11:32] For a long time, I met with the ambassador from a couple of these African countries and had a great little chat about what was going on there. They wanted to become this one country in particular, the data processing center. For Africa and Africa, of course, very big country or continent, I should say with a lot of countries and a lot of financial transactions.

[00:12:01] And they figured what we need is a good data center. We need data lines coming in. And so they got some of those data lines and they got the data center. The data center provided by our friends in China. And so this data center was being used for a few different things, but it sure was not being used for these financial transactions.

[00:12:27] So they wanted it to be used for because China. Provided the equipment. And we know from a lot of articles, a lot of research and from the federal government, the China has been spying on us. And I have seen it personally with some of these DOD sub subcontractors. In other words, it's not necessarily directly contracting with the department of defense, but providing parts and things via subcontractor relationships.

[00:12:59] And China is a problem. So what do they do? How is this small African countries supposed to become the data processing country for all of Africa, with Chinese equipment? How could they possibly do it without Chinese equipment? And that's what the ambassador was telling. We need this equipment this is it.

[00:13:19] They had Chinese routers, switches processors. They had racks of equipment set up in virtual environments and they were all set to go. China's been doing similar things in other parts of the world where they come in, they might build a port for instance, which has happened many times, one in Indonesia, particularly I'm thinking of, and they financed the port.

[00:13:45] If you don't make the payment on that data center or the payment on the port or the payment on the railroad system, et cetera, that China has installed in your country, guess what's in that contract, you forfeit them. So the data center now becomes absolutely. China's not just a lean on it, not just a lease from China.

[00:14:11] It is China's data center. That port is China's port. In fact, they own the largest port. Now I think in all of Indonesia, maybe the whole Pacific rim over there, I'm not sure, but that's what they've been doing. Same thing with railroads, et cetera, et cetera. So China really has a lot of companies and countries over the.

[00:14:35] That's something we didn't want to have happen here in president Trump, you might remember was very adamant about it. He did a whole lot of work to make sure that none of the Chinese interests would really be able to take over and control our us interest. It makes sense to me. So what has China been doing to us?

[00:14:58] We know about the steel and remember China was dumping cheap steel into the us and world markets that hurts us. We have a need to make things here. If we ever haven't forbid got into a war. And we needed ships or boats or planes, or we needed armaments of some sort or another. We need to be able to make them in the United States or in an allied country.

[00:15:29] You remember how many problems that Britain had during the war? Trying to ship stuff over. I have two kids that were merchant Mariners and the U S merchant Marine academy is the only. Of the military academies, that flies battle standards because they lost cadets who were there at the school during warfare.

[00:15:53] Okay. It's a bad thing. We don't want that to happen. So not having to rely on other countries actually ends up being a bit of a positive thing, depending on what it is. China's sent us things like dog food, that's contaminated, baby food contaminated. Even those, green recyclable bags, people take to the grocery store.

[00:16:16] Yeah, contaminated with lead. It goes on and on. They also had control of 99% of certain precious metals that are needed for some of our key manufacturing here in the U S so we put tariffs on China for steel. We did the same thing in 2021. In fact, they put a tariff of 23% in 2021 to protect the steel manufacturers here in the U S.

[00:16:45] From these cheap Chinese imports, not just cheap, but low quality steel Weiwei, you know about them. They owned the smartphone business in many parts of the world. In fact, here in the United States, you could get cheap Walway phones. Now, Weiwei of course, if much about Canadian history, know about Northern telecomm, who did a little.

[00:17:10] Pioneering in the whole phone business for many decades and the allegations. And there's some proof that I've seen that leads me to believe that these allegations are correct. Are that while always stolen? Northern telecoms designs, its plans, et cetera, and put all of that together to make Walway.

[00:17:32] So they steal the plans, they steal the engineering, they steal the research and development, the intellectual property. They then start making it, of course, without having to worry about the investments into R and D and developing products. Now they just stole them and then they flood the markets worldwide with.

[00:17:52] Equipment paid and manufactured in some cases by slave labor in almost every case by substantially low wages and. They then control of the market. So we said no way to Walway and that was something president Trump started. It's actually a really good thing. And Google apps are now no longer allowed on Huawei phones.

[00:18:19] So China used to have a 99%, almost total monopoly on rare earth metals. I'm going to bring this article up on the screen from our friends over at American. But now they have fallen to less than 60% monopoly. So they've been trying to stop shipments of rare earth metals to countries all over the world to drive up the prices.

[00:18:45] They did the same thing here to Japan because of the contesting in the south China sea of some of these islands of some of these mineral rights. But since then in the last decade, rare earth metal. Are being mined. In other parts of the world, we talked here about what California is doing. California is now going to be mining lithium and some of these other rare earth metals that we need to make batteries.

[00:19:15] We need to make processes. We need to make cars. We need to make light bulbs right on. And. They used to have a near monopoly on foreign off shore investment because companies were going to China like crazy, because the cheap wages over there, 1.4 billion consumers has been leading companies that make movies like Disney to go over to China.

[00:19:39] But things have really stopped in some of these growth areas for China. And in fact, have reversed in a very big way. They're clamped down on business, censoring of wealthy capitalists food, shortages, growth, centralized government corruption. Gross, excuse me, corruption, mismanagement, stagflation, plunging birth rate, all resulted in investments and opportunities.

[00:20:04] Fleeing China. Great article in American thinker. Keep an eye out for it in the newsletter this week and stick around. But first check out Craig peterson.com. Make sure you're on my email list. And if you like watching video, Hey, I'd like to invite you to watch me and follow me on YouTube and rumble.

[00:20:27] This is straight out of the, what were you thinking department? In fact, what are you thinking? Yeah, the us army is planning on going green. Yeah. They want electric vehicles in war.

[00:20:44] This is a plan that you just are going to have to shake your head at a, again, it's a little bit of idiocy, but before we talk specifically about the plan, I want to talk about something related.

[00:20:59] Now, remember this plan is from the U S army and they want some goals read Sean on climate change and electric vehicles here over the next 20, 30 years. So let's look at the science behind what they're talking about, and I'm going to show you the actual statement that came out from the military. And one of president Biden's appointees is just nuts, absolutely nuts, but I'm going to back up a little.

[00:21:34] For those of you who are watching along at home. Let me pull this up for you. This is from slash. And it's quoting a report over on the wall street journal and pulling some stuff together. But what they're doing in this particular article is talking about how our friends who have come up with these super computer designed.

[00:22:02] To model our weather have been be fuddled they've reworked 1.2 million lines of computer code in order to compensate for something that I don't know about you, but if I was writing the code, I probably would have compensated for it in the first place cloud. Clouds. Yeah. Yeah. It turns out this is just to me, absolutely boggling the mind, that great glowing orb that appears in the sky.

[00:22:35] From time to time. Yeah. I'll give or take half of the day. That thing called the sun apparently has something to do with the earth warming up. And do you know what else does, the clouds that are up in the sky? Those clouds can reflect the sun's heat and they can also hold heat in on the ground side, who would have thought.

[00:23:01] So all of these models that they've been using, cause remember by now, as of more than a decade ago, New York Manhattan is underwater. Remember? Yeah. Al gore with his scientific moon movie at this science. Is just cited. It's proven and Florida by now was underwater. And so as Manhattan, and of course neither is true because they had no idea what they were talking about.

[00:23:27] This article in the wall street journal, Totally baffles me. And I'm just showing you the excerpt from slash.here on the screen because the wall street journal was paid. And I don't want to have to push you guys to paid stuff if I can avoid it. But they thought it was really strange cause they updated the simulation in 2018 and in 2018 it turned out that the earth was.

[00:23:55] Way more sensitive to greenhouse gases than they thought. And, oh man, they had to think about that because, in Boulder, the national center for atmospheric research they said if that number was correct, that would be really bad news. Yeah. And at least 20 older climate models disagreed with the new one, but they were simpler and this new one is an open source model.

[00:24:20] So anybody can look at the code and kind of figure it out. So I, then what ended up happening is. More than a dozen other models were released and it turns out wait a minute, now they're agreeing with us. Do you remember that spaghetti code that predicted the COVID 19 was going to kill?

[00:24:40] It was a two and a half million people in the United States. Of course didn't get anywhere near. Close to that, because the way we kept the stats, right? W co dine with COVID versus because of COVID right. Remember that whole controversy. It turns out that the scientists concluded that their new calculations have been thrown off kilter by the physics of clouds in a warming world, which may amplify or.

[00:25:08] Climate change. Isn't that what I had just said, that Kyle taken, they can block the sun and they can also keep heat in. A night with lots of moisture in the air, whether it's humidity or cloud is going to stay warmer than a night where there's no clouds. These are experts. So the fact that they left out clouds and the effect they might have, I must make a whole lot of sense, because this is a science and the science has settled.

[00:25:34] Yeah. So Andrew Gettleman now physicist there in Boulder said that the old way is just wrong. We know that I think our higher sensitivity is wrong to it. It's probably a consequence of other things we did by making clouds better and more realistic to solve one problem and create another I, again, I got to point out science, mind.

[00:25:59] Science is not settled on pretty much anything and it never has been. And until we are all knowing, it never will be. So keep that in mind and quit having your heads just be so inflated that you think that you're absolutely right, because I'm not absolutely right. They're not absolutely right. No, one's absolutely right.

[00:26:23] So let's get into the army here. This is just so exciting. Cause Christine wor Muth is the secretary of the army now, and the army is going to lead by example. And we put this up on the screen. I just realized that I'll have this up on the screen for you guys. We will use our buying power to drive change in the industry and leverage best practices from.

[00:26:47] Sources. There's another great quote here from the secretary of defense. W we face all kinds of threats in our line of work yet. Yeah. Secretary of defense army. Yeah. Okay. But a few of the threats truly deserve to be called existential. The climate crisis does climate change is making the world more unsafe and we need to act right.

[00:27:14] That's what she's saying, that this thing goes on for pages, what the goals are. So I decided, okay, Craig, let's have a look at this. I'm going to do a search in this PDF for the word risk. What are the risks? If we're going to be messing with the military, with the electric vehicles, because in the middle of a war zone, it's great.

[00:27:33] You just, you stop, you plug your electric vehicle and let it charge for half an hour. And then you're off and running. And particularly where tanks are right. Where we're trying to protect our personnel. Maybe have an offensive. They'll wait while we charge our tanks, right? Oh and a little tiny solar cell, or we cover it with solar cells.

[00:27:51] That's going to be enough to charge it if we leave it sitting there for a week. So we're okay. So what are the risks associated with us being idiots and moving towards an electric army? Okay, so risks here. Okay. So this is a risk to the climate. This is climate risks. Oh, this is red mitigating climate risks, assertion of climate change risks impacting the army at all levels from how and where our units operate and train to how to service as a whole.

[00:28:21] Okay. So that's risks of when the climate changes, as we know it will, because those guys wrote 1.2 million new lines of code. Okay. So we know it's going to change. Okay. So let me see risks, climate change, imposes, climate threats, and risks. Address the risks associated with these. Let's see here.

[00:28:43] What else do we got? Climate change risks. Climate change risks. Oh, they're going to install micro grids on every installation. Okay. Climate change risks. This is nuts. And the New York post has a great article on this insanity. Oh my gosh. What are we going to do with these. Yeah, our military, we're going to stop and charge our vehicles.

[00:29:10] Yeah. All right, everybody stick around and visit online. Craig Peter sohn.com. I'll keep you up to date.

[00:29:24] We're going to talk about this Bitcoin laundering case that really turned the internet upside down. Cryptocurrencies, Bitcoin, how safe is it? How secure is it really? And what happened here? Because this Bonnie and Clyde failed.

[00:29:41] This is an article from the New York times.

[00:29:44] Now I know I don't like to, you guys know this show you stuff that you have to pay to go to a paid site and particularly something like the New York times. It's amazing to me how they have some really great journalists that do a good job on some of these stories. And then they just totally go political on so many of the other stories, and I'm not talking about the editorial page, knock yourself out.

[00:30:11] But anyways, this is a fascinating story to me because so many of us think that using Bitcoin is going to be safe after. Cryptocurrency. And crypto means cryptography and cryptography means we're keeping ourselves safer. Isn't it? Isn't that? How that's all supposed to work kind of the bottom line while in reality, it doesn't always work out that way.

[00:30:40] And when it comes to cryptocurrency, it definitely does. And I want to explain a little bit about cryptocurrency for people, if you don't understand it very well, just putting the very, very, basically the way it works is there are ledgers, just like the old ledgers you used to see at the banks or businesses, those big.

[00:31:02] And they'd maybe do double entry ledgers, or maybe some other types. Nowadays. Of course, all of this stuff has done on computers, but the idea is you walk into your bank and you say, I want a hundred dollars from my account. So the bank opens up its ledgers and sees, okay. Your account has X dollars in it.

[00:31:23] They give you a hundred dollars in that ledger. Now they marked down that your account now is a hundred dollars less because you just would do a hundred bucks. That's the simple way it works with the bank. It's actually very similar with the script old currencies, but what happens in cryptocurrencies is you're not dealing with one institution.

[00:31:46] So it isn't just your retirement plan that fidelity friends. With it, when it comes to cryptocurrencies, these ledgers are maintained by hundreds of different businesses and people around the world. Thousands depends on the cryptocurrency itself. And the idea is when you go and you want to take your a hundred dollars for instance, from the bank, they look it up in their one ledger in that ledger is assumed to be correct.

[00:32:15] But when it comes to cryptocurrencies, there have to be the majority of ledgers that agree about how much money. And those ledgers are all public ledgers. So it's like having a Swiss bank account in that your account is represented by a number that's actually where the cryptography comes in and the keys, public keys and everything else.

[00:32:40] But your account is essentially represented by a number. So if you want to pay the a hundred dollars to. In cryptocurrency. So it's probably some fraction of some cryptocurrency what's going to happen is you are going to have half of the ledgers for that particular cryptocurrency agree that you're transferring a hundred dollars.

[00:33:07] From account number 1, 2, 3, 4 to someone else's account, which is 5, 6, 7, 8, just as an example. Very simplified example. So now what happens is the people who are running the ledger that you're using the main ledger, check the other ledgers and push your transaction onto the ledgers. That's why it takes a while for cryptocurrency transactions to occur.

[00:33:32] Because it has to push out to these ledgers. Half of them have to agree in order for it to be a reasonable and accepted transactions. That make sense. Good. So what we have here now because of public ledgers is public information. The amount of money you have in that number to count can be seen by anyone who cares to look.

[00:34:00] It's really that simple. Anybody can see it. So why are people thinking that it's crypto it's safe? It can't be taken by the government or bad guys, et cetera. Those concepts are all insane. The. Sort of privacy or security you have is related to the ledger. So the security is half of the ledgers have to agree.

[00:34:23] So someone hacks one ledger, that's not enough to get control of all of your cryptocurrency or whatever it might. If someone hacks your wallet, that's a different story entirely. Okay. But that's not what we're talking about right now, but everybody can see that you have a hundred dollars in account.

[00:34:43] Number 1, 2, 3, 4, the pro the trick is, and the problem for law enforcement, they don't necessarily know who owns account 1, 2, 3. So what law enforcement does in order to get money back or to arrest people is they watch these accounts. So in this particular case, there's Bonnie and Clyde, if you will hack a cryptocurrency exchange.

[00:35:09] So this is again, one of these ledgers sites and they'll often exchange us dollars for various cryptocurrencies. Back in 2016, Bitfinex was the name of it. And they store $71 million in Bitcoin from effectively wallets are there on that site. But because these trades are publicly. People on the internet knew that it happened.

[00:35:39] In fact, people on the internet were watching that wallet waiting for money to move. And this couple that's alleged to have stolen it's Iliya Lichtenstein and Heather Morgan, that account could, they could see that $71 million was in it. But over time, six years later, the value of Bitcoin had gone up substantially.

[00:36:06] And today is worth about $4 billion. Isn't that just amazing and a lot of money. So they moved it to another account and that's when the got in trouble. So if you have a Swiss bank account, 1, 2, 3, 4, and you transfer money to someone else that I know, I now can trace that account. I say, oh, I know who has that.

[00:36:35] Yeah, that's 71 million worth of Bitcoin. Back in the day, that's now worth 4 billion was in this account and they just bought themselves a new Porsche cayenne at this dealership. And all law enforcement has to do is knock at the dealership, say who was it? And now they know who the people are, but in this particular case, The bad guys had left that money in that Bitcoin account, but that money did get transferred, but guess what?

[00:37:05] It wasn't them, people on the internet were thinking that the hackers had emerged that they were transferring the money to other Bitcoin accounts, which you see fairly frequently for these illegal transactions, but it wasn't the hackers who move that stolen. Bitcoin. This is again from the New York times, it was the government which had seized it as part of investigation into two New York city entrepreneurs, one with a little known Russian emigre and techie investor who had just named the other, his wife, an American businesswoman, and would be social media influencer with an alter ego.

[00:37:44] Is this a terrible rapper named razzle con. Yeah, amazing. You can't make this stuff up. Can you, so they're charged with conspiracy to launder billions of dollars in Bitcoin. Ilya is 34 and Heather's 31 accused of siphoned off chunks of the currency, trying to hide it in this complex network of digital wallets and personas.

[00:38:07] And if they're convicted of it and a second. Spare seat count that has been put against them. They could be facing up to 25 years in prison. So as is always the case, oh, you asked the neighbor, he was a good boy. He was a very good boy. I love that. How we are, but he's that little bit all over the.

[00:38:26] But the couple's neighbors said they're goofy, normal types of people never expected that. But these are part of a real change that we've been seeing over the last few years into investigations in the cryptocurrency field. Now, remember crypto isn't necessarily the best thing.

[00:38:44] Own any, never have owned any. I played around with some mining stuff at one point, just on my regular computer to see what it was all about, but it is not anything that's worth anything to anyone. Frankly, what I did now, a lot of people have been buying it. Of course, part of the problem with it is in order for it to be truly useful, you have to convert it back into something like a us dollar or maybe some other type of currency.

[00:39:11] And that's often when people get caught and nowadays on the tax forms, it even asked you about any sort of crypto holdings that you might have. So remember all of that. They don't know, by the way, this is again from the article, the New York times, if they were directly involved in this breach all those years ago, but this is really crypto culture and it really is the fringe.

[00:39:40] And they went crazy online and started looking at the digital trail. Her videos suddenly shared widely. Yeah. They've become infamous, is the right way to put all of that. Hey, if you like the show, I would really encourage you to follow me. You can follow, listen to my podcast on tune in on any of the major, in fact stream.

[00:40:09] Platforms out there SoundCloud you'll find me on apple, et cetera. And I just started videotaping the shows last week. And this week I've done little things before, but now I'm trying to do the whole. So you can watch me on the show as I'm recording it live and see a little bit behind the scenes, which I've always liked.

[00:40:35] I've been watching how we Carr and grace Curley do their show. And I thought, it's well worth it this week. I did a little bit of editing on. Cut out some of the in between, cause I had some longer coffee and fit and had to stretch my legs a couple of times, but you get to see the whole thing behind the scenes.

[00:40:54] And if you sign up for my newsletter, you're going to get my weekly trainings. You're going to find out about boot camps I'm doing and other things, but you have to. Go to Craig Peter sawn.com. You'll see a right there on any page, frankly, to scroll down a little bit. It'll pop up right at the top of the page.

[00:41:14] Put in your name and email address, and I'm going to send you a few special reports, including my report on passwords. Craig peterson.com.

[00:41:25] You obviously know about the great resignation. It has been a big problem for a lot of companies out there. Great. For job seekers. Great for you. If you're trying to maybe get a raise, et cetera, especially if you're in the tech industry.

[00:41:42] This great resignation thing, man. Has it hit companies? And one of the biggest problems companies are having is with tech workers.

[00:41:55] You might remember back in the day, we had a big shortage of some of the cybersecurity people, right? Where we couldn't find them. There were numbers saying that there's like a million and a half or more open jobs for cybersecurity people. Now I did a little investigation into that number because it sounded high to me.

[00:42:18] Cause I, I was coding it. It was a number that came from some pretty reasonable sources. But I think this is one of those things where you had one news source stating it and then all of a sudden other people started quoting it. I don't think it was really a million and a half. And what I found was that the people that had put that number together were looking at it and saying, if you have a business.

[00:42:46] Who you should, you have working for you when it comes to cybersecurity? So there's like the CSO, the chief information security officer, which is something I do on a fractional basis for businesses all of the time, helping them to up their security. So you had to have a CSO, you needed to have a team.

[00:43:06] Looking at the logs that was paying attention to the networks. If something happened, they would know when they did investigate and maybe they would do patching close bugs. Which is a different person. One is the network operation center people. And if you're going to have a 24 7 network operation center, that means you need at least four people probably.

[00:43:30] And so the added all of this stuff up right there, the desktop people that are making sure the end points are protected and kept up to date and upgraded. That's how they came up with that, one and a half, 2 million open jobs in the us for technology. The reality was different obviously.

[00:43:50] And now with the great resignation where all of these people are. Out of the jobs. And part of the problem was already the beginning of the lockdowns. They had people suspended. They laid them off or they said, okay maybe we'll have you back. It's only two weeks to flatten the curve.

[00:44:11] So yeah, take a couple of weeks off. And so that gave people the opportunity over that. Period, which actually was two years, right? A minute. Maybe it's just my imagination. I'm not sure. But did that whole flatten the curve period that lasted for two years, people said I don't like this job because Frank.

[00:44:32] There is very few jobs. There are very few jobs that are as stressful as the cyber security jobs, because you're dealing all of the time with the senior executives saying I'm not going to double log in. I'm not going to carry a token around with me. I'm not going to have my screen time out after.

[00:44:55] Dean minutes or five minutes? No, it has to be half an hour and I just can't get my work done otherwise. So you're fighting with senior management who approved the budget in the first place, to at least do the minimal stuff. You're fighting with senior management to. The budget you need in order to keep the company safe.

[00:45:15] Because nowadays, if you're not keeping a company safe, you can go out of business like that, lose your reputation, lose your intellectual property. I've seen it before with companies, small companies, bigger companies. You've got to make sure all of your backups are in place there. You're using. 3, 2, 1 strategy nowadays, it's more of a 4, 3, 2, 2 1, 1 zeros hero strategy.

[00:45:40] I'll have to do a webinar on that one or a little meeting. We'll get together and talk about it. But again, if you're interested in that you gotta go to my website and stamped for the email list. Craig peterson.com. Just trying to figure it all out is difficult. And then you get all of these false alerts from software and you got to figure out, was this a legitimate alert or was this a false alert?

[00:46:04] What should I do about this? Or should I do about that? Who's really trying to break in. Why are they trying to break in? All of that sort of stuff gets to be difficult. So it's a stressful job. So a lot of people that were in cyber security at the beginning of the lockdown, I said I got to find something better.

[00:46:21] I know a couple of listeners who decided at the age of 55 to 60 in both cases that they would go change their careers had enough of what they were doing and we're going to go and do cybersecurity, took some of these classes, got the basics together and found jobs. In cybersecurity now they're not going to be experts, but they certainly knew more than the other people at the business, including the I T directors.

[00:46:53] And I say that with air quotes. So they both changed jobs during the. Now that's an interesting thing to me because I, and I'm not pointing my finger at either one of these guys, but the number one thing you have, if you are in cybersecurity, if you are a CSO is the top drawer of your desk.

[00:47:14] Assuming you have a desk, there's two things. One is your resume. And the other is your resignation letter because. Ultimately any business can be hacked. Now, I don't want people to say I'm throwing my hands up because it doesn't matter. Any business can be hacked. I'm not going to deal with this, right?

[00:47:31] Why would I spend any money on it all because you can control. Likely you are to be hacked and you can get like a 98 to a hundred percent effectiveness depending on how you measure things. And if something does happen, what matters is, how can you recover? So if you look at things like the sniffs to cybersecurity framework, you'll see, there's all kinds of provisions in there to make sure the business survives a hack.

[00:48:01] Okay. Stuff you needed to do stuff you need to be concerned about. But the whole cyber security side of the business is. Still in high demand because businesses more and more are realizing they can't just get by with running antivirus software anymore. You can't just say, oh I've got wonderful.

[00:48:24] A windows defender on my PC and that's working great. I don't need anything else. Now you have to have a much more advanced system. There's no two ways about it. So what we're finding is people in the it business right now can find a job if they were. Great article here. Let me show you a little bit.

[00:48:45] If you're watching, you'll see this on the screen. Two articles this week that I thought were really great, and I want to run through a little bit, but one is from. Wired magazine. That's a magazine I've subscribed to for a long time. They got some crazy ideas, but they got some good stuff, dude. And it's talking about the shortage of qualified workers and the competition.

[00:49:11] It's fascinating. And then another one here, I'll show you from the New York times magazine. And it's talking about the recruiters who are trying to recruit in the tech space. Now, in both of these cases, what we're talking about are job vacancies that are open in a minimum, hundreds of thousands in the U S right.

[00:49:36] Yeah, it's hard to tell, but what you can tell and what we are seeing is that these are recruiters who used to be stocked quite literally, sometimes by people looking for a job are now lucky. If they get a return, email, or phone, That's how bad it's gotten for them. And the story goes through this one recruiters kind of background saying, yeah I had this one person who's looking for a job and they stalked me, found my picture on LinkedIn and then stood outside the building, waiting for me to come out and then basically shoved the resume in my face and talked me up.

[00:50:21] Another one saying I had mentioned on the phone that I really liked tophi what shows up the next morning, this beautiful handmade toffee perfectly wrapped. So it has gone in just a few years from that where people will do anything in order to try and get a hold of the hiring manager, to where it is today, where people are just saying.

[00:50:44] Forget about it, it just isn't worth my time. The other thing that the recruiters are fine. Is that people when, if they do get ahold of them are saying basically, Hey, I'm just burned out. No, I don't think I have the energy anymore to do this, which is an interesting response. People because of the lock down have just had their.

[00:51:10] Their excitement, squashed, and ability to look forward to what my career is going to be if you're younger and if you're older, like I am, you're looking at it saying I've still got a lot of good years left and I'd love to do this and have my my wisdom, if you will, from all of these decades in the it world and in cybersecurity put to good use, which is why I said I'm doing the fractional.

[00:51:36] Chief information security officer for businesses. But what we are finding is. People can get the jobs, even people who are already retired to semi retired. I read another article this week that I thought was rather interesting. And we'll talk about that a bit when we get back, because it's going to take a few, but.

[00:51:59] The resume side of things. No, we heard the T of course the tophi trick the standing outside and stocking them tricky, et cetera. So what is happening right now? When you want a job, then maybe you've been in the market before for a lot of years and you're competing against the kids that are out there.

[00:52:21] Things have changed stick around and visit me online. Craig Peterson dot.

[00:52:28] We're going to finish up our discussion about jobs and open it, positions it in general. And also going to talk about some of the tips for older employees on the resume. I had a bit of a shocker this week..

[00:52:44] This article, and I'm going to pull up on my screen for those who are watching online is I think fascinating.

[00:52:51] This is from the New York times, and it's talking about recruiters and it's from a recruiter's perspective, Frank. And it's saying here, this is by the way, the one that had that story about the lady that used to be just hunted down all of the time, but the same recruiters are in such a demand that they too are scarce, which means their fees have never been here.

[00:53:17] In house tech recruiter, salaries are up about 30% organizations looking for help in cloud and cybersecurity positions have increased fees. They're offering two recruiting services to as high as 45% of the first year salary. Isn't that something that's a Robert half. I should have them on the show. They have been on a few times in the past, this particular lady who left her job, where she was always being courted and started freelance recruiting before the lockdown back in 2018.

[00:53:55] But there are big challenges are frankly going beyond finding just regular humans. The New York times says is that people are talking to potential hires. The recruiters have a big picture view of just how quickly the market is moving. And they've got to course take that and translate it into something that hiring managers would understand.

[00:54:17] And that's a fine line. Between, Hey, I'm trying to help you out here. You really should pay attention. And this is a hard sell right solely. It's a really interesting line. And we're also finding that of course of the candidates themselves are getting a lot of money. Salaries are way. Pop and for a good reason, people are in demand, especially if you have the skills.

[00:54:44] And so many people just don't want to work anymore. I have a couple of ways. I've looked at this over the years. I have what I call the McDonald's test. I don't think I've been to McDonald's in more than a year and I was on a road trip at the time, but it's how good is the service at McDonald's?

[00:55:02] Because if typically the service at whatever retail store you go to is pretty good. It usually means, wow. People are looking for jobs and it's hard to find a job. So you've got basically overqualified people working there on the other end. People who are working in the customer service retail space, which unfortunately, that's your face? That's your company. The people that answer the phone or the talk to your customers, those are the people who are out front. So in dealing with those people, w are they the best or the worst? If there are a lot of open positions while typically, and I hate to say this, but typically they're not your best employees.

[00:55:49] So that's kinda my McDonald's test. Did I get great service at McDonald's or Wendy's or burger king or at the mall? Or did I not get great service? And right now, We're not getting great service, any of those sorts of places. It's actually been more than a little frustrating. And sometimes even at the local coffee shop, it's been a little frustrating.

[00:56:10] The other thing, this is surprised me. Th this was this week right now. I've never been a. Another words, just in other words I, it doesn't matter to me if someone's younger or older certainly you can get to a age where there's senility. The other obvious problems with mental function look at president Biden, frankly, and some of the issues he has at least from time to time.

[00:56:38] But other than that, I'd never have. So I was really surprised when I was reading an article that. And it was talking about your resume if you want to get hired. And I'm going to run through some tips here because I spent some time doing some more research on this. You guys know, I'm not a spring chicken.

[00:56:58] I'm not an old man. The brain's obviously functioning just fine. And that's a good thing. Probably will be well into my eighties. Hopefully nineties that's been the history in my family. I at you're 60 years old, even 70 years old, you still got a lot of good years left in you. So when I'm looking at this and saying, okay, I, what I do is what's called a fractional Cecil, fractional chief information security officer for businesses.

[00:57:28] So what I do is I go into a business part time because I limit myself to somewhere between three and four. Customers at a time. And I have a team behind me that helps with all of the paperwork, the documentation, for all the compliance and everything else. It's out there. And as I'm doing all of this stuff for the company I'm bringing them in compliance with the cybersecurity regulations and in a lot of industries, if you're not in compliant, you're in big trouble.

[00:58:00] Okay. Then that makes sense. I think to most people. So I was thinking, okay, how can I promote my fractured? Chief information, security officer stuff. I tied it up a little bit of my LinkedIn page. I really got to get some stuff together on my Craig Peterson page and mainstream page as well, which is my company.

[00:58:21] But I am, I've done what I've done. So I started doing a little research saying what sort of stuff should I have out there on LinkedIn or other places? And this is where I really got surprised. And this is where the aid just stuff comes. And that is. Everybody. And I did a whole bunch more research on this and everybody says if your older do not even put dates on the resume of when you did things, don't put anything on the resume.

[00:58:51] That's more than 10 or 15 years old. And if you've got experience from back then, like I do, I could go in and be a cobalt programmer today. I did a lot of COBOL goading back in the seventies. IBM assembler. I did a lot of that. I even did 65 0 2 assembler for those that might remember that chip.

[00:59:10] And I've done a lot of kernel work over the years. See is my language of choice and was for years as I maintained and developed code for the Unix kernels. So all of that. Out the window. And what you do is you put it under additional experience. And even if you're saying, Hey, listen I've been doing this.

[00:59:30] Like I've mentioned to you guys before that I have what, over 35 years of cybersecurity experience and it's legit, right? You guys know I've been helping to develop the internet since the early 1980s, like 81 is when I got going a little bit in 83 is when I was into it pretty much full time. But apparently that's unknown nowadays.

[00:59:55] So instead of saying, Hey, listen, I've got 40 years of actually I've got closer to 45. I started in 75. I think it was in networking. IBM, networking, the old RJE and stuff. That's a no. I should say 10 plus years of computer network experience, because apparently what's been happening is these machine learning tools that hiring managers are using our age just now businesses are using them because of this problem we just talked about here from the New York times, recruiters are even getting hard to find.

[01:00:37] And employees are some in some towns, some cities wages are up 10% in the it area, just in general, let alone cyber secure. So you've got to go through automated systems now, as opposed to a person that's always been tough dealing with HR because HR, they, they don't know the business. They certainly don't know the jobs.

[01:01:02] They just got some bullet points, outlines that they're working with. So w we'll talk about this more. When we get back, I'm going to go through some points here, Korn ferry, and others have a lot of good points. And as I said, we should probably try and get Robert half on at some point they're local here.

[01:01:19] So anyways, visit me online, sign up right now, Craig Peter sohn.com and stick around. Cause we've got a lot more to go.

[01:01:28] We talked a little bit about the jobs, what it looks like out there, what recruiters are doing. I'm going to review here now the resumes, really? What should you have on them? Particularly if you're a little. Older like me.

[01:01:44] New York times. Great article about this. And I am also going to show you this other little article from wired here. We're going to go full screen for those of you watching here online, but the tech companies are really getting desperate. This is a chief economist over Dorsha. Published in a report saying the people are resigning at the highest rates since 2009.

[01:02:14] Huge numbers are leaving the labor market entirely and more than 80% do not want a job. The highest on record since 1993. That's absolutely amazing looking at these numbers. So this whole great resignation as it's called has really widened the gap. Let me make these, this text a little bigger for you guys.

[01:02:39] And there have been some huge gaping holes. In the workforce out there. S I T in general is really looking for people big time, cybersecurity, also looking for people. And I'm in the process right now of hiring a couple more. And let me tell you, it's more difficult than it's ever been before. In it alone.

[01:03:05] This, again, this is according to wired. 31% of workers actively sought out a new job between July and September last year. That's the highest amongst all industries, according to Gartner guys that make all this, these studies that they sell to businesses, data from global. Knowledge found 76% of global.

[01:03:27] It decision-makers are dealing with critical skills gaps on their teams, multiply the problem across other tech roles. And it's clear that there's a massive skills shortage and it's just amazing. They have. Sign on bonuses on top of sign-on bonuses, they're trying to move. Hey, we've got better snacks.

[01:03:49] And Facebook does out there in the bay area of California. They're having people working from home now. It's Hey, if you want to work from home, you can. Most people are w one of my sons just got a job. He. Performing kind of a CSO function. Like I do. He's worked with me for more than 10 years and that he is just working from home.

[01:04:14] He's never actually stepped foot in the office and he has been doing everything virtual, including the whole interview in process. Absolutely amazing. So they're calling this stuff a golden. Hello. In the business already saying, Hey, I didn't get one of those. Yeah. Cause you've been working there for five years, but everyone internally recognizes it's an unusual situation.

[01:04:40] And for us to continue to grow, we need to be. Competitive there's sign-on bonuses and they found those have not been effective in the it world because candidates are looking to maximize the opportunity to get much higher salaries elsewhere. Now, I did a proposal. I'm working with a company right now, and I did a proposal for them to provide some of these fractional chief information security officers.

[01:05:08] Function. I'm helping to define where they need to go, how they need to get there. I'm doing all the documentation on everything I'm working on, the HR policies everything, including securing the networks, helping them get the hardware, running it, renting them stuff right off the bat so that they can secure themselves very quickly.

[01:05:27] Whole bunch of stuff that I'm doing for. And it, frankly, I think it makes a lot of sense, but how could they possibly hire somebody like me? How could they hire someone like my son? So I went online to glass door. You might know about that website, glassdoor.com. It lets you check out businesses. What jobs might they have open and look at reviews from an employee's standpoint of.

[01:05:57] Glassdoor is pretty good for that. And I looked at salaries right now. Somebody like me, that is a CSO makes between 250 and $900,000 a year, depending on the size of the county. Now that's real money. Last time I checked, even with the inflation that we're looking at right now, I don't know. Maybe I won't keep up with it.

[01:06:23] I saw some inflation numbers. Of course, they move these out of the consumer price index because it would make it look bad. But some of these inflation numbers are over 20%. It's just not. So thank a salary, 250,000 to just shy of $900,000 a year. Salary. Plus load, which you have to add normally what about 30%?

[01:06:48] And then plus all of the equipment, plus the CSO needs a team, everything else. This is a huge problem. And they need to be hiring people to fill those jobs they use. These are just amazing. Permanent remote positions in the us doubled from 9%, 18% during the last quarter of 2021 doubled in the last quarter of last year ladders.

[01:07:18] And. All on jobs. This is according to the ladders. Okay. And it could increase to 25% by 2020 since making the transition to remote. First, we have been able to broaden our hiring options globally and not be restricted to a talent pool in one area. Now that's an interesting thing too, and that presents some interesting problems.

[01:07:42] It's one thing to manage people who are out of the. Upbringing as you are that have the same standards that you are and hiring somebody from somewhere else in the world, they're going to have different expectations. And boy, have I found that by hiring teams in India, Russia, and the Philippines, as well as the us.

[01:08:08] Big differences. So you gotta be, you gotta be careful with all that. Okay. So I promised I would get here into resumes for people like us, right? This is not what they say. And this is particularly interesting to me because again, I'm still working and I do it on a contract basis, obviously. I provide these services.

[01:08:29] This is something I think that applies to me too. So I'm pulling up a page. You can see on the screen, this is from the muse.com and it's called smart moves, age proof resumes for older workers. Okay. And they have four of them set up and they've got a nice picture of a lady. Looks like she's working from home with age, comes, wisdom and experience.

[01:08:51] That's why I was shocked. When I saw what was going hot and right. Where they were going ahead and saying, don't put anything on your resume. That makes it look like you're older. Okay. The quote here is age-ism is an unfortunate and very real part of the job search for older workers. And for some, it can start to creep into their experience as early as their forties.

[01:09:17] Isn't that incredible? Absolutely incredible. It's, I kinda dealt with this way back when, in the eighties, because I was younger then obviously than I am now. And there's this impression, at least there was, and it seems just still be around. But somehow if you're working with newer technologies, you need young people to do.

[01:09:40] That is not true. As I've said a million times, there's only a few ways that you can code something. So if you're a programmer and you want to solve a problem, there's really only a few ways to do it. In fact, there's books published with algorithms. That's the. Programmed stuff, right? The core of the programming that show you how to do things.

[01:10:04] So w we'll be back in just a minute, take a minute. Visit me online. Craig peterson.com. I love to see you there. And when we get back, we're going to finish this discussion, but it's an important one for employers as well as employees here, because I think many businesses are making a huge mistake. Craig peterson.com.

[01:10:32] We just talked some more about hiring. Age-ism the problems that come with that for both the employer and the employee. And we're going to get now more into this from the muse. We're going to talk about the four things you should be doing with your resume.

[01:10:48] There's there's a lot to be said for having experience. I mentioned about how businesses who are hiring programmers should really rethink the idea of hiring the young guy that knows the latest programming languages.

[01:11:07] Because again, There are so many things that you need to know besides how do you code this line? It's what Google did for many years. It probably still does. They don't want you to necessarily write a program in go, which is Google's latest, cool language, but they want you to solve a problem. They want to see your problem solving skills.

[01:11:32] How are you going to do it? Nobody has more skills than someone that's been doing that for decades. Again, there's only so many ways to program something. I don't care what language you're using. We used to have a saying, you can write COBOL in any language, but it's true. That's all we used to say.

[01:11:53] So when it comes to it in general, the older the person is the more experience they have in the field. The better off they're going to be with your company. Because again, there's only so many ways to break into a computer. Yeah. There's the latest, greatest virus out there, but managing people, managing expectations, working with senior staff, doing presentations for investors.

[01:12:23] That's the sort of thing that takes experience. How do you get that experience? There's only one way and that's to get the experience. It takes time learning a new programming language for a programmer, not a big deal at all. Again, there's only so many ways to do something and a programmer like me.

[01:12:41] That's done a lot written hundreds of thousands of lines of code, and at least a dozen computer languages. Pick it up. A new language is easy. I picked up Python and was able to be programming in it. Using API APIs online, all of the newest ways of programming and interfacing with other backend systems.

[01:13:03] I was able to write something that was putting together a whole bunch of cybersecurity stuff from scratch in the matter of a couple of hours on a language I'd never used before. Okay. How do you deal with that? It's the question of the hour, right? So let's have a look at this article here from the muse.

[01:13:24] They've got some suggestions for us. No. If you've been in the work case for workplace, excuse me, for decades, you've got a lot of experience, but putting it all down can be a real liability. I remember I used to have a a dossier. I had a resume, which was like a one pager. Then I had a dossier. The one on for 30 plus pages of all the things I had done.

[01:13:51] I wrote some of the very first I designed and implemented and used for a customer, some of the very first firewalls ever made routers, load sharing. But do I want to put that all on the resume? Probably not, but I understand that technology extremely well. So the resumes don't have to be a single page, but it's saying, remember it doesn't have to be a memoir.

[01:14:19] It doesn't have to be like my dossier going through everything to prove your worth. And what they're saying here specifically. This is a Gary Sussman. It's just a marketing tool whose sole purpose is to land you an interview. It doesn't have to be exhaustive and comprehensive just has to show that you can solve the problem.

[01:14:40] The hiring manager is hiring someone to solve and the beauty right now, again, if you're in the it, if you're in cybersecurity is they need. People. So it's going to be easier to get through. And if you are an older person who has learned a bit about cyber security, maybe taken an online course or two, that you have a much better job or a chance of getting hired for job than you probably have ever had.

[01:15:06] Okay. It goes on and on employers are most interested in how your recent work ties back to the job that you're applying for rather than your experience 15 years ago. Okay. That makes sense. So dedicate more resume space to detailing the positions you've held over the past to 10 to 15 years that are related to the job.

[01:15:30] Number two, do not date yourself. No. I mentioned earlier in the show that most businesses now are using some form of machine learning call it artificial intelligence, whatever you might want to call it, but they are doing the initial cuts. So they're looking for buzzwords that's for sure. Okay. And.

[01:15:53] What they're also looking for is saying, okay this guy's got more than 10 years experience. Who's got 35 years of 40, 45 years of experience in this, so do we want to hire them or are they just burned out? They don't want to do it anymore. What we're finding is the younger kids are definitely get burned down older people, not so much.

[01:16:15] We do what we love. No matter your age here. So Sussman explains that when he included, as number of years of experience, hiring managers told him he was too qualified, which he interpreted to mean they couldn't afford to pay someone his age, what his skills and experience were worth. He had better luck when he focused on more reason to experience and made his age less obvious.

[01:16:40] And if you've heard any professional certifications don't list, the year the certificate was earned. But do provide the expiration date on those certificates. Okay. A while, including a role you held or diploma you earned two decades ago are obvious signs. You're an older worker, there's other subtle clues, older professionals as sometimes.

[01:17:01] As lacking technology savvy. Do you guys think that I lack technology savvy, right? No. When the FBI InfraGuard program needed someone who knew technology could run technology and run their training programs, who did they turn to the FBI InfraGuard program? MI. Okay. So these sorts of assumptions, many people are making are dead wrong.

[01:17:29] I made no, I made sure there's no indication my agent, my resume, no mention my graduation year, no old school email addresses. If you have AOL Yahoo hot. Ditch it open and GML account. Once you've gotten that new email address added to the top of your resume, along with your mobile phone number and the URL to your LinkedIn profile, that's how they're hiring nowadays.

[01:17:52] You don't really need to put your physical address in any more, but you could put in your city and state. But remember, after the lockdown, a lot of people are working remotely and a lot of people have taken jobs and have never. Even gone to the office. And I used, my son is at example earlier he recommends removing all mention of outdated or standard software knowledge.

[01:18:15] This is an interesting point and a potential problem. I mentioned earlier. That I did a lot of cobalt programming back in the day. A lot for banks, market research companies and others. We were sown to COBOL. We wrote an assembler in COBOL. Okay. If you know what that means, that's the opposite of what you normally would do.

[01:18:38] Okay. Here's the issue I want to bring up. There are still COBOL applications out there, and it is very hard to find somebody that wants to write in one of these older programming languages or maintain some of these older programming languages. Okay. So that's the catch 22. Lean into your resume gaps.

[01:19:02] It says where as some older workers have to overcome the perception that they have too much experience, others need to explain a gap in your resume. If you stepped out of the workforce to raise children, to care for parents, or have been unemployed due to layoff. You might be wondering how do you handle it?

[01:19:20] Hiring managers are familiar with resume gaps, so it's not necessarily a cause. So what he's saying here is put volunteer experience in to the gaps. So you were helping somebody out, maybe you worked in a family business. There's things like that are not negatives. Highlight your achievements.

[01:19:42] This is the main thing here. Okay. I've seen this again and again. Older workers might feel intimidated about the job search process, but you've got a credible ACE in the hole that you can confidently present database examples of how you've delivered the delivered impressive benefits and solutions for your employers over the span of your career.

[01:20:06] This is true. Everybody. I don't care if you are 20 years old entering the labor market, or if you are 80 years old, still in the labor market, letting them know your success as what you've done. So for instance, for me as a fraction, Chief information security officer. I can talk about all of the companies that I've done incredible work for and what it's meant to them.

[01:20:36] In some cases, I have saved them from the brink of bankruptcy because of money stolen from operating accounts and because of ransomware and other types of malware, intellectual property theft, just on an. So he gives an example here, I think is pretty good. He says, instead of saying responsible for marketing materials and event promotion say created marketing materials and promoted events through social media, boosting attendance by 80%, over six month period.

[01:21:11] So you see what he's doing. Instead of responsible for keeping records to track contractor costs say developed and implemented a new record keeping system saving the company $12,000 per year in contract costs. You might include summary statements. I've always done that at the top of the resumes to outline what it is.

[01:21:33] I do what I can do for them. This whole thing. It's easy to feel overwhelmed. It's a little disconcerting when you're trying to do a job search. I know that just watching some of my kids just get, looked over. I have another one that's pretty high up in a business and she's been. Overlooked she's applied for jobs and came down to the last two people.

[01:22:01] She was one of the people, and I think the last three times she was overlooked. So you gotta be careful of that. And also because there's so much money out there right now, for people that are hiring work hard to keep the employees you have. That's it for today. Make sure you visit me online. Craig Peter sohn.com.

[01:22:23] If you have any questions, I'm more than glad to answer them. I get emails every day. Me, Me@craigpeterson.com and I'd be glad to help fill in the gaps. Take care everybody. Bye-bye.

View Details

Conservative/libertarian host Craig Peterson is heard throughout New England every week giving his opinion on Cybersecurity, new Technologies, and Government involvement.

This week, Craig talks about the latest announcement from the Feds: "Shields Up!" They're warning about Cyber attacks against the US. Coming from Russia, they expect untold carnage. But how likely is it?

Also this week: Senators trying to spy on all our digital information (including a RINO Republican). The "Right to Repair" backfires. Six reasons Meta/Facebook is failing. The top Cyber problems in 2021. More malware attacking Apple Mac computers. The five things businesses need to do for Cyber Security right now.

We've got a big alert from this CISA. That's our cybersecurity and infrastructure agency to come down about a week or so ago. It's been going up and down and of course the tensions out there are causing problems. So let's talk about it.

[The following is an automated transcript.]

[00:00:17] CISA is an agency of the federal government. And it's one that I follow frankly, pretty closely, because they are the ones that are supposed to be helping us in industry, as well as helping the federal government keep their security stuff in order now, are they well, yeah, they are. They are, but the bottom line is they've got a whole bunch of rules.

[00:00:44] Cool new things. And I'm going to show that to you here. This is called shields up over at CISA. For those of you who are watching online, you'll be able to see it right here. So let me just switch over. You've got it up now. Let me just go full screen on that so you can see the whole thing, but this is see.

[00:01:06] C I S A.gov and they have a whole ton of cybersecurity resources there. One of the things I hear the most from people is just how freaking difficult it is to try and keep track of things, even understand the regulations, let alone learn all of this stuff, but you can see on their site that.

[00:01:28] Training and exercises summit, that's coming up, combating cyber crime, and many other things. So what we're concerned about right now is. But this whole thing with Russia. Now you've heard about Russia or a lot, of course we've caught the germ report talking about Russian fake collusion, frankly. And we have Russians who have been hacking us.

[00:01:53] In fact, I've got an article on that today. Let me pull that up as well. You'll be able to see it. It is an incredible thing when you get right down to it. What Russia has been trying to do is attack and steal things directly from our agencies, right? The DOD as well. If you are a contractor, You are in a great deal of trouble.

[00:02:18] I don't have that article handy, but they are going after all of our friends at the DOD and all of their contractors and subcontractors. So what happened? There was technology that was supposed to believe be implemented at all of the contractors that of course did not get implemented. So that's a problem if you ask me, but it's now changed.

[00:02:43] Okay. 2022, what has happened? 20, 20, 22, they decided that the regulations that were in place were not tough enough. Not even close to being tough enough. So what. Is they added teeth, incredible teeth to these what are called CMMC regulations, which are the regulations that are about the cyber security maturity, if you will, of these DOD contractors.

[00:03:12] So now we're looking at this article, I'll pull it up on my screen again here that this has particular ones from security Boulevard, but it is warning about the risk of the Russians really hacking us. Now that's nothing new. We've known about that for a long time. We've known that the Russians and the Chinese are both trying to get in.

[00:03:34] I have customers who I picked up after they'd been hacked. And in fact, in most cases they didn't even know they'd been hacked was just something weird that was going on. So this alerts highlighting several cybersecurity vulnerabilities that these nation states and cybercriminals are likely to be leveraging.

[00:03:56] And they've outlined certain steps that organizations can take to reduce the risk. So what are those steps? I'm going to bring them up right now for those of you who are watching, but I may make it a little. How do you do this while they're saying let's break it down. We want you to reduce the likelihood of a damaging cyber intrusion.

[00:04:19] Again, sisa.gov. If you want to follow along at home, cis.gov, validate that all remote access to the organization's network and privileged or administrative access. Requires multi-factor authentication. We're setting that up for a company right now. In fact, ensure that software is up-to-date prioritizing updates, that address known exploited vulnerabilities identified by CISA.

[00:04:44] So you see that link that's right there. That brings us to this massive. Database, if you will of known vulnerabilities just 38 pages, 377 known vulnerabilities. So how does this work? When you get right down to it, you can look at the CVS. CVS over here on the left. If you cook on one of the CVS.

[00:05:07] It gives you some really good information, including some information about how to fix it, how to patch it and what the severity is. So what you want are those that are being actively exploded in the wild, basically 10 or a nine. There is a scale of zero to 10. Probably not even zero, but that's where the scale is.

[00:05:31] You notice here, by the way I add Dole bay is their top one. They are terrible when it comes to a lot of their software. So you can start. By whatever you might want to sort it by when it was added the action and the due date, which is for again, federal government people and federal government contractors and there's notes there as well.

[00:05:55] So this is something, if you are responsible for the cybersecurity in your business, you might be the office manager. That's so common in small companies and as the office manager, you are supposed to be. In charge of the computers. I can tell you with a great deal of assurance that most of the companies that are providing computers service are not providing these types of updates in a timely manner.

[00:06:25] Why because it's difficult to do so you have to do it. You have to track it. Okay. So shields up, let's go right back to that. They're talking about the other things that you should do. If you're using cloud services, this is just incredible because there's more. To do Microsoft. I had to put this in a proposal this week because the company didn't realize you're using all of this Microsoft 365 thing.

[00:06:53] You've probably heard about that. They've got email, they've got SharePoint, they've got all these other wonderful services and it's nice in an expensive to use, but here's your. The problem is that these particular services don't provide you with backups. It's not a guarantee, data, integrity, any data loss is your problem.

[00:07:15] And Microsoft has been sued on this unsuccessfully so far I might add. So just because it's in the cloud, not only does it mean it's not safe, it is just another word for someone else's computer and it can be completely. Unsafe. So you gotta watch it. You gotta be careful. So CSUs warning about that.

[00:07:35] They've got this free hygiene service. Now I applied for this. I'm going to pull this up again on my screen here for those who are watching live. But. The hygiene services. Very interesting because they say, Hey, listen, we'll go ahead and do it. And these CSUs cyber security assessment services are available at no cost, so who can receive them.

[00:07:58] Now, remember, I'm involved with the infra guard program. I put together their training for two years, I established that whole program training thousands of government and business sector people on cybersecurity. So you'd think they would respond to me. This is a huge program. There are people have probably even been on my webinars that I've held.

[00:08:23] They didn't get back. They say, okay, you can receive these free services while federal state, local tribal territorial, government, public, and private sector, critical infrastructure organizations will that to me, my clients, every last one of my clients is in a critical infrastructure service.

[00:08:43] Now it can be a dentist office. That's pretty critical. Just ask someone, who's got an infection. It, I have other people who are in the DOD. Base or providing materials and also products, manufactured products to government contractors, et cetera. So did these people get ahold of me return my email? No, nothing.

[00:09:07] So you can have look at this if you want to. But I got to tell you, it really turned me off from some of these CSUN people. So anyways, you can sign up, but you can't get it right. Take steps to quickly detect a potential intrusion. There's a lot of subsets here. You can see on my screen, or you can just go to sisa.gov/shields-up.

[00:09:29] I'll try and put a link to this in my newsletter this week ensure the organization is prepared to respond. If an intrusion occurs, that's a very big. As well, you have to have people, you have to have drills. You have to know what's happening when to do it. This is everybody right? This is HR. This is your public relations people.

[00:09:47] This is your it people. This is everybody all the way through the business. They've all got to be involved in this maximize the organization's resilience to destructive cyber incident. What is the. What has been happening lately? Coming out of Russia, isn't just ransomware it's they destroy your data.

[00:10:07] A very bad thing. If he asked me, and if he asked a lot of other companies out there, so you got to understand this, you got to be careful with this. Make sure you are following this rather closely, frankly, and this type of alert it's there. It's going to be there for a long time. No question about it.

[00:10:25] Shields. I liked that. I think it's neat. Obviously we got some star Trek fans in the work, so I don't know, just star wars have the, they have shields, but I don't remember them saying chills up. That was a card thing. Wasn't it? So there you go. Every organization is at risk. This is a big worry.

[00:10:42] It comes and goes. It's like. Orange and green and yellow or whatever those colors were over on the other side, right from our friends at Homeland security.

[00:10:53] We've been legitimately concerned for years about the government, watching what we're doing, listening into what we are saying while there's ways that they've been monitoring us for a very long time. And the senators now want even more.

[00:11:09] Senators, right? What are you going to do about them?

[00:11:12] It is back. I'm going to put this up on the screen for those watching live, but people don't want outsiders reading their private messages, not physical mail, right? Not texts, not DMS. Great little article here from the electronic frontier foundation. These guys are just amazing. I have agreed with most of what they've done and.

[00:11:35] Some of what they've done, but basically what they're saying is we have a right to privacy and it is enshrined in the U S constitution. It's something we're supposed to be paying attention to. Isn't it. And what we're supposed to be secure in includes our papers done. Which papers are we talking about here?

[00:11:58] I've got some paper here. This is an index card, right? I've got some paper here. There's some notes on it. So I'm supposed to be secure in this. So I guess that means that the file cabinet over there is a secure, right? We don't have to worry about the government breaking into my file cabinet.

[00:12:14] How about these things? How about our smart devices, our smartphones? How about our computers, our laptops, et cetera, always supposed to be secure in those, the constitution doesn't mention those things. It's funny how some people look at the second amendment to say, oh, it only covers a blunder buses, it just, It doesn't cover any modern weapons. And yet at the same time, they'll argue the exact opposite way when it comes to being secure in our papers, because we are supposed to be secure with all of our communications. Senator Richard Blumenthal and Lindsey Graham. One's a rhino and one's a dyno, right?

[00:12:54] Richard Blumenthal, a Democrat from Connecticut and Senator Lindsey Graham Republican from South Carolina have re-introduced what they're, what's called the Ernie act, earn it act and incredibly unpopular bill from 2020. Now it had a lot of opposition, which I think is fantastic, frankly. And it whole thing got through.

[00:13:19] But what the eff is concerned about is that in fact, this could end up being a massive new surveillance. It would be run by private companies. You saw what happened with the filings in Washington, DC from the germ investigation, right? Private companies were being used by the Democrats to spy on the sitting president of the United States.

[00:13:46] Incredible way. So Ernie. I have a surveillance system run by private companies would roll back some of the most important privacy and security features in technology that are used by people around the globe. So it's things like using signal, which is generally thought to be the best end to end private communications app out there, signal WhatsApp, which is questionable because it's owned by Facebook.

[00:14:13] But they say it's end to end encrypted, just, be careful about those things. I message on apple is end to end encrypted, but apple does respond to subpoenas and provides information, which again is supposed to be able to do. But should the government be able to go to third parties to get into your private papers?

[00:14:35] That's a completely separate thing, but the earnings act could ensure that hosts. Anything online, we're talking about backups, websites, cloud photos, your voice messages, all kinds of stuff is captured and scan. This is really scary. Now I'm going to put this back up on the screen because it's also talking about how this bill empowers the states and territories to put their own sweeping internet regulations into place and they strip away.

[00:15:14] The critical legal protections for websites, apps, things like social media. That's the whole thing. Section two 30 was about when we talked about two 30 on my Shelby. And two 30 is double-edged you got social media sites saying while section two 30, lots of us limit what people can say on our platform.

[00:15:38] I would tend to think that it actually says the opposite that they're not being held. They can't be held liable for what a third party says on their platform. So it's definitely not the same. And in fact, since they can't be held liable for what set on Facebook or Twitter, et cetera, they should not be censoring it because if they started censoring it now, all of a sudden aren't they a publisher they've got editorial.

[00:16:08] So liability comes into play here. Yeah. They don't want that, but that's what section two 30 is all about. And there's been a lot of debate about that over the last five or 10 years. And there's arguments on the far left and the far right. End in the centers to why it should go away and why it should stay.

[00:16:27] All right. So I tend to be on the, I think it should stay side. I don't like what some of these companies are doing by censoring speech, particularly, libertarian or conservative speech, they sensor like crazy. But the bottom line is if the, they didn't have that, then how about the good sites that are out there?

[00:16:48] The rumbles of the world, et cetera, that are trying to get a good message out to everybody. And are protected by section two 30. If 2 31 away a company like Facebook that has billions of dollars. Would remain the only major social media site, because nobody else could go in. They'd all be sued out of existence and they could not conform to all of these government regulations.

[00:17:14] That's part of the reason big companies love big government. It makes it so they don't have big competition. Absolutely amazing. The, so this document here. Earn it, bill is saying. And another document that came out from the bill sponsors. Amazon is not scanning enough of its content. Now, Amazon is the host of Amazon web services and I've used them before.

[00:17:42] I still use some of their services. For instance, for transcribing this show, I wrote some code that uses API APIs that go into Amazon and upload it and download transcripts and then reformat it for me. So I use some of those, but Amazon. Has the lion share of what's called the cloud data services.

[00:18:07] So they're storing a lot of data for people. Long-term data in a glacier, for instance, and short-term data and ask three. But they're complaining a huge number of websites are hosted there. And this Bill's aim is to ensure that anything hosted online gets scanned and the bill creates this is just, you couldn't make this up a 19 person, federal commission dominated by law enforcement agencies, which are late.

[00:18:36] Best practices for attacking the problem of online child abuse. It's for the children, everybody, regardless of whether state legislatures take their lead from that commission or the bill sponsors themselves, we know where the road will end says CFF. Absolutely. True government approved software, like photo DNA.

[00:18:59] I don't know if you've heard about what happened with photos and with Metta Facebook, but they just lost a huge lawsuit where they were sued by a few different states about you remember the, it would automatically tag people in photos. So it was doing photo recognition, the photo DNA thing. And they got sued because.

[00:19:23] Obeying the law. Yeah. Talk about that one for an hour as well. So earn it. Not something you want, but apparently these senators wanted as well.

[00:19:36] We've got a problem with our cars nowadays. Have you tried to turn a wrench on one of these things? They're all computerized. I don't mean a computer. Some of the cars nowadays have dozens of computers in them. How about repairing them? We're going to talk about right to repair.

[00:19:53] A great article in ARS Technica that you'll find, and this is about the flight.

[00:20:00] For the right to repair. Now, there have been a few right to repair bills that have been released over the years. And the idea behind this is well, having a big fancy car is wonderful. You can drive it all over. But how about when it's time to get that car repaired? What are you going to do? How are you going to do it right?

[00:20:26] Does that make sense to you? It can be a real problem. And this article is fascinating because it talks about this chief Morelli who had a Subaru SUV. Now she bought this in 2018. A lot of people buy Subarus because that engine is incredible. There's nothing like a boxer engine. That's where I'm on. My motorcycle has, and I have 160 something thousand miles on my motorcycle.

[00:20:53] These super engines last, no, the electronics, the motors, the electric motors. I had different story. Are there problems with Subaru's? But it made her feel safe. So off she goes, right? Like Volvos. People buy those for perceived safety as well. I have some issues with those, but her husband mark decided to purchase his own car last summer.

[00:21:18] So they went to the Subaru dealer near their home in south east, Massachusetts. Now here's the catch to all of this Massachusetts passed a right to repair ballot measure that was approved overwhelmingly in 2020. So what that means is that all of the vehicle manufacturers have to use a standard.

[00:21:47] Computer interface in order to do anything on the car, the idea being that you can take it to a regular mechanic that can read from that wonderful little port under your dashboard can maybe do a little bit of reprogramming of the car and not have something different that they have to buy. Like for almost every car.

[00:22:10] I know I have. Oh, for quite a few years, I'll a Honda dealer as a customer of mine on the cybersecurity and computer side. And I ended up having to have help Honda's headquarters in Japan, fix major problems that they had with this little computer device that they were using to fix the car. So they're there.

[00:22:37] They are trying to fix them and the device just isn't working and the device has to be constantly upgraded because there's bugs in their software and there's new features in the cars. So it has to be upgraded and updated and everything. So the idea behind right to repair is we can't have everybody out there constantly trying to upgrade their hardware in order to talk to the car.

[00:23:04] And they shouldn't have to buy multiple pieces of hardware for a single family of cars, let alone multiple pieces of hardware to cover all cars. So Massachusetts voters did the right thing, right? Cause they said. We want the right to repair our cars. You can't keep us out of them anymore. So that's when she and mark, I had a bit of a surprise.

[00:23:30] Because they went and bought a Subaru in mass, another one. And then they found out that the Subaru telematics system and the app that went along with it, and that includes remote engine start, it gets cold up here. New England, no emergency assistant, no automated messages. Tire pressure was low oil needed, changing.

[00:23:56] What's available now, if they had remembered they were living in Southern mass Southeastern mass, but they could have gone just over to Rhode Island or up to New Hampshire. And Bob that same car and would have had all of those features. You see what happened is Subaru said we cannot support this right to repair because that means we have to have a, basically a different car format.

[00:24:28] Now this isn't the first time we've seen this type of problem before California and Massachusetts have both had crazy. If you will laws on the books for a long time defining, oh wow. You can't have diesel. Cause it has this too many particulate matter pieces of matter in it. And it has to have this kind of mileage overriding federal regulations by.

[00:24:50] So let's not the first time now. I'm in New Hampshire, live for your die is our state motto. And all of the states around us, have we effectively banned diesel vehicles, New Hampshire hasn't we could get into this. But basically a diesel vehicle is every bit as clean and non-polluting as an electric car.

[00:25:13] In fact, it's less polluting when you consider the lifetime of the vehicle and the manufacturing of the cars. Okay. With the batteries and everything else. They were pretty upset about it. And this article of ARS Technica talks about this a little bit more. It says Subaru disabled, the telematic system, and the associated features on new cars registered in mass last year as part of a spat over a right to repair ballot measure.

[00:25:42] As I mentioned before, this open data platform that they're talking about here in the LA. It doesn't even exist yet. We've talked about laws before and how really the laws either a few steps behind technology or they try and get in front of technology and just mess it up. Like they have with nuclear power, right?

[00:26:06] The new nuclear, the fourth generation is just amazing stuff. And yet they really messed up. It says that it doesn't exist in automakers have filed suit to prevent the initiative from taking effect. So first Subaru and then Kia turned off telematic systems on their newest cars in mass, which has really gotten some people upset.

[00:26:26] And here's the quote from them. This was not to comply with the law compliance with the law. This time is impossible, but rather to avoid. Violating it now. Isn't that interesting because again, companies and people have to do things to avoid violating. Okay. I'm going to say it stupid laws. So interesting staff.

[00:26:49] This is just the latest dispute in this whole thing about the right to repair. What should you be able to do with your car? What shouldn't you now? I've got some really bad news if you're a right to repair advocate because. All of the newer cars that are coming up, particularly these electric cars that they love so much in Massachusetts, these electric cars are going to be sold as a base model.

[00:27:19] And then what's going to happen is you pay monthly. In order to have certain features turned on you. If you follow Tesla, Tesla has done this thing where it's okay. Six grand and you can get the auto drive. And the course they still don't have the fully autonomous driving. And then they raised it to eight grand.

[00:27:42] I think it's 10 grand now, or maybe even $12,000 for it. And they decide, okay let's step into that and we're going to change it. And some of these companies, I think it was, I'm not going to mention the name because I'm not absolutely positive, but some of these car companies have decided, oh, you, you know that remote start that you paid extra for them and you got your car.

[00:28:02] Unless you pay us $8 a month, you're not going to get the remote start. So think about that for a few minutes. Your car's going to have the ability to drive autonomously. It's going to have the ability to do all kinds of wonderful things, but you won't be able to use them. Unless you pay your monthly fees.

[00:28:22] Talk about right to repair. All right. Hey, I have a weekly newsletter and that newsletter has a little bits of training for everybody business or otherwise, but you have to sign up, go right now to Craig peterson.com.

[00:28:40] About Metta and that Metta has been busy making changes because Metta is really Facebook. And if you've been paying attention, the medicine. Huge stock drop.

[00:28:55] Metta oh my word. I, where to even begin? Mark Zuckerberg and company have known for a while that their company is going to be in trouble.

[00:29:08] Metta is the parent company. Of Facebook just like alphabet, right? The parent company of Google. So it's almost like a reverse merger, or they move them around. So Metta is now the company that owns Facebook as well as other properties. And what Facebook has been doing for years now.

[00:29:29] Over a decade is by. Potential competitors. If you have enough money in the bank, you can just go ahead and spend that money to buy competitors. Then you don't have to worry about competing with them. Look at the Insta. Look at WhatsApp. Look at many of these other things that Facebook has acquired over the years and what they're looking for of course, and always have been looking for is eyeballs.

[00:29:56] And they want to know what are those eyeballs really interesting. They've been doing a good job at that and have been really sucking a lot of data out of us. And I don't need to really say this, but Hey, listen, if you're not paying for it, you are the product. They suffered their biggest one day.

[00:30:18] Wipe out. Ever this year, this is an article from our friends at the New York times. So they're saying Mehta, the company formerly known as Facebook suffered its biggest one day. They called it a wipe out. I love that as that stock plummeted 26% and its market value plunged by more than $230 billion. So they had a really bad earnings report.

[00:30:51] They have been trying to transition from social networking towards what they're calling the virtual world of the metaverse. Now the metaverse has been a promise for a very long time. And you can think of it in a few different ways. One way is the, you have the goggles. I don't know if you've seen ready player one, a scifi movie where this kid is.

[00:31:18] Trying to solve this. Basically you're a riddle that was put in place by this guy, geeky guy that founded this company and they all played this video game against each other. And they had not only the goggles, but they had a whole suit, so they could feel what was going on. Ready player one. Very cool.

[00:31:40] So that's one idea of the metaverse, which is you don't have to live in the real world. You can just live in this virtual world and that's exactly what they did. So they reported some modest games and new users at over at Metta, which includes of course, Instagram messenger and WhatsApp, which are the core of their money.

[00:32:05] I lost about a half a million users over the fourth. How is that a quarter to quarter or half a million users? So that's the first time they've had a decline like that in the company's history. And frankly, Facebook was such a Darlene of the stock market because they were continually growing. It was like the perfect bet.

[00:32:31] There's no way you could lose money, investing it in Facebook. And yet, in fact, What did they do? They lost money. They lost a lot of the money. Now executives over at Facebook are saying, Hey, listen, we can grow this company more. We haven't even done anything with WhatsApp. The, the running that you might remember back in the day, WhatsApp used to charge a dollar a year.

[00:32:57] Now that doesn't sound like much, but when you have a hundred million members or more yeah, that's a fair amount of money to run a small company that has, I think it was like 50 employees at its peak here. So they're saying over at Facebook we could start inserting ads into WhatsApp.

[00:33:17] We could start monitoring communications. What. That's why I don't trust WhatsApp. There's a lot of things that we could, things we could do. We get generated a lot of revenue from WhatsApp users. They're also looking at weather metas, other top apps like Instagram might beginning getting to the top of their user growth.

[00:33:39] Now I've been talking with a couple of. That are in one of my mastermind groups. And they've been talking about how they've found their businesses have grown very well using. Instagram advertising and not just advertising, organic stuff where they post things and people find it on there, which I thought was kinda interesting because we're all pretty much in the business to business world and they really like it.

[00:34:06] So I'm going to try it out too. And if you've used Instagram, And the success been success with it for your business. I'd love to know. Just drop me an email Craig at Maine, or excuse me. me@craigpeterson.com. mainstream.net is my main business. Where I'm I do the CSO work the chief information security officer stuff.

[00:34:30] So apple introduced what they're calling. App tracking transparency. This is a pretty big deal. Put this up on my screens. You guys can see it, but apple made some changes to I O S and what it's doing is trying to wall off its safari browser from tracking software. The total. What does that mean, frankly, to somebody like Facebook?

[00:35:00] It's going to be very hard for marketers to be able to figure out who is doing what a win now to top that all off our friends at Google who also make money from us in our eyeballs, our friends at Google have said we're not going to use the pixels. Who used. And what Google is doing is incentive tracking you as an individual user.

[00:35:27] They're going to put you in a bucket with a whole bunch of similar users. So in other words, I'm not much of a change on Google's front, but enough of a change that it has made investors more than a little bit worried about what the future holds, because Apple's blocking their access people. You guys, right?

[00:35:49] How many of you guys attended those webinars? I did on how to disable tracking on your computer, on your browsers, et cetera. When you're going online, a lot of you guys did, so we don't want to be tracked. We don't want them to be tracking us. And again, how do they make their money? They make their money by tracking us.

[00:36:13] And that is precisely what they've been doing. No wonder that our friends at Metta had a terrible, no, get good, very bad week earlier this years. So Apple's limiting it. Google is stealing online advertising chair because remember Google has ads all over the place. They're on all kinds of platforms on.

[00:36:42] It's not just on the one Facebook site, for instance, for Facebook. So in Google's earning call the same week, Google reported record sales, particularly in e-commerce search advertising. No. Where you go to Google and you're searching for something that can be bought online. Yeah. That's particularly where they made money.

[00:37:04] Very same category that tripped up Mehta the last three months of 2020. So Google is not heavily dependent on apple for user data. You said it was like to do the Google had far more third-party data for measurement and for optimization purposes to Metis ad platform. All of this great information here in New York times article I've got it up on my screen so you can see it.

[00:37:28] Next one, ticked. They have been stealing young eyeballs, like crazy Tik TOK has been very popular. It is unfortunately owned by a Chinese company. And there has been a lot of talk lately about how tick talk, collects our data. And we don't actually know what they do with it, but we do. That it's in China and all of these businesses in China ties to what the people's liberation army, the Chinese communist party.

[00:38:02] They have more than a billion users on their site and the videos are addictive. Like one of my kids forwarded me one this morning. I was happy. I didn't have to download the Tik. Yeah. I was able to watch it on my web browser. It was actually quite funny, but it has been an amazing competitor for Meadows, Instagram, for eyeballs and attentions people, by the way, have also been a business friends.

[00:38:29] I know have been making some pretty good inroads using tick-tock advertising. So what does Mehta do? I can't buy, tick-tock not for sale, so they introduced something. They call real. And if you're on Instagram, you'll see reels ads been very prominent. R E L S. Yeah. It's currently the number one driver of engagement across the app.

[00:38:56] So reels is attracting users. It isn't making money as well as Instagram is stories in the main feed, make way more money for them and spending on the metaverse. According to the New York times popped up on my screen again. Is bonkers. So Zuckerberg is thinking that the Internet's next generation is this Metro versus this wonderful world of who knows what, that he's willing to spend big money on it. And I'm highlighting some this screen from New York times article because the spending a mounted apparently to more than $10 billion last year, and. Metta is going to spend even more than that in the future. And there's no evidence that it's really going to work, what's going to happen. Now we also have, of course, the specter of antitrust laws here in the us, various similar y'all laws in Canada. It's the anti combines act in Canada, but same thing in. They have already been sued. They're going to be sued again. So Metta is in meta trouble and we'll see what ends up happening with these guys.

[00:40:11] But this is really interesting because frankly. Even though Zuckerberg says they're not a monopoly, regulators are disagreeing. And I agree with the regulators for once. All right. Hey, visit me online. Sign up for that newsletter. Get all of those free little trainings every week and a whole lot more.

[00:40:31] Craig peterson.com.

[00:40:33] And data breaches are a very big problem. So what do we do about them? What are they? That's the first step, right? You got to know what you're protecting and you got to know what the attacks are. So we're going to talk about that. What has been the case in the last 12 months?

[00:40:50] The three most common causes of data breaches in 2021 were.

[00:40:58] This is according to dark reading number one, cyber attacks. And we're going to talk about those different types of cyber attacks. Number two, human errors and system errors. Those are very big ways to get attacked and get breached. And physical attacks was the third one. Now what do all of those things mean?

[00:41:19] And what are they doing? We know the Russians and the Chinese are trying to get our information. In both cases, it's espionage. In both cases, they want to see the information about our military, what the military is doing and how. Can really steal our secrets. Look at the newest fighter in the Chinese air force.

[00:41:44] That fighter looks a lot like our fighter. In fact, they beat us to the punch and making it. Here's what we can tell. Still got some things to work out, but they made it from our designs, which they stall that's the allegation. And certainly looking at the two planes. I think that's probably exactly what happened.

[00:42:07] That's what they're doing. So that's on one end of the scale, right? Way, way up there, where it's major industrial espionage, it's worth billions of dollars. And then there's you and me. So from the you and me standpoint, what are they looking to get? On one end, they just want to cause chaos and confusion.

[00:42:30] We know, for instance, during the 2020 election cycle, there were all. Of social media posts that were not legitimate. They weren't real, they were all fabricated. We know that they were trying to do it, particularly the Russians, just to confuse the issue entirely same thing in 2016, we can expect a lot more of that as elections go forward.

[00:42:56] So that's one thing, how can they do that effectively while they need a lot of computers? How do they get their hands on a lot of computers? Simple, they steal them. So what they want to do is get their hands on your computer, on my computer. And once they've got their hands on our computers, now they can use them in order to do posts online.

[00:43:21] So they it's going to look like it's in 1, 2, 3 main street, downtown USA, because of. They're using your computer to do these posts. Now, the other thing they'll use your computer for is to hack other people and other people's computers. So you've seen it for years. I remember. The Matthew Broderick movie war games, and they were trying to go through, remember back then it was dial up modems going through the network in order to hide where they were and to get around blocks that were in place.

[00:43:56] That sort of thing is continuing to happen today, where they can hop between the computers, but some businesses, for instance, have been hosting videos of just horrific things that are being shared by. Bad guys jihadists over in the middle east, the people all around the world, the using our computers as store and forward.

[00:44:19] The biggest thing right now is what's called fishing. Now fishing has a few different categories and if you're watching this, you can see right now, The eighth, the growth in fishing over the last three years. So in 2019, it was 928 cases. Again, this is reported right to 2020. It went down slightly.

[00:44:45] Yeah. The vid, and then 2021, it doubled to 1600. Isn't that amazing. It doubled. So there's fishing, there's smishing and there's email compromise that amounts to the biggest amount of hacking that's happening. So what does that mean? What is this big hacking that's going on? It's pretty simply put, we're talking about hackers who are trying to fool us into doing things.

[00:45:16] So you've heard about phishing attacks. I'm sure. Before. P H I S H I N G. And that's where a bad guy sends you an email. It looks like it's from some legitimate sores and it might be a bank. It might be the FBI, PayPal, you name it. So you open it up and when you open it up, what ends up happening? Wow. Click on the link inside there.

[00:45:39] There are bugs in various email programs. There haven't been over the years. We're just having that headline show up in the summary, caused your machine to be compromised. But nowadays, most of the time you have to in fact, click on something, doing that. So that's fishing. I just prepared a video for our clients.

[00:46:02] One of whom was having a real bad problem with phishing attacks, using specifics for their business, it's okay, now one of our vendors got hacked and they're using their email server, defend fish, send phishing emails that happens with. So I put together a training video for their people. Okay.

[00:46:23] Here's the vendor. Here's what these things look like. Here's how you report it. Here's what to do about it. The next one is Smith. This is effectively the same thing as fishing, but it's using SMS. It's using text messages to try and get you to do something. So again, it might be a link that sent to you in a text message, or it might be a message saying, call me, I get almost every day I'm asking.

[00:46:52] On WhatsApp. We use WhatsApp for one of my masterminds. I'm not a fan of WhatsApp, you know that, but that's what everybody else is using. It's not the worst thing in the world, but I get I would say at least weekly, maybe every twice a week, who knows, but I get a message saying is this Brian?

[00:47:10] Of course I'm not Brian, right? I'm Craig Peterson. So the normal response from somebody would be. No, this isn't Brian's number, but the problem is that now you have engaged with them. They know there's a real person, they start a conversation, they try and get a little bit of information about you, and then use that against you to get into bank accounts, to steal money, et cetera, which is the third.

[00:47:37] Fishing, which is called BEC, which is the business email compromise. This is absolutely huge. According to the FBI, there have been billions of dollars stolen using BEC I know one company that got really nailed and their operating account got emptied because of a business email compromise. So what is that?

[00:47:59] That's where you get an email. At your business email address and that email again, just like a regular phishing email looks legitimate. So you look at that email and it looks legitimate. You open it up. Okay. So far it's the same thing, but what they're trying to do with the business email compromise is get you to do something that's going to hurt the business.

[00:48:24] In these cases that I've been talking about, what happens is it looks like it's from the CEO or looks like it's from the CFO. We could talk about a lot of the different compromises that have happened. Probably one of the most famous is with Barbara Cochran. She of course, on shark tank and she had about $400,000 almost stolen from her because in the email was.

[00:48:51] To basically her bookkeeper accountant saying, Hey, we need to pay 400 grand. Here's the account number, because remember she's in real estate. So there, rehabs happened in all of the time and the assistant, I think caught it and they were able to stop the transaction, which is amazing because you only.

[00:49:10] Second is quite literally in order to stop those types of transactions. So she stopped it, but that's an example of a business, email compromise. There are fancier ones that happen to this is the problem with having your email addresses or names even on your website. So people can just go to the company website and say who's the CEO, who's the CFO who.

[00:49:37] This person who's that person. And so they go through all of that information and they've now got something they can use against you. So what do they do? They know who the CEO is, so they chum up to the CEO, Facebook or other social media, LinkedIn. Where'd they go to school and then they send us a note on, let's say LinkedIn or Facebook saying, Hey, I want to follow you.

[00:50:01] I want to talk whatever you don't remember me because you put on LinkedIn that you went to Harvard business school. So yeah, you remember me? We were in class together. This is Joanne. And we took econ 1 0 1 at Harvard. So now a conversation starts up, they get LinkedIn to you, they get your Facebook start following you and see, oh, they're going to be in The Bahamas this week.

[00:50:26] That means they're out of touch. So during that week, they go ahead and send an email to the CFOs saying, Hey, we've got this new vendor. And if we don't go ahead and pay this vendor, we're going to lose. Because we haven't paid them in three months. So the CFO then wires the money. Now you might think, oh, that's just too much work.

[00:50:45] First of all, a hundred thousand dollars will support families in Eastern Europe for about three to five years. Okay. Secondly, that particular tactic didn't just get them a hundred thousand dollars. It got them $45 million. Oh. And it wasn't them. It was a, her a single. That was able to do that. So business, email, compromise, you've got to watch it.

[00:51:11] And then of course, all of the normals, right? Ransomware, malware, a unsecured cloud environment, credential stuffing, et cetera, et cetera. All right. Hey, I want you guys to take a minute right now. Go to Craig peterson.com one cheer there. You'll see right at the top of the page, I'm going to pull this up here for those watching on video.

[00:51:34] Subscribe for email updates. You'll get my updates. You'll get my trainings as well. Craig peterson.com.

[00:51:41] I'm a Mac fan and being a Mac fan means that I like max and a lot of people like max, because they are typically safer than a windows computer, but now that they become so popular, Hey, they're a target, too.

[00:51:57] So here's your problem. As it might say, Macs are starting to see the heat. In this case, the heat they're seen is something called update agent. It has been around a while. And many people have downloaded it. And I've known about various types of Mac malware over the years. Some of them worse than others.

[00:52:22] The one in particular that I'm thinking of a friend of mine paid for this stuff that was supposed to keep his Mac clean. So first of all, If you're looking for some anti-malware software for year Mac, I prefer what Cisco has as very nice advanced stack that you can use. But in addition, here, you can use, if you can't get the advanced Cisco stuff, you can use Malwarebytes.

[00:52:49] It is quite good. Now, historically, one of the main reasons you want to protect your Mac against viruses, including. Windows viruses is that your Mac can potentially spread a virus to a windows machine. So let's say the virus is sitting there inside of an Excel file, a word file. Some other document exec, whatever it might be.

[00:53:14] So that virus is sitting inside of there. It's not going to hurt your Mac. It's a windows virus, right? So now you send the file to somebody else and now they are on a windows machine and they are susceptible. They get nailed with it. Okay. So that's been the main reason historically. You want to make sure your Mac machines are clean.

[00:53:36] Cisco on the Mac, advanced mow, worse platinum. Does look for windows malware. Okay. As well as something that might be affecting a Mac, but what we're looking@hererightnowoverondarkreading.com is a piece of malware that is specifically aimed at max. And it's interesting too, because it isn't just max.

[00:54:03] It actually has multiple versions that included. Our friends over on the windows side. So it's called update agent or wizard update. And it is malware that I, as always, it seems is pretending as legitimate software, right? Support agents, video software. It's been around for a couple of years now. Adobe flash.

[00:54:29] Not only was it a serious security problem, but Adobe flash, as it turns out, was shoes to spread a whole lot of malware here over the years. So they've constantly updated this thing. They came up with a new version in October. They've been sending it around using Amazon and cloud front in order to do it.

[00:54:52] So instead of using zip files or. Apple uses, which are called DMGs, which are basically compressed file systems. The new version can use zip files or Mac DMGs. It's not good. Again, be very careful. Now apple has had for quite a while, and a signature based thing where software developers register with apple, they sign the software, they send out, but there are ways around it.

[00:55:24] And some of the hackers have been exploiting those ways. In fact, this version is the fifth version. Of this update agent and wizard software. Okay. So be very careful with it. Don't think that because you have a Mac, you are guaranteed safe because you're not, but they're also talking in this article about jam.

[00:55:49] Now. Jam is a great. Of software for managing your Macs. We use IBM's mass 360 for our clients, and it lets us do mobile device control as well as for desktops. If you're a CSO, how valuable, something like that really can be apple has their own thing built in. If you have Meraki equipment, they have their own lightweight.

[00:56:15] Controller as well, but jam is very well known in the industry and it's one of the better ones out there jam was showing in research last year, that ad where is continuing to be a much bigger threat to Mac users than most other types of malware. Now, what is that? What are we talking about here? Add where is where a piece of software.

[00:56:41] Gets onto your computer and shows you ads. That's one type, right? There's other types of ad wares as well. The most malicious types being, they will run as JavaScript inside your browser. Or sometimes they'll add, they'll run as an extension. That happened to one of the extensions I loved for. And I used it all the time and someone bought it and turned it into ad where spyware.

[00:57:09] Okay. So on the Mac front, it's very hard to get a legitimate piece of nastiness, like ransomware on your. You actually have to go out of your way to allow it to get installed, but this ad where some of it even minds Bitcoin, we've talked about that before, but what will happen is there's just an added in ad network, right?

[00:57:34] So if I pull up my screen again here, this is just the regular webpage here for dark reading. It's the article we're talking about. Here's some sponsors. Content is actually from one password, which is, something. I really if you look down at the very bottom of the screen is kinda hard to see, but it's the link to this takes you to ad click.g.doubleclick.net.

[00:57:58] That down there on my screen. So that particular URL now is going to track. You see how long that URL is. It has all of this other you ID type stuff. That's an ad. And then ad was probably delivered via a network of some sort, these editor choices, things. These are not ads that are purchased.

[00:58:21] These are probably coming from dark reading itself, who knows. But this Menlo security ad is an ad. You click on it. You can see, again, this is doubleclick.net. These ones here are not doubling. Those are direct on this paper. So what is that double click is what we call an ad network. So if I'm an advertiser and I want to get in front of people who really liked technology, maybe the visited the one password page, which I've done, right?

[00:58:53] So I go to the one password page. It deposits a cookie on my browser. Now I'm on dark reading and on the dark reading site, what's it going to do? The ad network is going to show me an ad for things that thinks I'm interested in one password. The guys who bought through paid for the ad to double-click.

[00:59:14] So that's how double clicks making money. They show the ad to me on dark reading. So that's how dark readings making money either by showing the ad or potentially by being paid. When I click on the ad, if I do click on that ad. All right. So if it's a company you liked, don't click on the ads because it's going to cost them money.

[00:59:34] If it's a company you don't like, then click on the ads, there's actually plugins by the way, that will click on every ad on every page you go to. But not really, it's not going to take you to all these sites. It's just going to look like you clicked on it. So these ad networks. Are being used by bad guys to put an ad in that is actually some form of malware.

[00:59:57] So just seeing the ad might cause some JavaScript to start. And you've probably seen this before. All of a sudden your computer screen shot is full of all of this crap. Where did that come from? It probably came from a small window hidden window, but came from some of this ad stuff that's happened.

[01:00:14] All right. Big problem. And it is right now, the biggest problem in the Mac world, according to jam, and it's called malvertising. You got all these cute names for everything malvertising in this case. Hey, thanks for spending a few. Today, if you would, please go right now, go to Craig peterson.com. You'll see at the top subscribe for email updates.

[01:00:43] When you subscribe, you're going to get my top special reports on passwords and other things, and you'll get my weekly emails and trainings stick around.

[01:00:54] Cloud security. Wow. What a mess. If you are using any of these services online, you probably have a cloud security issue. That means your websites, too.

[01:01:09] Security pros like myself are very frustrated by what we loosely call the cloud.

[01:01:19] So the cloud is just a name, frankly, for somebody else's computer. So you might be using a cloud for instance. Salesforce.com system you might be using your email, Hotmail, Yahoo, right? You might be using Microsoft mail. There's a lot of them out there and they're all cloud systems. Being a word for somebody else's computer.

[01:01:48] That doesn't necessarily mean that's somebody else's backing it up or that they're providing adequate cyber security for it. So we've got an article right here. Again, from our friends at dark reading, Robert limos about why security professionals are frustrated with cloud security. So more and more companies are moving their operations to the cloud.

[01:02:16] And because there are so few people available for cyber security. They're really getting in trouble. Okay. They're really getting in trouble. There's a lot of security data that does never get looked at. It's full-time jobs for people, depending on again, how much cyber security they need so many false alerts and we've got warnings from the feds now that are probably going to continue forever.

[01:02:48] Cybersecurity breaches that they're seen and they're thinking they're going to come. So security data they're saying is wasting more than half of the time spent on security issues. That is not a good thing because there are so many false positives when it comes to cyber security. So how does the basic cybersecurity work?

[01:03:13] For instance, if we were to look at one of the firewalls that we maintain for our. Or our clients, you would see attacks coming up every few seconds. I can show two on just one little machine. If you're talking about a bigger company or a contractor for the department of defense or a subcontractor for the government in any angle, you will see.

[01:03:40] Sometimes dozens of attacks per second. So they're pinging. They are trying to connect to services like Microsoft, remote desktop. They're trying to break in any way they can. That is frankly, a pretty huge problem. Are those legitimate security alerts? Yeah, I guess they are. I have stuff set up so that if someone is trying to, for instance, log in remotely on one of these remote type protocols and they fail three times in a row, they are automatically added to the firewall automatically.

[01:04:22] And they are. Now it removes that ban after a while, but if they do it again, they get banned again. So we know who the bad guys are. And let me tell you, there are a lot of bad guys out there. I don't know if I can get on that machine right now, because I think you might find that. Interesting. Yeah. It's not going to let me on right now, so I'm not going to do that, but it is a very big problem.

[01:04:53] Should I be looking at each one of those security alerts about somebody trying to remotely connect to one of these connection services, right? Desktop services, SSH services. Probably not, it's probably not the best use of my time. So what we have is other canaries, if you will, in the networks. So other points that, okay, they're trying to get in from the outside, but people are always trying to get in past the gate.

[01:05:23] But if they are not successful getting past the gate, I don't really care so much about. Okay. So how do we tell if they're inside the network? So we have other security probes inside the network. We have probes in the switches themselves. We have every network segment. Firewall from each other.

[01:05:46] And in some cases we have absolutely zero trust. So every connection to any machine is checked and firewalled depends on how much cybersecurity you need. So this is a report from a Cod automation firm called Lacework and they talked to 500 security practitioners, blah, blah, blah. They are saying that the vast majority of respondents regularly have to deal with at least a 20% false positive rate and a third deal with a 50% false positive rate.

[01:06:25] The analysts are not alone. Only a third of developers believe that the time spent on security is meaningful. According to the survey and frankly, that's what we have found as well. And that's why we have automated systems and the automated systems say, whoa, this looks really bad. And that's when a person gets involved.

[01:06:48] So it's a real problem. Now here's the next step. And the next step is while we had so many people who were working from home. And because of the lockdowns. Following the start of the Corona virus pandemic, according to this article or dark w reading organizations quickly moved operations to the cloud, we know that's true. We've seen it. We've helped companies secure themselves from their hasty moves to the CRA the cloud. But after two years, companies still have a long way to go before moving. All of the operations to a cloud is less than half of respondents consider the most important applications to be cloud native.

[01:07:34] Now, this is really important because some companies have been moving in, particularly some of the larger ones moving critical applications back in house. Now the cloud is wonderful. A lot of vendors love the cloud because it's MRR monthly recurring revenue. Yeah, you can use my software, but you have to pay me every month.

[01:07:57] Oh. And by the way, I don't want to support you guys anymore. I don't want to have to get onto your servers and take this apart girls. So I'm going to do all of this on my servers. We'll call it the cloud. Maybe it's on Amazon or Azure. Maybe it's in my data center, whatever. And I'm going to charge you a premium.

[01:08:14] What's happening with your data when it's sitting on their computer or Amazons or Microsoft's computers out there, right? It's a very legitimate question and a very concerning question, frankly, cloud apps, particularly those that aren't specifically security related. Won't have the types of details on security that are really needed.

[01:08:41] So you talk about all of the false positives that you have as a business in your own networks. How about false positives that these guys would have in the cloud? The bottom line is forget about. You can't see any of those security breaches. You don't know if your data has been stolen, et cetera, et cetera.

[01:09:04] And that's why we use a cloud lock in front of all of these cloud apps. Now, this is fascinating too. This is from our friends. Over at a glass. What is it about burning glass technologies? Only professionals with application security experience are expected to be in greater demand with a five-year growth rate of 164%.

[01:09:29] Okay. Yeah. And they're talking about 115% growth as well. Hey, visit me online, get all of this information and more put in a little bit of training right at Craig. Peter saw. Calm go there right now at the very top, you can sign up, get my newsletters and get my special reports. Craig peterson.com.

[01:09:54] So we know already hackers went wild. So what are the things we should be doing to help keep ourselves safe? Five things. We're going to go through. Right now how to stay safe.

[01:10:09] This whole thing with hackers is it's just so annoying. I got hacked back in. I'm trying to remember.

[01:10:19] 91 92, something like that. And I, it. It really sent me for a loop to go about three days to figure out what was going on. So I had a couple of deck servers. You might remember those digital equipment corporation. I was working for them as a contractor. So I had purchased those systems and I had them in my data center that I had built in the building that I bought.

[01:10:44] And it was down on the ground floor. It was something I was really proud of. Cool. It was so neat. So I was down there in the computer room trying to figure out what had happened because my customers were calling and complaining that the email wasn't working, it wasn't going through what was the. I had banked some dial up modems.

[01:11:07] I had my T1 lines going to the internet, which costs a pretty penny and all in all, just trying to figure out what's what, and how did this happen? And it turned out it was a back door that was purposely built into the male applicant. So with the mail application and was send mail. I was using at the time, still a great mail program, but I tend to use postfix now.

[01:11:33] And then of, I use again, Cisco's advanced mail filters and I often will use Microsoft email for businesses and then put the additional mail filters in front of that. Send mail had this feature so that you could get onto someone else's mail server that was misconfigured and reconfigured. Which was really a cool idea.

[01:11:57] It worked great for years when the internet was a safe place when it was just us online, a bunch of wonderful people, libertarians trying to spread the word and the gospel of libertarianism and sending jokes back and forth and using Usenet and everything. This is before websites even existed.

[01:12:21] And. It was a shock to me to see what had happened. And it was something called the Morris worm. And one of these days where we should probably talk about that whole worm thing, but it nailed me and my machine was spreading it to other machines on the internet. And the reason it all slowed down in the mail stop was it was so busy, spinning off new processes to find other machines to infect.

[01:12:49] But the machine just ran out of gas. So it was very frustrating. And although my business was a technology business at the time, I've always almost always had technology businesses. But it was not an internet security business. Who was dealing with that then, nobody, because it was barely legal to do business on the internet.

[01:13:10] I think I was doing it before. It was actually. To do business on the internet. There was just Al gore in me back then. At that problem really got to me. And none of my customers understood what had happened. And there was no reason to even try and explain what a worm was and stuff. I just said, some hacker got in and of course, Back then hacker was a term disused for people that were not professional computer programmers, a hacker where somebody that sat there and hacked code and tried to figure it out and trying to put it together.

[01:13:44] That was a. What do you do? You'd tell them the basics of what happened and you continue on your way. So I almost lost the business, frankly. I ended up losing some customers over the next few months, but not very many. So it worked out okay. But then in talking to friends of mine, I found out even more of them that had been hacked and that it was a a serious problem for.

[01:14:09] What do they do? They turn to me cause I knew I'd been hacked before I was a techie guy and I went on and I built some big. Systems. I built the largest website in the world at the time. And it was, you might be familiar with it, big yellow or yellow pages.com. Any of those sorts of platforms.

[01:14:33] The first one of those and got that up online, built the whole data center and even had to make our own routers at the time and firewalls. We actually designed one of the world's first firewalls, and that was my design. And I had a couple of guys that helped to implement it with me. We had to do everything back.

[01:14:53] And ever since then, I've had a focus on this because one of my clients had a million dollar, a day lottery system down in New York city. You got to keep that safe. And they were sending out millions of emails. So I had to learn about the email security, all of that stuff. So I mentioned all of that to you guys, because think about the position you're in now.

[01:15:16] I don't think it's much. And then the position I was in 30 years ago, but you don't want to spend all of the time that I've had to spend the last 30 years to understand this better and to learn how to protect it better. So that's why I do what I do. I try and get this information out to you. Here's this another article from our friends at dark reading and it's a Leche, I think they invite people to come on and write things for them, but he's talking okay. He's the product strategy manager over at UConn to can canonical they've been around quite a while. Been to was a Linux distribution. What's happening. We know about the colonial pipeline, right? We know the hack that happened and how bad that hack was.

[01:16:08] They was absolutely huge. And it affected all of the east coast for fuel. Every kind of fuel you can think of a real big problem. Russian linked. The hackers that broke into this. Okay. Probably the largest hack ever on a U S utility system. I'm pretty sure it was solar winds, another big hack. They hacked companies that were providing.

[01:16:34] Services to businesses, including security services, right? That's why we don't use them. And we reported serious security problems to them a year and a half before they were hacked. Did they fix them? No, they did not. So this article goes on to talk about how through September in 2021, there were about 1300 breaches in the U S.

[01:16:59] These are reported breaches and K and they're broke the all-time record last year. No two ways about it. And then president Biden in 2021. With an executive order that is forcing now the federal government to eventually become secure and department of defense and the department of defense contractors.

[01:17:24] Okay. Very big problem. He's trying to fix it. Of course, Trump tried to fix it. And president Obama tried to fix it. Everybody's tried to fix it. And so far it just hasn't happened. And our typical, I teach teams really are struggling, trying to stop some of these intrusions, including the more sophisticated ones, which are the intrusions that tend to be coming from nation states.

[01:17:50] The intrusions that are coming from China, Russia, North Korea, and Iran, those are the main. That are coming after us. So what are the things you can do? And I'm going to explain these kind of briefly you can, of course, look this article up yourself, but it is on dark reading. And if you're watching this on video, you can follow along.

[01:18:13] Zero trust is the first thing that is the new, if you will kid on the block or new, where, when it comes to cybersecurity, because what it does now is it assumes all traffic on your network needs to be monitored closely because it could be. So at the very least you're monitoring all the traffic. We do that for our clients as well.

[01:18:39] And you can get into very sophisticated firewall rules, which again, we have to stop certain applications from being reachable from machines. They should not be reachable from. Okay. So there's no silver bullet to. Put zero trust in place, or even to make it work, but you need to do it. So if you're responsible for cyber security in your business, to some degree, checkout, zero trust, next one.

[01:19:07] What data assets do you have because you need to protect them. This particular article is calling them a software bill of materials. But you need to know what you have to protect. What software are you running? What data do you have? What data is controlled by regulations, federal regulations, et cetera.

[01:19:29] You have to know all of that. You have to secure it properly. You need automated vulnerability management. That's why we tie into. Fingers real time, database of hacks going on in the world. And we use that in real time, again, to protect endpoints and to protect network points, secure configuration. That's another thing we do.

[01:19:54] I'm going to probably have this as part of a webinar, if you will, or at least a course, there's about 250. Yeah, that many changes you have to make to windows to try and secure. In fact, I have behind me, this book is probably about five inches thick. It's a binder on how to secure windows 10 and it has gotten even bigger with windows 11.

[01:20:19] Okay. And you have to be aware of the regulations you have to comply with now at the very least. Every last business out there needs to comply, which is called the NIST CSF. I'm helping another company right now, gain compliance with this. This is the national Institute of standards and technology, consumer security, not consumer computer security framework, NIST CSF.

[01:20:50] It is the basics out there. There's others that get more complicated. The CMMC the PCI DSS HIPAA. Hi-tech right. We can go on and on, but those are the five things. Zero trust. No, what data you have, what software you have to protect of my automatic vulnerability management. I'm telling you're not getting that.

[01:21:12] Buying something from best buy or from a big box retailer, online, secure configuration and regulatory. Hey, thanks for being with us today. It has been fun. I enjoy sharing this and I really realized that this morning, even more, this is a blessing for me. Hopefully it's been a blessing for you.

[01:21:34] Check me out, go online and get my newsletter. Craig peterson.com and have a great week ahead. Take care. Bye-bye.

View Details

Is Your Email On The Dark Web?
Let's Check Now!

Do you know how to find out if you have had your private information stolen? Well, you know, the odds are probably that you have, but where was it stolen, when, and what has been stolen? How about your password and how safe that password is? We're going to show you real hard evidence.

[The following is an automatic transcript.]

[00:00:16] Knowing whether or not your data has been stolen and what's been stolen is very important.

[00:00:24] And there is a service out there that you can go to. They don't charge you a thin dime, anything, and you can right there find out which of your account has been compromised. And. Out on the dark web. Now the dark web is the place that the criminals go. That's where they exchange information they've stolen.

[00:00:49] That's where they sell it. That's where you can buy a tool to do Ransomware hacking all on your own. Far less than 50 bucks. Ransomware as a service is available where they'll do absolutely everything except infect people. So you just go ahead and sign up with them; you pay them a 20% or sometimes more commission.

[00:01:12] You get somebody to download, in fact, to themselves with the Ransomware, and they do everything else. They take the phone call; they find out what it is. The company is doing, and they set the ransom, and they provide tech support for the person that got ransomed to buy Bitcoin or sometimes some of these other cryptocurrencies.

[00:01:38] In fact, we've got another article in the newsletter this week about cryptocurrencies and how they may be falling through. Floor because of Ransomware. We'll talk about that a little later here, but here's the bottom line. You want to know this. You want to know if the bad guys are trading your information on the dark web; you want to know what data they have so that you can keep an eye on it.

[00:02:11] Now you guys are the best and brightest, you know, you have to be cautious, or you wouldn't be listening today. And because, you know, you've been caught, you need to be careful. You have been cautious, but the time you need to be the most cautious is right after one of the websites that you use that hasn't been hacked because the fresher, the information, the more it's worth on the dark web, your identity can be bought on the dark web for.

[00:02:38] Penny's depending on how much information is there. If a bad guy has your name, your email, the password you've used on a few different website, your home address, social security number, basically the whole shooting match. They can sell your personal information for as little as. $2 on the dark web. That is really bad.

[00:03:02] That's sad. In fact, because it takes you a hundred or more hours. A few years ago, they were saying about 300 hours nowadays. It's less in order to get your identity kind of back in control. I suspect it probably is closer to 300, frankly, because you. To call anybody that pops up on your credit report. Oh, and of course you have to get your credit report.

[00:03:29] You have to review them closely. You have to put a freeze on your. Got an email this week from a listener whose wife had her information stolen. He had lost a wallet some years ago and she found because of a letter that came saying, Hey, thanks for opening an account that someone had opened an account in her name.

[00:03:51] Now the good news for her is that it had a zero balance. Caught it on time. And because it was a zero balance, it was easy for her to close the account and he's had some problems as well because of the lost wallet a few years back. So again, some basic tips don't carry things like your social security card in your wallet.

[00:04:17] Now you got to carry your driver's license because if you're driving, the police wanted, okay. Nowadays there's in some ways less and less of a reason to have that, but our driver's license, as you might've noticed on the back, many of them have either a QR code or they've got a kind of a bar code scan on them, but that big QR code contains all kinds of information about.

[00:04:41] You that would normally be in the online database. So maybe you don't want to carry a bunch of cash. Although, you know, cash is king and credit cards can be problematic. It kind of depends. And the same thing is true with any other personal identifiable information. Keep it to a minimum in your wall. But there is a place online that I mentioned just a minute ago that does have the ability to track much of the dark web.

[00:05:13] Now this guy that put it together, his name's Troy hunt, and Troy's an Australian he's been doing this. Public service for forever. He tried to sell his little company, but the qualifications for buying it included, you will keep it free. And there are billions of people, or I shouldn't say people there's billions of requests to his website about people's private information.

[00:05:42] So, how do you deal with this? What do you do? Well, the website is called, have I been poned? Have I been E and poned P w N E D. Ponying is an old term that comes from. Uh, these video games before they were online. And it means that basically I own you, I own all of your properties. You've been postponed and that's what Troy kind of followed here.

[00:06:11] Have I been postponed to.com is a website that you can go to now. They have a whole bunch of other things. They have API calls. For those of you who are programmers and might want to keep an eye out for your company's record. Because it does have that ability as well. And it has a tie ins too, with some of the password managers, like one password to be able to tell is my new password, any good.

[00:06:41] And which websites have been hacked. Does that make sense? And so that is a very good thing, too, because if you know that a website that you use has been hacked, I would like to get an email from them. So the first thing right there in the homepage, you're going to want to do. Is click on notify me. So you ensure in your email address, I'm going to do that right now, while we're talking, they've got a recapture.

[00:07:12] I'm not a robot. So go ahead and click that. And then you click on the button. Notify. a lot of people are concerned nowadays about the security and safety of their information. They may not want to put their email address into a site like this. Let me assure you that Troy. Is on the op and up, he really is trying to help.

[00:07:39] He does not use any of the information that you provide on his website for evil. He is just trying to be very, very helpful. Now his site might get hacked, I suppose, but it has been just a huge target of. Characters and because of that, he has a lot of security stuff in place. So once you've put your email address right into the notify me box, click on notify me of

[00:08:06] Of course you got to click the I'm not a robot. So once you've done that, It sends you a verification email. So all you have to do at that point, it's just like my website. When you sign up for my newsletter, keep an eye out for an email from Troy from have I been poned.com asking you if you signed up for his notification service?

[00:08:31] Obviously it is a very good idea to click on his link in the email. Now I caution people, it costs. And you guys all of the time about clicking on links and emails, because so many of them are malicious, but in the case of like Troy or my website, or maybe another one that you sign up for, if you just signed up for.

[00:08:54] You should expect an email to come to your mailbox within a matter of a couple of minutes, and then you should spend just that minute or so. It takes to click on that email to confirm that you do want to get the emails from the website, because if you don't hit that confirmation, you're not going to get the emails.

[00:09:17] Let me explain a little bit about why that is. Good guys on the internet don't want to spam you. They don't want to overload you with all kinds of emails that may matter may not matter, et cetera. They just want to get you information. So every legitimate, basic a guy out there business, a organization, charity that is legitimate is going to send you a confirmation email.

[00:09:50] The reason is they don't want someone to who doesn't like you let's say to sign you up on a few hundred different emails site. And now all of a sudden you're getting. Well, these emails that you didn't want, I had that happen to me years and years ago, and it wasn't sites that I had signed up for. In fact, some of them were rather pornographic and they kept sending me emails all of the time.

[00:10:19] So Troy is going to send you just like I do another legitimate website, send you an email. The link that you must click. If you do not click his link, you are not going to get the emails. It's really that simple. Now, Troy looking at a site right now has information on 11 billion pond account poned accounts.

[00:10:47] Really? That is huge. It is the largest collection that's publicly available of. To count. So I'm, we're going to talk about that a little bit more. And what information does he have? How does he protect it? What else can you find out from? Have I been poned? This is an important site. One of the most important sites you can visit in order to keep yourself safe.

[00:11:16] Next to mine. Right? Make sure you visit right now. Craig peterson.com/subscribe and sign up for my newsletter and expect that confirmation email to.

[00:11:29] Have you been hit by Ransomware before? Well, it is a terrible thing if you have, but what's the future of Ransomware? Where is it going? We've talked about the past and we'll start with that and then move into what we're expecting to come.

[00:11:46] The future of Ransomware is an interesting one. And we kind of have to look at the past in Ransomware.

[00:11:55] Ransomware was pretty popular in that bad guy. Just loved it. They still do because it is a simple thing to do. And it gives them incredible amounts of flexibility in going after whoever they want to go. After initially they were sending out Ransomware to anybody's email address. They could find and hoping people would click on it.

[00:12:24] And unfortunately, many people did click. But back then the ransoms were maybe a couple hundred dollars and you paid the ransom and 50% chance you got your data back. Isn't that terrible 50% chance. So what do you do? How do you make all of this better? Make your life better? Well, Ransomware really, really drove up the value of Bitcoin.

[00:12:54] Bitcoins Ascension was largely based on Ransomware because the bad guys needed a way that was difficult to trace in order to get paid. They didn't want the bank to just sweep the money back out of your account. They didn't want the FBI or other agencies to know what they were doing and where they were located.

[00:13:20] So, what they did is, uh, they decided, Hey, wait a minute. Now this whole crypto game sounds interesting. And of course talking about crypto currency game, because from their viewpoint, it was anonymous. So they started demanding ransoms instead of dollars, PayPal, even gift certificates that they would receive from you.

[00:13:46] They decided we're going to use some of the cryptocurrencies. And of course the big one that they started using was Bitcoin and Bitcoin has been rather volatile. Hasn't it over the years. And its founding was ethically. Empty, basically what they did and how they did it. It's just disgusting again, how bad some people really are, but they managed to manipulate the cryptocurrency themselves.

[00:14:17] These people that were the early. There's of the cryptocurrency called Bitcoin and they manipulated it. They manipulated people into buying it and accepting it, and then they managed to drive the price up. And then the, the hackers found, oh, there's a great way to do it. We're going to use Bitcoin. And so they demanded ransoms and Bitcoin, and they found that no longer did they have to get like a hundred dollar gifts, different kid for Amazon.

[00:14:46] Now they could charge a thousand dollars, maybe even a million dollars or more, which is what we saw in 2021 and get it paid in Bitcoin. Now Bitcoin is kind of useful, kind of not useful. Most places don't take Bitcoin as payment, some have started to because they see it might be an investment in the future.

[00:15:11] I do not use Bitcoin and I don't promote it at all, but here's what we've been seeing. Uh, and this is from the chief technology officer over tripwire, his name's Dave Meltzer. What we've seen with ransom. Attacks here. And the tie to Bitcoin want to cry back in 2017 was terrible and it destroyed multiple companies.

[00:15:39] One of our clients had us protecting one of their divisions and. We were using really good software. We were keeping an eye on it. In fact, in the 30 years I've been protecting businesses from cyber intrusions. We have never, ever had a successful intrusion. That's how effectively. And I'm very, very proud of that.

[00:16:05] Very proud of that. We've we've seen ransomware attacks come and go. This wanna cry. Ransomware attack destroyed every part of the company, except for. The one division we were protecting, and this is a big company that had professional it, people who really weren't very professional. Right. And how, how do you decide, how do you figure out if someone really knows what they're talking about?

[00:16:32] If all they're doing is throwing around buzzwords, aren't, that's a huge problem for the hiring managers. But anyways, I digress because having a. Particular series of letters after your name representing tests that you might've passed doesn't mean you're actually any good at anything. That's always been one of my little pet peeves over the decades.

[00:16:55] Okay. But another shift in the targeting of Ransomware now is showing a major uptick in attacks. Operational technology. Now that's a real big thing. We've had some huge hits. Uh, we think of what happened with solar winds and how it got into solar wind software, which is used to monitor computers had been.

[00:17:24] And had inserted into it. This one little nice little piece of code that let the bad guys into thousands of networks. Now we've got another operational technology hack in progress. As we speak called vog for J or log for shell. Huge right now, we're seeing 40% of corporate networks are right now being targeted by attackers who are trying to exploit this log for J.

[00:17:53] So in both cases, it's operational software. It's software businesses are using. Part of their operations. So we're, and part of that is because we're seeing this convergence of it, which is of course information technology and operational technology environment. In many times in the past, we've seen, for instance, the sales department going out and getting sales force or, or something else online or off.

[00:18:25] They're not it professionals in the sales department or the marketing department. And with all of these kids now that have grown up and are in these it departments in their thirties and think, wow, you know, I've been using technology my whole life. I understand this stuff. No, you don't. That has really hurt a lot of bigger companies.

[00:18:48] Then that's why some companies have come to me and saying, Hey, we need help. We need some real adult supervision. There's, there's so many people who don't have the decades of experience that you need in order to see the types of holes. So. We've got the it and OT kind of coming together and they've exposed a technology gap and a skills gap.

[00:19:16] The businesses are trying to solve right now in order to protect themselves. They're moving very quickly in order to try and solve it. And there they've been pretty much unable to. And w we use for our clients, some very advanced systems. Hardware software and tools, because again, it goes back to the kind of the one pane of glass.

[00:19:38] Cisco doesn't really only have one pane of glass, but that's where it goes back to. And there's a lot of potential for hackers to get into systems, but having that unified system. That Cisco offers really helps a lot. So that's kinda my, my little inside secret there, but we walk into companies that have Cisco and they're completely misusing them.

[00:20:02] In fact, one of these, uh, what do you, would you call it? Well, it's called a school administrative unit in my state and it's kind of a super school board, super school district where there's multiple school districts. Hold two. And they put out an RFP because they knew we liked Cisco and what some of the advantages were.

[00:20:22] So they put out a request for proposal for Cisco gear and lo and behold, they got Cisco gear, but they didn't get it configured properly, not even close. They would have been better off buying something cheap and being still exposed. Like, you know, uh, I'm not going to name some of this stuff you don't want to buy.

[00:20:42] Don't want to give them any, uh, any airtime as it were. But what we're finding now is law enforcement has gotten better at tracking the digital paper trail from cryptocurrencies because cryptocurrencies do have a. Paper trail and the bad guys didn't realize this. At first, they're starting to now because the secret service and the FBI have been taking down a number of these huge ransomware gangs, which is great.

[00:21:16] Thank you very much for doing that. It has been phenomenal because they've been able to stop much of the Ransomware by taking down these gangs. But criminal activity that's been supported by nation states like North Korea, China, and Russia is much harder to take down. There's not much that our law enforcement can do about it.

[00:21:42] So w how does this tie into Ransomware and cryptocurrency while ultimately. The ability to tr address the trail. That's left behind a ransom payment. There's been a massive shift in the focus from government trying to tackle the underlying problem of these parolees secured curdle Infor critical infrastructure sites.

[00:22:06] And that's what I did training for. The eyes infra guard program on for a couple of years, it has shifted. Now we've got executive orders. As I mentioned earlier, from various presidents to try and tighten it up and increase government regulation mandate. But the big question is, should you pay or not? And I recommend to everyone out there, including the federal government recommends this, by the way, don't pay ransoms because you're just encouraging them.

[00:22:40] Well, as fewer and fewer ransoms are paid, what's going to happen to Bitcoin. What's going to happen to cryptocurrencies while the massive rise we saw in the value of Bitcoins will deteriorate. Because we won't have businesses trying to buy Bitcoin before they're even ransomed in order to mitigate any future compromise.

[00:23:06] So I love this. I think this is great. And I think that getting more sophisticated systems like what, like my company mainstream does for businesses that I've been doing for over 30 years is going to draw. Well, some of these cryptocurrencies like Bitcoin down no longer will the cryptocurrencies be supported by criminals and Ransomware.

[00:23:35] So that's my hope anyways. And that's also the hope of David Meltzer, chief technology officer over at tripwire hope you're having a great year so far. You're listening to Craig Peter sohn.com. Sign up for my. At Craig peterson.com. And hopefully I can help you have a little bit of a better year ahead.

[00:23:57] All of these data breaches that the hackers got are not graded equal. So we're going to go through a few more types of hacks, what they got. And what does it mean to you and what can you do about it?

[00:24:13] Have I been B EEN poned P w N E d.com. And this is a website that has been put together by a guy by the name of Troy hunt. He's an Australian and it goes through the details of various. So that he has found now it's not just him. There are a lot of people who are out there on the dark web, looking for hacks, and there's a few different types of hacks.

[00:24:43] And of course, a lot of different types of information that has been compromised and gathered by the bad guys. And, um, stat just out this week is talking about how businesses are so easy. To compromise. It is crazy. This was a study that was done by a company called positive technologies, and they had a look at businesses.

[00:25:11] Basically they did white hacking of those businesses and found that 93% of tested networks now. 3% of tested networks are vulnerable to breaches. Now that is incredible. And according to them in dark reading, it says the vast majority of businesses can be compromised within one month by a motivated attacker using common tech.

[00:25:42] Such as compromising credentials, exploiting, known vulnerabilities in software and web applications or taking advantage of configuration flaw. Isn't that something in 93% of cases, an external attacker could breach a target company's network and gain access to local devices and systems in 71% of cases, the attacker could affect the business in a way deemed unacceptable.

[00:26:13] For example, every. Bank tested by positive technologies could be attacked in a way, the disrupted business processes and reduced their quality of service. It's a very big deal. And much of this has to do with the fact that we're not taking cyber secure. Seriously as businesses or as government agencies.

[00:26:41] Now, the government agencies have been trying to pull up their socks. I got to give a handout to president Biden. He really started squeezing many of these federal contractors to get security in place. President Trump really pushed it even back to president Obama, who. Pushed this fairly heavily. Now we're starting to see a little bit of movement, but how about the smaller guys?

[00:27:08] How about private businesses? What are you doing? So I'm going through right now. Some of the basic things you can get from, have I been poned and what you can do with all of that data, all of that information, what does it mean to you? So I'm looking right now at my business email address, which isCraig@mainstream.net, pretty simple Craig and mainstream gotten that.

[00:27:36] And I found because this email address is about 30 years old. Yeah. I've been using it a long time, about 14 data breaches and. Paste. All right. So what does that mean? What is a paste? Well, pastes are a little bit different than a regular hack. All right. The paste is information that has been pasted to a publicly facing.

[00:28:03] Website. Now there's many of them out there. There've been a lot of breaches of Amazon site of Amazon databases, Azure, all of these types of things. But we're, we're talking about here are these websites that are designed to. People to share whatever they want. So for instance, you might have a real cool program, wants to people, those to try out to you don't have the bandwidth to send it to them.

[00:28:28] You certainly can send it via email because it's much, much, much too big. So sites like Pastebin or out there to allow you to go ahead and paste stuff in and share the link. Pretty simple, fairly straightforward. Well, these pay sites are also used by hackers to make it even easier for them to anonymously share information.

[00:28:55] And many times the first place that a breach appears is on one of these paste sites. So have I been poned searches through these different pastes that are broadcast by a Twitter account called dump Mon, which is a site where again, bad guys are putting information out about dumps had been found as well as good guys.

[00:29:20] All right. And they. Port, uh, on, in the dump mom dump MUN Twitter account. If you're interested, it's at D U M P M O N. They report emails that are potential indicator of a breach. So finding an email address in a paste. Necessarily mean it's been disclosed as a result of a breach, but you should have a look at the paste and determine whether or not your account has been legitimately compromised as part of that breach or not.

[00:29:53] All right. So in my case again, for theCraig@mainstream.net email address, it was involved. In a paste. So let me see what it says. So let me see. It shows it involved in a pace. This is pace title AA from July, 2015. So this is information from published to a publicly facing website. I don't know if I click on that.

[00:30:22] What does it do? Yeah. Okay. So it actually has a link to the paste on AEs to ban. And in this case it's gone, right? It's been deleted. It could have been deleted by the Pastebin staff. Somebody told them to take it down, whatever it is. But again, have I been poned allows you to see all of the information that has been found by the top security.

[00:30:48] Researchers in the world, including various government agencies and allows you to know what's up. So let's have a look here at passwords. So if you click passwords at the very top, this is the other tool you should be looking at. You can safely type in the passwords you use. What have I been poned does is instead of taking the passwords from these hacks in the clear and storing them, it creates a check some of the password.

[00:31:21] So if you type a password into this, I'm going to type in P a S S w Z. Oh, excuse me. Uh, oh, is that, let me use a better password. P at S S w zero RD. One of the most common passwords on the internet, common passwords ever. Okay. So it says, oh no, poned this password has been seen 73,586 times B four. Okay. It says it, the passwords previously.

[00:31:53] Appeared in a data breach and should never be used if you've ever used it anywhere before change it. You see, that's why you need to check your passwords here. Are they even safe to use because what the bad guys have done in order to counter us using. Longer passwords. Cause it's not the complexity of the password that matters so much.

[00:32:16] It's the length of the password. So they don't have enough CPU resources in order to try every possible password from eight characters through 20 characters long, they could never do that. Would take forever or going to try and hack in. So what they do is they use the database of stolen passwords in order to try and get in to your account.

[00:32:42] Hey, I'm going to try and summarize all of this in the newsletter. So keep your eye. For that. And again, the only way you're going to find that out and get my summary today, including the links to all of this stuff is by being on my email list. Craig Peterson.com/subscribe. That's Craig Peterson, S O n.com/subscribe, stick around.

[00:33:09] Did you know, there is a site you can check your password against to see if other people have used it. And if that password has been stolen, it's a really great site called have I been postponed? And we're going to talk about it more right now.

[00:33:26] You know, I've been doing cyber security pretty much as a primary job function here in my career for about, let me see.

[00:33:37] Not since 92. So my goodness, uh, yeah, an anniversary this year. Okay. 30 years. So you're listening to a lot of experience here as I have. Protect some of the biggest companies in the world, the department of defense, defense, and military contractors all the way down through our local dentist's office. So over 5,000 companies over the years, and I helped perform what are called virtual CIS services.

[00:34:11] Which are services to help companies make sure that they have their security all lined up. And we also have kind of a hacker audit whether or not you are vulnerable as a business to being hacked. So we'll go in, we'll look at your systems. We can even do a little bit of white hat hacking in order to let you know what information is out there available about your company.

[00:34:39] And that's really where. Have I been poned comes in. It's a very simple tool to use and it gives you some great information, some really good information about what it is that you should be doing. What is that? I had a meeting with the FBI, one of my client's sites, because they had been hacked and my client said, yeah, go ahead and bring them in.

[00:35:03] And it turned out to be the worst infection that the Boston office of the FBI has ever seen. There were active Chinese backdoors in there stealing their information. Their plans are designed everything from them. Right there. Right. And, oh, it was just incredible to see this thing that it all started because they said they had an email problem.

[00:35:30] We started looking at more closely and we found him indications of compromise, et cetera. So it gets bad. I've been doing this for a long time. But one of the things that you can do, cause I understand not everybody can do what we do. There are some very complicated tools we use and methods, methodologies, but this is something anyone can do.

[00:35:53] Again, this site's called, have I been poned.com? You don't have to be a white hat hacker to use this. This is not a tool for the black hats, for another words, for the bad guys, for the hackers out there. This is a tool for you, whether you're a business person or a home user. And we talked about how you can sign up there to get a notification.

[00:36:18] If your account has been hacked. So I'm going to the site right now. Have I been poned, which is spelled P w N E D. Have I being B E N poned P w N E d.com. And I'm going to type in me@craigpetersong.com, which is my main email address for the radio show and others. So good news. It says. Postage found. In other words, this particular email address has not been found in any of the hacks on the dark web that Troy has access to.

[00:36:56] Now, remember, Troy does not know about every hack that's occurred. He does not know about every data breach that has occurred, but he knows about a whole lot of them. And I mean, a lot. If you look on his site right there in the homepage, you'll see the largest breaches that he knows about drug. For instance, 510 million Facebook accounts that were hacked.

[00:37:24] He has the most recently added breaches. We just got an addition from the United Kingdom, from their police service over there. Some of the more recent ones include Gravatar accounts. Gravatar you might have a, it's a very common, in fact, 114 million Gravatar accounts information were compromised. So me at Craig Peterson is safe.

[00:37:52] Well, let me check. My mainstream email address now, mainstream.net is the website that I've been using for about 30 years now online. And this is the company that I own that is looking at how do we protect businesses? No. And we're a small company, basically a family operation, and we use a lot of different people to help out with specific specialties.

[00:38:21] But let me seeCraig@mainstream.net, this one's guaranteed to be poned all right, because again, that email addressCraig@mainstream.net is close to 30 years old. Uh, okay. So here we go. 14 data breaches. It says my business email address has been involved. Eight tracks back in 2017 and it says compromised data was emails and passwords.

[00:38:48] The Apollo breach in July of 2018. This was a sales engagement startup email address, employer, geographic location, job, title, name, phone number salutation, social media profiles. Now you see this information that they got about me from this Apollo breach. Is the type of information that they need in order to fish you now, we're talking about phishing, P H I S H I N G.

[00:39:17] And the whole idea behind fishing is they trick you into doing something that you probably. Should not do. And boy, do they trick you into it? Okay. So the data left, exposed by a Paulo was used in their revenue acceleration platform and it's data that they had gathered. That's fishing stuff. So for instance, I know my company name, they know where it's located.

[00:39:44] They know what my job title is, uh, phone numbers, uh, how to address me, right. Not my pronouns, but salutations, uh, and social media profile information interest in it. So think about all of that and how they could try and trick me into doing something that really is against my best judgment. My better interest makes sense.

[00:40:09] Co this big collection collection. Number one in January, 2019, they found this massive collection of, of a credential stuffing lists. So that's combinations of email addresses and passwords. It's the, uh, 773 million record collection. So what password stuffing is, is where they have your username. They have your passwords that are used on multiple accounts.

[00:40:40] Now, usually the username is your email address and that's a problem. And it really bothers me when websites require your email address for you to log in, as opposed to just some name that you make up. And I make up a lot of really cool names based on random words. Plus I have 5,000 identities that are completely fabricated that I use on various social media sites or other sites where I don't care if they have my right information.

[00:41:14] Now, obviously the bank's gonna need your information. You can't give it to the, you know, the fake stuff to law enforcement. Too anyways, but that's what credential stuffing is. They will use the email address that you have, that they found online in one of these massive dumps, or maybe one of the smaller ones are long with the passwords.

[00:41:39] They found that you use on those websites and they will stuff them and other. They'll use them on a website. They will continually go ahead and just try different username, different password combinations until they get in. Now, that is a very, very big problem called credential stuffing. And that's why you want to make sure that you change your password when a breach occurs.

[00:42:10] And it isn't a bad idea to change it every six months or so. We'll talk more about this when we get back, but I want you to make sure you go right now because we've got bootcamps and other things starting up with just probably mid to late January. And you only find out about them@craigpeterson.com.

[00:42:32] Make sure you subscribed. .

View Details

Are You Ready For the Latest Cyber Attack From Russia? Yet another warning coming out from the federal government about cyber security. And this one is based on what's been happening in Ukraine. So we're going to talk about that situation, the whole cyber security over there, and why it's coming here.

[Automated transcript follows]

CISA is the Cybersecurity and Infrastructure Security Agency. How's that for a name? It's not as bad as what does S.H.I.E.L.D mean? Over from the Marvel universe.

But the cybersecurity and infrastructure security agency is the agency that was created to not just protect federal government systems, although they are providing information for.

[00:00:41] People who protect those systems, but also for businesses and you and me and our homes. So they keep an eye on what's happening, what the various companies out there are finding, because most of the cybersecurity information that we get is from private companies and they. But it altogether, put it in a nice little wrapping paper.

[00:01:06] In fact, you can go onto their website anytime that you'd like to, and find all kinds of stuff that is going to help you out. They've got a ton of documents that you can download for free little steps that you can take. It's at csun.gov, C I S a.gov. And they've got the known exploited vulnerabilities catalog.

[00:01:30] That's something that we keep up to date on to help make sure our clients are staying ahead of the game. They've also got their review board securing public gatherings. They also run the stop ransomware.gov site that you might want to check out. And we'll be talking a little bit more about ransomware and the ways to protect yourself a little later today.

[00:01:53] Now Seesaw is interesting too, because when they are releasing information, most Americans really aren't aware that they even exist. They do. And they've got a big warning for us this week. There's a site that I follow called bleeping computer that you might want to keep an eye on and they have.

[00:02:16] I'll report just out this week that you, crane government agencies and corporate entities were being attacked. This was a coordinated cyber attack last Friday, a week ago, where websites were defaced data wiping malware was deployed and causing all of these systems to become not just a corrupt, but some of these windows devices to be completely.

[00:02:45] Operable now that is a bad thing. The reason for this, this is speculation, but it isn't a whole lot of speculation. Right? Am I getting out of, on a limb here particularly, but the whole idea behind this is a cyber war, that Russia's got, what is it now? 130,000 troops, whatever it is over a hundred thousand.

[00:03:08] On the border of Ukraine, they invaded Ukraine a few years ago. Russians shot down a passenger airline in Ukrainian air space. This that was a few years back. They've been doing all kinds of nastiness to those poor Ukrainians. They also had a massive ransomware attack in Ukraine. That was aimed at their tax software.

[00:03:36] Some countries do the electronic filing thing a lot differently than the us does. A couple of examples are Ukraine. France is another one that comes to mind. We have clients in France that we've had to help with cyber safety. And we're always getting popups about major security problems in the tax software, because they have to use this software that's provided by the French government.

[00:04:04] Ukraine's kind of the same way. The biggest. Company providing and the tax filing software for Ukraine was hacked and they use that hack to then get into the tech software and make it so that when that software was run by these Ukrainian companies, they would get ransomware. It was really rather nasty.

[00:04:30] So the Russians had been playing games over in Ukraine for quite a while. But what's apparently happened now, is that a thing? Those things, same things are coming our way now. It's not just because of the fact that a Ukraine is being threatened, maybe they're going to encroach even more, take more than Crimea, which they did last time.

[00:04:56] We're in the U S and what are we doing? President? Biden's been sending troops to Europe, troops to Poland, Germany, and also advisors to the Ukraine. He's removed the embassy staff, at least the vast majority of it from Ukraine. And I just I think. To what happened with his completely unplanned withdrawal that we did in Afghanistan and how things just got really bad there.

[00:05:28] And I'm not worried about what's going to happen in Ukraine because the Russians aren't particularly fond of the idea that we are sending aid and support to. Yeah, it's a bad thing. President Obama sent them blankets, but Biden is sending them military weapons and ordinance, which is what they'd need to fight.

[00:05:54] So Russia has shown that they will attack a country via electronic means cyber means, right? Cyber attacks. And so what's happening now is the bad guys from. That have been the facing websites and who have been doing more than that, wiping computers and making them completely unusable could well come after us because they're really going to be upset with what's happening now.

[00:06:28] And that was CNN has reported the Ukrainian it services company that helped develop many of these sites was also a big. And of course that means bottom line, that this is what's called a supply chain attack. What I mentioned earlier with the Ukrainian tax software, that's a supply chain attack where you are buying that software, or you're mandated to use the software to file your taxes by the government.

[00:06:58] And what happens while it turns out that software is contaminated, that's called a supply chain attack. Now crane issued a press release about a week ago, saying that the entities were hit by both attacks, leading them to believe that they were coordinated. This is a quote here. Thus, it can be argued with high probability that the interface.

[00:07:24] Of websites have attacked government agencies and destruction of data by Viper are part of a cyber attacking, but causing as much damage to the infrastructure of state electronic resource that's from the Ukrainian government, not the best English, but their English is much better than my Ukrainian or Russian.

[00:07:44] So you, crane is blaming these attacks on Russia, incomes, CS. So you says now urgent. Business people in the us and other organizations to take some specific steps. So quote, here from the Seesaw insights bulletin, the CSO insights is intended to ensure that senior leaders at the top of every organizational where the cyber risks and take urgent near term steps to reduce the likelihood and impact of a potentially damaging compromise.

[00:08:19] All organizations, regardless of the sector or side should immediately implement the steps outlined below. So here's the steps and there are a lot of them. One I'm going to do these, you should find in your newsletter today. Hopefully that all made it in. But three basic things. One reduce the likelihood of a damaging cyber intrusion.

[00:08:47] And we're going to talk about the best way to do backups here a little later on today. Make sure your software is up to date. Make sure your organization's it personnel disabled, all ports and protocols, not essential for business purposes. This is all basic stuff, but I got to say. I bet you, 98% of businesses and organizations, haven't done these things.

[00:09:07] The next major category here, take steps to quickly detect a potential intrusion, and then ultimately maximize the organizations resilient to destructive. Incident. So that means doing things like testing your backup procedure, make sure your data can be restored rapidly, or you have a way to get your business back online quickly.

[00:09:31] What we tend to do is in our backup strategy, depending on how much the company can afford, to be down. To be out of business if they lose all of their stock versus what it costs to do this, but we will put a server on site at the company and that server then does some of the backups, right? It does all of the initial backups.

[00:09:55] And then what happens is it gets relayed to us. It gets pushed to tape and tape is really good. We'll talk about that in just a few minutes, but the other big thing is. The backup that we have local to their business also has what's called a virtual machine infrastructure built on it. So if a machine goes down, If it gets wiped or if it just crashes and can't be recovered easily, we can spin up that machine.

[00:10:28] A copy of it in our little virtual environment in just a matter of minutes. So these are all things you should be considering. If you're interested, you can send an email to me@craigpeterson.com. I can send you a checklist that a little more extensive than this, or I can help you with any other questions you have.

[00:10:47] I get lots of questions every week from everything for on retirees, wondering what they should do all the way through businesses that we help government contractors and others. This isn't good. Russia is likely coming after us. Based on this. Visit me online. Craig peterson.com or email me@craigpeterson.com with your questions.

[00:11:14] With all of this talk about hackers, ransomware data, wiping systems. What's the best way to protect yourself, but what do you do to really protect against ransomware? I can tell you, it's not just plugging another hard disk into do backups.

[00:11:31] We have a lot of problems nowadays. We've got so many hackers out there. We're talking about a multi-billion dollar industry to go after us.

[00:11:43] It's just depressing. Really. When you think about it, I think about the old days where security, wasn't a huge concern, right? Physical security. I had one of my first jobs was at a bank and I was, this was back way back in the a G it would have been the mid seventies and I was one of the operators of the main.

[00:12:09] And so as a mainframe operator, we'd load up the tapes and we would ship them places. We'd also go ahead and put them in the vault so that they were in a fireproof vault, and we could recover anything we needed to recover. It worked out pretty darn well, and it was a fun job, but most of the time it was cleaning the tape drive heads and taking those tapes, those big round tapes, you might remember those.

[00:12:38] Nine track tapes and maybe the fancy stuff, 52 50 BPI or 800 BPI of one end or the other, or the spectrum. And we just had to make sure they were physically safe nowadays of course, mainframes are still around and are still absolutely fantastic. They're just phenomenal. Some of the technology IBM has in their mainframes.

[00:13:04] Most of us, aren't using those. Most of us are using a regular computer or I'm sitting in front of a Mac right now that I use for the radio show. We have windows, computers, Linux machines, right? All of those things that we have in our business and that we maintain securely for our clients. But what do you do when we're talking about random?

[00:13:27] You can cross your fingers and hope that you'd hope you don't get ransomed. That sort of a practice doesn't usually work out too well for people, but you can do backups and many people do. So let's talk about the backups. Let's say that you have your computer and you're doing a backup and you have one or two generations worth of backups for your company.

[00:13:52] Ransomware nowadays does not just typically destroy your whole disk. Usually what it does is it encrypts files like doc files, doc X, right? Excel files, all kinds of files that thinks might be useful to you. And then of course, the rest, it pops up says, pay me. And off you go. The reason for that is so your computer still works so that you can enter in the decryption code.

[00:14:22] Once you've paid the ransom, hopefully it works for you give or take 50% of the time. You will get your data back. If you pay the ransom much of the time. But let's go back to that one or two generations of backup. You're using a cloud service, let's say, and your computer gets ransomware. That cloud service backup software will still work.

[00:14:48] What if it's working? So you're now backing up your encrypted files to the backup site in the cloud. Do you see where I'm going with this? Your backups? No. Same thing is true. If you're backing up to a local hard disk, many people do it and it's handy. I recommend that you do that, but it's not all you should do.

[00:15:13] So that disc is attached. We had a. Boy, who was it here? Yeah, we have a client in Maine and they have a really smart system administrator and he designed these disk drives that would physically disconnect themselves from a machine when the backup was not running and would physically connect themselves when the backup.

[00:15:38] Was running. So the idea there was okay, great. We've got a local backup on a local disk and if the bad guys managed to get a hold of the machine, they're not going to be able to encrypt the. And, as long as the backup isn't running, I thought that was a brilliant solution. Doesn't solve some problems, but it certainly takes care of some others.

[00:16:03] So if you are doing a backup, you've got to make sure you've got multi generations. I tend to keep a year's worth. Now there's other considerations. There's the federal rules of. Procedures that say you have to have bad cops. They have to go back years. And there are also other things the payment card industry requires certain types of backups.

[00:16:29] If you are a government contract, We have them as clients and they have certain data retention policies based on the length of the contract. They have keep it for some years afterwards. It goes on and on. So if your data is lost or stolen or encrypted, and your backup is encrypted or deleted, You are in real trouble depending on the type of business you're in.

[00:17:00] So what's the right answer to this. I've talked about 3, 2, 1 backup for a long time, and it's still a very good methodology for doing backups, but nowadays they're talking about 3, 2, 1, 1 backup, which is again, that's a bit of a different methodology. In doing backups, but the idea is you've got multiple copies of your data on multiple types of media in multiple places.

[00:17:34] That's the bottom line. What is the gold standard for this? I it's something that gets to be a little expensive. Again, we have another client that we've had for years, and they are looking for a replacement for the backup system. Now. And so we proposed something that's based on what's called LTO technology, which is a type of a tape drive.

[00:17:59] It's a small cassette, right? It's not those big 12 inch reels of tape that we used to lug around and it's amazingly dance. The new LTO tape drives have space on them for as much as 45. Terabytes of information. It's also great because it's encrypted by hardware, government level encryption automatically, and those tapes can be taken offline.

[00:18:29] You can take the tape. Now we picked up a client who had been doing backups and they were using little USB drives and every day he'd take the drive home and bring in the next drive. So he had five drives, right? So he had the drive for Monday, Tuesday, Wednesday, Thursday, Friday. And he was taking them home, but he missed one of the key things to check the back.

[00:18:57] He hadn't checked the backup and their backup had not been running for more than a year and a half. So that's the other thing you have to do? The LTO tapes are really the gold standard. It goes back to that for one of the first jobs of mine, right? The job I mentioned, where I was mounting tapes and filing them and moving them around and mountain disc packs and pulling them out and everything.

[00:19:24] It still makes sense. They'll last for decades, they cannot be hacked because they are literally offline. You can ship them to places to have them stored. I have a course on backups and if you're really interested, send me a an email to me@craigpeterson.com. And I'll go ahead and. Send you a link to the course, you can watch it.

[00:19:52] But yeah, I think this is really important. Of course, I'm not going to charge you for that, but magnetic tape it's established. It's understood. It's proven it's been around for many decades and LTO tape is unique. It needs all five best practices for addressing ransomware. Even be able to recover.

[00:20:16] If you want more information, just email me@craigpeterson.com or sign up for my free newsletter. Craig peterson.com.

[00:20:26] Switching from gasoline powered engines to these new electric cars is no environmental panacea. At least that's what West Virginia university is saying. And the E. Just changed its mind as well.

[00:20:42] Ford of course, about a year ago, unveiled its new electric.

[00:20:47] F-150 the lightning and Ford has stopped taking orders for them because they are going to have to make double what they thought they would have to make. Ford also has a similar problem with yet another electric vehicle. The Mustang GM is doing a few different electric. Coles. And so is everybody else, frankly, Porsche even now has an electric car out.

[00:21:16] That is all well and good. Isn't it. And there's certainly problems, particularly with manufacturing nowadays, trying to get the CPU's and other electronic components you need. They're even having trouble getting electric motors for electric windows in vehicles. Now they're coming. Crank window with a little coupon saying later on, we'll convert it to electric for you all kinds of problems, but there's one that I haven't heard anybody but myself talk about.

[00:21:48] And so I was online looking around, doing some searches, seeing if I was, like the only one there's no way right now, I'm not the smartest person in the world. I don't pay the most attention to everything. And I found that. Virginia university is in total agreement with that with me, it's just amazing.

[00:22:11] They looked at recent trends and they're cautioning as I have been for years, at least a decade. Now they're cautioning about what seems to be a race to put more electric vehicles. On the road. And the problem is that these electric vehicles in their demand for electricity may well out, run what's needed to keep the vehicles on the road.

[00:22:40] So here's a quote from them. The electric grid will struggle to handle the quick charging of very many electric vehicles at the same time. Okay yeah, by the way, like hardly any quick charging is generally what everyone thinks about, like going to the gas station, getting a full charge in 10 to 15 minutes, which would be a tremendous instantaneous load on the local distribution center.

[00:23:07] My concern is the huge power dumps required at quick charging stations along the interstate. It sounds good, but it'll require a lot of new infrastructure to get the power to the charging stations, as well as building those charging stations. So where does the power come from? Power storage is going to be required if we're going to also move towards fixing.

[00:23:32] Power sources such as solar and wind. We do not have power storage capability yet in large enough quantities to do this on a large scale. Solar does not work at night. The wind doesn't blow all the time. Also, we do not have the distribution on the streets to move fast charging into residential neighborhoods on mass.

[00:23:57] Electric vehicles are great, but we have not fully considered the impact it'll have on our electrical grid infrastructure. It will require a lot of expansion of our electrical distribution and charging facilities. Remember, electric power comes from the power company. I heard an interview with a lady the other day, and they asked her, where does the electricity come?

[00:24:19] She said, From the plugin, the wall, right? We must consider this when considering wide-scale electric vehicle adoption, much as there is to gain from electric vehicles. I don't believe we're ready yet as a society for completely electrical vehicle transportation system. With time and infrastructure development, we can be.

[00:24:41] I totally agree. This is Rory Nutter, professor lane, department of computer science, electrical engineering, Benjamin M. Slater, college of engineering and mineral resources. I totally agree with that. We don't have the ability to generate the electricity. We don't have the ability to store the excess electricity.

[00:25:05] So in other words, if we're using solar at nighttime, we don't have the sun, we can't run solar. So we got to store the solar. And in fact, we have to make about twice as much electricity as we need during the day so that if we can store it, we can then use it in. The same thing with wind, right? It's fickle.

[00:25:29] It just doesn't work that well. So what do we need? Basically right now, we need to stop turning off our coal powered plants, our natural gas plans and our nuclear plant. Because we need to still have electricity. Look at what's happened last year. And this year over in Europe with the crazy cutbacks that they've been doing on some of these plants, coal nowadays with the scrubbers that are on our cold powered, flat plant is clean energy.

[00:26:03] It's not like the old days where you lived on the south side of the tracks and you got all of the wind blowing towards you that had all of that nasty cold ass. You ever seen any of those pictures? It was just terrible. All of that nasty sitcom. It's not something we need to worry about nowadays.

[00:26:21] The other big thing that ties into all of this is so how do we generate our electricity cleanly? A hundred percent cleanly? Nothing. Per cent, but just a couple of weeks ago, the European commission presented their 27 members states with new draft rules that classified natural gas and nuclear power as green fuels for electricity generation.

[00:26:52] Listen, if we want electric cars, which as we've talked about before are highly polluting. Yes. Because of the materials in them, because of the materials that go into the batteries, having to mine it, having to ship it, having to process it and then having to change out those battery packs after 80,000 or a hundred thousand miles.

[00:27:13] Did you see this guy? There was a meme in the video about this online a few weeks ago. How to test. His Tesla needed a battery replacement. It would cost him, I can't remember what it was. 20, $30,000. A lot of money. So he decided to just blow up the car. That's all it took. I saw another Tesla that had water damage.

[00:27:38] From, being down in new Orleans or somewhere, the flooding occurred. And the guy bought that Tesla because Tesla won't sell the parts to fix the car after the water damage. And so he ripped out the batteries, ripped out the electric motors and he bought a high power engine. And gasoline and put it into the Tesla and made really, quite a very cool car.

[00:28:05] You can find it online if you want to look for that, it's quite cool. What they ended up doing. It took us quite a while to do it, but they did it. So now that we're seeing. That nuclear is green. Let's talk about why we've been so afraid of nuclear. One of the biggest problems of course is so what do you do with all of the waste?

[00:28:25] And that's a legitimate question, but what you're really talking about when you ask that question are the reactors that went online 50 years ago, or that were approved 50 years ago because of the regulations. There are. These nuclear plants that have been provisioned in the last 20 years that are still using that old technology.

[00:28:47] So when we get back, we're going to talk about this more. What about the waste? What our fourth generation nuclear power plants, how safe are they when they say they're intrinsically safe? What does that mean? And how and why? Because I'm predicting to this point that we're going to have to switch back to nuclear and even the European union, if you can believe it agrees with.

[00:29:17] Hey, make sure you take a minute. Go online. Craig peterson.com. Subscribe to my free newsletter. You can get it right there. I send you out stuff every week. And this week is no exception. We've got a bunch of bullet points that if you are in a business position, you got to protect yourself immediately. So I tell you how Craig peterson.com.

[00:29:42] So what are these new rules for nuclear energy? And why is it absolutely necessary that we do something like this? Get fourth generation nuclear online. If we can even consider electric vehicles on our roads.

[00:29:59] Things have changed in the European union. They've been trying to figure out how they're gonna handle all of these electric vehicles, how they're going to properly handle all of the solar cells and the wind turbines.

[00:30:14] And there's even some work over in the EU. To get the tide to generate electricity, some very cool stuff. Actually, that's been done, I love tech and I'm into all of this stuff, frankly. I think we should be doing a lot of it. What I don't think we should be doing. Is getting ahead of ourselves. And unfortunately that's really what's being going on.

[00:30:40] We don't have a grid that can really use the electricity that we can generate from our windmills, from our solar cells, from anything, frankly. And we cannot. All of that electricity that we might be generating and somehow have that electricity be stored and used distributed appropriately to our charging station.

[00:31:07] And our grid was built and designed to have a few central point where the electricity is made, where it's generated and then distributed to some pretty specific types of things like housing, development, businesses, et cetera. You can't just go ahead and open a big business man. in a residential area.

[00:31:29] And part of the reason for that is the grid isn't set up for it. You don't have three phase power going into residential areas or even more than that, you don't have the high voltage, the high current, et cetera. So how are you going to be able to quick charge electric cars in the regular residential neighborhoods?

[00:31:51] I w how about at a hotel? Yeah. Okay. A hotel is probably. Multiple phases and has a fair amount of power there, but the amount of strain that's put on the grid by trying to just rapid charge a single car is huge. So how can we deal with that as well? The quickest and easiest way to deal with it is just put more large power plants online.

[00:32:17] Some people don't like that. Don't like that idea at all, frankly, but we're not ready. What are we going to do? Look at what happened in Texas with a fairly minor reliability or re reliance, I should say, on these windmills last winter and things with this winter, as cold as it's been, that could really cause some just incredible problems.

[00:32:44] Nuclear is being reconsidered, particularly fourth generation nuclear power plants. The greenhouse gas emissions from nuclear power are one 700th of those of coal. The nuclear power plants produce one, 400th greenhouse gas emissions of a gas plant, and they produce a quarter of the greenhouse gas emissions from solar.

[00:33:13] Now you're saying, Hey Craig, come on, I get it. Wait a minute. How can solar produce greenhouse gas? It does. And it produces greenhouse gases because of the manufacturing processes, as well as of course it off gases. So how do we make all of this stuff work? We all saw the China syndrome and we heard from experts like Jane Fonda, how we would all die.

[00:33:38] If we put a nuclear power plant. These are intrinsically safe, power plants much different than they used to be. Nuclear power frankly is a much safer business than most people think it is. They no longer these new plants produce. The the nastiest what's called high level nuclear waste.

[00:34:04] They can reprocess it right there in the plant. They can start in fact where some of the nuclear waste though has been generated from the older nuclear plants and get rid of that. It's amazing. So people are asking okay. Plutonium might have a half-life of 24,000 years, but it doesn't emit much radiation.

[00:34:28] We get that. How about the higher levels of radiation? Because some of it can last for hundreds of thousands of years. According to the U S radiation expert, Robert Gale for every terawatt hour of electricity produced nuclear energy is 10. To 100 times safer than coal or gas. What it does emit are alpha particles, which do not even penetrate human skin.

[00:34:58] They've done all kinds of risk assessments and tried to figure out what's going to happen. What can we do? And I'm not going get into all the details here, but it is intrinsically safe because. What really happens is that the, these new plants he's fourth generation, a newer plant are instead of using water, for instance, that can do reactors out of Canada, use heavy water in order to cool those rods.

[00:35:29] It was same sort of thing we've had in the meltdowns before they're using a liquid silica inside. They're set up in such a way that they do not need to have pumps running. So the Fukushima reactor that you might remember in Japan that failed because of the tsunami and the fact that one fact, this is what was their killer that their electrical generation from the diesel generators went offline.

[00:36:00] Why did it go offline? Oh, I can see the grid going offline, but how about a diesel generator? If you have a below sealer, And the water comes in. You're in big trouble now. They didn't have it like below, permanently below sea level and Fukushima. But when that tsunami wave came in, it was below sea level.

[00:36:20] They just, man, we could talk for a long time about the problems that they had over there. The nepotism, the line on the forums. They fact they did not do the upgrades that the manufacturer has suggested on and on. So these new reactors can lose all power and you won't have a China store. They won't go through a meltdown and they're even designed in such a way using physics things called the law of gravity, who would have thought, right?

[00:36:55] So that what happens in the worst case scenario is no one gets hurt. It just eats in on itself and then stops runs out of. So we've got to remember all of this stuff. Okay. The nuclear power of yesteryear is not the nuclear power of today. And the nuclear power of today is so green and so safe that even the European commission presented new draft rules that said to the natural gas, nuclear power, our agreement.

[00:37:33] Fuels for electricity generation. So assuming the rules are approved and Francis in favor, Germany isn't as into nuclear power. In fact, they plan on having all of their plants shut off by the end of 2025, which is crazy because they're already having serious problems with their solar and wind.

[00:37:57] And that's why they're buying so much natural gas now for. Yeah, American influence dropping over there. Thank you again, president Biden for allowing that pipeline to go through. All right. Anyhow. They're assuming they're approved Germany. Apparently isn't likely to try and block these rules. It means that nuclear, the new nuclear force generation or newer is going to be right there alongside renewables, like wind and solar on the list of the EUS technology that are approved for financial support.

[00:38:34] Now, this is very good news because as I mentioned earlier, What happens when it comes to solar at nighttime doesn't work solar. When it's raining, doesn't work solar. When it's snowing, doesn't work solar. When it's cloudy, doesn't work. Ryan, how about the windmills? When the wind is. They don't work when they break down, which happens a lot due to mechanical failures, they don't work.

[00:39:07] So having the. New nuclear plants that are intrinsically safe, that don't generate this really nasty radiation, and stuff that we have to store for a thousand years, et cetera. The high level nuclear waste makes a lot of sense because unlike the. Solar plants or other things that might be on someone's house that cannot be easily controlled by the central grid.

[00:39:37] In other words, Hey, stop generating electricity because I got enough right now. And what Germany has been doing is putting it into heat sinks, heating up lakes and other things, to get rid of that extra solar energy people are generating on their homes and businesses. What you can do is, Hey, we are at the point where we don't have enough sun.

[00:39:58] It's really cold. People are trying to heat their homes, or it's really hot. People are trying to cool to their homes. And yet it's raining heavily or there's a lot of clouds. So all you have to do at that point is turn off. That nuclear power plant or multiple plants. You see the way it's going.

[00:40:16] You're not going to have some massive plant with a bunch of reactors. No. Where they're going with this is to have community reactors in the multi megawatt range that can be put into communities and the power distributed directly. Into the community and these power plants are good for 20 years and these new ones, they are typically going to be buried in the.

[00:40:46] And then every 20 years they get dug up, put onto a truck, shipped off, they get recharged, brought back and you're off and running again, a whole different concept. And I love it. We're starting to do this in the United States. We've got some early approvals for some of these, and I was shocked and amazed and happy that the Biden administration has decided.

[00:41:10] To approve the new nuclear here in the United States. So there'll be some test plants going online relatively soon. That just makes so much sense. These 50 year old nuclear red regulations and plants, they just don't work. Make sure you visit me online. Craig peterson.com. I'm going to have a lot of stuff for you every week.

[00:41:36] Craig peterson.com.

[00:41:42] I hope weekend's going well for you. There's lots of fun stuff to do. And it's fun getting out of the house. Isn't it getting out, going out, going around. There's a, an outlet store close by where I live and it's one of these outdoor. Outlet things. And it was fun. Just walking around, enjoying the little bit of fresh air, no matter what the weather has.

[00:42:07] I even enjoy going up there when there's some snow on the ground. Because again, it's a little bit of a it's fun. It's a little bit of a change, which is not. Part of what I love about living in the Northeast. You really get all four seasons and they can be really nice. Black Friday of course came and went.

[00:42:26] It was not a bad black Friday, but one of the questions I am been asked all week long, all month long, frankly, has to do. When should I buy, what should I buy? What are the deals? And it is weird this year. Let me tell you really weird. And the reason I say that is I didn't my show prep. And I spent some hours just looking on different websites and looking at opinion pieces, looking at news sources, just trying to find, okay, what's going on?

[00:43:01] What's the real word out there. Our items, as rare as everybody seems to be saying they are, or is it easy enough to find. That's what we're going to talk about right now. Really. We've had a very turbulent two years for retail, every branch of retail, whatever it is, it's been terrible. So many people have lost their businesses.

[00:43:24] So many small businesses, small retail restaurants, some restaurants that I, I enjoy and just haven't been to in years, really. Completely gone, which is such a crying shame. And a lot of people have put a lot of the blame for the general retail malaise on Amazon and Walmart. Because again, I had a discussion just this last weekend with.

[00:43:56] Oh, a friend's father. And he was saying, wow, I've been a biologist in pharmacology for years. And th this is just as just a science, it's all science talking about the lockdown. And so I pointed out how let me see. I got family from Canada. They cannot drive across the border because of the lockdown, but in, in the states, they won't let us, we won't let them fly.

[00:44:21] But they are drive in, I should say, but they will let them fly in. How does that science, there's coronavirus not survive at 30,000 feet. Is that what it is? No, come on. People it's politics and part of the politics was. Walmart got to stay open and all of these other small businesses couldn't so what are they supposed to do?

[00:44:46] How are they supposed to compete? And, yeah. Hey, I understand you need clothes, right? And you need food. Most Walmarts have both. You might need medicine in order to even survive. So that kind of makes sense, but why. Walmart. Why did the government choose Walmart and target are going to survive all of you, little mom and pops stores, that maybe you've been multi-generational where it's your parents.

[00:45:16] And maybe even your grandparents that started the store, started the restaurant. And now all of a sudden there's a lockout and you cannot be over. It just, it entirely political. And I understand the science behind all of this. I have spent a lot of time studying it and you might remember if you've listened to me even.

[00:45:40] Dean or 20 years ago, I'm trying to remember when it was, I started talking with scientists about RNI, RNA interference and the coolest stuff that was happening with African violets and getting the purple flowers to change to white and all of the stuff they were doing. It's exciting. It's fun. But why.

[00:46:01] Did we use politics here. And so many people lost their livelihood. So many people lost their businesses. It's absolutely incredible. And just pain companies basically to stay closed. It doesn't make sense either. Because now you're pumping more money into the economy and that's causing inflation because there are not more products or not more vendors.

[00:46:23] There's not enough competition. So the prices go up. And when there's inflation, how about people who are retired, who have saved something. And now their money is worth what the inflation rates are. Again, it's a hidden tax, but it's really hard on retirees because their money that they've saved, they're getting the pitons, you put it in a savings account and you're making a fraction of 1%.

[00:46:51] And yet we're seeing inflation rates on things like fuel being almost a hundred percent. Think about what it was like in 2019, what the gas prices were. It is insane. So small businesses have to be supported. They are the backbone. They are the innovators. Walmart didn't start as a big company. They started very small.

[00:47:18] He innovated his claim to fame. That old Sam Walton was let's go ahead and have the best prices and anywhere. And so they got the best prices by beating up their suppliers, et cetera, but it all worked. And Walmart increased, raised its it's demonstrable again through real science, but they raised the standard of living in every community.

[00:47:47] They opened a store. It's absolutely funneling. But Walmart stopped innovating a long time ago. Now again, the innovations come just like they do in the tech world. Typically not from the existing companies, facebook isn't innovating, they bought WhatsApp, they bought so much of the technology they're using to drive their company.

[00:48:10] Oculus. You look at it, right? That's their future. According to of course Mr. Mark. What did it come from? What was the cost? They by their competition. So I want to encourage everybody to really try and go out of your way, try and shop at these small places. There are. And so many of these malls nowadays local stores where they've got together and they're running their co-op or where someone's managing a buying product from local craftsman, really that they, everything from these women that are knitting doilies all the way on out, through very cool black iron work things that you can find there.

[00:48:59] That maybe you can find on Amazon, maybe they come from China. Maybe they're locally sourced. Not very likely, but it's been a very tough time here for so many of these industries. One of the things that I did talk about this week, I, one of my radio appearances is. Tik TOK live shopping. If you haven't heard of tick tock is this short form video site.

[00:49:25] And it started by people saying, okay, with this song use that song to make a funny little 32nd. And 22nd and that's what people did. And it was really quite cool to see they there's some innovative people out there. Tick talk has a lot of, I share nowadays way more popular amongst the younger people than Facebook is become something for the older people.

[00:49:51] But what tech talk is now doing is providing live shop. And this is an innovation that really started in China, which of course is where tick-tock is located. But in 2020, there was a survey done that found that two thirds of Chinese consumers said that they bought products via live stream in the past year.

[00:50:15] So what's live stream. I want you to think about QVC online share or a television shop. Those channels, those infomercials that come on at night, but particularly the channels that are constantly selling stuff like micro did a little bit of that at one point in time, right? His interview was, he came in and the, he, the guy who was interviewing him, held up a pen.

[00:50:39] Is that okay, you sell me this pencil. And so micro went on and on for 10 minutes or more just talking about the pencil and everything related to the pencil and what a great quality was. All he course, she didn't know anything about it. And that's part of what bothers me about some of these things, right?

[00:50:56] These people are just making stuff up, but Tech-Talk live now is allowing you to go ahead and make funny little thing. Gain an audience. Maybe they're not funny. Maybe they're just informative. Have them inserted into people's streams and then sell it right there. In fact, instant purchasing of a featured product during a live stream.

[00:51:24] And then obviously audience participation, they got chat functions, reaction buttons. This is what's coming our way. And so all of you, small businesses out there, I really want to encourage you pay attention to social media. This is the sort of thing that you can do. You can target your local area, which is where most small businesses operate, right?

[00:51:50] It's in, in your town. It's maybe a 10, 20 mile radius, depending on what you're doing, what you're selling. And you can micro target nowadays. That's the joy. That's the beauty of the online world. Micro-targeting Hey, and if you're interested, let me know. We can talk a lot more about this because I have studied this for years now.

[00:52:13] Hey, stick around Craig peterson.com online.

[00:52:21] So while you're shopping online, what are some of the things you should do or look out for? I've got a few ideas. I'm going to tell you what I do, and it has worked wonders for me. So here we go.

[00:52:36] When you're shopping online, there are some obvious tips, just run through them very quickly because I don't, I think you guys being the best and the brightest really know these things.

[00:52:51] So just very quickly, make sure your security. Today, make sure that everything is patched up the way that it should be, that you have some really great anti-malware hopefully advanced anti-malware, but apply any updates before you start doing shopping, because this is a bad time of year to lose all of your personal information and to have your money stolen.

[00:53:18] Number two. If you're seeing an email or you're seeing a deal that really looks too good to be true. Take caution here. Do you see a place? Oh, I got five brand new Sony PlayStation fives for sale. You might not want. To buy those, right? The minister, Jeff Foxworthy hears your sign. So be careful about that.

[00:53:45] Criminals are really taking advantage of consumers who life's been tough, money's been tight. You're trying to find a deal. So be careful about that. Okay. Coupons or other way, the bad guys have been trying to get consumers. To compromise their own cyber security. Okay. 12% of emails out there are considered to be spam emails.

[00:54:12] I think it's more like 80% or 90%, but then I've had the same email address for 30 years. Okay. So don't click on link. Be sure you shop on the real website and apply coupons there by manually typing out the code. So for instance if let's say you use duck, go for your search engine, which you should be using for most cases, most searches a duck go says, okay, let me see where coupons here you go.

[00:54:41] Here's a site that has a lot of coupons be careful about those sites, because some of them are trying to lure you in. Are the websites you're going to the real ones, the legit one. Are you clicking a link in your email in order to get to that sale site? Double check, because what they're doing is using some of these URLs that aren't.

[00:55:08] And we see those all of the time. They'll have a misspelling of the business name or they'll do something else. So they might have Amazon Dodd bad guys.com. Oh, okay. Amazon. Okay. Is Amazon obviously they wouldn't say bad guys, but yeah. That's what they're doing. So be careful. So once you're on a website, look for that little padlock that's to the side, click on it and double.

[00:55:35] To make sure that it is legit because they might have us. What's called a secure, sir. And they might have a certificate that's valid for the site that you just went to, but it's not, there's a different kit for Amazon or Walmart or target or w whatever Joe's clothing.com. It might be something entirely different.

[00:55:58] So be careful, okay. Is what you're looking at on the ad. Because there are a lot of fake advertisements out there that looked like they got great deals. And even though black Friday has come and gone, they're going to continue to do this through the end of the year and be on. Okay. So rather than clicking on the ad, just type in the retailer.

[00:56:26] Information, because some of these ads that are showing up are in fact, almost every last one of them is coming from what's called an ad network. So that ad network is where people go and buy ads and they say, Hey, I want to retarget people that were at this site or clicked on this link, et cetera, et cetera.

[00:56:46] And now. If you are a bad guy, all you have to do is sneak into one of those big ad networks. And all of a sudden your bad guy ads are showing up everywhere. So you see a great ad for a Chromebook. For instance, we've talked about those before you can just go ahead. Okay. Chromebook. No problem. Wow. Yeah.

[00:57:05] Yeah. Type it in. If the ads for a Chromebook from Walmart, just type in walmart.com. Okay. Avoid clicking on ads. Isn't it terrible how bad it's gotten, man. I liked the internet better back in the 1980s and nineties. How should you pay? We're going to talk about that in a minute. Public why fi is a potential problem.

[00:57:31] The bad guys will often create fake hot spots and you are now using their hot spot. Now this isn't as much of a problem as a used to be because your visits to most websites nowadays are encrypted. Do you remember that lock? I mentioned in the URL. That means it is using SSL or TLS, which is a secure communications pro protocol.

[00:57:56] So if you're seeing that, you know that you basically have a VPN, you don't have to buy a VPM service. You don't have to use a VPN service. You have a VPN that's being provided by the website, your. And that's really what that lock means. So the public wifi is less of an issue for the monitoring, what you're doing, although yeah, they can still do some monitoring.

[00:58:22] They might play with DNS and things, but they can also scan you, which is the biggest problem from my perspective about using public wifi and never. Share your personal data. If you can avoid it, one of the things we're going to be covering in the upcoming boot camps and workshops is using fake or alternate email addresses.

[00:58:46] I do it all of the time. That's why I have 3000, 3000. Yes. You heard it right different log-ins right now in use active use on. In my password manager, at least over the last decade. So I've accumulated a lot of them. So I use a different email address pretty much all of the time. And I'll, I explain how to do that in the boot camps and workshops that are coming up.

[00:59:13] So keep an eye on. On my weekly emails again, Craig peterson.com/subscribe. So you can find out about them, these, the free ones. I really want to give you guys all of the basics, right? So that's what I'm going to be doing anyways. How should I pay? This is maybe the even bigger side of things. It is very rare that I actually put my credit card number in on a website at least.

[00:59:41] Real credit card number. There's a number of options that are available to you now that weren't before, even if it's not a credit card, even if it's a debit card and generically, this is known as single use credit cards. So we've got a few. I use typically capital one's email E N O. If you have a capital one card of any sort, this is a little browser plugin that you can put on.

[01:00:11] Now, the downside of this is they will by default, try and look. Every webpage you visit. So from their perspective, it's worth it because now they get that data from you. However, in all modern browsers, you can restrict when it runs. But what happens is I go to a website, it wants a credit card and I can pop up that little Eno browser plugin.

[01:00:40] And now. Todd I can generate a virtual credit card number that's tied in behind the scenes to my real credit card number. I can even put an expiration date on that credit card number. So it can't be used after a certain. Some of these virtual credit card options, even allow you to say, Hey, it really is only single use.

[01:01:04] It can only ever be used once. And that way the bad guys can't run up your credit card. Bill Citibank, American express, JP Morgan, and the more have these types of options and basically any visa or MasterCard. Look for virtual credit cards. From your bank or whoever's providing your credit card. Hey, stick around.

[01:01:28] You're listening to Craig Peterson and I'll be right back.

[01:01:33] We're going to talk a little bit now, since it's getting near the end of the year, about what kind of technology do we think is going to be big next year. And I've got to mention this project. My daughter has been working on it. Finally hit the ocean.

[01:01:49] My daughter has been busy. You might know she's been in the maritime industry for quite a while now.

[01:01:58] And a man, she went to, she graduated 2008. I think it was this daughter. And you probably already know I have five daughters, right? Three sons too. So it was a mix, but she has been working on a ship called the Yarra Burkland it's over in Norway. And what the ship is doing here is hauling fertilizer, anything.

[01:02:24] Oh, wow. Isn't that exciting? Wow. Craig, I'm so excited for you. It is the world's first autonomous electric ship period. Okay, cargo ship and what it is doing ultimately, is it to eliminating the need for about 40,000 truck round trips a year. See what's happening over there in Norway is there's a factory that's right.

[01:02:52] Located right next to a mine. That's making all of this fertilizer and it needs to be hauled down through some fjords. To get to the main shipping Depot where it can be loaded onto the big ocean ship. So these trucks are going up and over the mountains alongside the fjords. And this is a ship that's going to take a trip that's about seven and a half nautical mile.

[01:03:19] So give or take eight miles and on the water. And now Norway is doing this in its own waterways. So there's no problem with international rules and regulations about ships here. This is just local and it loads itself. It drives itself and it unloads itself. I think that's really cool. And what it does is it plugs itself.

[01:03:47] When it is on either port w now we've seen this with some ships, right? You might've been on some of these ferries that are electric. They work pretty well for electric ferries. Cause they're usually short haul. They connect up to shore power and they do a rapid charge and they're ready for. The next leg of their ship while they are busy taking all of their load in right.

[01:04:11] Makes sense. And you might've done it, but this is different. And a lot of the incidents that happen in shipping are due to human error. Think about all of the problems we've had with Navy ships, even running into things, human error, and a lot of that's due to fatigue. On the ships. I don't know if you know it.

[01:04:32] I have two kids that three actually that have been in the maritime industry the big maritime industry and they take four hour shifts. So four on four off four on four off every day. So fatigue is a very big deal for a lot of the shipping industry. And for the first few years, they're planning on having this ship be.

[01:04:58] They're going to be up, of course, on the bridge monitoring everything, because you got a problem with artificial intelligence machine learning. If a big ship is coming along and there's a kayak in the way, it's actually the kayaks job to get out of the way. But if you run over a kayaker things, aren't going to go very well for you, frankly.

[01:05:20] But how does a computer recognize that kayak? Maybe Marine life or even some sort of a swell that's out there. So they think they've got most of this solved. And this is the project that my daughter's been working on for a few years here. She's a Mariner. She has her captain's license unlimited. Tonnage unlimited vessels on unlimited waterways anywhere in the world is just incredible.

[01:05:49] All of the stuff she's done. So the wheelhouse could disappear all together, but they've got to make sure that everything is working pretty darn well. Okay. Large vessels. Do anything about the kayak? All they can do is warn, but they definitely can't maneuver. And that's why the deep draft vessels have priority over sailboats or pretty much anything else that's out there.

[01:06:14] But, and what that brings up is the fact that we don't have the regulations yet for these autonomous ship. We don't have the regulations yet for the autonomous cars, right? This is normal. The technology tends to proceed the regulations, and we have regulations in place right now for autonomous vehicles in certain areas.

[01:06:39] But they're nowhere near mature. It's going to take a while before everything is all frigging. And now that is leading us into our friends at Ford. Ford's done a couple of interesting announcements over the last couple of weeks. So I have to bring the. And an effort really to deal with this ongoing chip shortage.

[01:07:02] Ford has made a deal with global founders. Global foundries is a chip maker and they have a non-binding agreement. Now that makes it interesting. If it's non-binding. Why even bother, but the press release says opening the door for global foundries, deliver more chips to Ford in the short term, but what's happening right now because of the chip shortages.

[01:07:30] Companies are designing their own. Purpose built chips rather than relying on the general purpose chips made by Intel or AMD Qualcomm, Samsung and video media tech, depending on what kind of chips we're talking about. This is fascinating because it is hurting Intel. No question about it. And AMD. So what does Intel done?

[01:07:55] Intel is moving its stance to being more of a contracted chip manufacturer. So you can go to Intel and say, here's my chip design. Go ahead and make that forest. And off they'll go and they will manufacture it and then probably even help you with some of the design things. Fascinating. Now, the other thing that's been happening for a while is if you look at apple, for instance, they have been using their own chips in their I phones and eye pads.

[01:08:32] Now they also are using their own chips in the laptops and various desktop computers. So apple is the highest profile example I can think of offhand. That have replaced Intel's chips. That's absolutely amazing. Google has also created its own chip for the latest pixel phone. So if you buy the latest flagship pixel, which I would not do, because this is the first time they're really using their own chip, but they've got their own chip now in.

[01:09:09] Amazon has been deploying its own chips in its internal servers to improve performance as well as to make it better for the Alexa voice assistant. You see how long tail that's a marketing term, but really how special purpose designed purpose built chips are. So it's huge. Intel's changing course.

[01:09:35] They've never been a great chip designer. If he asked me and a few know my history, I've been down at the chip level. I was down there for many years in the kernel of operating systems and dealing directly with all. From chips, when you're thinking about drivers and the low end and the operating system, that's what I did for a lot of years.

[01:09:57] So I'm glad to see this happen. It's going to be better for you because the devices can be cheaper because they don't use a general purpose chip. The chip is built and designed. For what it's being used for. So good news there for four, because Ford is going to be doing the same sort of thing.

[01:10:18] I bet mark my words. Okay. I didn't get to the predictions for this year, but I will, when we get back this upcoming year, stick around, of course you listening to Craig, Peter Sohn, you can get all kinds of information. And in fact, if you sign up for my email list, which is not a heavy marketing.

[01:10:39] Believe me, you'll get a bunch of different special reports. So ones I think are going to help you out the most. Craig peterson.com.

[01:10:50] We just talked about the future when it comes to chips and our computers, we're going to continue that discuss discussion right now on artificial intelligence and machine learning. What else is going to be important next?

[01:11:06] You just got my basic predictions about what's going to happen with chip manufacturing. These various vendors of various devices are going to continue to move away from Intel AMD, et cetera, these general purpose chips and move more to special purpose chips.

[01:11:29] Now there's a number of special purpose type designs that have been out there for a very long time. For instance, a six OCB in industry. No, those I programmed some way back when. I have gotten much more complicated, but for instance, when we're putting in systems for a business, we will typically use Cisco systems that have a basics so that everything is extremely fast.

[01:11:56] You don't notice any delay and yet it can do very heavy duty filtering. Packet examination, stream examination, because it's being done in hardware. That's the advantage to it. So we're going to see more and more that since Apple's already moved to their own chips, Google has already moved to their own chips, Amazon, their own chips, et cetera.

[01:12:20] And there'll always be a need for general purpose chips. In fact, you can say that the apple chips for instance, are fairly. Purpose they're being used in your iOS devices, your iPhone, your iPad, but they're also being used in desktop applications. But if you look more closely at what Apple's done, it has a couple of different types.

[01:12:43] Of CPU's inside the chip. So it has the high performance CPU's that are only engaged when it needs some serious computing going on. It has the low power, lower performance CPU's that are also built into that same chip that now handle background tasks, things. Dated the don't need a whole lot of CPU or don't need to be really fast.

[01:13:09] And then it also has graphics processing units that will handle things like screen updates, moving stuff around on the screens. There is a lot of technology in that chip in reality, it's it would use to take three. Completely different sets of chips to do what the one apple chip can do. So it is an example of a special purpose CPU.

[01:13:38] We're going to be seeing more and more of those now as a consumer, you're not really going to notice other than, wow, this thing's fast or wow. This battery lasts forever. You're going to have some great functionality. And I think we are seeing, because they're spinning. $2 billion a week right now in the industry, you're going to be seeing more of these fabs come online, chip fabrication plants, and they take a long time to build and put up online, but they're going to be making more specialized chips, which I really.

[01:14:12] There's an article that came out based on a survey from the I Tripoli. And this is called the impact of technology in 2022. And beyond of these are some global technology leaders. Of course I Tripoli was all about electrical engineering back in the day today, it's more about general technology. But here's the results.

[01:14:37] What is important for next year? Now, remember, I don't give investment advice. So don't look at this as things you should be putting your money into. This is just stuff that is good to know and probably should be considered, but this is not again, investment advice. Technologies will be the most important in 2022.

[01:14:57] While according to this kind of little brain trust, if you will, amongst the respondents more than one in five, say that AI and machine learning are going to be very important. What's the difference between artificial intelligence and machine learning. The lines are blurred nowadays. They used to be a lot more clear machine learning used to be the machine, the computer learns it.

[01:15:24] Let's say it's working on a factory floor and it has to do some welding on a joint. And the, it has sensors and it learns, oh, okay. This part, when it comes into me may be here, but I might be there and I might be here. So I got move around a little bit. That's basic machine. Artificial intelligence, which I think is a super set of machine learning, but other people argue the other way, they don't know what they're talking about.

[01:15:50] There is artificial intelligence is where it doesn't even have to be taught how to learn. It. Just figures things out. So it's. When it's built, talk to learn where that piece that it needs to weld is likely going to be and how to find it. It just knows. Okay I'm supposed to weld. So how do I do that?

[01:16:16] That's much more of an artificial intelligence. So that's number one, artificial intelligence next. Cloud computing 20%. Now my opinion on cloud computing is not very high, frankly, because cloud is just the name for somebody else's computer cloud computing does not mean it's safer. It does not mean that it requires less work on your part where I think cloud computing can help a business is where.

[01:16:50] Push over flow to the cloud. The many businesses that have moved technology to the cloud have moved it back now because frankly, the cloud did not provide them with what they thought they'd get, which is cheaper, better computing. And a lot of the breaches that we're getting nowadays are in the cloud.

[01:17:13] People's databases being exposed, applications, being exposed. It's great for hackers because they know, okay, let me see. Amazon has the majority of all cloud computing in the world. So let's just scan Amazon computers and see what we can find. And they're going to find that this bank has this opener, that company has that database available, et cetera, et cetera.

[01:17:37] So be careful with that, but they think cloud's number two, five G. 17% that I am very excited about it. And here's why five G is a generic term for the high speed room wireless data. So think cell phone basically, but why it really matters is it's designed to handle billions of devices. So that you can have a lot of people sharing data and getting to data, sharing a network connection in a densely populated area.

[01:18:16] That's where it really shined. And then it also has a faster data rate than the older technology. One of the things you'll find as you compare, if you really dig into the technology compare, the various cell companies is that for instance, T mobile, which is who I use has a lower frequency spectrum.

[01:18:41] Lower frequencies can not carry as much data for, but what they can do, I'm really oversimplifying. But what they can do is more readily peers, glass, and brick and walls. So T-Mobile's frequencies are lower than Verizon, for instance. So Verizon can get you faster data. But can't get it into as many places and not as well as T-Mobile just really putting this quite simply.

[01:19:14] And in fact, just what was it? Two weeks ago, we had a court order stopping the deployment of these higher frequency, 5g networks. Because of complaints from some people particularly in the avionics, in the airline industry where they're saying they could be squashing some of our critical systems because they're using some of the old satellite frequencies for 5g up in the upper bands.

[01:19:42] Anyhow, one of the things that 5g. Which has already been used for is what I was involved with. I was involved with emergency medicine for a long time and I was an EMT I P D back in the day. So almost a paramedic. And think about what could happen now, you're in the back of an ambulance that you could be the hands for the doctor who can be seeing the patient as you're driving down the highway, bringing that person in, because historically I remember this one woman.

[01:20:16] Placenta previa and had just soaked through some towels with blood. She was in really bad shape and we were squeezing IVs to get fluid into her. It was incredible. It was something else. And we brought her right in on the gurney, in emergency room and right up to the operating room and put her on the table, right from her ambulance gurney while with five G.

[01:20:42] They can be doing that now, not just in an ambulance, but in, in more rural areas, doctors can be operating remotely on someone. It's very cool. This whole tele medicine, including remote surgery. It's huge. So these technology leaders agreed with me on that 24% is the number one most benefit for or five G telemedicine.

[01:21:08] Number two, remote learning and education 20%. Personal and professional day-to-day communications. Think of all of the stuff we're doing now, how much better that's going to get entertainment, sports, live streaming, manufacturing, and assembly transportation, traffic control. Now we're down to 7% and by the way, that's where the cars are talking to each other.

[01:21:31] If you have five G. You don't need a mesh because you can use 5g, carbon footprint reduction in energy efficiency. That's 5% and 2% farming and agriculture. Our farming equipment is already using GPS in order to plow fields, planned fields, harvest fields. It's amazing. So there you go. Those are the top pieces of technology that are predicted to influence us next year.

[01:22:01] I think it's absolutely correct. And I've got to give you a bit of good news here again. 97% of these people polled agree that their teams are working more closely than ever before. Because of these working from home workplace technologies and apps for office check-in, et cetera. Good news. All around.

[01:22:26] Hey, if you want more good news. If you want to know what's happening, even some bad news, I got the right place for you to go. I have five minute little trainings in my emails every week. I have bootcamps again, all of this is the freeze stuff. You imagine what the paid stuff is but I want you to understand this.

View Details

Have You Been Phished? Email Spoofing is in full swing!

In this video, I review what's happening right now. The how, why, and and you can do about it!

View Details

Do You Know How Hackers are Spoofing You? All About Email spoofing!

We just got an email this week from a customer and they're saying, "Oh no, my email has been hacked." What does that mean? Was it really hacked? We're going to talk right now about email spoofing, which is a very big deal.

[Following is an automated transcript]

[00:00:15] Email spoofing is being a problem for a long time, really? Since the 1970s. I remember when I got my first spoofed email back in the eighties and there was really a little bit of confusion.

[00:00:30] I went into it more detail, of course, being a very technical kind of guy, and looked behind the curtains, figured out what was going on. Just shook my head. I marveled at some people. Why would you do this sort of thing? The whole idea behind email spoofing is for you to receive an email, looks like it's from someone that it's not now, you've all seen examples of this.

[00:00:55] Everybody has. And those emails that are supposedly from the bank, or maybe from Amazon or some other type of business or family friend, this is part of what we call social engineering, where the bad guys are using a little bit about what they know about you, or maybe another person in order to. Frankly, fool you.

[00:01:19] That's what spoofing really is. There were a lot of email accounts that were hacked over the last what, 30, 40 years. And you might remember these people sending out an email saying, oh, my account got hacked because you just got emails. Back in the day, what people were trying to do is break into people's email accounts and then the bad guys after having broken in now knew everybody that was in the contact list from the account that was just broken into.

[00:01:54] Now they know, Hey, listen, this person sends an email. Maybe I can just pretend I'm them. Days it, the same thing still happens. But now typically what you're seeing is a more directed attack. So a person might even look in that email account that they've broken into and poke around a little bit and find out, oh, okay.

[00:02:16] So this person's account is a purchasing manager at a big company. So then they take the next step or maybe this tab after that and try and figure out. Okay, so now what do I do? Oh, okay. So really what I can do now is send fake purchase orders or send fake requests for money. I've seen in the past with clients that we've picked up because the email was acting strangely where a bad guy went ahead, found.

[00:02:49] Invoices that have been sent out by the purchasing person and the send the invoices out and changed the pay to information on the invoice. So they took the PDFs that they found on the file server of the invoices went in and changed them, change the account that they wanted, the funds ACH into. And once they had that happen, they just sent the invoice out again saying overdue.

[00:03:18] Off goes in the email and the company receives it and says, oh okay, I need to pay this invoice. Now. Sometimes it marked them overdue. Sometimes they didn't mark them overdue. I've seen both cases and now the money gets sent off and that invoice gets paid and then gets paid to the wrong person.

[00:03:38] Or maybe they go ahead and they don't send the invoice out, but they just send a little notification saying, Hey, our account has changed. Make sure you. Direct all future payments to this account. Instead. Now you might be thinking wait a second here. Now they send this email out. It's going to go into a bank account.

[00:03:57] I can recover the money while no, you can't. Because what they're doing is they are using mules. Now you've heard of meals before. He might've even seen that recent Clint Eastwood movie. I think it was called. But typically when we think of mules, as people we're thinking about people who are running drugs well, in this case, the bad guys use mules in order to move money around.

[00:04:24] And now sometimes the people know what they're doing. The FBI has had some really great arrests of some people who were doing this, particularly out in California, some of them cleaned. Yeah. I didn't know what was happening. It was just somebody, asked me to send money. It's like the Nigerian scam where the Nigeria in the Nigerian scam, they say, Hey I'm, I'm Nigerian prince, you've heard of these things before. And I need to get my money out of the country. I need to place to put them. And so if you have a us account, I'm going to transfer money into it. You can keep a thousand dollars of that 5,000 and I'm going to wire in just as a fee. Thanks for doing this. I, this is so important and it's such a hurry and I'm going to send you the.

[00:05:11] What they'll often do is send you a money order. It couldn't be a bank check, could be a lot of things, and then you go ahead and you cash it and oh, okay. Or cash just fine. And then you wire the $4,000 off to the bad guy. The bad guy gets the money and is off. Running in the meantime, your bank is trying to clear that bank check or that money order.

[00:05:38] And they find out that there is no money there because frankly what might've happened? I, this is one I've seen, I'm telling you about a story w we helped to solve this problem, but I had taken out a real money order from a bank, and then they made copies of it. Basically, they just forged it. And so they forged a hundred copies of it.

[00:06:01] So people thought they were getting a legitimate money order. And in some cases, the banks where the money order was, you mean deposited, did conf confirm it? They called up the source bank. Oh yeah. Yeah. That's a legit money order and then they all hit within a week or two. And now the, you are left holding the bag.

[00:06:22] So that's one thing that happens. But typically with these mules, the money comes to them in that account. They are supposed to then take that money and put it in their PayPal account and send it off to the next. And it might try jump to through two or three different people, and then it ends up overseas and the bad guys have gotten so good at this and have the cooperation of some small countries, sometimes bigger countries that they actually own.

[00:06:54] The bank overseas of the money ultimately gets transferred into. And of course there's no way to get the money back. It's a real. So with spoofing, they're trying to trick you into believing the emails from someone that you know, or someone that you can trust. Or as I said, maybe a business partner of some sort in most cases, it's some sort of a colleague, a vendor or a trusted brand.

[00:07:22] And so they exploit the trust that you have, and they ask you to do something or divulge information. They'll try and get you to do something. So there's more complexity tax. Like the ones that I just explained here that are going after financial employees, there might be some, an accountant, a bookkeeper, or bill payer and receivables payables.

[00:07:48] I've seen CFO attacks, but the really the spoofed email message looks legitimate on the surface. They'll use the legitimate logo of the company that they're trying to pretend that they're from. For instance, PayPal. Phishing attack. They have a spoofed email sender and typical email clients like you might be using for instance, on Microsoft outlook.

[00:08:13] The sender address is shown on the message, but most of the time nowadays the mail clients hide the actual email address, or if you just glance at it, it looks legit. You've seen those before these forged email headers. Yeah, it gets to be a problem. Now we use some software from Cisco that we buy.

[00:08:38] You have to buy. I think it's a thousand licenses at a time, but there were some others out there, Cisco again, by far the best and this, the software. Receives the email. So before it even ends up in the exchange server or somewhere else online, that email then goes through that Cisco server. They are comparing it to billions of other emails that they've seen, including in real time emails that are.

[00:09:06] Right now. And they'll look at the header of the email message. You can do that as well. With any email client, you can look at the header, Microsoft and outlook calls, it view source. But if you look at the email header, you'll see received. Headers that are in there. So say, receive colon from, and they'll give a name of a domain and then you'll see another received header and give another name of a machine.

[00:09:33] And it'll include the IP address might be IVF IPV four of your six, and you can then follow it all the way through. So what'll happen is partway through. You'll see, it took a hop that is. Not legitimate. That's where it comes in. Nowadays, if you have an email address for your business, man, a domain, you need to be publishing what are called SPF records.

[00:10:01] And those SPF records are looked at there compared to make sure that the email is properly signed and is from. The correct sender. There's a SPF records. There's a mother's too, that you should have in place, but you'll see that in the headers, if you're looking in the header. So it gets pretty complicated.

[00:10:24] The SPF, which is the sender policy framework is a security protocol standard. It's been around now for almost a decade. It's working in conjunction with what are called domain based message, authentication, reporting, and conformance. Heather's D mark headers to stop malware and phishing attacks. And they are very good if you use them properly, but unfortunately when I look, I would say it's still 95% of emails that are being sent by businesses are not using this email spoofing and protection.

[00:11:00] So have a look at that and I can send you a couple articles on it. If you're in trusted Craig Peterson.com.

[00:11:07] So we've established that email spoofing happens. What are the stats to this? And how can you further protect yourself from email spoofing? Particularly if you're not the technical type controlling DNS records, that's what's up right now.

[00:11:24] There's so much going on in the cybersecurity world. It affects all of us. Now, I think back to the good old days 40 years ago where we weren't worried about a lot of this stuff, spoofing, et cetera.

[00:11:38] But what we're talking about right now is 3.1 billion domain spoof. Emails sent every day. That's a huge thing. More than 90% of cyber attacks. Start with an email message. Email spoofing and phishing have had a worldwide impact costing probably $26 billion over the last five years. A couple of years ago, the FBI, this is 2019.

[00:12:09] Reported that about a house. A million cyber attacks were successful. 24% of them were email-based and the average scam tricked users out of $75,000. Yeah. So it's no wonder so many people are concerned about their email and whether or not those pieces of email are really a problem for them. And then anybody else.

[00:12:36] So a common attack that uses spoofing is CEO fraud, also known as business, email compromise. So this is where the attacker is spoofing or modifying, pretending to be a certain person that they're not they're impersonating an executive or owner, maybe of a business. And it targets. People in the financial accounting or accounts payable departments or even the engineering department.

[00:13:03] And that's what happened with one of our clients this week. They got a very interesting spoofed email. So even when you're smart and you're paying attention, you can be tricked the Canadian city treasurer. Tricked into transferring a hundred grand from taxpayer funds, Mattel tricked into sending 3 million to an accountant, China, a bank in Belgium, tricked into sending the attackers 70 million Euro.

[00:13:33] It happens and I have seen it personally with many businesses out there. So how do you protect yourself from email? Spoofing now, even with email security in place, there's some malicious email messages that are still going to get through to the inboxes. Now we're able to stop better than 96% of them just based on our stats.

[00:13:56] In fact, it's very rare that one gets through, but here are some things you can do and watch out for whether you're an employee responsible for financial decisions, or maybe you're someone who is. Personal email at work. Here's some tricks here. So get your pencil ready. Number one, never click links to access a web.

[00:14:20] Where you're asked to log in, always type in the official URL into your browser and authenticate on the browser. In other words, if you get an email from your bank or someone else, and there's a link in there to click that says, Hey oh man, here's some real problems. You got to respond right away.

[00:14:44] Don't do that go to paypal.com or your bank or your vendor's site, just type it into your browser, even though you can hover over the email link and see what it is. Sometimes it can be perfectly legitimate and yet it looks weird. For instance, when I send out my emails that people subscribe to that right there on Craig peterson.com, the links are going to come from the people that handle my email lists for me, because I send out thousands of emails at a time to people that have asked to get those emails.

[00:15:24] So I use a service and the services taking those links, modifying them somewhat in fact dramatically. And using that to make sure the delivery happened, people are opening it and that I'm not bothering you. So you can unsubscribe next step. You can, if you want to dig in more, look at the email headers.

[00:15:47] Now they're different for every email client. If you're using outlook, you have to select the email, basically in the left-hand side. Okay. You're going to control, click on that email and we'll come up and you'll see something that says view source. So in the outlook world, they hide it from you.

[00:16:07] If you're using a Mac and Mac mail, all you have to do is go to up in the menu bar email and view, header and cut off. There it is. I have many times in the past just left that turned on. So I'm always seeing the headers that reminds me to keep a look at those headers. So if you look in the header, And if the email sender is let me put it this way.

[00:16:33] If the person who is supposed to have sent it to you is doing headers proper, properly. You're going to see. A received SPF section of the headers and right in there, you can look for a pass or fail and response, and that'll tell you if it's legit. So in other words, let's use PayPal as an example, PayPal has these records that it publishes that say all of our emails are going to come from this server or that server of.

[00:17:06] And I do the same thing for my domains and we do the same thing for our clients domains. So it's something that you can really count on if you're doing it right, that this section of the headers. And that's why I was talking about earlier. If you have an email that your sending out from your domain and you don't have those proper headers in it, there's no way.

[00:17:33] To truly authenticate it. Now I go a step further and I use GPG in order to sign most of my emails. Now I don't do this for the trainings and other things, but direct personal emails from me will usually be cryptographically signed. So you can verify that it was me that sent it. Another thing you can do is copy and paste the text, the body of that email into a search engine.

[00:18:05] Of course I recommend duck go in most cases. And the chances are that frankly they've sent it to multiple people. That's why I was saying our Cisco based email filter. That's what it does, it looks for common portions of the body for emails that are known to be bad, be suspicious of email from official sources like the IRS, they're not going to be sending you email out of the blue most places. Aren't obviously don't open attachments from people that you don't. Special suspicious ones, particularly people we'll send PDFs that are infected. It's been a real problem. They'll send of course word docs, Excel docs, et cetera, as well.

[00:18:56] And the more. I have a sense of urgency or danger. That's a part of the email should really get your suspicions up, frankly, because suggesting something bad is going to happen. If you don't act quickly, that kind of gets around part of your brain and it's the fight or flight, right? Hey, I gotta take care of this.

[00:19:19] I gotta take care of this right away. Ah, and maybe you. So those are the main things that you can pay attention to. In the emails, if you are a tech person, and you're trying to figure this out, how can I make the emails safer for our company? You can always drop me an email as well. Me, M e@craigpeterson.com.

[00:19:45] I can send you to a couple of good sources. I'll have to put together a training as well on how to do this, but as individually. At least from my standpoint, a lot of this is common sense and unfortunately the bad guys have made it. So email is something we can no longer completely trust. Spoofing is a problem.

[00:20:07] As I said, we just saw it again this week. Thank goodness. It was all caught and stopped. The account was not. It was just a spoofed email from an account outside the organization that was act Craig peterson.com. Stick around.

[00:20:26]

[00:20:26] The value of crypto coins has been going down lately quite a bit across the board, not just Bitcoin, but the amount of crypto mining and crypto jacking going on. That hasn't gone down much at all.

[00:20:50] hi, I'm Craig Peter Sohn, your cyber security strategist. And you're listening to news radio, w G a N a M five 60 and FM nine. Point five, you can join me on the morning drive every Wednesday morning at 7 34, Matt and I go over some of the latest in news. You know about crypto coins, at least a little bit, right?

[00:21:18] These are the things like Bitcoin and others that are obstensively private, but in reality, aren't that private. If you receive coins and you spend coins, you are probably trackable. And if you can't spend that, the crypto currencies, why even bother getting it in the first place. One of the big drivers behind the price of these crypto currencies has been criminal activity.

[00:21:50] We've talked about that before. Here's the problem we're seeing more and more nowadays, even though the price of Bitcoin might go down 30%, which it has, and it's gone down in bigger chunks before. It does not mean that the bad guys don't want more of it. And what better way to mine, cryptocurrency then to not have to pay for.

[00:22:18] So the bad guys have been doing something called crypto jacking. This is where criminals are using really ransomware like tactics and poisoned website to get your computer, even your smartphone to mine, cryptocurrencies for. No mining, a Bitcoin can cost as much in electric bills that are in fact more in electric bills.

[00:22:45] Then you get from the value of the Bitcoin itself. So it's expensive for them to run it. Some countries like China have said, no, you're not doing it anymore because they're using so much electricity here in the U S we've even got crypto mining companies that are buying. Old power plant coal-fired or otherwise, and are generating their own electricity there locally in order to be able to mine cryptocurrencies efficiently, effectively so that they can make some profit from it.

[00:23:20] It's really quite the world out there. Some people have complained about their smartphone getting really hot. Their battery only lasts maybe an hour and it's supposed to last all day. Sometimes what's happened is your smartphone has been hijacked. It's been crypto jacked. So your smartphone, they're not designed to sit there and do heavy computing all day long.

[00:23:47] Like a workstation is even your regular desktop computer. Probably isn't. To be able to handle day long mining that has to happen. In fact, the most efficient way to do crypto mining of course is using specialized hardware, but that costs them money. So why not just crypto Jack? All right. There are two primary ways.

[00:24:11] Hackers have been getting victims, computers to secretly mine. Cryptocurrencies one is to trick them into loading. Crypto mining code onto their computers. So that's done through various types of fishing, light tactics. They get a legitimate looking email that tricks people into clicking on a link and the link runs code.

[00:24:32] Now what's interesting is you don't, even for cryptocurrency crypto jacket, you don't even have to download a program in. To have your computer start mining cryptocurrencies for the bad guys. They can use your browser to run a crypto mining script. And it runs in the background. As you work right, using up electricity, using up the CPU on your computer.

[00:25:00] They also will put it into ads. They'll put it on a website and your browser goes ahead and runs the code beautifully. So they're really trying to maximize their returns. That's the basics of crypto jacking what's been particularly bad lately has been the hackers breaking into cloud account. And then using those accounts to mine cryptocurrency, one of the trainings that I had on my Wednesday wisdoms has to do with password stuffing and my Wednesday wisdoms, you can get by just subscribing to my email over there@craigpeterson.com.

[00:25:46] But what happens here is they find your email address. They find. Password on one of these hacks that is occurred on the dark web. You weren't on the dark web, but your username or email address and password are there on the dark web. And then they just try it. So a big site like Amazon, or maybe it was your IBM also has cloud services can be sitting there running along very well, having fun.

[00:26:19] Life's good. And. Then they go ahead and try your email address and password to try and break in. Now, you know how I keep telling everybody use a good password manager and this week I actually changed my opinion on password managers. So you know, that I really like the password manager that you can get from one password.com.

[00:26:46] It really is fantastic. Particularly for businesses, various types of enterprises, one password.com. However, where I have changed is that some of these browsers nowadays, particularly thinking about Firefox Google Chrome safari, if you're particularly, if you're on a Mac, all have built in password managers that are actually.

[00:27:12] Good. Now they check. Have I been poned, which is a site I've talked to you guys about for years. To make sure that your accounts are reasonably safe than not being found on the dark web, the new password that it came up with or that you want to use. They check that as well. Make sure it's not in use. So here's an example here.

[00:27:34] This is a guy by the name of Chris. He lives out in Seattle, Washington, and he makes mobile apps for local publishers. Just this year, new year's day, he got an alert from Amazon web services. Now Amazon web services, of course, cloud service. They've got some really nice stuff, starting with light ship and going up from there, I've used various services from them for well, since they started offering the services over very many years and.

[00:28:06] They allow you to have a computer and you can get whatever size computer you want to, or fraction of a computer. You want to, he got this alert because it said that he owed more than $53,000 for a month's worth of hosts. Now his typical Amazon bill is between a hundred and 150 bucks a month. My typical Amazon bell is now 50 to maybe $80 a month.

[00:28:36] I cannot imagine getting a $53,000 bill from our friends at Amazon. So the poor guy was just totally freaking out, which is a very big deal. So I'm looking at an article from insider that you can find a business insider.com. They were able to confirm that, yes, indeed. He got this $53,000 bill from Amazon and yes, indeed.

[00:29:02] It looks like his account had been hacked by cryptocurrency miners. So these guys can run up just incredibly large charges for the raw computing power. They need to produce some of these digital cryptocurrencies, like Bitcoin there's many others out there. But this isn't new. This is happening all of the time.

[00:29:26] Google reported late last year, that 86% of account breaches on its Google cloud platform were used to perform cryptocurrency mining. So make sure you are using a good password manager that generates good passwords. And I have a special report on passwords. You can download it immediately when you sign up for.

[00:29:50] My email, my weekly email newsletter@craigpeterson.com and it tells you what to do, how to do it. What is a good password? What the thinking is because it's changed on passwords, but do that and use two factor authentication. Multi-factor authentication as well. And I talk about that in that special report too.

[00:30:13] And visit me online. Sign up right now. Craig Peterson.com.

[00:30:18] We're moving closer and closer to completely automated cars, but we want to talk right now about car hacks, because there was an interesting one this week that has to do with Tesla. And we'll talk about some of the other hacks on cars.

[00:30:34] Connected cars are coming our way in a very big way.

[00:30:40] We just talked about the shutdown of two G and 3g in our cars. We, it wasn't really our cars, right? Two G 3g. That was for our cell phones. That was. Years ago course now for four GLTE 5g, even 10 G is being used in the labs. Right now. It's hard to think about some of those older technologies, but they were being used and they were being used by cars, primarily for the navigation features.

[00:31:15] Some cars use these data links, if you will, that are really on the cell phone network in order to do remote things like remote start. For instance, I have a friend who's Subaru. Of course was using that. And now she's got to do an upgrade on her car because that 3g technology is going away depending on the carrier, by the way, some of it's going away sooner.

[00:31:43] Some of it's going away later, but it'll all be gone at the end of 2020. What are we looking at? As we look into the future, I'm really concerned. I don't want to buy one of these new cars at the same time as I do, because they are cool, but I don't want to buy one of those because of the real problem that we could have of what well of having that car.

[00:32:09] I need an upgrade and not been able to do it. I watched a video of a guy who took a Tesla that hadn't been damaged badly in a flood, and it was able to buy it for cheap. Why? Because Tesla will not sell you new motors and a new batteries for a car like that. So he got the car for cheap. He found a Chevy Camaro that had been wrecked, but its engine and transmission were just fine.

[00:32:39] He ripped everything out of the Tesla and went ahead after that, cause you got to clean that out, and water damage. You spray wash all to the inside. He got right down to the aluminum, everything that wasn't part of the core aluminum chassis was gone. And then he built it back up again. He managed to keep all of those Tesla systems working, that, that screen that you have upfront that does the temperature control, cruise maps, everything out.

[00:33:11] He kept that it was able to work. The, automated stuff, cruise control type stuff. And now he had a very hot car that looked like a Tesla. He took it out to SEMA, which is pretty cool. I'd love to see that, but it was a Tesla with a big V8 gasoline engine in it. He's done a, quite a good job on it.

[00:33:35] It was quite amazing to see it took them months. It was him and some of his buddies. These new cars are even more connected than my friend Subaru is they get downloads from the. Some of them are using Wi-Fi and 5g. Really one of the big promises of 5g is, Hey, our cars can talk to each other because now you can get a millisecond delay in going from one car to another versus what you have today, which can be a half a second or more, which can be the difference between having a rear end collision and being able to stop in time when it comes to these automated system.

[00:34:17] So they are more connected. They connect to the wifi in your homes. They connect to obviously the 5g network, which is where things are going right now. But what's happening with the hackers because really what we're talking about, isn't a computer on wheels. Oh no. Dozens of computers inside that car and your car has a network inside of it and has had for many years, this can bus network and even fancier ones nowadays that connect all of your systems together.

[00:34:52] So your entertainment system, for instance, is connected to this network. And that was used. You might remember a couple of years ago on a Chrysler product where the bad guy installed. Or using the thumb drive onto that entertainment system and had a reporter drive that car down the road. This is all known.

[00:35:16] It was all controlled. And was able to the bad guy right there, the demonstration in this case, I guess you'd call them a white hat hacker. He drove that car right off the road while the reporter was trying to steer otherwise because cars nowadays don't have a direct linkage between anything in any.

[00:35:38] That's why I love my 1980 Mercedes TESOL. You turn the steering wheel. It isn't actually connected to the wheels to that front end of the car. All it's doing is telling the computer you want to turn and how much you want to turn that brake pedal. Doesn't actually. Compress hydraulics and cause the brakes to engage that fuel pedal doesn't actually move the throttle on the car.

[00:36:03] The throttle is really being controlled and moved by the computers. So the car is completely electronic. It feels like a regular car, right? We're not talking about the Tesla's of today or tomorrow. We're talking about Volvos that have been sold for more than a decade. We're talking about a lot of different cars.

[00:36:24] So now you have a platform on wheels that can be dangerous because it can be, in some cases, remotely controlled, it can have software that may be crashes. We know that part of the infrastructure quote, unquote bill, which contains almost no infrastructure. It's amazing how they named these things. Isn't it.

[00:36:45] And what is it like 6% it actual infrastructure and the infrastructure bill? One of the things in there that is not infrastru. Is a demand, a law that says the car manufacturers have to include a remote. Button, if you will, so that a police officer could go ahead and say, okay, I'm pursuing this car and they're not stomping.

[00:37:11] I don't want to risk people's lives. As this bad guy tries to elude me here in backstreets. Kids can get hit, et cetera. So they push the button and the car stops that all sounds great. The problem is that you could potentially be opening some security problems by having this remote stop button that can be used by anybody really right.

[00:37:40] Since when is it going to be limited to just law enforcement? Isn't that a problem? According to Caren driver, I'm looking at their magazine right now. They're saying that there were at least 150 automotive cybersecurity incidents in twenty nineteen, a hundred and fifty incidents, part of a 94% year over year increase since 2016.

[00:38:05] In other words, every year. The number of automotive, cybersecurity and incidences has doubled. And that's according to report from a company called upstream security. So we're lost. So looking at what w maybe ransomware for a car. So that your car gets hacked. You can't hack my 1980 Mercedes diesel.

[00:38:28] It is impossible to hack into an unconnected car, but if you are driving a vehicle it's likely at risk from some sort of digital true. We've even seen from some of the bugs. We've seen cars from Japan that have decided to drive into the Jersey barrier because it misunderstands exactly what it is. We've seen cars from Tesla.

[00:38:57] Drive right into the back of a parked fire truck mentioned doing that at speed, right? And cause a fire truck full of water, et cetera. I've actually seen that one happened personally. So the more sophisticated the system is, the more connected your vehicle is. The more exposed you are in Detroit free press has a great little article on that right now.

[00:39:23] And in there he's saying we have taken. Whatever model car you think of. And we hack them through various places. I can control your steering. I can shut down and start your engine. Control your brakes, your doors, your wipers, open and close your. There's a lot of people who are trying to break into these cars.

[00:39:46] And there's a lot of people who are trying to protect them. That hacker duo back in 2015, who took control of that Jeep Cherokee, just think about that sort of. There's an Israeli based automotive cybersecurity company who told the free press that he expects the current trend of hackers, holding digital data on computers for ransom to also move to cars.

[00:40:12] So when this happens, the driver will not be able to start the vehicle until they pay off the rant. Or suffer the consequences, which could be wiping the cars systems operating systems could be Kenning the car to catch on fire. Think of what can happen with each generation with those batteries.

[00:40:32] There's no way around it. You're going to have to get it towed and get all of the software reloaded in the company. And now this week, it comes out that in 19 year old kid said that he was able to hack into over 25 Teslas that he tried via a bug in a popular. It's an open source tool that people are using to link into their Teslas to do various types of remote control.

[00:41:01] And he posted a tweet on this guy's name's David Colombo. You'll find them on Twitter, went viral and he reported the vulnerability to the people who are maintaining the software and they fixed it. In fact, the very same day and Tesla also pushed updates to their vehicle. That invalidated the signatures and the key exchanges that we're having.

[00:41:28] So this is a 19 year old researcher. He's able to hack into cars in 13 countries, 38, 13 countries. Yeah. Worth of Teslas without the owner's knowledge. No, he says I, I can not. Doors, I can turn off the security system. I can open windows. I keyless start and things turn on the stereo, honk the horn view, the cars location, and if the driver was present, but he doesn't think he could actually move the vehicle remotely, but that's a 19 year old.

[00:42:02] What's going to happen when we implement the law that was just passed that says our cars have to be remotely controllable by anybody basically. Yeah. It's scary. Hey, I want to invite you guys to take a minute, go to Craig peterson.com. Make sure you sign up for my newsletter there, and I'll keep you up to date on all of this stuff and you'll even get my show notes.

[00:42:28] Craig peterson.com.

[00:42:30] The hacker world got turned upside down this past week as Russian president Putin decided to crack down on the hackers. Now, this is a very big change for Russia. We're going to talk about my theories. Why did this happen?

[00:42:56] hi, I'm Craig Peterson, your cyber security expert. And you're listening to news radio, w G a N a M five 60 and FM 98.5. Hey, you can join me. Wednesday morning, did 7 34 on the morning drive. As we keep you up to date, russian hackers have long been known to go after basically whoever they want. They have really gone after the United States and other Western company countries.

[00:43:30] And as part of what they've been doing, they have been making a lot of money and keeping Vladimir Putin pretty darn happy. He's been a happy because they're bringing more. Into mother Russia, he's happy because they are causing confusion amongst Russia's competitors out there, particularly the United States.

[00:43:55] But there's one thing that Putin has been absolutely steadfast. And that is not allowing any of the hackers to go and hack any of the countries that are part of their little pact over there. Think of the old Warsaw pack they got that band back together. So as long as they didn't harm any Russian or, a affiliated country, They could do basically whatever they wanted and they did.

[00:44:29] And they have caused a lot of trouble all over the world. So Friday Russia. As security agency announced that it had arrested members of the cyber gang called reveal. Now we have talked about them for a long time. They have come and gone. The FBI and other countries have shut down their servers.

[00:44:56] So reveal disappears for awhile. Then pops his head up again. And Russia said that they arrested members of revival who were responsible for massive ransomware crimes against us companies the last year. So why would they do that? I'm looking right now at the Russian website here, that's part of the FSB.

[00:45:26] And it's saying that the Russian federal security service in cooperation, the investigation department of the ministry of internal affairs of Russia in the cities of Moscow St. Petersburg, Leningrad lips. As, I guess it is regions. They stop the illegal activities, a members of an organized criminal community and the basis for the search activities was the appeal of competent U S authorities who reported on the leader of the criminal community and his involvement in an encroachment on the information, sir, resources of foreign high tech companies by drusen militia software, encrypting information and extorting money for its decreased.

[00:46:11] Now that all sounds like the stuff that Vlad has been just a happy about in years past. So why did this happen? What brought this about nowadays in this day and age? What is he doing? I've got a little bit of a theory on that one because there have been some interesting development. One of them is this hacker.

[00:46:38] In Belarus. Now, Belarus is one of those countries that's closely affiliated with Russia friend of Russia, right? Part of the old Warsaw pact. And you might remember that Bella ruse is right there by you. And of course, we've got this whole issue with Ukraine and whether or not Russia is going to invade president and Biden said something incredibly stupid where he said, yeah a moral response is going to depend upon what Russia does, if it's just a minor invasion.

[00:47:17] You're you remember? The president Biden's saying that just absolutely ridiculous. And then of course, the white house press secretary and various Democrat operatives tried to walk the whole thing back, but it's a problem because Russia has, what is it now like 120,000 troops on the border.

[00:47:37] Now, if you know anything about history, you know that the military army. March on their stomachs, right? Isn't that the expression you've got to feed them. You have to have a lot of logistics in place. In fact, that's what really got a lot of the German military in world war two. Very nervous because they saw how good our logistics were, how good our supply chain was.

[00:48:03] We were even sending them. They cakes to men in the field that they discovered these cakes in great shape. And some of the German armies, particularly later in the war, didn't even have adequate food to eat. What do you think is happening with the Russian troops that are sitting there?

[00:48:20] They need food. They need supplies, including things like tanks, heavy artillery, ammunition. All of that sort of stuff. So how do they do that? They're moving it on rail, which they have done in Russia for a very long time. You might remember as well in world war II, the problems with the in compatibility between the German rail gauge and the Russian rail gauge as Germany tried to move their supplies on Russian rails and Soviet rails, ultimately, but on Russian rails and just wasn't able to do.

[00:48:57] So hacktivists in Bella ruse right there next to Ukraine said that they had infected the network of Bella Russa's state run railroad system with ransomware and would provide the decryption key. Only if Bella Reuss president stopped. Russian troops ahead of a possible invasion of Ukraine. So this group, they call themselves cyber partisans wrote on telegram.

[00:49:30] Now I got to warn everybody. Telegram is one of the worst places to post something. If you want some privacy, excuse me, some privacy, some security it's really bad. Okay. No two questions. So they have, apparently this is according to what they wrote on telegram. They have destroyed the backups as part of the pec low cyber campaign.

[00:49:55] They've encrypted the bulk of the servers, databases and work station. Of the Belarus railroad, dozens of databases have been attacked, including, and they name a bunch of the databases. Automation and security systems were deliberately not affected by a cyber attack in order to avoid emergency situations.

[00:50:20] They also said in a direct message that this campaign is targeting specific entities and government run companies with the goal of pressuring the Belarus government to release political prisoners. And stop Russian troops from entering Bellaruse to use its ground for the attacks on Ukraine. Now, this is frankly fascinating from a number of different angles.

[00:50:46] One is, it is very easy nowadays to become a cyber hacker. And in fact, it's so easy. You don't even have to do anything other than send N E. And it's been done, frankly. It's been done people who are upset with a, an ax, for instance upset with a particular company, you can go onto the dark web and you can find companies.

[00:51:13] And this revival company was one. That will provide you with the ransomware and they will do everything for you except get that ransomware onto a computer. So you could bring it in to an employer. You can send it by email to the ax. As I mentioned, you can do a lot of stuff. And then the. Ms. Cyber hacker guys, the bad guys will go ahead now and they will collect the ransom.

[00:51:43] They'll even do tech support to help the people buy Bitcoin or whatever currency they want to have used. And then they take a percentage. So they might take 30% of it. There's a whole lot. We can talk about here too, including trust among thieves and everything else. It is easy to do this. So to see an organization like these cyber partisans, which I'm assuming is an organization, it could be as little as one person taking ransomware, going into specific computer systems breaking in.

[00:52:18] Because again, even here in the U S how many of us have actually got their computer systems all patched up to date? The answer to that is pretty close to zero. And they can now go after a government, they can protect their friends. It's really something. When you start thinking about it, right? No longer do you have to be North Korea or China or Russia in order to hack someone to the point where they commit.

[00:52:51] And in this case, they're not even after the money, they just want these political prisoners freed and they want Russia to stop shipping in troops supplies, into the area in Belarus next to or close to. Very fascinating. There, there is a whole lot of information about this online. If you're interested, you can read more about it.

[00:53:15] It's in my newsletter, my show notes. I have links to some articles in there, but it really is a tool for the under. We've never really seen this before. It's quite an interesting turn in the whole ransomware narrative. It's just in crazy. That's a quote from a guy over at Sentinel one. Alright.

[00:53:40] Lots to consider and lots to know and do, and you can find out about all of the. One way, subscribe right now@craigpeterson.com. I promise. I'm not going to her Hess. You stick around.

[00:53:55] We've heard a lot about automated cars. And of course we talked about them a lot here too, but that original vision of what we would have, it's gone now. It's fascinating. We're going to talk about that journey of automated cars.

[00:54:12] For years, automakers have been telling this story about how these automated cars are going to drive themselves around and do just wonderful things for us.

[00:54:24] And as part of that, they've decided that. The way it's going to work. And I remember talking about this, cause I think it's a cool idea is that there will be fleet of these vehicles think about maybe an Uber or Lyft where you get on the phone and you order up a card and it says, Hey that driver will be here.

[00:54:45] Here's the license plate, the driver's name and picture. It's really cool, but general motors and Lyft haven't gotten there. They signed in agreement. To have electric autonomous cars as part of Lyft's fleet of drivers. They did a back in 2016, a long time ago. Ford promised what it called robo taxis and that they would debut by 2021 Dimeler of course, the company that makes Mercedes-Benz said it would work with Uber to deploy fleets of their car.

[00:55:27] And the logic was really financial and it made a lot of sense to me, which is why I was so excited. I have car outside. You know about my Mercedes, you. How often do I drive that 40 year old car? Most of the time it's sitting there parked, most of the time, because I don't go very many places very often.

[00:55:50] What would it be like then to just be able to have an Uber or Lyft type app on my phone that says, okay, tomorrow I have a 10 o'clock meeting in Boston and I want a car to take me there. So the. Checks with the servers and figures out. Okay. At 10 o'clock meaning, that means you're going to have to leave at eight 30 in order to get around the traffic that's normally happening.

[00:56:18] And so we'll have a car there for you. So all I have to do is walk out the apple, probably remind me, my butt out of bed and get outside. Cause the car is about to arrive. So the car pulls into my driveway or maybe just stops on the road and the app reminds me, Hey, the car's there I go out. I get in.

[00:56:37] And on the way down, I can work on getting ready for the meeting, getting some things done, just really kicking back, maybe having a nap as we go. And I'm there on time for my 10 o'clock. Just phenomenal. And from a financial standpoint, nowadays, how much is a car costing you? Have you ever done the math on that?

[00:56:59] How much does a typical car loan run you per month? And I also want to put in how about these leases? How many of us are leasing cars? My daughter leaves to Gargan believe she did that. Didn't leave to me. It didn't make financial sense, but maybe that's just because I've been around a while. But looking right now at some statistics from credit karma, they're saying us auto loans, new cars, your average monthly payment is $568.

[00:57:32] For an average loan term of 71 months. Good grief used cars, about $400. A month payment and average loan term, 65 months. I can't believe that I've never had a car loan for more than three years. Wow. That's incredible. So we're talking about six year notes on a new car. Wow. I guess that's because people buy cars based on the monthly payment, right?

[00:58:04] So figure that out. If you're paying $500 a month, how about just paying a subscription service? $500. You can get so many rides a month and you don't have to maintain the car. You don't have to buy insurance. You don't have to make any fixes. You don't have to do anything. And the car will just show up.

[00:58:23] That's what I was excited about. And it had some just amazing implications. If you think about it, it city dwell over dwellers and people who were directly in the suburbs, it'd be just phenomenal. And you could also have the robo taxis for longer trips. You can abandon that personal car. Really alternate.

[00:58:46] So now it's been about a decade into this self-driving car thing that was started. And, we were promised all of these cars, it reminds me of the fifties, we're all going to be driving, flying cars by. George Jetson one, when was he flying around the cities, but that's not happening.

[00:59:07] Okay. The progress on these automated vehicles has really slowed automakers and tech companies have missed all kinds of self-imposed deadlines for the autonomy. Look at what Elon Musk has promised again and again, it's. Basically in 2020, late 2020, it was going to have fully autonomous cars even calls itself dry.

[00:59:30] When it isn't really self-driving, it certainly isn't fully autonomous it more or less drives. It stays in the lane as it's driving down the highway. But the tech companies are looking for other ways to make money off of self-driving tech. Some of them have completely abandoned. There's self-driving cars, the sensors like the LIDAR, and I've had the LIDAR people on my show before they've all gotten cheaper.

[00:59:55] It doesn't cost you $50,000. Now just for one LIDAR sensor, think about what that means to these cars. So some of these manufacturers of these future autonomous cars are shifting to a new business strategy. And that is selling automated features directly to customers. In other words, you're going to buy a car, but that car isn't going to do much.

[01:00:24] Think about the golden key that the tech companies have used for years, right? IBM well-known for that, you buy a mainframe or from IBM or a mini computer from digital equipment corporation, and you have the same computer as someone that has this massive computer. But in fact the difference is that they turn off features and we're seeing that right now.

[01:00:49] I'm, I've mentioned that Subaru before where they are charging people for upgrades, but some of the companies are charging you monthly to use a remote start feature for instance, and many others. So what's happening is a major change. We have the consumer electronic show, right? January 20, 20 and general motors CEO, Mary Barra said that they would quote, aim to deliver our first personal autonomous vehicles as soon as the middle of this decade.

[01:01:22] So again, it slipped, right? I'm looking at it, a picture of what they're considering to be. The new Cadillac car that should be out next year. Maybe thereafter. It is gorgeous. Absolutely gorgeous. But this announcement, right? Yeah. We're going to have autonomous vehicles, middle of the 2020s. She had no specific details at all.

[01:01:48] And apparently this personal robo car project is completely separate from this robo taxi fleet that's been developed by GM's cruise subsidiary. And cruise said it has plans to launch a commercial service in San Francisco this year. So they're going after multiple paths. The logic here is financial.

[01:02:11] The reasoning has changed and they're offering autonomy as a feature for the consumer market. Tesla, Elon Musk, they've been charging $10,000 now for the autopilot driver assistance feature. They're planning on raising it to $12,000 here early 2022 Tesla technology. Can't drive a car by itself.

[01:02:37] But he's going to charge you if you want it. And I expect that's going to be true of all of the major manufacturer that's out there. And by the way, they're also looking at customization, like color changing cars and things. They're going to charge them as features. Hey, stick around. Visit me online.

[01:02:58] Craig peterson.com.

[01:03:01] Ju

[01:03:01] st

[01:03:01] how secure are our smartphones. We've got the iPhones, we've got Android out there. We've talked a little bit about this before, but new research is showing something I didn't really expect, frankly.

[01:03:23] hi, I'm Craig Peter sawn, your cybersecurity strategist. And you're listening to news radio w G a. A M five 60 and FM 98.5, like to invite you to join me on the morning, drive Wednesday mornings at 7 34, Matt and I always discussing the latest in cybersecurity technology. And, Matt always keeps you up to date.

[01:03:50] We've got some new research that wired had a great article about last week that is talking about the openings that iOS and Android security provide for anyone with the right tools. You're probably familiar at least vaguely with some cases where the FBI or other law enforcement agencies have gone to apple and tried to have.

[01:04:17] Old break into iPhones. Apples, refuse to do that one in particular, down in Southern California, where they tried to get apple to open up this I phone and tell them who was this person talking to after a shooting of foul of fellow employees at a. It was really something, there was a lot of tense times and we've seen for decades now, the federal government trying to gain access to our devices.

[01:04:51] They wanted a back door. And whenever you have a back door, there's a potential that someone's going to get in. So let's say you've got a. And your house has a front door. It has a backdoor, probably has some windows, but we'll ignore those for now. Okay. And you have guards posted at that front. All in someone needs to do is figure out to how to get into that back door.

[01:05:18] If they want to get into your house, it might be easy. It might be difficult, but they know there's a back door and they're going to figure out a way to get in. And maybe what they're going to do is find a friend that works for that security company, that post of the guards out front. And see if that friend can get a copy of the.

[01:05:39] That'll let them in the back door. And that's where we've had some real concerns over the year years here, a decades, frankly, our first, I remember this coming up during the Clinton administration, very big deal with the. That they were pushing. This was a cryptographic chip that they wanted every manufacturer to use if they wanted to have encryption and the white house and every gov federal government agency, and probably ultimately every local agency had the ability to break any encryption that was created by the clipper.

[01:06:17] In fact, we were able to track Saddam Hussein and his sons and his inner circle. Because he was using some encrypted phones that were being made by a company in England. And that company in England did have a back door into those encrypted phones. And so we were able to track them and we could listen in, on all of their communications back and forth.

[01:06:44] And it's really frankly, oppressed. When that sort of thing happens. So what do you do? What are you supposed to do? How can you make it so that your devices are safe? There are some ways to be relatively safe, but these cryptographers over Johns Hopkins university, Use some publicly available documentation that was available from apple and Google, as well as their own analysis.

[01:07:14] And they looked into Android and iOS encryption and they founded lacking. So they studied more than a decades worth of reports. How about which mobile security features had been bypassed had been a hack. I had been used by law enforcement and criminals in order to get into these phones. They got some of these hacking tools off of the dark web and other places, and they tried to figure.

[01:07:46] So we've got a quote here from Johns Hopkins, cryptographer, Matthew Green, who oversaw the research. It just really shocked me because I came into this project thinking that these phones are really protecting user data. Now I've come out of the project, thinking almost nothing is protected as much as it could be.

[01:08:10] So why do we need a backdoor for law enforcement? When the protections that these phones actually offer are so bad. Now there's some real interesting details of if you like this stuff, I followed cryptography for many decades. Now I've always found it. Fascinating. There are some lightweight things I'm going to touch on here.

[01:08:33] We won't get too deep in this, but here's another quote. Again, Johns Hopkins university on Android. You can not only attack the operating system level, but other different layers of software that can be vulnerable in different ways. Another quote here on iOS in particular, the infrastructure is in place for hierarchal encrypted.

[01:08:57] Now higher are hierarchical. Encryption is various layers of encryption. If you have an iPhone or an iPad, or if you have most Android phones nowadays, if you use a passcode in order to unlock the phone or even a fingerprint or a face. Your method of authentication is used to encrypt everything on the phone, but in reality, everything on the phone is only fully encrypted when the phone is powered off.

[01:09:36] Now that's a real, interesting thing to think about because obviously the phone can't work. If everything's encrypted. It needs access to the programs. It needs access to your data. So what they found bottom line was the only way to have a truly safe machine or a smartphone in this case is to turn it off because when you turn it on and it boots up on first boot, now it gets.

[01:10:08] Either by bio medical information, like your fingerprint or your face sprint or your passcode, it then has a key that it can use to decrypt things. So apple has on the iPhone, something, they call complete protection and that's again, when the iPhone has been turned off on boots up because the user has to unlock the device before anything can happen on the phone.

[01:10:33] And the is protections are very. Now you could be forced to unlock the phone by a bad guy, for instance, or in some cases, a warrant or an order from a judge, but forensic tools that, that they are using the police and the criminals really would have almost no luck at pulling information off of your phone.

[01:10:59] That would be useful at all because it would all be encrypted, right? If they could. So once you've unlocked your phone after that first reboot molt, after that reboot, right? You unlocked it after power up. A lot of the data moves into a different mode that apple calls protected until first user authentication.

[01:11:20] But it's what I call after first unlock. So when you think about it, your phone is almost always in the after first unlocks. Because how often do you reboot your phone? No, it's pretty rare that your phone might do on. And this is particularly true for I-phones might do updates and boot and reboot. And then of course you have to unlock that phone, but it doesn't go much further.

[01:11:49] The net and that's, what's interesting. That's how law enforcement and the bad guys, these Israeli companies and others have been able to get into iPhones and get into Android devices because ultimately if that computer is turned on and you've logged in, there's a lot of data. That's no longer encrypted.

[01:12:10] Oh. And by the way, that's also how some of these attacks occur on our laptops. Particularly if you traveled to. In the memory on that laptop that you close the lid on, you have to re log into is the key to UNHCR, unencrypt, everything, right? Because you logged in once. So all they have to do is freeze the memory, duplicate the memory and put it back in part of the reason, by the way that apple laptops have their memory soldered in you can't do that kind of attack.

[01:12:44] Stick around. We'll be right back.

[01:12:48] VPNs are good and they are bad. It depends on the type of VPN. Many of these commercial VPNs of people are using are actually very bad for you when it comes to your security.

[01:13:04] VPNs are problematic. I did a couple of boot camps on VPNs. Probably I think it was about last year.

[01:13:13] Yeah, it was last spring. And I went through and explained and showed exactly why commercial VPNs are one of the worst things you could possibly do if you want. To stay secure. Now I lemme just give you the high level here. I have given people copies of this, if you're interested in a link to that VPN webinar that I did, I'd be glad to send it to you.

[01:13:45] Just email me Emmy at Craig Peterson, doc. And ask me for the VPN information and I'll send that all off to you. I also wrote something up that I've been sending out to people that have asked about VPNs. Cause it's one of the most common questions we have Franklin, but here's your problem with commercial VPNs?

[01:14:05] Most all of them say, oh, your information safe at zero logging, et cetera. And yet we have found again and again that's not. In fact, it can't possibly be true in almost every case because most of these VPN services are running out of other people's data centers. So they might be in an Amazon data center or IBM or Microsoft.

[01:14:32] And inside that data center, your data is coming in and then it's going to. So let's say you're using a VPN and you're connecting to a website. I don't care. Go to google.com via a VPN. So you're using one of these services. That's advertised all over creation. And what happens now is. Your web request to get to Google passes over that encrypted VPN and comes to an exit point because at some point it has to get onto the regular internet.

[01:15:07] How else are you going to get to that website? On the other side? You can't, unless you get to the regular internet. So at the other side, now the server is that's receiving the end point of view. VPN is going to send the request to Google. Google is going to respond to that VPN server. It's going to be encrypted and sent back to you.

[01:15:30] So what's the problem with that? There's multiple problems. One is the data center can see. That there is the request going up to Google. Now he might not be able to tell who it was. But if that VPN server has been hacked. And let me tell you, it is a big target for hackers, government hackers, as well as bad guys.

[01:15:54] Then they do know who went out there and depending on how it was hacked and how the VPN was set up, they may even be able to see all of the data that you're sending back and forth. It's called a man in the middle of. And some of these VPN services do it by having you install some software on your computer.

[01:16:15] And as part of that installation, they provide you with a master key that they then use to spoon. The keys for the websites. You're going to some, explain that what happens is if you were to go right now on your web browser, go to Craig peterson.com as an example. So Craig peterson.com. I'm typing it in right now in the browser.

[01:16:43] That's directly in front of me. Now you'll see a little lock up in the URL. What does that mean? If you click on that lock, it says something about the connection being secure. Are you familiar with that? What's actually happening is it's using SSL TLS keys, but it's using encryption now to send the data from your computer.

[01:17:11] To my server, that's hosting Craig peterson.com. And then my server is sending all of the webpage back to you. Encrypted. Any fact, a VPN has been established between your web browser and my web server. So why use a third-party VB? Because your data is encrypted already, right? Could it be more simple than that?

[01:17:46] Now, remember again, that the server on the VPM service that you're using is a prime attack target for everybody else. As I said from government agencies through hackers. So your data is likely less safe because if they get a hold of it, they can do all kinds of things to your data and to. And then on top of it, all the VPN service may well be selling your data in order to make money, to support the VPN service because free VPNs, inexpensive VPN sees the ones that are charging you five or 10 bucks a month cannot possibly afford to provide you with that service.

[01:18:38] And in the bootcamp, I go through all of the numbers here, the costs involved. With a VPN service it's not possible to do. They can't make any money off of it. So it is a very big problem for you to use one of these public VPN services. Now, I want to talk about an arc article that was on Z.

[01:19:06] Apparently your old pole, which is of course the police over there in the European nations has seized servers. What servers, VPN servers in Europe. Now they seized the servers because they were used by who was it? Grandma looking at pictures of the grandkids. Was it people watching cat videos who was using the VPN server?

[01:19:33] The paid VPN service. Wow. It was criminals. And when they seized these VPN servers that were also being used by criminals, they found more than a hundred businesses that had fallen victims to attacks. So who uses VPN services? People who want to hide something as well as people who just want to have their data secure.

[01:20:01] Another reason not to use VPN services. So as a part of the joint action by Europol Germany's police Hanover police department, the FBI, UK national crime agency, and others seized 15 servers used by VPN lab dot. Okay. So VPN lab.net net, obviously no longer usable. And they started looking at all of the records that were being kept in these servers and use that to find the criminal.

[01:20:36] Does that make sense to you? So VPN lab.net was according to these charges, facilitating illicit activities, such as malware distribution. Other cases showed the services use in setting up infrastructure and communications behind ransomware campaigns, as well as the actual deployment of ransomware. You like that.

[01:20:59] Now they were using open VPN technology, which is actually very good. As part of that VPN information, I can send you if you're interested, just email me M e@craigpeterson.com. Let me know what you're interested in, and I'll whoop you off an email. Give me a few days I can get behind sometimes, but you can set up your own private VPN server if that's what you want to do.

[01:21:25] And I've gotten instructions on how to do that in that little special report in that email, but They were providing what they called online anonymity, this VPN lab.net service for as little as $60 a year. Okay. You like that? So they provided what they call double VPN servers and a lot of different countries and made it a popular choice for cyber criminals.

[01:21:52] Very big deal. Okay. So be very careful with VPNs. Also be careful of the VPN you might be using for your business. Let's say you've got something that isn't terribly secure or not secure at all as your firewall, right? So you buy a nice little firewall or this is so great. It's not expensive. And I got it online from a big box retailer.

[01:22:14] Most of them out there do not meet. The minimum standards you really need in order to keep your business. And there's only two companies that do one of them, Cisco, and one of them's Juniper, that's it? None of the other firewalls with VPNs meet the minimal standards you need to have, but those be glad to sell it to you.

[01:22:37] They'll be glad to tell you that it's perfectly secure, but it is not okay. Just went through that again with a company this week an engineering firm and at least they understand some of the stuff, but they were trying to do the right thing and they were being misled by these various vendors. So this action against VPN lab took place in January involved with authorities from Germany.

[01:23:03] The Netherlands Canada, Czech Republic, France, Hungary, Latvia, Ukraine, us UK, as well as your old pole. So there you go. You've gotta be careful don't trust VPNs, right? I've been saying that for a very long time. And then the other thing I want to. Is hopefully this summer we're going to be traveling.

[01:23:28] And when you're traveling, the temptation is to use public wifi might be at the hotel. It might be at a restaurant coffee shop, whatever. Okay. I admit to doing that myself. But here's two things you need to be careful with. One use, good DNS filtering. Now we sell and provide umbrella, which is a Cisco product, which is extremely good.

[01:23:56] DNS filtering. You can get free DNS filtering that isn't configurable, doesn't have the options, but is fantastic called open DNS. I've got, again, I did a bootcamp on that. I can send you information on it if you want. It doesn't cost you a dime for any of this stuff, but open DNS. And then the other thing I do, I have a high-end Cisco firewall and VPN.

[01:24:21] So when I'm on the road, even when I'm using data from the phone company, I have my secure VPN turned on FIPs compliant, by the way, for those who know what that means. Hey, visit me online. CraigPeterson.com. Get my show notes. Get my "Wednesday Wisdoms," everything. Craig peterson.com. It's easy to sign up right there on any page.

View Details

Do You Trust Homeland Security And The FBI For Your Cyber Security?

What a week the FBI got hacked, Homeland Security supposedly is sending out emails about hackers in your network. This is what we're going to talk about to start with today. What are these new emails and how are they trying to con you? And can we trust the Feds for our Cyber Security?

[Following is an automated transcript]

This is a little bit concerning. We know that the FBI's email system got hacked. And for everyone that's sitting there saying gee, if the FBI gets hacked, there's no way my business can possibly survive an attack. Remember that the FBI is a huge target. They have so many systems, so many people and the bad guys really would love to send email out as though they are the FBI.

[00:00:47] And in fact, they did, they used the FBI's email servers to send out some of these fake emails. I thought that was funny, but be that as it may, the FBI closed. But there are things you can do to protect yourself, to protect your email. And my wife and I have been working diligently on a guide.

[00:01:10] Now, that I protect businesses. I work closely with the FBI, been doing cyber security for more than 30 years. I hate to admit that. But I've been on the internet for more than 40 years. So I've been at this for a very long time and there are things you can do.

[00:01:29] So we're making available a guide. So she's taken a lot of my teachings and is boiled it down. It looks like it's going to be 25 ish pages. And it's just the key things, the primary things that you can do. To stop your email from getting hacked, your bank accounts, et cetera. There are some pretty simple things you can do.

[00:01:54] So we're putting that together and we're also putting together a bootcamp and both of these are free. Okay. Absolutely free. And in the bootcamp, again, this book isn't about selling you all of the, my services and stuff. It's giving you. Actionable things you can do. Yes, you can do. You don't need to be the FBI or a cybersecurity expert to do them, but five things you can do that will, I don't know, 10 X, your cybersecurity, really?

[00:02:30] It's that big a deal. And it's going to take you less than an hour to do all of this stuff. So for those people who like the boot camp, so we're going to have. And one of these zoom things and we're going to do it live and I'm going to explain it to you, spleen it. And you're going to have some homework before the bootcamp, because I want you to have some skin in the game too.

[00:02:56] You're not paying me or anything. So I want to make sure that you've done your homework so we can quickly. Go through all of the stuff that we need to cover in the bootcamp and people who are interested in being the example, which means they are going to get more information than anybody else.

[00:03:13] You can also say, Hey, listen, yeah, please use mine as an example. So we'll look at all of these different things. We're going to focus in on that first bootcamp primarily on. The stuff with passwords, what should you do? How should you do it? How can you tell if your password has been stolen? If your email accounts been compromised, all of that sort of thing.

[00:03:37] And you need to be on my email list in order to find out about this stuff. And in fact, when you sign. I've got three special reports that Karen and I wrote that are really going to be helpful for you. These are three that we've been using with our clients for years, but again, actionable. To do right, is not some marketing sales guy trying to sell you the latest, greatest piece of antivirus software that doesn't work.

[00:04:09] So you can get that. If you go to Craig peterson.com right now slash subscribe. If you want the deep link, Craig peterson.com/subscribe. We'll go ahead and sign you up. I have a little automated sequence. It's going to send you the emails with all of the attachments. We got one, that's an introduction to Karen and I, you get to see both of us.

[00:04:35] And it's a really cool picture of when we're on vacation one time and you can get all of that again. It's free. This is the free newsletter. This isn't the paid newsletter. Craig peterson.com. Slash subscribe. All right. So I can help you out with all of that free content. And I have lots of it. I'm on the radio every week talking about free, right.

[00:04:59] And you can avoid these things. So I hate to bring up this FBI hack because as I discussed again with Karen this week I don't want people to feel like there's nothing that they can do. I have a friend, her name's Laura and she's in one of my mastermind groups. And Laura is, was listening to me because another mastermind member got hacked and it had what was it?

[00:05:24] $45,000 ultimately stolen from him. And we helped him out. And so I was explaining, okay, so here's the things you can do. And. Basically all she heard was I'm never going to be able to do this. And she's a technical person. She teaches people how to become business analysts, which is pretty technical, there's a lot of steps involved in doing business and analyst work. And so I was really surprised to hear from her that she had. The securing herself was just too hard. The FBI gets hacked, et cetera. And so that's why when I came to this realization, the bottom line is, yeah. Okay. It can be hard if you're like me and you've been in doing this for 30 years, you've got the curse of knowledge, right?

[00:06:16] So all of this stuff, this isn't for you. If you know everything, okay, this is for people who. Quite understand what's going on. Definitely don't understand what they should do. Don't know what they should buy. Don't know how to use the free stuff that Microsoft and apple give you and how to pull it all together.

[00:06:37] That's what I want you to be able to understand, and we spend time every. Going through this and every newsletter. I have a, an opening now that is a lot about three to five minute read. If that it can be very quick read and is helping you to understand some of the things that you can and should do.

[00:07:00] So you'll get that as part of the newsletter. Again, Craig peterson.com. That's in my free newsletter. You should see the paid newsletter. It's a big deal because it's your life. It's a big deal because it's your business. It's a big deal because it's your job on the line. And most of the time, and when I pick up a new client, it's somebody who's the office manager.

[00:07:23] Frankly, more than your office manager, sometimes the business owner, owner operator says to the office manager, Hey, we got to do something about cybersecurity and then I get. Saying, Hey, can you do a cyber health assessment for us and that cyber health assessment, which we'll do for almost anybody out there will tell you the basic self.

[00:07:46] Okay. Here's what you got to do. You've got to update this. You should turn off this software or you should do this and that with your firewall so that they have. I a little checklist, that they can run through. That's the whole idea behind one of these cyber health assessment. And then what happens is they say, okay let's talk some more and we go in and talk with them, talk with the owner.

[00:08:12] Do they want to do, help them put together a more detailed plan and then they are off and running so they can do it themselves. They can hire someone, they can have us do it for them, whatever seems to make the most sense, but it's very important. To do it, to do something because sitting there trusting the Google's going to take care of you or apple or whomever, it is trusting Norton antivirus is going to take care of.

[00:08:43] I was reading a quote from John McAfee. He's the guy that started the whole antivirus industry. Now, of course, he passed away not too long ago, under suspicious circumstances, but he came out and said, Hey, listen, antivirus is. Because right now this year, these weren't his stats. These are stats published.

[00:09:04] You can find them online. Just duck, go them. Yeah. I don't use Google for most things. And you'll find that the antivirus is ineffective 77, 0% of the time. What do you need to do? You need to listen to me here because I am going to help keep you up to date here. Some people are auditory listeners.

[00:09:23] You need to make sure that you get the newsletter so that you get the weekly updates and you find out about these free trainings and special reports that we put together. Makes sense to you and you can attend the boot camps where we cover the basically one hour meetings on zoom, just like you're used to, and we cover one or more specific topics and we do it live and we use your information.

[00:09:54] The information you want us to have a, do you want us to share? So how could that be better? And it's the same sort of stuff, but deeper dives and more interactive obviously than radio. And you can listen to me here every week. I think it's important that you do, and you understand this stuff. So anyways ramble.

[00:10:14] It all starts with email. How do you keep your emails safe? You might remember years ago, you, people were getting broken into and emails were sent out using their accounts. That happened decades ago and it's still happening today. Right now, Craig peterson.com. I promise you. I am not a heavy marketer.

[00:10:36] Okay. You're going to get good, actionable information that you can put to use in a matter of minutes, Craig peterson.com/subscribe. Hey, stick around. I promise. I'll get you this department of Homeland security warning in just a minute. We'll be right back.

[00:10:59] Our intelligence monitoring indicates exfiltration of several of your virtualized clusters in a fist sophisticated chain attack. Your, I am trying to put on this like official voice. And it didn't do so well anyways, that's what we're going to talk about.

[00:11:14] This is an email that came from the department of Homeland security warning about hackers in our network.

[00:11:23] Okay. The subject line here, the one I'm looking at, and this is a justice week, urgent threat. In systems read the email goes on. We tried to black hole, the transit nodes used by this advanced persistent threat actor. However, there is a huge chance you will modify as attack with fast flux technologies. I don't know if that ties into a flux capacitor or not, which he proxies through.

[00:11:53] Multiple global accelerators. So this is somebody who doesn't really know what they're talking about. They're just throwing up big words. We identified the threat actor to be. Somebody whom is believed to be in of course, whom wrong usage of the word here is believed to be affiliated with the extortion gang, the dark overlord, comma, uppercase.

[00:12:18] We highly recommend you to check your systems and IDs monitoring. Be where this threat actor is currently working under the inspection of the NCC. I see, as we are dependent on some of his intelligence research, we cannot interfere physically within four hours, which could be enough time to cause severe damage to your infrastructure.

[00:12:44] Stay safe. USDA department of Homeland security, cyber threat detection and analysis network analysis. Total control panel. So this is classic when it comes to scammers. And the classic part is that you could do. Is the grammars bad. The wording is confusing, his punctuation is wrong and he's throwing out all whole bunch of words that are used when it comes to hackers.

[00:13:20] There are things like advanced, persistent threats. That's one of the biggest problems in fact, businesses have today. But in reality, the way he used it, Incorrect now that's something I would notice cause I've been doing this stuff for more than 30 years, but the average person is never going to notice something like this.

[00:13:44] So it's been pretty, in fact, pretty successful now, a little different than usual here. These fake messages don't have attachments. They don't have phone numbers. They don't have web links. Therefore what? Your email filter is not going to look at them and say, oh, these look risky. These URL links are going to risky sites.

[00:14:11] I'm going to block it. That's what we do. We have the advanced email filtering from Cisco that we use for our clients, or that includes their amazing artificial intelligence for fishing and stuff. So an email like this is not go. To trigger those types of alarms. So they're saying don't panic, avoid contacting the FBI for further details and ignore the accusations that are made in the email.

[00:14:39] This is so focused though. So flows is a cybersecurity company. They have a lot of stuff. They have some pretty good stuff. It's not there's not. But spam house is tracking it. Now, if you've ever been blacklisted, it's called black holing really by people who might've used your domain to send spam, or maybe you're a spammer, you've heard of spam house and I've been blacklisted before inappropriately.

[00:15:07] The good news is my. That I use for emailing is about 30 years old as well. So it's got a pretty good reputation over the years, but spam house is saying now that this is a scam they've been tracking it. It's a well-known scam and it's been widely circulated. To those office managers that I said are often the people who call us when there's a cybersecurity problem, or we get calls from office managers when something doesn't look right with the emails.

[00:15:44] And we have a client that had been getting these weird emails and. We were called saying, what's going on, have a look. We looked and we found all kinds of problems. So that again, an office manager approaching us and thinking everything's fine because they had Norton and they had the more advanced Symantec stuff and it didn't catch.

[00:16:09] Any of this really nasty stuff, but that's part of what Spamhaus does. And they're looking at it and saying, oh, okay, wait a minute. Now we're seeing these emails come out. They are definitely not coming from fbi.gov, which is what the return address is. And so spam house tags, it spam. Assassin's going to tag it and it's not even going to make it.

[00:16:37] Anything about a log on are our email filter. So a number of people have received it. If you've received this email, I'd love to know it because they really are trying to go after the people who are a little bit more into this now, how do they find them? Apparently? They have stolen the email addresses by scraping them from public sources.

[00:17:03] So databases published by Aaron, for instance, the American registry for internet numbers. And I'm assigned my own number is CP 2 0 5 because I was so early on by Aaron they're the guys that have been managing. The basic internet domain stuff here in the U S for very long time. And it also doesn't mean by the way that Aaron had any sort of a breach.

[00:17:28] And really just showing that the crooks behind this disinformation campaign have really been focusing on people who appear to be in network administration, because those are the email addresses and names that Aaron is going to have. So why are they doing this? Why are they sending it out into it's frankly, it's kinda hard to tell some of the emails have a QR code in them.

[00:17:58] Now that is intriguing because here's how, again, how a lot of these basic email filters work, they look at it, they say what links are in there? How many links, how much of the email is a graphic? And they understand while it's going to internet bad guys.com. There's the link right there. Forget about it.

[00:18:22] I'm not going to forward this email to the intended recipient, but if there's a QR code in that email to almost every email filter out through. It only looks like a graphic. So might've been a picture of your mother as far as it knows. Most of them are not very smart. So you getting an email, having a QR code in it and saying, oh, that's interesting.

[00:18:47] Let's check out that QR code. That's where the hazard com. All right. So be very careful fake news like this. It's not only unfair to the people who are accused in it, which is what happened here. They can be accusing your own it department. They can be accusing. People within your department, which is typically what's happening and then what they may try and do now that you don't trust your, it people, your security people, because they're mentioned by name in the email, but remember their names are probably scraped off of a.

[00:19:27] That you don't trust them. And now they attack you and you don't trust that you've been attacked. So fake news, a term coined by Hillary Clinton during hurricane campaign, but that's exactly what it is entirely fake. So this email, if you get one from Homeland security about threat actors in your systems, almost certain.

[00:19:51] Fake stick around. We've got a lot more coming up. Don't forget to subscribe. Get my weekly newsletter. I'm going to be published and even more, I think probably starting next month. I'm going to be sending a couple emails out a week because I got to get you guys up to speed so that you're ready for the upcoming bootcamp.

[00:20:13] Stick around.

[00:20:15] Everybody knows about the chip shortage, right? Computer chips. They're just hard to find. I'm hearing all kinds of ads from Dell lately on the radio. And they're saying just buy now. They're not selling new high-end machines anymore.

[00:20:30] This is a story from the verge about who has allegedly kinda stepped in about Intel's plans to increase chip production.

[00:20:42] And you'd think that the white house would be encouraging chip production. Considering the shortages, the justice week, it came out Tesla hasn't been delivering their electric car. Without USB ports. Other manufacturers are no longer providing you with an electric window for your car. It's a crank window.

[00:21:05] Car manufacturers did it to themselves, frankly, by stopping orders for chips during the lockdown, thinking that somehow people wouldn't need cars anymore. And yet their sales of cars went up and when they go. Yeah. Guess what happens to the price? The price goes up, right? Inflation. You have more money chasing fewer goods.

[00:21:29] So they really nailed themselves. Don't feel so sorry for some of these car manufacturers. We need more chips. I mentioned one of the manufacturers of PCs, the many of us use in our offices and Jews in our homes. Dell is a good company. They have been for a long time. However, you gotta be careful when you're buying computers because Dell makes very low end computers all the way up through good solid servers.

[00:21:58] Same. Thing's true with. P Hewlett, Packard, excuse me, Hewlett Packard. Remember those guys back in the day? Yeah. They also make everything from cheap computers that you never would buy should not buy all the way up through really good ones. It's like going to Walmart, you go to the Walmart and you don't want to buy any of the computer sitting there with one exception.

[00:22:24] And that is the Chromebook. If you buy a mid tier Chromebook at Walmart, you're going to get a good little computer. Doesn't run windows, doesn't run Microsoft office word, et cetera, but it can still edit those documents. And it's a very good machine that is kept up to date. Just watch the price $110 Chromebook, probably isn't going to last.

[00:22:48] It doesn't have much storage on it, et cetera. A $2,000 Chromebook is probably major overhead. So go somewhere in the $400 $500 range for a Chromebook, which is by the way where they're selling some of the laptops. Wouldn't those laptops, same price point. Now again, that's why I just wouldn't buy any of that.

[00:23:12] So we need more chips. We need higher end chips. They are very hard to get our hands on right now. We're talking about electrification of everything. And if you've heard me on the radio during morning drive time, I've been just bemoaning how the government's putting the horse before the. They're out there saying electric, and shutting down pipelines and coal mining and coal power plants.

[00:23:39] Although coal is one of the cleanest energy sources nowadays because of all of the scrubbing that's going on with the output of the coal plant. And also of course, they're, they've been stomping. Most of the nuclear plants from coming online, even though the new. Technology in nuclear is impossible to fail.

[00:24:01] They use basic physics to make sure that these things aren't going to do a Jane Fonda China's syndrome thing. Okay. So it's just crazy. We don't have the electrical. Even if we put up, it would take literally millions of wind farm, our turbines, and obviously millions of rooms and fields covered with solar cells.

[00:24:29] We would still need nuclear. We would still need other sources of power because the sun doesn't shine all the time and the wind doesn't blow all of the time. This is just completely backward. People aren't thinking it through. It's again, it's the knee jerk. And of course they're investing heavily. They being the congresspeople of themselves, particularly those Congress people like the Al Gore's of the world and Nancy Pelosi and Chuck Schumer, because they are forcing a move to this technology that isn't ready for prime time.

[00:25:05] And at the same time, we are trying to buy electric cars. How are we going to charge them? How are we going to run our homes? It's like Europe, people froze to death last winter in Europe. It's going to happen again this year. And the thing about what happened in Texas last year. Yeah. Some of that was because they weren't prepared, but guess what else happens?

[00:25:30] Sometimes the wind isn't blowing in Texas. So there's just all kinds of problems. So Intel is saying we got to increase our chip production. Intel's main business right now, by the way, he seems to be moving towards making chips on behalf of other people, other companies, rather than making their own chips.

[00:25:53] Isn't that kind of interesting. And the industry, the chip fab industry, the ones that fabricate the chips, make the chips are spending about $2 billion a week. According to the latest numbers I saw to try and expand the manufactured. Apparently Intel went to the white house because they want some of our tax dollars.

[00:26:17] The money they'd take at the point of a gun. They want some of that so that they can build their business, build it back better. And apparently some sources close to the situation told Bloomberg that Intel. Posed making silicone wafers in a Chinese factory, which could start production towards the end of next year.

[00:26:44] But in a move that I agree with had the Biden white house, apparently Intel was strongly discouraged due to potential security issues. Yeah, no kidding. Some major security issues here. We don't want to give away our technology to make this leading edge stuff. Think about the us. We were always the country that people came to for technology.

[00:27:15] I mentioned this week on the radio, the cotton gin way back when look at how much labor. That that cut look at the internal combustion engine. And again the Teamsters, the horses, the cleanup crews in New York city. All of that went goodbye pretty much because of technology and people got higher technology.

[00:27:40] Jobs and everyone became more efficient and that's, what's supposed to happen right now when right now waste, basically we have stagflation in other words, prices are going up, but we're not getting any more productivity out of it. That's a real problem. And that's why they keep talking about the problems we were having in the late seventies.

[00:28:01] And I remember those well, I remember gas lines sitting there in California waiting to buy gas. It was incredible what was happening out there. So Intel thinks it needs to secure funding from the federal government in order to ramp up the production. Bloomberg announced, Orwell said that Intel currently has no plans to produce silicone wafers in China after discussing it with governor.

[00:28:31] Officials and it will instead consider other solutions. Now I hope those other solutions are to make those plants, those chip fab plant here in the United States. Let's put ourselves back on a leading edge footing here. Google moved its artificial intelligence lab to China talking about. Anti American thing to do moved it to China, artificial intelligence.

[00:29:01] That's something we need. The us needs to be the world leader in some of these technologies. And frankly, we're not the leader anymore. It's it frankly, a. So you can check this out. It's on the verge. You'll also find it up on my website. Craig Peter sohn.com. Make sure you sign up for the newsletter so you can get all of these little trainings, five minutes a weekend can make a big difference.

[00:29:33] Craig peterson.com.

[00:29:35] Hey, I don't want to depress anyone, but Bitcoin is now a 13 year old teenager. And back in January, 2009, Bitcoin was priced at well. Wow. We'll get into this in just a minute.

[00:29:51] Bitcoin January 3rd, 2009 is when it was launched. And E Bitcoin was priced at you ready for this point?

[00:30:03] Zero 8 cents each. Okay. The and because of that, a lot of people. I have been seen we've got to get into this and that in fact, Elon Musk has been pushing up the price of another digital currency. All of the initial price increases in Bitcoin were due to fraud.

[00:30:26] According to a lot of reports and we can get into those if you'd like fraud. Yeah. That's a great way to launch a whole new product. And they also played some other games. For instance, the biggest driver of Bitcoin price for a long time was crux. For ransomware. Yeah. People had to buy ransom and pay ransoms.

[00:30:54] How do you pay a ransom while usually it was with Bitcoin and that meant you had to turn us dollars or other foreign currencies into Bitcoin. And as economists in the white house, don't seem to understand when there is more money tracing, a limited commodity, the price of the commodity goes up, whether it's gasoline, food, or Bitcoin, and that's exactly what happened.

[00:31:27] Percentage wise, how much of an increase has there been in the value of Bitcoin? Let me see here. If I can figure this out 7 billion, 750000000% increase. Isn't that something now of course we don't all have these magical glasses that let us look forward to figure it out. Out, but it's based on this peer to peer electronic cash system that was written about by someone or a group of people that went by the pseudonym of Natasha Nakamoto.

[00:32:07] And there've been a few people over the years who have claimed that they are the person that started it and maybe one of them is, and may be, none of them are who knows, but this was first published, October 31st, 2008. So about a month later is when it started to trade and it is just incredible here.

[00:32:29] Bitcoin was really perceived initially. Threat by government and financial institutions. I think it's still perceived as a threat. My government, they are able to track Bitcoin and other cryptocurrencies in many cases and the way they track it as well. If you have Bitcoin, what good is it? Unless you can use the Bitcoin to either buy something or to traded for us dollars or another hard currency, that's how they're tracking.

[00:33:03] Without getting into a lot of detail here, but it's interesting to look at because the Bitcoin white papers proposing a solution to prevent what they were calling double spending. And when you don't trust a third party necessarily, and that's where we got these logs, if you will, the. Balance sheets that were being used to track everything.

[00:33:29] And then you had the voting, you had to have 50% of these systems that were tracking all of the transactions, agree on a transaction, et cetera. And that's actually been a problem for Bitcoin because of the. Intermediaries, you have to go through or get to approve your transaction. It's a, frankly, a problem that's really slowed down transaction.

[00:33:57] So you can't just go like with a credit card and pay for something that's done. It can take your day or more. Now it's interesting that we're getting close to the ultimate limit of Bitcoin offerings. The blockchain's mind blocked number 707,000. Which by the way, offered a mining reward of six and a quarter Bitcoins.

[00:34:25] So think about that. It costs you more to mine, Bitcoins than they're worth. If you're trying to do it in the Northeast. Pretty much anywhere in the United States. So don't just run out and start doing it. My son and I don't know, five, eight years ago, something like that, we decided we'd start trying to do some mining and we didn't find any Bitcoins and it was just cooking some machines.

[00:34:50] And so we said, forget about it. And we gave out on it. It does have a hard cap. Then it's got a ways to go. I said, it's approaching. It is, but there's 21 million Bitcoin is the hard cap and the community that maintains the software and maintains Bitcoin because it is a committed. Has it been modifying the rules as time went around at about how many Bitcoin you get when you're mining something, into solving these problems and how the blockchain works.

[00:35:26] And how many honest and dishonest mentions were in the original Bitcoin white paper and how can they reject invalid blocks? So there's a lot of technical stuff going on and it's changing. All of the time. And ultimately it's the consensus mechanism that has been slowing it. So when it costs you more to mine, a Bitcoin than you get for it.

[00:35:54] So let's do a little bit of math here. If we say that how much is a Bitcoin worth right now? So we say current value of Bitcoin. I'm typing it in right now. So it's about $57,000. Per Bitcoin, if say 57,000 here we go. 57,000 times. What did I say? Six and a quarter, right? So $362,000 equivalent is what they, the person who mined this block was paying.

[00:36:32] That sounds pretty good. Doesn't it? Yeah, it really does. It adds up quite quickly. But when you consider that it costs more to mine, a Bitcoin than it costs, then you get to paid for it. 350, $6,000. That's a lot of electricity on a lot of hardware. And because of that, China has. Down Bitcoin mining operations, because it uses so much electricity and in the United States and in some other countries, but here in the U S and in the UK, some of these Bitcoin mining operations have been buying.

[00:37:11] Coal powered power plants, coal fired power plants so that they can produce their own electricity so they can make it worthwhile to mine. So things are going to change. They're going to be changing the rules. As I said, we've got a total of 21 million Bitcoin ultimately. And so far we've only just mined number 707,540.

[00:37:38] So the interchange, the rules, I'm going to keep an eye on this cause that's an interesting one. Elon Musk, his quote is Crip. Cryptocurrency is fundamentally aimed at reducing the power of a centralized government. And that by the way, can be one of the main reasons that Bitcoin hasn't been really adopted in the mainstream yet.

[00:37:58] And Ilan has all kinds of tweets. Bitcoin and other cryptocurrencies, he says, Bitcoin is my safe word. Isn't that? Something he's been primarily the guy behind Dodge coin, which is yet another crypto currency, D O G. Coyne D O G E coin doge, coin. And you can find that online. I think it has new doge even publicly traded while it's certainly traded as a crypto.

[00:38:28] Okay. So doge coin right now is worth 22 cents. It's down from its month, week, and day highs. I'm looking. Here. Yeah. Yeah. So it's gone up and down. It's been worth more. Yeah. A couple of weeks ago. So that's part of the problem with it. If you don't have money that you can absolutely waste, don't buy this stuff and I'm not an investment advisor, but I've never bought any Bitcoin or any other cryptocurrency.

[00:39:01] And the problem is, and from my perspective that it is not real at all. Yeah, you can say, look at this, I could have made 7000000% on that. You could do the same thing almost if you had, instead of buying a brand new Tesla model as eight years ago, seven years ago, and paying $77,000 for that.

[00:39:25] If you had bought $77,000 worth of Tesla stock, you'd be in the millions of dollars in value. And so we've got the Raven company out there. I don't know if you know these guys or not. I watched a motorcycle show. They're going from the tip of south America all the way on up to San Diego. And they had this Rivy and electric truck, which is really quite cool.

[00:39:52] They are public right now. They just won. And they have a market capitalization. In other words, a value of ribbon, which has only made a couple of dozen vehicles. That's it? Total. And they're owned by people who work for the company. Their market capitalization is 50% more. Then most of the major manufacturers out there, it's just crazy how much it is worth and why it's because people are looking at it saying Tesla appreciated 7000000%.

[00:40:30] Ravion's going to do the same. And by the way, they are cool cars. I love the idea behind. Electric vehicles. It's just that we got the cart before the horse who don't have the electricity. We're not making the hard decisions. We're just ripping stuff out. It's absolutely crazy. By the way, they had a 15% drop in the value of their shares on Wednesday.

[00:40:54] It'll go up. It'll go down. But it's w it's something we got to test remember? Okay. Cryptocurrency is not it yet of Tesla. Stock is worth something will probably always be worse. Something cryptocurrency is worth something, but tomorrow may be worth zero, and don't go crazy. These market caps of startup companies that have never done anything being worth 50% more than major us auto manufacturer.

[00:41:26] What that's crazy. Visit me online. Craig peterson.com.

[00:41:33] Clothing prices have been going up. In fact, apparel prices were up 4.2% in the last 12 months that as of August, we've got cotton going up. There's a whole bunch of things that are going up and a company out there called dress X thinks it has a solution for all of these prices.

[00:41:58] Hi everybody. I'm Craig Peterson, your cybersecurity strategist, and all around technology guru. And you're listening to news radio w G a. I am five 60 and FM 98.5. I like to invite you to join me on the morning drive right here on w G a N Wednesday mornings at seven 30. The clothing has been going up.

[00:42:26] Everything's been going up, I put some gas in my car the other day. I have a, you might know, of course, a 1980 Mercedes and my wife drives a nice little Ford edge, not a particularly big SUV, a, guest's a midsize SUV. And I put, I think it was about 15 gallon Zan and it costs me more. 55, $0. I can't believe it.

[00:42:57] We used to have a little diesel little Volkswagen Passat diesel. We would drive around and we were getting pretty close to 60 miles per gallon, around town. And diesel was about a buck, a gallon, and it cost 20 bucks to fill the silly thing up. And we could drive all the way down to New York city and back on.

[00:43:17] $20 worth of diesel one fill up. Okay. None of that's true anymore, is it? And we're looking at some increases. It's not like the kind of increase we've seen in certain foodstuffs or gasoline or eating oil. Apparel prices are up and there's a company out there that thinks that maybe they have a bit of a solution for you.

[00:43:41] It's called dress ex I found a video online of a young lady. Who's got a lot of followers, interesting lady. And she was trying them out. She'd tried a different dress or different clothes every day for a month. No, I did not watch all of the video, but I got the basic idea. And the idea is that people are buying digital clothes.

[00:44:09] Now I think of that for a minute. Would you pay for a designer? And maybe you wouldn't pay for designer dress, already and AOC is dress that she wore, the lady of the people only cost. What was it? $30,000. Per seat for her to go to that banquet. And I think her dress was like five or $6,000.

[00:44:33] You can get a dress just like AOC. That's designed by a high-end fashion designer for somewhere between 40 and $60. Okay, but it's a virtual dress. It's not a real dress, not in the real world. It's interesting what they're doing and trying to do. If you have used some of these online sites like Instagram, they have various types of what they call filters.

[00:45:01] So you can put a filter on you and there's like a makeup filter, for instance, that makes you look like you're all made up, it gets rid of all of the blemishes on. In, and there's other filters that do backgrounds and do different things and make you look like you're a kitty cat or whatever. They'd all kinds of crazy things.

[00:45:22] This company called dress ex has now come out with filters that you can use in their app. And they don't work too well right now, but people have been buying these digital close to. Now you don't wear them out. Okay. There, this is really like the King's new clothes. You might remember that story.

[00:45:46] And if all you have on are your digital clothes, you don't have anything on. However, what it does is if you're using their app and you're moving around and with their app, Paste these clothes on you. And it's a little funky right now. It's not the best, but you can bet that's exactly where it's going.

[00:46:09] And it reminds me of a blues, a Bruce Willis movie. I can't remember the name of it. And it's I think really bringing up a whole type of. Dysphoria that I think people are going to have more and more where you're living in this artificial life and that artificial life that you're in now that's called SIRA gets, I was just looking up as we were talking that artificial life that you're in is so nice.

[00:46:40] You don't want to live. In the real world. And I'm starting to see this now with things like dress X, which you'll find online, address x.com. You can now wear anything you want. You can use the filters that are available generally to change. Parents to change your ethnicity, to change anything you want.

[00:47:04] And if you ever saw Sarah gets, it was a very interesting movie. I liked it. I watched it because I generally like Bruce Willis and Rosa Mon pike, who were the two primary actors in this movie. But in the movie, everybody was just sitting there. And they were in these 3d chairs. And while you're in that chair, you could be anybody anywhere doing anything and literally anyone.

[00:47:32] And so you're sitting in the chair. If you can see around you, it looks real. It feels real everything about it is real, at least for the most part, but in reality, And none of it's real. And these people, they, some of them got out of those chairs and while they were out a nasty things happen to them. In fact, it was, he was a cop and they were investigating some murders of these people who were again, using what they were calling.

[00:48:05] Sarah gets nowadays with what our friends over at face. Or doing, you are going to see it called something else. Facebook, in case you didn't know Facebook changed its name. Now Facebook is still Facebook, but the parent company like Google split off and change the company name Facebook did the same thing.

[00:48:27] They're calling it. And the idea is to have this meta universe where again, just like in surrogates gets nothing is real, just like on dress ex you can wear any fashion you want to, and instead of paying thousands of dollars, you pay tens of dollars, basically. Now I mentioned that their video isn't very good.

[00:48:53] At least not yet over address X, but you can go to dress X. You can take photos of yourself and send them to dress X. They will go ahead and put whatever clothes you want to be. On you it's basically. Yeah, it's Photoshopping, but they do a pretty good job in general. I looked at a whole bunch of them, but it it, it looked pretty real.

[00:49:19] You don't have to consider the fit. You don't have to worry about how big you are because all of these clothes adjust, infinitely a store. Doesn't have to stock a bunch of them. So we're moving. This whole metaverse idea and these digital clothes, which are really a thing nowadays has vice said, vice.com.

[00:49:43] We're moving more and more to this unreal world and some real unreal fashions too. I'm looking at some of them and it's hard to even describe them. It looks like there's all of these. Things growing all over the clothes that are coming out and just doing all kinds of weird things. So there you go.

[00:50:06] I'm note on fashion. I'm looking right now at a picture that's right in front of the metropolitan museum of art in New York, and a lady is wearing one of the. Digital dresses. Now they tell you what you should be doing. And when you take that picture is aware of skin tight clothes so that they can match the digital close to you a little bit better.

[00:50:31] But w we'll see, she's saying that in this. Tweet at the, in front of the mat, she's saying I just can't wait for the met gala. What it will look like in 21, 21, because you know what, she's not wrong about this. It's really coined to change. There's some real cool stuff. Go to my website. If you want to see this, you can find it on vice, but I have a link to it.

[00:50:54] Just look for this. Show notes and you'll find it right there. In fact, you're getting even search for on my website because I have everything transcribed. Just look for digital clothes because there are thing now. Hey, I also want to talk a little bit here about. The the next little article, which is what's happening right now with apple.

[00:51:17] And you've probably heard about these ID cards in Austria right now, they are stopping people randomly and asking for their papers. They want your papers. If you are, have not been, they call it vaccinated. It's not a vaccine. Really. It's so funny to see the CDC change to the definition of vaccine, just so it meets their jab standards.

[00:51:45] But if you're not vaccinated, there's an immediate, it's about of $3,500 fine that the police officer will issue to you. And of course, there's police everywhere. Just stopping people randomly and asking for their papers. Apple is making various us states that have decided they want to use a digital ID card.

[00:52:11] For customer support. And also for some of the technology. Now, the initial idea behind this and apple has been working on it for a while, is that you can have your driver's license in the iPhone wallet, app, more secure. It's certainly more convenient for most people. Sometimes you might forget your wallet, but most people don't forget their iPhones.

[00:52:38] Yeah. The feature when combined with Apple's biometric security measures really could also cut down on fraud. So we've got about a half a dozen states right now that have signed up with apple and our pain part of the freight for these things. And when they pull you over and ask for your papers, you'll have them right there in your iPhone.

[00:53:00] Isn't that handy stick around. We got more to talk about. Thanks for joining. Today and visit me online. Craig peterson.com. Stick around.

[00:53:11] I had more than a little guilt installed in me when I was a kid. And I still hear to this day, there's a lot of people who had that right. There was your mother, maybe your father, but man this scammers are using it.

[00:53:26] This new scam is an interesting one.

[00:53:29] It's a consumer complaint, email scam, and it really is building on your fear of getting in trouble. At work, right? It's your fear of just basically getting in trouble? And man, my, did my mother ever beat that into me as a child. So the bad guys are using this now. Great article over at Sofos and they're naked security blog here.

[00:53:59] But the goal of these criminals is really to make you feel guilty, to convince you that if you don't excuse me, that you haven't done anything, you skip doing something, you, maybe you did something wrong and you've caused a serious inconvenience, not only to the company as a whole, but to someone more important than you inside the organization.

[00:54:26] Hey, I'm looking at an email right now. It's too Paul Deklan. It says, doc, I'm on my way to the sofa post office. Why didn't you inform us about the class customer complaint in PDF on you? Please call me back now. The main manager assistant is how it's signed. And it's got a link right there to what looks like a customer complaint for.

[00:54:51] Supposedly in PDF. So technically this is called spear fishing. It's a targeted attack and this greets you by name and it pretends to come from a manager in your company. So they've done a little bit of research on you and on the company, and that makes it something that really pops out. And because we're all used to ignoring the Nigerian prince scams and I helped to design a system.

[00:55:23] In fact, that got rid of those Nigerian prince scams and found some of the scammers. But have you ever had an angry customer who was yelling at you and said something like just you wait, I'm going to report you to your manager. It's scary. I'm going to ask like this, what did I do? I was at a McDonald's this week grabbing a double cheeseburger and the people who were running the drive-through were amazing.

[00:55:54] Simply amazing. And the guy who handed me the bag was, again, really great. These, you don't see this type of person very often in so many of these lower end, if you will, jobs. And so I asked to speak to the manager. And so the guy called over his managers says, I don't know what's up. And she came over and I congratulated her on how wonderful per team was that the lady that took the order was just as pleasant and helpful as can be.

[00:56:27] And the young man who handed me the food again, Greeted me nicely and just took care of everything. It was just absolutely amazing. But I could tell that he was worried about what I was going to say. Is he going to get in trouble because of something he did or didn't do with his manager? Cause he doesn't want.

[00:56:49] Fired obviously, but doesn't want to get down onto her bad side. How about if you got one of these types of messages in your mailbox, because if you're feeling guilty and you're afraid of what's going to happen, they have now activated a center in your brain. Basically the lizard level of the brain that is going to cause you to make mistakes.

[00:57:15] And you are going to hurry and feel guilty and click the link. It's just like that customer of ours, where he clicked the link in an email thinking it was from the better business bureau. It's the same sort of thing worried about, oh my gosh, what's going to happen here. Oh, no. Operations manager, the business.

[00:57:34] It can be a lot of trouble. The owners are really going to be upset with me and he opens it up. And what is it? It's ransomware now the good news is we were protecting them and since we were protecting them, the ransomware was stopped. In its tracks and that's what you want to have happen. But they were using the same psychological tactic.

[00:57:56] So we've gotta be careful, right? This is more believable than a dear colleague or hello. It's got your name in it. And when you look deeply in the headers, you'll see that it's fake. But from the basic text alone, Not so much so interesting. Interesting. Here's another one attention and your name dear you.

[00:58:21] You're in big trouble. I suggest you bring your coat. When you come to the meeting, yours sincerely, and it's got the outsourcing manager's name. As a signature. So yeah. Okay. The junior staff in these outsource jobs, like the frontline support, the pressure's high, you're getting these, you're going to make mistakes.

[00:58:43] So I just want to warn everyone. Watch for mistakes. Watch what you're doing. The these PDFs that they're sending you are not necessarily legit. You'll click on the link. It's going to have something that usually says something like a customer complaint PDF. You're going to download the thing. And then you're going to click on view my file.

[00:59:06] And of course, preview PDF is not really going to preview the PDF. In fact, in this particular case, Sofos is saying that it was a Microsoft app bundle. Okay. It's like a PKG format. So be very careful. The other thing that we've seen a lot of, and it's still happening now is aimed at Adobe.

[00:59:29] Now Adobe has had some horrible software from a cybersecurity standpoint, such as flash. You should no longer have flash on your machine at all. Apple has never directly supported flash. They never shipped it because of the major security problems and because of the issues that apple and Adobe had back and forth with each other, that's a kind of a separate thing.

[00:59:55] The PDF. Component Adobe reader that so many people have, you don't need it on a Mac is really rare. You need to preview the built-in Mac reader works great. And you can fill out the forms using just preview on a windows machine that doesn't have that feature. So you've got to get the Adobe PDF component knock yourself out and get it, but be careful because.

[01:00:23] It is one of the top things people are doing or using to lure you into downloading bad socks. So you can see in this particular case from Sofos, sometimes a trusted app with the check mark and it's totally bogus. Okay. If you click on trusted app, you'll see what purports to be a software bundle from Adobe in the us and the digital signals from an accounting firm in Southeast England.

[01:00:56] So it's all stuff to look at. Here's the bottom line. If you get an email like this and you're not. If it claims be from your bank, the IRS, you name it, reach out to them directly. Call them look them up. Do not use a phone number that's in the email. Do not use a phone number. That's in a link page, linked page from the email.

[01:01:22] Find out what their number is, call their customer support and find out if it's legit or con. Your security people to find out if it's legit, it's really that simple. Okay. Very simple. So check it out online again, this was a sofa article, but you'll see it at my website. Craig peterson.com. I also want to remind everybody in case you haven't heard, maybe it wouldn't be a reminder, right?

[01:01:48] That we're doing some boot camps starting up here in about them. Free cyber-security bootcamps are goon to teach you things you can do over the course of an hour that are going to 10 X, your cybersecurity stance. That's the whole goal of the boot camps and workshops stick around. We'll be right back.

[01:02:11] Craig peterson.com.

[01:02:13] What are the features these secure email providers are providing? What are the costs? Which ones might you want to consider? We're going to run through the top three right now. What are their features and why would you want to use them?

[01:02:30] We started talking a little bit about proton mail, some of the real basics here, and it is still the kind of 800 pound gorilla when it comes to secure email, finally they had to capitulate to the Swiss court because they are located in Switzerland.

[01:02:49] So just goes to show that even being Swiss doesn't mean that it is. Completely secured, then there's a difference too. I want to point out between having a government issue, a subpoena and a court order to have your information revealed. There's a big difference between that and a hacker who's trying to hack you and get into your life.

[01:03:16] So I think most of us understand that we need to be secure in our documents. We need to have that privacy is guaranteed to us from the constitution, but we also need to have one more level of security, which is okay. How. The hackers. So having a hack free life means you there's a lot of things that you have to be concerned about, email being one of them.

[01:03:43] So I'm not too worried about proton mail and the fact that they had a court order to. Provide IP addresses for a specific group of people. And it was a very small group and I can see that. I can agree with that. Proton mail does have a free version. That's the one I have because I want to try it out.

[01:04:06] And it has a 500 megabytes of free. The storage, you can get up to 20 gigabytes and proton mail starts at $4 a month. It has end-to-end encryption, which is really important. Again, it means from you all the way to the recipient, all three of these that I'm going to talk about have end-to-end encryption.

[01:04:32] They also all have. Two-factor authentication. Remember when we're talking about two factor authentication, a lot of places try to pass off this thing where they send you a text message with a number in it. They try and pass that off as two factor authentication. Yeah, it is a type of two factor authentication, but it's not a.

[01:04:53] If you're already doing something like maybe you've got cryptocurrency, you are potentially not only under attack, but I'm very hackable. If you're using a text message in order to verify who you are. So that's an important thing to remember. Proton mail has self-destructing messages, which is a very big thing, very positive.

[01:05:18] It tends to be expensive. Proton mail being the 800 pound gorilla kinda dictates what kind of price they want to charge and they are on the more expensive. Side the web client is a little bit on the outdated side. It does not support pop three, which I doubt is an issue for any of you guys out there because nowadays the modern email clients aren't using.

[01:05:45] Anyways, any more now proton mail has PGP support. I use PGP, I have a built into my Mac mail and it allows me to send and receive end to end encrypted messages. And that's something you might want to look at a plugin that uses PGP or GPG, which is effectively the same. Which allows you to send and receive encrypted email using your regular email client.

[01:06:15] However, the person who's receiving it the far end has to have that PGP client or GPG client as it is. So it might not be the best idea in the world to use that. I use it and I use it for. People within the organization that I know have PGP, because again, we're dealing with third parties information.

[01:06:38] We have clients and the clients trust us. So we have to be pretty darn careful with some of that stuff. So that's our first one, proton mail. It's something I've used. I know a lot of you are using it. I had so many responses to that email that I sent out to everybody talking about secure email and specifically proton mail.

[01:07:00] And you guys were all telling me, Hey, listen, I'm switched on I'm away from Google forever because Google is by far the least secure of anybody you could be using out there. Now, the next one is called Tata. To U T a N OTA. So it gets just what Tatan call 10 town, tow hours, something like that, but a N O T a I'm sure you guys are gonna all send me pronunciation guides and it has again, a free version, one gigabyte.

[01:07:34] So twice as much as proton mail and it doesn't really offer quite as much storage, but it starts at a dollar 18 month. Down from proton mail's four bucks a month. It also has end to end. Encryption also has two factor authentication. It has an encrypted search function, a calendar function, and aliases. I use aliases not only for my hack free life, but I use aliases because I will.

[01:08:04] To use a different email address for pretty much everybody I'm dealing with. So these, this way to do that is with an alias. One of the problems here with top I, this is a German company. I bet you it's a German word. Somehow Tottan TOA is that it is injured. Germany is one of those 14 eyes countries. That means it's one of the 14 countries, large countries that share information about people online and spy on each others.

[01:08:42] Citizens. See, that's how the government's gotten around it. The government have preclusions from monitoring citizens. So what did they do while they all get together, serve with the five eyes now once twenty-something eyes, but they're part of the 14 eyes agreement. So Germany, for instance, would spy on us citizens while they're in the U S.

[01:09:07] And the U S will spy on German citizens while they're in Germany and all over the world. Okay. So that's a negative, however, as a general rule, the European union has pretty good privacy laws, so you're probably safe. And then the third one, which is again, the third in my priorities here too, is called counter mail.

[01:09:33] Now it has. Interesting features, for instance, they have what are called Ram only servers. So the server boots up, obviously it has to boot off of some sort of a device, but once it's running, everything's in memory. So if that server loses power, it loses everything. Now that's an interesting thing to do and can be a problem if you're trying to store emails, right?

[01:10:01] It has men in the middle attack protection, which all of these due to one degree or another, but counter male makes that a kind of a big deal. They have a safe box and anonymous payment systems that you can use. And it starts at $3 and 29 cents a month. They have a four gig storage limit. They do not have a free version.

[01:10:23] So I liked this one counter mail, but I do use proton mail, at least for testing. Some mothers also rans here that allow you to send and receive encrypted mail. Secured mail is Zoho mail, Z O H O mail. The X, Y Z is another one post steel. So I've used Zoho before, by the way post geo P O S T E O.

[01:10:51] You might want to look@mailbox.org and start mail. So there you go. Top three proton mail. That's still my recommendation. If you want some secure email and it'll cost you a bit, if you want cheaper, look at this two U T a N O T. T U T a N O T a. All right, everybody make sure you spend right now about a minute.

[01:11:16] Go to Craig peterson.com and sign up for my weekly newsletter and training.

[01:11:22] Is there no such an example of Silicon valley and they're a attitude of fake it until you make it, or is it the reality of Silicon valley? What's happening out there? We work in another.

[01:11:43] Hi, I'm Craig Peter Sohn, cybersecurity strategist. And you're listening to me on news radio, w G a N a M five 60 and FM and 98.5. You can listen to me anytime, anywhere, just grab the tune in app and type in w G a N, or pull out your smartphone. It's all there. Theranose. How many of you guys know about therum knows they had a really great idea and it was started in 2003 by a 19 year old young lady named Elizabeth Holmes.

[01:12:24] That is pretty young, but her idea was why do we need to have a whole tube or more of blood in order to do blood? With the technology we have nowadays, we should be able to just use a drop of blood and be able to test for hundreds of diseases with just a pinprick of blood. It seemed pretty incredible at the time, but she was able to.

[01:12:51] Been a yarn that got a lot of people right into investing in her company. We're talking about nearly a billion dollars in capital that was put into their nose. How could she have fooled all of these people or was she fooling them? Was she doing what you expect to have done in Silicon valley? That is in fact the argument that her attorneys are using right now.

[01:13:21] She is on trial because this company Theranose was never able to produce and tests. They could just take out a drop of blood and run hundreds of tests on it. And there's a lot of evidence that has come out that has shown in fact, a great little documentary that I watched not little on her and the company Theranose.

[01:13:47] That showed that they had in fact, been taking vials of blood and using other people's equipment, not the Theranose equipment to do the valuations of the blood, to look for diseases, to look for things like vitamin D deficiency that is in fact, something that could have helped with this whole COVID-19 thing.

[01:14:10] A real quick. Check a vitamin D levels in your blood, but what happened? Elizabeth Holmes was really a great talker. She was able to convince a lot of people and a lot of businesses, including Walgreens to invest in her. Not only did she have Walgreens invest in her, but some of the biggest names that you can think of in the investing community, including Rupert Murdoch, he invested in fairness.

[01:14:41] Now her argument in her, or at least her attorney's argument is, Hey, listen, we're not doing anything differently than any other Silicon valley company that's out there. It's this whole creed that they have of fake it until you make it. Is that legit. Is it just one more live from Silicon valley? There's a great article that was in Forbes, talking about some of these, what are called unicorns.

[01:15:11] These are companies that are startups and are taken under the wing by investors, starting with angels, and then moving into venture capitalist, actually, even before angel. Friends and family and moving into venture capitalist positions, and then eventually public companies, all of these businesses really required proof before they got any funding.

[01:15:37] So here's an example from Forbes, Airbnb. Obviously they, hadn't what we consider today to be a rather unique business model. But it had been tried before. The whole assumption was that people would rent rooms in their homes on this huge scale, but they didn't have any. They were the first to make it in this global trend, they built up this whole idea of becoming a hotelier yourself with your home.

[01:16:08] But when the founder, Brian Chesky tried to get angel capital, he did not get a dime. He had to prove that renters were interested and people were interested in renting out their homes and that he could pull them together. Once he proved that, then he was able to get the money and prove is you. To have a viable business.

[01:16:34] First, it's really rare that you don't have to, Facebook was started by Zuckerberg now, all of those stories, but the whole idea was having Harvard students connect with the. And then he expanded it to students and other universities and then expanded it to the world at large, his natural initial investors, like most are friends and family, people who give the money to you because they want to see you successful.

[01:17:01] Eventually. Zuckerberg was able to prove it and get money from Silicon valley. And then VCs, I'm not getting into any of the ethics of how he did it or any of these other people that had Google. Google was started by these two Stanford students page and Brin, and they got angel capital from investors.

[01:17:24] And, but these investors were different than most the investors into Google, where people who were already very successful in the computer industry and could understand the ideas behind the algorithm and believed in page and Brynn and that they could grow this company. Microsoft. Again, another company that started with a extremely questionable methods was started by gates.

[01:17:52] And now. They didn't have any VCs, either. They started by running programs for other people. They convinced IBM that they needed to license an operating system from Microsoft and Microsoft didn't even have the rights to, and then they went out and acquired it on a non-exclusive basis. IBM acquired it from Microsoft and non-excludable exclusive basis.

[01:18:15] Then they got VC money after they started to take off. Okay. Amazon was started by bayzos with funding from his family and small investors from Seattle. He got a VC from Silicon valley after he launched and was already earning thousands in revenues. Bezos had real proof. Walmart was started by Sam Walton with 25 grand from his father-in-law.

[01:18:43] He built this business and financing strategy and used his skills to become one of the world's most successful companies as he grew. We work. I don't know if you've seen these. There's a great documentary out there. And we work that I watched too, but again, like Elizabeth Holmes, he was a great guy at standing in front of a group and getting investors to put money.

[01:19:08] And he was even great at getting people to buy from. We work that he even started this whole, I think it was called wee life thing where he had people who would move into the building. That they were renting this office space from, and they'd all lived there. They all had their own little units and they'd get together every night and they'd eat together and have community and everything again, collapsed when they couldn't sustain the momentum.

[01:19:38] And it was like a Bernie Madoff thing where he needed more money coming in order to support it. And he got incredible amounts of money from this big Japanese investor. And then we've got Theron. Elizabeth Holmes. She failed when this investigative reporter questioned whether the technology really works, the investigative reporter said, Hey, can you really do hundreds of tests reliably with just a drop of blood?

[01:20:10] Why did this report, or even have to ask the question at all? How about all of these investors? Huge companies? My, including my medical field companies. How did all of them get built basically into spending about a billion dollars with her in an investor? It is a real problem. And it's a real question because ultimately what we're talking about is companies and Silicon valley thinking you fake it till you make it, who are bilking investors and everybody else out of it.

[01:20:46] Now you have to have a certain amount of that. No matter what the company is. Do you. Faith in yourself. You've gotta be able to stand up and make a presentation to customer or to an investor, an angel investor or friends or family, whatever it might be. But how could you have sold value to customers that convince them?

[01:21:09] To pay the rent that's needed before you've even shown her profit. And that's a big question. Things have not changed in Silicon valley because of what we work did. And because of their failure, things have not changed because of Elizabeth Holmes and Theranose and the major failure there. These people are investing money.

[01:21:30] They hope that two times out of 10, one times out of 10, they will actually make money from their investments. We're talking about the venture capitalists and they are jumping on all of these things that are, maybe. Quite legal. That was actually the pitch that was used by the founder of Uber.

[01:21:52] Yeah. We don't really know if this is quite legal or not, but we're going to let people use their own vehicles to drive their own cars, to pick up strangers and take them places. And it was obviously not legal, especially in big cities where they had laws about all of this. And then all of a sudden now Silicon valley.

[01:22:14] Really listening closely and say, oh, not quite legal. Okay. That means you are going to completely overturn the whole industry. And that means we could make a whole lot of money on you again, just the knee jerk. So we've got to be careful. The other side of the point and coin is the secret sauce, which is many companies are being careful to not disclose things for very good reason.

[01:22:40] They don't want an employee to leave and take with them. Their secrets. Look at the lawsuits that have been out there with Google and some of the other self-driving companies. You stole an executive, the executive brought all of this knowledge. Them. And maybe even some documents, this should not be legal.

[01:23:01] And now you've got the Biden administration issuing an executive order, trying to change this whole thing by saying, while you cannot lock people in to not disclosing or to your secrets or to not compete with you. How well to Silicon valley or any business anywhere. To keep their secrets, their secret sauce, the recipe to Coke.

[01:23:28] If you will, how are you going to keep it secret if you cannot hold people to these non-disclosure agreement? And so I think again, the Biden administration is going the complete. Wrong direction. I'm going to keep an eye on this whole Theranose thing, this trial that's going on. I didn't have an idea how it's going to turn out, but we do have to change the fake it till you make it.

[01:23:54] Ideology of Silicon valley. Hey, take a minute and sign up online. Get my free special reports and trainings. Craig peterson.com. Your cybersecurity strategist.

View Details

Are You Ready For Your Car to Spy On You? It's Already the Law

They pass the infrastructure bill, which means now it's time to figure out what is in the infrastructure bill. And we're going to talk about the technology that they decided to fund the technology that will win the game because it has billions of dollars of federal money behind it.

[Following is an automated transcript]

[00:00:16] This is disappointing, but it's normal, right?
[00:00:20] It's absolutely normal because the federal government has always been one that picks winners and losers. If you're old enough, you remember, of course, VHS. Tapes right too. Do you remember beta tapes? Beta max tapes. Beta max was quite the standard for professional production for the longest time, a better technology, frankly, a lot better than VHS.
[00:00:46] Same. The thing's true with beta, but beta lost. And, of course, we ended up with VHS tapes. That's an example of technologies that were backed by investors. And we've seen a lot of that. Look at what's happened with the Serono trial, again, technology backed by investors. And it turned out to not work and in quite a dramatic way, frankly.
[00:01:13] We've seen that repeatedly and keep hitting my mic here, and the problem that we really have, isn't so much that investors get things wrong because they. I was talking with a friend of mine. Who's has been an angel investor and part of VC partnerships for a long time. And he was saying, we're lucky if we get maybe one out of 20 times, we get.
[00:01:37] Now, these are professionals, and my friend, he's a technology guy. He and I contracted together at the same time over a digital equipment corporation. And he came to me for a lot of advice about business. Now, I look back and think, my gosh, the way he did it. You can have all kinds of decisions in life.
[00:01:58] Some are going to bring you closer to family. Some are going to bring you more peace and joy and happiness, and some are going to give you very gray hair that you're going to lose very quickly. And he chose the kind of gray hair. But he was really clear about that. Cause I had said to him, what is a one-time out of 10 VCs make money?
[00:02:19] And that's when he corrected me. He said, no, it's really one out of 20 if they're lucky because that doesn't even happen all of the time. Now think about him. He was working on the scuzzy subsystem, which is. It's a complicated topic, but basically, a computer can talk to its hard disks.
[00:02:38] Okay. Let's just keep it simple. And I was working in the kernel, which is the core of the operating system, and was rewriting kernel modules and routines. To work with a few different types of features and functions. I was very deep, very complicated. He was rather deep, rather complicated.
[00:02:59] There's always a battle, by the way, between compiler people and kernel people as to who has the more complicated job, but he wasn't either. So he's just a kernel guy, I guess. So he went on. He started a company, he got VC angel funding and VC funding. He made a card for your computer that you could plug in that would provide not just scuzzy support, but he moved the file system out of the operating system or onto the card.
[00:03:30] that's something I had actually done a decade earlier with the network moving it out. But anyway, that's a different story entirely. So many things I've done all my life that I wish I'd been able to monetize. But anyways, w he doesn't, he's not a slacker. Let me put it that way. When it comes to technology, neither are his partners, and yet one time out of 20 and along comes the infrastructure.
[00:03:55] They call it the infrastructure bill. It really bothers me to call bills that are not the infrastructure bill that had. What was it? About five, 6% are actually going to infrastructure. So it's like the Democrats under the president, the last president Obama they, he had this shovel-ready jobs, which of course wasn't true.
[00:04:15] And most of the money didn't go to building infrastructure. It just got worse. It's just crazy, and we're not paying attention. So I'm going to help you right now. Enough ranting and raving. The infrastructure bill contains money for some things. We'll talk about a few of them here in a minute and have new regulations.
[00:04:37] And one of those regulations that I've been talking about on the radio this week is this requirement to put kill switches in all new cars. That is really a big deal. Now a kill switch, of course, is something that will stop the engine, and it'll stop the car. That's the whole idea. And various types have been bantered bandied about, including pulling the car over to the side of the road.
[00:05:06] If the driver stops responding as a driver might have a heart attack or fell asleep, perhaps something happened in that car should probably pull over and get out of traffic, turn on the flashers which then makes it a target. Apparently, for some of these Teslas, we've seen articles about that in the news.
[00:05:24] Yeah, don't park on the side of the road. I was in emergency medicine for a long time. And one of the things I can pass along that may save your life is if you have to pull over, do not stay in the car, do not stand in front of the. And particularly in the evening or at night because the flashing lights and the vehicle at the side of the road is a beacon for drunk drivers to come and hit you as well as some of these autonomous vehicles, apparently just get out of the car.
[00:05:56] Behind the car off the road. Okay. Go off the road behind the vehicle, not next to the car off the road, not in front of the car, off the road, behind the car. So if it does get hit, you are less likely to suffer severe damage yourself, but this kills switch. That's part of this bill that was passed in sign. Of course, a remote feature requires all manufacturers to include the ability.
[00:06:24] For police departments and potentially others. And this is where some of the problems come in to be able to stop them. Now you might remember back in 98, there's a Saifai series called the X-Files. It was a very cool series. And there's an episode called kill switch about the artificial intelligence gone wild.
[00:06:47] And that, that is, of course, a while ago back when most people were still using a dial-up modem. But this was a tale of technology, run amuck, and it was warning about handing too much of your life over to technology. Oh, that's one thing. But in this case, isn't it safer, right? Because somebody is whipping through neighborhoods at 80 miles an hour in their car, trying to avoid police.
[00:07:16] Shouldn't have, please be able to stop that car and pull it. So the problem is multifold, frankly, and having this kill switch one constitutes law-abiding. There's a great article on motorists.com, and it shows a picture of this down in New Zealand. Our car was pulled over. And the police found the trunk was full of contraband.
[00:07:42] Now we've seen this before, right? And movies, Miami Vice, and others, where they pull over the car. It's got all this contraband in the trunk. It's cocaine and various other things. No. This isn't Auckland, New Zealand and the trunk was full of Kentucky fried chicken meat. They were running Kentucky fried chicken, just like the Kennedys, running illegal booze back in the day. Yeah. That's how they made their millions. They were running Kentucky fried chicken. Now this bill signed into law by president Biden states that this kills switch, which uses referred to as a safety device, must passively monitor the performance of a motor vehicle driver to accurately identify whether that driver may be impaired.
[00:08:34] In other words, big brother will constantly be monitoring how you drive. So if you do something that the system has been programmed to recognize as driver impairment or unsafe driving, your car could just shut off, which could be incredibly dangerous. I want to point out this week too. Another article I read about Teslas and how Tesla had introduced it last fall, a feature.
[00:09:02] So you could set how the car was going to drive. Do you want to move? Real cool, laid-back fashion. Do you want the car to drive an average way, or do you want it to be aggressive? Just weave in and out of traffic a bit and tailgate and do all of those sorts of things, and you could set it, and there is a public backlash, and Tesla got rid of it.
[00:09:22] It is back now. How do you tell if a driver's being unsafe? When will a car in its autonomous mode do the same things human drivers shouldn't be doing? Or what if you're hauling contraband, Kentucky fried chicken? How is the driving going to be measured as impaired? Now I know in many states you have these breathalyzers that are court-ordered, installed in cars.
[00:09:52] Okay, so that makes sense. Somebody has been drunk driving many times. You don't want them drunk driving ever again, please. And thank you. But how about having that system in every car? Because it fails. It doesn't work sometimes. And how about the back door? Because that's essentially what we're talking about.
[00:10:14] These cars will have a back door that allows someone named government authorities to access them whenever they want. Would they need a warrant to do it? Probably not. Even as hackers could access the back door and shut down your vehicle, think about lad having a kill switch that would kill all cars and trucks in the United States.
[00:10:41] Right? There are so many potential problems here and they haven't been thought about. Oh, obviously, it's government, but we're going to talk, or we'd get back about the investment that is part of this multi-trillion dollar bill that you and your kids and grandkids are paying for.
[00:11:02] We know they snuck a backdoor kill, switch into all cars manufactured after 2026 into this infrastructure belt. What else is in there? That's going to affect technology. That's what we're going to talk about right now.
[00:11:17] We know about this now. After it passed, finally, people had a chance to read it because this provision on the kill switch was not debated in the house.
[00:11:29] It was not debated in this. Just like they've been doing was so many other things for so long now, they just bundle them all together in a bill. They gave it a cute little cuddly title, and then they go ahead and put whatever it is they want into it. These are these omnibus bills that they should have gotten rid of decades ago.
[00:11:54] It is absolutely crazy to me. I just. Get it. Why are we putting up with this? So now the next step here is the investments that are being made. Now I'm going to type in right now, how successful are angel investments? Okay. So here we go. Bunch of ads for angel investing says you can have an average return of 1.1 X cap.
[00:12:27] All right. And it goes on and on. This is a company called core associates. The success rate of angel investors. This is from Investopedia, the effective internal rate out return for a successful portfolio for angel investors is approximately 22%. Now, remember that over. So that's pretty amazing. Those numbers are much higher than what my friends said that they can expect absolutely much, much.
[00:12:58] But I can tell you one thing for sure. Government quote, investments, end quote, rarely ever actually payout because you've got political motivations in there. It's one thing to be a smart technology guy investing in technology. But how about those people in Congress? That aren't smart technology guys.
[00:13:22] How about the doctors in Congress? Look at what Senator Paul ran. Paul has been saying he is a doctor and what he's been saying about the whole COVID thing and the way the government has handled it. We are really going down the wrong road to here because government. Taking the money from us at the point of a gun.
[00:13:44] Try not paying your taxes and see what happens rarely ends up. Okay. So the us Congress passed November six. Biden's trillion. Plus infrastructure bill that includes 65 billion of investments in the power grid to accommodate rising, renewable energy capacity and demonstration clean tech project. So what's that one about?
[00:14:10] That particular one is because our grid cannot handle solar and also the windmill power. The rates, we would need to have it, our grid set up so that you have a few centralized power stations, and then that power is distributed to the area. It's not set up for having tens of thousands of power stations.
[00:14:35] So there you go, president Biden, put money in to try and figure out well, Hey, how do we accomplish? How do we accommodate them? Noma, Germany has done. Is they've gone ahead and they're using a massive lake as a heat sink to get rid of the extra electricity that's being generated. When it comes to a regular power plant, you can turn it up.
[00:14:59] You can turn it down the same. Thing's true for every type of power plant, whether it's powered by water or nuclear or coal, you can turn it up. But when it comes to wind and solar, you can't turn it down. If it's a nice sunny day, you're not going to be able to turn that power down. It's still coming out.
[00:15:18] You got to do something with it. You can cut it. Open the circuit. But the power companies that run the grid don't have that kind of fine-grain control over the electricity that you're generating in your house or in your business. There's so many problems that start to open up here. So they're spending $65 billion.
[00:15:40] That is a lot of money to figure this out. Okay. Personally, I'd rather see the private sector do it because they're going to have a better chance of coming up with something that's really going to work next part here. Okay. And by the way, Colin it or trillion-dollar-plus is being favorable because they played all kinds of gimmicks with this money.
[00:16:03] Just, I just found out. In fact, I think it was a couple of weeks ago, June. Do you remember. President Biden moved all of the college loans from private sources into the white house. Do you remember that? So the white house is controlling all college loans at the time I thought, okay, it's just them paying back the unions, the teacher's unions, right?
[00:16:27] Because it also included provisions that you cannot have be bankrupt and get rid of your college. Th that's just mind boggling to me, but as it turns out what he was doing. Okay. All of that's true. But what he was actually doing is saying, oh, there's over a trillion dollars in college loans. So we're going to move them into the white house and call those assets to offset all of the money we're spending.
[00:16:58] You see what we're talking about here? It's just not. Electric vehicles, clean energy, public transit are all part of this trillion-dollar-plus legislation. It's got $550 billion, a half, a trillion dollars to fund advancements in public transit, clean energy electric vehicles, roads, and bridges. Okay. It's always electric.
[00:17:26] Really? The right winner here is electric. The beta max that should have won out over VHS. How about hydrogen? How about some other way? How about natural gas or LP gas? What we'll never know because some of that is not going to get funding. However, there is going to be some funding. For nuclear development?
[00:17:50] No, I've talked a lot about this on the radio before, but the bottom line is as nuclear is the only green energy that we can really get. Now you can hear some people saying, oh, okay. You're not sure not to know. Look at the current generations of nuclear power. Now, unfortunately, the regulations around nuclear power were written what, 70, 60 years ago, right?
[00:18:17] When nuclear power was nasty stuff, it came out of the projects that we had in world war II to build nuclear bomb. Now these six generation nuclear power plants are as clean as can be. They only need to be refueled every 10 to 20 years, and they're small enough to fit into a small building smaller than your average home.
[00:18:40] And you can put one of these in the neighborhood in a small town, and that will power the. Thing. Okay. So we're already getting 27%, according to president Biden of our power from these decades, old nuclear and hydropower facilities, they've got 21 and a half-billion dollars in this for clean energy demonstrations and research hubs focused on next-generation technologies, helping to get us to that net-zero by 2050 that they're looking at.
[00:19:13] To get to, so this will be interesting because there they've got 8 billion earmarked for hydrogen and carbon capture. Guess what's going to get more, yeah. Carbon capture, direct air capture, and we don't know what's going to happen with this. We're turning cow, carbon into stone, basically with some of these plans and experiments are underway.
[00:19:34] So what happened. When we need that carbon again. But 8 billion is earmarked for hydrogen and carbon capture direct capture, 10 billion, two and a half billion earmarked for advanced nuclear. So I'm happy with that. Not that they're spending the money, not at all, but that they're actually putting it into something that might make a difference.
[00:20:00] And hydrogen funding in this, by the way, it looks like it's a big win for oil and the whole oil industry stick around.
[00:20:09] This year, we have a live show at the consumer electronic show. That's a cool thing. I was not able to go this year, but we're going to talk right now about some new technologies that were unveiled just this year. From some of the major manufacturers.
[00:20:27] Samsung had some really cool announcements out at the consumer electronic show.
[00:20:34] There were a lot when you consider how many people attend that show every year, it was way down this year, by the way, usually there's like 120,000. The people who attend, give or take this year, it was like a fifth of that number, hardly anybody, but there were still thousands of businesses that were there, exhibiting products and software and things.
[00:20:58] Hopefully next year I'll be able to head back out there again. I just don't like all this lockdown craziness that they have, and man, they had quite a bit of it out there. This year, just a large part of the reason. I didn't know. But Samsung had some cool stuff. We'll talk about that right now.
[00:21:16] You might've seen the galaxy fold, you know what that's about where you have a phone. That folds in half and it has a couple of displays on it. There's one display that might all always be visible. There have been some cool phones in the past that had LCD, just regular, old, black and white displays on the outside.
[00:21:38] And you open it up inside and there's color. Now galaxy has come out with the tri-fold flex and flex. Concepts, you can't buy these right now, but they're really quite cool because this tri-fold is something that looks like a little big bit of a big iPhone. So you, if you're familiar with iPhone, It's probably about 25, 30% bigger than your iPhone when it's all folded up.
[00:22:09] But I'm just talking about the face. It's obviously a lot thicker than your iPhone, and then you can fold it out and you have, what is. Tablet. Now, this is quite cool. This tablet look, and I'm looking at it right now. And it is neat. If you need to carry something around, of course, courses, Android.
[00:22:30] And I always advise you guys against not getting Android because of the inevitable security problems that they have. But it is quite cool. What they've done a whole way, which of course, another company you definitely should not buy from. If you're stuck on Android, then go ahead and buy the latest Samsung do not buy Walkway LTE or.
[00:22:55] Algae, any of these other guys that are out there. Okay. No safe place to, to put it on the table. At least with the tri-fold at the bottom is going to be good, but we'll see, they had another one that is a scaled up galaxy Z fold. And what you do with this thing is you pull the screen. Out now, this is something that we looked at years ago, where we had these foldable screens that would actually roll right up into the device and you could pull it out as well.
[00:23:29] We haven't really seen that go anywhere. You might remember back to the future where they had displays that were so cheap on the cereal boxes that they were disposed of. And it would play a little video, cute little video that went along with this cereal that you are buying, but we'll see what happens there.
[00:23:47] This version of the flex ass has been another trade shows. It's got this tri-fold design. There have not been a whole lot of real successes with the galaxy folds in the past. I don't know if you'll be able to see it. They've also got the flex G and this is what they call a multifold product that folds inwards twice in kind of a G shape.
[00:24:13] I'm looking at it right now. So it just folds up entirely. You can't see any display when it's all folded up, but it gives you a bigger display ultimately, and that's a thing. They also came up with the flex note and this is a laptop that has no keyboard on it. So it expands to. And then you would have it folded a little bit so that you could use the bottom half of the display as a touch key pad, which is cool.
[00:24:45] We'll see what happens with that. But there were a few things like that Samsung had out there. I like, frankly, the ability to have a device with me that can double as a laptop, and there have been some attempts at it in the past, including one, the projects are keyboard. On to any surface and then measures where your fingers are and hears and feels the taps of your finger on the surface to figure out what it is, you're typing and things but they've all been gimmicky.
[00:25:17] Now I want to talk about something that just came out that I guess you could say it's a little bit gimmicky, but it's real world stuff. And that is GM has something they're calling their ultra cruise driver's assistance. And this is going to come out in 2023, they think, and they're using a Snapdragon platform using Cellcom.
[00:25:42] Five nanometer chipsets. Now that's pretty cool because the five nanometers stuff is something you don't see very much apple is using it. Now some of these others are other manufacturers are too, but what's going to happen is this new ultra cruise is really it's out there right now, which is really quite good, but they are.
[00:26:08] Coleen and ultra crews, because it's better than the supercruise that you're seeing on the road. So alter cruise, you can't buy it yet again, that's for next year, but supercruise is limited to restricted access divided. Lane highways alter crude is gotten to operate on more than 2 million miles of roads in the US and K.
[00:26:33] So in Alterra crews, equipped car from GM is going to sense its environment. It's got a bunch of different sensors, including LIDAR, which is a laser radar thing, optical cameras, as well as regular rates. And it's going to have the sensor fuse 360 degree view of the world around it. It's going to recognize and react to permanent traffic control devices like stop signs, traffic lights, even handle left turns.
[00:27:00] Although apparently it's going to need a little bit of driver input and like super cruises, altar cruises, a driver assistance system. So it's under a level two, which is. Pretty advanced frankly, and the human driver is still responsible for the situational awareness. In other words, stay awake. This has a driver monitoring system, making sure you are awake and you're going to have to supervise it.
[00:27:27] So that's the problem I have with it. I would rather have a system that monitors. As I'm driving, they have a system that's supposed to be running on its own. And I have to monitor again. I think that's a huge mistake, the same mistake that has been made many times in the past, but it's. People are not good at monitoring computers.
[00:27:51] Computers are good at monitoring people. So I, my ideal is to have a system or I'm driving. I'm holding onto the steering wheel. I got maybe my foot on the gas. Maybe not, maybe it's on cruise control, but if I decide to do something that the onboard computer thinks is wrong. So I'm varying into another lane and there's a car there.
[00:28:13] I just assumed to have the car kind of jerk the steering wheel a little bit, and I have a little alarm go off. Hey, there's a car next to you. Comma you idiot. And I'm back in the. I think that makes the most sense, but if I am fighting against it, so if I pull really hard, I turn even harder to the right.
[00:28:35] The system says, okay, you must know what you're doing. I'm going to let you go. And it now lets you drive into that other lane. And there may be a lot of reasons for that. I'd rather have hit a car on the side then rearrange. Julian do a dump truck that stopping on the road in front of me. So there's those types of human evaluations that you're going to make, that the computers really cannot make.
[00:28:59] That's the way I wish it would go. In other words, I'd rather be driving something made by our friends at Boeing than drive something that is. Maybe a little bit of a problem from Airbus. And if you are already a Volvo owner, I want to point out that you are already in the car. That's what I just described.
[00:29:22] And that's part of the reason I haven't driven Volvo. I haven't been buying them and that is involved. The computer can override what you want to do. Your steering wheel is not hooked up directly to the wheels, your brake pedal, your gas pedal. None of them are hooked up like they used to be. I've got a 1980 Mercedes. And there's direct linkage to all of those things. So if I'm turning my steering wheel, it is in fact directly hooked up to that front end of the car. And I am really turning the wheels. Push down on the accelerator. There's a mechanical linkage that goes right to that engine and moves a controller on the fuel injection system.
[00:30:08] Same thing with the brakes. However, in ma many modern cars, not all of those things are direct linkages for many vehicles. In fact, your gas pedal does not really. Directly to the car. All it does is provide a potential geometer, one of those little volume dial type things that is sending a signal to the computer, and then the computer's actually controlling it all.
[00:30:36] So a Volvo is designed to not let you pull more than one G laterally. In other words, it only lets you turn the. So hard so far, and the idea there is just stop you from rolling over. But I, again, I can see situations where you might not want that computer to override you. And certainly not in the fashion that Volvo does it.
[00:31:00] So that's why I'm not a Volvo fan, right? Although they consider themselves safety experts. I guess they are in some ways, but now they're a Chinese company. So I don't know. I'm getting even more confused. He visited me online. Craig, peter.com. This week. If you subscribe, you'll get my password special.
[00:31:20] We've got some news on the 5g front with Verizon deciding to change its pricing strategy. So we're going to talk about that. And we're also going to talk about the promise of 5g. We keep hearing about it. What is it and what does it mean for us?
[00:31:37] Verizon's making a major change here in its five G upgrade. I'll tell you about that in just a few minutes.
[00:31:44] First of all, let's talk about 5g and what the promise of 5g is, frankly, 5g. Absolutely a huge change. It really is a complete transformation of so many industries. Our society is going to change because of 5g. Now, initially there's going to be some bumps in the road. Like we'll talk about here with Verizon, but 5g is the data plan that is being rolled out or the data technology that is being rolled out.
[00:32:19] All major salaried or phone companies, and it's going to allow them to compete against cable companies. These satellite services that are by the way, in such trouble right now, they're looking to combine themselves together. The whole dish networks thing it's really that world is going to change and 5g is going to make it even harder for them because 5g is 10 times faster.
[00:32:48] Than 4g LTE. Remember how fast 4g was now? That doesn't mean that 5g is guaranteed to be 10 times faster than 4g. LTE is right now at your home or office or commute. But what it does mean is that it has that potential. Now it's going to matter. Who your carrier is going to matter who you are, how far you are from those cell towers, because 5g requires far more cell towers than 4g ever did or anything prior to it because of the frequencies and the bandwidth that, yeah, that 10 times faster comes with a price, but 5g also supports 10,000 times more network.
[00:33:33] Then 4g does and can handle a hundred times more devices than 4g networks. And it is also one 50th, the latency of Phi or for. One 50th, which means the latency, the amount of time that it takes for the packet to get to the other side and potentially back is one 50th of what it was in 4g. So what that means is 5g is going to make your video calls seem like they're local.
[00:34:06] There's so much bandwidth that they can send high resolution. Text or data. So video, for instance, now let's talk about one of the really, I think big applications it's already been tried a little bit here, but it has to do with telemedicine. All of us probably have had some sort of a run in with telemedicine because of the.
[00:34:29] Down the doctor doesn't want to see you now, but he will see you potentially over a video call. Now that's a big deal. How about the next step up and the next let's get to surgery. What happens if you are living in a town that doesn't have a surgeon that specializes in this one particular bone inside your middle of.
[00:34:53] How many places have that right. In the Boston area. Of course, we are lucky to have some of the best hospitals and doctors in the world without a doubt. But how much detail do you want? You don't want a doctor. Who's never performed that surgery before you want a doctor. This performed at a thousand times.
[00:35:12] So when we're talking about 5g, what that means is that doctor could be at a remote hospital, could be using one of these control surfaces that allows them to hold on to tools that are hooked up to computers that are almost like the scalpel or the other tools they might be using to perform their surgery.
[00:35:34] Yeah. In maybe even a doctor's office for outpatient thing or you're in a hospital and a surgical center. There's of course a surgical staff right there. And there is a computer system set up with all of these remote controls and those remote controls are controlling, specific tools that the doctor wants.
[00:35:56] And. So the local people are there. Doesn't keep an eye on your breathing and make sure you're properly medicated and put under and that your blood pressure's correct, et cetera. And now that surgeon that works on that one bone in the middle ear can remotely control all of the surgical. Almost like they're local and that's possible because of 5g.
[00:36:21] Now I know many places have fiber. I have fiber at my office. We have three gigabits of a high speed fiber coming in as three gig up and three gig down. And that's just great. And it's wonderful, but not every place has that kind of bandwidth available where we go. To the internet backbone from the office, we have an, our own ASN and stuff they'll get into too much detail, but basically we're part of the internet backbone.
[00:36:49] So I think that's a really an interesting thing when you get right down to it, because now that doctor could be in a rural area, that doctor could be in New York City and you are out in middle of nowhere, Lancaster, New Hampshire, for instance. You're in that little hospital there, or that outpatient clinic in, in Lancaster or wherever it is you are, and that doctor can now control all of that surgical equipment.
[00:37:19] So it's going to change a lot of things. Having that kind of latency allows that doctor to have incredible control over those regions. Scalpels and other surgical tools. And it also lets that doctor see everything that's going on in super high definition video. Assuming, of course, you've got the cameras and you've got the right displays, et cetera.
[00:37:41] Now, this is going to change, not just the medical industry, but it's going to change many industries. As I mentioned earlier, think about things like your clothing, your cars, almost anything nowadays can be embedded with some sort of a computer apple has been working on kind of the apple glasses thing.
[00:38:02] Remember what Google came up with Google glass and it's going to be built right. To your glasses. You're going to be able to ask questions of Siri and it'll be able to answer them, show you things, put overlays on your glasses. So you're trying to get to a place you've never been to before your glasses are going to show you where you're going.
[00:38:23] Same thing inside your car. It's going to be projecting upon these windscreen in front of. So you're going to be able to see all of the directions and things right there. It's going to be telling you your speed or other things that you care about right then and there. And it's all going to be doing it over this amazing 5g network.
[00:38:43] Now it's going to take a while for it all to roll out. We're seeing the starts of it, in reality, we're probably talking about a decade to completely roll out 5g networks and to start really seeing its value, and much of the value comes from something I complain about all the time. The. Of things.
[00:39:03] Now, the internet of things, of course, is all of these devices we were just talking about. But instead of hooking your jacket up to the wifi, where at home and you, of course, you're gonna wear the jacket out and get a cup of coffee, and then you're going to go do some shopping and visit some friends that jacket's going to be able to keep you up to date and provide feedback wherever you are because of.
[00:39:30] Hi, high bandwidth available to it. Remember it can handle a hundred times more devices on 5g than it can on 4g. And that's what they're looking for. The automated driving, where the cars can all talk to each other. But instead of that mesh network that we were trying to build previously where the cars talk to each other, and that means everybody's got to be on the right frequencies and talking the right way.
[00:39:55] Just do the 5g. And let them all just talk over the internet with. There's so much stuff that's going to be able to happen here. Artificial intelligence tied into the glasses. Like we mentioned augmented reality again, so much. So they're thinking that by 2025, we may see 1.8 billion 5g connections deployed worldwide.
[00:40:21] Now that seems like a very big number until you get into how many people. On the earth. And you can see that it's not even going to be one device for every person, but it is going to be a huge thing in the developed world. And the bandwidth and latency are important and 5g solves most of that problem for most applications.
[00:40:44] But right now we are. I see the roll-outs and right now T-Mobile has the best 5g network nationwide. And it has very high data rates, but not as high as Verizon's are because Verizon's using different frequencies and it can get more bandwidth out of those frequencies than T-Mobile can, but T-Mobile has better coverage.
[00:41:08] So this is a trade off, right? If you're already with the company. And you're happy enough with them. There really isn't much reason to move to a T-Mobile or whatever it might be, because they're all going to have pretty good performance. And as I said, it's going to be about a decade before we're really realizing what's going on.
[00:41:27] But Verizon on January 19, launched its 5g on the C band spectrum. And there's been a lot of stuff back and forth about that. And some of it comes from the airline industry because it's using some of the frequencies that are close by and they're afraid it's going to. Problems with the airplane navigation systems and data feedback systems, but this is going to provide even faster 5g speeds for Verizon customers.
[00:41:57] So even though right now T-Mobile has a leg up. That doesn't mean that they're going to have a leg up forever. That's true. But. You're beyond unlimited Verizon smart phone plans and the other plans that include data. They're all changing right now. So check with Verizon, if you have Verizon as your character, because here's what our carrier I should say, because things are changing.
[00:42:23] Hey, visit me online. Craig peterson.com.
[00:42:29] Patents were intended to help innovation, not just stifle it. And you look at people like Edison. He had more patents than anyone else in his age, but now we've got a different world with Google and Apple and Samsung.
[00:42:44] This week, we have an article about Google losing the Sonos patent.
[00:42:51] Now, this is fascinating to me because one has happened here is we have two companies. We have Sonos who I've had on my radio show before, who has these great speakers that you can put in your home? And the idea is they all connect to your wifi and the speakers can talk to each other or talk to the internet.
[00:43:12] You can play the music you want. You can extend your television speakers, et cetera, and you can control them all. And play them all with the same songs, this up the volume down the volume, all kinds of cool stuff. Google came out with their own speakers and there was a problem with that because Sono says that it pitched Google.
[00:43:38] For support of Google play music to go to these Sono speakers. Now I've got to tell you full disclosure here. I was in a similar position here to Sonos many years ago, and I had developed software that allowed a computer system to run old code, basically. So what this was is it was for COBOL and I could emulate.
[00:44:07] The code that went into this old Sperry Cade computer assisted data entry system, which was really quite a little accomplishment. And I sold it to RCA Astro space who used it to make the space shuttles, the space shuttle program, Telstra how long ago that was right. And it was pretty cool. It was a great accomplishment.
[00:44:28] But I had gone to Sperry and I paid my own way down to their headquarters in Pennsylvania. And I did a presentation for them, showed them, okay, this is what I'm doing. You guys I'd love it. You're talking about selling it. You've already sold it to a couple of different companies and I would love for you guys to sell it some more.
[00:44:50] And Sperry went behind my back and. I had a project going to replace their Cade system. Now I was using Sperry branded anyways, Unix systems in order to do this. So they would still be able to sell hardware. The fee for this new hardware, as well as my software, that monthly fee was lower than just the maintenance fee on this old K data entry system.
[00:45:22] Now that's a huge deal. And I think what happened to Sperry said we gotta be able to sell them more stuff has got to be more expensive. They never talked to me about it again. And then about two years ago or two years after that, then. I had a trade show, announced they're brand new system for data entry and they wasn't the best.
[00:45:46] And they had taken some of my ideas and tried to implement them. Now they did a terrible job implementing them, but they stole my idea. And it's very difficult to Sue another company much to my chagrin because I've been cheated, ripped off. I don't know what, how you want to call it, but many times for stuff like this.
[00:46:09] And so it just has really beaten me down over the years. So what's happening here is Sono is this company that makes these great speakers and sound systems went to Google and said, Hey. I would love for your streaming music system to tie directly into Sonos. And that was the Google play music is what it was called.
[00:46:33] So there they go. And Google gets okay, great meeting. Let's go have 'em now. I kept this and Google gotta be hide. The scenes. Look at Sono, says operations back in 2013, and I'm sure their founders were thinking what I was, oh, this is great. They're either going to license it or they're going to buy us.
[00:46:52] And this is going to be fantastic for us. Sono says Google use that access to quote, blatantly and knowingly. Copies synopsis features for the Google Home speaker, which launched in 2016. And then, so nos sued Google in early 20, 20 Eddie Lazarus, and this an article in ARS Technica that chief article had Sonos told the New York Times.
[00:47:18] We appreciate that the ITC has definitely validated the five Sonos patents at issue in this case and ruled any equivocable. Yeah. And equivocally and does not be in there. The Google infringes, all five patents that isn't across the board, when that is surpassingly rare in patent cases, I have to agree. I think that sort of thing is just terrible.
[00:47:44] Just terrible. So what does Google. We're going to talk about a Samsung apple case as well. And they did a much different thing, but what does Google do here? Google has decided that due to a recent legal run, this is a quote from Google due to a recent legal ruling. We're making some changes to how to set up your devices and how the speaker group functionality will work moving forward.
[00:48:11] By the way, I corrected the grammar as. Terrible grammar. If you're using the speaker group feature to control the volume in the Google Home app, by voice with the Google assistant or directly on your nest hub display, you'll notice a few changes. So basically what Google did is they removed functionality from their speakers, and then they push that out to everybody out there.
[00:48:37] Now Sonos has been criticized for pushing updates. Devices, it's owner says we're not going to support this anymore. So they send out an update that makes the speaker completely useless, which is just crazy. But this volume changes the biggest annoyance on the list of features that Google has dropped.
[00:48:57] So rather than saying, oh, okay, you know what I'm really? Yeah. We messed up because we did get all of this inside information and then we use some of your technology without licensing. It let's reach a mutual agreement here and we'll pay you whatever, some sort of royalties for the past and in the future.
[00:49:19] No. They decide to keep fighting. Isn't that just incredible. And Google's says, yeah, we're not paying anything. We're just going to remove it from all of our speakers. So we don't have to pay you any royalties going forward. And there's a great customer reaction that was on a subreddit. Actually, there's a whole bunch of them, angry customers, demanding refunds, threatening lawsuits, and one who said you got sued by Sonos and we pay the price either, get some better lawyers and win the suit or pay Sonus or royalty or start issuing refunds to the customers. Fascinating. Despite Sarno's having one Sarno still says it. Hasn't got the outcome at once. Sonos wants Google to pay royalties for its patent, not pull the rug out from under the customers by stripping features from already purchased products.
[00:50:11] So a Google is going to keep getting pressure from Sonos as we go forward here, hopefully they'll pay pat patent licenses for stuff in the past. Now patents are something that are a double-edged sword. And I want to talk when we get back about the whole pattern thing between Apple and Samsung, we're not going to talk about every one of the patent issues, but we're going to focus in on why.
[00:50:39] Oh on one patent. And I also want to talk about what I see to be the problems with the patent system. There were major changes made during the Obama administration, and they made some things much, much worse, and a couple of things, a little bit better. Okay. Isn't that always the case when government gets involved, right?
[00:51:00] Yeah. At least you hope sometimes some things get a little bit better. So we'll talk about that. If you've ever thought about taking something and patenting it, you're going to want to listen. Or if you have friends or family that are great little inventors, because there's a lot of things here that most people just aren't aware.
[00:51:19] Hey, take a couple of minutes. If you would go online to Craig Peters, son.com, I've got all kinds of great information there. And if you sign up for my email list this week, you'll get my special report on passwords, which password manager to use and what to do. Craig peterson.com.
[00:51:40] So what is so wrong with the patent system? It has been such a huge problem for small companies against big companies, but what's the underlying problem.
[00:51:52] We were just talking about Google and Sonos and how Google lost this case in this international. Court and has not lost a case here in the us yet where it needs to pay royalties. So what happens in this case with the ITC is if Google removes certain functionality from the devices, in this case, the smart speakers, they can import them to the United States.
[00:52:22] I suspect Sonos is going after Google for patent infringement and royalties. But Google is just being a, I don't know what you wanna call it, but they're, they got their head somewhere and I, it just isn't. I explained how I went through something like this more than once in fact. And it wasn't just Sperry.
[00:52:45] Microsoft has been doing this sort of thing for a long time. I'm sure Apple has basically been doing that as well. In fact, Apple sued Samsung using a patent. The claim that that slide to unlock feature that Apple has been using on I-phones is Apple's invention. If you can believe that. Tells you about part of this problem, that slide to unlock really?
[00:53:13] That is an obvious next step. And that's what we had with patents in the past. If something was an obvious next step in technology, you could not patent it. You asked me that makes a whole lot of sense, because if it's an obvious next step, how is patenting it and getting the exclusive right to use and sell that technology, how is that going to help the advancement of technology and.
[00:53:46] Because that is what patents are there for. That's why they were included in the constitution. And the idea was you work hard and long for years and you come up with a cotton gin, for instance, there's going to save incredible amounts of labor and you patent it and you're rewarded for that. So you can now exclusively sell it and licensed.
[00:54:10] And you are also, of course, required to put all of the information about how to make your patent into the public domain via the patent office. So it's a cool thing. It makes a lot of sense, and I'm glad to see that it same place, but we've had a lot of problems lately. I'd looked at some numbers here before we started talking today.
[00:54:37] There's been over 350,000 US patents that were granted in 2019. 350,000 granted new member, not every patent application is granted. And that number 350,000 patents in 2019 is four times higher than the per capita rate in 19. That is huge. And the reason for this is research managers at these larger companies like Microsoft, look at a patent as being cheap and easy to get.
[00:55:13] And so why not file for them? So in the early 2000 bill gates decided that Microsoft needed more patents so that it could wield them against competitors. And within a few years, Microsoft increased their annual patent application rate by 50%. Now patents are easy to get because the standards now that are in place, thank you, President Obama and the Congress are lower than they have ever been.
[00:55:43] And also because the burden is now on the US patent and trademark office to prove that an invention is. Patentable. So you're relying on bureaucrats, many of whom sit on their butts all day long, right? And their number one job is not to get fired. No, I'm making incredible broad generalizations here, but that's really true.
[00:56:09] Everybody wants to be Fowchee getting paid a half a million dollars almost per year to sit around and make bad decisions. Why not? So patent examination is slow because of this. It takes three years or more after you file a patent application in order to get your patent approved. Now think about that in the technology world, taking three years from the time you come up with an idea to the time you finally get a patent.
[00:56:46] So they've increased staffing at the US patent and trademark office, but the patent backload. It is continuing to grow, and the examiners are spending, on average, only 20 hours reviewing each application. But think about that for a minute, 350,000 patents granted in 20 19, 20 hours reviewing each application.
[00:57:11] Now I said only 20 hours spent because in reality, It should be more, the patent examiners are supposed to be reading and understanding the invention. This described in the patent application, they're supposed to determine whether that invention meets the claim of the application. And then they're supposed to search existing technology to see if the invention already exists and then write a response to the applicant.
[00:57:42] time was again, a next step, an obvious next step wasn't patentable, but now you gotta just fight over this stuff and it's first to file. So if you come up with a really great idea that you want to patent and you play with it a little bit and you refine it, and then you file it only to find out that someone else already has a patent on your technology.
[00:58:08] 'cause they got there first and there have been cases where someone has developed something and they intend on patenting it, the word gets out about what they're doing. And then the third party files a patent on it before the actual person who invented it. This is just crazy. This type of examination is just bound to cause problems cause errors, many patents are just too broad or they cover obvious inventions.
[00:58:40] Like what? I just mentioned the slide to unlock thing on the Apple home screen. Lock screen being. It's something that Apple wasn't forcing against Samsung, Samsung just gave up after years of fighting it. So what are you supposed to do? If you're a little guy, right? You don't have the money that Samsung has or that apple has.
[00:59:05] One of the things that mark Cuban has done that I like. And he and I disagree on. Oh, a lot of things. But mark human endowed, a chair at the electronic frontier foundation, which is an organization I also support dedicated to the elimination of stupid. Patents and quote-unquote. So the idea is let's get rid of some of these stupid patents.
[00:59:28] Let's maybe update our patent system. And frankly, I think the patent system should be gone. Now that's a pretty bold statement, right? That's my opinion, obviously, but for technologies, like what you might put into a smartphone for technologies, am I going to software, et cetera? The life of that product is only going to be maybe a year or two or three years before the competition takes over.
[00:59:57] And now you are moving on to something else, and you've gone through what a three year difficult, expensive, very costly, sometimes impossible process of trying to get a patent on. So let's look at a smartphone technology. Let's say you want to start a new smartphone company, a patent attorneys going to have to review hundreds of patents, including many patents that were not even granted until long after the product could be launched.
[01:00:29] Does that make sense, too? It's going to take years to go through this patent process. And the failure to license. All of these different relevant patents creates a risk of litigation. So you'd be crazy to try and come up with something. Look at Motorola, Motorola exists basically as a patent portfolio, Microsoft has their patent portfolio.
[01:00:57] Apple has a Google, has it. Some of these companies have cross-licensed their patents because there's so many, and they have no idea how they're going to affect each other. So they just give blanket. So they say, okay here's what we'll do. We'll trade our portfolio with your portfolio. So you can use any of our patents and we can use any of your.
[01:01:18] The real problem, isn't it. And smartphone litigation, because of all of these complexities is just way too common. Apple who is truly a pioneer in smartphones. I don't think anybody would argue that. Although obviously they weren't the first, but there are definite pioneer they've been involved in. Dozens and dozens hundreds, probably of lawsuits around the globe as both a defendant and a plaintiff.
[01:01:46] And as a plaintiff, apple sometimes has been using its patents to beat other competitors over the head to stop them from coming up with new, innovative. This is a huge deal here. Frankly, Apple was able to convince the court that their version of the slide to unlock feature was patentable. And after seven years, as I mentioned here, Samsung agreed to pay license fees, to apple, to just settle the case, get it over with and economic research that is being done.
[01:02:21] And I'm looking at right now. What site is this? This is direct costs from some of these yeah. Boston University, school of law law and economics research paper, number 12 dash 34. And it's talking about these non-practicing entities known as patent trolls, that these litigation costs and license fees are stifling innovation in a very big way.
[01:02:48] Frankly, I think the, we got to get rid of the patent system entirely. It's gone. When an investor gets a patent, they're supposed to reveal the secret sauce behind the invention in the patent, in this public document that I mentioned so that other people can learn about the invention and use it to improve technology.
[01:03:08] That's the theory, but the practice has been something out it's been. To beat competitors over the head and shoulders to stop them from being able to compete is a very bad thing. So there you go. My opinion. Hey, if you want to get this week special report on passwords and password managers, sign up right now.
[01:03:31] Craig peterson.com/subscribe.

View Details

Do You Have a Smartspeaker? Another Danger Comes Your Way!

By now, you've heard of tick talk. You might use Tik TOK. Many people do. It's their go-to site online, especially if you're a little on the younger side. Here is a danger of some of these tick talk challenges and combine that with Alexa. Oh my

[Following is an automated transcript]

This is a little bit on the scary side. We built our house some 25 years ago, we contacted a builder, and I put together all of the specs, and I made sure that the wood he used was better than average.
[00:00:30] It's all plywood. It's not particle board or composite boards. And I made sure they were thicker than needed for all of the rules. Struts were closer together than the code required. And we had more oversized plumbing than what was needed through the house. And one of the things I did was I had him wire the house, actually the electrical contractor, with a heavier gauge wire than usually.
[00:01:02] So that I had 20 amp sockets at every socket in the house. Now we put the special 20 amp sockets on some of them, like in the kitchen, we have a commercial toaster, as a sort of thing you need, when you got eight kids and a half of our married life, we had other families living with us too, that we were helping out everything from training through just getting them through.
[00:01:26] Bot. So there were times when we had 20 plus people living in my house. It got crowded, but I wanted to make sure everything was above code so that it would work well and work well for us and know how much juice we tend to use. Yeah, you don't want to see my electric bill. I decided, yeah, let's do the heavier gauge wire, and let's put the sockets in one of the things I had the electrician do to make the sockets a little bit safer.
[00:01:57] This was back before you had these. I, frankly, hate them, but these safety sockets where you push in the plugin Erie must try it for something to get plugged in. There are ways to defeat those safety sockets, and that's where this problem comes in. I had him install the sockets.
[00:02:18] You might consider them to be upside down. So the top of the socket had little grounding. And then underneath that, you had the hot and the neutral lines. So the idea there was, while if something fell onto a plug that wasn't plugged in all the way, or if the kids decided they'd stick something on it, it would go to ground or made sense to be.
[00:02:45] And apparently, it's worked because none of my kids are dead yet. So that's a good thing. There are these challenges on Tik Tok. You've probably heard of them. That's how they got themselves going. They had that, that ice bucket challenge, and many others that people were doing, and they continue to this day.
[00:03:06] One of the tick-tock challenges is very stupid and dangerous. And that's where this article from ARS Technica comes from. Eric Bankman wrote. When was this? Oh my gosh, this is right at the beginning of the year. A 10-year-old girl and her mother used Amazon Alexa. And what was happening in the kid wanted some challenges.
[00:03:32] Mom wanted some challenges, and they were doing a whole bunch of things. Physical challenges, like laying down and rolling over a holding a shot on your foot from a phys ed teacher on YouTube. And the girl just wanted another one. So for those of you who are uninitiated, the plug challenge consists of.
[00:03:54] Partially plugging a phone charger into an electrical outlet. Now the phone chargers usually do not have a grounding pin. So my little workaround of mounting all of the sockets upside down wouldn't matter. Cause if you look at that little charger plug, it's usually just two pins, and it usually doesn't care about the polarity.
[00:04:16] It doesn't have the more significant the side and the smaller side, the. Yeah. I can't remember what they call now, but if they're both the same size, so you can put it in either direction, the spades that you put in. So if you put it in part way, you have defeated the safety mechanism in all of these modern plugs.
[00:04:38] So you put it in part way, you have to push hard and in it goes, and then you pull it out partway. So that's part one. Can you plug this phone charger intellectual outlet partway so that those two conductors are exposed, and then yeah. Then they ask you the challenge is to drop a penny onto the exposed prong.
[00:05:08] So you can get anything from a tiny spark. That little coin may jump off to a full-blown electrical fire. Now, mom was there, and she yelled. No Alexa, no. And the daughter said she's too intelligent to do something. Anyway, I'm looking at a picture here that ARS Technica published of a wall socket, where a short had happened.
[00:05:35] This wall socket is mounted sideways. I don't get that. And the hot side is up. So anything falling against the sock, and by the way, the faceplate is metal. And it was grounded. So anything falling onto a plug that's only partially plugged in because the socket sideways falls onto it. It touches the metal faceplate, and you've got a fire burning.
[00:06:05] So they've got a picture of one of these in a house and you can see where the smoke went up. Now. I don't think the whole house caught on fire here, but it was a major zap. It reminds me of the days when we had. The fuses in the basement. And if a fuse blew, all you really needed to do is go down there and stick a quarter in it.
[00:06:26] And you're fine, which means it's defeated the purpose. Anyways, you gotta be careful. At Amazon confirmed in a statement to the BBC that it has removed that particular challenge from Alex's database. Obviously these are computer generated, and they're based on Tik TOK, idiots. You shouldn't be using Tik TOK for a lot of reasons.
[00:06:52] One of them is it has been alleged that they have been spying for the Chinese. It is a Chinese company. It's part of 10 cents. And the, there's just a little stupid thing. So Amazon said, as soon as you became aware of this error, We took action to fix it. So again, you can't necessarily trust your kid at home with a, an Alexa doing challenges.
[00:07:18] I just can't believe it. It's just incredible exactly what happened here. Hey, I want to give you a real quick tip. Last week, we went over how you can find out. If your computer has been hacked, basically. In fact, we were a little bit more specific. We said, okay, what I want to do here is know if not just the computers have been hacked, but as someone's stolen my.
[00:07:47] Email and or my password. And we explained why and everything else. Then if you missed it last week, you can just go right ahead, online to to oh my I'm just having man's beginning of the year, right? That's what happened. Go online to Craig peterson.com/itunes or slash your favorite podcast player.
[00:08:08] And you can listen to it there. So really good little article from. And make use of technology. And they're talking about what are some of the things you can do? You should do. You shouldn't do when it comes to external GPU's and now if you are a regular computer user, you don't even need one of these things and people might've tried to talk you into it.
[00:08:35] Now, also that GPU is these graphical processing units are built into all of our computers nowadays. All of these new computers that our friends at Apple have come up with have some amazing GPS built into them. Those are great. They're used to update your actual windows screen that you're looking at hate Microsoft for stealing words like windows, mean things anyways.
[00:09:03] But the external GPU is something I use on my main production workstation. So I've got GPU's they work great. And when I'm processing video and doing the edits, and then the final renders, that's when an external GPU comes in. So I can guarantee you if you don't know what I'm talking about here, I guarantee you.
[00:09:29] I need an external GPU. Now the couple of other things to know, if you are looking for an, a GPO of any sort to build and put in your existing computer to build in somewhere out somewhere else, the GPU's are difficult to get right now. And part of the reason for that is so many people have been using them for mining cryptocurrencies, because they're quite good at that.
[00:09:55] Now there's special hardware that's being made. To mine, cryptocurrencies, but GPU's frankly are great little work around for anybody that just has a basic computer and wants to try and do a little crypto mining. So you're going to have a hard time getting ahold of these. GPU's just like many other chipsets out there and my own personal experiences.
[00:10:19] I don't need the top end one because of it takes a few extra minutes to render something. When I'm making a video, it's not a big deal, cause I'm not making videos all day long. So a little tip for you on GPU's and external GPU's. And do you need them, what should do. Use them for, Hey, I am doing some training every week.
[00:10:43] Kind of what we just did just now, but about cybersecurity and other things in my weekly newsletter. So make sure you sign up Craig peterson.com AU. And if you could, and if you are a podcast listener, like to invite you to subscribe to my podcast, you can find it at Craig peterson.com/itunes.
[00:11:07] We've got the end of a era for a device that was considered to be quite secure. In fact, some of our presidents, particularly the one that comes to mind is President Obama used it extensively, and it isn't what it was.
[00:11:23] This device that I'm thinking of right now, and we'll see if you can guess what it is, but it was extremely popular.
[00:11:31] It was for sending and receiving messages that even had some other functions, but it was mainly an email thing. I remember having a couple of those back in the day that was strictly email. They were, they actually nice. And then of course texting came along and they kept up with the times a little bit.
[00:11:49] What we're talking about is the end of the line. This was a Canadian company, a company that was well-known worldwide by the name of rim. They were providing the Blackberry operating system. They had servers that were designed and built to be secure. So you could rest assured that all of your data was safe, no loud you to send and receive emails.
[00:12:23] And it had that wonderful little click keyboard on it. Something that went the way of all the world. That keyboard is now gone, and it's gone for good, as has the ability to use some of those blackberries that you bought over the years to keep yourself. I just had to play taps underneath that, but it's just incredible.
[00:12:51] It is the end of the day for the company, the once dominated the entire smartphone business. If you didn't have a Blackberry, you weren't cool and you weren't secure or secure. And you weren't able to communicate as easily. They were actually. Excellent little devices in their day. I want to add another note here when we're talking about secure, because Blackberry was very big and saying, Hey, listen, it's very secure.
[00:13:21] It's all encrypted. We keep all your emails, encrypted, all your communications and gripped and what we found out, by the way, is it turned out that the Canadian government, basically the equivalent of the FBI, CIA NSA had the master key for all Blackberry messages. And not only did it have the master key, it shared the master key with the United States secret agencies, the end of the.
[00:13:53] CIA, et cetera. So if you were thinking you could use your Blackberry and keep your information safe, you are wrong. You remember when President Obama was elected? One of the first things they scrambled for in the tech business was how do we secure our. Mary. And of course, all kinds are not our Blackberry, his Blackberry, all kinds of rumors erupted that, it was people controlling president Obama and they were using the Blackberry and they're using it because it was secure.
[00:14:22] You, do you remember the whole uproar around. And the biggest problem was obviously our intelligence knew that they weren't secure and they could read any message they wanted to, as well as the Canadian government. And remember the whole five eyes thing back in the day, these five different governments that shared information on their own citizens.
[00:14:45] So it was a real windfall for the United States because Canada was. EV all of this shop software was developed for the Blackberry. It's where all of the servers were located, and data could easily be routed to Canadian servers away from us servers if they wanted to monitor somebody. And so Canada was the one spying on you, technically not your government.
[00:15:08] They'd never do that. So it was an interesting time, frankly. As of January 4th, 2020, These Blackberry phones will no longer be provided with provisioning services, which means they are going to gradually lose the ability to join networks, including the cellular network, by the way. So it's man, it's something that many kids.
[00:15:40] I have never even seen. And I look at it and just think, I remember envied some of the guys that had the blackberries at the time. And I had a couple of other little devices, keyboard-driven that were from people who have been guests on my radio show. And I really liked those, but in the Blackberry was just crazy expensive as far as I was concerned.
[00:16:02] But Blackberry's leadership really messed up. The guys who are developing Android at the time realized, oh, wait a minute. The iPhone is a pretty popular. It's going to be extremely popular. So Android then they mimicked the Blackberry at first, made it look like a Blackberry. And then they switched over and made the Android operating system be like an iPad.
[00:16:31] So they can pick, can compete with it, but Blackberry didn't see any of this coming. And it took over a year after the iPhone came out for Blackberry, for rim research and motion to come up with its own touchscreen phone. And the software was really quite a mass where they tried to. Basically crowbar in some new features and they had the old features.
[00:16:56] They're still incorporate users during this whole time. We're falling into love with their apple phones and then eventually the Android phone. Told their IP department, it departments that they needed to support the iPhone and the Android phones. And so they did, and Blackberry eventually gave up on its own phones and they started releasing Android versions.
[00:17:21] Do you remember those, the Android phones from. Mary, they got out of the hardware business entirely. And now what they're doing is they're trying to promote corporate security services. And that's really what they're trying to do. It's a new claim to fame. Yeah. Remember I just told you last time they were promoting that they were secure.
[00:17:42] They weren't at all. No, they were to some extent, but so the last version of Blackberry opera and he said, The very last release that they had was in 2013. Yeah. 2013 year that hold. So the devices affected here by this shutdown are by all standards, extremely low old. And remember you got to get security updates.
[00:18:07] So these machines, I can't even believe this still online when Blackberry hasn't given an update to them since 2013, that's almost a decade now, nine years. So if you're still using it, stop, and if you're trying to figure out what to use, get an iPhone. And if you say, oh, Hey, films are too expensive. Don't get the latest, greatest iPhone.
[00:18:31] Get a slightly older one because they are supported for five or more years out, unlike everything else out there now, although. We now have Samsung promising some longer support, like five-year support for some of the devices. So we'll see how that ends up going. But frankly, Blackberry, they're done for.
[00:18:53] It's a shame. So there's a handful of software services that relied on the Blackberry servers to function. So if you were using Blackberry world or Blackberry link, those also stopped functioning on the 4th of January and the number of people still using it. I don't know. When was the last time you saw a Blackberry and have you used one I'd love to hear from you go ahead and drop me into the.
[00:19:21] Craig. Yeah, exactly. me@craigpetersawn.com. Let me know, did you have a Blackberry? Are you still using one? And did they bother telling you about the shutdown that was coming up, but this is it. This is the end of what was a very significant technology. So here's to Blackberry. All right, stick around everybody.
[00:19:50] Make sure you are on my email list. I'm going to do something new too, with the list. I'm going to start sending you my show notes. Now you can opt-out of the show notes, just the show notes, if you want to, but expect to start seeing them show up in your email box. And this is the same show notes I send out to all of the radio and television stations I appear on because it's the most important news of the week.
[00:20:17] Artificial intelligence is making its way into all kinds of aspects of our lives. And one of them that concerns me maybe the most, in some ways it's a benefit and others is AI in the criminal justice system.
[00:20:33] China has developed what it calls an AI. Or artificial intelligence prosecutor.
[00:20:41] And they're saying that they can identify dissident and press charges for common crimes with 97% accurate. Now that is a very big claim. And the whole idea behind this is their servers services. If you will, in the court system are overloaded. We have the same problem. Most countries have the same problem.
[00:21:07] I was just looking at India. They've got some 37 million backlog court cases. Absolutely. Phenomenal. So the system now in China can press charges for Shanghai's eight most common crimes that runs on a standard PC. And it takes part in the decision-making process. They say, although apparently it's actually making their decisions, but there are fears.
[00:21:37] The machine could be weaponized by the state. Now it's interesting. Looking at the actual charges that it's designed to press right now, they're saying that it was trained using 17,000 real life cases. And it's able to identify and press charges for the eight most common crimes in Shanghai. These include provoking.
[00:22:05] Now that's a term used to stifle dissent in China credit card, fraud, gambling crimes, dangerous driving theft, fraud, intentional injury, and obstructing official duties. In other words pretty much everything, right? You go against the government. It's just going to charge you. And that's what they say high prosecutor's going to do.
[00:22:28] Now I'm looking to it. Some more details. From the management review journal. And they're saying that the system can replace prosecutors in the decision-making process to a certain extent. Now let's look at some other countries we've got, for instance, Germany, and they're using image recognition and digital forensics to help with their caseloads.
[00:22:54] China's using a system. No. System 2 0 6 to evaluate evidence of a suspect's potential danger and conditions for arrest. Now, we've had some really weird things happening here in the US with our criminal justice system. Some of them are absolutely idiotic. But things like just letting people out the same day that really should be held because they committed a moderately serious crime.
[00:23:20] And we just had cases just at the end of 2021, where we had people. Who had been arrested and got out that same day and then went on to commit serious crimes, rape, murder, and other things. So what are we doing here in the US unfortunately we have found out that in the us, we are monitoring the.
[00:23:49] The funds that people need to put up that are called bail in order to be released from jail. So normally you'd go in front of a justice of the peace and maybe a court clerk, and they would look at what the charges are or what your background is, how sticky you are in the community, family, business ties, et cetera, and then set up.
[00:24:14] So you now put up the bail cash or otherwise, and you are released on basically usually your own recognizance. They're very somewhat, so we are all ready in many areas using artificial intelligence for that entire. Process, there's no pleading with the computer's saying I can't afford a $200,000 bail.
[00:24:39] There's no pleading with the computer saying, listen, I've been a member of the Rotary club for 20 years and I own a business here. I have tight ties to the community. That bail is just way too high because in many communities they are using artificial intelligence and relying on it a hundred percent.
[00:24:57] That's one of the big problems with computers. People because they don't really understand them. Just say fine. Just yeah, go. The computers is almost always right. Yeah. The other problem is we don't know how it was programmed. Now in the case of this Chinese computer, that acts as a prosecutor for charging.
[00:25:20] They fed it 17,000 cases. Do we know what those cases are? Do we know what the computer weighs when it's making its decisions? And we've seen this already, in some cases here in the us where normally you can face your accuser. Normally you can go to the court and say, this decision by the justice of the peace was not quite right.
[00:25:43] It needs to be fixed right now. All well and good. And so if they had someone or they'd come in and testify to say, yeah, you're not a flight risk, et cetera, you're fine. But when it comes to the computers, people tend to just believe them. What were those 17,000 cases where they were, they all nasty dissidents?
[00:26:05] What did the computer learned from it? And some of these cases that we've had in the us we've found. That even the people that provided the software, that AI software, they don't know what the decision-making process actually was because the computer learned how to do it. And you need to understand AI models and how they're fed data and how they work.
[00:26:31] But basically the computers come up with their own way of thinking through things. Just to make this simple. So it's not necessarily totally logic. It's not like back in the day, you'd write software that says, okay, if they have lived in that same home for over twenty-five years, they have kids in school, they own a business, et cetera, et cetera.
[00:26:51] So you set up all of the explicit parameters. And from that, now you can say okay, fine. So you've got, went down this path based on. Person was and what their background was. Therefore, you came to this conclusion. That's not what's happening with this newer AI, not at all. And then you also have the question.
[00:27:12] Okay. What does 97% accurate? Who's going to take responsibility when there is a mistake. Now I'm not talking about the 3% that they're admitting could be mistakes. I'm talking about the 97% of the time. And then if you now move up to the courts, who are they going to talk to? The prosecutor, the machine, the designer of the algorithm.
[00:27:38] Are they going to examine all 17,000 cases that were fed into this? I goes back to what I said before about airplanes. People are not good at monitoring computers, but computers can be good at monitoring people. In other words, in this case, the artificial intelligence may help detect a mistake, but it really cannot replace humans in making a decision.
[00:28:05] It's very true. China's relying more and more on AI to boost productivity. They're using AI with facial recognition systems for their social credit score that allows people to get on. Train you can't get on a train unless you have a high enough social credit score. And if you J rock walk, you have now lost points.
[00:28:28] So it's it's really crazy. So I'm very concerned about this. I found some great information by the way, online from the justice department about what they are looking to have AI do. And it's basically everything making decisions and informing. What should happen? They're looking at using chat chatbox to provide legal advice for pro se litigants.
[00:28:56] In other words, people that are trying to defend themselves can go to a chat box that will give them some direction. That's all in the works. I'm looking at the official documents right now, criminal justice testing and evaluation consortium, looking at artificial intelligence. Hey, make sure you subscribe to my podcast.
[00:29:17] Craig peterson.com/itunes, and I hope I've earned a five star review. And if you could take a minute, just give it right there.

View Details

Have You Checked If Your Email Is On The Dark Web? Let's Do It Now! Do you know how to find out if you have had your private information stolen? Well, you know, the odds are probably pretty bad, but where was it stolen? When? What has been stolen? How about your password and how safe is that password? We're going to show you real hard evidence, and what you can do to fix things!

[Following is an automated transcript]

[00:00:16] Knowing whether or not your data has been stolen and what's been stolen is very important.

[00:00:24] And there is a service out there that you can go to. They don't charge you a thin dime, nothing, and you can right there find out which of your account has been compromised. And. Out on the dark web. Now the dark web is the place that the criminals go. That's where they exchange information they've stolen.

[00:00:49] That's where they sell it. That's where you can buy a tool to do ransomware hacking all on your own. Far less than 50 bucks. In fact, ransomware as a service is available where they'll do absolutely everything except infect people. So you just go ahead and you sign up with them, you pay them a 20% or sometimes more commission.

[00:01:12] You get somebody to download in fact to themselves with the ransomware and they do everything else. They take the phone call, they find out what it is. Company is doing and they set the ransom and they provide tech support for the person that got ransomed in order to buy Bitcoin or sometimes some of these other cryptocurrencies.

[00:01:38] In fact, we've got another article in the newsletter this week about cryptocurrencies and how they may be falling through. Floor because of ransomware. We're going to talk about that a little later here, but here's the bottom line. You really want to know this. You want to know if the bad guys are trading your information on the dark web, you want to know what information they have, so you can keep an eye on.

[00:02:11] Now you guys are the best and brightest, you know, you gotta be cautious or you wouldn't be listening today. And because, you know, you've been caught need to be cautious. You have been cautious, but the time you need to be the most cautious is right after one of the websites that you use, that hasn't been hacked because the fresher, the information, the more it's worth on the dark web, your identity can be bought on the dark web for.

[00:02:38] Penny's depending on how much information is there. If a bad guy has your name, your email, the password you've used on a few different website, your home address, social security number, basically the whole shooting match. They can sell your personal information for as little as. $2 on the dark web. That is really bad.

[00:03:02] That's sad. In fact, because it takes you a hundred or more hours. A few years ago, they were saying about 300 hours nowadays. It's less in order to get your identity kind of back in control. I suspect it probably is closer to 300, frankly, because you. To call anybody that pops up on your credit report. Oh, and of course you have to get your credit report.

[00:03:29] You have to review them closely. You have to put a freeze on your. Got an email this week from a listener whose wife had her information stolen. He had lost a wallet some years ago and she found because of a letter that came saying, Hey, thanks for opening an account that someone had opened an account in her name.

[00:03:51] Now the good news for her is that it had a zero balance. Caught it on time. And because it was a zero balance, it was easy for her to close the account and he's had some problems as well because of the lost wallet a few years back. So again, some basic tips don't carry things like your social security card in your wallet.

[00:04:17] Now you got to carry your driver's license because if you're driving, the police wanted, okay. Nowadays there's in some ways less and less of a reason to have that, but our driver's license, as you might've noticed on the back, many of them have either a QR code or they've got a kind of a bar code scan on them, but that big QR code contains all kinds of information about.

[00:04:41] You that would normally be in the online database. So maybe you don't want to carry a bunch of cash. Although, you know, cash is king and credit cards can be problematic. It kind of depends. And the same thing is true with any other personal identifiable information. Keep it to a minimum in your wall. But there is a place online that I mentioned just a minute ago that does have the ability to track much of the dark web.

[00:05:13] Now this guy that put it together, his name's Troy hunt, and Troy's an Australian he's been doing this. Public service for forever. He tried to sell his little company, but the qualifications for buying it included, you will keep it free. And there are billions of people, or I shouldn't say people there's billions of requests to his website about people's private information.

[00:05:42] So, how do you deal with this? What do you do? Well, the website is called, have I been poned? Have I been E and poned P w N E D. Ponying is an old term that comes from. Uh, these video games before they were online. And it means that basically I own you, I own all of your properties. You've been postponed and that's what Troy kind of followed here.

[00:06:11] Have I been postponed to.com is a website that you can go to now. They have a whole bunch of other things. They have API calls. For those of you who are programmers and might want to keep an eye out for your company's record. Because it does have that ability as well. And it has a tie ins too, with some of the password managers, like one password to be able to tell is my new password, any good.

[00:06:41] And which websites have been hacked. Does that make sense? And so that is a very good thing, too, because if you know that a website that you use has been hacked, I would like to get an email from them. So the first thing right there in the homepage, you're going to want to do. Is click on notify me. So you ensure in your email address, I'm going to do that right now, while we're talking, they've got a recapture.

[00:07:12] I'm not a robot. So go ahead and click that. And then you click on the button. Notify. a lot of people are concerned nowadays about the security and safety of their information. They may not want to put their email address into a site like this. Let me assure you that Troy. Is on the op and up, he really is trying to help.

[00:07:39] He does not use any of the information that you provide on his website for evil. He is just trying to be very, very helpful. Now his site might get hacked, I suppose, but it has been just a huge target of. Characters and because of that, he has a lot of security stuff in place. So once you've put your email address right into the notify me box, click on notify me of

[00:08:06] Of course you got to click the I'm not a robot. So once you've done that, It sends you a verification email. So all you have to do at that point, it's just like my website. When you sign up for my newsletter, keep an eye out for an email from Troy from have I been poned.com asking you if you signed up for his notification service?

[00:08:31] Obviously it is a very good idea to click on his link in the email. Now I caution people, it costs. And you guys all of the time about clicking on links and emails, because so many of them are malicious, but in the case of like Troy or my website, or maybe another one that you sign up for, if you just signed up for.

[00:08:54] You should expect an email to come to your mailbox within a matter of a couple of minutes, and then you should spend just that minute or so. It takes to click on that email to confirm that you do want to get the emails from the website, because if you don't hit that confirmation, you're not going to get the emails.

[00:09:17] Let me explain a little bit about why that is. Good guys on the internet don't want to spam you. They don't want to overload you with all kinds of emails that may matter may not matter, et cetera. They just want to get you information. So every legitimate, basic a guy out there business, a organization, charity that is legitimate is going to send you a confirmation email.

[00:09:50] The reason is they don't want someone to who doesn't like you let's say to sign you up on a few hundred different emails site. And now all of a sudden you're getting. Well, these emails that you didn't want, I had that happen to me years and years ago, and it wasn't sites that I had signed up for. In fact, some of them were rather pornographic and they kept sending me emails all of the time.

[00:10:19] So Troy is going to send you just like I do another legitimate website, send you an email. The link that you must click. If you do not click his link, you are not going to get the emails. It's really that simple. Now, Troy looking at a site right now has information on 11 billion pond account poned accounts.

[00:10:47] Really? That is huge. It is the largest collection that's publicly available of. To count. So I'm, we're going to talk about that a little bit more. And what information does he have? How does he protect it? What else can you find out from? Have I been poned? This is an important site. One of the most important sites you can visit in order to keep yourself safe.

[00:11:16] Next to mine. Right? Make sure you visit right now. Craig peterson.com/subscribe and sign up for my newsletter and expect that confirmation email to.

[00:11:29] Have you been hit by ransomware before? Well, it is a terrible thing if you have, but what's the future of ransomware? Where is it going? We've talked about the past and we'll start with that and then move into what we're expecting to come.

[00:11:46] The future of ransomware is an interesting one. And we kind of have to look at the past in ransomware.

[00:11:55] Ransomware was pretty popular in that bad guy. Just loved it. They still do because it is a simple thing to do. And it gives them incredible amounts of flexibility in going after whoever they want to go. After initially they were sending out ransomware to anybody's email address. They could find and hoping people would click on it.

[00:12:24] And unfortunately, many people did click. But back then the ransoms were maybe a couple hundred dollars and you paid the ransom and 50% chance you got your data back. Isn't that terrible 50% chance. So what do you do? How do you make all of this better? Make your life better? Well, ransomware really, really drove up the value of Bitcoin.

[00:12:54] Bitcoins Ascension was largely based on ransomware because the bad guys needed a way that was difficult to trace in order to get paid. They didn't want the bank to just sweep the money back out of your account. They didn't want the FBI or other agencies to know what they were doing and where they were located.

[00:13:20] So, what they did is, uh, they decided, Hey, wait a minute. Now this whole crypto game sounds interesting. And of course talking about crypto currency game, because from their viewpoint, it was anonymous. So they started demanding ransoms instead of dollars, PayPal, even gift certificates that they would receive from you.

[00:13:46] They decided we're going to use some of the cryptocurrencies. And of course the big one that they started using was Bitcoin and Bitcoin has been rather volatile. Hasn't it over the years. And its founding was ethically. Empty, basically what they did and how they did it. It's just disgusting again, how bad some people really are, but they managed to manipulate the cryptocurrency themselves.

[00:14:17] These people that were the early. There's of the cryptocurrency called Bitcoin and they manipulated it. They manipulated people into buying it and accepting it, and then they managed to drive the price up. And then the, the hackers found, oh, there's a great way to do it. We're going to use Bitcoin. And so they demanded ransoms and Bitcoin, and they found that no longer did they have to get like a hundred dollar gifts, different kid for Amazon.

[00:14:46] Now they could charge a thousand dollars, maybe even a million dollars or more, which is what we saw in 2021 and get it paid in Bitcoin. Now Bitcoin is kind of useful, kind of not useful. Most places don't take Bitcoin as payment, some have started to because they see it might be an investment in the future.

[00:15:11] I do not use Bitcoin and I don't promote it at all, but here's what we've been seeing. Uh, and this is from the chief technology officer over tripwire, his name's Dave Meltzer. What we've seen with ransom. Attacks here. And the tie to Bitcoin want to cry back in 2017 was terrible and it destroyed multiple companies.

[00:15:39] One of our clients had us protecting one of their divisions and. We were using really good software. We were keeping an eye on it. In fact, in the 30 years I've been protecting businesses from cyber intrusions. We have never, ever had a successful intrusion. That's how effectively. And I'm very, very proud of that.

[00:16:05] Very proud of that. We've we've seen ransomware attacks come and go. This wanna cry. Ransomware attack destroyed every part of the company, except for. The one division we were protecting, and this is a big company that had professional it, people who really weren't very professional. Right. And how, how do you decide, how do you figure out if someone really knows what they're talking about?

[00:16:32] If all they're doing is throwing around buzzwords, aren't, that's a huge problem for the hiring managers. But anyways, I digress because having a. Particular series of letters after your name representing tests that you might've passed doesn't mean you're actually any good at anything. That's always been one of my little pet peeves over the decades.

[00:16:55] Okay. But another shift in the targeting of ransomware now is showing a major uptick in attacks. Operational technology. Now that's a real big thing. We've had some huge hits. Uh, we think of what happened with solar winds and how it got into solar wind software, which is used to monitor computers had been.

[00:17:24] And had inserted into it. This one little nice little piece of code that let the bad guys into thousands of networks. Now we've got another operational technology hack in progress. As we speak called vog for J or log for shell. Huge right now, we're seeing 40% of corporate networks are right now being targeted by attackers who are trying to exploit this log for J.

[00:17:53] So in both cases, it's operational software. It's software businesses are using. Part of their operations. So we're, and part of that is because we're seeing this convergence of it, which is of course information technology and operational technology environment. In many times in the past, we've seen, for instance, the sales department going out and getting sales force or, or something else online or off.

[00:18:25] They're not it professionals in the sales department or the marketing department. And with all of these kids now that have grown up and are in these it departments in their thirties and think, wow, you know, I've been using technology my whole life. I understand this stuff. No, you don't. That has really hurt a lot of bigger companies.

[00:18:48] Then that's why some companies have come to me and saying, Hey, we need help. We need some real adult supervision. There's, there's so many people who don't have the decades of experience that you need in order to see the types of holes. So. We've got the it and OT kind of coming together and they've exposed a technology gap and a skills gap.

[00:19:16] The businesses are trying to solve right now in order to protect themselves. They're moving very quickly in order to try and solve it. And there they've been pretty much unable to. And w we use for our clients, some very advanced systems. Hardware software and tools, because again, it goes back to the kind of the one pane of glass.

[00:19:38] Cisco doesn't really only have one pane of glass, but that's where it goes back to. And there's a lot of potential for hackers to get into systems, but having that unified system. That Cisco offers really helps a lot. So that's kinda my, my little inside secret there, but we walk into companies that have Cisco and they're completely misusing them.

[00:20:02] In fact, one of these, uh, what do you, would you call it? Well, it's called a school administrative unit in my state and it's kind of a super school board, super school district where there's multiple school districts. Hold two. And they put out an RFP because they knew we liked Cisco and what some of the advantages were.

[00:20:22] So they put out a request for proposal for Cisco gear and lo and behold, they got Cisco gear, but they didn't get it configured properly, not even close. They would have been better off buying something cheap and being still exposed. Like, you know, uh, I'm not going to name some of this stuff you don't want to buy.

[00:20:42] Don't want to give them any, uh, any airtime as it were. But what we're finding now is law enforcement has gotten better at tracking the digital paper trail from cryptocurrencies because cryptocurrencies do have a. Paper trail and the bad guys didn't realize this. At first, they're starting to now because the secret service and the FBI have been taking down a number of these huge ransomware gangs, which is great.

[00:21:16] Thank you very much for doing that. It has been phenomenal because they've been able to stop much of the ransomware by taking down these gangs. But criminal activity that's been supported by nation states like North Korea, China, and Russia is much harder to take down. There's not much that our law enforcement can do about it.

[00:21:42] So w how does this tie into ransomware and cryptocurrency while ultimately. The ability to tr address the trail. That's left behind a ransom payment. There's been a massive shift in the focus from government trying to tackle the underlying problem of these parolees secured curdle Infor critical infrastructure sites.

[00:22:06] And that's what I did training for. The eyes infra guard program on for a couple of years, it has shifted. Now we've got executive orders. As I mentioned earlier, from various presidents to try and tighten it up and increase government regulation mandate. But the big question is, should you pay or not? And I recommend to everyone out there, including the federal government recommends this, by the way, don't pay ransoms because you're just encouraging them.

[00:22:40] Well, as fewer and fewer ransoms are paid, what's going to happen to Bitcoin. What's going to happen to cryptocurrencies while the massive rise we saw in the value of Bitcoins will deteriorate. Because we won't have businesses trying to buy Bitcoin before they're even ransomed in order to mitigate any future compromise.

[00:23:06] So I love this. I think this is great. And I think that getting more sophisticated systems like what, like my company mainstream does for businesses that I've been doing for over 30 years is going to draw. Well, some of these cryptocurrencies like Bitcoin down no longer will the cryptocurrencies be supported by criminals and ransomware.

[00:23:35] So that's my hope anyways. And that's also the hope of David Meltzer, chief technology officer over at tripwire hope you're having a great year so far. You're listening to Craig Peter sohn.com. Sign up for my. At Craig peterson.com. And hopefully I can help you have a little bit of a better year ahead.

[00:23:57] All of these data breaches that the hackers got are not graded equal. So we're going to go through a few more types of hacks, what they got. And what does it mean to you and what can you do about it?

[00:24:13] Have I been B EEN poned P w N E d.com. And this is a website that has been put together by a guy by the name of Troy hunt. He's an Australian and it goes through the details of various. So that he has found now it's not just him. There are a lot of people who are out there on the dark web, looking for hacks, and there's a few different types of hacks.

[00:24:43] And of course, a lot of different types of information that has been compromised and gathered by the bad guys. And, um, stat just out this week is talking about how businesses are so easy. To compromise. It is crazy. This was a study that was done by a company called positive technologies, and they had a look at businesses.

[00:25:11] Basically they did white hacking of those businesses and found that 93% of tested networks now. 3% of tested networks are vulnerable to breaches. Now that is incredible. And according to them in dark reading, it says the vast majority of businesses can be compromised within one month by a motivated attacker using common tech.

[00:25:42] Such as compromising credentials, exploiting, known vulnerabilities in software and web applications or taking advantage of configuration flaw. Isn't that something in 93% of cases, an external attacker could breach a target company's network and gain access to local devices and systems in 71% of cases, the attacker could affect the business in a way deemed unacceptable.

[00:26:13] For example, every. Bank tested by positive technologies could be attacked in a way, the disrupted business processes and reduced their quality of service. It's a very big deal. And much of this has to do with the fact that we're not taking cyber secure. Seriously as businesses or as government agencies.

[00:26:41] Now, the government agencies have been trying to pull up their socks. I got to give a handout to president Biden. He really started squeezing many of these federal contractors to get security in place. President Trump really pushed it even back to president Obama, who. Pushed this fairly heavily. Now we're starting to see a little bit of movement, but how about the smaller guys?

[00:27:08] How about private businesses? What are you doing? So I'm going through right now. Some of the basic things you can get from, have I been poned and what you can do with all of that data, all of that information, what does it mean to you? So I'm looking right now at my business email address, which isCraig@mainstream.net, pretty simple Craig and mainstream gotten that.

[00:27:36] And I found because this email address is about 30 years old. Yeah. I've been using it a long time, about 14 data breaches and. Paste. All right. So what does that mean? What is a paste? Well, pastes are a little bit different than a regular hack. All right. The paste is information that has been pasted to a publicly facing.

[00:28:03] Website. Now there's many of them out there. There've been a lot of breaches of Amazon site of Amazon databases, Azure, all of these types of things. But we're, we're talking about here are these websites that are designed to. People to share whatever they want. So for instance, you might have a real cool program, wants to people, those to try out to you don't have the bandwidth to send it to them.

[00:28:28] You certainly can send it via email because it's much, much, much too big. So sites like Pastebin or out there to allow you to go ahead and paste stuff in and share the link. Pretty simple, fairly straightforward. Well, these pay sites are also used by hackers to make it even easier for them to anonymously share information.

[00:28:55] And many times the first place that a breach appears is on one of these paste sites. So have I been poned searches through these different pastes that are broadcast by a Twitter account called dump Mon, which is a site where again, bad guys are putting information out about dumps had been found as well as good guys.

[00:29:20] All right. And they. Port, uh, on, in the dump mom dump MUN Twitter account. If you're interested, it's at D U M P M O N. They report emails that are potential indicator of a breach. So finding an email address in a paste. Necessarily mean it's been disclosed as a result of a breach, but you should have a look at the paste and determine whether or not your account has been legitimately compromised as part of that breach or not.

[00:29:53] All right. So in my case again, for theCraig@mainstream.net email address, it was involved. In a paste. So let me see what it says. So let me see. It shows it involved in a pace. This is pace title AA from July, 2015. So this is information from published to a publicly facing website. I don't know if I click on that.

[00:30:22] What does it do? Yeah. Okay. So it actually has a link to the paste on AEs to ban. And in this case it's gone, right? It's been deleted. It could have been deleted by the Pastebin staff. Somebody told them to take it down, whatever it is. But again, have I been poned allows you to see all of the information that has been found by the top security.

[00:30:48] Researchers in the world, including various government agencies and allows you to know what's up. So let's have a look here at passwords. So if you click passwords at the very top, this is the other tool you should be looking at. You can safely type in the passwords you use. What have I been poned does is instead of taking the passwords from these hacks in the clear and storing them, it creates a check some of the password.

[00:31:21] So if you type a password into this, I'm going to type in P a S S w Z. Oh, excuse me. Uh, oh, is that, let me use a better password. P at S S w zero RD. One of the most common passwords on the internet, common passwords ever. Okay. So it says, oh no, poned this password has been seen 73,586 times B four. Okay. It says it, the passwords previously.

[00:31:53] Appeared in a data breach and should never be used if you've ever used it anywhere before change it. You see, that's why you need to check your passwords here. Are they even safe to use because what the bad guys have done in order to counter us using. Longer passwords. Cause it's not the complexity of the password that matters so much.

[00:32:16] It's the length of the password. So they don't have enough CPU resources in order to try every possible password from eight characters through 20 characters long, they could never do that. Would take forever or going to try and hack in. So what they do is they use the database of stolen passwords in order to try and get in to your account.

[00:32:42] Hey, I'm going to try and summarize all of this in the newsletter. So keep your eye. For that. And again, the only way you're going to find that out and get my summary today, including the links to all of this stuff is by being on my email list. Craig Peterson.com/subscribe. That's Craig Peterson, S O n.com/subscribe, stick around.

[00:33:09] Did you know, there is a site you can check your password against to see if other people have used it. And if that password has been stolen, it's a really great site called have I been postponed? And we're going to talk about it more right now.

[00:33:26] You know, I've been doing cyber security pretty much as a primary job function here in my career for about, let me see.

[00:33:37] Not since 92. So my goodness, uh, yeah, an anniversary this year. Okay. 30 years. So you're listening to a lot of experience here as I have. Protect some of the biggest companies in the world, the department of defense, defense, and military contractors all the way down through our local dentist's office. So over 5,000 companies over the years, and I helped perform what are called virtual CIS services.

[00:34:11] Which are services to help companies make sure that they have their security all lined up. And we also have kind of a hacker audit whether or not you are vulnerable as a business to being hacked. So we'll go in, we'll look at your systems. We can even do a little bit of white hat hacking in order to let you know what information is out there available about your company.

[00:34:39] And that's really where. Have I been poned comes in. It's a very simple tool to use and it gives you some great information, some really good information about what it is that you should be doing. What is that? I had a meeting with the FBI, one of my client's sites, because they had been hacked and my client said, yeah, go ahead and bring them in.

[00:35:03] And it turned out to be the worst infection that the Boston office of the FBI has ever seen. There were active Chinese backdoors in there stealing their information. Their plans are designed everything from them. Right there. Right. And, oh, it was just incredible to see this thing that it all started because they said they had an email problem.

[00:35:30] We started looking at more closely and we found him indications of compromise, et cetera. So it gets bad. I've been doing this for a long time. But one of the things that you can do, cause I understand not everybody can do what we do. There are some very complicated tools we use and methods, methodologies, but this is something anyone can do.

[00:35:53] Again, this site's called, have I been poned.com? You don't have to be a white hat hacker to use this. This is not a tool for the black hats, for another words, for the bad guys, for the hackers out there. This is a tool for you, whether you're a business person or a home user. And we talked about how you can sign up there to get a notification.

[00:36:18] If your account has been hacked. So I'm going to the site right now. Have I been poned, which is spelled P w N E D. Have I being B E N poned P w N E d.com. And I'm going to type in me@craigpetersong.com, which is my main email address for the radio show and others. So good news. It says. Postage found. In other words, this particular email address has not been found in any of the hacks on the dark web that Troy has access to.

[00:36:56] Now, remember, Troy does not know about every hack that's occurred. He does not know about every data breach that has occurred, but he knows about a whole lot of them. And I mean, a lot. If you look on his site right there in the homepage, you'll see the largest breaches that he knows about drug. For instance, 510 million Facebook accounts that were hacked.

[00:37:24] He has the most recently added breaches. We just got an addition from the United Kingdom, from their police service over there. Some of the more recent ones include Gravatar accounts. Gravatar you might have a, it's a very common, in fact, 114 million Gravatar accounts information were compromised. So me at Craig Peterson is safe.

[00:37:52] Well, let me check. My mainstream email address now, mainstream.net is the website that I've been using for about 30 years now online. And this is the company that I own that is looking at how do we protect businesses? No. And we're a small company, basically a family operation, and we use a lot of different people to help out with specific specialties.

[00:38:21] But let me seeCraig@mainstream.net, this one's guaranteed to be poned all right, because again, that email addressCraig@mainstream.net is close to 30 years old. Uh, okay. So here we go. 14 data breaches. It says my business email address has been involved. Eight tracks back in 2017 and it says compromised data was emails and passwords.

[00:38:48] The Apollo breach in July of 2018. This was a sales engagement startup email address, employer, geographic location, job, title, name, phone number salutation, social media profiles. Now you see this information that they got about me from this Apollo breach. Is the type of information that they need in order to fish you now, we're talking about phishing, P H I S H I N G.

[00:39:17] And the whole idea behind fishing is they trick you into doing something that you probably. Should not do. And boy, do they trick you into it? Okay. So the data left, exposed by a Paulo was used in their revenue acceleration platform and it's data that they had gathered. That's fishing stuff. So for instance, I know my company name, they know where it's located.

[00:39:44] They know what my job title is, uh, phone numbers, uh, how to address me, right. Not my pronouns, but salutations, uh, and social media profile information interest in it. So think about all of that and how they could try and trick me into doing something that really is against my best judgment. My better interest makes sense.

[00:40:09] Co this big collection collection. Number one in January, 2019, they found this massive collection of, of a credential stuffing lists. So that's combinations of email addresses and passwords. It's the, uh, 773 million record collection. So what password stuffing is, is where they have your username. They have your passwords that are used on multiple accounts.

[00:40:40] Now, usually the username is your email address and that's a problem. And it really bothers me when websites require your email address for you to log in, as opposed to just some name that you make up. And I make up a lot of really cool names based on random words. Plus I have 5,000 identities that are completely fabricated that I use on various social media sites or other sites where I don't care if they have my right information.

[00:41:14] Now, obviously the bank's gonna need your information. You can't give it to the, you know, the fake stuff to law enforcement. Too anyways, but that's what credential stuffing is. They will use the email address that you have, that they found online in one of these massive dumps, or maybe one of the smaller ones are long with the passwords.

[00:41:39] They found that you use on those websites and they will stuff them and other. They'll use them on a website. They will continually go ahead and just try different username, different password combinations until they get in. Now, that is a very, very big problem called credential stuffing. And that's why you want to make sure that you change your password when a breach occurs.

[00:42:10] And it isn't a bad idea to change it every six months or so. We'll talk more about this when we get back, but I want you to make sure you go right now because we've got bootcamps and other things starting up with just probably mid to late January. And you only find out about them@craigpeterson.com.

[00:42:32] Make sure you subscribed. .

View Details

Are You Ready For the Next Hacker Wave? It's Going to Be Brutal!

Right now, we're going to talk about this vulnerability, this huge vulnerability in almost the entire internet that will affect your life over the following number of years. And if you're a business, you better pay close attention.

[Following is an automated transcript]

[00:00:16] Well, we are looking at what is being called the single most significant, most critical vulnerability ever.

[00:00:24] And if you want more information on this, have a look at last week's show, you'll find it up on my website. I talked quite a bit about it. You can email me M e@craigpeterson.com. I've put together a little cheat sheet that you can use to find out. What should I do? If you're an IT professional, this isn't something that you can do if you're a regular home user because you probably don't have any software your maintaining that has this log for J vulnerability.

[00:00:59] But I do have to warn you that you probably do have a little bit of hardware that might have it in there. Many of these firewalls used in homes have it, not all of them, uh, I'm, a minority of them, but here's why this is the single most significant and most critical vulnerability ever. There is a programming lab library that is used in the job.

[00:01:26] Programming language that logs events, if you're writing software and let's say their software is running a website, it could be almost anything. And do you notice a condition that's not quite right? What should you do while you should log it? And then, hopefully, the people that are running your software are monitoring the logs.

[00:01:49] See the logs? No. Oh my gosh. Uh, there is something wrong here. One of the logs that I keep an eye on that just absolutely amazes me, frankly, is the SSH Daemon logs. Now SSH is a protocol. It uses encryption to get onto other machines using the command line. Now I've used a lot of protocols over the years to do this.

[00:02:17] Telnet was the first, and SSH is something that I've been using for a very long time. You might remember the Heartbleed bug from a few years back. That nailed a lot of people, but I keep an eye on that SSH log because. If someone's trying to log into my system from the internet, that log will show it.

[00:02:39] It's going to say that someone to try to use this username; they were coming from this IP address, and they failed to get in. And I have software that automatically monitors that log and says, well, if someone's coming from the same. Address multiple times. And they are unsuccessful at logging in add their internet address to my firewall blocking rules.

[00:03:09] So what ends up happening is. Well, they just can't even get to my machine anymore. They're trying to hack me. same thing's true with the web blogs. If we have people who are trying to, for instance, kind of put us out of business doing what's called a denial of service attack, where they are sending us a lot of data.

[00:03:31] Well, we can at our site or upstream from us have that IP address. Block. And that stops the attack, distributed denial of service attacks, or are a little bit more complicated. So all of this gets logged. It all gets written to a file, or it gets pushed off to a server that keeps track of the logs. And, and then there's analysis software, the looks at logs for.

[00:03:57] Anomalies, all of that sort of stuff. It makes a lot of sense. Right. But this particular library that's used by Java programmers has a bug in it that allows a remote user to send just a small string, nothing fancy at all that can command. The web server that is using the logging function to go ahead and download malware.

[00:04:28] Well, the easiest low-hanging fruit, when it comes to what kind of malware can we put onto a computer is quite simply crypto mining. So the bad guys they'll go ahead and they'll just send a small string, very simple. They don't have to compile a program. They don't have to do much of anything. They just send this little small.

[00:04:50] And if that string gets logged, for instance, by my SSH, my remote access demon, or gets logged by the web server or something else, all of a sudden that wonderful little feature that allowed you to easily log things. Is your enemy because that feature is going to interpret that particular string that was sent to the log and try and be helpful.

[00:05:18] But in fact, it could be given a command to download this remote file. Ran, then run that remote file. And that remote file initially here has primarily been crypto mining soft. So now your computer's being used by someone else. Your electricity's being used to mine. Things like Bitcoins or some of these other cryptocurrencies that are out.

[00:05:45] Now the real reason, this is a huge, huge problem. Again, let me quote here. This is from Ahmad, a mate. I should say you're an over a tenable. It is by far the single biggest, most critical vulnerability ever. Why is that true? There's a couple of reasons. Ease of use is the obvious reason. It is so easy to use, not just for crypto mining, but for hacking any machine you would care to hack.

[00:06:19] And then the second reason is it is in bedded everywhere. There are millions of computers that are vulnerable. We're seeing a hundred. Computers per minute, being hacked using this vulnerable. And if you are running, let's say a firewall that has this vulnerability. We have some clients that had this vulnerability and it is obviously a bit of a problem, right?

[00:06:51] Well, that vulnerability now allows bad guys to get onto that firewall. And perhaps beyond that firewall, in order to do pretty much whatever they want. To do. This is huge, huge, huge, lots of software has flaws, and you need to be able to recover from the flaws. I've talked many times about how there are only two types of software.

[00:07:23] There are software that has been hacked and there are software that will be hacked. So you need to make sure you know, that if someone gets into your network or gets into your computer, that you can restrict the damages, you can keep it under control. But with this log for J vulnerability, B. Everywhere in, not just that one library, but remember that one library is used all over the place.

[00:07:52] It's in hundreds of thousands of pieces of software. Now, every one of these vendors has to grab the most recent version, recompile their software and send and re link it in deep pans. Right. I understand this is Java and then send it out to all of their customers to install the software. This is the second reason.

[00:08:15] It is such a big. There will be sites. There will be pieces of software that have this vulnerability for years to come. And one of the biggest examples of this vulnerability is almost every Android device out there. Think of all of the phones. People have Androids being used for tablets it's in televisions, it's everywhere.

[00:08:40] And with this particular vulnerability. Being everywhere. Every vendor that uses Android is going to have to release patches that you're going to have to install. Now it's one thing to have a brand new TV, and we've got a brand new Samsung TV and it's hooked up to the internet. It streams, Disney and discovery.

[00:09:05] And it's just a wonderful thing. I love my TV, right then of course you probably realize I don't use smart TV features because of this particular type of person. What ends up happening? Well, how long is Samsung actually going to support updates for your television or Vizio who, by the way, one of the worst companies, when it comes to your privacy of your information on your television, how long, uh, how about your Android phones?

[00:09:39] More than half of all Android smartphones out there, we'll never get another software. If you are still using Android smartphones now is the time to switch to an iPhone. I have been talking about this for years. I am not like the world's biggest apple fan. I'm not trying to make everybody an apple fan. I really don't care.

[00:10:06] What I do care about is the ability of the software designers, those software implementers and the hardware manufacturers, the people that are in the supply chain on that Android device. I care that they do. Provide updates when it comes to security problems. And if you're using an iPhone, yeah. Again, two types of software right now, like phones have had vulnerabilities that can be vulnerable, but apple is supporting right now, still the iPhone six S which came out what five or six years.

[00:10:46] With full security updates. They've even gone back further. Sometimes the Nat. So make the switch right now. If you are an it professional, I've got this whole list of resources that I vetted, I know are good that you can use to scan for this vulnerability in your network or on your. To where just email me M e@craigpeterson.com.

[00:11:12] And if you have any questions about this or cybersecurity in general, just reach out again. me@craigpeterson.com.

[00:11:21] Did you know that cyber flashing is a thing. We talked about it a couple of years ago, but it's back in the news this week and also apple air tags. They just released a new feature for our friends with Android. We'll tell you why.

[00:11:38] Have you seen these air tags? Have you used them? They came from an idea that was really pioneered by company. Tile. And I guess they, I don't know what happened with the patent. I guess it didn't have one or apple wouldn't have been able to do this, but then again, you know, you've got a really big company you're up against a, it doesn't matter whether you're in the right.

[00:12:02] Sometimes I'm not sure what happened there, but they have. These trackers called air tags. And I mentioned before on the show that my daughters have a total of five cats, well, actually six cats. Now I think of it. And what they've done is bought air tags and put them on. All of the cats callers. So they took them, they they've got them fastened on with this little holder.

[00:12:31] You can get all kinds of holders. The air tags themselves are just little round buttons, really, and you can stick them into your wallet. For instance, in case you keep forgetting or losing your wallet, you can also put them into a holder. So they go on a key chain. I have a couple of flashlights at the house.

[00:12:50] And if you're like me and you have other people around and it's dark and they know where your flashlight is, they'll take and borrow it right now. You don't get your flashlight back. It kind of bothers me. I probably shouldn't bother me as much as it does, but then when I need the flashlight, I just can't find this.

[00:13:12] So, what did we put on the flashlight? We put an air tag on there. So the airtight ties into your iPhone. And if you have a newer iPhone, it's just absolutely amazing because the, the airtight will tell you where it is, but the newer iPhone, you can use it and it will walk you through. Up to the air tag, like, okay, it's a foot in front of you on the left-hand side or whatever, it'll take you there.

[00:13:42] It's very cool. It's like these futuristic scifi movies. The problem with air tags that we discussed on the air here is that they have been used for evil. And what the bad guys have been doing is they'll take an air tag. They might drop it in your purse in order to follow you. Isn't that scary. They also have been taking the air tags and putting them on expensive cars so that they can follow you home.

[00:14:16] Now, obviously nowadays it's extremely hard to steal one of the more expensive cars cause they've got all of this automation in them. The fancy systems do stop you from stealing it. Even my old F150 had a little chip built into the key so that it wouldn't start and less, that key that was starting. It actually had that RFID chip in it so that this technology.

[00:14:45] Isn't being used so much to steal the car, but to know where you live and when you are home and when you're not home, you know, I've been warning everybody for many years, not to post on social media about vacation saying, oh, we're leaving. We're going to be gone in the Caribbean for two weeks. We're going for new year's party here, Christmas there, Hanukkah celebration, whatever it is you're doing, because the bad guys use that information to.

[00:15:19] I'm break into your home and to steal things from your business. And I'm, I'm going to get into all of the details right now of how they do that. I've talked about it on the show before, and I'm sure I will talk about it again. And you'll even see some of the references on my website@craigpeterson.com.

[00:15:36] If you're interested, there's some real interesting stories up there. What's happened to people. That particular problem of having an air tag and then having it put on to you to track you, or do you track your car or other devices is a huge potential problem. Now, apple built into the iPhone, a special little feature some time ago that when they, in fact, when they came out with the air.

[00:16:11] So that when an airtight is following you, in other words, someone dropped it into your purse or your pocket or on your car. And that air tag is moving with you. It says, Hey guy, uh, there is an air tag following you. And at that point you can say, wait a minute, uh, what's going on here now? It's not going to warn you about your own air tags.

[00:16:35] You know, the ones that you own. It's going to warn you about an, a foreign air tag one. That's not yours. In other words, someone's trying to track you so brilliant. Move on. Apple's part to get that out right away before there were any really scary, bad news stories about the same thing happened. How about Android users?

[00:16:57] That's where the problem really is starting to come up. If you're an Android user, you don't have the ability to detect an air tag. Well until now. So if an air tag was following you, it wouldn't. Let you know, it couldn't let you know it didn't know. So apple is now offering what's called tracker detect.

[00:17:21] It's an app on the Google play store, a free app that you can download if you using Android. And, you know, there are many, many, many, many reasons not to use Android and there's. Are almost as many to use iPhones. Okay. So if you use an Android switched to an iPhone, but if you're stuck on Android, because that's what your business gave you until you have to use it, have a look for tracker detect to end the apps description on the play store says tracker detect looks for item trackers that are separated from their owner, and that are compatible with Apple's find mine network.

[00:18:02] These items, trackers include air tags and compatible devices from other companies. If you think someone is using air tag or another device to track your location, you can scan, scan to try and. So, I'm not sure that it's as good as the apple implementation, where the apple will pop up and say, even though you're not scanning for an air tag, say, Hey, somebody's tracking you.

[00:18:31] It sounds like you have to actually use. Just scan for it. But Android users, according to Mac trust can scan the area to find nearby error tag trackers. If they think that there's an air tiger or other device that's being used to track their location, uh, an apple support document that you'll find online on support that apple.com.

[00:18:57] Says, if you think someone is using an air tiger, other item tracking to track your location, you can scan to try and find it. If the app detects an air tag near you for at least 10 minutes, you can play a sound to help locate it. So that's the part that makes me think that it's always active. Okay. On your, on your Android device, it's free and you can get it right there in the Google play.

[00:19:23] This next item is really, it applies to all of us here in the us, and it applies also to people over in the UK. And the UK is really getting kind of upset about this because apparently there are no laws against. Flashing now there are in the U S and it kind of depends on where you live, but cyber crap flashing is really a crime or should be a crime what's been happening.

[00:19:58] Is people again who have iPhones have this ability to share files or websites, et cetera, with another person. It's fantastic. It's called airdrop. I just love this. And I use it all the time even to share files between my own devices. And what happens with air drop is you, you take the file and the use open up airdrop and you see, oh, okay.

[00:20:26] There's my wife right there. So I click on the file. I drag it on top of it, a little Karen icon in airdrop, and now she gets a notice. Hey, there's a file from. Coming on in, and it does well, I always in my family and my business people, I always said to them, Error drop, uh, settings to only allow an airdrop from people that are in my contact list.

[00:20:57] And that reason for that is this particular problem. People have been cited. Flashing. So what they do is they send obscene pictures to strangers through airdrop. And this term can also of course, apply to Bluetooth devices because you can also send these things via Bluetooth. I don't want to really talk a lot about what's really happening here.

[00:21:28] Hopefully, you know what flashing is, or flasher is sending these obscene pictures, but the tone, the term was coined in August 25th. This female commuter was airdropped two pictures, obscene pictures, and they reported it to the British transport police. But we've seen, I have seen, and I've talked about cases where people are driving down the highway and all of a sudden on their phone come these obscene pictures because someone was driving past and they air dropped, or they use Bluetooth to send obscene.

[00:22:09] There is an easy way to not allow that to happen. And that is the settings that I use, which is only allow airdrop from people in your contact list. You know, these are absolutely amazing features that they have, but there are some really weird people out there that think that this is the, this is a fun way, uh, to really mess with other people.

[00:22:36] It's. It's just crazy. Okay. By the way, you can also turn air drop off. If you never use it, don't worry about it or a turn it on when you need it. And when someone's going to send something to you, Hey, I want you guys to take a couple of minutes here. If you go to Craig peterson.com/subscribe. You're going to find out about the bootcamps we have.

[00:23:01] You're going to get my weekly trainings that I have. These are just an email. They just last a few minutes. You are going to love them. I get all kinds of compliments and this is in my free newsletter. Okay. It's not going to cost you anything. I'm not going to be hammering you on buying stuff. I want this information out.

[00:23:24] That's why I am here today on. Everybody needs to understand this stuff. Craig peterson.com/subscribe, and I will be seeing you in the email world.

[00:23:39] One of the things we wonder the most about is what's the future. What's the future of laptops and future of computers. We talked about some of these new chips that are out there, but this is an interesting story about what Dell is doing. Yeah. Dell.

[00:23:55] I want to follow up a little bit about the 3g shutdown. We didn't quite get through the list.

[00:24:02] All almost all of the Volvos from 2015 on to 2018, have this problem. There's only two automakers that told the drive.com that U S vehicles are unaffected by the end of 3g. So if you own a Ferrari or a McLaren, You're okay. Okay. Also what's interesting is what the different guys are doing. Subaru has an interesting little plan here going forward.

[00:24:35] If you have what they call a connected vehicle plan. And this is according to a service bulletin filed with the national highway traffic safety administration. And then they will do a retrofit at no cost. How's that for nice. A lot of these manufacturers are upgrading to 4g. Yeah, the, uh, you know, LTE, the stuff that was really fast, you remember that I was remembering getting 50 megabits and that it was just incredible.

[00:25:05] But at any rate, they're offering that and the option to purchase a subscription. To 4g. So you'll be able to get two gig of data per month at $10 a month. Now that's for some manufacturers, not all of them, have it $30 a month if you want unlimited data. So depending on how much you're driving GM started pushing a free over the air update in October to keep OnStar running.

[00:25:32] After the 3g shut down though, some 2015 model year cars will need a ma a hardware worse. Tesla says it plans to charge $200 to upgrade older model S vehicles, but no additional fees are noted for it. Toyota, Toyota and Lexus are not planning to retrofit. Affected vehicles in its public FAQ Toyota sites, a clause and its disclosures that said certain connected services may change at any time without notice.

[00:26:08] And when the drive ass Toyota, if it plans to offer an upgrade paid or otherwise for consumers who own effective vehicles, the answer was assumed. No. And Toyota, by the way, is one of the companies that has decided, Hey, um, we're just going to go ahead. And, uh, you, you, you know, that remote start that you got for those cold winters.

[00:26:31] Yeah. W we've decided that, uh, even though you paid for, you know, what, three, four years ago, we're going to start charging you monthly to use your remote start. Uh, come on guys. So have a little. Um, try and find out, talk to your, uh, your automotive dealer or go to duck, duck, go and look up your car and type in three G uh, end of life at the same time and see what it comes up with at your model in there.

[00:27:05] But I am very disappointed with Toyota. I have some friends that just loved Toyota. I bought a brand new one. Way back when, when would have been like 82, 3, something like that, a great little car Cresseta with a supra engine in it. And I drove that for quite a few years. The good, tough little car I had to keep replacing the water pump, but that was the only problem we ever had with it.

[00:27:31] But I haven't owned a Toyota since then, but this is, and I've actually been thinking about it lately, but this is something that really turns me off. I don't know about. Let's get into our next, a little problem area. And that is fleet managers. If you are relying on electronic logging devices and other internet of things, devices to track your trucking fleet.

[00:27:57] There's some problems. Uh, let's see here, here's a quote. This is from Czech Republic. Uh, John Nichols, executive vice president of sales for north America and mixed telematics estimated that about 80% of his customers are still using 3g devices. Now this was about a year ago. This is from a November, 2020 article.

[00:28:22] So this is going to be a very. Problem for you as well. Uh, for any people who have fleet vehicles that they're trying to maintain, hopefully you know about this. Hopefully your vendors are going to take care of it for you. I'm impressed. The GM set their cars up with the hardware that can handle 3g and 4g.

[00:28:44] And all you need is a software upgrade to have it switch. I think that was very smart of them. So. Kudos to GM for that particular thing. Dell led let's get into the future of computers and laptop design. Dell has been doing some interesting things. Now you probably heard me a couple of weeks ago be moan Dell because they have businesses.

[00:29:06] Specialists and experts that you can call that really know almost nothing about what you really need. And it just drives me crazy because Dell has been selling my customers, hardware that doesn't meet the customer's needs because frankly, the customers don't really know what their needs are. And so that's something that I've helped them with.

[00:29:28] And I, if you email me@craigpeterson.com, I written up. On what the best computers to buy are based on what it is you need, you know, what, what are the tricks that you need to follow? But what Dell is doing right now is something they're calling concept Luna, and I've seen things like this before. There was a, a cell phone that was being manufactured that allowed you to change modules.

[00:29:58] They were literally just click and go and kind of like Lego. Almost and the phones weren't that popular. I don't even think they're in business anymore. I can't remember their name, but those particular clicking NGOs were clicked and gone is kind of the bottom line on it because they were kind of big.

[00:30:19] They were kind of clumsy. They weren't released something people wanted to use. You know, Android comes from Google. And Google has their basic tests and says, this is what Android should look like, but every manufacturer puts their own look and feel on top of that Android operating system. And what that ends up doing for you is, you know, makes it a little more pleasant and also.

[00:30:49] So that you don't really, really want to go and change your phones. Cause you're used to the way this particular phone works, but Dell is looking at doing kind of the same thing. They're looking at this electronic waste problem where you have a laptop, it gets old, you throw it away. And, but now it looks like there's more sustainability.

[00:31:14] Built into things like this Luna design, they're trying to make the company's laptops more environmentally friendly and in the process are going to make them more repairable, which is kind of cool. If you look at what Apple's done in their laptops, there's basically nothing inside there. That's user replaced.

[00:31:36] Okay, you can probably replace a battery. I use a company I've had their president on my show a few times. Uh, Larry, um, Connor, I think it is his last name, but OWC other world computing and they've got. Little upgrades and replacement parts and videos on how to do it and all the tools you need to, to upgrade your Mac.

[00:32:00] But nowadays apple is soldering the memory on the motherboard, or even more recently using the apple chips. And by the way, this is part of the reason they're so fast. They are putting the memory right on the same silicone and. The CPU itself. So they're moving towards a one chip with everything on it. So if you buy an apple computer nowadays, I love them.

[00:32:29] They are great. They've got great security built in, et cetera, et cetera, but you better buy a computer that has enough memory and enough storage on it to last you for some years. Because a lot of these computers I'm picking on apple right now, but there's a lot of other vendors the same way. They are not upgradeable, but concept Luna should work pretty well boring.

[00:32:56] This idea from that's right. It was framework. That was the name of it. Anyways, stick around and visit me online. Craig peterson.com.

[00:33:05] If you own a car and that car has been made, uh, all the way up to 2021 and your car is using. The internet by a 3g, which is most cars. I got a little news for you.

[00:33:22] We are looking at a real big problem here that most people haven't heard of.

[00:33:29] I was talking in fact, this week on the air with someone who has a car to Volvo and they have a remote little starter, which has been great for. And they were informed that they needed to do an upgrade. And that upgrade turned out to be very costly. I had another listener who has a solar panel on the roof of their house and their solar panel on that roof is designed to.

[00:34:03] Be able to get updates, software updates, let you know, what's the charge like how much sun is there today? Maybe you should brush off some of the snow. All of that is communicated by the. But how, how was that working? The problem that most vendors have is, uh, how do they get the data to, and from their devices?

[00:34:30] If you think about, for instance, Elon Musk, with the wonderful little Tesla cars, they want to push an update and we're seeing this more and more by. The older cars, most cars, non Tesla, as you take them into the dealer for service. And while it's there they go ahead and plug it in. They download new software firmware from the internet and install it on your car.

[00:34:56] And you are often driving. Maybe you're none the wiser. Maybe you got some new features. So it's one thing for them. To have control over a basic network, uh, network that our car dealer might have where they say, okay, here's the specs you need this much. Download speed. You need that. You need the other thing simple enough.

[00:35:20] But how about you and your home or you and your business? How does that time system keep track of the employees when they sign in and out? Does it upload it to the internet? Did you have to plug it into your network? Did you have to hook it up to your wifi? I can tell you from personal experience, anytime we touch your network and there is.

[00:35:45] Problem later on, we own the problem, even if we had nothing to do with it. It's again, it's another Craig ism, whoever touched the computer last owns the next problem. So these vendors have decided, well, we can solve that problem. All we need to do is use cellular phone data. So they put effectively a little cell phone onto their devices.

[00:36:13] Just like that Volvo we were talking about or other high-end luxury cars. So there's solar panel has a 3g modem in it. The cars have 3g modems in them to unlock the doors, to start the. In many cases, right? They also have updates that come down from the cloud, quote, unquote, over three G for your navigation system to let you know, Hey, there's heavy traffic.

[00:36:45] I'm going to reroute you. We're rerouting all of that data coming from the 3g network, coming through it, or being pushed up via the 3g network. All of that data is in trouble and it's in trouble because. Every major carrier is eliminating three G next year. Yeah, it is really that bad. A T and T is shutting down 3g services in February.

[00:37:16] Sprint's following in March and T-Mobile in July and Verizon. On December 31st, all of them, 2022, that is a very big deal and a very big problem. So what can you do about it? No, it depends. The roof, solar panels, we were just talking about their vendor, told them they could do the upgrade for them, and it would be $800.

[00:37:47] Very very big deal. We also had other people who were talking about their cars and what had to happen with them. And the cars are look like they're tending to be more expensive. You can expect to pay between 520 $500 for an upgrade because many of them are saying, Hey, w you know, we're not going to just fix this one problem.

[00:38:10] We have to replace the whole module. And that means. To replace your infotainment system in your car. Infotainment of course, being basically everything that has to do with your GPS navigation, your satellite radio, your, uh, your car play from apple or Android car or whatever it is you might be using.

[00:38:33] That's why it gets so expensive. So. Keep an eye out. This is going to be a very, very big deal. We're looking at everything from owner applications, like going ahead and starting that engine to warm it up to emergency calls services to in navigation, functionality, reporting telematics, which is the data about your car back to the dealer.

[00:39:02] Ultimately, so, you know, your car says, oh, uh, you need to go in and get your oil changed. And it's going to be a, you know, we can set up alarm and you want it. And you know, some of them are very, very fancy and all of that is going to go away and includes a lot of luxury cars all the way through. Some 2021 models, but many, many of them, if not most of them through 2019.

[00:39:29] Okay. Is that a very, very big deal or what these 3g towers are going away? The companies, the cell phone companies are planning on reusing that bandwidth and they're going to put it into where yeah. 5g, exactly 5g. So here's a few. The cars that you might want to be concerned about Acura. They have something called link, uh, and they have, let's see the MDX ILX, RDX, uh, RLX TLX NSX, like kind of sounds like almost all of them.

[00:40:06] So Acura is going to have a problem with almost all of their cars that were made between 2014 and 2017. Audi. They're going to have problems with, again, all their cars, a three, four or 5, 6, 7, 8, the RS Q3 five and seven. Yeah, pretty much all of their cars from 2012 through 2018. So I already saw this coming and decided to fix it early, so good for them.

[00:40:39] So basically if your car is older than 2018 model year, you're going to have some problems, Bentley. A number of models produced prior to 2020. And if you're driving a Bentley and do you want to give it to some guy, you know, really great looking guy, you can just let me know Craig. Yeah. Yeah.

[00:40:57] me@craigpeterson.com BMW number models produced before 2019 general motors. Models may between 2015 and 2021 across its fleet will be affected, but it's not breaking down with specific vehicles across it's brands of Buick Cadillac, Chevy, GMC, but they did in this case, it's the drive.com track down a technical service bulletin that indicates almost every post 2015 model is affected.

[00:41:32] Okay. Yeah. Bu-bye a Honda again, pretty much everything. From 2018 to 2021 Lexus all models 2010 to 2017 Mazda. Pretty much everything. 2016 to 2019 Mitsubishi, every eclipse cross and Outlander Porsche 9 11, 18, 7 eighteens, et cetera, et cetera. All of them, 20 14, 20 19 Subaru. Pretty much everything. 2016 and on Tesla model as built before 2015 Toyota.

[00:42:14] Ooh, they got some interesting problems, 2010 and on Volkswagen, much the same stick around. Visit me online. Craig peterson.com.

View Details

2021-12-18 1144

[00:00:00] Well, the tech world is all a buzz with this log for J or log for shell. However you want to call it because we are looking at what is probably the biggest security vulnerability the internet has had in a long time.

[00:00:16] This is huge, huge, huge to chew.

[00:00:19] I don't know how to express it anymore, but there are multiple problems here. And even the patch that was released to fix this problem was broken as being exploited in the last 24 hours. There've been no less than 30 different new. Variations of the exploit. So what is going on? There is a computer language that's used by many programmers, particularly in larger businesses called Java.

[00:00:52] You might remember this, I've been following it and using it now, since it first came out very long time ago from sun Microsystems. Java is a language that's designed to have kind of an intimate. CPU processor. So think about it. If you have an Intel chip that is an x86 type chip, what can you use instead of that Intel chip to run that code?

[00:01:19] Well, there are some compatible chips made mainly by AMD advanced micro devices, but you're really rather limited. You have problems. Power. Well, you know, guess what you're stuck. You're stuck in that architecture. And then on the other end of the spectrum, you have some of these devices that are designed by companies like apple, Google has their own.

[00:01:41] Now that our CPU's their graphics processing units as well. And they completely replaced the Intel architecture. But the Intel code, the programs that are written for the Intel architecture that are compiled for Intel are not going to work on the apple chips and vice versa. So what did apple do? Well, apple, for instance, just moved from Intel over to.

[00:02:08] Own chipsets and these chips don't run Intel code. So how can you run your old apple apps? Well, apple has a little translator. They call Rosetta. It sits in the middle and it pretends it's an Intel processor. This really rather simple. And they've done an amazing job on this. And w Rosetta is actually a third party company and they helped apple as well with the transition from the IBM power series chips to the Intel chips.

[00:02:41] So how do you move the code around while you either have. Recompile it, you may have to redesign it, rearchitect it for the new type of processor and the new types of computers that are supported by that processor. Or you may do what Apple's done here a couple of times now, and that is having an interpreter in the middle that pretends it's something else pretends as an Intel chip.

[00:03:07] And then you can still run your in. Code because it knows, okay. It was designed originally for this apple Intel architecture. So I know how to make all of this work Java steps in and says, well, why are you doing all of that? That's kind of crazy. Isn't it moving all of your code around all of the time. So Java's original claim to fame was what will, will make life easy for?

[00:03:33] What you do is you write your code. Using Java in Java is very similar to C plus plus in some of these other languages that are out there. And that language, when you're writing your source code will be compiled into an intermediate. Code. So what happened is sun Microsystems designed this virtual machine?

[00:03:56] Now don't think of it like a normal VM, but we're talking about a CPU architecture and CPU instructions. And so what it did for those CPU instructions. Which is really quite clever, as I said, well, we'll come up with what we think are the most useful. And it's a Cisco architecture for those of you who are ultra geeks like myself.

[00:04:19] And we will go ahead and implement that. And so the compiler spits out code for this CPU that doesn't actually exist anywhere in the known universe. And then what happened is sun went out and said, okay, well, we'll make an interpreter for. Artificial CPU that'll run on Intel chips and we'll make another one that runs on these chips, that chips and the other chips, beautiful concept, because basically you could write your code once debug it and run it off.

[00:04:53] Anything that was kind of one of the original claims to fame for Unix, not so the run at anywhere part of it, but the part that says, well, it doesn't take much work to move your code to different machine, and we're not going to get into Unix and its root I've been around the whole time. It's kind of crazy.

[00:05:13] I just finished reading a book and saying, I remember that I remember that. And they were going through all of the history of everything I was in the middle of that. I did that. That was the first one to do this. It was kind of fun. Anyhow, what Java has done now is it's really solidified itself in the larger enterprises.

[00:05:34] So basically any software that you might be using, like our website that is particularly with a larger business. Is going to be using Java and that Java language is using libraries. So in programmers, instead of doing what I used to do way back when which is right in assembly code, or even in COBOL, and basically you had to write everything, every part of every program, anything you wanted to have done, you had to write, or maybe you borrowed somebody else's code and you embedded it in.

[00:06:08] And mind you, we only had 32 kilobytes of memory in the mainframe back then the 360 30, for those of you who remember those things, but here is where things really changed. You now had the ability to take that code that you wrote and put it on a smart. You could take that exact same code, no recompiling or anything, and take that code and run it on a mainframe on our super computer in a car.

[00:06:38] So Java became very popular for that. Very reason in these libraries that Java provided, made it even quicker to program and easier to program. Now there's some problems with languages. Java, which are these object oriented languages where you can, for instance, say one plus one equals two. Right. That will make sense.

[00:07:02] But what does it mean when you use a plus sign? When you're talking about words? So you say apple plus oranges, what's that going to eat? Well, that's called overloading an operator, and this is not a course on programming languages, but what happens is a person can write the library and says, oh, well, if the programmer says a non-Apple plus an orange or string plus a string, what I want you to do is concatenate the strings.

[00:07:31] Now that programmer who wrote that has to kind of figure out a couple of things, make some assumptions. Oh, well, I should I put a space between apple and. Or not. And what do they really mean? Okay. So this is how I'm going to interpret it. So that, it's a very, very simple example. But the concept is that now with these overloaded opera operations and these libraries that can go deep, deep, deep, you now have the additional problem of people designing and writing the libraries, making assumptions about what the programmer wants and what the programmer needs.

[00:08:09] Enter the problem with the log for J vulnerability. This is a very big, big deal because we're talking about a library function that is being used in Java by programmers. Now, you know that I have been warning everybody. Android for years, the biggest problem with Android isn't its user interface. It isn't that it's made by somebody else.

[00:08:37] Right? The biggest problem. And of course, this is my opinion is that Android software is provided by Google and. It is given basically to any manufacturer that wants to license it. And then that manufacturer can't just take Google and run it. Right. Have you ever tried to install windows or Linux or free BSD?

[00:09:04] It's mainly a windows problem, frankly, but you go on ahead and install that in. What do you need in windows while you get to need driver? Oh, well, wait a minute. This laptop is three years old. So how, how can I find them? And then you go around and you work on it and takes you a day and you finally find everything you need.

[00:09:22] And you've got all of the drivers and now it works. But Microsoft provided you with the base operating system. Why do you need drivers? Well, you know the answer to that and it's because every piece of equipment out there is different. Think about this in the smartphone market. Think about it in the more general.

[00:09:39] Android market. There are thousands of these devices that are out there and those different devices are using different hardware, which require different drivers. So when Google comes up with a software patch, how well we just fix the log for J issue that patch. Has to be given to the devices manufacturer who then has to talk to the manufacturers of the various components and make sure that the device drivers that they're using by the manufacturer are actually compatible.

[00:10:20] They're going to. Got the upgrades, wire it all together, and then test it on all of the different phones that they have and cars because cars are running it. Now you see how complicated this get. And most Android devices will net. Get another update. They will never get a security patch versus apple.

[00:10:43] Right now. They're still supporting the apple six S that came out in 2015. If I remember right, it's five or six years old. Now you don't find that in the Android space. You're lucky if you get two years worth of support, we're going to continue this. But this is, uh, this is really, really important. I'm going to talk more about the actual problem.

[00:11:06] What is being done about it? What you can do about it as an individual, a home user, and as a business, in fact, keep an eye on your mailboxes. Cause I've got some more links to some sites about what you can do and how to do it and how to test for it. Anyways, stick around. You're listening to Craig Peterson.

[00:11:29] We're talking about what is likely to be the biggest set of hacks in internet history right now. It's absolutely incredible what's going on. So we're going to talk about what it means to you and what's really going on.

[00:11:45] This whole problem is probably bigger than anybody really realizes because Java, as I explained is a very common computer programming language.

[00:12:00] And it has a lot of features that bigger businesses love. They love the ability to have multiple programmers working on something at the same time. They love the inheritance and multiple inheritance and all of these wonderful features of Java. Well, one of the really cool features is that you can, while your program is running, have the program change.

[00:12:25] It's. That's effectively what it's doing. It's pulling in libraries and functions in real time. And that's where this particular problem comes in. This has been a nightmare for Java forever. It's one of the reasons I have never migrated to Java for any of the projects that I have. Don, it just gets to be a nightmare.

[00:12:49] It kind of reminds me of Adobe flash. It was the biggest security problem that has ever been. And the number two Java and Java is running in the Android operating system. It is the core of the operating system. All of the programs are almost certainly written into. And now we're seeing Java turnip in the, not just entertainment systems in our cars, but in the actual computers that are driving the cars, running the cars.

[00:13:22] And I get very concerned about this. We had two major outages just this week before this log for J thing came about over at Amazon. And those two Amazon outages knocked thousands of businesses. Off the air out of business. You couldn't get to them. You remember the big problem with Facebook that we talked about a little while back and in both cases, it looks like they were using some automatic distribution of software sent out the wrong stuff.

[00:13:52] Right? And now you are effected. Well, what happens? What happens with the cars? If they push out a bad patch, how are we going to know. Hmm, what's that going to mean? And if your car has Java in it, are you going to be vulnerable to this? Well, you, you wouldn't be vulnerable to log for J if your computer wasn't hooked up to anything, but nowadays the cars are hooked up to the net.

[00:14:20] We've had a couple of car dealers for our clients. Who've had the Mercedes we've had Acura Honda and others over the years. And it's interesting going in there now and working with them because they are doing massive downloads of firmware whenever a car comes in. So that car, if they don't have the right kind of networks, that car can take hours to do.

[00:14:49] Dates. And I got to tell you, man, I I'm just shocked by so many businesses, not willing to spend the money that it really takes. So the poor technician is sitting there waiting for it to happen. You know, we could make it happen in 15 minutes, but they're stuck there waiting for three or four hours sometimes for some of these downloads, no it's called cash them locally.

[00:15:09] Right? These cars, some of them need new and different firmware. Some of them use the same and have. A reliable, fast internet connection. And we've done that for many companies. Anyways, I'm kind of going off on a bit of a tangent here. So forget that let's get back into this with Java. You can have a routine.

[00:15:32] Call another routine that was not even necessarily thought of by the programmer. Now, can you imagine that? So you're, you're programming and you're, you're not considering adding something that's going to send email out and yet you could have a log in. That's part of the DNS, uh, and it gets logged that actually causes an email to be sent or causes anything else to happen.

[00:16:02] That the exact problem we're seeing right now, it's absolutely crazy patterns in text fields, things like you can put a user desk agent. Right, which is normal for nature. GTP connection. You say, this is, this is usually a guy who was using Chrome version bar or Firefox or safari, but you put the user agent field.

[00:16:26] And then after that, you've put in some, a little bit of code that tells Java, Hey, what I want you to do is this. This is a problem because we're finding now that I'm, again, I said the last 24 hours, 30 different exploits over a million companies have been attacked on this. And we're talking about 10.

[00:16:51] Companies, absolutely hacked every minute right now. Can you think, let's just think about that. And we're in the middle of what? Right? The big holiday season, we've had some holidays, there's people online, shopping there's businesses that are trying to buy stuff, business stuff, almost every one of those sites is likely to be compromised.

[00:17:17] It's that bad. It's absolutely nuts. What's happening here. This is a huge flaw, huge flaw. And by the way, it is flaw. Number this you ready for? This 44,228. In the year 2021. So the written 44,000 flaws that have been discovered and reported, this is the CVE system for those of you who are interested, but this really is a worst case scenario.

[00:17:50] Because this log for J library is being pulled in to so many pieces of software out there on so many different platforms. The paths to, uh, to exploit this vulnerability are almost unlimited. And because there's so many dependencies on this particular log for J library, it's going to make it very difficult to patch without breaking other things.

[00:18:21] And the fact the exploit itself fits in. Tweet can be injected almost anywhere. So it's going to be a very long weekend for a lot of people, but let me tell you this, it is not going to be solved in a few days, a week a month. We're going to be seen this. Years, because you have to be the person that wrote the program that has the source code to link in the new libraries, distributed out to your customers.

[00:18:52] Do you see what a nightmare? This is now? Some people are saying, well, you know, let's blame this on open source. This, this is an open source product. Well, yeah, it is an open source project and it turns out that even though anyone can grab this, these, this library routine or any of these pieces of code, anybody can grab it.

[00:19:13] Anybody can look at it. It turns out it's one guy. Who actually maintained this, who has a budget of $2,000 a year to maintain it. Nobody else pitched in. And all of these big companies are all out there grabbing this code that this guy has been working on and not paying much attention to it. Not donating to the product.

[00:19:37] Which is saving them millions of dollars, not that one project, but all of these projects collectively in the open source community, it's it is more far reaching than this stretch vulnerability. You might remember this drug vulnerability that's was, that was the root cause of the massive breach at Equifax that Explo exposed all of our personal information.

[00:20:05] To the dark web. That's how bad this is. Oh my gosh. So Hey, if you want information, I've got a links, a bunch of links set up here on what to do while you're waiting for the log for J updates from your vendors, how you can find on your servers. If they have the log for J vulnerability, I've got a bunch of information that I've stored up on that.

[00:20:32] And some others just email me, just email me. M e@craigpeterson.com asked for the list of the log for Jay's stuff or the Java's stuff. I'll figure it out. Be glad to send it to anyone that's interested. And if you need to scan to find out yourself and your business, let me know to me@craigpeterson.com.

[00:20:55] Wow. I was just going through a list published by Seesaw, this federal government agency that tracks some of these types of vulnerabilities. And wow, this list is daunting of all of these pieces of software that are vulnerable to this huge hack.

[00:21:12] this is now a problem for each and every one of us.

[00:21:16] I think I've established the man. This is nasty, nasty, nasty, nasty. So what do you do? First of all, I sent out. Email a list of things have in fact, a few different lists of things that you can do. So I had one for consumers, one for businesses and kind of a general thing as well. And then a bunch of references.

[00:21:43] Of course there's even more references and more great information now because I got that email. Pretty early. So I hope hopefully you had a chance to really look through that, but here let's just talk a little bit about this, what to do thing you already know because you guys really are the best and brightest that you need to be careful when you're on.

[00:22:07] You cannot be online, Willy nilly, clicking on things. And that includes emails and links. And this time a year, in fact, all year long, we're looking for. Wow, let's see. Is there a great bonus here? Look at they're having a sale, a discount. Oh no. I've only got three hours to respond or the deal's going to go away.

[00:22:28] I've usually been of the sort that I just am, not that influenced by some of these deals, but. I do sometimes want to find out what it is. So I find myself this week clicking through on. I'm on a lot of marketing lists because I like to follow what different marketers are doing, right. That's technology.

[00:22:51] And it's something I want to keep you guys informed about. And I found myself just crazy amount of double checking to make sure the link was valid. Now I'm sure you guys have, if you're on my email list, you might notice that the from address is not the me at Craig Peterson. Calm email address. You can always send email to me@craigpeterson.com and it ends up in my email box.

[00:23:17] And it might take me a few days, or even as much as a week or two to get back to you. If it's something there's an emergency, you really need to fill out the form on my website, but I will get back with you. But the problem that some people have noticed lately is. It doesn't say return address or sent from me@craigpeterson.com.

[00:23:41] It's got this rather long convoluted, uh, convoluted, uh, URL that has nothing to do with Craig peterson.com, sows a number of people question it, it is a tracking email. When can the idea is if I am going to be able to get back to people and if Karen is going to be able to nudge. I have to have these things tracked.

[00:24:06] So the email from address, when you hit reply, it is going to go to the, again, my email list server guys, and it is going to get tracked so I know. Okay. Okay. So now I've got a few minutes or an hour. Let's sit down and go through a lot of these emails so I can get back to people. That's a problem for many people, that's even more of a problem today than it ever has been in the past.

[00:24:35] Now there's been a few sites that have done something about tracking because many people don't like to be tracked. Right. My self included, although, as I've always explained on the show, it's kind of a double-edged sword because I would rather see commercials or ads for a Ford F-150 pickup truck. When I'm looking to buy.

[00:24:58] Uh, car or certainly a truck. I don't want to see ads for things I don't care about. Right. And you probably don't either. So the tracking, I don't think is a huge deal. The statistics that have come out from apple recently are very interesting because what apple ended up doing is they put some new technology and to stop tracking.

[00:25:24] And to stop you from being tracked. And basically what they're doing is a couple of things. One, they've got this new feature where they will download images and emails from their website, so that it's not a, you know, they're, they're not being able to localize where you are and then they're also doing something where you.

[00:25:50] Are you, you are, you can't be tracked like you used to be able to be tracked. Let me just put it simply like that applications now have to have that little label warning label in the app store to let you know what they might be tracking, et cetera. So they've been accepting anti tracking behavior that came from our friends from.

[00:26:13] Apple now Google, Facebook and others have been very upset about this thinking that they were going to lose a lot of business here in the advertising side, because you wouldn't be able to track them. So if you've got an apple iOS device, you probably noticed, it says, allow app to track your activity across other companies.

[00:26:37] And websites, your data will be used to measure advertising efficiency. I don't know that that's such a bad thing. And looking at the stats right now, I'm looking at Google's income. And a lot of that comes from YouTube after. Apple launched its new privacy initiative and it looks like Google really wasn't hit very badly.

[00:27:01] What Facebook was worried about that they would just be losing all kinds of revenue. Also didn't turn out to be true. So it's an interesting thing to see and I've got to really compliment apple again. At this time on trying to keep our information private, I read a really great book, uh, this, so this is how the world ends talking about the whole cyber race and where things are likely going.

[00:27:32] And it it's frankly impressive. To see what Google has done to try and keep out our government from their networks, as well as foreign government and the whole thing with the Chinese hackers we've talked about before, where I've found them. Active inside our customer's network before. And this is where we get called in because there's a problem.

[00:28:00] We look around, we find indications of compromise. We find the Chinese inside. Okay. So it isn't something that we were protecting them, the Chinese got in, but we come in after the fact and have to clean up the mess. But what we have really seen happen here is the largest transfer in. Of wealth, I should say, in history, the largest transfer of wealth in history to.

[00:28:27] From us and from other countries, but primarily from us because of what they've stolen. And so Google really has fought hard against it. The Chinese have been in their systems have stolen a lot of stuff. Apple has fire fought hard against it, but we know about the apple stuff. Google's seems to be a little quieter about some of it.

[00:28:47] So they may be selling our information to advertisers, but there certainly are trying to keep nation states out. I'm really wondering too, what is Google doing? Moving that artificial intelligence lab to China. It just it's insane. We know we, if we're going to get out of this financial position, we're in as a country, we need to have an amazing new technology.

[00:29:11] So people are coming to the United States and we're certainly not seeing that. At least not yet. It's all been stolen. So what to do, man. I started talking about that and we got a little sidetracked. So I will talk about that a little bit more here coming right up and what to do if you're a consumer, if you're a business person.

[00:29:35] And of course, as I mentioned earlier, I have. Quite a list. I'm more than glad to send you. If you go ahead and just email me, M e@craigpeterson.com. I'll keep you up to date, let you know what's happening and give you those links that you can follow to find out exactly what is happening and what you can do, including some tools. There are some tools out there to check to see if that vulnerability exists inside your networks or systems me@ Craig peterson.com. And I'll be glad to reach out, reach back to you. Stick around.

[00:30:12] I'm gonna tell you what to do as a consumer because of this massive internet hack that is underway. It is huge, huge, huge. Also going to talk a little bit about apple and what they're doing with their tracker detect app on Android devices.

[00:30:29] This will be going on for months and probably years in some cases, because there are many systems that will never.

[00:30:40] Patched for this vulnerability. So from now on, you need to be doubly cautious about almost everything, the big targets for this. Then people who tend to be the most valuable. Big businesses. And I can send you a list of devices that are known to be either, uh, immune to this they've been fixed or patched and devices that are known to have this problem.

[00:31:08] So. You send me an email. Excuse me. If you have any questions about it. So it's me M e@craigpeterson.com. I'd be glad to send you that list. Seesaw has it online. You can certainly search for it yourself. If you're interested in. So for you as an individual, it's just extra caution, you know, use these one time, use credit card numbers.

[00:31:39] I have talked about this before. And that is, I use fake identities as much as I possibly can online. And I'm not trying to defraud anyone. Of course, that would be legal. What I'm trying to do is not make myself as easy at target. As is frankly, uh, pretty much anybody who uses a computer out there, because if you're always using your, in the same name and email address and having forbid password, then you are a bigger target than you have to be.

[00:32:15] And so. I have a whole, uh, index file. I have a spreadsheet that I put together with 5,000 different identities, different names, of course, different sexes, races, origin stories, everything. And the whole idea behind that is why does some company that's providing me with some little website thing, need my real info.

[00:32:41] They don't, obviously you give you real info to the banks or. Counts, but you don't need to give it to anybody else. And that's what I do. That's kind of my goal. So if you can do that, do do that. Apple also has a way for you to use random. Email address a suit can set up a different email address for every website you visit.

[00:33:07] There are a few services out there that can do it. If you're interested, drop me an email. me@craigpeterson.com. I'll send you a list of some of them. Uh, I think they're, they're all paid except for the app. But you have to have an apple account in order to use it. One of the things that businesses really need to do is do a scan.

[00:33:30] Again, I can send you a list of scanners so that you can look at your network, see if there's any. Obvious that might have huge implications for your business. Uh, again, me@craigpeterson.com, one of the things apple has come up with that I, I really have turned out to like, and I think I mentioned them before on the air, but it's these news.

[00:33:55] Trackers that apple has, that you can put on things. And we spoke a little bit last week about the problem with these trackers being put on to high-end cars, and then being used to track the car. Now apple got around that problem a while ago, by letting you know, Hey, there is a tracker following you isn't that handy.

[00:34:17] So, you know, wait a minute, somebody dropped one of these little tags into my purse. Coat my car or whatever it might be. And so now you can have a look and see where is this thing that's following me and get rid of it. Well, of course, in order to know that there's one of these apple tags tracking, you you've needed to have an apple phone.

[00:34:43] Because it'll warn you. Apple now has something called tracker detect. If you are using an Android phone, I would highly advise you to get this app tracker detect app on Android. And it's designed to help you Android users from being tracked by apple airtight. 'cause if, if you don't know you're being tracked right, then you can't know if you're being tracked.

[00:35:12] If you don't have an iPhone, unless you get this app so good for them, apple has it up now on the Google play store. That's just in the last week or so, and it lets you locate nearby air tags. So let's, uh, I think a very good thing kind of wonder if apple isn't using the Androids also for part of the.

[00:35:33] Crowdsourcing for the air tags, but, uh, that's a different conversation. Great article in vice this week by Aaron Gordon, about how car companies want you to keep paying. Features you already have, and they specifically made a call out about a car manufacturer. Toyota. Who's now charging $80 a year for people who bought their car years ago, six years ago, $80 a year.

[00:36:09] If you want to keep using the remote start function on your key. Yeah, so you paid for it and life was good. You went a few years, really nice on a cold winter day or a hot summer day, warm up the car or cool it down all automatically. But now Toyota is charging. $80 a year. So people are saying, well, why I bought it?

[00:36:34] Why, why would I pay for that? Apple's now claiming that the several first years were merely a free trial period, but this isn't even the big play for these car companies, this $80 a year for marginal features like remote start instead. Is probably going to happen. And I agree with this author as well is we're going to see a, an approach that Elon Musk has used with his Teslas.

[00:37:06] They're going to charge extra for performance, for range, for safety upgrades, for electric vehicles that actually make the car better car, a better car. Right? So upgrades used to be difficult or impossible with gas cars. A lot of these are trivial for the electric cars, with the dashboards that have games that you can play while you are charging.

[00:37:32] Some of them were complaining about it being for when they're on the road. Of course that's going to happen because frankly, when, once we get a full autonomous car, what are outs are you going to do? Uh, I should also mention this isn't really a, but Mercedes-Benz has been awarded the very first license for the manufacturer sale and distribution of a fully autonomous vehicle.

[00:38:00] The very first they are licensed for up to, I think it was 37 miles per hour. On their car and anything beyond that, you still have to retain control, but that's an amazing thing. And it only works on roads that are mapped. And what Mercedes is doing is they have these super high definition maps. So the car knows exactly where it is.

[00:38:29] If you are a Tesla owner, you know that a few years ago, Paid, I think it was $2,000 for your Tesla to be able to drive itself. And of course they, they haven't been able to drive themselves. You know, they, yeah, there's been features here and there, but how are you getting those features? How will you going to get that self-driving mode?

[00:38:52] We'll test those, calling them over the air upgrades. And they're also saying. Th this is part of the Tesla ownership experience to quote their website. All right. So they've had all kinds of over the air upgrade. They've had some free software. They've had paid ones, Tesla charges, thousands of dollars for its autopilot.

[00:39:16] Now a lot of money, I think it was five grand. And now they've got this beta driver assist system as well, and they also have. To others. You might remember the ludicrous speed. Um, long range model three would dual motors is capable of accelerating from zero to 60 in 3.9 seconds. But when you buy the car, the zero to 60 time is a half a second longer.

[00:39:48] So pay an extra $2,000 and you get that extra half second and accelerate. Yeah, there's nothing different. They don't even have to change. Really changed the software. There's no hardware differences. It's just, you pay them two grand and they, your cars catheter to the internet and they just unlock a key is not something.

[00:40:11] Now, there are some people that hack the way around that paywall, but then Tesla blocked it and reversed the hack as well. A Tesla has sold their cars now for years with the same 75 kilowatt hour battery. But software locked them to 60 and 70 kilowatt hours might remember. We talked about this with a hurricane that came ashore down in Texas, where Tesla, anyone in that area provided them with an automatic upgrade for extra batteries.

[00:40:43] So they could go further in order to get out of the zone of their herd. Before them in software lock-in and a 60 and 70 kilowatt hours, unless you paid an additional $3,000 for that extra 30 or 40 miles of range. Isn't that something. Yeah. So Tesla has temporarily unlocked them, but this is where we're going.

[00:41:06] You're going to be going into the car dealership while in Tesla's case. It's on the, on the internet, which I think is better. Frankly, dealerships are handy in order to get a repair, but. You can get a repair at some of these little specialty shops it's often better and certainly cheaper than what the dealership sells, but you're not only going to be haggling over the price of the vehicle and delivery times.

[00:41:32] You're going to be haggling over all of these different features. And it's never going to end because they're going to keep having software upgrades that you're going to have to pay for. Uh, Pollstar this is an electric vehicle company spun off from Volvo new. Remember Volvo is now Chinese company. Yeah.

[00:41:51] Chinese. Yeah. So much for safety, right? Uh, they're going to charge an extra thousand dollars for a slight increase in horsepower and torque, just like Tesla does. So this is the future. Of car companies. Hey, I want to remind everyone, if you go to my website, Craig peterson.com. Right now you can sign up for my weekly newsletter.

[00:42:15] It is packed full of great information for you. Every week. We've got some free boot camps coming up after the first of the year, and you need to be on my email list to find out about it. Craig Peter sohn.com/subscribe.

[00:42:32] And following my newsletter, you probably saw what I had in the signature line the last few weeks, how to make a fake identity. Well, we're going to take it a little bit differently today and talk about how to stop spam with a fake email.

[00:42:49] I think I've told you before I had email way back in the early eighties, late seventies, actually. So, yeah, it's been a while and I get tens of thousands of email every day, uh, sent to my domain, you know, mainstream.net. That's my company. I've had that same domain name for 30 years and, and it just kinda got out of control.

[00:43:16] And so we have. Big Cisco server, that exclusively filters email for us and our clients. And so it cuts down the tens of thousands to a very manageable couple of hundred a day. If you think that's manageable and gets sort of almost all of the fishing and a lot of the spam and other things that are coming.

[00:43:39] But, you know, there's an easier way to do this. Maybe not quite as effective, but allowing you to track this whole email problem and the spam, I'm going over this in some detail in. Coming bootcamp. So make sure we keep an eye on your emails. So you know about this thing again, it's free, right? I do a lot of the stuff just to help you guys understand it.

[00:44:04] I'm not trying to, you know, just be June to submission to buy something. This is a boot camp. My workshops, my boot camps, my emails, they are all about informing you. I try to make them the most valuable piece of email. During the week. So we're going to go into this in some detail in this upcoming bootcamp.

[00:44:25] But what we're looking at now is a number of different vendors that have gotten together in order to help prevent some of the spam that you might've been in. Uh, I think that's a very cool idea to have these, these sometimes temporary, sometimes fake email addresses that you can use. There's a company out there called fast to mail.

[00:44:50] You might want to check them out. There's another company called apple. And you might might want to check them out. I'll be talking about their solution here as well. But the idea is why not just have one email address? And if you're an apple user, even if you don't have the hardware, you can sign up for an apple account.

[00:45:12] And then once you have that account, you can use a new feature. I saw. Oh, in, in fact, in Firefox, if you use Firefox at all, when there's a form and it asks for an email address, Firefox volunteers to help you make a fake ish email address. Now I say fake ish, because it's a real email address that forwards to your normal regular.

[00:45:40] Email address. And as part of the bootcamp, I'm also going to be explaining the eight email addresses, minimum eight, that you have to have what they are, how to get them, how to use them. But for now you can just go online to Google and this will get you started and do a search for Apple's new hide. My email feature.

[00:46:00] This lets you create random email addresses and those email addresses. And up in your regular, uh, icloud.com or me.com, whatever you might have for your email address, address that apple has set up for you. Isn't that cool. And you can do that by going into your iCloud settings. And it's part of their service that are offering for this iCloud plus thing.

[00:46:27] And they've got three different fi privacy focused services, right? So in order to get this from apple, so you can create these unlimited number of rather random looking emails, for instance, a blue one to six underscore cat I cloud.com that doesn't tell anybody. Who you are, and you can put a label in there.

[00:46:51] What's the name of the website that, that, or the, the, a URL of the website, the two created this email for, and then a note so that you can look at it later on to try new member and that way. Site that you just created it for in this case, this is an article from CNET. They had an account@jamwirebeats.com.

[00:47:15] This is a weekly music magazine subscription that they had. And apple generated this fake email address, blue one to 600 score Canada, cobb.com. Now I can hear you right now. Why would you bother doing that? It sounds like a lot of work. Well, first of all, it's not a whole lot of work, but the main reason to do that, If you get an email address to blue cat, one, two6@icloud.com and it's supposedly from bank of America, you instantly know that is spam.

[00:47:53] That is a phishing email because it's not using the email address you gave to TD bank. No it's using the email address that it was created for one website jam wire beats.com. This is an important feature. And that's what I've been doing for decades. Email allows you to have a plus sign. In the email address and Microsoft even supports it.

[00:48:23] Now you have to turn it on. So I will use, for instance, Craig, plus a Libsyn as an example@craigpeterson.com and now emails that Libson wants to send me. I'll go to Craig. Libsyn@craigpeterson.com. Right? So the, the trick here is now if I get an email from someone other than libs, and I know, wait a minute, this isn't Libsyn, and that now flags, it has a phishing attack, right.

[00:48:58] Or at the very least as some form of spam. So you've got to keep an eye out for that. So you got to have my called plus, and if. Pay for the premium upgrade, which ranges from a dollar to $10. Uh, you you've got it. Okay. If you already have an iCloud account, your account automatically gets upgraded to iCloud plus as part of iOS 15, that just came out.

[00:49:25] All right. So that's one way you can do it. If you're not an apple fan. I already mentioned that Firefox, which is a browser has a similar feature. Uh, Firefox has just been crazy about trying to protect your privacy. Good for them, frankly. Right? So they've been doing a whole lot of stuff to protect your privacy.

[00:49:47] However, there you are. They have a couple of features that get around some of the corporate security and good corporate security people have those features block because it makes it impossible for them to monitor bad guys that might hack your account. So that's another thing you can look at as Firefox.

[00:50:06] Have a look@fastmail.com. And as I said, we're going to go into this in some detail in the bootcamp, but fast mail lets you have these multiple email accounts. No, they restricted. It's not like apple where it's an infinite number, but depending on how much you pay fast mail is going to help you out there.

[00:50:26] And then if you're interested, by the way, just send an email to me, me. Craig peterson.com. Please use that email address emmy@craigpeterson.com because that one is the one that's monitored most closely. And just ask for my report on email and I've got a bunch of them, uh, that I'll be glad to send you the gets into some detail here, but proton mail.

[00:50:52] Is a mail service that's located in Switzerland? No, I know of in fact, a couple of a high ranking military people. I mean really high ranking military people that are supposedly using proton mail. I have a proton mail account. I don't use it that much because I have so much else going on, but the advantage.

[00:51:14] Proton mail is it is in Switzerland. And as a general rule, they do not let people know what your identity is. So it's kind of untraceable. Hence these people high up in the department of defense, right. That are using proton mail. However, it is not completely untraceable. There is a court case that a proton man.

[00:51:41] I don't know if you'd say they lost, but proton mail was ordered about a month ago to start logging access and provide it for certain accounts so they can do it. They are doing it. They don't use it in most cases, but proton mail is quite good. They have a little free level. Paid levels. And you can do all kinds of cool stuff with proton mail.

[00:52:05] And many of you guys have already switched, uh, particularly people who asked for my special report on email, because I go into some reasons why you want to use different things. Now there's one more I want to bring up. And that is Tempa mail it's temp-mail.org. Don't send anything. That is confidential on this.

[00:52:27] Don't include any credit card numbers, nothing. Okay. But temp-mail.org will generate a temporary email address. Part of the problem with this, these temporary email address. Is, they are blocked at some sites that really, really, really want to know what your really mail address is. Okay. But it's quite cool.

[00:52:51] It's quite simple. So I'm right there right now. temp-mail.org. And I said, okay, give me email address. So gave me one. five04@datacop.com. Is this temporary email, so you can copy that address. Then you can come back into again, temp-mail.org and read your email for a certain period of time. So it is free.

[00:53:18] It's disposable email. It's not particularly private. They have some other things, but I wouldn't use them because I don't know them for some of these other features and services. Stop pesky email stop. Some of these successful phishing attempt by having a unique, not just password, but a unique email for all those accounts.

[00:53:42] And as I mentioned, upcoming bootcamp, and I'll announce it in my weekly email, we're going to cover this in some detail. Craig peterson.com. Make sure you subscribe to my newsletter. Stick around.

[00:53:57] Well, you've all heard ransomware's up. So what does that mean? Well, okay. It's up 33% since the last two years, really. But what does that amount to, we're going to talk about that. And what do you do after you've been ransomed?

[00:54:14] Ransomware is terrible. It's crazy. Much of it comes in via email.

[00:54:21] These malicious emails, they are up 600% due to COVID-19. 37% of organizations were affected by ransomware attacks in the last year. That's according to Sofos. 37% more than the third. Isn't that something in 2021, the largest ransomware payout, according to business insider was made by an insurance company at $40 million setting a world record.

[00:54:53] The average ransom fee requested increased from 5,020 18 to around 200,000 in 2020. Isn't that something. So in the course of three years, it went from $5,000 to 200,000. That's according to the national security Institute, experts estimate that a ransomware attack will occur every 11 seconds for the rest of the year.

[00:55:22] Uh, it's just crazy. Absolutely. Crazy all of these steps. So what does it mean? Or, you know, okay. It's up this much is up that much. Okay. Businesses are paying millions of dollars to get their data back. How about you as an individual? Well, as an individual right now, the average ransom is $11,605. So are you willing to pay more than $11,000 to get your pictures back off of your home computer in order to get your.

[00:55:58] Work documents or whatever you have on your home computer. Hopefully you don't have any work information on your home computer over $11,000. Now, by the way, most of the time, these ransoms are actually unaffiliate affair. In other words, there is a company. That is doing the ransom work and they are pain and affiliate who are the, the affiliate in this case.

[00:56:27] So the people who infected you and the affiliates are making up to 80% from all of these rents. Payments. It ju it's crazy. Right? So you can see why it's up. You can just go ahead and try and fool somebody into clicking on a link. Maybe it's a friend of yours. You don't predict particularly like some friend, right.

[00:56:49] And you can go ahead and send them an email with a link in it. And they click the link and installs ransomware, and you get 80% of them. Well, it is happening. It's happening a lot. So what do you do? This is a great little article over on dark reading and you'll see it on the website. The Craig peterson.com.

[00:57:14] But this article goes through. What are some of the steps it's by Daniel Clayton? It's actually quite a good little article. He's the VP of global security services and support over at bit defender bit defender is. Great, uh, software that you've got versions of it for the Mac. You've got versions four of it for window.

[00:57:37] You might want to check it out, but he's got a nice little list here of things that you want to do. So number one, Don't panic, right? Scott Adams don't panic. So we're worried because we think we're going to lose our job June. Do you know what? By the way is in the top drawer of the majority of chief information, security officers, two things.

[00:58:03] Uh, w one is their resignation letter and the second one is their resume because if they are attacked and it's very common and if they get in trouble, they are leaving. And that's pretty common too. Although I have heard of some companies that understand, Hey, listen, you can't be 100% effective. You got to prioritize your money and play.

[00:58:31] It really is kind of like going to Vegas and betting on red or black, right? 50, 50 chance. Now, if you're a higher level organization, like our customers that have to meet these highest compliance standards, these federal government regulations and some of the European regulations, even state regulations, well, then we've got to keep you better than 99% safe and knock on wood over the course of 30 years.

[00:58:59] That's a long I've been doing. 30 years. We have never had a single customer get a S uh, a. Type of malware, whether it is ransomware or anything else, including one custom company, that's a multinational. We were taking care of one of their divisions and the whole company got infected with ransomware. They had to shut down globally for.

[00:59:25] Two weeks while they tried to recover everything, our little corner of the woods, the offices that we were protecting for that division, however, didn't get hit at all. So it is possible, right? I don't want you guys to think, man. There was nothing I can do. So I'm not going to do anything. One of the ladies in one of my mastermind groups basically said that, right?

[00:59:49] Cause I was explaining another member of my mastermind group. Got. And I got hit for, I think it turned out to be $35,000 and, you know, that's a bad thing. Plus you feel just so exposed. I've been robbed before, uh, and it's just a terrible, terrible feeling. So he was just kind of freaking out for good. But I explained, okay, so here's what you do.

[01:00:15] And she walked away from it thinking, well, there's nothing I can do. Well, there are things you can do. It is not terribly difficult. And listening here, getting my newsletter, going to my bootcamps and the workshops, which are more involved, you can do it. Okay. It can be done. So I don't want. Panic. I don't want you to think that there's zero.

[01:00:41] You can do so that's number one. If you do get ransomware, number two, you got to figure out where did this come from? What happened? I would change this order. So I would say don't panic. And then number two is turn off the system that got rants. Turn it off one or more systems. I might've gotten ransomware.

[01:01:04] And remember that the ransomware notification does not come up right. When it starts encrypting your data. It doesn't come up once they've stolen your data. It comes up after they have spread through your organization. So smart money would say shut off every computer, every. Not just pull the plug. I w I'm talking about the ethernet cable, right?

[01:01:32] Don't just disconnect from wifi. Turn it off. Immediately. Shut it off. Pull the plug. It might be okay. In some cases, the next thing that has to happen is each one of those machines needs to have its disc drive probably removed and examined to see if it has. Any of that ransomware on it. And if it does have the ransomware, it needs to get cleaned up or replaced.

[01:01:57] And in most cases we recommend, Hey, good time. Replace all the machines, upgrade everything. Okay. So that's the bottom line. So that's my mind. Number two. Okay. Um, he has isolated and save, which makes sense. You're trying to minimize the blast radius. So he wants you to isolate him. I want you to turn them off because you do not want.

[01:02:22] Any ransomware that's on a machine in the process of encrypting your files. You don't want it to keep continuing to encrypting. Okay. So hopefully you've done the right thing. You are following my 3, 2, 1 backup schedule that I taught last year, too, for free. For anybody that attended, hopefully you've already figured out if you're going to pay.

[01:02:43] Pay. I got to say some big companies have driven up the price of Bitcoin because they've been buying it as kind of a hedge against getting ransomware so they can just pay it right away. But you got to figure that out. There's no one size fits all for all of this. And at over $11,000 for an individual.

[01:03:06] Ransom, uh, this requires some preparation and some thought stick around, got a lot more coming up. Visit me online, Craig Peterson.com and get my newsletter along with all of the free trainings.

[01:03:23] Well, the bad guys have done it again. There is yet another way that they are sneaking in some of this ransomware and it has to do with Q R codes. This is actually kind of cool.

[01:03:39] By now you must have seen if not used QR codes.

[01:03:44] These are these codes that they're generally in a square and the shape of a square and inside there's these various lines and in a QR code, you can encode almost anything. Usually what it is, is a URL. So it's just like typing in a web address into your phone, into your web browser, whatever you might be using.

[01:04:07] And they have been very, very handy. I've used them. I've noticed them even showing up now on television ad down in the corner, you can just scan the QR code in order to apply right away to get your gin Sioux knives. Actually, I haven't seen it on that commercial, but, uh, it's a different one. And we talked last week about some of these stores that are putting QR codes in their windows.

[01:04:34] So people who are walking by, we even when the store is closed, can order stuff, can get stuff. It's really rather cool. Very nice technology. Uh, so. There is a new technique to get past the email filters. You know, I provide email filters, these big boxes, I mean, huge machines running Cisco software that are tied into, uh, literally billion end points, plus monitoring tens of hundreds of millions of emails a day.

[01:05:11] It's just huge. I don't even. I can ha can't get my head around some of those numbers, but it's looking at all those emails. It is cleaning them up. It's looking at every URL that's embedded in an email says, well, is this a bad guy? It'll even go out and check the URL. It will look at the domain. Say how long has this domain been registered?

[01:05:34] What is the spam score overall on the domain? As well as the email, it just does a whole lot of stuff. Well, how can it get around a really great tight filter like that? That's a very good question. How can you and the bottom line answer is, uh, how about, uh, using the QR code? So that's what bad guys are doing right now.

[01:05:58] They are using a QR code in side email. Yeah. So the emails that have been caught so far by a company called abnormal security have been saying that, uh, you have a missed voicemail, and if you want to pick it up, then scan this QR. It looks pretty legitimate, obviously designed to bypass enterprise, email gateway scans that are really set up to detect malicious links and attachments.

[01:06:33] Right? So all of these QR codes that abnormal detected were created the same day they were sent. So it's unlikely that the QR codes, even that they'd been detected would have been previously. Poured it included in any security blacklist. One of the good things for these bad guys about the QR codes is they can easily change the look of the QR code.

[01:06:59] So even if the mail gateway software is scanning for pictures and looking for a specific QR codes, basically, they're still getting them. So the good news is the use of the QR codes in these types of phishing emails is still quite rare. We're not seeing a lot of them yet. We are just starting to see them, uh, hyperlinks to phishing sites, a really common with some of these QR codes.

[01:07:30] But this is the first time we've seen an actor embed, a functional QR code into an email is not. Now the better business bureau warned of a recent uptick, ticking complaints from consumers about scams involving QR codes, not just an email here, but because these codes can't really be read by the human eye at all.

[01:07:53] The attackers are using them to disguise malicious links so that you know, that vendor that I talked about, that retail establishment that's using the QR codes and hoping people walking by will scan it in order to get some of that information. Well, People are going to be more and more wary of scanning QR codes, right?

[01:08:15] Isn't that just make a lot of sense, which is why, again, one of the items in our protection stack that we use filters URLs. Now you can get a free. The filter and I cover this in my workshop, how to do it, but if you go to open DNS, check them out, open DNS, they have a free version. If you're a business, they want you to pay, but we have some business related ones to let you have your own site to.

[01:08:47] Based on categories and all that sort of stuff, but the free stuff is pretty generalized. They usually have two types, one for family, which blocks the stuff you might think would be blocked. Uh, and other so that if you scan one of these QR codes and you are using open DNS umbrella, one of these others, you're going to be much, much.

[01:09:11] Because it will, most of the time be blocked because again, the umbrella is more up-to-date than open DNS is, but they are constantly monitoring these sites and blocking them as they need to a mobile iron, another security company. I conducted a survey of more than 4,400 people last year. And they found that 84% have used a QR code.

[01:09:37] So that's a little better than I thought it was. Twenty-five percent of them said that they had run into situations where a QR code did something they did not expect including taking them to a malicious website. And I don't know, are they like scanning QR codes in the, in the men's room or something in this doll?

[01:09:56] I don't know. I've never come across a QR code. That was a malicious that I tried to scan, but maybe I'm a little more cautious. 37% were. Saying that they could spot a malicious QR code. Yeah. Yeah. They can read these things while 70% said they'd be able to spot a URL to a phishing or other malicious website that I can believe.

[01:10:23] But part of the problem is when you scan a QR code, it usually comes up and it says, Hey, do you want to open this? And most of that link has invisible is, is not visible because it is on your smartphone and it's not a very big screen. So we'll just show you the very first part of it. And the first part of it, it's going to look pretty darn legit.

[01:10:46] So again, that's why you need to make sure you're using open DNS or umbrella. Ideally, you've got it installed right at your edge at your router at whoever's handling DHCP for your organization. Uh, in the phishing campaign at normal had detected with using this QR code, uh, code they're saying the attackers had previously compromised, some outlook, email accounts, belonging to some legitimate organizations.

[01:11:15] To send the emails with malicious QR codes. And we've talked about that before they use password stuffing, et cetera. And we're covering all of this stuff in the bootcamp and also, well, some of it in the bootcamp and all of this really in the workshops that are coming up. So keep an eye out for that stuff.

[01:11:36] Okay. Soup to nuts here. Uh, it's a, uh, it's a real. Every week, I send out an email and I have been including my show notes in those emails, but I found that most people don't do anything with the show notes. So I'm changing, I'm changing things this week. How some of you have gotten the show notes, some of you haven't gotten the show notes, but what I'm going to be doing is I've got my show notes on my website@craigpeterson.com.

[01:12:07] So you'll find them right. And you can get the links for everything I talk about right here on this. I also now have training in every one of my weekly emails. It's usually a little list that we started calling listicles and it is training on things you can do. It is. And anybody can do this is not high level stuff for people that are in the cybersecurity business, right.

[01:12:39] Home users, small businesses, but you got to get the email first, Craig peterson.com and sign.

[01:12:46] California is really in trouble with these new environmental laws. And yet, somehow they found a major exception. They're letting the mine lithium in the great salt and sea out in California. We'll tell you why.

[01:13:03] There's an Article in the New York times. And this is fantastic. It's just a incredible it talking about the lithium gold rush.

[01:13:14] You already know, I'm sure that China has been playing games with some of these minerals. Some of the ones that we really, really need exotic minerals that are used to make. Batteries that are used to power our cars. And now California is banning all small gasoline engine sales. So the, what is it? 55,000 companies out in California that do lawn maintenance are going down.

[01:13:45] To drive those big lawnmowers around running on batteries. They're estimating it'll take 30 packs battery packs a day. Now, remember California is one of these places that is having rolling blackouts because they don't have. Power, right. It's not just China. It's not just Europe where they are literally freezing people.

[01:14:09] They did it last winter. They expect to do it more. This winter, since we stopped shipping natural gas and oil, they're freezing people middle of winter, turning off electronics. California, at least they're not too likely to freeze unless they're up in the mountains in California. So they don't have enough power to begin with.

[01:14:28] And what are they doing there? They're making it mandatory. I think it was by 2035 that every car sold has to be electric. And now they have just gotten rid of all of the small gasoline engines they've already got. Rolling blackouts, come on. People smarten up. So they said, okay, well here's what we're going to do.

[01:14:52] We need lithium in order to make these batteries. Right. You've heard of lithium-ion batteries. They're in everything. Now, have you noticed with lithium batteries, you're supposed to take them to a recycling center and I'm sure all of you do. When your battery's dead in your phone, you take it to a recycling center.

[01:15:11] Or if you have a battery that you've been using in your Energizer bunny, and it's a lithium battery, of course you take it to the appropriate authorities to be properly disposed of because it's toxic people. It is toxic. So we have to be careful with this. Well, now we're trying to produce lithium in the United States.

[01:15:38] There are different projects in different parts of the country, all the way from Maine through of course, California, in order to try and pull the lithium out of the ground and all. Let me tell you, this is not very green at all. So novel. Peppa Northern Nevada. They've started here blasting and digging out a giant pit in this dormant volcano.

[01:16:09] That's going to serve as the first large scale, lithium mine in the United States and more than a decade. Well, that's good. Cause we need it. And do you know about the supply chain problems? Right. You've probably heard about that sort of thing, but that's good. This mine is on least federal lands. What does that mean?

[01:16:31] Well, that means if Bernie Sanders becomes president with the flick of a pen, just like Joe Biden did on his first day, he could close those leads to federal lands. Yeah. And, uh, we're back in trouble again, because we have a heavy reliance on foreign sources of lithium, right. So this project's known as lithium Americas.

[01:16:56] There are some native American tribes, first nation as they're called in Canada. Uh, ranchers environmental groups that are really worried, because guess what? In order to mine, the lithium, and to do the basic processing onsite that needs to be done, they will be using. Billions of gallons of groundwater.

[01:17:20] Now think of Nevada. Think of California. Uh, you don't normally think of massive lakes of fresh water to. No. Uh, how about those people that are opposed to fracking? Most of them are opposed to fracking because we're pumping the water and something, various chemicals into the ground in order to crack the rock, to get the gas out.

[01:17:43] Right. That's what we're doing. They don't like that. But yet, somehow. Contaminating the water for 300 years and leaving behind a giant mound of waste. Isn't a problem for these so-called Greenies. Yeah. A blowing up visit quote here from max Wilbert. This is a guy who has been living in a tent on this proposed mine site.

[01:18:10] He's got a. Lawsuits that are going, trying to block the project. He says blowing up a mountain. Isn't green, no matter how much marketing spend people put on it, what have I been saying forever? We're crazy. We are insane. I love electric cars. If they are coolest. Heck I would drive one. If I had one, no problem.

[01:18:29] I'm not going to bother to go out and buy one, but, uh, yeah, it's very cool, but it is anything but green. Electric cars and renewable energy are not green, renewable energy. The solar and the wind do not stop the need for nuclear plants or oil or gas burners, or cold burners, et cetera. Because when the sun isn't shining, we still need electricity.

[01:19:01] Where are we getting to get it? When the wind isn't blowing or when the windmills are broken, which happens quite frequently. Where are we going to get our power? We have to get it from the same way we always have from maybe some, uh, some old hydro dams. Right. But really we got to start paying a lot more attention to nuclear.

[01:19:25] I saw a couple of more nuclear licenses were issued for these six gen nuclear plants that are green people. They are green, but back to our lithium mine. They're producing cobalt and nickel as well as the lithium. And they are ruined this to land, water, wildlife, and. Yeah. Yeah, absolutely. Uh, we have had wars over gold and oil before and now we're looking at minerals.

[01:19:59] In fact, there's a race underway between the United States, China, Europe, Russia, and others, looking for economic and technological dominance for decades to come by grabbing many of these precious minerals. So let's get into this a little bit further here. Okay. So they're trying to do good, but really they're not green.

[01:20:24] They're they're not doing good. And this is causing friction. Okay. Um, first three months of this year, us lithium miners raise nearly three and a half billion dollars from wall street, seven times the amount raised in the last six months or 36 months. Yeah, huge. Money's going into it. Okay. They're going after lithium from California's largest leak, the Salton sea.

[01:20:55] Yeah. Yeah. So they're going to use specially coded beads to extract lithium salt from the hot liquid pumped up from an aquifer more than 4,000 feet below the surface. Hmm. Sounds like drilling aren't they anti drilling to the self-contained systems connected to geothermal power plants generating emission free electricity.

[01:21:16] Oh, that's right. They don't have a problem with the ring of fire in California with earthquakes and things. Right. Ah, yeah. Drilling on that and using the, the, uh, It's not going to be a problem. Uh, so, um, yeah, so that you're hoping to generate revenue needed to restore the lake fouled by toxic runoff from area farms for decades.

[01:21:40] So they're looking to do more here. Lithium brine, Arkansas, Nevada, North Dakota, as I mentioned already, Maine. Uh, they're using it in every car that's out there, smartphones, et cetera. Uh, the us has some of the world's largest reserves, which is, I guess, a very good thing. Right? A silver peak mine in Nevada is producing 5,000 tons a year, which is less than 2% of the world's supply.

[01:22:12] Uh, this is just absolutely amazing going through this. Okay. Um, I know bomb administration official, Ben Steinberg said right now, China decided to cut off the U S for a variety of reasons. We're in trouble. Yeah. You think. Uh, the another thing here in the New York times article is from this rancher and it's a bit of a problem.

[01:22:38] He's got 500 cows and calves. Roaming is 50,000 acres in Nevada's high desert is going to have to start buying feed for. This local, mine's going to reach about 370 feet. Uh, here's another kind of interesting thing. This mine one mine is going to consume 3,200 gallons of water. Per minute. Yeah. In, in Baron Nevada, I I'm looking at a picture of this and it is just dead sagebrush.

[01:23:09] Oh my gosh. So they're expecting the water table will drop at least 12 feet. They're going to be producing 66,000 tons of battery grade, lithium carbonate a year. But, uh, here we go. They're digging out this mountain side and they're using 5,800 tons of so FERC acid per day. Yeah. They're mixing clay dug out from the ma from the Mount side with 5,800 tons of clay of sulfuric acid.

[01:23:42] I should say every day, they're also consuming 354 million cubic yards. Of mining waste. I'm not consuming creating 354 million cubic yards of mining waste loaded with, uh, discharged from this sulfuric acid treatment and may contain. Modest amounts of radioactive uranium. That's. According to the permit, documents are expecting it'll degrade quote unquote 5,000 acres of winter range used by the antelope herd, the habitat of the Sage groves nesting areas for Eagles.

[01:24:20] It just goes on and on. It is not. BLM is not, of course stumbled the bureau of land management, but I guess both PLMs are not, and this is a real problem and the tribes are trying to stop it. The farmers are trying to stop it, but Hey, California needs more lithium batteries for their electric cars.

[01:24:42] They're electric lawn mowers, leaf blowers, et cetera. So we've got to get that lithium. We've got to get it right away, uh, in order for their green appetite in. Hey, get some sanity. Craig peterson.com. Sign up for my newsletter right now. Craig Peterson, S O n.com.

View Details

Did Your Computer Have "Intel Inside"? It Won't For long!

We're going to talk a little bit about shopping right now. Then we'll get into our chip crunch, and why Intel is being left on the side of the computer road.

[Following is an automated transcript.]

[00:00:16] There's lots of fun stuff to do. And it's kind of fun getting out of the house. Isn't it getting out, going out, going around? There's a, an outlet store close by where I live and it's kind of one of these outdoor. Outlet things. And it was fun. Just walking around, enjoying the little bit of fresh air, no matter what the weather has.

[00:00:40] Uh, I even enjoy going up there when there's some snow on the ground. Because again, it's a little bit of a, uh, it's, it's fun. It's a little bit of a change, which is not. Part of what I love about living in the Northeast. You really get all four seasons and they can be really, really nice. Well, black Friday of course came and went.

[00:01:01] It was not a bad black Friday, but one of the questions I been asked all week long, all month long, frankly, has to do. When should I buy, what should I buy? What are the deals? And it is weird this year. Let me tell you really weird. And the reason I say that is I didn't my show prep. And I spent some hours just looking on different websites and looking at opinion pieces, looking at news sources, just trying to find, okay, what's going on?

[00:01:36] What's the real word out there. Our items, as rare as everybody seems to be saying they are, or is it easy enough to find. Well, that's what we're going to talk about right now. Really. We've had a very turbulent two years for retail, every branch of retail, whatever it is, it's been been terrible. So many people have lost their businesses.

[00:02:03] So many small businesses, small retail restaurants, some restaurants that I, I enjoy and just haven't been to in years, really. Completely gone, which is such a crying shame. And a lot of people have put a lot of the blame for the general retail malaise on Amazon and Walmart. Because again, you know, I had a discussion just this last weekend with.

[00:02:35] Oh, friend's father. And he was saying, well, you know, I've been a biologist in pharmacology for years. And, uh, you know, th this is just as just a science. It's all science talking about the lockdown. And so I pointed out how, well, let me see, let me see. I got family from Canada. They cannot drive across the border because of the lockdown, but in, in the states, they won't let us, us, we won't let them fly.

[00:03:03] But they drive in, I should say, but they will let them fly in. How does that science, right. There's coronavirus not survive at 30,000 feet. Is that what it is? You know? No, come on. People it's politics and part of the politics was. Walmart got to stay open and all of these other small businesses couldn't so what are they supposed to do?

[00:03:29] How are they supposed to compete? And yet, Hey, I understand you need clothes, right? And you need food. Most Walmarts have both. You might need medicine in order to even survive. So that kind of makes sense, but why. Walmart. Why did the government choose Walmart and target are going to survive all of you, little mom and pops stores, you know, that maybe have been multi-generational where it's your parents.

[00:04:00] And maybe even your grandparents that started the store, started the restaurant. And now all of a sudden there's a lockout and you cannot be over. It just, it entirely political, entirely political. And I understand the science behind all of this. I have spent a lot of time studying it and you might remember if you've listened to me even.

[00:04:26] Dean or 20 years ago, I'm trying to remember when it was, I started talking with scientists about RNI, RNA interference and the coolest stuff that was happening with African violets and getting the, the purple flowers to change to white and all of the stuff they were doing. It it's exciting. It's fun. But why.

[00:04:49] Did we use politics here. And so many people lost their livelihood. So many people lost their businesses. It's, it's absolutely incredible. And just pain companies basically to stay closed. Uh, doesn't make sense either. Because now you're pumping more money into the economy and that's causing inflation because there are not more products or not more vendors.

[00:05:15] There's not enough competition. So the prices go up. And when there's inflation, how about people who are retired, who have saved something. And now their money is worth what the inflation rates are. Again, it's a hidden tax, but it's really hard on retirees because their money that they've saved, you know, they're getting the pitons, you put it in a savings account and you're making a fraction of 1%.

[00:05:43] And yet we're seeing inflation rates on things like fuel being almost a hundred percent. Think about what it was like in 2019, what the gas prices were. It is insane. So small businesses have to be supported. They are the backbone. They are the innovators. Walmart didn't start as a big company. They started very small.

[00:06:10] He innovated his claim to fame. That old Sam Walton was let's go ahead and have the best prices and anywhere. Right. And so they got the best prices by beating up their suppliers, et cetera, but it all worked. And Walmart increased, raised its it's demonstrable again through real science, but they raise the standard of living in every community.

[00:06:39] They opened a store. It's absolutely funneling. But Walmart stopped innovating a long time ago. Now again, the innovations come just like they do in the tech world. Typically not from the existing companies, right. Facebook isn't innovating, they bought WhatsApp, they bought so much of the technology they're using to drive their company.

[00:07:02] Oculus. You look at it, right? That's their future. According to of course, uh, you know, Mr. Mark. What did it come from? What was the cost? Right. They by their competition. So I want to encourage everybody to really try and go out of your way, try and shop at these small places. There are. And so many of these malls nowadays kind of local stores where they've got together and they're running their co-op or where someone's managing a bind product from local craftsman, really that they, everything from these women that are knitting doilies all the way on out, through very cool black iron work things, things that you can find there.

[00:07:54] That maybe you can find on Amazon, maybe they come from China. Maybe they're locally sourced. Not very likely, but it's been a very, very tough, tough time here for so many of these industries. One of the things that I did talk about this week, I, one of my radio appearances is. Tik TOK live shopping. If you haven't heard of tick tock, tick tock is this short form video site.

[00:08:21] And it kind of started by people saying, okay, well with this song, uh, use that song to make a funny little 32nd. And 22nd and that's what people did. And it was really quite cool to see they there's some innovative people out there. Tick talk has a lot of, I share nowadays way more popular amongst the younger people than Facebook is Facebook has kind of become something for the older people.

[00:08:49] But what tech talk is now doing is providing live shop. And this is an innovation that really started in China, which of course is where tick-tock is located. But in 2020, there was a survey done that found that two thirds of Chinese consumers said that they bought products via live stream in the past year.

[00:09:13] So what's live stream. I want you to think about QVC online share or a television shop. Those channels, those infomercials that come on at night, but particularly the channels that are constantly selling stuff like micro did a little bit of that at one point in time, right? His interview was, he came in and the, he, the guy who was interviewing him, held up a pen.

[00:09:37] Is that okay, you sell me this pencil. And so micro went on and on for 10 minutes or more just talking about the pencil and everything related to the pencil and what a great quality was. All he course, she didn't know anything about it. Right? And that's part of what bothers me about some of these things, right?

[00:09:55] These people are just making stuff up, but talk live now is allowing you to go ahead and make funny little things. Gain an audience. Maybe they're not funny. Maybe they're just informative. Have them inserted into people's streams and then sell it right there. In fact, instant purchasing of a featured product during a live stream.

[00:10:22] And then obviously audience participation, they got chat functions, reaction buttons. This is what's coming our way. And so all of you, small businesses out there, I really want to encourage you pay attention to social media. This is the sort of thing that you can do. You can target your local area, which is where most small businesses operate, right?

[00:10:48] It's in, in your town. It's maybe a 10, 20 mile radius, depending on what, what you're doing, what you're selling. And you can micro target nowadays. That's the joy. That's the beauty of the online world. Micro-targeting Hey, and if you're interested, let me know. We can talk a lot more about this because I have studied this for years now.

[00:11:12] Hey, stick around Craig peterson.com online.

[00:11:20] So while you're shopping online, what are some of the things you should do or look out for? I've got a few ideas. I'm going to tell you what I do, and it has worked wonders for me. So here we go.

[00:11:35] When you're shopping online, there are some obvious tips, just run through them very, very quickly because I don't, I think you guys being the best and the brightest really know these things.

[00:11:50] So just very quickly, make sure your security. Today, make sure that everything is patched up the way that it should be, that you have some really great anti-malware hopefully advanced anti-malware, but apply any updates before you start doing shopping, because this is a bad time of year to lose all of your personal information and to have your money stolen.

[00:12:18] Uh, number two. If you're seeing an email or you're seeing a deal that really looks too good to be true. Take, take caution here. Right? Do you see a place? Oh, I got five brand new Sony PlayStation fives for sale. You might not want. To buy those, right? The minister, Jeff Foxworthy. Here's your sign. So be careful about that.

[00:12:46] Criminals are really taking advantage of consumers who, uh, you know, life's been tough, money's been tight. You're trying to find a deal. So be careful about that. Okay. Coupons or other way, the bad guys have been trying to get consumers. To compromise their own cyber security. Okay. Uh, 12% of emails out there are considered to be spam emails.

[00:13:15] I think it's more like 80% or 90%, but then I've had the same email address for 30 years. Okay. Uh, so don't click on link. Be sure you shop on the real website and apply coupons there by manually typing out the code. So for instance, if, if let's say you use duck, duck, go for your search engine, which you should be using for most cases, most searches a duck duck go says, okay, let me see where coupons here you go.

[00:13:46] Here's a site that has a lot of coupons be careful about those sites, because some of them are trying to lure you in. Are the websites you're going to the real ones, the legit one. Are you clicking a link in your email in order to get to that sale site? Double check, because what they're doing is using some of these URLs that aren't.

[00:14:14] Right. And we see those all of the time. They'll have a misspelling of the business name or they'll, they'll do something else. So they might have Amazon Dodd bad guys.com. Oh, okay. Amazon. Okay. Is Amazon, uh, obviously they wouldn't say bad guys, but yeah. That's kind of what they're doing. So be careful. So once you're on a website, look for that little padlock that's to the side, click on it and double.

[00:14:43] To make sure that it is legit because they might have us. What's called a secure, sir. And they might have a certificate that's valid for the site that you just went to, but it's not, there's a different kit for Amazon or Walmart or target or w you know, whatever Joe's clothing.com. It might be something entirely different.

[00:15:07] So be careful, okay. Is what you're looking at on the ad. Because there are a lot of fake advertisements out there that looked like they got great deals. And even though black Friday has come and gone, they're going to continue to do this through the end of the year and be on. Okay. So rather than clicking on the ad, just type in the retailer.

[00:15:35] Information, because some of these ads that are showing up are in fact, almost every last one of them is coming from what's called an ad network. So that ad network is where people go and buy ads and they say, Hey, I want to retarget people that were at this site or clicked on this link, et cetera, et cetera.

[00:15:54] And now. If you are a bad guy, all you have to do is sneak into one of those big ad networks. And all of a sudden your bad guy ads are showing up everywhere. So you see a great ad for a Chromebook. For instance, we've talked about those before you can just go ahead. Okay. Chromebook. No problem. Wow. Yeah.

[00:16:14] Yeah. Type it in. If the ads for a Chromebook from Walmart, just type in walmart.com. Okay. Avoid clicking on ads. Isn't it terrible how bad it's gotten, man. I liked the internet better back in the 1980s and nineties. Uh, how should you pay? We're going to talk about that in a minute. Public why fi is a potential problem.

[00:16:40] The bad guys will often create fake hot spots and you are now using their hot spot. Now this isn't as much of a problem as a used to be because your visits to most websites nowadays are encrypted. Do you remember that lock? I mentioned in the URL. Well, that means it is using SSL or TLS, which is a secure communications pro protocol.

[00:17:07] So if you're seeing that, you know that you basically have a VPN, you don't have to buy a VPM service. You don't have to use a VPN service. You have a VPN that's being provided by the website, your. And that's really what that lock means. So the public wifi is less of an issue for the monitoring, what you're doing, although yeah, they can still do some monitoring.

[00:17:33] They might play with DNS and things, but they can also scan you, which is the biggest problem from my perspective about using public wifi and never. Share your personal data. If you can avoid it, one of the things we're going to be covering in the upcoming boot camps and workshops is using fake or alternate email addresses.

[00:17:57] I do it all of the time. That's why I have 3000, 3000. Yes. You heard it right different log-ins right now in use active use on. Uh, in my password manager, at least over the last decade. So I've accumulated a lot of them. So I use a different email address pretty much all of the time. And I'll, I explain how to do that in the boot camps and workshops that are coming up.

[00:18:25] So keep an eye on. On my weekly emails again, Craig peterson.com/subscribe. So you can find out about them, you know, these, the free ones. I really want to give you guys all of the basics, right? So that's what I'm going to be doing anyways. How should I pay? This is maybe the even bigger side of things. It is very, very rare that I actually put my credit card number in on a website at least.

[00:18:54] Real credit card number. There's a number of options that are available to you now that weren't before, even if it's not a credit card, even if it's a debit card and generically, this is known as single use credit cards. So we've got a few things. I use typically capital one's email E N O. If you have a capital one card of any sort, this is a little browser plugin that you can put on.

[00:19:25] Now, the downside of this is they will by default, try and look. Every web page you visit. So from their perspective, it's worth it because now they get that data from you. However, in all modern browsers, you can restrict when it runs. But what happens is I go to a website, it wants a credit card and I can pop up that little Eno browser plugin.

[00:19:53] And now. Todd, uh, I can generate a virtual credit card number that's tied in behind the scenes to my real credit card number. I can even put an expiration date on that credit card number. So it can't be used after a certain. Some of these virtual credit card options, even allow you to say, Hey, it really is only single use.

[00:20:18] It can only ever be used once. And that way the bad guys can't run up your credit card. Bill Citibank, American express, JP Morgan, and the more have these types of options and basically any visa or MasterCard. Look for virtual credit cards. From your bank or whoever's providing your credit card. Hey, stick around.

[00:20:42] You're listening to Craig Peterson and I'll be right back.

[00:20:46] We're going to talk a little bit now, since it's getting near the end of the year, about what kind of technology do we think is going to be big next year. And I've got to mention this project. My daughter has been working on it. Finally hit the ocean.

[00:21:02] My daughter has been busy. You might know she's been in the maritime industry for quite a while now.

[00:21:11] And a man, she went to, she graduated 2008. I think it was this, this daughter. And you probably already know I have five daughters, right? Uh, three sons too. So it was kind of a mix, but she has been working on a ship called the Yarra Burkland it's over in Norway. And what the ship is doing here is hauling fertilizer, anything.

[00:21:38] Oh, wow. Isn't that exciting? Wow. Craig, I'm so excited for you. Well, it is the world's first autonomous electric ship period. Okay, cargo ship and what it is doing ultimately, is it to eliminating the need for about 40,000 truck round trips a year. See what's happening over there in Norway is there's a factory that's right.

[00:22:07] Located right next to a mine. That's making all of this fertilizer and it needs to be hauled down through some fjords. To get to the main shipping Depot where it can be loaded onto the big ocean ship. So these trucks are going up and over the mountains alongside the fjords. And this is a ship that's going to take a trip that's about seven and a half nautical mile.

[00:22:34] So give or take eight miles and on the water. And now Norway is doing this in its own waterways. So there's no problem with international rules and regulations about ships here. This is just local and it loads itself. It drives itself and it unloads itself. I think that's really, really cool. And what it does is it plugs itself.

[00:23:02] When it is on either port w now we've seen this with some ships, right? You might've been on some of these ferries that are electric. They work pretty well for electric ferries. Cause they're usually short haul. They connect up to shore power and they do a rapid charge and they're ready for. The next leg of their ship while they are busy taking all of their load in right.

[00:23:26] Makes sense. And you might've done it, but this is, this is different. And a lot of the incidents that happen in shipping are due to human error. Think about all of the problems we've had with Navy ships, even running into things, human error, and a lot of that's due to fatigue. On the ships. I don't know if you know it.

[00:23:47] I have two kids that, well, three actually that have been in the maritime industry, uh, the, the big maritime industry and they take four hour shifts. So four on four off four on four off every day. So fatigue is a very big deal for a lot of the shipping industry. And for the first few years, they're planning on having the ship be.

[00:24:15] They're going to be up, of course, on the bridge monitoring everything, because you've got a problem with artificial intelligence machine learning. If a big ship is coming along and there's a kayak in the way, it's actually the kayaks job to get out of the way. But if you run over a kayaker things, aren't going to go very well for you, frankly.

[00:24:37] But how does a computer recognize a kayak? Maybe Marine life or even some sort of a swell that's out there. So they think they've got most of this solved. And this is the project that my daughter's been working on for a few years here. She's a Mariner. She has her captain's license unlimited. Tonnage unlimited vessels on unlimited waterways anywhere in the world is just incredible.

[00:25:06] All of the stuff she's done. So the wheelhouse could disappear all together, but they've got to make sure that everything is working pretty darn well. Okay. Uh, large vessels. Do anything about the kayak? All they can do is warn, but they definitely can't maneuver. And that's why the deep draft vessels have priority over sailboats or pretty much anything else that's out there.

[00:25:32] But, and what that brings up is the fact that we don't have the regulations yet for these autonomous ship. Well, we don't have the regulations yet for the autonomous cars, right? This is normal. The technology tends to proceed the regulations, and we have regulations in place right now for autonomous vehicles in certain areas.

[00:25:57] But they're nowhere near mature. It's going to take a while before everything has all frigging. And now that is leading us into our friends at Ford. Ford's done a couple of interesting announcements over the last couple of weeks. So I have to bring the. And an effort really to deal with this ongoing chip shortage.

[00:26:21] Ford has made a deal with global founders. Global foundries is a chip maker and they have a non-binding agreement. Now that makes it interesting. If it's non-binding. Why even bother, but the press release says opening the door for global foundries to deliver more chips to Ford in the short term. But what's happening right now because of the chip shortages.

[00:26:50] Well, companies are designing their own. Purpose built chips rather than relying on the general purpose chips made by Intel or AMD Qualcomm, Samsung and video media tech, depending on what kind of chips we're talking about. This is fascinating because it is hurting Intel. No question about it. And AMD. So what does Intel done?

[00:27:15] Intel is moving its stance to being more of a contracted chip manufacturer. So you can go to Intel and say, here's my chip design. Go ahead and make that for us. And off they'll go and they will manufacture it and they probably even help you with some of the design things. Fascinating. Now, the other thing that's been happening for a while is if you look at apple, for instance, they have been using their own chips in their I phones and eye pads.

[00:27:52] Now they also are using their own chips in the laptops and various desktop computers. So apple is the highest profile example I can think of offhand. That have replaced Intel's chips. That's absolutely amazing. Google has also created its own chip for the latest pixel phone. So if you buy the latest flagship pixel, which I would not do, because this is the first time they're really using their own chip, but they've got their own chip now.

[00:28:28] Amazon has been deploying its own chips in its internal servers to improve performance as well as to make it better for the Alexa voice assistant. You see how long tail that's a marketing term, but really how special purpose purpose designed purpose built chips are. So it's huge. Intel's changing course.

[00:28:55] They've never been a great chip designer. If he asked me and a few know my history, you know, I've been down at the chip level. I was down there for many years in the kernel of operating systems and dealing directly with all. From chips, you know, when you're thinking about drivers and the low end and the operating system, that's what I did for a lot of years.

[00:29:18] So I'm, I'm glad to see this happen. It's going to be better for you because the devices can be cheaper because they don't use a general purpose chip. The chip is built and designed. For what it's being used for. So good news there for four, because Ford is going to be kind of doing the same sort of thing.

[00:29:39] I bet mark my words. Okay. Well, I didn't get to the predictions for this year, but I will, when we get back this upcoming year, stick around, of course you listening to Craig, Peter Sohn, you can get all kinds of information. And in fact, if you sign up for my email list, which is not a heavy marketing.

[00:30:02] Believe me, you'll get a bunch of different special reports. So ones I think are going to help you out the most. Craig peterson.com.

[00:30:13] Well, we just talked about the future when it comes to chips and our computers, we're going to continue that discuss discussion right now on artificial intelligence and machine learning. What else is going to be important next?

[00:30:29] So, what is the future?

[00:30:31] We're getting close to, you know, the end of the year and the beginning of the year. So what am I looking forward to? Well, you just got my basic predictions about what's going to happen with chip manufacturing. These various vendors of various devices are going to continue to move away from Intel AMD, et cetera, these general purpose chips and move more to special purpose chips.

[00:31:02] Now there's a number of special purpose type designs that have been out there for a very long time. For instance, a six OCB in industry. No, those I programmed some way back when. I have gotten much more complicated, but for instance, when we're putting in systems for a business, we will typically use Cisco systems that have a basics so that everything is extremely fast.

[00:31:29] You don't notice any delay and yet it can do very heavy duty filtering. Packet examination, stream examination, because it's being done in hardware. That's the advantage to it. So we're going to see more and more that since Apple's already moved to their own chips, Google has already moved to their own chips, Amazon, their own chips, et cetera.

[00:31:53] And there'll always be a need for general purpose chips. In fact, you can say that the apple chips for instance, are fairly. The purpose they're being used in your iOS devices, your iPhone, your iPad, but they're also being used in desktop applications. But if you look more closely at what Apple's done, it has a couple of different types.

[00:32:16] Of CPU's inside the chip. So it has the high-performance CPU's that are only engaged when it needs some serious computing going on. It has the low power, lower performance CPU's that are also built into that same chip that now handle kind of background tasks, things. Dated the don't need a whole lot of CPU or don't need to be really fast.

[00:32:42] And then it also has graphics processing units that will handle things like screen updates, moving stuff around on the screens. There is a lot of technology in that chip in reality, it's it would use to take three. Completely different sets of chips to do what the one apple chip can do. So it is an example of a special purpose CPU.

[00:33:11] We're going to be seeing more and more of those now as a consumer, you're not really going to notice other than, wow, this thing's fast or wow. This battery lasts forever. You're going to have some great, great functionality. And I think we are seeing, because they're spinning. $2 billion a week right now in the industry, you're going to be seeing more of these fabs come online, chip fabrication plants, and they take a long time to build and put up online, but they're going to be making more specialized chips, which I really.

[00:33:46] Well, there's an article that came out based on a survey from the I Tripoli. And this is called the impact of technology in 2022. And beyond of these are some global technology leaders. Of course I Tripoli was all about electrical engineering back in the day today, it's more about general technology. But here's the results.

[00:34:12] What is important for next year? Now, remember, I don't give investment advice. So don't look at this as things you should be putting your money into. This is just stuff that is good to know and probably should be considered, but this is not again, investment advice. So. Technologies will be the most important in 2022.

[00:34:33] While according to this kind of little, little brain trust, if you will, amongst the respondents more than one in five, say that AI and machine learning are going to be very important. What's the difference between artificial intelligence and machine learning. Uh, the lines are blurred nowadays. They used to be a lot more clear machine learning used to be the, the machine, the computer learns it.

[00:35:02] Let's say it's working on a factory floor and it has to do some welding on a joint. And the, it has sensors and it learns, oh, okay. Well, this part, when it comes into me may be here, but I might be there and I might be here. So I got to kind of move around a little bit. That's basic machine. Artificial intelligence, which I think is a super set of machine learning, but other people argue the other way, but you know, they don't know what they're talking about.

[00:35:30] There is artificial intelligence is where it doesn't even have to be taught how to learn. It. Just figures things out. So it's. When it's built, talk to learn where that piece that it needs to weld is likely going to be and how to find it. It just knows. Okay, well, I'm supposed to weld. So how do I do that?

[00:35:56] That's much more of an artificial intelligence. So that's number one, artificial intelligence next. Cloud computing 20%. Now my opinion on cloud computing is not very high, frankly, because cloud is just the name for somebody else's computer cloud computing does not mean it's safer. It does not mean that it requires less work on your part where I think cloud computing can help a business is where.

[00:36:30] Push over flow to the cloud. The many businesses that have moved technology to the cloud have moved it back now because frankly, the cloud did not provide them with what they thought they'd get, which is cheaper, better computing. And a lot of the breaches that we're getting nowadays are in the cloud.

[00:36:53] People's databases being exposed, applications, being exposed. It's great for hackers because they know. Okay, well, let me see. Amazon has the majority of all cloud computing in the world, so let's just scan Amazon computers and see what we can find. Right. And they're going to find that this bank has this opener, that company has that database available, et cetera, et cetera.

[00:37:17] So be careful with that, but they think cloud's number two, five G. 17% that I am very excited about it. And here's why five G is kind of a generic term for the high speed, uh, room wireless data. So think cell phone basically, but why it really matters is it's designed to handle billions of devices. So that you can have a lot of people sharing data and getting to data, sharing a network connection in a densely populated area.

[00:37:58] That's where it really, really shined. And then it also has a faster data rate than the older technology. One of the things you'll find as you compare, if you really dig into the technology compare, the various cell companies is that for instance, T mobile, which is who I use has a lower frequency spectrum.

[00:38:24] Lower frequencies can not carry as much data for, but what they can do, I'm really oversimplifying. But what they can do is more readily peers, glass, and brick and walls. So T-Mobile's frequencies are lower than Verizon, for instance. So Verizon can get you faster data. But can't get it into as many places and not as well as T-Mobile just really putting this quite simply.

[00:38:57] And in fact, just what was it? Two weeks ago, we had a court order stopping the deployment of these higher frequency, 5g networks. Because of complaints from some people, uh, particularly in the avionics, in the airline industry where they're saying, well, they could be squashing some of our critical systems because they're using some of the old satellite frequencies for 5g up in the upper bands.

[00:39:25] Anyhow, one of the things that 5g. Which has already been used for is what I was involved with. You know, I was involved with emergency medicine for a long time and I was an EMT I P D uh, back in the day. So almost a paramedic. And think about what could happen now, you're in the back of an ambulance that you could be the hands for the doctor who can be seeing the patient as you're driving down the highway, bringing that person in, because historically I remember this one woman.

[00:40:01] Placenta previa and had just soaked through some towels with blood. She was in really bad shape and we were squeezing IVs to get fluid into her. It was, it was incredible. It was something else. And we brought her right in on the gurney, in emergency room and right up to the operating room and put her on the table, right from her ambulance gurney while with five G.

[00:40:27] They can be doing that now, not just in an ambulance, but in, in more rural areas, doctors can be operating remotely on someone. It's very cool. This whole tele medicine, including remote surgery. It's huge. So these technology leaders agreed with me on that 24% is the number one, most benefit four or five G telemedicine.

[00:40:53] Number two, remote learning and education 20%. Personal and professional day-to-day communications. Think of all of the stuff we're doing now, how much better that's going to get entertainment, sports, live streaming, manufacturing, and assembly transportation, traffic control. Now we're down to 7% and by the way, that's where the cars are talking to each other.

[00:41:16] If you have five G. You don't need a mesh because you can use 5g, carbon footprint reduction in energy efficiency. That's 5% and 2% farming and agriculture. Our farming equipment is already using GPS in order to plow fields, planned fields, harvest fields. It's amazing. So there you go. Those are the top pieces of technology that are predicted to influence us next year.

[00:41:46] I think it's absolutely correct. And I've got to give you a bit of good news here again. 97% of these people polled agree that their teams are working more closely than ever before. Because of these working from home workplace technologies and apps for office check-in, et cetera. Good news. All around.

[00:42:11] Hey, if you want more good news. If you want to know what's happening, even some bad news, I got the right place for you to go. I have five minute little trainings in my emails every week. I have bootcamps again, all of this is the freeze stuff. You imagine what the paid stuff is like, but I want you to understand this.

[00:42:32] Okay. Craig, peter.com/subscribe. Do it right now.

[00:42:39] I had a good friend this week that had his life's work stolen from him. Yeah. And you know what caused it? It was his passwords. Now, you know what you're supposed to be doing? I'm going to tell you exactly what to do right now.

[00:42:55] Well, let's get right down to the whole problem with passwords.

[00:43:00] I'm going to tell you a little bit about my friend this week. He has been building a business for. Maybe going on 10 years now, and this business relies on advertising. Most businesses do so in some way, we need to have new customers. There's always some attrition there's customers that go away. So how do we keep them?

[00:43:25] Well, we do what we can. How do we get new customers? Well, for him, it was. Advertising, primarily on Facebook. He did some Google ads as well, but Facebook is really where he was focused. So how did he do all of that? Here's the bottom line. You have to, if you are going to be advertising on Facebook, you have to have an advertising account.

[00:43:51] Same thing's true with Google. And then on that account, you tie in either your bank account or your credit card. I recommend a credit card so that those transactions can be backed up. And on top of all of that now, of course you have to use a pixel. So the way the tracking works is there are pixels on websites, you know, about those already.

[00:44:17] And the bottom line with the pixels. Those are also. Cookie's about the pixels are used to set a cookie so that Facebook knows what sites you've gone to. So he uses those. I use those. In fact, if you go to my website, I have a Facebook pixel, the get set. And the reason for all of that is so that we know with.

[00:44:39] I'd be interested in something on the site. So I know that there's a lot of people that are interested in this page or that page. And so I could, I have not ever, but I could now do some advertising and I could send ads to you so that if you were looking at something particular, you'd see ads that were related to that, which is what I've always said.

[00:45:04] Is the right way to go. If I'm looking to buy a pickup truck, I love to see ads for different pickup trucks, but if I don't want a car or truck, I don't want to see the ads. Right. It isn't like TV where it seems sometimes every other ad is about. Car or a pickup truck. It drives me kinda crazy because it's a waste of their money in advertising to me because I don't want those things.

[00:45:33] And it's also not only just annoying in money wasting. There are better ways to do targeting. And that's what the whole online thing is. Anyways, I told you about that because he had set up this pixel years ago. Basically the Facebook pixel gets to know you gets to know. All of the people who like you, that might've bought from you.

[00:45:58] Cause you can have that pixel track people through your site, your purchase site, they know what you purchase on the shopping cart, et cetera. And you can identify these people over on Facebooks and them ads because they abandoned the cart or whatever it is you want to do there. There's just a whole ton of stuff that you can do for these people.

[00:46:19] And it's so bad. It is so valuable. It takes years to build up that account years to put that pixel in place. And our friend here, he had done exactly that. Then he found that his account had been compromised. And that is a very bad thing in this case because the bad guy used his account to place ads. Now there's really two or three problems here.

[00:46:52] We'll talk about one of them is. Why was the bad guy going after him? Well, he has been running ads on Facebook for a long time. So as far as Facebook is concerned, his account is credible. All of the ads he runs don't have to be reviewed by a human being. They can, can go up almost immediate. He doesn't have to wait days for some of these things to go up.

[00:47:21] So our bad guy can get an account like his, that has years worth of advertising credibility, and now start advertising things that are not correct. So there again is part of the value of having one of these older accounts for advertising. And so the bad guy did that use his credibility. And then secondly, he used 25 grand worth of my friend's money to run ads.

[00:47:51] Also of course, very bad, very, very bad. So I sat down with him. In fact, it was this last week and I was out on a trip with just kind of a vacation trip. It was absolutely wonderful. You know, I, I never just do vacation. Right. It's always business plus work whenever I do anything like this, but I was on.

[00:48:11] Trip last week. And so my eldest son who works closely with me, and he's also part of the FBI InfraGuard program. I had him reach out to my friend and they, he helped them out and they talked back and forth. Here's the problem that he has. And I'm trying to figure out a really good way to solve this. And I haven't figured that out yet.

[00:48:35] And you know, if you guys have an idea because you are the best and brightest, you really are. Go ahead and drop me an email me@craigpeterson.com if you know, a good way around this particular problem, which is he has. This Facebook could count as well as many other accounts, including his website, hosting account, his email account, et cetera.

[00:48:57] And. Uh, he has people who manage his ads for him who manages website for him, who put up some of the promotions for him, you know, the advertising and everything else. So these are third-party. This is what we generically call a supply chain, risk people who are not him have access to his stuff, his private stuff.

[00:49:24] And, well, how does he do it or how did he do it? Is he went ahead and gave them. Access by giving them accounts or passwords. How well were they guarding their passwords and their accounts? So the first thing I had my friend do was go to have I been poned.com. You'll find that online at have HIV. E I been.

[00:49:50] Poem dispelled PW, N E d.com. So I took him to have I been poned and I had him put in his email address, the one he uses the most and it showed up in five different. Hacks data dumps. So these are five different sites where he had used that same email address in this case. And he found out that in those five cases, the bad guy's got his passwords and personal information.

[00:50:21] All bad. Right. And he went ahead and cleaned it up. So I said, well, put in the password because have I been, poned also let you check your password, just see if it has been used by someone else and then stolen. So there are billions of passwords in this database. It's incredibly. Of all of these known passwords.

[00:50:44] So he put in his password and no it had not been stolen, but the problem is how about the people that were managing his ads on Facebook and managing his Facebook ad. We're the usernames, which are typically the email addresses and the passwords kept securely. That's a supply chain thing I'm talking about, and that's where I I'd love to get him.

[00:51:12] But from you guys, me@craigpeterson.com. If you think you have a good answer, What we've been doing. And our advice to him was use one password. That's the only one to use. I don't trust the last pass anymore. After their last big hack where they got hacked, uh, one password, the digit one password. And go ahead.

[00:51:33] And set it up. And in a business scenario, you can have multiple vaults. So have a vault. That's just for people that are dealing with your Facebook ad account, maybe have another vault for people who are posting for you on Facebook. Or better yet when it comes to Facebook, go ahead and have an intermediary that is trusted, uh, kind of like the, if this, then that, or there's a few of them out there that can see that you put the post up on the website and automatically posted on Facebook.

[00:52:09] So you don't have to get. All of these people, your passwords, but again, it's up to you. You got to kind of figure out if that makes sense to you that those are the types of things that I think you can do. And that is what we do as well. Now, one of the beauties of using one password like that, where you're not sharing all of your passwords to everything you're sharing, the minimum amount of login information that you possibly can share is that if they leave your employees, All you have to do is remove their access to the appropriate vault or volts, or maybe all of your volts.

[00:52:49] And this is what I've done with people that worked for me in the U S and people would work for me overseas and there have been a lot of them and it has worked quite well for me. So with one pass, We can enforce password integrity. We can make sure the passwords on stolen. One password ties automatically into have I been postponed.

[00:53:12] So, you know, if a password has been exposed, if it's been stolen online, it's a great way to go. Now I've got an offer for you guys who are listening. I have a special report that I've sold before on passwords, and it goes through talks about one password. He talks about last pass, which I'm no longer really recommending, but give some comparisons and how you can use these things.

[00:53:35] Make sure you go and email me right now. Me, M e@craigpetersohn.com. That's Emmy at Craig Peter Sohn, S O. Dot com and just ask me for the password special report, and I'll be glad to get that on off to you. There is a lot of good detail in there and helps you, whether you're a home user or a business.

[00:54:02] So the next step in your security is multi-factor authentication. Interesting study out saying that about 75% of people say that they've used it for work or for business, but the hard numbers, I don't think the.

[00:54:18] One of the things that you have to do is use good passwords. And the best way to do that is to use a password manager.

[00:54:27] I was talking about a friend of mine who had been hacked this last week and his account was hacked. His Facebook ad account was hacked. We asked him if we could reach out to. BI and he said, sure. So we checked with the FBI and they're looking to turn this into a case, a real case, because they've never seen this type of thing, the hijacking of an advertising account who hijacked it.

[00:54:56] And why did they hide jacket? Was this in preparation maybe for. Playing around with manipulating our next election cycle coming up. There could be a lot of things that they're planning on doing and taking over my friend's account would be a great way to have done it. So maybe they're going to do other things here.

[00:55:15] And our friends at the FBI are looking into it. How now do you also keep your data safe? Uh, easily simply. Well, when we're talking about these types of accounts, the thing to look at is known as two factor authentication or multifactor authentication. You see my friend, if he had been using multi-factor authentication.

[00:55:42] I would not have been vulnerable. Even if the bad guys had his username, email address and his password, they still would not be able to log in without having that little six digit code. That's the best way to do multi-factor authentication. When we're talking about this code, whether it's four or 5, 6, 8 digits long, we should not be using our cell phones to receive those.

[00:56:16] At least not as text messages, those have a problem because our phone numbers can be stolen from us and they are stolen from us. So if we're a real target, in other words, they're going after you. Joe Smith and they know you have some, $2 million in your account. So they're going after you while they can, in most cases take control of your phone.

[00:56:45] Now you might not know it and it doesn't have to be hacked. All they have to do is have the phone company move your phone number to a new phone. Once. So that means one of the things you need to do is contact your telephone vendor, whoever it is, who's providing new that service. That's a company like Verizon sprint T-Mobile, uh, a T and T one of those companies that are giving you cell service, you have to contact them and set up a pass.

[00:57:15] So that if they have a phone call coming in and that phone call can be faked. So it looks like it's coming from your phone, even if there was a phone call coming in, whether it's coming from your phone or not, they have to get that password or pass code that you gave them. And once they have that pass code now, Right.

[00:57:37] Uh, and that's great, but if you don't have that in there targeting you specifically, then you're in trouble. So for many of us really, it, it may not make a huge difference. Uh, but I would do it anyways. I have done it with every one of my cell phone carriers now. A couple of decades set up a password. So the next step is this multifactor authentication.

[00:58:03] If I'm not supposed to get it via text message to my phone, how do I get it? Well, there are a couple of apps out there. There's a free one called Google authentic. And Google authenticator runs on your phone. And once it's there on your phone and you are setting it up on a website, so Facebook, for instance, your bank, most websites out there, the bigger ones, all you have to do is say, I want to set up multi-factor authentication, and then it'll ask you a case.

[00:58:34] So how do you want to do it? And you can say, I want an app and they will display. A Q R code. That's one of those square codes with a bunch of little lines inside of it. You're seeing QR codes before they become very common. And you take your phone with the Google authenticator app. Take a picture. Of that little QR code on the screen, and now it will start sinking up so that every 30 seconds Google authenticator on your phone will change that number.

[00:59:08] So when you need to log back into that website, it's going to ask you for the code. You just pull up Google authenticator and there's the code. So that's the free way to do it. And not necessarily the easiest way to. Again, going back to one password. I use this thing exclusively. It is phenomenal for keeping my passwords, keeping them all straight and then encrypted vault, actually in multiple encrypted vault it's so that I can share some of them.

[00:59:37] Some of them are just strictly private, but it also has that same authenticator functionality built right into it. Microsoft has its own authenticator, but you can tell Microsoft that you want to use the standard authenticator. Of course, Microsoft has to do everything differently. Right. But you can tell it.

[01:00:00] And I do tell it, I want to use a regular authenticator app, not Microsoft authentication. By the way. That's why I advise you to do don't use the Microsoft authenticator, just use one authenticator for all of the site, and then Microsoft will give you that same QR code. And then you can take that picture and you're off and running.

[01:00:20] Next time you log in, it asks you for the code and instead of texting it to you to your phone smarter, otherwise it will not. That require you to open up your authenticator. So for me, for instance, when I'm logging into a website, it comes up and asks for the username, asked for the password. Both of those are filled out automatically by one password for me.

[01:00:44] And then it asks for that code, uh, indication code and. One password automatically puts it into my pace to buffer copy paste, buffer, and I just paste it in and they they've got the code. So I don't have to remember the codes. I don't remember passwords. I don't have to remember usernames or email addresses.

[01:01:05] One password remembers them all for me. Plus it'll remember notes and other things. So you can tell, I really like one password. We use it with all of our clients. That's what we have for them. And it does meet even a lot of these DOD requirement on top of. Depending again, how much security you need. We will use duo D U O and it also has this authenticator functionality and we will also use UBI keys.

[01:01:37] These are those hardware key. They do oh, can provide you with hardware tokens. Those are those little tokens that can go onto your key ring. That show a changing six digit number every 30 seconds. And that's the same number that would be there in your smartphone app. Your one password or Google authenticator smartphone.

[01:01:59] Hopefully, I didn't confuse you too much. I think most of the reason we're not using the security we should is because we're not sure how to, and we don't know what we're going to be. And I can see that being a big problem. So if you have questions about any of this, if you would like a copy of my password security, special report, just send an email to me.

[01:02:25] M e@craigpetersohn.com. That's me M e@craigpeterson.com. That's S O n.com. I'll be glad to send it to you. Also, if you sign up for my newsletter there on my website@craigpeterson.com, you are going to get. I was hold little series of these special reports to help you out, get you going. And then every week I send out a little bit of training and all of my articles for the week.

[01:02:56] It's usually six to 10 articles that I consider to be important so that, you know, what's going on in the cybersecurity world. So you can. With it for yourself, for your family, for your business. Craig peterson.com. Stick around everybody. We'll be right back again. Craig peterson.com. .

[01:03:20] According to researchers. 32% of teen girls said that when they felt bad about their bodies, Instagram made them feel worse. And you know what Facebook knew and knows Instagram is toxic for teen girls.

[01:03:37] There's a great article that came out in the wall street journal.

[01:03:40] And I'm going to read just a little bit here from some of the quotes first. When I went on Instagram, all I saw were images of chiseled bodies, perfect. Abs and women doing 100 burpees in 10 minutes, said, Ms. Uh, now 18, who lives in Western Virginia. Amazing. Isn't it. The one that I opened now with 32% of teen girls said that when they felt bad about their bodies, Instagram, I made them feel worse.

[01:04:12] So that is some studies again, that looks like, um, yeah, these were researchers inside Instagram and they said this in a March, 2020 slide presentation that was posted to Facebook's internal message board that was reviewed by the wall street journal quote comparisons on Instagram can change how young women view and describe themselves.

[01:04:38] Apparently for the past three years, Facebook has been conducting studies into how Instagram is affecting its millions of young users. Now, for those of you who don't know what Instagram is, it allows these users to create little stories, to have. Pictures videos of things that they're doing, and it it's a lifestyle type thing you might've heard of course, of how this, this, uh, I don't know what it is.

[01:05:09] Kidnapping murder plot. These, this young couple and the body I think was found up in Wyoming. Uh, I'm trying to remember, but, uh, of her and it's yeah, there it is. It wasn't my OMI. And I'm looking up right now, Gabby potato. That's who it is. She was what they called a micro influence. And I know a lot of people who can loom, that's what they want to be.

[01:05:37] There's a, a young lady that stayed with us for a few months. She had no other place to live. And so we invited her in here and, uh, we got some interesting stories to tell about that experience. And it's, you know, a little, a little sad, but anyhow, she got back up on her feet and then she decided she was going to become an influence.

[01:06:01] And what an influencer is, is someone that has a lot of followers. And of course, a lot means different numbers. You get these massive influencers that have tens of millions of people that quote, follow unquote them. And of course, just think of the Kardashians they're famous for. Being famous, nothing else.

[01:06:23] Right. Uh, they have subsequently done some pretty amazing things. At least a few of them have. And we've got one of those daughters who now was the first earliest billionaire, I think it was ever youngest. So they have accomplished some amazing things after the fact, but they got started. By just becoming famous by posting on these social media sites.

[01:06:48] So you get a micro influencer, like Gabby Petito, who is out there posting things and pictures. And you look at all of these pictures and, oh my gosh, they're up at this national park. Oh, isn't she so cute. Oh, look at her boyfriend. They'll look so good together. And people. Fall for that image, right? It's just like Photoshopping these pictures of models, changing them.

[01:07:16] There've been some real complaints about those over the years. So Instagram sets these kids up with these pictures of people that are just totally unrealistic. One of the slides from a 2019 presentation says, quote, we make body. Excuse me. We make body image issues worse for one in three teenage girls teams, blame Instagram for increases in the rate of anxiety.

[01:07:49] And depression said another slide. This reaction was unprompted and consistent across. Groups among teens is this according to the wall street journal who reported suicidal thoughts, 13% of British users, and 6% of American users trace the desire to kill themselves to Instagram. Again, according to one of these presentations, isn't this just absolutely amazing.

[01:08:18] And you might've heard it discussed a little bit. I saw some articles about it, obviously in the news wall street journal had it, but this is a $100 billion company, Instagram. That's what their annual revenues. More than 40% of Instagram users are 22 years old and younger. And about 22 million teens log into Instagram in the U S each day, compared with 5 million that log into Facebook, the younger users have been declining.

[01:08:57] Facebook it's getting, uh, the population there is getting older and older on Facebook. In average teens in the us spend 50% more time on Instagram than they do on Facebook. Uh, and also tick-tock, by the way I took talk has now surpassed YouTube in some of these metrics, quote, Instagram is well-positioned to resonate.

[01:09:20] And when with young people said a researcher's slide posted internally. Inside Facebook and post said there is a path to growth. If Instagram can continue their trajectory. Amazing. So Facebook's public phase has really tried to downplay all of these negative effects that the Instagram app has on teens, particularly girls, and hasn't made its research public or available to academics or lawmakers who have asked for it.

[01:09:54] Quote, the research that we've seen is that using social apps to connect with other people. Positive mental health benefits said mark Zuckerberg. He's the CEO of course of Facebook. Now this was 2020. In March one at a congressional hearing, he was asked about children and mental health. So you see how he really lawyered the words that they can have, can have positive mental health benefits, but Facebook's own internal research seems to show that they know it has a profound negative effect on a large percentage of their users.

[01:10:36] Instagram had Adam Moseri told reporters in may of this year, that research he had seen suggest the app's effect on team's wellbeing is likely quote quite small. So what the wall street journal seems to be pointing out here is that Facebook is not giving us the truth on any of this stuff. It's really sad.

[01:10:58] We've got to be careful. No, apparently Mr. Moseri also said that he's been pushing very hard for Facebook to really take their responsibilities more broadly. Uh, he says they're proud of this research. I'm just kind of summarizing this before we run out of time here, but it shows the document. Uh, internal documents on Facebook show that they are having a major impact on teen, mental health, political discourse, and even human trafficking.

[01:11:36] These, this internal research offers an unparalleled picture. Uh, Courtney told the wall street journal of how Facebook is acutely aware that the products and systems central to its business success routine. Fail great article. I've got it in this week's newsletter. You can just open it up and click through on the link to the wall street journal.

[01:12:01] They have a pay wall and I kind of hate to use payroll articles, but this one, this one's well worth it. And they do give you some free articles every month. So if you're not on that newsletter, you can sign up right now. Craig peterson.com. You'll get the next one. If you miss a link today, if you want some, you know, the special report on passwords, et cetera, just email me directly.

[01:12:29] Give me a few days to respond. Uh, but me M e@craigpeterson.com. That's me M e@craigpeterson.com.

[01:12:41] We've all worked from home from time to time. At least if we're somehow in the information it industry, I want to talk right now about why you need a personal laptop. Even if the business is providing you with a laptop.

[01:12:57] Laptops are something that was designed to be personal, but many of us are using them as our main computer.

[01:13:06] I know I often am using my laptop, a couple of my kids and my wife. It's really their main computer, even though they all have other computers that they could potentially be using, laptops are just handy and you have them with, you can take them with you. We've got workstation set up that are kind of.

[01:13:27] Workstations, if you will, where there are three screens set up and they're all hooked up into one central screen controller that then has a USBC connection that goes right into the, your laptop. So you can be sitting there with four screens on your Mac laptop on your Mac pro if you needed four screens, it's really handy.

[01:13:53] No question. Many of us have a laptop for home and a laptop for business. And many of us also look at it and say, oh wow, this is a great laptop I got from work. It's much better than my home laptop. And you start to use the business laptop for work. At home. Okay. That's what it's for. Right. But then we start to use that business laptop for personal stuff.

[01:14:25] That's where the problems start. We've seen surveys out there that are shown. Then half of workers are using work issue devices for personal tasks that might be doing it at home. They might be doing it at the office. Things like personal messages, shopping, online, social media, reading the news. So the prospect of using your work laptop as your only laptop, not just for work, but also for maybe watching some movies, group chat and messaging, reading, fan fiction, paying bills, emailing to family or friend.

[01:15:06] It just seems not. It's so tempting. It's just natural. I'm on it. I'm on it all day long. Why wouldn't I just use it? And this is particularly true for people who are working from home, but we have to be careful with that. It's really something that you shouldn't be doing for a couple of reasons. One that.

[01:15:30] Top that's a business. Laptop is the property of the business. It's just like walking home with boxes, full of pencils and paper back in the old days, it is not yours to use for personal use. We also have to assume, assume since it is the company's laptop that hopefully it's been secure. Hopefully they haven't set up.

[01:15:57] So it's going through a special VPN at the office and it's going through special filters, maybe snort filters or something else. That's doing some deeper inspection on what's coming through your laptop. Well, there are also likely on that laptop. Tools that are monitoring your device. Things like key loggers, biometric tracking, Jill location, software that tracks your web browser and social media behavior, screenshot, snapshot software, maybe even your cam.

[01:16:34] Is being used to keep track of you. I know a number of the websites that I've used in the past to hire temporary workers. Those workers have to agree to have you monitor what they're doing. These hourly workers, subtle take screenshots of their screen, unbeknownst to them. Yeah. Pictures from the cameras at random intervals.

[01:16:58] Again, unbeknownst to them, it'll track what they're doing. And so I can now go in and say, okay, well he billed me five hours for doing this. And I look at his screen and guess what? He wasn't doing that for all of those five hours that he just billed me. Well, the same thing could be true for your company, even if you're not paid by the hour.

[01:17:23] Right now, we're looking at stats that show over half of the businesses that are providing laptops for the employees to use more than half of them are using monitoring software. And through this whole lockdown, the usage of these different types of monitoring systems has grown. Now there's some of the programs you're using.

[01:17:50] You might be VPN in, you might be using slack or G suite enterprise, all good little pieces of software. They can monitor that obviously, but it goes all the way through to the business. And using your slack access as paid for, by the businesses also idiotic to do things like send messages to your buddies, set up drinks after work, complain to other people about someone else in the business, your boss, or otherwise your it, people at the business can see all of that.

[01:18:31] They can see what you're doing with slack. Even if you have a separate personal account. It's still more likely that you'll end up mixing them up if you're logged into both on the same computer. So the bottom line is if you are on a work computer, whether it's a laptop or something else, you can reasonably assume that I T can see everything.

[01:18:56] That's not. They own it. Okay. And they have to do some of this stuff to protect themselves. We put software on laptops for companies not to spy on employees. That's none of our business, but we put software on computers for employees. To make sure they stay safe. Think of what happens when your computer, your laptop, whatever it might be connects to the company's network.

[01:19:25] Now that can be through a VPN. It can be because you take your laptop home or on the road when you're traveling and you bring it back into the office. If that computer is infected, somehow now you've brought that infection into the office. And that's how a lot of the malware works. It goes from computer to computer.

[01:19:48] So once they get in that front door where there's through a website and email that you clicked on or in a computer that you're bringing into the office, they can start to move around. Now it's not just your activity. And this is an interesting article from the verge by Monica chin. It's not just your activity that they can see on your laptop, but in many cases, they're also able to look at anything you're downloading any of your photographs or videos that you might've sinked up from your smart.

[01:20:26] Laura loading these types of things, your text messages on your work device for safe keeping, or just because it's your primary device might seem harmless, right? Cause you're just going to remove them before you hand it in. But some companies such as apple won't allow you to wipe your device before handing it in regardless of how personal the contents are.

[01:20:48] And that makes sense too, because many times an employee leaves. And they don't give the company all of the information that they have, that they're obliged to give back to their employer. Things that they've been working on, customer information, et cetera. So Manalive, there are plenty of other devices out there.

[01:21:10] Hopefully if you leave your company with plenty of notice, moving a bunch of things off your work device in the last few days, uh, might raise some eyebrows at the. And I'm saying hopefully, because they should notice that sort of thing, because it could be malicious activity. It could be an insider risk that maybe they're not even aware of.

[01:21:33] There's so much you could go wrong here. So bottom line don't use the work laptop for home. So what should you use? You know, my personal recommendation. Almost always is get a Mac. They are safer to use the patches that they get are usually not destructive. You know, sometimes you can install a patch for windows and now your machine just don't work anymore.

[01:22:01] Right. You've had that happen. I know every last one of us out there that are tried to install Microsoft patches for a while have had that happen to them. All of a sudden the patch has completely messed up your computer and you are so out of luck, it's ridiculous. Right? So don't, you know, hopefully don't do that, but I like the max because they are basically safer than windows.

[01:22:27] And also because the patches just work on them, apple tends to get them out in plenty of time to try and protect us the next level. If he can't afford an apple in. Apple laptops really are not expensive when you consider how long they last and the quality that components, they are not expensive at all.

[01:22:47] But if you can't afford that, the next thing I would look at is getting a Chromebook. There are a lot of companies that make Chromebooks Chrome is an operating system from Google. It's similar to Android. Google keeps the Chromebooks up-to-date. They patch them quite regularly and make sure that there aren't nastiness is going on.

[01:23:11] You just have some of the same issues and Android has patches might take a while to get to you because it has to go through the vendor that made the Chromebook. You might have a Chromebook for Sam from Samsung, for instance, it's not Google's even though it's called a Google Chromebook. Now Chromebooks rely heavily on the cloud services that Google provides, but they can also run just locally.

[01:23:38] So with a Chromebook and you can get them for as little as 150 bucks, but remember you get what you pay for. Or as much as I've seen them in the $2,000 price range with fancy GPU's, local storage and other things, but at 150 bucks, it could be well worth it for you. It lets you do the regular word processing.

[01:24:02] Just think of what you can do with Google docs, spreadsheets. Again, Google docs, spreadsheets, all of those types of things are built into it. You can. Cruz the web, obviously using Google Chrome on your Chromebook. And send and receive email, which is what most people do. That's really kind of all, most people do at home.

[01:24:26] So consider that as well. I also like iPad. They are quite safe again, but they tend to be more expensive and they can do pretty much everything. And now with Android support built right into Google Chromebooks, you can even run Android apps. So there you go. Keep safe and be safe out there. Right. Have a hack free life.

[01:24:52] Make sure you get my newsletter. Craig peterson.com/subscribe. Craig peterson.com/subscribe.

View Details

Do You Think There's Nothing You Can Do to Keep the Bad Guys Out?

What a week. The FBI got hacked. Homeland security supposedly is sending out emails about hackers in your network. This is what we're going to talk about to start with today. What are these new emails, and how are they trying to con you?

[Automated Transcript Follows]

This is a little bit concerning. We know that the FBI's email system got hacked. And for everyone sitting there saying, well, gee, if the FBI gets hacked, there's no way my business can survive an attack. Remember that the FBI is a huge, huge target. They have so many systems, so many people, and the bad guys really, really would love to send an email out as though they are the FBI.

[00:00:49] And, they did, they used, they used the FBI's email servers to send out some of these fake emails. I thought that was kind of funny, but be that as it may, the FBI closed. But there are things you can do to protect yourself, to protect your email. And my wife and I have been working diligently on a guide.

[00:01:13] Now, you know that I protect businesses. I work closely with the FBI, been doing cyber security for more than 30 years. I kind of hate to admit it. But, uh, you know, you know, I've been on the internet for more than 40 years. So I've been at this for a very, very long time and there are things you can do. So we're making available a guide.

[00:01:38] So she's taken a lot of my teachings and is boiled it down. It looks like it's going to be 25 ish pages. And it's just the essential things, the primary things that you can do. To stop your email from getting hacked, your bank accounts, et cetera. There are some pretty simple things you can do. So we're putting that together, and we're also putting together a Bootcamp and both of these are free.

[00:02:07] Okay. Absolutely free. And in the bootcamp, again, this book isn't about selling you all of the, my services and stuff. It's giving you. Actionable things you can do. Yes, you can do. You don't need to be the FBI or a cybersecurity expert to do them, but five things you can do that will, I don't know, 10 X, your cybersecurity, really?

[00:02:35] It it's, it's that big a deal. And it's going to take you less than an hour to do all of this stuff. So for those people who like the boot camp, so we're going to have. And, uh, you know, one of these zoom things and we're going to do it live and I'm going to explain it to you, spleen it. And you're going to have some homework before the bootcamp, because I want you to have some skin in the game too.

[00:03:02] Right. You're not paying me or anything. So I want to make sure that you've done your homework so we can quickly. Go through all of the stuff that we need to cover in the boot camp and people who are interested in kind of being the example, which means they are going to get more information than anybody else.

[00:03:21] You can also say, Hey, listen, uh, yeah, please use mine as an example. So we'll look at all of these different things. We're going to focus in on that first bootcamp primarily on. The stuff with passwords, you know, what should you do? How should you do it? How can you tell if your password has been stolen? If your email accounts been compromised, all of that sort of thing.

[00:03:44] And you need to be on my email list in order to find out about this stuff. Right. And in fact, when you sign. I've got three special reports that Karen and I wrote that are really going to be helpful for you. These are three that we've been using with our clients for years, but again, actionable. To do right, is not some marketing sales guy trying to sell you the latest, greatest piece of antivirus software that doesn't work.

[00:04:18] So you can get that. If you go to Craig peterson.com right now slash subscribe. If you want the deep link, Craig peterson.com/subscribe. We'll go ahead and sign you up. I have a little automated sequence. It's going to send you the emails with all of the attachments. We got one, that's kind of an introduction to Karen and I, you get to see both of us.

[00:04:44] And, uh, it's a really cool picture of when we're on vacation one time and you can get all of that again. It's free. This is the free newsletter. This isn't the paid newsletter. Craig peterson.com. Slash subscribe. All right. So I can help you out with all of that free content. And I have lots of it. I'm on the radio every week talking about free, right.

[00:05:08] And you can avoid these things. So like, I kind of hate to bring up this FBI hack because as I discussed again with Karen this week, I, I don't want people to feel like there's nothing that they can do. I have a friend, her name's Laura and she's in one of my mastermind groups. And Laura is, was listening to me because another mastermind member got hacked and it had like, what was it?

[00:05:36] $45,000 ultimately stolen from him. And we helped them out. And so I was explaining, okay, so here's the things you can do. And. Basically all she heard was, uh, I'm never going to be able to do this. And, and she's a technical person. She teaches people how to become business analysts, which is pretty technical, right.

[00:06:00] There's a lot of steps involved in doing business and analyst work. And so I was really surprised to hear from her that she had. The securing herself was just too hard. You know, the FBI gets hacked, et cetera. And so that's why when I came to this realization, the bottom line is, yeah. Okay. It can be hard if you're like me and you've been in doing this for 30 years, you've got the curse of knowledge, right?

[00:06:30] So you, you know, all of this stuff, this isn't for you. If, if you know everything, okay, this is for people who. Quite understand what's going on. Definitely don't understand what they should do. Don't know what they should buy. They don't know how to use the free stuff that Microsoft and apple give you and how to pull it all together.

[00:06:52] That's what I want you to be able to understand, and we spend time every. Going through this and every newsletter. I have a, an opening now that is a lot about three to five minute read. If that it can be very, very quick read and is helping you to understand some of the things that you can and should do.

[00:07:16] So you'll get that as part of the newsletter. Again, Craig peterson.com. That's in my free newsletter. You should see the paid newsletter. Uh, it's a big deal because it's your life. It's a big deal because it's your business. It's a big deal because it's your job on the line. And most of the time, and when I pick up a new client, it's somebody who's kind of the office manager.

[00:07:42] Well, frankly, more than your office manager, sometimes the business owner, you know, owner operator says to the office manager, Hey, we got to do something about cybersecurity and then I get. Saying, Hey, can you do a cyber health assessment for us and that cyber health assessment, which we'll do for almost anybody out there will tell you the basic self.

[00:08:05] Okay. Here's what you got to do. You've got to update this. You should turn off this software or you should do this and that with your firewall so that they have. I a little checklist, right. That they can run through. That's the whole idea behind one of these cyber health assessment. And then what happens is they say, okay, well, let's, let's talk some more and we go in and talk with them, talk with the owner.

[00:08:32] Do they want to do, help them put together a more detailed plan and then they are off and running so they can do it themselves. They can hire someone, they can have us do it for them, whatever seems to make the most sense, but it's very important. To do it, to do something because sitting there trusting the Google's going to take care of you or apple or whomever, it is, uh, you know, trusting Norton antivirus is going to take care of.

[00:09:04] I was reading a quote from John McAfee. He's the guy that started the whole antivirus industry. Now, of course, he passed away not too long ago, under suspicious circumstances, but he came out and said, Hey, listen, antivirus is. Because right now this year, these weren't his stats. These are stats published.

[00:09:24] You can find them online. Just duck, duck, go them. Yeah. I don't use Google for most things. Uh, and you'll find that the antivirus is ineffective 77, 0% of the time. So, what do you need to do? Well, you need to listen to me here because I am going to help keep you up to date here. Some people are auditory listeners.

[00:09:46] You need to make sure that you get the newsletter so that you get the weekly updates and you find out about these free trainings and special reports that we put together. Makes sense to you and you can attend the boot camps where we cover the basically one hour meetings on zoom, just like you're used to, and we cover one or more specific topics and we do it live and we use your information.

[00:10:17] The information you want us to have a, do you want us to share? So how could that be better? And it's the same sort of stuff, but deeper dives and more interactive obviously than radio. And you can listen to me here every week. I think it's important that you do, and you understand this stuff. So anyways, ramble, ramble.

[00:10:37] It all starts with email. How do you keep your emails safe? You might remember years ago, you, people were getting broken into and emails were sent out using their accounts. Well, that happened decades ago and it's still happening today. So. Right now, Craig peterson.com. I promise you. I am not a heavy marketer.

[00:11:01] Okay. You're going to get good, actionable information that you can put to use in a matter of minutes, Craig peterson.com/subscribe.

[00:11:13] Our intelligence monitoring indicates exfiltration of several of your virtualized clusters in a fist sophisticated chain attack. Your, I am trying to put on this like official voice. Right. And it didn't do so well anyways, that's what we're going to talk about, right now.

[00:11:29] This is an email that came from the department of Homeland security warning about hackers in our network.

[00:11:37] Okay. The subject line here, the one I'm looking at, and this is a, the justice week urgent threat. In systems read the email goes on. We tried to black hole, the transit nodes used by this advanced persistent threat actor. However, there is a huge chance you will modify as attack with fast flux technologies.

[00:12:01] I don't know if that ties into a flux capacitor or not, which he proxies through. Uh, multiple global accelerators. So this is somebody who doesn't really know what they're talking about. They're just throwing up big words. We identified the threat actor to be. Somebody whom is believed to be in of course, whom wrong usage of the word here, uh, is believed to be affiliated with the extortion gang, the dark overlord, comma, uppercase.

[00:12:33] We highly recommend you to check your systems and IDs monitoring. Be where this threat actor is currently working under the inspection of the MCC. I see, as we are dependent on some of his intelligence research, we cannot interfere physically within four hours, which could be enough time to cause severe damage to your infrastructure.

[00:12:59] Stay safe. USDA department of Homeland security, cyber threat detection and analysis network analysis. Total control panel. So this is classic when it comes to scammers. And the classic part is that you could do. Is the grammars bad. The wording is confusing, his punctuation is wrong and he's throwing out all whole bunch of words that are used when it comes to hackers.

[00:13:35] You know, there are things like advanced, persistent threats. That's one of the biggest problems in fact, businesses have today. But in reality, the way he used it, Incorrect now that's something I would notice cause I've been doing this stuff for more than 30 years, but the average person is never going to notice something like this.

[00:13:59] So it's been pretty, in fact, pretty successful now, a little different than usual here. These fake messages don't have attachments. They don't have phone numbers. They don't have web links. Therefore what? Well, your email filter is not going to look at them and say, oh, these look risky. These URL links are going to risky sites.

[00:14:26] I'm going to block it. Right. That's what we do. We have the advanced email filtering from Cisco that we use for our client, or that includes their amazing artificial intelligence for phishing and stuff. So an email like this is not go. To trigger those types of alarms. So they're saying don't panic, avoid contacting the FBI for further details and ignore the accusations that are made in the email.

[00:14:55] This is so focused though. So is a cybersecurity company. They have, they have a lot of stuff. They have some pretty good stuff. It's not, um, there's not. But spam house is tracking it. Now, if you've ever been blacklisted, it's called black Coleen really by people who might've used your domain to send spam, or maybe you're a spammer, you've heard of spam house and I've been blacklisted before inappropriately.

[00:15:25] The good news is my. That I use for emailing is about 30 years old as well. So it's got a pretty good reputation over the years, but spam house is saying now that this is a scam they've been tracking it. It's a well-known scam and it's been widely circulated. To those office managers that I said are often the people who call us when there's a cybersecurity problem, or we get calls from office managers when something doesn't look right with the emails.

[00:16:01] And we have a client that had been getting these weird emails and. We were called saying, what's going on, have a look. We looked and we found all kinds of problems. Right? So that again, an office manager approaching us and thinking everything's fine because they had Norton and they had the more advanced Symantec stuff and it didn't catch.

[00:16:27] Any of this really nasty stuff, but that's part of what Spamhaus does. And they're looking at it and saying, oh, okay, wait a minute. Now we're seeing these emails come out. They are definitely not coming from, uh, fbi.gov, which is what the return address is. And so spam house tags, it spam. Assassin's going to tag it and, and it's not even going to make it.

[00:16:56] Anything, but a log on are our email filter. So a number of people have received it. If you've received this email, I'd love to know it because they really are trying to go after the people who are a little bit more into this now, how do they find them? Apparently? They have stolen the email addresses by scraping them from public sources.

[00:17:22] So databases, uh, published by Aaron, for instance, the American registry for internet numbers. And I'm assigned my own number is CP 2 0 5 because I was so early on by Aaron they're the guys that have been managing. The basic internet domain stuff here in the U S for very long time. And it also doesn't mean by the way that Aaron had any sort of a breach.

[00:17:47] And really just showing that the crooks behind this disinformation campaign have really been focusing on people who appear to be in network administration, because those are the email addresses and names that Aaron is going to have. So why are they doing this? Why are they sending it out into it's frankly, it's kinda hard to tell some of the emails have a QR code in them.

[00:18:18] Now that is intriguing because here's how, again, how a lot of these basic email filters work, they look at it, they say, well, what links are in there? How many links, how much of the email is a graphic? And they understand while it's going to internet bad guys.com. There's the link right there. Forget about it.

[00:18:42] I'm not going to forward this email to the intended recipient, but if there's a QR code in that email to almost every email filter out through. It only looks like a graphic. So might've been a picture of your mother as far as it knows. Most of them are not very smart. So w you getting an email, having a QR code in it and saying, oh, that's kind of interesting.

[00:19:07] Let's check out that QR code. That's where the hazard com. All right. So be very, very careful fake news like this. It's not only unfair to the people who are accused in it, which is what happened here. There can be accusing your own it department. They can be accusing. People within your department, which is typically what's happening and then what they may try and do now that you don't trust your, it people, your security people, because they're mentioned by name in the email, but remember their names are probably scraped off of.

[00:19:47] That you don't trust them. And now they attack you and you don't trust that you've been attacked. Right? So fake news, a term coined by Hillary Clinton during her campaign, but that's exactly what it is entirely fake. So this email, if you get one from Homeland security about threat actors in your systems, almost certain.

[00:20:12] Fake fake, fake, fake stick around. We've got a lot more coming up. Don't forget to subscribe. Get my weekly newsletter. I'm going to be published and even more, I think probably starting next month. I'm going to be sending a couple emails out a week because I got to get you guys up to speed so that you're ready for the upcoming bootcamp.

[00:20:35] Everybody knows about the chip shortage, right? Uh, computer chips. They're just hard to find. I'm hearing all kinds of ads from Dell lately on the radio. And they're saying just buy now. Well, they're not selling new high-end machines anymore. The white house. This is a story from the verge has allegedly kinda stepped in about Intel's plans to increase chip production.

[00:21:04] And you'd think that the white house would be encouraging chip production. Considering the shortages, the justice week, it came out Tesla hasn't been delivering their electric cars. Without USB ports. Other manufacturers are no longer providing you with an electric window for your car. It's a crank window.

[00:21:28] Car manufacturers did it to themselves, frankly, by stopping orders for chips during the lockdown, thinking that somehow people wouldn't need cars anymore. And yet their sales of cars went up and when they go. Yeah. Guess what happens to the price? The price goes up, right? Inflation. You have more money chasing fewer goods.

[00:21:52] So they really nailed themselves. Don't feel so sorry for some of these car manufacturers. We need more chips. I mentioned one of the manufacturers of PCs, the many of us use in our offices and, and Jews in our homes. Dell is a good company. They have been for a long time. However, you gotta be careful when you're buying computers because Dell makes very low end computers all the way up through good solid servers.

[00:22:22] Same. Thing's true with. P Hewlett, Packard, excuse me, Hewlett Packard. Remember those guys back in the day? Yeah. They also make everything from cheap computers that you never would buy should not buy all the way up through really good ones. It's kind of like going to Walmart, you go to the Walmart and you don't want to buy any of the computer sitting there with one exception.

[00:22:48] And that is the Chromebook. If you buy a mid tier Chromebook at Walmart, you're going to get a good little computer. Doesn't run windows, doesn't run Microsoft office word, et cetera, but it can still edit those documents. And it's a very good machine that is kept up to date. Just watch the price $110 Chromebook, probably isn't going to last.

[00:23:12] It doesn't have much storage on it, et cetera. A $2,000 Chromebook is probably major overhead. So go somewhere in the $400 $500 range for a Chromebook, which is by the way where they're selling some of the laptops, windows, laptops, same price point. I, again, that's why I just wouldn't buy any of that. So we need more chips.

[00:23:37] We need higher end chips. They are very hard to get our hands on right now. We're talking about electrification of everything. And if you've heard me on the radio during morning drive time, you know, I've been just bemoaning how the government's putting the horse before the. They're out there saying electric, electric, electric, and shutting down pipelines and coal mining and coal power plants.

[00:24:04] Although coal is one of the cleanest energy sources nowadays because of all of the scrubbing that's going on with the output of the coal plant. And also of course, they're, they've been stomping. Most of the nuclear plants from coming online, even though the new. Technology in nuclear is impossible to fail.

[00:24:26] They use basic physics to make sure that these things aren't going to do a Jane Fonda, a China's syndrome thing. Okay. So it's just crazy. We don't have the electrical. Even if we put up, it would take literally millions of wind farm, our turbines, and obviously millions of rooms and fields covered with solar cells.

[00:24:54] We would still need nuclear. We would still need other sources of power because the sun doesn't shine all the time and the wind doesn't blow all of the time. This is just completely backwards. People aren't thinking it through. It's again, it's the knee jerk. And of course they're investing heavily. They being the Congress, people of themselves, particularly those Congress people like the Al Gore's of the world and Nancy Pelosi and Chuck Schumer, because they are forcing a move to this technology that isn't ready for prime time.

[00:25:31] And at the same time, we are trying to buy electric cars. How are we going to charge them? How are we going to run our homes? It's like Europe, people froze to death last winter in Europe. It's going to happen again this year. And the thing about what happened in Texas last year. Yes. Some of that was because they weren't prepared, but guess what else happens?

[00:25:55] Sometimes the wind isn't blowing in Texas. So there's, there's just all kinds of problems. So Intel is saying, well, we got to increase our chip production. Intel's main business right now, by the way, seems to be moving towards making chips on behalf of other people, other companies, rather than making their own chips.

[00:26:20] Isn't that kind of interesting. And the industry, the chip fab industry, the ones that fabricate the chips, make the chips are spending about $2 billion a week. According to the latest numbers I saw to try and expand the manufactured. Well, apparently Intel went to the white house because they want some of our tax dollars.

[00:26:44] You know, the money they'd take at the point of a gun. They want some of that so that they can build their business, build it back better. And apparently some sources close to the situation told Bloomberg that Intel. Posed making silicone wafers in a Chinese factory, which could start production towards the end of next year.

[00:27:12] But in a move that I agree with had the Biden white house, apparently Intel was strongly discouraged due to potential security issues. Yeah, no kidding. Some major security issues here. We don't want to give away our technology to make this leading edge stuff. Think about the U S. We were always the country that people came to for technology.

[00:27:43] I mentioned this week on the radio, the cotton gin way back when look at how much labor. That, uh, that cut look at the internal combustion engine. And again, the Teamsters, the horses, the cleanup crews in New York city. Right. All of that went goodbye pretty much because of technology and people got higher technology.

[00:28:10] Jobs and everyone became more efficient and that's, what's supposed to happen right now when right now based basically we have stagflation in other words, prices are going up, but we're not getting any more productivity out of it. That's a real problem. And that's why they keep talking about the problems we were having in the late seventies.

[00:28:31] And I remember those well, I remember gas lines sitting there in California waiting to buy gas. It was incredible what was happening out there. So Intel thinks it needs to secure funding from the federal government in order to ramp up the production. Bloomberg announced, Orwell said that Intel currently has no plans to produce silicone wafers in China after discussing it with governor.

[00:29:01] Officials and it will instead consider other solutions. Now I hope those other solutions are to make those plants, those chip fab plant here in the United States. Let's put ourselves back on a leading edge footing here. Google moved its artificial intelligence lab to China talking about. Anti American thing to do moved it to China, artificial intelligence.

[00:29:31] That's something we need. The us needs to be the world leader in some of these technologies. And frankly, we're not the leader anymore. It's it frankly, a shame. So you can check this out. It's on the verge. You'll also find it up on my website. Craig peterson.com. Make sure you sign up for the newsletter so you can get all of these little trainings, you know, five minutes a weekend can make a big difference.

[00:30:03] Craig peterson.com.

[00:30:05] Hey, I don't want to depress anyone, but Bitcoin is now a 13 year old teenager. And back in January, 2009, Bitcoin was priced at well. Wow.

[00:30:19] January 3rd, 2009 is when it was launched. And E Bitcoin was priced at you ready for this point?

[00:30:30] Zero 8 cents each. Okay. So, uh, the, uh, uh, and because of that, a lot of people. I have been seen, well, you know, we, we've got to get into this and that in fact, Elon Musk has been kind of pushing up the price of another digital currency. All of the initial price increases in Bitcoin were due to fraud.

[00:30:57] According to a lot of reports and we can get into those if you'd like fraud. Yeah. That's a great way to launch a whole new product. And they also played some other games. For instance, the biggest driver of Bitcoin price for a long time was crux. For ransomware. Yeah. People had to buy ransom and pay ransoms.

[00:31:25] How do you pay a ransom while usually it was with Bitcoin and that meant you had to turn us dollars or other foreign currencies into Bitcoin. And as economists in the white house, don't seem to understand when there is more money tracing, a limited commodity, the price of the commodity goes up, whether it's gasoline, food, or Bitcoin, and that's exactly what happened.

[00:31:58] Percentage wise, how much of an increase has there been in the value of Bitcoin? Um, uh, let me see here. You see if I can figure this out 7 billion, 750000000% increase. Isn't that something now of course we don't all have these magical glasses that let us look forward to kind of figure it out. Out, but it's based on this peer to peer electronic cash system that was written about by, uh, someone or a group of people that went by the pseudonym of Natasha Nakamoto.

[00:32:42] And there've been a few people over the years who have claimed that they are the person that started it and maybe one of them is, and may be, none of them are who knows, but this was first published, October 31st, 2008. So about a month later is when it started to trade and it is just incredible here.

[00:33:04] Bitcoin was really perceived initially. Threat by government and financial institutions. I think it's still perceived as a threat. My government, they are able to track Bitcoin and other cryptocurrencies in many cases and the way they track it as well. If you have Bitcoin, what good is it? Unless you can use the Bitcoin to either buy something or to traded for us dollars or another hard currency, that's how they're tracking.

[00:33:38] Without getting into a lot of detail here, but it's interesting to look at because the Bitcoin white papers proposing a solution to prevent what they were calling double spending. And when you don't trust a third party necessarily, and that's where we got these logs, if you will, the. Uh, balance sheets that were being used to track everything.

[00:34:06] And then you had the voting, you had to have 50% of these systems that were tracking all of the transactions, agree on a transaction, et cetera. And that's actually been a problem for Bitcoin because of the. Intermediaries, you have to go through or get to approve your transaction. It's a, frankly, a problem that's really slowed down transaction.

[00:34:34] So you can't just go like with a credit card and pay for something that's done. It can take your day or more. Now it's interesting that we're getting close to the ultimate limit of Bitcoin offerings. The blockchains mind blocked number 707,000. Which by the way, offered a mining reward of six and a quarter Bitcoins.

[00:35:01] So think about that. Well, it costs you more to mine, Bitcoins than they're worth. If you're trying to do it in the Northeast. Pretty much anywhere in the United States. So don't just run out and start doing it. My son and I, I don't know, five, eight years ago, something like that, we decided we'd start trying to do some mining and we did, and we didn't find any Bitcoins and it was just cooking some machines.

[00:35:28] And so we said, forget about it. And we gave out on it. It does have a hard cap. Then it's got a ways to go. I said, it's approaching. It is, but there's 21 million Bitcoin is the hard cap and the community that maintains the software and maintains Bitcoin because it is a committed. Has it been modifying the rules as time went around at about how many Bitcoin you get when you're mining something, into solving these problems and, and how the blockchain works and how many honest and dishonest mentions were in the original Bitcoin white paper and how can they reject invalid blocks?

[00:36:18] So there's a lot of technical stuff going on and it's changing. All of the time. And ultimately it's the consensus mechanism that has been slowing it. So when it costs you more to mine, a Bitcoin than you get for it. So let's do a little bit of math here. If we say that how much is a Bitcoin worth right now?

[00:36:42] So we say current value of Bitcoin. I'm typing it in right now. So it's about $57,000. Per Bitcoin. If we say 57,000, uh, here we go. 57,000 times, what did I say? Six and a quarter, right? So $362,000 equivalent is what they, the person who mined this block was paying. That sounds pretty good. Doesn't it? Yeah, it really does.

[00:37:17] It adds up quite, quite quickly. But when you consider that it costs more to mine, a Bitcoin than it costs, then you, then you get to paid for it. 350, $6,000. That's a lot of electricity on a lot of hardware. And because of that, China has. Down Bitcoin mining operations, because it uses so much electricity and in the United States and in some other countries, but here in the U S and in the UK, some of these Bitcoin mining operations have been buying.

[00:37:54] Coal powered power plants, coal fired power plants so that they can produce their own electricity so they can make it worthwhile to mine. So things are going to change. They're going to be changing the rules. As I said, we've got a total of 21 million Bitcoin ultimately. And so far we've only just mined numbers, 707,540.

[00:38:21] So the interchange, the rules, I'm going to keep an eye on this because that's kind of an interesting one. Elon Musk, his quote is Crip. Cryptocurrency is fundamentally aimed at reducing the power of a centralized government. And that by the way, can be one of the main reasons that Bitcoin hasn't been really adopted in the mainstream yet.

[00:38:42] And Ilan has all kinds of tweets. Bitcoin and other cryptocurrencies, he says, Bitcoin is my safe word. Isn't that? Something he's been primarily the guy behind Dodge coin, which is yet another crypto currency, D O G. Coyne D O G E coin doge, I guess, coin. And you can find that online. I think it has new doge even publicly traded while it's certainly traded as a crypto.

[00:39:12] Okay. So doge coin right now is worth 22 cents. It's down from its month, week, and day highs. I'm looking. Here. Yeah. Yeah. So it's gone up and down. It's been worth more. Yeah. A couple of weeks ago. So that's part of the problem with it. If you don't have money that you can absolutely waste, don't buy this stuff and I'm not an investment advisor, but I've never bought any Bitcoin or any other cryptocurrency.

[00:39:46] And the problem is, and from my perspective that it is not real at all. Yeah, you can say, look at this, I could have made 7000000% on that. Well, you could do the same thing almost if you had, instead of buying a brand new Tesla model as, uh, you know, eight years ago, seven years ago, and paying $77,000 for that.

[00:40:11] If you had bought $77,000 worth of Tesla stock, you'd be in the millions of dollars in value. Right? And so we've got the Raven company out there. I don't know if you know these guys or not. I watched a motorcycle show. They're going from the tip of south America all the way on up to San Diego. And they had this reveal and electric truck, which is really quite cool.

[00:40:39] Well, they are public right now. They just won. And they have a market capitalization. In other words, a value of ribbon, which has only made a couple of dozen vehicles. That's it? Total. And they're owned by people who work for the company. Their market capitalization is 50% more. Then most of the major manufacturers out there, it's just crazy how much it is worth and why it's because people are looking at it saying, well, Tesla appreciated 7000000%.

[00:41:19] Ravion's going to do the same. And by the way, they are cool cars. I love the idea behind. Uh, you know, electric vehicles. It's just that we got the cart before the horse who don't have the electricity. We're not making the hard decisions. We're just ripping stuff out. It's absolutely crazy. By the way, they had a 15% drop in the value of their shares on Wednesday.

[00:41:45] Uh, it'll go up. It'll go down. But it's, uh, w it's something we got to test remember? Okay. Cryptocurrency is not it yet of Tesla. Stock is worth something will probably always be worse. Something cryptocurrency is worth something, but tomorrow may be worth zero, and don't go crazy. These market caps of startup companies that have never done anything being worth 50% more than major us auto manufacturer.

[00:42:18] What that's crazy.

[00:42:19] Clothing prices have been going up. In fact, apparel prices were up 4.2% in the last 12 months. That's as of August, we've got cotton going up. There's a whole bunch of things that are going up and a company out there called dress X thinks it has a solution for all of these prices.

[00:42:40] Everything's been going up, I put some gas in my car the other day. I have a, you might know, of course, a 1980 Mercedes and my wife drives a nice little Ford edge, not a particularly big SUV, kind of a guess a mid-size SUV. And I put, I think it was about 15 gallon Zan and it costs me more. 55, $0. I can't believe it.

[00:43:12] We used to have a little diesel little Volkswagen Passat diesel. We would drive around and we were getting pretty close to 60 miles per gallon, around town. And diesel was about a buck, a gallon, and it cost 20 bucks to fill the silly thing up. And we could drive all the way down to New York city and back on.

[00:43:31] $20 worth of diesel one fill up. Okay. Uh, none of that's true anymore, is it? And we're looking at some increases. It's not like the kind of increase we've seen in certain foodstuffs or gasoline or eating oil. Apparel prices are up and there there's a company out there that thinks that maybe they have a bit of a solution for you.

[00:43:56] It's called dress ex I found a video online of a young lady. Who's got a lot of followers, interesting lady. And she was trying them out. She'd tried a different dress or different clothes every day for a month. No, I did not watch all of the video, but I got the basic idea. And the idea is that people are buying digital clothes.

[00:44:25] Now I think of that for a minute. Would you pay for a designer? And maybe you would, maybe you wouldn't pay for designer dress, but you know, already like, and AOC is dress that she wore, you know, the lady of the people, uh, only cost. What, w what is it? $30,000. Per seat for her to go to that banquet. And I think her dress was like five or $6,000.

[00:44:53] Well, you can get a dress just like AOC. That's designed by a high-end fashion designer for somewhere between 40 and $60. Okay, but it's a virtual dress. It's not a real dress, not in the real world. It's interesting what they're doing and trying to do. If you have used some of these online sites like Instagram, they have various types of what they call filters.

[00:45:21] So you can put a filter on you and there's like a makeup filter, for instance, that makes you look like you're all made up, right. That gets rid of all of the blemishes on. In, and there's other filters that do backgrounds and do different things and make you look like you're a kitty cat or whatever.

[00:45:41] They'd all kinds of crazy things. Well, this company called dress ex has now come out with filters that you can use in their app. And they don't work too well right now, but people have been buying these digital close to. Now you don't wear them out. Okay. This is really like the King's new clothes. You might remember that story.

[00:46:06] Right. And if all you have on are your digital clothes, you don't have anything on. However, what it does is if you're using their app and you're moving around, uh, and with their app, Paste these clothes on you. And it's a little funky right now. It's not the best, but you can bet that's exactly where it's going.

[00:46:32] And it reminds me of a blues, Bruce Willis movie. Can't remember the name of it. And, uh, it's I think really bringing up a whole, a whole type of. Dysphoria that I think people are going to have more and more where you're living in this artificial life and that artificial life that you're in now that's called SIRA gets, I was just looking up as we were talking, uh, that artificial life that you're in is so nice.

[00:47:05] You don't want to live. In the real world. And I'm starting to see this now with things like dress X, which you'll find online, address x.com. You can now wear anything you want. You can use the filters that are available generally to change. Parents to change your ethnicity, to change anything you want.

[00:47:28] And if you ever saw Sarah gets, it was a very interesting movie. I liked it. I watched it because I generally like Bruce Willis and Rosa Mon pike, who were the two primary actors in this movie. But in the movie, everybody was just sitting there. And they were in these 3d chairs. And while you're in that chair, you could be anybody anywhere doing anything and literally anyone.

[00:47:57] And so you're sitting in the chair, you can see around you, it looks real, it feels real everything about it is real, at least for the most part, but in reality, And none of it's real. And these people, they, some of them got out of those chairs and while they were out a nasty things happen to them. In fact, it was, he was a cop and they were, uh, investigating some murders of these people who were again, using what they were calling.

[00:48:30] Sarah gets nowadays with what our friends over at face. Or doing, you are going to see it called something else. Uh, Facebook, in case you didn't know Facebook changed its name. Now Facebook, Facebook is still Facebook, but the parent company kind of like Google split kind of off and change the company name, uh, Facebook did the same thing.

[00:48:56] They're calling it. And the idea is to have this meta universe where again, just like in surrogates, nothing is real, just like on dress ex you can wear any fashions you want to, and instead of paying thousands of dollars, you pay tens of dollars, basically. Now I mentioned that their video isn't very good.

[00:49:21] At least not yet over address X, but you can go to dress X. You can take photos of yourself and send them to dress X. They will go ahead and put whatever clothes you want to be. On you it's basically. Yeah, it's Photoshopping, but they do a pretty good job in general. I looked at a whole bunch of them, but it, uh, you know, it, it looked pretty real.

[00:49:48] You don't have to consider the fit. You don't have to worry about how big you are because all of these clothes adjust, infinitely a store. Doesn't have to stock a bunch of them. So we're moving. This whole metaverse idea and these digital clothes, which are really a thing nowadays is vice said, vice.com.

[00:50:12] We're moving more and more to this unreal world and some real unreal fashions too. I'm looking at some of them and it's, it's hard to even describe them. It looks like there's all of these. Things growing all over the clothes that are coming out and just doing all kinds of weird things. So there you go.

[00:50:36] I'm note on fashion. I'm looking right now at a picture that's right in front of the metropolitan museum of art in New York, and a lady is wearing one of the. Digital dresses. Now they tell you what you should be doing. And when you take that picture is aware of skin tight clothes so that they can match the digital close to you a little bit better.

[00:51:01] But, uh, w w we'll see, she's saying that in this project, Tweet at the, in front of the mat, she's saying I just can't wait for the met gala. What it'll look like in 21, 21, because you know what, she's not wrong about this. It's really coined to change. There's some real cool stuff. Go to my website. If you want to see this, you can find it on vice, but I have a link to it.

[00:51:24] Just look for this. Show notes and you'll find it right there. In fact, you're getting even search for on my website because I have everything transcribed. Just look for digital clothes because there are thing now. Hey, I also want to talk a little bit here about. The, uh, the next little article, which is what's happening right now with apple.

[00:51:48] And you've probably heard about these ID cards in Austria right now, they are stopping people randomly and asking for their papers. They want your papers. If you are, have not been, they call it vaccinated. It's not a vaccine. Really. It's still funny to see the CDC change to the definition of vaccine, just so it meets their jab standards.

[00:52:16] But, uh, if you're not vaccinated, there's an immediate, it's about of $3,500 fine that the police officer will issue to you. And of course, there's police everywhere. Just stopping people randomly and asking for their papers. Well, apple is making various us states that have decided they want to use a digital ID card.

[00:52:43] For customer support and also for some of the technology. Now, the initial idea behind this, and Apple's been working on it for a while, is that you can have your driver's license in the iPhone wallet, app, more secure. It's certainly more convenient for most people. Sometimes you might forget your wallet, but most people don't forget their iPhones.

[00:53:10] Yeah. The feature when combined with Apple's biometric security measures really could also cut down on fraud. So we've got about a half a dozen states right now that have signed up with apple and our pain part of the freight for these things. And when they pull you over and ask for your papers, you'll have them right there in your iPhone.

[00:53:32] Isn't that handy stick around. We got more to talk about. Thanks for joining. Today and visit me online. Craig peterson.com. Stick around.

View Details

Is Your Firewall Actually Protecting You?
What Should You Be Doing?

New stats are out this week. So what's the number one vector of attack against us? Our Firewalls. And they're failing.

So, what's going on. And what can you do about it?

[Automated transcript follows]

[00:00:16] And of course, I'm always talking about cyber security, because if you ask me that is one of the biggest problems we have in business.

[00:00:27] Today. Well, yeah, you got to find employees. In fact, uh, it's almost impossible to find them in the cyber security space as well. And it's been hard for years. So I try to keep you up-to-date here. We've got boot camps that are coming up and you are really going to like them. We've been working on some supplemental materials for it.

[00:00:47] And of course these boot camps are always free, so you can join it. You can have your friends come and learn the. Basics. It's not one of these high sell things. Right. I, I got a little letter in the mail this week saying, Hey, you can come and get a free steak dinner. And of course it's kind of like a timeshare, right?

[00:01:09] Jay, you have to listen to the pitch. Yes. Stay over. On us. And you are going to be sitting there for four hours listening to this crazy pitch that's going on. That's not what my bootcamps are. Anybody that's been to. One of them will tell you we work on it. I explain it. You know what you have to do, how you have to do it, the wise, the winds, the wherefores.

[00:01:35] So if you would like to learn more for yourself, Make sure you sign up Craig peterson.com sign up for my newsletter. And when a bootcamp is coming up, I will be sure to tell you about it in the newsletter so that you can attend. And it's important to, to understand that this is yeah. Aimed at business, the, these boot camps, but almost everything businesses have to do or shouldn't be doing the same thing applies to you in your.

[00:02:08] So, if you are a small business person, if you're someone who has some it experience, and you've been assigned to worry about cyber security, this is for you. If you are a very small business and you're kind of the Jack of all trades, and you've got to worry about cybersecurity, this is for you. And I just got.

[00:02:31] This week from someone on my email list who is retired and she was talking about her husband and her, they don't have any kids, no errors. They're trying to protect their financial investments. And of course I responded saying, Hey, I'm not a financial investment advisor, but I can certainly give you some cyber security input, which I did.

[00:02:53] And you can ask your questions as well. I'm more than glad to hear them. And you probably, if you've sent them in, you know, I always answer them now. My big man, a few days might take me a week, but I will get around to it. And I try and respond to the emails. Sometimes I answered here on the radio show or on my podcast, but usually it's via email me.

[00:03:17] At Craig peterson.com. And of course, that's also on my website, Craig peterson.com. And that's also my name Craig Peters on.com. So let's get into the firewall thing. When you have a network, you are connecting that network to your computers, maybe. To your security cameras, to your printers that you have, maybe there's a lock system.

[00:03:44] Maybe there's more, all of this stuff is interconnected and it's all rather well and good. You can have a whole lot of fun with it, but it is not as particularly good if you can't get out to the internet. So what do we do? We hook our network, whether it's home or if it's business to the internet. Now, you know, all of this stuff so far, right?

[00:04:06] You're following me. The internet is actually inter connected networks. In case you didn't know, there are now millions of networks that are connected on the internet. There are core networks out there. We were my company like number 10,000. I think it was, uh, a S an R a S number autonomous system. So we were fairly early on.

[00:04:32] And of course, as you know, I've been on the internet in various forums since the early 1980s and helping to develop the protocols, but it is important to remember it is an interconnected network of networks. You might ask why? Well, the bottom line is you aren't connecting your network with other networks that have malicious software on them.

[00:04:58] Maybe they're just poorly configured. Maybe they're causing a denial of service attack effectively because there's so badly configured. But whatever the case may be, you are still exposed. If you look at the traffic that's coming to your router. So your router is sitting at the edge of your network connected to your internet service provider.

[00:05:19] So it might be Comcast or Verizon or a whole slew of others. But your network is connected via a router. Then the router knows how do I get my data from the input to the output or from the output to the input, if you will upstream and downstream data, that's what the router is for. And if you look at the data on your router and most of us can't, but if you were able to, what you will see is hundreds of thousands of internet packets coming to, and from your.

[00:05:55] Router your endpoint every day. Usually these are bad guys doing what are called scans. They do port scans. They're primarily looking for services. So what do you, do you have a firewall now in many cases, you'll get a device from your Janette service provider that has a router built in and has a firewall built in, and it has wifi.

[00:06:19] All of this stuff, all built in together makes life all nice and warm and fuzzy and Catalina, doesn't it. But in reality, it's not necessarily a good thing to have it all in one, because you're definitely not going to get the best of breed and router or firewall or wifi, but that's a different story. What is that firewall for that router?

[00:06:41] Of course, it's getting all this internet traffic and anything that's on the internet that is. I'm trying to get to you is going to go through the. And anything that you are trying to send up to the internet, like for instance, to try and get a web page or something is also going to go up through that router.

[00:07:02] So how do you protect yourself time? Was that there wasn't really much of a way to protect yourself. And frankly, there weren't a lot of reasons. To try and protect yourself. And the internet was just this wonderful open thing, lots of fun and played around a lot. Back in the early nineties, it was, it was just a joy in the late eighties to, to be connected up to the internet and then bad guys started doing bad things.

[00:07:30] We took the concept of what you have in an automobile and applied it to the. If you're driving your car, your in the passenger compartment and that passenger compartment is hopefully warm in the winter and cool in the summertime. And you are protected from that big mean nasty engine that's in front of you, or if you're driving an electric car from those mean nasty batteries that are probably below you in that car and what's between you and the.

[00:08:04] Of course a firewall. And the idea is to keep the nastiness of that engine, all of the heat, the oil, the grime, the wind, everything else is associated with that engine. Keep that away from you so that you can now drive that car just comfortably in that controlled climate of the passenger compartment, that concept was then applied to the inter.

[00:08:30] And in fact, I designed and implemented one of the first firewalls ever made way back when and the firewall in the internet Partland is very similar to the car in the car. You have some protrusions through that fire. Don't you, you you've got a steering wheel. How does that get up to the front of the car?

[00:08:53] Well, it goes through the firewall and around that steering wheel, of course there's some EBDM, some rubber type stuff that helps stop anything from coming through right next to that steering column. Same, thing's true with the brake pedal and the gas pedal. At least it used to be. Nowadays, it's so much of this as drive by wire, that the only thing going through the firewall is a wire and there's no mechanical linkage.

[00:09:24] Unlike my car, which is a 1980 Mercedes-Benz diesel. Where yes, indeed. Direct linkages to everything. So the firewall in the cars protecting you from the nastiness in the engine compartment and the firewall, when it comes to your internet is doing something very similar. Think about your house for a minute, you have a house with doors and windows.

[00:09:53] I would hope. And a chimney and maybe a couple of other protrusions that are going outside of the house. Well, you have some similar problems and when it comes to the internet and when it comes to the firewall, With your house, sir. Sure. You could post a guard out front, a whole series of them. You've got a dozen guards out front and they are all guarding that front door.

[00:10:19] But if no, one's watching the back door, if no one's paying attention to the windows, there's still ways for the bad guys to get in. And that's what we're going to talk about. How does the internet firewall tie into this analogy of cars and the analogy of your home? Because it's a very important point when you get right down to it.

[00:10:44] We need to understand this because the number one tactic reported this week by MITRE and Cisco is exploitation of public facing application. So I'm going to explain what that is. What's your firewall can do for you and what you should do for your firewall. A stick around. We've got a lot more coming up.

[00:11:09] I want to invite you to go. Of course, right now, online to Craig peterson.com. Once you're there, just sign up for mind's newsletter. Simple Craig peterson.com.

[00:11:25] This week, we found out what the top five tactics are that are most frequently being used by bad guys to attack us. This is done by MITRE and Cisco systems. Number one, public facing applications. What does that mean?

[00:11:42] We've been talking about this report, but really what we've been delving into is how data flows on your network, whether it's a home network or maybe it's a business network, how does this whole mess work?

[00:11:58] And when miters talks about the biggest problem here, 91% of the time being what's called an exploit of a public facing application, what does that mean? We went through the basics of a firewall and a router. So all of the data coming from the internet, coming into the router, then handed to the firewall.

[00:12:24] Any data going out, goes into the firewall. And then the. So that's the pretty simplistic version. And of course the firewall on your network does a similar thing to the firewall in your car. It stops the bad stuff, at least it's supposed to, but your home and your car both have different ways of getting.

[00:12:48] Past the firewall in the house. It's your doors and your windows in the car. Of course, it's where the steering column goes through where the brake pedal and the gas pedal go through the clutch, all of that stuff that perch, um, permeates, it goes through. That firewall. And of course, you've probably, if you're been around for awhile, you've had leaks coming through your firewall and, uh, you know, how poorest they can be sometimes.

[00:13:18] Well, we have the same type of thing on our internet firewalls. Every home has doors and what we call the doors in on the internet is similar to what they call them. On the, in the Navy, on the water, the reports. So think about a porthole in a boat, or think about a, a door, a port, which is the French word for door.

[00:13:45] What happens on the internet? For instance, if you're trying to connect to Craig peterson.com, you are going to connect to a specific port on my server. So the address typically, uh, is going to be resolved by DNS. And then once it gets to the server, you can connect to port 4 43. You might try and connect to port 80, but I'll do a redirect, but that's neither here nor there.

[00:14:12] So you're going to connect to that port four 40. So my firewall has to say, Hey, if somebody is coming in and wants to get to port 4 43, which is called a well-known port, that's the port that all web server. Listen on. So if someone's trying to get to my port, my web server on port 4 43, let them in. But if someone's trying to get to another port, don't let them in.

[00:14:48] Now there's multiple ways to respond or not respond. I can talk about that right now. That'd be for deep dive workshop, but the idea is. Each application that you are connecting to, or that your providing has. Part of the problem that we've been seen. And this is a very big problem is that people are not changing the administrative passwords on their machines.

[00:15:20] So administrative passwords mean things like admin for the username and admin for the password on your firewall. So. Your firewall, if you have what's called when admin enabled, what that means is someone on the wide area network. In other words, The internet, someone on the internet or on the, when can connect to your firewall and control it.

[00:15:51] This is, as you can imagine, a very big thing, and it is something that we cover in one of our workshops, explained it all and all of the details and what to do, but most businesses and most people have not properly configured their firewalls. When we're talking about number one, problem, 91% of the time being an exploit against public facing applications.

[00:16:18] What that means is they could very well just be trying to connect to the administrative interface on your firewall. Unfortunately, they will often offer. Change the software on your firewall. So they won't just reconfigure. They'll just change it entirely. And they'll do all kinds of evil things. Again, we're not going to get into all of that and what to look for and what can happen.

[00:16:44] But number one thing everybody's got to do, and I saw some stats this week as well, that made me want to bring the. Most people and most businesses about two thirds have not changed the default passwords on the hardware that they have. Now it can understand sometimes the kids confusing. No question about.

[00:17:07] But if you don't change the password on something that's public facing, in other words, something that can be reached from the internet or again, the wide area network. I know there's a lot of terms for this, but something that someone else can get at from outside your network. And it's the default password like admin admin, you could be in a whole lot of.

[00:17:35] So check that right now, please double check that triple check that because even if you have a router from a big internet service provider, again, like the Comcast Verizon's, et cetera of the world, they will almost always have it set up. So you can change that administrative password and Jewish. Now I, again, for clients, I have some different advice than I have for, for just regular users, but make sure you change that.

[00:18:09] And here's the second part of the problem. What happens if you have a business and let's say you're not hosting your own website, like I've been doing for a couple of decades and how three 30 years, I guess now. Um, and so you've got your website hosted at some. Web height site, hosting place, you know, Gator or one eye and one eye and one or GoDaddy or whatever.

[00:18:35] Okay. So, okay. That's fine. So let's not inside our network. Uh, w we don't worry about the security because that's the vendor's problem. Now we're talking about, okay, what happens. My users who need to work from home. This gets to be a very big problem for so many people, because work from home is important.

[00:19:00] So what are you going to do? Well, basically in most cases, unfortunately, businesses are just exposing an application to the internet. So they might, they might. Terribly configured networks, where there is a direct connection that goes right to the files. So you connect to a port on their firewall and it immediately redirects it internally.

[00:19:30] Remaps it to the file server. And some people are really, really clever. Alright. Or so they think, because what they'll do is they'll say, okay, well, you know, that, that normal port number. Okay. So I'm going to move. Port number. So you're going to connect to port 17, 17 on my firewall, and it's going to connect you to the file share on my file server so that people from home can just connect to port 17, 17, and ta-da, there are all the files and yeah, we're, we're using passwords, so it'll be okay.

[00:20:06] It'll be fine. Um, but, uh, guess what it isn't for a few. Different reasons are we're going to be talking about those here in just a minute. Yeah, I want to encourage you right now. Take a minute. Go online. Craig peterson.com. You'll find lots of information there. I've got 3,500 articles, all searchable, Craig peterson.com.

[00:20:32] But more importantly, make sure you sign up for my newsletter. Craig peterson.com/subscribe. So that you can keep up to date on everything that is important in all of our lives.

[00:20:51] We're talking about firewalls at home at the office, what it means to have public facing services, really applications, people working from home. How can you make it easy for them and hard for the bad guy?

[00:21:15] Many businesses had to quickly change the way their computers were set up because of course the lockdown and people working from home.

[00:21:26] And, um, unfortunately. Many mistakes were made. And some of this, in fact, I'm going to talk a lot of this problem up to these managed services providers break, fix shops. My, my fellow information technology contractors, if you will, because they didn't know any. Most of these people have been computer people, their whole lives, right.

[00:21:55] They played with PCs when they were young and they might've taken a course or two and wow. MCSC certified. Believe me, this is not something that a straight up MCSC or. And frankly, most of the it certifications can really understand or really handle the cybersecurity can be done, but there's so many things they overlook just like what I was just talking about, exposing a file server directly to the internet.

[00:22:29] I mentioned, okay. While they thought it was going to be safe because there's a username and password, but there's a couple of huge problems here. Problem. Number one. When you're exposing a service to the internet, like for instance, the files server, you are exposing software that may have exploitable, but.

[00:22:54] And again, going back to those stats from earlier this week, more than half of all of the systems that are out there are not patched to date. It's so bad that president Biden just ordered the federal government agencies to apply patches some as old as three years. So what happens now? Well, the bad guy scan, and guess what they found.

[00:23:23] Port that you thought was just so clever because it wasn't the standard port number for that service. Maybe it's SMB or CIFS or something else. And, uh, they found it because they scan, they look, they see what the response is that tells them what type of a server sitting there. And then they try, well, let me see.

[00:23:45] There's the zero day exploits, but why bother with those? Let's just start with the good old standard ones. And unfortunately, because so many machines are not patched up at all, let alone properly patched up. You, they end up getting into the machine. It's really that simple, just because it's not patched up.

[00:24:08] How does that sound? Huh? Yeah, it's just plain, not patched up. It's not available for anyone to be able to use anybody to be able to access. Right. It there it's not restricted. So the passwords don't matter if you haven't patched your systems. And then the second problem is that. Are brute force attacks against so many servers out there.

[00:24:36] And most of the time, what we're talking about is Microsoft, but, you know, there's the share of bugs kind of goes around, but Microsoft and really, they get nailed a lot more than most beet, mainly because they're probably the number one out there that's in use today, not in the server community, certainly, but certainly also in the.

[00:24:59] It's been, you know, small businesses, that's all they know. So they just run a Microsoft server and more and more, you kind of have to run it because I, I get it. You know, there's so many apps that depend on the various functions that are provided by the active directory server at Microsoft and stuff. So we, we do that for our customers as well.

[00:25:19] So are you starting to see why the brute force against a server will often get them in and the smarter guys figure out what the business is? And then they go to the dark web and they look up those business emails. Addresses that they have that have been stolen along with the passwords that were used.

[00:25:43] That's why we keep saying, use a different password on every site because that stolen password now. Is going to be tried against your service, your, your file server. That might be there. You might be trying to have a VPN service that the people are VPN in from home. You might have remote desktop, which has been.

[00:26:08] Abject failure when it comes to cybersecurity, it's just been absolutely terrible. So you might have any of those types of things. And if they've got your email address and they've got the passwords you've used on other sites, which they've stolen and they try them, are they going to work? Odds are yes, because most people, I got another set of stats this week.

[00:26:36] Most people use the same password for every site out there or every type of site. So they might get a second, most common is they use one password for all of their social media sites. They use another one for all of their banking sites. So we cover this in some depth in our bootcamp so that you understand how to do the whole password thing.

[00:27:03] And what I recommend is a piece of software called one password. I don't recommend that you just use one password for everything. I was misunderstood by someone the other day. You mean just w w I use one password for everything. Yeah, you do. And then I talked to them a little bit more because I thought that was an odd question.

[00:27:24] And it turned out, he was thinking, you just have the one password, like, like, you know, P at sign SSW, zero RD. Right? You use that everywhere. No, there's a piece of software go to one password.com. That's what I recommend as a password manager. And I show you how to use that and how to use it effectively in my bootcamp.

[00:27:48] Absolutely free. Just like the radio is free. I'm trying to get the information out to as many people as possible, but you gotta be on my list. Craig peterson.com. Make sure you go there. So I've explained the basics here of what happens. We have a door open or windows, open ports on our servers, on our firewalls at home.

[00:28:15] And at work. So the thing to do, particularly if you're a business, but even if your home user is check that firewall configuration. And let me tell you something that probably won't come as a surprise. Most of these internet server. The providers are in the business to make as much money as possible. And cybersecurity is very much secondary.

[00:28:40] They know they talk about it and they talk about software defined networks and things that sound really cool. But in reality, what they give you is. Configured very well and is going to expose you. So make sure you go in, they will set it up. For instance, if they're providing you with television services, they'll set it up so that they can just bypass your firewall and get into the cable box that they installed in your house.

[00:29:09] Yeah. Obviously that's not something they should be doing because now they are opening you up to attack. What happens when there's a cybersecurity problem with the cable box? We've seen this problem too, with television vendors where they poke a hole out through your firewall so that they can then gather statistics and do firmer updates and everything else.

[00:29:34] It's insane. It really is. These vendors are not thinking about you. They're not thinking about the consequences. It is a very, very sad situation, but now you know what to do and how to do it. Okay. I explained today, firewalls. I explained router. I explained ports, which should be open, which should not be open.

[00:29:58] And the reasons why I even mentioned passwords, I get into that in a lot of detail in my bootcamp, Craig peterson.com to get on that waiting list. Craig peterson.com, just subscribe and you'll be kept up to date.

[00:30:14] There has been a whole lot of discussion lately about Metta. You might've heard. In fact, you probably did that. Facebook changed its name to Metta and they're aiming for something called the metaverse. So what is it exactly and what's it going to do for or to you?

[00:30:32] The metaverse oh my gosh. I had a great discussion this week about the metaverse this came out in, um, and originally anyways, in this novel called the what was it now?

[00:30:47] A snow crash. That's what it was 1992, Neil. Stevenson or Steffenson. I'm not sure how he pronounces it, but in this book, which was a cyberpunk model and I've, I've always thought cyber punk was cool. Uh, is the metal versus an imaginary place that's made available to the public over the world wide fiber optics network.

[00:31:13] And it's projected onto virtual reality goggles sound familiar yet. And in the. You can build a buildings park signs as well as things that do not exist. In reality, such as vast hovering overhead light show, special neighborhoods were three where the rules of three-dimensional spacetime are ignored and free combat zones where people can go hunt and kill each other.

[00:31:42] Great article about this in ARS Technica this week. And, uh, that was a little quote from the book and from the article. Phenomenal idea. Well, if you have read or seen the movie ready player one, and I have seen the movie, but a friend of mine this week said the book is so much better. So I'm going to have to read that book, ready player one.

[00:32:06] But in it, you have these people living in. Dystopian future where everything is badly worn down, the mega cities, people building on top of each other and they get their entertainment and relaxation and even make money in. Prison time by being inside this virtual world, they can go anywhere, do anything and play games, or just have fun.

[00:32:39] One of the vendors that we work with at my company mainstream has this kind of a virtual reality thing for. I kind of a summit, so people can go and watch this presentation and I think it's stupid, but they, you walk in. And it's, uh, this is just on a screen. They're not using like those Oculus 3d graph glasses, but you walk into an auditorium.

[00:33:13] So you've got to make your little avatar walked on. Dun dun, dun dun, dun, dun, dun, dun, dun, and then go to an empty seat. And then you have to make your avatar sit down. Right? I, I have never played a game like this. I never played second life. Never any of that sort of thing. It was kind of crazy to me. And then I was doing a presentation, so I had to go Dundon then, then, then the, up onto the rostrum there and stand behind the podium and, and then put my slides up on this virtual screen.

[00:33:49] It was ridiculous. I have a full television production studio here in my, in my lab. Right. And that's, this is where I do the radio show. This is where I do my television appearances. This is where I do pretty much everything. Right. And so what I can do is I can split screen with my face, with the desktop.

[00:34:12] You can see my desktop, I can draw on it, circle things, highlight things or whatever I want to do. Right. But no, no, no, no. I was in their virtual reality. And so all I could do is. I have the slides come up. In fact, I had prepared beforehand, pre-taped it? A, the whole presentation, but I couldn't play that video.

[00:34:37] No, no, no. I had to show a slide deck, you know, death by PowerPoint. I'm sure you've been there before. It's very, very frustrating in case you can tell for me, well, we've seen this type of thing. I mentioned some of the things like that. I'm in second life. I'm sure you've heard of that before. Sims is another one you've probably heard of before.

[00:35:01] These types of semi metaverses have been around a very long time. And, and in fact, all the way on back to the nineties is Habbo hotel. G I don't know if you ever heard of that thing, but it was non-line gaming and social space. I helped to develop one for a client of mine back in the early nineties.

[00:35:23] Didn't really go very far. I think it was ahead of its time. It's it's interesting right now, enter. Mark Zuckerberg. Do you remember a few years ago, mark Zuckerberg had a presentation. He was going to make this huge announcement, right? They bought Oculus. What was it? It was like crazy amount of money. And then he came in the back of the hall.

[00:35:50] And nobody noticed he walked all the way up to the front and nobody even saw him because they were all wearing these 3d glasses. And of course, today they are huge. They are awkward and they don't look that great, the pictures inside, but the idea is you can move your head around and the figures move as your head moves, almost like you're in the real world.

[00:36:13] And that's kind of cool and people thought it was kind of cool and they didn't see Zuckerberg because they all had these things on. And the inside was playing a little presentation about what Facebook was going to do with Oculus. Well, they just killed off the Oculus name anyways here a couple of weeks ago, over at Facebook about the same time that got rid of the Facebook name and went to meta.

[00:36:39] The Facebook product is so-called Facebook and it appears what they are going to be doing is taking the concept of a metaverse much, much further than anyone has ever taken it before. They're planning on there's speculation here. Okay. So, you know, don't obviously I don't get invested. I don't give investment advice, investment advice.

[00:37:10] Um, but I do talk about technology and, uh, I've been usually five to 10 years. I had so take that as well. They as the grain of salt, but I think what they're planning on doing is Facebook wants to become the foundation for Mehta versus think about things like world of Warcraft, where you've got the. Gain that people are playing.

[00:37:39] And it's a virtual reality, basically, right? It might be two D, but some of it's moving into the three-dimensional world. Other games like Minecraft and roadblocks, they have some pretty simple building blocks that people can use network effects and play your creativity to make your little world and the ability.

[00:38:04] To exchange and or sell your virtual property. That's where I think Mr. Zuckerberg is getting really interested now because if they can build the platform that everybody else the wants to have a virtual world builds their virtual world on top of. Man, do they have a moneymaker? Now? People like me, we're going to look at this and just poo poo it.

[00:38:35] I I'm sure I'm absolutely sure, because it will be another 20 years before you really think it's. You know, some of these scifi shows have talked about it. You know, you can feel someone touching you, et cetera, et cetera. Yeah. That's going to be very crude for a very long time. And now CGI is pretty good.

[00:38:57] Yeah. You watch the movies. CGI is great, but that takes weeks worth of rendering time on huge farms, clusters of servers. So it's going to take quite a while. Looking at the normal advancement of technology before this really becomes real. Now there have also been us court cases over who owns what in bad happened with Eve online.

[00:39:28] Second life where disagreements over player ownership of the virtual land created by the publisher, which was Linden labs. When. And I've also mentioned in the past how our friends over at the IRS have tried to tax some of the land that you own inside these virtual worlds. So ownership, do you really own it?

[00:39:55] Does it really exist? What would non fungible tokens maybe it does. And these non fungible tokens are. Basically just a check, some verification, I'm really oversimplifying of some sort of a digital something rather lately. And initially it was mostly pictures. And so you had a picture of something and you owned that and you could prove it because of the blockchain behind it.

[00:40:27] But I think this is where he's really interested because if he can build the base platform. Let the developers come up with the rules of what's it called it a game and come up with what the properties look like and how people can trade them and sell them and what kind of upgrades they can get. Right.

[00:40:48] So let's nothing Zuckerberg has to worry about. Uh, Metta or Zuckerberg then worries about, okay. So how do we collect money for these? How do we check with the transactions? Uh, somebody wants to buy those sort of Damocles. How does that transaction work and how do we Facebook Metta? How do we get a slice of the act?

[00:41:16] You got to believe that that's where things are going. And if they have the ability to make this base platform and be able to take characters from one part of a developer to another part of the developer, you could have worlds where Gandalf might be fighting bugs bunny. Right? Interesting. Interesting and Warner brothers, all these movie companies would probably be coming out with complete virtual reality.

[00:41:49] So when you're watching James Bond, you're not just watching James Bond, you can look around, you can see what's happening. People sneaking up behind. And ultimately you could be James Bond, but that's decades away. I think a good 20 years. All right, everybody. Thanks for sticking around here. Make sure you go online.

[00:42:11] Craig peterson.com/subscribe. Get my weekly newsletter. Find out about these free boot camps and other things that I have. So we can keep you up to date and keep you safe.

[00:42:25] We already talked about Metta and their name, change the metaverse, but there's something else. Facebook did this last week that surprised a lot of users, something they started in 2010, but has been controversial ever since.

[00:42:41] We had a pretty big announcement, frankly, this last week from our friends over at Facebook, not the one where they change their name and the.

[00:42:51] Basically trying to create a metaverse platform. That's going to be the one platform that rules the world. Although those are my words by the way. But Facebook has announced plans now to shut down a decade old. Facial recognition system this month. We'll see what they do with this. If they follow through entirely, but they're planning on deleting over 1 billion faces that they have already gone through and analyzed.

[00:43:26] You might remember. In 2010, Facebook had a brand new feature. It started announcing, Hey, did you know that so-and-so just posted your picture? Is this you? Is this your friend, is this sewn? So do you remember all of those questions? If you're a Facebook user back in the day? Well, they were automatically identifying people who appeared in digital photos and suggested that users or users tagged them with a click we're going to get to and admitted here.

[00:43:57] Uh, and of course that then linked the Facebook account for. The picture that you tagged to the images and let that person know. And of course Facebook's ultimate goal is to get you to stay on long, as long online, as long as possible. Because if you're online, you are going to be looking at ads that are aimed primarily at.

[00:44:18] Well, facial recognition has been a problem. We've seen it a worldwide. I just read through a restatement from the electronic frontier foundation, talking about facial recognition and the problems with it, how some people have been arrested based on facial recognition and held for over a day. We'll have cases where the police use to kind of a crummy photograph of them from a surveillance video sometimes also from a police car, in some areas, the police cars are continually taking video and uploading it to the internet, looking for things like license plates, to see if a car.

[00:45:00] Parking ticket that hasn't been paid or it hasn't paid us registration all the way through looking at faces, who is this person? And some in law enforcement have kind of thought it would be great to have kind of like Robocop. You remember Robocop, not the ed 2 0 9. There was also in that movie. That's also very scary, but when they look at someone who's on a street at autonomous.

[00:45:24] Pops up in their glasses, who it is, any criminal record, if there any sort of a threat to et cetera. And I can understand that from the policemen standpoint. And I interviewed out at the consumer electronic show, a manufacturer of. That technology, it was kind of big and bulky at the time. This was probably about six or eight years ago, but nowadays you're talking about something that's kind of Google glass size, although that's kind of gone by the wayside too.

[00:45:54] There are others that are out there that you. Facial recognition. Technology has really advanced in its ability to identify people, but you still get false positives and false negatives. And that's where part of the problem becomes from they have been taking and they been private companies primarily, but also some government agencies they've been taking pictures from.

[00:46:21] They can find them. We've talked about Clearview AI before this is a company that literally stole pitchers, that it could get off the internet. They scan through Facebook, Instagram, everywhere. They could find faces and they tied it all back in. They did facial recognition. On all of those photos that they had taken and then sold the data to law enforcement agencies.

[00:46:49] There's an app you can get from Clearview AI. That runs on your smartphone and you can take a picture of someone in the street, clear view. AI will run that face through their database and we'll tell you who it is, what their, what their background is, where their LinkedIn page is their Facebook page, wherever it found them online.

[00:47:13] Basically what they've been doing. Now Clearview had a problem here this last couple of weeks because the Australian government ordered them to delete all facial recognition, data belonging, to anyone that lives. In Australia. Now that's going to be a bit of a problem for clear view, because it's hard to identify exactly where people live just based on a photograph.

[00:47:40] And the United Kingdom is also considering doing this exact same thing. Now, clear views have been sued. They violated the terms of service from Facebook and some of these other sites that I mentioned, but they did it anyway. And clear view was. To destroy all the facial images and facial templates they had retrieved about any Australian.

[00:48:08] I think that's probably a pretty good idea. I don't like the idea of this data being out there. Well, if your password is stolen and we're going to be talking about that in our bootcamp, coming up here in a couple of weeks about how to determine if your username or your password is stolen. But, uh, and of course, if you want to get that.

[00:48:29] Bootcamp and go to that. There's no charge for it, but you have to know about it. And the only way is to sign up. You have to make sure you're on my email list@craigpeterson.com. But what happens when your email address is stolen or your password, or both are stolen from a web. Oh, typically they end up on the dark web.

[00:48:50] They sell personal identification for very little money. In some cases it's only a few dollars per thousand people's identities. It is absolutely crazy. So the bad guys are looking for that information, but you can change your password. You can change your email address, but if your facial information is stolen, Can't change your face.

[00:49:18] If your eye print is stolen, you can't change your eye. I have a friend who's pretty excited because he got to go right through the security at the airport ever so quickly. Cause all they had to do was scan his eyeball. Well, that data is valuable data because it cannot be changed. And it can, in some cases be replicated.

[00:49:41] In fact, the department of Homeland security and the transportation safety administration had the database of face print stolen from them in 2019. To about 200,000 people's identities were stolen, the face sprints. It's just absolutely crazy. And this was some, a vendor of us customs and border protection.

[00:50:05] And it, it, you can't write down to it. I read the detailed report on it just now. And the report that came out of the federal government said, well, it went to a contractor who. Took the data, all of the face prints off site over to their own site. And it wasn't encrypted when they took it over there. But it does mention that it was taken from an un-encrypted system at customs and border protection.

[00:50:34] So wait a minute. Now you're blaming the contractor that you hired because it wasn't encrypted and yet you didn't encrypt it yourself either. I, you know, I guess that kind of goes around, but they want to. They want your biometric information just as much as they want anything else. Think about your phones.

[00:50:53] Nowadays, apple has done a very good job with the biometrics and the fingerprints and making sure that that information is only ever stored on the phone. It never goes to apple, never leaves the phone it's in what apple calls, the secure long term. And if you mess with it at all, it destroys itself, which is part of the problem with replacing a cracked screen yourself on an iPhone, because you're going to disturb that secure enclave and the phone will no longer work.

[00:51:24] That is not true when it comes to many other devices, including most of your Android phones that are out there. It is. So if the bad guys have. Your face print, they, and they can create 3d models that can and do in fact, go ahead and fool it into letting you in that that's information they want. So why are we allowing these companies to like clear view AI?

[00:51:52] And others to buy our driver's license photos to the federal government, to also by the way, by our driver's license photos, by them from other sites and also our passport information. It's getting kind of scary, especially when you look into. China has a social credit system. And the Biden administration has made rumblings about the same here in the U S but in China, what they're doing is they have cameras all over the place and your faces.

[00:52:27] And they can identify you. So if you jaywalk, they take so many points off of your social credit. If you don't do something that they want you to do or be somewhere, they want you to be, you lose credits again, and you can gain them as well by doing various things that the government wants you to do. And.

[00:52:49] And ultimately, if you don't have enough social credit, you can't even get on a train to get to work. But the real bad part are the users. This is a minority in China and China's authorities are using. Us facial recognition, technology and artificial intelligence technology. Hey, thanks Google for moving your artificial intelligence lab to China in order to control and track the users.

[00:53:19] Absolutely amazing in the United States law enforcement is using this type of software to aid policing, and we've already seen problems of overreach and mistaken IRS. So Facebook to you're leading a billion of these frameworks. If you will, of people's faces biometrics. Good for them. Hopefully this will continue a tread elsewhere.

[00:53:46] Well, we've talked a little bit today about firewalls, what they do, how your network is set up. If you miss that, make sure you catch up online. My podcast@craigpeterson.com, but there's a whole new term out there that is changing security.

[00:54:03] It's difficult to set up a secure network.

[00:54:07] Let's just say mostly secure because if there's a power plug going into it, there's probably a security issue, but it's difficult to do that. And historically, what we've done is we've segmented the networks. So we have various devices that. Maybe be a little more harmful and on one network, other devices at a different level of security and many businesses that we've worked with, we have five different networks each with its own level of secure.

[00:54:38] And in order to get from one part of the network, for instance, let's say you're an accounting and you want to get to the accounting file server. We make sure your machine is allowed access at the network level. And then obviously on top of that, you've got usernames and passwords. Maybe you've got multifactor authentication or something else.

[00:54:59] I'll make sense, doesn't it? Well, the new move today is to kind of move away from that somewhat. And instead of having a machine or a network have firewall rules to get to a different network or different machine within an organization. There's something called zero trust. So again, think of it. You've, you've got a network that just has salespeople on it.

[00:55:25] You have another network that might have just your accounting people. Another network has your administrative people and other network has your software developers, et cetera. So all of these networks are separate from each other and they're all firewalled from each other. So that only for instance, at county people can get to the accounting server.

[00:55:44] Okay, et cetera. Right? The sales guys can enter the sales data and the programmers can get at their programs. And maybe the servers that are running their virtual machines are doing testing on what was zero trust. It is substantially different. What they're doing with zero trust is assuming that you always have to be authentic.

[00:56:11] So instead of traditional security, where, where you're coming from helps to determine your level of access, you are assuming that basically no units of trust. So I don't care where you're coming from. If you are on a machine in the accounting department, We want to verify a lot of other information before we grant you access.

[00:56:38] So that information probably does include what network you're on. Probably does include the machine you're on, but it's going to all. You as a user. So you're going to have a username. You're going to have an ID. You're going to have a multi-factor authentication. And then we're going to know specifically what your job is and what you need to have specific access.

[00:57:04] Because this follows the overall principle of least privilege to get your job done. Now you might've thought in the past that, oh my gosh, these firewalls, they're just so annoying. It's just so difficult to be able to do anything right. Well, zero trust is really going to get your attention. If that's what you've been saying.

[00:57:23] But here's an example of the traditional security approach. If you're in the office, you get access to the full network. Cause that's pretty common, right? That's not what we've been doing, but that's pretty common where we have been kind of working in the middle between zero trust and this traditional you're in the office.

[00:57:41] So you can potentially get it. Everything that's on the off. And if you're at home while all you have to do is access a specific portal, or as I've explained before, well, you are just connecting to an IP address in a hidden port, which won't remain hidden for. So maybe in a traditional security approach, the bouncer checks your ID.

[00:58:08] You can go anywhere inside this club and it's multi floor, right. But in a zero trust approach, getting into the club, having that bouncer look at your ID is only the first check, the bartender or the waiter. They also have to check your ID before you could be served. No matter where you are in the club and that's kind of how they do it right now, though, they'll make a mark on your hand or they'll stamp it.

[00:58:35] And now they know, okay, this person cannot get a drink for instance. So think of it that way, where every resource that's available inside the business independently checks whether or not you should have access to. This is the next level of security. It's something that most businesses are starting to move towards.

[00:58:57] I'm talking about the bigger guys, the guys that have had to deal with cybersecurity for awhile, not just the people who have a small business, most small businesses have that flat network that. Again about right. The traditional security approach of all you're in the office. So yeah, you can get at anything.

[00:59:15] It doesn't matter. And then you, you have the sales guys walking out with your client list and who knows what else is going on? Think of Ferris, Bueller, where he was updating his grades and miss days at high school, from his home computer. And you've got an idea of why you might want to secure. You are network internally because of, again, those internal threats.

[00:59:40] So keep an eye out for it. If you're looking to replace your network, obviously this is something that we've had a lot of experience with. Cisco is probably the best one out there for this, but there are a few other vendors that are pretty good. If you want to drop me an email, I'll put together a list of some of the top tier zero.

[01:00:02] Providers so that you can look at those. I don't have one right now, but I'd be glad to just email me M e@craigpeterson.com. We can point you in the right direction, but if you have an it person or department, or whether you outsource it to an MSP, a managed services provider, make sure you have the discussion with them about zero.

[01:00:28] Now, when I'm looking at security, I'm concerned about a bunch of things. So let me tell you something that Karen and I have been working on the last, oh man, few weeks. I mentioned the boot camp earlier in the show today. And one of the things that we're going to do for those people that attend the bootcamp is I think incredible.

[01:00:49] This has taken Karen so much time to dig up. Once she's done is she's worked with me to figure out what are the things that you need to keep tabs on. Now, again, this is aimed primarily at businesses, but let me tell you, this is going to be great for home users as well. And we've put together this list of what you should be doing.

[01:01:15] About cybersecurity every week. And in fact, a couple of things that are daily, but every week, every month, every quarter, every six months and every year, it's a full checklist. So you can take this and sit down with it and, you know, okay. So I have to do these things this week and this isn't. Response to anything in particular, it does meet most requirements, but frankly, it's something that every business should be doing when it comes to the cybersecurity.

[01:01:53] It includes things like passwords. Are they being done? Right? Did you do some training with your employees on fishing or a few other topics all the way on down to make sure you got some canned air and blew out the fan? In your workstations, you'd be amazed at how dirty they get. And he is the enemy of computers that makes them just fail much, much faster than, than 82, same thing with server.

[01:02:22] So it is everything. It is a lot of pages and it is just check she'd made it nice and big. Right. So even I can read it. But it's little check marks that you can mark on doing while you're going through it. So we're doing some more work on that. She's got the first couple of iterations done. We're going to do a couple more, make sure it is completely what you would need in order to help keep your cyber security in.

[01:02:50] But the only way you're going to get it is if you are in the BR the bootcamp absolutely free. So it was this list, or of course you won't find out unless you are on my email list. Craig Peterson.com/subscribe.

[01:03:06] One of the questions I get asked pretty frequently has to do with artificial intelligence and robots. Where are we going? What are we going to see first? What is the technology that's first going to get into our businesses and our homes.

[01:03:22] Artificial intelligence is something that isn't even very well-defined there's machine learning and there's artificial intelligence.

[01:03:33] Some people put machine learning as a subset of artificial intelligence. Other people kind of mess around with it and do it the other way. I tend to think that artificial intelligence is kind of the top of the heap, if you will. And that machine learning is a little bit further down because machines can be programmed to learn.

[01:03:54] For instance, look at your robot, your eye robot cleans the floor, cleans the carpet. It moves around. It has sensors and it learned, Hey, I have to turn here. Now. I robot is actually pretty much randomly drew. But there are some other little vacuum robots that, that do learn the makeup of your house. The reason for the randomization is while chairs move people, move things, move.

[01:04:22] So trying to count on the house, being exactly the same every time isn't isn't exactly right. Uh, by the way, a lot of those little vacuums that are running around are also sending data about your house, up to the manufacturer in the. So they often will know how big the house is. They know where it's located because you're using the app for their robot.

[01:04:47] And that, of course it has access to GPS, et cetera, et cetera. Right. But where are we going? Obviously, the little by robot, the little vacuum does not need much intelligence to do what it's doing, but one of the pursuits that we've had for. Really since the late nineties for 20, 25 years are what are called follower robots.

[01:05:13] And that's when I think we're going to start seeing much more frequently, it's going to be kind of the first, um, I called it machine learning. They call it artificial intelligence who you really could argue either one of them, but there's a little device called a Piaggio fast forward. And it is really kind of cool.

[01:05:34] Think of it almost like R2D2 or BB eight from star wars following you around. It's frankly, a little hard to do. And I want to point out right now, a robot that came out, I think it was last year from Amazon is called the Astro robot. And you might remember Astro from the Jetsons and. This little robot was available in limited quantities.

[01:06:01] I'm looking at a picture of it right now. It, frankly, Astro is quite cute. It's got two front wheels, one little toggle wheel in the back. It's got cameras. It has a display that kind of makes it look like kids are face, has got two eyeballs on them. And the main idea behind this robot is that it will.

[01:06:23] Provide some protection for your home. So it has a telescoping camera and sensor that goes up out of its head up fairly high, probably about three or four feet up looking at this picture. And it walks around your one rolls around your home, scanning for things that are out of the normal listening for things like windows breaking there, there's all kinds of security.

[01:06:50] That's rolled into some of these. But it is a robot and it is kind of cool, but it's not great. It's not absolutely fantastic. Amazon's dubbing the technology it's using for Astro intelligent motion. So it's using location and mapping data to make sure that Astro. Gets around without crashing into things.

[01:07:18] Unlike that little vacuum cleaner that you have, because if someone loves something on the floor that wasn't there before, they don't want to run over it, they don't want to cause harm. They don't want to run into your cats and dogs. And oh my maybe lions and bears too. But, uh, they're also using this computer vision technology called visual ID and that is used.

[01:07:41] With facial recognition, drum roll, please, to recognize specific members of the family. So it's kind of like the dog right in the house. It's sitting there barking until it recognizes who you are, but Astro, in this case, Recognizes you and then provide you with messages and reminders can even bring you the remote or something else and you just drop it in the bin and off it goes.

[01:08:08] But what I am looking at now with this Piaggio fast forward, you might want to look it up online, cause it's really. Cool is it does the following, like we've talked about here following you around and doing things, but it is really designed to change how people and goods are moving around. So there's a couple of cool technologies along this line as well.

[01:08:35] That it's not, aren't just these little small things. You might've seen. Robots delivery robots. The Domino's for instance, has been working on there's another real cool one out there called a bird. And this is an autonomous driving power. Basically. It's a kind of a four wheel ATV and it's designed to move between the rows of fruit orchards in California or other places.

[01:09:01] So what you do to train this borough robot is you press a follow button on it. You start walking around the field or wherever you want it to go. It's using, uh, some basic technology to follow you, cameras and computer vision, and it's recording it with GPS and it memorizes the route at that point. Now it can ferry all of your goods.

[01:09:29] Around that path and communicate the path by the way to other burrow robots. So if you're out doing harvesting or whether it's apples out in the east coast, or maybe as I said out in California, you've got it. Helping you with some of the fruit orchards. It's amazing. So this is going to be something that is going to save a lot of time and money, these things, by the way, way up to 500 pounds and it can carry as much as a half a ton.

[01:09:58] You might've seen some of the devices also from a company down in Boston, and I have thought that they were kind of creepy when, when you look at it, but the company's called Boston dynamics and. They were just bought, I think it was Hondai the bought them trying to remember. And, uh, anyway, These are kind of, they have robots that kind of look like a dog and they have other robots that kind of look like a human and they can do a lot of different chores.

[01:10:33] The military has used them as have others to haul stuff. This one, this is like the little dog, it has four legs. So unlike a lot of these other robots that are on wheels, this thing can go over very, very. Terrain it can self write, et cetera. And they're also using them for things like loading trucks and moving things around, um, kind of think of Ripley again, another science fiction tie, uh, where she's loading the cargo in the bay of that spaceship.

[01:11:05] And she is inside a machine. That's actually doing all of that heavy lifting now. Today, the technology, we have a can do all of that for us. So it is cool. Uh, I get kind of concerned when I see some of these things. Military robots are my favorite, especially when we're talking about artificial intelligence, but expect the first thing for these to be doing is to be almost like a companion, helping us carry things around, go fetch things for us and in the business space.

[01:11:40] Go ahead and load up those trucks and haul that heavy stuff. So people aren't hurting their backs. Pretty darn cool. Hey, I want to remind you if you would like to get some of the free training or you want some help with something the best place to start is Craig peterson.com. And if you want professional help, well, not the shrink type, but with cyber security.

[01:12:06] email me M E at Craig peterson.com.

[01:12:10] Just in time for the holidays, we have another scam out there and this one is really rather clever and is fooling a lot of people and is costing them, frankly, a whole lot of money.

[01:12:26] This is a very big cyber problem because it has been very effective. And although there have been efforts in place to try and stop it, they've still been able to kind of get ahead of it. There's a great article on vice that's in this week's newsletter. In my show notes up on the website and it is talking about a call that came in to one of the writers, Lorenzo, B cherry, um, probably completely messy and that name up, but the call came in from.

[01:13:03] Supposedly right. Paid pals, uh, fraud prevention system. Someone apparently had tried to use his PayPal account to spend $58 and 82 cents. According to the automated voice on the line, PayPal needed to verify my identity to block the transfer. And here's a quote from the call, uh, in order to secure your account, please enter the code we have sent to your mobile device.

[01:13:32] Now the voice said PayPal, sometimes texts, users, a code in order to protect their account. You know, I've said many times don't use SMS, right? Text messages for multi-factor authentication. There are much better ways to do it. Uh, after entering a string of six digits, the voice said, thank you. Your account has been secured and this request has been blocked.

[01:13:57] Quote, again, don't worry. If any payment has been charged your account, we will refund it within 24 to 48 hours. Your reference ID is 1 5 4 9 9 2 6. You may now hang up, but this call was actually. Hacker they're using a type of bot is what they're called. These are these automated robotic response systems that just dramatically streamlined the process for the hackers to gain access into your account.

[01:14:31] Particularly when you have multi-factor authentication codes where you're using. An SMS messages, but it also works for other types of one-time passwords. For instance, I suggest to everybody and we use these with our clients that they should use something called one password.com. That's really you'll find them online.

[01:14:54] And one password.com allows you to use and create one time password, same thing with Google authenticator, same thing with Microsoft authenticator, they all have one-time password. So if a bad guy has found your email address and has found your password online in one of these hacks, how can they possibly get into your PayPal account or Amazon or Coinbase or apple pay or.

[01:15:26] Because you've got a one time password set up or SMS, right? Multifactor authentication of some sort. Well they're full and people and absolute victims. Here's what's happening. Th this bot by the way, is great for bad guys that don't have social engineering skills, social engineering skills, or when someone calls up and says, hi, I'm from it.

[01:15:51] And there's a problem. And we're going to be doing an upgrade on your Microsoft word account this weekend because of a bug or a security vulnerability. So what, what I need from you is I need to know what username you're normally using so that I can upgrade the right. So we don't, it doesn't cost us a whole bunch by upgrading accounts that aren't being used.

[01:16:15] So once the account name that you use on the computer and what's the password, so we can get in and test it afterwards, that's a social engineering type attack. That's where someone calls on the phone, those tend to be pretty effective. But how about if you don't speak English very well? At all frankly, or if you're not good at tricking people by talking to them, well, this one is really great.

[01:16:44] Cause these bots only cost a few hundred bucks and anybody can get started using these bots to get around multi-factor authentication. See, here's how it works. In order to break into someone's account, they need your username, email address and password. Right? Well, I already said. Much many of those have been stolen.

[01:17:07] And in our boot camp coming up in a few weeks, we're going to go through how you can find out if your username has been stolen and has been posted on the dark web and same thing for your password. Right? So that's going to be part of the. Coming up that I'll announce in the newsletter. Once we finished getting everything already for you guys, they also go ahead and buy what are called bank logs, which are login details from spammers who have already tricked you into giving away some of this information.

[01:17:41] But what if you have multi-factor authentication enabled something I'm always talking about, always telling you to do. Well, these bots work with platforms like Twilio, for instance, uh, and they are using other things as well, like slack, et cetera. And all the bad guy has to do with that point is going.

[01:18:07] And, uh, say, they're trying to break into your account right now. So they're going to, let's get really, really specific TD bank. That's where my daughter works. So let's say you have a TD bank account. And the hacker has a good idea that you have a TD bank account knows it because they entered in your username and password and TD bank was letting them in.

[01:18:32] But TD bank sent you a text message with that six character code, right? It's usually digits. It's usually a number. So what happens then? So the bad guys says, okay, so it's asking me for this six digit SMS code. I could hijack their phone, but that's more work. How about this? So all they have to do is put the information into this channel for the bot.

[01:18:59] The bot picks it up, calls you with that message. You've picked up the phone. It's supposedly PayPal or TD bank or whomever on the phone gives you a fake message of some sort, and then it asks you for. You're two factor authentication code. It says we're going to send you the code. Right? And so now you have the code because the bad guy tried to break into your account.

[01:19:30] And so you give the code to the robot, to the bot that's on the phone. And guess what the bad guy now has. The bad guy now has the code that you entered, which is actually the code that he needed to put on to the bank's website in order to get into your bank account. Yeah, it sounds a little bit, uh, complicated, but in reality, it's pretty simple and it's much simpler than they've been doing already, which has cost billions of dollars so far, according to the FBI.

[01:20:03] So besides sites like PayPal, Amazon Venmo, some of these bots are targeting specific banks, specifically bank of America and chase. And with others users can customize the automatically read. This as well. So there you go. Keep an eye out. Absolutely keep an eye out. And these sites that are being used in order to coordinate with the bots, they are keeping an eye out.

[01:20:29] They're trying to shut them down very quickly. Uh, their names are out there. I'm not going to say them. I don't want to give the bad guys a little, any more help and trying to find out what they are or where they are. Uh, Yeah, by the way, the pricing one month access to one of these bots right now is $540 lifetime access to one of these bots to cheat people out of the bank accounts, et cetera is 27 50.

[01:20:57] And the next day the price goes up. So it's from 27 50, it goes up to $4,000. So they're using pretty typical marketing techniques. Hey, before we go today, I got a couple more things I want to hit really quickly. One. The threat against our critical infrastructure is real. And we've talked before about the hackers going after the critical infrastructure and that's bad enough in July of last year, according to wired magazine, uh, DJI.

[01:21:30] To drone. Now you're familiar with those DJI. I think they're the biggest drone manufacturer in the world. They're Chinese company. We've had warnings from the, uh, the feds about using some of these things because they have been tracking where they are taking pictures and sending them back to the communists in.

[01:21:54] Yeah. Anyways, in this particular case, this drone was fit up with two, four foot long nylon ropes dangling from the rotors, a thick copper wire countered to the ends of those ropes with the electrical. The bad guys had removed any obviously identifiable markings. And that includes the onboard camera memory card, because of course your onboard, camera's going to have a serial number, but guess what?

[01:22:26] Sodas. Parts of that device, including the drone itself. Uh, but anyways, the bad guys aren't necessarily the smartest and they were trying to avoid detection we're guessing here. Right. But it makes sense. And the operation, according to some security bulletins that I got from the FBI that was also put out by Homeland security in the national counter terrorism center was to do.

[01:22:56] Operations by creating a short circuit. So here comes this big drone Mo you know, fair-sized drone and it is approaching this substation. And you've seen those before with the transformers and the wires everywhere. And the plan is to get that cop. Piece of wire on top of a couple of these high, current lines and high voltage for the most part and short it out.

[01:23:26] And that short circuit is going to knock the power off. Well, I'm not going to get into the details of how our electrical grid works, but this device wouldn't have done what the bad guys wanted to do. But even more, it crashed onto the roof of an adjacent building before it even reached to these substation.

[01:23:45] So there you go. They had removed the camera, so they really didn't have any idea where it was. It was flying, they were watching it, but it got too far away and they totally messed it up. But there's a potential. For consumer drones to wreck havoc. You might remember what happened in Venezuela and Venezuela.

[01:24:05] Back in 2018, there was an explosive Laden drone tried to assassinate the president last weekend in Iraq, three drones tried to assassinate the Iraqi prime minister last weekend. All right, have a great weekend and make sure you join me online. Craig peterson.com.

View Details

If you follow my newsletter, you probably saw what I had in the signature line the last few weeks: how to make a fake identity. Well, we're going to take it a little bit differently today and talk about how to stop spam with a fake email.

[Automated transcript follows]

[00:00:16] Email is something that we've had for a long time.

[00:00:19] I think I've told you before I had email way back in the early eighties, late seventies, actually. So, yeah, it's been a while and I get tens of thousands of email every day, uh, sent to my domain, you know, mainstream.net. That's my company. I've had that same domain name for 30 years and, and it just kinda got out of control.

[00:00:46] And so we have. Big Cisco server, that exclusively filters email for us and our clients. And so it cuts down the tens of thousands to a very manageable couple of hundred a day. If you think that's manageable and it gets sort of almost all of the fishing and a lot of the spam and other things that are coming.

[00:01:09] But, you know, there's an easier way to do this. Maybe not quite as effective, but allowing you to track this whole email problem and the spam, I'm going over this in some detail in. Coming bootcamp. So make sure we keep an eye on your emails. So you know about this thing again, it's free, right? I do a lot of the stuff just to help you guys understand it.

[00:01:34] I'm not trying to, you know, just be June to submission to buy something. This is a boot camp. My workshops, my boot camps, my emails, they are all about informing you. I try to make them the most valuable piece of email. During the week. So we're going to go into this in some detail in this upcoming bootcamp.

[00:01:55] But what we're looking at now is a number of different vendors that have gotten together in order to help prevent some of the spam that you might've been in. Uh, I think that's a very cool idea to have these, these sometimes temporary, sometimes fake email addresses that you can use. There's a company out there called fast to mail.

[00:02:20] You might want to check them out. There's another company called apple. And you might might want to check them out. I'll be talking about their solution here as well. But the idea is why not just have one email address? And if you're an apple user, even if you don't have the hardware, you can sign up for an apple account.

[00:02:42] And then once you have that account, you can use a new feature. I saw. Oh, in, in fact, in Firefox, if you use Firefox at all, when there's a form and it asks for an email address, Firefox volunteers to help you make a fake ish email address. Now I say fake ish, because it's a real email address that forwards to your normal regular.

[00:03:10] Email address. And as part of the bootcamp, I'm also going to be explaining the eight email addresses, minimum eight, that you have to have what they are, how to get them, how to use them. But for now you can just go online to Google and this will get you started and do a search for Apple's new hide. My email feature.

[00:03:30] This lets you create random email addresses and those email addresses. And up in your regular, uh, icloud.com or me.com, whatever you might have for your email address, address that apple has set up for you. Isn't that cool. And you can do that by going into your iCloud settings. And it's part of their service that are offering for this iCloud plus thing.

[00:03:57] And they've got three different fi privacy focused services, right? So in order to get this from apple, so you can create these unlimited number of rather random looking emails, for instance, a blue one to six underscore cat I cloud.com that doesn't tell anybody. Who you are, and you can put a label in there.

[00:04:21] What's the name of the website that, that, or the, the, a URL of the website, the two created this email for, and then a note so that you can look at it later on to try new member and that way. Site that you just created it for in this case, this is an article from CNET. They had an account@jamwirebeats.com.

[00:04:45] This is a weekly music magazine subscription that they had. And apple generated this fake email address, blue one to 600 score Canada, cobb.com. Now I can hear you right now. Why would you bother doing that? It sounds like a lot of work. Well, first of all, it's not a whole lot of work, but the main reason to do that, If you get an email address to blue cat, one, two6@icloud.com and it's supposedly from bank of America, you instantly know that is spam.

[00:05:23] That is a phishing email because it's not using the email address you gave to TD bank. No it's using the email address that it was created for one website jam wire beats.com. This is an important feature. And that's what I've been doing for decades. Email allows you to have a plus sign. In the email address and Microsoft even supports it.

[00:05:53] Now you have to turn it on. So I will use, for instance, Craig, plus a Libsyn as an example@craigpeterson.com and now emails that Libson wants to send me. I'll go to Craig. Libsyn@craigpeterson.com. Right? So the, the trick here is now if I get an email from someone other than libs, and I know, wait a minute, this isn't Libsyn, and that now flags, it has a phishing attack, right.

[00:06:28] Or at the very least as some form of spam. So you've got to keep an eye out for that. So you got to have my called plus, and if. Pay for the premium upgrade, which ranges from a dollar to $10. Uh, you you've got it. Okay. If you already have an iCloud account, your account automatically gets upgraded to iCloud plus as part of iOS 15, that just came out.

[00:06:55] All right. So that's one way you can do it. If you're not an apple fan. I already mentioned that Firefox, which is a browser has a similar feature. Uh, Firefox has just been crazy about trying to protect your privacy. Good for them, frankly. Right? So they've been doing a whole lot of stuff to protect your privacy.

[00:07:17] However, there you are. They have a couple of features that get around some of the corporate security and good corporate security people have those features block because it makes it impossible for them to monitor bad guys that might hack your account. So that's another thing you can look at is Firefox.

[00:07:37] Have a look@fastmail.com. And as I said, we're going to go into this in some detail in the bootcamp, but fast mail lets you have these multiple email accounts. No, they restricted. It's not like apple where it's an infinite number, but depending on how much you pay fast mail is going to help you out there.

[00:07:57] And then if you're interested, by the way, just send an email to me, me. Craig peterson.com. Please use that email address emmy@craigpeterson.com because that one is the one that's monitored most closely. And just ask for my report on email and I've got a bunch of them, uh, that I'll be glad to send you the gets into some detail here, but proton mail.

[00:08:22] Is a mail service that's located in Switzerland? No, I know of in fact, a couple of a high ranking military people. I mean really high ranking military people that are supposedly using proton mail. I have a proton mail account. I don't use it that much because I have so much else going on, but the advantage.

[00:08:45] Proton mail is it is in Switzerland. And as a general rule, they do not let people know what your identity is. So it's kind of untraceable. Hence these people high up in the department of defense, right. That are using proton mail. However, it is not completely untraceable. There is a court case that a proton man.

[00:09:12] I don't know if you'd say they lost, but proton mail was ordered about a month ago to start logging access and provide it for certain accounts so they can do it. They are doing it. They don't use it in most cases, but proton mail is quite good. They have a little free level. Paid levels. And you can do all kinds of cool stuff with proton mail.

[00:09:35] And many of you guys have already switched, uh, particularly people who asked for my special report on email, because I go into some reasons why you want to use different things. Now there's one more I want to bring up. And that is Tempa mail it's temp-mail.org. Don't send anything. That is confidential on this.

[00:09:57] Don't include any credit card numbers, nothing. Okay. But temp-mail.org will generate a temporary email address. Part of the problem with this, these temporary email address. Is, they are blocked at some sites that really, really, really want to know what your really mail address is. Okay. But it's quite cool.

[00:10:22] It's quite simple. So I'm right there right now. temp-mail.org. And I said, okay, give me email address. So gave me one. five04@datacop.com. Is this temporary email, so you can copy that address. Then you can come back into again, temp-mail.org and read your email for a certain period of time. So it is free.

[00:10:48] It's disposable email. It's not particularly private. They have some other things, but I wouldn't use them because I don't know them for some of these other features and services. Stop pesky email stop. Some of these successful phishing attempt by having a unique, not just password, but a unique email for all those accounts.

[00:11:12] And as I mentioned, upcoming bootcamp, and I'll announce it in my weekly email, we're going to cover this in some detail. Craig peterson.com. Make sure you subscribe to my newsletter.

[00:11:25] Well, you've all heard is up. So what does that mean? Well, okay. It's up 33% since the last two years, really. But what does that amount to, we're going to talk about that. And what do you do after you've been ransomed?

[00:11:42] Ransomware is terrible. It's crazy. Much of it comes in via email.

[00:11:49] These malicious emails, they are up 600% due to COVID-19. 37% of organizations were affected by ransomware attacks in the last year. That's according to Sofos. 37% more than the third. Isn't that something in 2021, the largest ransomware payout, according to business insider was made by an insurance company at $40 million setting a world record.

[00:12:21] The average ransom fee requested increased from 5,020 18 to around 200,000 in 2020. Isn't that something. So in the course of three years, it went from $5,000 to 200,000. That's according to the national security Institute, experts estimate that a ransomware attack will occur every 11 seconds for the rest of the year.

[00:12:50] Uh, it's just crazy. Absolutely. Crazy all of these steps. So what does it mean? Or, you know, okay. It's up this much is up that much. Okay. Businesses are paying millions of dollars to get their data back. How about you as an individual? Well, as an individual right now, the average ransom is $11,605. So are you willing to pay more than $11,000 to get your pictures back off of your home computer in order to get your.

[00:13:27] Work documents or whatever you have on your home computer. Hopefully you don't have any work information on your home computer over $11,000. Now, by the way, most of the time, these ransoms are actually unaffiliate affair. In other words, there is a company. That is doing the ransom work and they are pain and affiliate who are the, the affiliate in this case.

[00:13:55] So the people who infected you and the affiliates are making up to 80% from all of these rents. Payments it's crazy. Right? So you can see why it's up. You can just go ahead and try and fool somebody into clicking on a link. Maybe it's a friend of yours. You don't productively like some friend, right. And you can go ahead and send them an email with a link in it.

[00:14:20] And they click the link and it installs ransomware and you get 80% of them. Well, it is happening. It's happening a lot. So what do you do? This is a great little article over on dark reading and you'll see it on the website. The Craig peterson.com. But this article goes through. What are some of the steps it's by Daniel Clayton?

[00:14:48] It's actually quite a good little article. He's the VP of global security services and support over at bit defender bit defender is. Great, uh, software that you've got versions of it for the Mac. You've got versions four of it for window. You might want to check it out, but he's got a nice little list here of things that you want to do.

[00:15:13] So number one, Don't panic, right? Scott Adams don't panic. So we're worried because we think we're going to lose our job June. Do you know what? By the way is in the top drawer of the majority of chief information, security officers, two things. Uh, w one is their resignation letter and the second one is their resume because if they are attacked and it's very common and if they get in trouble, they are leaving.

[00:15:47] And that's pretty common too. Although I have heard of some companies that understand, Hey, listen, you can't be 100% effective. You got to prioritize your money and play. It really is kind of like going to Vegas and betting on red or black, right? 50, 50 chance. Now, if you're a higher level organization, like our customers that have to meet these highest compliance standards, these federal government regulations and some of the European regulations, even state regulations, well, then we've got to keep you better than 99% safe and knock on wood over the course of 30 years.

[00:16:27] That's a long I've been doing. 30 years. We have never had a single customer get a S uh, and. Type of malware, whether it is ransomware or anything else, including one custom company, that's a multinational. We were taking care of one of their divisions and the whole company got infected with ransomware.

[00:16:50] They had to shut down globally for. Two weeks while they tried to recover everything, our little corner of the woods, the offices that we were protecting for that division, however, didn't get hit at all. So it is possible, right? I don't want you guys to think, man. There was nothing I can do. So I'm not going to do anything.

[00:17:14] One of the ladies in one of my mastermind groups basically said that, right? Cause I was explaining another member of my mastermind group. Got. And I got hit for, I think it turned out to be $35,000 and, you know, that's a bad thing. Plus you feel just so exposed. I've been robbed before, uh, and it's just a terrible, terrible feeling.

[00:17:37] So he was just kind of freaking out for good. But I explained, okay, so here's what you do. And she walked away from it thinking, well, there's nothing I can do. Well, there are things you can do. It is not terribly difficult. And listening here, getting my newsletter, going to my bootcamps and the workshops, which are more involved, you can do it.

[00:18:03] Okay. It can be done. So I don't want. Panic. I don't want you to think that there's zero. You can do so that's number one. If you do get ransomware, number two, you got to figure out where did this come from? What happened? I would change this order. So I would say don't panic. And then number two is turn off the system that got rants.

[00:18:29] Turn it off one or more systems. I might've gotten ransomware. And remember that the ransomware notification does not come up right. When it starts encrypting your data. It doesn't come up once they've stolen your data. It comes up after they have spread through your organization. So smart money would say shut off every computer, every.

[00:18:56] Not just pull the plug. I w I'm talking about the ethernet cable, right? Don't just disconnect from wifi. Turn it off. Immediately. Shut it off. Pull the plug. It might be okay. In some cases, the next thing that has to happen is each one of those machines needs to have its disc drive probably removed and examined to see if it has.

[00:19:18] Any of that ransomware on it. And if it does have the ransomware, it needs to get cleaned up or replaced. And in most cases we recommend, Hey, good time. Replace all the machines, upgrade everything. Okay. So that's the bottom line. So that's my mind. Number two. Okay. Um, he has isolated and save, which makes sense.

[00:19:40] You're trying to minimize the blast radius. So he wants you to isolate him. I want you to turn them off because you do not want. Any ransomware that's on a machine in the process of encrypting your files. You don't want it to keep continuing to encrypting. Okay. So hopefully you've done the right thing.

[00:20:00] You are following my 3, 2, 1 backup schedule that I taught last year, too, for free. For anybody that attended, hopefully you've already figured out if you're going to pay. Pay. I got to say some big companies have driven up the price of Bitcoin because they've been buying it as kind of a hedge against getting ransomware so they can just pay it right away.

[00:20:25] But you got to figure that out. There's no one size fits all for all of this. At over $11,000 for an individual ransom, uh, this requires some preparation and some thought stick around, got a lot more coming up. Visit me online, Craig Peterson.com and get my newsletter along with all of the free trainings.

[00:20:52] Well, the bad guys have done it again. There is yet another way that they are sneaking in some of this ransomware and it has to do with Q R codes. This is actually kind of clever.

[00:21:08] By now you must've seen if not used QR codes.

[00:21:12] These are these codes that they're generally in a square and the shape of a square and inside there's these various lines and in a QR code, you can encode almost anything. Usually what it is, is a URL. So it's just like typing in a web address into your phone, into your web browser, whatever you might be using.

[00:21:35] And they have been very, very handy. I've used them. I've noticed them even showing up now on television ad down in the corner, you can just scan the QR code in order to apply right away to get your gin Sioux knives. Actually, I haven't seen it on that commercial, but, uh, it's a different one. And we talked last week about some of these stores that are putting QR codes in their windows.

[00:22:02] So people who are walking by, we even when the store is closed, can order stuff, can get stuff. It's really rather cool. Very nice technology. Uh, so. There is a new technique to get past the email filters. You know, I provide email filters, these big boxes, I mean, huge machines running Cisco software that are tied into, uh, literally billion end points, plus monitoring tens of hundreds of millions of emails a day.

[00:22:39] It's just huge. I don't even. I can ha can't get my head around some of those numbers, but it's looking at all those emails. It is cleaning them up. It's looking at every URL that's embedded in an email says, well, is this a bad guy? It'll even go out and check the URL. It will look at the domain. Say how long has this domain been registered?

[00:23:01] What is the spam score overall on the domain? As well as the email, it just does a whole lot of stuff. Well, how can it get around a really great tight filter like that? That's a very good question. How can you and the bottom line answer is, uh, how about, uh, using the QR code? So that's what bad guys are doing right now.

[00:23:26] They are using a QR code in side email. Yeah. So the emails that have been caught so far by a company called abnormal security have been saying that, uh, you have a missed voicemail, and if you want to pick it up, then scan this QR. It looks pretty legitimate, obviously designed to bypass enterprise, email gateway scans that are really set up to detect malicious links and attachments.

[00:24:01] Right? So all of these QR codes that abnormal detected were created the same day they were sent. So it's unlikely that the QR codes, even that they'd been detected would have been previously. Poured it included in any security blacklist. One of the good things for these bad guys about the QR codes is they can easily change the look of the QR code.

[00:24:26] So even if the mail gateway software is scanning for pictures and looking for a specific QR codes, basically, they're still getting. So the good news is the use of the QR codes in these types of phishing emails is still quite rare. We're not seeing a lot of them yet. We are just starting to see them, uh, hyperlinks to phishing sites, a really common with some of these QR codes.

[00:24:58] But this is the first time we've seen an actor embed, a functional QR code into an email is not. Now the better business bureau warned of a recent uptick, ticking complaints from consumers about scams involving QR codes, not just an email here, but because these codes can't really be read by the human eye at all.

[00:25:21] The attackers are using them to disguise malicious links so that you know, that vendor that I talked about, that retail establishment that's using the QR codes and hoping people walking by will scan it in order to get some of that information. Well, People are going to be more and more wary of scanning QR codes, right?

[00:25:43] Isn't that just make a lot of sense, which is why, again, one of the items in our protection stack that we use filters URLs. Now you can get a free. The filter and I cover this in my workshop, how to do it, but if you go to open DNS, check them out, open DNS, they have a free version. If you're a business, they want you to pay, but we have some business related ones to let you have your own site to.

[00:26:15] Based on categories and all that sort of stuff, but the free stuff is pretty generalized. They usually have two types, one for family, which blocks the stuff you might think would be blocked. Uh, and other so that if you scan one of these QR codes and you are using open DNS umbrella, one of these others, you're going to be much, much.

[00:26:39] Because it will, most of the time be blocked because again, the umbrella is more up-to-date than open DNS is, but they are constantly monitoring these sites and blocking them as they need to a mobile iron, another security company. I conducted a survey of more than 4,400 people last year. And they found that 84% have used a QR code.

[00:27:05] So that's a little better than I thought it was. Twenty-five percent of them said that they had run into situations where a QR code did something they did not expect including taking them to a malicious website. And I don't know, are they like scanning QR codes in the, in the men's room or something in this doll?

[00:27:24] I don't know. I've never come across a QR code. That was a malicious that I tried to scan, but maybe I'm a little more cautious. 37% were. Saying that they could spot a malicious QR code. Yeah. Yeah. They can read these things while 70% said they'd be able to spot a URL to a phishing or other malicious website that I can believe.

[00:27:50] But part of the problem is when you scan a QR code, it usually comes up and it says, Hey, do you want to open this? And most of that link has invisible is, is not visible because it is on your smartphone and it's not a very big screen. So we'll just show you the very first part of it. And the first part of it, it's going to look pretty darn legit.

[00:28:14] So again, that's why you need to make sure you're using open DNS or umbrella. Ideally, you've got it installed right at your edge at your router at whoever's handling DHCP for your organization. Uh, in the phishing campaign at normal had detected with using this QR code, uh, code they're saying the attackers had previously compromised, some outlook, email accounts, belonging to some legitimate organizations.

[00:28:43] To send the emails with malicious QR codes. And we've talked about that before they use password stuffing, et cetera. And we're covering all of this stuff in the bootcamp and also, well, some of it in the bootcamp and all of this really in the workshops that are coming up. So keep an eye out for that stuff.

[00:29:03] Okay. Soup to nuts here. Uh, it's a, uh, it's a real. Every week, I send out an email and I have been including my show notes in those emails, but I found that most people don't do anything with the show notes. So I'm changing, I'm changing things this week. How some of you have gotten the show notes, some of you haven't gotten the show notes, but what I'm going to be doing is I've got my show notes on my website@craigpeterson.com.

[00:29:35] So you'll find them right. And you can get the links for everything I talk about right here on this. I also now have training in every one of my weekly emails. It's usually a little list that we've started calling listicles and it is training on things you can do. It is. And anybody can do this is not high level stuff for people that are in the cybersecurity business, right.

[00:30:07] Home users, small businesses, but you got to get the email first, Craig peterson.com and signup.

[00:30:14] California is really in trouble with these new environmental laws. And yet, somehow they found a major exception. They're letting the mine lithium in the great salt and sea out in California. We'll tell you why.

[00:30:31] There's an Article in the New York times. And this is fantastic. It's just a incredible it talking about the lithium gold rush.

[00:30:43] You already know, I'm sure that China has been playing games with some of these minerals. Some of the ones that we really, really need exotic minerals that are used to make. Batteries that are used to power our cars. And now California is banning all small gasoline engine sales. So the, what is it? 55,000 companies out in California that do lawn maintenance are going down.

[00:31:13] To drive those big lawnmowers around running on batteries. They're estimating it'll take 30 packs battery packs a day. Now, remember California is one of these places that is having rolling blackouts because they don't have. Power, right. It's not just China. It's not just Europe where they are literally freezing people.

[00:31:37] They did it last winter. They expect to do it more. This winter, since we stopped shipping natural gas and oil, they're freezing people middle of winter, turning off electronics. California, at least they're not too likely to freeze unless they're up in the mountains in California. So they don't have enough power to begin with.

[00:31:57] And what are they doing there? They're making it mandatory. I think it was by 2035 that every car sold has to be electric. And now they have just gotten rid of all of the small gasoline engines they've already got. Rolling blackouts, come on. People smarten up. So they said, okay, well here's what we're going to do.

[00:32:20] We need lithium in order to make these batteries. Right. You've heard of lithium-ion batteries. They're in everything. Now, have you noticed with lithium batteries, you're supposed to take them to a recycling center and I'm sure all of you do. When your battery's dead in your phone, you take it to a recycling center.

[00:32:39] Or if you have a battery that you've been using in your Energizer bunny, and it's a lithium battery, of course you take it to the appropriate authorities to be properly disposed of because it's toxic people. It is toxic. So we have to be careful with this. Well, now we're trying to produce lithium in the United States.

[00:33:06] There are different projects in different parts of the country, all the way from Maine through of course, California, in order to try and pull the lithium out of the ground and all. Let me tell you, this is not very green at all. So novel. Peppa Northern Nevada. They've started here blasting and digging out a giant pit in this dormant volcano.

[00:33:38] That's going to serve as the first large scale, lithium mine in the United States and more than a decade. Well, that's good. Cause we need it. And do you know about the supply chain problems? Right. You've probably heard about that sort of thing, but that's good. This mine is on least federal lands. What does that mean?

[00:33:59] Well, that means if Bernie Sanders becomes president with the flick of a pen, just like Joe Biden did on his first day, he could close those leads to federal lands. Yeah. And, uh, we're back in trouble again, because we have a heavy reliance on foreign sources of lithium, right. So this project's known as lithium Americas.

[00:34:25] There are some native American tribes, first nation as they're called in Canada. Uh, ranchers environmental groups that are really worried, because guess what? In order to mine, the lithium, and to do the basic processing onsite that needs to be done, they will be using. Billions of gallons of groundwater.

[00:34:48] Now think of Nevada. Think of California. Uh, you don't normally think of massive lakes of fresh water to. No. Uh, how about those people that are opposed to fracking? Most of them are opposed to fracking because we're pumping the water and something, various chemicals into the ground in order to crack the rock, to get the gas out.

[00:35:11] Right. That's what we're doing. They don't like that. But yet, somehow. Contaminating the water for 300 years and leaving behind a giant mound of waste. Isn't a problem for these so-called Greenies. Yeah. A blowing up visit quote here from max Wilbert. This is a guy who has been living in a tent on this proposed mine site.

[00:35:38] He's got a. Lawsuits that are going, trying to block the project. He says blowing up a mountain. Isn't green, no matter how much marketing spend people put on it, what have I been saying forever? We're crazy. We are insane. I love electric cars. If they are coolest. Heck I would drive one. If I had one, no problem.

[00:35:57] I'm not going to bother to go out and buy one, but, uh, yeah, it's very cool, but it is anything but green. Electric cars and renewable energy are not green, renewable energy. The solar and the wind do not stop the need for nuclear plants or oil or gas burners, or cold burners, et cetera. Because when the sun isn't shining, we still need electricity.

[00:36:29] Where are we getting to get it? When the wind isn't blowing or when the windmills are broken, which happens quite frequently. Where are we going to get our power? We have to get it from the same way we always have from maybe some, uh, some old hydro dams. Right. But really we got to start paying a lot more attention to nuclear.

[00:36:53] I saw a couple of more nuclear licenses were issued for these six gen nuclear plants that are green people. They are green, but back to our lithium mine. They're producing cobalt and nickel as well as the lithium. And they are ruined this to land, water, wildlife, and. Yeah. Yeah, absolutely. Uh, we have had wars over gold and oil before and now we're looking at minerals.

[00:37:27] In fact, there's a race underway between the United States, China, Europe, Russia, and others, looking for economic and technological dominance for decades to come by grabbing many of these precious minerals. So let's get into this a little bit further here. Okay. So they're trying to do good, but really they're not green.

[00:37:53] They're they're not doing good. And this is causing friction. Okay. Um, first three months of this year, us lithium miners raise nearly three and a half billion dollars from wall street, seven times the amount raised in the last six months or 36 months. Yeah, huge. Money's going into it. Okay. They're going after lithium from California's largest leak, the Salton sea.

[00:38:23] Yeah. Yeah. So they're going to use specially coded beads to extract lithium salt from the hot liquid pumped up from an aquifer more than 4,000 feet below the surface. Hmm. Sounds like drilling aren't they anti drilling to the self-contained systems connected to geothermal power plants generating emission free electricity.

[00:38:44] Oh, that's right. They don't have a problem with the ring of fire in California with earthquakes and things. Right. Ah, yeah. Drilling on that and using the, the, uh, It's not going to be a problem. Uh, so, um, yeah, so that you're hoping to generate revenue needed to restore the lake fouled by toxic runoff from area farms for decades.

[00:39:08] So they're looking to do more here. Lithium brine, Arkansas, Nevada, North Dakota, as I mentioned already, Maine. Uh, they're using it in every car that's out there, smartphones, et cetera. Uh, the us has some of the world's largest reserves, which is, I guess, a very good thing. Right? A silver peak mine in Nevada is producing 5,000 tons a year, which is less than 2% of the world's supply.

[00:39:40] Uh, this is just absolutely amazing going through this. Okay. Um, I know bomb administration official, Ben Steinberg said right now, China decided to cut off the U S for a variety of reasons. We're in trouble. Yeah. You think. Uh, the another thing here in the New York times article is from this rancher and it's a bit of a problem.

[00:40:06] He's got 500 cows and calves. Roaming is 50,000 acres and Nevada's high desert is going to have to start buying feed for. This local, mine's going to reach about 370 feet. Uh, here's another kind of interesting thing. This mine one mine is going to consume 3,200 gallons of water. Per minute. Yeah. In, in Baron Nevada, I I'm looking at a picture of this and it is just dead sagebrush.

[00:40:37] Oh my gosh. So they're expecting the water table will drop at least 12 feet. They're going to be producing 66,000 tons of battery grade, lithium carbonate a year. But, uh, here we go. They're digging out this mountain side and they're using 5,800 tons of so FERC acid per day. Yeah. They're mixing clay dug out from the ma from the Mount side with 5,800 tons of clay of sulfuric acid.

[00:41:10] I should say every day, they're also consuming 354 million cubic yards. Of mining waste. I'm not consuming creating 354 million cubic yards of mining waste loaded with, uh, discharged from this sulfuric acid treatment and may contain. Modest amounts of radioactive uranium. That's according to the permit documents, they're expecting it'll degrade quote unquote 5,000 acres of winter range used by the antelope herd, the habitat of the Sage groves nesting areas for Eagles.

[00:41:48] It just goes on and on. It is not. BLM is not, of course stumbled the bureau of land management, but I guess both PLMs are not, and this is a real problem and the tribes are trying to stop it. The farmers are trying to stop it, but Hey, California needs more lithium batteries for their electric cars.

[00:42:10] They're electric lawn mowers, leaf blowers, et cetera. So we've got to get that lithium. We've got to get it right away, uh, in order for their green appetite in. Hey get some sanity. Craig peterson.com. Sign up for my newsletter right now.

[00:42:28] Doing a little training here on how to spot fake log-in pages. We just covered fishing and some real world examples of it, of some free quiz stuff that you can use to help with it. And now we're moving on to the next.

[00:42:44] The next thing to look for when it comes to the emails and these fake log-in pages is a spelling mistake or grammatical errors.

[00:42:56] Most of the time, these emails that we get that are faking emails are, have really poor grammar in them. Many times, of course the, the commas are in the wrong place, et cetera, et cetera. But most of us weren't English majors. So we're not going to pick that up myself included. Right. That's why I use Grammarly.

[00:43:17] If you have to ever write anything or which includes anything from an email or a document, uh, you, you probably want to get Grammarly. There's a few out there, but that's the one I liked the best for making sure my grammar. So a tip, I guess, to the hackers out there, but the hackers will often use a URL that is very close to.

[00:43:41] Where are you want to go? So they might put a zero in place of an O in the domain, or they might make up some other domain. So it might be a amazon-aws.com or a TD bank dash. Um, account.com, something like that. Sometimes the registrars they'll catch that sort of thing and kill it. Sometimes the business that they are trying to fake will catch it and let them know as well.

[00:44:16] There's companies out there that watch for that sort of thing. But many times it takes a while and it's only fixed once enough people have reported it. So look at the URL. Uh, make sure it's legitimate. I always advise that instead of clicking on the link in the email, try and go directly to the website.

[00:44:38] It's like the old days you got a phone call and somebody saying, yo, I'm from the bank and I need your name and social security number. So I can validate the someone broke into your account. No, no, no, no, no, they don't. They don't just call you up like that nowadays. They'll send you a message in their app.

[00:44:55] That's on your smart. But they're not going to call you. And the advice I've always given is look up their phone now. And by the way, do it in the phone book, they remember those and then call them back. That's the safest way to do that sort of thing. And that's true for emails as well. If it's supposedly your bank and it's reporting something like someone has broken into your account, which is a pretty common technique for these fissures, these hackers that are out there, just type in the bank URL as you know, it not what's in the email and.

[00:45:32] There will be a message there for you if it's legitimate, always. Okay. So before you click on any website, Email links, just try and go directly to the website. Now, if it's one of these deep links where it's taking new Jew, something specific within the site, the next trick you can play is to just mouse over the link.

[00:45:57] So bring your mouse down to where the link is. And typically what'll happen is at the bottom left of your. Your screen or of the window. It'll give you the actual link. Now, if you look at some of them, for instance, the emails that I send out, I don't like to bother people. So if you have an open one of my emails in a while, I'll just automatically say, Hey, I have not opened them in a while.

[00:46:25] And then I will drop you off the list. Plus if you hit reply to one of my newsletters, my show notes, newsletters. That's just fine, but it's not going to go to me@craigpeterson.com and some people you listeners being the best and brightest have noticed that what happens is it comes up and it's some really weird URL that's so I can track who responded to.

[00:46:53] And that way I can just sit down and say, okay, now let me go through who has responded? And I've got a, kind of a customer relationship management system that lets me keep track of all of that stuff so that I know that you responded. I know you're interacting, so I know I'm not bothering you. Right. And I know I need to respond to.

[00:47:13] Well much the same thing is true with some of these links. When I have a link in my newsletter and I say, Hey, I'm linking to MIT's article. It is not going to be an MIT. Because again, I want to know what are you guys interested in? So anytime you click on a link, I'll know, and I need to know that, so I know why, Hey, wait a minute.

[00:47:37] Now, 50% of all of the people that opened the emails are interested in identifying fake login pages. So what do I do? I do something like I'm doing right now. I go into depth on fake login. Pages. I wouldn't have known that if I wasn't able to track it. So just because the link doesn't absolutely look legit doesn't mean it isn't legit, but then again, if it's a bank of it involves financial transactions or some of these other things be more cautious.

[00:48:13] So double-check for misspellings or grammatical errors. Next thing to do is to check the certificate, the security certificate on the site. You're on this gets a little bit confusing. If you go to a website, you might notice up in the URL bar, the bar that has the universal resource locator, that's part of the internet.

[00:48:40] You might've noticed. There's a. And people might've told you do check for the lock. Well, that lock does not mean that you are saying. All it means is there is a secure VPN from your computer to the computer on the other side. So if it's a hacker on the other side, you're sending your data securely to the hacker, right?

[00:49:07] That's not really going to do you a whole lot of good. This is probably one of the least understood things in the whole computer security side, that connect. Maybe secure, but is this really who you think it is? So what you need to do is click on their certificate and the certificate will tell you more detail.

[00:49:32] So double-check their certificate and make sure it is for the site. You really. To go to, so when it's a bank site, it's going to say, you know, the bank is going to have the bank information on it. That makes sense. But if you go for instance on now, I'm going to throw a monkey wrench into this whole thing.

[00:49:51] If you go to Craig peterson.com, for instance, it's going to say. Connection is secure. The certificate is valid, but if you look at their certificate and the trust in the details, it's going to be issued by some company, but it's going to just say Craig peterson.com. It's not going to give a business name like it would probably do for a bank.

[00:50:17] So you know, a little bit of a twist to it, but that's an important thing. Don't just count on the lock, make sure that the certificate is for the place you want to contact. Last, but not least is multi-factor authentication. I can't say this enough. If the bad guys have your username or email address and your password for a site, if you're using multifactor authentication, they cannot get.

[00:50:56] So it's going to prevent credential stuffing tactics, or they'll use your email and password combinations that have already been stolen for mothers sites to try and hack in to your online profile. So very important to set up and I advise against using two factor authentication with your, just a cell phone, as in a text message SMS, it is not secure and it's being hacked all of the time.

[00:51:26] Get an authorization. App like one password for instance, and you shouldn't be using one password anyways, for all of your password. And then Google has a free one called Google authenticator. Use those instead of your phone number for authentication.

[00:51:43] I've been warning about biometric databases. And I, I sat down with a friend of mine who is an attorney, and he's using this clear thing at the airport. I don't know if you've seen it, but it's a biometric database. What are the real world risks?

[00:52:00] Well, this " Clear"company uses biometrics. It's using your eye. Brent, if you will, it's using your Iris.

[00:52:08] Every one of us has a pretty darn unique Iris, and they're counting on that and they're using it to let you through TSA very quickly. And this attorney, friend of mine thinks it's the best thing since sliced bread, because he can just. Right on through, but the problem here is that we're talking about biometrics.

[00:52:30] If your password gets stolen, you can change it. If your email account gets hacked, I have another friend who his account got hacked. You can get a new email account. If your Iris scan that's in this biometric database gets stolen. You cannot replace your eyes unless of course you're Tom cruise and you remember that movie, right.

[00:53:00] And it's impossible to replace your fingerprints. It's possible to replace your face print. Well, I guess you could, to a degree or another, right. Some fat injections or other things. Could it be done to change your face sprint, but these Iris scans fingerprints and facial images are something I try not to provide any.

[00:53:27] Apple has done a very good job with the security of their face print, as well as their fingerprint, because they do not send any of that information out directly to themselves, or do any database at all. They are stored only on the device itself. And they're in this wonderful little piece of electronics that cannot be physically compromised.

[00:53:56] And to date has not been electronically compromised either. They've done a very, very good. Other vendors on other operating systems like Android, again, not so much, but there are also databases that are being kept out there by the federal government. I mentioned this clear database, which isn't the federal government, it's a private company, but the federal government obviously has its fingers into that thing.

[00:54:27] The office of personnel. Uh, for the federal government, they had their entire database, at least pretty much the entire database. I think it was 50 million people stolen by the red, Chinese about six years ago. So the communists. Uh, copies of all of the information that the officer personnel management had about people, including background checks and things.

[00:54:55] You've probably heard me talk about that before. So having that information in a database is dangerous because it attracts the hackers. It attracts the cybercriminals. They want to get their hands on it. They'll do all kinds of things to try and get their hands. We now have completely quit Afghanistan.

[00:55:19] We left in a hurry. We did some incredibly stupid things. I just, I can't believe a president of the United States would do what was done here. And now it's been coming out that president Biden completely ignored. The advice that he was getting from various military intelligence and other agencies out there and just said, no, we're going to be out of there.

[00:55:46] You have to limit your troops to this. And that's what causes them to close the airbase bog that we had had for so many years. Apparently the Chinese are talking about taking it over now. Yeah. Isn't that nice. And whereas this wasn't an eternal war, right? We hadn't had anybody die in a year and a half.

[00:56:05] Uh, it's crazy. We have troops in south Vietnam. We have troops in Germany. We have troops in countries all over the world, Japan, you name it so that we have a local forest that can keep things calm. And we were keeping things calm. It's just mind blowing. But anyhow, politics aside, we left behind a massive database of biometric database.

[00:56:40] Of Afghanis that had been helping us over in Afghanistan, as well as a database that was built using us contractors of everyone in the Afghan military, and basically third genealogy. Who their parents were the grandparents blood type weight, height. I'm looking at it right now. All of the records in here, the sex ID nationality.

[00:57:13] Uh, date of exploration, hair color, favorite fruit, favorite vegetables, place of birth, uncle's name marker signature approval. Signature date, place of birth. Date of birth address, permanent address national ID number, place of ISS. Date of ISS native language salary. Date of salary, group of salary, police of salary education.

[00:57:38] Father's named graduation date kind of weapon. And service number. These were all in place in Afghanistan. We put them in place because we were worried about ghost soldiers. A gold soldier was someone who we were paying the salary of taxpayers. The United States were paying the salaries of the Afghan military for quite some time.

[00:58:06] And we were thinking that about half of the. Payroll checks. We were funding. We're actually not going to people who were in the military, but we're going to people who were high up within the Afghan government and military. So we put this in place to get rid of the ghost soldiers. Everybody had to have all of this stuff.

[00:58:33] In the database, 36 pieces of information, just for police recruitment. Now this information we left behind and apparently this database is completely in the hand of the Taliban. Absolutely. So we were talking about Americans who helped construct Afghanistan and the military and the Teleman, the looking for the networks of their Poland supporters.

[00:59:07] This is just absolutely amazing. So all of the data doesn't have clear use, like who cares about the favorite fruit or vegetable, but the rest of it does the genealogy. Does they now know who was in the police department, who was in the military, who their family is, what their permanent address is. Okay.

[00:59:31] You see the problem here and the biometrics as well in the biometrics are part of this us system that we were using called hide H I D E. And this whole hide thing was a biometric reader. Well, the military could keep with them. There were tens of thousands of these things out in the field. And when they had an encounter with someone, they would look up their biometrics, see if they were already in the database and in the database, it would say, yeah, you know, they're friendly, they're an informant.

[01:00:08] Or we found them in this area or w you know, we're watching them. We have concerned about them, et cetera, et cetera. Right. All of their actions were in. Well turns out that this database, which covered about 80% of all Afghans and these devices are now in the hands of the Taliban. Now, the good news with this is that that a lot of this information cannot be easily extracted.

[01:00:40] So you're not going to get some regular run of the mill Taliban guide to pick one of these up and start using. But, uh, the what's happening here is that we can really predict that one of these surrounding companies like Pakistan that has been very cooperative with the Taliban. In fact, they gave refuge to Saddam, not Saddam Hussein, but to bin Ladin and also Iran and China and Russia.

[01:01:13] Any of those countries should be able to get into that database. Okay. So I think that's really important to remember now, a defense department spokesperson quote here, Eric Faye on says the U S has taken prudent actions to ensure that sensitive data does not fall into the Tolo bonds. And this data is not at risk of misuse.

[01:01:38] Misuse that's unfortunately about all I can say, but Thomas Johnson, a research professor at the Naval postgraduate school in Monterey, California says, uh, not so fast. The Taliban may have used biometric information in the Coon dues attack. So instead of taking the data straight from the high devices, he told MIT technology review that it is possible that Tolo bond sympathizers in Kabul provided them.

[01:02:11] With databases as a military personnel against which they could verify prints. In other words, even back in 2016, it may have been the databases rather than these high devices themselves pose the greatest risk. This is very concerning big article here in MIT technology review. I'm quoting from it a little bit here, but there are a number of databases.

[01:02:39] They are biometric. Many of these, they have geological information. They have information that can be used to round up and track down people. I'm not going to mention world war two, and I'm not going to mention what happened with the government before Hitler took over, because to do that means you lose that government had registered firearms, that government had registered the civilians and the people and Afghanistan.

[01:03:13] The government was also as part of our identification papers, registering your religion. If you're Christian, they're hunting you down. If you were working for the military, they're hunting new day. And this is scary. That's part of the reason I do not want biometric information and databases to be kept here in the U S Hey, make sure you get my show notes every week on time, along with free training, I try to help you guys out.

[01:03:50] Craig peterson.com. Craig peterson.com. Here I am. Cybersecurity strategist and available to you.

View Details

How Ransomware, Trojanware, and Adware Hurt You.
And Why ExpressVPN Isn't Safe to Use.

Ransomware, Trojanware Adware. What's the difference between these different types of malware.? And when it comes down to our computers, which should we worry about the most and which should we worry about the most?

[Automated Transcript Follows]

[00:00:17] There are a lot of different types of malware that are out there and they're circulating and scaring us.

[00:00:23] And I think for good reason, in many cases, ransomware of course, is the big one and it is up, up, up. It has become just so common. Now that pretty much everybody is going to be facing a serious ransomware attack within the next 12 months. The numbers are staggering. And what are they doing while now they're getting you with the double whammy.

[00:00:50] The first whammy is they encrypt your data. Your computers are encrypted, everything on them. So you can't use them anymore. Bottom line. Yeah, they'll boot they'll run enough in order to be able for you to pay that ransom. But any document that you might care about, any PDF, any word doc, and the spreadsheet is going to be encrypted.

[00:01:14] And the idea behind that is. You have to pay in order to get that decryption key about 50% of the time. Yeah. About half of the time. Even if you pay the ransom, you'll get your data back the rest of the time. No, you you'll never see it again. So what do you do about that type of ransomware? Well, obviously most people just pay the rent.

[00:01:39] But that's gone up as well. We've seen over a hundred percent increase in the amount of ransom people happy. So what's the best thing to do. What's the easiest thing to do in order to help you with this type of ransomware while it's obviously to have good backups. Now I'm going to be doing a bootcamp.

[00:02:00] We're going to talk about this and a workshop. I really want to get going with these one week long workshops. So we'll do a, at least a couple of times a month in these boot camps that we'll do pretty much every week here, but they're coming up fairly soon. You'll only know about them. If you are on my email list, that is Craig peterson.com and the number one thing that you can do to.

[00:02:27] You when you're hit with this type of rent somewhere, because if you're not taking all of the other precautions, you should be digging under really good that you're going to get hit the better than 50%. And once you do is have a good backup, and I want to warn everybody because I've seen this again and against people just keep making this mistake, probably because they don't get it.

[00:02:51] They don't understand why and where and how, when it comes to ransom. The mistake is they do a backup to a local desk. Now, many times the backup is on a thumb drive or USB drive. So you just go to the big box store. You go to Amazon, you order an external drive. You're just amazed how cheap they are.

[00:03:16] Nowadays. Once you've got that drive, you plug it in. You turn on some backup software. Maybe it's something you've used for some years, maybe. If you have a Mac, you're just using the built-in backup software. Even the windows operating system now comes with some built-in backup and you think you're off and running because every so often it back.

[00:03:40] If we're using a Mac is smart enough to not only back up your whole machine, but as you're editing files, it's going to go ahead and make a backup of that file as you're editing it. So if there is a crash or something else, you're not going to lose much. I just love the way apple does that. Huge problem.

[00:03:59] Because if the disc is attached to your machine, or let's say that disc is on a file server, cause you're smart, right? You set up some network attached storage of some sort and your machine has access to it. And so you're sending it off of your machine to a central. Well, you still got a problem because if your machine can read or more particularly right to a location on your network or locally, that ransomware is going to also encrypt everything, it can find there.

[00:04:37] So, if you are sharing a network drive and you get ransomware, when you remember the odds are better than 50%, you're gonna get it. Then what happens? What would this type of ransomware it not only encrypts the files on your computer, but encrypts them on the backup as well. And it also encrypts them on any of the.

[00:04:58] File servers or network attached storage the, to have on your network. So now everything's encrypted. You wonder why someone and people pay the ransom? Oh, that's a large part of the reason right there. And I keep saying this type of ransomware because there isn't another type of ransomware and they usually go hand in hand.

[00:05:21] The bad guys were not making enough money off of holding your files. Rants. So the next thing the bad guys have done is they've gone to a different type of extortion. This one is, Hey, if you don't pay us, we are going to release your files to the world. Now they might do it on a dark website. They might do it on a publicly available site, which is what many of them are starting to do now.

[00:05:51] And you're going to either be embarrassed or subject to a lot of fines or both, because now if your files have. Confidential information. Let's say it's your intellectual property. Now, anybody who bothers to search online can find your intellectual property out there. If you have anything that's personally identifiable information.

[00:06:18] And it gets out. Now you are subject to major fines. In fact, in some states like California and Massachusetts, you are subject to fines. Even if the bad guys don't post it online. So that's the second type of ransomware and it's a bad type. And usually what'll happen is the bad guys, get their software on your machine and they can do it in a number of different ways.

[00:06:45] One of the popular ways to do it now is to just break in because. Our businesses, we've, we've set up something called remote desktop, and we're using remote desktop for our users to get in. And maybe we're using some form of a VPN to do it with, or maybe we've made the mistake of using express VPN. And, uh, we have that now connected up to our homes and we think that that's keeping us safe.

[00:07:13] And I got a few things to say about that as well. These VPN services. What happens now while Microsoft remote desktop has been under major attack and there are some major flaws. Some of these were patched more than a year ago now, but according to recent studies, 60%, almost two thirds of businesses have not applied the patches.

[00:07:42] You know, th this is basic stuff. And I understand how hard it can be and it can be confusing and you can break your systems, but you have to weigh that against well, what's going to happen if our systems are broken into, because we didn't apply the patch. So that's the second type of ransomware and that's what most people are afraid of and for good reason.

[00:08:07] And one of the things we do for businesses and we do ransomware audits, we have a look at your systems, your firewalls, et cetera, and make recommendations to. Man. I got to talk about this too, cause it really upset me this week. I signed up for a webinar just to see what was going on. There's a company out there that sells these marketing systems to managed services providers.

[00:08:33] And I, I, I had to turn it off like instantly because it was just such. Garbage that they were telling managed services providers MSPs to do. I couldn't believe it. So this guy was talking about how, again, I turned it back on and I said, Hey, I've got to watch us anyways, because I need to know what's going on.

[00:08:54] And this guy was telling these managed services providers, how they can double their clothes. I couldn't believe this guy. Cause he was saying that what they do is they offer to do a ransomware audit for businesses and they say, normally we charge $6,000 to do a ransomware audit, but I tell you what we'll do it for you for.

[00:09:20] Now, this is a guy that he had an MSP managed services provider. Apparently he had started it and he was bringing in more than $1 million per month in revenue. Can you imagine that monthly recurring revenue over a million dollars? And so he's telling people businesses, Hey, I have a $6,000 audit that we'll do.

[00:09:47] For free, Hey people, how long have we said, if you're not paying for something your, the product remember Facebook, right? Google, Instagram, all of those guys, Twitter, you don't pay for it, but your information is the product. So what's this guy doing well, guess what? His audit, it's going to show his audit.

[00:10:10] It's going to show that you need him. And he's sucked in hundreds of businesses and he didn't even know what he was doing when it came to the audits or protecting them. It is insane. What's going on out there. I am ashamed of my industry, absolutely ashamed of it. You know, I've got my first attack, successful attack against my company back in 91 92.

[00:10:42] And I learned this stuff because I had to, and I help you guys because I don't want you to get stuck. Like I was so important, important word of advice. If you want to nod it, go to someone that charges you for the audit. That's going to do a real one. It's going to give you real advice that you can really need and use rather than, Hey, you knew do use me.

[00:11:11] Because my free audit tells you so, so many scams.

[00:11:15] What is ad where in what is crypto, where these are two types of real, kind of bad things. Won't gray areas, things that are hurting us, our mobile devices, our businesses. And our homes.

[00:11:32] Adware is also a type of malware that's been around a long time. But it does live in a gray area.

[00:11:42] And that gray area is between basically marketing and, uh, well outright fraud. And I don't even want to call it just marketing because it's very aggressive market. What they will do with add where is they? They will have some JavaScript code or something else that's embedded on a webpage, and that's usually how you get it.

[00:12:09] And then once it's in, in your browser, it sits there and it pops up things. So it'll pop up an ad for this, pop up an ad for that, even if it's. Uh, part of the site that you're on right now, and it can live for months or years on your computer. We've known for a long time about ad where on the windows environment and how it has just been just terribly annoying at the very least Microsoft and genetic Explorer.

[00:12:40] One of the worst web browsers ever. Perpetrated on humankind was well-known for this. And of course, Microsoft got rid of internet Explorer, and then they came up with her own symposer browser, the edge browser that was also openly scorned. And so Microsoft got rid of their edge browser and switched over to basically Google Chrome chromium, and then changed his name to the edge browser.

[00:13:11] And so you think you're running edge, but you're kind of not, you kind of are. So they did all of that in order to help with compatibility and also to help with some of these problems that people have had using that Microsoft browser online, very, very big problems. So what can you do about it and what does it do to you and where can be very.

[00:13:37] You might've had it before words always popping up again and again and again on your browser, just so crazy knowing it it's insane, but it can also be used to spy on where you're going online and potentially to, to infect you with something even worse. Sometimes some of this ad where we'll purposely click on ads, that the people who gave you the ad were, are using as kind of like a clickbait type thing.

[00:14:09] So you go to a website and it was. Automatically click certain ads and click on unbeknownst to you, right? It's as though you went there so that people have to pay for that ad. And sometimes aids are very, very complicated. Sometimes they'll use. In order to drive a competitor out of business or out of the market, because the ads are so expensive because so many people are supposedly clicking on the ads.

[00:14:40] But in reality, you didn't click on the ad. You're not going to see that page that you supposedly clicked on, and it's going to cost that advertiser money, whole bunch of money. You might not care. Right. But it is. Ad ware over on the Mac, however, is the only real malware menace at all I had to where is something that choosed fairly frequently on the Mac?

[00:15:09] It is pretty darn easy to get rid of. And as a general rule, it doesn't work very well on the Mac. Although I have seen some cases where it got very, very sticky. Where someone ended up installing it, it wasn't just running in the browser, but they installed it on their Mac, which is something you should never do.

[00:15:29] But apple has some things in place to help stop any of this from happening. And it's gotten a lot better. I haven't seen this problem in a couple of years, but apple is using the signature based blocking technology called export. They also have at apple, this developer based notarization of apps. And so the run of the mill malware, which includes most of this Al where really can't find a foothold.

[00:15:57] But I want to remind everybody that if they can get Al add where onto your computer, they might be able to get something worse. So you really got to keep an eye out for no two ways about it. There are some companies out there, for instance, there's this one. Parrot, which is a program linked to this Israeli marketing firm that gains persistence on your browser and potentially could gain root access to the Mac system.

[00:16:30] So careful, careful on all fronts now. Anti-malware stuff that we use for our clients is called amp, which is an advanced malware protection system. That's been developed by our friends over at Cisco it's amp is very, very good. Unfortunately, you cannot get it unless you buy it from somebody like us and you have to buy so many seats for some of this stuff, it gets gets expensive quickly.

[00:17:00] Um, if you can't do that much, a lot of people like Malwarebytes, there are some very good things about it, but be careful because in order for this to work, this is Railey parrot software to work. It has a fake install. So again, it's just be careful if you know how apple installed software, you know that unless you have instigated it, it's not going to be installed.

[00:17:30] You're not just going to see an installer. And say, Hey, we're apple install us. Right? Apple just does it in the background when it comes to updates patches. But they're very sneaky here trying to install things like the Adobe floor. Player, which has been deprecated. Deprecated is completely now gone from Mac systems and from windows systems, you should not be using flash at all anymore.

[00:18:02] It was very, very bad. So up becomes you, you go to wound stole the leaders flash player, or, and I'm sure they're going to change this or something else, right? It won't be flashed in a future. It'll be a Adobe. Would you also don't need on a Mac. So anyhow, that's what you got to be careful of ad were still a big problem in windows.

[00:18:25] Not much as much as it used to be. Uh, thanks to the change to Google Chrome, which Microsoft has rebranded as of course its own edge browser. Much of a problem at all on Macs, but be very, very careful in either platform about installing software that you did not start installing. Now earlier this year, there's a security firm called red Canary that found something that's been named silver Sparrow.

[00:18:58] That was on a. 30,000 Mac computers. And apparently the developers for this malware had already adapted it to apples and one chip architecture and have distributed this binary, this program as a universal binary. Now in the macro, the member doesn't just use Intel. It used to use power PCs and then it used Intel.

[00:19:21] And now it's using its own architecture for the chips themselves. So a universal binary is something that will run on Mac Intel based and Mac architecture base. But, uh, the bottom line is that this proof of concept. Malware, if you will had no payload. So we know it's out there, we seen it now on almost 30,000 Mac computers, but at this point it's not really doing much, much at all.

[00:19:53] So. These are malicious search engine results and they're directing victims to download these PKGs, which are Mac packaged format installers based on network connections from your browser shortly before download. So just be very careful about all of that. It can be something as annoying as malware or something as a malicious.

[00:20:17] Well, potentially as ransomware. Particularly if you're running windows, Hey, if you want to find out more about this, if you want to get into some of my free courses here, we got free boot camps coming up. Make sure you go to Craig peterson.com/subscribe. More than glad to send you my show notes, a little bit of training, and of course, let you attend these free bootcamps that are now to sell you stuff, but solve problems for you.

[00:20:49] Hey, if you use VPNs to try and keep yourself safe, particularly if you use express VPN. Wow. What just came out is incredible. It is anything but safe and secure.

[00:21:06] Express VPN was purchased by a company called Cape K A P E. Cape is a company that had changed its name because oh, things were bad.

[00:21:19] Right. It was originally founded under the name of cross writer. And you might've seen notices from your anti-malware software over the years for everything from Malwarebytes on saying that, oh, it blew up. To this cross writer piece of malware, most of the time it's ad ware, but it is really interesting to see because this company was founded by a person who was part of the Israeli secret service. Right? So it wasn't of course not. It's not called the secret service over there in Israel. And it, frankly, it compares to our NSA, you know, no such agency. Yeah. It's part of unit 8,200 in the Israeli intelligence military. And it's been dubbed, of course, Israel's NSA. Teddy Saggy, which was one of these investors also was mentioned in the Panama papers.

[00:22:24] Remember those? We talked about those back in 2016, those were leaked and that showed these law firm, this one particular law firm in panel. And that we're sheltering assets for people all over the world. And so now that express VPN is owned by this company that is, this company built entirely by intelligence agents for almost a billion.

[00:22:55] Dollars in cash and stock purchases. That's a much, they sold express VPN for almost a billion dollars, which is kind of crazy when you think of it as a VPN service, but makes a lot of sense. If you're going to want to monitor what people are doing, where they're going, maybe even break into their systems or better choice than a VPN provider and the.

[00:23:20] The company has been buying up VPN providers and is now the proud owner of express VPN. If you attended my VPN workshop that I had, oh, it's probably been a year and I'm going to start doing these again. I promise, I promise. I promise, but you know how much I just like VPNs. In fact, one of you guys, I'm sorry, I forgot your name.

[00:23:46] Send me. A couple of weeks ago now about VPNs and saying, I know how much you disliked VPN look at this article. And it was talking about this whole thing with express VPN. So they just now all over the place, the discussions online about what. Been to hear who the founder was, the CEO, the CTO, this growing portfolio that they have in Sunbrella of ownerships, that now is centralized in a multiple VPNs.

[00:24:15] Now, Cape technology only started acquiring VPN companies about four years ago. And they've been in business now for over a decade. And what were they doing before? They started buying VPN companies? While they own VPN companies. Oh, they were a major manufacturer and distributor of. Malware of varying types.

[00:24:40] Now the first part of the show today, of course, I was explaining some of the differences, like ad words, et cetera, so that you could understand this story. Right? Ghulja that? So you can understand this. That's what these guys have been doing. It's absolutely crazy. So the F the co-founder of Cape technology and former CEO started his career in information technologies while serving in the Israeli defense forces.

[00:25:08] As I mentioned, Israeli intelligence Corps under unit 8,200 it's that unit is responsible for. Dean what's called signal intelligence and data decryption. Now we have signal intelligence here as well, and that's basically intercepting signals, figuring out what's being said, what's going on? Where they are, the size of the forces, et cetera.

[00:25:32] I have a friend of mine, a young lady who is in signal intelligence in, I think it's the Navy, but every part of our military has it is. However, our military doesn't directly control VPM services like express VPN that can be used in a very big spike capacity. That's what I'm really concerned about. Now. I also, I found an interesting article on zero hedge about this, uh, you know, this company express, VPN being acquired.

[00:26:06] But they're also pointing out that companies that were founded by former operatives of unit 8,200. That again, the Israeli version of the NSA included. Ways Elbit systems, which is right in my hometown of Merrimack, New Hampshire and slews of other startups now ways. Right. I, I used ways I recommended people to use it and of course, Google bought it a few years back and that's when I stopped using it, but it was really nice.

[00:26:39] It worked really well. And I had no idea the information was likely going to. The Israeli defense Corps. Oh my goodness. There's spy agencies, uh, and a bunch of other startups, by the way. It's estimated that there have been over 1000 stack tech startups that came out of the people working at unit 8,208.

[00:27:07] Again, they're CIA NSA, uh, guys, their spine on everybody. You can, you believe that? And they've been bought by a mentioned Google, but other companies like Kodak, PayPal, Facebook, Microsoft have bought them. So in addition to the thousands of companies, according to zero. Uh, unit 8,200 has also fostered close working relationship with the U S government, which you would expect, right?

[00:27:33] Edward Snowden. You remember him? He disclosed leaked documents. He obtained, which included an agreement between the NSA and the Israeli defense force. The agreement showed that the U S intelligence. Agency would share information. It collected under domestic surveillance operations with it. Israeli counterpart.

[00:27:53] You remember we talked before about the five eyes, seven eyes searching eyes. It's up in the twenties. Now these countries that spy on each other citizens. For the other countries, right? Yeah. Your information might not be collected by the U S government, but the U S government gets it by buying it from private contractors, which it says it can do because we're only barred from collecting it ourselves.

[00:28:17] We can use private contractors that collected on you. And also by going in partnership with foreign government. Because again, we can't collect that information, but we can certainly have the Israelis or, or the Brits or the Australians or Canada. They could collect it from. Can you believe this, how they're just stretching these rules to fit in what they want to fit.

[00:28:39] Okay. Completely ignoring not only the constitution, but the laws of the United States. It's, it's just absolutely incredible. So critics of this unit, Eddy 200 attested that the Israeli intelligence outfit routinely uses the data received from the NSA by providing it to. Politicians Israeli politicians for the basics of blackmailing.

[00:29:06] Yes. Blackmailing others. Yes. Indeed. Other whistle blowers have revealed any two hundreds operations have been able to disrupt Syrian air defense systems, hack Russia. Cap Kaspersky labs. You remember I told you guys don't use Kaspersky antivirus and has outfitted several Israeli embassies with Glendale, seen surveillance systems, cleanse Stein.

[00:29:31] However you want to pronounce it. By the time Cape technologies acquired his first VPN company. Uh, the CE original CEO had left and he went on to found cup pie before leaving as it CEO in 2019, it goes on and on, uh, bottom line gas, SWAT express VPN, which is advertised by so many conservatives. Now looks like it is actually part of a spy operation.

[00:30:01] So sign up now. Craig peterson.com. Craig peterson.com/subscribe. You're going to want to attend my free VPN webinar. Hey, I don't have anything to sell you when it comes to VPNs. I just want you to know the truth.

[00:30:17] Labor shortages are making businesses turn direction. And now that we're laying off people or firing them because they didn't take the jab, what are businesses going to do? Well, I have news for you that reduced workforce, well, guess what?.

[00:30:34] U.S. Businesses are really seriously moving to automation.

[00:30:39] Now they've been doing this since the start of this whole lockdown. They were doing it even before then. I tell the story of when I was in France, a boom went four or five years ago now, and I stayed off the beaten path. I was not in the touristy areas. I speak French. So I went just where the. I decided to go, my wife and I, so we rented a car and we spent a month just kind of driving around where do we want to go next to, or do we want to go next?

[00:31:08] It was a whole lot of fun. And while we were there on a Sunday, I came to realize that these small French towns have no restaurants open on Sunday, nothing at all, talking about a bit of a culture shock. That's not true. There was one restaurant opened in the town and that restaurant was, and McDonald's.

[00:31:30] So when I go to McDonald's here a few years ago in France, central France. And when I walk in, there's nobody at the counter, but they're all. Oh, half a dozen kiosks out front. So you go and you order your hamburger, whatever might be, or your drinks, et cetera, right there in the kiosk, you pay for them riding the kiosk.

[00:31:53] And there's some people working out back that are then making the hamburgers or the milkshakes or coffee, whatever you ordered and bringing it up to the front. And then they just put her right there for you to grab that simple. And this was of course, pre. Down days, I assume that it has gone even more automated.

[00:32:14] Uh, they're in France, but hard to say. And I've seen the same thing here in the us. I was out in Vermont just about a month ago and I was riding with a buddy of mine, motorcycle riding, couple of buddies, actually. And we stopped in this small. Town. And we went to this little breasts, breakfast restaurant and the breakfast restaurant had maybe four or five tables inside.

[00:32:42] And you just sat at the table. No waitress came up, but there's little sign with the QR code. So it said a scan, the QR code to get started. So you scanned it, it knew based on the QR code, which table you were at, and it showed you the menu that was in effect right then and there. So the lunch menu or the breakfast or the all day, you got to pick it and then you selected what you wanted.

[00:33:08] It used whatever payment you wanted. I used apple pay. And in order to pay for my breakfast and my buddy ordered what he wanted. And then out came a waitress who delivered the food. Once it was already in the drinks, it was very automated. It allowed them to cut back on some people and others, this small restaurant, they probably had one last waitress, but when you kind of had in the shifts.

[00:33:33] Days and vacation days is probably two waitresses. So they're saving some serious money because a system like this that you just scan a QR code and do the order and it prints up in the kitchen is cheap compared to hiring. Well, of course, it's hard to hire people, especially in the restaurant industry nowadays heck and in my business where we go in and we do analysis of computer networks and systems, it's almost impossible to find people that are really well qualified that understand the regulations that apply to these different businesses.

[00:34:10] So it's like, forget about it. There's more than a million of these jobs open right now. And just in this cybersecurity. Well, September mark, the end of the real lockdown induced unemployment benefits workers. Didn't just flood the labor market as we kind of expected. And we have now few, we have more people now.

[00:34:38] Who are out of the workforce. Who've decided not to look for a job than we did in 2008. So that's telling you something 2008 during the great recession. Interesting things are about to happen, but there's a great little article that I found in. Times this week, and it's talking about this quality local products company out of Chicago, the prince logos on merchandise, like t-shirts water bottles, you know, the little stress balls, all of that sort of stuff.

[00:35:10] And he said prior to the pandemic, we had over 120 employees. That's the co-founder talk in there. And he said, Primary focus was on growth. We simply plugged any holes or any efficiencies that we could along the way with human capital, bringing people in. But once the lockdown happened, of course, all of a sudden now you don't have the access to employees you had before.

[00:35:36] So they had a huge decrease also in business. So those two went hand in hand. They let a lot of people go and they use the opportunity to program many of the previous manual and human controlled activities into computers. So now 18 months later, yeah, two weeks to flatten the curve. Right? 18 months later, the company employees, 83 workers.

[00:36:03] And as managing a workload, that's pretty much the same as pre lockdown. So they went from over 120 employees down to 83. So basically they cut 40 employees from the workforce. That's a whole lot of quarter of the workforce gone. They don't need them anymore. So that's going to help produce more profits for them.

[00:36:27] A lot more profits. Cause usually automating. Yeah, it can be painful, but it usually has major paybacks and that's exactly what it had for them. And they're saying that they anticipate that they can reduce employees even more by the end of this year and get their head count below. 50 now 50 is a magic number.

[00:36:48] So it was a hundred when it comes to employees. Well, one is like the biggest magic number because when, once you have one employee, you all of a sudden have to comply with all kinds of rules, regulations, state, local, federal. But if you hit 50 employees, you have the next step of major new regulations that are gonna affect your business.

[00:37:09] And then when you hit a hundred employees, Even more, so many people try and keep their businesses below 50 employees because it's just not worth it to have all of those regulations, additional regulation, taxes, and everything else. Another company, this is a California based property management. The managing more than 90,000 commercial and residential properties.

[00:37:33] And what they've done is they added a chat feature to the website, the company's called sea breeze. And he says, even though we have the live chat, you can still reach us outside of business hours. Well, You are using the chat or you can call us either way, but they're saying people like the simple form and someone gets back to them as soon as they can.

[00:37:57] So they're avoiding now having staff available 24 7 to respond to chat messages and to respond to the voicemails and phone calls that come in. So it's pretty good all the way around, frankly, new shopping models are in place. I'm looking at a picture of a business and it has. Of course, a window up front and in the window they have jewelry.

[00:38:21] This is a jewelry store and they've got QR codes in front of each of these pieces of jewelry right on the inside of the window. So if you're interested in finding out more about that piece of jewelry, Just scan the QR code. It'll take you to the right page on their website and we'll even let you buy the jewelry and they will mail it to you again.

[00:38:46] How's that for? Great. If you have a business in a tourist jury area and you don't want to be open until 11:00 PM at night, your story can keep selling for you. Even when you're close. This is window shopping, taken to an extreme, very simple. To do as well. This company is called full me waiter. Obviously they've got a bit of a sea theme here.

[00:39:10] So once someone orders the jewelry and the other merchandise sent right to them, or they can have it set for pickup in the store, when they next open it's phenomenal. They're calling. Alfresco shopping space, right from the sidewalk. So businesses again are returning to pre pandemic levels and he, this guy is available in the store by appointment only he's loving it.

[00:39:37] And he says that customers have been so satisfied with this QR code window shopping contract. That he wrote a guidebook. You can get it@scantshopsolution.com or excuse me, scan, just shop solution.com. I misread that. So any retailers who want to use this method, if you don't know what QR codes are, or you don't know how to code it into a website, et cetera, she's got webinars she's taught on it and she's got the guide book.

[00:40:05] I think this is great. Right? So she's now making some money on. Explain to other people, how she did this. It's phenomenal across industries. Epic times is saying the staffing shortages could be temporary, but as firms are further embracing, embracing automation and all of its benefits, some of these jobs that people just don't want anymore may actually be going away.

[00:40:33] And I think this is ultimately a problem. We had, uh, you know, again, I'm older generation, right? Us baby boomers. We had opportunities when we were younger. I had newspaper routes. I had the biggest drought in the area. I can't remember. It was like 120 homes. It was huge. It took me hours to do, but I made money.

[00:40:56] I learned how to interact with people. I knew, I learned how to do bill collection, how important it was not to let customers get too far behind on their bills. Although I have been slack on that one, I'm afraid, but it helped me out a lot. So, what are kids going to do that need to learn a work ethic that need to be able to have a job, make the mistakes, maybe get fired a once or twice or, or three times maybe learn how to interact with customers.

[00:41:27] Everyone, I think can benefit from some retail experience. Get that when you're young and if these jobs don't exist, then. Or the younger generations here, are they just going to be trying to find jobs they can do with Instagram? Right? They're all I know. A few kids who have said, well, I'm a social media influencer and you look them up and okay.

[00:41:50] So they got a thousand people following them. I have far more than that, but you know, it, that's not a job. It's not going to last. Your looks are only going to last so long. Right now you start having a family and you start working hard outdoors, et cetera. There's a lot of things that make that all go away.

[00:42:09] So I think many businesses now we're going to continue to accelerate our plans program out and. A lot of weld pain positions, as well as these entry-level positions in the next five or 10 years. Really? I don't even know if it's going to be 10 years retool retrain our workforce, or everyone's going to be in for a world of hurt.

[00:42:33] Hey, make sure you subscribe. So you're not in a world of hurt. Get my latest in news, especially tech news and cybersecurity. Craig peterson.com.

[00:42:46] In this day and age, if you don't have a burner identity, you are really risking things from having your identities stolen through these business, email compromises. It's really crazy. That's what we're going to talk about.

[00:43:03] An important part of keeping ourselves safe in this day and age really is con to confuse the hackers. The hackers are out there. They're trying to do some things. For instance, like business, email compromise. It is one of the biggest crimes out there today. You know, you hear about ransomware and. It hits the news legitimately.

[00:43:26] It's very scary. It can really destroy your business and it can hurt you badly. If you're an individual you don't want ransomware. Well, how about those emails that come in? I just got an email in fact, from a listener this week and they got a phone call. His wife answered and it was Amazon on the phone and Amazon said, Hey, listen, your account's been hacked.

[00:43:54] We need to clear it up so that your identity doesn't get stolen. And there's a fee for this. It's a $500 fee. And what you have to do is just go to amazon.com. Buy a gift card and we'll then take that gift card number from you. And we'll use that as the fee to help recover your stolen information. So she went ahead and did it.

[00:44:20] She went ahead and did all of the things that the hackers wanted and now they had a gift card. Thank you very much. We'll follow up on this and. Now she told her husband, and of course this isn't a sex specific thing, right. It could have happened to either one. My dad fell for one of these scams as well.

[00:44:44] So she told her husband or her husband looked at what had happened and said, oh my gosh, I don't think this is right. Let me tell you, first of all, Amazon, your bank, various credit card companies are not going to call you on the phone. They'll send you a message right. From their app, which is usually how I get notified about something.

[00:45:10] Or they will send an email to the registered to email that. Uh, that you set up on that account. So that email address then is used by them to contact you right. Pretty simple. Or they might send you a text message. If you've registered a phone for notifications, that's how they contact you. It's like the IRS.

[00:45:35] I was at a trade show and I was on the floor. We were exhausted. And I got no less than six phone calls from a lady claiming to be from the IRS and I needed to pay right away. And if I didn't pay right away, they were going to seize everything. And so all I had to do. Buy a gift card, a visa gift card, give her the number and she would use that to pay the taxes it and this lady had a, an American accent to one that you would recognize.

[00:46:10] I'm sure. And it's not something that they do now. They do send emails, as I said. So the part of the problem with sending emails is, is it really them? Are they sending a legitimate email to a legitimate email address? Always a good question. Well, here's the answer. Yeah, they'll do that. But how do you know that it isn't a hacker sending you the email?

[00:46:42] It can get pretty complicated. Looking into the email headers, trying to track. Where did this come from? Which email servers did it go through? Was it authenticated? Did we accept? Did the, uh, the provider use proper records in their DNS, the SPIF, et cetera, to make sure that it's legitimate. Right? How do you follow up on that?

[00:47:07] That's what we do for our clients. And it gets pretty complicated looking at DKMS and everything else to verify that it was legitimate, making sure that the email came from a registered MX server from the, the real center. There is a way around this. And this has to do with the identities, having these fake burner identities.

[00:47:33] I've been doing this for decades myself, but now it's easy enough for anybody to be able to do. There are some services out there. And one of the more recommended ones. And this is even the New York times, they have an article about this. They prefer something called simple log-in. You can find them online.

[00:47:57] You can go to simple login dot I O. To get started now it's pretty darn cool. Cause they're using, what's called open source software it's software. Anybody can examine to figure out is this legitimate or not? And of course it is legitimate, but, uh, they it's, it's all out there for the whole world to see.

[00:48:17] And that means it's less likely in some ways to be hacked. There are people who argue that having open source software means even more. In some ways you are, but most ways you're not, anyways, it doesn't matter. Simple login.io. Now, why would you consider doing this? Uh, something like simple login? Well, simple login is nice because it allows you to create dozens and dozens of different email address.

[00:48:51] And the idea is with simple log-in it will forward the email to you at your real email address. So let's say you're doing some online shopping. You can go ahead and set up an email address for, you know, whatever it is, shopping company.com, uh, that you're going to use a shopping company.com. So you'd go there.

[00:49:13] You put in two simple log-in, uh, I want to create a new identity and you tag what it's for, and then you then go to some, um, you know, shopping company.com and use the email address that was generated for you by simple login. Now you're a simple login again. Is it going to be tied into your real email account, wherever that might be if using proton mail, which is a very secure email system, or if using outlook or heaven forbid Gmail or one of these others, the email will be forwarded to you.

[00:49:52] You will be able to see that indeed that email was sent to your. Shopping company.com email address or your bank of America, email address, et cetera, et cetera, that makes it much easier for you to be able to tell, was this a legitimate email? In other words, if your bank's really trying to get ahold of you, and they're going to send you an email, they're going to send you an email to an address that you use exclusive.

[00:50:22] For bank of America. In reality, you only have the one email box that is over there on wherever proton, mail, outlook, Gmail, your business. You only have that one box you have to look at, but the email is sent to simple login. Does that make sense? You guys, so you can create a, these alias email boxes. It will go ahead and forward.

[00:50:49] Any emails sent to them, to you, and you'll be able to tell if this was indeed from the company, because that's the only place that you use that email address. That makes it simple, but you don't have to maintain dozens or hundreds of email accounts. You only have the one email account. And by the way, you can respond to the email using that special aliased email address that you created for the shopping company or bank of America or TD or whomever.

[00:51:22] It might be, you can send from that address as well. So check it out online, simple log-in dot IO. I really liked this idea. It has been used by a lot of people over, out there. Now here's one other thing that it does for you, and this is important as well. Not using the same email address. Everywhere means that when the hackers get your email address from shopping company.com or wherever, right.

[00:51:56] pets.com, you name it. They can not take that and put it together with other information and use that for business, email compromise. Does that make sense? It's it makes it pretty simple, pretty straightforward. Don't get caught in the whole business email compromise thing. It can really, really hurt you.

[00:52:19] And it has, it's one of the worst things out there right now, dollar for dollar it's right up there. It, by the way is one of the ways they get ransomware into your systems. So be very careful about that. Always use a different email address for every. Website you sign up for. Oh, and they do have paid plans like a $30 a year plan over at simple IO will get you unlimited aliases, unlimited mailboxes, even your own domain name.

[00:52:50] So it makes it pretty simple, pretty handy. There's other things you might want to do for instance, use virtual credit cards. And we'll talk about those a little bit. As well, because I, I think this is very important. Hey, I want to remind everybody that I have started putting together some trainings.

[00:53:12] You're going to get a little training at least once a week, and we're going to put all of that into. We have been calling our newsletter. I think we might change the name of it a little bit, but you'll be getting those every week. And the only way to get those is to be on that email list. Go to Craig peterson.com/subscribe.

[00:53:35] Please do that right. I am not going to harass you. I'm not going to be one of those. And I've never been one of those internet. Marketers is sending you multiple dozens of emails a day, but I do want to keep you up to date. So stick around, we will be back here in just a couple of minutes. And of course you're listening to Craig Peterson.

[00:53:59] And again, the website, Craig peterson.com stick around because we'll be right back.

[00:54:05] One of the best ways to preserve your security on line is by using what we're calling burner identities, something that I've been doing for more than 30 years. We're going to talk more about how to do that right.

[00:54:20] We've talked about email and how important that is. I want to talk now about fake identities. Now, a lot of people get worried about it. It sounds like it's something that might be kind of sketchy, but it is not to use fake identities in order to confuse the hackers in order to make it. So they really can't do the things that they.

[00:54:46] To do they can't send you fishing ear emails, particularly spear phishing emails. That'll catch you off guard because you're using a fake. How do you do that? Well, I mentioned to you before that I have a thousands of fake identities that I created using census data. And I'm going to tell you how you can do it as well.

[00:55:13] Right? There's a website out there called fake name a generator. You'll find it online@fakenamegenerator.com. I'm on that page right now. And I'm looking at a randomly generated identity. It has the option right on this page to specify the sex. And it says random by default, the name set, I chose American the country United States.

[00:55:44] So it is applying both American and Hispanic names to this creative. And now remember it's doing the creation based on census data and some other public data, but it is not giving you one identity of any real. I think that's important to remember, and you're not going to use these identities for illegal purposes.

[00:56:11] And that includes, obviously when you set up a bank account, you have to use your real name. However, you don't have to use your. If you will real email address, you can use things like simple login that will forward the email to you, but we'll let you know who was sent to. And if you only use that one email address for the bank, then you know that it came from the bank or the email address was stolen from the bank.

[00:56:40] Right. All of that stuff. We've talked about that already. So in this case, The name has come up with for me is Maurice D St. George in Jacksonville, Florida even gives an address, uh, in this case it's 36 54 Willis avenue in Jacksonville, Florida. So if I go right now, Uh, two, I'm going to do use Google maps and I am going to put in that address.

[00:57:11] Here we go. Jacksonville willows avenue, all the guests. What there is a Willis avenue in Jacksonville, and it's showing hoes from Google street view. Let me pull that up even bigger. And there it is. So ta-da, it looks like it gave me. Fairly real address. Now the address it gave me was 36 54, which does not exist.

[00:57:40] There is a 365, but anyways, so it is a fake street address. So that's good to know some, if I were to use this, then I'm going to get my. Uh, my mail saying why about I pass? So, uh, Maurissa tells you what Maurice means, which is kind of neat. It'll give you a mother's maiden name. Gremillion is what a gave me here, a social security number.

[00:58:06] So it creates one that passes what's called a check sum test. So that if you put it into a computer system, it's going to do a real quick check and say, yeah, it looks. To me. So it's was not just the right number of digits. It also passes the check, some tasks. Well-known how to do a check sum on their social security numbers.

[00:58:27] So again, it's no big deal. And remember, you're not going to use this to defraud anyone. You're going to use this for websites that don't really need to know, kind of give me a break. Why do you need all this information? It gives me a phone number with the right area code. Uh, and so I'm going to go ahead and look up this phone number right now.

[00:58:50] Remember, use duck, duck go. Some people will use Google search and it says the phone number gave me is a robo call. As I slide down, there's some complaints on that. Uh, so there you go. So they giving us a phone number that is not a real person's phone number, country code, of course one, cause I said United state birth date.

[00:59:13] Oh, I was born October 7th, year, 2000. I'm 20 years old. And that means I'm a Libra. Hey, look at all this stuff. So it's giving me an email address, which is a real email address that you can click to activate or right there. Again, I mentioned the simple login.io earlier, but you can do a right here and it's got a username and created for me a password, which is actually a pretty deep.

[00:59:41] The password. It's a random one, a website for me, my browser user agent, a MasterCard, a fake MasterCard number with an expiration and a CVC to code all of this stuff. My height is five six on kind of short for. Uh, my weight is 186 pounds own negative blood type ups tracking number Western union number MoneyGram number.

[01:00:11] My favorite color is blue and I drive a 2004 Kia Sorento and it also has a unique ID. And, uh, you can use that wherever you want. So the reason I brought this up again, it's called fake name generator.com is when you are going to a website where there is no legal responsibility for you to tell them the true.

[01:00:39] You can use this. And so I've, I've used it all over the place. For instance, get hub where you have, uh, it's a site that allows you to have software projects as you're developing software. So you can put stuff in, get hub. Well, they don't know to know, need to know who I really am. Now they have a credit card number for me.

[01:01:01] Because I'm on a paid plan. I pay every month, but guess what? It isn't my real credit card number. It isn't the number that I got from fake name generator. My credit card company allows me to generate either a single use credit card numbers, or in this case, a credit card. Number four, get hub doc. So just as an example, that's how I use it.

[01:01:24] So if get hub gets hacked, the hackers have an email address and a name that tipped me off right away, where this is coming from. And if the email didn't come from GitHub by no, they either sold my information to a marketing company, or this is a hacker. Trying to manipulate me through some form of his fishing scheme.

[01:01:47] So I know you guys are the breasts and best and brightest. A lot of you understand what I'm talking about and I'm talking about how you can create a burner identity. And let me tell you, it is more important today to create a burner identity. Then it has ever been at any point in the past because frankly burner identities are one of the ways that you can really mess up some of the marketing firms out there that are trying to put the information together, these data aggregator companies, and also the hackers.

[01:02:24] And it's really the hackers that were off up against here. And we're trying to prevent them from. Getting all of this information. So when we come back, I want to talk about the next step, which is which credit cards can you get? These single use card numbers from? Should you consider using PayPal when my Google voice be a really good alternative for you?

[01:02:52] So we're going to get into all of that stuff. Stick around in the meantime, make sure you go to Craig peterson.com/subscribe. Get my newsletter. All of this. Is in there. It makes it simple. It's a simple thing to do. Craig peterson.com. And if you have any questions, just email me M e@craigpeterson.com.

[01:03:20] Having your credit card stolen can be a real problem for any one of us. It gives the bad guys, a lot of options to spend a lot of money very quickly. We're going to talk right now about virtual credit cards. What are they, what does it mean?

[01:03:37] Virtual credit cards come in two basic forms.

[01:03:41] One is a single use credit card, which was quite popular back when these things first came out and another one is a virtual credit card that has either a specific life. In other words, it's only good for 30 days or that can be used until you cancel it. If you have a credit card, a visa, MasterCard, American express discover all of the major card issuers will give you the ability to reverse any charges that might come onto your cards.

[01:04:19] If your card is stolen or missing. Now that makes it quite easy. Doesn't it? I want to point out that if you're using a debit card, as opposed to a credit card, there's not much challenging you can do with the credit card. You can say, I am not going to make my pain. And, uh, because of this, that, and the other thing, this was stolen, et cetera, they can file it as a disputed charge.

[01:04:46] They can do an investigation find out. Yeah. I'm you probably were not at a bus terminal down in Mexico city, which happened to me. 'cause I was up here in New Hampshire, quite a ways down to Mexico city. And so they just reversed it out. That money never came out of my bank account because it was on a credit card.

[01:05:08] If I were using a debit card. That money would have come right out of my account. Now, mind you, a bus ticket in Mexico city is not very expensive, but many people have had charges of many thousands of dollars. And if you need that money in your checking account, and you're using a debit card, you got a problem because your check for, well, if you ever have to pay rent again, red check is going.

[01:05:38] Bound because they just empty it out to your bank account. So now you have to fight with the bank, get the money back. They will, they will eventually refund it, but it could make some of you. Transactions that you might've written a check or something, it'll make them bounce. And that could be a real problem.

[01:05:57] These, it could make them bounce. So using a credit card is typically less of a hassle online. So why would you want to use a virtual card or also known as a master credit card? Masked and may S K E D? Well, the main reason behind this is to allow you. Control payment. I've used them. In fact, I use them exclusively on every website online.

[01:06:29] And I'm going to tell you the names of some of them here in just a couple of minutes, but I use them all of the time. And part of the reason is let's say, I want to camp. Uh, service. Have you ever tried to cancel a service before and you have to call them many times, right. And so you're, you're arguing with somebody overseas somewhere who doesn't want you to close the account.

[01:06:53] And of course the. Bump you up to the next level person who also doesn't want you to close the account. And so you have to fuss fuss, fuss, fuss. Have you ever had that experience and I'm sure you have. It just happens all the time. So with using the virtual credit card, Well, the advantage to me is, Hey, if you are going to try and fight with me, I don't care because I'm just going to cancel that credit card number.

[01:07:24] So I don't have to cancel my credit card. I don't have to have the company reissue credit card for me. I don't have to do any of this sort of thing that makes my life pretty easy. Doesn't it? And so, because of that, I am now I think in a much better. Place, because it just, I don't have to fight with people anymore.

[01:07:43] So that's one of the reasons I used it. The other big reason is if it gets stolen, they can cause less harm. Some of these credit card it's virtual credit cards are set up in such a way that you can limit the amount that's charged on them. Do you like that? So if you are using it on a site that maybe is charging you $50 a month, no problem.

[01:08:09] $50 a month comes off of the credit card. And if someone tries to charge more bounces and then hopefully you find out, wait a minute, it just bounced on me right now. Then next step up is okay. It bounced and. Uh, I am just going to cancel the card and then you issue a new credit card number for that website.

[01:08:32] So an example. In my case has get hub.com. We keep software up there and they charge me every month if get hub were to get hacked and that credit card number stolen I'm I really don't care because there's almost nothing that can happen. And if good hub doesn't properly cancel. My account, I can just cancel the credit card and, you know, let them come after me.

[01:08:57] Right. This isn't going to happen. So then it's also called a master credit card number because it's a little safer than using your real credit card details. I also want to point out something about debit card. I went for years with no credit cards at all. Nowadays, many of my vendors will take a credit card for payment.

[01:09:20] And in fact, give me a bit of a better deal. And then with the credit card, I can get 2% cash back, which I use to pay down the credit card. Right. It couldn't get any better than that, but when you're using a debit card, what I always. Is I had two accounts that I could transfer money between at the bank.

[01:09:42] So I had one checking account. That was my main operating, if you will account. And then I had another checking account where I would be. Just moving money out of it. Or you could even do it with a savings account, but some banks, they only let you do so many transactions a month on a savings account. So the idea is I know that I have this much in credit card obligate while debit card obligations for this month, that money is going to be coming out.

[01:10:11] So I make sure that. In the debit card account to cover the legitimate transactions I know are coming up and then I keep everything else in the other account. And then I manually transferred over every month. So that's how I dealt with the whole debit card thing. And it worked really well for me. Bottom line.

[01:10:30] I think it's a really great. So there you go, who are the companies that you can use to do this? I've used some of these before all of them have worked really well. If you have a capital one credit card, they have something called Eno, E N O, and it's available to all capital one card. You know, even has an extension for your web browsers.

[01:10:59] So if it notices you're on a webpage, it's asking for credit card number, it'll pop up and say, do you want me to create a credit card number or a virtual one for this websites you can make your payment. Does it get much easier than that? Citibank has something they call a virtual credit cards available to all Citibank card holders, master pass by MasterCard.

[01:11:23] That's available to any MasterCard visa, American express discover Diner's club card holders, credit, debit, and prepaid cards by their way. So you might want to check that one out. Uh, yeah, so that's the only one I see on my list here. That will do it for debit cards, Masterpass by MasterCard American express checkouts, available to all American express card holders.

[01:11:51] Chase pay available to all chase card holders, Wells Fargo, wallet, uh, visa checkouts, available to all visa, MasterCard, and American express and discover color card holders, credit and debit cards. Plus. Prepaid cards. Okay. So it does do the debit cards as well. Final that's all owned by Goldman Sachs and is not accepting any new applicants and entro pay.

[01:12:19] Also not accepting new applicants. There's a couple online. You might also want to check out our Pyne. Premium Al buying. I'm buying a, B I N E blur premium. You might want to check that out as well. All right, everybody make sure you check me out. Craig peterson.com/subscribe.

[01:12:43] We're going to wrap up how you should be using these burner identities of few more tips and tricks that are going to help keep you safe from the hackers that are out there. So here we go.

[01:12:58] There are a lot of hackers out there.

[01:13:01] The numbers are just astounding. The cost of these hackers coming in and stealing our information is just unbelievable. And it goes all the way from big corporations, from things like the colonial pipeline, the U S government all the way on down through you and me. I want to tell you a little story about a friend of mine.

[01:13:28] He is about 75 years old and he supplements his income by driving for Uber eats and one other company. And so what he'll do is someone puts in an order for food somewhere. He'll go pick it up and then he'll drive it to where whoever wanted wanted, whoever ordered it. Now, there are. Pricing number of scams with this.

[01:13:55] So he's very careful about some of that orders, a cookie, for instance, because it's usually a bit of a scam anyways, we won't get into those, but I'll tell you what happened to him. His information was stolen online as it was probably yours. Mine I know was as well. So it's all stolen. What do you do? While in his case, what ended up happening is they managed to get into his email account.

[01:14:27] Once they're in his email account, they now had access to the emails he was getting from one of these companies. Now it wasn't the Uber eats guy. He was, there was another company. So let's just explain this a little bit. Uber eats sends him a request for him to go ahead and do a double. So, you know, go to the restaurant, pick it up and take it to this client's house.

[01:14:54] And in order for him to register, he had to register an email address. Now, of course, he uses the same email address for everything, all of the. Now, personally, that drives me a little bit insane, but that's what he does. And he has just a few passwords. Now. He writes them down a little book and heaven forbid he ever lose the book so that he can remember them.

[01:15:24] He just wants to keep his life simple. Right. He's 75. He's not technophobic, but you know, he's not up on all of this stuff. What he found was a paycheck didn't show. And it was an $800 paycheck. We're talking about real money that he should have had in his. It didn't show up. So he calls up the company and says what happened to my paycheck and their record show?

[01:15:53] Yes, indeed. It had been paid. We paid you, we deposited right into your account. Just like you asked. Yeah. You know, ACH into the account. Great. Wonderful. What had happened is bad guys had gone, gained control of his email address and use that now. Because they figured, well, I see some emails in his account from this food delivery service, so, well, let's try and see if this email address that we're looking at right now.

[01:16:26] All of his emails let's look and see. Okay. Yeah. Same. Email address and same password as a used ad at this email address. Yeah, it worked. Okay. Great. So now we have access to this guys food delivery account. So they changed. The bank account number now, easy enough to confirm, right. They change it and send you an email.

[01:16:54] Hey, I want to make sure that it was you until the bad guys, the hackers click out, yada yada. Yeah, it was me and then delete the email. So he doesn't see it. And now his $800 paycheck. In fact, I think there were a couple of different checks is deposited directly into the bad guy's bank account and. The money of course is transferred out pretty quickly.

[01:17:18] Now the, that guys, these hackers are using what are called mules. You might be familiar with that in the drug trade. They'll have a third party deliver the drugs just to mule. They don't know what all is going on. They probably know the delivering drugs in this case, most of the meals are useful idiots of which there are many in this country.

[01:17:43] Unfortunate. Uh, political and otherwise. And these people are convinced that all they need to do is transfer the money into this account so that the hackers can then pull it out. And you know, now they're going to take care of their grandmother who is stuck in the hospital and they have no way to pay for it.

[01:18:07] And they can't transfer the money out of the country during. That's one of the stories they use for people. And in many cases, these meals know what they're doing. The FBI earlier this year arrested a whole group of mules out in California that were purposefully transferring the money. They knew what they were doing.

[01:18:28] So his money was now out of the country. No way to get it. And this food delivery company was not about to pay him. So it, isn't just the big guys it's you and me as well. So what I want to talk about right now is multi-factor authentication. Now. You guys are the best and brightest. I hope you understand this.

[01:18:54] If you have questions, please reach out to me. I am more than glad to send you some good material on this. Just me. M E add Craig peterson.com. I am here to help. So. What multi-factor authentication does is allows you to not just log in by using an email address and a password, or maybe a username and a password.

[01:19:21] Which is much better by the way. I don't like it. When sites require an email address to log in. Although as you know, I use multiple email addresses and I think you should as well, a different email address for every site out there beyond question, you should be doing that. So anyways, this is. You should be doing with multifactor authentication, they will have you put in your email address, have you put in your password and then they'll do something that is supposedly something you have.

[01:19:56] So the best security is something, you know, along with something you physically have. So in most cases, they'll use two factor authentication by sending you a text message with a code. And then you type in that usually six digit code and now you're in, and it only does that. If it doesn't recognize the browser, are you using or in many cases, have it needs to be a little more secure that it's only good for 24 hours or maybe a week?

[01:20:26] That is not good enough. You should be using a code generator. Google has one for free, but I want you guys to use something called one password. That's the digit one past. You'll find it online. You'll find it in all the app stores. It is what we use for the most part. It's great for families. And it's great for businesses because you can have different vaults and you can share them and control access.

[01:20:58] Now there's a couple of reasons why that we're talking about multi-factor authentication right now. So the first reason kind of the biggest reason is you can use it for generating password. Fairly random ones or fairly memorable ones. And then when you go to a site, one password can pop up and give you the password for the site.

[01:21:22] So you don't even have to look it up. You don't have to remember it. You don't have to look it up. Isn't that phenomenal. And then it also has built into it. Token this, this, uh, six digit key generator. I'm trying to keep this simple. So you can then use that for the site. So it says, okay, so, uh, what's the code go to your, your code generator.

[01:21:47] So you just go to one password. There it is. Copy it and paste it right in. And you're in that alone would have prevented my buddy's account from getting there. It's that simple, one more thing that you want to use one password. And that is those questions that you're asked to verify. It's you many sites out there banks are really big into this and I don't get it cause it's not very good in most cases.

[01:22:16] So they'll ask you things like where were you born? What's your mother's maiden name? Where did you go on your first day too? What was the car that you owned first or, you know, your dog's name, et cetera. The reason, those things are so bad is because the hackers can go online, look at your social media and figure out the answers to a lot of those questions.

[01:22:42] Right? Bad, bad, bad, bad, bad. So what you should be doing is using one password and it allows you to put notes pretty much anything you want to in the record for that website. So you go to the website and you log in, create your account right. To log in. So you're going to give it your, probably your email address, which is a bad idea, but that's, what's required.

[01:23:11] Use one pass. To generate a strong password for you that you'll put in. You'll use one password. Hopefully they have multi factor authentication that allows you to use one of these code generators. Uh, Google has theirs is called Google authenticator, and one password is compatible with that. Microsoft has done.

[01:23:35] Own thing. And it's not compatible with almost any website online. So don't use a Microsoft authenticator other than for Microsoft products, like using the, a windows 365 thing that they have, uh, does use Microsoft authenticator, but you can also use the Google one and the one password one, and then in the notes section, make up answers to the questions.

[01:24:01] So it asks you, what was your mother's maiden? And say something different, like, uh, in security, where D was your high school? It was name of elementary school. Make something up on streaming. Okay. Use random answers. Record them in one password. You're going to have to look them up. If you ever on the phone with the bank or whomever, because you're not going to remember them, but that's good because they don't appear in your.

[01:24:32] Social media anywhere and they don't appear anywhere else other than your secured encrypted one password fault. Thanks for being with us. I appreciate you guys listening and you can find all of this. I'm going to turn all of these and did a little mini courses here over the next few weeks, and there's only one way you're going to get it.

[01:24:55] And that is by being on my email list. Craig peterson.com/subscribe. Go there right now. Craig peterson.com/subscribe.

View Details

How Many Times Per Week Are You Being Cyber Attacked? From Where? How? Why?

We've got a new study out showing that North American organizations, businesses, and others, are being hit with an average of 497 cyber attacks per week, right here in the good old USA.

[Following is an automated transcript]

This is a study by checkpoint software technologies. Checkpoint, I used, oh my gosh. It would have been back in the nineties back then. They were one of the very first genuine firewall companies. And it was a system that I was putting in place for my friends over at troopers. I think it was New England telephone. It might've been Verizon by then. I can't even remember, man.

[00:00:41] It's been a little while, but it was, a system we were using in front of this massive system that I designed, I made the largest internet property in the world. At that time called big yellow. It morphed into super pages. It might be familiar with. But it was me and my team that did everything. We built the data center out.

[00:01:05] We wrote all of the software. Of course they provided all of the yellow pages type listing so we can put it all in. And we brought it up online and we were concerned. Well, first of all, You know, I've been doing cyber security now for over 30 years. And at this point in time, they wanted something a little more than my home grown firewall.

[00:01:29] Cause I had designed and written one in order to protect this huge asset that was bringing in tens of millions of dollars a year to the phone company. So they said, Hey, listen, let's go ahead and we'll use checkpoint and get things going. We did, it was on a little, I remember it was a sun workstation. If you remember those back in the.

[00:01:52] And it worked pretty well. I learned how to use it and played with it. And that was my first foray into kind of what the rest of the world had started doing, this checkpoint software, but they've continued on, they make some great firewalls and other intrusions type stuff, detection and blocking, you know, already that I am a big fan, at least on the bigger end.

[00:02:17] You know, today in this day and age, I would absolutely use. The Cisco stuff and the higher end Cisco stuff that all ties together. It doesn't just have the fire power firewall, but it has everything in behind, because in this day and age, you've got to look at everything that's happening, even if you're a home user.

[00:02:37] And this number really gets everybody concerned. Home users and business users is. Businesses are definitely under bigger attacks than home users are. And particularly when we're talking about businesses, particularly the bigger businesses, the ones that have a huge budget that are going to be able to go out and pay up, you know, a million, $10 million ransom.

[00:03:05] Those are the ones that they're after and this analysis. Point software who does see some of those attacks coming in, showed some very disturbing changes. First of all, huge increases in the number of cyber attacks and the number of successful ransoms that have been going on. And we're going to talk a little bit later, too, about where some of those attacks are coming from, and the reason behind those attack.

[00:03:36] According to them right now, the average number of weekly attacks on organizations globally. So far, this year is 40% higher than the average before March, 2020. And of course that's when the first lockdowns went into effect and people started working from home in the U S the. Increase in the number of attacks on an organizations is even higher at 53%.

[00:04:07] Now you might ask yourself why, why would the U S be attacked more? I know you guys are the best and brightest, and I bet it, I don't even need to say this because you can figure this out yourself, but the us is where the money is. And so that's why they're doing it. And we had president Biden come out and say, Hey, don't attack the.

[00:04:27] well, some of those sectors are under khaki for more after he said that then before, right. It's like giving a list to a bad guy. Yeah. I'm going to be gone for a month in June and yeah, there won't be anybody there. And the here's the code to my alarm. Right. You're you're just inviting disaster checkpoints.

[00:04:49] Also showing that there were more. Average weekly attacks in September 21. That's this September than any time since January, 2020. In fact, they're saying 870 attacks per organization globally per week. The checkpoint counted in September was double the average in March, 2020. It's kind of funny, right?

[00:05:14] It's kind of like a before COVID after COVID or before the Wu Han virus and after the Wu Han virus, however, we might want to know. So there are a lot of attacks going on. Volume is pretty high in a lot of different countries. You've heard me say before some of my clients I've seen attack multiple times a second, so let's take a second and define the attack because being scanned.

[00:05:40] I kind of an attack, the looking to see, oh, where is there a device? Oh, okay. Here's a device. So there might be a home router. It might be your firewall or your router at the business. And then what it'll do is, okay, I've got an address now I know is responding, which by the way is a reason. The, we always configure these devices to not respond to these types of things.

[00:06:04] And then what they'll do is they will try and identify it. So they'll try and go into the control page, which is why you should never have when. Configuration enabled on any of your routers or firewalls, because they're going to come in and identify you just on that because all of a sudden them brag about what version of the software you're running.

[00:06:26] And then if it's responding to that, they will try and use a password. That is known to be the default for that device. So in a lot of these devices, the username is admin and the password is admin. So they try it and now off they go, they're running. Some of these guys will even go the next step and we'll replace the software.

[00:06:52] In your router or firewall, they will replace it so that it now directs you through them, everything you are doing through them. So they can start to gather information. And that's why you want to make sure that the SSL slash TLS. That encryption is in place on the website. You're going to, so if you go to Craig peterson.com right now, my website, I'm going to go there myself.

[00:07:22] So if you go to Craig peterson.com, you're going to notice that first of all, it's going to redirect you to my secure site and it doesn't really matter. You won't see it. Okay. But you are there because if he. Typically at the left side of that URL bar where it says, Craig peterson.com. You'll see, there's a little lock.

[00:07:44] So if you click that lock, it says connection is secure. Now there's a lot more we could go into here. But the main idea is even if your data is being routed through China or. Both of which have happened before many tens of thousands, hundreds of thousands of time times. I'm not even sure of the number now.

[00:08:06] It's huge. Even if your data is being routed through them, the odds are, they're not going to see anything. That you are doing on the Craig Peterson site. Now, of course you go into my site, you're going to be reading up on some of the cybersecurity stuff you can do. Right. The outages what's happened in the news.

[00:08:27] You can do all of that sort of thing on my side, kind of, who cares, right? Um, but really what you care about is the bank, but it's the same thing with the bank. And I knew mine was going to be up there. And when everybody just check it out anyway, so. So the bad guys, then do this scan. They find a web page log in.

[00:08:47] They try the default log in. If it works, the Le the least they will do is change. What are called your DNS settings. That's bad because changing your DNS settings now opens you up to another type of attack, which is they can go ahead. And when your browser says, I want to go to bank of america.com. It is in fact, going to go out to the internet, say is bank of America, the bad guys.

[00:09:18] Did, and they will give you their bank of America site that looks like bank of America feels like bank of America. And all they're doing is waiting for you to type into your bank of America, username and password, and then they might redirect you to the. But at that point, they've got you. So there are some solutions to that one as well, and Firefox has some good solutions.

[00:09:44] There are others out there and you had to have those that are in the works, but this is just an incredible number. So here's what I'm doing, right. I have been working for weeks on trying to figure out how can I help the most people. And obviously I needed to keep the lights on, right? I've got to pay for my food and gas and stuff, but what I'm planning on doing and what we've sketched out.

[00:10:10] In fact, just this week, we got kind of our final sketch out of it is we're going to go ahead and have a success path for cyber security. All of the basic steps on that success path will be. Okay. So it will be training that is absolutely 100% free. And I'll do a deeper dive into some of these things that I'm doing that I'm doing right now here on the radio, because you can't see my desktop.

[00:10:40] It's hard to do a deep dive and it's open to anybody, right? If you're a home user or if you're a business user, all of the stuff on that free. Is going to help you out dramatically. And then after that, then there'll be some paid stuff like a membership site. And then obviously done for you. If the cybersecurity stuff is just stuff that you don't want to deal with, you don't have the time to deal with.

[00:11:05] You don't want to learn, because believe me, this is something that's taken me decades to learn and it's changing almost every day. So I understand if you don't want to learn it to. That is the other option. I'll give you, which is done for you, which we've been doing now for over 20, 30 years. Stick around.

[00:11:25] We'll

[00:11:25] So which sectors are economy are being hacked? I mentioned that in the last segment, but yeah, there are some problems and the sectors that president Biden lined out laid out are, are the ones that are under, even more attack after his message.

[00:11:42] 497 cyber attacks per week. On average here in the US, that is a lot of attacks. And we started explaining what that meant so that we talked about the scan attacks that are automated and some person may get involved at some point, but the automated attacks can be pretty darn automated. Many of them are just trying to figure out who you are.

[00:12:09] So, if it shows up, when they do that little scan that you're using a router that was provided by your ISP, that's a big hint that you are just a small guy of some sort, although I'm shocked at how many bigger businesses that should have their own router, a good router, right. A good Cisco router and a really good next generation firewall.

[00:12:34] I'm shocked at how many don't have those things in place, but when they do this, That's the first cut. So if you're a little guy, they'll probably just try and reflash your router. In other words, reprogram it and change it so that they can start monitoring what you're doing and maybe grab some information from.

[00:12:56] Pretty simple. If you are someone that looks like you're more of a target, so they connect to your router and let's say, it's a great one. Let's say it's a Cisco router firewall or Palo Alto, or one of those other big companies out there that have some really good products. Uh, at that point, they're going to look at it and say, oh, well, okay.

[00:13:18] So this might be a good organization, but when they get. To it again, if when access has turned on wide area, access has turned down, that router is likely to say, this is the property of, uh, Covina hospital or whatever it might be, you know? And any access is disallowed authorized access only. Well, now they know.

[00:13:42] Who it is. And it's easy enough just to do a reverse lookup on that address. Give me an address anywhere on the internet. And I can tell you pretty much where it is, whose it is and what it's being used for. So if that's what they do say they have these automated systems looking for this stuff it's found.

[00:14:02] So now they'll try a few things. One of the first things they try nowadays is what's called an RDP attack. This is a remote attack. Are you using RDP to connect to your business? Right? A lot of people are, especially after the lockdown, this Microsoft. Desktop protocol has some serious bugs that have been known for years.

[00:14:25] Surprisingly to me, some 60% of businesses have not applied those patches that have been available for going on two years. So what then button bad guys will do next. They say, oh, is there a remote desktop access? Cause there probably is most smaller businesses particularly use that the big businesses have a little bit more expensive, not really much more expensive, but much better stuff.

[00:14:51] You know, like the Cisco AnyConnect or there's a few other good products out there. So they're going to say, oh, well, okay. Let's try and hack in again. Automate. It's automated. No one has to do anything. So it says, okay, let's see if they patch, let's try and break in a ha I can get in and I can get into this particular machine.

[00:15:14] Now there's another way that they can get into their moat desktop. And this apparently has been used for some of the bigger hacks you've heard about recently. So the other way they get in is through credential stuff. What that is is Hey, uh, there are right now some 10 billion records out on the dark web of people's names, email addresses, passwords, and other information.

[00:15:43] So, what they'll do is they'll say, oh, well this is Covina hospital and it looks it up backwards and it says, okay, so that's Covina hospital.org. I have no idea if there even is a Gavino hospital, by the way, and will come back and say, okay, great. So now let's look at our database of hacked accounts. Oh, okay.

[00:16:04] I see this Covina hospital.org email address with a password. So at that point they just try and stuff. Can we get in using that username and password that we stole off of another website. So you see why it's so important to be using something like one password, a password generator, different passwords on every site, different usernames on every site, et cetera, et cetera.

[00:16:29] Right. It gets pretty important per te darn quickly. So now that they're in, they're going to start going sideways and we call that east west in the biz. And so they're on a machine. They will see what they can find on that machine. This is where usually a person gets some. And it depends in historically it's been about six days on average that they spend looking around inside your network.

[00:17:00] So they look around and they find, oh yeah, great. Here we go. Yep. Uh, we found this, we found that. Oh, and there's these file server mounts. Yeah. These SMB shares the, you know, the Y drive the G drive, whatever you might call it. So they start gaining through those and then they start looking for our other machines on the network that are compromised.

[00:17:23] It gets to be really bad, very, very fast. And then they'll often leave behind some form of ransomware and also extortion, where that extort you additionally, for the threat of releasing your data. So there, there are many other ways they're not going to get into them all today, but that's what we're talking about.

[00:17:43] Mirman, we're talking about the 500 cyber attacks per week against the average. North American company. So we have seen some industry sectors that are more heavily targeted than others. Education and research saw an 60% increase in attacks. So their education and I've tried to help out some of the schools, but because of the way the budgets work and the lowest bidder and everything else, they, they end up with equipment.

[00:18:17] That's just totally misconfigured. It's just shocking to me. Right. They buy them from one of these big box online places. Yeah. I need a, a Cisco 10, 10. And I need some help in configuring it and all, yeah, no problems or we'll help you. And then they sell it to the school, the school installs it, and it is so misconfigured.

[00:18:38] It provides zero protection, uh, almost zero, right. It provides almost no protection at all. And doesn't even use the advanced features that they paid for. Right. That's why, again, don't buy from these big box. Guys just don't do it. You need more value than they can possibly provide you with. So schools, 1500 attacks per week research companies, again, 1500 attacks per week, government and military.

[00:19:10] Entities about 1100 weekly attacks. Okay. That's the next, most highest attacked. Okay. Uh, health care organizations, 752 attacks per week on average. Or in this case, it's a 55% increase from last year. So it isn't just checkpoints data that I've been quoting here. That, that gives us that picture. There are a lot of others out there IBM's has Verizon's has all of these main guys, and of course in the end, They've got these huge ransoms to deal with.

[00:19:50] Hey, in New Hampshire, one of the small towns just got nailed. They had millions of dollars stolen, and that was just through an email trick that they played in. K again. I T people, um, I I've been thinking about maybe I should put together some sort of coaching for them and coaching for the cybersecurity people, even because there's so much more that you need to know, then you might know, anyways, if you're interested in any of this.

[00:20:22] Visit me online. Craig peterson.com/subscribe. You will get my weekly newsletter, all of my show notes, and you'll find out about these various trainings and I keep holding. In fact, there's one in most of the newsletters. Craig peterson.com. Craig Peterson, S O n.com. Stick around.

[00:20:43] We've been talking about the types of attacks that are coming against us. Most organizations here in north America are seeing 500 cyber attacks a week, some as many as 1500. Now, where are they coming from?

[00:21:00] Whether they're scanning attacks, whether they're going deeper into our networks and into our systems who are the bad guys and what are they doing? Microsoft also has a report that they've been generating, looking at what they consider to be the source of the attacks. Now we know a lot of the reasons I'm going to talk about that too, but the source is an interesting way to look at.

[00:21:29] Because the source can also help you understand the reason for the attacks. So according to dark reading, this is kind of an insider, a website you're welcome to go to, but it gets pretty darn deep sometimes, but they are showing this stats from Microsoft, which you can find online that in the last year rush.

[00:21:53] Has been the source of 58% of the cyber cat tax. Isn't that amazing now it's not just the cyber attacks. I, I need to clarify this. It's the nation state cyber tech. So what's a nature's nation state cyber attack versus I don't know, a regular cyber attack. Well, the bottom line is a nation state cyber attack is an attack that's occurring and is actually coordinated and run by and on behalf of a nation state.

[00:22:31] Uh, So Russia at 58% of all nation state attacks is followed by North Korea, 23% Iran, 11% China, 8%. Now you probably would have thought that China would be. Right up there on that list, but Russia has 50% more of the nation state cyber attacks coming from them than from China. And then after China is south Vietnam, Viet, or I should say South Korea, Vietnam, and Turkey, and they all have less than 1%.

[00:23:14] Now, this is this new pool of data that Microsoft has been analyzing. And it's part of this year's Microsoft digital defense report, and they're highlighting the trends in the nation state threat cyber activity hybrid workforce security. Disinformation and your internet of things, operational technology and supply chain security.

[00:23:35] In other words, the whole gambit before, before all of this, now the data is also showing that the Russian nation state attacks are increasingly effective, calming from about a 21% successful compromise rate last year to 32%. So basically 50% better this year at effectiveness there, Russians are also targeting more government agencies for intelligence gathering.

[00:24:10] So that jumped from 3% of their victims last year to 53%. This. And the Russian nation state actors are primarily targeting guests who us, right? The United States, Ukraine and the United Kingdom. Now this is all according to the Microsoft data. So why has Russia been attacking us? Why is China been attacking us and why the change this.

[00:24:38] Well, Russia has been attacking us primarily to rent some us it's a cash cow for them just like oil and gas. They are making crazy money. Now that president Biden has made us dependent on foreign oil supplies. It's just insanity and even dependent on. Gas coming from other places. Well guess where the number one source of gases now for Europe and oil it's Russia.

[00:25:08] So we are no longer going to be selling to Europe. Russia is so they're going to be making a lot of money off of. But before then they were actually counted on ransomware to help fund the Russian federal government, as well as of course, these Russian oligarchs, these people who are incredibly rich that have a substantial influence on the government.

[00:25:33] Don't if you're wondering who they might be, just think of people like, oh, I don't know. Bill gates and, uh, w who are on the, some of the other big guys, you know, Tim cook, uh, Amazon's Jeff bayzos Elon Musk, right? Those are by my definition and looking it up in the dictionary, they are all a. They get exemptions to laws.

[00:25:58] They get laws passed that, protect them. In fact, most of regulations actually protect these big companies and hurt small companies. So I would call them oligarchs and that's the same sort of thing in Russia in Russia. Okay. They probably have a little bit more underhanded stuff than these guys here do, but that's what Russia has been.

[00:26:21] China has been continually going after our national secrets, national defense, the largest database of DNA of Americans DNA, of course, is that unique key. If you will building block for all of us, that's what DNA is. And the largest database of all of that uniquely identifying information is in. China stole from the office of personnel management records of a federal employees, their secret clearance, all of their background check information who was spoken with, what did they have to say?

[00:27:03] And on and on. So China has been interested in infiltrating our businesses that provide things to the military and the military themselves and the federal state, and even the local governments that's who they've been targeting. And that's why there's 8% number might seem small. Although, as I just mentioned this year, Russia moved, moved dramatically.

[00:27:30] They used to be about 3% of their attacks or against the government agencies. And now it's 53%. So Russia. And China are going after our national secrets and they can use them in a cold war, which as I've said, I think the first shots of the third world war have been fired. And frankly, they're all cyber, it's all online and Russia.

[00:27:57] Isn't the only nation state actor who's changing its approaches here as espionage is the most common goal amongst all nation state groups as of this year. Tivity of hackers reveals different motivations in Iran, which quadrupled its targeting of Israel. Surprise, surprise. Over the last year. And Iran has been launching destructive attacks, things that will destroy power, power plants, et cetera, and North Korea, which is targeting cryptocurrency companies for profit.

[00:28:29] So they're stealing these various crypto coins again, funding their government. So it's, it's a problem. Absolute problem. Government sectors are some of the most targeted 48%. These NGOs non-government organizations that act kind of a quasi government functions and think tanks are 31%. Uh, and Microsoft, by the way, has been alerting customers of nation, state attack, attack attempts.

[00:29:01] Guess how many this year that they had to warn about 20,500 times in the past three years. So that's a lot and Microsoft is not a company that's been out there at the front lines. It never has been it's in behind. So to have them come out and say, this is. And okay, by the way, your stolen username and password run for a buck per thousand, and it's only gonna take you hundreds of hours to get it all cleared up.

[00:29:32] Isn't that nice spear fishing for a hire can cost a hundred to a thousand dollars per successful account takeover and denial of service attacks are cheap from protected sites, roughly $300. Per month. And if you want to be ransomware king, it's only going to cost you 66 bucks upfront 30% of the profit.

[00:29:54] Okay. Craziness. Hey, visit me online. Sign up Craig, peter.com/subscribe.

[00:30:03] I had an interesting mastermind meeting this week. There's six of us. We're all business owners and it opened my eyes pretty dramatically because one of the members got hacked, but that's not what I really want to emphasize.

[00:30:20] This whole cybersecurity thing gets pretty complicated, pretty quickly. And a friend of mine who is in one of my mastermind groups had a real problem. And the here's here's what went on. We'll call him Walt for back of a letter, lack of a better name since that is his name.

[00:30:40] And he doesn't mind me sharing this with you. Walt has a very small business that he and his wife run, and they have a couple of contractors that help out with some things, but his business is very reliant on advertising and primarily what he does is Facebook advertising. Now I've been talking for two years, I think in this mastermind group about cyber security and the fact that everyone needs good cyber security.

[00:31:13] And he always just kind of pole hum to, uh, wow. You know, and it's just too complicated for me. I got to thinking for a, you know, a bit, really a few weeks, what does he mean to complicated? Cause there's some basic things you can do. So this week on Tuesday, I was on our mastermind groups meeting and I explained, okay, so here's what happened to Walt.

[00:31:42] He had $40,000 stolen, which by the way, it's a lot of money for a teeny tiny husband wife company. And. Uh, well, here's what we did. He, we helped them. We got the FBI involved and, you know, with our direct ties, cause we work with them on certain types of cases and he got back every dime, which is just totally unheard of.

[00:32:06] But um, without going into all of the details there, I spent a problem. 1520 minutes with the whole group and the mastermind explaining the basics of cyber security. And that really kind of woke me up, frankly, because of their responses. Now these are all small business owners and so they're making pretty decent money.

[00:32:31] In fact, every one of them and they all have some contractors and some employees all except for Walt and his wife, they had just have contractors and. I had two completely different responses from two members of this group that no. Let me tell you this was really eye opening for me. And this is why you might've heard me in the first segment talking about this, but this is why I have really changed my view of this stuff, this cybersecurity stuff, because I explained.

[00:33:08] If you're using things like Norton antivirus or McAfee, antivirus, or really any of them, even the built-in Microsoft defender this year, those standard antivirus system. I have only been able to catch about 30% of the malware out there, 30%, you know, that's like having a house and you've got a security guard posted out front.

[00:33:39] He's armed, he's ready to fight. And yet all of your windows are open and all of your doors are unlocked. And all someone has to do is crawl in the side window because that guy that's posted up front, he's not going to be able to stop. So 30% effectiveness. And of course, Walt had all of the basic stuff.

[00:33:59] He thought he was good enough. It's not worth spending time or money doing any of this. And of course it turned out to be well worth the time and money if he had done it. But he has a friend who has contacts and, and made things happen for him. So I guess he's kind of, kind of lucky in that regard, but I explained that and I said, do you know the, the way you.

[00:34:21] To go. If you're a small business, it's about $997 a month for a small business, with a handful of employees to get the type of security you really need. There's going to catch. 90 something 98%. Maybe if, if things go well of the stuff going on, in other words, you don't just have an armed guard at the front door.

[00:34:46] You've got all the windows closed and blocked and the doors closed and locked as well. So yeah, somebody can still get in, but they got to really want to get in and risk getting caught. So that's kind of the analogy that I used now. One of the members of my. Of my mastermind thought, well, okay. Cause you're just being Frank with me.

[00:35:09] Right? We're all friends. She said, well, initially I thought, oh Craig, I'm going to have to have you help out with stuff here. Cause my, you know, I'm concerned about my security. I make some good money. Uh, she's the one that has employee. She has a million dollar plus a year business and she wants to keep it safe.

[00:35:26] But then she. Uh, you know, but, but you know, you were talking about all of this Norton and stuff and that it doesn't work. So I, I just, I don't have any hope. And that's when the another member jumped in and this other member said, well, Uh, oh, that's not what I got at all. I got the, the normal off the shelf stuff that you buy that you're going to get from Amazon, or you're going to get from PC connection or wherever that stuff is not going to work, but there is stuff that does, but it's only professional stuff.

[00:36:02] You can only get it from professionals that are trained in certified. Which is the right message. Right. That was the message I was trying to relay. Yeah. Don't try and do it yourself because you can't even get the right tools that you need. That is frankly a problem. So that really got me to think. In, in a very big way, because here are two people that have heard me talk about cybersecurity and their eyes probably glazed over, but now their eyes, I know at least one of these ladies definitely glazed over.

[00:36:36] So I've come to the realization that sometimes I. A little too deep into things. And although I can explain it quite well to many people, sometimes people glaze over and I get emails from you guys saying kind of the same thing. I really appreciate it. I don't understand a lot of what you're saying, Craig, but thanks for being there.

[00:36:59] Listen to you every week here on the radio. Uh, then that's good. That's reassuring, but now I've come to realize a few things. One is. The I've got to be a lot clearer in my messaging, because even when talking to my friends, it is a little bit overwhelming for them sometimes. Right. And then the next thing is everybody needs help because you're being lied to.

[00:37:29] Right. How are people getting ransomware? If the stuff that they're buying work. Maybe it's just me, but I think there's a disconnect there. So a lot of you guys have gone out and you've hired people and I want to spend just a few minutes right now, going through some red flags that you need to be looking out for in vendor security assessment.

[00:37:56] Now I'm putting one together. As well, right yet another one. Uh, and what I'm trying to do is help you out, right? This is not as sales tool. It is trying to help you figure out where you're at. I'm putting together a webinar that I'm going to be holding these what I'm calling bootcamps, where I go through and show you exactly how to do the basic steps that you need to do in order to be safe on.

[00:38:25] Okay. If an online, all that means is your, is plugged in, right. Okay. It doesn't mean you're going out and doing a lot of stuff out there on the internet just means it's connected. So those are going to be coming out. I will send an email out as soon as all of that. Stuff's ready. Cause. Absolutely free. And these assessments, I have the basic one that you can do yourself.

[00:38:47] It's a self-assessment. And then I have the more advanced ones that I do that are five grand. Okay. So you've got to be a decent sized business for this to make sense where we look for all of the security problem. On all of your computers and your networks, and then give you a list of things you need to do and how to do them.

[00:39:10] Okay. So it's well worth it for them, but if you're a very small company and you're trying to do some of this yourself, I want to help you. So that's what these boot camps are going to be all over. And also what the scorecard is going to be all about. So that's coming up, but here are some good red flags and an assessment.

[00:39:30] I found this again on dark reading. This is kind of an insider website for those of us in the cybersecurity business, but, um, How can you verify the information that vendors are giving you about their own cybersecurity posture? We've heard in the news and I've talked about them all year, this year, and for years past.

[00:39:56] That are we're vendors can be our worst nightmare because some of these hacks come in through our vendors. So you've got yourself, a cybersecurity company. How do you know if they are really telling you the truth? And man, is that hard for you to know? Right. You're going to ask him questions and the salesmen are going to say, oh yeah, yeah, yeah.

[00:40:21] That's why we don't have salesmen. Right. We have engineers. You talk to me, you might talk to my son or my daughter, people who have been doing this with me, who I have trained and helped out. So this guy who wrote the article and there's this on attributed, I don't see an attribution on here on this page.

[00:40:41] I definitely want to give him, probably I heard is John Babinec wrote this thing and he is a principle threat hunters. What he calls himself over at net and rich. So he says, here's what you got to do. And if you're trying to be cost-effective, he puts it in. What I call an ed month clause. And one of these days I'll tell you that story, but he calls it a validity check question so that an honest vendor would tell you, no, they don't do X and give you a good reason why they don't like it's not cost effective.

[00:41:17] It's outside of a reasonable risk model. Does that make sense to you? So when you're trying to evaluate a vendor, who's going to be doing your cyber security put in one of these validity checks put in one of these questions. It doesn't really matter to you, but it's something that would be very hard for one of these cybersecurity companies to do.

[00:41:42] And maybe it doesn't fit the risk model that you have. I think it's just absolutely brilliant. Probably one of the better ways when you're trying to evaluate an MSSP as cybersecurity managed or otherwise provider stick in something like that. So you have a red flag that just stands out for you. All right.

[00:42:04] Make sure you are registered online. Craig Peter sohn.com/subscribe. So you can find out about all of these trainings coming up.

[00:42:17] If you've never heard of the Carrington event, I really hope, frankly, I really, really do hope we never have to live through one of these. Again, there is a warning out there right now about an internet apocalypse that could happen because of the Sun.

[00:42:34] Solar storms are something that happens really kind of all of the time. The sun goes through solar cycles. About every seven years, there are longer cycles as well. You might know. I have an advanced class amateur radio license I've had for a long time, and we rely a lot when we're dealing with short wave on the solar cycle.

[00:42:59] You see what happens is that the sun charges, the atmosphere. You see that if you've ever seen the Northern light, that is. Part of the Sunzi missions, hitting our magnetic field and kind of getting sucked into the core of the earth, if you will, as they get caught in that field. And the more charged the atmosphere is, the more bounce you get.

[00:43:24] That's what we call it bounce. And the reason us hams have all these different frequencies to use is because of the battle. We can go different frequencies with different distances, I should say, using different frequencies. So think about it right now. You've got the earth and I want to talk from Boston to Chicago.

[00:43:47] For instance, I know about how many miles it is, and I have to figure out in the ionosphere up in the higher levels of the atmosphere, what frequency. To use in order to go up into the atmosphere, bounce back, and then hit Chicago. That's the idea. It's not quite as simple or as complex in some ways, as it sounds, a lot of people just try different frequencies and a lot of hams just sit there, waiting for anybody anywhere to talk to, particularly if they are.

[00:44:20] It's really quite fun. Now what we're worried about, isn't so much just the regular solar activity. We get worried when the sun spots increase. Now, the solar cycle is what has primary image. On the temperature on earth. So no matter what, you might've heard that isn't your gas, guzzling car or a diesel truck that causes the Earth's temperature to change.

[00:44:49] Remember the only constant when it comes to the Earth's temperature has been changed over the millions of years. We had periods where the earth was much warmer than it is now had more common that carbon dioxide in the atmosphere than it does now had less. In fact, right now we are at one of the lowest levels of carbon dioxide in the atmosphere in earth, long, long.

[00:45:15] So the sun, if you might remember, comes up in the morning, warms things up, right? And then it cools down. When the sun disappears at nighttime, it has a huge impact. It's almost exclusively the impact for our temperatures. If there's other things too, for instance, eruption can spew all to hold a lot of carbon dioxide.

[00:45:40] In fact, just one, just Mount St. Helens wanted erupted, put more carbon dioxide into the atmosphere than man has throughout our entire existence. Just to give you an idea, right? So these alarms that are out there, uh, you know, come on, people. Really, and now we're seeing that in, uh, this last year we had a 30% increase in the ice cap up in the, in, up in the north, up in Northern Canada, around the polls.

[00:46:12] Uh, we also had some of these glaciers growing. It was so funny. I saw an article this year, or excuse me, this week that was showing a sign that was at one of our national parks. And it said this glacier will have disappeared by 2020. Of course it hasn't disappeared. In fact, it has grown now and it's past 2020.

[00:46:34] Anyhow, the sun has a huge impact on us in so many ways. And one of the ways is. Well, something called a coronal mass ejection. This is seriously charged particles. That tend to be very, very directional. So when, when it happens, when there's one of these CMS coronal, mass ejections, it's not just sending it out all the way around the sun everywhere.

[00:47:02] It's really rather concentrated in one. One particular spot. Now we just missed one not too long ago. And let me see if I can find it here. Just mast, a cm E near miss. Here we go. There a solar super storm in July, 2012, and it was a very, very close shave that we had most newspapers didn't mention it, but this could have been.

[00:47:33] AB absolutely incredible. We'd be picking up the pieces for the next 50 years. Yeah. Five, zero years from this one particular storm. And what happens is these, these solar flares, if you will, are very, very extreme, they CME. You're talking about x-rays extreme UV, ultraviolet radiation, reaching the earth at the speed of light ionizes, the upper layers of atmosphere.

[00:48:02] When that happens, by the way, it hurts our communications, but it can also have these massive effects where it burns out saddle. And then causes radio blackouts, GPS, navigation problems. Think about what happened up in Quebec. So let me just look at this call back, uh, hit with an E and yeah, here we go. And March 13th, 1989.

[00:48:33] Here we go. Here's another one. Now I remembered. And this is where Quill back got nailed. I'm looking at a picture here, which is, uh, looking at the United States and Canada from the sky and where the light is. And you can see Quebec is just completely black, but they have this massive electrical blackout and it's becomes.

[00:48:57] Of this solar storm. Now they, these storms that I said are quite directional, depending on where it hits and when it hits things can get very, very bad. This particular storm back in 1989 was so strong. We got to see their Rora Borealis, the Northern lights as far south, as Florida and cue. Isn't that something, when we go back further in time to this Carrington event that I mentioned, you could see the Northern lights at the equals.

[00:49:35] Absolutely amazing. Now the problem with all of this is we've never really had an internet up online. Like we have today when we had one of the storms hit. And guess what we're about to go into right now, we're going into an area or a time where the sun's going to be more active, certainly on this, this 11 year cycle and possibly another bigger cycle too, that we don't really know much about.

[00:50:07] But when this hit us back in the 1850s, what we saw was a, uh, a. Telegraph system that was brought to its knees. Our telegraphs were burned out. Some of the Telegraph buildings were lit. They caught on fire because of the charges coming in, people who were working the telegraphs, who are near them at the time, got electric shocks or worse than that.

[00:50:34] Okay. 1859 massive Carrington event compass needles were swinging wildly. The Aurora Borealis was visible in Columbia. It's just amazing. So that was a severe storm. A moderate severity storm was the one that hit in Quebec here, knocked out Quebec, uh, electric. Nine hour blackout on Northeast Canada. What we think would happen if we had another Carrington event, something that happened to 150 years ago is that we would lose power on a massive scale.

[00:51:13] So that's one thing that would happen. And these massive transformers that would likely get burned out are only made in China and they're made on demand. Nobody has an inventory. So it would be at least six months before most of the country would get power back. Can you believe that that would be just terrible and we would also lose internet connectivity.

[00:51:39] In fact, the thinking that we could lose internet connectivity with something much less than a severe storm, maybe if the Quebec power grid solar, a massive objection here. Maybe if that had happened, when. The internet was up. They might have burned out internet in the area and maybe further. So what we're worried about is if it hits us, we're going to lose power.

[00:52:07] We're going to lose transformers on the transmission lines and other places we're going to lose satellites and that's going to affect our GPS communication. We're going to lose radio communication, and even the undersea cables, even though they're now no longer. Regular copper cables. It's now being carried of course, by light in pieces of glass.

[00:52:32] The, those cables need to have repeaters about every 15 miles or so under underwater. So the power is provided by. Copper cables or maybe some other sort of power. So these undersea cables, they're only grounded at extensive intervals, like hundreds or thousands of kilometers apart. So there's going to be a lot of vulnerable components.

[00:52:59] This is all a major problem. We don't know when the next massive. Solar storm is going to happen. These coronal mass ejections. We do know they do happen from time to time. And we do know it's the luck of the draw and we are starting to enter another solar cycle. So be prepared, everything. Of course, you're listening to Craig Peterson, cybersecurity strategist.

[00:53:28] If you'd like to find out more and what you can do, just visit Craig peterson.com and subscribe to my weekly show notes.

[00:53:39] Google's got a new admission and Forbes magazine has an article by Zach Dorfman about it. And he's saying you should delete Google Chrome now after Google's newest tracking admission. So here we go.

[00:53:55] Google's web browser. Right? It's been the thing for people to use Google Chrome for many years, it's been the fastest. Yeah, not always people kind of leapfrog it every once in a while, but it has become quite a standard. Initially Microsoft is trying to be the standard with their terrible browser and yeah, I to Exploder, which was really, really bad and they have finally completely and totally shot it in the head.

[00:54:29] Good move there on their part. In fact, they even got rid of their own browser, Microsoft edge. They shot that one in. They had to, I know I can hear you right now saying, oh, Craig, I don't know. I just use edge browser earlier today. Yeah. But guess what? It isn't edge browser. It's actually Google Chrome. The Microsoft has rebranded.

[00:54:52] You see the guts to Google Chrome are available as what's called an open source project. It's called chromium. And that allows you to take it and then build whatever you want on top of. No, that's really great. And by the way, Apple's web kit, Kat is another thing that many people build browsers on top of and is part of many of these browsers we're talking about right now, the biggest problem with the Google Chrome.

[00:55:22] Is they released it so they could track you, how does Google make its money? Well, it makes us money through selling advertising primarily. And how does it sell advertising if it doesn't know much or anything about you? So they came out with the Google Chrome browser is kind of a standard browser, which is a great.

[00:55:43] Because Microsoft, of course, is very well known for not bothering to follow standards and say what they have is the actual standard and ignoring everybody else. Yeah. Yeah. I'm picking on Microsoft. They definitely deserve it. Well, there is what is being called here in Forbes magazine, a shocking new tracking admission from.

[00:56:05] One that has not yet made headlines. And there are about what 2.6 billion users of Google's Chrome worldwide. And this is probably going to surprise you and it's frankly, Pretty nasty and it's, I think a genuine reason to stop using it. Now, as you probably know, I have stopped using Chrome almost entirely.

[00:56:31] I use it when I have to train people on Chrome. I use it when I'm testing software. There's a number of times I use it, but I don't use. The reality is the Chrome is an absolute terror. When it comes to privacy and security, it has fallen way behind its rivals in doing that. If you have an iPhone or an iPad or a Mac, and you're using safari, apple has gone a long ways to help secure your.

[00:57:09] Well, that's not true with Chrome. In fact, it's not protecting you from tracking and Dave up data harvesting. And what Google has done is they've said, okay, well, we're going to get these nasty third party cookies out of the whole equation. We're not going to do that anymore. And what they were planning on doing is instead of knowing everything specifically.

[00:57:34] You they'd be able to put you in a bucket. So they'd say, okay, well you are a 40 year old female and you are like driving fast cars and you have some kids with a grandkid on the way, and you like dogs, not cats, right? So that's a bucket of people that may be a few hundred or maybe up to a thousand. As opposed to right now where they can tell everything about you.

[00:58:04] And so they were selling that as a real advantage because they're not tracking you individually anymore. No, we're putting you in a bucket. Well, it's the same thing. Right. And in fact, it's easier for Google to put you in a bucket then to track everything about you and try and make assumptions. And it's easier for people who are trying to buy ads to place in front of you.

[00:58:28] It's easier for them to not have to kind of reverse engineer all of the data the Google has gathered in instead of. To send this ad to people that are in this bucket and then that bucket. Okay. It makes sense to you, but I, as it turns out here, Google has even postponed of that. All right. They really have, they're the Google's kind of hiding.

[00:58:54] It's really what's going on out there. Uh, they are trying to figure out what they should do, why they should do it, how they should do it, but it's, it's going to be a problem. This is a bad habit. The Google has to break and just like any, anybody that's been addicted to something it's going to take a long time.

[00:59:16] They're going to go through some serious jitters. So Firefox is one of the alternatives and to Google Chrome. And it's actually a very good one. It is a browser that I use. I don't agree with some of the stuff that Mozilla and Firefox does, but again, right. Nobody agrees on everything. Here's a quote from them.

[00:59:38] Ubiquitous surveillance harms individually. And society Chrome is the only major browser that does not offer meaningful protection against cross cross site tracking and Chrome will continue to leave users unprotected. And then it goes on here because. Uh, Google response to that. And they admit that this massive web tracking out of hand and it's resulted in, this is a quote from Google and erosion of trust, where 72% of people feel that almost all of what they do online is being.

[01:00:19] By advertisers, technology firms or others, 81% say the potential risks from data collection outweigh the benefit by the way, the people are wrong. 72% that feel almost all of what they do on online is being tracked. No, no. The answer is 100% of what you do is probably being tracked in some way online.

[01:00:41] Even these VPN servers and systems that say that they don't do log. Do track you take a look at proton mail just last week. Proton mail it's in Switzerland. Their servers are in Switzerland. A whole claim to fame is, Hey, it's all encrypted. We keep it safe. We don't do logging. We don't do tracking, uh, guess what they handed over the IP addresses of some of the users to a foreign government.

[01:01:10] So how can you do that? If you're not logging, if you're not tracking. Yeah, right. They are. And the same thing is true for every paid VPN service I can think of. Right. So how can Google openly admit that their tracking is in place tracking everything they can, and also admit that it's undermining our privacy and.

[01:01:38] Their flagship browser is totally into it. Right? Well, it's really, it's gotta be the money. And Google does not have a plan B this anonymized tracking thing that they've been talking about, you know, the buckets that I mentioned, isn't realistic, frankly. Uh, Google's privacy sandbox is supposed to Fitbit fix it.

[01:02:00] I should say. The, the whole idea and the way it's being implemented and the way they've talked about it, the advertisers on happy. So Google's not happy. The users are unhappy. So there you go. That's the bottom line here from the Forbes article by Zach Dorfman, delete Google Chrome. And I said that for a long time, I do use some others.

[01:02:27] I do use Firefox and I use. Which is a fast web browser, that some pretty good shape. Hey, if you sign up for my show's weekly newsletter, not only will you get all of my weekly tips that I send to the radio hosts, but you will get some of my special reports that go into detail on things like which browser you shouldn't be using.

[01:02:52] Sign up right now. Craig peterson.com.

[01:02:57] Many businesses have gone to the cloud, but the cloud is just another word for someone else's computer. And many of the benefits of the cloud just haven't materialized. A lot of businesses have pulled back and are building data centers again.

[01:03:14] The reason I mentioned this thing about Microsoft again, and the cloud is Microsoft has a cloud offering.

[01:03:23] It's called Microsoft Azure. Many people, many businesses use it. We have used it with some of our clients in the past. Now we have some special software that sits in front of it that helps to secure. And we do the same thing for Amazon web services. I think it's important to do that. And we also use IBM's cloud services, but Microsoft is been pitching for a long time.

[01:03:51] Come use our cloud services and we're expecting here probably within the next month, a big announcement from Microsoft. They're planning on making it so that you can have your desktop reside in Microsoft's cloud, in the Azure cloud. And they're selling really the feature of it doesn't matter where you are.

[01:04:17] You have your desktop and it doesn't matter what kind of computer you're on. As long as you can connect to your desktop, using some just reasonable software, you will be able to be just like you're in front of a computer. So if you have a Chromebook or a Mac, Or a windows or tablet, whatever, and you're at the grocery store or the coffee shop or the office, you'll be able to get it, everything, all of your programs, all your files.

[01:04:47] And we, Microsoft will keep the operating system up to date for you automatically a lot of great selling points. And we're actually looking into that. Not too heavily yet. We'll give them a year before we really delve into it at all. Cause it takes them a while to get things right. And Microsoft has always been one that adds all kinds of features, but most of the time, most of them don't work and we can, we can document that pretty easily, even in things like Microsoft.

[01:05:18] Well, the verge is now reporting that Microsoft has warned users of its as your cloud computing service, that their data has been exposed online for the last two years. Yeah, let me repeat that in case you missed it, you, uh, yeah. I'm I'm I might've misspoken. Right. Uh, let me see, what does it say? It says, um, users of Azure cloud competing service.

[01:05:48] So that's their cloud. Microsoft's big cloud. Okay. Um, their data has been. Exposed online. Okay. So that means that people could get the data, maybe manipulate the data that sort of exposed means for the last two years. Are you kidding me? Microsoft is again, the verge. Microsoft recently revealed that an error in its Azure cosmos database product left more than 3,300 as your customers data.

[01:06:24] Completely exposed. Okay guys. So this, this, this is not a big thing, right? It can't possibly be big thing because you know who uses Azure, right. Nobody uses a zer and nobody uses hosted databases. Come on, give me a break. Let me see, what else does this have to say? Oh, okay. It says that the vulnerability was reported, reportedly introduced into Microsoft systems in 2019, when the company added a data visualization feature called Jupiter notebook to cosmos DB.

[01:06:59] Okay. Well, I'm actually familiar with that one and let's see what small companies let's see here. Um, some Azure cosmos DB clients include Coca Cola. Liberty mutual insurance, Exxon mobile Walgreens. Hmm. Let me see. Could any of these people like maybe, maybe Liberty mutual insurance and Walgreens, maybe they'd have information about us, right.

[01:07:26] About our health and social security numbers and account numbers and credit cards. Names addresses. Right, right. That's again, why I got so upset when these places absolutely insist on taking my social security number, right? It, it, first of all, when it was put in place, the federal government guaranteed, it would never be used for anything other than social security.

[01:07:53] And the law even said it could not be used for anything other than social security. And then the government started expanding it. Right. And the IRS started using it. To track all of our income and you know, that's one thing right there, the government computers, they gotta be secure. Right. All of these breaches we hear about that.

[01:08:12] Can't be true. Uh, so how about when the insurance company wants your personal information? Like your social security number? What business is it of? There's really no. Why do they have to have my social security number? It's a social security number. It's not some number that's tattooed on my forehead.

[01:08:36] That's being used to track me. Is it this isn't a socialist country like China is, or the Soviet union was right. It's not socially. So why are they tracking us like that? Walgreens? Why do they need some of that information? Why does the doctor that you go to that made the prescription for Walgreens? Why do they need that information?

[01:09:00] And I've been all over this because they don't. Really need it. They want, it makes their life easier, but they don't really need it. However, it exposes us. Now, if you missed the email, I sent out a week ago, two weeks ago now, I guess. You missed something big because I, in my weekly newsletter went through and described exactly what you could do in order to keep your information private.

[01:09:35] So in those cases where websites asking for information that they don't really need, right? You don't want to lie, but if they don't really need your real name, why you're giving them your real name? Why do you use a single email address? Why don't you have multiple addresses? Does that start make sense to you guys?

[01:09:54] And now we find out that Microsoft Azure, their cloud services, where they're selling cloud services, including a database that can be used online, a big database, uh, 3,300 customers looks like some of them are actually kind of big. I don't know. ExxonMobil pretty big. Yeah. I think so. Walgreens, you think that that might be yeah, yeah, yeah, yeah.

[01:10:22] Y. Why are we trusting these companies? You know it, if you have a lot of data, a lot of customers, you are going to be a major target of nation states to hack you and bat just general hackers, bad guys. But you're also, if, if you've got all this information, you've also got to have a much higher level of security than somebody that doesn't have all of that information.

[01:10:52] Does that make sense too? Did I say that right? You don't need the information and, and I've got to warn anybody that's in a business, whether you're a business owner or you're an employee, do not keep more data than you need the new absolutely need to run your company. And that includes data about your customers.

[01:11:16] And maybe, maybe it's even more specifically data about your customer. Because what can happen is that data can be stolen and we just found. That? Yes, indeed. It could have been, it was exposed Microsoft the same. We don't know how much it was stolen. If anything was stolen. Um, yeah, Walgreens. Hey, I wonder if anyone's going to try and get some pain pills illegally through, uh, this database hack or a vulnerability anyways.

[01:11:47] All right, everyone. Stick around. We'll be back. Of course, you listening to Craig Peterson. I am a cybersecurity strategist for business, and I'm here to help you as well. You can ask any question any time, uh, consumers are the people I help the most, you know, I wish I got a dime for every time I answered a question.

[01:12:09] Just email me@craigpeterson.com me@craigpeterson.com and stick around.

[01:12:18] Whether or not, you agree with the lockdown orders that were put in place over this COVID pandemic that we had. Uh, there are some other parts of the world that are doing a lot more.

[01:12:34] Australia has, I don't know. I think that they went over the deep end. The much, the same thing is true right next door to them.

[01:12:45] And I am looking at a report of what they are doing with this new app. Uh, you might be aware that both apple and Google came out with an application programming interface. That could be used for contract tack tracking, contact tracking. There you go. Uh, it wasn't terribly successful. Some states put some things in place.

[01:13:13] Of course you get countries like China. I love the idea because heaven forbid you get people getting together to talk about a Tannen square remembrance. Now you want to know who all of those people were, who were in close proximity, right? So, you know, good for China a while, as it turns out, Australia is putting something in place they have yet another COVID lockdown.

[01:13:39] They have COVID quarantine orders. Now I think if you are sick, you should stay on. I've always felt that I, you know, I had 50 employees at one point and I would say, Hey, if you're sick, just stay home. Never required a doctor's note or any of that other silliness, come on. People. If someone's sick, they're sick and let them stay home.

[01:14:04] You don't want to get everybody else in the office, sick and spread things around. Right. Doesn't that just kind of make sense. Well, they now in Australia, don't trust people to stay home, to get moving. Remember China, they were, they were taking welders and we're going into apartments in anybody that tested positive.

[01:14:22] They were welding them into their apartment for minimum of two weeks. And so hopefully they had food in there and they had a way to get fresh water. Australia is not going quite that far, but some of the states down under. Using facial recognition and geolocation in order to enforce quarantine orders and Canada.

[01:14:47] One of the things they've been doing for very long time is if you come into the country from out of the country, even if you're a Canadian citizen, you have to quarantine and they'll send people by your house or you have to pay to stay for 10 days in a quarantine hope. So you're paying the course now inflated prices for the hotel, because they're a special quarantine hotel.

[01:15:14] You have to pay inflated prices to have food delivered outside your door. And that you're stuck there for the 10 days, or if you're at home though, they, you know, you're stuck there and they'll send people by to check up on you. They'll make phone calls to check up on you and. They have pretty hefty find.

[01:15:36] Well, what Australia has decided to do is in Australia is Charlene's even going from one state to another state are required to prove that they're obeying a 14 day quarantine. And what they have to do is have this little app on their phone and they, the app will ping them saying, prove it. And then they have to take a photo of themselves with geo location tag on it and send it up via the app to prove their location.

[01:16:15] And they have to do all of that within 15 minutes of getting the notification. Now the premier of the state of south Australia, Steven Marshall said we don't tell them how often or when on a random basis, they have to reply within 15 minutes. And if you don't then a police, officer's going to show up at the address you're supposed to be at to conduct an in-person check.

[01:16:43] Very very intrusive. Okay. Here's another one. This is a, an unnamed government spokesperson who was apparently speaking with Fox news quote. The home quarantine app is for a selected cohort of returning self Australians who have applied to be part of a trial. If successful, it will help safely ease the burden of travel restrictions associated with the pandemic.

[01:17:10] So there you go. People nothing to worry about. It's just a trial. Uh, it will go away. Uh, just like, uh, for instance, income tax, as soon as rule, number one is over, it will be removed and it will never be more than 3% and it will only apply to the top 1% of wage-earners. So there you go. Right. And we all know that world war one isn't over yet.

[01:17:34] Right. So that's why they still have it in somehow. Yeah, some of the middle class pays the most income tax. I don't know. Interesting. Interesting. So there you go. Little news from down under, we'll see if that ends up happening up here. News from China, China has, uh, China and Russia have some interesting things going on.

[01:17:55] First of all, Russia is no longer saw. Country, they kind of are. They kind of aren't, they are a lot freer in many ways than we are here in the United States. Of course, China, very heavily socialist. In fact, they're so socialists, they are communist and China. And Russia both want their kids to have a very good education in science, engineering, and mathematics.

[01:18:23] Not so much on history, not so much on, on politics. Right. But definitely heavy on the, on the sciences, which I can see that makes all the sense. I think everybody should be pretty heavily on the science. Well, according to the wall street journal this week, gamers under the age of 18 will not be allowed to play online games between 8:00 PM and 9:00 PM on Friday, Saturdays and Sundays.

[01:18:53] Okay. So basically what they're doing, I reverse that what they're doing is they're only allowing the kids three hours of gaming per week. In other words, they can play between eight and 9:00 PM, Friday, Saturday, and Sundays. I think that might overload some gaming servers. Coke gaming addiction has affected studies and normal lives.

[01:19:13] And many parents have become miserable. That's China's press and public administration. Sedna state. Okay. Um, there's going to be some relief during the school holidays. Children will be allowed 60 minutes per day for gaming, uh, hard to say how China plans didn't force it, but they have their ways, right.

[01:19:35] Uh, identity cards. By the way required for playing online. They've got a facial recognition system introduced in July by 10 cent. Remember all of the uproar around 10 cent and their apps and president Trump trying to get them blocked here in the U S well, yeah, there you go. Facial recognition bill right into the app, and it's proven effective at catching children pretending to be adults in order to get around government gaming curves.

[01:20:05] So this goes on and on and, and Korea as well, South Korea has had some very big problems. You might remember it was headlines just a few years ago of some of these south Korean kids dying because they were playing video games for days straight with no sleep, no real food. Right. Just taking all of these so-called energy.

[01:20:31] And will literally gave me in themselves to death. So South Korea passed a law that prevented young people from playing online video games late at night. So that was introduced back in 2011 and it's targeted at players 16 around. And south Korean miners were prevented from playing online PC games between midnight and six, 8:00 AM.

[01:20:57] Now South Korea has scrapped that law. Interesting. So they're saying it's out of respect for younger citizens, right? They're going to abolish this law, replace it by. Permit system that allows players to request a permit per game and play during self-assigned hours that their parents will sign off on.

[01:21:21] This is in an article from GameSpot, by the way, a gamespot.com. You might remember them too, the whole Robin hood scandal. But, uh, I think it's an interesting question. When my kids were young lo those many years ago, I got this box that the, you took the TV wire, you ran it into the box and you could program.

[01:21:47] So that each kid had their own code and you could specify how much time the kid could watch TV or how much time or, or when they could watch TV and how much time cumulative the kids could have. And it actually worked pretty well. And the kids certainly complained a lot about it. And a couple of them tried to work the way around it kind of hard to when the plug is inside the box, but.

[01:22:13] Yeah, ingenuity as they are. They, they were able to do that. They cut the wire off and put a, another power connector on the end of the TV wire. Anyhow, uh, Microsoft, we've been talking about them a lot. This show. I do not like Microsoft, you know, that already the windows 11 is coming out and we talked about.

[01:22:37] Before, because windows 11 is plying. Microsoft is planning on requiring you to have a very modern computer. You need to have a TPM in it, which is this special security module. You need to have a certain speed, et cetera, but the TPM is a big thing. That's going to make it. So most of your computers won't work.

[01:23:03] Tons of pushback on that. I can see what Microsoft is trying to do it. They really would love to have a clean operating system that really wasn't getting hacked all the time. Right. And this will help it won't solve their problem, but it will help. So that they're going to be doing now is they're going to over the course of months, starting October 5th.

[01:23:28] They're going to release windows 11 to certain people, kind of one at a time type approach. So they're not going to force everyone to upgrade. They're not going to offer it to everyone. And Microsoft is going to offer a preview of the Android apps in the Microsoft store for windows insiders in the months ahead.

[01:23:52] But they're planning on having a phased rollout through winter. Date, and you're not going to see it most likely when it starts to roll out, but you will be seen and to end with the stringent system requirement, apparently what they're going to do is not auto update your computer if it's not new enough.

[01:24:13] And if it doesn't have a TPM, but you can manually install windows 11, at least that's what they're doing right now. Well, that's it for today. We had some more stuff I didn't get to, but we always have more every week. And I try to keep you up to date. We do trainings, visit me online so you can find out about all of this stuff.

[01:24:35] The trainings, most of them are absolutely free. Craig peterson.com/subscribe. Craig peterson.com.

View Details

What Happened With Facebook's Outage?
When Will It Happen Again?

Facebook had a huge outage all of its properties. So why did it happen? How did it happen? And what's going to happen in the future? The frankly, some of this technology just isn't that stable. And I'm going to explain why right now!

[Automated transcript follows]

[00:00:20] I've already talked about it a little bit this morning on the show, but Facebook was. Facebook was down a lot. Facebook too was down a long time. And Mr. Zuckerberg has now lost about $7 billion because of how long it was down. And Craig Peterson joins us now to talk a little bit about exactly what happened, why it matters, what it means and so much more.

[00:00:39] Craig, how are you this morning?

[00:00:41] Hey, good morning. Doing well.

[00:00:42] Thanks. Good to have you as always. So tell me first. What actually happened yesterday. I read that the explanation from Facebook seems like not a big deal as just a configuration problem, a little unexpected issue. They're not sure exactly what happened or looking into it.

[00:00:57] It's not a big deal though. Continue on with your day. What's the reality, what actually happened.

[00:01:01] Yeah, nothing to see here. You look at the number of companies and the companies Facebook has bought over the years, basically since 2005, they've spent $410 billion on all these companies named some names.

[00:01:17] You might actually recognize you remember Friendster?

[00:01:20] I do remember friends. Yes. That was a little, that's a little bit back there, but yeah.

[00:01:25] That was about 10 years ago, they paid $40 million for that. But of course, Facebook has moved on from that and owned all kinds of companies. Right now.

[00:01:35] It's got Instagram, WhatsApp, by the way they paid 19 billion is what it's wiping sorts out Oculus live rail and many

[00:01:45] others basically. That's when Ben one of the main complaints events. Supposedly being a monopoly is that they've been gobbling up their competition and other things that maybe even weren't competition, but things they could just add to the big beast and have it consolidated at all under Facebook's banner.

[00:02:02] Yeah. So the problem that tech guys have is this scale, massive scale. So on top of all of that, they have they claimed to have almost half the people. Earth go logging on to Facebook. So how do you deal with numbers like these and gets very difficult. And what appears to have happened is they're using a tool.

[00:02:26] There's a few that we use. And in fact, we'd had a similar problem yesterday with my company's networks, where w here's what happened? Here's the basics, right? You heard it was a DNS problem. Some people have said that. That's not the real problem. The real problem lies underneath that. And it's something that we have to deal with because we're working with multiple companies that have multiple network connections, and that's where it comes from the multiple network connections.

[00:02:56] So on the internet, what happens if you're going to go to Facebook, you're typing in facebook.com that has to be turned into an internet address. And to do that, you use DNS. But how bout beneath that basically the street directory who has main street in downtown Portsmouth. For instance, if you want to get there, there's another protocol that's used beneath DNS, and this protocol is used to actually map the, these addresses, these internet numbers.

[00:03:32] So that was the problem yesterday. And I checked it online myself with a site that we use to monitor all of this type of ad dressing. And what turned out had happened is Facebook stopped advertising where it addresses. If you tried to look up Facebook, you couldn't find it. And you got a DNS error because the DNS servers addresses were unknown.

[00:03:57] You knew the address, but you didn't know how to get to that address on the. And Facebook has become so big. They're using automated tools in order to push the configurations to all of these, what are called BGP servers. So what probably happened yesterday in reading some things on Reddit and other places where there are some people who claim to be working for Facebook, what probably happened.

[00:04:26] Somebody forgot to put the peer configurations into their BGP routing tables, pushed it out to all of their BGP routers worldwide. Now I've got to say on the outage that lasted six or eight hours with a problem. This is amazing because now you have to worry about the cold start of the whole. Some kind of like Texas, another four minutes, they would have been without power in some areas for months,

[00:04:57] we were referring to it.

[00:04:58] I'm thinking of a cold start your side. It sounds like you're starting a car. It's too cold outside and the car just doesn't have enough juice in the battery. So it's a, is that basically what happened?

[00:05:06] Yeah. Yeah. What happened is you couldn't get to anything. Facebook probably could not get to its own routers to update the configuration.

[00:05:14] Similarly took so long then is that they really were having a difficult time even gaining access to the thing that would be necessary to fix it.

[00:05:20] Exactly. And there were a lot of people, myself included that were thinking man, it's going to be days because the cold start also has problems with like caches.

[00:05:31] For instance, you go to a page. There's pictures, there's videos, there's texts while all of that information gets stored in a cache. So it doesn't have to be generated every time somebody sees something. So there would be cold Cassius out there that would need to be updated. It's a nightmare. This was a nightmare scenario for them and was probably caused by letting some junior guy.

[00:05:55] We'll make some changes through their BGP table.

[00:05:59] That is remarkable. We're talking with Craig Peterson, our tech guru. He joins us on Wednesdays typically to go over the world of technology. And of course we'll do that tomorrow as well, but we wanted to have him join us to talk a little bit about Facebook before I let you go.

[00:06:11] Craig. I The implications of this, I think are massive. I take to consider, even if you don't care about Facebook, if you don't use it, it's not part of your life. Obviously it is such a big part of not just American life, but this is a worldwide issue, right? I It is used by billions and billions of people and this kind of an outage lasting this long is not only unprecedented, but really important in terms of having good Lord.

[00:06:34] If you're a, if you're a Facebook. I was talking about that a little bit earlier this morning. If you had Facebook stock, how do you feel today? I know mark Zuckerberg doesn't feel great. That's why he lost $7 million of value yesterday. How does this affect at Facebook, the company going forward here, this, and when you combine this with the whole whistleblower thing, it's not exactly been a good week.

[00:06:51] Yeah, not at all. This problem frankly, comes from the early days or earlier days of the internet. I was on the internet back in the early 1980s and helping to develop the protocols. And back then, we were not worried that. That's type of massive scale. We were not worried about hackers, really getting in.

[00:07:13] Cause it was a great community. I'm most of us knew each other and we used to joke around and have a lot of fun. These protocols were not designed for the types of problems we're seeing today. So until these problems are solved, not by Facebook, but by the internet community as a whole, these types of things can happen again.

[00:07:37] So Facebook, it could go down again because frankly we have seen times where for instance, traffic from the Washington DC area was all routed through Moscow. So you would send data from the white house and I'm know to someone in the building, across the street. And it was referred through mosque gal who knows what the Russians are doing with all of that data, but we just don't have the safeguards in place that would support, frankly, the way we are using the internet today.

[00:08:12] Facebook could face this problem. Again, we're talking about fiber as much as I've seen numbers, $500 million an hour in lost revenue from Facebook, but it could happen to anyone. And I'm sure there will be a lot of work here. Others, people sharpening pencils, and finally getting in line on how do we actually do.

[00:08:33] The stop work at huge scale. Huge. We're talking now hundreds of billions, probably trillions of devices connected to the internet by 2025.

[00:08:46] They're actually sharpening pencils. Craig, you think anybody uses pencils anymore? I begged to do. Not a technology companies. Craig Peterson, we appreciate it as always.

[00:08:55] Of course you hear them on Saturdays as well on WGAN and we'll hear his voice tomorrow, joining us for the more traditional tech topics, other things besides Facebook to chat about, obviously, but we appreciate him joining this morning. Thanks a lot, Greg. And we'll talk to you tomorrow.

[00:09:07] Take care.

View Details

Could Using the Right Multi-Factor Authentication Save You?

I had a good friend who, this week, had his life's work stolen from him. Yeah. And you know what caused it? It was his password. Now, you know what you're supposed to be doing? I'm going to tell you exactly what to do right now.

Let's get right down to the whole problem with passwords.

I'm going to tell you a little bit about my friend this week. He has been building a business for. Maybe going on 10 years now, and this business relies on advertising. Most companies do so in some way; we need to have new customers. There's always some attrition. Some customers go away. So how do we keep them?

We do what we can. How do we get new customers? For him, it was. Advertising, primarily on Facebook. He did some Google ads as well, but Facebook is really where he was focused. So how did he do all of that? Here's the bottom line you have to, if you are going to be advertising on Facebook, you have to have an advertising account.

The same thing's true. Google. And then, on that account, you tie in either your bank account or your credit card. I recommend a credit card so that those transactions can be backed up. And on top of all of that now, of course, you have to use a pixel. So the way the tracking works is there are pixels on websites, about those already.

And the bottom line with the pixels. Those are also. Cookies are about the pixels are used to set a cookie so that Facebook knows what sites you've gone to. So he uses those. I use those. In fact, if you go to my website, I have a Facebook pixel that gets set. And the reason for all of that is so that we know with.

I'd be interested in something on the site. So I know that there are many people interested in this page or that page. And so I could, I have not ever, but I could now do some advertising. I could send ads to you so that if you were looking at something particular, you'd see ads related to that, which I've always said.

It is the right way to go. If I'm looking to buy a pickup truck, I love to see ads for different pickup trucks, but if I don't want a car or truck, I don't want to see the ads. It isn't like TV where it sometimes seems every other ad is about. Car or a pickup truck. It drives me crazy because it's a waste of their money in advertising to me. After all, I don't want those things.

And it's also not only just annoying in money-wasting. There are better ways to do targeting. And that's what the whole online thing is. Anyways, I told you about that because he had set up this pixel years ago. Basically, the Facebook pixel gets to know you. All of the people who like you that might've bought from you.

Cause you can have that pixel track people through your site, your purchase site, they know what you purchase on the shopping cart, et cetera. And you can identify these people over on Facebook and their ads because they abandoned the cart or whatever it is you want to do there. So there's just a whole ton of stuff that you can do for these people.

And it's so bad. It is so valuable. It takes years to build up that account. Years to put that pixel in place. And our friend here, he had done precisely that. Then he found that his account had been compromised. And that is a terrible thing in this case because the bad guy used his account to place ads. So now there are really two or three problems here.

We'll talk about one of them. Why was the bad guy going after him? He has been running ads on Facebook for a long time. So as far as Facebook is concerned, his account is credible. All of the ads he runs don't have to be reviewed by a human being. They can go up almost immediately. He doesn't have to wait days for some of these things to go up.

So our bad guy can get an account like his that has years' worth of advertising credibility and now start advertising things that are not correct. So there again is part of the value of having one of these older accounts for advertising. And so the bad guy did that use his credibility. And then secondly, he used 25 grand worth of my friend's money to run ads.

Also, of course, very bad, very bad. So I sat down with him. In fact, it was this last week, and I was out on a trip with just a vacation trip. It was absolutely fantastic. I never just do vacation. It's always business plus work whenever I do anything like this, but I was on a trip last week. And so my eldest son who works closely with me, and he's also part of the FBI InfraGard program. So I had him reach out to my friend, and he helped them out, and they talked back and forth. So here's the problem that he has. And I'm trying to figure out a perfect way to solve this. And I haven't figured that out yet.

And if you guys have an idea because you are the best and brightest, you really are. So go ahead and drop me an email at me@craigpeterson.com if a good way around this particular problem, which is he has. This Facebook could count and many other accounts, including his website, hosting account, email account, et cetera.

And. He has people who manage his ads for him. Who operates his website for him, who put up some promotions, advertising, and everything else. So these are third-party. This is what we generically call a supply chain, risk people who are not him have access to his stuff, his private property.

And how does he do it, or how did he do it? Is he went ahead and gave them. Access by giving them accounts or passwords. How well were they guarding their passwords and their accounts? So the first thing I had my friend do was going to haveIbeenpwned.com.

I had him put in his email address, the one he uses the most, and it showed up in five different. Hacks data dumps. So these are five various sites where he had used that same email address in this case. And he found out that in those five cases, the bad guy's got his passwords and personal information.

All bad. And he went ahead and cleaned it up. So I said put in the password because have I been, pwned also let you check your password, just see if it has been used by someone else and then stolen. So there are billions of passwords in this database. It's incredible of all of these known passwords.

So he put in his password, and no, it had not been stolen, but the problem is how about the people that were managing his ads on Facebook and managing his Facebook ad. We're the usernames, which are typically the email addresses and the passwords kept securely. That's a supply chain thing I'm talking about, and that's where I'd love to get him.

But from you guys, me@craigpeterson.com. If you think you have a good answer, What we've been doing. And our advice to him was use one password. That's the only one to use. I don't trust last pass anymore. After their last big hack where they got hacked one password, the digit one password. And go ahead.

And set it up. And in a business scenario, you can have multiple vaults. So have a vault. That's just for people that are dealing with your Facebook ad account, maybe have another vault for people who are posting for you on Facebook. Or better yet when it comes to Facebook, go ahead and have an intermediary that is trusted the, if this, then that, or there's a few of them out there that can see that you put the post up on the website and automatically posted on Facebook.

So you don't have to get. All of these people, your passwords, but again, it's up to you. You got to figure out if that makes sense to you that those are the types of things that I think you can do. And that is what we do as well. Now, one of the beauties of using one password like that, where you're not sharing all of your passwords to everything you're sharing, the minimum amount of login information that you possibly can share is that if they leave your employees, All you have to do is remove their access to the appropriate vault or vaults, or maybe all of your vaults.

And this is what I've done with people that worked for me in the US and people would work for me overseas, and there have been a lot of them and it has worked quite well for me. So with one pass, We can enforce password integrity. We can make sure the passwords on stolen. One password ties automatically into have I been postponed.

If a password has been exposed, if it's been stolen online, it's a great way to go. Now I've got an offer for you guys who are listening. I have a special report that I've sold before on passwords, and it goes through talks about one password. He talks about the last pass, which I'm no longer really recommending, but give some comparisons and how you can use these things.

Make sure you go and email me right now. Me, Me@craigpeterson.com. That's ME at Craig Peterson dot com and just ask me for the password special report, and I'll be glad to get that on-off to you. There is a lot of good detail in there and helps you, whether you're a home user or a business.

So the next step in your security is multi-factor authentication. Interesting study out saying that about 75% of people say that they've used it for work or for business, but the hard numbers, I don't think they agree

One of the things that you have to do is use good passwords. And the best way to do that is to use a password manager.

I was talking about a friend of mine who had been hacked this last week and his account was hacked. His Facebook ad account was hacked. We asked him if we could reach out to. BI and he said, sure. So we checked with the FBI and they're looking to turn this into a case, a real case, because they've never seen this type of thing, the hijacking of an advertising account who hijacked it.

And why did they hide jacket? Was this in preparation maybe for. Playing around with manipulating our next election cycle coming up. There could be a lot of things that they're planning on doing and taking over my friend's account would be a great way to have done it. So maybe they're going to do other things here.

And our friends at the FBI are looking into it. How now do you also keep your data safe? Easily simply. When we're talking about these types of accounts, the thing to look at is known as two factor authentication or multifactor authentication. You see my friend, if he had been using multi-factor authentication.

I would not have been vulnerable. Even if the bad guys had his username, email address and his password, they still would not be able to log in without having that little six-digit code. That's the best way to do multi-factor authentication. When we're talking about this code, whether it's four or 5, 6, 8 digits long, we should not be using our cell phones to receive those.

At least not as text messages, those have a problem because our phone numbers can be stolen from us and they are stolen from us. So if we're a real target, in other words, they're going after you. Joe Smith and they know you have some, $2 million in your account. So they're going after you while they can, in most cases, take control of your phone.

Now you might not know it and it doesn't have to be hacked. All they have to do is have the phone company move your phone number to a new phone. Once. So that means one of the things you need to do is contact your telephone vendor, whoever it is, who's providing new that service. That's a company like Verizon sprint T-Mobile a T and Tone of those companies that are giving you cell service, you have to contact them and set up a pass.

So that if they have a phone call coming in and that phone call can be faked. So it looks like it's coming from your phone, even if there was a phone call coming in, whether it's coming from your phone or not, they have to get that password or passcode that you gave them. And once they have that passcode now, and that's great, but if you don't have that in there targeting you specifically, then you're in trouble. So for many of us really it may not make a huge difference. But I would do it anyways. I have done it with every one of my cell phone carriers now. A couple of decades set up a password. So the next step is this multifactor authentication.

If I'm not supposed to get it via text message to my phone, how do I get it? There are a couple of apps out there. There's a free one called Google authentic. And Google authenticator runs on your phone. And once it's there on your phone and you are setting it up on a website, so Facebook, for instance, your bank, most websites out there, the bigger ones, all you have to do is say, I want to set up multi-factor authentication, and then it'll ask you a case.

So how do you want to do it? And you can say, I want an app and they will display. A Q R code. That's one of those square codes with a bunch of little lines inside of it. You're seeing QR codes before they become very common. And you take your phone with the Google authenticator app. Take a picture. Of that little QR code on the screen, and now it will start sinking up so that every 30 seconds Google authenticator on your phone will change that number.

So when you need to log back into that website, it's going to ask you for the code. You just pull up Google authenticator and there's the code. So that's the freeway to do it. And not necessarily the easiest way to. Again, going back to one password. I use this thing exclusively. It is phenomenal for keeping my passwords, keeping them all straight and then encrypted vault, actually in multiple encrypted vault it's so that I can share some of them.

Some of them are just strictly private, but it also has that same authenticator functionality built right into it. Microsoft has its own authenticator, but you can tell Microsoft that you want to use the standard authenticator. Of course, Microsoft has to do everything differently. But you can tell it.

And I do tell it, I want to use a regular authenticator app, not Microsoft authenticator. By the way. That's why I advise you to don't use the Microsoft authenticator, just use one authenticator for all of the sites, and then Microsoft will give you that same QR code. And then you can take that picture and you're off and running.

Next time you log in, it asks you for the code and instead of texting it to you to your phone smarter, otherwise it will not. That require you to open up your authenticator. So for me, for instance, when I'm logging into a website, it comes up and asks for the username, asked for the password. Both of those are filled out automatically by one password for me.

And then it asks for that code identification code and. One password automatically puts it into my pace to buffer copy-paste, buffer, and I just paste it in and they've got the code. So I don't have to remember the codes. I don't remember passwords. I don't have to remember usernames or email addresses.

One password remembers them all for me. Plus it'll remember notes and other things. So you can tell, I really one password. We use it with all of our clients. That's what we have for them. And it does meet even a lot of these DOD requirement on top of. Depending again, how much security you need. We will use duo D U O and it also has this authenticator functionality and we will also use UBI keys.

These are those hardware key. They do oh, can provide you with hardware tokens. Those are those little tokens that can go onto your key ring. That show a changing six-digit number every 30 seconds. And that's the same number that would be there in your smartphone app. Your one password or Google authenticator smartphone.

Hopefully, I didn't confuse you too much. I think most of the reason we're not using the security we should is because we're not sure how to, and we don't know what we're going to be. And I can see that being a big problem. So if you have questions about any of this, if you would like a copy of my password security, special report, just send an email to me.

M e@craigpeterson.com. That's me M e@craigpeterson.com. That's S O N.com. I'll be glad to send it to you. Also, if you sign up for my newsletter there on my website@craigpeterson.com, you are going to get. I was hold little series of the special reports to help you out, get you going. And then every week I send out a little bit of training and all of my articles for the week.

It's usually six to 10 articles that I consider to be important so that, what's going on in the cybersecurity world. So you can. With it for yourself, for your family, for your business. Craig peterson.com.

According to researchers. 32% of teen girls said that when they felt bad about their bodies, Instagram made them feel worse. And you know what Facebook knew and knows Instagram is toxic for teen girls.

There's a great article that came out in the Wall Street Journal.

And I'm going to read just a little bit here from some of the quotes first. When I went on Instagram, all I saw were images of chiseled bodies, perfect. Abs and women doing 100 burpees in 10 minutes, said, Ms. Now 18, who lives in Western Virginia. Amazing. Isn't it. The one that I opened now with 32% of teen girls said that when they felt bad about their bodies, Instagram, I made them feel worse.

So that is studies again, that looks like yeah, these were researchers inside Instagram and they said this in a March, 2020 slide presentation that was posted to Facebook's internal message board that was reviewed by the wall street journal quote comparisons on Instagram can change how young women view and describe themselves.

Apparently, for the past three years, Facebook has been conducting studies into how Instagram is affecting its millions of young users. Now, for those of you who don't know what Instagram is, it allows these users to create little stories, to have. Pictures videos of things that they're doing, and it's a lifestyle type thing you might've heard, of course, of how this I don't know what it is.

Kidnapping murder plot. These, this young couple and the body I think was found up in Wyoming. I'm trying to remember, but of her and it's yeah, there it is. It wasn't my OMI. And I'm looking up right now, Gabby potato. That's who it is. She was what they called a micro influence. And I know a lot of people who can loom, that's what they want to be.

There's a young lady that stayed with us for a few months. She had no other place to live. And so we invited her in here and we got some interesting stories to tell about that experience. And it's, a little sad, but anyhow, she got back up on her feet and then she decided she was going to become an influence.

And what an influencer is someone that has a lot of followers. And of course, a lot means different numbers. You get these massive influencers that have tens of millions of people that quote, follow unquote them. And of course, just think of the Kardashians they're famous for. Being famous, nothing else.

They have subsequently done some pretty amazing things. At least a few of them have. We've got one of those daughters who now was the first earliest billionaire. I think it was ever youngest. So they have accomplished some amazing things after the fact, but they got started. By just becoming famous by posting on these social media sites.

So you get a micro-influencer, like Gabby Petito, who is out there posting things and pictures. And you look at all of these pictures and, oh my gosh, they're up at this national park. Oh, isn't she so cute. I'll look at her boyfriend. They'll look so good together and people. Fall for that image, right? It's just like Photoshopping these pictures of models, changing them.

There've been some real complaints about those over the years. So Instagram sets these kids up with these pictures of people that are just totally unrealistic. One of the slides from a 2019 presentation says, quote, we make body. Excuse me. We make body image issues worse for one in three teenage girls teams, blame Instagram for increases in the rate of anxiety.

And depression said another slide. This reaction was unprompted and consistent across. Groups among teens is this according to the wall street journal who reported suicidal thoughts, 13% of British users, and 6% of American users trace the desire to kill themselves to Instagram. Again, according to one of these presentations, isn't this just absolutely amazing.

And you might've heard it discussed a little bit. I saw some articles about it, obviously in the news wall street journal had it, but this is a $100 billion company, Instagram. That's what their annual revenues. More than 40% of Instagram users are 22 years old and younger. And about 22 million teens log into Instagram in the US each day, compared with 5 million that log into Facebook, the younger users have been declining.

Facebook it's getting the population there is getting older and older on Facebook. In average teens in the us spend 50% more time on Instagram than they do on Facebook. And also tick-tock, by the way I took talk has now surpassed YouTube in some of these metrics. Quote, Instagram is well-positioned to resonate and win with young people said a researcher's slide posted internally.

Inside Facebook. Another post said there is a path to growth. If Instagram can continue their trajectory. Amazing. So Facebook's public phase has really tried to downplay all of these negative effects that the Instagram app has on teens, particularly girls, and hasn't made its research public or available to academics or lawmakers who have asked for it.

Quote, the research that we've seen is that using social apps to connect with other people. Positive mental health benefits said Mark Zuckerberg. He's the CEO of course of Facebook. Now this was 2020. In March one at a congressional hearing, he was asked about children and mental health. So you see how he really lawyered the words that they can have positive mental health benefits, but Facebook's own internal research seems to show that they know it has a profound negative effect on a large percentage of their users.

Instagram had Adam Moseri told reporters in may of this year, that research he had seen suggest the app's effect on team's wellbeing is likely quote quite small. So what the wall street journal seems to be pointing out here is that Facebook is not giving us the truth on any of this stuff. It's really sad.

We've got to be careful. No, apparently Mr. Moseri also said that he's been pushing very hard for Facebook to really take their responsibilities more broadly. He says they're proud of this research. I'm just summarizing this before we run out of time here, but it shows the document. Internal documents on Facebook show that they are having a major impact on teen, mental health, political discourse, and even human trafficking.

These, this internal research offers an unparalleled picture. Courtney told the wall street journal of how Facebook is acutely aware that the products and systems central to its business success routine. Fail great article. I've got it in this week's newsletter. You can just open it up and click through on the link to the wall street journal.

They have a paywall and I hate to use payroll articles, but this one's well worth it. And they do give you some free articles every month. So if you're not on that newsletter, you can sign up right now. Craig peterson.com. You'll get the next one. If you miss a link today, if you want some, the special report on passwords, et cetera, just email me directly.

Give me a few days to respond. But me M e@craigpeterson.com. That's me M e@craigpeterson.com.

We've all worked from home from time to time. At least if we're somehow in the information it industry, I want to talk right now about why you need a personal laptop. Even if the business is providing you with a laptop.

Laptops are something that was designed to be personal, but many of us are using them as our main computer.

I know I often am using my laptop, a couple of my kids and my wife. It's really their main computer, even though they all have other computers that they could potentially be using, laptops are just handy and you have them with, you can take them with you. We've got workstation set up that are kind of.

Workstations, if you will, where there are three screens set up and they're all hooked up into one central screen controller that then has a USBC connection that goes right into the, your laptop. So you can be sitting there with four screens on your Mac laptop on your mac pro if you need four screens, it's really handy.

No question. Many of us have a laptop for home and a laptop for business. And many of us also look at it and say, oh wow, this is a great laptop I got from work. It's much better than my home laptop. And you start to use the business laptop for work. At home. Okay. That's what it's for. Right. But then we start to use that business laptop for personal stuff.

That's where the problems start. We've seen surveys out there that are shown. Then half of workers are using work issue devices for personal tasks that might be doing it at home. They might be doing it at the office. Things like personal messages, shopping, online, social media, reading the news. So the prospect of using your work laptop as your only laptop, not just for work, but also for maybe watching some movies, group chat and messaging, reading, fan fiction, paying bills, emailing to family or friend.

It just seems not. It's so tempting. It's just natural. I'm on it. I'm on it all day long. Why wouldn't I just use it? And this is particularly true for people who are working from home, but we have to be careful with that. It's really something that you shouldn't be doing for a couple of reasons. One that.

Top that's a business. Laptop is the property of the business. It's just like walking home with boxes, full of pencils and paperback in the old days, it is not yours to use for personal use. We also have to assume, assume since it is the company's laptop that hopefully it's been secure. Hopefully they haven't set up.

So it's going through a special VPN at the office and it's going through special filters, maybe snort filters or something else. That's doing some deeper inspection on what's coming through your laptop. Well, there are also likely on that laptop. Tools that are monitoring your device. Things like key loggers, biometric tracking, Jill location, software that tracks your web browser and social media behavior, screenshot, snapshot software, maybe even your cam.

Is being used to keep track of you. I know a number of the websites that I've used in the past to hire temporary workers. Those workers have to agree to have you monitor what they're doing. These hourly workers, subtle take screenshots of their screen, unbeknownst to them. Pictures from the cameras at random intervals.

Again, unbeknownst to them, it'll track what they're doing. And so I can now go in and say, okay, well he billed me five hours for doing this. And I look at his screen and guess what? He wasn't doing that for all of those five hours that he just billed me. Well, the same thing could be true for your company, even if you're not paid by the hour.

Right now, we're looking at stats that show over half of the businesses that are providing laptops for the employees to use more than half of them are using monitoring software. And through this whole lockdown, the usage of these different types of monitoring systems has grown. Now there's some of the programs you're using.

You might be VPN in, you might be using slack or G suite enterprise, all good little pieces of software. They can monitor that obviously, but it goes all the way through to the business. And using your slack access as paid for, by the businesses also idiotic to do things like send messages to your buddies, set up drinks after work, complain to other people about someone else in the business, your boss, or otherwise your it, people at the business can see all of that.

They can see what you're doing with slack. Even if you have a separate personal account. It's still more likely that you'll end up mixing them up if you're logged into both on the same computer. So the bottom line is if you are on a work computer, whether it's a laptop or something else, you can reasonably assume that I T can see everything.

That's not. They own it. Okay. And they have to do some of this stuff to protect themselves. We put software on laptops for companies not to spy on employees. That's none of our business, but we put software on computers for employees. To make sure they stay safe. Think of what happens when your computer, your laptop, whatever it might be, connects to the company's network.

Now that can be through a VPN. It can be because you take your laptop home or on the road when you're traveling and you bring it back into the office. If that computer is infected, somehow now you've brought that infection into the office. And that's how a lot of the malware works. It goes from computer to computer.

So once they get in that front door where there's through a website and email that you clicked on or in a computer that you're bringing into the office, they can start to move around. Now it's not just your activity. And this is an interesting article from the verge by Monica chin. It's not just your activity that they can see on your laptop, but in many cases, they're also able to look at anything you're downloading any of your photographs or videos that you might've sinked up from your smart.

Laura loading these types of things, your text messages on your work device for safekeeping, or just because it's your primary device might seem harmless, right? Cause you're just going to remove them before you hand it in. But some companies such as Apple won't allow you to wipe your device before handing it in regardless of how personal the contents are.

And that makes sense too, because many times an employee leaves. And they don't give the company all of the information that they have, that they're obliged to give back to their employer. Things that they've been working on, customer information, et cetera. So Manalive, there are plenty of other devices out there.

Hopefully if you leave your company with plenty of notice, moving a bunch of things off your work device in the last few days, uh, might raise some eyebrows at the. And I'm saying hopefully, because they should notice that sort of thing, because it could be malicious activity. It could be an insider risk that maybe they're not even aware of.

There's so much you could go wrong here. So bottom line don't use the work laptop for home. So what should you use? You know, my personal recommendation. Almost always is get a Mac. They are safer to use the patches that they get are usually not destructive. You know, sometimes you can install a patch for windows and now your machine just won't work anymore.

Right. You've had that happen. I know every last one of us out there that are tried to install Microsoft patches for a while have had that happen to them. All of a sudden the patch has completely messed up your computer and you are so out of luck, it's ridiculous. Right? So don't, you know, hopefully don't do that, but I like the max because they are basically safer than windows.

And also because the patches just work on them, apple tends to get them out in plenty of time to try and protect us the next level. If he can't afford an apple and. Apple laptops really are not expensive when you consider how long they last and the quality that components, they are not expensive at all.

But if you can't afford that, the next thing I would look at is getting a Chromebook. There are a lot of companies that make Chromebooks Chrome is an operating system from Google. It's similar to Android. Google keeps the Chromebooks up-to-date. They patch them quite regularly and make sure that there aren't nastiness is going on.

You just have some of the same issues and Android has patches might take a while to get to you because it has to go through the vendor that made the Chromebook. You might have a Chromebook for Sam from Samsung, for instance, it's not Google's even though it's called a Google Chromebook. Now Chromebooks rely heavily on the cloud services that Google provides, but they can also run just locally.

So with a Chromebook and you can get them for as little as 150 bucks, but remember you get what you pay for. Or as much as I've seen them in the $2,000 price range with fancy GPU's, local storage and other things, but at 150 bucks, it could be well worth it for you. It lets you do the regular word processing.

Just think of what you can do with Google docs, spreadsheets against Google docs, spreadsheets, all of those types of things are built into it. You can. Cruz the web, obviously using Google Chrome on your Chromebook. And send and receive email, which is what most people do. That's really kind of all, most people do at home.

So consider that as well. I also like iPad. They are quite safe again, but they tend to be more expensive and they can do pretty much everything. And now with Android support built right into Google Chromebooks, you can even run Android apps. So there you go. Keep safe and be safe out there. Right. Have a hack free life.

Make sure you get my newsletter. Craig peterson.com/subscribe. Craig peterson.com/subscribe.

The national cyber director, Chris Inglis said that we need cyber bullets, that cyber bullets are part of the war on hacks. And it makes sense on one level. But when you get into the reality, it's a much different story..

I had an interesting email this week from a listener. Actually he sent it about two weeks ago when I finally was able to get to it this week and responded, and he was pointing out how there are some things that I talk about on the show that I put into my newsletter that are really good.

And. I'm paraphrasing here but theoretical to so many people, there's some things that you can figure out pretty easily yourself. Some things you can do yourselves and other things that are just different. To do still. And a lot of that has to do with the websites you go to in order to maintain your passwords.

And he was complaining specifically about bank of America and how you can, according to what he has found here in the real world, you can come up with a. Password a 20 character long password that is going to keep everything nice and safe at trend to be generated. You're using one password and great. So you set your password up in bank of America's account, and then you try and log in later, and it doesn't work because it lets you put 20 character passwords and when you're creating it, yeah.

But the login screen only takes the first 16. So of course they'd home match. You see it's things like that really are pushing us back, holding us back. But I'd say pushing us back from being secure as a country, there, there just aren't enough people paying enough attention to make sure this cyber security, even the basic stuff like passwords and two factor authentication are being done properly.

So one of the things I wanted to make sure you guys were aware of is I need to know when you're having these problems, because what I want to do is put together some trainings to show you exactly how to do it. Because on some websites you were saying, it's pretty hard to use one password he's paying for it, but it's kinda difficult for him.

And I think in some ways, a lack of understanding. Then, it can be difficult to spend a bunch of time trying to watch some training videos for some of the software. And so I want to hear when you're having problems so I can do what I did for him this week and spend a little time, write some stuff up, and I even am reaching out to some of this website.

People like bank of America who are really messing up cyber security for people who are trying to do the right thing and writing them and saying, Hey, listen, I'm part of the FBI InfraGard program. I'm a member of it. I paid a lot of attention to cybersecurity. Heck I ran the training for the FBI InfraGard program for a couple of years, and there are some real things lacking.

In the login anyways, and this one particular case of the cybersecurity, but I don't know all of this stuff. I'm not using all of these things and I have a disadvantage over you guys, and that is that I've been doing this for so long. I've forgotten what it's like to not know it. Does that make sense?

So if you have something that I've talked about on the show, that's appeared in my newsletter and you're having some confusion over, let me know. Just email me M e@craigpeterson.com. What he did is he just hit reply to my newsletter. And of course, that goes to me and me@gregpeterson.com and it tracks it.

So I know I need to reply, so I can sit down and go through and answer people's questions. I sent out a lot of the copies of my password, special report to people you guys had requested specifically some of the. People out there had requested a little bit of help. And I had sent out an email to most of the people that I could identify as being business people.

I sent out a little thing saying, Hey, listen, if you could use half-hour my help, let me know myself or my team. And then, again, you can just send me an E Craig. So I answered a lot of those questions this week. And in fact, that's how I come up with much of what I cover here on the show. You guys ask the questions and that's how I know that it's a real problem.

If I understand it, that's one thing. But for the people who don't do cybersecurity as their primary job or a strategy, I get it. I can get why you guys are confused. So make sure you get my weekly newsletter. So you can find out about all of the trainings, the free stuff, the paid courses, and. It's easy.

Just go to Craig peterson.com/subscribe. That's Craig Peterson, P E T E R S O N. Craig peterson.com/subscribe. And I'm more than glad. Add you to that list. And there are now thousands of people on that list to get my email pretty much every week. If you miss it one week, it's probably, cause I just got too busy, but I put out all my show notes.

I put it all a little bit of training notes, all. The us government is supposedly getting ready to fire what they're calling cyber bullets in response to these significant hacking attacks. This is what they're calling a comprehensive strategy to dissuade. Adversaries. And this is all from the national cyber security director, Chris Inglis.

This is from an article in American military news.com by Chris Strome. That was out this week. And of course I included that in my newsletter this week as well, coming out. Today or tomorrow, depends on how this all goes right with the weekend. I got to help a buddy out today, but president Joe Biden has been really talking about how do we use cyber weapons to retaliate.

For instance, he gave a list of industries that Russia should not be. As though Putin himself is running all of these hacks or come out of Russia. Yeah, certainly there are some that are part of their military, but there many of them that are just bad guys that are trying to make some money, we should feel sorry for them.

So Biden gives him this list and says, Hey, listen, if you attack any of these various industries or actually portions of our economy, We are going to retaliate. We have seen the us retaliate under President Trump and the retaliation. Of course he did all kinds of economic stuff to stop it. And much of which has been reversed by president Biden's administration, but also he attacked them directly in.

Down some power systems there in the Moscow area, which I thought was really kinda cool. So kudos to President Trump for doing that and for president and Biden now to say, Hey, we are going to attack back. Of course. The biggest question is. What would we be attacking? How would we be attacking it? And for what reason, for instance, the red Chinese have gone after our office of personnel management, OPM records and got them all back in 2015.

So they now know everything about everybody that had a secret security clearance or the took a paycheck from the federal government. All of those records, they would get their hands on them and get them on all of the records a lot. So Inglis was in front of the let's see here, the, yeah, he was a former director of the national security agency.

He's the first to hold his Senate-confirmed position at the white house, this national cyber director position. And he says there is a sense that we can perhaps fire some cyber bullets and shoot our way out of this English set at the conference. It was hosted by the way, by the national security agency and a nonprofit group, he said that will be useful in certain circumstances.

If you had a clear shot at a cyber aggressor and I can take them offline, I would advise that we do so as long as the collateral effects are acceptable. Yeah. What we have done here under president Biden administration is we have shut down some people who were operating illegally, we have shut down some cyber actors that were attacking us.

So we've been doing that, but it isn't exactly. Wow. We just saw a muzzle flash over there. And so we are returning fire to the area of that muzzle flash, because as I've said many times before, we just don't know. Where in fact that bullet is coming from, it makes it a lot more difficult. English went on to say there's a larger set of initiatives that have to be undertaken.

Not one of those elements is going to be sufficient to take this. Out let's see here, the us should make clear to Russia now their adversaries, what kinds of attacks would prompt a response, which is what president Biden did when he was talking with, of course, President Putin over there, red lines of both good and bad red lines are clear and crisp.

Although I got to say many of our administrations have. Really done anything about it. It's the red line in the sand and Syria president Obama didn't do anything when they stepped over that red line. So yeah. And then with what we just finished doing in Afghanistan, where we drew a red line and said, we're going to protect all of you who helped us.

And then we not only abandoned them, but we abandoned Americans behind there. I don't think a lot of people aren't going to believe us. So here's the last statement here. And again, this is an article in American military news from our cyber chief is the government actions. Aren't always going to be broadcast.

In some cases, it's not helpful to broadcast those for all of mankind to see another one. We are doing some things behind the scenes. And I have certainly seen some of the results of those over the last few years. Stick around. You're listening to Craig Peterson online@craigpeterson.com.

You've got a smartphone and there are some new versions out, right? New hardware, new software, Android iOS. How long should you keep that device? How long can you stay safe with that older device?

Apple has now done something. Different something they've never done before. One of the reasons that apple equipment tends to be safer than almost anything else out there is that they have, what's known as a closed ecosystem. There's arguments both directions here on whether that's safer or not.

But the real advantage when it comes to cybersecurity is there are only. So many versions of the iPhone out there. What are we now in a couple of dozen versions of the hardware platform that makes it easier for apple to be able to support older versions of the software and multiple pieces of hardware, much easier than for, let's say Microsoft windows.

It doesn't even have a single. Platform or Android, where there are hundreds of hardware platforms out there and tens of thousands of versions of the hardware, because one model phone can contain many. Changes different types of hardware to talk to the cell towers or the screen you name it. So it's very hard to keep up. Android has for quite a while now supported three versions of their operating system. Of course, we're talking about Google, but Android operating system. So they support the current release. Of Android and the Breviary release is two previous releases in fact of Android. Now that is frankly a pretty good thing to know, but there's over a billion Android devices out there that are no longer supported by security updates.

We've got Android 10, nine, and eight that are fairly supported right now. We're actually up to Android 12. So here's how it works. If you've got Android version 10 out, if that's the main one, then you can continue to do. Eight and nine and get updates, security updates. But then here's the problem, everybody, those security updates are coming out of Google, but that does not mean that they are making it all the way to you.

So there you go. It's one thing for Google to provide updates, but if you can't get them because your phone manufacturer is not supporting them, you've got trouble Samsung. Is probably the best company other than maybe Google and the Google Pixel phone. Samsung's the best company to go to. If you want some longer-term support.

Many of these other companies just don't provide support past the current version. So keep that in mind as well. Android 12 was the 12th major version of Android announced by Google, February, 2021. And it is starting to roll out a Android. The 11th, 11 is the one that was out in February of last year. At least it was announced then.

And we're, they're coming out, they're getting pushed out. So basically Google is saying the current version plus two prior versions. And that usually gives you about a four or maybe even a five year window. So if you're. An Android device from a major manufacturer, particularly Samsung on the Android side, your device is going to be good for at least four years, maybe five years now on the, and by the way, you don't necessarily have to upgrade the.

You could be continuing to run an older release saw, as I mentioned earlier, if it version 11 is the current one that's out there being supported, which it is right. 12 is early still, but version 11, that means two prior versions still get security updates. You don't get featured.

Dates, you don't get the new stuff, but you get security updates. So Android 11, the current one that means 10 and nine get security updates. So you don't, you're not being forced to do an upgrade. Most people don't upgrade their phones from an older major release to a newer major release. In other words, they don't try and go from Android eight to Android 11.

Because in fact, most of the time, the hardware manufacturer doesn't support it. That's why there's over a billion Android devices out there right now that cannot get security updates. So have a look at your phone and your vendors. See what you're running. You probably want to do an update because most phones cannot get any support on the, in the apple side.

Things are a lot different with Apple iOS, which is the operating system used on the iPhone and the I pad apple has always forced you to move to the next major version. No, they only force you to do that. If they support the hardware. And I've got to say kudos to them, they're still supporting the iPhone six S which came out quite a while.

The iPhone success is something that my wife has been using and that I had as well. In fact, she got my old iPhone success, but that's a six-year-old. Phone came out in September of 2015. So it is still getting security updates, and we'll probably continue to get them. Not only is it getting security update this six-year-old iPhone success is getting the latest and our iOS operating system.

It's getting iOS 15. Isn't that just amazing? Yeah, exactly. And so not just security updates, like you might get from some of the other vendors out there, Android vendors. So the apple keeps their arms around you for quite a while. Here's, what's changed now with Apple and iOS, the, for the first time ever in the iOS world, Apple is not forcing you to upgrade.

So you're not being forced to upgrade to iOS 15. You can continue to run iOS 14. And that's how apples got around the security patches in the past, because what happens is you get the updates and installs them. Basically. There's no reason for you not to upgrade your phone. And so you do so apple never had to worry about releasing some of these fixes for really old versions of iOS.

Although they have done that from time to time. In the Mac iOS side, Apple has done a couple of good things. The, where they always have supported basically three releases, what Google's doing with Android. So you now have a new feature. If you will, with iOS, here's a PSA for everyone. Public service announcement.

You don't have to take the iOS 15 upgrade. Now I did. I put it on my iPhone and I seem to have some sort of a problem with messages where it's telling people that my phone has notifications turned off, which it does not. So I haven't figured that one out yet. I'll have to look into that a little bit more, but.

This is nice because that means you're not going to have to upgrade your iPhone to iOS 15. You'll still get security updates for iOS 14, something Apple's never done before. We'll see if they continue this. We will see if they match Google going back. Three releases in Android. It just never been done before over on the iOS.

So good news for them. Also course in the windows world and the Mac world, you really should upgrade the operating system as much as you can. Windows 11 though, man, windows 11. And I said this to my newsletter. I warned you guys is going to be a nightmare. For many people. You are not going to be able to do an automatic upgrade unless you have the newest of hardware, with the highest end of features, Craig peterson.com.

One of the very big ransomware operations is back online. And now we have some inside information from one of the contractors working for this ransomware organization and oh yeah, there's an FBI tie, too..

This organization, ransomware gang, almost business, whatever you might want to describe them as is known as revolt. They have a few other names, but that's the really big one. And they are basically the 800 pound gorilla in the ransom. Business, you might be using cloud services right now.

Maybe you use Microsoft's email service. Their Microsoft 360, I think, is what they call it now and use it for email and various other things pretty handy. It's mostly in the cloud. Computers you own or operate or have to maintain. I think that makes some sense too, but here's the bottom line it's software as a service right now, salesforce.com software as a service, Oracle has their accounting stuff.

QuickBooks online, all software as a service. It isn't just those legitimate businesses that I just mentioned. That are using the cloud that are providing software as a service where you're paying monthly or however frequently. And you're getting this software as a service. That's what that means.

Typically it means it's in the cloud and you don't have any real control over it. That's what this ransomware gang has been doing. This gang known as rebill. They all appear to be in. And there's some interesting stuff. That's come out. A transcript was released of an interview with one of their contractors.

Now the original interview was in Russian. So I read through a translation of the Russian. I have no idea how good it is, but it is being quoted by a bank. Insider magazine that you might be familiar with bank info, security. That's one of the places that I follow. And there's a few interesting things that he talked about that I want to get into, but these are the people who have been behind things like the colonial pipeline attack and some of the other very large attacks, the way they work, their business model is.

You can license their software, their ransomware software, and you go after a business or a government agency, whatever it might be, you get that ransomware software inside. And the reveal gang will take a percentage of the money that you have in rent. Now, how is that for a, an interesting business model, right?

Taking something that the rest of the world has been using, and then take that model and put it into the legal side of the world. For three weeks, during this whole reveal ransomware attack, this summer turns out that the FBI secretly withheld the key that could have been used to decrypt. And computers that reveal had infected with ransomware and looks like kids up to maybe 1500 networks.

Now those are networks, not just computers. That includes networks run by hospitals, schools, and businesses, including critical infrastructure businesses. The way the FBI got their hands on this decryption game. Is by penetrating reveal gangs servers. So they got into it. They were able to grab the keys and then the FBI waited before.

Did anything with it. See, what they were trying to do is catch the people behind reveal. And so they didn't want to release information, get information out there to the press that might tip off those bad guys over there in Russia. And then shut down their operations. But as you might know, because I mentioned it here before the reveal gang went offline on July 13th, before the FBI could really track them down.

And then the FBI didn't release the key until July 21st. And then I think it was Malwarebytes released a decryption tool. So if you had been hacked by the gang, you could. Now, remember it isn't reveal itself. That's doing most of them. Ransomware hacking if you will or a placement it's small guys. And that's why some people, including this contractor that apparently worked for the reveal gang itself says, people think that it's the Russian government, that it's Putin, that's doing this.

He said, in fact, it's not it's small guys. And people like me are getting four or five hours a night. Because we're working so hard trying to make a whole of this work, come up with the new software approaches. We have to provide code tech support unquote to our affiliates, as well as tech support to the people who have had their computers and their data ransomed.

So it a real interesting mix. Absolutely. Interesting mix. Now Christopher Ray here a couple of weeks ago, he's the FBI director told Congress that cool. We make these decisions as a group, not unilaterally. To the FBI and working with other government agencies, these are complex decisions designed to create maximum impact.

And that takes time and going against adversaries, where we have to marshal resources, not just around the. But all over the world. So this Russian based gang first appeared in 2019, they've been around, they've been exporting large amounts of money from businesses for a very long time. One of the interest he'd things I think about all of this is that this reveal gang has their software as a service, and they provide it to quote affiliates, quote that, go ahead and then install the software, get you to install it on your computers in order to ransom you a double whammy ransom you, but there's now reports out there that there's a secret back door in the ransomwares code that allow.

Rebill to go around their affiliates and steal the proceeds. How's that for hilarious, you've got a bad guy who goes in and gets the software from revolt, pays them a commission, and then reveal apparently has been jumping in on these customer support chats. In other words, you just got nailed and because you got nailed with ransomware, you have to go to.

Chat room. And so you go in there and you're getting customer support on how to buy Bitcoin and how to transfer to their wallet. And apparently revival is getting right in the middle and is extorting money from these people directly instead of having the affiliates do it pretty amazing. So here's this part of this interview?

It was aired on the Russian news outlet, London. And was trans translated by yeah. Flashpoint. Here are the guys that got the full transcript of the interview. He says in the normal world, I was called a contractor, doing some tasks for many ransomware collectives that journalists considered to be famous.

Money is stolen or extorted with my hands, but I'm not ashamed of it. I do. And again, this goes into the thinking of many of these bad guys of Americans are all rich and they don't deserve what they have. He said, let's put it this way. This is a very time consuming job. And if you've earned enough, then you can quit the game.

But chronic fatigue, burnout, deadline. All of these words from the life of ordinary office workers are also relevant for malware developers. So there you go. You should feel sorry for these malware developers who are developing software to steal millions from you and. Down our critical infrastructure.

Hey, join me online. Craig peterson.com. And if you subscribe to my weekly newsletter right there on the site, I'll send you a few of my special reports. The most popular ones will come to you right there in your email box. Craig peterson.com/subscribe.

We all pretty much have some form of insurance. And we're going to talk right now about the types of cyber insurance you may have. Now this might be through your homeowners policy or perhaps a rider on a business policy.

Many of our homeowners policies have started coming with cyber insurance.

So we're going to talk about that. What is it? Businesses as well are also using cyber insurance and I'm sure you've heard of insurance basically called LifeLock and what that's all about. So let's kind of start. When we have a breach in a business, usually what happens is information about our customers is stolen.

Look at some of the biggest breaches in history where we. Hundreds of millions of our personal records stolen Equifax breach is an example of a huge breach where we had all kinds of personal information that was stolen by the bad guys. Now, some of this information gets stale pretty quickly, but of course, other parts of it like our address, our social security number, they are probably not going to change for years.

If for. No, of course our social security number will never change the social security administration. Just doesn't reissue them for very many reasons at all. And they do not reissue a social security number was stolen online because. Just about everybody's has, so what does a company like LifeLock do?

They keep an eye on your credit report for you. And they're looking at what's going on new accounts that are open. They look at various other things, just related to that. And they, at that point say, wait a minute, something weird is happening. Now my credit cards, for instance, I have a credit card that if let's say I buy two of the same thing, one after the other and the, both the same price that credit card company pops a message right up on my phone saying, Hey, did you just buy two?

Of these $15 things from and I can say yes or no, if I'm out on the road and I am purchasing gas, the credit card can pop up on my phone and it does and say, Hey, will you just trying to buy gas at this gas station? Because what'll happen as you use the credit card at the pump. And the pump says it was denied and then up at pops and yeah.

Okay. No, that was me. And they said, okay, we'll try the transaction. Okay. And we'll approve it next time. And that's all automated. And that has nothing to do with LifeLock. LifeLock is there to more or less detect that something happened and if something happened and it was a bad guy and basically your identity was stolen.

So they might be trying to buy a Ferrari in your name or maybe a 10 year old, four Ford focus, whatever it might be. And. They will help you try and clean it. That's what they do. So that's why it's cheap. And I don't know that it's terribly useful to you if you're really concerned. Go ahead and do that, but do keep an eye on your credit report.

I do as well. My bank has free credit reporting for me, my credit card. Same thing. Free credit reporting that lets me know everything that's going on. So that's an easy way to tell WhatsApp. And there are different types of cyber insurance beyond this sort of thing, beyond the LifeLocks of the world. And many of us just get our cyber insurance through our homeowner's policy.

It's a little rider. And businesses can buy cyber insurance as well. We have cyber insurance, that's underwritten by Lloyd's of London and we provide a $500,000 or million-dollar policy to our clients. As well, because that's what we do is cyber security, right? So the idea is if one of our clients gets hit, we have some insurance to back us up, but of course we go a lot further.

It's almost like the LifeLock where if you do get hit by ransomware or something else, we will help you get back in business. We'll help restore your data. We'll help you with providing you. The information you need in order to do press releases, which agencies you need to contact, which of your customers you need to contact.

And we've got scripts for all of that. So you can send it all out and just take care of it. So the idea is you don't want ransomware. So you hire us. We are extremely likely to keep ransomware out of your systems. And on top of that, if you are hit with ransomware, we restore everything. LifeLock does not do that.

Obviously they all, I'll only do stuff after the fact and the cyber insurance you buy from an insurance agency is much the same, and there's a huge caveat with these policies that we're buying for our businesses and for our homes. And that is. They have a checklist at the insurance companies. Did you do this and this?

And if you did, then they might payout if you did not, they may not payout. In fact, pay outs on cyber insurance policies are not known because. Bottom line. They really don't payout. Okay. I'm looking at some numbers right now and about paying ransoms and everything else. You may or may not.

You got to have a look at it. Many of these policies are never paid out by the cyber insurance covers. They usually just regular insurance companies, but it's a special rider. And what they do is they say, Hey, listen, you did not follow the rules, so we're not going to payout. And there are many cases.

If you go online and do a search, just use duck, go and say cyber insurance, payout. Lawsuits I'm doing that right now is. And it'll come up and show. Oh, okay. Does it cover lawsuits? Why are liability claims so costly? Yeah, exactly. A 2% payouts is talking about here. I'm invoicing, the most common cyber insurance claim denial.

Yeah, it goes on and on. There are a lot is an act of war clause could nix cyber insurance payouts. That's another big one that they've tried to use. So the cyber insurance company will say, Hey, that was China attacking you. Therefore it was an act of. And you can bet if there is a big hack, they will use that.

Think of what happens with the hurricanes coming onshore. How much do they push back on payouts? Especially with the real big one, it would bankrupt them. So we gotta be very careful. There are some different types of cyber insurance. Policies do which have different types of coverages. You've got the first party lost loss, I should say.

So that's you to covering you and your loss, your first-party expenses, third party liability. Each one of those has specific parameters. So sub-limit retention and others. First-party losses are usually including the loss of revenue due to business interruption. First party expenses would include all of the services and resources that you needed to use to recover from attack like forensic or system rebuilding services.

These third-party liabilities. May cover expenses and legal fees related to potential damage caused by the incident to third parties like partners, customers, or employees whose sensitive information may have been compromised. So read them carefully. Be very careful. There are next-generation, cyber insurance policies are going even further and make these types of services.

Prior to any incident to reduce exposures and prevent incidents in the first place. Now we don't provide insurance. We are not an insurance company, but that's basically what we're trying to do here. Not become an insurance company, but to make sure. The businesses have the right services so that the likelihood of anything happening or is extremely low.

And then following up after the fact it's different obviously than insurers in and insurance, the guardians, Jessica Crispin had a great article about a couple of weeks ago that I've been hanging on. And it's talking about this tattle where that's been incorporated into the computers we're using at home.

Now we're specifically talking about employers that are putting this. The software on computers, they belong to the companies. A lot of businesses are worried. If workers are at home or where we can't see them, how do we know that they're actually working, not watching Netflix or something else on.

They have, of course, come up with software that can reassure your boss. It does things like take snapshots of what you're doing. Record your keystrokes grabs photos from. Picture from your camera. There's a new program called sneak, which makes your webcam take a photo of you about once a minute and makes available to the supervisor to prove you're not away from your desk.

There's no warning in advance. It just takes that photograph catches your doom. Pretty much anything can be absolutely anything. Then, it's the type of thing you'd expect the national security agency to do. So there are some good reasons for this lack of trust because sometimes employees have not been doing what they should be doing, but this author is blaming mostly the employer here.

These companies that took out PPP loans to stay running through the end of the pandemic and then laid off thousands of workers. Anyway, there's widespread wage theft that end up to hundreds of millions of dollars a year. There's all kinds of stories out on social media, about restaurant owners, withholding waitstaff tips, et cetera, et cetera.

So this is a problem I would encourage you if you are a business owner to doublethink, should I be spying on my employees at home and a funeral employee realize it is probably perfectly legal for your employer to be using this tattle with. To keep track of you. Hey, I've got a bunch of training coming up.

There is stuff every week, in fact, in my newsletter and you can get it. Craig peterson.com/subscribe. And if you'd like my special report on passwords, make sure you send me an email. me@craigpeterson.com. And if you subscribe, you'll get a bunch of my special reports. Take care. Have a great weekend and visit me Craig peterson.com

View Details

Are You Using Encrypted Email Yet?
Here's How!

Security emails aren't something that most people think much about. Yet, they're becoming more and more important as the bad guys are monitoring us more closely to steal our information, and then there are advertisers. So, do you want them to see your stuff?

[Automated transcript]

Email is something that's been around now for quite a while.

It was undoubtedly even before the internet standards came out. Many of the systems had a version of the email. I remember some systems back in the early. The seventies, late sixties that had an email functionality is something that we've always needed. Usually, it was for just communicating within a group.

And then, in the early eighties, when I got on the internet, we could send email to people all over the world, and the email then looked a lot like it did. Now you net email, we use different types of addressing for, but basically, it's the same thing that we're used to today. Many of us have Gmail accounts.

I have some Gmail accounts. I use them basically for throw-away stuff that I don't want to have tracked. I don't use Gmail for anything that I consider particularly important, because again, it's not saying. So now there are two types of security. Really. We need to consider, and I got an email from one of the listeners today.

Who's on my newsletter? And he said, Hey, I love all of the stuff you put in the newsletter every week. It helps keep me updated on what's happening in cyber security and what things I need to know. But I'm reluctant to click on any of the links in your email because they're all trackers.

I do that so that I know what the people who subscribed to the newsletter are interested in. So, for example, I see many people clicking on an email I sent out a few months ago talking about different emails, services, and which ones provide the most WhatsApp security.

If a lot of people click on that, Then I know. Oh, okay. Great. People are interested in this. So I'll talk more about it on the radio show. I'll probably put something together for the newsletter so that they have it. It's like the example I've used for a couple of decades now, which is, Hey, if I'm looking to buy a car, I don't mind seeing a car.

Because it gives me something to compare. If I'm looking to buy an F150, I don't want to see ads for the latest Chrysler minivan. I'd like to see ads for people who are competing to sell me a Ford pickup truck. Maybe some competitors, maybe Dodge gets in there with the Ram or Chevy. Their truck, but I wanted to focus in it.

It just makes sense to me because I don't want to waste time on some shoes when that's not what I'm interested in and the person who's paying to show me this ad for shoes is wasting money and being a small businessman. I hate to see that I know what it's like. It gets really frustrating to be spending a lot of money on advertising.

That really is not going in. So you have that type of a monitoring where the advertisers are looking at, what you are looking at, what you're searching for. They know the sites you're going to, they know you're interested in that. F-150. Make sense to you? It certainly does to me as well. So I don't have a big problem at all with a people collecting basic advertising information about me.

It starts to go over a line. It's a little bit of a, an obscured thing, frankly, but it starts to go over the line where they're gathering all this information that could be useful for a bad. We don't want hackers to have the information. I want to have a hack free life. I don't want them going out there and finding information about me and, oh, I'm going to be on vacation.

I'm going to be out of town for three weeks and unable to be reached. And so that gives them the opportunity to now go in via phishing campaign. Maybe try and get my CFO to write a check to somebody or, do something that's frankly, quite malicious. What do we do? How do we deal with that? What makes sense there?

That's a really good question, frankly, and that line has to be drawn by you personally. I draw it as, I don't really care most of the time if someone knows. So here's what I do with my mail client. I turn off the automatic download of photos of pictures, and that way I can see the email. And if it's.

Piece of spam, where I don't even want that spammer to know that I opened the email. They're not going to be able to find out because my male client is not downloading photos. The way it works is you as a marketer or as a spammer. In this case, you are giving a unique URL for that. So that unique URL.

Now, if that photo's downloaded, tells you that almost certainly that person opened your email. What's a legitimate email address. You can spam it some more in the future, a little bit more about them. The same thing is true with my emails. For instance, if you sign up at Craig peterson.com/subscribe, and you get my weekly email.

The training and all the other stuff, that's, all for free in there. You now are telling me when you open it, that you opened my email. Now, why would you want to tell me that? Why would you want to tell anybody that? Nowadays when it comes to email delivery, one of the things we have to face as businesses and as a marketer, who am I using?

Mt. Is that you are great. Every email is scored. This has been true for a long time. SpamAssassin the software I've used for. I don't even know how long now, at least a decade, maybe two. And it looks at the content of the email. It looks to see how much of the email is a graphic. How much of it is using these types of words that are often used by spammers or.

Maybe crazy marketers. So they will score that email. And if it's above a certain score, if it's accumulated too many bad points that email doesn't get delivered, we have a similar system. We have some real fancy stuff that we use ourselves and we use for our clients from Cisco that compares all of these emails that are being delivered worldwide, millions of the members.

And learns from it and automatically blocks them for me, which is really great. But if I'm sending you emails, just like if you're on my email list, I'm going to send you an email at least one a week. Usually not more than two, but basically one email a week. It's not only scored on how my email reads the wording, the.

But it's also scored on how old is my domain. Have other people reported my emails as spam and how many people have opened that email sites? Google track that. So if you're on Google, if you're using. It will come up and the email come up and Google says, okay, he read the email. Maybe he downloaded the photos.

He was very interested in it. But if people are not opening the emails, you start to develop as a person sending an email, a low-risk. Lower and lower in this case, lowers is bad. Then the case of SpamAssassin hires bad. So what'll happen then is your emails will stop getting delivered. You don't want that.

I put a lot of work into these emails. I send out every week. I usually have a number of tips, usually six to eight different ones in each email. I don't want that to go to waste. So if people are not opening my email. Then I'm going to automatically remove them after a period of time from my email list, because I don't want to send email to people who aren't going to open it, because if I do that sites like Google and many others are going to stop delivering my emails to everybody else, the people that do want it, just see how that works.

So I am reliant on understanding if you open the. How can I tell? I can tell if you clicked on a link and I can also tell if you've downloaded any of the graphics that might be in that. Otherwise, I have to assume you're not opening that email. And if you're not opening that email, I don't want to send it to you because if I send it to you and you don't open it, it's going to slow down or completely stopped the delivery to other people within the.

For instance, gmail.com. And this is true for any of the major mail vendors that are out there. And I don't want that to happen. So what I ended up doing, if you have an open them for awhile, I'll send you an email saying, Hey sorry to be bothering you here. But I wanted to make sure that you did want to get these emails or I'm going to automatically remove them.

You might've had that from other people before then. The reason those emails are sent out isn't because I'm being snotty about it. It isn't because I'm upset that you subscribed and you haven't been reading the emails. It's because I don't want my email delivery to other people to be damaged because you have no pundit.

Even though I do block images from being downloaded on my emails at the top of the email when I open it up and it has a little button that says load images. And if that email is from someone that I care about it, isn't from just some spammer that stole my email address or bought it from somebody else.

If it's a legitimate email, I want to see, I click on that load images. So what happens now is the images in that email or downloaded the whoever sent me the email now knows that email was opened up and I don't also get kicked off for their list. Now, a few of you guys have complained about that with me, just not complained as much as said, why are you kicking me off of your email?

I told you it's because you haven't been opened that. Oh, but I haven't opened them. You haven't. But if you turn off the load images on emails, then I don't know that you've been reading them and therefore you're going to automatically end up being re removed. When we come back, I want to talk about secure email providers.

I'm going to compare some of them. And that came up this week because what was the number one secure email vendor out there? They no longer are. So we'll talk about that. It's all in the news. Visit me online. Craig peterson.com.

You use email, everybody uses email, but which providers provide you with security and what do these different types of security actually mean to you? Of frankly? What is security? What is a secure email?

There are a number of different secure email providers.

And there are multiple ways of defining secure email nowadays. All of the email that I send and receive from my company and I send and receive for our client companies is incorrect. There something called TLS. That is basically it's the same as HDDP S it's you know, that secure VPN that set up. No, I don't want you to get confused with these VPM services.

It has nothing to do. But if you go into your web browser and you look up in the URL bar, you'll see a little lock. It's typically on the left side of that bar, you click on it and it will come up and say, the connection is secure. What does that mean? It means that the data that you send from your browser.

We'll get to that remote server in a secure fashion will be encrypted. So if it's intercepted the third party, won't be able to decrypt it. Now there's exceptions to this, but we'll just keep it nice and simple. When we're talking about email and the two email servers talking to each other, we're talking about the same sort of thing.

If you send an email, you have an email provider. It might be my company, but it's not likely, right? Because we only deal with a certain number of small to medium businesses, but the email goes from you to a server. So let's say you're using Microsoft 365. So your email, as you're sending it to me@craigpeterson.com that email.

Goes from your browser or your email client over to the Microsoft 365 server. Now I understand there's different ways to do it. In fact, we don't do it quite this way. We always go through an intermediate server that we maintain that helps keep things secure, but the email goes over to Microsoft 365. And that first connection is probably a secured connection also by TLS.

Now you're sending it to me@craigpeterson.com. That was the two address in your email. So what happens next is it needs to find out who's handling the email for Craig peterson.com. It finds out, and then it says, A again, TLS session and encrypted session over to my email server. That encrypted session is much the same as what you have on your web browser.

It is. Very hard, very unlikely that anyone in between can see your email. And then the email ends up on my server, whatever service I'm using for my server. And then it ends up at my client. It might be on my phone. It might be on my desktop. It could be anywhere. And again, that is using another encrypted session.

There's different protocols that might be involved. For instance, I map S SMTP maybe there's TLS over SMTP, whatever. We're not going to get into all of those technical details before you guys all leave me because your eyes just glossed over, but there are a lot of ways to have that all encrypted.

So just sending an email from your phone to me@craigpeterson.com means it's going through a minimum. Four machines and each time it gets to one of these machines it's encrypted. That's hopeful, right? I'm going to knock on wood here because in reality, not every one of these points has encryption. Not every email service has that type of encryption, TLS, or other ones.

What I want to talk about now is the secure email providers. If you have Microsoft 365 email, you can go to and Microsoft website and send and receive email there. Do your calendar there. You've seen that before. I've used that before, so you can do it all online on the web server. You can also do it on your client on whatever device you have.

These secure email providers. I'm going to talk about right now as a rule are using a web front. So what is a secure email? Obviously the first step needs to be the connection from you to the server needs to be encrypted. And if you're using a web based encryption, which again is that HTTPS, which is the TLS nowadays.

That is encrypted end to ended choosing public key encryption, the whole RSA patent. And it's just fascinating stuff. It was absolutely amazing what they were able to come up with. I love it. There is also the server itself, which needs to be secured somehow. And then how about the ultimate delivery to the third party?

Now we use Cisco again. For our email filters, but that our Cisco server that we have for ourselves here in our very own data center located right here then server also handles emails for some of our other clients. So what happens now is if I want to send a secure email to somebody. Party. So I want to send it to somebody working at the bank or working at the repair shop, whatever it might be.

All I have to do is in the subject line, just say secure and the Cisco email, server's going to notice that. And it is then going to send an email off to the recipient saying you need to come to this IP address. And it gives them a link and I, and grab your secure email. So in that way, I know it was delivered to curly because whoever the recipient is had to go to this secure site on this mail server that my company maintains.

Okay. So that's another way of doing it. If you don't have the types of equipment that I have here in software that we use for small businesses, then there are still some options. The number one for quite a while has been proton mail, P R O T O N M a I L. And I wrote a big thing about that. You would have got that in my newsletter a few months ago.

If you save those things, which you shouldn't do by the way, save them all, just do a search for proton mail in there, and you'll see my detailed explanation of what it is, why you might want to use it. Proton mail is located over in Switzerland. And of course, Swiss has some good privacy laws sodas, the European union, but that was their claim to fame.

Hey, we are in Switzerland. We do not do log. We do have self-destructing messages and we have some real neat little features that you can use on your on your device. That's proton mail. It's been very good, but just this month, a Swiss court ordered proton mail to log the attachment. To their service.

So now when I say attachments, what I mean is the IP address is the two addresses the, from addresses of any body that's using their service. No, they were specifically looking for this one individual. And so now they are doing some logging. They actually have to change their website. So that's a negative and we'll explain why that's a negative.

And we'll talk about a couple of. I of the email services that are out there right now and what you can use, what you might want to use, what the costs are, so that you have a good idea. So stick around because of course we'll be right back. And I want to invite you right now to just take a couple of minutes, go to CraigPeterson.com and subscribe to the newsletter so that you get everything.

You'll get my show notes every week. You'll get some of these free trainings I'm in trying to make it so that it's under three minutes to help you understand different concepts and things that are going on. Craig, Peterson.com/subscribe

What are the features? These secure email providers are providing, what are the costs? Which ones might you want to consider? We're going to run through the top three right now. What are their features and why would you want to use them?

We started talking a little bit about Proton Mail, some of the real basics here, and it is still the kind of 800 pound gorilla when it comes to secure email, finally they had to capitulate to the Swiss court because they are located in Switzerland.

So just goes to show that even being Swiss doesn't mean that it is. Completely secured, then there's a difference too. I want to point out between having a government issue, a subpoena and a court order to have your information revealed. There's a big difference between that and a hacker who's trying to hack you and get into your life.

So I think most of us understand that we need to be secure in our documents. We need to have that privacy is guaranteed to us from the constitution, but we also need to have one more level of security, which is okay. How. The hackers. So having a hack free life means you there's a lot of things that you have to be concerned about, email being one of them.

So I'm not too worried about Proton Mail and the fact that they had a court order to. Provide IP addresses for a specific group of people. And it was a very small group and I can see that. I can agree with that. Proton Mail does have a free version. That's the one I have because I want to try it out.

And it has a 500 megabytes of free. The storage, you can get up to 20 gigabytes and Proton Mail starts at $4 a month. It has end-to-end encryption, which is really important. Again, it means from you all the way to the recipient, all three of these that I'm going to talk about have end-to-end encryption.

They also all have. Two-factor authentication. Remember when we're talking about two factor authentication, a lot of places try to pass off this thing where they send you a text message with a number in it. They try and pass that off as two factor authentication. Yeah, it is a type of two factor authentication, but it's not a.

If you're already doing something like maybe you've got cryptocurrency, you are potentially not only under attack, but I'm very hackable. If you're using a text message in order to verify who you are. So that's an important thing to remember. Proton Mail has self-destructing messages, which is a very big thing, very positive.

It tends to be expensive. Proton Mail being the 800 pound gorilla kinda dictates what kind of price they want to charge and they are on the more expensive. Side the web client is a little bit on the outdated side. It does not support pop three, which I doubt is an issue for any of you guys out there because nowadays the modern email clients aren't using.

Anyways, any more now Proton Mail has PGP support. I use PGP, I have a built into my Mac mail and it allows me to send and receive and do end encrypted messages. And that's something you might want to look at a plugin that uses PGP or GPG, which is effectively the same. Which allows you to send and receive encrypted email using your regular email client.

However, the person who's receiving it at the far end has to have that PGP client or GPG client as it is. So it might not be the best idea in the world to use that. I use it and I use it for. People within the organization that I know have PGP, because again, we're dealing with third parties information.

We have clients and the clients trust us. So we have to be pretty darn careful with some of that stuff. So that's our first one, proton mail. It's something I've used. I know a lot of you are using it. I had so many responses to that email that I sent out to everybody talking about secure email and specifically proton mail.

And you guys were all telling me, Hey, listen, I'm switched on I'm away from Google forever because Google is by far the least secure of anybody you could be using out there. Now, the next one is called top-down. Two U T a N OTA. So it gets just what Tatan call 10 town, tow hours, something like that, but a N O T a I'm sure you guys are gonna all send me pronunciation guides and it has again, a free version, one gigabyte.

So twice as much as proton mail and it doesn't really offer quite as much storage, but it starts at a dollar 18 month. Down from proton mail's four bucks a month. It also has end to end. Encryption also has two factor authentication. It has an encrypted search function, a calendar function, and aliases. I use aliases not only for my hack free life, but I use aliases because I will.

To use a different email address for pretty much everybody I'm dealing with. So these, this way to do that is with an alias. One of the problems here with top I, this is a German company. I bet you it's a German word. Somehow Tottan TOA is that it is injured. Germany is one of those 14 eyes countries. That means it's one of the 14 countries, large countries that share information about people online and spy on each other's citizens.

See, that's how the government's gotten around it. The government have preclusions from monitoring citizens. So what did they do while they all get together, serve with the five eyes now once twenty-something eyes, but they're part of the 14 eyes agreement. So Germany, for instance, would spy on us citizens while they're in the U S.

And the U S will spy on German citizens while they're in Germany and all over the world. Okay. So that's a negative, however, as a general rule, the European union has pretty good privacy laws, so you're probably safe. And then the third one, which is again, the third in my priorities here too, is called counter mail.

Now it has. Interesting features, for instance, they have what are called Ram only servers. So the server boots up, obviously it has to boot off of some sort of a device, but once it's running, everything's in memory. So if that server loses power, it loses everything. Now that's an interesting thing to do and can be a problem if you're trying to store emails, right?

It has men in the middle attack protection, which all of these due to one degree or another, but counter male makes that a kind of a big deal. They have a safe box and anonymous payment systems that you can use. And it starts at $3 and 29 cents a month. They have a four gig storage limit. They do not have a free version.

So I liked this one counter mail, but I do use proton mail, at least for testing. Some mothers also rans here that allow you to send and receive encrypted mail. Secured mail is Zoho mail, Z O H O mail. The X, Y Z is another one post deal. So I've used Zoho before, by the way post geo P O S T E O.

You might want to look@mailbox.org and start mail. So there you go. Top three proton mail. That's still my recommendation. If you want some secure email and it'll cost you a bit, if you want cheaper, look at this T U T A N O T A. All right, everybody make sure you spend right now about a minute.

Go to Craig peterson.com and sign up for my weekly newsletter and training.

Is there no such an example of Silicon valley and they're a hoity toity attitude of fake it until you make it, or is it the reality of Silicon valley? What's happening out there? WeWork and others.

Theranos. How many of you guys know about Theranos? They had a really great idea and it was started in 2003 by a 19 year old young lady named Elizabeth Holmes.

That is pretty young, but her idea was why do we need to have a whole tube or more of blood in order to do blood? With the technology we have nowadays, we should be able to just use a drop of blood and be able to test for hundreds of diseases with just a pinprick of blood. It seemed pretty incredible at the time, but she was able to.

Been a yarn that got a lot of people right into investing in her company. We're talking about nearly a billion dollars in capital that was put into their nose. How could she have fooled all of these people or was she fooling them? Was she doing what you expect to have done in Silicon valley? That is in fact the argument that her attorneys are using right now.

She is on trial because this company Theranos was never able to produce and tests. They could just take out a drop of blood and run hundreds of tests on it. And there's a lot of evidence that has come out that has shown in fact, a great little documentary that I watched not little on her and the company Theranos.

That showed that they had in fact, been taking vials of blood and using other people's equipment, not the Theranos equipment to do the valuations of the blood, to look for diseases, to look for things like vitamin D deficiency that is in fact, something that could have helped with this whole COVID-19 thing.

A real quick and cheap check a vitamin D levels in your blood, but what happened? Elizabeth Holmes was really a great talker. She was able to convince a lot of people and a lot of businesses, including Walgreens to invest in her. Not only did she have Walgreens invest in her, but some of the biggest names that you can think of in the investing community, including Rupert Murdoch, he invested in fairness.

Now her argument in her. At least her attorney's argument is, Hey, listen, we're not doing anything differently than any other Silicon valley company that's out there. It's this whole creed that they have of fake it until you make it. Is that legit. Is it just one more live from Silicon valley?

There's a great article that was in Forbes, talking about some of these, what are called unicorns. These are companies that are startups and are taken under the wing by investors, starting with angels, and then moving into venture capitalist, actually, even before angel. Friends and family and moving into venture capitalist positions, and then eventually public companies, all of these businesses really required proof before they got any funding.

So here's an example from Forbes, Airbnb. Obviously they, hadn't what we consider today to be a rather unique business model. But it had been tried before. The whole assumption was that people would rent rooms in their homes on this huge scale, but they didn't have any pre. They were the first to make it in this global trend, they built up this whole idea of becoming a hotelier yourself with your home.

But when the founder, Brian Chesky tried to get angel capital, he did not get a dime. He had to prove that renters were interested and people were interested in renting out their homes and that he could pull them together. Once he proved that, then he was able to get the money and prove is you. To have a viable business.

First, it's really rare that you don't have to, Facebook was started by Zuckerberg now, all of those stories, but the whole idea was having Harvard students connect with the. And then he expanded it to students and other universities and then expanded it to the world at large, his natural initial investors, like most or friends and family, people who give the money to you because they want to see you successful.

Eventually here. Zuckerberg was able to prove it and get money from Silicon valley. And then VCs, I'm not getting into any of the ethics of how he did it or any of these other people that had Google. Google was started by these two Stanford students page and Brin, and they got angel capital from investors.

And, but these investors were different than most the investors into Google, where people who were already very successful in the computer industry and could understand the ideas behind the algorithm and believed in page and Brynn and that they could grow this company. Microsoft. Again, another company that started with extremely questionable methods was started by gates.

And now. They didn't have any VCs, either. They started by running programs for other people. They convinced IBM that they needed to license an operating system from Microsoft and Microsoft didn't even have the rights to, and then they went out and acquired it on a non-exclusive basis. IBM acquired it from Microsoft and non-excludable exclusive basis.

Then they got VC money after they started to take off. Okay. Amazon was started by bayzos with funding from his family and small investors from Seattle. He got a VC from Silicon valley after he launched and was already earning thousands in revenues. Bezos had real proof. Walmart was started by Sam Walton with 25 grand from his father-in-law.

He built this business and financing strategy and used his skills to become one of the world's most successful companies as he grew. We work. I don't know if you've seen these. There's a great documentary out there. And we work that I watched too, but again, like Elizabeth Holmes, he was a great guy at standing in front of a group and getting investors to put money.

And he was even great at getting people to buy from. We work that he even started this whole, I think it was called wee life thing where he had people who would move into the building. That they were renting this office space from, and they'd all lived there. They all had their own little units and they'd get together every night and they'd eat together and have community and everything again, collapsed when they couldn't sustain the momentum.

And it was like a Bernie Madoff thing where he needed more money coming in order to support it. And he got incredible amounts of money from this big Japanese investor. And then we've got Theron. Elizabeth Holmes. She failed when this investigative reporter questioned whether the technology really works, the investigative reporter said, Hey, can you really do hundreds of tests reliably with just a drop of blood?

Why did this report, or even have to ask the question at all? How about all of these investors? Huge companies, my including medical field companies. How did all of them get built basically into spending about a billion dollars with her in an investor? It is a real problem. And it's a real question because ultimately what we're talking about is companies and Silicon valley thinking you fake it till you make it, who are bilking investors and everybody else out of it.

Now you have to have a certain amount of that. No matter what the company is. Do you think. Faith in yourself. You've gotta be able to stand up and make a presentation to customer or to an investor, an angel investor or friends or family, whatever it might be, but how could you have sold value to customers and convince them?

To pay the rent that's needed before you've even shown a profit. And that's a big question. Things have not changed in Silicon valley because of what we work did. And because of their failure, things have not changed because of Elizabeth Holmes and Theranos and the major failure there. These people are investing money.

They hope that two times out of 10, one times out of 10, they will actually make money from their investments. We're talking about the venture capitalists and they are jumping on all of these things that are, maybe. Quite legal. That was actually the pitch that was used by the founder of Uber.

Yeah. We don't really know if this is quite legal or not, but we're going to let people use their own vehicles to drive their own cars, to pick up strangers and take them places. And it was obviously not legal, especially in big cities where they had laws about all of this. And then all of a sudden now Silicon valley.

Really listening closely and say, oh, not quite legal. Okay. That means you are going to completely overturn the whole industry. And that means we could make a whole lot of money on you again, just the knee jerk. So we've got to be careful. The other side of the point and coin is the secret sauce, which is many companies are being careful to not disclose things for very good reason.

They don't want an employee to leave and take with them. Their secrets. Look at the lawsuits that have been out there with Google and some of the other self-driving companies. You stole an executive, the executive brought all of this knowledge. Them. And maybe even some documents, this should not be legal.

And now you've got the Biden administration issuing an executive order, trying to change this whole thing by saying, while you cannot lock people in to not disclosing or to your secrets or to not compete with you. How well to Silicon valley or any business anywhere. To keep their secrets, their secret sauce, the recipe to Coke.

If you will, how are you going to keep it secret if you cannot hold people to these nondisclosure agreement? And so I think again, the Biden administration is going the complete. Wrong direction. I'm going to keep an eye on this whole Theranos thing, this trial that's going on. I didn't have an idea how it's going to turn out, but we do have to change the fake it till you make it.

Ideology of Silicon valley. Hey, take a minute and sign up online. Get my free special reports and trainings. Craig peterson.com. Your cybersecurity strategist.

It doesn't look like what's app is safe anymore. So what can you use if you want to have a conversation with someone, how many of you have a friend that's in China or Iran or Afghanistan or one of those other countries?

I was warning about our friends at Facebook. Of course they've been buying competition and in fact, they're being sued right now because of that.

And they have been going after these companies that look like they are going to eat Facebook's lunch and then they buy them for way more. The market value. So what are the founders supposed to do? If I was offered crazy money for my company, I'd sell it at the drop of a hat. Just like that. It'd be done.

Thank you very much. WhatsApp is one of those apps. My Facebook and Facebook bought it, allegedly because it looked like it was going to be serious competition. So our friends at the federal government decided, okay, we'll let this one go and we'll let them know. When Facebook gets their hands on something, it's like Google, getting their hands on, what's going to happen.

Ultimately Facebook is going to be using it in order to sell you things. I'm not against having these various websites that we use, online apps and other things going ahead and Colleen us a little bit. What about things we want things to mean might want that we don't even know we want because we don't know they're available.

So there's a lot of good reasons from a marketing perspective for them to be able to find out what we're into. They used to be a little bit different than it is today, but not that much. I was in the. Oh, direct marketing business way back in the seventies. It was my second job, really. And I wrote software.

That was part of this system that actually put all of our competitors in the country, out of business. Yeah. I wonder if they're still around. It's called marketing electronics of Canada. And let me see if it comes up. Eh, statistics and be okay, so it's not really around anymore. So they master gone out of business.

But what we would do for our customers is we'd say, okay, so who should you mail to this? It was direct mail back in the day. And so when we get asked a business, we were in and so they'd say, oh, okay. How about we mail to what 40 year old men who maybe want to buy a pickup truck? So how would we do that?

We would look for the magazines that 40 year old men were likely to be. We'd look for anything, the newspaper subscriptions, neighborhoods. It was a real big deal. When, of course the zip code came in. That's not what it is in Canada, but the postal codes came into place because then we could narrow it down based on neighborhoods.

So we'd put all of this together and we'd say, okay if someone is getting this magazine, And they're definitely not getting that magazine, but they're getting this newspaper and they live in this part of town. Then we put all of that together and we did the duplicate eliminations and figured out exactly.

Okay, this is who we want to be. And then we would do direct mail for the customer to all of those people. So it would be whatever it might be back in the day, it was Grolier encyclopedia was our, one of our customers and Columbia music. You remember, those guys was one of our customers and a few other places out there and we made pretty good money and the, it was pretty easy to do.

But back then we were doing almost the same thing. This was what now? 40 plus years ago, as they are doing today. But Facebook of course has way more information. They don't just know what website you might be going to, which is the equivalent of which magazines did you subscribe to back in the day, but they all say.

Are in the middle of your conversations, they know who your friends are. They know what your friends have bought. They know what your friends are interested in. So it's not that much different than it used to be, but it's more intrusive because now instead of only having one. A couple of hundred magazines Countrywide that people might subscribe to.

We now have millions of websites that we're likely to go to. And we have the conversations, the listen in which frankly, I think is the worst part of all of them. So when they bought WhatsApp, there was a warning of by myself and others saying, be careful, Facebook's going to start to watch you on WhatsApp and Facebook.

Good. No. That's never going to happen. There's an article that came out this week. Okay. It's absolutely amazing. This was from pro public. Who looked at the WhatsApp messaging platforms, privacy claims, WhatsApp of course offers quote end-to-end encryption and quote, which most people interpret means that Facebook who owns WhatsApp.

Can neither read your messages nor send them off to law enforcement. So some of us are concerned that they're reading it and they're using it from Arcadena et cetera, which okay. I can see, that's a little bit of an invasive invasion of privacy, but it's nothing that hasn't been going on since the 1950s.

And the other side of it is what happens if the bad guys get their hands on that information or law enforcement? It reminds me of the old days was stolen, remember stolen. And in his henchmen, they said, Hey, show me the person I'll show you the crime. And the reason he was able to say that is there's so many potential laws that you can bring.

If you tell me the person's name, I'll dig into them and watch them, and we'll be able to accuse them of a crime and get them convicted and thrown in prison. So there's those of us who are worried about that potentially happening, then you might say it's not going to happen today. I think frankly, it well could happen today more than it could have, or would have happened just a few years ago, but it keeps getting worse and worse.

So I get all. Stuff, but the claim to WhatsApp being safe to say anything on that. No one's monitoring you. No one can see what you're saying is basically false because what they've found a ProPublica is that Facebook employs about a thousand WhatsApp moderators whose entire job is reviewing WhatsApp messages.

Now, about some of the censorship this has been going on at Facebook. This is not the same thing because in general, in Facebook, of course, everything is open and available for their computer systems to flag. The automated systems will see it and say, oh, okay. Yeah, this is bad. And they'll just shut you down and then maybe send it off for a person to review.

What's happening here with WhatsApp is someone can flag a message that they have received at. Improper now that's where it starts getting to be a little bit crazy here, because with this loophole in WhatsApp's end-to-end encryption, now you don't have that to fall back on that they don't have it, that they can't read.

The recipient of any of the WhatsApp messages can flag it once. Flag the messages copied on the recipient's device and sent as a separate message to Facebook for review. Now, the messages are typically flagged for the same reasons they would be on Facebook, but one of the things that's been happening.

Is with this content moderation, people who have received the messages from people that they don't like are reporting these messages to Facebook. So they might be in, in a group. You typically is why it works happening. And in, within this group, there's people who are saying things that they just don't like.

That is frankly a loophole. Absolutely a loophole. So it's not any different from someone receiving a message screenshot in it or shown their device to another person that's received. But now it's an automated process. Millions of teams every year have found that out too, with their disappearing videos on Snapchat.

They don't all just disappear. And that's a problem we're having right now with WhatsApp. So what should you use? What could you use? The number one recommendation that I have for you guys is to use signal. You'll find it online. Signals available for every mobile device out there, pretty much it's available for most desktop operating systems and it is end to end encrypted.

And the guy who wrote it who has Mr. Marlin spike has an odd name? He has done this because he wants people to have true privacy in their messages. So signal pretty good. WhatsApp, not so good. You might not want to use it, but by the way, it's huge in use. Hey, take a minute. If you haven't already sign up for my weekly show notes and my trainings that are in them, you'll get them absolutely free.

Craig peterson.com. And if you had done that, you'd already know all about WhatsApp and signal and what type of email you should be using.

Big data has strikes again in this time it's in Los Angeles. If you get pulled over by the police, would you give them your social media information, your email address, et cetera. Question mark? Huh? Here we go.

LAPD has started doing something that most people are saying is unethical and may be illegal is well, they were sued the Los Angeles police department in order to.

Some information out of the police department. Cause some people had been reporting things and the Brennan center for justice is what it's called, sued them. Okay. Now this is at the New York school of law. The NYU school of law, the Brennan center is, and they filed a public records request with LAPD and police departments from other major cities.

And they were trying to find out what's going on. What kind of data are these police departments collecting and the LAPD resisted making these documents available? I guess that's a clue, right? And so they did ultimately provide over 6,000 pages of documents after the Brennan center. Sued the department.

And one of these documents was a memo from the LAPD chief. His name was Charlie. Back in May, 2015. He said that quote one, completing. F I report officers should ask for persons shall social media and email account or information and included in the additional info box. Now, what they're talking about is a, basically a field contact or field interview form, and he was telling them that they need to get all kinds of information, basically anything they can, but more specifically, once or Twitter handle Instagram.

Profiles. There's a spot on here for all kinds of information. I'm looking at the report right now. Who are the name your date of birth, your sex, your gang, your or your monitoring moniker? Yeah, not everyone's in a gang guys. And let's see field interview, incident number, the division detail.

So the only thing, oh, and by the way, social security number as well. And if you're asking them for their social security number, it tells you they have to read this assess federal law requires that you be in. When asked for your social security number that must be provided for use and identification authority for required.

This information is based upon field interview procedures operational prior to January 1st, 1975. Remember the social security number was only going to be used by the treasury department for. Income to verify that you'd been paying and would not be used by any other federal departments or state and local.

In fact, it was illegal at the time. Anyways, I guess I'm rambling about this. Cause the social security number thing really upsets me because of. Everybody's collecting it and the bad guys have your social security number and it's being used as some sort of a university universally unique number.

We call those UIDs IDs in the computer world, but it's not. And unlike a regular you ID that can easily be regenerated, they will not issue you in a new social security number. If your old one was stolen. It's really crazy. So it may be an unusual policy, even though the LAPD has been doing it for years.

Let's see. So a lawyer in the burn-in centers, the library in national security programs wrote, he said, apparently nothing bars officers from filling out field interview forms for each interaction, they engage. On patrol, notably our review of information about the field information cards in 40 other cities did not reveal any other police departments that use the cards to collect social media data though.

Details are spars, publicly available documents to try to determine if other police departments are channeling. I collect social media during the field interview were requested, but found that most are not very transparent about their practices. So I guess that's not too surprising. Here's where it starts getting more concerning for me anyways.

And that is, they are feeding all of this information from these contact cards into a system that was developed by. Amazon. This is a system called plant Palentier. There you go. Palentier. And in fact, there was an open letter that was written by the staff at Amazon to Jeff. Bayzos asking bayzos to stop selling this technology to law enforcement.

Okay. That's how bad it is. Here's an article from ARS Technica. Amazon staff have called on CEO, Jeff Bezos to stop selling facial recognition technology to law enforcement and government agencies. Do the book 10 channel that the tech is used to harm the most marginalized. Microsoft and Google also have done the same thing.

Now you hear that and you say, that's really good, kudos to you. I'm glad that you are trying to stop this. And yet at the same time, these same employees don't seem to have a problem with selling this technology to the red, Chinese. At all, they don't seem to have a problem with it in some of these other countries that are using it for just terrible things.

Further this letter that they wrote demanded that Amazon stopped selling their cloud services to data analytics from planet here. They have numerous government contracts involved in the operation of ISIS detention and deportation programs goes on and on. So what makes sense to you? The ACL you recently reported that Amazon's recognition facial technology is being sold to police departments.

It can identify faces in photos and videos. Amazon pitched in as a way of identifying and tracking suspects. The issue that is raised here by the ECLU is the militarization of the police. How far can it go? Should it go? The targeting of activists and ISIS family separation policy. Now this was in 2018, just so that okay. So back in the day, of course, anything president Trump did was evil. And so this stuff they came out and said was evil. I haven't, I looked and I haven't got anything more reasoned about this. So for some reason, the Biden administration using this, isn't a problem LAPD using this apparently was a problem and continues to be a problem.

Keep an eye out for it locally, because here's the other side of this whole thing they say. Are they being the police officer when they pull you over I need this information. I need to inspect your car. I need to search your person, et cetera. They may need to, but that doesn't mean that they have the.

Legal right or constitutional right to do it. So typically the police only ask for things that they can constitutionally asked for, that they should ask for. And people, most people know they can refuse a search depending on the circumstances and they, but they don't because you're honoring the police officer.

Going on from there honoring the police officer. I also mean that people are allowing the police to gather this information because of, again, the respect that giving to that police officer. And in fact, they apparently do. There's another study in this article that talks about that. It's a problem.

We gotta be careful all of this data being fed into a big system that tracks us, that, the bad guys are going to get their hands on that data. Eventually. Hey, visit online Craig peterson.com and check out today's newsletter. You'll find in there links to this and all of today's stories.

Do you remember when president Trump was trying to block Tik TOK, this Chinese social site that so many of us were using? Of course now that's all gone. That's all history. And there's another piece of news about them.

Tik TOK is a social media site that really rose a like crazy. It is owned by 10 cent, which is a Chinese company. Now, as all companies in China are controlled by the socialists, the communist party of China, the CC CCC CCP. Remember those initials from back in the day.

They are now being given access to location information about Americans, about all kinds of places in the United States, in photos, people's names, their locations, you name it. Through tick talk to Chinese government, the Chinese military, the people's liberation army as they call it. And we're giving all of this information voluntarily.

So president Trump had a problem with that. Why should a Chinese company be allowed to track American citizens? Now at the time, took talk was quite popular and was growing in popular. Now we're seeing a news story from the BBC saying the tech talk has overtaken YouTube in the average watch time per user in the United States and the United Kingdom.

YouTube is still the bigger video site. They have YouTube as far more users, they have far more video that's watched, but what we're talking about here is something that is specific, but it's still scary, which is the average us tick-tock user watches, more video than the average YouTube view. So if you're a marketer, maybe it's time to get on Tik TOK, but also right now, tick talk is really the younger generations.

It's not the older folk. Okay. I expect that eventually just like Facebook started with the college students and it has now really grown to being a an over 40, even over a 50 year old web. At Facebook, the same thing will happen for Tik TOK, but we're getting concerned here because tic talk is upended the streaming and social landscape.

With these small videos, it reminds me of how the goldfish, why is the gold fish or the happiest animal in the world? Because it only has a five second. That was just great from Ted lasso. I don't know if you've watched that show at all. That's one of these apple TV shows out there it's really it's really true because these Tik TOK videos are extremely short and the whole goal of it is to have something that's funny and they've had challenges and various other things that they've done too, but they have really gone crazy.

Google has tried to counter tic talk. They've had their own little thing. Facebook's had their own little thing with these short videos, but this time spent metric that we're talking about here is from the monitoring from app Annie. That's the name of it. And it only accounts. Android phones because some of this monitoring cannot be done on I-phones.

Okay. But it also does not include China where tech talk is a major app in over in China. It's called . I probably didn't pronounce that one quite right either, but it is a massive audience that they have out there and. I'm looking at all of the stat. It's just absolutely amazing. You can see those of course in the newsletter for today, but yeah.

Live streaming apps Twitch. For example, viewers can purchase bits virtual currency and send them to cheer for streamers journal, live stream and stuff. This is an interesting business. Tik TOK has definitely taken it over. And we're seeing that that nobody's been able to really do anything. YouTube has it's Tik TOK clone called YouTube short.

It was launched in may. This is a 62nd video clips, whole ideas. It's mobile first it's swipe up. Also out there with, I love this. This is ARS Technica, calling it a photocopier, which is what YouTube does, within an upstart video service comes along a Twitch, see YouTube gaming. Anyways, everybody's trying to get into it.

No one's being successful at it yet, other than tech talk. And do we really want the red, Chinese having access to all of that? Think what's innovative. You've got GPS information coming from your smartphone. So they know exactly where it's taken. They know who you are. They know information about you as a user.

I don't know. It gets scary. And then you think about what happened with the Wu Han lab and what escaped out of there. Could they use that? Might they use that home? My goodness on a very concerned. Okay. From Krebs on security, we have a warranty. For Microsoft users, attackers are now exploiting a windows zero day PLA.

So this is a previously unknown vulnerability in windows 10 and many windows server versions. And what it allows them to do is seize control over PCs. When users open a malicious document or. A booby trapped website. There's currently no official patch for it, but Microsoft has released recommendations in order to help mitigate the threat.

These mitigations aren't the best, frankly, but we'll see it affects what's called the Ms. HTML component of internet Exploder on windows 10 and many windows servers that are out there. And of course, internet Exploder has been deprecated. For use people should not be using it anymore. So for those of you who are still using internet Explorer, I've got two words for you from the famous Bob new heart, just an amazing guy.

So here we go. Okay. Here you're there. That's from an old routine. I couldn't help, but think of it, but yeah, that's the bottom line. You need to stop using internet Explorer. It does not work well. It is bug Laden. Like most Microsoft software seems to be, and it is now under direct attack. So make sure that.

Patch had Shirley patch off. And now I am in the middle of putting together. This is another bit of free content for everybody, but two things. One is a cyber health assessment that you can do yourself. And shall I show you how? And I'm going to have a course on that too. A paid course that gets into a lot more detail.

But the basics is, I want you guys to understand that. And then the other thing is in the next 90 days, what are the things that you should do and can do to make your computers safer? Now, as usual, this is aimed at businesses, but works great for. Individuals for home users. And we'll see how this ends up going.

But frankly, the zero day attacks are going to keep happening. They happen to Microsoft. They happen to apple. They happen to everybody, but they all release patches. The only one that you are going to have trouble with patches on is older versions of windows. And of course Android. What else do I have to say?

Any older Android phone? Cause they lose support very quickly. So don't use those, but make sure patch Tuesday. All of those patches are installed from Microsoft and visit me online. Craig peterson.com. Make sure you sign up for my newsletter so you can get these coming up and more.

View Details

Do You Know How to Identify a Fake Web Page? The FBI's reporting that more than 70% of all business hacks are because of our employees. They're clicking on emails, they're going to websites, what can we do? How do we know if a website is legitimate or not?

[Automated transcript]

[00:00:19] There's a great little article that McAfee published now, McAfee is a company that's been in the cybersecurity business for quite a while.

[00:00:28] I do not use their products. I use some competing products. I have not been impressed with their products.

[00:00:35] Let me tell you this particular web post that they put up is fantastic and you'll see it in my newsletter this week. Make sure you get that.

[00:00:45] Have you ever come across a website that didn't look quite right if you haven't, you haven't been on the internet very much because whether you're an individual at home or you are in a business environment, we are likely going to end up on websites that are not legitimate. Sometimes we'll see these things, that company logo might be wrong. There's not enough information on the page. You've been there before and this looks down page. The odds are that you were on a hack site, a site that's trying to get you to do something most of the time when you end up on these sites, they're trying to get you to put in your username and password.

[00:01:31] Already that the bad guys have stolen your username and password from so many websites out there. So why would they try and do it this way? It's because if they're pretending to be your bank and you try and log in, They know this as your bank account, and many times they immediately try and get into your bank account or your phone account, whatever it might be.

[00:01:56] This is a very long-standing tactic that's relied on by hackers everywhere. Usually it's a knockoff of a real page. They'll take it and they will recreate it. Then it's easy to do if you're in a web browser right now, when you go to your bank's website. You can just go to file, save as, and go ahead and save the entire webpage and you'll get everything.

[00:02:23] You'll get all of the links that are on there. All of the graphics that are there, it'll pull it in for you all automatically. And that's all they do. That's what they use. Just a copy. How do they get in front of you in the first place? Typically the hackers will go ahead and send a phishing email.

[00:02:43] They'll make the email sound legitimate. They'll make it look legitimate. They'll often even use a URL that looks a lot like it. B the real banks email. I've seen it before where the URL is bank of america.safe site.com. That sort of a thing. I'm not blaming safe site. They could be a great company.

[00:03:04] I don't know. I just made it up as we're going, but that type of a URL where it's not really bank of america.com or it's a misspelling of bank of America, that's the sort of thing that gets to be pretty darn common and. Clicking on that link and then submitting your information. It hasn't been leading to credit card fraud, data extraction, wire transfers, identity theft, and a whole lot more.

[00:03:34] Now with the COVID relief, that's been out there. All of these things from filing for unemployment claims through filing for PPP protection as a business, the whole. Industry has changed. I'm talking about the hacker industry here, because there are so many people who are falling for these scams and ransomware as well has gone up over 300%.

[00:04:08] It's just absolutely amazing. Now, if you go online and you duck, duck, go. Fake login pages. And for those of you who don't know what I mean by that duck go is the search engine I've been recommending lately. It is a search engine that doesn't take politics into play like Google does. And it also does not track you.

[00:04:31] And what you're looking at it is ad based. It gets its revenue from advertisement, but it's not selling your information just on the basic search. That you're doing. I think it's a very good alternative, but if you go ahead and your search for fake login pages, you're going to find thousands of guides on how to create websites.

[00:04:53] And these bad guys can create these websites in absolutely no time at all. It just a minute or two in order to make one of them. Now it can be difficult nowadays to figure out if it's a fake site, because the, again, the hackers are constantly updating their techniques to be more sophisticated. So it's made it more difficult for consumers to really recognize when something's fraudulent.

[00:05:22] Now I want to get it into a psychological term. In attentional, blindness. You've probably heard of this. I remember this from, I think it was college days for me, so a very long time ago, but there's a study that was done on inattentional blindness called the invisible gorilla test. If you go right now online and just search for invisible gorilla test, you'll see a bunch of these coming.

[00:05:52] No, there's even a book called that the invisible gorilla test that came out about 11 years ago, 12 years ago, I think. But here's the bottom line on this? They tell you to do something in this study. What they did here is there's a video. People there's six people, three of them are dressed with white shirts and three of them have black shirts and they're passing basketballs back and forth.

[00:06:20] The white shirts are only passing to the white shirts and the black shirts under the black shirts. And what they ask you to do is count the number of times the team in white past. Now, you're sitting there watching, knowing they're going to try and fool you, you're paying a whole lot of attention to it.

[00:06:40] And then at the end, they ask you a question that may be not expecting the video. I just watched on this, that was called the monkey business. Illusion is the name of this. I counted and I counted carefully and I came up with 16 passes. So the monkey business, illusion, 16 times the people in the white shirts passed the basketball back and forth.

[00:07:06] So I got that. But then they said did you notice the person in the gorilla costs? Who walked through the game. He didn't just walk through the game, walked in, beat on this chest and then walked out of the game. If you didn't know about this and okay. In chorus, all honesty, I always try and put everything upfront here.

[00:07:29] I knew about it beforehand. I remember from college days. But eight, most people actually about 50% of people who did not know, there is a gorilla in the middle of this. Would not have noticed the gorilla walking through the game, but this monkey business illusion video, there's something else too.

[00:07:52] And I've got to admit, I did not notice that. And that is the curtain color change. From red to gold, this curtain that was in the background of all of these players. And I didn't notice one other thing. I'm not going to tell you what that is. You'll have to watch the video of yourself too, to figure that out again, just go online and search for the monkey business illusion.

[00:08:19] And I think you'll find it. So the reason I brought this up is because if you come across a well forged login page and you're not actively looking for signs of fraud, you're fairly likely to miss a cybercriminals gorilla. You're likely to miss that the logo's not quite right, or the placement isn't the same as I'm used to.

[00:08:45] Because you're focused in, on doing what you're supposed to be doing. It's the whole concept as well of have tunnel vision. And I'm sure you're aware of that. We've all had that before, where we're really focused on this one little thing and we don't notice everything else going on. It particularly happens in high stress times.

[00:09:08] So how do you steer clear of the fake login pages? We're going to talk about that when we get. But it's absolutely crucial for everyone, even if you've had phishing training and you are trying to be cautious, you could fall for this invisible gorilla and enter in your personal details, not something that you really want.

[00:09:36] Hopefully you guys got my newsletter last weekend. I got a lot of comments on it. People are saving. In fact, that's the first thing I said in this email last week is don't lose this because it went through point by point on about 10 different things that you should be doing too. Yourself and your business safe during the holidays.

[00:10:03] Now, of course we had labor day coming up. We're going to have more holidays, right? There's always more holidays in the future and less it's after the first of the year, then you got to wait a long time. Make sure you get it, make sure you dig it out. If he didn't notice it just search for me@craigpeterson.com.

[00:10:23] That's where the email comes from and have a look at that. I have links on how to do all of those things. It's very important. FBI warning out just last week.

[00:10:33] I just told you about one of the biggest problems we are facing right now, when it comes to hackers and then has to do with fishing and going to fake login pages. Now I'm going to tell you exactly what to do.

[00:10:47] How do you steer clear of these fake log-in pages and how do you protect yourself in case you accidentally do provide the bad guys with the information that you shouldn't have?

[00:11:01] If they've got your email address or your login name and they have your password, it's pretty easy for them to log in. In most cases right into your bank account. So first of all, don't fall for phishing, but as we just described because of this whole inattentional blindness that we have, it's easy enough to fall, pray for this.

[00:11:28] Beat yourself up too bad if you followed, if you fell for some of that stuff, but there is a great little website the Google has that you might want to check out. And that website gives you a real quick quiz, is the best way to. And it shows you some emails and you get to determine whether or not you think it's fishing and then it tells you what the reality of it is.

[00:11:59] So go to fishing quiz. Dot with google.com. If you miss that, you can always email me M e@craigpeterson.com and I'll send it off to, but phishing quiz dot with google.com. And of course, phishing is spelled P H I S H I N G fishing. Dot with google.com. So you can go there and right there on the screen, it says, take the quiz.

[00:12:30] You can hit it and make up a name and an email address. So it doesn't have to be your real name or your real email address. Okay. It's not going to send you anything. It's not going to sign you up for stuff. It just wants to use it in. Phishing email examples. That's going to give you, so I put in a fake name and a fake email address and it is showing me an email.

[00:13:00] So to me, from a Luke, John. And it says Luke Johnson shared a link to the following document, Tony 21 budget department dot doc. So if I click on that, I have now told them, Hey, I'm open to all that sort of stuff. It's so anyways, it's got the link and it's got the opening docs and you now up above say, is this phishing or is it.

[00:13:27] Legitimate. Okay. So if we say fishing that says, correct, this is a phishing email. You might have spotted the look alike, you are out. And that is indeed exactly what it is cause it it wasn't legitimate. And remember when you mouse over a link, you can see down at the bottom. The URL that is going to open up for you.

[00:13:51] So you can just go through this at your own speed at your own pace and figure it out again. If you didn't get that, you can always email me M E ed Craig peterson.com. And I'll be glad to get back to you. So that's a good way to learn about fishing. I want to con really warn, I should say businesses. If you are sending out phishing emails to your employees to see if they are opening fake phishing emails or not.

[00:14:23] That's an okay. Practice. The problems really come in with the companies that are sending out phishing emails and are then following up in such a way that employee is punished in some places they are being punished by if you've opened three fake emails over the last year or whatever it might be.

[00:14:47] But over the last year, you're. It's that bad. So we have to be careful. You're not going to increase the confidence of your employees by doing that. And what's, you're actually going to end up doing is slowing down the productivity of your employees. Because now they're going to be really worried about opening, any emails that look like they might be legitimate.

[00:15:14] And so your business is going to slow right down. So having some more training about it. Okay. I can see that everyone makes mistakes and we've got to remember that as well, but watch free, man. But we really are trying to get you to move quickly, act fast, or I need this answer right away. Or one of the big ones is we've got this vendor and in fact, I'll, let me give you a real world example.

[00:15:41] It's a manufacturing company and of course they. To buy product from vendors, as supplier. And then they use that product or whether it's copper or whatever it might be now to put it all together to make their products. And this one person, this one, hacker a lady again in Eastern Europe, she went and found out about this company.

[00:16:08] Okay, great. Found on their website, who the CEO was, who the CFO was. Okay, great. And was able to find the CEO online on Facebook and on his Facebook account, he said, yeah, we're going to The Bahamas. Rear-ending a sailboat. We're going to be out there, the whole family for two weeks. This is going to be fantastic disconnected.

[00:16:37] So she found all of that. Now what she had to do was she found out who it was. The CEO, what school he went to. So first she had to get around the restrictions. Cause he had said, don't share my posts with anyone other than friend. So she sent him a message because she found his LinkedIn profile. You see how easy this is to do.

[00:16:59] She found his LinkedIn profile and that he went to Harvard and got his MBA. So she sent him. A little note saying, Hey, remember me Janie from X, Y, Z class at Harvard, and want to be friends catch up a little bit. And then he doesn't remember who she is, but the picture looks cute enough. I might as well say yes.

[00:17:21] And now she had his contact information over on LinkedIn, send him a friend request over on Facebook as well. That's how she found out he was going to be gone for two weeks. And so now she knows when he's gone. And where he's going to be completely out of touch. So once he's gone about two or three days later, she sent an email off to the CFO inside the company and said, Hey.

[00:17:49] We've got this new vendor they've been providing us with product for the last three months. We haven't paid them at all yet. I need you to wire. It was a little more than $40 million because she'd done her homework. She knew how much money the company made, what their expenses probably were. I need you to wire $40 million to this account, or they're going to stop.

[00:18:17] All shipments to us. And instead of the CFO doing a little bit more homework into it and digging in and finding out because talking to the people in receiving that we've never received anything from that company. I don't know what you're talking about. And then talking with the guy on the manufacturing floor, the CFO didn't do any of that, just okay. This looks legit. And by the way, it is so easy for these hackers to also gain access to personal email accounts. And we're not going to spend time going into that right now. So he wired. Yes indeed. So there's an example of falling for fishing. A little bit of follow up on the part of the CFO would have shown him that this was not legitimate.

[00:19:07] Even over on Shark Tank. Barbara Cochran. She fell prey to this, actually it was her assistant and who wired some $400,000 to a vendor that wasn't real. Now the good news is the assistant copied Barbara who saw the email right away and said, whoa, wait a minute. They called the bank and they put a stop on it..

[00:19:34] Doing a little training here on how to spot fake log-in pages. We just covered fishing and some real world examples of it, of some free quiz stuff that you can use to help with it. And now we're moving on to the next step.

[00:19:50] The next thing to look for when it comes to the emails and these fake login pages is a spelling mistake or grammatical errors.

[00:20:02] Most of the time, these emails that we get that are faking emails are, have really poor grammar in them. Many times, of course the commas are in the wrong place, et cetera, et cetera. But most of us weren't English majors. So we're not going to pick that up myself included. That's why I use Grammarly.

[00:20:21] If you have to ever write anything or which includes anything from an email or a document you probably want to get Grammarly. There's a few out there, but that's the one I liked the best for making sure my grammar. So a tip, to the hackers out there, but the hackers will often use a URL that is very close to it.

[00:20:45] Where are you want to go? So they might put a zero in place of an O in the domain, or they might make up some other domain. So it might be amazon-aws.com or a TD bank-account.com. Something like that. Sometimes the registrars they'll catch that sort of thing and kill it. Sometimes the business that they are trying to fake will catch it and let them know as well.

[00:21:19] There's companies out there that watch for that sort of thing. But many times it takes a while and it's only fixed once enough people have reported it. So look at the URL. Make sure it's legitimate. I always advise that instead of clicking on the link in the email, try and go directly to the website.

[00:21:41] It's like the old days you got a phone call and somebody saying, yo, I'm from the bank and I need your name and social security numbers. So I can validate the someone broke into your account. No, they don't. They don't just call you up like that nowadays. They'll send you a message in their app.

[00:21:56] That's on your smart. But they're not going to call you. And the advice I've always given is look up their phone. And by the way, do it in the phone book, they remember those and then call them back. That's the safest way to do that sort of thing. And that's true for emails as well. If it's supposedly your bank and it's reporting something like someone has broken into your account, which is a pretty common technique for these fissures, these hackers that are out there, just type in the bank URL as it not what's in the email.

[00:22:33] There will be a message there for you if it's legitimate, always. Okay. So before you click on any website, Email links, just try and go directly to the website. Now, if it's one of these deep links where it's taking new Jew, something specific within the site, the next trick you can play is to just mouse over the link.

[00:22:58] So bring your mouse down to where the link is. And typically what'll happen is at the bottom left. Your screen or of the window. It'll give you the actual link. Now, if you look at some of them, for instance, the emails that I send out, I don't like to bother people. So if you have an open one of my emails in a while, I'll just automatically say, Hey, I have opened them in awhile, and then I will drop you off the list.

[00:23:28] Plus if you hit reply to one of my newsletters, my show notes, newsletters. That's just fine, but it's not going to go to me@craigpeterson.com and some people you listeners being the best and brightest have noticed that what happens is it comes up and it's some really weird URL that's so I can track.

[00:23:51] Who responded to me. And that way I can just sit down and say, okay, now let me go through who has responded? And I've got a, kind of a customer relationship management system that lets me keep track of all of that stuff so that I know that you responded. I know you're interacting, so I know I'm not bothering you.

[00:24:11] And I know I need to respond. Much the same thing is true with some of these links. When I have a link in my newsletter and I say, Hey, I'm linking to MIT's article. It is not going to be an MIT. Because again, I want to know what are you guys interested in? So anytime you click on a link, I'll know, and I need to know that, so I know why, Hey, wait a minute.

[00:24:36] Now, 50% of all of the people that opened the emails are interested in identifying fake login pages. So what do I do? I do something like I'm doing right now. I go into depth on fake logs. Pages. I wouldn't have known that if I wasn't able to track it. So just because the link doesn't absolutely look legit doesn't mean it isn't legit, but then again, if it's a bank of it involves financial transactions or some of these other things be more cautious.

[00:25:11] So double check for misspellings or grammatical errors. Next thing to do is to check the certificate, the security certificate on the site. You're on this gets a little bit confusing. If you go to a website, you might notice up in the URL bar, the bar that has the universal resource locator, that's part of the internet.

[00:25:38] You might've noticed a. And people might've told you do check for the lock. That lock does not mean that you are safe. All it means is there is a secure VPN from your computer to the computer on the other side. So if it's a hacker on the other side, you're sending your data securely to the hacker, right?

[00:26:05] That's not really going to do you a whole lot of good. This is probably one of the least understood things in the whole computer security side, that connect. May be secure, but is this really who you think it is? So what you need to do is click on their certificate and the certificate will tell you more detail.

[00:26:29] So double check their certificate and make sure it is for the site. You really. To go to, so when it's a bank site, it's going to say, the bank is going to have the bank information on it. That makes sense. But if you go for instance on now, I'm going to throw a monkey wrench into this whole thing.

[00:26:48] If you go to Craig peterson.com, for instance, it's going to. Connection is secure. The certificate is valid, but if you look at their certificate and the trust in the details, it's going to be issued by some company, but it's going to just say Craig peterson.com. It's not going to give a business name like it would probably do for a bank.

[00:27:14] So you know, a little bit of a twist to it, but that's an important thing. Don't just count on the lock, make sure that the certificate is for the place you want to contact. Last, but not least is multi-factor authentication. I can't say this enough. If the bad guys have your username or email address and your password for a site, if you're using multifactor authentication, they cannot get in.

[00:27:53] So it's going to prevent credential stuffing tactics, or they'll use your email and password combinations that have already been stolen for mothers sites to try and hack in to your online profile. So very important to set up and I advise against using two factor authentication with your, just a cell phone, as in a text message SMS, it is not secure and it's being hacked all of the time.

[00:28:23] Get an authorization. Like one password, for instance, and you shouldn't be using one password anyways, for all of your passwords. And then Google has a free one called Google authenticator. Use those instead of your phone number for authentication.

[00:28:40] You're listening to Craig Peterson, cybersecurity strategist, and online@craigpeterson.com.

[00:28:48] I've been warning about biometric databases. And I sat down with a friend of mine who is an attorney, and he's using this clear thing at the airport. I don't know if you've seen it, but it's a biometric database. What are the real world risks?

[00:29:04] This clear company uses biometrics.

[00:29:08] It's using your eye. Brent, if you will, it's using your Iris. Every one of us has a pretty darn unique Iris, and they're counting on that and they're using it to let you through TSA very quickly. And this attorney, friend of mine thinks it's the best thing since sliced bread, because he can just. On through, but the problem here is that we're talking about biometrics.

[00:29:34] If your password gets stolen, you can change it. If your email account gets hacked, I have another friend who his account got hacked. You can get a new email account. If your Iris scan that's in this biometric database gets stolen. You cannot replace your eyes unless of course you're Tom cruise and you remember that movie, and it's impossible to replace your fingerprints. It's possible to replace your face print. I guess you could, to a degree or another, some fat injections or other things. Could be done to change your face sprint, but these Iris scans fingerprints and facial images are something I try not to provide any.

[00:30:29] Apple has done a very good job with the security of their face print, as well as their fingerprint, because they do not send any of that information out directly to themselves or to any database at all. Period. They are stored only on the device itself. And they're in this wonderful little piece of electronics that can not be physically compromised.

[00:30:59] And to date has not been electronically compromised either. They've done a very good job. Other vendors on other operating systems like Android, again, not so much, but there are also databases that are being kept out there by the federal government. I mentioned this clear database, which isn't the federal government, it's a private company, but the federal government obviously has its fingers into that thing.

[00:31:29] The office of personnel. For the federal government, they had their entire database, at least pretty much the entire database. I think it was 50 million people stolen by the red, Chinese about six years ago. So the communists. Copies of all of the information that the officer personnel management had about people, including background checks and things.

[00:31:55] You've probably heard me talk about that before. So having that information in a database is dangerous because it attracts the hackers. It attracts the cybercriminals. They want to get their hands on it. They'll do all kinds of things to try and get their hands. We now have completely quit Afghanistan.

[00:32:20] We left in a hurry. We did some incredibly stupid things. I just, I can't believe our president of the United States would do what was done here. And now it's been coming out that president and Biden completely ignored. The advice that he was getting from various military intelligence and other agencies out there and just said, no, we're going to be out of there.

[00:32:46] You have to limit your troops to this. And that's what causes them to close the air base battleground that we had for so many years. Apparently the Chinese are talking about taking it over now. Yeah. Isn't that nice. And whereas this wasn't an eternal war, right? We hadn't had anybody die in a year and a half.

[00:33:05] It's crazy. We have troops in south Vietnam. We have troops in Germany. We have troops in countries all over the world, Japan, you name it so that we have a local forest that can keep things calm. And we were keeping things calm. It's just mind blowing. But anyhow, politics aside, we left behind a massive database of biometric database.

[00:33:38] Of Afghanis that had been helping us over in Afghanistan, as well as a database that was built using us contractors of everyone in the Afghan military and the basically third genealogy. Who their parents were the grandparents blood type weight, height. I'm looking at it right now. All of the records in here, the sex ID nationality.

[00:34:11] Date of exploration, hair color, favorite fruit, favorite vegetables, place of birth, uncle's name marker signature approval. Signature date, place of birth. Date of birth address, permanent address national ID number place of ISS. Date of ISS native language salary data salary, group of salary, police of salary education, father's name, graduation, date, weapon and service now.

[00:34:41] These were all in place in Afghanistan. We put them in place because we were worried about ghost soldiers. A gold soldier was someone who we were paying the salary of taxpayers of the United States were paying the salaries of the Afghan military for quite some time. And we were thinking that about half of the.

[00:35:06] Payroll checks. We were funding. We're actually not going to people who were in the military, but we're going to people who were high up within the Afghan government and military. So we put this in place to get rid of the ghost soldiers. Everybody had to have all of this stuff. In the database, 36 pieces of information, just for police recruitment.

[00:35:39] Now this information we left behind and apparently this database is completely in the hand of the Taliban. Absolutely. So we were talking about Americans who helped construct Afghanistan and the military and the telephone. The looking for the networks of their Ponant supporters. This is just absolutely amazing.

[00:36:07] So all of the data doesn't have clear use, like who cares about the favorite fruit or vegetable, but the rest of it does the genealogy. Does they now know who was in the police department, who was in the military, who their family is, what their permanent address is. Okay. You see the problem here and the biometrics as well in the biometrics are part of this us system that we were using called hide H I D E.

[00:36:41] And this whole hide thing was a biometric reader. The military could keep with them. There were tens of thousands of these things out in the field. And when they had an encounter with someone, they would look up their biometrics, see if they were already in the database and in the database, it would say, yeah, they're friendly, they're an informant.

[00:37:03] Or we found them in this area or w we're watching them. We have concern about them, et cetera, et cetera. All of their actions were in. Turns out that this database, which covered about 80% of all Afghans and these devices are now in the hands of the Taliban. Now, the good news with this is that a lot of this information cannot be easily extracted.

[00:37:32] So you're not going to get some regular run of the mill Taliban guy to pick one of these up and start using. But the what's happening here is that we can really predict that one of these surrounding companies like Pakistan that has been very cooperative with the Taliban. In fact, they gave refuge to Saddam, not Saddam Hussein, but to a bin Ladin and also Iran and China and Russia.

[00:38:04] Any of those countries should be able to get into that database. Okay. So I think that's really important to remember now, a defense department spokesperson quote here, Eric Fay on says the U S has taken prudent actions to ensure that sensitive data does not fall into the Tolo bonds. And this data is not at risk of misuse.

[00:38:29] Misuse that's unfortunately about all I can say, but Thomas Johnson, a research professor at the Naval postgraduate school in Monterey, California says not so fast, the taller Bon may have used biometric information in the Coon dues. So instead of taking the data straight from the high devices, he told MIT technology review that it is possible that Tolo bond sympathizers in Kabul, provided them with databases of military personnel, against which they could verify prints.

[00:39:07] In other words, even back in 2016, it may have been the databases rather than these high devices themselves pose the greatest risk. This is very concerning big article here in MIT technology review. I'm quoting from it a little bit here, but there are a number of databases. They are biometric. Many of these, they have geological information.

[00:39:35] They have information that can be used to round up and track down. Now, I'm not going to mention world war two, and I'm not going to mention what happened with the government too, before Hitler took over, because to do that means you lose that government had registered firearms, that government had registered the civilians and the people and Afghanistan.

[00:40:04] The government was also as part of our identification papers, registering your religion. If you're Christian, they're hunting you down. If you were working for the military, they're hunting you down. And this is scary. That's part of the reason I do not want biometric information and databases to be kept here in the U S Hey, make sure you get my show notes every week on time, along with free training, I try to help you guys out.

[00:40:41] If you've never heard of the Carrington event, I really hope, frankly, I really do hope we never have to live through one of these. Again, there is a warning out there right now about an internet apocalypse that could happen because of the sun.

[00:40:58] Solar storms are something that happens really all of the time. The sun goes through solar cycles. About every seven years, there are longer cycles as well. You might know. I have an advanced class amateur radio license I've had for a long time, and we rely a lot when we're dealing with short wave on the solar cycle.

[00:41:22] You see what happens is that the sun charges, the atmosphere. That if you've ever seen the Northern light, that is. Part of the Sunzi missions, hitting our magnetic field and getting sucked into the core of the earth, if you will, as they get caught in that field. And the more charged the atmosphere is, the more bounce you get.

[00:41:46] That's what we call it bounce. And the reason us hams have all these different frequencies to use is because of the bow. We can go different frequencies with different distances, I should say, using different frequencies. So think about it right now. You've got the earth and I want to talk from Boston to Chicago.

[00:42:08] For instance, I know about how many miles it is, and I have to figure out in the ionosphere up in the higher levels of the atmosphere, what frequency. To use in order to go up into the atmosphere, bounce back, and then hit Chicago. That's the idea. It's not quite as simple or as complex in some ways, as it sounds, a lot of people just try different frequencies and a lot of hams just sit there, waiting for anybody anywhere to talk to, particularly if they are.

[00:42:41] It's really quite fun. Now what we're worried about, isn't so much just the regular solar activity. We get worried when the sun spots increase. Now, the solar cycle is what has primary image. On the temperature on earth. So no matter what, you might've heard that isn't your gas, guzzling car or a diesel truck that causes the Earth's temperature to change.

[00:43:10] Remember the only constant when it comes to the Earth's temperature has been changed over the millions of years. We had periods where the earth was much warmer than it is now had more common that carbon dioxide in the atmosphere than it does now had less. In fact, right now we are at one of the lowest levels of carbon dioxide in the atmosphere in earth long.

[00:43:36] So the sun, if you might remember, comes up in the morning, warms things up, right? And then it cools down. When the sun disappears at nighttime, it has a huge impact. It's almost exclusively the impact for our temperatures. There's other things too, for instance. eruption can spew all to hold a lot of carbon dioxide.

[00:44:01] In fact, just one, just Mount St. Helens wanted erupted, put more carbon dioxide into the atmosphere than man has throughout our entire existence. Just to give you an idea, right? So these alarms that are out there, come on, people. Really, and now we're seeing that in this last year, we had a 30% increase in the ice cap up in the, in, up in the north, up in Northern Canada, around the polls.

[00:44:32] We also had some of these glaciers growing. It was so funny. I saw an article this year, or excuse me, this week that was showing a sign that was at one of our national parks. And it said this glacier will have disappeared by 2020. Of course it hasn't disappeared. In fact, it has grown now and it's past 2020.

[00:44:54] Anyhow, the sun has a huge impact on us in so many ways. And one of the ways is. Something called a coronal mass ejection. This is seriously charged particles. That tend to be very directional. So when it happens, when there's one of these CMS coronal, mass ejections, it's not just sending it out all the way around the sun everywhere.

[00:45:21] It's really rather concentrated in one. One particular spot. Now we just missed one not too long ago. And let me see if I can find it here. Just mast, a cm E near miss. Here we go. There a solar super storm in July, 2012, and it was a very close shave that we had most newspapers didn't mention it, but this could have been.

[00:45:51] AB absolutely incredible. We'd be picking up the pieces for the next 50 years. Yeah. Five, zero years from this one particular storm. And what happens is these solar flares, if you will, are very extreme, the CME. You're talking about x-rays extreme UV, ultraviolet radiation, reaching the earth at the speed of light ionizes, the upper layers of atmosphere.

[00:46:19] When that happens, by the way, it hurts our communications, but it can also have these massive effects where it burns out saddle. And then causes radio blackouts, GPS, navigation problems. Think about what happened up in Quebec. So let me just look at this back hit with an E and yeah, here we go. And March 13th, 1989.

[00:46:50] Here we go. Here's another one. Now I remembered. And this is where Quill back got nailed. I'm looking at a picture here, which is looking at the United States and Canada from the sky and where the light is. And you can see Quebec is just completely black, but they have this massive electrical blackout and it's becomes.

[00:47:13] Of this solar storm. Now they, these storms that I said are quite directional depending on where it hits and when it hits things can get very bad. This particular storm back in 1989 was so strong. We got to see their Rora Borealis, the Northern lights as far south, as Florida and cute. Isn't that something, when we go back further in time to this Carrington event that I mentioned, you could see the Northern lights at the eclipse.

[00:47:50] Absolutely amazing. Now the problem with all of this is we've never really had an internet up online. Like we have today when we had one of the storms hit. And guess what we're about to go into right now, we're going into an area or a time where the sun's going to be more active, certainly on this 11 year cycle and possibly another bigger cycle too, that we don't really know much about.

[00:48:22] But when this hit us back in the 1850s, what we saw was a a. Telegraph system that was brought to its knees. Our telegraphs were burned out. Some of the Telegraph buildings were lit. They caught on fire because of the charges coming in, people who were working the telegraphs, who are near them at the time, got electric shocks or worse than that.

[00:48:48] Okay. 1859 massive Carrington event compass needles were swinging wildly. The Aurora Borealis was visible in Columbia. It's just amazing. So that was a severe storm. A moderate severity storm was the one that hit in Quebec here knocked out Quebec electric. Nine hour blackout of Northeast Canada. What we think would happen if we had another Carrington event, something that happened to 150 years ago is that we would lose power on a massive scale.

[00:49:27] So that's one thing that would happen. And these massive transformers that would likely get burned out are only made in China and they're made on demand. Nobody has an inventory. So it would be at least six months before most of the country would get power back. Can you believe that would be just terrible and we would also lose internet connectivity.

[00:49:52] In fact, the thinking that we could lose internet connectivity with something much less than a severe storm, maybe if the Quebec power grid solar, a massive objection here. Maybe if that had happened, when. The internet was up. They might have burned out internet in the area and maybe further. So what we're worried about is if it hits us, we're going to lose power.

[00:50:20] We're going to lose transformers on the transmission lines and other places we're going to lose satellites and that's going to affect our GPS communication. We're going to lose radio communication, and even the undersea cables, even though they're now no longer. Regular copper cables. It's now being carried of course, by light in pieces of glass.

[00:50:45] The, those cables need to have repeaters about every 15 miles or so under underwater. So the power is provided by. Copper cables or maybe some other sort of power. So these undersea cables, they're only grounded at extensive intervals, like hundreds or thousands of kilometers apart. So there's going to be a lot of vulnerable components.

[00:51:12] This is all a major problem. We don't know when the next massive. Solar storm is going to happen. These coronal mass ejections. We do know they do happen from time to time. And we do know it's the luck of the draw and we are starting to enter another solar cycle. So be prepared. Of course, you're listening to Craig Peterson, cybersecurity strategist.

[00:51:42] If you'd like to find out more and what you can do, just visit Craig peterson.com and subscribe to my weekly show notes.

[00:51:52] Google's got a new admission and Forbes magazine has an article by Zach Dorfman about it. And he's saying you should delete Google Chrome now after Google's newest tracking admission. So here we go.

[00:52:09] Google's web browser. It's been the thing for people to use Google Chrome for many years, it's been the fastest. Yeah, not always people leapfrog it every once in a while, but it has become quite a standard. Initially Microsoft is trying to be the standard with their terrible browser and yeah, I to Exploder, which was really bad and they have finally completely and totally shot it in the head.

[00:52:42] Good move there on their part. In fact, they even got rid of their own browser, Microsoft edge. They shot that one in. They had to, I know I can hear you right now saying, oh, Craig, I don't know. I just use edge browser earlier today. Yeah. But guess what? It isn't edge browser. It's actually Google Chrome. The Microsoft has rebranded.

[00:53:04] You see the guts to Google Chrome are available as what's called an open source project. It's called chromium. And that allows you to take it and then build whatever you want on top of. No, that's really great. And by the way, Apple's web kit, Kat is another thing that many people build browsers on top of and is part of many of these browsers we're talking about right now, the biggest problem with the Google Chrome.

[00:53:35] Is they released it so they could track you, how does Google make its money? It makes us money through selling advertising primarily. And how does it sell advertising if it doesn't know much or anything about you? So they came out with the Google Chrome browser is a standard browser, which is a great.

[00:53:55] Because Microsoft, of course, is very well known for not bothering to follow standards and say what they have is the actual standard and ignoring everybody else. Yeah. Yeah. I'm picking on Microsoft. They definitely deserve it. There is what is being called here in Forbes magazine, a shocking new tracking admission from.

[00:54:17] One that has not yet made headlines. And there are about what 2.6 billion users of Google's Chrome worldwide. And this is probably going to surprise you and it's frankly, Pretty nasty and it's, I think a genuine reason to stop using it. Now, as you probably know, I have stopped using Chrome almost entirely.

[00:54:42] I use it when I have to train people on Chrome. I use it when I'm testing software. There's a number of times I use it, but I don't use it. The reality is that Chrome is an absolute terror. When it comes to privacy and security, it has fallen way behind its rivals in doing that. If you have an iPhone or an iPad or a Mac, and you're using safari, apple has gone a long ways to help secure your data.

[00:55:19] That's not true with Chrome. In fact, it's not protecting you from tracking and Dave data harvesting. And what Google has done is they've said, okay we're going to get these nasty third party cookies out of the whole equation. We're not going to do that anymore. And what they were planning on doing is instead of knowing everything specifically.

[00:55:43] You they'd be able to put you in a bucket. So they'd say, okay, you are a 40 year old female and you are like driving fast cars and you have some kids with a grandkid on the way, and you liked dogs, not cats, right? So that's a bucket of people that may be a few hundred or maybe up to a thousand. As opposed to right now where they can tell everything about you.

[00:56:12] And so they were selling that as a real advantage because they're not tracking you individually anymore. No, we're putting you in a bucket. It's the same thing. And in fact, it's easier for Google to put you in a bucket than to track everything about you and try and make assumptions. And it's easier for people who are trying to buy ads to place in front of you.

[00:56:34] It's easier for them to not have to reverse engineer all of the data the Google has gathered in instead. To send this ad to people that are in this bucket and then that bucket. Okay. It makes sense to you, but I, as it turns out here, Google has even postponed of that. All right. They really have, they're the Google's kind of hiding.

[00:56:59] It's really what's going on out there. They are trying to figure out what they should do, why they should do it, how they should do it, but it's going to be a problem. This is a bad habit. The Google has to break and just like any, anybody that's been addicted to something it's going to take a long time.

[00:57:19] They're going to go through some serious jitters. So Firefox is one of the alternatives and to Google Chrome. And it's actually a very good one. It is a browser that I use. I don't agree with some of the stuff that Mozilla and Firefox does, but again, nobody agrees on everything. Here's a quote from them.

[00:57:41] Ubiquitous surveillance harms individually. And society Chrome is the only major browser that does not offer meaningful protection against cross site tracking and Chrome will continue to leave users unprotected. And then it goes on here because. Google response to that. And they admit that this massive web tracking out of hand and it's resulted in, this is a quote from Google and erosion of trust, where 72% of people feel that almost all of what they do online is being.

[00:58:19] By advertisers, technology firms or others, 81% say the potential risks from data collection outweigh the benefit by the way, the people are wrong. 72% that feel almost all of what they do on online is being tracked. No. The answer is 100% of what you do is probably being tracked in some way online.

[00:58:41] Even these VPN servers and systems that say that they don't do logs. Do track you take a look at proton mail just last week. Proton mail it's in Switzerland. Their servers are in Switzerland. A whole claim to fame is, Hey, it's all encrypted. We keep it safe. We don't do logging. We don't do tracking guess what they handed over the IP addresses of some of the users to a foreign government.

[00:59:09] So how can you do that? If you're not logging, if you're not tracking. Yeah, they are. And the same thing is true for every paid VPN service I can think of. So how can Google openly admit that their tracking is in place tracking everything they can, and also admit that it's undermining our privacy.

[00:59:36] Their flagship browser is totally into it. It's really, it's gotta be the money. And Google does not have a plan B this anonymized tracking thing that they've been talking about, the buckets that I mentioned, isn't realistic, frankly. Google's privacy sandbox is supposed to Fitbit fix it.

[00:59:56] I should say. The whole idea and the way it's being implemented and the way they've talked about it, the advertisers on happy. So Google is not happy. The users are unhappy. So there you go. That's the bottom line here from the Forbes article by Zach Dorfman, delete Google Chrome. And I said that for a long time, I do use some others.

[01:00:20] I do use Firefox and I use. Which is a fast web browser. That's pretty good shape. Hey, if you sign up for my shows weekly newsletter, not only will you get all of my weekly tips that I send to the radio hosts, but you will get some of my special reports that go into detail on things like which browser you shouldn't be using.

[01:00:46] Sign up right now. Craig peterson.com.

[01:00:50] Many businesses have gone to the cloud, but the cloud is just another word for someone else's computer. And many of the benefits of the cloud just haven't materialized. A lot of businesses have pulled back and are building data centers.

[01:01:07] Now, the reason I mentioned this thing about Microsoft again, and the cloud is Microsoft has a cloud offering.

[01:01:17] It's called Microsoft Azure. Many people, many businesses use it. We have used it with some of our clients in the past. Now we have some special software that sits in front of it that helps to secure. And we do the same thing for Amazon web services. I think it's important to do that. And we also use IBM's cloud services, but Microsoft is been pitching for a long time.

[01:01:45] Come use our cloud services and we're expecting here probably within the next month, a big announcement from Microsoft. They're planning on making it so that you can have your desktop reside in Microsoft's cloud, in the Azure cloud. And they're selling really the feature of it doesn't matter where you are.

[01:02:11] You have your desktop and it doesn't matter what kind of computer you're on. As long as you can connect to your desktop, using some just reasonable software, you will be able to be just like you're in front of a computer. So if you have a Chromebook or a Mac, Or windows or tablet, whatever. And you're at the grocery store or the coffee shop or the office, you'll be able to get it, everything, all of your programs, all your files.

[01:02:41] And we, Microsoft will keep the operating system up to date for you automatically a lot of great selling points. And we're actually looking into that, not too heavily yet. We'll give them a year before we really delve into it at all. Cause it takes them a while to get things right. And Microsoft has always been one that adds all kinds of features, but most of the time, most of them don't work and we can document that pretty easily, even in things like Microsoft.

[01:03:11] The verge is now reporting that Microsoft has warned users of its as your cloud computing service, that their data has been exposed online for the last two years. Yeah, let me repeat that in case you missed it, you yeah. I'm I might've misspoken. Let me see, what does it say? It says users of Azure cloud competing service.

[01:03:36] So that's their cloud. Microsoft's big cloud. Okay. Their data has been. Exposed online. Okay. So that means that people could get the data, maybe manipulate the data that's exposed means for the last two years. Are you kidding me? Microsoft is again, the verge. Microsoft recently revealed that an error in its Azure cosmos database product left more than 3,300 as your customer's data.

[01:04:12] Completely exposed. Okay guys. So this is not a big thing, right? It can't possibly be big thing because you know who uses Azure, nobody uses a zer and nobody uses hosted databases. Come on, give me a break. Let me see, what else does this have to say? Oh, okay. It says that the vulnerability was reported, reportedly introduced into Microsoft systems in 2019, when the company added a data visualization feature called Jupiter notebook to cosmos DB.

[01:04:46] Okay. I'm actually familiar with that one and let's see what small companies let's see here. Some Azure cosmos DB clients include Coca Cola. Liberty mutual insurance, Exxon mobile Walgreens. Let me see. Could any of these people like maybe Liberty mutual insurance and Walgreens, maybe they'd have information about us, about our health and social security numbers and account numbers and credit cards. Names addresses. That's again, why I used to get so upset when these places absolutely insist on taking my social security number, right? It, first of all, when it was put in place, the federal government guaranteed, it would never be used for anything other than social security.

[01:05:34] And the law even said it could not be used for anything other than social security. And then the government started expanding it. And the IRS started using it. To track all of our income and that's one thing right there, the government computers, they gotta be secure. All of these breaches we hear about that.

[01:05:52] Can't be true. So how about when the insurance company wants your personal information? Like your social security number? What business is it of? There's really no. Why do they have to have my social security number? It's a social security number. It's not some number that's tattooed on my forehead. That's being used to track me.

[01:06:18] Is it this isn't a socialist country like China is, or the Soviet union was right. It's not social. So why are they tracking us like that? Walgreens? Why do they need some of that information? Why does the doctor that you go to that made the prescription for Walgreens? Why do they need that information?

[01:06:40] And I've been all over this because they don't. Really need it. They want, it makes their life easier, but they don't really need it. However, it exposes us. Now, if you missed the email, I sent out a week ago, two weeks ago now, you missed something big because I, in my weekly newsletter went through and described exactly what you could do in order to keep your information private.

[01:07:13] So in those cases where websites asking for information that they don't really need, right? You don't want to lie, but if they don't really need your real name, why you're giving them your real name? Why do you use a single email address? Why don't you have multiple addresses? Does that start make sense to you guys?

[01:07:33] And now we find out that Microsoft Azure, their cloud services, where they're selling cloud services, including a database that can be used online, a big database 3,300 customers looks like some of them are actually big. I don't know. ExxonMobil pretty big. Yeah. I think so. Walgreens, you think that might be yeah.

[01:07:57] Why. Why are we trusting these companies? If you have a lot of data, a lot of customers, you are going to be a major target of nation states to hack you and bat just general hackers, bad guys. But you're also if you've got all this information, you've also got to have a much higher level of security than somebody that doesn't have all of that information.

[01:08:24] Does that make sense to you? Did I say that right? You don't need the information and I've got to warn anybody that's in a business, whether you're a business owner or you're an employee, do not keep more data than you need the new absolutely need to run your company. And that includes data about your customers.

[01:08:48] And maybe it's even more specifically data about your customer. Because what can happen is that data can be stolen and we just found it. That? Yes, indeed. It could have been, it was exposed Microsoft the same. We don't know how much it was stolen. If anything was stolen. Yeah, Walgreens. Hey, I wonder if anyone's going to try and get some pain pills illegally through a, this database hack or a vulnerability anyways.

[01:09:17] All right, everyone. Stick around. We'll be back. Of course, you listening to Craig Peterson. I am a cybersecurity strategist for business, and I'm here to help you as well. You can ask any question any time consumers are the people I help the most, I wish I got a dime for every time I answered a question.

[01:09:38] Just email me@craigpeterson.com and stick around.

[01:09:44] Whether or not, you agree with the lockdown orders that were put in place over this COVID pandemic that we had. There are some other parts of the world that are doing a lot more.

[01:10:00] Australia has. I don't know. I think that they went over the deep end that much, the same thing is true right next door to them.

[01:10:11] And I am looking at a report of what they are doing with this new app. You might be aware that both apple and Google came out with an application programming interface. That could be used for contract tack tracking, contact tracking. There you go. It wasn't terribly successful. Some states put some things in place.

[01:10:38] Of course you get countries like China. I love the idea because heaven forbid you get people getting together to talk about a Tannen square remembrance. Now you want to know who all of those people were, who were in close proximity, right? Good for China a while, as it turns out, Australia is putting something in place they have yet another COVID lockdown.

[01:11:03] They have COVID quarantine orders. Now I think if you are sick, you should stay here. I've always felt that I, I had 50 employees at one point and I would say, Hey, if you're sick, just stay home. Never required a doctor's note or any of that other silliness, come on. People. If someone's sick, they're sick and let them stay home.

[01:11:26] You don't want to get everybody else in the office, sick and spread things around. Doesn't that just make sense. They now in Australia, don't trust people to stay home, to get moving. Remember China, they were taking welders and we're going into apartments in anybody that tested positive.

[01:11:42] They were welding them into their apartment for minimum of two weeks. And so hopefully they had food in there and they had a way to get fresh water. Australia is not going quite that far, but some of the states down under. Using facial recognition and geolocation in order to enforce quarantine orders and Canada.

[01:12:07] One of the things they've been doing for very long time is if you come into the country from out of the country, even if you're a Canadian citizen, you have to quarantine and they'll send people by your house or you have to pay to stay for 10 days in a quarantine hope. So you're paying the, of course now inflated prices for the hotel, because they're a special quarantine hotel.

[01:12:34] You have to pay inflated prices to have food delivered outside your door. And that you're stuck there for the 10 days, or if you're at home though, they, you're stuck there and they'll send people by to check up on you. They'll make phone calls to check up on you. They have pretty hefty fines.

[01:12:54] What Australia has decided to do is in Australia is Charlene's even going from one state to another state are required to prove that they're obeying a 14 day quarantine. And what they have to do is have this little app on their phone and they, the app will ping them saying, prove it. And then they have to take a photo of themselves with geo location tag on it and send it up via the app to prove their location.

[01:13:32] And they have to do all of that within 15 minutes of getting the notification. Now the premier of the state of south Australia, Steven Marshall said, we don't tell them how often or when on a random basis, they have to reply within 15 minutes. And if you don't then a police, officer's going to show up at the address you're supposed to be at to conduct an in-person check.

[01:13:59] Very intrusive. Okay. Here's another one. This is an unnamed government spokesperson who was apparently speaking with Fox news quote. The home quarantine app is for a selected cohort of returning self Australians who have applied to be part of a trial. If successful, it will help safely ease the burden of travel restrictions associated with the pandemic.

[01:14:27] So there you go. People nothing to worry about. It's just a trial. It will go away. Just for instance, income tax, as soon as rule, number one is over, it will be removed and it will never be more than 3% and it will only apply to the top 1% of wage-earners. So there you go. And we all know that world war one isn't over yet.

[01:14:47] So that's why they still have it in somehow. Yeah, some of the middle class pays the most income tax. I don't know. Interesting. Interesting. So there you go. Little news from down under, we'll see if that ends up happening up here. News from China, China has China and Russia have some interesting things going on.

[01:15:08] First of all, Russia is no longer. Country, they are. They aren't, they are a lot freer in many ways than we are here in the United States. Of course, China, very heavily socialist. In fact, they're so socialists, they are communist and China. And Russia both want their kids to have a very good education in science, engineering, and mathematics.

[01:15:35] Not so much on history, not so much on, on politics. But definitely heavy on the sciences, which I can see that makes all the sense. I think everybody should be pretty heavily on the science. According to the wall street journal this week, gamers under the age of 18 will not be allowed to play online games between 8:00 PM and 9:00 PM on Friday, Saturdays and Sundays.

[01:16:02] Okay. So basically what they're doing, I reverse that what they're doing is they're only allowing the kids three hours of gaming per week. In other words, they can play between eight and 9:00 PM, Friday, Saturday, and Sundays. I think that might overload some gaming servers. Cov gaming addiction has affected studies and normal lives.

[01:16:23] And many parents have become miserable. That's China's press and public administration. Sedna state. Okay. There's going to be some relief during the school holidays. Children will be allowed 60 minutes per day for gaming hard to say how China plans didn't force it, but they have their ways, identity cards. By the way required for playing online. They've got a facial recognition system introduced in July by 10 cent. Remember all of the uproar around 10 cent and their apps and president Trump trying to get them blocked here in the U S yeah, there you go. Facial recognition bill right into the app, and it's proven effective at catching children pretending to be adults in order to get around government gaming curves.

[01:17:12] So this goes on and on and Korea as well, South Korea has had some very big problems. You might remember it was headlines just a few years ago of some of these south Korean kids dying because they were playing video games four days straight with no sleep, no real food. Just taking all of these energy.

[01:17:37] And we'll literally gaming themselves to death. So South Korea passed a law that prevented young people from playing online video games late at night. So that was introduced back in 2011 and it's targeted at players 16 or up. And south Korean miners were prevented from playing online PC games between midnight and six, 8:00 AM.

[01:18:03] Now South Korea has scrapped that law. Interesting. So they're saying it's out of respect for younger citizens, right? They're going to abolish this law, replace it by. Permit system that allows players to request a permit per game and play during self-assigned hours that their parents will sign off on.

[01:18:27] This is in an article from GameSpot, by the way, a gamespot.com. You might remember them too, the whole Robin hood scandal. But I think it's an interesting question. When my kids were young lo those many years ago I got this box that the, you took the TV wire, you ran it into the box and you could program.

[01:18:51] So that each kid had their own code and you could specify how much time the kid could watch TV or how much time or when they could watch TV and how much time cumulative the kids could have. And it actually worked pretty well. And the kids certainly complained a lot about it. And a couple of them tried to work the way around it hard to when the plug is inside the box.

[01:19:17] Yeah, ingenuity as they are. They were able to do that. They cut the wire off and put another power connector on the end of the TV wire. Anyhow Microsoft, we've been talking about them a lot. This show. I do not like Microsoft, that already the windows 11 is coming out and we talked about.

[01:19:38] Before, because windows 11 is plying. Microsoft is planning on requiring you to have a very modern computer. You need to have a TPM in it, which is this special security module. You need to have a certain speed, et cetera, but the TPM is a big thing. That's going to make it. So most of your computers won't work.

[01:20:04] Tons of pushback on that. I can see what Microsoft is trying to do it. They really would love to have a clean operating system that really wasn't getting hacked all the time. And this will help it won't solve their problem, but it will help. So that they're going to be doing now is they're going to over the course of months, starting October 5th.

[01:20:28] They're going to release windows 11 to certain people, one at a time type approach. So they're not going to force everyone to upgrade. They're not going to offer it to everyone. And Microsoft is going to offer a preview of the Android apps in the Microsoft store for windows insiders in the months ahead.

[01:20:51] But they're planning on having a phased rollout through winter. Date, and you're not going to see it most likely when it starts to roll out, but you will be seen and to end with the stringent system requirement, apparently what they're going to do is not auto update your computer if it's not new enough.

[01:21:13] And if it doesn't have a TPM, but you can manually install windows 11, at least that's what they're doing. That's it for today. We had some more stuff I didn't get to, but we always have more every week. And I try to keep you up to date. We do trainings, visit me online so you can find out about all of this stuff.

[01:21:33] The trainings, most of them are absolutely free. Craig peterson.com/subscribe. Craig peterson.com.

View Details

You Need to Start Using Burner Identities ASAP!

In this day and age, if you don't have a burner identity, you are really risking things from having your identities stolen through these business email compromises. It's really crazy. That's what we're going to talk about.

[Automated transcript]

An essential part of keeping ourselves safe in this day and age is to confuse the hackers. The hackers are out there. They're trying to do some things. Ransomware, for instance, like[00:00:30] business email compromise, is one of the most significant crimes times out there today.

It hits the news legitimately. It's terrifying. It can really destroy your business, and it can hurt you badly. If you're an individual, you don't want ransomware. How about those emails that come in? In fact, I just got an email from a listener this week, and they got a phone. His wife answered, and it was [00:01:00] Amazon on the phone, and Amazon said, Hey, listen, your account's been hacked.

We need to clear it up so that your identity doesn't get stolen. And there's a fee for this. It's a $500 fee. And what you have to do is just go to amazon.com. Buy a gift card, and we'll then take that gift card number from you. And we'll use that as the fee to help recover your stolen information. [00:01:30] So she went ahead and did it, and she went ahead and did all of the things that the hackers wanted.

And now they had a gift card. Thank you very much. We'll follow up on this and. Now she told her husband, and of course, this isn't a sex-specific thing, right? It could have happened to either one. My dad fell for one of these scams as well. So she told her husband, or her husband looked at what had happened and [00:02:00] said, oh my gosh, Don't think this is right.

Let me tell you, first of all, Amazon, your bank, various credit card companies are not going to call you on the phone. They'll send you a message right from their app, which is usually how I get notified about something. Or they will send an email to the registered email app. No, that you set up on that account.

So that [00:02:30] email address then is used by them to contact you, pretty simple. Or they might send you a text message. If you've registered a phone for notifications, that's how they contact you. It's like the IRS. I was at a trade show, and I was on the floor. We were exempt. And I got no less than six phone calls from a lady claiming to be from the IRS, and I needed to [00:03:00] pay right away.

And if I didn't pay right away, they were going to seize everything. And so all I had to do was. Buy a gift card, a visa gift card, give her the number and use that to pay the taxes. And this lady had an American accent to one that you would recognize. I'm sure. And it's not something that they do now.

They do send emails, as I [00:03:30] said. So the part of the problem with sending emails is it really them? Are they sending a legitimate email to a legitimate email address? Always a good question. Yeah. Here's the answer. Yeah, they'll do that. But how do you know that it isn't a hacker sending you the email?

It can get pretty complicated. Looking into the email headers, trying to track. Where did this come from? Which email servers did it go through? [00:04:00] Was it authenticated? Did we accept? Did the provider use proper records in their DNS, the SPIF, et cetera, to ensure that it's legitimate? How do you follow up on that?

That's what we do for our clients. And it gets pretty complicated looking at DKMS and everything else to verify that it was legitimate, ensuring that the email came from a registered MX server from the actual [00:04:30] server. There is a way around this. And this has to do with the identities, having these fake burner identities.

I've been doing this for decades myself, but now it's easy enough for anybody to be able to do it. There are some services out. And one of the more recommended ones. And this is even the New York times; they have an article about this. They [00:05:00] prefer something called simple login. You can find them online. You can go to simple login dot I O.

To get started now, it's pretty darn cool. Cause they're using what's called open-source software, it's software. So can anybody examine to figure out this is legitimate or not? And of course, it is fair, but it's all out there for the whole world to see. And that means it's less likely in some ways to be hacked.

There are people who [00:05:30] argue that having open-source software means even more. In some ways, you are, but in most ways, you're not; anyway, it doesn't matter. Simple login.io. Now, why would you consider doing this? Something like simple login? Simple login is friendly because it allows you to create dozens and dozens of different email addresses.

And the idea is with a simple login, it will [00:06:00] forward the email to you at your actual email address. So let's say you're doing some online shopping. So you can go ahead and set up an email address for, whatever it is, shopping company.com that you're going to use a shopping company.com. So you'd go there.

You put into simple login "I want to create a new identity," and you tag what it's for. You then go to some shopping company.com and [00:06:30] use the email address generated for you by simple login. Now you're a simple login account. Is it going to be tied into your real email account, wherever that might be if you're using proton mail, which is a very secure email system, or if using outlook or heaven forbid Gmail or one of these others, the email will be forwarded to you.

You will be able to see that indeed, that [00:07:00] email was sent to you. So shopping company.com email address or your bank of America, email address, et cetera, et cetera, that makes it much easier for you to be able to tell, was this a legitimate email? So, in other words, if your bank's really trying to get ahold of you, and they're going to send you an email, they're going to send you an email to an address that you use exclusively.

For bank of America. In reality, you only have the one email [00:07:30] box over there wherever proton, mail, outlook, Gmail, your business Excel. You only have that one box you have to look at, but the email is sent to simple login. Does that make sense? You guys, so you can create these alias email boxes.

It will go ahead and forward. Any emails sent to them, to you, and you'll be able to tell if this was indeed from the company, because [00:08:00] that's the only place that you use that email address. That makes it simple, but you don't have to maintain dozens or hundreds of email accounts. You only have one email account.

And by the way, you can respond to the email using that unique aliased email address you created for the shopping company or bank of America or TD or whomever. It might be, you can send from that address as well. [00:08:30] So check it out online, simple login dot IO. I really liked this idea. It has been used by a lot of people over, out there.

Now here's one other thing that it does for you, and this is important as well. Not using the same email address. Everywhere means that when the hackers get your email address from shopping company.com or wherever, pets.com, you name it. [00:09:00] They can not take that and put it together with other information and use that for business, email compromise.

Does that make sense? It's it makes it pretty simple, pretty straightforward. Don't get caught in the whole business email compromise thing. It can really hurt. And it has; it's one of the worst things out there right now, dollar for dollar, it's right up there. It, by the way, is one of the ways they get ransomware into your [00:09:30] systems.

So be very careful about that. Always use a different email address for every Website you sign up for. Oh, and they do have paid plans like a $30 a year plan over at simple IO will get you unlimited aliases, unlimited mailboxes, even your own domain name. So it makes it pretty simple, pretty handy.

There are other things you might want to do, for instance, use virtual credit cards. [00:10:00] And we'll talk about those a little bit. As well, because I think this is very important. But, hey, I want to remind everybody that I have started putting together some pieces of training. You're going to get a little training at least once a week, and we're going to put all of that into it.

What we have been calling our newsletter. I think we might change the name of it a little bit, but you'll be getting those every week. And the only way to get those is to be on [00:10:30] that email list. Go to Craig peterson.com/subscribe. Please do that right now. I am not going to harass you. I'm not going to be one of those.

And I've never been one of those internet marketers that sending you multiple dozens of emails a day. But I do want to keep you up to date. So stick around; we will be back here in just a couple of minutes. And, of course, you're listening to Craig Peter's son. [00:11:00] And again, the Website, Craig peterson.com. Stick around.

Cause we'll be right back.

One of the best ways to preserve your security online is by using what we're calling burner identities, something that I've been doing for more than 30 years. We're going to talk more about how to do that right now.

You can do some things [00:11:30] to help keep yourself and your identity safe online.

We've talked about email and how important that is. I want to talk now about fake identities. Now, a lot of people get worried about it. It sounds like it might be sketchy, but it is not to use fake identities to confuse the hackers to make it. So they really can't do the [00:12:00] things that they.

To do, they can't send you fishing ear emails, particularly spear-phishing emails. That'll catch you off guard because you're using a fake. How do you do that? I mentioned to you before that I have thousands of fake identities that I created using census data. And I'm going to tell you how you can do it as well.

There's a website out there called fake [00:12:30] name a generator. You'll find it online@fakenamegenerator.com. I'm on that page right now. And I'm looking at a randomly generated identity. It has the option right on this page to specify the sex. And it says random by default, the name set, I chose American the country United States.

So it is applying both American [00:13:00] and Hispanic names to this creation. And now remember it's creating based on census data and some other public data. But, still, it is not giving you one identity of any real people. So I think that's important to remember, and you're not going to use these identities for illegal purposes.

And that includes, obviously, when you set up a bank account, you have to use your real [00:13:30] name. However, you don't have to use yours. If you have an actual email address, you can use things like simple login that will forward the email to you, but we'll let you know who was sent to. And if you only use that one email address for the bank, you know that it came from the bank or the email address was stolen from the bank.

All of that stuff. We've talked about that already. So, in this case, The name that has come up with [00:14:00] for me is Maurice de St. George in Jacksonville, Florida even gives an address. In this case it's 36 54 Willis avenue in Jacksonville, Florida. So if I go right now two, I'm going to use Google maps, and I will put in that address.

Here we go. Jacksonville willows avenue, all the guests. What? There is Willis avenue in Jacksonville [00:14:30], and it showing hoes oh, from Google street view. Let me pull that up even bigger. And there it is. So ta-da, it looks like it gave me. Fairly real address. Now the address it provided me was 36 54, which does not exist.

There is a 365, but anyway, so it is a fake street address. So that's good to know some, if [00:15:00] I were to use this, I'm going to get mine. Am I male saying about I pass. Maurissa tells you what Maurice means, which is neat. It'll give you a mother's maiden name. Gremillion is what gave me here a social security number.

So it creates one that passes what's called a checksum test so that if you put it into a computer system, it's going to do a real quick check and say, yeah, it looks good to me. So it was not just the right [00:15:30] number of digits. It also passes the check, some tasks. Well-known how to do a checksum on their social security numbers.

So again, it's no big deal. And remember, you're not going to use this to defraud anyone. You're going to use this for websites that don't really need to know; give me a break. Why do you need all this information? It gives me a phone number with the right area code. And so I'm going to go ahead and look up this phone number right now.

Remember, use duck go. Some [00:16:00] people will use Google search, and it says the phone number gave me is a robocall. As I slide down, there's some complaints on that. So there you go. So they giving us a phone number that is not a real person's phone number, country code, of course one, cause I said United state birth date.

Oh, I was born October 7th, year, 2000. I'm 20 years old. And that means I'm a Libra. Hey, look at all this stuff. So it's giving me an [00:16:30] email address, which is a real email address that you can click to activate or right there. Again, I mentioned the simple login.io earlier, but you can do a right here, and it's got a username and created for me a password, which is actually a pretty deal.

Password. It's a random one, a website for me, my browser user agent, a MasterCard, a fake MasterCard number with an expiration and a [00:17:00] CVC to code all of this stuff. My height is five-six on kind of short. My weight is 186 pounds own negative blood type ups tracking number Western union number MoneyGram number.

My favorite color is blue, and I drive a 2004 Kia Sorento, and it also has a unique ID. And you can use that wherever you want. So the reason I brought this up again, it's called [00:17:30] fake name generator.com is when you are going to a website where there is no legal responsibility for you to tell them the truth.

You can use this. And so I've used it all over the place. For instance, get hub where you have it's a site that allows you to have software projects as you're developing software. So you can put stuff in, get hub. They don't know to know, need to [00:18:00] know who I really am. Now they have a credit card number for me.

Because I'm on a paid plan. I pay every month, but guess what? It isn't my real credit card number. It isn't the number that I got from fake name generator. My credit card company allows me to generate either a single use credit card numbers, or in this case, a credit card number for get hub dock. So just as an example, that's how I use it.

So we've get hub gets hacked, the [00:18:30] hackers, have an email address and a name that tipped me off right away, where this is coming from. And if the email didn't come from GitHub by no, they either sold my information to a marketing company, or this is a hacker. Trying to manipulate me through some form of his fishing scheme.

So I know you guys are the breasts and best and brightest. A lot of you understand what I'm talking about, and I'm talking about how you [00:19:00] can create a burner identity. And let me tell you, it is more important today to create a burner identity. Than it has ever been at any point in the past, because frankly, burner identities are one of the ways that you can really mess up some of the marketing firms out there that are trying to put the information together, these data aggregator companies, and also the hackers.

And it's really the hackers that [00:19:30] were off up against here. And we're trying to prevent them from. Getting all of this information. So when we come back, I want to talk about the next step, which is which credit cards can you get? These single use card numbers from? Should you consider using PayPal when my Google voice be a really good alternative for you?

So we're going to get into all that stuff. Stick around in the [00:20:00] meantime, make sure you go to Craig peterson.com/subscribe. Get my newsletter. All of this. Is in there. It makes it simple. It's a simple thing to do. Craig Peterson.com. And if you have any questions, just email me, M e@craigpeterson.com.

Having your credit card stolen can be a real problem for any one of us. It gives the bad [00:20:30] guys, a lot of options to spend a lot of money very quickly. We're going to talk right now about virtual credit cards. What are they, what does it mean?

Virtual credit cards come in two basic forms.

One is a single use credit card, which was quite popular back when these things first came out, and another one is a virtual credit card that has either a specific life. In other words, it's only good for 30 days [00:21:00] or that can be used until you cancel it. If you have a credit card, a visa, MasterCard, American express, discover all of the major card issuers will give you the ability to reverse any charges that might come onto your cards.

If your card is stolen or misused. Now that makes it quite easy. Doesn't it? I want to point out that if you're using [00:21:30] a debit card, as opposed to a credit card, there's not much challenging you can do with the credit card. You can say, I am not going to make my payment. And because of this, that, and the other thing, this was stolen, et cetera, they can file it as a disputed charge.

They can do an investigation to find out. Yeah. I'm you probably were not at a bus terminal down in Mexico City, which happened to me. Because I was up [00:22:00] here in New Hampshire, quite a ways down to Mexico City. And so they just reversed it out. That money never came out of my bank account because it was on a credit card.

If I were using a debit card. That money would have come right out of my account. Now, mind you, a bus ticket in Mexico city is not very expensive, but many people have had charges of many thousands of dollars. And if you need that money in your checking account, [00:22:30] and you're using a debit card, you got a problem because your check for if you ever have to pay rent again, red check is going to.

Bound because they just empty it out to your bank account. So now you have to fight with the bank, get the money back. They will eventually refund it, but it could make some of you. Transactions that you might've written a check or something, it'll make them bounce. And that could be a real problem.

These, it could make them [00:23:00] bounce. So using a credit card is typically less of a hassle online. So why would you want to use a virtual card or also known as is a master credit card masked and may S K E D? The main reason behind this is to allow you. Control payment. I've used them. In fact, I use them exclusively on every Website [00:23:30] online.

And I'm going to tell you the names of some of them here in just a couple of minutes, but I use them all the time. And part of the reason is let's say, I want to cancel. A service. Have you ever tried to cancel a service before and you have to call them many times, and so you're arguing with somebody overseas somewhere who doesn't want you to close the account.

And of course, Bump you up to the next level person who also doesn't want you to close the account. And [00:24:00] so you have to fuss. Have you ever had that experience and I'm sure you have. It just happens all the time. So with using the virtual credit card, the advantage to me is, Hey, if you are going to try and fight with me, I don't care because I'm just going to cancel that credit card number.

So I don't have to cancel my credit card. I don't have to have the company reissue credit card for me. I don't have to do any of this sort of thing that [00:24:30] makes my life pretty easy. Doesn't it? And because of that, I am now I think in a much better. Place, because it just, I don't have to fight with people anymore.

So that's one of the reasons I used it. The other big reason is if it gets stolen, they can cause less harm. Some of these credit card it's virtual credit cards are set up in such a way that you can limit the amount that's charged on them. Do you like that? [00:25:00] So if you are using it on a site that maybe is charging you $50 a month, no problem.

$50 a month comes off of the credit card. And if someone tries to charge more bounces and then hopefully you find out, wait a minute, it just bounced on me. Then next step up is okay. It bounced and. I'm just going to cancel the card, and then you issue a new credit card number for that Website.

So an example. In my case is [00:25:30] get hub.com. We keep software up there, and they charge me every month if get hub were to get hacked and that credit card number stolen I'm I really don't care because there's almost nothing that can happen. And if good hub doesn't properly cancel. My account, I can just cancel the credit card and let them come after me.

This isn't going to happen. So then it's also called a master credit card number, cause it's a little safer than using your [00:26:00] real credit card details. I also want to point out something about debit card. I went for years with no credit cards at all. Nowadays, many of my vendors will take a credit card for payment.

And in fact, give me a bit of a better deal. And then with the credit card, I can get 2% cashback, which I use to pay down the credit card. It couldn't get any better than that, but when you're using a debit card, what I always do. [00:26:30] Is I had two accounts that I could transfer money between at the bank.

So I had one checking account. That was my main operating, if you will account. And then I had another checking account where I would be. Just moving money out of it. Or you could even do it with a savings account, but some banks, they only let you do so many transactions a month on a savings account. So the idea is I know that I have this much credit card [00:27:00] obligate while debit card obligations for this month, that money is going to be coming out.

So I make sure that. In the debit card account to cover the legitimate transactions I know are coming up and then I keep everything else in the other account. And then I manually transferred over every month. So that's how I dealt with the whole debit card thing. And it worked really well for me. Bottom line.

I think it's a really great idea. So there you go, who are the companies that [00:27:30] you can use to do this? I've used some of these before all of them have worked really well. If you have a capital one credit card, they have something called Eno, E N O, and it's available to all capital one cardholder. Eno even has an extension for your web browsers.

So if it notices you're on a webpage, it's asking for credit card number, it'll pop up and say, do you want me to create a [00:28:00] credit card number or a virtual one for this Website you can make your payment. Does it get much easier than that? Citibank has something they call a virtual credit cards available to all Citibank cardholders, master pass by MasterCard.

That's available to any MasterCard visa, American express discover diners club cardholders, credit, debit, and prepaid cards by their way. So you might want to check that one out. Yeah, [00:28:30] so that's the only one I see on my list here. That will do it for debit cards, master pass by MasterCard American express checkouts available to all American Express cardholders.

Chase pay available to all chase cardholders, Wells Fargo, wallet visa checkouts, available to all visa, MasterCard, and American express and discover color cardholders, credit and debit cards. Plus. Prepaid cards. Okay. So it does [00:29:00] do the debit cards as well. Final that's all owned by Goldman Sachs and is not accepting any new applicants and entro pay.

Also not accepting new applicants. There's a couple online. All right, everybody, make sure you check me out. Craig peterson.com/subscribe.

We're going to wrap up how you should be using these burner identities of [00:29:30] few more tips and tricks that are going to help keep you safe from the hackers that are out there. So here we go.

There are a lot of hackers out there.

The numbers are just astounding. The cost of these hackers coming in and stealing our information is just unbelievable. And it goes all the way from big corporations, from things like the colonial [00:30:00] pipeline, the US government all the way on down through you and me. I want to tell you a little story about a friend of mine.

He is about 75 years old, and he supplements his income by driving for Uber eats and one other company. And so what he'll do is someone puts in an order for food somewhere. He'll go pick it up and then he'll drive it to where whoever wanted, whoever ordered it. Now, [00:30:30] there are. Pricing number of scams with this.

So he's very careful about some of that orders, a cookie, for instance, because it's usually a bit of a scam anyway, we won't get into those, but I'll tell you what happened to him. His information was stolen online as it was probably yours. Mine I know was as well. So it's all stolen. What do you do? In his case, what ended up [00:31:00] happening is they managed to get into his email account.

Once they're in his email account, they now had access to the emails he was getting from one of these companies. Now it wasn't the Uber eats guy. He was, there was another company. So let's just explain this a little bit. Uber eats sends him a request for him to go ahead and do a deliver. Go to the restaurant, pick it up and take it to this client's house.

[00:31:30] And in order for him to register, he had to register an email address. Now, of course, he uses the same email address for everything. All of it. Now, personally, that drives me a little bit insane, but that's what he does. And he has just a few passwords. Now. He writes them down a little book and heaven forbid he ever lose the book so that he can remember them.

He [00:32:00] just wants to keep his life simple. He's 75. He's not technophobic, he's not up on all of this stuff. What he found was a paycheck didn't show. And it was an $800 paycheck. We're talking about real money that he should have had in his pocket. It didn't show up. So he calls up the company and says what happened to my paycheck and a record show?

Yes, indeed. It had been paid. We [00:32:30] paid you, we deposited right into your account. Just like you asked. Yeah. ACH into the account. Great. Wonderful. What had happened is bad guys had gone, gained control of his email address and use that now. Because they figured I see some emails in his account from this food delivery service, let's try and see if this email address that we're looking at right now.

All of his emails let's [00:33:00] look and see. Okay. Yeah. Same. Email address and same password as he used at this email address? Yeah, it worked. Okay. Great. So now we have access to this guy food delivery account. So they changed. The bank account number, no easy enough to confirm. They change it, Mel. Hey, I want to make sure that it was you until the bad guys, the hackers, click out, yada.

Yeah, it was [00:33:30] me and then lead the email. So he doesn't see it. And now his $800 paycheck. In fact, I think there were a couple of different checks is deposited directly into the bad guy's bank account and. The money of course has transferred out pretty quickly. Now the, that guys, these hackers are using what are called mules.

You might be familiar with that in the drug trade. They'll have a third [00:34:00] party deliver the drugs just to mule. They don't know what all is going on. They probably know the delivering drugs in this case. Most of the meals are useful idiots, of which there are many in this country, unfortunately. Political and otherwise.

And these people are convinced that all they need to do is transfer the money into this account so that the hackers can then pull it out. And now [00:34:30] they're gonna take care of their grandmother who is stuck in the hospital and they have no way to pay for it. And they can't transfer the money out of the country directly.

That's one of the stories they use for people. And in many cases, these mules know what they're doing. The FBI earlier this year arrested a whole group of mules out in California that were purposefully transferring the money. They knew what they were doing. So his money was now out [00:35:00] of the country. No way to get it.

And this food delivery company was not about to pay him. So it isn't just the big guys it's you and me as well. So what I want to talk about right now is multi-factor authentication. Now. You guys are the best and brightest. I hope you understand this. If you have questions, please reach out to me. I am more than glad to send you some good material on this.

Just [00:35:30] me. M E add Craig peterson.com. I am here to help. What multi-factor authentication does is allows you to not just log in by using an email address and a password, or maybe a username and a password. Which is much better, by the way. I don't like it. When sites require an email address to log in.

Although as I use multiple email addresses, and I think you should as well, a different email address for every site [00:36:00] out there beyond question, you should be doing that. So anyway, this is. You should be doing with multi-factor authentication. They will have you put in your email address, have you put in your password, and then they'll do something that is supposedly something you have.

So the best security is something, along with something you physically have. So in most cases, they'll use two factor [00:36:30] authentication by sending you a text message with a code. And then you type in that usually six digit code, and now you're in, and it only does that. If it doesn't recognize the browser, are you using, or in many cases of, it needs to be a little more secure than that it's only good for 24 hours or maybe a week.

That is not good enough. You should be using a code generator. Google [00:37:00] has one for free, but I want you guys to use something called one password. That's the digit one password. You'll find it online. You'll find it in all the app stores. It is what we use for the most part. It's great for families. And it's great for businesses because you can have different vaults and you can share them and control access.

Now there's a couple of reasons why that we're talking about multi-factor authentication right [00:37:30] now. So the first reason kind of the biggest reason is you can use it for generating passwords. Fairly random ones or fairly memorable ones. And then when you go to a site, one password can pop up and give you the password for the site.

So you don't even have to look it up. You don't have to remember it. You don't have to look it up. Isn't that phenomenal. And then it also has built into it. Token this six digit [00:38:00] key generator. I'm trying to keep this simple. So you can then use that for the site. So it says, okay, what's the code go to your code generator.

So you just go to one password. There it is. Copy it and paste it right in. And you're in that alone would have prevented my buddy's account from getting there. It's that simple, one more thing that you want to use one password. And that is those questions that you're [00:38:30] asked to verify. It's you many sites out there banks are really big into this and I don't get it cause it's not very good in most cases.

So they'll ask you things like where were you born? What's your mother's maiden name? Where did you go on your first day to what was the car that you owned first? Or, your dog's name, et cetera. The reason, those things are so bad is because the hackers can go online, look at your [00:39:00] social media and figure out the answers to a lot of those questions.

Bad. So what you should be doing is using one password, and it allows you to put notes pretty much anything you want to in the record for that Website. So you go to the Website and you log in, create your account right. To log in. So you're going to give it your, probably your email address, which is a bad idea, but [00:39:30] that's, what's required use one password.

To generate a strong password for you that you'll put in. You'll use one password. Hopefully they have multi factor authentication that allows you to use one of these code generators. Google has theirs is called Google authenticator, and one password is compatible with that. Microsoft has done. Own thing.

And it's not compatible with almost any Website online. So don't use the [00:40:00] Microsoft authenticator other than for Microsoft products, like using the, a windows 365 thing that they have does use Microsoft authenticator, but you can also use the Google one and the one password one, and then in the notes section, make up answers to the questions.

So it asks you, what was your mother's maiden name? And say something different insecurity, where, what is your high school? It was named [00:40:30] movie elementary school, make something up a stream. Okay. Use random answers. Record them in one password. You're going to have to look them up. If you ever on the phone with the bank or whomever, because you're not going to remember them, but that's good because they don't appear in your.

Social media anywhere and they don't appear anywhere else other than your secured encrypted one password fault. [00:41:00] Thanks for being with us. I appreciate you guys listening, and you can find all of this. I'm going to turn all of these and did a little mini-courses here over the next few weeks, and there's only one way you're going to get it.

And that is by being on my email list. Craig peterson.com/subscribe. Go there right now. Craig peterson.com/subscribe.

As if this year and last year haven't been enough weirdness, [00:41:30] it looks like George Orwell is kind of lending some help here. You won't believe what the us department of Homeland security is planning on doing well, maybe it will.

If you missed the last hour, it is absolutely must-listen radio.

And so what I'm going to be doing is I will put it up online for you guys. You can get it by going to Craig [00:42:00] peterson.com/podcast. Hopefully, I'll get it up soon after the show today, but I went through and explained ways. That you can protect your privacy online. Absolutely protect it. So you don't get that kind of advice or most people, most people are trying to sell you a product that just doesn't really work that well.

I I'm telling you what does work, what the experts do, what Edward Snowden would do. What I [00:42:30] have been doing for more than 30 years personally, in order to help keep my identity safe. So check it out again. Craig peterson.com/podcast. Now I want to point out too, that if it's not upon you, look, make sure you refresh your browser.

So you're going to want to do what's called a cache clear refresh. So. And the browser by that URL bar, you'll see a little, it's usually a little circle [00:43:00] with an arrow on the end. That's your refresh, but you need to also reflect, refresh your cache. So you're going to hold down the shift. And hit that little circle with the arrow on the end, and then you'll be able to listen to all of that.

And I'm thinking right now, I'm probably going to try and turn that into a series of emails so that you guys can just read. Through it over the course of a few weeks. Cause man, did I cover a [00:43:30] lot? And you can get that when those come out in. And even if I don't get around to this, I do do emails with training in them.

And with of course the latest news. And you get that by subscribing again, Craig peterson.com. We've got to help you guys out. You need to know this. Okay. Absolutely. You, you personally need to know that. Well, this whole or wellbeing thing is scary, frankly. [00:44:00] I just finished going through reading George Orwell's 1984 again, and it was just so eyeopening.

I read it many moons ago, and I learned a lot from it then, but now I see it out in the streets. I see it with what's been happening with government and even businesses. And we've complained about them many times here on the show. Haven't we, some of the deep [00:44:30] state, big tech ties that go between each other.

It's no longer really the military-industrial complex. We're talking about the deep sea. High tech complex. It's a bad thing. It's a scary thing. Well, what they're doing right now, and this is a great article from news busters.org is they've got this Alliance between the department of Homeland security and private [00:45:00] companies that they're trying to put together.

Now, news semesters, isn't saying. That it's already in place. They're saying this is what they're planning on, putting them place. However, I know what they have in place, and they're already doing a bunch of this. Again, it goes back to that app. Isn't really free that app that supposedly is free, is doing something it's gathering information, data on you, and then it's selling it.

And the people that are buying it are data. Aggregators is what they're called. [00:45:30] 20 years ago, I had some of the top data aggregators on the show and I sat down with them and I said, well, let's look me up because they have information, public records, some private stuff, like obviously buying it from these app developers.

And I said, let's look me up, find out what you have on me. So we looked me up, and I would say about three quarters of it was wrong. Which was really kind of interesting. And this is [00:46:00] data that was used back then, mainly for what's called skip tracing. So you have a bill to pay. You don't pay it. You move out of town.

That's the process to find do is called skip tracing. And that's what they would do nowadays. It turns out that local. Federal police departments and other agencies are buying this data from the data brokers so that they can now track you. Now they're not allowed to, by [00:46:30] law track you, you know that, right.

But the government is doing what one might call lawyering. That's what we called it in robotics. I was part of a us robotics team with kids, and they would always look at the rules, and they would get reprimanded. The teams would if they lawyered the rules. In other words, if they met the exact definition of what it was in the rules, but they didn't meet the spirit of the rule.[00:47:00]

They would get reprimanded. They might even get kicked out. And that did happen a few times. However, if you're the government and you get to say which laws you want to follow, which court rulings you want to follow, think of what's been happening lately, right? We're not going to, yeah, I know. I know I can't do this.

I can't do this. I can't do this. I can't do this. I have a pen and a phone. I'm going to do it anyway. Or just reverse all of the actions of the prior administration. [00:47:30] And even though the Supreme court says, Hey, you cannot do this, but we're not going to rule on it because the this policy is only in place for a couple more weeks.

And then you do it again. Anyways, the government isn't, isn't even obeying the rules. Th the strict letter of the law. They're not even obeying, let alone the spirit of the law just drives me crazy. The wall street journal just reported, uh, about a week [00:48:00] ago here last Sunday that the department of Homeland security is considering hiring private companies to analyze public social media for warning signs of extremist violence, spurring debate within the agency over how to monitor for such threat while protecting American civil liberties.

Now I'm glad they're at least giving you. Lip service to protecting our civil civil liberties, right. That I think is a very good [00:48:30] thing. They should be protecting them, but this just has the tendency to continue to inch forward again and again and again. So this effort has not received approval and has not been.

But it's going to involve. According to the wall street journal is sifting through large flows of internet traffic to help identify online narratives that might provide leads on developing tax weather from home [00:49:00] or. Eh, this is, this is just amazing. Now I mentioned on the radio, uh, previously that I have personal experience with one of these large federal law enforcement agencies that has been doing what I considered to be completely unreasonable things with people's information and also completely unreasonable things [00:49:30] in defining.

Where the thread is. You've probably heard it all over the news that, that it's all these conservative groups that are the real threat. Well, it's not the conservative groups that have been out there, burning down cities, demonstrating, beating people with clubs, pulling people out of cars, and BD. No, it's not.

So where, where are these people coming from, and how do they define these [00:50:00] extremist actions? How do they define it? Right. Well, you can tell that there's obviously some extremism involved when there's a riot, but they will respond to a riot in Washington, DC after Trump rally, but they don't respond to riots all over the country and major cities.

And in many cases they don't even do arrests. Oh, it's absolutely amazing what's going on. So I'm very, [00:50:30] very worried about this fusion of big tech and deep state government, because it's become really kind of a hallmark of the Biden administration. Senator Josh Holly's Republican from Missouri really went after the Biden administration for pressuring private companies to help spy on the techs of American citizens.

This is back in July and he said that the big government, big corporation [00:51:00] Alliance is the real danger here. And. Absolutely have to agree. This is going to be a problem. And giving the government access to more personal data is going to be an even bigger problem in months and years to come. Particularly if we just let them do.

Willy nilly and that's kinda what's happening. What kind of oversight is there really think about the Pfizer courts that are [00:51:30] supposed to be providing oversight for monitoring, uh, people who are not citizens. And yet it looks like. Our law enforcement agencies. We're targeting citizens specifically through the Pfizer courts who are playing games.

So I absolutely don't want this to happen. I don't want any administration, Republican-Democrat, you name it. I don't want any of them to have access to [00:52:00] this type of deal. And I go right back on this and a, here's a great quote to explain why I'm going to use a quote from lever inti barrier. He was the most ruthless and longest-serving secret police chief in Joseph Stalin's reign of terror.

He said, show me the man and I'll show you the crime. That should scare all of us, because even though the administration today, isn't doing that [00:52:30] types of things Stalin was doing, obviously we don't know what's going to happen in the future and we cannot let the hackers gain access to this information because believe me, they're going to be going after it as well.

So don't collect it in the first place.

Let's do think that surveillance on citizens, criminal and otherwise, is a rarity. We're going to talk about the New York police department [00:53:00] and their secret funds used for surveillance tools alone.

Here we go. This is from wired magazine, you know, definitely not a right wing entity.

They have been reporting on a number of situations where the government has really overreached when it comes to our information and our privacy. And they have this report now that has been [00:53:30] released. And. Yeah, that and some other documents and Sydney fossil wrote this article, and he's saying that the documents are showing that police bot facial rec recognition, software vans, equipped with x-ray machines and stingers.

Cell site simulators with no public oversight. And I'm going to explain what each one of these things is and what they are typically used [00:54:00] for. But this is amazing. No problem. Oversight now that's according to documents released last Tuesday. So when all these documents are showing that the New York police department spent at least $159 million over the last 15 or so years through this little known special expenses fund, the did not require [00:54:30] approval by the city council or any other municipal official.

Frankly. I think one PP has something to answer for here. We'll have to ask Tom Selleck about it. Right? The documents are made public by two civil rights groups, the legal aid society and their surveillance technology oversight project would says that what the N Y P D was doing amounted to our surveillance slash fund.

[00:55:00] It's just crazy, um, stops director, which is again, the, uh, surveillance technology oversight project stop. Their executive director said that the police are still blocking other records needed by the public to understand the way New York is being policed. This is just something out in 2018, the New York police department awarded almost $7 million to the [00:55:30] idea solutions company, which by the way, sells biometric tools, including facial recognition.

So what they have done in essence now is set things up in New York. Kind of like they are over in China where they have cameras located all over the place. And those cameras are capturing pictures of pedestrians. How the only kind of saving grace nowadays is a lot of people are wearing [00:56:00] face mask, although, and because a lot of people were in face masks, there's new software that will recognize people, even if they're aware.

A face mask obviously depends on the type of face mask, but you know, it's still doing that. So they have all of these cameras. They have this facial recognition software. And they can track you as you're walking around the city. In fact, they can do it in reverse, [00:56:30] which frankly is kind of cool that there are also these airplanes in the sky, over many of our big cities.

Now, New York, they're concerned about it. Of course of what happened on nine 11. People get really nervous seeing airplanes over there. So they're using high flying drones that can't really be seen with the naked eye or heard, and they are taking continual video of the entire city [00:57:00] and of all of the streets.

So let's say a bank gets robbed, they can try. Those robbers back in time using these drones or airplanes, along with the surveillance software in the cities, mash of cameras and find out where they came from. Okay. So it looks like this was the staging area for the bank robbers, and then they can go back further in time and see where the bank robbers came from.

What were they [00:57:30] doing? Where did they go? That technology all exists. Now, it's not that good yet, but you know, it ended up, it will end up being that good. But this goes right back to what I was talking about a little earlier with, uh, show me the man, I'll show you the crime. What happens if those cameras pick you up on a street where a drug deal was going down?

Now you've seen it on TV. You've seen it in the movies where they poem money back and forth a POM, [00:58:00] the drugs, you wouldn't even know that a drug deal was happening and now you get pulled into it. How about what happened on January six in Washington, DC? There was a riot. We all know that the Capitol building, but now the FBI and other law enforcement agencies are pulling people in who cell phones pinged in the general area.

In Washington, DC. So if you were down there and you [00:58:30] were part of a school tour that day, and you went to maybe the Trump rally, maybe you didn't maybe just went to the reflection pond down there. They investigated you. If you were in our hotel, they investigated you. If you used a credit card in the area, they investigated.

And that's being alleged right now by some of these people that were investigated and have had minor charges brought [00:59:00] against them that this was a total witch hunt. It was fabricating the crime. Again, show me the man. I'll show you the crime. I mean, under Stalin, the dictator over in the Soviet Union, you know, socialist government for those that aren't familiar with it.

These contracts that were received through kind of a freedom of information request to buy these civil rights groups were heavily [00:59:30] redacted. And so I made it very difficult to understand how many single tool functions were purchased, how they could work together to create a surveillance Dragnet. Over people in New York City, this secrecy also blocks a more complete understanding of the relationship between the New York police department is vendors in the public.

So again, it's a double-edged sword it's yet. You want to catch the bank robber. You [01:00:00] want to catch the murderer, but most of the time, those people know how to. Fool the system, don't they, uh, in 2014, the New York police department signed a five-year $800,000 contract with Elbit Systems, which is Israel's largest defense contractor.

And by the way, they aren't just in Israel. They're also, they have a plant in New England. Uh, kind of all over [01:00:30] and Elbit provides a wide range of surveillance tools used by customs and border patrol on our borders, including cameras and sensors that make up this virtual border Raul wall that we have on our Southern border.

It, this is not good. And I want to add one more thing. I said, I explained what these things are, you know what x-ray is. And some of these trucks are using millimeter-wave stuff and are our x-ray and people [01:01:00] walking down the street, supposedly to see if they have a weapon. Huh? Okay. So just walking past one of these vans expose you to health risks, no warning about that cancer risks from these mobile x-ray vans and these stingray devices are fake cell phone towers.

So they capture your information. Who you're calling where you're calling and your text messages, whether you are a target [01:01:30] of an investigation under court order, or just someone walking around the streets in New York, check me out online. Craig peterson.com.

Investment money is rolling into these high tech startups. That means if you're looking for a new job in high tech, it may be your lucky day, particularly if you want a job with a startup. So here we go.

Jobs in tech have always been [01:02:00] pretty good. Generally speaking, technology is what drives the economy. It is what boosts productivity, and it is right now, a really hot job market there. More small businesses, startups are being funded by angels and venture capitalists than there have been for a few years.

That means we've got money now pouring into [01:02:30] these little startups. There's a great little article in ARS Technica by Ariel pod dress. And she's talking about this company called revenue. This is a startup. They just closed their Series B, which means they had their second investment round. And this is a platform for managing in-app subscriptions.

They just got $40 million in the idea behind this $40 million series [01:03:00] B series B is to grow the company and. To hire more people. And of course, it's hard to grow the company without hiring more people, even if you're in the software business. So we're talking about a 35 person. Startup that's getting $40 million.

That's more than a million dollars per existing employee. They want to get another 50 employees by the end of the year and a hundred by the end of next year. [01:03:30] Now I've got to say, I, I had a startup, it was me and it was me and it was me. Right. I started it. I worked really hard, and I built it up to 50 employees.

I didn't have a dime of investment money, but now this investment money is out there like crazy, but revenue, cat's having a hard time along with most of these other startups, hard time hiring people. So, what they've done now [01:04:00] is they've got a whole bunch of extra perks. Things like unlimited vacations.

Yes, indeed. No more. Two weeks you earn an extra day for every year. You work there or a seven. These other rules that around for a very long time unlimited vacations. They'll give you a stipend. If you have an office at your home that you're working. Plus, they're also providing equity and salaries on par with some of [01:04:30] the big tech companies, regardless of where you live.

Right now, Facebook is, and Google are both looking at saying, Hey, listen, you know, you live a hundred miles outside of Silicon Valley. You don't deserve to be paid as much as an employee that lives right here in San Jose. So now we're going to cut your pay by 10%, 15%, sometimes even more. So these little guys are saying, Hey, listen, you can [01:05:00] work for us.

We don't care where you live. Timbuktu in Northern Africa just doesn't matter. As long as you can work from home, we'll pay you the same as if you're living right here in Silicon Valley in California. And we'll even give you extra money because we know it costs you money to be able to work from home because you're probably going to have to get a better internet line.

You're going to have to have a phone that works so that we can call you. Maybe you have to call customers. [01:05:30] These types of offers really weren't around before the lock. But now we're seeing high-tech salaries, being driven, even higher benefits that are really being massively beached up, uh, beefed up, I should say.

And companies that are offering incredible salaries and flexibility. So there you go. These companies are basically competing with Google, [01:06:00] Facebook, et cetera. So what does that mean? Well, these small startups like revenue cat are getting a lot of money, almost $300 billion invested in these startups worldwide.

And it's really hurting the big guys because they're talking about cutting salaries, even though they don't need to. It's not as though they're suffering. They're these big companies, they're still sitting on [01:06:30] billions of dollars in cash. Isn't that something. And so they are starting to really hurt because the small guys are stealing employees, quote-unquote, from the dice, which is, has this industry career database is saying overall tech job postings are up 16% this year.

We're seeing also, by the way, a whole [01:07:00] bunch cut backs because of the technology in how many people, these companies need to have a look at restaurants. Now they're doing QR codes for the menus QR codes to pay your bills. So there's even fewer people. That have to work in restaurants going forward. We've got meetings that are being held on WebEx or zoom.

You don't go see the doctor anymore. You're using telehealth software programmers. [01:07:30] Engineers are being used more broadly between March and July. There are more than 300,000 openings for software and, uh, other types of computer high-tech engineers. It's 13% higher than even 2016. It is absolutely amazing.

I had one person who responded. And when I offered, maybe it makes sense for me to do kind of a career [01:08:00] webinar on high-tech jobs. Right. What would it take to get into specifically the cyber security industry? Because it's something I know it's something I've been helping to drive the whole industry now for over 30 years.

And I had only had one person respond. Uh, although I know of. I have a few listeners that have actually done that. They went and got themselves qualified in cyber security, but only one person makes me [01:08:30] think that, you know, what does one person represent maybe a hundred listeners. So there are some of you.

I don't think I'm going to end up doing this little thing. Cause I was going to just do a free webinar and what it takes to become a cybersecurity analyst. Uh, but uh, we'll see what happens here kind of going forward, but there's a lot that can happen. There's tech co-workers out there who are leaving some of these high tech firms.

There are also [01:09:00] lawsuits about the golden handcuffs, so that have been put on people, you know, that say, Hey, you can't compete with us or you can't even be in the same industry. Some of those. Contracts are being knocked down in some states. Uh, it's kind of interesting to see what happens. Um, there's a couple more things.

Yeah. Here, different hedge funds, but it's a really great article. It's in ours. Double-check [01:09:30] your newsletter that I sent out or is going out this weekend. If you haven't received it yet, you should get it at some point this weekend. A very interesting one. If you're considering high tech jobs, ARS, Technica, Vicky.

Now, if you want to track technology and cybersecurity, you know, already I go through thousands of articles every week. Now you can talk to my wife about it right in the evenings. And even sometimes you're in the day I'm [01:10:00] sitting there reviewing articles and all these sites, I put them together for you guys.

So, you know, what's happened. And cyber security, what the latest breaches are, what you can do about it. I am going to continue with some of the trainings, pick them up again here within the next couple of weeks so that we can keep you guys up to date, but there's only one way you can find out about them.

There's only one way that you can get involved, and that's, by making [01:10:30] sure you subscribe to my show notes newsletter, and you can get that by going to Craig Peter sohn.com/subscribe. You'll get all of these free trainings. You'll find out about what's going on, what you need to do in your. Small business door also in your home computers and environment, but everything from the CEO on down Craig peterson.com/subscribe.

[01:11:00] I've been complaining about Facebook and what they have been doing to potential competitors for years, the same types of complaints I can make against Microsoft and Google to a lesser degree. While now the federal trade commission's coming out, agreeing with me.

This is something that I think has been a long time coming.

And this is the federal trade commission's lawsuit against Facebook. Now, lest you think that this is a Trump thing. [01:11:30] This is a Biden thing. Trump administration had filed suit, and then the suit was dropped, and now the federal trade commission has refiled the lawsuit against Facebook and has included some additional proof.

That it hopes is going to Boyce bolster its case. The last one was rejected by the court. Great article by ARS Technica as Tim D chant. You'll find that in [01:12:00] my newsletters as well. Craig peterson.com/subscribe. You can get my show notes for absolutely free. Well, this refiling is in response to the federal trade commission's initial case thrown out in June by us district, judge James Boasberg, who didn't think that the agency provided enough information or a real strong definition, what you might call a bright line in [01:12:30] legal terms of Facebook's market in its first five.

This is really kind of an interesting problem here because basically, the federal trade commission is alleging that Facebook lacked the business and human and technical talent to survive the transition to mobile. That's according to Holly Vedova, she's the acting director of the federal trade commission's bureau of [01:13:00] competition.

She also said after failing to compete with the new innovators, Facebook illegally bought or buried them when the popularity became any sense. Or existential, she said threat. Now, this is the same type of thing we've seen Microsoft do for decades and worse, frankly. It's similar things that Google has done to competition.

Although I think Google hasn't been as bad at this as [01:13:30] Microsoft or Facebook have been, but the federal trade commission filed this original lawsuit in December. And that was under Joseph's Simmons, who was appointed by former president Trump, of course. And he cast the Simmons, the deciding vote in the initial filing with the two Republican commissioners voting against it.

Now that to me is surprising because I'm all for free trade. In this [01:14:00] case of Facebook has been doing all kinds of anti competitive things. And it's interesting to see the statement here from the federal trade commission that FAPE spoke, lacked the business acumen and technical talent to survive. So that again tells you that Facebook might have a lot of really great political people in there working and censoring and deleting posts and some great marketing [01:14:30] people, but they sure don't have it.

The technical talent. I love that. I would love to see the judge ultimately rule that way, but here's the problem. Facebook acquired Instagram and WhatsApp. And I've talked about this on the show before. And the other thing that they did and the way they acquired them was a problem. We'll talk about that in a second.

The other thing they did that I haven't talked about before is. The way they blocked [01:15:00] competitors from accessing the API APIs now API APIs or application programming interfaces. It's what all of us programmers use nowadays. So rather than that, developing. For where that does, what Facebook does. I just go ahead and use Facebook's published interfaces.

So the idea is I call an API using some methodology, and I say, I want this post to go. [01:15:30] In my Craig Peterson account or in my tech talk channel, right. Our group is actually what Facebook calls it. And then Facebook says, okay, great. And it publishes it for me. And that saves me from having to have to go to every Website out there that I post my radio show that I post my blog, Kat, my blogs on too.

The podcast. It saves me from having to go to every one of those places online and repost, everything [01:16:00] manually. Those are API APIs. So I actually use a service that does that for me, using API APIs from Facebook and other places. I use it to publish onto YouTube. I use it to publish onto some of the instep platforms, et cetera, et cetera.

But what happened here is Facebook invited developers to start using these APS, the eyes that they had put together, and then later trained the API [01:16:30] policies to actually be an antique competitive weapon. Developers could only access Facebook's platform and its user base. If they agreed to not compete with Facebook or the other thing that they could not do, if they wanted to use API APIs from Facebook is they could not help facilitate.

The growth of rivals. That is absolutely amazing. So the FTC lawsuit [01:17:00] says Facebook recognize that the transition to mobile posed an existential challenge and that Facebook had a brief window of time to stymie emerging. Threats. This is right in the lawsuit. Failing to compete on business talent. Facebook developed a plan to maintain its dominant position by acquiring companies that could emerge as or aid competitive threat by buying up these companies, Facebook [01:17:30] eliminated the possibility that rivals might harness the power of the mobile internet to challenge Facebook's dominance.

So when we look at things like WhatsApp, for instance, here's a small company that they acquired. Okay. So let me see. This is from Investopedia online and the title is WhatsApp. The best Facebook purchase ever. Question mark. Okay. [01:18:00] Facebook acquired WhatsApp in 2014. Now, how much did they acquire for how much was WhatsApp really worth at the time?

It's hard to say, but you can compare it with other companies of similar size and it was probably worth 20 million, maybe 50 million at most. Right. Um, initial bid from Facebook for WhatsApp was $16 [01:18:30] billion for a company that was probably worth $50. Okay. Yeah. Uh, it brought in 10 million in revenue.

WhatsApp did at the time, and it lost 150, $38 million in that same period. So let me see. The company loses $138 million on revenues of $10 million. And Facebook buys it for 16 billion in their initial offering. Well, [01:19:00] that was the, that was the initial purchase price. You can read up all you want on this.

There's lots of information. So why did Facebook do it? Because they wanted to buy it potential competitor to Facebook messenger. And that's exactly what they did. And they've done that again and again, paint far more than what the market would really dictate so that they could get rid of a competitor.

Another one is [01:19:30] an ANOVA, O N a V O. This was a VPN service that tracked users activities that they bought back in 2013 and Facebook called the Novo. Cool. This is a quote from the lawsuit. Again, according Facebook execs that the acquisition of the VPN service would be really cool for identifying acquisition targets.

With our acquisition of a Nova. We now have insight into the most popular apps. We should [01:20:00] use that to help us make strategic acquisition. So in other words, by having a VPN server, so what have I said about VPN. Don't use these public VPN services because no matter what, they're promising you, it's not true.

I did a whole webinar on this. In fact, I did it like two or three times last year. Um, but they buy the VPN service. They get people using the VPN service. They're tracking everything that's going on [01:20:30] on that VPN service. And now they know what's popular out there and anything that's popped. Facebook buys.

Why are they buying it? Well, the allegation here by the federal trade commission and from me for years is that they're buying them so they can stay in business because they can not. Move around. They don't have the talent according to Biden's now federal [01:21:00] trade commission, a T-Mobile. I got to mention this.

I am a T mobile user, and T-Mobile now has been breached and probably about 53 million customers. Personally, identifiable information was breached as part of this. Yeah. So we'll know more. T-Mobile says it's notifying customers whose information was out there as part of the breach. This is part of the reason I don't [01:21:30] like giving my social security number to these people because by the way, If it's stolen, the social security administration will not issue a new social security number.

That's part of the reason I want you to be on my email list. Craig peterson.com/subscribe. I have a bunch of techniques that you can use. To help keep your information safe, your real information safe. That [01:22:00] is by the way, T-Mobile has had six other data breaches in the past four years. How are they still in business?

I'm looking for a new company to move to Waymo has now released information. It's 6.1 million miles of self-driving car data in Phoenix, 6.1 million miles. 18 crashes 29 near miss [01:22:30] collisions during 2019 and the first nine months of 2020. Most of these, by the way, were rear Enders, some vehicles swipes, and even one incident when a Waymo vehicle was T-boned at an intersection by another car at nearly 40 miles an hour.

Nobody's seriously hurt there. So congratulations to Waymo, of course, a Google alphabet related. And it's kind of interesting to see they've actually begun offering rides [01:23:00] in fully driverless vehicles to the general public. So they're way ahead out there. You saw what Musk said this week about their, their autonomous stuff over at Tesla?

Yeah. Not quite ready yet. Hey, thanks for joining me today. Make sure you joined me online. Craig peterson.com/subscribe to get my weekly show notes for free.

View Details

Apple is Adding Tech to Look At Your Photos For Child Abuse

This is a tough one. Apple has decided that it will build into the next release of the iPhone and iPad operating systems, which monitors for child porn.

[Automated transcript]

Apple has now explained that they will be looking for child abuse images in specific ones. And I just am so uncomfortable talking about this, but the whole idea behind it is something we need to discuss. Apple said they're going to start scanning for these images and confirmed the plan. In fact, when people said, are you sure you're going to be doing that?

[00:00:44] Here's what. IOS 15, which is the next major release of Apple's operating system for I-phones. And for I pad is going to use a tie to something called the national center for missing and exploited children. And the idea behind this is to help stop some of this child abuse. And some people traffic in children; it's just unimaginable.

[00:01:14] What happens out there really is some people. It's just such evil. I, I just don't get it. Here's what they're going to be doing. There are ways of taking checksums of pictures and videos so that if there is a minor change in something that might occur because it was copied, it does not mess it up.

[00:01:40] It still can give the valid checksum and. Iman, that technology is detailed, but basically, just think of it as a checksum. So if you have a credit card number, there is a checksum digit on that bank accounts have checked some digits. If you mess it up a little bit, okay, it's an invalid checksum, so that number's obviously wrong in this case.

[00:02:04] What we're talking about is a checksum of a pitcher or oven. And these various child safety organizations have pictures of children who are abused or who are being abused, who are being exploited. And they have these checksums, which are also called hashes. So that is now going to be stored on your iOS device.

[00:02:34] And yes, it's going to take some space on the device. I don't think it's going to take an enormous amount of space, considering how much space is on most of our iPhones and iPads that are out there. Apple gave this detection system is called CSam, an absolute thorough technical summary. It is available online, and I've got a to this article in this week's newsletter, but they released this just this month, August of 2021.

[00:03:07] And they're saying that they're using a threshold, that is. Quote set to provide an extremely high level of accuracy and ensures the less than one in 1 trillion chance per year of incorrectly flagging a given account. So now I can say with some certainty in having had a basic look through some of the CSM detection documentation that they're probably right about that, that the odds are excellent.

[00:03:40] Small that someone that might have a picture of their kids in a bathtub, the odds are almost so close to zero. It is zero that it will be flagged as some sort of child abuse because it's not looking at the content of the picture. It's not saying that this picture maybe a picture of child exploitation or a video of her child being exploited.

[00:04:02] If it has not been seen before by the national center for missing exploited. It will not be flagged. So I don't want you guys to get worried that a picture at the beach of your little boy running around and just boxer trunks, but a lot of skin showing is going to get flagged. It's not going to happen.

[00:04:25] However, a pitcher that is known to this national center for missing and exploited children is, in fact, going to be flagged, and your account will be flagged. Now it's hard to say precisely what they're going to do. I haven't seen anything about it, of the apples. Only say. That that they're going to deploy software.

[00:04:51] That will analyze images in the messages application for a new system that will warn children and their parents from receiving or sending sexually explicit photos. So that's different. And that is where again, a child, you put parental settings on their iPhone. If they're taking these. Pictures, selfies, et cetera.

[00:05:14] Girls sending it to a boyfriend, sending it to his girlfriend, whatever it might be. The parents will be warned, as are the children looking for things that might be of sexual content. Okay. It really is. It's really concerning. Now let's move on to the part that I'm concerned about. I think everyone can agree that both of those features are something good that will ultimately be very good, but here's a quote.

[00:05:41] Apple is replacing its industry-standard end-to-end encrypted messaging system with an infrastructure for surveillance and censorship. Now, I should say this guy who's co-director for the center for democracy and technology security and surveillance product project. He's Greg, no, him, no Chaim, is saying this. He said Apple should abandon these changes and restore its users, faith in the security and integrity of apple devices and services.

[00:06:15] And this is from an article over a tech. So this is now where we're getting. Because what are they doing? How far are they going? Are they going to break the end encryption in something like I messages? I don't think they are going to break it there. So they're not setting up, necessarily, an infrastructure for surveillance and censorship. But, still, Apple has been called on, as has every other manufacturer of the software.

[00:06:45] I remember during the Clinton administration, this whole thing with eclipse. The federal government was going to require anyone who had any sort of security to use this chip developed by the federal government. And it turns out, of course, the NSA had a huge backdoor in it, and it was a real problem.

[00:07:04] Look at Jupiter. That was another encryption chip, and it was being used by Saddam Hussein and his family to communicate. And it turns out, yeah, there's a back door there too. This was a British project and chip that was being used. So with apple, having resisted pressure. To break into phones by the US government.

[00:07:28] But some of these other governments worldwide that have been very nasty have been spying on their citizens who torture people who don't do what apple are not happy, what the government wants them to do been trying to pressure Apple into revealing this. So now I have to say, I have been very disappointed in all of these major companies, including Apple. When it comes to China, they're just drooling at the opportunity to be there.

[00:07:57] Apple does sell stuff there. All of these companies do. Yeah, Google moves their artificial intelligence lab to China, which just, I cannot believe they would do something like that. AI machine learning, those or technologies that will give the United States a real leg up technology-wise to our competitors worldwide.

[00:08:18] They move to China, but they have complied with this great firewall of China thing where the Chinese people are being censored. They're being monitored. What's going to happen now because they've had pressure from these governments worldwide to install back doors in the encryption systems.

[00:08:39] And apple said, no, we can't do that because that's going to undermine the security for all users, which is absolutely true. For example, if there is a door with a lock, eventually, that lock will get picked. And in this case, if there's a key, if there's a backdoor of some sort, the bad guys are going to fight. So now Apple has been praised by security experts for saying, Hey, listen, we don't want to undermine security for everybody, but this plan to do ploy, some software that uses the capabilities of your iPhone to scan.

[00:09:16] Your pictures, your photos, videos that you're sharing with other people and sharing selected results with the authorities. Apple is really close to coming across that line to going across it. Apple is dangerously close to acting as a tool for government surveillance. And that's what John Hopkins university cryptography professor Matthew Greene said.

[00:09:47] This is really a key ingredient to adding surveillance to encrypted messages. This is again, according to our professor over John Hopkins, green professor green, he's saying that would be a key in Greece and then adding surveillance, encrypted messaging, the ability to add scanning systems like this to end encrypted messaging systems has been a major ask by law enforcement, the world.

[00:10:15] So they have it for detecting stuff about missing and exploited children. That's totally wonderful. And I'm okay with that. No problem. But that now means that Apple's platform can add other types of scanning. All right. We'll see what ends up happening next, which is warning children and their parents about sexually explicit photos is also a bit of a problem here.

[00:10:47] Apples. Yeah, on this is messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages it's saying. If it detects it, they're going to blur the photo. The child will be warned, presented with helpful resources, and reassured it is okay if they do not want to view them.

[00:11:17] And the system will let parents get a message. If children view a flagged photo, similar protections are available for child attempts to send sexually explicit images. Interesting. Isn't it. Interesting world. So I think what they're doing now is, okay, they're really close to that line, going over.

[00:11:39] It could mean the loss of lives in many countries that totally abuse their citizens or subjects, depending on how they look at them. Hey, make sure you check me out online. Craig Peterson.com.

View Details

The IRS Has Been Selling Bitcoin - Pay Up!

Bitcoin is all the rage. In fact, many people have considered investing in these cryptocurrencies or something. Of course, many have invested in it. I played around with them about a decade ago, and the IRS seized 1.2 billion worth of it.

[Automated transcript]

You might remember, we talked years ago about the IRS trying to tax things in the virtual world. So if you were in one of these real-life-type things and you owned property, as it were inside this virtual world, they wanted to tax it. So, of course, if you sold something with real hard money and. You sold it inside that real world with real hard cash, you would end up having to pay taxes.

[00:00:43] Just if you sold a hammer to someone, that's the way it works. A lot of people have decided that, for some reason, cryptocurrency is entirely untracked. Now we know about cases. I've talked about them here where some of these coins, in this particular case, are talking about Bitcoin or have been used online.

[00:01:11] And in fact, the government has found out who was using it and really stepped in, in a big way. Silk Road is the most significant example. This was an online black market for everything you can think of, from illegal drugs to firearms, to all kinds of illicit commodities for sale online.

[00:01:36] Back in 2013, they used Bitcoin to buy and sell things in this free trade zone. I think they called themselves, and Silk Road was just thriving. But then, on comes the federal government and federal agents in the United States really cut their teeth in crypto search and seizure. With taking down the silk road, you might remember this was very unprecedented.

[00:02:06] People had no idea. What they could do. How could the federal government monitor this? Can I buy and sell these Bitcoins? All of that sort of thing. And 20 years as the chief of money laundering and asset forfeiture. Yeah, us attorney's office for the Southern District of New York. Sharon Levin said that this whole takedown or silk road was utterly unprecedented, and it was new technology.

[00:02:37] What do you do well because of people. Here cryptocurrency and crypto, of course, being short for cryptography, they figure that okay. While obviously, it is absolutely untraceable, untrackable. Tell that to the people that this year has tried to ransom money out of enough. US corporations, some of the major -- consider Colonial Pipeline and what happened with them and how at least half of their cryptocurrency was returned to them.

[00:03:11] So don't think that this stuff is a way that you can get away with breaking in the law or not paying taxes. It is not the whole. Business, if you will, of crypto seizure and sale is growing incredibly fast. In fact, the federal government just enlisted the help of the private sector to manage and store these crypto tokens that have been seized.

[00:03:43] Now, I mentioned that the IRS has seized about $1.2 billion worth of cryptocurrency this fiscal year. That is a whole lot of cryptocurrency. And what are they doing with it while it's the same thing? Remember the drug dealers back in the day. Miami, what was happening? I used to love the Miami Vice TV show. What happened there while they seized boats, they confiscated cars.

[00:04:09] They seized cash. Obviously, they can just be put back into circulation, but what do they do everything else? Cores, they go ahead, and they sell it at auction. And that's what they've been doing. Then in June, they started auctioning off Litecoin and Bitcoin cash. They had 11 different lots on offer.

[00:04:34] It was a four-day auction, and it included 150.2, 2 5 6 7 1 5 3 Litecoin. You like that. Remember, cryptocurrency is not necessarily a whole coin. It's like having a gold coin. That's worth 500 bucks. How are you going to use that to buy a loaf? But what happens with these cryptocurrencies is you can buy and sell fractions of a coin.

[00:05:00] So that's why you get into the millions of a piece of a coin. So they sold 150 ish Litecoin and about 0.00022 in Bitcoin cash worth more than 21 grand. So that's one of the 11 lots that were out there. And this crypto property is what they're calling. It had been confiscated as part of a tax noncompliance case.

[00:05:30] I'm looking right now at the public auction sale notice. And where it was, where you could go online. It was on https://gsaauctions.gov. Suppose you want to check these things out, as in the general services administration. In that case, auctions.gov, GSA, auctions.gov, and they were selling it, and it was a taxpayer, it tells you all kinds of information about them.

[00:05:52] It's a. Crazy here, but you have to pay by cash to certified cashiers or treasures check drawn on different banks. And it's really cool to look at some of these things, but you can find them online. So if you're interested in buying them might be an excellent way to buy them, these various cryptocurrencies if you want to get into them.

[00:06:15] But a lot can refer to almost anything could be, as I said, boats or cars like it was on Miami vice. It could be some number of crypto coins that are being auctioned. So they're going to be doing more and more of that. So then, apparently, the feds are saying that they have no plans to step back from being basically a crypto broker.

[00:06:41] Here is the bottom line here because they're seizing and selling all of these assets. So keep an eye out for that. Remember what is going on? The silk road site that I mentioned had been shut down or operating on the dark web. It used Bitcoin exclusively nowadays are using various types of coins.

[00:07:04] Most of them are ultimately traceable, and we're not going to get into all of the details behind it, but the bottom line is, so what do they do now? Think about this. Silk road had 30,000 Bitcoin that they were able to identify in CS. And it was probably the most significant Bitcoin seizure ever. And it sold for about $19 million.

[00:07:32] So that was quite a few years ago. Somebody just pulls up a calculator here, say 30,000 times, and what's Bitcoin nowadays. I'm not quite sure. Let's say it's $15,000. So in today's money, it had half a billion dollars. Today's value, a half, a billion dollars worth of Bitcoin in there isn't that something, and that was all seized, and it was all auctioned off.

[00:07:58] So keep an eye on that. They're following the money is the technique they're using. You can find out a lot more at us, marshals.gov, and that is how they found it. If you've got pictures. You're going to have to sell it. You're going to have to transfer. You have to do something with it. And that's where they're getting.

[00:08:19] Bottom line, particularly if you take the Bitcoin and turn it into something else, but this would take a while to explain. And I was thrilled to be able to sit in on a presentation done by the treasury department on how they handle all of this. It's frankly very fascinating. So, hey, make sure you spend a couple of minutes and join me online.

[00:08:44] Craig peterson.com. You can sign up for my newsletter. You can listen to my podcasts, and you can get some free, special reports just for signing up.

View Details

The "Great Resignation" in Big Tech - Better Jobs, More Money

There seems to be a worker shortage. And many businesses are finding that, frankly, people involved in technology are resigning; they're calling it a great resignation of workers. We have a lot of problems as business people, filling jobs nowadays.

[Automated transcript]

[00:00:20] And one of the things I've thought about doing is maybe even starting a course for people who want to figure out if this whole cybersecurity thing is right for them. I think that might make a lot of sense for some people. And there are some of you listeners. I know, because I've talked to you who have gone out and.

[00:00:40] Gotten into, is that a word who have changed careers into the cybersecurity realm? So does it make sense for you? I don't know. Do you think it would make sense for me to offer something? A cybersecurity course to give you guys the basics and help you understand it and see if it might be good for you.

[00:01:00] Only, you know that, and if you're interested, make sure you drop me a note just to me, M E Craig peterson.com, and let me know what you think. Still, the big tech is suffering from this great resignation of workers and workers in the technology field right now. So it's a good time to leave. Now, this isn't the same as many workers who, for instance, were in the restaurant business for many years, were in food service.

[00:01:31] You make money. Maybe you don't make money. Who knows those. And, of course, those jobs pretty much disappeared during the lockup. Big tech, it's different from big tech. Most of these people, most of us, frankly, retained our jobs. We were still able to work, still able to do the stuff we'd always been doing. Still, we were doing it from home, and many employees looked at the situation and said, I am not going to leave.

[00:02:05] Because I don't know if I'll be able to get a new job. Does that make sense to you? So we have a bit of pent-up demand in the tech field of people who maybe didn't like the boss, didn't really like what they were doing but kept the job because at least it was a job. It paid some bills. And from the bottom-line standpoint, it didn't make sense to.

[00:02:29] Now we see something else going on; people are leaving like crazy Facebook here. There's a quote in an article in MarketWatch. Lost this guy named Raymond Andres. Who's now the chief technology officer at the air table. Now I've used air table before I was a client of theirs for a while. It's really something.

[00:02:52] If you need to do some essential project management or have a process for doing something. That needs to be tracked, and maybe something handed over to another person when it meets a particular stage. Check it out, air table.com online. Still, he left Facebook, and he said there's been a burst of activity of people leaving.

[00:03:15] If anything. The lockdown delayed decisions. And that's exactly what I was saying. I've been saying that for a very long time, but there's another factor involved when it comes to technology. And that is the funding, which is just amazing. You might remember a couple of years ago we had this. Brakes on IPO's on initial public offerings.

[00:03:40] These tech companies just were not going to go public at all. And because of that, many angel investors and venture capitalists said, forget about it. I'm not going to go ahead and make any sort of investment. So that is when many of these small companies just failed, and of course, incomes the lockdown, and even more of them died.

[00:04:03] But now. But the investors are a spinner spending a lot of money so far this year. There have been 84 initial public offerings in the US alone. Isn't that amazing? 50 plus billion dollars in IPO's. Now that's up from about 38 billion. Last year. So there's obviously money in the IPO world. So that gets the venture capitalists interested.

[00:04:36] So VC money is also at record highs. This year's track is to be the best year yet. According to PitchBook through June. This year 2021, $150 billion has been raised among about 7,000 deals. Now that's ahead of last year's record, a total of $164 billion for the year. So we're looking at some significant money going in.

[00:05:10] And we have many people leaving from Google and Facebook and Amazon and Apple, maybe your company as well, who are saying, wow there's some real opportunity now I could get in on the ground floor. The VC money is a record high, so I can take at least some salary enough to make it heck I haven't had to pay rent for a year.

[00:05:33] So I can afford to do that, to try and. Something with some of my friends, and that's precisely what they're doing. Robert half, a company I've had on my show before Robert half international, did a survey. They found that about one-third of the almost 3000 information technology professionals.

[00:05:57] They surveyed said they planned to look for a new job in the next few months. They're also saying Robert half is that while employers posted more than 365,000 job openings in June alone, they're not getting filled; that's, by the way, the highest monthly. In about since September 2019, according to CompTIA, which is an industry trade group.

[00:06:25] I'm a member of that. My company is a member of comp Tia as well. So there are a lot of things happening that are really driving people to startups. And there's a lot of advantages to that. So here's another guy. This is an engineering manager who left Facebook last year. And he quickly returned.

[00:06:46] He said working at a startup, you have much more connection with employees, and things moved faster. So tiger graph, by the way, also hired ex-Googlers. And they're increasing the workforce this year too, about 300 from 90. So think about what they're doing. So that's not, yeah, technically, it's probably still a startup, but it's 300 employees.

[00:07:10] That's not us. That is a lot of employees, and they've got a lot of money behind them. Here's another guy. And she's saying, I thought I would be a lifer at Amazon. But this was a tremendous opportunity. I can have a far more significant impact and more influence on the company's trajectory, which quite frankly was harder at Amazon.

[00:07:33] And we're seeing more and more of particularly the younger employees looking at that. Her name's Anna fag fabric. Sorry about the names butchering here, but she's now at freshly. Officer. So many people are saying in this survey from Robert half international that having a chance to impact a smaller company was a significant reason for leaving.

[00:08:01] And that's after years of massive growth at big tech companies. So again, IBM in the 1970s. They were the ruler; they were the king. It was impossible. If you work for IBM, man, they're going to be around forever. And, of course, they still are. And they have excellent products, especially the Z series mainframe, but they're not the company they were.

[00:08:24] And I think we now are seeing. The next step in these big high-tech, but is no longer being the companies that they were innovation is going to leave with these employees, and they're going to really be hurt and hurt quite a bit. All right. So coming up, we're going to talk, of course, more about some of the more critical tech stuff you've got to. If you haven't already get on my email list, I'll send you a couple of special reports that we.

[00:08:54] As well as, of course, every week, one or two newsletters, not sales documents, newsletters, Craig peterson.com.

View Details

1126-01-windows_11_and_tpm

[00:00:00] Microsoft has had some incredibly successful operating systems and some significant failures. Think of windows millennial edition. While now they're coming up with windows 11, and frankly, things just aren't looking that good.

[00:00:16] If you know me, you know how I have had some issues with Microsoft here over the years; they are a company that has been, in my opinion, very dishonest have been doing all kinds of immoral things for a very long time by destroying.

[00:00:36] Parts of the market that they considered being competitors of theirs, so they have used their position at the top of the market with billions of dollars in cash to really nail anybody that tries to challenge them. And it's incredible to me what has happened over the years. But, of course, you might know Microsoft did.

[00:00:57] Putting an investment into Apple. And many people say that investment that bill gates authorized really saved apple from total collapse. And I can see how is this a reasonable audience or argument? But the bottom line, when we get down to it, is that Microsoft Windows has never been a great operating system.

[00:01:21] It's always had issues. It's always had glitches, and we could go into a lot of reasons for that. But I think one of the main ones is that it has really tried to stay compatible with everything, all of the. When you were a kid, you certainly rode a bicycle. But, still, the bike you might be riding when you're in your thirties or forties will probably not have three wheels.

[00:01:46] And it's probably not going to have a pedal connected to the front wheel. It will be a whole lot different, and Microsoft, over the years, has tried to make their more modern operating systems as time has gone on. Compatible with older operating systems of theirs. And that inevitably leads to problems.

[00:02:06] If you're trying to fix a problem, Einstein said this, right? If you're trying to fix a problem, you cannot use the thinking that created the problem in that first place. So to fix a problem, you have to think at a different level. And when it comes to software and operating systems, you actually. To program at a different level.

[00:02:29] And the entire structure of the programs has to be different than it is when you're starting. Microsoft has been doing that a little bit. And with Windows 11, they are really trying, they've gotten such black eyes over the years for security problems, and I think they deserve them for the most part.

[00:02:50] Now they're forcing you to use what's called a TPM. Now, these TPMS have been around for quite a while. You see them built into your Macs, and they've been built into your apple Macs now for years, built-in frankly to your iOS devices for your iPhone also for years. But this is a trusted platform module TPM.

[00:03:17] And the idea behind a TPM is that your computer hardware is locking. All of this information and the senior TPM. Now there are a lot of complicated implementations of TPMS. The implementation that apple uses stores, all kinds of stuff that makes sure you're booting properly, security, keys, et cetera. What Microsoft is doing now is for windows 11.

[00:03:47] If you're going to. Your machine has to have a TPM and not just an older TPM 2.0. Now there are alpha images available right now for developers of Windows 11. And I have to absolutely encourage you if you are a software developer to get an alpha version of windows so that you can double-check, is my software is still going to be able to run in this.

[00:04:13] And I also want to encourage you if you are relying on particular applications. Maybe they're a little older, perhaps they're not, but if your business requires you to use a piece of software, you really should get windows 11. Right now, get the alpha code, follow it through beta and test your software.

[00:04:36] Make sure it works. If it isn't working, then talk to your software vendors, warn them that it's. Because Windows 11 requiring TPM support, although it doesn't need it right now in this alpha version that they're releasing, it does require it. Supposedly when they finally release Windows 11, the computers you have today probably don't have this chip.

[00:05:07] We have a client who decided they would go out and buy their own server against our judgment. And what we told them they should be doing. So they went out, and they purchased an HP server from HP enterprise, and they did. And it did not have most of the security staff they needed, including it did not have a TPM.

[00:05:27] It did not have one of these trusted platform modules on it. Now, in their case with this HP server, they could buy one after the fact and install it. Although the entire machine had to be destroyed entirely and reloaded, that's a minor price to pay versus purchasing a whole new server.

[00:05:48] The TBM is not necessarily going to be compatible with the new version of windows. In fact, Microsoft surface tablets. I look this up to their highest-end surface tablets, Microsoft branding all over it. Microsoft certified $6,000 almost to buy this top-end surface tablet with all the bells and whistles you can get on it.

[00:06:15] It will not work with windows 11. How's that? So the reason Microsoft is doing this, I think, is a good reason. They really want to lock down this system to no longer have as many security problems. And we're not going to get into all of the different types of security problems that TPM is not going to solve a lot of them, but it's going to solve.

[00:06:40] Some of them, but the program manager over Microsoft, her name is Al area. I guess it is Carly. She said that the hardware floor of TPM 2.0 support will be in place for the final version. We'll see. I think a lot of people are going to push back. However, Microsoft really does and legitimately does want to make sure that everything is safe.

[00:07:07] So keep that in mind. There are a lot of people complaining about it, the alpha version. And that is why you have an alpha version. They're complaining about it because of the TPM, but also because of some of the other things that are going on with windows 11, at least right now, some of the things Microsoft has announced they've got, for instance, group policy will not let you get around hardware enforcement for windows 11.

[00:07:34] Microsoft is still going to block you from upgrading your device. To make sure your devices stay supported and secure. So that's good news, and it's good news because many times in the past, how many of us we've upgraded our machines and a new version of the operating system. And I use "upgrade" with air quotes around it, but we've upgraded our machines, and they won't work with the new version.

[00:08:00] The audience here for her short statement, which was part of this, a Microsoft tech community user questions, was agitated. They did not like the answers that she was giving. And this is according to windows central, the videos, top comment, read, quote, a lot of these answers come off as super Tone Deaf.

[00:08:22] It is looking like Windows 11 will be another problem. So for those of us, that know, yeah. Windows eight was really quite the flop member. They very quickly came out with windows eight one, and Microsoft is the only tone-deaf company out there. I've got to say, I think Apple has been remarkably tone-deaf in many different ways.

[00:08:44] Now they seem to be waking up doing some things a little bit better, so kudos to them for that. But a lot of companies, really. Tone, deaf to what users want. And there's a lot of blog posts here. We'll have to see if what they're saying ultimately ends up in windows 11. If it does, things will be a bit of a problem.

[00:09:08] But part of the reason we don't know. Because Microsoft disabled any more comments on the video, they were getting so many of them. And of course, there are trolls people who hate Microsoft. I'm certainly not one of them. They also, by the way, deleted all existing comments on the video here about windows 11 with their program manager in response to the negativity. The voting is still open on this video, and 2,700 dislikes and only 146 likes as of this last week. It's interesting. Microsofts are really rushing to these new hardware requirements. They're being very aggressive, and I think they're handling it. Sound familiar. We've heard these sorts of things before, but now we'll see here into the legitimacy of this. How much is it going to benefit is limited because where are we solving our biggest problems?

[00:10:09] People cooking, links, things get installed, et cetera, that nothing to TPM will be able to handle. The TPM is going to make sure that you have a secure boot that's it's missing. The goal in life. So how was it? We will help with a lot of this other stuff we will see, and I'll definitely keep you up to date on this?

[00:10:28] It's real. Hey, I want to remind you guys, go to Craig peterson.com. Hopefully, you got my newsletter last week. I gave you a private link to a webinar that I did about VPN because there's a lot of people selling VPNs. Unfortunately, most of them are misrepresenting what they can. And in fact, most of them make you less safe.

[00:10:53] So don't miss another thing. Go to Craig peterson.com right now. And subscribe

View Details

[Automated transcript]

Weekly - Microsoft is planning on making you buy a new computer

[00:00:00] Microsoft has had some incredibly successful operating systems and some significant failures. Think of windows millennial edition. While now they're coming up with windows 11, and frankly, things just aren't looking that good.

[00:00:16] If you know me, you know how I have had some issues with Microsoft here over the years. They are a company that has been, in my opinion, very dishonest have been doing all kinds of immoral things for a very long time by destroying.

[00:00:36] Parts of the market that they considered being competitors of theirs, so they have used their position at the top of the market with billions of dollars in cash to really nail anybody that tries to challenge them. And it's incredible to me what has happened over the years. But, of course, you might know Microsoft did.

[00:00:57] Putting investment into Apple. And many people say that investment that bill gates authorized really saved apple from total collapse. And I can see how is this a reasonable audience or argument? But the bottom line is that Microsoft Windows has never been a great operating system when we get down to it.

[00:01:21] It's always had issues. It's always had glitches, and we could go into a lot of reasons for that. But I think one of the main ones is that it has really tried to stay compatible with everything, all of the. When you were a kid, you certainly rode a bicycle. But, still, the bike that you might be riding when you're in your thirties or forties is probably not going to have three wheels.

[00:01:46] And it's probably not going to have a pedal connected to the front wheel. It is going to be a whole lot different, and Microsoft, over the years, has tried to make their more modern operating systems as time has gone on. Compatible with older operating systems of theirs. And that inevitably leads to problems.

[00:02:06] If you're trying to fix a problem, Einstein said this, right? If you're trying to fix a problem, you cannot use the thinking that created the problem in that first place, in order to fix a problem, you have to think at a different level. And when it comes to software and operating systems, you actually. To program at a different level.

[00:02:29] And the entire structure of the programs has to be different than it is when you're starting. Microsoft has been doing that a little bit. And with Windows 11, they are really trying, they've gotten such black eyes over the years for security problems, and I think they deserve them for the most part.

[00:02:50] Now they're forcing you to use, what's called a TPM. Now these TPMS have been around for quite a while. You see them built into your Macs, and they've been built into your apple Macs now for years built-in frankly to your iOS devices for your iPhone also for years. But this is a trusted platform module TPM.

[00:03:17] And the idea behind a TPM is that your computer hardware is locking. All of this information and the senior TPM. Now there are a lot of difficult implementations of TPMS. The implementation that apple uses stores, all kinds of stuff that makes sure you're booting properly security, keys, et cetera. What Microsoft is doing now is for windows 11.

[00:03:47] If you're going to. Your machine has to have a TPM and not just a older TPM 2.0, now there are alpha images available right now for developers of Windows 11. And I have to absolutely encourage you if you are a software developer to get an alpha version of windows so that you can double-check, is my software still going to be able to run in this.

[00:04:13] And I also want to encourage you if you are relying on certain applications and maybe they're a little bit older, maybe they're not, but if your business requires you to use a piece of software, you really should get windows 11. Right now, get the alpha code, follow it through beta and test your software.

[00:04:36] Make sure it works. If it isn't working, then talk to your software vendors, warn them that it's. Because Windows 11 requiring TPM support, although it doesn't require right now in this alpha version that they're releasing, but it does require it. Supposedly when they finally release windows 11, your computers that you have today probably don't have this chip.

[00:05:07] We have a client that decided they were going to go out and buy their own server against our judgment. And what we told them they should be doing. So they went out and they bought we're going to get an HP server from HP enterprise and they did. And it did not have most of the security staff that they needed, including it did not have a TPM.

[00:05:27] It did not have one of these trusted platform modules on it. Now, in their case with this HP server, they could buy one after the fact and install it. Although the entire machine had to be completely destroyed and reloaded, that's a minor price to pay versus buying a whole new server.

[00:05:48] The TBM is not necessarily going to be compatible with the new version of windows. In fact, Microsoft surface tablets. I look this up their highest end surface tablets, Microsoft branding all over it. Microsoft certified $6,000 almost to buy this, or, top end surface tablet with all of the bells and whistles you can get on it.

[00:06:15] It will not work with windows 11. How's that? So the reason Microsoft is doing this, I think is a good reason. They really want to lock down this system so that we're no longer having as many security problems. And we're not going to get into all of the different types of security problems that TPM is not going to solve a lot of them, but it's going to solve.

[00:06:40] Some of them, but the program manager over Microsoft, her name is Al area. I guess it is Carly. She said that the hardware floor of TPM 2.0 support is going to be in place for the final version. We'll see. I think a lot of people are going to push back. However, Microsoft really does and legitimately does want to make sure that everything is safe.

[00:07:07] So keep that in mind. There are a lot of people complaining about it, the alpha version. And that is why you have an alpha version, they're complaining about it because of the TPM, but also because of some of the other things that are going on with windows 11, at least right now, some of the things Microsoft has announced they've got, for instance group policy will not let you get around hardware enforcement for windows 11.

[00:07:34] Microsoft is still going to block you from upgrading your device. To make sure your devices stay supported and secure. So that's good news and it's good news because many times in the past, how many of us we've upgraded our machines and to a new version of the operating system. And I use upgrade with air quotes around it, but we've upgraded our machines and they won't work with the new version of it.

[00:08:00] The audience here for her little statement, which was part of this, a Microsoft tech community user questions was very upset. They did not like the answers that she was giving. And this is according to windows central, the videos, top comment, read, quote, a lot of these answers come off as super tone.

[00:08:22] Deaf is looking like Windows 11 will be another windows. So for those of us that know yeah. Windows eight was really quite the flop member. They very quickly came out with windows eight one and the Microsoft is, and the only tone-deaf company out there, I've got to say, I think Apple has been very tone-deaf in a lot of different ways.

[00:08:44] Now they seem to be waking up doing some things a little bit better, so kudos to them for that. But a lot of companies really. Tone, deaf to what users want. And there's a lot of blog posts here. We'll have to see if what they're saying ultimately ends up in windows 11. If it does, things will be a bit of a problem.

[00:09:08] But part of the reason we don't know. Is because Microsoft disabled, any more comments on the video, they were getting so many of them. And of course there's trolls people who hate Microsoft. I'm certainly not one of them. They also, by the way, deleted all existing comments on the video here about windows 11 with their program manager in response to the negativity, the voting is still upon this video and.

[00:09:37] 2,700 dislikes and only 146 likes as of this last week. It's interesting. Microsofts are really rushing to these new hardware requirements. They're being very aggressive, and I think they're handling it. Sound familiar. We've heard these sorts of things before, but now we'll see here into the legitimacy of this, how much is it going to benefit is limited as well because where are we having our biggest problems?

[00:10:09] People cooking, links, things get installed et cetera, that nothing to TPM is going to be able to handle. The TPM is going to make sure that you have a secure boot that's it's missing. Goal in life. So how was it we're going to help with a lot of this other stuff we will see, and I'll definitely keep you up to date on this.

[00:10:28] It's a real. Hey, I want to remind you guys, go to Craig peterson.com. Hopefully you got my newsletter last week. I gave you a private link to a webinar that I did about VPN, because there's a lot of people selling VPNs. Most of them are misrepresenting what they can. And in fact, most of them make you less safe.

[00:10:53] So don't miss another thing. Go to Craig peterson.com right now. And subscribe

[00:10:59] There seems to be a worker shortage. And a lot of businesses are finding that frankly, people who are involved in technology are resigning, they're calling it a great resignation of workers. We have a lot of problems as business people, filling jobs nowadays.

[00:11:20] And one of the things I've thought about doing is maybe even starting a course for people who want to figure out if this whole cybersecurity thing is right for them. I think that might make a lot of sense for some people. And there are some of you listeners. I know, because I've talked to you who have gone out and.

[00:11:40] Gotten into, is that a word who have changed careers into the cybersecurity realm? So does it make sense for you? I don't know. Do you think it would make sense for me to offer something? A cybersecurity course to give you guys the basics and help you to understand it, to see if it might be good for you.

[00:12:00] Only, you know that, and if you're interested, make sure you drop me a note just to me, M E Craig peterson.com and let me know what you think, but the big tech is suffering from this great resignation of workers and workers in the technology field right now. It's a good time to leave. Now, this isn't the same as many workers who, for instance, were in the restaurant business for many years, were in food service.

[00:12:31] You make money. Maybe you don't make money. Who knows those. And of course, those jobs pretty much disappeared during the lockup. Big tech, it's different in big tech. Most of these people, most of us, frankly, we retained our jobs. We were still able to work, still able to do the stuff we'd always been doing, but we were doing it from home, and many employees looked at the situation and said, I am not going to leave.

[00:13:04] Because I don't know if I'll be able to get a new job. Does that make sense to you? So we have a bit of a pent up demand in the tech field of people who maybe didn't like the boss didn't really like what they were doing, but kept the job because at least it was a job. It paid some bills. And from the bottom-line standpoint, it didn't make sense to.

[00:13:28] Now we see something else going on, people are leaving like crazy Facebook here. There's a quote in an article in MarketWatch. Lost this guy named Raymond Andres. Who's now the chief technology officer at air table. Now I've used air table before I was a client of theirs for a while. It's really something.

[00:13:51] If you need to do some basic project management, or if you have a process for doing something. That needs to be tracked and maybe something handed over to another person when it meets a certain stage, check it out, air table.com online, but he left Facebook and he said, there's been a burst of activity of people leaving.

[00:14:15] If anything. The lockdown delayed decisions. And that's exactly what I was saying. I've been saying that for a very long time, but there's another factor involved when it comes to technology. And that is the funding, which is just amazing. You might remember a couple of years ago we had this. Brakes on IPO's on initial public offerings.

[00:14:40] These tech companies just were not going to go public at all. And because of that, many angel investors and venture capitalists said, forget about it. I'm not going to go ahead and make any sort of investment. That is the time when a lot of these small companies just failed and of course, incomes the lockdown and even more of them failed.

[00:15:03] But now. But the investors are a spinner spending a lot of money so far this year, there have been 84 initial public offerings in the U S alone. Isn't that amazing? 50 plus billion dollars in IPO's. Now that's up from about 38 billion. Last year. So there's obviously money in the IPO world. So that gets the venture capitalists interested.

[00:15:36] So VC money is also a record hives. This year's track to be the best year yet. According to PitchBook through June. This year 2021, $150 billion has been raised among about 7,000 deals. Now that's ahead of last year's record, a total of $164 billion for the year. So we're looking at some major money going in.

[00:16:09] And we're have a lot of people that are leaving from Google and Facebook and Amazon and Apple, maybe your company as well, who are saying, wow there's some real opportunity now I could get in on the ground floor. The VC money is a record high, so I can take at least some salary enough to make it heck I haven't had to pay rent for a year.

[00:16:32] So I can afford to do that, to try and. Something with some of my friends and that's exactly what they're doing. Robert half, which is a company I've had on my show before Robert half international, they did a survey and they found that about one third of the almost 3000 information technology professionals.

[00:16:56] They surveyed said they planned to look for a new job in the next few months. They're also saying Robert half is that while employers posted more than 365,000 job openings in June alone, they're not getting filled that's by the way, the highest monthly. In about since September, 2019, and that's according to comp Tia, which is a, an industry trade group.

[00:17:24] I'm a member of that. My company is a member of comp Tia as well. So there are a lot of things happening that are really driving people to startups. And there's a lot of advantages to that. So here's another guy. This is an engineering manager who left Facebook last year. And he quickly returned.

[00:17:45] He said working at a startup, you have much more connection with employees and things moved faster. So tiger graph, by the way, also hired ex-Googlers. And they're increasing the workforce this year too, about 300 from 90. So think about what they're doing. That's not, yeah, technically it's probably still a startup, but it's 300 employees.

[00:18:10] That's not us. That is a lot of employees, and they've got a lot of money behind them. Here's another guy. And she's saying, I thought I would be a lifer at Amazon. But this was a tremendous opportunity. I can have a far greater impact and more influence on the company's trajectory, which quite frankly was harder at Amazon.

[00:18:32] And we're seeing more and more of particularly the younger employees looking at that. Her name's Anna fag fabric, sorry about the names butchering here, but she's now at freshly she's their chief criminals commercialization. Officer. So a lot of people are saying in this survey from Robert half international that having a chance to have an impact at a smaller company was a major reason for leaving.

[00:19:00] And that's after years of massive growth at big tech companies. So again, IBM in the 1970s. They were the ruler, they were the king. They was impossible. If you work for IBM, man, they're going to be around forever. And of course, they still are. And they have amazing products, especially the Z series mainframe, but they're not the company they were.

[00:19:24] And I think we now are seeing. The next step in these big high-tech, but is no longer being the companies that they were innovation is going to leave with these employees, and they're going to really be hurt and hurt quite a bit. All right. So coming up, we're going to talk, of course, more about some of the more important tech stuff, you've got to, if you haven't already get on my email list, I'll send you a couple of special reports that we.

[00:19:54] As well as of course, every week, one or two newsletters, not sales documents, newsletters, Craig peterson.com.

[00:20:04] Bitcoin is all of the rage. In fact, these cryptocurrencies or something, a lot of people have considered investing in of course, many have invested in it. I played around with them about a decade ago, and the IRS seized 1.2 billion worth of it.

[00:20:19] You might remember, we talked years ago about the IRS trying to tax things in the virtual world. So if you were in one of these real life type things and you owned property, as it were inside this virtual world, they wanted to tax it. Of course, if you sold something with real hard money and. You sold it inside that real world with real hard money, you would end up having to pay taxes.

[00:20:47] Just if you sold a hammer to someone, that's the way it works. A lot of people have decided that, for some reason, cryptocurrency is completely untracked. Now we know about cases. I've talked about them here where some of these coins in this particular case, we're talking about Bitcoin or has been used online.

[00:21:15] And in fact, the government has found out who was using it and really stepped in, in a big way. Silk road is the biggest example. This was an online black market for everything you can think of, from illegal drugs to firearms, to all kinds of illegal commodities that were for sale online.

[00:21:40] This was back in 2013, they were using Bitcoin to buy and sell things on this free trade zone. I think they called themselves and silk growed was just thriving. On comes the federal government and federal agents in the United States really cut their teeth in crypto search and seizure. With taking down the silk road, you might remember this was very unprecedented.

[00:22:10] People had no idea. What they could do. How could the federal government monitor this? Can I buy and sell these Bitcoins? All of that sort of thing. And 20 years as the chief of money laundering and asset forfeiture in. Yeah, us attorney's office for the Southern District of New York. Sharon Levin said that this whole takedown or silk road was completely unprecedented and it was new technology.

[00:22:41] What do you do well because people. Here cryptocurrency and crypto, of course, being short for cryptography, they figure that okay. While obviously it is absolutely untraceable untrackable. Tell that to the people that this year have tried to ransom money out of enough. US corporation, some of the major consider for instance, colonial pipeline and what happened with them and how at least half of their cryptocurrency was returned to them.

[00:23:15] So don't think that this stuff is a way that you can get away with breaking in the law or not paying taxes. It is not the whole. Business, if you will, of crypto seizure and sale is growing incredibly fast. In fact, the federal government just enlisted the help of the private sector to manage and store these crypto tokens that have been seized from.

[00:23:47] Now I mentioned that the IRS has seized about $1.2 billion worth of cryptocurrency this fiscal year. That is a whole lot of cryptocurrency. And what are they doing with it while it's the same thing? Remember the drug dealers back in the day. Miami, what was happening? I used to love Miami vice TV show. What happened there while they seize boats, they seized cars.

[00:24:13] They seized cash. Obviously, they can just put back into circulation, but everything else, what do they do? Cores, they go ahead and they sell it at auction. And that's what they've been doing. Then in June, they started auctioning off light coin and Bitcoin cash. They had 11 different lots on offer.

[00:24:38] It was a four day auction and it included 150.2, 2 5 6 7 1 5 3 light coin. You like that. Remember cryptocurrency is not necessarily a whole coin. It's like having a gold coin. That's worth 500 bucks. How are you going to use that to buy a loaf? But what happens with these cryptocurrencies is you can buy and sell fractions of a coin.

[00:25:04] So that's why you get into the millions of a piece of a coin. So they sold 150 ish like coin and. Above 0.00022 a Bitcoin cash worth more than 21 grand. So that's one of the 11 lots that was out there. And this crypto property is what they're calling. It had been confiscated as part of a tax noncompliance case.

[00:25:34] I'm looking right now at the public auction sale notice. And where it was, where you could go online. It was a GS, a auctions.gov. If you want to check these things out, as in the general services administration, auctions.gov, GSA, auctions.gov, and they were selling it, and it was a taxpayer, it tells you all kinds of information about them.

[00:25:56] It's a. Crazy here, but you have to pay by cash to certified cashiers or treasures check drawn on different whatever banks. And it's really cool to look at some of these things, but you can find them online. If you're interested in buying them might be a good way to buy them, to buy these various cryptocurrencies if you want to get into there.

[00:26:20] But a lot can refer to almost anything could be, as I said, boats or cars like it was on Miami vice. It could be some number of crypto coins that are being auctioned. So they're going to be doing more and more of that. Then, apparently, the feds are saying that they have no plans to step back from being basically a crypto broker.

[00:26:46] Here is the bottom line here because they're seizing and selling all of these assets. So keep an eye out for that. Remember what is going on? The silk road site that I mentioned had been shut down or operating on the dark web. It used Bitcoin exclusively nowadays are using various either types of coins.

[00:27:09] Most of them are ultimately traceable, and we're not going to get into all of the details behind it, but the bottom line is so what do they do now? Think about this. Silk road had 30,000 Bitcoin that they were able to identify in CS. And it was probably the biggest Bitcoin seizure ever. And it sold for about $19 million.

[00:27:37] So that was quite a few years ago. Somebody just pull up a calculator here, say 30,000 times, and what's Bitcoin nowadays. I'm not quite sure. Let's say it's $15,000. So in today's money, it had a half, a billion dollars. Today's value, a half, a billion dollars worth of Bitcoin in there isn't that something, and that was all seized and it was all auctioned off.

[00:28:03] So keep an eye on that. They're following the money is the technique they're using. You can find out a lot more at us, marshals.gov, and that is how they found it. If you've got pictures. You're going to have to sell it. You're going to have to transfer. You have to do something with it. And that's where they're getting.

[00:28:24] Bottom line, particularly if you take the Bitcoin and turn it into something else, but this would take a while to explain. And I was very happy to be able to sit in on a presentation that was done by the treasury department on how they handle all of this. It's frankly very fascinating. Hey, make sure you spend a couple of minutes and join me online.

[00:28:49] Craig peterson.com. You can sign up for my newsletter. You can listen to my podcasts, and you can get some free, special reports just for signing up.

[00:28:59] This is a tough one. Apple has decided that they are going to build in to the next release of the iPhone and iPad operating system. Something that monitors for child porn.

[00:29:12] Apple has now explained that they are going to be looking for child abuse images in specific ones. And I just am so uncomfortable talking about this, but the whole idea behind it is something we need to discuss. Apple said, they're going to start scanning for these images and confirmed the plan. In fact, when people said, are you sure you're going to be doing that?

[00:29:43] Here's what. IOS 15, which is the next major release of Apple's operating system for I-phones. And for I pad is going to use a tie to something called the national center for missing and exploited children. And the idea behind this is to help stop some of this child abuse and there's people who traffic in children, and it's just unimaginable.

[00:30:13] What happens out there really is some people it's just such evil. I, it I just don't get it. Here's what they're going to be doing. There are ways of taking checksums of pictures and videos, so that if there is a minor change in something that might occur, because it was copied that it does not mess it up.

[00:30:39] It still can give the valid checksum and. Iman, that technology is detailed, but basically just think of it as a checksum. So if you have a credit card number, there is a checksum digit on that bank accounts have checked some digits so that if you mess it up a little bit, okay, it's an invalid checksum, so that number's obviously wrong in this case.

[00:31:03] What we're talking about is a checksum of a pitcher or oven. And these various child safety organizations have pictures of children who are abused or who are being abused, who are being exploited. And they have these checksums, which are also called hashes. That is now going to be stored on your iOS device.

[00:31:33] And yes, it's going to take some space on the device. I don't think it's going to take an enormous amount of space considering how much space is on most of our iPhones and iPads that are out there. Apple gave this detection system is called C Sam, a real thorough technical summary. It is available online, and I've got a, to this article in this week's newsletter, but they released this in just this month, August of 2021.

[00:32:06] And they're saying that they're using a threshold that is. Quote set to provide an extremely high level of accuracy and ensures the less than one in 1 trillion chance per year of incorrectly flagging a given account. Now I can say with some certainty in having had a basic look through some of the CSM detection documentation, that they're probably right about that, that the odds are very good.

[00:32:39] Small that someone that might have a picture of their kids in a bathtub, the odds are like almost so close to zero. It is zero that it will be flagged as some sort of child abuse, because it's not looking at the content of the picture. It's not saying that this picture, maybe it is a picture of child exploitation or a video of her child being exploited.

[00:33:01] If it is not one that has been seen before by the national center for missing exploited. It will not be flagged. So I don't want you guys to get worried that a picture at the beach of your little boy running around and just boxer trunks, but a lot of skin showing is going to get flagged. It's not going to happen.

[00:33:24] However, a pitcher that is known to this national center for missing and exploited children is in fact going to be flagged and your account will be flagged. Now it's hard to say exactly what they're going to do. I haven't seen anything about it, of the apples. Only say. That that they're going to deploy software.

[00:33:50] That's going to analyze images in the messages application for new system that will warn children and their parents from receiving or sending sexually explicit photos. So that's different. And that is where again, a child, you put parental settings on their iPhone. If they're taking these. Pictures, selfies, et cetera.

[00:34:13] Girls sending it to a boyfriend, sending it to his girlfriend, whatever it might be. The parents are going to be warned, as are the children that is looking for things that might be of a sexual content. Okay. It really is. It's really concerning. Now let's move on to the part that I'm concerned about, because I think everyone can agree that both of those features are something good that are ultimately going to be very good, but here's a quote.

[00:34:40] Apple is replacing it's industry standard end to end encrypted messaging system with an infrastructure for surveillance and censorship. Now, this is a guy who's co-director for the center for democracy and technology security and surveillance product project, I should say. He's Greg, no, him, no Chaim, is saying this, and he said apple should abandon these changes and restore its users, faith in the security and integrity of their data on apple devices and services.

[00:35:14] And this is from an article over an tech. So this is now where we're getting. Because what are they doing? How far are they going? Are they going to break the end encryption in something like I messages? I don't think they are going to break it there. They're not setting up necessarily an infrastructure for surveillance and censorship, but apple has been called on as has every other manufacturer of software.

[00:35:44] I remember during the Clinton administration, this whole thing with eclipse. Where the federal government was going to require anyone that had any sort of security to use this chip that was developed by the federal government. And it turns out, of course, the NSA had an very big backdoor in it, and it was a real problem.

[00:36:04] Look at the Jupiter. That was another encryption chip and it was being used by Saddam Hussein and his family in order to communicate. And it turns out yeah, there's a back door there too. This was a British project and chip that was being used. So with apple, having resisted pressure. To break into phones by the US government.

[00:36:27] But some of these other governments worldwide that have been very nasty, who've been spying on their citizens who torture people who don't do what apple are not happy, what the government wants them to do have been trying to pressure Apple into revealing this. Now I have to say, I have been very disappointed in all of these major companies, including apple, when it comes to China, they're just drooling at the opportunity to be there.

[00:36:56] Apple does sell stuff there. All of these companies do. Yeah, Google move their artificial intelligence lab to China, which just, I cannot believe they would do something like that. AI machine learning, those or technologies that are going to give the United States a real leg up technology wise to our competitors worldwide.

[00:37:17] And they move to China, but they have complied with this great firewall of China thing where the Chinese people are being censored. They're being monitored. What's going to happen now because they've had pressure from these governments worldwide to install back doors in the encryption systems.

[00:37:38] And apple said, no, we can't do that because that's going to undermine the security for all users, which is absolutely true. If there is a door with a lock, eventually that lock will get picked. And in this case, if there's a key, if there's a backdoor of some sort, the bad guys are going to fight. Now Apple has been praised by security experts for saying, Hey, listen, we don't want to undermine security for everybody, but this plan to do ploy, some software that uses the capabilities of your iPhone to scan.

[00:38:15] Your pictures, your photos, things that videos that you're sharing with other people and sharing selected results with the authorities. Apple is really close to coming across that line to going across it. Apple is dangerously close to acting as a tool for government surveillance. And that's what John Hopkins university cryptography professor Matthew Greene said on.

[00:38:46] This is really a key ingredient to adding surveillance, to encrypted messages. This is again, according to our professor over John Hopkins, green professor green, he's saying that would be a key in Greece and then adding surveillance, encrypted messaging, the ability to add scanning systems like this to end encrypted messaging systems has been a major ask by law enforcement, the world.

[00:39:14] So they have it for detecting stuff about missing and exploited children. That's totally wonderful. And I'm fine with that. No problem. But that now means that Apple's platform has the ability to add other types of scanning. All right. We'll see what ends up happening these the next thing, which is warning children and their parents about sexually explicit photos is also a bit of a problem here.

[00:39:46] Apples. Yeah on this is messages uses on-device machine learning to analyze image attachments, and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages it's saying, if it detects it, they're going to blur the photo. The child will be warned, presented with helpful resources and reassured it is okay if they do not want to view them.

[00:40:16] And the system will let parents get a message. If children do view a flagged photo and similar protections are available for child attempts to send sexually explicit photos. Interesting. Isn't it. Interesting world. So I think what they're doing now is, okay, they're really close to that line, going over.

[00:40:38] It could mean the loss of lives in many countries that really totally abuse their citizens or subjects, depending on how they look at them. Hey, make sure you check me out online. Craig peterson.com. Hey, sorry about having to talk about this, but man, this isn't.

[00:40:57] It's time for a little bit of good news. We now have satellite internet performance. That's pretty much on par with fixed broadband, and it isn't just in the us. We're going to talk about that right now. What are the options?

[00:41:13] You might remember the whole Sputnik thing and what happened there really drove the space race forward very rapidly, but we're using much fancier satellites than Sputnik, which of course, all it was doing was sending out a beep.

[00:41:30] It was alive. And I remember I went over to a friend's house. I have an advanced class amateur radio license, and I went over to a friend's house, and he had some satellite equipment. He was also a ham, and we were able to tune his satellite in his satellite dish into a couple of the satellites up there.

[00:41:52] Now the amateur radio community has one or more satellites. I'm not sure. We were really impressed with all of the stuff that's up there in the sky. There are satellites, of course, that we don't even know what they're doing because they're top-secret government satellites. And they're probably a decade ahead of the rest of the industry.

[00:42:15] But he was pulling down images from some of these satellites that were open-source of what's happening on the earth and just all kinds of things back before heavy encryption. It was very cool to think that these satellites were miles up in space. No, I'm looking@somestatisticsherefromspeedtest.net.

[00:42:37] I don't know if you've ever tried it. You should try and go to speed. Test one word.net on your web browser. And it'll open up a little window. It's a company called Uber. And that window will allow you to start a test. And the first thing it does is it tries to find, okay, where are you located? And who has the closest reflector that we can use for speed testing?

[00:43:02] Usually there's something not too far away from you. If you are out in the Netherlands and of course, many of you listening, kind of our Netherlands, when it comes to internet access, you have pretty slow internet and speed test dot nettle. I'll put there's three numbers, you, or maybe four, you really have to pay attention to.

[00:43:25] You've got the download number and that's telling you how fast the data comes down to your browser from that particular spot, which is typically, as I said, close to you, although nowadays something that's far away on the internet, isn't going to be that much. So download matters and then probably what matters the most for most people.

[00:43:48] The next thing to look at is upload most of the time. If you have a regular consumer internet link, your upload speed is about 10, maybe as much as 20% of your download speed. So if you're getting megabit down, It's going to be 10% of that megabit down, maybe as much as 20%. So you're going to get about a hundred K up versus the megabit down it again, it varies.

[00:44:21] A lot of places will have 50 megabits down and 10 megabits up so it can vary. Now the up speed, the uplink speed is what's going to affect you when you are trying to upload a file. So maybe you're trying to upload something to work, or you are trying to stream a video cause you're trying to run a webinar.

[00:44:45] That's what that is. The next number that you have to pay attention to is the round trip time. So that's the time it takes from a packet to get from your computer to the server that you're connected to. And then back again. Usually that's measured in milliseconds. And I remember the very first time I was using the ethernet, it was thick wire, ethernet, and 10 megabits.

[00:45:16] And wow. I was just so fast and very expensive to use. And the delay pinging another machine. In other words, sending a packet from my machine to another machine on the network. And then having that packet returned to me was anywhere from if it was like lightning fast, 10 milliseconds, and more likely it was 30, 40, 50, even a hundred milliseconds on the same day.

[00:45:44] Nowadays, if you're looking@yournumbersonspeedtest.net, you are probably seen speeds that just blow away what I was using back then because things have just gotten so much faster. You've probably seen a few milliseconds in speed round trip, speed time again, depending on how good your link is. And then the fourth one you have to pay attention to is.

[00:46:11] And jitter is where you are seeing inconsistent speeds in those round trip times. And that's going to affect live stuff, particularly live audio, which we'll notice a lot to that. Hey, the audio is just terrible. It's dropping out at me. Maybe sounds digitized. Usually. Parts dropout gamers care a lot about the jitter because that's going to affect their game and how they play their game.

[00:46:42] So I just ran it here on my studio computer. Now we have fiber optics. We have a business line that goes directly to Comcast backbone and I'm seeing. From where I am to a server that's about 90 miles away, I would say my ping time round trip is three milliseconds. It's just, I'm still blown away by that.

[00:47:08] Cause I remember using dial up modems that were 110 bits per second, 110. And that was just absolutely amazing. And then 300, can you believers? 300 bod and it's changed a lot, right? So three milliseconds round trip time for me. And I'm trying to brag or make you feel bad. I'm just telling you what it can be.

[00:47:30] My download speed is 720. Megabits per second. And that's because right now we're downloading a few different things and my upload speed is a gigabit per second. So you can see in a commercial link, typically your download and your upload speeds are the same. It is not, it is in 10% obviously is exactly the same.

[00:47:54] So those are the numbers you should look at. I don't see on my results. The jitter, maybe there's not reporting that anymore, or maybe they only reported on bad lines. I'm not sure, but again, speed test.net. So they have released this guys@speedtest.net, some stats on the satellite companies, because our friends over at startling, that's Elon Musk's company think Tesla and SpaceX, they are showing.

[00:48:28] Amazing download speeds. They're showing 97 megabits a second download. Now that doesn't of course, I really approach the gigabit that I'm seeing, but this is from a satellite. It's just amazing. And they're going to see if more now all fixed all speeds of everyone. One in the United States that has gone to speed test.net and ran speed tests.

[00:48:56] All speeds averaged out in the United States come to 115 megabits. So Starlink is almost as fast as the average broadband connection in the United States. Now here's a little, here's where they really shine to upload speed of about 14 megabits a second. So that's not bad that still fits within our model that we talked about latency.

[00:49:24] 45 milliseconds. Now compare that with what I had, which was what three milliseconds it's slow, but it's again, remember it's a satellite. So it's going from the earth station while it's actually going from your computer to their satellite dish at your location is going up to the satellite is coming back down to an earth station is picking up the signals from the satellite, and then it's going to the server.

[00:49:53] So 45 milliseconds is pretty good. I want to put that in perspective, though. The two biggest competitors right now, satellite internet are Hughes net and ViaSat Hughes net. This is again, according to speed, test.net. Download speed is averaging a little less than 20 megabits a second. So it's 20% of the speed of startling.

[00:50:20] Yeah, pretty bad. A and star links latency. Remember, and this matters a lot. If you're trying to do live video or you're trying to run your phone over it, latency is 724 milliseconds. So that's three quarters of a second. From the time a packet goes out until it comes back. So that will affect any sort of phone calls that you're making on HughesNet and then ViaSat none, much better download speed of 18 megabits a second, which is worse, but the upload is slightly better than HughesNet and their latency is slightly.

[00:50:56] What I'm saying is Starlink is really starting to shine. And Elon Musk is saying they are going to be even better. They're going to be much better. Give them a little bit of time. The reason that Charlene has the faster latency. Much, much faster latency than our friends at HughesNet or ViaSat is that they have low earth orbit satellite.

[00:51:23] So they are sitting up there. They do have some drag from our atmosphere, so they will come down. There's things in place to take care of all of that sort of stuff. But Starlink it's going to be available pretty much everywhere. The country. India is very excited about this because they've had real problems with the internet in some of the rural areas.

[00:51:48] But Hey, if you are out in the middle of nowhere in the United States, there is hope check out, Starlink online, lots of great stuff. Hey, stick around. We will be right back. You're listening to Craig Peterson.

[00:52:05] The hackers are still going after with ransomware, they're still doing just blanket attacks. They're still doing massive fishing, but they have glommed on to something that is being much more effective. That's what we're going to be talking about.

[00:52:21] This is a huge problem. We have seen some very high profile ransomware lately. Think of what happened with colonial pipeline, the whole solar winds attack, and much more the bad guys are trying to figure out a way to more inexpensive. Ransom money from us to more inexpensively, get all of our confidential information.

[00:52:48] I have a client that before he was my client, all of his data was stolen and they run right to the Chinese. I have another client who's operating account was completely emptied. And the problem in both of these cases, Was really the client not doing what they should be doing, but supply chain problems, supply chains, the software, you have the hardware you have that you're relying on it.

[00:53:19] One of the major types of businesses that are being attacked right now are our managed security services, company, security researchers who are trying to do, with all the effort they can maybe keep ourselves safe. But they're not doing what they should be doing. You've heard me complain for many years about programmers.

[00:53:43] I'm saying that in air quotes, people who have learned how to do Microsoft C sharp or visual basic, whatever it might be. At a very high level in share. Yeah, they can put stuff together. It reminds me of when the spreadsheets first started hitting the boardrooms, all of a sudden, business people, managers all the way on up through the board were saying I don't need the it department anymore.

[00:54:09] In order to get these numbers, I can just gather them in myself and put together a spreadsheet. I'll be safe. Everything will be great. I'm going to get that information now instead of having to wait for it, to get some programmers involved and get it done. The problem in all of these cases is exactly this.

[00:54:29] These are non-professionals that are trying to do the job. Those spreadsheets, many of them had bad data on them. They compiled into even worse data because there were in many cases. Problems with the spreadsheet. I remember when I was a professor at Pepperdine University and I was teaching management information systems out there in the west coast and beautiful campus, by the way, if you've never been there out at Pepperdine, right on the coast.

[00:54:59] But when I was working with those students, who were, it was his MIS 4 22 last year undergraduate. I ended up emphasizing spreadsheet. Because I realized most of them didn't really know how to do it. Yeah. Okay. They could go ahead and put a little thing in there that says, add up all of these columns and this row and multiply by that and cut out.

[00:55:25] I've got a number coming out, but is that number correct? It's like a county. And that's why accountants use double entries in the accounting systems to make sure everything zeroes out. Make sure everything is correct. And by having someone who's a manager using this spreadsheet, you might get some great information and might get it quickly.

[00:55:46] It might be absolutely correct, but it's very possible that it won't be. And from my experience and programmers are the worst of the worst, because many of them started when they were kids, very bright kids who were working on stuff and hacking it things. That's where the term hacker comes from.

[00:56:05] Hacker wasn't necessarily a bad thing. They certainly. Bad guys. They were just hacking it. The computer's trying to figure out how to program, and if something went wrong, they would hack at the code a little bit more to try and fix it and figure it out. Non-professional they were just hacking that stuff.

[00:56:23] And that's what we called them hackers. And so it was a derogatory term for someone that didn't really know what they were doing, but they were hacking their programming or hacking it. Some other part of it. Versus having people who are actually trained and experienced Microsoft got sued because of how bad windows millennial edition was and windows Vista.

[00:56:49] And they found that the majority of the code had been written by interns, by kids, right out of school without the experience. What does that mean? Why am I really bashing the younger generations? It has to do with the ability to foresee problems and the best way to be able to foresee a problem is to have seen it before, for instance, that you've gotta be careful when you're allocating right.

[00:57:15] And that it's not necessarily going to be cleared properly, or if at all, and that the return points can be changed in programs. That's one of the things that hackers do most nowadays. So if you have software that's written by people that don't realize all of the implications of what they're doing, you could be in trouble.

[00:57:38] I like to use the analogy of a car. Back in the day, many of us are turned a wrench and we tinkered with the older cars. We had a whole lot of fun with them trying to figure out how can I improve this? And we'll do this to the carb and we'll change this and look at this airflow problem, pretty basic stuff.

[00:57:56] But today, what we're dealing with is a car that is a whole bunch of major components. We went to replace an air intake because of a bad sensor in a Ford Crown Vic. And it was one of the last model years. And back in the day, you could pretty easily fix that. You just buy the little sensor and put it in there.

[00:58:20] And you're all set. We had to buy the whole component, which included the air intake, manifold all the way on back to the sensor and everything that was behind it. It was absolutely crazy and cost a lot of money. So think of someone who is trying to build a car today, we might equate this to you by a transmitter.

[00:58:43] You buy an engine, hopefully they fit together. If all right, have you ever tried to match a transmission to an engine and it's not right. Do you have to get a converter or make a converter that goes in the middle, or do you have to drill it out in order to make it Mount properly? All of those sorts of problems.

[00:59:00] And then you've got all of the other components in the vehicle as well that are mix and match. That's what programmers are doing nowadays. Nowadays, a programmer grabs this library that does something. So, for instance, Apple has a library you can use that identifies faces, but you don't know how it works.

[00:59:22] You don't know that transmission, how it works. Is it really going to work for you? It wasn't smart to combine that 600 horsepower engine with a Vega Chevy Vega transmission. For those of you old enough to remember what that is. But it didn't stop you from doing that either. And that's what we're seeing.

[00:59:42] That's what these supply chain attacks are all based on that. So much software is written by people that have not had the experience to think through the potential problems. And Microsoft is to blame for making it really easy for anyone to write a program, just like you could blame VisiCalc back in the day for making it really easy for anyone to make a spread.

[01:00:07] But those spreadsheets weren't accurate. The software that we're getting from our suppliers, which include Microsoft. This latest, huge hack came right through Microsoft exchange. It was a zero day bug. The same types of problems that we've had with some of the other software that's out there. Think about how we got the solar winds attack.

[01:00:31] Think about some of these other ones that we've had that are just absolutely massive. It can kill us and kill us in a very big, when we're talking of course, about all of our systems and software. Hey, I want to remind you guys, just spend a couple of minutes. If you would go online, Craig peterson.com.

[01:00:51] You're going to get the sort of thing. Last weekend. I sent out a video that I chaired with some friends, and I shared it with anybody on my list. Last weekend, it was just part of the newsletter on VPNs, who you can tell. Who you can't trust and the best ways and times to use a VPN. All right. Stick around.

[01:01:12] We'll be right back. You're listening to Craig Peterson online@craigpeterson.com.

[01:01:20] So now, a little bit about what supply chain attacks are. We're going to get into that a little bit more now, what can you do about it? And this European union-funded study that came in the wake of these two major cyber attacks.

[01:01:36] The European Union has now forecasted that there's going to be four times more software supply chain attacks in 2021 than there were in 2010. That, my friend, is a very big deal. These cybercriminals are now shifting to larger cross border targets.

[01:01:59] This is just an amazing report. You can look at it. It's called threat landscape for supply chain attacks. And they looked at 24 supply chain incidents that have occurred between January 20, 20 and July, 2021. The basics here are a supply chain attack is where a software provider or some sort of a trusted provider is hacked.

[01:02:25] Usually they're are hacked in a way that they don't realize they've been hacked and then they pass off. The hacked software to you. I can remember a Microsoft product back when they used to ship them on DVDs or CDs. And we got that thing. One of the first steps was always to scan it for viruses, and we did.

[01:02:48] And sure enough, Microsoft was shipping out software with a virus on it all. The same sorts of things have been happening with thumb drives some of these ones, particularly cheap ones that you buy online often have built right into them. Malware. Now with some of the reason for the malware is legitimately purposeful.

[01:03:12] Okay. What they're trying to do is get you to have their little ransomware work for them so they can make some money off of you. In other cases, you have a thumb drive that a friend gave to you, and you're now using a little thumb drive and guests. Yeah, you are a little thumb drive has some nastiness on it.

[01:03:32] Same, thing's true with Microsoft word documents that might have macro viruses, if you will, that are built into them. These little Trojans do the same thing with the Excel spreadsheets and on. But what they're finding right now is that these hackers are trying to get to the companies that provide services for the bigger companies.

[01:03:55] And that's where it can hurt you and hurt you in a big way. I was just talking about how many programmers just aren't terribly professional. And some of that has to do with their lack of experience and those programmers might be using a library. So, for instance, get hub, which I use, and it's very common to be used out there online.

[01:04:18] It has all kinds of source code called open-source code. So you can use it. You can model. That some of that software has been infected. And then there are people who are using languages that are nice and simple, like Python and others. And you write in this scripting language and pull in libraries that come from public sources that do things for you.

[01:04:41] So they might do something like display something on this screen. They might go out and grab something from a URL online or connect to a database. And what the bad guys have found out is we're not, double-checking all of the sources of all of this software, and that is causing some huge security holes.

[01:05:04] And what ends up happening is companies like solar wind are using some of this soft. And they then might be including it in the software they're providing you now, in the case of solar winds, it's a little bit different, but it's the same concept. Solar wind software was being used by a large number of companies in the U S.

[01:05:29] Agencies were using solar wind software. And so we're regular old, small businesses because what happens is you hire a managed services provider and they don't have time to look at all of your computers all of the time. So they have software that they're using called a Ryan in this particular case. And I'll Ryan is installed on all of your computers.

[01:05:55] So probably unbeknownst to you there's software on your computers. That is not being written by that managed services provider. But in this case was being written and provided by solar winds. Solar winds got hacked and the hackers put into solar wind software. Code that would eventually end up on your computer and your computer getting hacked.

[01:06:18] So you just see how complicated this gets, right? You guys are the best and brightest, but you've probably got your eyes spinning a little bit here because we're talking about multiple layers of like again, direction, right? So these attacks, which mode, it looks like it began maybe in March 20, 20.

[01:06:38] We're only detected in December last year, and they have been linked to this Russian organization called cozy bear, but we'll see what happens. We've got the more recent ones, which is the reveal. Ransomware got gang, this R E V I L reveal. And they exploited vulnerability. In Casias VSA, which again is another management platform that's used by many of these companies out there that are providing managed services.

[01:07:09] Now I've got to say by means of full exposure here. We had to use both of these pieces of software before. And when we looked into them, we found that they. Insecure. In fact, it sounds like some of these companies had been warned by their own employees, that the entire architecture of their software was insecure.

[01:07:33] Okay. So we ditched them all. We're using Cisco's software, they're advanced malware protection. The real high-end firewalls with special software, the backend that's running. So we're not getting into all of these crazy acronyms and names right now. So just so you know, that's what we use. That's what we use for our customers.

[01:07:56] I even have that at my house. Okay. So a little bit more expensive, but it's a lot cheaper than having to hire a whole bunch of it. People to keep track of everything else now, because say. I had gotten, I had this ransomware that was distributed to Casa, his client. And potentially to kiss his clients, and this reveal gang demanded a $70 million ransomware payment say is denied that it paid it.

[01:08:28] They may or may not have paid it. You might remember in the Trump years, they said, absolutely. Don't pay ransoms, or we may come after you because that is illegal to pay a ransom by. Because you are supporting a terrorist organization. So you gotta be careful with stuff like that. Don't pay ransoms, right?

[01:08:48] Because it also tells them that you are a company that pays ransoms. So guess who they're going to come after again, you, because they know you'll pay. So a lot of incidents, I'm looking at a timeline of the attacks that were studied in this report coming out of the European. Yeah. And it is amazing here.

[01:09:06] The unit max beans. That's one of those libraries. I was talking about the able desktop as Sydney. Was Vera excelling on VC or excuse me, VG, solar winds, big knocks, Mon pass Ukraine, SEI, click studios cast private stock investment manager goes on Fujitsu ledger. So this is a huge problem. And this is the sad part.

[01:09:34] European union's predicting. It'll go up four fold this year. So what do you do? You have to audit your vendors. And that usually means you have to have an agreement plays. They accept the responsibility if you are hacked. So keep it up. Yeah. Let me know if you'd like more help with that. You can always email me M e@craigpeterson.com.

[01:09:59] I think I got a couple of those contracts kicking around these vendor contracts. If you'd, I'll send one to, but you have to reach out to me. M E. At Craig peterson.com. All right, stick around. We've got one more segment today, and I want to make sure you spend a couple of minutes online. Craig peterson.com.

[01:10:20] And go ahead and sign up. Sign up for my weekly newsletter.

[01:10:28] We're going to do a little bit of wrap up right now, including talking about I message some of the changes that have come in Apple's messenger application, that many people are saying it shocking, and you should stop using it right now.

[01:10:44] This is an article in Forbes by Zach Dorfman, where he's talking about why you should stop using iMessage after what he's calling the shock iPhone app.

[01:10:58] Has had a number of major problems here recently that have been in the news. Of course they have about half of the smartphones in the country, right there. But things have become a little worse for apple here recently. And what we're worried about is, for instance, this whole Pegasus that we talked about a couple of weeks ago, where it is, what's called a zero-click piece of metal.

[01:11:25] Where they can send you a text message, even if they're not a friend of yours and take over your phone. And we've seen things like that before. In fact, I think it was in Saudi Arabia, where was it? The crown prince received a video from somebody. He played it, and it exploited some vulnerabilities in the video player and allowed them to have full access to his phone.

[01:11:49] And don't remember all of the details, but that part, I do remember. So the big question is, have all of these major security issues being fixed by apple is I messaged say for not, apple is saying it is encrypted end to end. They don't keep messages. There's some question about that because of a major incident back in 2018, where Apple was going to make sure it encrypted all of your backups and then.

[01:12:18] FBI apparently spoke to apple and got them to change their opinion on the whole thing, which is another interesting problem. Isn't it. So what do you do, what do you do with that? And what do you do? Very good question. Earlier this year we had WhatsApp make a major change. They had course also said we've got end to end encryption with WhatsApp or wonderful.

[01:12:41] And then people really questioned it because it was now owned by our friends over at Facebook. Is there privacy thereon WhatsApp? Is it legitimate? Is it just a bad PR move? What's going on WhatsApp, by the way, with 2 billion users worldwide and WhatsApp Facebook said, Hey, listen, we're gonna start giving you ads.

[01:13:05] And basically people were worried about them examining the content of their messages in order to give them targeted ads, et cetera. So now apples just confirmed what Forbes is calling the most shocking and controversial update in the platforms. History. And here's what's going on. Pegasus, of course, as I mentioned, this click attack, Apple's got his new update now, right?

[01:13:32] That is using machine learning. In order to see if a minor child might be sending a picture pornographic or otherwise they should not be sending or receiving. And we also have built into it. Now, this child sexual abuse. Check some set of people. That looks on your devices to see, do you have any photos that match, just check some part of the problem with this isn't that I'm not worried about these children that are being exploited.

[01:14:06] Cause I am, I'm absolutely against that. But the bigger question here is, okay, so what's next is apple going to capitulate to the government and let them know if you have a certain picture of something rather the government doesn't like, where is this going to end? So in other words, Apple's phones being a lockbox.

[01:14:30] The Apple iPad is being a lockbox is really. No longer going to be true. It is no longer going to be that encrypted lockbox that has been promised to us the electronic frontier foundation. As a little comment here, they say Apple's compromise on end to end encryption may appease government agencies in the U S and abroad, but it is a shocking about phase four users who have relied on the company's leadership in privacy.

[01:15:00] And security, which is absolutely true. Now there's not much controversy, frankly, about limiting the spread of child sexual abuse material, but where we go on from there, that's where it starts getting a little more questioning here. Here's a, this is a Jake Moore over at east set. You said the initial.

[01:15:21] Potential concern is that this new technology could drive CSM further underground. See Sam being this child abuse material, but at least it is likely to catch those at the early stages of their offending. The secondary concern, however, is that it highlights the power in which apple holds with the ability to read what is on devices and match any images to those known on a database.

[01:15:47] This intrusion is grown with intensity and often packaged in a way that is for the greater good, right? Isn't that always the case. So we're doing it for the children. I talked about this extensively earlier. You can find it in my podcast, go to Craig peterson.com/podcast. Right now you can listen to it there.

[01:16:08] Take a look in your emails from the newsletter. Pretty good about trying to send those out the last few weeks. I haven't been that great because of issues here, family issues and others. So it's been a little tough. So I apologize for that, but we all want to see technology develop. That's going to help tackle abuse.

[01:16:27] It's going to stop the real bad guys that are out there. But what happens when China says we want access to this? We want to know when there's any pictures of a weaker symbol, for instance, or something else. What's Apple going to do they get, they can no longer say, oh, that's not taught. We don't have that technology.

[01:16:45] There's nothing we can do. Just like Apple has done with the iPhones in the past, saying we don't have a back door. There is no backdoor key. We can't crack into that. That doesn't stand up when they say, okay, China comes to them or Iran or Saudi Arabia, or you name the country and says, Hey, we don't want people to see these particular messages.

[01:17:08] Absolutely amazing. So timing on this dreadful. Okay. Part of iOS 15, apparently Pegasus raised two serious concerns that Apple's ecosystem, including I message has still got some dangerous vulnerabilities and that Apple's opaque communications in the kind of a black box security really were an unhealthy man.

[01:17:32] Now Apple has in the last few months, opened up that black box, a bit to security researchers, but it's still not that open. Now we add a third, which is what happens on your iPhone. No longer stays on your iPhone. Now I get asked by a lot of people. What should I do? Where should I go? What's a safe place. I still say Apple's your best bet in general, but the next problem is so what's next after that?

[01:18:02] I can still say Android sure is not the platform you want to use. The guidance. Google has snuck stuff in time and time. Again, even going so far as to sneak a microphone. Into the nest thermostats without telling a soul and without it being on any of the datasheets. So Google's definitely not to be trusted.

[01:18:24] There are other distributions for certain phones that are based on various types of Unix. They may be good. That may not be good. One of the companies I really liked a few years ago, discontinued it's secure and it was based on Android, but they were cleaning it up a little bit. So we'll see. These attacks that came against apple to give them some credit.

[01:18:47] They were very sophisticated. They cost millions of dollars to develop. They didn't last long because apple released patches. Once I found out what had happened, and they're typically used to target an individual, think of that journalist. Who went to the Saudi embassy. I'm trying to remember his name.

[01:19:07] Cause saggy, I think was his name, but this is a real problem. Okay. We think by the way that it was fixed in 1471, but these new security child abuse things are being added in the next release. So I'm keeping an eye out. I'll keep an eye on all of this. So keep listening and not I'll let you know how things go.

[01:19:31] Apple is likely done veil the next generation I phones in September. So we've got trend force out there, outlining what it expects for the next iPhone. Now I have an iPhone. And it is about to go out of support. As soon as this new phone comes out, my eight is going to be too old to get support, but it's going to be called the iPhone 13, which is going to be formally announced by apple.

[01:19:59] So the exterior design, I'm looking at a picture of it right now. That little notch is smaller than before. They're also using some smaller silicone smaller chips inside so they can put an even bigger battery. These new iPhones are going to have support for 5g millimeter wave. And that's going to be available for sale in more countries after the release of the iPhone 13, because it's covering more bands, which is a really good thing.

[01:20:30] The circuit boards are moving from the stuff that we've seen for decades. These rigid printed circuit boards to new design that has a flex. Printed circuit board, which is quite nice because if you've ever been to phone before, you know how painful that can end up being, and they're saying this should have the increased battery because of it.

[01:20:53] There's some more stuff that should be in that phone that I've read a few articles about new features that'll be in there. China, by the way, is decreasing in its purchases of iPhone. The revenue went from 19% in 2017, down to 16 in 2020 coming from China, but they still are big players, 16.7% of global smartphone marketplace.

[01:21:20] They're also expecting by the way that these new iPhones are going to have the new processor in them as well, the a 15, and also there's going to be brand new. Mac book's coming out too. That should have some neat stuff in them. By the way, the number one app this last year was Tik TOK. It surged from fourth place to first place, knocking Facebook out of the top spot.

[01:21:48] But the top five is made up of the main Facebook apps. Yeah. WhatsApp, Instagram, and messenger. And then of course would tick talk at the top. And then the next two places go to Snapchat and telegram with another short video app from China in eighth spot. So Pinterest and Twitter, by the way. The top 10.

[01:22:10] Hey everybody. Thanks for being with me today. Make sure you keep up on it. No, the latest you can help your friends. You can help your family. You guys are the best and brightest. You guys are the guys that people rely on for technology. I know it because you tell them. Any questions, comments, just email me M e@craigpeterson.com and visit the website.

[01:22:34] Listen to the podcast and please subscribe. Take care everybody. Bye-bye.

View Details

Are You One of More Than 700,000 On U.S. "Watch-Lists"?

Craig Peterson: You've heard about the no-fly list, right? Yeah. How about the terrorist and other watch lists? It's impossible to get your name off, even when there was no reason to be there in the first place?

Well, I got some news.

The Department of Homeland security has been criticized for many things over the years. One of the things that they have been criticized quite a bit about is this watch list that they maintain. They have a watch list for no-fly. People get put on that watch list. It was initially intended to be, we know this guy's a terrorist, so we're going to put them on, right.

[00:00:45] It's not always the way it goes. It starts out almost innocuous, and before you know it, there are all kinds of people getting caught in this big, big net.

[00:00:55] That's what's been happening lately. But, unfortunately, it's going to worsen because the Department of Homeland security has decided to hire regular old companies to help develop this no-fly list and this terrorist watch list.

[00:01:14]Apparently, these companies will be looking through all kinds of public data, maybe some private data, social media to provide information for this new domestic terror watch list.

[00:01:28] So you look at that and say, okay, I can see that.

[00:01:32] We've talked before the problem, man, 20 years ago. I think I was talking about these data aggregators and the issues they create. They're taking public records; they're putting them all together. They're figuring out how it all meshes together, and they come up with a pretty accurate picture of who you are.

[00:01:53] Now, I've got to say when I've had them on my show here before, I was talking to them and said, okay, I want to look up my own records. So I looked them up on their platforms. I did not see a single one that was more than about 30% correct about me.

This was again, some years ago. I think it's probably been almost a decade since I last spoke with the data aggregators. They really are trying to blend into the background,

[00:02:21] Nowadays, this data that's put together by these artificial intelligence systems is not necessarily that accurate, and that gets to be a real problem.

[00:02:33] So who is DHS gonna hire? Well, from the description reported here by the Conservative Tree House, it is going to be big tech, specifically, Google, Facebook, YouTube, Instagram, Snapchat, Twitter, and more.

[00:02:54] The DHS will put them under contracts to hire and organize internal monitoring teams to assist the government by sending information on citizens they deem dangerous. Again, what could go wrong?

[00:03:10] Our government is not allowed to spy on us. How many times have we talked about this? You have, of course, the five eyes, and then they added more and more. These are governments that spy on each other's citizens for each other.

[00:03:26] So, for instance, the US cannot spy on US citizens. So we have an arrangement with the United Kingdom, New Zealand, Australia, Canada to spy on the US citizens for us that makes sense to you.

[00:03:44] Can you believe that?

[00:03:46]We spy on their citizens for them, and they spy on our citizens for us. All is good.

[00:03:57]What's happening here is The Department of Homeland security realizes it cannot spy on us directly. This is what they've been doing for a very long time, they go to the data aggregators, and they pull up the data that they want.

[00:04:12]They want to see if this guy is maybe selling illicit drugs, and they pull up public records.

[00:04:19]What cars does he have? How many homes do they own? Who's he dating? Has she all of a sudden been buying diamonds and mink coats? What's going on here?

[00:04:31]Now we're seeing that the US intelligence apparatus. It's really going live quickly to put together lists of Americans who could be potential threats to the government and need to be watched.

[00:04:49] Now it's all well and good. It's just like president Biden this week saying, Oh, we're going to have these red flag laws. We're going to stop the sale of certain types of firearms and things. It all sounds good.

[00:05:04] The reality is we have known about some of these people before, right? So this is all just a red herring that the federal government is doing right now because the real problem is these terrorists, the domestic and otherwise that have shot up schools, have almost always been reported to law enforcement as dangerous people. Some have even been on lists that say they cannot buy firearms, yet they get guns. Bad guys.

[00:05:39] It's like here in the US. Where does our fentanyl come from? We're not making a domestically. Our fentanyl is coming from China often through Mexico. It is killing people here in the US.

[00:05:54]The whole George Floyd incident, and what's happening with fentanyl in his system, right. The question is, did the police operate properly? What killed him? According to the coroner's report? It was the fentanyl that killed him.

[00:06:09]One way or the other that fentanyl got here from China and is being used on the streets, and people are dying from it. Fentanyl's illegal. How could they possibly get it?

[00:06:24] It's illegal for a felon to be in possession of a firearm. So how did a criminal get the gun?

[00:06:32] The police were warned about people in San Bernardino, California. They were warned. The people in that business told the police. We were calling. We're apprehensive about this guy, and nothing happened.

[00:06:48] So now what are we going to do? We're going to cast an even wider net. We cannot take care of the reports that come in right now. We're going to get even more reports, and they're going to be coming from these AI systems. Again, what could possibly go wrong here? It's absolutely incredible.

[00:07:12]They look at these reports. They try and determine these are actionable, the FBI or other law enforcement agencies. They've been deciding no, it's not actionable. They've been right sometimes, and they've been wrong other times. This is a real problem.

[00:07:29]What shocked me is NBC news with Andrea Mitchell, NBC news. Not a centrist news organization, very far left. NBC News is even reporting on this. They realize the consequences. Here's a quote from NBC. "DHS planning to expand relationships with companies that scour public data for intelligent and to better harness the vast trove of data it already collects on Americans." "The department is also contemplating changes to its terrorist. Watch listing process." Absolutely amazing.

[00:08:16] Two senior Biden administrative administration officials told NBC News that Homeland security whose intelligence division did not publish a warning of potential violence before the January sixth Capitol riots are seeking to improve its ability to collect and analyze data about domestic terrorism, including the sorts of public social media posts that threatened a potential attack on the Capitol."

[00:08:44] "DHS is expanding its relationships with other companies that scour public data for intelligence. One of the senior officials said, and also to better harness the vast trove of data it already collects on Americans, including travel and commercial data through customs and border protection, immigration, customs enforcement, the coast guard, secret service, and other DHS components". There you go from NBC news.

[00:09:11] So remind yourself what the FBI contractors with access to the NSA database already did in their quest for political opposition, research, and surveillance, and then get everything we were just talking about.

[00:09:28]The director of national intelligence declassified a FISA judge's ruling. This is judge James Boasberg, 2018 ruling, where the FBI conducted tens of thousands of unauthorized NSA database queries. Do you remember that story? Very, very big deal. This judge is obviously passing these things out like candy and the FBI misusing its power and authority. Again, what could possibly go wrong?

[00:10:00]By the way, President Obama apparently has been telling us that we should use the no-fly list to keep people from owning guns.

[00:10:08]There's already a database maintained by the FBI. So this whole thing is, as I said, a red herring. Things are going to get really bad if law enforcement does this. Frankly, they're going to do it. There are no two ways about it.

[00:10:25]We have to be more careful about keeping our information, our data private.

[00:10:32] That's what my whole course: "Improving Your Windows Privacy and Security," is all about. Locking it down because the way Microsoft ships windows and how it installs and configures itself by default does not keep your data private. That's a problem. So that's what we're going through.

[00:10:54]Remind yourself of this and just keep chanting, "nothing bad could happen here," right? Ah, the joys of all of these computers and databases and the way they work nowadays.

[00:11:07] By the way, if your information is out there at all, even if you use fake names and numbers and addresses and things like I do when it's not required. Right.

[00:11:20] I don't lie to the bank. I don't lie to the IRS. Nobody else needs to know the truth. Even if you have been, trying to keep it private. Good chance that they know who you are and where you are. Crazy. Crazy.

[00:11:36] Hey, visit me online. Craig peterson.com. Make sure you subscribe to my weekly newsletter.

View Details

Have Your Healthcare Records Have Been Stolen? What can you do about it?

Craig Peterson: We're talking about ransomware and what's the Conti gang and others doing nowadays.

Hello everybody. Craig Peterson here. Thanks for joining us today. I appreciate you spending a little bit of time, and I enjoy helping bring you guys up to speed on what is happening. There's just so much of it. You wouldn't believe what I have to filter out.

[00:00:23] The Conti gang has been very successful. Still, their money started to dry up recently when people figured out if they had a decent backup, they could just go ahead and ignore the ransom demand. So instead of paying that ransom, just go ahead and restore from backup. So they had to do something different.

[00:00:47]What the Conti gang did, as well as pretty much everybody else in the ransomware business, is okay; what we're going to do now is we're going to find all of the other machines we can find on the network. Then we're even going to have real people get onto these computers remotely that they've compromised and had a poke about. See if there is patient healthcare information? Are the bank account numbers on this machine? Are there plans on what to do? Where to go? What's the business going to do next week?

[00:01:25] But mainly stuff they can sell right away. If you take credit cards, you know that the payment card industry is all over you if credit card numbers are stolen. Those are nowhere near as valuable as patient health record information. As I mentioned a little bit earlier, we're talking about 2000% more than 20 times more value to your healthcare records.

[00:01:55]Now what happens is Conti gang says, "Oh, looky. We've got patient information here. It has names, addresses, social security numbers. It has birth dates. It has diagnostic information," and then they upload it.

[00:02:11]We had something like this happened with one of our clients. It wasn't a ransomware attack; ultimately, it may have been. They came in through an unsecured VPN and that they would not let us shut down.

[00:02:25]We told them to shut it down, and they didn't. In come the bad guys, they actually were coming up via Mexico in this case. Although I doubt they were located in Mexico.

They took that VPN connection; they used it to get on to the computer and found something interesting. So they started to exfiltrate the data. In other words, Take that data and send it out.

[00:02:52] That's precisely what the Conti gang and others are doing now.

[00:02:55]We noticed, wait a minute, this is all automatic. Why is data going out from this host at that speed to this address at this time of day? It wasn't a typical pattern. So our hardware-software that's sitting there in their network automatically shut it down hard.

[00:03:19]They were able to exfiltrate just a tad bit of data, and then it was stopped instantly.

[00:03:26] The Conti gang gets your data, and then they try and say pay up from an extortion standpoint. Instead of just holding your data ransom, they're extorting you. Saying, if you do not pay us, we will release this data.

[00:03:45]The Conti ransomware gang has its own website out there. It's called a leak site. There are many of them out there.

[00:03:53]I'm not going to give you the URL; it's right there. There's their logo. Conti gang has a logo, and it says Conti news. It's talking about how you can make your payments to them and what data was released and that this person paid up, but it was too late. We don't have the data anymore, which means it was released and too bad. So sad.

[00:04:18] I wouldn't want to be you.

[00:04:19] Here's another ransomware gang, the Avedon ransomware gang. So again, they had stolen personal information. They had health information, and they had the ransom side and the extortion side built into it. This was about an attack on the Capitol medical center in Olympia, Washington.

[00:04:42]They have leaked some of it they're threatening to reveal even more. If Washington Olympia capital medical center doesn't pay up.

[00:04:52] First of all, ransomware results in data exfiltration 70% of the time now. In other words, 70% of the time, your data is stolen before the file encryption.

Pretty bad. Pretty bad.

[00:05:08]Things can get particularly harmful because these ransomware attacks are a growing concern. They're disrupting patient care and healthcare, right?

[00:05:17] Disabling critical systems because they have been even holding ransom some of the diagnostic equipment.

[00:05:25] MRI machines that were connected to the network were running Windows. So who would use Windows in the machine that's healthcare critical?

[00:05:36] Obviously interrupt revenue flow, and they had to now go get involved with real expensive remedies. So it really puts him in a horrible spot, very bad.

[00:05:47]We've had almost double the number of healthcare institutions attacked this year versus last year.

[00:05:53] I'm not going to go through all of these things here. I explained the difference between some of these real sites and fake sites and how you can get access to it.

[00:06:04]By the way, if you're interested, I did record this. I'd be glad to send it out to just let me know; just email me@craigpeterson.com, and I can send you some of this healthcare stuff, the slide deck, or whatever you might like.

[00:06:16]Phishing campaigns, way up. You probably heard about that. I gave some examples of that emailing patient information without encrypting it.

[00:06:25] Wireless infusion pumps that are, of course, compromised because they're running an operating system that hasn't been patched. Usually Windows. Think of that there are Windows in that infusion pump, but it could be a version of Linux. It's not fixed. It's crazy. Vital sign equipment. Oh my gosh.

[00:06:46]We're also seeing that this patient health information being stolen now is being used to create fake insurance claims.

[00:06:55]I was talking about how much this is worth, and it's worth a lot while this is one of the reasons it's worth a lot, your personal, private patient health information.

[00:07:08] If you have a diagnosis and that diagnosis has been stolen, and then they can file a health insurance claim. Yeah. You see where I'm going with your information, as though you received some treatment or some care for the diagnosis in your healthcare records. It's just that simple.

[00:07:33] Average cost of a data breach right now, by the way, if you are a regular business, it's $158 per record for non-healthcare, and it's $408 per record.

[00:07:47] If you are in healthcare at all. That's a doctor's office. That's not just hospitals; it's anybody. And by the way, mobile breaches are massive 43% of healthcare organizations who reported a mobile breach said the mobile breach caused long lasting repercussions.

[00:08:09] Now, think about this. If you're a patient. How well are your records protected? I can tell you based on what I've seen and talked with healthcare people, seeing statistics. They're not protected very well at all.

[00:08:25]People will start going to jail over this. People in the healthcare industry, that is.

View Details

Have Your Healthcare Records Have Been Stolen, too?

Craig Peterson: We all have healthcare records, and they have some of our most personal information. That's what we're talking about today in follow-up to a webinar I did for the healthcare industry. So we're going to chat right now a little bit more about your privacy.

Craig Peterson here.

The actual hard stats on our healthcare records, a lot of them have been stolen. It's just crazy to think about because, in reality, we have had millions of records stolen, 300 million healthcare records stolen to be exact since 2015; that is pretty bad.

[00:00:38] I'm looking at a chart right now that I showed to this healthcare industry group that is showing that the hacking event has almost doubled over the last three years, year to year, every year. So in 2018, 164 powerful hacks 2019, 312. That's a good double. 2020, 430, which isn't quite a double. So we are seeing a lot of data being stolen. But, of course, stolen data means misused data, which is a huge problem.

[00:01:14] Now, in the healthcare industry, they've got a different problem. That is these HIPAA rules. Now HIPAA has been in place for quite a while. It's supposed to have been provided Portability of our records. Does anybody have any real luck with that? I know there are some I haven't.

[00:01:30] Portability, I don't even know where my health records have ended up. Frankly, cause my doctor ended up closing up shop, and I just have no idea. But it's supposed to be Portability and privacy. Well, the most common violations of these HIPAA regulations revolve around professional hackers.

[00:01:50] Then you've got business associate disclosure. Remember I mentioned that. The cloud is not an excuse for not protecting your data. You cannot hand that off to a third party. There are many more that I go into in the presentation.

[00:02:05]Then here's the next thing I wanted to talk with you guys about that is the amount of ransomware out there. I'm going to have a little bit of a ransomware offering.

[00:02:15]If you're not a subscriber right now, go to craig peterson.com/subscribe. You'll actually see it on the site @craigpeterson.com. If you scroll around, do a few things on the site, it should pop up automatically for you.

[00:02:31]Now we're just talking about healthcare, and of course, this is every business and every person out there.

[00:02:37] I talked about this Conti gang. I don't know if you've heard of them. C ON T I.

[00:02:42] Now, remember what I've said before about ransomware. It used to be that you'd get ransomware. Your computer would now have its data encrypted. Then it would pop up this big red screen up that said you've got ransomware to get to all of your data back because what the ransomware did was encrypt it. You need to go to this website. You need to pay this amount of Bitcoin to this Bitcoin wallet, and off it goes, right? That's the idea.

[00:03:13]According to the FBI, you'll get all your data back half the time. That's even if you pay the ransom. Now, too, the state department and the FBI might come after you if you pay a ransom -- because now you are supporting terrorist organizations, not just criminal enterprises. Huge deal.

[00:03:34] Now, the other side of ransomware, and this is what just hit with a few different medical providers here. I talked about the Rehobeth McKinney Christian health center services, New Mexico because now it's much more advanced instead of just getting on your computer, encrypting your files, demanding a ransom to get the decryption key. They even pre-install the decryptor for you. Isn't that handy?

What they are doing is they get onto a computer, and then they start East-West spreading. Now we've seen that for years.

[00:04:08] I remember one of our clients, a car dealer, and this was five-seven years ago. They got some ransomware. Somebody clicked on something that they shouldn't have, and suddenly their machine gets ransomware. The device, of course, is hooked up to the network. It is, in fact, mounting drives from their file server. So his machine has access to all of these files. This guy was a manager over there at this car dealership. So he had access to all of the files.

[00:04:47] Think about that for a minute. What his machine did back then is it said, Oh great, here are some network drives. So it started encrypting the S drive and the H drive, and the K drive. All of these different letters for these SMB mounted drives from the file server.

[00:05:03]We were in there beforehand, and we installed our security stuff.

[00:05:08]When his machine got this brand new strain of ransomware, and of course, he didn't want us looking at what was on his device. So we couldn't install all of the antivirus software because then we would have access to it.

[00:05:22]We've got another client that's like that too, where the owner of the business doesn't want us installing software to really keep his machine clean.

[00:05:29] I don't know why people do that. Are they just trying to play their cards close to the chest? Is that what they're trying to do? Are they looking at something they shouldn't be looking at at work?

[00:05:43] Why do people do that? If you've got hints, let me know. Cause I would love to know me@craigpeterson.com. Why do people do that?

[00:05:52]Anyhow, his machine got the ransomware. It tried to start spreading to the file server. Now, we had special hardware and software installed. So we saw that spread start. We immediately shut down. It was all automatic. It was just shut down because our systems shut down his network port.

[00:06:13] His computer had the ransomware. We were able to just go ahead and restore from backup. The bad guys know that if all they're doing is encrypting your data, then who cares? You restore from backup.

[00:06:29] Now, hopefully, you're following a three-two-one backup scheme. Most places don't.

[00:06:36] Hopefully, you're testing it as well. We try every backup that we make for our customers every day. About once a week, we will spin up the servers in a virtual environment and make sure that it can boot to know we have a good backup.

I got to tell you guys that the backups are not working most of the time, and it gets to be a real problem.

[00:06:57]What these guys have figured, including this Conti gang, is we're not going to be able to get as much money out of them by just encrypting their discs. We need to do something else. So while they're trying to spread East-West inside, what they're doing is okay, so they got a hold of this manager's computer. They start scanning for other computers and scanning for vulnerabilities scanning for ways it can gain access.

[00:07:26] Unfortunately, the statistics show us that most of us have file shares turned on our windows machines.

[00:07:34] That's one of the things I talk about in my Improving Windows Security course, what to do, how to do, how to turn that off because that is the second target of ransomware. Once it gets onto your machine.

[00:07:49] You've got to turn off those file-sharing services.

View Details

Are You Getting Dragged Into Dealing With Cybersecurity?

Craig Peterson: You probably know I've been doing cybersecurity now for 30 years in the online world. Yeah, that long. I'm afraid I have some confessions to make about our relationships here, cybersecurity people, and employees.

I got pulled into this whole business of cybersecurity quite literally, kicking and screaming. I had already been involved in the development of the internet and internet protocols for a decade before. In fact, one of the contracts that I had was with a major manufacturer of computer systems.

[00:00:39]What I did there was design for Unix systems a way to check for malware and manage them remotely. Yes, indeed, I made one of the first RMM systems, as we call them nowadays. We also tied that RMM system, of course, into Windows and a few other operating systems. Unix was where I was working at the time.

[00:01:05] I am what they called an OG in the industry. My gosh, my first job with computer networks was back in 75. Believe it or not, a long time ago. Back then, of course, it was mainframe to mainframe basically and some of the basic protocols, the RJE, and stuff. I know I've got many older people who are listening saying, yeah, I remember that. It brings back memories.

[00:01:32] In fact, I got a note just this week from a listener who was saying his first computer was a Sinclair. Do you remember those things? Oh my gosh. It brought back so many memories for us older guys. But it was just such a great little device with the keys and much different than I'd ever seen before. The XZ81. I just looked it up online so I can remember what the model number was. Timex made that. Suppose you can believe that too. It's just. Wow. It had a Z 80 CPU, which of course, was like an 8080, which was Intel's big chip at the time, running at 3.25 megahertz. Yes, indeed. Very cool. I love that computer anyways. I digress.

[00:02:22]The whole industry at the time was non-existent, yeah. You had antivirus software. We started seeing that in the eighties. We had some terrible operating systems that many people were running like Windows, just absolutely horrific.

[00:02:40] Remember windows three-point 11 and XP and millennial edition just some of the most terrible software ever. That's what happens when you have interns? A lot of the code came out in one of the lawsuits for one of these versions of Windows.

[00:02:55]It was a different world, and I had to figure out what was going on because I had some servers that were Unix servers. This was the early nineties, and I hosted email for companies and websites and filtered things with some precursor to SpamAssassin. It was really something. I had some DECservers, Digital Equipment Corporation. Remember those guys, and suddenly, customers started calling me because the email wasn't working. It turned out it was working, but it was extremely slow, and I had to figure out why.

[00:03:37]I telneted to my server. I got on, started poking around the servers.

[00:03:43] I had a computer room and the first floor of the building I owned, and I was on the second floor. So off we go looking around, trying to figure out what is going on. It was me, actually. I said we, but it was really me. Cause I knew the most about this stuff.

[00:03:59] These processes just continued to fork, and I was trying to figure out why it is creating all these new processes. What's going on? What has happened here? Back then, The internet was a much different place. We trusted everybody. We had fun online. We would spam people who broke our almost unwritten internet rules about being kind to other people. What spam was, where the whole term comes from is you would send the script from Monty Python spam and eggs, spam and ham spam, spam, spam routine.

[00:04:37]You send it to somebody that was breaking these unwritten rules, like trying to sell something on the internet. Absolutely verboten. What a change to today.

[00:04:48]I saw some of this stuff going on. I was trying to figure out what it was, but we trusted everybody. So my mail server, which was Sendmail, at the time. We still maintain some instances of Sendmail for customers that need that.

[00:05:04] Nowadays. It's usually more something like postfix in the backend. You might have Zimbra or something out front, but postfix in the backend. We allowed anybody on the internet to get on to our mail server and fix some configuration problems. They didn't have full access to everything. Firewalls weren't, then, what they are today.

[00:05:29] In fact, one of our engineers just had to run out to a client who did something we told them not to do. They were using the SonicWall firewall on their network, as well as they had our stuff. So we had an excellent Cisco firepower firewall sitting there. So then they have this SonicWall so that they're people, remotely could connect to the SonicWall firewall because it's good enough. SonicWall says it's compliant. So the SonicWall firewall was being used to scan the network and load stuff. Does that sound familiar? Much to our chagrin.

[00:06:08] So he had to run out and take care of that today. It sounds like we might have to do a rip and replace over there restore from backups. You have no idea what these bad guys might've done. We've seen Chinese into these networks before, Chinese malware. It's not been very good.

[00:06:23]Boy, am I wandering all over the place?

[00:06:24]Back to this, we would allow people to get onto our network to fix things. If something was wrong, if we were misconfigured, they could help us and get on and do it because the Sendmail configuration was not for the faint-hearted.

[00:06:42]In the days before Google, right? Eventually, we had Archie and Veronica, and Jughead. They did basic searches across FTP servers. That's my kicking and screaming story.

[00:06:56]I was trying to run a business where we hosted email for companies, which we still do to this day, and where we had some, back then we didn't have websites. The web didn't come in into play until a couple of years later, but we did host FTP sites for businesses so that they could share files back and forth.

[00:07:22]That's what I wanted to do. That was my business.

[00:07:26] Later on, I ended up helping 80% of my clients find the other web hosts after these $8 Gator hosting things. We just got a call on that this week. Somebody who'd been a client of ours 20 years ago went with a guy that charges $5 a month for web hosting. They have personally identifiable information on that site if you can believe it. He was complaining because it wasn't working. He was getting a C-panel error anytime he went to the site. We said, Hey, listen, this problem is the guy that you're hosting from. We did a little research, and we checked the IP address and how many sites we're at that IP address. This guy that was charging them $5 a month had 150 different websites at that one IP address. Now that's not bad. He hosted all of these 150 at a site that charges the eight to $10 a month for Webhosting.

[00:08:29] He had all of these sites on top of a server that already split up hundreds of ways. It's just amazing what people do.

[00:08:38]Man alive.

We got rid of 80% of those customers, the ones that wanted cheap, that's fine, get greedy, and see what happens to you. But, some of them still maintain a good relationship with us, so we help them out from time to time, right?

[00:08:52] What am I going to do? So somebody calls me, I gotta help them. That's precisely what we do now with this malware problem.

[00:09:01] What's going on here? We talked already about the Great Suspender and how Google has said, Hey, this now has malware in it, so we're removing it from your web browsers. That, to me, makes a ton of sense. Why not do that?

[00:09:18]This is another example of what happened with SolarWinds. This is an example of a supply chain infection. What happened with that? Somebody bought Great Suspender from the developer and then added this basic malware to the Great Suspender. Just it's a terrible thing. Very surprising, but one of the most significant exploits used by the bad guys right now is the security team's poor relationship with other employees within the organization.

[00:09:56]What's going on, and it goes back to this customer that we just had to run out to.

[00:10:01] Why did they do what we told them not to do?

View Details

App Tracking Traps a Catholic Priest.
How It Can Affect You, Too

Craig Peterson: I've got two hot topics for you this morning. One about this Catholic priest that ended up resigning and how that happened to tie into this Grindr account. And how it affects you because this type of technology used to convict him in the court of public opinion is something that. It could also easily be used against you.

[00:00:25] And, by the way, it probably is. Now the next thing is this chip shortage. I've got a quote here from the Intel CEO. When is the chip shortage going to go away? When can we get out? Play stations and our new cars. So here we go.

[00:00:43] Matt Gagnon: I'm going to start. With a story that I think I covered maybe a week or two ago, and I went on a pre prolonged grant. I know you may or may not have heard me do it, but it was about this Catholic priest issue. I know you know about this in some depth and detail, as I said before. But there is this issue here.

[00:01:00] He was essentially outed as having visited gay bars and had done several other things. We'll just say using Grindr, right? All these types of things. And of course, being a high-ranking Catholic official, the accusations of hypocrisy and whatnot come and blah, blah, blah, et cetera.

[00:01:18] What's interesting about the story, though, to me, Craig is, the media covered it as a hypocrite priest has been found out. But how that information was discovered is not only creepy but really scary. So I want you to tell me exactly how this happened and what implications do you think it has for our privacy going forward?

[00:01:39] Because this is about a heck of a lot more than one Catholic priest. This is about Greg Peterson and what he's up to when I don't know. What does it do?

[00:01:46] Craig Peterson: Yeah, it absolutely is everyone. Every one of you guys that are listening right now could affect you. Here are the basics of what happened. As Matt just explained, he was outed here because he was using an app.

[00:02:00] Now it wasn't just because of this one. That was being used. And then, again, how many times do I know Matt? You said this. I've heard from you many times. "You are the product." There's something free. It's not free. So behind the scenes, what happened is some people thought that maybe. Bishop was doing something that you weren't supposed to be doing.

[00:02:22] They figured they would look into it a little more, trying to figure out some more details. And so they went to some of these apps and bought information. Now Grindr is one of these hookup apps, and they went to Grindr and bought location data. And it's anonymized, right? That's what we're always telling everybody.

[00:02:44] Oh yeah. Yeah. I

[00:02:45] Matt Gagnon: [00:02:45] don't have your name, right? They don't. Yeah. They may give you some information to people who asked for that data, but it doesn't have things that would identify you.

[00:02:52] Craig Peterson: [00:02:52] Like the NSA. Don't worry. It's just anonymized. They say this stuff all of the time. However, there are many studies you can find online on how to de-anonymize data.

[00:03:05] One of the easiest ways, for instance, to find out where Matt lives is, if you know an app or you suspect a few apps you might be using, you just buy the data from those apps about their users. You can now narrow it down because this phone tends to sleep at the same place every day. And that's true for you too.

[00:03:24] And in this particular case, this clergyman was using this app in various places. So at least the app went to some of these capital meetings, high-level meetings, et cetera. And so they put all of this data together and added two and two together and then confronted him saying, Hey, listen, we know it's you.

[00:03:47] There was no indisputable evidence of it. There was evidence that he went to all of these different meetings, and he was in all of them, and he was the only person that was all of them. And then his, this must be there for his phone, and it must be him. So this is all legal data. Now I want to add one more layer to the top of this.

[00:04:06] It's legal. You can buy it. I can buy it. And the federal government is buying it because they're not allowed to track it as supposedly helpful. But, still, there's a lot of evidence that they are. And because the feds, advertisers, and others have been buying all of this data and putting it together, they also track and de-anonymize them.

[00:04:28] Matt Gagnon: That's, I think, an excellent explanation. Thank you for doing that, Craig, because it's such a technical thing. I think that's what many of these companies rely on because it's difficult to understand how this even works. So the public getting fired up about it is pretty tricky, right?

[00:04:42]You got to understand it, to know what to be, even opposed to, and ultimately the selling of your data anonymized or not is occurring, and it's a problem. And The inevitable question really comes here. Craig, if you don't like this, what do you do about it? Is there any way to fight against this in some fashion?

[00:05:01]There's certainly, I suppose, political changes that could be made, and maybe law is different, but maybe there are things in your life you could do right now that. Would Lakey make you less susceptible to this?

[00:05:12]Craig Peterson: [00:05:12] This is really big. And the data also is being bought by advertisers, obviously roadside services.

[00:05:21] And one of the creepiest things too is you go to a specific type of a clinic and all of a sudden you start seeing ads about a competitor or maybe how, what you shouldn't be doing there. So what do you do about it? Here's another problem. Our phone carriers were caught about two, three years ago selling your real-time location data to these data brokers.

[00:05:45] And I've had a few of them on my show before, in years past, but it's just. Don't put apps on your phone that you don't need. The iOS, Apple phones, and Android phones can turn off tracking and turn it off on an individual app basis. Now that doesn't mean that your phone can't.

[00:06:10] Because they can. All right. But what it does mean is that a specific app might not have access to your location just because you're playing Tetris. So apple has even gone further now. It has made it so that the apps cannot find out what other apps are on the phone and even go to a website on your computer or phone, even though you might have cookies turned off.

[00:06:35] And you've done that. Some of the other things that I've advised people to do. Yeah. The computer can still report which apps are installed and to a website, to any website the same thing with your phone. Apple's taken some fundamental, extra steps to try and block all of that. So far in the Google ecosystem. It's still more open.

[00:06:56] Yeah. Delete the apps you don't need. Turn off tracking in your settings for pretty much everything. Obviously, you need it for maps. And if you are using Google maps, talking about selling your data,

[00:07:11] Matt Gagnon: [00:07:11] indeed. All right. Kirk Peterson, I have a couple other questions for you here. I'm not sure if we'll get a time for all of them.

[00:07:16] However, I did want to talk a bit about the chip shortage here because I continually get frustrated by my inability to buy a PlayStation, which is now a. Five month-long problem for me that trying to buy one of these things. But it's so much more than that. I was talking to somebody else. Maybe last week it was talking about trying to buy a car and you can't even, they don't even have stock.

[00:07:36] Like they don't even have the car at all. And manufacturers are now starting to make their cars differently. So that they don't require the chips that there's a shortage of so that they can actually produce the vehicles. Again, I'm hearing things about crank windows in cars, like just crazy stuff here because of this chip shortage.

[00:07:51] And it might last into 2023. Is that

[00:07:55] Craig Peterson: [00:07:55] right? Yeah. Yeah. And that's what the CEO over at Intel is saying. Now, this is going to last a while. Everybody made mistakes here during the lockdown. We had never had this before, where the government forced businesses to shut down. If you are in business, you are an important business, or you'd be out of it, of business.

[00:08:14] That's just the way it goes. And that's true for the whole chip supplier, right? So we have a long way to go as well. He's saying right now, and they are rebuilding manufacturing capability. Now here's part of the problem with the capacity is the. As they're made up, the newer trips keep getting smaller and require different ship fabrication techniques and fabrication plants.

[00:08:39] That's a huge deal when you get right down to it. And what it means is look at the apple with their M1 chip, and they have just this high-speed chip of Apple's, making its own fabrication, plants, et cetera. So the chips that they're wanting today cannot be made with older fabrication plants.

[00:08:59] Now, some of them have been brought online, and some of those fabrication plants are making older chips. You are right about cars. I drive a 1980 Mercedes-Benz diesel. There, there are no electronics to speak of in this car. And my kids said, Hey, do you know your car's worth like $10,000? It was I. It was just amazing.

[00:09:21] You're absolutely right. The car manufacturers are dropping things, and they are lowering the prices supposedly. But, still, they're lowering the prices based on what that costs them. So, for instance, in some of these higher-end cars where you might have a smart charger that you just put your phone on, you don't have to plug anything in, and it charges up.

[00:09:42]They'll give you a $40 credit. But how are you going to install that later on? How are you going to install electric ones? That was when they put in 10 old ranks. So this is really a big problem. It's hitting everybody. It's tremendously hurting my business. I'm not getting compensated for it because it's taken us forever. We ordered a box of desks for our clients in November.

[00:10:07] They showed up this last month. So we're going to have to live with this. Probably into 20, 23, and maybe even longer. It should start letting up sometime next year. But your PlayStation Matt is still a way off.

[00:10:24] Matt Gagnon: Wonderful. Thanks a lot. Craig Peterson, our tech guru, joins us at this time every week. We will talk to you again, sir, next week.

View Details

Intel Tells Us How Long the Shortage Will Last

[automated transcript]

We're looking at a big chip shortage. You probably heard a little bit about it, but how long is it going to last? And we've got this explosive report out right now about spyware and some of the cyber hacking and what's happening with Android versus iOS. What should you be using, 50% of Americans are using Android, and the rest is split up mostly with Apple. iOS. So what's going on there? This is a research group that says, my goodness. The media outlets just aren't reporting the truth. So here we go with Mr. Chris Ryan.

[00:00:40] Chris Ryan: A couple of things we're going to get today with Craig Peterson are the host of tech talk first design, the chip shortage, and how long that may last.

[00:00:47] The second is a fascinating report on spies where I think a lot of us feel that our phones, and even to a large extent, our laptops are safe because we maybe haven't experienced any overt issues with cybersecurity whether or not that's true. We'll talk about it in a second. Craig Peterson joins us right now. Craig, how are you?

[00:01:08] Craig Peterson: Good morning. I'm doing great this morning.

[00:01:11] Chris Ryan: So we get into a couple of not great stories, though. As into the Intel, CEO says the chip shortage could last until 2023, as we continue to hear about supply chain issues and how they lead to the inflation of consumer costs. What do you think of this particular story, and how do you think it will affect those issues that we see with various shortages.

[00:01:36] Craig Peterson: Yeah, this is a huge deal because, of course, when we're talking about chip shortages, we're talking about affecting everything. It's harder to get a car. For instance, that's driven up the price of used cars, as well as new cars. I mean your computers. We're trying to order them for some of our clients.

[00:01:54] And we have seen some of the delivery times out six months, we just about two or three weeks ago. We just got it. Some discount in that we had ordered in November last year. So think about how long it is. And now we've got the wall street journal reporting after the Intel company posted second-quarter earnings on Thursday and the Intel CEO saying we have a long way to go yet.

[00:02:22] And what they're trying to do. Rebuild infrastructure and build new infrastructure capacity. We have to remember that this is partially due to the lockdown, but the other side of this is competition. These chips keep getting faster at an order. Yeah. Faster. They have to get smaller internally. That's that nanometers thing that you keep hearing about with chip sizes and densities.

[00:02:49] So these older fabrication plans that they couldn't bring back online and that they are, in some cases, bringing back online cannot make the newest chip. So it's a constant gain. So one of the biggest problems we have is. Building brand new chip fabrication plans over the whole lockdown thing. And most of them are in Taiwan.

[00:03:11] So this could go until 2023, frankly.

[00:03:15] Chris Ryan: And it also shows how tied our productivity and our consumption-based economy are into what's taking place in other countries as well. We've talked a lot about COVID in this country, but there are. Countries that are out there where we see some meager rates of vaccination, China.

[00:03:35] We obviously don't know much about them, but Japan, Taiwan vaccination rates are meager there. So we talk obviously a lot about the US side of things, but many of these supply chain issues are driven by the economic and health environments in a foreign country.

[00:03:56] Craig Peterson: Sure, we have a worldwide economy.

[00:03:59] We've got Australia now completely locked down. There are parts from Australia that we need as well as all of these other countries. For example, India's vaccination rate is less than 3% right now. And we require a lot of support from India as well as part. So as we move forward continually the worldwide.

[00:04:20] Source and really the source of everything I can know I can dock is going to be worldwide, and more and more of these countries are going to be playing a bigger part. That's Craig

[00:04:28] Chris Ryan: Peterson, he's the host of tech talk on news radio six, 10, and 96, 7 Saturdays and Sundays at 11:30 AM. Interesting reports on Android and iOS.

[00:04:39] Security. And, I think that many individuals who have not experienced identity theft have not experienced significant cyber attacks against them, they feel that they're safe, and they're not really. That's safe. So I want to get your thoughts on that and B what leads to even if you are vulnerable, what leads to that way, an extended period of time, which you don't experience anything, and the kind of that complacency set.

[00:05:10]Craig Peterson: Many of our devices have been hacked. So if you think it hasn't been you by not know, they're doing everything from not ransoming your phone or random your computer, but using your computer to mine. Coin. And that can be a real problem when it says mark phone and all of a sudden your battery keeps dying after half an hour.

[00:05:33] It just keeps getting on. It might be used right now for Bitcoin mining, all the ways through, of course, some of the ransoms that are visible so much. Mean now; there is happening in the background. Your computer could be used for one of these botnets to attack others and do other major things. Now, what we're concerned about on the security or cybersecurity researcher side is being able to get into these devices and get into the systems to examine them.

[00:06:07] We've got this Pegasus malware, right? Which apparently has been used against some 50,000 journalists and government people, agencies, and others. And they, all you had to do was open your phone, open a message, no cocaine involved. And your phone has been. IOS, which is Apple's operating system, has been relatively closed.

[00:06:30] That's a pro in some ways, and it's a con and others, and we've had all kinds of security researchers over the years here complaining about that while apple made some major changes and has now provided security researchers—access to absolutely everything and also great logging Android.

[00:06:51] Unfortunately, the assumption is if it's Android, anti-virus can not protect it because Android is really a hodgepodge that was thrown together. It's thrown on to thousands of different models of phones that are out there. So we are. Better than one with an apple, people assume an apple is going to be more secure.

[00:07:13] So they're being held to a higher standard, and they are stepping up frankly, to the plate here, Chris,

[00:07:20] Chris Ryan: [00:07:20] you, if you are a business owner, a public official, a person that holds a government position, something that is, would be very intriguing too. Packer or to an organization. And you have questions about your security and whether you are secure, and how do you go about creating an environment where you feel comfortable?

[00:07:43]Particularly if you are not all that knowledgeable on the topic of cybersecurity.

[00:07:49] Craig Peterson: I read a great article yesterday. And it was talking about how we, as a whole, pretty much everyone thinks that you can't do anything about it. So we're just going to give up and

[00:08:03] Chris Ryan: yeah, if I were to get targeted, I get targeted.

[00:08:04] But I think that even when you think about somebody like throw Brad Pitt out there, right? Brad Pitt has to be the target of just about every single hacking organization imaginable. You would assume to want to get information, access to capital, ransomware, whatever. If you are the higher, you move up the food chain as a public official or a celebrity that you would be accustomed to being hacked by.

[00:08:27] Everyone. What do you do if you are concerned about that?

[00:08:31]Craig Peterson: some things can be done, but you cannot use the standard software. We already know that the Norton antivirus and all these other basic antiviruses do not work. They don't protect you against modern threats. In fact, more than 70%.

[00:08:48] Of the threats this year on cannot be stopped by the wonderful little antivirus software we've had for years. So you have to move up to the next level. We're working right now with a small bank. Who's trying to really secure everything because of these sorts of problems. But I, If you are in a position where you are bigger targets than usual, you have to take extra steps.

[00:09:15] You have to use advanced malware protection. In all of these years, I've been securing computers out for 30 years. We have never, ever, I had a client that had ransomware, and we're talking about multinational clients all the way on, down through your local dentist. So it can. Done, but you can't just rely on the technology that was invented 20 years ago.

[00:09:39] Just top ad guys, but it is there, but you're going to have to Lord and get the right people involved. Craig. Thank you so much. Take care.

View Details

Google's Being Sued by the States -- And it doesn't look good for them Craig Peterson: We talked earlier about Amazon and how much trouble they're in right now, Google apparently is in a similar boat. We had just this week, dozens of state attorneys, general suing Google on antitrust grounds.

[00:00:16] You can reach me online. Just me. M E Craig peterson.com or what most people do is they just hit reply to my newsletter.

[00:00:25] Hopefully you're on my newsletter, right? That goes out every week. If you're on that newsletter you can just hit reply and ask me questions. Any questions you want? I'm more than glad to answer them. I know most of you guys, you're not business people. I am still glad to answer your questions for you to keep you on the right track.

[00:00:42] The whole idea here is it's to keep you going. Safer. And if you're a business person, what the heck, maybe I can help you out as well while the here is a problem. And it's a very big problem. We have these absolutely huge companies that are using their market position in order to really control the entire world.

[00:01:09] Now it's a very big problem because you have companies that are sitting on billions of dollars in cash who can and do keep their competition out of the market. Now, one of the ways that keep them out, and I've mentioned this before, Microsoft has done this multiple times as lost lawsuits about it, particularly over in Europe, but they find somebody who might be a competitor and they basically squeeze them out of them.

[00:01:39] Even though they're not necessarily even a direct competitor. One of the things Facebook does is they buy companies for 10, a hundred times sometimes more. Then they're actually worth, would you take 50 million for your company? That's worth 50 million? You might not.

[00:01:56] Would you take 500 million for the company? How about a billion dollars? That's where it starts becoming very questionable about what they're doing. One of the things that Google is allegedly doing right now is preemptively squashing com competing app stores. When you look at Google and the Google Android ecosystem, who sells the most Android devices out there, right?

[00:02:24] The high-end devices, the number one seller of Android phones is of course, Sam. And Samsung started to put a store too. An app store. So you could buy Samsung, Sam sung apps now, apple and Google, both charge about the same rates as a general rule. It's 30% for these bigger companies that they have to pay the app store, okay. I'm okay with that. They both spent the time to build the platform, to monitor it, to try and keep the app store clean and guides. That's definitely worth something. But what if Samsung came along and said, okay, we're only going to charge 10% royalty. In our app store and the apps will run on all of our Samsung Android phones.

[00:03:13] So it's still using the Google operating system. It's still Android. It will probably run on other than Samsung phones as well. That's the whole nature of, but that hasn't happened. And why hasn't it happened? These state attorneys general are saying that what has happened is the Samsung galaxy store got squashed by Google.

[00:03:41] So it could maintain its monopoly on Android app distribution. So it says that Google engaged in a bunch of different anti-competitive practices. They offered large app developers, profit share, and agree. In exchange for exclusive exclusivity. Okay. I can see that the apple iPhone came out. Do you remember this exclusively on ATN T's network?

[00:04:08] Is that a problem? They're saying also the Google created unnecessary hurdles for what's called sideloading. So sideloading is where you might go to another app store in order to install something. Or maybe it's something that you want to put on your site. It's not fully approved by the Google play store.

[00:04:29] So that's the basics of what the side loaning is all about. So saying that they made that even harder. Okay. From Google standpoint, do we really want to. Allow anything to run on our phones. And here's the question, here's why, right? What do I do for living cyber security? What is one of the things you have to do for cybersecurity?

[00:04:51]You've got to put in special routers, special firewalls and software on servers and computers. Whoever touches a computer last owns the next problem. That's been my mantra forever. So if we installed some software on a computer or we had the customer installed some software on a computer, and there's a problem who they get.

[00:05:14] They're going to call me, right? Because I was the last one to touch their computer. And at that point now I have to show, okay, it wasn't me. It was this other piece of software. QuickBooks is a piece of junk, you know what, whatever it is, I'm going to have to justify it. And frankly, I'm probably going to have to fix it.

[00:05:33] So Google is saying. We don't want all of these app stores that might have apps that are not secure apps, that crash apps that might cause problems with the Android ecosystem. I think that's perfectly legitimate. Apparently these state attorneys general don't think it is. And here's the last one. This is a.

[00:05:56] Attempting to buy off Samsung to limit competition from the Samsung galaxy app store. Now, Google is saying that this lawsuit is merit lesson. I can see a whole bunch of legitimate argument on their part. They also said, quote, and this is an article from ARS Technica. It's a strange, it's strange that a group of state attorneys general.

[00:06:21] Chose to file a lawsuit, attacking a system that provides more openness and choice than the others. In other words, are taking a jab at apple because apple is very closed for the reasons I just decided to hear that Google I'm sure is going to argue as to why they are closed. Okay. Apparently the state attorneys general are saying, quote, Google promised repeatedly that Android would be the basis for an open ecosystem in which industry participants could freely compete.

[00:06:56] Google has not kept its word. Instead. Google has taken steps to close the ecosystem from competition and insert itself as the middleman between app developers. Consumers. Okay. Can, so can you see that they're also complaining this 30% commission. It's a monopoly rent that unfairly burdens consumers and developers, and K-12, you could argue that I don't fall for that one personally.

[00:07:24] Now the buy-off is where I think that there's a lot. Yep. Teeth in this particular lawsuit. Cause they're saying that we've got the commission rate argument, right? We've got those. It's not as open as you said, it would be. But these attorneys general have spent a lot of time dissecting Google's alleged efforts to keep competing app stores at bay by, and they said Google was willing to offer Samsung myriad benefits and concessions in order to prevent Samsung's galaxy store from being built out.

[00:08:00]Again, Is that a huge problem. If you've got a big customer or a potential partner coming to you and saying, okay, I want a few concessions here. I'm not going to pay 30%, or I want to have some of you, my developers in house with your people so that they can short circuit some of the problems that always develop those are.

[00:08:25] In the business in business period. And when it comes to software development, right? People, businesses have we'll use apple again as an example jam, which is a really great set of software to help manage your devices. Jan PF, you might want to check it out. So jam had their engineers camp out at Apple's headquarters, apparently four months while they were working on.

[00:08:52] Some of the, their software for the next release of Apple's iOS and Mac iOS. Is that unfair? Yeah, in a way it is right because here I am little Mr. Small developer and I'm not gaining access to Apple's top engineers and able to send mine out there to live with apple engineers and ask questions and help them debug my software.

[00:09:18] But it happens every day. Makes sense. So it says though the galaxy store was not nearly as popular as the play store. Google feared that Samsung would develop into a strong competitor, especially since the company sells a majority of high-end Android phones in the us ARS Technica says Google was particularly concerned that Samsung would get an exclusive game.

[00:09:43] For the store to attract more users, which Samsung did do in 2018, when it partnered with epic to launch fortnight exclusively on the galaxy store. And that one, move that one game. That one app. Costs Google millions of dollars in revenue. So we'll see what happens here. They make other claims in there. Apparently it even offered a Google offered to white label, the play stores, the galaxy store, so that Samsung could maintain its branding, all kinds of negotiations, the types of things I've seen before, the types of things that are.

[00:10:23] Particularly uncommon, but a European commission is also going after them with an antitrust investigation. They've done that a few years ago with this is a problem. These companies are huge and we don't let them fail. Look at what happened. GM and Chrysler, both got bail and the federal government Chrysler got bailouts twice.

[00:10:45] The free market. You never would have had that happen. The best part of Chrysler would still exist and those weak parts would have been gone. That's what bankruptcy law is all about GM. The same thing, the best parts of GM would have remained. We would have probably had better cars today. Then we have, if DM GM had been allowed to go bankrupt and yeah, it's going to hurt people, but guess what?

[00:11:11] It's hurting people right now from the other side. And when I see this happening as well at Google and Amazon, of course they haven't gone bankrupt, but they both along with Facebook and a few others, they're both huge. Huge and they control so much of the market. So what's the best way forward. What do you think I'd love to hear from you?

[00:11:32] Just drop me an email. me@craigpeterson.com. What is the solution to this? Hey, make sure you get my newsletter. We got all of this information, of course, a whole lot more comes out every week. May be semi-weekly here fairly soon. See how it goes, but go to Craig, Peter sohn.com/subscribe. You'll get my free newsletter and you'll keep up to date on what you need to do to keep yourself safe.

[00:12:02] Craig peterson.com.

View Details

Recommendations to Turn Off Your Printers - eCar Fire Warning Craig Peterson: Hey, we got another emergency patch out from our friends at Microsoft. And in this case, it has to do with printers and remote printer access. Do you have employees working from home?

Microsoft has their big monthly patches that they release. They also have weekly patches that they released that are for slightly more critical vulnerabilities. And then they have. Patches that are released because there is a severe problem going on right now while that's what we are staring down.

There is a vulnerability called print nightmare, and this is located in the windows print. Spooler serve. Now the windows print spooler services, what it sounds like. This is the service that handles all of your print jobs. So if you are using this service, Turns out there's a serious bug and Microsoft tried to patch it once and failed.

[00:01:10] And they've got another patch out right now seems to be working, but organizations are really urged to deploy these patches as soon as possible or deceased. Inbound remote printing until they can be applied. So that's why I said, if you have people who are working from home, because many of us turned on remote desktop and you better make sure that's properly patched up so that people could.

[00:01:37] Then and get a desktop. Although Microsoft has an interesting solution that is going to be announced in early August about having your own windows machine there in their cloud. So it looks like you'll be able to have windows machine for about 35 bucks a month. Microsoft will have to keep it up to date.

[00:01:56] I think that's a very cool thing, but they're coming out with that here very shortly. Within the next month or so, we'll see what happens, but this is a problem because if it's exposed to the internet, We're expecting to actually already be seeing active exploit. Now here's the problem Microsoft's trying to solve.

[00:02:19] We have three different types of patches. You have the monthly patches that they release. You have your, which of the patch Tuesday. You also have patches that are released every week, which are more critical. And then these types of patches, these are patches for what are called. Zero day attacks. There is nothing normal out there, a regular stuff that would catch this and stop it.

[00:02:46] Now, the advanced malware protection that we use from Cisco, it will catch this sort of thing, but it'll only catch it after it's been seen a few times and then identified, obviously by now it's been identified. So it's pretty darn cool. So Microsoft's monthly updates. Last month included a patch for another vulnerability in the windows print spooler service.

[00:03:11] And it was initially called a local privilege ex escalation issue. That means that you had to be on that computer in order to gain access to these advanced privileges and features. Turns out that it wasn't entirely just local. And now there is a new one where it can be exploited to get remote code execution and not just privileged privilege, escalation.

[00:03:39] That means that they can now run programs on your computer. And with privilege escalation, they can run those programs as whomever they might want to do. So this is pretty big Blackhat USA conference coming right up and they are going to be hosting one of their talks called diving into spooler and what they did to discover these local and remote.

[00:04:09] Vulnerabilities in the windows print spooler Hey, it's definitely a problem. There is a proof of concept exploit out there, and that means that the bad guys are not too long from coming up with their own. So there you go. Again, patch it up close and remote access, at least for the time being. To your print spooler because it could be a very big deal.

[00:04:34] Another thing you could do is disable the prince Pooler service. You can just use stop service dash name spooler dash force, and that will. Pop it right on down. Okay. And then by the way, in case your machine reboots, you probably wouldn't do a set service dash named spooler dash start-up type disabled in order to make sure it doesn't restart, but there'll a lot to worry about right now, a whole lot, frankly, to worry about right now because of the Russians are coming.

[00:05:06] Here's another one. This is Chevy bolt. Now, I have had some major complaints about Tesla and the way Tesla has these door handles that recess in entirely and how it has happened that during an accident, those door handles don't pop out and people cannot be extracted from cars. And the biggest problem you have in an accident with a car full of batteries is.

[00:05:34] Of course the high voltage and current that's stored in the batteries that now when they, it out, it starts a toxic fire. Very nasty. Just this week, the national highway traffic safety administration issued an alert for all 2017 to 2019 Chevy. Owners now I know a lot of these bolt owners are actually government agencies.

[00:05:59] They're not individuals, but I thought I'd bring it up. Anyways. There was a fire in a Vermont state representatives. Car's name's Timothy Brown. And his Chevy bolt decided it was going to catch on fire. Now, there was a recall by GM of these Chevy volts that had this problem, and apparently it doesn't entirely.

[00:06:26] Fix it, they are still plaguing GM. And man, in this particular case this rep of course in Vermont being a I don't know, leftist, I have to assume, but a fan of electric cars, his car. Sad they're burning, which is pretty bad, ironic, but this happened when was this? Oh, it looks like this happened just a couple of weeks ago.

[00:06:52] He's the state chairman in Vermont of the house committee on energy and technology. I've been supporting electric vehicles go sponsor bills relating to electric. And plug-in. So now his 2019 Chevy bolt course caught in fire, caught on fire, and there are others out there. 68,000 cars. All right. So two phases to the recall first phase is a temporary solution.

[00:07:20] The second one is a more permanent one. Apparently this has to do with the batteries spontaneous. Catching fire. So this isn't something that's related to a car accident. It's a spontaneous combustion problem. That's not too good. It's a defect in the LG chem battery packs that are in these cars. So here you go.

[00:07:43] If you drive to work every day and you charge your Chevy bolt every night, the United States, federal government is telling you to stop doing that. Yes. If you have a Chevy bolt, they're advising you to not charge it at night. I'm not sure when you're going to charge it. Cause the idea is you charge it at night.

[00:08:03] You drive in the day, right? So they're saying there's, you can't do that. If you have to charge it at night, make sure you park the car away from any structures and definitely do not park your Chevy volt. That might be part of this. Recall inside a garage. How's that for bad, the original recall, by the way, came out in November, 2020 for potential fire hazard in the, again, the high voltage battery pack, those cells could possibly heat up and ignite internally.

[00:08:35] Yeah. And if that fire spreads of the rest of the car and spreads to the building it's parked in or nearby building. Yeah. So keep an eye out. If you have a Chevy bolt, this is the type of problem in a phase as we start more and more to move into the electric vehicle realm. Yeah. Eventually it'll all get worked out, but it isn't perfect today.

[00:08:57] Hey, visit me online Craig peterson.com and keep up with the latest in what you have to do with technology.

View Details

COVID's Biggest Victim? The Traditional Workplace

Craig Peterson: Work from home is a huge deal, especially for a couple of segments of our society. And I want to talk a little bit about that now, as employees are returning to work, should they be returning to the office?

There is a great article here this last week in Forbes magazine by Dana Brownley. And it was one of their editors' picks, and Forbes picked it, I think, for excellent reason. And that is so many of us have been working from home. And for many of us, it's been a godsend.

I've worked from home now for over 20 years. And for me, it's been a godsend because my priority was helping to raise our eight children. And it's hard to do that, and it's hard to homeschool them if you are not at home. So that's what I had done. And I was very privileged to be able to do that.

[00:00:54] And our kids have all turned out amazing. Many people are caregivers, and it isn't necessarily just kids. But right now, I'm looking at a survey that was conducted. It's called the Prudential May 2021 pulse of the American worker survey. And they're showing the 2000 respondents that 38% identified themselves as caregivers, with nearly 40% of those providing care.

[00:01:25] For school-age children, when you are starting to look at benefits packages, many families need to be able to have some form of childcare. And what has snuck in because of the lockdown is that many of us can work from home. So many of us have been more productive at home. And then, on top of it, all we can take.

[00:01:52] Of our family. So let's look at the stats. We told you about school-age children. That's about 40%, 32% are taking care of young children. And this is 40% of all workers. Okay. People 30% are caring for someone with a disability, some health issue. And 23% are taking care of older adults.

[00:02:20] That's 40% of the workforce. That is a lot of people. A lot of people, 38% is the exact number. So there, many of these caregivers are returning. Really a traditional work environment where they're going to the office, but they have unique needs. And I think every last one of us has to consider that and look at it and figure out how we can make things work.

[00:02:51] And when we look at the numbers again for the caregivers, 45% say that they've considered leaving the workforce entirely. Due to personal demands. And 53% are saying that they would retrain for a career in a different field or industry. If they had the opportunity, we have some of our best people out there that are taking care of the kids of our loved ones.

[00:03:21] Our parents. And again, look at mine, a situation here where I was at home helping to take care of our kids along with my wife. Neither one of us could have carried on a regular job and homeschooled eight kids. Neither one of us could have done that. What kind of talent might we be losing? Squeezing these people out of our workforce, particularly when we've now proven that most businesses can allow their workers to work from home.

[00:03:57] Now, they found in the survey that there were three primary types of support caregivers, and these types are looking for different types of flexibility. Number one, they're saying that 42% wanted increased workplace flexibility. No, that makes a whole lot of sense. So they can work from home.

[00:04:20]Maybe some of your best employees or people who want to work in another part of the country. I have a friend; his brother-in-law is a real good programmer in this one particular type of programming. I think it's sales and he is living there now in a completely different country on the other side of the world.

[00:04:42] And yet. He's still doing programming for these people here in the United States, talking about workplace flexibility. He is sitting over there not far from China and is enjoying himself. He loves it there. And of course, his costs are much lower, et cetera, et cetera. So consider that, not just that there might be working from home, but maybe they want to take the kids over to Europe, live there for six weeks.

[00:05:10] There's a lot of things people want. So that's 42% of our people that are working. Okay. Increased workplace place. Flexibility. The number two increased paid time off by 38%. Again, something we got to consider seriously. Now I know how hard it is to be able to fill in for someone that's on vacation or. Maybe they're caring for a loved one.

[00:05:38] Maybe they just had a baby, et cetera, but it's essential when you get right down to it. Because again, who's better for raising our children, us, or a stranger who's going to more or less warehouse them. You have to keep a look at that. There's a great article from the Harvard business school.

[00:05:59] It's titled. COVID killed the traditional workplace. What should companies do now? That's an excellent question because now the lockdown is mostly behind us. Executives can't expect the offices to run the same way they did to come in and do the same things they always did. But in reality, Harvard business school faculty members are saying there are ways to keep our employees happy and productive.

[00:06:32] And that is exactly what we're talking about. But, no, for many caretaker takers caregivers, I should say paid time off is more valuable than a pay increase. And that's particularly true for those who are at the higher end of the pay scale. It gives them a lot more flexibility. They can get away sometimes from all of their responsibilities and obligations, which is just so important.

[00:06:57] There's here's another one. This is a job list survey from CNBC. The article entitled here's how much money workers would give up for better. Life balance. And they go in, in that particular article and say that the average worker who says they currently have work-life balance, it would take an extra $10,000 in pay per year for them to give up their personal time.

[00:07:20] I'm not sure that's right. I think it would be a lot more than that. And it also says just 30% of workers said they'd give up part of their pay for a better work-life balance. And the threshold varies by the type of worker. So that's where we, I think, really get into it now. So those are the first two, the third one is 37%.

[00:07:41] So these are all within 4% of each other—a greater commitment to health and wellbeing. Now I've seen studies before saying businesses that put in a gym and put in workout rooms, et cetera. They never actually see them use—the way they expect for them to be used. And I don't think that's what people are talking about here, but we really are thinking a lot more about health and wellbeing since so many of us have been scared because of the COVID outbreak, but maybe I should be paying more attention to our health.

[00:08:17]But we also have the mental health look at all of the problems we've seen from so many mental health issues because of the. Down. So Harvard again came out and said for employers that we need to signal the health of facilities. It's crucial to attracting people back. So again, The right kinds of air filters, right?

[00:08:39] Kinds of lighting, make sure people feel safe while they're in the office and maybe cut back the number of days they have to be there. Hey, stick around. We'll be right back. We got a lot more to cover. You're listening to Craig Peterson, of course, and visit me online. Craig peterson.com.

View Details

The FBI Weaponized Google Pixel 4a Phones!

If you look into buying a used Google Pixel 2a, I've got some news for you. The FBI has been very busy, and they've conned the con man. I love this story. The FBI has been trying to track bad guys for a very long time, and there've been several ways they've done it.

We know obviously about phone taps. We've seen those before the old days. I don't know if you've ever been to one of the original. Telephone switching stations were all not even original, but the types they had in the late sixties and early seventies. I remember going to see one, and all of these switches were going.

[00:00:43] People were dialing the phones and everything. It was just so cool. And back then, to trace a phone call, what they had to do is find the original. Sore. So they would go to that row, that column, that exact little unit that was hooked up directly to your phone. And then they would see, okay, this is in position this, and then go to that next switch.

[00:01:08] Okay. Position that next switch, position that, and go all the way through. That's the really older days, not the old days where you had somebody that was at a switchboard doing it. Nowadays, of course, it's all done by computers. The telephone company turns your voice into a digital signal, and it's usually done right in your local neighborhood.

[00:01:29] It isn't even done at the central office anymore. So by the time your voice is outside the central office, it's digital. It's hauled on nowadays, even partially an internet protocol. Network. They used to use different protocols back in the day. And so, it makes it quite easy for them to tap your line. Now, of course, there's the legal side of this.

[00:01:53] Do they have the legal right to do it to the need a court order or what kind of a court order? Do they need it, right? All of that stuff. But that is the side. It's effortless to find out where calls went, where they came from, and to listen in because it's just digital—Data's completely copyable with absolutely no particular problems at all in copying it.

[00:02:17]Last month. The FBI and the Australian federal police acknowledged that they had indeed been working on this encrypted device. And the company was called a nom, which is a fake company and a nom sole. 12,000 smartphones to criminal syndicates around the world. That's the wording that the police used.

[00:02:45] So these were being sold as secure devices. They did things like they removed the cell leader, modem functionality they'd changed the boot ROMs. They removed the GPS. So the idea was, Hey, you missed your badge. You can use one of our Anom phones, and it's using a special version of the Android operating system, and you can send messages back and forth.

[00:03:10] It's a completely secure messenger service with end-to-end encryption, right? Like we're always being promised. And so what happened is bad guys started referring. Bad guys to this, right? Cause if they wanted to talk to the other guy, they both needed these Anom phones. Otherwise, they wouldn't be able to talk to each other.

[00:03:31]And so they were recommending the use of these phones to their friends that were in the illegal businesses as well. So this I'm just chocolate is so great. So the FBI weaponized. Android phones, at least this particular model of it. And there's a whole community in the Android world. It doesn't exist in the iPhone world because this is much harder to do in the iPhone world, but they call themselves the model.

[00:04:03] Community. And so they'll get a phone from some vendor. They'll make some changes to it that led to maybe change networks or do other fancy things. So they, after the FBI, used some of this technology. The modding community and did some just amazing things with this custom rom. Now you're going to love this part.

[00:04:24] Okay. So when you boot this phone up, this is according to ARS Technica. The phone will have, of course, a little boot screen and. The highest custom from here is the boot loader and other things, but it showed an arcane, oh, S boot screen that's the name, arcane O S and every place, the normal Android distribution that comes from Google with the.

[00:04:52] B I's arcane. Oh, west green. It's just phenomenal that these guys would do this and would fall for it. So the FBI told the criminals, Hey alleged criminals, Hey, these are secure devices, the really focused on security, and there is a pin scrambling fee. What would happen if on your phone?

[00:05:14]You might enter pin some phones, you might use a fingerprint, or he might use a face ID. This was a security feature. And what happened is normally you've got what, 1, 2, 3, 4, 5, 6, 7, 8, 9, 0. And you type in your pin, and off you go, what this did, is it scrambled it? So it might be nine too.

[00:05:34]Just the scramble of the digits up so that when you enter your pin, you're not always touching the screen in the same place so that people could not guess your code from the fingerprints you're leaving behind. Now, this is also interesting. It, this is a great way to do it. If you're doing it for real, having to run an anonymous phone, they had two different interfaces on the phone, and a different one would pop up depending on. Pin you typed into the lock screen. So the first pin would show a bunch of non-functional apps that are pretty popular in the app store, like Tinder, Instagram, Facebook, Netflix, candy crush games.

[00:06:18] So if somebody is checking out your phone, forcing you to unlock it, they're not going to find budge. And by the way, none of those things work. But. If I had designed it, I would have made them so that they would work. So you can fool some of us by trying to rob us and steal your phone.

[00:06:32] The second pin you could enter tells you chose your pins, but it was supposed to be the secure section. She didn't have the phone. So it had a clock, a calculator, and the settings. But the calculator app actually opened a login screen to a nom as an anonymous. And that, again, the bad guys are told all that's a secure, encrypted way to chat.

[00:06:57]This is just amazing. So they will do use that. So they go into the calculator app and now allowed them to chat with their friends. But what they did not realize. Is, it was actually sending all of the messages also un-encrypted to the FBI. Okay, absolutely amazing. Amazing. So now, some of these bad guys are selling their phones online.

[00:07:28] I remember I warned you at the very beginning. If you're going to buy a pixel for a, you want to listen to this first because the bad guys are selling. Their phones are online. And so, several people have been trying to figure it out—some posts on Reddit and elsewhere. You guys know how to deal with this arcane.

[00:07:48] S, how can I reset this? What should I do? Okay. A lot of confused people. How do I fix this thing? You're not going to be able to fix it. Okay. By the way, this thing I think is really cool because the guy who he bought it legit guy bought it use. You said the installed operating system is arcane O S 10.

[00:08:06] The system updater says that Archana, YC 11 is available for download, but I don't want to do it in case it makes something even harder to fix. So maybe the FBI is bad. At sending out updates and fixes, most of the Google Android vendors are out there, and I'm just laughing all the way through here.

[00:08:27]So, there are some things that a tech-savvy user should know. So I want you guys to pay attention to this, particularly if you're using an Android device. So the first thing is when you start up a newer Android phone when it's made in the last few years, The first thing that happened is that Google runs something called verified boot, which makes sure the operating system has not been modified.

[00:08:58] So, the operating system from the device manufacturer will be signed using a cryptographically secured. What was happening here is these devices were failing verified boot, of course, because the FBI had modified the boot ROMs. And if your device fails, verified boot, your Android device either could be an unlocked boot loader or a relaunch boot loader with tampered software.

[00:09:27] It's going to show a message. And, in this case, the FDA FBI devices have a message that says your device is loading a different operating system, complete with their yellow exclamation point icon and a link for Google support pages. Phenomenal. And by the way, the article I'm sending this out in my newsletter, but it says.

[00:09:54] How resistance changes. Google has an order. So it sent them to the legitimate Google support. So there you go. There's a perfect little piece of advice right now. The FBI changed many Android operating systems and tripped out many Android settings that might've revealed something about the fact that it really was a spy device system settings for app storage, and accounts have been removed.

[00:10:23] So pay attention, right? If your machine boots up, the plane's about the bootloader, you've got a problem, and it isn't just Android. Obviously, Apple will do that. The newer versions of windows are starting to do that as well with TPMS, and windows 11 is really going to bring a lot of that to the forum.

[00:10:44] Hey, you're listening to Craig Peterson, and you can find me online. Craig peterson.com. Check it out and stick around.

View Details

How Could Facebook Do a Better Job at Controlling Disinformation?

Hello, everybody. Great discussion this morning about Facebook and what is going on with their monitoring and controlling some of the topics. Should they have something in place that really stops false information? How could they do that? And what's their real motivation behind all of this.

With Mr. Christopher Ryan, we also got into how the general services administration has completely messed up. Again, it's authorization, this FedRAMP authorization. Why are our federal agencies using some tools like zoom that have been proven to be very insecure, and they're using them with the blessing of GSA, who says they're secure.

[00:00:50] So here we go.

[00:00:52] Chris Ryan: Craig Peterson is the host of tech talk on news radio 610, 96.7. You can check him out Saturdays and Sundays at 1130. Craig, how are you?. Hey, good morning. Doing great. Appreciate being with us. So one of the topics we did we've delved into today is social media giants and censorship of quote-unquote misinformation is. The white house weighed in on this last week and criticized Facebook as a purveyor of misinformation based upon allowing individuals platforms to push forward their opinions.

[00:01:27] From a media standpoint, we have gatekeepers available and able to squelch misinformation and provide a great environment that can provide the most accurate information possible. Is there any way, shape, or form that a Facebook or a Twitter can? Have any sort of an algorithm or staffing or personnel; this is not even whether you should do it or shouldn't do it.

[00:01:55] Is any way feasible or possible for them to strike down misinformation?

[00:02:03] Craig Peterson: [00:02:03] Yeah. This is a tough one. It's easy enough. You've got, of course, Justin sitting there with the big button, and the Eaton cut us off at any point. But when it comes to Facebook or Twitter or any of these other big places you have, what is it now?

[00:02:20] Billion active users per month, just on Facebook. So what you were asking about is there some algorithm. Obviously, people can't do this, and the answer is I have, yeah, a fascinating article. I'll be talking about it next Saturday. How about IBM's Watson? You probably remember Watson pretty well.

[00:02:39] It was going to rule the world. It won jeopardy. It was absolutely amazing. And it really hasn't done much since then. One of the most advanced AIS we've had, and Microsoft and Google both have them; China's working on artificial intelligence to try and figure it out. But the biggest problem that we have is.

[00:02:59] What is the sentiment there. How can you tell an article is criticizing something legitimately, or if they are endorsing something that might be a bad idea, then who gets to choose? What's a good idea. What's a bad idea. This isn't easy to do

[00:03:16] Chris Ryan: [00:03:16] Chris. And there are no rules either. I said before; I don't think it was appropriate for social media to ban Trump.

[00:03:24] I don't; I think that many individuals push forward misinformation and tr and lack truth and their intent is not good. And they're still allowed to do whatever they wish. So I think that you have to create a. A platform and an infrastructure to determine what the role should be.

[00:03:45]And what, how many times do you get to push things forward that aren't true or et cetera? There are no rules.

[00:03:51] Craig Peterson: [00:03:51] Yeah. I look at this and a profit motive on the part of Facebook, certainly in these others. And that is, they want your watch. The Facebook channel. They want you on that feed all day long.

[00:04:05] So the more that you aren't interested in a topic or position, maybe a position is totally false. Maybe you are flat earth, or the more information they're going to feed you—the how the earth is flat and less about anything else. So what we've ended up with now with these social media sites is something that really polarizes us even more than we were polarized before because we see more and more information that confirms our suspicions and where we're at.

[00:04:36] So I see that as an even bigger problem because we're frankly, Getting isolated. We don't have the editorial in the newspaper that might be left, might be right. It might be the center. As time goes on by these submitted authors, it's showing you what you want to see. And that's a big,

[00:04:56] Chris Ryan: [00:04:56] right. And the Facebook feed has also changed over the years where initially it was just your friends, basically, and their information more and more, the feed has gotten filled.

[00:05:07]Topics that they have determined that you're interested in and sources that may or may not be accurate that present that information. And this has happened to me, and I'm sure it happens to everybody else. Know, You may click on the art, one of those articles, and be interested in it.

[00:05:22] And then the next thing 50% of your feed is similar articles or ads that are associated with things that you have looked up. So the Facebook feed has changed dramatically. Over the years to the point where it was initially, there weren't many ads, and you wonder how they made their money to the point of which now, where there are a lot of ads.

[00:05:43] And they're also continually feeding you information on topics that you're interested in.

[00:05:49] Craig Peterson: [00:05:49] Yeah. And topics that, again, might be correct, might be false. And what Facebook

[00:05:54] Chris Ryan: [00:05:54] is doing you, in fact, giving you information that may not be accurate. So not just your friends, Facebook itself is providing you with information that may be false.

[00:06:04] Craig Peterson: [00:06:04] Remember the days in Facebook, or again earlier on where if you followed someone, if you liked someone, you would see their posts, they would show up in your stream. Now Facebook realizes, oh my goodness, you've got hundreds of friends out there. They're all posting stuff. And Facebook decides what you want to see.

[00:06:26] Many of the celebrities dropped off of Facebook because people that wanted to see their posts were no longer seeing them because. Facebook was moderating it. So we've come full circle under discussion. Facebook is doing moderation, and the moderation they're doing is, again, isolating us and dividing us even more.

[00:06:46] That's a huge problem. What's the solution. I w was this day and age. I'm not exactly sure because they, the algorithms. They could be doing more moderation. Should they be doing it? And, of course, that's the whole discussion around section 320.

[00:07:02] Chris Ryan: Exactly. So let's talk a little bit about zoom; an article has come out about zoom and its cybersecurity issues, and the GSA is blocked.

[00:07:12] Senator Ron Wyden reviewed documents used to approve zoom for government use in government meetings. And that this is not just the federal level. It happens all the time at the local level as well. And there were initial concerns about cybersecurity and zoom, but a lot of those concerns and the topic of conversation about them seem to go away during the course of the pandemic; how safe is zoom, and obviously, you haven't.

[00:07:39] Individuals, whether it's from a non-profit private sector or government perspective, who are discussing compassionate things on zoom. And they assume that no one is listening, but are they?

[00:07:52] Craig Peterson: Yeah, that's a terrible assumption, particularly when it comes to zoom. The big concern here in this particular article that appeared in the tech crunch has to do with the investigation that's done by the fed.

[00:08:06] So we know there's obviously information that needs to be kept secret other classified information, and then there's information that might be damaging. And what's happened here is the general services administration gave zoom their authorizations. FedRAMP authorization saying, yeah, go ahead and use it.

[00:08:25] It's going to be fine. Everything's great. Turned out. Zoom was not encrypting these sessions from end to end. In fact, routing some of our conversations live through Chinese. They're using Chinese programmers to write this stuff. They installed back doors on Macs, just all kinds of incredible, terrible stuff that zoom hadn't been doing.

[00:08:50] And some of it is alleged continuing to do. And yet, somehow, it received this authorization from the GSA. How that. Did that happen? Now, there are some secure ways to speak online. Really WebEx is the only one that is fully authorized, and then you have to have the right version of it. Microsoft teams have some stuff that is also authorized and.

[00:09:19] Truly end to end. Zoom is not to be trusted, but what really concerns me is it looked like the federal government delving into any of these tools to verify whether or not they appear to be safe was terribly flawed. And that's exactly what the Senator has been trying to do and why and how, and they're just not providing the information.

[00:09:43] Chris Ryan: [00:09:43] I have a basic theory. Applies, I think to tech and social media; if something is free, ask why and figure out why is this free? Why are you able to do it for free? What is in it for the company, and then decide whether or not you want to use it? But I think that people are all in, on giving their information, using.

[00:10:06] These things and they don't really understand what the business platform is? How is this being used? And I think that is something that individuals should be cognizant of. Craig has always thanked you so much. Take care. That was Craig Peterson. He is the host of tech talk.

View Details

Amazon Is In For a Rough Ride

Did you know that Amazon has a new CEO? I remember back in the nineties; I pledge that I would never use Amazon again because they filed and were awarded a patent on technology everybody was using. Jeff Bezos is out of a job.

[00:00:19] This is a guy that grew a company that all they did initially really was book sales, and they had a warehouse the size of the Amazon, right? Because they wanted to represent everybody. They had every book ever published, and to a large degree. They did. They had a whole lot of bucks, and then I've expanded, of course, beyond that.

[00:00:47]And beyond that, to the point today where they are doing some well, again, shady things I mentioned in the intro that I was concerned about what Amazon was doing with pat. They got a patent on this one-click purchase. Now I have been a fan of patents for a long time. I do not like the patent law as it exists today.

[00:01:14] And in fact, I haven't liked it for quite some time, but this patent law where you don't have to show that there was no prior art and frankly, the prior art does not matter at all. I think that's huge. And I've had a number of patent attorneys on my show, talking about it and talking about what we may want to change.

[00:01:37]Jeff Bezos grew it to today, where it really is the number one provider of online services is. You might, in fact, almost certainly are using Amazon's services, whether you realize it or not to go to most, any website, any of the big ones they're probably using Amazon's web services. They're probably using Amazon storage, and Amazon has dozens and dozens of different services.

[00:02:09] So it's a very big deal. And Jeff Bezos, who's the guy that started all of that, sat down stepped on. I should say. Now it's rare that the founder of a company ends up taking the company public. Public, basically, that just doesn't really happen because all of a sudden, when you're public, your whole job changes, and no longer can you make a decision, a snap decision about something, and then go ahead and do it.

[00:02:37] You've got to be very careful about what you do when you do it, how you do it, you have to announce it and everything, but just an amazing man being able to take it—all of that. And by the way, he have the largest settlement, a divorce settlement in history with his ex-wife. It's amazing, but he is still the world's richest human.

[00:02:59] Now he has this company called blue origin, which is his rocket company. He's got the Bezos earth fund, and he's still chairman of Amazon's board. So he's not going anywhere. However, we've got this new guy, Andy Jassy, who has stepped in as the CEO of Amazon. He was the head of Amazon's online services, which is absolutely huge. It's their most profitable arm by far. So he's taking this whole thing over when Amazon, frankly, is in a lot of trouble. Now they're basics of, Hey, there, the money that they're making, their profits and everything, that's all well and good, but there are ongoing antitrust investigations.

[00:03:52] There's a battle with labor. And we're talking about, of course, big labor here—the unions. There's increased competition in the cloud space. Just look at what happened with the US military in there. I think it was at least a billion dollar. I can't remember the exact number, a cloud contract because Amazon was battling Microsoft Azure and it was awarded.

[00:04:20] And then just a couple of weeks ago it was pulled back again. They're also seeing increased competition in their online services from Google. And I use some of those Google services. In fact, if you go to Craig peterson.com, it's actually right now using some of those Google services. So they are really getting nailed from a whole bunch of different directions.

[00:04:45] And this guy Jassy has worked there since 97. But he may be the perfect person to guide Amazon through. W really now we're talking about the middle-aged, that's the time when you're supposed to buy your convertible, buy your motorcycle, et cetera. The middle aged years. And in this case, there's some problems.

[00:05:10] Here's a quote I want to read from this Yahoo article is actually I think AP yeah. Yahoo finance. This Yahoo article and it's from Harvard business school, because we've got regulators who are circling, and this may be the main reason Jeff stepped down. I don't know, but quote, you may want somebody who has the confidence of the chair.

[00:05:35] And the board you want somebody who understands the strategy and was part of it and knows where the bodies are buried and the mistakes that have been made and how to move forward. This is from Harvard business school, professor of business administration. Rosabeth Moss Kanter, and I think she's right.

[00:05:58] Absolutely because this road ahead for him is going to be tough. But the fact that he ran their most profitable division tells you something, it tells you a lot and he might be the exact right guy to be able to do that. Amazon's now got a market capitalization of about $2 trillion, which is huge.

[00:06:20] And it's certainly enough to get some of these regulators. Paint a lot of attention to what's going on. We've got the Washington DC attorney general, who has accused them of violating the district of Columbia's antitrust act. And that has to do with, for bidding third-party resellers, from offering cheaper rates for their products on competing sites.

[00:06:43] Cause remember what Amazon does. About half or more. In fact, I think now of their products are not actually sold by Amazon. They're certainly not Amazon products. They are products from resellers who are just selling on Amazon. They're using Amazon is their platform. And that way Amazon will manage the inventory.

[00:07:06] It'll warehouse a little ship it out. It'll handle the returns. Yeah. What Amazon is doing is charging these sellers for the space in the warehouses, which is perfectly legitimate and taking a percentage of the deals. Are there other websites that might give these sellers or resellers or stuff they're importing from China or wherever.

[00:07:31] Might there be other sites that give them better deals? Will you bet there are sites out there. So that's why she's suing them. Federal regulators look like they might be coming in as well. The federal trade commission's newly appointed chairman. She's a fierce critic of the. Amazon way of doing business and she made herself a name by publishing an article for Yale's law journal titled Amazon's antitrust paradox.

[00:08:01] So before she was even appointed to the federal trade commission, she was already calling for changes in the current antitrust regulatory framework. And that might be widely invited administration has appointed her, but there's six antitrust bills. Targeting big tech right now that are working their way through the house of representatives.

[00:08:24] And we've talked about some of those already, and, I do not like these huge tech companies that are making crazy profits and using those profits to keep other people out. And Amazon's one of the largest employers in the country. And after years of complaints from somewhere house workers, we've got the labor unions now in the mix trying to take action.

[00:08:49] Now, I don't have a single problem with labor unions while at some of their tactics, I have problems with, I don't have a problem with the labor union. In the private space. I have a huge problem with I'm in government space. And we could talk about that at some point, but I don't have a problem with them trying to organize inside Amazon.

[00:09:12] So the international brotherhood of Teamsters. Yeah. I remember the guys that drive the horses. They announced that they're going to begin working to organize Amazon workers. So that might succeed. There was another one in Alabama that had failed. So are you getting the hint here? This is huge. It's huge.

[00:09:32]By the way, Amazon's offering warehouse workers starting pay at $15 per hour plus benefits. So that doesn't seem too bad. If you ask them. But again, with the pandemic, all of the stuff going on there been a lot of calls for Amazon to quote, treat its workers better. So we'll see. We'll see what happens.

[00:09:53] Other problems with Amazon that we've talked about before are things like fake reviews. You and I, we look at the reviews, it's critical in us buying things. Isn't it. We look at the reviews and say, oh, wow. Jeepers. There's 500 reviews here and it's four and a half stars. Okay. So I can have confidence that this product is good.

[00:10:17] It's going to work. And yet some of these sellers, what they're doing is bribing people to give a good review. So they'll say, Hey, you buy my product. And then they send the product in with, along with the product is a little note saying, Hey, if you give me a review and send me a link, I'll send you an extra battery or whatever it might be.

[00:10:39] That has been a real problem for Amazon, even worse than that, because at least those people might give an honest review, right? Worse than that is that some of these reviews are paid for. So some of the sellers it's alleged are going out there. They are hiring. People and paying them to give reviews. Now, those ones are very obvious.

[00:11:04] If you look at the reviews, so don't just look at there's 500 and the average is 4.5. Look at some of the reviews in the wording. So I've seen reviews where it was for a massager, and there was talking about what a great. A set of wheels that has on it. And they work really well. And it's very smooth when you're out, riding it on the trails.

[00:11:27] Wait a minute wait, we're talking about a massager here. We're not talking about a bicycle, so that's one of the ways to tell if the reviews are fake, they're don't even talk about the product at all, or any of its real features. The other one is look at the wording because most of these fake reviews.

[00:11:45] Don't use English, so good. All right. Okay. Thanks for being with me. I want to make sure you stick around and visit me online. In the meantime, go to Craig peterson.com. If you sign up for my free newsletter, you'll be getting that every week with all of the details. I'll try and catch you up and you can listen to my podcast, right from there.

[00:12:09] CraigPeterson.com. That's Peterson with an O.

View Details

Kaseya and the Problem with Managed Service Providers

We have really in front of us, a critical warning. We're trying to figure out what should we do or to stop people from attacking us. That's a problem. What should we do? Many of us have gone out to managed services providers, and now they have let us down. Did you hear about the Kaseya hack?

It has had a huge impact on people. It's absolutely crazy. Or you heard about a thousand companies that got together and they have hired a negotiator in order to negotiate the ransom with the bad guys that have ransom there. It is huge. It's huge. But let's talk about why this happened, because I think there are many things that you and I have overlooked here over the years, this ransomware God guy, gang called REvil, R E V I L has targeted cause say, or customers through.

[00:01:04] Say, but it isn't just kissy customers. It's really cause say, is customers for the most part. Now your head might be spinning a little bit, but here's, what's happening. I'm a business owner. You guys know that right now. Let's say that I don't do cybersecurity for businesses. That's what I do.

[00:01:24] But let's say I make widget. I as a widget maker, do not have enough knowledge about computers to, to really do it myself. So let's say I've grown and I've got 20 employees. The odds are very good that my office manager is the one in charge of the computer. The office manager probably orders.

[00:01:49] Computers probably tries to figure out what's going wrong. By the time of it at 50 computers or 50 employees, I've probably got a full-time it person who goes around and tries to take care of things. But before I've got that, full-time it person I'm probably going to outsource it. And by the way, a lot of companies, it's more like a hundred to 200 employees before they get someone who's really dedicated to it.

[00:02:18] So then that awkward teenage stage between where the office managers trying to do it. And finally the office manager can try and hire an it professional. Is where they go and outsource it. You talk to various types of companies. What are in the industry called break, fix shops. That's usually the first stop which is calling them up saying I've got a broken computer.

[00:02:44] Can you fix it? And maybe they can, maybe they can't. And then a lot of break fix shops have tried to level out their income so that they have predictable monthly income so that they can hire the right number of people for the number of customers that they have. Although I've got to say most of them are badly overbooked.

[00:03:04]Now that they've hired those people, they this outsource break fix shop. They come in and say, okay here's what we can do for X amount per month per computer or employee, we will take care of those computers for you. One of the things that they'll promise to do is that they will take care of your cybersecurity for you.

[00:03:25] Now, cybersecurity is frankly, a specialty. It is not something that everybody can do. Even if you're using some of the best stuff in the world, like what we do, we have Cisco hardware, we have Cisco software that we run advanced malware protection. So that's the best of the top of the line.

[00:03:45] Most smaller businesses aren't going to want to pay for it, even though they might be able to afford it. Push those people out right now, because we're talking about, you were talking about a smaller business. So what does that outsourced it provider do for you? They might change their name and call themselves a managed services provider.

[00:04:06] And that's all well and good, but they need help as well. So I'm making widgets. I have this break fix shop that came in and fixed my computers a few times. And now they're handling my cyber security. Isn't that wall well, and goods was wonderful. So now they're handling, supposedly my cybersecurity. But they know they can't do it themselves and it would be too expensive to do it because they went cheap.

[00:04:33]You bought the least expensive option or, close to the least expensive option. So wait, and by the way, cheap in this case means that it's under $150 per. Person slash workstation per month. That's what it costs to get this stuff done. So you might be paying 25 or maybe even $50. They can't do it for that.

[00:04:57] So what do they do? They go to a company like. Now they also have some others. They have what are called arm AMS that keep track of some basic stuff for you, but they go to Garcia and say, okay, Casia we want you to monitor the computers, keep them up to date, et cetera for. Now did I, the widget manufacturer go ahead and hire to take care of stuff.

[00:05:23] Did Kasiah even do it themselves or did they outsource it? Do I even know the Kaseya exists because it's really Kaseya that is managing my computers doing. We have, there has a software that doing the upgrade on my computers. This is a real problem because the widget maker, Nope, I didn't hire KSA. I didn't even know they existed.

[00:05:49] I trusted my local. Your local guy is not taking care of your cybersecurity. Almost completely guaranteed. There's very few companies like mine out there that we actually do it ourselves because we have looked at Kaseya. We've looked at all of these platforms. Every last one of them has had major problems.

[00:06:12] So here comes Casia with over a hundred thousand customers that gets hacked and distributes the hack to all of its customers that are running some of these on-premise devices that are trying to manage the networks for not Cassias clients, but for KSA as clients, client. Okay. Do you see how this is the level of indirection?

[00:06:35] You see how this is going to affect? This is a huge problem. And Casia not only have we warned some of these companies, like Kaseya about major design flaws in their software, but cause say his own engineers apparently about three years ago, warned Cacia about major design flaws in the software that they were using.

[00:07:01] So they knew about this. They were warned months, if not years in advance about it. So what does it say you do? They're concerned about profit and features, so they just keep adding features as alleged by their former employees instead of fixing the security problems. Cause it would be too hard to fix, take too long cost too much, and it isn't going to increase our revenue.

[00:07:26] Are you sitting down? Can you believe this is one of the major operators out there, major operators that is, is behind your manager services provider and your break fix shop that's who's doing it out there. So there are probably far more than that this thousand Kaseya clients that have gathered together to try and negotiate the ranch.

[00:07:57] And I got to say, I, I would be extremely disappointed if Kaseya customers didn't gather together and Sue them in a very big way. Curly sins, people claiming to be former Cacia employees are saying they warned the company about major flaws in their software. And that is what hit all of Cassias customers.

[00:08:24] Customers. This is incredible here. This is a much different style of relationship that companies have typically, right? Yeah. Okay. Law firms they'll outsource stuff, right? So let's say there's some maritime law. They'll go to a maritime law firm. They'll outsource it. So yeah, there are some models where this is done, but this is done routinely.

[00:08:49] In the cybersecurity space. It's not something we do. We stuck our toe toes into that pond and we didn't like it. We didn't want our customers to be hurt by this sort of thing. But anyway, there you have it. Okay. There, you have it all about profit and not about you. And by the way, it's also about how much you're willing to pay.

View Details

Predictions About Olympic Cyberattacks

We're all excited about the upcoming Olympic games. And so are the hackers. Oh my goodness. I just finished reading a report by the cyber threat Alliance about what they're expecting to happen at these Olympic Games in Tokyo.

The Olympics have always been a huge target when it comes to the bad guys.

[00:00:23] You might remember there have been abductions at the Olympics before where some of the Olympic competitors were held at gunpoint. Of course, we're not going to forget that one anytime soon. And looking back through the last few Olympics, there have been many different types of attacks, some more successful than others, frankly, but looking at this report, they were talking about the 2008 Beijing Olympic.

[00:00:51] The attacks then were relatively limited. There were about a 12 million cyber alerts per day. Now this is part of the problem with cyber security. You get so many alerts. What do you do? How do you. Bond and none of those 12 million cyber alerts per day resulted in a successful attack. Now that was back in 2008, there were some scams like ticket scams are always are, but nothing big.

[00:01:23] The next one was the London Olympic. In 2012 and the London Olympic, they had pretty much low level attacks and they didn't result in any real high impact cyber security event. And the most significant event back in 2012 was evidence. Credible cyber threat against electrical infrastructure. That was of course in place for those Olympic games.

[00:01:50] There was a distributed denial of service attack on the power systems. Nothing much really happened, no real impact. Then 2016 Rio de Janeiro. They were starting to pay more attention to cyber security for very good reasons. Frankly, there was a large scale denial of service attack that was carried out by this bot net.

[00:02:16] Let me explain what that is. A denial of service attack is where you might have a website for instance. Providing service to your customers that might be going there to look at your catalog, maybe buy some things. It might be a government agency. It might be an important part of the Olympics in this case and their critical infrastructure.

[00:02:37] So denied service means you either knock it off the air or so people can't get it. Or there's also the distributed denial of service attack. Now D dos are the distributed ones are where you have hundreds or thousands of computers out on the internet, all over the place that are trying to get to maybe the home page, maybe the purchase page.

[00:03:04] And because the coming from all over the internet, they're very hard to shut. And that's where we have the botnets coming in, too. Botnets are groups of computers that have been compromised by the hackers. So what they do now is they command, for instance, you're a home computer that you don't even know is under the control of one of these bad guys, your home computer now, issues or requests.

[00:03:33] Hey, yeah, give me the home page of Olympics 2020. And off it'll go dutifly and try and get the homepage. That's all well, and good. If the load on the server is what they're expecting. You've been to sites, right? You hear something mentioned on the radio and like Craig peterson.com. Now, because I mentioned my website, Craig Peterson, S O n.com.

[00:03:58] And there are people listening. Some of you guys are going to go to my website. Now the normal traffic of having dozens of new people go to my website is not going to bring the site down. However, here's the other side of this? What happens if maybe two or three times as much traffic as I expect is going to come to the site?

[00:04:22]I've compensated for that. We should be able to handle that just fine. But what happens if all of a sudden it's a thousand times what we're expecting because there's 20, 30, 40,000 cases. Peter is out there that are trying to get my homepage or in this case, the Olympic. Homepage. Obviously the server's not going to be able to respond and it's either going to crash or and I'm sure they set this up the right way.

[00:04:49] It's going to deliver a message saying the servers over loaded right now. Try again a little bit. And by the way, if you get that message on a website saying, Hey, try it in a few minutes, please try it in a few minutes. Don't just hit reload because that's going to put even more load on that poor little overloaded server.

[00:05:10] Now what they had here coming in 2016 at the Rio de Janeiro Olympics was a staggering 540 gigabytes. Per second worth of people requesting homepages. That is insane. That is a lot of bandwidth. And the fact that they apparently had that much bandwidth available coming in is also amazing, but also remember people are looking at videos.

[00:05:41] Am I. To get the insider scoop, add some stuff happening behind the scenes. Now, many of the attacks in 2016 started before the Olympic games, even. And what they were doing is attacking different parts of the Olympics infrastructure operationally. So it's a problem. It's a very big problem. They survived that whole thing.

[00:06:09] And by the way, the Brazilian government ended up trying to protect the world cup back in 2014 as well by spending a whole lot of money and time on this. But remember, Even back in 2008, we were talking about 12 million cyber alerts per day. How can you staff up for that back then? It was back then.

[00:06:32] We're seeing some of our clients being hit with hundreds of cyber attacks a minute and multiple per second, sometimes 10 20, 30. Per second. It's just incredible. What happens? In fact, divide those numbers out 12 million divided by how many seconds in a day. It just shows you how amazingly huge it is.

[00:06:56] Now we have seen time. Past where a country like North Korea, for instance, doesn't like what Sony pictures is doing. So North Korea then attacks Sony pictures. And in the case of Sony, they downloaded a bunch of confidential information. They released it. They embarrassed some people now, hardly anybody got fired.

[00:07:16] It's absolutely amazing. But anyway, What's happening right now is Russia. Think about all of the Russian attacks against our businesses and our critical infrastructure as a country, they have been huge, massive attacks. We have now Russia at a point where they are getting massive amounts of. built up.

[00:07:45] Why? Because they submitted doped samples in 2019 to the Olympic committee. Yeah. So this was a, the McLaren report released by the world anti-doping agency. Describe what we're really systematic effort by the Russian government to really undermine the drug testing process. We've also seen the Russians in the past because they've been caught doing this.

[00:08:14] And the Chinese as well, putting in some of the competitors, particularly into things like gymnastics that were too young to compete based on the Olympic rules that were in place. So we had all of this happen during, and after the 2014 Sochi winter Olympics. Guess what those restrictions on their athletes are still in place and in place in a very big way, they will not play the Russian national Anthem at the ceremonies at the Olympics.

[00:08:48] And they will not allow the Russian flag to be carried. In fact, their athletes have to carry a neutral. Flag. So expect some serious attacks from Russia against the Olympics. And remember the Olympics. There are no spectators. Everybody's going to be watching this thing on a line. So it's going to be interesting.

[00:09:14] We'll keep an eye and let you know how things go. Stick around. Visit me online. CraigPeterson.com.

View Details

Facebook Confirms Its Asking People to Report "Extremists"

Reporting on your neighbors is something you would expect from a socialist government, right? A communist government, a fascist government, any form of socialist government. Now Facebook is doing exactly that and it's going to interfere with our lives.

Facebook has now confirmed what it's calling a test of its "do-you-know" an extremist prompt and that's got me really rather worried.

And it has a lot of other people worried as well. I was talking to a friend of mine who was also in the media biz, who was saying just over the last couple of weeks. He's received this a bunch of times. And I mentioned this to another friend of mine who is not in the media business. And he said that he got it as well.

[00:00:48] And he said his was: are YOU an extremist? Which I think is interesting. First of all, extremist is not defined. And of course, with these people who are monitoring accounts on Facebook, announce where their definition of extremist is going to be. The definition of an extremist by the government going to very political parties is going to Berry very, and we're talking about this anti-extremist promt, not just asking you if you are an extremist, like my friend said he got, but it's asking if you know someone else who is an extremist or who may become an extremist.

[00:01:28] That is absolutely amazing to me. Amazing. It's bad enough that the government has picked winners. It has this whole section to 10, you've heard about before in the FCC rules that says we know if you're Facebook or Google, no one can Sue you for anything that you do. That is absolutely insane as far as I'm concerned, but there will be lawsuits on this they're already been filed.

[00:01:58] Why would Facebook block thought that it didn't think was appropriate? The whole idea behind the first amendment? Isn't just that it applies to the federal government. It is a code of conduct for all of us. It's a code of conduct for these massive multimedia platforms. We should be allowing all kinds of speech and we should not allow people to hide because what they've done now is they've moved to other platforms.

[00:02:29] The don't do this kind of monitoring and they are current carrying on their speed. If someone comes out and says something that is racist, that is violent, that is, is threatening to commit a crime. We know about it. If it's out there in the open, we all have the crazy neighbor that everybody in the neighborhood knows about because they are, and they're saying it, Facebook starting to block it.

[00:02:55]We're just not going to know. And then what do they do? If you report someone who is saying some things that you think might be extreme, things like you should check voter ID at the voting booth. There are people that think that's extreme and they report you what's likely to happen. We know already that one of the things that many people who have been doing online is reporting people.

[00:03:22] They don't like as someone who is posting things that are violent or extreme and getting their stuff blocked and demonetized in some cases, but just plain old blocked. It's a great little tool for people to shut up. Other people, just shut them down, shut them up. They can't say it anymore just because they disagree with the content that's already in place.

[00:03:48] Now what's going to happen. If someone is reported as being, not an extremist or on the road to extremism, what liability is there on Facebook's side? What liability is there with, for instance, the FBI or local one force. There are obvious things that should be reported to law enforcement. If someone's saying they're going to harm themselves or harm someone else then we need to have a closer look at that.

[00:04:14] If you actually have the belief that they will and can do that. I was as a mandated reporter for 10 years because I was in emergency medical services. If I thought someone was trying to commit harm to themselves or someone else, I was mandated to report, but I have to think that I can't just use the reporting tools as a way to shut up my political opponents.

[00:04:43] So someone reports another person as being an extremist of Facebook, Facebook then sends it to who are they going to send it to the FBI? What's the FBI going to do well. The FBI is mandated to report again in their reports and investigate. So what are they going to do for the investigation? It needs to rise to a level of the FBI thinks that this might be an illegal activity so that they can investigate it.

[00:05:11] They can hopefully stop something before it happens. Something violent, something nasty. But what does the investigation take ground? I'm taking you all the way down the road here. The investigation is going to include them having a look at what you said, looking at the people who are within your social network.

[00:05:32] So who do you. Two. Who do you follow? Who follows you? They may start looking at your phone. Who are you calling? What SMS messages are you receiving? Where are you hanging out? Where's your phone going every day? Who goes to that bar that you like to hang out at? Oh my goodness. You went to a gun range.

[00:05:50] Who's at that gun range and so very quick. The investigation is all of a sudden roping everybody and all of your family members, all of your closest friends, anybody that might've liked something that you had said recently, even though it might not have been extremist. And so now by having Facebook looking for extremists and people who might be on the road to extremism and counting on you to report them, they have opened up a can of worms.

[00:06:22] Huge can of worms and remember too, with the FBI and with others, including the NSA and the CIA, they have this multi hop rule. I think it's three hops now. So if they suspect you of something and what is suspect you, is it the fact that someone reported you as being an extremist, just because they disagree with you politically, they disagree with your religion.

[00:06:48] Is that enough for them to suspect it. So now they can monitor not just your stuff, but anyone that has talked to you or liked you and anyone that has talked to them or It doesn't take long. I think that whole Kevin bacon thing, right? Everybody in Hollywood's within five degrees of Kevin bacon. In fact, I think everybody in the United States is within five degrees of Kevin bacon.

[00:07:12] In other words, they can hop through opt to five people and connect to anyone in the country. That is absolutely huge. Absolutely huge. According to the verge. Facebook is doing this in response to the Christ church call for action campaign Christchurch. Remember in New Zealand and there was an atrocity that was committed there.

[00:07:41] These hate and dangerous organizations. That's what they're up to. They're trying to stop all of this. And it goes back to March in 2019. I think it was this attacking Christchurch. Obviously a terrible thing. People knew about this person and their radical approaches. The police have been informed, but nothing happened.

[00:08:05] So now we want even more monitoring to go on. At least Facebook does. This is really a problem. There's all kinds of bad behavior online. We hide behind our supposedly anonymity. Look at the terrible thing. Some people say online about you name it, right? Different people, kids in high school, either people in other walks of life.

[00:08:33] It is terrible. So Facebook has this support page titled what can I do to prevent rattling? Radek radicalization. There we go. I knew I could say it. It's a really good question. Yeah. They've got links on that page to life after hate exit USA program, which Facebook says help people find a way out of hate and violence.

[00:08:57] I'm all great with that. I think that's a good thing. It's not a bad thing, but now having them report people that someone. In their non-inferior wisdom decides might be hate speech or might be on a road to extremism because remember anybody that voted for Donald Trump is considered to be someone who's on the road to extremism, or is an extremist.

[00:09:22] For voting for him, the worst president ever. How many times have you heard that sort of thing? It has happened all of the time. And so we've got to be very careful about these open reporting things that are online. We have to be careful about reporting. Other people, it brings to mind two things.

[00:09:41] One is two TV shows. One is one. That apple produced and you can watch, and it's all about this guy. You were a reporter, a news anchor, and he was supposedly sexually harassing someone and yeah, he was to a degree, but the crime and the punishment was just totally out of whack. And one of my wife's favorite shows the It was the good wife and now it's a good fight.

[00:10:12] That's what it is in season five, episode three. It is delving into this in a very big way. What happens when you report someone? Should they be reported? You've got to think twice about that. Even when, again, I was in EMS, what happens if I report someone potential neglect potential child abuse here, they can go through hell.

[00:10:37] So be very careful. I don't like this move by. But you probably figured that out already, right? Hey, you stick around. We've got a lot more to talk about today and I also want to encourage you. If you haven't already go to my website, sign up for the newsletter. Craig peterson.com/subscribe and get all of the latest and most important technology news in your mailbox.

View Details

2021-07-17 1122

Craig Peterson (2): Reporting on your neighbors is something you would expect from a socialist government, right? A communist government, a fascist government, any form of a socialist government. Now Facebook is doing exactly that, and it's going to interfere with our lives.

[00:00:16] Facebook has now confirmed what it's calling a test of its "do-you-know" an extremist prompt, and that's got me really rather worried.

[00:00:28] And it has a lot of other people worried as well. I was talking to a friend of mine who was also in the media biz, who was saying just over the last couple of weeks. He's received this a bunch of times. And I mentioned this to another friend of mine who is not in the media business. And he said that he got it as well.

[00:00:48] And he said it was: are YOU an extremist? Which I think is interesting. First of all, an extremist is not defined. And of course, with these people who are monitoring accounts on Facebook, announce where their definition of extremist is going to be. The definition of an extremist by the government going to very political parties is going to Berry very, and we're talking about this anti-extremist prom, not just asking you if you are an extremist, like my friend said he got, but it's asking if you know someone else who is an extremist or who may become an extremist.

[00:01:28] That is absolutely amazing to me. Amazing. It's bad enough that the government has picked winners. It has this whole section to 10, you've heard about before in the FCC rules that say we know if you're Facebook or Google, no one can Sue you for anything that you do. That is absolutely insane as far as I'm concerned, but there will be lawsuits on this they've already been filed.

[00:01:58] Why would Facebook block thought that it didn't think was appropriate? The whole idea behind the first amendment? It isn't just that it applies to the federal government. It is a code of conduct for all of us. It's a code of conduct for these massive multimedia platforms. We should be allowing all kinds of speech, and we should not allow people to hide because what they've done now is they've moved to other platforms.

[00:02:29] They don't do this kind of monitoring, and they are currently carrying on their speed. If someone comes out and says something that is racist, that is violent, that is, is threatening to commit a crime. We know about it. If it's out there in the open, we all have the crazy neighbor that everybody in the neighborhood knows about because they are, and they're saying it, Facebook is starting to block it.

[00:02:55]We're just not going to know. And then what do they do? If you report someone who is saying some things that you think might be extreme, things like you should check voter ID at the voting booth. There are people that think that's extreme, and they report to you what's likely to happen. We know already that one of the things that many people who have been doing online is reporting people.

[00:03:22] They don't like someone who is posting things that are violent or extreme and getting their stuff blocked and demonetized in some cases, but just plain old blocked. It's a great little tool for people to shut up. Other people, just shut them down, shut them up. They can't say it anymore just because they disagree with the content that's already in place.

[00:03:48] Now, what's going to happen. If someone is reported as being not an extremist or on the road to extremism, what liability is there on Facebook's side? What liability is there with, for instance, the FBI or local one force. There are obvious things that should be reported to law enforcement. If someone's saying they're going to harm themselves or harm someone else, then we need to have a closer look at that.

[00:04:14] If you actually have the belief that they will and can do that. I was a mandated reporter for 10 years because I was in emergency medical services. If I thought someone was trying to commit harm to themselves or someone else, I was mandated to report, but I have to think that I can't just use the reporting tools as a way to shut up my political opponents.

[00:04:43] So someone reports another person as being an extremist of Facebook; Facebook then sends it to who are they going to send it to the FBI? What's the FBI going to do well. The FBI is mandated to report again in their reports and investigate. So what are they going to do for the investigation? It needs to rise to a level of the FBI thinks that this might be an illegal activity so that they can investigate it.

[00:05:11] They can hopefully stop something before it happens. Something violent, something nasty. But what does the investigation take ground? I'm taking you all the way down the road here. The investigation is going to include them having a look at what you said, looking at the people who are within your social network.

[00:05:32] So who do you. Two. Who do you follow? Who follows you? They may start looking at your phone. Who are you calling? What SMS messages are you receiving? Where are you hanging out? Where's your phone going every day? Who goes to that bar that you like to hang out at? Oh my goodness. You went to a gun range.

[00:05:50] Who's at that gun range and so very quick. The investigation is all of a sudden roping everybody and all of your family members, all of your closest friends, anybody that might've liked something that you had said recently, even though it might not have been extremist. And so now, by having Facebook looking for extremists and people who might be on the road to extremism and counting on you to report them, they have opened up a can of worms.

[00:06:22] Huge can of worms and remember too, with the FBI and with others, including the NSA and the CIA, they have this multi-hop rule. I think it's three hops now. So if they suspect you of something and what is suspect you, is it the fact that someone reported you as being an extremist, just because they disagree with you politically, they disagree with your religion.

[00:06:48] Is that enough for them to suspect it. So now they can monitor not just your stuff, but anyone that has talked to you or liked you and anyone that has talked to them or It doesn't take long. I think that whole Kevin bacon thing, right? Everybody in Hollywood's within five degrees of Kevin bacon. In fact, I think everybody in the United States is within five degrees of Kevin bacon.

[00:07:12] In other words, they can hop through opt to five people and connect to anyone in the country. That is absolutely huge. Absolutely huge. According to the verge. Facebook is doing this in response to the Christ church call for action campaign Christchurch. Remember in New Zealand, and there was an atrocity that was committed there.

[00:07:41] These hate and dangerous organizations. That's what they're up to. They're trying to stop all of this. And it went back to March 2019. I think it was this attacking Christchurch. Obviously a terrible thing. People knew about this person and their radical approaches. The police have been informed, but nothing happened.

[00:08:05] So now we want even more monitoring to go on. At least Facebook does. This is really a problem. There are all kinds of bad behavior online. We hide behind our supposed anonymity. Look at the terrible thing. Some people say online about you name it, right? Different people, kids in high school, either people in other walks of life.

[00:08:33] It is terrible. So Facebook has this support page titled what I can do to prevent rattling? Radek radicalization. There we go. I knew I could say it. It's a really good question. Yeah. They've got links on that page to the life after hate exit USA program, which Facebook says help people find a way out of hate and violence.

[00:08:57] I'm all great with that. I think that's a good thing. It's not a bad thing, but now having them report people that someone. In their non-inferior wisdom, decides might be hate speech or might be on the road to extremism because remember anybody that voted for Donald Trump is considered to be someone who's on the road to extremism or is an extremist.

[00:09:22] For voting for him, the worst president ever. How many times have you heard that sort of thing? It has happened all of the time. And so we've got to be very careful about these open reporting things that are online. We have to be careful about reporting. Other people, it brings to mind two things.

[00:09:41] One is two TV shows. One is one. That apple produced and you can watch, and it's all about this guy. You were a reporter, a news anchor, and he was supposedly sexually harassing someone, and yeah, he was to a degree, but the crime and the punishment were just totally out of whack. And one of my wife's favorite shows It was the good wife, and now it's a good fight.

[00:10:12] That's what it is in season five, episode three. It is delving into this in a very big way. What happens when you report someone? Should they be reported? You've got to think twice about that. Even when, again, I was in EMS, what happens if I report someone potential neglect potential child abuse here, they can go through hell.

[00:10:37] So be very careful. I don't like this move by. But you probably figured that out already, right? Hey, you stick around. We've got a lot more to talk about today, and I also want to encourage you. If you haven't already, go to my website, sign up for the newsletter. Craig peterson.com/subscribe and get all of the latest and most important technology news in your mailbox.

[00:11:04]Craig Peterson: We're all excited about the upcoming Olympic games. And so are the hackers. Oh my goodness. I just finished reading a report by the cyber threat Alliance about what they're expecting to happen at these Olympic Games in Tokyo.

[00:11:22] The Olympics have always been a huge target when it comes to the bad guys.

[00:11:28] You might remember there have been abductions at the Olympics before where some of the Olympic competitors were held at gunpoint. Of course, we're not going to forget that one anytime soon. And looking back through the last few Olympics, there have been many different types of attacks, some more successful than others, frankly, but looking at this report, they were talking about the 2008 Beijing Olympic.

[00:11:56] The attacks then were relatively limited. There were about 12 million cyber alerts per day. Now, this is part of the problem with cybersecurity. You get so many alerts. What do you do? How do you? Bond and none of those 12 million cyber alerts per day resulted in a successful attack. Now that was back in 2008; there were some scams like ticket scams are always are, but nothing big.

[00:12:27] The next one was the London Olympics. In 2012 and the London Olympics, they had pretty much low-level attacks, and they didn't result in any real high-impact cybersecurity event. And the most significant event back in 2012 was evidence. The credible cyber threat against electrical infrastructure. That was, of course, in place for those Olympic games.

[00:12:55] There was a distributed denial-of service attack on the power systems. Nothing much really happened, no real impact. Then 2016 Rio de Janeiro. They were starting to pay more attention to cybersecurity for very good reasons. Frankly, there was a large-scale denial of service attack that was carried out by this botnet.

[00:13:21] Let me explain what that is. A denial of service attack is where you might have a website, for instance. Providing service to your customers that might be going there to look at your catalog, maybe buy some things. It might be a government agency. It might be an important part of the Olympics in this case and their critical infrastructure.

[00:13:42] So denied service means you either knock it off the air, or so people can't get it. Or there's also the distributed denial of service attack. Now DDOS are the distributed ones where you have hundreds or thousands of computers out on the internet, all over the place that are trying to get to maybe the home page, maybe the purchase page.

[00:14:09] And because they coming from all over the internet, they're very hard to shut. And that's where we have the botnets coming in, too. Botnets are groups of computers that have been compromised by hackers. So what they do now is they command, for instance, you're a home computer that you don't even know is under the control of one of these bad guys, your home computer now, issues or requests.

[00:14:37] Hey, yeah, give me the home page of Olympics 2020. And off it'll go dutifully and try and get the homepage. That's all well and good. Suppose the load on the server is what they're expecting. You've been to sites, right? You hear something mentioned on the radio and like Craig peterson.com now, because I mentioned my website, Craig Peterson, S O n.com.

[00:15:03] And there are people listening. Some of you guys are going to go to my website. Now the normal traffic of having dozens of new people go to my website is not going to bring the site down. However, here's the other side of this? What happens if maybe two or three times as much traffic as I expect is going to come to the site?

[00:15:27]I've compensated for that. We should be able to handle that just fine. But what happens if all of a sudden it's a thousand times what we're expecting because there are 20, 30, 40,000 cases. Peter is out there that are trying to get my homepage or, in this case, the Olympic. Homepage. Obviously, the server's not going to be able to respond, and it's either going to crash or and I'm sure they set this up the right way.

[00:15:53] It's going to deliver a message saying the servers overloaded right now. Try a little bit again. And by the way, if you get that message on a website saying, Hey, try it in a few minutes, please try it in a few minutes. Don't just hit reload because that's going to put even more load on that poor little overloaded server.

[00:16:15] Now what they had here coming in 2016 at the Rio de Janeiro Olympics was a staggering 540 gigabytes. Per second worth of people requesting homepages. That is insane. That is a lot of bandwidth. And the fact that they apparently had that much bandwidth available coming in is also amazing, but also remember people are looking at videos.

[00:16:46] Am I. To get the insider scoop, add some stuff happening behind the scenes. Now, many of the attacks in 2016 started before the Olympic games even. And what they were doing is attacking different parts of the Olympics infrastructure operationally. So it's a problem. It's a very big problem. They survived that whole thing.

[00:17:14] And by the way, the Brazilian government ended up trying to protect the world cup back in 2014 as well by spending a whole lot of money and time on this. But remember, Even back in 2008, we were talking about 12 million cyber alerts per day. How can you staff up for that back then? It was back then.

[00:17:37] We're seeing some of our clients being hit with hundreds of cyber attacks a minute and multiple per second, sometimes 10, 20, 30 per second. It's just incredible. What happens? In fact, divide those numbers out 12 million divided by how many seconds in a day. It just shows you how amazingly huge it is.

[00:18:01] Now we have seen time. Past where a country like North Korea, for instance, doesn't like what Sony pictures are doing. So North Korea then attacks Sony pictures. And in the case of Sony, they downloaded a bunch of confidential information. They released it. They embarrassed some people now; hardly anybody got fired.

[00:18:21] It's absolutely amazing. But anyway, What's happening right now is Russia. Think about all of the Russian attacks against our businesses and our critical infrastructure as a country; they have been huge, massive attacks. We have now Russia at a point where they are getting massive amounts of. built up.

[00:18:50] Why? Because they submitted doped samples in 2019 to the Olympic committee. Yeah. So this was a the McLaren report released by the world anti-doping agency. Describe what we're really systematic effort by the Russian government to really undermine the drug testing process. We've also seen the Russians in the past because they've been caught doing this.

[00:19:19] And the Chinese as well, putting in some of the competitors, particularly into things like gymnastics that were too young to compete based on the Olympic rules that were in place. So we had all of this happen during and after the 2014 Sochi winter Olympics. Guess what? Those restrictions on their athletes are still in place, and in place in a very big way; they will not play the Russian national Anthem at the ceremonies at the Olympics.

[00:19:53] And they will not allow the Russian flag to be carried. In fact, their athletes have to carry a neutral. Flag. So expect some serious attacks from Russia against the Olympics. And remember the Olympics. There are no spectators. Everybody's going to be watching this thing on a line. So it's going to be interesting.

[00:20:19] We'll keep an eye and let you know how things go. Stick around. Visit me online. Craig peterson.com.

[00:20:27]We have really in front of us a critical warning. We're trying to figure out what we should do or to stop people from attacking us. That's a problem. What should we do? Many of us have gone out to managed services providers, and now they have let us down. Did you hear about the Kaseya hack?

[00:20:47] It has been a huge impact on people. It's absolutely crazy. Or you heard about a thousand companies that got together, and they have hired a negotiator in order to negotiate the ransom with the bad guys that have ransom there. It is huge. It's huge. But let's talk about why this happened, because I think there are many things that you and I have overlooked here over the years; this ransomware God guy, gang called REvil, R E V I L has targeted cause say, or customers through.

[00:21:32] Say, but it isn't just kissy customers. It's really cause, say, it is customers for the most part. Now your head might be spinning a little bit, but here's what's happening. I'm a business owner. You guys know that right now. Let's say that I don't do cybersecurity for businesses. That's what I do.

[00:21:52] But let's say I make a widget. I was a widget maker, do not have enough knowledge about computers, to really do it myself. So let's say I've grown and I've got 20 employees. The odds are very good that my office manager is the one in charge of the computer. The office manager probably orders.

[00:22:17] Computers probably tries to figure out what's going wrong. By the time of it at 50 computers or 50 employees, I've probably got a full-time it person who goes around and tries to take care of things. But before I've got that full-time IT person I'm probably going to outsource it. And by the way, a lot of companies, it's more like a hundred to 200 employees before they get someone who's really dedicated to it.

[00:22:46] So then that awkward teenage stage between where the office managers trying to do it. And finally the office manager can try and hire an it professional. Is where they go and outsource it. You talk to various types of companies. What are in the industry called break, fix shops. That's usually the first stop which is calling them up saying I've got a broken computer.

[00:23:12] Can you fix it? And maybe they can, maybe they can't. And then a lot of break fix shops have tried to level out their income so that they have predictable monthly income so that they can hire the right number of people for the number of customers that they have. Although I've got to say most of them are badly overbooked.

[00:23:32]Now that they've hired those people, they this outsource break fix shop. They come in and say, okay here's what we can do for X amount per month per computer or employee, we will take care of those computers for you. One of the things that they'll promise to do is that they will take care of your cybersecurity for you.

[00:23:53] Now, cybersecurity is frankly, a specialty. It is not something that everybody can do. Even if you're using some of the best stuff in the world, like what we do, we have Cisco hardware, we have Cisco software that we run advanced malware protection. So that's the best of the top of the line.

[00:24:13] Most smaller businesses aren't going to want to pay for it, even though they might be able to afford it. Push those people out right now, because we're talking about, you were talking about a smaller business. So what does that outsourced it provider do for you? They might change their name and call themselves a managed services provider.

[00:24:34] And that's all well and good, but they need help as well. So I'm making widgets. I have this break fix shop that came in and fixed my computers a few times. And now they're handling my cyber security. Isn't that wall well, and goods was wonderful. So now they're handling, supposedly my cybersecurity. But they know they can't do it themselves and it would be too expensive to do it because they went cheap.

[00:25:01]You bought the least expensive option or, close to the least expensive option. So wait, and by the way, cheap in this case means that it's under $150 per. Person slash workstation per month. That's what it costs to get this stuff done. So you might be paying 25 or maybe even $50. They can't do it for that.

[00:25:25] So what do they do? They go to a company like. Now they also have some others. They have what are called arm AMS that keep track of some basic stuff for you, but they go to Garcia and say, okay, Casia we want you to monitor the computers, keep them up to date, et cetera for. Now did I, the widget manufacturer go ahead and hire to take care of stuff.

[00:25:51] Did Kasiah even do it themselves or did they outsource it? Do I even know the Kaseya exists because it's really Kaseya that is managing my computers doing. We have, there has a software that doing the upgrade on my computers. This is a real problem because the widget maker, Nope, I didn't hire KSA. I didn't even know they existed.

[00:26:17] I trusted my local. Your local guy is not taking care of your cybersecurity. Almost completely guaranteed. There's very few companies like mine out there that we actually do it ourselves because we have looked at Kaseya. We've looked at all of these platforms. Every last one of them has had major problems.

[00:26:40] So here comes Casia with over a hundred thousand customers that gets hacked and distributes the hack to all of its customers that are running some of these on-premise devices that are trying to manage the networks for not Cassias clients, but for KSA as clients, client. Okay. Do you see how this is the level of indirection?

[00:27:03] You see how this is going to affect? This is a huge problem. And Casia not only have we warned some of these companies, like Kaseya about major design flaws in their software, but cause say his own engineers apparently about three years ago, warned Cacia about major design flaws in the software that they were using.

[00:27:29] So they knew about this. They were warned months, if not years in advance about it. So what does it say you do? They're concerned about profit and features, so they just keep adding features as alleged by their former employees instead of fixing the security problems. Cause it would be too hard to fix, take too long cost too much, and it isn't going to increase our revenue.

[00:27:54] Are you sitting down? Can you believe this is one of the major operators out there, major operators that is, is behind your manager services provider and your break fix shop that's who's doing it out there. So there are probably far more than that this thousand Kaseya clients that have gathered together to try and negotiate the ranch.

[00:28:25] And I got to say, I, I would be extremely disappointed if Kaseya customers didn't gather together and Sue them in a very big way. Curly sins, people claiming to be former Cacia employees are saying they warned the company about major flaws in their software. And that is what hit all of Cassias customers.

[00:28:52] Customers. This is incredible here. This is a much different style of relationship that companies have typically, right? Yeah. Okay. Law firms they'll outsource stuff, right? So let's say there's some maritime law. They'll go to a maritime law firm. They'll outsource it. So yeah, there are some models where this is done, but this is done routinely.

[00:29:17] In the cybersecurity space. It's not something we do. We stuck our toe toes into that pond and we didn't like it. We didn't want our customers to be hurt by this sort of thing. But anyways, there you have it. Okay. There, you have it all about profit and not about you. And by the way, it's also about how much you're willing to pay.

[00:29:41]Did you know that Amazon has a new CEO? I remember back in the nineties, I pledge that I would never use Amazon again because they filed and were awarded a patent on technology everybody was using. Jeff Bezos is out of a job.

[00:30:00] This is a guy that grew a company that all they did initially really was book sales and they had a warehouse the size of the Amazon, right? Because they wanted to represent everybody. They had every book ever published and to a large degree. They did. They had a whole lot of bucks and then I've expanded of course, beyond that.

[00:30:28]And beyond that, to the point today where they are doing some well, again, shady things I mentioned in the intro that I was concerned about what Amazon was doing with pat. They got a patent on this one click purchase. Now I have been a fan of patents for a long time. I do not like the patent law as it exists today.

[00:30:55] And in fact, I haven't liked it for quite some time, but this patent law where you don't have to show that there was no prior art and frankly, the prior art does not matter at all. I think that's a huge. And I've had a number of patent attorneys on my show, talking about it and talking about what we may want to change.

[00:31:18]Jeff Bezos grew it to today where it really is the number one provider of online services is. You might in fact, almost certainly are using Amazon's services, whether you realize it or not to go to most, any website, any of the big ones they're probably using Amazon's web services. They're probably using Amazon storage and Amazon has dozens and dozens of different services.

[00:31:50] So it's a very big deal. And Jeff Bezos, who's the guy that started all of that sat down stepped on. I should say. Now it's rare that the founder of a company ends up taking the company public. Public, basically, that just doesn't really happen because all of a sudden, when you're public, your whole job changes and no longer can you make a decision, a snap decision about something, and then go ahead and do it.

[00:32:18] You've got to be very careful about what you do when you do it, how you do it, you have to announce it and everything, but just an amazing man being able to take it. All of that. And by the way, have the largest settlement, a divorce settlement in history with his ex wife. It's amazing, but he is still the world's richest human.

[00:32:40] Now he has this company called blue origin, which is his rocket company. He's got the Bezos earth fund and he's still chairman of Amazon's board. So he's not going anywhere. However, we've got this new guy, Andy Jassy, who has stepped in as the CEO of Amazon. He was the the head of Amazon's.

[00:33:06] Online services, which is absolutely huge. It's their most profitable arm by far. So he's taking this whole thing over when Amazon frankly, is in a lot of trouble. Now they're basics of, Hey, there, the money that they're making, their profits and everything, that's all well and good, but there's ongoing antitrust investigations.

[00:33:33] There's battle with labor. And we're talking about, of course, big labor here. The unions. There's increased competition in the cloud space. Just look at what happened with the us military in there. I think it was at least a billion dollar. I can't remember the exact number, a cloud contract because Amazon was battling Microsoft Azure and it was awarded.

[00:34:01] And then just a couple of weeks ago it was pulled back again. They're also seeing increased competition in their online services from Google. And I use some of those Google services. In fact, if you go to Craig peterson.com, it's actually right now using some of those Google services. So they are really getting nailed from a whole bunch of different directions.

[00:34:26] And this guy Jassy has worked there since 97. But he may be the perfect person to guide Amazon through. W really now we're talking about the middle-aged, that's the time when you're supposed to buy your convertible, buy your motorcycle, et cetera. The middle aged years. And in this case, there's some problems.

[00:34:51] Here's a quote I want to read from this Yahoo article is actually I think AP yeah. Yahoo finance. This Yahoo article and it's from Harvard business school, because we've got regulators who are circling, and this may be the main reason Jeff stepped down. I don't know, but quote, you may want somebody who has the confidence of the chair.

[00:35:16] And the board you want somebody who understands the strategy and was part of it and knows where the bodies are buried and the mistakes that have been made and how to move forward. This is from Harvard business school, professor of business administration. Rosabeth Moss Kanter, and I think she's right.

[00:35:39] Absolutely because this road ahead for him is going to be tough. But the fact that he ran their most profitable division tells you something, it tells you a lot and he might be the exact right guy to be able to do that. Amazon's now got a market capitalization of about $2 trillion, which is huge.

[00:36:01] And it's certainly enough to get some of these regulators. Paint a lot of attention to what's going on. We've got the Washington DC attorney general, who has accused them of violating the district of Columbia's antitrust act. And that has to do with, for bidding third-party resellers, from offering cheaper rates for their products on competing sites.

[00:36:24] Cause remember what Amazon does. About half or more. In fact, I think now of their products are not actually sold by Amazon. They're certainly not Amazon products. They are products from resellers who are just selling on Amazon. They're using Amazon is their platform. And that way Amazon will manage the inventory.

[00:36:47] It'll warehouse a little ship it out. It'll handle the returns. Yeah. What Amazon is doing is charging these sellers for the space in the warehouses, which is perfectly legitimate and taking a percentage of the deals. Are there other websites that might give these sellers or resellers or stuff they're importing from China or wherever.

[00:37:12] Might there be other sites that give them better deals? Will you bet there are sites out there. So that's why she's suing them. Federal regulators look like they might be coming in as well. The federal trade commission's newly appointed chairman. She's a fierce critic of the. Amazon way of doing business and she made herself a name by publishing an article for Yale's law journal titled Amazon's antitrust paradox.

[00:37:42] So before she was even appointed to the federal trade commission, she was already calling for changes in the current antitrust regulatory framework. And that might be widely invited administration has appointed her, but there's six antitrust bills. Targeting big tech right now that are working their way through the house of representatives.

[00:38:05] And we've talked about some of those already, and, I do not like these huge tech companies that are making crazy profits and using those profits to keep other people out. And Amazon's one of the largest employers in the country. And after years of complaints from somewhere house workers, we've got the labor unions now in the mix trying to take action.

[00:38:30] Now, I don't have a single problem with labor unions while at some of their tactics, I have problems with, I don't have a problem with the labor union. In the private space. I have a huge problem with I'm in government space. And we could talk about that at some point, but I don't have a problem with them trying to organize inside Amazon.

[00:38:53] So the international brotherhood of Teamsters. Yeah. I remember the guys that drive the horses. They announced that they're going to begin working to organize Amazon workers. So that might succeed. There was another one in Alabama that had failed. So are you getting the hint here? This is huge. It's huge.

[00:39:13]By the way, Amazon's offering warehouse workers starting pay at $15 per hour plus benefits. So that doesn't seem too bad. If you ask them. But again, with the pandemic, all of the stuff going on there been a lot of calls for Amazon to quote, treat its workers better. So we'll see. We'll see what happens.

[00:39:34] Other problems with Amazon that we've talked about before are things like fake reviews. You and I, we look at the reviews, it's critical in us buying things. Isn't it. We look at the reviews and say, oh, wow. Jeepers. There's 500 reviews here and it's four and a half stars. Okay. So I can have confidence that this product is good.

[00:39:58] It's going to work. And yet some of these sellers, what they're doing is bribing people to give a good review. So they'll say, Hey, you buy my product. And then they send the product in with, along with the product is a little note saying, Hey, if you give me a review and send me a link, I'll send you an extra battery or whatever it might be.

[00:40:20] That has been a real problem for Amazon, even worse than that, because at least those people might give an honest review, right? Worse than that is that some of these reviews are paid for. So some of the sellers it's alleged are going out there. They are hiring. People and paying them to give reviews. Now, those ones are very obvious.

[00:40:45] If you look at the reviews, so don't just look at there's 500 and the average is 4.5. Look at some of the reviews in the wording. So I've seen reviews where it was for a massager, and there was talking about what a great. A set of wheels that has on it. And they work really well. And it's very smooth when you're out, riding it on the trails.

[00:41:08] Wait a minute wait, we're talking about a massager here. We're not talking about a bicycle, so that's one of the ways to tell if the reviews are fake, they're don't even talk about the product at all, or any of its real features. The other one is look at the wording because most of these fake reviews.

[00:41:26] Don't use English, so good. All right. Okay. Thanks for being with me. I want to make sure you stick around and visit me online. In the meantime, go to Craig peterson.com. If you sign up for my free newsletter, you'll be getting that every week with all of the details. I'll try and catch you up and you can listen to my podcast, right from there.

[00:41:50] Craig peterson.com. That's Peterson with an O.

[00:41:56]If you look into buy a used Google pixel for a I got some news for you. The FBI has been very busy and they've conned the con man. I love this story. The FBI has, been trying to track bad guys for a very long time and there've been a number of ways they've done it.

[00:42:19] We know obviously about phone taps, right? We've seen those before the old days. I don't know if you've ever been to one of the original. Telephone switching stations, all not even original, but the types they had in the late sixties, early seventies. I remember going to see one and all of these switches were just going

[00:42:40] People were dialing the phones and everything. It was just so cool. And back then, in order to trace a phone call, what they had to do is find the original. Sore. So they would go to that row, that column, that exact little unit that was hooked up directly to your phone. And then they would see, okay, this is in position this, and then go to that next switch.

[00:43:04] Okay. Position that next switch, position that and go all the way through. That's the really older days, not the old days where you had somebody that was at a switchboard doing it. Nowadays, of course, it's all done by computers. The telephone company turns your voice into a digital signal and it's usually done right in your local neighborhood.

[00:43:26] It isn't even done at the central office anymore. So by the time your voice is outside the central office, it's digital it's hauled on nowadays, even partially an internet protocol. Network. They used to use different protocols back in the day. And so it makes it quite easy for them to tap your line. Now, of course, there's the legal side of this.

[00:43:50] Do they have the legal right to do it to the need a court order or what kind of a court order? Do they need right. All of that stuff. But that is side. It's very easy to find out where call went, where it came from and to listen in because it's just digital. Data's completely completely copyable with absolutely no particular problems at all in copying it.

[00:44:14]Last month. The FBI and the Australian federal police acknowledged that they had indeed been working on this encrypted device. And the company was called a nom, which is a fake company and a nom sole. 12,000 smartphones to criminal syndicates around the world. That's the wording that the police used.

[00:44:42] So these were being sold as secure devices. They did things like they removed the cell leader, modem functionality they'd changed the boot ROMs. They removed the GPS. So the idea was, Hey, you missed your badge. You can use one of our Anom phones and it's using a special version of the Android operating system and you can send messages back and forth.

[00:45:07] It's a completely secure messenger service end to end encryption, right? Like we're always being promised. And so what happened is bad guys started referring. Bad guys to this, right? Cause if they wanted to talk to the other guy, they both needed these Anom phones. Otherwise they wouldn't be able to talk to each other.

[00:45:28]And so they were recommending the use of these phones, to their friends that were in the illegal businesses as well. So this I'm just chocolate is so great. So the FBI weaponized. Android phones, at least this particular model of it. And there's a whole community in the Android world. It doesn't exist in the iPhone world because this is much harder to do in the iPhone world, but they call themselves the model.

[00:46:00] Community. And so they'll get a phone from some vendor. They'll make some changes to it that led to maybe change networks or do other fancy things. So they, after BI used some of this technology. The modding community and did some just amazing things with this custom rom. Now you're going to love this part.

[00:46:21] Okay. So when you boot this phone up, this is according to ARS Technica. The phone will have of course, a little boot screen and. The highest custom rom here, which is the boot loader as well as other things, but it showed an arcane, oh, S boot screen that's the name, arcane O S and every place, the normal Android distribution that comes from Google with the.

[00:46:48] B I's arcane. Oh, west green. It's just absolutely phenomenal that these guys would do this and would fall for it. So the FBI told the criminals, Hey alleged criminals, Hey, these are secure devices, the really focused on security and there is a pin scrambling fee. What would happen is on your phone?

[00:47:11]You might enter pin some phones, you might use a fingerprint, or he might use a face ID. This was a security feature. And what happened is normally you've got what, 1, 2, 3, 4, 5, 6, 7, 8, 9, 0. And you type in your pin and off you go, what this did, is it scrambled it? So it might be nine to.

[00:47:31]Just the scramble of the digits up so that when you enter your pin, you're not always touching the screen in the same place so that people could not guess your code from the fingerprints you're leaving behind. Now, this is also interesting. It, this is a great way to do it. If you're doing it for real, having to run an anonymous phone, they had two different interfaces on the phone and it a different one would pop up depending on. Pin you typed into the lock screen. So the first pin would show a bunch of non-functional apps that are pretty popular in the app store, like Tinder, Instagram, Facebook, Netflix, candy crush games.

[00:48:15] So if somebody is checking out your phone, forcing you to unlock it, they're not going to find budge. And by the way, none of those things work. But. I would have, if I had designed it, I would have made them so that they would work. So you can fool some of us trying to Rob you and steal your phone.

[00:48:28] The second pin that you could enter in, tell you chose your pins, but it was supposed to be the secure section. She didn't have the phone. So it had a clock, a calculator, and the settings. But the calculator app actually opened a login screen to a nom as an anonymous. And that, again, the bad guys are told all that's a secure, encrypted way to chat.

[00:48:54]This is just amazing. So they will do use that. So they go into the calculator app and now allowed them to chat with their friends. But what they did not realize. Is, it was actually sending all of the messages also un-encrypted to the FBI. Okay, absolutely amazing. Amazing. So now some of these bad guys are selling their phones online.

[00:49:25] I remember I warned you at the very beginning. If you're going to buy a pixel for a you want to listen to this first because the bad guys are selling. Their phones online. And so a number of people have been trying to figure it out. Some posts on Reddit and elsewhere. You guys know how to deal with this arcane.

[00:49:44] S how can I reset this? What should I do? Okay. A lot of confused people. How do I fix this thing? You're not going to be able to fix it. Okay. By the way, this thing I think is really cool because the guy who he bought it legit guy bought it use. You said the installed operating system is arcane O S 10.

[00:50:03] The system updater says that Archana, YC 11 is available for download, but I don't want to do it in case it makes something even harder to fix. So maybe the FBI is bad. At sending out updates and fixes, then most of the Google Android vendors that are out there and I'm just laughing all the way through here.

[00:50:24]So there are some things that a tech savvy user should know. So I want you guys to pay attention to this, particularly if you're using an Android device. So the first thing is when you start up a newer Android phone, when it's made in the last few years, The first thing that happened is that Google runs something called verified boot, and that makes sure the operating system has not been modified.

[00:50:55] So the operating system from the manufacturer of the device will be signed using a cryptographically secured. What was happening here is these devices were failing verified boot of course, because FBI had modified the boot ROMs. And if your device fails, verified boot, your Android device either could be an unlocked boot loader or a relaunch boot loader with tampered software.

[00:51:24] It's going to show a message. And in, in this case, the FDA FBI devices just have a message that says your device is loading a different operating system, complete with their yellow exclamation point icon and a link for Google support pages. Absolutely phenomenal. And by the way, the article I'm sending this out in my newsletter, but it says.

[00:51:51] How resistance changes. Google has an order. So it sent them to the legitimate Google support. So there you go. There's a really good little piece of advice right now. The FBI changed a lot of the Android operating systems, tripped out a whole bunch of Android settings that might've revealed something about the fact that it really was a spy device system settings for app storage and accounts have been removed.

[00:52:19] So pay attention, right? If the machine, if your machine boots up, plane's about the bootloader, you've got a problem and it isn't just Android. Obviously apple will do that. The newer versions of windows are starting to do that as well with TPMS and windows 11 is really going to bring a lot of that to the forum.

[00:52:41] Hey, you're listening to Craig Peterson and you can find me online. Craig peterson.com. Check it out and stick around.

[00:52:50]Work from home is a very big deal, especially for a couple of segments of our society. And I want to talk a little bit about that now, as employees are returning to work, should they be returning to the office?

[00:53:06] There is a great article here this last week in Forbes magazine by Dana Brownley. And it was one of their editors pick and it was picked I think for very good reason. And that is so many of us have been working from home. And for many of us.

[00:53:24] Bennett godsend. I've worked from home now for over 20 years. And for me, it's been a godsend because my priority was helping to raise our eight children. And it's hard to do that, and it's hard to homeschool to them if you are not at home. So that's what I had done. And I was very privileged to be able to do that.

[00:53:45] And our kids have all turned out amazingly. Many people are caregivers and it isn't necessarily just of kids. But right now I'm looking at a survey that was conducted. It's called the Prudential May, 2021 pulse of the American worker survey. And they're showing the 2000 respondents that 38% identified themselves as caregivers with nearly 40% of those providing care.

[00:54:16] For school, age children when you are starting to look at benefit packages, it is important for many families to be able to have some form of childcare. And what has snuck in because of the lockdown is that many of us actually can work from home. Many of us have been more productive at home. And then on top of it, all we can take.

[00:54:43] Of our family. So let's look at the stats. We told you about school age children. That's about 40%, 32% are taking care of young children. And this is the 40% of all workers. Okay. People 30% are caring for someone with a disability, some sort of a health issue. And 23% are taking care of an older adult.

[00:55:10] That's 40% of the workforce. That is a lot of people. A lot of people, 38% is the exact number. So there, many of these care givers are returning. Really a traditional work environment where they're going to the office, but they have very unique needs. And I think every last one of us have to consider that and have to look at it and figure out how can we make things work.

[00:55:41] And when we look at the numbers again for the caregivers, 45% say that they've considered leaving the workforce entirely. Due to personal demands. And 53% are saying that they would retrain for a career in a different field or industry. If they had the opportunity, we have some of our best people out there that are taking care of our kids of our loved ones.

[00:56:12] Our parents. And again, look at mine, a situation here where I was at home helping to take care of our kids along with my wife. Neither one of us could have carried on a regular job and homeschooled, eight kids. Neither one of us could have done that. What kind of talent might we be losing? By squeezing these people out of our workforce, particularly when we've now proven that most businesses can allow their workers to work from home.

[00:56:48] Now they found in the survey that there were three primary types of support caregivers and these types are looking for different types of flexibility. Number one, they're saying that 42% wanted increased workplace flexibility. No, that makes a whole lot of sense, right? So they can work from home.

[00:57:11]Maybe some of your best employees or people who want to work in another part of the country. I have a friend, his brother-in-law is a real good programmer in this one particular type of programming. I think it's sales and he is living there now in a completely different country on the other side of the world.

[00:57:33] And yet. He's still doing programming for these people here in the United States, talking about workplace flexibility. He is sitting over there not far from China and is enjoying himself. He loves it there. And of course his costs are much lower, et cetera, et cetera. So consider that, not just that there might be working from home, but maybe they want to take the kids over to Europe, live there for six weeks.

[00:58:01] There's a lot of things people want. So that's 42% of our people that are working. Okay. Increased workplace place. Flexibility. The number two increased paid time off 38%. Again, something we got to seriously consider. Now I know how hard it is to be able to fill in for someone that's on vacation or. Maybe they're caring for a loved one.

[00:58:28] Maybe they just had a baby, et cetera, but it's very important when you get right down to it. Because again, who's better for raising our children, us, or a stranger who's going to more or less warehouse them. You have to keep a look at that. There's a great article from the Harvard business school.

[00:58:50] It's titled. COVID killed the traditional workplace. What should companies do now? That's a very good question because now the lockdown is mostly behind us. Executives can't expect the offices to run the same way they did people to come in and do the same things that they always did. But in reality, Harvard business school, faculty members are saying there are ways to keep our employees happy and productive.

[00:59:22] And that is exactly what we're talking about. No for many caretaker takers caregivers, I should say paid time off is more valuable than a pay increase. And that's particularly true for those who are at the higher end of the pay scale. It gives them a lot more flexibility. They can get away sometimes from all of their responsibilities and obligations, which is just so important.

[00:59:48] There's here's another one. This is a job list survey from CNBC. The articles entitled here's how much money workers would give up for better. Life balance. And they go in, in that particular article and say that the average worker who says they currently have work life balance, it would take an extra $10,000 in pay per year for them to give up their personal time.

[01:00:11] I'm not sure that's right. I think it would be a lot more than that. And it also says just 30% of workers said, they'd give up part of their pay for better work-life balance. And the threshold varies by the type of worker that's where we, I think really get into it now. So those are the first two, the third one is 37%.

[01:00:32] So these are all within 4% of each other. Greater commitment to health and wellbeing. Now I've seen studies before that are saying businesses that put in a gym and put in workout rooms, et cetera. They never actually see them use. The way they expect for them to be used. And I don't think that's what people are talking about here, but we really are thinking a lot more about health and wellbeing since so many of us have been scared because of the COVID outbreak, but maybe I should be paying more attention to our health.

[01:01:07]But we also have the mental health look at all of the problems we've seen from so many mental health issues because of the. Down. So Harvard again, came out and said for employers, it means that we need to signal the health of facilities. It's crucial to attracting people back. So again, The right kinds of air filters, right?

[01:01:30] Kinds of lighting, make sure people feel safe while they're in the office and maybe cut back the number of days that they have to be there. Hey, stick around. We'll be right back. We got a lot more to cover. You're listening to Craig Peterson, of course, and visit me online. Craig peterson.com.

[01:01:50]Hey, we got another emergency patch out from our friends at Microsoft. And in this case, it has to do with printers and remote printer access. Do you have employees working from home?

[01:02:05] Microsoft has their big monthly patches that they release. They also have weekly patches that they released that are for slightly more critical vulnerabilities. And then they have. Patches that are released because there is a severe problem going on right now while that's what we are staring down.

[01:02:31] There is a vulnerability called print nightmare, and this is located in the windows print. Spooler serve. Now the windows print spooler services, what it sounds like. This is the service that handles all of your print jobs. So if you are using this service, Turns out there's a serious bug and Microsoft tried to patch it once and failed.

[01:03:01] And they've got another patch out right now seems to be working, but organizations are really urged to deploy these patches as soon as possible or deceased. Inbound remote printing until they can be applied. So that's why I said, if you have people who are working from home, because many of us turned on remote desktop and you better make sure that's properly patched up so that people could.

[01:03:28] Then and get a desktop. Although Microsoft has an interesting solution that is going to be announced in early August about having your own windows machine there in their cloud. So it looks like you'll be able to have windows machine for about 35 bucks a month. Microsoft will have to keep it up to date.

[01:03:47] I think that's a very cool thing, but they're coming out with that here very shortly. Within the next month or so, we'll see what happens, but this is a problem because if it's exposed to the internet, We're expecting to actually already be seeing active exploit. Now here's the problem Microsoft's trying to solve.

[01:04:10] We have three different types of patches. You have the monthly patches that they release. You have your, which of the patch Tuesday. You also have patches that are released every week, which are more critical. And then these types of patches, these are patches for what are called. Zero day attacks. There is nothing normal out there, a regular stuff that would catch this and stop it.

[01:04:37] Now, the advanced malware protection that we use from Cisco, it will catch this sort of thing, but it'll only catch it after it's been seen a few times and then identified, obviously by now it's been identified. So it's pretty darn cool. So Microsoft's monthly updates. Last month included a patch for another vulnerability in the windows print spooler service.

[01:05:02] And it was initially called a local privilege ex escalation issue. That means that you had to be on that computer in order to gain access to these advanced privileges and features. Turns out that it wasn't entirely just local. And now there is a new one where it can be exploited to get remote code execution and not just privileged privilege, escalation.

[01:05:30] That means that they can now run programs on your computer. And with privilege escalation, they can run those programs as whomever they might want to do. So this is pretty big Blackhat USA conference coming right up and they are going to be hosting one of their talks called diving into spooler and what they did to discover these local and remote.

[01:06:00] Vulnerabilities in the windows print spooler Hey, it's definitely a problem. There is a proof of concept exploit out there, and that means that the bad guys are not too long from coming up with their own. So there you go. Again, patch it up close and remote access, at least for the time being. To your print spooler because it could be a very big deal.

[01:06:25] Another thing you could do is disable the prince Pooler service. You can just use stop service dash name spooler dash force, and that will. Pop it right on down. Okay. And then by the way, in case your machine reboots, you probably wouldn't do a set service dash named spooler dash start-up type disabled in order to make sure it doesn't restart, but there'll a lot to worry about right now, a whole lot, frankly, to worry about right now because of the Russians are coming.

[01:06:57] Here's another one. This is Chevy bolt. Now, I have had some major complaints about Tesla and the way Tesla has these door handles that recess in entirely and how it has happened that during an accident, those door handles don't pop out and people cannot be extracted from cars. And the biggest problem you have in an accident with a car full of batteries is.

[01:07:24] Of course the high voltage and current that's stored in the batteries that now when they, it out, it starts a toxic fire. Very nasty. Just this week, the national highway traffic safety administration issued an alert for all 2017 to 2019 Chevy. Owners now I know a lot of these bolt owners are actually government agencies.

[01:07:50] They're not individuals, but I thought I'd bring it up. Anyways. There was a fire in a Vermont state representatives. Car's name's Timothy Brown. And his Chevy bolt decided it was going to catch on fire. Now, there was a recall by GM of these Chevy volts that had this problem, and apparently it doesn't entirely.

[01:08:17] Fix it, they are still plaguing GM. And man, in this particular case this rep of course in Vermont being a I don't know, leftist, I have to assume, but a fan of electric cars, his car. Sad they're burning, which is pretty bad, ironic, but this happened when was this? Oh, it looks like this happened just a couple of weeks ago.

[01:08:43] He's the state chairman in Vermont of the house committee on energy and technology. I've been supporting electric vehicles go sponsor bills relating to electric. And plug-in. So now his 2019 Chevy bolt course caught in fire, caught on fire, and there are others out there. 68,000 cars. All right. So two phases to the recall first phase is a temporary solution.

[01:09:11] The second one is a more permanent one. Apparently this has to do with the batteries spontaneous. Catching fire. So this isn't something that's related to a car accident. It's a spontaneous combustion problem. That's not too good. It's a defect in the LG chem battery packs that are in these cars. So here you go.

[01:09:34] If you drive to work every day and you charge your Chevy bolt every night, the United States, federal government is telling you to stop doing that. Yes. If you have a Chevy bolt, they're advising you to not charge it at night. I'm not sure when you're going to charge it. Cause the idea is you charge it at night.

[01:09:54] You drive in the day, right? So they're saying there's, you can't do that. If you have to charge it at night, make sure you park the car away from any structures and definitely do not park your Chevy volt. That might be part of this. Recall inside a garage. How's that for bad, the original recall, by the way, came out in November, 2020 for potential fire hazard in the, again, the high voltage battery pack, those cells could possibly heat up and ignite internally.

[01:10:26] Yeah. And if that fire spreads of the rest of the car and spreads to the building it's parked in or nearby building. Yeah. So keep an eye out. If you have a Chevy bolt, this is the type of problem in a phase as we start more and more to move into the electric vehicle realm. Yeah. Eventually it'll all get worked out, but it isn't perfect today.

[01:10:48] Hey, visit me online Craig peterson.com and keep up with the latest in what you have to do with technology.

[01:10:56]We talked earlier about Amazon and how much trouble they're in right now, Google apparently is in a similar boat. We had just this week, dozens of state attorneys, general suing Google on antitrust grounds.

[01:11:13] You can reach me online. Just me. M E Craig peterson.com or what most people do is they just hit reply to my newsletter.

[01:11:22] Hopefully you're on my newsletter, right? That goes out every week. If you're on that newsletter you can just hit reply and ask me questions. Any questions you want? I'm more than glad to answer them. I know most of you guys, you're not business people. I am still glad to answer your questions for you to keep you on the right track.

[01:11:39] The whole idea here is it's to keep you going. Safer. And if you're a business person, what the heck, maybe I can help you out as well while the here is a problem. And it's a very big problem. We have these absolutely huge companies that are using their market position in order to really control the entire world.

[01:12:06] Now it's a very big problem because you have companies that are sitting on billions of dollars in cash who can and do keep their competition out of the market. Now, one of the ways that keep them out, and I've mentioned this before, Microsoft has done this multiple times as lost lawsuits about it, particularly over in Europe, but they find somebody who might be a competitor and they basically squeeze them out of them.

[01:12:35] Even though they're not necessarily even a direct competitor. One of the things Facebook does is they buy companies for 10, a hundred times sometimes more. Then they're actually worth, would you take 50 million for your company? That's worth 50 million? You might not.

[01:12:53] Would you take 500 million for the company? How about a billion dollars? That's where it starts becoming very questionable about what they're doing. One of the things that Google is allegedly doing right now is preemptively squashing com competing app stores. When you look at Google and the Google Android ecosystem, who sells the most Android devices out there, right?

[01:13:21] The high-end devices, the number one seller of Android phones is of course, Sam. And Samsung started to put a store too. An app store. So you could buy Samsung, Sam sung apps now, apple and Google, both charge about the same rates as a general rule. It's 30% for these bigger companies that they have to pay the app store, okay. I'm okay with that. They both spent the time to build the platform, to monitor it, to try and keep the app store clean and guides. That's definitely worth something. But what if Samsung came along and said, okay, we're only going to charge 10% royalty. In our app store and the apps will run on all of our Samsung Android phones.

[01:14:10] So it's still using the Google operating system. It's still Android. It will probably run on other than Samsung phones as well. That's the whole nature of, but that hasn't happened. And why hasn't it happened? These state attorneys general are saying that what has happened is the Samsung galaxy store got squashed by Google.

[01:14:38] So it could maintain its monopoly on Android app distribution. So it says that Google engaged in a bunch of different anti-competitive practices. They offered large app developers, profit share, and agree. In exchange for exclusive exclusivity. Okay. I can see that the apple iPhone came out. Do you remember this exclusively on ATN T's network?

[01:15:05] Is that a problem? They're saying also the Google created unnecessary hurdles for what's called sideloading. So sideloading is where you might go to another app store in order to install something. Or maybe it's something that you want to put on your site. It's not fully approved by the Google play store.

[01:15:26] So that's the basics of what the side loaning is all about. So saying that they made that even harder. Okay. From Google standpoint, do we really want to. Allow anything to run on our phones. And here's the question, here's why, right? What do I do for living cyber security? What is one of the things you have to do for cybersecurity?

[01:15:48]You've got to put in special routers, special firewalls and software on servers and computers. Whoever touches a computer last owns the next problem. That's been my mantra forever. So if we installed some software on a computer or we had the customer installed some software on a computer, and there's a problem who they get.

[01:16:11] They're going to call me, right? Because I was the last one to touch their computer. And at that point now I have to show, okay, it wasn't me. It was this other piece of software. QuickBooks is a piece of junk, you know what, whatever it is, I'm going to have to justify it. And frankly, I'm probably going to have to fix it.

[01:16:30] So Google is saying. We don't want all of these app stores that might have apps that are not secure apps, that crash apps that might cause problems with the Android ecosystem. I think that's perfectly legitimate. Apparently these state attorneys general don't think it is. And here's the last one. This is a.

[01:16:53] Attempting to buy off Samsung to limit competition from the Samsung galaxy app store. Now, Google is saying that this lawsuit is merit lesson. I can see a whole bunch of legitimate argument on their part. They also said, quote, and this is an article from ARS Technica. It's a strange, it's strange that a group of state attorneys general.

[01:17:18] Chose to file a lawsuit, attacking a system that provides more openness and choice than the others. In other words, are taking a jab at apple because apple is very closed for the reasons I just decided to hear that Google I'm sure is going to argue as to why they are closed. Okay. Apparently the state attorneys general are saying, quote, Google promised repeatedly that Android would be the basis for an open ecosystem in which industry participants could freely compete.

[01:17:52] Google has not kept its word. Instead. Google has taken steps to close the ecosystem from competition and insert itself as the middleman between app developers. Consumers. Okay. Can, so can you see that they're also complaining this 30% commission. It's a monopoly rent that unfairly burdens consumers and developers, and K-12, you could argue that I don't fall for that one personally.

[01:18:21] Now the buy-off is where I think that there's a lot. Yep. Teeth in this particular lawsuit. Cause they're saying that we've got the commission rate argument, right? We've got those. It's not as open as you said, it would be. But these attorneys general have spent a lot of time dissecting Google's alleged efforts to keep competing app stores at bay by, and they said Google was willing to offer Samsung myriad benefits and concessions in order to prevent Samsung's galaxy store from being built out.

[01:18:57]Again, Is that a huge problem. If you've got a big customer or a potential partner coming to you and saying, okay, I want a few concessions here. I'm not going to pay 30%, or I want to have some of you, my developers in house with your people so that they can short circuit some of the problems that always develop those are.

[01:19:22] In the business in business period. And when it comes to software development, right? People, businesses have we'll use apple again as an example jam, which is a really great set of software to help manage your devices. Jan PF, you might want to check it out. So jam had their engineers camp out at Apple's headquarters, apparently four months while they were working on.

[01:19:49] Some of the, their software for the next release of Apple's iOS and Mac iOS. Is that unfair? Yeah, in a way it is right because here I am little Mr. Small developer and I'm not gaining access to Apple's top engineers and able to send mine out there to live with apple engineers and ask questions and help them debug my software.

[01:20:15] But it happens every day. Makes sense. So it says though the galaxy store was not nearly as popular as the play store. Google feared that Samsung would develop into a strong competitor, especially since the company sells a majority of high-end Android phones in the us ARS Technica says Google was particularly concerned that Samsung would get an exclusive game.

[01:20:40] For the store to attract more users, which Samsung did do in 2018, when it partnered with epic to launch fortnight exclusively on the galaxy store. And that one, move that one game. That one app. Costs Google millions of dollars in revenue. So we'll see what happens here. They make other claims in there. Apparently it even offered a Google offered to white label, the play stores, the galaxy store, so that Samsung could maintain its branding, all kinds of negotiations, the types of things I've seen before, the types of things that are.

[01:21:20] Particularly uncommon, but a European commission is also going after them with an antitrust investigation. They've done that a few years ago with this is a problem. These companies are huge and we don't let them fail. Look at what happened. GM and Chrysler, both got bail and the federal government Chrysler got bailouts twice.

[01:21:42] The free market. You never would have had that happen. The best part of Chrysler would still exist and those weak parts would have been gone. That's what bankruptcy law is all about GM. The same thing, the best parts of GM would have remained. We would have probably had better cars today. Then we have, if DM GM had been allowed to go bankrupt and yeah, it's going to hurt people, but guess what?

[01:22:07] It's hurting people right now from the other side. And when I see this happening as well at Google and Amazon, of course they haven't gone bankrupt, but they both along with Facebook and a few others, they're both huge. Huge and they control so much of the market. So what's the best way forward. What do you think I'd love to hear from you?

[01:22:29] Just drop me an email. me@craigpeterson.com. What is the solution to this? Hey, make sure you get my newsletter. We got all of this information, of course, a whole lot more comes out every week. May be semi-weekly here fairly soon. See how it goes, but go to CraigPeterson.com/subscribe. You'll get my free newsletter and you'll keep up to date on what you need to do to keep yourself safe.

[01:22:59] CraigPeterson.com

View Details

The New Anti-Robocall Technology is Coming Online

I know everybody I talk to hates these robo calls. They're happening all of the time. What are we doing about it? The FCC has made some changes and they just went into place. So we're going to talk about STIR/SHAKEN, right?

Of course the government has to come up with some really cute acronyms and that's what's turned, shaken are, but here is what's happened. We have the ability to over TCPI P send phone calls. In fact, in my phone, I have a phone that's hooked up to T-Mobile and it is using wifi.

[00:00:38] So when I'm making a phone call, it is going over my wifi in the office or at my house or wherever. It doesn't even use the regular salad or network, unless it has to why? Because it's all TCP IP. And then on top of it, sometimes with LTE and now always with five G you are using TCP IP. So your voice is converted into a digital signal.

[00:01:10] Right there on your phone. And it is handled as data, just like pretty much any other data would be handled. Now our cell phones, of course, for a long time have been digital and have been in coding it, but they have not been using it as regular TCPI peop. So what the federal communications realized is since most of the tracks.

[00:01:35] That we have on our phone networks nowadays is actually internet traffic. It's TCP IP. Why don't we add a little bit to the protocol? And they came up with this whole new way of being able to track the originator of a phone call right now, if you have a landline, this is not going to benefit you at all.

[00:02:02] And we're going to talk about the different carriers here, but they don't have to comply these landline operators for another couple of years. Although the FCC right now is circulating a petition and is trying to make it so they have to comply. More quickly, but the nation's largest phone companies have met this deadline that was set by the FCC to put this new anti robocall technology in place.

[00:02:31] But I want to warn you guys that does not mean that it is going to stop all of these robo calls anytime. Soon where it's not going to stop, but you might have noticed that at the end of June, there was a noticeable cutback in some of these robocalls. Now these are the scammers that are calling us and are pretending that they are a local phone number, right?

[00:02:59] Their biggest trick is, yeah, I've got the same area code and first three digits, I'll call it a prefix as you do. So you should answer that phone. They announced at the FCC last Wednesday that quote, the largest voice service providers are now using stir shaken caller ID authentication standards in their internet protocol networks in accordance with the June 30th deadline set by the FCC.

[00:03:26] This widespread implementation helps protect consumers against malicious. Spoofed robo calls and helps law enforcement track the bad. So it, I think is a very good idea. It's a step in the right direction. It is going to help a whole lot at T and T Verizon T-Mobile and us cellular have all put these in place.

[00:03:54] In March, the FCC denied petitions for deadline extension from Verizon and us cellular are saying that they didn't meet the high standard of undue hardship. I think that makes sense. You've got to force these guys. Sometimes Verizon was saying that they had a small area of their fiber based home phone network that would not be able to meet it.

[00:04:17] So again, it's landline. Versus the home phone that work, many of us have it. Comcast provides it as well, but basically if it's it IP based, they didn't have any sort of exceptions. So Verizon is now exchanging the stir shaken enabled phone calls with wireless carer carriers. It represents about 80% of the U S wireless industry.

[00:04:45] Verizon said this week, so 80%. Yeah, you should have seen a bit of a drop more than 135 million calls a day are currently being exchanged between Verizon and the other carriers with the number of calls that are being exchanged using this tracking technology grow. It's also been deployed on IP enabled wire line phone networks operated by Comcast charter at and T Verizon and many others.

[00:05:17] So we're pretty happy about this. We'll see what ends up happening in general, but some care companies that carry a lot of robo calls are not yet required to follow the stir shaken technology and the rules around. Because there's an exemption for carriers with a hundred thousand or fewer customers. So that's going to be a bit of a problem, but think about how you have to roll out technology.

[00:05:46] Rolling it out via these big carriers and doing that first is seeing where the holes are in the technology. What's not working properly. That's the way to handle it. And then by having the big carriers do it, they're going to bear the brunt of the expense. Because always right. Those big screen TVs used to be five to 10,000.

[00:06:12] I remember $15,000. That's a very big deal. And then it goes down and down. Now you can buy them at Walmart for 300 bucks. So having the big guys do at first makes a lot of sense. It's going to prove the technology, improve the technology, drive the costs down, and then you can bet that these smaller carriers are also going to be required to do this fairly soon.

[00:06:38] So the way the protocols are working is they are using tokens and to verify. The accuracy of the caller ID. So they're using public key cryptology. For those of you who know what that is using digital certificate, getting major us companies to adopt. It really was very big milestone. I'm very glad they finally did it by the way.

[00:07:01] Stir, shaken. Ordered by Congress and FCC chairman as PI. You remember him? He did a lot of great things to help out communications, but he was only having voluntary compliance. And so it didn't lead to like widespread adoption. So this law really forced them into it. And they're now. So we'll see what happens.

[00:07:28] Small carriers are exempt for now. Landlines. Aren't doing it. There's a lot of the TDM based stuff out there, but it's going to happen. There's also a gap in, at and T network right now. So we'll see. What ends up happening? Hey, I want to encourage you guys. If you have not already to sign up for my newsletter, I don't spam you, right?

[00:07:50] I'm not one of these robo spammers that we see out there that are just sending all kinds of garbage all the time I put together. Usually six to eight, sometimes as many as 10 articles every week that I think you need to see. And when I put them together, make them available for you. It makes just a huge difference in people's lives.

[00:08:13] I get thank you notes. Everybody. Not everybody, but I get thank you notes every week from people who read that newsletter and thing. They thank me for my time and all of the effort that we put into this. This is an effort of love by my wife and I, so do that. It will help. I give all kinds of great advice and warn you about things that are happening right now.

[00:08:37] Just spend a minute, go to Craig peterson.com and you'll see right there in the home page, scroll down a little bit. There'll be a little red line at the top where you can put in your email address and I'll sign the app. And I will be sending you some special reports that are really going to help you out right away.

[00:08:56] So do that right now. CraigPeterson.com/subscribe

View Details

60% of Used Amazon Echos Can Be Compromised
Don't Sell Used Google Home, Nest, Echos, etc.!

The majority of Americans, at least those of middle income and higher, have the smart devices in their homes. It's everything from the Amazon echo all the way up through our thermostats. Are these a good idea? And what do we do when we get rid of them?

IoT, you might've seen that before. And it stands for the internet of things, and these devices are actually computers on them. Have even more than one computer. Some of them have a lot of processing power. You look at some of these speakers, like the apple; the big apple speaker has some amazing processing belt right into it.

Of course, it also has a number of different ways that you can use it with Siri and everything else that's in it. But if you're going to sell these things, if you're going to sell your echo dot or other things, what should you be looking at? How can you do this? I had a listener who reached out to me.

[00:00:56] This was only a couple of weeks ago, and he had a problem. All of a sudden, he was getting charges from Amazon for things. Did not order. So he asked me what's the right way to go here. And, being the coach that I am, I pointed him in the right direction, which was pointed him at the Amazon security people.

[00:01:20] So he got a hold of them and spoke with them. It turned out that his Amazon echo that he had was what was used to order all of these items. And guess what? He didn't have that Amazon echo; he had sold that Amazon echo, and when he sold it if somebody bought it right, a used echo online and was using it to order things and have them shipped, not to his house.

[00:01:53] Elsewhere. So it is a really big potential problem that has been looked into, and there is a group of researchers on the Northeastern university who bought. 86 use devices. And this is an article from Ars Technica, Dan Gooden, who wrote this and what he, what they found over the 16 months is that 61% of these devices that they bought 61% had not been reset at all.

[00:02:33] No, that to me is not terribly surprising, but it's horrific. If you're trying to keep your data safe because think of what these smart devices have in them. They've got your location; they've got your wifi networks and passwords. They may have account information; what did you go ahead and link it to which accounts are on.

[00:03:00] There are a whole bunch of things that can be gleaned from them. Now he, this listener, said that he had reset his device, and you can and should do that if you're going to give it to someone in the family, which is what I would recommend as opposed to selling it. And I'll tell you why. These devices have inside of them a particular type of memory it's called NAND flash memory.

[00:03:32] And the memory is you can think of it in similar ways to your solid-state desk drive. Back in the old days, the operating system would say, go ahead and write this block of data. This 512 byte block out to Track 17 sector one, and it would go ahead and write it to track 17 sector. But the problem with NAND devices and most SSDs all of them, frankly, is that you can only write so many times before the memory goes bad and it can be 10,000 to a hundred thousand times.

[00:04:13] And if you've ever wondered, why is this solid state disc so much more expensive than the other ones? Usually it's because it's using better memory that can take more. Cycles read cycles, do it all you want all day long, cycles is the problem. So they have come up with some technology that they build into these that does a level.

[00:04:36] And what that means is track 17 sector. One is really located here at position X. And then if you right track 17 sector one, again, it's really located at a completely different position. Y so that the right now get leveled across the entire division. Okay. You don't really have to understand that in great detail, but I know there's a few of you guys being the best and brightest that really want to understand that a little bit better.

[00:05:05] So that's why certain flash memory, certain SSDs are more expensive than others. Now here's the problem. When we're talking about these smart home devices, they're using this type of memory and NAND flash memory has a problem in Ohio has a few problems, but the biggest problem is it's not terribly reliable.

[00:05:30] Especially the type of Nan flash they use in these inexpensive devices. So it's not terribly reliable. So it builds in check sums, right? So those out at the same time, so that when a treat him back, he can say, whoa, wait a minute. This is block is bad. And then it can recreate the block on that flash memory, which is really great.

[00:05:52] Now, when you erase your device, It doesn't really, excuse me. When you reset your device, it doesn't really erase your device. I want you to think of windows as an example. You might know that if you delete a file from your windows computer, it's not actually deleted. It's actually still there. It just reallocates the space that file was using.

[00:06:18] So it can use it for yet. Another file. So you you delete something it's still there. So when you're getting rid of that computer, what you used to do with a spinning hard disk is you would run multiple rights on that desk, solving entire desk. You'd drive zeros, you'd write ones, you'd write random patterns and you'd be.

[00:06:43] And there are fancier ways to do it, the government, and it, many of the government contractors actually shred the desks. They have shredding machines, you can feed a whole computer into these things are just amazing. And then they send it off for recycling. What we do is we remove the platters inside the desk, the aluminum platters, and we melt them down in a furnace that we.

[00:07:10] I still had furnace. Now there's nothing readable on it. Cause all comes out as a big blob of aluminum. One word. Resetting your device just like deleting a file on your windows. Computer does not actually remove it. And nowadays we're reusing this leveling technology in these SSDs and NAND chips.

[00:07:34] We are really not getting rid of it. It might not be rewritten for a very long time. Because again of the leveling technology. So there's another process you can do known as off chip, which will require you to completely just assemble a desalt or the flash memory, and then mess around with it a little bit more.

[00:07:57] But here's the problem. Even though the listener said that he had reset factory reset his device before he sold it. It still had all of his information on the device. So all of the bad guys had to do is remove those chips and. And right inside, there was his Amazon account information, password, everything, it needed, the key to make orders with Amazon.

[00:08:29] Now that is a problem. If you ask me and it isn't just Amazon, this isn't just echo devices. We're talking about. The same thing can be true for that smart thermostat that you bought that Google thermostat, that smart. Doorbell that you have on the front of your house, though, those all contain this type of memory.

[00:08:51] So what I tend to do is take a hammer to. If you don't have a, what do you call it now where you can melt it down a furnace where you can melt them down, specifically designed for doing this type of thing. Then here's what I advise you to do. Get a drill with L fairly large bit. You want at least a three-quarter inch metal bit that you can put on to that drill.

[00:09:16] I used to use a drill press that we have and drill three. Large holes into the platter. So you don't have to open up the disc drive at all, but you'll notice there's a round section of the drive. That's where you want to drill into that round section of the drive, three big holes. And that disc is for all intents and purposes unrecoverable.

[00:09:40] So the bad guys can't get your bank information. They ha they can't get it. That spreadsheet that you have with all your passwords, you not in person Best and brightest come on guys. And they can't get anything off of that. So when I'm talking about IOT devices, what do we do? What do we do?

[00:09:59]Basically, I would say don't sell them. They're cheap enough. You can get an accurate. For well, under 50 bucks, 80 bucks at the high end for the ones with the video and everything built into them. When you're done with it personally, I would destroy it, physically destroy it. Cause that's the only way to make sure your data is not going to be.

[00:10:25] Hey, stick around. You're listening to Craig Peter son. Make sure you get my newsletter. The free one is at CraigPeterson.com/subscribe.

View Details

FBI Using a "Honeypot" for a Massive Sting Operation
& Olympic Cybersecurity

This time, the FBI didn't just set up a sting, they set up a honeypot. And I talked about it with Mr. Matt Gagnon coming right up. Along with a couple of other major points this week, including what has been happening with the Olympics and cybersecurity. So here we go.

[00:00:22] Matt Gagnon: Craig. Let's get into some of these topics, if you can.

I had an interesting conversation yesterday with some folks about tech policy what's been going on censorship, et cetera. It's obviously a pretty common topic when you talk to especially conservative minded folk they're pretty upset about what's going on there there. And one of the, one of the people I was talking to who said to me that that's, somebody must have dimed them out that they had a Facebook post that was blocked because Facebook.

[00:00:48] Was maybe notified that they did something and it was pulled down here that does that brings to mind this story about the, do you know an extremist prompt at Facebook? Are they testing something like that where you basically are diming out your neighbors and seeing stuff. And then all of a sudden you're reporting to the authorities at Facebook, that somebody has a opinion that is just not okay.

[00:01:08] Craig Peterson: [00:01:08] Yeah, this, where could this possibly lead? This is a crazy, they are doing that. Facebook has admitted it and you know what shocked me the most about this isn't that? Hey, the two known extremist, or are you an extremist? And the Alicia. People C N until you reported on this, which just shocked talk to me, frankly, but they say this is part of a, what they're calling a redirect initiative.

[00:01:35] So if you're looking at for something, they'll send you somewhere else. If they don't think what you're looking for is appropriate. And then they're asking you, are you an extreme Mister? True. Oh my gosh. People don't you read history? Where is this going to take us? I don't

[00:01:54] Matt Gagnon: [00:01:54] know. It's a good question, Craig.

[00:01:56]Clearly this is part of the evolving narrative here of exactly how social media companies are trying to moderate content and deal with their perception of what extremism is and whatnot. I, to me though, I have this question, maybe you can answer it. Is a market, just not at play here. With Facebook, continuing to do things like this and alienating like half the country, ha and beyond our country, right?

[00:02:21] I This is happening all over the world, right? Is there not a market for a company that doesn't do things like this, that doesn't moderate it's its content like that? Can we not have something out there? That clearly, takes out violent content and real threats and just like sick, disgusting racism or whatever, but more or less is a free speech zone.

[00:02:39] Otherwise you're telling me that couldn't survive. In today's world. What's wrong with that? Why can't it happen? Where's the market.

[00:02:46] Craig Peterson: [00:02:46] If you're going to survive something like that as a startup, you need, first of all, the seed information, you need people to start signing up and you need money coming in.

[00:02:56] And Facebook is doing everything that can anybody that's a startup that looks promising, whether it's WhatsApp or Instagram, they will be purchased. They'll be bought out. Now, these guys might be saying I'm going to have a free speech platform. It's going to be absolutely fantastic. We know what's happened with a couple of those already, but what Facebook does is they come along and say your company is worth about $50 million.

[00:03:23] How about, I give you a billion for it and wildly over overvalued. Then Microsoft does much the same thing with potential competitors and drives them out of business or buys them out of business. So the Facebook is in a very interesting spot. Plus then there's the whole section two 10. And w you can shoo newspaper out of existence, but if a newspaper publishes a story and that story is not factually accurate, they go out of business.

[00:03:55] So newspaper takes some time, tries to do some investigation, gets multiple sources to confirm, and then publishes in story. Facebook doesn't have to worry about any of that stuff. So why are they doing this in the first place? And they are wildly profitable to the terms of hundreds of billions of dollars.

[00:04:14] And they just don't care. They have what they have morals, is what they called. And they're saying we cannot allow this to happen. And they are leading the country down the Primrose path. Although the numbers seem to be showing a lot of people ditching Facebook, and there are some other platforms that are trying to get charted, trying to go.

[00:04:39] But it just isn't happening there. This is not a free market system and we don't have one in this country. We haven't had full free markets for over a hundred years now, entirely regulated. They pick the winners and specifically the government has picked Facebook and Google is to have those winners by providing them with legal cover.

[00:05:02] I think we've got to pull back the kimono and looked at what's really happening.

[00:05:07] Matt Gagnon: [00:05:07] Greg Peters on joining us as he always does on Wednesdays at this time, talking over tech topics, Craig, one of the other things that's happening in the world soon here is the Olympics. I've been watching a lot of Olympic trials, a lot of things on TV as we prepare for this, I'm an Olympics nerd.

[00:05:22] So I love this stuff and there's obviously a lot of competition at the Olympics, but there's a different darker background of competition out there. And it's the cybersecurity experts trying to protect the infrastructure at the Olympics. Again. The bad guys, as you might say. And how does that play out?

[00:05:36] Because this is, nobody's really reporting on it. Nobody talks about this much, but this is a really big part of this gigantic event.

[00:05:42]Craig Peterson: [00:05:42] Think about what's happening in Japan right now. They are having these Olympic kind of, trials things. If you will, where we're losing. Four out of five of the basketball games.

[00:05:53] I can't believe that part, but here's the bottom line. No rule be no spectators. Everyone in the world. That's interested in seeing the Olympics have to watch it online. Somehow all of the major news networks are getting their feeds and a lot of that going over the internet. There's a lot of exposure. We have all of the people who are competing, who are using special apps who have special electronic controls.

[00:06:22] We had a huge problem last time around in 2018 with the Olympic winter Olympics, because there were some cybercriminals that managed to bring the whole thing down. So we are really on our toes worldwide. Now, including here in the U S what a target. It's a beautiful place for the bad guys to go make a name for themselves, ransom, et cetera, et cetera.

[00:06:46] So there are whole teams. I've got a little bit of insight information here, but there's whole teams of people around the world that are monitoring. What's going on, are looking into everything that looks like they're being probed. Everyone. So 10 show hat. They are really staying on top of it. And these teams, Matt are some of the best in the world or teams I've worked with before.

[00:07:11] So knock on wood. It'll be okay. But the Olympics, they are a huge hacking targets.

[00:07:16]Matt Gagnon: [00:07:16] Finally, I want to also ask you about speaking of the bad guys and trying to take them on here. There's ways of trapping them and the FBI created an interesting one here. Google pixel is involved in this very interesting story here.

[00:07:26]Did they use a honeypot to basically entice some of these people in and then trap them and then get them out of this work?

[00:07:36] Craig Peterson: [00:07:36] It's Winnie the Pooh is such his head in there. He got the stock. The FBI came up with a real interesting concept that is a bad guys. Want to be able to communicate privately?

[00:07:47] So they modified some pixels now and they did it in such a way that they turn off the cellular. They turn off, they remove cellular, they remove the GPS trackers, they removed a bunch of things. And then they sold these phones on the black market or out on the dark web saying, no, these phones are going to keep you safe because of this, that, and the other thing.

[00:08:12] And we've got a special operating system. They called these devices and arm and the bad guys started using, and they didn't really do any research talking to them and they were recommending it to each other. These hacker groups, these criminal organizations that were smuggling people, right? Kidnapping people was selling arms on the dark web, et cetera.

[00:08:35] They started using it for Nona miscommunications. What they didn't know. Is everything that was sent on these devices, everything that was done with them was sent to the FBI. So what some of us went to Interpol and others. So the concept is great. Let's turn off the cell. Let's turn off the GPS that's to remove them from the device.

[00:08:58] The problem was they didn't know good law enforcement. Was in fact monitoring everything that was being said there more than 12,000 smartphones like this that were out in circulation and heavy use by the bad guys. And now you can buy one of your very own FBI monitored phones on eBay. People started to buy them because they are based on a Google pixel foray.

[00:09:22] Custom firmware in them, which is a bit of a problem. And they do have arcane OOS as well, but people are trying to figure out why can't I get my phone to work? I just bought on eBay, but they have been shutting down major criminal organizations worldwide. Because of this honey pot, they really got stuck.

[00:09:44] They got

[00:09:44] Matt Gagnon: [00:09:44] them. It makes it basically, it's a way of, it's a way of trying to learn from it and it works ultimately. So Craig Peterson, our tech guru joins us on Wednesdays at this time. Unfortunately, Greg we're out of time, so we have to stop here, but again, you can hear them on Saturdays. Thanks a lot, Craig.

[00:09:57] And we will talk to you again. Next

[00:09:59] Craig Peterson: [00:09:59] week. All right. Take care. There's nothing that helps this show get out better than having you subscribe to the podcast. I appreciate you guys listening. I can't tell you how much, because it does help get the word out. And that's what I'm trying to do is help everybody understand what's going on.

[00:10:16] Please, whatever platform you're listening on. Go ahead and subscribe. And if you wouldn't mind, give me a five-star rating. And the 800 pound gorilla is still our friends over at apple iTunes. Believe it or not when it comes to the ratings of these different podcasts. So if you could go there the easy.

[00:10:38] Craig peterson.com/itunes. That'll automatically redirect you to my page on iTunes. Craig peterson.com/itunes. Oh, by the way, in case you didn't know, I'm also on YouTube now posting a lot of these podcasts as little videos. Yeah you'll see when you get there and that's at CraigPeterson.com/youtube.

[00:11:01] Take care everybody. Bye bye.

View Details

Facebook's Extremist Prompt Leads To...
What to Do About Ransomware?

We got hacked again as a country and what's being done about it. What's the Biden administration doing? They sent us special Envoy over to Russia. Yeah, Senator former Senator John Kerry. But what's he talking about? The climate deal. This is hurting us badly here in the United States. It's hurting at least a third of our businesses every year.

Just this year alone. Ransomware payments have gone up threefold. It is incredible. What's happening and he's doing nothing about it. And then we, so we've got to talk about this Facebook protest prompt that they've come up with now. Hey, do you know someone. Might be an extremist or it might be, become an extremist.

Do you realize what's going to happen? If everybody's starts to reporting on everybody else? We already know that we've got these trolls out there that report people, that report posts just because they don't like the person. Now, what are we going to do? Start FBI investigations. Every time someone says someone is an extremist, just cause they don't like them.

What is an extremist? Anyways, we get into that. So here we go with Mr. Jim Polito.

[00:01:14]Jim Polito: Two things. I want to two things. I want to talk about one the weak and feckless response of Joe Biden to the latest hack by the Russians. But before we get into that, So Facebook really was asking you to rat out your neighbors like 1984, like George Orwell's, 1984, Facebook.

[00:01:39] Admitted that they were asking people to identify extremists using the social media website.

[00:01:47] Craig Peterson: [00:01:47] Yeah, they did. And you know what, Jim, this is shocking to me. We've looked at Google before and compared it to duck, duck go, and how Google just doesn't, it blocks things. CNN has been one of those similar, I don't even want to call it a news source.

[00:02:02] But even CNN business reported this, but some Facebook users here in the us were getting prompts. If they were worried about someone that they might know might be coming an extremist. This is shocking to me. Absolutely shocked. And show them my wife likes to watch the good fight where, which is these are the lawyers.

[00:02:28] And they tend to be very leftist. The latest episode, season five, episode three, she called me in, and then I had to look at this. They were dealing. This situation where we have now people reporting on other people and because someone who might've done something, and maybe you help them out a bit at one point in your life, all of a sudden the FBI is in your life to try to figure out what's happening.

[00:02:54] They are asking you now to report on other people. This is crazy what this is going to lead to. And yeah, Facebook's doing it. And even CNN reporter.

[00:03:05] Jim Polito: [00:03:05] Wow. We're talking with tech talk guru, Craig Peterson. So because people sent me screen grabs of it and things like that, that they were being asked if they knew I knew an extremist, and please define extra what's the definition of extremist.

[00:03:22]I just talked about Joe Biden and the DNC, wanting to team up with a phone carrier. To monitor and correct anti-vaccination messages. Did you hear this one? I'm sure you did actually. I'll send it to you. I'll send it to you. This is it was from political. And that's why it wasn't from a Craig Peterson type website.

[00:03:46] It was from Politico was Fred was running the websites. It dumb people like myself read. Okay. But anyway, Politico said that the DNC, the the Biden administration they want to scrutinize phone and social media messages for misinformation. And they're asking what do they call them? SMS short message service carriers.

[00:04:13] They want them to they wanna have fact-checkers more aggressively work with SMS carriers to dispel misinformation about vaccines. That's a quite, that's quite a little propaganda outfit you got going there. Remember

[00:04:28] Craig Peterson: [00:04:28] if you're sending a text message, that message is stored. Remember a Strzok and Paige, right?

[00:04:34] The whole thing with the FBI lovers and their text messages showing up. If you're using your apple phone. And you're using messages to send messages to other apple users. If it's blue, it means it's encrypted end to end and they cannot monitor. They cannot report to. If it's green, which is an unfortunate choice of colors, that means it's sending it by this old protocol.

[00:04:58] That was actually a hack of, for the cell phone industry. It's a green means it's in the clear, but the fact Tim there, they're going to monitor that. And then what are they going to do? Start prying into your life and everybody, it's. Wow.

[00:05:15] Jim Polito: [00:05:15] Yeah. This is not good between that, the messages, all of this I'm fine with.

[00:05:20]If the administration wants to get their message out there about vaccinations and this and that's fine but don't do it. Don't do it the way you're doing it. That's Orwellian truly is our Wellington.

[00:05:33]Craig Peterson: [00:05:33] It's. It sets things up. For, if let's say you love Biden and we've got the all have the stab of then okay, fine.

[00:05:44] What's so what happens if another Trump it's an, that you absolutely hate you want the next administration or the one after that to have this kind of information?

[00:05:53] Jim Polito: [00:05:53] I don't. Yeah. I know. All right, let's get to, let's get to the latest with Vladimir Putin and with Joe Biden. I don't know if you saw the clip.

[00:06:03] I don't have it here handy. Joe Biden. The other day, someone asked him a reporter, asked him about the latest cyber attacks and he tried to pull a card from his pocket, said, oh, I just got briefed on that. He was all over the place. Didn't know what to say. I'll have more to say about it later. That's.

[00:06:21] Twofold one, it speaks to his cognitive ability, but two, it speaks to what is the response been from this government? He had the summit with him and said, here's 14 things. I don't want you to touch. And yet Putin turns around and touches

[00:06:37] Craig Peterson: [00:06:37] them. Yeah, he sure does. The response.

[00:06:42] And we, of course, Biden just sends an Envoy over to Russia meeting with Putin. John Barry, he's talking about climate change.

[00:06:55] He's

[00:06:55] not

[00:06:56] Jim Polito: [00:06:56] talking about cyber attacks. He's talking about climate change.

[00:07:02] Craig Peterson: [00:07:02] We, yeah. And we now have as many, I've seen numbers as high as a hundred thousand businesses that were part of this latest attack that came from Russia. This cyber attack, this ransomware. In fact, I know of a thousand businesses that got together and they hired an attorney in order to try and negotiate.

[00:07:26] This is an attorney that negotiates with ransomwares right. We started the United States Navy to deal with ransoms coming in, out of the middle. Yeah, 200 years ago, the Marine Corps and the Navy, this is in saying what is happening. Trump of course put some pretty severe restrictions on Moscow in Russia to try and crack down on this.

[00:07:51] And we had to remember, again, the old Biden administration saying things like, oh, I told him to stop it right. We have to respond.

[00:08:06] Jim Polito: [00:08:06] I don't know. I'd like to think. Craig that there's some back channel stuff that your people, the guys like you understand and know about, and it's being done to slap him on the hand as the hand tries to reach over and grab again, I'd like to think that the really smart people on our side are doing that and send it the message without being public about it.

[00:08:29] Cause I would have not have a problem with that, but I don't even feel like I don't even feel like that's how. I don't even

[00:08:36] Craig Peterson: [00:08:36] feel like. We are a kind of slot them back at them. There, there aren't too many automated systems that'll do that. We're being hacked to hack back. The big problem with this is we're pretty darn insurers coming from Russia, but let's say that you're in the battle.

[00:08:55] And someone's shooting that too. First of all, someone shooting at you, where it's coming from inside of BAE systems has systems that are put onto our helicopters that notice exactly where the fire is coming from and return fire automatically. Okay. And wouldn't that be great. The problem is Jim that somebody hacked your home computer.

[00:09:17] It's now part of what's called a bot net. Somebody had somebody else's computer, same bot, and there may be a different one on and on. There are hundreds of thousands of computers worldwide that have been hacked. So the Russians go into a computer in Vancouver, BC, which is then connects to a computer in Vancouver, Washington that connects to Washington DC.

[00:09:38] And it took trying to hack. If you returned fire, you're going at somebody's home computer in Washington. And you get it. And then that home in Washington state, of course now let's say the FBI shows up and says, okay, something's coming from here. We've got to see your computer. They get on the computer.

[00:09:56]Guess what? It's now in Vancouver, BC, which is now an international problem. And who knows, maybe they went to China first. Maybe they went somewhere else. The only way we can do this is serious economic pressure. We have. Fight back that way, because this is the exact same type of thing that happens in a war with skirmishes going on.

[00:10:19] And they are winning by taking money. We're trying to negotiate with them right now and say, okay, we'll just pay you $70 million. If you unlock all of these computers, it's insanity. We keep doing the same.

[00:10:34] Jim Polito: [00:10:34] Over and over again, Craig I got to run. How can folks get more information from you? And I know that you talk about these things on the weekend show.

[00:10:42] Exactly.

[00:10:42] Craig Peterson: [00:10:42] Just visit Craig peterson.com. "Peterson", S O N.

[00:10:47] Jim Polito: [00:10:47] Craig and I guarantee you, I will celebrate Canada day next year. We won't let it. We won't let it be past Greg. Thanks so much for your time, buddy.

[00:10:56] Craig Peterson: [00:10:56] Thanks.

View Details

What Does the "Billionaire" Space Race Mean to You?

We have Sir Richard Branson up in space. The race of the billionaires, Jeff Bezos, of course being another one. What does this mean to us? Does this mean that space is solely for the rich? Is it going to help our businesses, our economy, what's behind all of this, and where are we going? That's exactly what I discussed this morning with Mr. Christopher Ryan. Let's find out how it's going to affect you and me.

[00:00:29] Chris Ryan: Yeah, Richard Branson is in the news day, Sir Richard Branson to you, Craig, as he reached the outer space and was able to bring individuals up there and do in your view, is this going to be a thing where commercial space travel is going to be something that we see and have access to. No average Americans.

[00:00:52] To me, I feel like it's taken decades for even this type of space flight to take place. And I feel we are still so far away from an average Joe, like you, or I will be able to afford to go into. The areas almost to outer space.

[00:01:12] Craig Peterson (2): [00:01:12] Yeah, the black-blue yonder, as it were. First of all, let's get something straight here. Sir Richard Branson made it almost into space, correct? They were 80 kilometers out. A hundred is generally considered. But where we're headed here is not really getting into space, which I think is totally cool. Where we're headed is being able to get up to those sorts of altitudes and then travel around the world.

[00:01:39] So we could see a trip from Boston to Tokyo taking just a few hours, rather than thinking the better part of a day.

[00:01:48] Chris Ryan: [00:01:48] Yeah. And very often, when we see these types of things, I mentioned this earlier, it leads to thoughts of what else is possible. And you may look at this and be like, oh, okay, it's these fancy-free billionaires trying to say they wanted outer space when they're actually, in the.

[00:02:04] Area between the black and the blue and achieving levels of weightlessness, et cetera. But the time that traveled took place and the propulsion of the flight indicates that higher speed. So travel is right around the corner. And to many, that may be as attractive as the actual joy ride aspect of it.

[00:02:25]You're going to be going at a great, at a greater speed. So some people that's not going to be what they want, maybe there'll be able to achieve elements within the aircraft in which people don't feel as though they're traveling at the speeds that they are certainly in this particular.

[00:02:40] A joy ride. That is exactly what they wanted. They want you to feel the propulsion. They want to feel the waitlist. They want all those elements. As we know, most commercial airline folks don't want to feel like they're dry; they're going 500 miles an hour. They want to feel.

[00:02:55] Relaxed during that.

[00:02:57] Craig Peterson: [00:02:57] And you have the problem of having the Sonic boom when you're lower in the atmosphere going those higher speeds you don't hear. But I think what we're ultimately looking at is as a whole change where our speeds really get into higher altitudes. And if we look at the history.

[00:03:15] In the tech business, we will remember when these flat-screen TVs, oh my gosh. 48 inches, only $15,000. And, of course, they'd never be achievable. We'd never be able to own those things, but people bought them. The people that had the money. Now you go to Walmart, and you can buy one of those for 150 bucks.

[00:03:35] That's where this is all going. All of these people competing with the billionaires in space. They are funding the research and development for the types of flights. You and I, Chris, will be able to afford it. It's not going to be as expensive as the Concord was. It's not going to be cheap, but it is going to provide real.

[00:03:57] And I think that's a fantastic thing. Yeah. Now

[00:04:00] Chris Ryan: [00:04:00] the 90 inch TV is something that is not out of the realm of possibility for individuals creating basically their own movie theaters to view sporting events, political shows, and movies, as they wish to in their home. And you're absolutely right. I The there, and as I mentioned before, this.

[00:04:16]Creates an environment where we start to think further about exploration and what is next; very often, people will look at the current state of technology and say this is where we're going to be. What more could we possibly do, but to scientists and inventors, it's always wondering what is next and what is possible, looking at the optimal, and figuring out a path to get here.

[00:04:42] Yeah.

[00:04:42] Craig Peterson: [00:04:42] And w where we're looking right now, NASA is working on this as are others, is having a space station in orbit that is designed for refueling and trips. So if a Virgin can get you up into lower space as work or one of these others, and then from there now you get onto another ship to go to Mars, or maybe the moon colony.

[00:05:06] The biggest problem we have in the largest expenditure of fuel is getting to. So point that at that edge. So we're going to be able to see tourism in space that normal people could afford. And that's going to allow us to colonize other planets, which of course, has been a wish of Elon Musk and many others for generations.

[00:05:28]What happens if we have another catastrophic event here that we. With the dinosaurs that wipes out everything, we're gone, but this is really the next step. And it's absolutely amazing. I'm so excited about what's ahead.

[00:05:46] Chris Ryan: [00:05:46] Do you think we are from that? Cause you mentioned this had been the talk of generations now at this point and decade after decade, even this type of space travel to lower space has been talked about.

[00:05:57] And two commercial flights have been talked about for decades. At this point, I feel like we're still really far away from anything of that nature taking place. And I'd be surprised to see colonization until the latter portion of my lifetime.

[00:06:13] Craig Peterson: [00:06:13] Yeah, you're probably right about that. However, as far as the moon goes, I think we will see.

[00:06:20] Stop starting, but it's not going to be your regular person. As you had mentioned, it's going to be the scientist. It's going to be the real explorers who are going there. But the original plan for the moon launch in the sixties was to have a refueling station in orbit around them. And that's been in the back of everybody's mind for a long time.

[00:06:38] I think that within the next 20 years, we will have that station up in space. That is the halfway point of here. That you can go to, and from there, continue onto the moon. And Elon Musk is really into Mars. And I don't know; he might just jump past everybody else who was there. There's a massive rocket that he's building to truly colonize Mars.

[00:07:03] He's thinking he's going to be doing this. You ask him, and it's within the next year or two, but the scientists are saying within the next five years, So we might be surprised because technology can jump just like

[00:07:15] Chris Ryan: [00:07:15] that. Yeah. Then, in conclusion, I think that this goes to a broader message about where we are at as Americans.

[00:07:24] And we spend all this time fighting over the political scraps instead of having a vision. Towards the future and the things that we can achieve together as Americans and whether it's a disease, whether it's expiration underwater into outer space the new inventions like we need to get back to a place where we're not focused on the little things that divide us as human beings but focused on what we want to achieve and talking about that.

[00:07:54] And not. Figuring out which Mame is the best to mock Trump or Biden, but to focus upon our society's mutual and shared goals. And to me, this type of stuff, that's talk about tech, the topic about inventions, the talk about what we could do, what we could optimize, optimize moving forward.

[00:08:14] That needs to be at the forefront. And that's what people are looking for in politicians too. They want somebody that's going to say; this is what we want to do. This is what we're going to do. And this is how we're going. I think we've

[00:08:25] Craig Peterson: [00:08:25] got to move towards looking to that future. Being excited about it rather than having the parties digging up.

[00:08:32] Tribalism.

[00:08:33] Chris Ryan: [00:08:33] I agree that Craig has always thank you so much. Take care. Craig Peterson host of tech talk on news radio six, 10 and 96, 7 Saturday and Sundays at 1130.

View Details

Being Green Now Includes New Nuclear Plants - It's The Only Solution

Whether or not, you believe there is a climate crisis or this man caused the only thing that's been constant here on earth has been change. And particularly the weather it's been much hotter and much colder than it is right now.

I do believe that we have climate crises from time to time.

[00:00:24]We know that there were cavemen and women living during the ice age. And I think they might call that a crisis. We've also had times where people. We're going and having a great life, the garden of Eden, you might think where the carbon dioxide levels were much higher than they are today. And that means the plants were greener.

[00:00:49] They grew more verdun to everything else. Okay. So there is a whole lot of change and it's been going on for. Now the statistics I've seen that make a lot of sense to me, show that there is warming going on. Now that doesn't mean that we're not going to about to drop into an ice age or mini ice age. Heck we had one of those back in the day.

[00:01:14]In the 18 hundreds or 17 hundreds over in England, a little mini ice age. So it happens and it swings both ways, but I remember very well back in the seventies, everyone was saying, oh, we're about to go into an ice age. We've got to do something about it. And we had science telling us that we needed to spread oil on the polar ice caps and on the Sahara desert in order to.

[00:01:42] Get more heat to stay here on the earth. Or we were about to enter a major ice age. Look it up. It's there. You might not want to use the Google because they do sensors stuff pretty heavily that they don't want you to see. So use duck go, but even Google. Has articles on this. I guess they're not all bad.

[00:02:04] So we've got to be very careful when we're looking at solutions that maybe are less than 1% our fault. In fact, it looks like it's far less than 1%. Our fault global warming is usually from the sun and the sun goes through cycles. So you have to be careful about those cycles and what you know, what's going on.

[00:02:29] So what I don't want to see us do is severely hurt ourselves. Hurting our economy is hurting people. People end up just struggling and in major depression and committing suicide. Look at what happened with the lockdowns that we just had and the year 2020. It was a bad thing. So do we really want to need jerk and cause serious harm to a lot of people.

[00:02:58] Now I am an environmentalist, the original type of environmentalist, right? Duck hunters were probably the most original of all of them and hunters in general, where duck hunters bought thousands of acres of land and put it into production. So that it could be left in its pristine state. So I'm really into all of that stuff.

[00:03:22] I'm think that makes sense. I don't think it makes sense for government to do it, but I think it makes sense. So here's what I'm struggling with right now. We've got people who used to drive Prius's who are now driving electric cars. Electric cars are highly toxic. They're using minerals that are mined in toxic places.

[00:03:48] They're using processes to process those minerals that are toxic as well. And it's been done in countries that are not controlling their toxic waste. No, even the plastic in the oceans, it's coming from seven rivers, none of them in the United States, but all of them, India, China, those are the primary ones.

[00:04:13] So what are we supposed to do with these cars? It's not only toxic in manufacturing, the cars and their batteries. It's toxic to dispose of them. We have no good way to dispose of the Carter, the batteries from your test. No good way to do it. Highly toxic, much, much worse, much, much worse than a diesel Humvee.

[00:04:37] So if we want electric cars and I can see why, I love the idea of electric cars. Absolutely love them. They're faster. They're comfortable. They're quiet. And they don't have tailpipe emissions. Now, remember that it's tail pipe emissions. It's not they're green because they're anything but green don't let anyone fool you into thinking that they are.

[00:05:01] How do we make the electricity? We've got a lot of people running around, out there who are saying when it comes to electricity and electrical generation, nuclear is terrible. It's going to kill us all. And they're thinking about Jane Fonda running around there, the China syndrome movie from the seventies, and they think of Chernobyl.

[00:05:20] That is technology in both of those cases. That's 50 to 70 years old. The new nuclear technology can no more have a meltdown than a ball that set at the bottom of a mountain is going to roll uphill. The new nuclear technology that we have today is not in widespread use because the regulations that are in place from the federal government still require 1950s to 1970s technology.

[00:05:55] They don't take into account this new technology, six generation nuclear. They cannot melt down because they use basic physics to keep control. Of the nuclear reactions and what happens afterwards? Look at Chernobyl. Look at the China syndrome stuff. Look at what happened at three mile island and all of those cases, they had systems that had to be active systems.

[00:06:20] They had pumps to pump cooling water in. What happens then when you don't have power like Fukushima, they have their generators so low that any sort of a flood. Would make those diesel generators shut down and then you have the meltdown, like they had it Fukushima, reactor. None of that is possible with the modern reactor.

[00:06:45] On April 30th, the Indian point nuclear plant in New York. This is an article from a Yahoo news was shut down 30 miles north of New York city. So it had provided electricity. The in fact, the overwhelming majority of New York city's carbon free electricity for decades, union jobs for a thousand people, federal regulators said the plant was perfectly safe, but Andrew Cuomo.

[00:07:14] The brilliant man running the state of New York is a key figure behind this. He said that the shuttering of this nuclear plan brought us a big step closer to achieving our aggressive, clean energy goals. These new nuclear plants, aren't going to melt down. And by the way, these new nuclear plants generate almost no way.

[00:07:38] After 20 years, the nuclear material is replaced and recycled. It is recycled back into other nuclear power generators. It, this stuff is absolutely amazing. So what happened after Cuomo shut down the Indian point nuclear power plant? The first full month, according to again, AP associated press the full and they are no conservative.

[00:08:06] The first full month without the plant has seen a 46% increase in the average carbon intensity of statewide electric and generation Y while they had to switch over to natural gas, they burning natural gas. They had to switch over to coal in some cases, right? What are they going to do? New York generated 9.3 terawatt hours, electricity and average carbon intensity of 174 kilograms per megawatt hour may was the first month after two year process of shutting down Indian points to one gigawatt reactor.

[00:08:47] Okay. So one gigawatt out of 9.3 terawatts okay. That's 9,300 gigawatts. Okay. So it's a small percentage of the actual electricity that was generated. And yet it accounted for so much clean energy that it ended up changing the amount and the amount of carbon emissions by 46%. When you look at it from a clean energy generation standpoint, it's absolutely amazing nightmares should have seen coming and German nuclear power.

[00:09:21] In Germany provided about a third of the country's power in 2000, and then they had this green party thing, it says, oh, we're all against, this is terrible. And so they can get a lot good. And they managed to close plans, citing health and safety concerns. So they went from a third of their electrical power coming from nuclear to 11%.

[00:09:45] We have two. Smart, not people we absolutely do. There's a recent paper that showed over the last two decades where we've been closing nuclear plants slowly but surely led to our carbon dioxide increase of 36 mega tons a year with increased air pollution predicted to kill 1100 people annually. Does that make sense to you guys?

[00:10:11] What's going on. So giving the stakes of global warming that these same people are constantly talking about why are we doing what we are doing? Why is there so much hostility to it? I've found a really interesting quote in here and it's from someone you might've heard. Yeah. Alexandria, Ocasio, Cortez.

[00:10:38] Remember her green new deal that would end up costing every American family, $120,000 plus after some initial hesitation now AP is reporting that AOC has said her green new deal leaves the door open for nuclear power. Jeremy Corbyn over in the UK. You've heard of him, his labor party and the former Brazilian president Luis de Salva.

[00:11:02] And Bolivia's ecosocialist former president evil. Miralis have all said that nuclear is an idea whose time may well have. So let's pay attention here. Let's wake up. Okay. We've got to make sure that we are doing the right thing. Oh, and the writer of this AP story. Yeah. He's the author of the socialist manifesto, the case for radical politics in an era of extreme inequality.

[00:11:35] So I have some hope. This guy is a radical socialist slash communist, frankly, fascist. And even he thinks we need to give the new nuclear another chance.

[00:11:48] Hey, check me out online. Subscribe right now to my newsletter. Get it every week. Doesn't cost you a dime. I have a free newsletter. Craig peterson.com/subscribe.

View Details

We've talked about a lot of the cybersecurity problems. I'm going to talk now about what Microsoft is doing with Windows 11, a lot of hardware out there right now, anyways, will not run windows 11. So what is Microsoft doing to solve this problem?

Microsoft has been blamed for many of the problems we've had with computers and computer security for a long time.

And between us, they're doing these things that caused security problems because of us, because of the users of windows. Microsoft seems to continually try and support the older software and older hardware till very recently, you could still run windows XP 95, 98 programs on your windows machine, on your new windows.

[00:01:05] Back then Microsoft. I had shoe horned in the internet protocols and tried to, make it secure. They ended up buying. I'm trying to remember now, cause I worked on this code. Way back when I think it was the spider implementation of TCPI P out of Ireland, that Microsoft ended up using as a base.

[00:01:25] And I fixed quite a few bugs in that, and there were many more to come, but I wasn't focused on cybersecurity back then on the software. And frankly, most people weren't Microsoft just wanted. Out and they wanted to make sure they were compatible with the older software. So where we, you and I are part of the problem.

[00:01:47] We complain when Microsoft comes up with something that's not compatible. And as a programmer, I complain every time. But not just Microsoft, but apple or Linux or whatever it is, comes up with a new interface, a new quote, better way of doing things unquote with their systems, whatever it might be. And, I guess it's nice to bellyache, but in most of these cases, they're making changes to help make the systems better and often better means more secure.

[00:02:23] And that's what they're doing right now with Microsoft windows 11. So they had an announcement here this last week, talking about. A requirement for a TPM chip. Now TPM means trusted platform module, and the basics of a trusted platform module are to have on the chip and most. So the case is the modern Intel chips.

[00:02:53] So ones that have been out for four years or so, as well as some of them more modern AMD chips have this TPM built in. And what the TPM is as trusted platform module is a small amount of storage that gives you the ability to store keys and to do basic cryptography. Now they're requiring the TPM 2.0 implementation for windows 11, which makes sense.

[00:03:27] It has a little bit stronger encryption in it, but in the windows world, what this is going to do is make sure that the brute force attacks that can happen at boot time don't work. So they're trying to brute force the way into that trusted platform module and to make sure that the rest of the boot is not interfered.

[00:03:54] So that's all Microsoft is going to be doing with it. It that's a good thing, frankly. I think it's a very good thing for them to start using this. Many of us have computers already that have TPMS built in and the TPM 2.0, and with MTPM sitting there, it isn't doing us any good. So Microsoft is going to take care of that.

[00:04:16] So I'm happy about that. It's going to help with secure. But it's not very good, frankly. That is only a small part of the security problem you and I have because our security problem extends to all kinds of things. So let's talk about what apple has done because. Yeah. You know what I'm about to say, right?

[00:04:39] I'm about to say that apple has done it correctly. The TPMS wish they could be. They dream of being an apple T2 because this T2 processor that apple has had for awhile has a lot more functionality. It has what apple calls, their secure enclave processor. So if you have an iPhone, for instance, that does face ID or fingerprint ID.

[00:05:06] All of that information is stored in this secure enclave. That means it is not sending your face up to apple. It is not sending your fingerprint up to apple is not sending it anywhere. It keeps it locally on the desk. In fact, this apple T2 chip also processes all of your disc activity. So your solid state storage that's on your device.

[00:05:34] Goes through this T2 chip audio, video image, signal processing, SSD controller, the secure enclave, AEs cryptography engine and the system management controller all live inside this T2 chip. Okay. So a TPM, like what Microsoft is going to be using is kindergarten compared to what apple is. Which doesn't mean there aren't bugs or haven't been bugs in the T2 chip, but it is designed for security and it's a really cool, and it has this other function that the enclave micro with the Encore, the microphone is always disabled.

[00:06:16] Whenever the lid is shut on that laptop. Because again, it goes through this T two chip. So it's helping to preserve your privacy. Even if the phone were to be hacked, it couldn't get at it because the electrical signals for again, audio video the disc controller, all go through the apple T2 chip, and apple has tried very hard to try and make sure that they are secure.

[00:06:47] So maybe Apple's slipped a little bit recently, but their T2 chip is absolutely. I'm going to quote here professor Buchanan he calls it a work of art compared with this loan. TPM chip is what he says. Oh, absolutely amazing. It is a problem. In fact, do you remember this whole list, Sonya and hack?

[00:07:11] A couple of years back where Estonia had issued ID cards to everybody and they could be used for financial transactions, et cetera. And about half of them were completely hackable. Again, it was a T2 chip flaw because they were not generating proper random keys when they were making these codes. So it's interesting.

[00:07:37] We could really get into that and the history of it and the NSA and what they did, blah, blah, blah. But it's really a good thing to follow. This is the TPM chip. Thank goodness. Microsoft is raising the bar again, and that means that the leader. Microsoft surface tablet, the high-end one, the $5,000 tablet.

[00:07:59] Which does not have a TPM 2.0 chip will not work with windows 11. So keep an eye on this. I'll keep an eye on it for you as well. The, this means basically that app, that not apple, that Microsoft is going to have to change up his game a little bit, and they might decide to not require TPM 2.0 because even hardware Microsoft has been selling does not support this very baseline.

[00:08:28] Primitive cybersecurity that basically only protects your booting. Okay. So again, apple wins whole hands down now. You're I think you're starting to get the idea of why I recommend apple over anything, Microsoft and now apple making their own chips makes me really happy. They'll be able to be even more secure.

[00:08:50] I'm using an M1 based apple mini right now, and I am just amazed at how good. This little device is very fast and quite secure. All right, everybody stick around. There's a whole lot more to talk about and we're going to get into it in some detail all here, but if we really want to fight the climate crisis, we've absolutely got to embrace nuclear power.

[00:09:19] Hey, make sure you are on my newsletter list. I have a free newsletter. Go to Craig peterson.com/subscribe and get that every week.

View Details

You might've heard me talk about this already, or you heard about it elsewhere. This US technology firm is called Kaseya. They're headquartered in Miami and they are used by businesses and governments around the world. And they're spreading ransom.

A week ago on Friday, a flood of ransomware hit hundreds of companies around the world.

[00:00:25] We're thinking now it may have been thousands. We don't have good numbers yet, but we're talking about grocery stores, public broadcasting schools, national railway system. They were all here. With ransomware. Now this is the modern ransomware, we think which encrypts your files, but also poles your data. So that later on, it can extort money from you.

[00:00:55] Okay. Very bad stuff. It really caused disruption in Sweden. They was incredible and forced hundreds of businesses to close. Now, every one of these victims had something in common. They had network management and remote controls, software developed by casinos. Now cause say it is used by, I think their their counters like a hundred thousand customers.

[00:01:25] So it's used by a lot of companies worldwide and they make software that allows other companies. So a third party there's yet another company here allows them to monitor that third party companies computer. So let me just lay this out for you. Here's how this works. You're a small business. You have it people, but they're busy just trying to keep windows up to date.

[00:01:55] And they're also trying to help your people understand how best to use computers, evaluate new software. Doing things, the, it, people should be doing, cyber security is a major specialty nowadays. It's something that you have to focus heavily on. And as you focus, you're still getting behind.

[00:02:16] So as that small business with a couple of people, maybe there's one person that has to deal with computers, right? It's often the office manager, that person. Now needs help when it comes to cyber security. In fact, that person needs help when it comes to keeping these computers up to date, because there's patches from Microsoft, for the operating system, for all of the Microsoft 365 stuff, there's patches for all of the Adobe software there's patches for you.

[00:02:49] You've probably gotten QuickBooks or some other accounting software that needs patches. It's just difficult. If not impossible, to keep up with all of this. And then, your users are probably using Google Chrome. They might be using safari or some other browser, those off to be kept up to date. So one that small business person does is they go to a managed services provider and they say, Mr managed services provider would you take care of all of my computer problems for me?

[00:03:20]And off they go, right? The managed services provider, maybe they have a few different ways of working, but maybe they go ahead and they say here's what we'll do for a fixed amount per month per computer or per employee. We will take care of your computers for you. So we'll go ahead and patch them, keep them up to date.

[00:03:40] If they fail, we'll fix them. We'll replace parts in them, all of that sort of stuff. That makes sense to you. So they contact this managed services provider who takes over their network. How does that manage services provider? Run the network. They don't do it the same way that small business used to do it.

[00:04:01] They can't afford to, if they're going to charge you cheap money, they are using what's called an RMS. And the RMM in this case, we'll go ahead and it will remotely manage all of these computers for the managed services provider for that it outsourcing company. So it'll check the releases of software to let them know, okay, here's what we need to upgrade, et cetera.

[00:04:31] In fact, it'll even do the upgrades most of the time. And then when you call in or you file a ticket, that also goes into the RMM. So they have a full history of what's happened. What's going on over there and they can hire cheap people that don't understand computers. And for most businesses, they think that's just fine, by the way, this is my nemesis.

[00:04:52]We don't use Kaseya, but that MSP is using cassette. It might be using solar winds for some of this stuff. It might be using some of these other products. Now, the reason we don't use them is because all of them have failed our security test. So my company is called mainstream and we. Are a managed services provider, a managed security services provider to be more exact.

[00:05:22] And we've been doing managed services work since the early 1990s for other companies. And so we've tried every major player in the game out there. We've used them. We tried them. We tried to figure out, okay, is this going to work? And we've looked for flaws in their design, major flaws, major security flaws.

[00:05:44] And every one that we have found major flaws with, obviously we canceled. So we done basically a 30 day trial and we canceled them. Connect wise you name it. Okay. Major flaws and this company, cause  also has major flaws, but you, the small business owner, you, the small business office manager, you did not choose.

[00:06:10] You had nothing to do that you hired an it outsourcing firm and, seemed to make sense at the time. And it probably does make sense, but that it outsourcing firm is in what we in the industry call a race to the bottom. They have to get their costs down to a couple of bucks a month per person.

[00:06:30] That works for you. Do you think they can really do a good job for a couple of bucks a month? No, obviously they can't. So you get companies like mine that we use people that are well-educated that all have. All of our people have major cybersecurity training. All of our people know. How to fix the problems.

[00:06:53] And we run scans daily on all of our customers to check and see what's up, what needs to be upgraded or what needs to be fixed, what needs to be changed. Does that make sense to you guys? So that's what we do. And that's why there are nemesis, right? It costs us. Or what we charge basically is $125 a month per.

[00:07:15] Person and we'll keep the computers secure. Nothing's perfect. But we have yet to be breached in those 30 years. So we'll keep them up-to-date and we'll have the special advanced malware protection stuff on them and every yeah. Thing else. But these other guys that are out there, our nemesis, they're not charging 125 bucks per person.

[00:07:37] Or per computer or it's more for server? No. They're charging 25 bucks or 50 bucks a person there. And they can do that because they can afford to do that. They don't have what's necessary in the backend to keep their customers secure. So these probably thousands of companies we know of at least hundreds have been hacked.

[00:08:05] With ransomware because of a decision they made about a company, this it outsource provider that they just didn't know enough about to be able to even evaluate that in a nutshell is the problem with cyber security today. Even if you were to try and hire people to work for you and build out your cyber security infrastructure at your business and running it.

[00:08:35] How could you evaluate those people or the tools they use in 10 real quick. And Casia told all of their direct customers to immediately turn off all of the systems that had anything to do with Kaseya. Okay. This is going to happen again, people, and it's going to happen again and again, and I get it.

[00:08:58] A lot of small businesses can't afford people like me. I don't know what the best answer is, but we're going to talk about Microsoft and their answer.

View Details

Hey, do you trust that all of the information you share with the IRS is being kept safe? As a general rule, it probably has been, but what we're finding right now is maybe it hasn't, maybe there's been a leak.  There is a lot to talk about when we're talking about the IRS.

[00:00:19] They of course have all of the information that they can get their hands on. They're already overloaded and we've got the Biden administration now looking for even more data to go to the IRS. You probably already know that if you do a transaction at a bank above $10,000, that it gets reported to the IRS and probably the FBI, the CIA, the NSA, and any other three-letter agency that you can think of course, that doesn't include the BATF.

[00:00:52] Because they're not a three-letter agency as much as they want to meet, but the IRS has records on everything, already that they know what your social security number is, what your name is, what your address is. They also have information about. The business you work for or businesses you work for, they know what you do for a living.

[00:01:13] They know that you have debt and what that debt is. They know your business relationships, your family status, who you're married to, who your children are, if you have disabilities, because of course you put that on your tax forms and. Bunch of other personal data. Why do the bad guys, Rob banks, or at least they used to because that's where the money is.

[00:01:38]So where are the bad guys going right now? We're going to talk more about that a little bit later on today. And if you miss it, you can catch my podcast as well at Craig peterson.com/podcast. But they're going after businesses that take care of cybersecurity. Businesses. So this is a very big deal, but nearly every American has complied voluntarily with paying our taxes, that there's a whole idea behind this system and with the Biden administration now looking at all of this and saying what we want to do now is not the $10,000 limit. That's for wimps. We want to know. Any money that goes into, or out of all taxpayers savings checking or any other accounts or the value of more than just $500.

[00:02:31] So what the Biden administration is looking to do is turn every financial institution into a full-time IRS agent, basically providing them with all of this additional data. And then there's also plans that have been drawn up in Washington, DC. To move us away from the dollar and move us to a virtual dollar.

[00:02:55] And there's even planned. This is just unbelievable. If I had said this stuff a few years back, no one would have believed me. There's also plans to say if you have more than a certain amount of money in your bank, we're only going to give you like a 0.6 equivalent. So they're going to take away 40% of the value of your.

[00:03:13] And if you don't have much money heck we'll just go ahead and give you one and a half to two times as much money as you have in your account. It is incredible here. And with the privacy breaches we have seen in the federal government announced. This really isn't something we can put up with. We can't have them going after everything all of the time, because it just becomes too big, a target.

[00:03:40] And I'm not just talking about a target for the typical bad guys. I'm talking about a target as well for. Bureaucrats that have gone out of control. That used to be that if you were going to be prosecuted, they would have heard a story from someone. So it's yeah. Janie just cared. Jenny just killed her husband.

[00:04:03] So the police hear about it because there's a rumor floating around town. They go to talk to Janie, trying to look for her husband and they don't find her. Huh? And so now suspicion rises and they start investigating, they'll pull Jamie's credit card records. Look at what told booze she drove through.

[00:04:23] They'll look at anything that they can to try and put it together. Who did Jamie call her phone records and talk to those people, try and put together a picture of what happened. But if we devolve into one of these just terrible socialist state that have popped up and failed every time around the world, then what can happen.

[00:04:46] And what always happens is yeah. Yeah. The laws are there, but they're only enforced against people that they don't like. And that's a bad thing. So people that they don't like, I don't know, political people is usually what happened. Here in this country, think of what happened with Al Capone. They went after him under tax laws.

[00:05:08]And in both cases, they're trying to go after a person or people, not crime. So Al Capone. Okay. You could argue, he was doing all of these crimes, getting money through extortion and murder and everything else. So they're investigating that and they found out, oh, he didn't pay his taxes.

[00:05:27] Let's go after him for that. Okay. You could argue that. But what we can see with the government, having all of this information, think about all of our smartphones and our Alexa's and our Google homes and our cars. They all. Everything all of the time. And if the government wants to come after you, they can.

[00:05:48] I remember 30 years ago reading an article saying before he get out of bed in the morning, you've probably broken about 20 law. It nowadays, it's probably more like 50 laws. There's so many of them. There's 20,000 laws. At least there was back then 30 years ago, there were 20,000 laws just on gun control.

[00:06:09] Okay. It's insane. You cannot live your day without breaking a law. So what did they do while they selectively enforce? They selectively prosecute. So what happens here while the IRS. Perhaps selectively leaked information. Yeah. This is a story I'm looking at right now that came from Fox news.

[00:06:30] And they're saying that ProPublica published a story that this is just incredible. Okay. That had information in it. That was apparently from the IRS. Now, this is bad because this is information that wasn't available anywhere else than the IRS. This is information that was private. The IRS, none of this information is supposed to get out, they, you can go after president Donald Trump for tax evasion. Come on guys. First of all, that you can't Sue the president. It's crazy. Everybody would be suing the president that they didn't like a president Biden would have thousands of lawsuits against him right now. And he'd never be able to get a thing done that he was elected to do because he'd have to constantly be responding to lawsuits.

[00:07:21] That's how things were established initially here in this country. And I made a lot of. Pretty close to initially in this country, it made a whole lot of sense. If the IRS has given all this information, that's a real big problem. So the IRS security systems or procedures might've been severely compromised and all those data stolen, right?

[00:07:41] You might've had one or more IRS employees committing felonies by providing what is legally protected, private, taxpayer information to outside. Or a ProPublica could have just made it up entirely. Who knows this story and ProPublica, I don't really want you guys to go there. You can, if you want to do a little research, obviously, but I don't want them to get the hits and clicks and everything else, but these apparently are trolls.

[00:08:11] I've never before seen taxpayer information. June 8th that published this protected taxpayer data in a highly partisan yeah. Surprises, ProPublica, centralized, and misleading. Our article targeting people by name. This is all from this Fox news story. We don't know the scale of this was obviously a breach of some sort.

[00:08:36] Was it a cybersecurity breach or not? I don't like any government agency having any information that absolutely doesn't have to have. And on the case of the IRS, they are, it's easy to argue. They need access to. Records, at least the ones we send them. If they think there's a discrepancy, we'll then have a look at the discrepancy, figure out what went wrong, but they don't need to have everything.

[00:09:06] This reminds me of what happened with the national security agency. Just sucking in all of the data. It could possibly find it. Denying it and then ultimately saying we're just collecting general information. No one's identified in any of this and think of what happened, Mike Flynn, think of what happened with some of these other people in government, where they were identified and there's games that they're playing.

[00:09:34] No, we just don't have time to talk about this today but basically what happens is they can monitor communications that go outside of the country. So apparently they are purposely routing, targeted it data out of the United States. And then back in, so you could sending an email to someone in Washington, DC, or making a phone call and you.

[00:10:00] Phone call your email is purposely being routed by government out of the country. And there's some evidence that this is happening. There's certainly a lot of accusations. I get it. Okay. We need to crack down on people who are evading paying taxes that are owed under the law, but forcing these financial institutions to provide the IRS even more private financial information is going to embolden IRS P.

[00:10:28] To do what just happened with ProPublica. It's going to also in Bolden the hackers, and we've got a story coming up too, about the value of Bitcoin going up and the hacks, ransomware hacks going up along with it because of the value. So we'll be talking about all of this stuff today. There's a whole lot to talk about, I want to make sure you are on my email list.

[00:10:51] CraigPeterson.com.  You can subscribe right there and you can get all of these articles I had talked about and more every week. Stick around. I'll be right back.

View Details

[As heard on WGAN 2021-07-07]

Good morning, everybody. We've got this massive attack underway. It's hitting businesses, and they're using supply chain attacks just like they did with Solar Winds. However, this one might actually be a little more fatal. A lot of businesses out there. So we talked about that this morning—this Kaseya hack.

[00:00:21] We also talked about selling your smart device. Is it a good thing? I got a report from a listener about a whole bunch of Amazon orders that they had not made. So I'll tell you a little bit about that. And also, IRS looks like there might've been a data breach of what's going on. And frankly, what is the Biden administration proposing?

[00:00:47] That's going to make things way worse when it comes to data breaches at the I R S in the future. So here we go with Mr. Matt Gagnon.

[00:00:57] Matt Gagnon: And we're back 7:36 WGAN morning news. A pleasure to have you on this fine Wednesday morning. Thanks for listening. Craig Peterson, our tech guru joins us every Wednesday at this time.

[00:01:07] And of course you also hear them on this very station on Saturdays at one o'clock Craig, Welcome back to the program. Good to talk to you as well.

[00:01:14] Craig Peterson: [00:01:14] Hey, thanks. Glad to be here. Have a great independence day with the family. They all came in from literally all over the world. So it was cool. Yes, indeed.

[00:01:24]Matt Gagnon: [00:01:24] I hope you had a good one and and thanks for joining us now on this July 7th. So Craig, I know that we have, obviously every week we have a, some, topics that we want to chat about, but I did want to bring up this big gigantic. That happened as well. If you don't mind going off script a little bit here and talking about what what what we're learning about this stuff.

[00:01:41] I was just checking out some stuff this morning about how it still remains unclear how many businesses were actually hit by this gigantic ransomware attack. And and of course now, Demands for $70 million and everything else. It's all very reminiscent of earlier tax in the year where we paid ransom.

[00:01:59] And then you got, keys to decode things and it didn't even really work. And then they had to do it their own way. It's just part of this evolving story that is ransomware attacks. It seems to be getting worse and worse. And I just wanted to maybe get your thoughts on the effect of this.

[00:02:12] And is it getting worse? Is, are we going to see more? Yeah.

[00:02:15]What we're looking at is called a supply chain attack. So think of maybe a company that makes boxes for instance, and they, of course they need stuff from the supply chain. They're going to have glue. They're going to have staples are going to have various other things.

[00:02:31] And they trust the, the incoming staples and glue, et cetera, are going to hold the boxes together. That's what we're seeing here. We're seeing a company in this case, it's a technology firm called they're based down in Florida that provides services for businesses and governments, world wide.

[00:02:52] And the beautiful thinking about this from the hacker standpoint is they don't have to hack a hundred thousand companies. All they have to do is hack. Company and that's cause say, yeah. So cause they provide services for managed services providers. These are the, it shops, the businesses that you're using to manage your computers, your networks, your security, and the software.

[00:03:22] This can say a thought. Has full administrative rights to these networks. So if you can compromise one piece of software, you now have the ability to compromise a hundred thousand businesses and install ransomware steal information. Ever you want to do so we're still not sure as you pointed out what the actual ultimate problems are going to be for businesses because not only managed services providers use cause say, but so do government agencies, we.

[00:04:00] Major problems in Sweden were major. Portions of their economy were completely shut down, including mass transit. We've seen these problems before. And what happened really is people are putting their trust in these managed services provider, which I'm one, that's what we do for businesses. We do it for everything from doctor's office.

[00:04:25] All the way through government contractors, DOD contractors, but we do not use these tools because they are not safe. We have some of our own that are completely isolated. We've got to really change what we're doing because. Is absolutely huge. And we really just don't know what the ultimate problem or, the results of this damage is going to be.

[00:04:54] It's very scary stuff. Obviously a brave new world. We live in Craig Peterson, our tech guru joins us on Wednesdays at this time. Craig, moving on to other stories here. Been frustrating for me to wait for the tax man, the IRS to actually get me back my refund. I still don't have it. I'm one of, one of those people that still has been a Saturday sitting here waiting and delaying and blah, blah, blah, et cetera.

[00:05:16]But our tax system, really works on trust, right? Trust that your data and information will be more or less secure with the IRS trust that the IRS is actually going to give you back the money you deserve when you file your taxes correctly, lots of trust involved in the system. But what happens then when the IRS itself has a data breach, all that information, all that stuff, I keep handing them every year is now basically open it's open season on that.

[00:05:40]That's not a good thing.

[00:05:42] Craig Peterson: [00:05:42] No, it's not, they know your family status. You're filing joint married or separate, whatever might be of what businesses you do business with, because that has to be disclosed. When you're saying this is where the income comes from, what debt you have. Medical or disability status and just a whole bunch of other things this year, including whether or not you have been toying and you've made money off of Bitcoin.

[00:06:07] So all of that goes into databases and we're really concerned right now because president Biden has said that he is going to have the IRS. Force disclosure of even more sensitive information on almost every American taxpayer. So this is part of the government gathering, everything going in and out of our accounts.

[00:06:34] In fact, the Biden administration is now trying to get the banks to report any transaction that anyone makes a more than $600. Which is turning our banks and financial institutions into full time, basically IRS agents, which is a real problem. So ProPublica published a story that had information that was only a bit.

[00:07:00] Through the tax records and named a number of people and some private information. So we're not exactly sure what's happened here. Obviously, if the IRS might have been breached, it might be some insiders that are releasing information to her political opponents, which is not what the IRS is supposed to be doing, but we have all of this data.

[00:07:26] You can. The IRS is a major target of Russia and China already has all of the background checks for secret clearance and above of every federal government employee and military member as of a couple of years ago. So it's a huge target. I don't like the idea of the government requiring even more information going to them because it's going to become a huge or.

[00:07:54] Matt Gagnon: [00:07:54] And finally, Greg, I also want to ask about this this story that I was reading about selling your Amazon echo, your Google home any sort of device like this. I know a lot of people have privacy concerns, you go to sell it, right? Does your information go with it?

[00:08:10]Should you be. Doing something special factory wipes or something beyond that, maybe hitting it with a sledgehammer. What should I be doing in order to make sure that my information is not handed on to the next group of people that have my stuff?

[00:08:22]Craig Peterson: [00:08:22] There was a little bit of a study that was just done where this group went online and bought a number of these devices.

[00:08:29] The Amazon echo was, you mentioned. Google home devices and a few others. This is at Northeastern university and they got almost a hundred of them from E-bay and the flea market. And then they started to have a look at them. The first thing you should do, if you are going to resell them is do a factory reset.

[00:08:50] And that makes it a lot harder for people to get information off of them. But it is frankly, between you and me. It's very easy. Even after a factory reset to pull off information like the wifi information, the location that the device was used at the, even the account information of the person that had the.

[00:09:15] Device. And I have actually had a listener that contacted me saying my Amazon account now has been hacked and has been used to order stuff. And so they worked with the fraud department at Amazon to figure out what had happened. And according to this listener, the front department reported back that they had ordered things from their Amazon echo device.

[00:09:39] They had sold online app. A factory wipe. So you mentioned the sledgehammer trick and that is very effective at that, but I'm worried about these. I don't think I would resell mine. I think I would destroy them. But the big thing that you have to worry about are the hard desks and storage devices that are on our computers.

[00:10:07] Take a drink. Drill three holes safely into the disc area, the round area on a desk, and pretty much anywhere in the center, if it's an SSD, if it's one of these solid state desks and make some nice big holes in it and throw it out in the trash, we actually remove the platters from the desk and we melt them down.

[00:10:30] We have a furnace, we melt them in for our client. That's the only thing. That's a hundred percent, but the. Put a nice drill through those hard disks or SSDs and a sledgehammer to these smart drives are not smart. Drive smart devices and you'll feel much better as long as you do it safely. Get a little aggression out too.

[00:10:51] Matt Gagnon: [00:10:51] Indeed. All right. Craig Peterson never have aggressive feelings when you joined the program. Always good to talk to you and get the lowdown on technological stories. Appreciate it. Good luck on Saturday, of course. And we'll talk to you again next week, sir.

View Details

[As heard on WTAG, WHJJ, WHYN on 2021-07-06]

Good morning, everybody. This morning, I got to talk about this IRS data breach. We're supposed to trust them what happened here. We're actually not quite sure. And apparently, neither does the IRS. We also got into a climate battle. Should we be doing something more with nuclear power? So we got into that in some detail as well.

[00:00:24] So here we go.

[00:00:25] Pat Desmarais: [00:00:25] Craig Peterson joins us. Craig is the Jim Polito show tech expert and has some great stories to talk about Craig. Good morning.

[00:00:34] Craig Peterson: [00:00:34] Hey, good morning Pat.

[00:00:36] Pat Desmarais: [00:00:36] Sorry, we can't meet in person, my friend, but it is what it is. The phone will have to do. Hey, you got some great stuff for us to go back and forth about one of these stories I have now.

[00:00:47] Part of, and it has to do with our tax system and sensitive information that you and I give these people, the IRS, and you're referencing a story that published sensitive information from people. And they got it from the IRS information that people file because they were filing their taxes.

[00:01:09]Craig, what's up.

[00:01:10] Craig Peterson: [00:01:10] Yeah, that's exactly what's happened. We have so much information at the federal government level, including people who have had secret background clearances, top-secret clearances, any clearances, and all of this data has been stolen, at least from the office of management and budget.

[00:01:31] They've lost. Data the guys that control all of the information about all of the employees, all of that was stolen by China. And now we're finding that the IRS something happened there, it was either hacked, or there were some major leaks from the IRS. Now what we have to do as citizens.

[00:01:53] Isn't file our taxes. It's called a voluntary system, but that doesn't mean that they won't come after you if you don't pay. But it's voluntary in that. We have to give them that information. Now, this is two-sided. We have private information, princess things like our social security numbers that have gotten out.

[00:02:13] Probably every person in the country's social security number, at least almost everybody's has already gotten into that habit of the bad guys, but can we trust the IRS? Can we trust the feds with handling some of our most sensitive information? And because, as you pointed out, some of this information was given to the IRS.

[00:02:36] Has it been published online? Pro Publica has a story that puts this information out there. And we can only assume one of a few things they've been hacked or maybe one or more IRS employees committed felonies by putting this information out there. And by the way, it's legally protected. They're not allowed to do that.

[00:02:57] Maybe within pro-public Publica story is false and alleged information's manufactured. We're not sure exactly what's happened here, pat; I don't hold out a lot of hope. I think that maybe they're yet another victim of the hat. And

[00:03:13] Pat Desmarais: [00:03:13] Craig, correct me if I'm wrong, but this is something that has been reported now for a few days.

[00:03:18] I know that smaller companies, many had been reported being hacked. Is that true? And what is going on technologically here? It seems like it increasingly is not wise. Like I hate it, Craig, when I'm asked to give my social security number online, I hate it. I hate it. I hate it. I don't like doing that.

[00:03:40]This is the stuff secure or not.

[00:03:43] Craig Peterson: [00:03:43] Yeah. Yeah. W one of the bad things worse is if your social security number is stolen and is misused, it can take you up to 300 hours to recover your information, your good credit, et cetera. And that 300 hours is usually during working hours because you've got to call the banks.

[00:04:02] You've maybe have to call a car manufacturer, finance agents, whatever it might be. It's crazy. And the IRS. Will the social security administration will not give you a new social security number. Now, what you're talking about is this, Kasaya hack. We had solar winds hack here just a few months ago, which was devastating to many federal agencies and businesses nationwide.

[00:04:29] And now we've got you. Say it is a company that provides tools that are used by many what are called managed services providers. So these MSPs will want to keep their prices down their costs down. So they have this automated system that kind of takes care of everything. But what we see now is, again, a supply chain hack.

[00:04:54] In other words, you are a business and you would like a little bit of security and you'd like your machines to be updated. So you hire a managed services provider that MSP uses another service provider in this case, to actually do the grunt work for them. So that is the supply chain to you as a small business.

[00:05:16] But this hat now is showing that it's been pretty darn deep. We don't even know how far it goes yet. Sweden basically got shut down their banks their transit systems here in the U S there are hundreds of companies that have now received ransomware. And it's in place. And by the way, also that leads to extortions after the fact.

[00:05:42] But they have this in place because of their supply chain, because their managed services provider was using software that as it turns out was not safe. And now they're in trouble. As a regular businesses. So to answer your question, pat, where we are not safe, we can not push off our responsibility to keep our businesses safe or to keep us as individuals safe.

[00:06:11] We can't push it off to someone else and we certainly can't push it off to the federal government. We're in a tight spot here. And Microsoft is responding in much the same way. Apple responded almost 10 years ago. And Microsoft is tightening up things dramatically in windows 11. They're using special chips that are going to be on boards and computers that now will.

[00:06:35] Down your secrets, your passwords and things, which is a good thing, but we're still looking at ply chain attacks. You as a business are trying to trust someone else to take care of your computers and pat, they're just not taking care of them. Yeah.

[00:06:51] Pat Desmarais: [00:06:51] Good information. And it's almost like we're being victimized by modern day.

[00:06:55]Technological, Bonnie and Clyde's correct. All right. Correct. Craig Peterson joins us here. The Jim Polito show tech expert. Let's switch gears. I'm a big nuclear power proponent. I know it's not the in thing people seem to want to decommission them. More than anything else. I don't even know if we build any new nuclear power plants, but you had a story up there about the nuclear power plant in New York.

[00:07:19] And there's evidence that, Hey, look at, you want to reduce the carbon footprint. You took this nuclear power plant offline, and you actually increased carbon emissions at the same time. Talk to us about that.

[00:07:33] Craig Peterson: [00:07:33] Yeah, 46 per cent increase in the average carbon intensity of electrical generation, because nuclear is safe, particularly the new nuclear plants.

[00:07:46] Now we're still regulating our nuclear plants as though it's 92. This deed, if you can believe that 70 year old regulations in place, we now are up to about the seventh generation of nuclear power and the way these are set up, don't think Jane. Don't think of the China syndrome, right? Where are you going to have this meltdown?

[00:08:08] And everyone's going to die. That is impossible. Now these nuclear designs, and there are designs that are being put in place. Pat. They're not all out there yet. A lot of people haven't really. There's 70 years behind up to date, but these nuclear plants are designed that if there is a failure of part of a system, the basic physics of it will not allow it to get out of control.

[00:08:38] So you can consider these nuclear plants like a ball. You have a big ball. It's nice and round. And you've got a flat hill. That ball is not about to roll up there. Tell because of physics and that's what they've done with these new designs and when people, so they didn't, they just, him. Down the physics of them, it cannot happen.

[00:09:01] And people have been worried about, oh my gosh, all this nuclear waste is just terrible. That was 70 years ago. People that newest designs, if we can change these regulations are such that the nuclear waste is crazy. Minimally. And it's nowhere near as concentrated, and it can be recycled back into these newest generations of nuclear plants.

[00:09:25] So the

[00:09:25] Pat Desmarais: [00:09:25] story that you have, Craig. The story that you have is the Indian point nuclear power plant, which is 30 miles north of New York city. Are there any in America at all? Craig knew these technologically advanced ones that you're referencing is any new nuclear plants being built in a way.

[00:09:46] Craig Peterson: [00:09:46] Only very small scale ones.

[00:09:48] The us military now is taking some of these designs and they've got in fact right now, a bunch of bids out because they want small nuclear plants that fit into the back of a trailer from just a regular tractor trailer that they can bring out to different areas to provide power for them. So on that, Gail, the answer's.

[00:10:10] Yes. There are a couple of companies that are making them on a similar scale where they will run a small town from a nuclear plant that is buried in the ground. And doesn't have to be touched for 20 years. So yes, but the large-scale ones. No, they it's just, it's crazy. If he asked me, they're just shutting them down.

[00:10:32] They're not building the new ones, even though the new tech pat is amazing.

[00:10:36] Pat Desmarais: [00:10:36] Yeah, that my criticism is not, I live on Cape Cod, so they shut the one down in Plymouth. Craig, as you probably know, I didn't have a problem with that, but my thing was, are you going to build a new one? Oh God. No, but it's but the technology is so improved.

[00:10:50] No no. So I think you're right. A lot of this is, your horse and buggy thinking on nuclear power. You're thinking of technology from 50, 70 years.

[00:10:58]Craig Peterson: [00:10:58] Yeah. You're absolutely right. Dan, so many people got scared by that China's syndrome movie, and they're just not understanding what's happening out there,

[00:11:07] Pat Desmarais: [00:11:07] It's like mirror in a crate, people saw reefer madness and they think that's what pot is all about. You know what I'm saying? People see movies and it screws them all up. I've always thought that. All right, I enjoyed this. I don't know what made me think of that. Craig, Peter son,

[00:11:24] Craig Peterson: [00:11:24] very much Alexandria Ocassio Cortez is onboard with you and me. She said her green new deal leaves the door open for this new nuclear power.

[00:11:35] Pat Desmarais: [00:11:35] Yeah. There's no carbon print or you still have the the radioactive stuff you have to deal with. You still have to, you have to take care of that and store it. I'm a big proponent of you spend all this money on Yucca mountain. Use Yucca mountain.

[00:11:47]It's controversial and I realize that, but I love what you're saying and it makes perfect sense that we ought to, we want to deal with global warming, carbon footprint.

[00:11:57] Let's embrace nuclear power. It's clean other countries do it. Craig Peterson. I wish I had a little bit more time with you. I've very much enjoyed this conversation and I can see why they they bring you around. Great information. I appreciate it, sir. I hope that we do. Thanks now, Craig Peterson, the tech expert on the Jim Pollito show.

[00:12:17] Great information there wholeheartedly agree about what he was saying about nuclear power. And we ought to expand our minds a little bit folks on the new technology, the new type of nuclear power plant, just sayin'.

View Details

We've got a new study out, and its showing that one in five manufacturing companies are not only targeted by cyber attacks, but are getting nailed and getting nailed badly.

[00:00:19]This is a bigger problem, than I think most of us realize, and I have a few manufacturing clients who have been nailed badly by cyber attacks. Very badly. There is a new study out that looked at this it's called the manufacturing cybersecurity. Index. And this is a report that has the results of surveys of 567 manufacturing employees.

[00:00:50] Now that is quite a few and most of these people were in fact, in the it side of things, some of them were specifically in the cyber securities. That one was most interesting about this. Isn't the fact that just that one out of five manufacturing companies is targeted by cyber attacks, but what the response, what the thoughts of these people that run the companies are.

[00:01:18] And I say that because I am just constantly amazed at how businesses just are not paying attention to this, and this is proof again, and here's what it is. Information stealing malware makes up about a third of attacks, but companies are worried about what ransomware, the worried about ransomware shutting down production.

[00:01:46] That is a very big deal because of course it does, but what is going to hurt you more? And that's what you got to figure out. That's what companies have to really look. These numbers that we're looking at are according to this article I'm reading at a dark reading, which is a great site. If you haven't been there before, and you'd like to follow some of these things in the cybersecurity world, definitely check it out.

[00:02:15] Dark reading, very easy to very easy to look at lots of good stuff. But Robert limos is a contributing writer over there. And he's the guy that wrote that. And so he is saying that more than one third of all manufacturing firms are attacked every month. That's absolutely amazing. Now, of course not all manufacturing employees really know when a company is being attacked, but ransomware attacks that they know, because usually that means much of the company is shut down when it happens.

[00:02:54]Because ransomware attacks have this major impact on the business and the other types of attacks.  information most of the time companies never find out unless it's too late again, it's usually ransom or extortion. They're two sides of the same coin. So an extortion attack might be where they get onto a network.

[00:03:19] Exfiltrate data. And then they say, Hey, listen, we've got all of this data. Do you want us to post your bank, account numbers, customer information, your intellectual property, your plans, whatever it is, you want us to post them online? Huh? And if not pay out. Okay. So this is, I think a very big problem.

[00:03:39] There are major blocks between it information technology and security teams. And I also have to point out that most it decisions nowadays most what would normally be an information technology decision is actually being handled by a line of business matters. Who chose the software you're using to track your customers?

[00:04:06] It was probably the sales guy, right? There's the, it's not, the CEO is not the it director. It's the director of sales or marketing or the accounting people who decided to use QuickBooks online as opposed to using something else. All of these types of decisions are out of the hands of it and are way out of the hands of the cybersecurity.

[00:04:34] That's because of this massive changing landscape out there. It's absolutely huge. Now there's a survey also of 250 information technology workers, and they found that 61% of the companies experienced a cybersecurity incident affecting their factories. 61%. Of manufacturers had a cybersecurity incident that affected the factories and three quarters of those incidences took production offline.

[00:05:07] That's according to another report that came out in March, just mindblowing. Isn't it. So ransomware accounts for only 13% of these attempted attacks on devices. But the information thieves account for 31% of the attacks and file us attacks account for 28%. So here's a quote from morphous sec. These are the guys that produced the first report.

[00:05:37] I mentioned, although these sobering threats are certainly not limited to the manufacturing industry, cyber attackers are acutely aware of the data manufacturing facilities have on hand, right? Think about all of that data, think about all of the intellectual property. So it goes on. In fact, some cyber crime groups have even been using ransomware as a smoke screen for cyber attacks, designed to steal intellectual property, increasing the damage they can inflict in the long run as they bully victims.

[00:06:12] By threatening to leak data if they don't pay. Now, I've warned about that before. If you've got something that looks like a ransomware attack happening, pops up on your screen, it's got that classic red screen ransomware page. That may just be a smoke screen. You may not have ransomware.

[00:06:31] Your files may not be encrypted because what most of these guys nowadays are doing is making additional money offers, stealing your files solid. It depends on the group and this isn't what dark side does, but some other groups do and they can really socket. Ever since the authorities disrupted the emo tech network in January, we've seen attacks split into and smaller groups are increasingly working together in new ways.

[00:07:00] And these highly targeted groups are very dangerous because they can execute multi-faceted attacks, giving the collective expertise. Again, it's just like business. If you're trying to sell something, you need to narrow down and you need to get as narrow as possible. And that means the cyber groups are specializing in a specific industry and they're specializing in a specific way.

[00:07:29] To attack. This is really fascinating. And there's a few reports that come out every year. Verizon has a very good one on cyber attacks. Statistics. IBM has one gardener of course always does their little thing on the side. Those tend to be, and more narrowly focused, but this is the first time we've seen this report.

[00:07:51] So we don't have any sort of comparative data from prior years. But what the, what these guys are saying is that in that the pandemic has shifted attack trends and ransomware has grown from single digit percentages to 13%. As I mentioned already, almost two thirds of surveyed employees believe that the chance of a breach increased because of remote work.

[00:08:19] And we know that's true. BI has been warning about that. We've seen it again and again. So be very careful. Okay. Most of these manufacturing companies have had people working from home during the lockdown, nearly two thirds said that it has increased the risk of a breach. And let me tell you, it really has.

[00:08:40] And so keep all of that in mind, if you are in manufacturing or if you're concerned about our manufacturing base here in the us man, is there something to be worried about? And that's a shame. How do we conduct business? How do we keep our economy going? If our manufacturers are getting knocked down or getting knocked out of the game, Hey, visit me online.

[00:09:04] CraigPeterson.com. You'll find all of this all on my podcast and much more.

View Details

Well, you probably know again here, because you're the best and brightest, what a vigilante is. Well, I bet you haven't really heard about this type of vigilante before, and it is causing havoc for as many as 40% of computers.

[00:00:17]Well, vigilantes have throughout history decided that they were going to take the launch of their own hands.

[00:00:24] Now, way back when there wasn't law enforcement, et cetera, that's just what you did. And then we ended up with the tribes and our tribes would decide, okay, what's going to happen to this person. And you know, one of the worst things that could possibly happen way back. Caveman days. And after frankly, the worst thing that could happen to you is getting banished because having a group of people who are living together, cooperating together, working together makes all of the difference when it comes to survive.

[00:01:00] And being kicked out of that tribe out of that group meant you had a very low chance of long-term survival. And if you went into another group, they'd really be suspicious about you because where did you come from? Did somebody kick you out because you did something really, really bad? You know, I kind of wonder if that's not deeply ingrained inside of us from all of those.

[00:01:26] Centuries millennia with that whole type of process in place where we see someone that's different than us. And we kind of wonder, right. If you think that's where that might've come from. Interesting thought. I don't know that I've ever seen any studies about that. So vigilantes, nowadays are people who they're not going to the chieftain.

[00:01:47] They're not going to the local police department or the prosecutor who a, whoever it might be. They are taking the law as it were into their own hands. Now it's not necessarily even the law, they just decide that they want something to happen in a particular way. And by having that happen in that particular way, they now have control.

[00:02:13] Right. They're making the law as it were not just enforcing it. We have a lot of malware out there and there's a lot of different types. You might remember what Sony did, Sony. Decided they didn't like people ripping their CDs. And so they went ahead and installed an automatic installer for windows computers.

[00:02:36] So if you tried to play your favorite Sony CD, right. Audio CD, listen to some music, it would automatically install some what. You and I would call malware on your computer and it would look at everything you were doing on your computer. To try and make sure that you were not trying to make a copy of the desk, not just a copy, but what we call ripping it.

[00:03:07] In other words, you have a CD and you have an MP3 player. How do you get the CD on the MP3 player? Cause you can't just stick it into an MP3 player, so you have to rip it and that converts it from the CD format into an MP3 format. So it's all digital. You can take it away. And I have really griped about the music industry before, because they make way more money off of CDs than they ever did off of records.

[00:03:36] Just because of how cheap it is. It costs them like 10 cents, not even to make a CD. And it costs them a couple of bucks to make a record back in the. So they decided they would do digital without thinking twice about while digital means you can a perfect copy, perfect coffee copy of that desk. And so it's only, he said, I'll go, well, here's what we're going to do.

[00:04:00] We're going to make this. And so it installed itself. Way down deep inside the operating system. It watched as you loaded up desks and watched what you did that is malware. And that was Sony being frankly, a vigilant. Yeah. They said, Hey, it's for copyright protection, but there was no encryption on CDs.

[00:04:24] There still isn't on compact discs. When we're talking about music desks, there is encryption on DVDs and that's what they did in order to say, well, you can't rip it because it's an encryption. Past the digital communications millennial act. And then from that act, they were able to now have controls. Hey, listen, if it's something's encrypted, you can't even try to dig.

[00:04:47] Okay. Pretty, pretty big deal. So there's a whole lot to this whole vigilante thing. And someone is added again, in this case, we found a researcher who has found something you just don't really see very often, you know, outside that sone thing, but it's booby trapped file. Yeah, there's these files that are out there on the internet on a bunch of torrent sites and others that are pirated software and they have a booby trap inside.

[00:05:25] Now the pirated software is typically things like a Microsoft windows or all of their different software, right word. And you name it all the way across the line. They also, by the way, have put some of this malware into games because there's a lot of people that run games and they grabbed these cracked games from the inside.

[00:05:52] So we're talking about boob bootleg talk. And so what this person or people, or whoever it is, is doing according to Sofos labs, principal researcher, his name is Andrew Brandt is get getting these people to install this software that has. A booby trap and that what it does is you think you're just installing the game or whatever it might be.

[00:06:22] But in reality, you're installing software that sends. The file name that was executed to an attacker controlled server. So it knows, oh, you're trying to run Microsoft word and it sends along your IP address of your computers. And then what it does is this vigilante software. It tries to modify the victim's computers so they can no longer.

[00:06:50] Access some, 1000 other pirate sites, like the pirate bay.com, which is a very popular site out. Oh, out there. So this is obviously not your typical malware, not at all. And they are doing this same type of thing. That's so needed way back in the day, modifying your computer so that you can not do something that may be illegal.

[00:07:19] It may be mostly, most of the time, he illegal, hard to say, but in reality, they're modifying it without you knowing. It's a very, very big deal. So people are using software, kind of like this vigilante software to steal stuff. Usually it's passwords, or maybe your keystrokes or cookies or your intellectual property access Eve, the people are even using ad networks, advertising networks to deliver software.

[00:07:51] But that will mind cryptocurrency for them. Okay. But those are all theft. That's what the motive is, but not in this case. These samples really only did a few things and none of them follow the motive for malware criminals. It's fascinating. He had a thing that he posted over there on Twitter, kind of talking about it, but once the victims executed this Trojan file, it gets sent out to a server and I'm sure the FBI is tracking down this server.

[00:08:24]It's one flourish. She drew.com in pronounceable. And it's it's not the one fee share, which is the name of a Cod storage provider, but it's pretty close to it. And it sends it out. I'm looking at the list of all of these websites that it tries to block by going into your hosts file. But it's an interesting way to approach it.

[00:08:48] Isn't it, frankly, by mapping the domains for all of these torrent sites and pirate site. To your local host, the malware is making sure that your computer, I can't access those websites. Okay. Anyways, if it happens to you just go in and edit the host file. It's really quite that simple. All right. Stick around everybody.

[00:09:10] But while you're waiting, go ahead, go online, go to CraigPeterson.com. Once you're there. You can easily subscribe to my newsletter and keep up-to-date on everything. CraigPeterson.com.

View Details

[As heard on WGAN 2021-06-30]

From man-caused like hackers through the environmental causes, like the sun, we could lose power. We've got a heat waves. We've got cold weather. We've got everything in between. What happens if we lose power, what do we need to do? That's what I discussed this morning with Mr. Matt Gagnon

[00:00:24] Matt Gagnon: [00:00:24] Craig Peterson joins us every Wednesday at this time to go over what's happening in the world of technology.

[00:00:29] He also joins this very station on Saturday. And talks about many of these very same issues in more depth of detail. Craig, welcome back to the program. Nice to have you as always, sir.

[00:00:39]Craig Peterson: [00:00:39] Hey, thanks. Glad to be here in such a nice or arm day, you said this tongue in his cheek.

[00:00:45] Matt Gagnon: [00:00:45] I believe oppressive heat is the word you press.

[00:00:47]Craig Peterson: [00:00:47] I grew up in in Canada and part of it was Northern Canada and the 70 degree day was like summertime. So my blood, I don't know my hips historically. I did the whole thing with the, the DNA in tracing ancestry. It's all from Northern. But you've Norwegian, et cetera. I think I am one of those minorities that is really heavily oppressed and should probably be getting free air conditioning.

[00:01:17] Cause my blood is just too, I don't know, sick, I guess for this.

[00:01:20] Matt Gagnon: [00:01:20] Yeah. I'm very sympathetic to you, Greg. And I think it does. I would say dovetail nicely into the question I was planning to ask you about. During heat waves here, that we've had so many different infrastructure attacks, hackers are getting into our energy.

[00:01:33] Great. And whatnot. That could be a bit of a deadly combination in the middle of a heat wave. Could it not? I would be concerned. I learned about that if I had your stick blood. So what should we all be concerned about as it relates to our security, as in, in terms of our energy grid end.

[00:01:47]Craig Peterson: [00:01:47] We need to spend some serious money.

[00:01:50] Think of that collapse that has happened down in Florida of that condo building. And the fact is that they had to spend millions to fix that building. In fact, it was like $120,000 per rev. Our grid, our electric grid, our water stations need the same type of investment. We have to tighten this stuff up because as you pointed out, we're seeing people dying right now because of the heat and the lack of air conditioning.

[00:02:23] Look at our grid. How many times has been attacked? And the problems that have come from it. Plus of course the whole nature thing which could destroy our grid would just one nasty solar flare. And we really have a combination of things that could cause serious damage. So if our enemies decide what they want to do is just.

[00:02:46] All kinds of confusion, people dying from the heat and in the wintertime, of course, also from the cold, they have the ability to shut down our grids. We really need to focus in on this. The price of electricity is going to go up even more if they do this, but it's an absolute necessity. Cause remember.

[00:03:09] Harrington event, which happened in the mid 18 hundreds, where there was a massive solar flare and it hit us here in the United States in a very bad way. But back then, it was just the, the Telegraph machines, one of those events, like the Harrington event happening now would put us back in the 18 hundreds for months and possibly years for some parts of this country, because we can't.

[00:03:36] Protect ourselves adequately from even that let alone the hackers out. There

[00:03:41] Matt Gagnon: [00:03:41] it is. Craig Peterson who joins us, he's our tech guru. And we hear from him every single Wednesday at this very time to talk over the world of technology. Another thing I've noticed too, spinning off into a totally different direction.

[00:03:53] Craig has obviously the criticism of, and hatred of. The big tech companies continues to grow. I think, and what's interesting about it is that there's a lot of distrust and dislike of them in a bipartisan way, right? There's a there's Republicans that don't like them, obviously because of the free speech issue.

[00:04:09] And there's a lot of left wing folks who also don't like them for entirely unrelated issues and reasons. But now there's a house committee which has approved a bill that could potentially break up Amazon, apple, Google, et cetera. What is

[00:04:22] Craig Peterson: [00:04:22] this all about? Yeah, this is a very big deal because these big tech companies keep getting bigger and they use techniques.

[00:04:31] The key competitors out of the marketplace and the techniques include buying companies that are worth tens of millions of dollars for a billion dollars, just so they don't have any competition. So we have this bill that was approved called the ending platform. Monopolies. Which came out with true bipartisan support came out of that committee.

[00:04:56] And the question is, what do you do, Matt? These companies are really doing things that are not technically against the antitrust act, so that we have act here in the S. But in reality, are it certainly by the spirit of that law because they are keeping competition out. Now, I would like to say that the free market would take care of this, but again, we don't really have a free market.

[00:05:26] And also the amount of control these people have is such that their profit margins are insane. Every one of these. Tech companies we're talking about. And then I include apple, Google, Facebook, Amazon. Every one of them has billions of dollars in cash sitting there in the bank to keep them. In that position.

[00:05:50] So it reminds me of the robber barons way back when the late 18 hundreds, early 19 hundreds, the controlled so many of our industries here in the United States, they cause the antitrust laws to be put into place. Something has to be done. And yeah. I just don't know, Matt I'm not somebody who really trusts government any more than I trust to any of these big tech companies.

[00:06:15]Matt Gagnon: [00:06:15] It's a question of who do you hate more right in the end of the day. All right. Final question for you, Greg. I'd like to go in this direction because we heard about John McAfee, recently passed away under not at all suspicious circumstances. Epstein didn't kill himself by the way.

[00:06:29]McAfee of course is the Titan nor was the Titan, the originator of a big antivirus software company, which many of us have had installed on our computers against our will and had to deal with in some way. Antivirus software is in and of itself interesting. Cause I was just reading somewhere that a lot of antivirus software actually misses.

[00:06:48] A gigantic amount of malware that ends up being on computers. Is this a problem? And if it is what do you do about this? There's just going to have to make your peace with the fact that your computer is infested with malware now or are there other options?

[00:07:01] Craig Peterson: [00:07:01] Yeah, McAfee of course had tattooed on his body.

[00:07:05] Find me dead. I did not kill myself. We know that he was not suicide. In Spain, the Spanish jail, your questions are really good. One because we're seeing as 70%. Mentoree antivirus software this year has missed 77 0% of the attacks that have been coming this year and McAfee himself came out and said that the McAfee antivirus software is useless against today's threats.

[00:07:39] One of the senior executives at Symantec, which of course has Norton and other antivirus products, all. Came out and said our software's useless against modern threats. So to answer your question, there are some things you can do. And I'm going to go into this in more detail this weekend. I think it's an important thing here on our July 4th weekend independence day.

[00:08:03] The bottom line is antivirus software no longer can protect you is using outdated technology. It's using signatures. So what happens is you can just like with a virus, you can get the virus and the body now knows those. T-cells remember how to fight that virus in the future. Antivirus software is much the same.

[00:08:30] It's looking for. Things that have been seen before. That's not what's happening anymore. We're seeing all new threats, just constantly. We're seeing phishing attacks and the, it gets around the antivirus software. There are some solutions or some things you can do. And frankly, if you're running windows, There's some pre things you can do.

[00:08:53] And I'm going to also, it's part of the series I've been doing. I'm going to be releasing this to people on my newsletter. I made a video last week, in fact about some things you can do. All right. But you have to sign up. You have to go to Craig peterson.com/subscribe. And you have to listen on Saturday from one till three, because we will be talking more about this as well.

[00:09:15] Matt Gagnon: [00:09:15] And there you go. Promoting the show on the weekend. I love doing it. Craig Peterson, our tech guru always joins us on Wednesdays at this time. I appreciate it, Craig. Thanks so much. And we'll talk to you again very soon, sir.

[00:09:24] Craig Peterson: [00:09:24] Take care, Matt.

View Details

[As heard on WTAG, WHYN, WHJJ on 2021-06]

You might have an idea of how much privacy has been lost. I went through a lot of the details today. The idea is to help you understand what you're doing to yourself by using all of these different new technologies and what can you do right now to start getting your privacy under control? So here we go with Mr. Polito.

[00:00:29] Jim Polito: Our good friend tech talk guru Craig Peterson has talked about this before. When you click that, "I accept" in the terms and conditions for something online, he is always explained what's going on there. And how, in many instances, as you are the product for that app, the app is in the product.

[00:00:48]Now there are more concerns about just clicking "I accept." Joining us now. We accept our good friend here every week at this time, Craig Peterson the tech talk guru. Good morning, sir.

[00:01:02] Craig Peterson: [00:01:02] Hey, good morning. Click away. It's quite a thing. Isn't it. Where does this article come from? We're talking about, did you notice this?

[00:01:10] The daily mail came out of the UK, not in America.

[00:01:15] Jim Polito: [00:01:15] Yeah, I know. Very interesting. And I just happened to have the daily mail app on my phone because it's one of the stops I make in show prep. So there's a warning. And of course, Greg, this doesn't come as any surprise probably to regular listeners because you've been talking about all the things that are included in there.

[00:01:36] And but what's the latest concern.

[00:01:38]Craig Peterson: [00:01:38] What they did is they put it all together and it's rare that you see this. So they started Dawn. What's the first thing you do while you check at your phone, I would actually put it back even a few hours. What do you do at night with your smartphone? You plug it in and it's sitting right there next to you.

[00:01:57]So now you've got all of these busy bodies that the tech companies cause remember. Apps, many of these are tracking use. They're not free. They're gathering information about you. So they know every night Jim puts his phone here and oh, buys the ways. So does this woman and this guy. Oh, okay. That's where Jim Pollito lives, right?

[00:02:21] So it's your smartphone manufacturer, particularly if it's Google, but it's true for apple app developers or mobile phone company, intelligence agencies. If they're watching you, which happens all the time. But all they're doing is collecting metadata.

[00:02:43] Yeah. That's exactly what it's used for, what time you're waking up where, who you're sharing your Baird bed with? Where are you going when you go to work? If you're speeding, when you're going to work, right? It's anybody's guess where all of this stuff is ending up at now. We're adding ring doorbells that we have on the front of our home.

[00:03:04] Please more than I think it's 1500 right now. Police departments are taking these feeds from ring. So now they have cameras in all of the neighborhoods. We have facial recognition from those ring cameras and from all the other cameras are putting around our home. So they know where we are, who we are.

[00:03:23] Vizio. A TV manufacturer has been caught. Watching us through a camera, hidden camera and the TV, listening to what we're saying. And even if the company isn't doing now, like your Samsung TV, they are tracking exactly what you're watching, where it's going. Facebook has been accused with. They're a wonderful little portal device, which is a, something that allows you to talk to someone.

[00:03:50] Face time. They've been accused of listening in on everything you're saying, because people including my son last week, he was at his girlfriend's house. She has the two of these Facebook portals. They started talking about maybe getting a hammock. Talking about it, not on a conversation on the portal at all.

[00:04:09] And all of a sudden what starts happening, their feeds are showing ads for hammocks, even though they hadn't looked for them before. So our cars are logging the places we're going. They're tracking how fast we're going. We have legislators right here in mass who are looking at it saying these electric cars, oh my gosh, we're not getting our gas taxes, which we don't bother using to fix the roads.

[00:04:34] That would be a terrible. It was electric cars. Aren't paying gas taxes. We want the cars to report on you and tell them how many miles you drove in math. And from that, they will send you a bill every year. If you want to, re-register your electric car. We were doing DNA testing kits for health reasons.

[00:04:55] Maybe we were trying to find out if we truly are Italian or. That genetic information is up for grabs anybody who's willing to pay for it. This is a surveillance state at something even the Staci weren't able to do. They only had files on about a third of the population of east Germany intelligence agencies today here in the us.

[00:05:17] Remember. Our information that was being kept by the federal government, including all the background check information for people that have secret top secret and other clearances, all of that information was stolen by China. We're giving this away. We are not keeping it safe. We're on top of all of this, Jim, we're telling people we're going on social media.

[00:05:40] Oh yeah. I'm going away for a week. We're going to a w wherever on vacation, it's going to be a great time. So now even the bad guys know this is amazing. We have right now started to enter the days of artificial intelligence. Yeah. And it's not like you and I, the way we think it's putting pieces of a puzzle together, that's what computer artificial intelligence is all about.

[00:06:06] And all of this stuff that we're allowing to be tracked from the national health service all the way on down in the UK and in the UK. This is really something we've got to start pulling our wings. And we're talking

[00:06:20] Jim Polito: [00:06:20] with our good friend tech talk guru, Craig Peterson, Craig here's the thing.

[00:06:25] So the reason that Facebook and these other places can offer all these services for free is because we are the customer and then they sell that information. You've just laid out the scenario about how those things get stolen, but they sell that information. Is this something where the government steps in with better regulation?

[00:06:47] Or is this something where the marketplace says, Hey, do you want something like Facebook? Okay. Pay me $5 a month and you can have it, and then we won't try to do all this stuff, you've got to pay you to have this service.

[00:07:01]Craig Peterson: [00:07:01] Facebook did try that at one point they were floating the idea.

[00:07:05] But I want you to consider one other thing here, Jim, when you're talking about this, when has government ever decided they needed less information about the people?

[00:07:21] Jim Polito: [00:07:21] Yeah. Yeah. You're rife. They don't, they want to know everything. Cause then they want to tax it. They want to regulate it. They want to, whatever. And here I am just bringing up regulation, but yeah.

[00:07:33] Craig Peterson: [00:07:33] That's exactly what they're going to do. That's what they do. The job of a bureaucrat data.

[00:07:38] I have Ribeiro grad in this country, whether they're working for the town of pod talk at Rhode Island, or they're working for the federal government, every bureaucrat in the country has one job don't get fired. And then the second job is grow my faith. Yeah. And that means that even if they were to pass laws, you remember, we already had laws about the federal government not watching us.

[00:08:04] And then we found out, oh, wait a minute, eight T and T had been feeding the federal government, all of the information about all of the phone calls in the country since 1950. Yeah, there were laws against it. Okay. It, even if they say, okay, you can't use this information, you're gathering from marketing is what I'm more at about, frankly, because if I'm looking to buy an F-150 truck, I'd love to see offers on F150 trucks.

[00:08:32] Okay. So being able to track me in my searches make sense. I'm extremely worried about. Everything else. And I'm very worried about this artificial intelligence being used, frankly, for evil. And it already is with some of these phishing attacks. It's this is just something it's something Facebook, by the way, even teams shadow profiles on people who don't even have accounts, because when you join Facebook, Facebook says, Hey, you want me to find your friends so you can link into them?

[00:09:05] Yeah. Just upload your contacts to. Who did

[00:09:11] Jim Polito: [00:09:11] so Craig, in the short time we have left what do you do? What do you do.

[00:09:16] Craig Peterson: [00:09:16] I'm having a meeting about that today. In fact, there's some friends, I have a couple of attorney friends, and some other friends who are looking at this and saying, this is nuts.

[00:09:25] What do we do? Apple is the only one. So you've found manufacturers out there that really does have your privacy in mind to a large degree. They have mostly been keeping us safe. That is generally speaking the best thing that you can do, but don't volunteer information, post himself up on Facebook.

[00:09:47] You're posting pictures that have the GPS coordinates of where it was taken. Facebook has based. So recognition don't do that. Get away from doing that sort of thing. Also be careful with the information that you're sharing with any other company out there, Google some of these free photo services, et cetera, et cetera, that pulling it all together.

[00:10:10] Facebook's given Microsoft search engine, the ability to see Facebook friends without their consent. It gave Netflix and Spotify the ability to read and even delete Facebook users. Private messages. Don't use these companies, mark Zuckerberg, the allegations are all out there that Facebook was started using illegal methods.

[00:10:32]Crazy illegal methods scraping the the horrible. Book, if you will, of students and having people rate how good looking that woman is. Okay. All well and good, I guess if you were a teenager, but come on, this is not an ethical company. Google is not, they've even removed this slope.

[00:10:52] Don't be evil from their website, stop using them things like duck, go for your searches posted up there. Don't make sure you turn off GPS tracking on everything you can paying attention. Apple now has this new feature that will tell you every app. Exactly what that app is supposedly doing in collecting data and doing with your data and make intelligent choices.

[00:11:19] Jim Polito: [00:11:19] I got it. Craig, how do folks get more information?

[00:11:23]Craig Peterson: [00:11:23] The easiest way is just go to Craig peterson.com. That's Frank Peterson with an o.com and you can subscribe to my newsletter. You'll get all of this stuff. You'll get also links to all of them like podcasts and nerves about I do about a dozen a week.

[00:11:39] Believe it or not. Wow. And you'll be able to listen to those and you can listen to them on the iHeart radio app. Just go to Craig peterson.com/iheart or click on the iHeart logo. On my homepage,

[00:11:51] Jim Polito: [00:11:51] Craig Peterson, everybody. He's the man, Craig. Thanks so much. We'll talk with you next week.

View Details

We've got some really cool news that some people have interpreted as bad news. And this has to do with general motors and their hydrogen fuel cell. This is a very interesting story.

I've always been fascinated with the Hindenburg and what happened there. And I did a lot of investigations. And of course, there was the initial investigation that happened back in 1937. When the Hindenburg actually crashed, I found online, you can buy pieces of the Hindenburg online.

[00:00:35] There's this kind of an auction house. You can get a small square of the fab. Of the Hindenburgs outer shell for 99 bucks. I found them online. I didn't buy any, although I was thinking, that might actually be cool, but what am I going to do with it? Rights to get on a wall then what w what was interesting about it and about the fabric was what the German engineers had.

[00:01:01] Now we know that you can use helium and helium is a great little gas it's inert. It's not going to catch fire. It is also lighter than air. There's a lunch, a lot of others, great properties that has, you can use it for super cooling things that you can't with. Most other gases, helium is much better for super cooling than oxygen is.

[00:01:23] And hydrogen is Excel. Helium is getting hard to find the United States had a strategic reserve of helium. Now, to me, that makes sense because we did at one point need helium. We had dirge bubbles. We still do. We still use helium to send weather balloon. Been various other things, but then the federal government decided ELA.

[00:01:48] We don't need to keep this reserve anymore. So they sold it off. As of next year, there won't be anything left in that strategic reserve. So where do we get helium? We get it from regular old oil mine. So they drill a hole it's created by the breakdown of various elements in the soil, primarily some of the hard rocks.

[00:02:14] And as they break down and decay, they produce helium as one of the byproducts. Now what's been happening in the reason we are in. A helium shortage. Number three in fact, is that we are now fracking. Fracking Lutz is extract a lot more natural gas and a lot more , which is what we're really trying to do and keep some of those costs down.

[00:02:44] But it also does not create as much helium and that's. And it's a really big problem when you get right down to it and you're trying to figure out if we're going to fill up a balloon, that's going to go up. What are we going to do now? Approximately a quarter of all of the helium that's news out there goes into these birthday balloons.

[00:03:09] Okay. So yeah, it's it's kinda cool, but it's not an absolutely necessary thing, frankly, but it is used in all kinds of other things, including experiments. You remember? I said that helium is used to super cool thing. Think of these massive hydraulic colliders, some of the other experiments that are going on, where we have a magnet.

[00:03:37] Now, one of the biggest, most important things we're doing with magnets right now is trying to create a container for nuclear fusion. Now nuclear fusion doesn't have the byproducts of nuclear fusion. Although we've solved most of those vision problems, you don't have this highly radioactive stuff anymore that we used to have in the old reactors.

[00:04:01] Although we haven't been building new ones for what, 40 years now. But those particular types of containers, if you will, are built by these big magnets. So these magnets hold it in place. And in order to get the amount of power we need to, to these magnet, we have to super cool them. We have to super cool, the power supplies, and that is typically using helium.

[00:04:27] So we've had to shut down some of these experiments. Because we don't have enough helium so much for the strategic reserve, that is almost completely depleted. And by the way, the federal government in its infinite wisdom sold that helium off at a fraction of fair market value. That's a problem because it just went crazy.

[00:04:52] People were using it for things that just weren't that important. And now many of our experiments are getting shut down, but in the world war two era and pre-World war II era Germany had a problem trying to get helium itself. Germany doesn't have a whole lot of oil reserves and it had to buy everything.

[00:05:12] And the United States really didn't want to sell here. To Germany. So what Germany did and you guys probably all know this from your history lessons, cause you are the best and brightest hydrogen was used. And because hydrogen was used it was a flammable gas. And when there was a spark, when it was trying to land.

[00:05:36] It went up, it caught fire. Now what's really interesting is if you look at the pictures that were taken of it burning, there were obviously elements other than hydrogen, because hydrogen burns beautifully pure. You can't really even see it. And what would normally happen is you wouldn't have. Poof.

[00:05:58] And the whole thing just burns up. You'd have a hole and that hole be shooting a flame out as it was ignited, right as the hydrogen was ignited and the whole, my discontinue to get a a little bigger until there's no pressurized hydrogen anymore. And the fire's over, but that's not what happened with the Hindenburg.

[00:06:18] She caught fire. Because of that spark and it had that spark because of the weather conditions at the time, they just weren't being cautious enough. In fact, that was the very last large dirigible Airship. Ever made, frankly it's crazy, yeah. We got the Goodyear blimp, we got some of these others and they need the helium to fill them up.

[00:06:43] And then over time it was kinda like a swimming pool. You filled it up and you, all you have to do is just add a little bit more now, and then you don't have to, because of leakage, you don't have to completely refill it all of the time. So what ended up happening is they had hydrogen on board.

[00:07:02] Had the spark started a flame and then the cloth material that coated this massive container holding all of the hydrogen caught fire, but it didn't just catch fire. What happened was it caught fire and. It burned very quickly because effectively the entire outside surface of the Hindenburg was coated with rocket fuel.

[00:07:30] Some of the same components that go into gunpowder aluminum powder, which gave it that kind of silver shine. They really messed up. So people are looking at what is happening now with general motors. Tech fuel cell technology and other a little bit worried because this technology was developed for cars.

[00:07:51] It is being used in some parts of the world, in some parts of the country. I know California has some hydrogen cars on the road with a fuel cell. Now they're not burning hydrogen. In order to transport the car, they're actually allowing a chemical process to occur. So the hydrogen atom is attracted to the oxygen atom and they use a membrane so that they're trying to get together.

[00:08:18] And that's what produces electricity. And then what is the result when you have two hydrogen atoms and an oxygen atom and they combine H two O so the only. Final end product here coming out of that car is pure. Which is cool. So GM says wait a minute. Now we have this technology, why don't we try and make airplanes a little bit more efficient?

[00:08:45] And so they're saying you don't, you're taking off with two tons of water on board. How about we put a hydrogen fuel cell in there. You will be well to generate electricity. Now that's a very big deal because now that electricity doesn't have to be generated by the turbines of the gas engine. And on top of it all, you don't have to take off with two tons of water on board because we can generate water as your.

[00:09:16] And of course, they're not going to coat it with a rocket fuel. They are going to put it in one of these really cool containers that is considered to be very safe. So it's very cool. So the litmus test, according to our friends over at general motors, he this is a GM executive. Director Charlie frees.

[00:09:36] He says our technology can address customer needs in a wide range of uses on land, sea, air, or rail. And this collaboration we could open up new possibilities for aircraft transitioning to alternative energy, power sources. Now I don't expect a plane to be actually flying on this any time soon.

[00:09:58]Hydrogen is a great little fuel, but it doesn't provide enough energy to get that jet off the ground at all, but it does provide enough energy to supplement it so good for them. I think this is a good use frankly, of the hydrogen fuel cells, as long as we can avoid it leaking and causing other major problems.

[00:10:21] But I think that can be solved. Look at what we've been able to do now. These containers for the pretty much everything that can be hit by a train at full speed and not. So I think we got this covered. All right, everybody stick around. We'll be right back. And we're going to talk about it. A new type of vigilante that you may not have heard of before.

[00:10:46] Of course, you're listening to Craig Peterson. Check me out online. CraigPeterson.com.

View Details

[ As heard on WGIR, WQSO, and WKXL on 2021-06-28]

Privacy is gone.

We started talking this morning with Mr. Christopher Ryan, and we got into our privacy. There's a great article that I'll have this weekend in my newsletter from the Daily Mail about about this whole thing.

And it's titled "Read This and You Won't Click 'I Agree' Ever Again". So we got into that and also into this new bill here, it's called the ending platform monopoly, please act, can we split up these huge companies, these social media companies, et cetera, that are providing various platforms. Should we split them up?

[00:00:37] This is a real interesting topic and one that's going to affect every last one of us. And of course, Chris and I both had opinions.

[00:00:46] Chris Ryan: [00:00:46] I am Chris Ryan. Craig Peterson is the host tech talk on news radio six, 10 and 96. 7 Saturdays and Sundays at 11:30 AM.

[00:00:54] One of the more fascinating things about the tech environment is how. Either we don't care or it's unbeknownst to us that we allow for tech companies to spy on us and to have an inner track basically to our minds and to our souls were for many years, we always wondered why other people were thinking, right?

[00:01:19] Like what does that person thinking? And there was no way to ever really. But now there are ways to know, because we look into things on Google. We look into things via searches and we like certain things. We agree on certain things. And as a result of that we at some points in time are just giving the money, the giving information to tech companies, but at other points in time, We're actually showing via social media, who we are in ways that we never would have done in the past and employers, friends, everybody get a completely different view of a person's true inner feelings and how their mind works via social media that we never had before.

[00:02:02] Craig Peterson: [00:02:02] It is potentially a huge problem. We've got these busy bodies, if you will, that are listening to basically all of the signals we're sending out. We tell them where we live. You may not have given them your address, but if you have apps on your phone that you guaranteed that smartphone now who stays in the same house every night, they know where you.

[00:02:26] They know what you're like because of what you're searching for online, the website you're going to, they know what you say with some of these devices. My son I had was over his girlfriend's house and had a conversation with her about getting a hammock in front of one of these little portals from our friends at Facebook.

[00:02:46]Immediately ad started showing up for all of us. So we're telling these tech companies, everything that we're doing, we have microphones in our rooms, our television visions, Vizio, which is one of the major manufacturers was caught watching us. Who is looking at the TV when they're looking at it so they can get better ratings.

[00:03:09] Microphones are being used. The spy agencies worldwide now have direct access to us. It's a real problem. And it's a problem for you and me, not just for someone that's a high tech. High value target. It's a problem for you and me because now all of this information is also available to the regular bad guys.

[00:03:30] That's what they're using for fishing. They're getting you to do things on marketers are getting you to do things. Obviously the PI getting all this information and showing you the right information at the right time, the bad guys are getting you to do things by clicking on it. So links going to websites that are actually going to cause you harm.

[00:03:51] And we're seeing huge increases in all of this, Chris. Right?

[00:03:56] Chris Ryan: [00:03:56] And it's the, those types of things are happening behind the scenes, but it's also a lot of the outward things. What do you post about, what do you say? How do you interact with other people? All of these types of things are accessible to the public at times, and also accessible, behind the scenes as well.

[00:04:13] And it allows for a catalog to be built on you as an individual. And we are. Insight into our inner thinkings and our process that we would never have thought about that our parents would have never thought about doing before. And as a result of that there is a lot of things that take place out in society that, may we may not understand, or we may not completely comprehend, but a lot of it has to do with.

[00:04:46] Behavior on social media and our inability to know when to say things and when not to say things, and that is a huge problem.

[00:04:56] Craig Peterson: [00:04:56] It is knowing when to shut up. It's right there in politics as well. The Obama campaign was the first to mine. Incredible amounts of data from Facebook. Incredible.

[00:05:09] Far more access than anyone had ever had before Facebook just literally gave it to them. And then you had the Trump campaign come along and the higher, the Cambridge Analytica guys who had access to much less data than the Obama campaign had. But in both cases you were saying. Ads that were so tightly targeted at people and individuals that you really were being manipulated because they know what you're saying.

[00:05:37] They know what you're doing, they know who your friends are, and they put it all together now to lead you down that Primrose path, whatever. See, that's where I really get concerned. We are absolutely being manipulated. And as you pointed out, Chris we're being manipulated voluntarily. We're telling them everything we possibly can about us when we're posting on these various sites.

[00:06:04] Chris Ryan: [00:06:04] That's a really good point. How's judiciary committee approved antitrust legislation that could prohibit platform operators like Amazon, apple, Google, and Facebook from favoring, their own products and services. And the legislation could even break up industry giants by forcing them to eliminate or sell certain divisions.

[00:06:21] I don't see any way shape or form that this becomes law. That being said there is a public desire. For law to come to fruition that creates a more even playing field breaks up big tech breaks up these corporate giants and creates an environment where there is more shared prosperity. And. I'm curious as to what your thoughts are on this and what direction this goes and does do these companies need to be broken up in your view, a and B given how tightly they're able to control political figures via donations and power and things of that nature.

[00:07:06] Is there any way that these big tech companies get back?

[00:07:10]Craig Peterson: [00:07:10] It's a great question. And I would love to say that let the marketplace take care of it, but these companies are so incredibly profitable. The odds of them going under are very slim. Look at how long now we've had Facebook and Google out there.

[00:07:27] I'm sure their predecessors died. Their predecessors, trying to have went that way. My space out, et cetera. But these people have had so much control, so much money, so much profit that the opposite they are going to be corrected by the marketplace are slim. Because part of the problem, Chris, with these huge guys is they keep everybody else out of the market.

[00:07:52] Get Instagram, a company that was worth maybe $50 million. Facebook has been out there paying a billion dollars to buy their perspective competition. And they've done it multiple times. Google has done it multiple times. We're talking about a hundred times what the company is worth, just so they don't have to face competition.

[00:08:16] So now that brings in this ending platform monopolies, right? That you just mentioned will that help? Yeah, but yeah, I don't know. How do you break them up? There's obvious ways you can slice them up, but is there the stomach for the federal government to get involved in this? And we're just giving it all to these companies with margins, proper margins that are insane.

[00:08:41]Chris Ryan: [00:08:41] As always.

[00:08:41] Craig, thank you so much. Appreciate your time. Hey, take care. Craig Peterson, joining us here on Hampshire day. Host of tech talk on news radio 610 and 96.7 Saturdays and Sundays at 11:30.

View Details

[Weekly Show #1119 2021-06-26]

We've got some really cool news that some people have interpreted as bad news. And this has to do with general motors and their hydrogen fuel cell. This is a very interesting story.

[00:00:13] I've always been fascinated with the Hindenburg and what happened there. And I did a lot of investigations. And of course the, there was the initial investigation that happened back in 1937. When the Hindenburg actually crash, I found online, you can buy pieces of the Hindenburg online.

[00:00:35] There's this kind of an auction house. You can get a small square of the fab. Of the Hindenburgs outer shell for 99 bucks. I found them online. I didn't buy any, although I was thinking, that might actually be cool, but what am I going to do with it? Rights to get on a wall then what w what was interesting about it and about the fabric was what the German engineers had.

[00:01:01] Now we know that you can use helium and helium is a great little gas it's inert. It's not going to catch fire. It is also lighter than air. There's a lunch, a lot of others, great properties that has, you can use it for super cooling things that you can't with. Most other gases, helium is much better for super cooling than oxygen is.

[00:01:23] And hydrogen is Excel. Helium is getting hard to find the United States had a strategic reserve of helium. Now, to me, that makes sense because we did at one point need helium. We had dirge bubbles. We still do. We still use helium to send weather balloon. Been various other things, but then the federal government decided ELA.

[00:01:48] We don't need to keep this reserve anymore. So they sold it off. As of next year, there won't be anything left in that strategic reserve. So where do we get helium? We get it from regular old oil mine. So they drill a hole it's created by the breakdown of various elements in the soil, primarily some of the hard rocks.

[00:02:14] And as they break down and decay, they produce helium as one of the byproducts. Now what's been happening in the reason we are in. A helium shortage. Number three in fact, is that we are now fracking. Fracking Lutz is extract a lot more natural gas and a lot more , which is what we're really trying to do and keep some of those costs down.

[00:02:44] But it also does not create as much helium and that's. And it's a really big problem when you get right down to it and you're trying to figure out if we're going to fill up a balloon, that's going to go up. What are we going to do now? Approximately a quarter of all of the helium that's news out there goes into these birthday balloons.

[00:03:09] Okay. So yeah, it's it's kinda cool, but it's not an absolutely necessary thing, frankly, but it is used in all kinds of other things, including experiments. You remember? I said that helium is used to super cool thing. Think of these massive hydraulic colliders, some of the other experiments that are going on, where we have a magnet.

[00:03:37] Now, one of the biggest, most important things we're doing with magnets right now is trying to create a container for nuclear fusion. Now nuclear fusion doesn't have the byproducts of nuclear fusion. Although we've solved most of those vision problems, you don't have this highly radioactive stuff anymore that we used to have in the old reactors.

[00:04:01] Although we haven't been building new ones for what, 40 years now. But those particular types of containers, if you will, are built by these big magnets. So these magnets hold it in place. And in order to get the amount of power we need to, to these magnet, we have to super cool them. We have to super cool, the power supplies, and that is typically using helium.

[00:04:27] So we've had to shut down some of these experiments. Because we don't have enough helium so much for the strategic reserve, that is almost completely depleted. And by the way, the federal government in its infinite wisdom sold that helium off at a fraction of fair market value. That's a problem because it just went crazy.

[00:04:52] People were using it for things that just weren't that important. And now many of our experiments are getting shut down, but in the world war two era and pre-World war II era Germany had a problem trying to get helium itself. Germany doesn't have a whole lot of oil reserves and it had to buy everything.

[00:05:12] And the United States really didn't want to sell here. To Germany. So what Germany did and you guys probably all know this from your history lessons, cause you are the best and brightest hydrogen was used. And because hydrogen was used it was a flammable gas. And when there was a spark, when it was trying to land.

[00:05:36] It went up, it caught fire. Now what's really interesting is if you look at the pictures that were taken of it burning, there were obviously elements other than hydrogen, because hydrogen burns beautifully pure. You can't really even see it. And what would normally happen is you wouldn't have. Poof.

[00:05:58] And the whole thing just burns up. You'd have a hole and that hole be shooting a flame out as it was ignited, right as the hydrogen was ignited and the whole, my discontinue to get a a little bigger until there's no pressurized hydrogen anymore. And the fire's over, but that's not what happened with the Hindenburg.

[00:06:18] She caught fire. Because of that spark and it had that spark because of the weather conditions at the time, they just weren't being cautious enough. In fact, that was the very last large dirigible Airship. Ever made, frankly it's crazy, yeah. We got the Goodyear blimp, we got some of these others and they need the helium to fill them up.

[00:06:43] And then over time it was kinda like a swimming pool. You filled it up and you, all you have to do is just add a little bit more now, and then you don't have to, because of leakage, you don't have to completely refill it all of the time. So what ended up happening is they had hydrogen on board.

[00:07:02] Had the spark started a flame and then the cloth material that coated this massive container holding all of the hydrogen caught fire, but it didn't just catch fire. What happened was it caught fire and. It burned very quickly because effectively the entire outside surface of the Hindenburg was coated with rocket fuel.

[00:07:30] Some of the same components that go into gunpowder aluminum powder, which gave it that kind of silver shine. They really messed up. So people are looking at what is happening now with general motors. Tech fuel cell technology and other a little bit worried because this technology was developed for cars.

[00:07:51] It is being used in some parts of the world, in some parts of the country. I know California has some hydrogen cars on the road with a fuel cell. Now they're not burning hydrogen. In order to transport the car, they're actually allowing a chemical process to occur. So the hydrogen atom is attracted to the oxygen atom and they use a membrane so that they're trying to get together.

[00:08:18] And that's what produces electricity. And then what is the result when you have two hydrogen atoms and an oxygen atom and they combine H two O so the only. Final end product here coming out of that car is pure. Which is cool. So GM says wait a minute. Now we have this technology, why don't we try and make airplanes a little bit more efficient?

[00:08:45] And so they're saying you don't, you're taking off with two tons of water on board. How about we put a hydrogen fuel cell in there. You will be well to generate electricity. Now that's a very big deal because now that electricity doesn't have to be generated by the turbines of the gas engine. And on top of it all, you don't have to take off with two tons of water on board because we can generate water as your.

[00:09:16] And of course, they're not going to coat it with a rocket fuel. They are going to put it in one of these really cool containers that is considered to be very safe. So it's very cool. So the litmus test, according to our friends over at general motors, he this is a GM executive. Director Charlie frees.

[00:09:36] He says our technology can address customer needs in a wide range of uses on land, sea, air, or rail. And this collaboration we could open up new possibilities for aircraft transitioning to alternative energy, power sources. Now I don't expect a plane to be actually flying on this any time soon.

[00:09:58]Hydrogen is a great little fuel, but it doesn't provide enough energy to get that jet off the ground at all, but it does provide enough energy to supplement it so good for them. I think this is a good use frankly, of the hydrogen fuel cells, as long as we can avoid it leaking and causing other major problems.

[00:10:21] But I think that can be solved. Look at what we've been able to do now. These containers for the pretty much everything that can be hit by a train at full speed and not. So I think we got this covered. All right, everybody stick around. We'll be right back. And we're going to talk about it. A new type of vigilante that you may not have heard of before.

[00:10:46] Of course, you're listening to Craig Peterson. Check me out online. CraigPeterson.com.

[00:10:52]Well, you probably know again here, because you're the best and brightest, what a vigilante is. Well, I bet you haven't really heard about this type of vigilante before, and it is causing havoc for as many as 40% of computers.

[00:11:10]Well, vigilantes have throughout history decided that they were going to take the launch of their own hands.

[00:11:16] Now, way back when there wasn't law enforcement, et cetera, that's just what you did. And then we ended up with the tribes and our tribes would decide, okay, what's going to happen to this person. And you know, one of the worst things that could possibly happen way back. Caveman days. And after frankly, the worst thing that could happen to you is getting banished because having a group of people who are living together, cooperating together, working together makes all of the difference when it comes to survive.

[00:11:53] And being kicked out of that tribe out of that group meant you had a very low chance of long-term survival. And if you went into another group, they'd really be suspicious about you because where did you come from? Did somebody kick you out because you did something really, really bad? You know, I kind of wonder if that's not deeply ingrained inside of us from all of those.

[00:12:19] Centuries millennia with that whole type of process in place where we see someone that's different than us. And we kind of wonder, right. If you think that's where that might've come from. Interesting thought. I don't know that I've ever seen any studies about that. So vigilantes, nowadays are people who they're not going to the chieftain.

[00:12:40] They're not going to the local police department or the prosecutor who a, whoever it might be. They are taking the law as it were into their own hands. Now it's not necessarily even the law, they just decide that they want something to happen in a particular way. And by having that happen in that particular way, they now have control.

[00:13:06] Right. They're making the law as it were not just enforcing it. We have a lot of malware out there and there's a lot of different types. You might remember what Sony did, Sony. Decided they didn't like people ripping their CDs. And so they went ahead and installed an automatic installer for windows computers.

[00:13:29] So if you tried to play your favorite Sony CD, right. Audio CD, listen to some music, it would automatically install some what. You and I would call malware on your computer and it would look at everything you were doing on your computer. To try and make sure that you were not trying to make a copy of the desk, not just a copy, but what we call ripping it.

[00:14:00] In other words, you have a CD and you have an MP3 player. How do you get the CD on the MP3 player? Cause you can't just stick it into an MP3 player, so you have to rip it and that converts it from the CD format into an MP3 format. So it's all digital. You can take it away. And I have really griped about the music industry before, because they make way more money off of CDs than they ever did off of records.

[00:14:28] Just because of how cheap it is. It costs them like 10 cents, not even to make a CD. And it costs them a couple of bucks to make a record back in the. So they decided they would do digital without thinking twice about while digital means you can a perfect copy, perfect coffee copy of that desk. And so it's only, he said, I'll go, well, here's what we're going to do.

[00:14:53] We're going to make this. And so it installed itself. Way down deep inside the operating system. It watched as you loaded up desks and watched what you did that is malware. And that was Sony being frankly, a vigilant. Yeah. They said, Hey, it's for copyright protection, but there was no encryption on CDs.

[00:15:16] There still isn't on compact discs. When we're talking about music desks, there is encryption on DVDs and that's what they did in order to say, well, you can't rip it because it's an encryption. Past the digital communications millennial act. And then from that act, they were able to now have controls. Hey, listen, if it's something's encrypted, you can't even try to dig.

[00:15:40] Okay. Pretty, pretty big deal. So there's a whole lot to this whole vigilante thing. And someone is added again, in this case, we found a researcher who has found something you just don't really see very often, you know, outside that sone thing, but it's booby trapped file. Yeah, there's these files that are out there on the internet on a bunch of torrent sites and others that are pirated software and they have a booby trap inside.

[00:16:18] Now the pirated software is typically things like a Microsoft windows or all of their different software, right word. And you name it all the way across the line. They also, by the way, have put some of this malware into games because there's a lot of people that run games and they grabbed these cracked games from the inside.

[00:16:45] So we're talking about boob bootleg talk. And so what this person or people, or whoever it is, is doing according to Sofos labs, principal researcher, his name is Andrew Brandt is get getting these people to install this software that has. A booby trap and that what it does is you think you're just installing the game or whatever it might be.

[00:17:15] But in reality, you're installing software that sends. The file name that was executed to an attacker controlled server. So it knows, oh, you're trying to run Microsoft word and it sends along your IP address of your computers. And then what it does is this vigilante software. It tries to modify the victim's computers so they can no longer.

[00:17:43] Access some, 1000 other pirate sites, like the pirate bay.com, which is a very popular site out. Oh, out there. So this is obviously not your typical malware, not at all. And they are doing this same type of thing. That's so needed way back in the day, modifying your computer so that you can not do something that may be illegal.

[00:18:11] It may be mostly, most of the time, he illegal, hard to say, but in reality, they're modifying it without you knowing. It's a very, very big deal. So people are using software, kind of like this vigilante software to steal stuff. Usually it's passwords, or maybe your keystrokes or cookies or your intellectual property access Eve, the people are even using ad networks, advertising networks to deliver software.

[00:18:44] But that will mind cryptocurrency for them. Okay. But those are all theft. That's what the motive is, but not in this case. These samples really only did a few things and none of them follow the motive for malware criminals. It's fascinating. He had a thing that he posted over there on Twitter, kind of talking about it, but once the victims executed this Trojan file, it gets sent out to a server and I'm sure the FBI is tracking down this server.

[00:19:16]It's one flourish. She drew.com in pronounceable. And it's it's not the one fee share, which is the name of a Cod storage provider, but it's pretty close to it. And it sends it out. I'm looking at the list of all of these websites that it tries to block by going into your hosts file. But it's an interesting way to approach it.

[00:19:41] Isn't it, frankly, by mapping the domains for all of these torrent sites and pirate site. To your local host, the malware is making sure that your computer, I can't access those websites. Okay. Anyways, if it happens to you just go in and edit the host file. It's really quite that simple. All right. Stick around everybody.

[00:20:03] But while you're waiting, go ahead, go online, go to CraigPeterson.com. Once you're there. You can easily subscribe to my newsletter and keep up-to-date on everything. CraigPeterson.com.

[00:20:18]We've been worrying about what is happening with ransomware with a cyber attacks and where is it coming from? We've got a new study out, did showing that one in five manufacturing companies are not only targeted by cyber attacks, but are getting nailed and getting nailed back.

[00:20:38]This is a bigger problem, and I think most of us realize, and I have a few manufacturing clients who have been nailed badly by cyber attacks. Very badly. There is a new study out that looked at this it's called the manufacturing cybersecurity. Index. And this is a report that has the results of surveys of 567 manufacturing employees.

[00:21:08] Now that is quite a few and most of these people were in fact, in the it side of things, some of them were specifically in the cyber securities. That one was most interesting about this. Isn't the fact that just that one out of five manufacturing companies is targeted by cyber attacks, but what the response, what the thoughts of these people that run the companies are.

[00:21:37] And I say that because I am just constantly amazed at how businesses just are not paying attention to this, and this is proof again, and here's what it is. Information stealing malware makes up about a third of attacks, but companies are worried about what ransomware, the worried about ransomware shutting down production.

[00:22:05] That is a very big deal because of course it does, but what is going to hurt you more? And that's what you got to figure out. That's what companies have to really look. These numbers that we're looking at are according to this article I'm reading at a dark reading, which is a great site. If you haven't been there before, and you'd like to follow some of these things in the cybersecurity world, definitely check it out.

[00:22:34] Dark reading, very easy to very easy to look at lots of good stuff. But Robert limos is a contributing writer over there. And he's the guy that wrote that. And so he is saying that more than one third of all manufacturing firms are attacked every month. That's absolutely amazing. Now, of course not all manufacturing employees really know when a company is being attacked, but ransomware attacks that they know, because usually that means much of the company is shut down when it happens.

[00:23:12]Because ransomware attacks have this major impact on the business and the other types of attacks. information most of the time companies never find out unless it's too late again, it's usually ransom or extortion. They're two sides of the same coin. So an extortion attack might be where they get onto a network.

[00:23:37] Exfiltrate data. And then they say, Hey, listen, we've got all of this data. Do you want us to post your bank, account numbers, customer information, your intellectual property, your plans, whatever it is, you want us to post them online? Huh? And if not pay out. Okay. So this is, I think a very big problem.

[00:23:58] There are major blocks between it information technology and security teams. And I also have to point out that most it decisions nowadays most what would normally be an information technology decision is actually being handled by a line of business matters. Who chose the software you're using to track your customers?

[00:24:25] It was probably the sales guy, right? There's the, it's not, the CEO is not the it director. It's the director of sales or marketing or the accounting people who decided to use QuickBooks online as opposed to using something else. All of these types of decisions are out of the hands of it and are way out of the hands of the cybersecurity.

[00:24:52] That's because of this massive changing landscape out there. It's absolutely huge. Now there's a survey also of 250 information technology workers, and they found that 61% of the companies experienced a cybersecurity incident affecting their factories. 61%. Of manufacturers had a cybersecurity incident that affected the factories and three quarters of those incidences took production offline.

[00:25:26] That's according to another report that came out in March, just mindblowing. Isn't it. So ransomware accounts for only 13% of these attempted attacks on devices. But the information thieves account for 31% of the attacks and file us attacks account for 28%. So here's a quote from morphous sec. These are the guys that produced the first report.

[00:25:56] I mentioned, although these sobering threats are certainly not limited to the manufacturing industry, cyber attackers are acutely aware of the data manufacturing facilities have on hand, right? Think about all of that data, think about all of the intellectual property. So it goes on. In fact, some cyber crime groups have even been using ransomware as a smoke screen for cyber attacks, designed to steal intellectual property, increasing the damage they can inflict in the long run as they bully victims.

[00:26:31] By threatening to leak data if they don't pay. Now, I've warned about that before. If you've got something that looks like a ransomware attack happening, pops up on your screen, it's got that classic red screen ransomware page. That may just be a smoke screen. You may not have ransomware.

[00:26:49] Your files may not be encrypted because what most of these guys nowadays are doing is making additional money offers, stealing your files solid. It depends on the group and this isn't what dark side does, but some other groups do and they can really socket. Ever since the authorities disrupted the emo tech network in January, we've seen attacks split into and smaller groups are increasingly working together in new ways.

[00:27:19] And these highly targeted groups are very dangerous because they can execute multi-faceted attacks, giving the collective expertise. Again, it's just like business. If you're trying to sell something, you need to narrow down and you need to get as narrow as possible. And that means the cyber groups are specializing in a specific industry and they're specializing in a specific way.

[00:27:48] To attack. This is really fascinating. And there's a few reports that come out every year. Verizon has a very good one on cyber attacks. Statistics. IBM has one gardener of course always does their little thing on the side. Those tend to be, and more narrowly focused, but this is the first time we've seen this report.

[00:28:09] So we don't have any sort of comparative data from prior years. But what the, what these guys are saying is that in that the pandemic has shifted attack trends and ransomware has grown from single digit percentages to 13%. As I mentioned already, almost two thirds of surveyed employees believe that the chance of a breach increased because of remote work.

[00:28:37] And we know that's true. BI has been warning about that. We've seen it again and again. So be very careful. Okay. Most of these manufacturing companies have had people working from home during the lockdown, nearly two thirds said that it has increased the risk of a breach. And let me tell you, it really has.

[00:28:58] And so keep all of that in mind, if you are in manufacturing or if you're concerned about our manufacturing base here in the us man, is there something to be worried about? And that's a shame. How do we conduct business? How do we keep our economy going? If our manufacturers are getting knocked down or getting knocked out of the game, Hey, visit me online.

[00:29:23] CraigPeterson.com. You'll find all of this all on my podcast and much more.

[00:29:28]We've had some good news this year about the bad guys and law enforcement. That's why it's good news because we've been shutting a bunch of them down. They're still out there and there's more and more, and it's getting more expensive, but I'm going to share some other good news.

[00:29:45] Ukraine has had a lot of cybersecurity problems.

[00:29:49] You might remember this tax program. That was the number one program used in the Ukraine, or I guess they just say Ukraine now. And it had a major piece of malware. And near, as we can tell, it was designed to attack the Ukrainian users of this tax software. Now, not just because, why would someone outside of Ukraine use the tax software?

[00:30:19]No. What happened was the software gets onto a computer and so much Maltz in the militia software game. It goes and tries to infect other computers and then other computers, it goes on and on. So what happened here was it looked like the we're trying to really wreck havoc with Ukraine and with the government's money supply coming from TAC.

[00:30:47] Remember this whole thing where you crane was invaded and we didn't do anything right. And Russia took it over that portion of trying to get down to some more, again, see access using Ukraine. So it an X part of Ukraine on it was, Hey, it isn't does it. It is nothing yet. It was Russian special forces. You had that airplane that went.

[00:31:11] Down apparently also by Russian special forces. So Ukraine has had. Enough and the Ukrainian police now have arrested members of this noon Torrijos ransomware gang that also has targeted American universities and other businesses here in the United States. This is a very big deal because it's bigger than it might appear.

[00:31:37] At first. This was the last Wednesday. The Ukrainian national police made an announcement that they were working with Interpol and the U S and south Korean authorities. Now why all of those different places? Obviously they might want to use a little bit of expertise, maybe. BI, maybe from some of these others, but as it turned out, the most of the damages were in the us and South Korea and the bad guys were there as well.

[00:32:13] This is also because they're having trouble, these ransomware people and people that are trying to spread other types of malware, their hands. Trouble finding the right employees. Yeah. Yeah. Employees sometimes their gig. And they'll hire people to launder money, unbeknownst to them many times, it says, Hey, I don't have a PayPal account.

[00:32:37] Can you I'll transfer some money to you on PayPal and I'll let you keep 50 bucks or whatever it is. And if you could just wire it into this bank account. So those are called mules and they're part of the money laundering. If you've done that you might've been involved in something illegal, some of those people were here in the U S cause that's again, they're trying to get the money out nowadays.

[00:33:01] They are also courts using Bitcoin primarily, but other cryptocurrencies as well. But these guys were, it was called Klopp. They had, or depending how we went. They had stolen a half a billion dollars. Basically half a billion dollars in damages. So everybody really wanted them. But this is the first time that a national law enforcement agency has carried out mass arrest of a ransomware game.

[00:33:34] That is a very big deal. So Ukraine is now doing more basically than Russia has. Russia is a hub for ransomware gangs. We know that right? Whether Putin has control over them as directed them or not, that is up to debate, but there are a lot of ransomware gangs over and run. And you think about Russia and how big it is you realize its economy is about the same as New York state.

[00:34:02]Yeah, it's a decent sized economy, but it's nothing compared to the other major economies in the world. They have Russia been blamed for harboring cyber criminals because they have not been prosecuting them and they don't extradite them. Remember president Biden was going to ask for extraditions and they're trying to figure out a deal and.

[00:34:28] President Putin said sure. We'll extradite them. If you extradite people, we want to, which of course isn't going to happen. So who have they been going after and what have they been doing? This group is one of several ransomware. Cartels is what the call-in on. Now that sees the target state. And then encrypted and demand a ransom to release it.

[00:34:55] And then they also do the double extortion where they say, Hey, if you don't pay the ransom to decrypt your files, we are going to leak sensitive information on it. So the targets they've included shell oil company, the international law firm Jones day. You might've heard of that one as well as several us universities, including Stanford in the university of California.

[00:35:25] Think of how big that is. I'd be shocked if university of California, wasn't the biggest. In the country. So in most cases, these hackers used a vulnerability in this file transfer product by company called a . So if you're using that's ACC E L I O N S in your business or to connect to your business or file transfers, double check it and make sure it's up to date because that's how they compromise their Vixen.

[00:35:55] But they're a victim. Obviously ransomware is in the spotlight right now. There've been a lot of these huge attacks hitting our critical infrastructure. We've got the colonial pipeline. We've also got a course them, big meat processing plant. We've seen them hit some of these water filtration, plant electric grid.

[00:36:19] All over the place. So governments, not just the us, but worldwide now are under a lot of pressure to try and stop these cyber criminals. So we'll see what happens, a small country like Ukraine. It is it's just amazing to me that they are taking the lead. It's a, it's just incredible. So let's look them up right now.

[00:36:46]Ukraine size financial see what it has to say here on duck. Duck go their economy. So they rank per capita GDP, gross domestic product, a hundred and 19th, not so good. And their GDP rank is 56. So in other words, most of their people are on the very poor side. And a number one looks like sector is agriculture.

[00:37:13] So they are a head of Russia. They are ahead of most countries except really Eastern European and the United States. So congratulations to Ukraine on that one. Very big. I'm trying to find out here how many people there were. Okay. So part of this take down Ukrainian police on Wednesday, and this is an article from ARS.

[00:37:38] Technica said that it had conducted 21 searches in the. Kiev, I guess it's pronounced region of homes and cars of those arrested seasoning equipment, 5 million Ukrainian here, Venus, which is around 200 grand and property video footage shared by the police shot officers ready in homes and what appeared to be wealthy neighborhoods and towing luxury cars, including Tesla.

[00:38:06] The police said, had managed to shut down some of the group's digital infrastructure. And it's unclear whether those arrested were core members of the group or affiliates. And the defendants here face eight years in Ukrainian prison does not sound like a fun time for you. That's for sure. I want to encourage everybody to take a few minutes if you haven't already and get my newsletter.

[00:38:31] Now, when you sign up for it, I'm going to send you a few special report talking about some of the things you can do. Right now in order to secure your computer, whether it's a home computer just one office, computer, or a whole office, I go through some of the most important things. Also you'll find on my home page, a video on how.

[00:38:57] To thwart most of the Russian ransomware. And it's really simple. So it's like a five minute, not even video shows you exactly what to do, and you are going to be ahead of those Russian hackers. So how's that for really good news. Now you can get my newsletter, which comes out every week and I try and keep you up to date on the goings on by going to Craig Peter sohn.com/subscribe.

[00:39:25] Now that's where you're going to find links to my podcast, which you can also find right there on my website. You can find all of the interviews or people are interviewing me. You can find this radio show, all two hours worth of my weekly podcast. You can find it all or right there on the homepage@craigpeterson.com.

[00:39:46] Now, if I could ask a favor. The way to get a podcast out into more and more hand is to get the subscription numbers up, not just the downloads, those are important, but the subscription numbers and to have people obviously listening to it or watching it did, by the way I post this up on YouTube as well.

[00:40:10] So you can watch it there. Listen, really. I am not posting much video right now. Do post some. But I, if I could encourage you to go to the 800 pound gorilla or even your favorite podcasting platform, go to Craig peterson.com/itunes. That will then take you directly to my iTunes podcast. Page Craig Peterson, that's Craig Peterson, P E T E R S O n.com.

[00:40:40] And. Put a slash and then I tuned ITU NES, and that. Get you to my iTunes podcast page. I hope I've earned five star review from you. So if you would leave a review and give me the five stars, hopefully, as I said, I've earned it. I'm also on a whole bunch of others. You can go to Craig peterson.com/spotify and many others.

[00:41:07] So check it out. Please do subscribe to the podcast, whatever your favorite podcast app is, and that will help. The word out, we can get a few more listeners here. I really do want to help these people out, help you out. Particularly Craig peterson.com. You'll find everything you need to get started right on the homepage.

[00:41:31] All right, everybody take care.

[00:41:32]Apple and Google are changing the way they are delivering privacy in a very big way. Have you ever spoken to your device and giving it a command? Yeah, the smartphones, et cetera. That's all changing for the better.

[00:41:48]Apple and Google have for very long time now been trying to do something that just fascinates me way back when in college, in the seventies, I was working on some software that did handwriting recognition and.

[00:42:05]It was just beyond, incredibly hard to do back then. And so we narrowed it down the scope down and just signature recognition. Is this the same person signature? And, we got somewhere, but it wasn't like very good, frankly. Today we have come a very long way. I am still amazed at how well computers can speak to us, but it isn't just them speaking.

[00:42:31] Now, of course our computers, our smartphones, or our watches can go ahead and listen. To what you're saying. Absolutely. Listen and listen closely and understand it. But the big question is how, what are they understanding? And from a privacy standpoint, where are they doing the understand? No. I wrote some software that takes meetings or other things like my radio shows and sends it on abit, packages it up and it sends it on up to Google are not Google.

[00:43:10] I should say Amazon. And has Amazon transcribe it for me. Now that software didn't take me very long to write because Amazon has these services that you can use using what are called API APIs, application programming interfaces. So I was able to write some software. That transcribed radio shows and transcribed meetings in the matter of Wembley, less than an hour, including all of the debugging and testing and everything else, to make sure everything was going to work and it wasn't going to fail. And it didn't keep stuff up in Amazon longer than it needed to and tied into my right accounts, everything. And. And our, I remember in the early eighties, trying to come up with a system that could take a phone call inbound and walk people through a menu and let them hit a button.

[00:44:03] So they, press one for this two for that, et cetera. And this was on an apple too. I was writing it in assembler and in basic, oh my gosh, bringing back all kinds of memories. We now have these great, incredibly smart devices. And since the Dawn of the iPhone, a decade plus ago, many of the smarts in our smartphone in our computers have come from somewhere else.

[00:44:28] Just like I have transcriptions done by Amazon. That's up in the cloud. They have all of their data centers in some amazing software that can trend transcribe almost anything even with kind of batteries. So the mobile apps and our phones, or sending our user data in this case, our voices that were recorded up to the cloud, and that would transcribe speech, or maybe giving you some ideas of what the next word is, you're trying to type.

[00:45:01] So you only have to hit one. Where it's changing now is where it's being processed. Apple has for quite a while done processing as much as possible in the local phone set the handset. So you wake it up. That processing is done locally. Same. Thing's true for Amazon. Google has been doing much the same thing and apple has added to its devices machine learning.

[00:45:28] That's designed to be able to do this more and more so that your question. So you might say, Hey Siri, what time is it can be processed locally in the device. That's exactly what Google is doing as well, because these smart phones, even the ones without machine learning, like a lot of these Android phones are smart enough.

[00:45:52] To do some real crucial and frankly sensitive machine learning tasks, like asking very simple questions or even doing the speech transcription. So at Apple's big event this month, apple said that its virtual assistant is going to be able to transcribe speech without using any cloud resources. Ella depends on the language.

[00:46:19] Obviously English is where they're probably are going to focus. And maybe a few other European languages. Future iPhones and iPads are going to be doing all of that locally. And if you pay close attention to the releases of Mac OOS, you'll see that future, like the next release of Mac iOS, that's already embedded.

[00:46:42] Is using special processing. That's only available using the apple chips because apple again is embedding machine learning into some of these. It's just amazing what they're doing. And Google is following suit. Google said the latest version of Android has a feature dedicated to secure on device processing of sensitive data.

[00:47:09] So they're calling that the private compute core that's Google's name for it. And initially it's going to be used to keep the smart reply feature. The Android has built into its mobile keyboard that can suggest responses to incoming messages, keep it local on the phone. So that's a good thing, right?

[00:47:30] This wizardry is going to give you more privacy because even though apple and anonymize. Anything that's going up to the cloud. Anything. If it is being, if your voice, for instance has been sent up so that it can be processed and it happens, like fad, it's just amazing how quickly it all happened.

[00:47:50]Google is doing much the same thing. They're just going to say we're just going to process it locally. So you might not notice a difference because of how fast both companies are able to process your voice, but on-device machine learning offers more privacy and even faster apps. Just really, again, using the old snap trick here a much snappier than they ever were before.

[00:48:20] And by not transmitting your personal data, it's cutting the risk of exposure. It's also saving time, because right now, again, it has to record it. It's often streaming it live so listens for its wake up word, which might be, Hey Siri or hello, Google or whatever you've got to set up to be. And my phone just woke up and it sends started streaming it up to the cloud.

[00:48:49] So you have to wait for the data to be sent then processed and then sent back. But it's amazing how fast it is. So this is very. Apple has always had your privacy and your security is one of their main focuses. But when it comes to our friends over at Google prying on your spine, on you, Brian eyes is really the name of their game.

[00:49:15] They want to know everything about everyone. My mom, one of my sons was over at his girlfriends and she has these face book. Devices, which I've always argued against people getting, cause there's nobody worse than Facebook. Even Google isn't as bad as Facebook and they were talking, he and his girlfriend about a hammer.

[00:49:41] And then within minutes they started getting advertisements for hammocks. Now they weren't talking through this Facebook portal, which is kinda like an the Alexa or the Google home with the camera and a screen on it. They weren't talking through it. They were just talking. Around it and they weren't looking it up on Facebook or anything.

[00:50:03] So they have their strong suspicions. They were being spied on. And frankly, I do too. Cause my son, this particular son knows tech extremely well. Okay. So Google started gathering data on the Chrome browser. And how much are we using it? What you're using it for through a technique, they call differential privacy, which adds what's called noise to harvest the data.

[00:50:28] Now you can get plugins for your browser, that issues randomly. Queries searches. So Google thinks, okay, so you just searched for size 13 socks, but you didn't, your browser did that in the background on purpose to basically poison Google's harvesting of your data, because they can't really tell the difference.

[00:50:52] So that Google has started doing this themselves in 2014 a little bit. So that the information about you. Really wasn't that accurate? Google's now trying to put you into a box. So rather than gathering all the information they can about you specifically about you just long-tailed about you, what they're doing.

[00:51:16] Is putting you in a box. So you are a 40 year old, white guy from new England who likes cars, right? So you'll be in that box as opposed to specifics about you. And that part of the reason for that is because they keep getting nailed by all kinds of lawsuits. Apple has a technical. On data gathered from phone phones to inform them well, what emojis people are using and type in predictions and apple completely.

[00:51:43] Anonymizes it. So it's interesting to see. I am glad to see both apple and Google out there in the forefront. Now, trying to anonymize stuff, trying to keep the processing on your device, which is going to save you a lot of time. And. Provide a little bit of privacy. So there you go. Major update to privacy coming first from apple, and then it looks like Google is going to follow suit.

[00:52:14] Hey, have you visited me online? You can get my newsletter for free. I have a free one. Go to Craig peterson.com/subscribe.

[00:52:26]I came across this article in Fox businesses week that I knew I had to talk about. And this is about ransomware and how a ransomware attack can really begin in some pretty simple ways. So we're going to talk about that, right now.

[00:52:43]You I'm sure heard of the colonial hack. You guys really are the best and brightest. If you're listening to this show and you are a regular, you are among the top 5%. Let me tell you, so you know about the colonial hack and colonial pipeline, of course. Down. We didn't really get nailed by up here in the Northeast, because the way of the way the pipeline works to see the pipeline sends fuel and stuff, sends all kinds of things. For all the way from down in the Gulf coast, the basically all the way up through new England and they ship different types of fuel and they can't ship them all at once and they don't ship to all areas at once. So let's say new England need some home heating oil. They will schedule a time and they'll say, okay.

[00:53:35] So from 8:00 AM on Monday until five, a 5:00 PM on Thursday. The pipelines are going to be full of home heating oil, headed up to noon. And all of those big oil tanks that you see, particularly in like north Western or Northeastern New Jersey, those our holding tank. So our friends at colonial pipeline will ship at op we'll, hold it.

[00:54:00] And then from there, it gets distributed by a trucks, to our homes and et cetera, et cetera. So they do the same thing for jet fuel, car fuel, gasoline, diesel, et cetera. Here in the Northeast, we had just been delivered a whole load of fuel and then the ransomware attack hit and colonial pipeline decided to.

[00:54:26] Down the whole pipeline. Now there's people who say they shut it down because they didn't want to lose money because their billing systems were offline and they didn't know who was getting, which fuel, et cetera. That might be part of it. But it's not a bad idea at all. If you're getting ransomware to shut the machine off.

[00:54:47] Just shut it off. So it doesn't spread to other machines and shut off the other machines as well. So they don't pick it up. Now we have some automated systems. So we had a client who they, one of their employees. In fact, it was one of the C level people, which of course they always demand exceptions to their security protocols.

[00:55:07]They managed to pull in some ransomware, bring it in. And we're looking at it, they're on their computer and it started to install itself and immediately our systems cut them off from the rest of the night. So they weren't able to the bad guys who are able to spread it all. It was on that one machine and we stopped it before it started doing anything really bad.

[00:55:33] Even on my max, I'm running some software. No, I should do a training on this, some free software that keeps an eye out for apps that are opening a lot of files and doing something that might be encrypting them. Sometimes it's hard to tell if your program, if something's being encrypted or not.

[00:55:50] So it tracks all of that and tries to, stop it. And it does a good job. Sometimes it stops legitimate software too. But when it stops at a pop has a little pop up, Hey, us, this program, it gives you the names doing this. Tells you the folders. And he said, okay that's fine. Just let it go. And in the, in Microsoft are not Microsoft in the Mac world, just like in the Unix world, you can suspend a process that's running.

[00:56:15] So it just sends a suspend signal to it until such time, as you either say, no, it's bad, kill it or let it continue. So they did the right things by shutting it all down and then trying to figure out, okay, so what's happened, where is it? What do we have to do? And they ended up paying the ransom. Do you remember that as well?

[00:56:35]We also had this problem with JBS and JBS of course, was that massive meat processor. It's actually a foreign company, but it had a huge. Us meat plant. And we've got a wonder, is this a real war? Is this a war we're starting to fight online? We're not at a kinetic war right now, but is China behind?

[00:57:00] This is Russia behind us. And I got to say it sometimes. It's really hard to tell they might be using. Russian tools, but it could be Chinese hackers. There are so many questions here. It's just hard to know. So how do these guys get it in? With my client, they brought it in thinking, oh, okay I'm going to put this on my thumb drive.

[00:57:21] I'll bring it in to look at it in the morning. And it was an email and it was supposedly from the better business bureau and they needed to do some follow-ups. So he brought it. That is referred to as social engineering. It is a kind of a phishing attack where they know, okay this company is obviously going to be concerned about a better business bureau thing and complaint, and they're going to want to respond because they want to keep the reputation up.

[00:57:47] Cause they were a retail operation. Makes sense. That's what social engineering is all about. Just looking for cracks in the human shielded organizations is the human shield, really doing what they should be doing. Have they been trained and it's so easy to get tricked. I don't like some of these companies that go ahead and send out emails that are phishing emails, seeing if they can get an one of their own employees to click on it.

[00:58:23] And then what they do is they reprimand. No initially might be okay. We got to go through another training and you, so you sit through the training. Okay, great. Great. Okay. I get it. Yeah. Yeah. Bad boy. Slap on the wrist. All so it might be that it might be something much more critical, much nastier where some of these businesses are in fact firing.

[00:58:47] You do it two times you're fired. Okay. Or three times that I've seen that more in Europe than in the us, but some of the companies are doing that. I could totally disagree with it. And anybody can be fooled, which is why you've got to have a multi-layer set of protection. Okay. But what this is doing is letting the attackers in the door.

[00:59:12] Once they're in the door, they try and get higher privileges, which is basically more security access so that they can start going into various files and machines and start spreading. We call it east west, right? Spreading laterally within your neck. And that's a key to carry out a ransomware attack. He can be that simple.

[00:59:36] Now most cyber attacks about 70% are related to email phishing. So phishing emails, which appear to come from a trusted source are very simple but effective. For them to conduct social engineering, ransomware virus attacks on a computer. They are all tied together and we're not going to get into a lot of depth here.

[01:00:00] I certainly do some webinars and some other trainings on this. In fact, my thinking of releasing my improving windows security training again, for people that want it where. Through. Okay. Here are the main configuration things you need to do on your windows, computer or did to help secure it. There's no perfect security, but improving it. So I've got that course out there. A lot of you guys have already taken. And I appreciate you and your support. Let me tell you because it helps to cover some of my costs, but I think I might do that again. Send a little thing to everybody letting them know about the improving windows security, the course.

[01:00:39] All right. So I want to invite you again, go to Craig peterson.com/subscribe. Now you may not know. So I'm going to explain right now what my newsletter is. Every week, I find six to 10 articles that I think are very important and I'm reviewing literally thousands of articles every week. Some of it's automated review and the rest is me sitting there looking at them, trying to find what are the ones I think you'll be interested in.

[01:01:12] Those from me every weekend, ish. I emailed this, go to Craig peterson.com/subscribe. CraigPeterson.com/subscribe. Stick around.

[01:01:25]A lot of us have been complaining about cookies and tracking for a long time and Google who has finally heard us. I'm I'm not sure I heard about this, but we're going to talk about third party cookies right now.

[01:01:40] Third party cookies are where you go to a website and that web browser kind of squeals on you. Shall we say. And what happens is Google, for instance, is trying to track you. Would you go online as you go between websites, they're calling this kind of an advertising surveillance industry on the web.

[01:02:07] And frankly, this third party cookie has really been an important part. Of this whole surveillance industry. What it does now is it allows a website to have a look at where you have been online. And when I say it allows a website, it's really Google, that's doing the tracking. Obviously you're going to a website, Google doesn't own every website out there.

[01:02:36] And in fact it barely owns any. When you look at the number of websites that are out there, Internet. So Google has this whole concept of if you're visiting this site and you have visited this site and this other site, I know something about them. And so it sells that information. So because it's seen the pattern, right?

[01:03:03] That's the whole idea behind the advertising. Phasing out these tracking cookies and these other persistent third party identifiers has been something people have been trying to get rid of for a very long time in the electronic frontier. The foundation you'll find them online@eff.org has been jumping up and down, trying to get everybody to pull up their socks.

[01:03:28] If you will. One of the first players to really jump into this as apple and apple has pretty much told the whole industry. Got to stop doing some of this tracking, some of the tracking is okay. Again, how many times have I said, if I'm looking for a Ford F-150 then I don't mind seeing ads for the Ford F.

[01:03:53] D, but why would I want to see ads for a motor scooter when I'm looking for a pickup truck and frankly, if I'm looking for an F-150, I expect to see ads maybe for a Chevy Silverado or a Dodge truck. Does that make sense to you? Because I'm looking for something and that's what I'm interested in seeing.

[01:04:17] While Google is now jumping onto this bandwagon, because apple has said we are going to be doing a couple of things. We are going to be forcing you app developers to tell everybody exactly what you are doing with their information, what you're tracking, who you're selling it to, what it's being used for.

[01:04:40] That's a very big deal. And it's got the whole advertising industry. Very. Worried and Google is coming along saying, okay, apple will do you a little bit of one better. And of course the biggest complaint, or, from Facebook who ironically has been buying newspaper ads, if you can believe that, google has been destroying the newspaper industry. Now it's going to newspapers to try and get people to stop apple from destroying Facebook's industry, right by blocking some of the advertising tracking that Facebook has been doing. Now, what they are doing is what Google is doing is looking to replace these third party cookies.

[01:05:30] And how were they going to do that? They are already doing a few rather sneaky things. For instance, they fingerprint your brow. Now your browser has a fingerprint because you have certain extensions on your browser that you've added. You have your computer, that which has an operating system that has a certain version.

[01:05:54] It has a certain amount of memory. It has a certain amount of disc storage, a lot of the private information, the personal information about, so your computer can be gleaned by a website. So one of the things they've been doing this, you okay, you're blocking cookies. No problem. I can still figure out who you are and they do now.

[01:06:17] They don't necessarily know exactly who you are, but they have a very good idea. One of the proposals the Google has come out with is called the federated learning of cohorts, which is very ambitious. Could be the replacement. If you will, for these third party cookies, that could be the most harmful. And what it is a way to make your browser do the profile.

[01:06:49] Itself. So historically they've been able to track your browser as you go around and then they have to pull all of that information together. They pull it together and they come up with a picture of you and who you are. Yeah. You're interested in buying a pickup truck, particularly a man. Okay. Is an example that picture gets a cat gets a detailed about you, but it's something that the advertisers have to put together.

[01:07:20] What this flock or federated learning of cohorts is doing is it's boiling down your recent browsing activity into a category. They're calling this a behavioral and behavioral label, and then they're sharing it with websites and advertisers. So the idea is basically your web browser. It self is going to put you in one or more buckets and the websites that you're visiting and the advertisers that are advertising on those websites will be able to get that label that your browser has put on.

[01:08:06] You. Yeah, you like that. So what eff is saying is that this could exacerbate many of the worst non privacy problems with behavioral ads, including discrimination and predatory targeting. You can guess what those things mean. So they're calling this a privacy sandbox, right? It's always the opposite. If Congress is passing a bill, that is a COVID relief bill, you can bet that there's very little to do with COVID relief in the bill. Wait a minute, actually. That's true. There's only 9% of the money in this almost $2 trillion spending plan. The night last 9%. That actually goes to COVID relief, instant COVID relief bill.

[01:08:53] Same thing here with Google. Privacy sandbox and it's going to be better. So Google says in the world we have today where data brokers and ad tech giant track and profile everybody with complete impunity, just like Equifax has just like cat. Kofax lost our personal identity. Bio level information, our social security numbers, or addresses or names or date of birth, et cetera, et cetera.

[01:09:20] Yeah. Yeah. Okay. We pay a small fine. Yet. We go on, I, are they out of business? Have they lost business? In fact, they gained business because people have been paying that Kofax too. Monitor their credit. Oh my gosh. But that framing and the Google is talking about is based on a false premise that you have to choose between old tracking and new tracking.

[01:09:45] Does that sound familiar? Yeah. So it's not an either or. We really should be rejecting this whole new federated learning of cohorts proposal. The Google has come out with, you can bet that apple is going to reject this outright because it's really rather terrible. If you care about your privacy on the other hand again, I look at it and say, I want an F-150.

[01:10:14] I don't mind ads for pickup trucks, so what's wrong with that? Okay. There's two sides to this. I just don't like them calling me by name. When I walked past a billboard.

[01:10:25]We really, aren't going to talk about Bitcoin in this segment. So stick around. I had to talk about Russia this last time around, but Bitcoin, the prices are surging. People are mining. What does that mean? And why are they using more electricity than the country of Argentina? Bitcoin has been around for a while. And I don't think anybody out there has not heard about Bitcoin. It is a power in and of itself. We don't know who actually came up with this whole concept. There's a concept behind Bitcoin called blockchain technology and blockchain technology is based on. The concept of ledgers, where you have ledgers, just like a bank ledger that keeps track of every transaction.

[01:11:16] And there are hundreds of thousands. There's just so many ledgers in the world. And in order to verify transactions, half of those ledger entries have to agree. Pretty basic on that level, but what is the Bitcoin itself, which sits on top of this blockchain technology? If you want to look at it, simply take a look at prime numbers.

[01:11:42] Hopefully you can name the first five prime numbers, right? 1 3, 5, 7 11. There you go. Ta-da those are the first five of I think I got those right prime numbers and applying numbers and number that is only divisible by itself. And why. Which is why one is a prime number and we use prime numbers a lot.

[01:12:06] Nowadays, most of the encryption that you're using is based on prime numbers. If you go to a secure website, you're using something called SSL, which is the secure socket layer. And that's what shows up in your browser, in that URL line as a little lock, if you see that lock, that you have.

[01:12:27] Effectively a VPN, a virtual private network between your browser and that remote server. Yeah. Guess what? You already have a VPN, right? Why use one of these VPNs that spies on you? So that is encrypted data and it's very difficult to encrypt in between. How does it do that? It's using something known as public key technology, the RSA algorithm.

[01:12:55] We're not going to go any further down that, but basically it's a allows someone to have a public. And use that public key to encrypt a message. And then you, the person who's receiving the message whose private key was used to do the encryption can decrypt it using their private key. So the public key side, the private keys side, it allows the encryption from end to end.

[01:13:24] That's what the SSL is. Okay. When we're talking about Bitcoin, we are talking about something that goes and uses some of the similar technology, because what it's doing is using the. Prime numbers. That's what the RSA algorithm is using this encryption algorithm, using these very large, very complicated prime numbers because you get past 11 and see 12.

[01:13:50] That's not a prime, right? Because it's divisible by two and six and three and four, and then let's see 13. Okay. That's a prime 14, no 15, no 16. No. Okay. It gets more difficult. I remember way back when writing a little program that just found prime numbers and it looked for prime numbers and the easiest way to do it was I would start.

[01:14:22] First of all, you take a number. Divide it into, there's no reason to go any higher than that when you're trying to figure out if it's prime or not. And then I would start looking at some of the base numbers to try and figure it out. And then of course, real mathematicians were able to figure out better ways to find primes.

[01:14:39]When we're talking about Bitcoin and some of these other cryptocurrencies, they are also using these very large prime numbers, just like you're being used for this public key encryption. And they also have some other parameters around some of these prime numbers. So to have a Bitcoin is to have this digital number that represents a unique prime number.

[01:15:06] If you want to mind what you're doing is you are trying to find a prime number that no one has ever found before, just to oversimplify things a little bit. So you find that pine number and Tonna. Now you have a Bitcoin sounds easy enough sounds quick enough. It is not easy and it is not quick. And it's not just the based on the prime number algorithm, but we're keeping this simple here.

[01:15:33]We have found millions now of these Bitcoins. I should look that up and find out exactly how many, but there are many Bitcoins. The whole algorithm, the whole system is set. To do some restrictions here. There's only a certain number of these Bitcoins that will ever be mined. It's estimated that something like 20% of the Bitcoins that were found have been lost because the encryption was Jews to keep the keys.

[01:16:08]People forgot it. You probably heard about this guy that has. A quarter of a billion dollars in Bitcoin in this wallet. And he only gets eight tries before it auto destructs, and he hasn't found them yet. So there's a quarter of a billion dollars that's unreachable, but that's what we're talking about here.

[01:16:27] Bitcoin. In this day and age, Bitcoin mining is so hard and it takes so much computing power that it is using up a couple of things. First of all, the thing that bothers me the most is it's using up these GPU's these graphical processing units, because GPU's, which we typically use for graphics processing are set up so that we have are hundreds, thousands.

[01:16:58] Processes that can be happening on that card simultaneously, various small little tiny processes that can be set up to somewhat be optimized for Bitcoin mining or mining, any of these other cryptocurrencies. And then the people who really want to make money on money. And these cryptocurrencies have machines that are special machines.

[01:17:22] They are designed specifically to mine, one type of coin, one of these crypto coins. So we're talking about Bitcoin. So there are machines that are designed to mine. Bitcoins, go to eBay and look for Bitcoin miner. They used to have all my on Amazon. I haven't checked in a while, but you'll find them in both places.

[01:17:45] At least you used to be able to, you can certainly still find the money. And you'll find some that are old, that are used and some brand new ones. It is expensive to mine them. One of my sons and I, we decided years ago to try and do a little mining. We probably should have tried harder. But we gave up because it was a, who knows what's going to happen with Bitcoin.

[01:18:08] There are so many cryptocurrencies. Then today, there are people introducing new cryptocurrencies all of the time. And I avoid those like the plague, because you never know what's going to happen. Bitcoin is definitely the 800 pound gorilla out there. We were able to mine, I guess my son, he mind a couple of other little currencies, they're worth a penny or two, not a very big.

[01:18:33] We have now so many people in China, for instance, that were doing Bitcoin mining, the China could not produce enough electricity to mine, the Bitcoins. So China went around and shut down anybody that was mining Bitcoin, and we have something called the Cambridge Bitcoin electricity consumption. Index. So this is an index it's designed to figure out how much electricity is being used in order to mine, Bitcoin.

[01:19:07] And this is course in, over in England, the university of Cambridge, the judge business school. I'm looking at a graphic right now that they have, and this is showing the electricity and Bitcoin. They actually have all of the data for downloading if he ever wanted to do some serious analysis, but it's showing there was hardly anything.

[01:19:30] And this, anything back in 20 16, 20 17, it was summer 2017 when it started to jump up. And that's of course, when the price of Bitcoin started to go up and it started to go up. Why? Mainly because of ransomware people having to pay ransomware and buy. Bitcoin in order to pay that ransom, but in terawatt.

[01:19:52] So now we are showing at about, okay, so this is I'm looking at Wednesday, February ten, twenty, twenty one, two hundred and eighty eight terawatts of electricity. On that one day isn't that something and the amount of electricity that's being used has been surging because of course the price of Bitcoin has been going up and just been going up.

[01:20:17]Crazy rate it, the amount of mining going on has doubled almost doubled since October last year. And we're talking about using more electricity than the entire country of Argentina. The Netherlands and the United Arab Emirates. It is absolutely amazing. Amazing how much we're using people are alarmed by this countries are having major problems in trying to figure this out.

[01:20:51] And what else is funny about it? They talk about Bitcoin being. One of the green technology? It turns out that Bitcoin because of the electricity that it's using for people to mine, new Bitcoin, it now has a carbon footprint comparable to the entire. Country island of New Zealand, it's producing about 37 mega tons of carbon dioxide per year.

[01:21:19] I think that's funny, frankly, because they call it green. It's like green cars that are electric GLAAD. Guess what? They, aren't green in so many ways. They're coolest hacked. Don't get me wrong, but they're just, don't think they're green because they're not. A lot of reasons for that. And I've talked about it many times in the past, on my radio show.

[01:21:39] And if you go to my website, you can just look that up and you can find out why, and I've got hard numbers there and everything else. All right, everybody make sure you visit me online. We have started some new stuff. If you are a frequent reader of mine. Now Sunday newsletter, which has my show notes. You are getting also one or two weather newsletters during the week.

[01:22:04] Just short trainings. I'm trying to help you out, but if you're not opening that newsletter, if you don't download the images and that's how I tell the joke opened it, then you're not going to get all of this supplemental material, including some audio programming that you can't get anywhere else. So make sure.

[01:22:22] To CraigPeterson.com and sign up for the newsletter and open the silly things. So you get all of this free training and more. CraigPeterson.com

View Details

[As heard on WGAN 2021-06-23]

You getting annoyed with these multi-factor authentication things where they're sending you a text, et cetera? So is Matt. We talked about what is coming pretty soon, frankly, that we'll get. Not only the multi-factor authentication being needed, but also even the passwords. We also got into this whole Senate debate about a 25% tax credit for semiconductor manufacturing.

[00:00:28] Why do they think it's needed and what are we going to do? So here we go with Mr. Matt. And of course me, Craig Peterson

[00:00:36] Matt Gagnon: [00:00:36] Well, you hear his voice here every Wednesday. You also hear it on Saturdays at one o'clock. Craig Peterson, our tech guru joins us. Now, once again, Craig, how are you?

[00:00:46] Craig Peterson: [00:00:46] Hey, I'm doing great, Matt.

[00:00:48] Matt Gagnon: [00:00:48] Good to have you as always. So I'm going to start off with a simple question for you, Craig, unrelated to any of the topics we're going to get to. But this morning I had to log into something using two factor identification. Can we do something else that's better than the. Is it, is there a less annoying way of being Uber secure in LA talking into stuff then having to like, like you go on Facebook, you try to log in with a password.

[00:01:10] Then it says you have to get a two factor identification. It has to send a text message to my phone. I've got to pick up my phone. I got to log into my phone, check the text message. See what the number is, use that number, type it into the thing on the, I can't take it anymore. Is there a better way? Probably not, right?

[00:01:30] Craig Peterson: [00:01:30] Yeah. There, there are better ways that are under testing right now. Really. They're a universal log-in sort of a thing. There are of course, password managers, which don't make that much easier. W frankly, if you're concerned really concerned about your security should never use text messages for two factor authentication, but Microsoft, Google, and apple have actually gotten together over the last year and come up with a standard.

[00:01:58] So there is a new standard in place, but sites like Facebook and many others still have not adopted it. We're actually heading to. Passwordless future where there is not even a password, let alone the two factor thing, and it's all handled locally by your browser. So those days are coming, Matt, they're just not here yet.

[00:02:19] Someday

[00:02:20] Matt Gagnon: [00:02:20] I can, man, can dream. Craig Peterson joins us on Wednesdays to talk over whatever it is. That's stuck in my crock today. Let me start off with one of the stories that we are prepared to talk about here a little bit, which is about the semiconductor shortage, right? There's a lot of ideas on how to do something about that.

[00:02:37]And right now in the Congress, our betters in in government are debating and talking about the idea of proposing some 25% tax credit for semiconductor manufacturing, obviously in response. To the ridiculous shortage that we have in these particular items. Tell me about this proposal.

[00:02:55] Is it something that might solve the problem?

[00:02:58]Craig Peterson: [00:02:58] That is, I love that statement there, Matt, by the way, just an hour. Better

[00:03:05] Matt Gagnon: [00:03:05] dripping with sarcasm.

[00:03:06] Craig Peterson: [00:03:06] Yeah. Yeah. That's exactly. Yeah. There, they're trying to get manufacturing back to the U S and in fact, it's already happening because businesses because of free market.

[00:03:18] Somewhat free market forces are deciding they cannot rely necessarily on having most of our chips made in Taiwan, frankly, as are, most of them are. And so we've now got Congress in the form of the Senate who are trying to figure out a way, how can we incentivize these companies to get back. So they went ahead and approve 52 billion.

[00:03:44] Dollars of course from their pocket change, right? It's from their staff for producing and research scenes, semiconductors and telecommunications equipment and figuring out what should be done. They even earmarked another $2 billion dedicated to trying to get ships that are used by automakers to be manufactured here in the U S now, is it going to.

[00:04:10]Probably, but we see some major drops here in manufacturing, in the us all across the board. Semiconductor microelectronics productions fallen to 12% of all of our production is made here in the us. The rest is overseas and that's down from almost 40% made here in the us in 1990s. So we'll see. It is a big problem, but I got to tell you, Matt, I don't think if this, because it's a big problem, that means it's the federal government.

[00:04:44] Matt Gagnon: [00:04:44] So do you have any other ideas on solutions then? If I, cause I agree with you. Generally speaking, anytime Congress attempts to try to manipulate markets. I get queasy and it's because there's always unintended consequences when they do that. And it's usually it perverts markets and never everything about it is bad.

[00:04:59]So is there a better way of trying to, fix the problem a, because clearly there's shortages of a lot of things, but then B this notion of security, you don't want all of the very critical infrastructure that you need production. Things, the products that make us go in our society produced somewhere that makes us vulnerable.

[00:05:17]Taiwan were to be blown up by China, that would present a problem for us. So what do you do instead?

[00:05:24] Craig Peterson: [00:05:24] It would absolutely would I, again, I think free market forces can work. They do work. But I also looked at this and say, our we're our whole country is dependent on having these as you pointed out.

[00:05:38] And therefore, frankly, this should be treated as a national defense emergency. We need to be doing it here in the U S we already have it. We're still a war, we never declared the end over the last war. So we still have this, our arms production laws in place and can force businesses to make things.

[00:05:58] I don't know that's the best idea, particularly with this, but we. To treat it differently. We cannot get chips for some of our fighter jets. In fact, we bought chips from China, inadvertently for our fighters that had malware built into the chips that were going into some of our military hearts. So I think the federal government is looking at this all wrong.

[00:06:26] They're also looking at this Taiwan, semiconductor manufacturing company, TSMC, which is the big guy in Taiwan. They're building the $12 billion semiconductor factory in Arizona. We've also got a jet Dutch chip maker. That's moving here to the us. We have other companies that are reactivating these old semiconductor plants, so it's happening.

[00:06:51] But I think we've got to look at this as a national defense. It's the same thing with our steel production, our aluminum production, much of this that we've allowed to go to other countries, as you said, might get blown up. Might not like this in the future. I will, we've got to take a much different approach as businesses and as the government.

[00:07:13] Matt Gagnon: [00:07:13] Hey, Craig Peterson, our tech guru joins us at this time every Wednesday, Craig, before I let you go, I also want to ask you about the general motors decision to start developing hydrogen fuel cells. This stuff is catnip for me. I love stories like this developing technology. Very interesting. What you say.

[00:07:29]Craig Peterson: [00:07:29] Of course people you're coming to mind, hydrogen and that little incidents in New Jersey in 1937, we've come a long way since the Hindenburg and GM came up with these hydrogen fuel cells for cars. Love the idea of hydrogen. There is one ultimate by-product and that is pure water. GM is saying we haven't had that much luck in the automotive industry.

[00:07:57] Where else can we use it? And they're looking at airplanes saying these planes take off with two tons of water on board, just to him. The toilets and the hand washing your hands, et cetera. And they also of course, are burning jet fuel in order to create electricity. So if we put a little hydrogen fuel cell on board, first of all, we can make these things.

[00:08:19] So they're intrinsically safe, but we're also now able to generate. On board, pure water has we're fly and any excess, or you can just dump overboard basically. And so we're saving two tons on takeoff weight and we're generating electricity. I think this is a very cool idea. And these fuel cells are going to be flying a little later this year in some test markets.

[00:08:44]Matt Gagnon: [00:08:44] If I, if they're saving all this weight on takeoff and I expect to be able to take it. Bag onto the onto the airplane. Right?

[00:08:51] Craig Peterson: [00:08:51] So they're not compensating for us getting a little heavier.

[00:08:57] Matt Gagnon: [00:08:57] All right. Craig Peterson, our tech guru joins us at this time every Wednesday. It's good luck on Saturday, Craig.

[00:09:02] Thanks so much for joining us as always. And we'll talk to you again next week.

View Details

[As heard on WTAG, WHYN, WHJJ on 2021-06-22 with Mr. Jim Polito]

We had more discussion today with Mr. Jim Polito about this fuel cell. Jim isn't as happy about it as I am. I think it's just a cool technology for airplanes for a few reasons, but we really got into that. And then we started talking about hydrogen, how do you make the hydrogen? How do you make electricity?

[00:00:19] So that product is into what we're looking at really now with nuclear. These new, what is it? Fifth or sixth generation plans. And that is probably what we should be doing. And yet there's so much pushback. Anyways, here we go with Mr. Jim Polito.

[00:00:39] Jim Polito: [00:00:39] You all know the story of the Hindenburg, right? Hydrogen, the Nazis.

[00:00:44]Dirigible the blimp. . It got its ability to rise through hydrogen. We wouldn't give the Nazis helium, which has the same properties, but is safe. Hydrogen is not safe. Wow. It looks like general motors is thinking about or working on a hydrogen fuel cell for airplanes. Joining us out to talk about this, but just briefly and some more important things is our good friends in tech talk guru.

[00:01:17] Craig Peterson. Good morning.

[00:01:19] Craig Peterson: [00:01:19] Hey, good morning. And today we have a shortage of helium as well. For birthday parties, I would have gotten more expensive. Maybe. Yeah, maybe there's something there. Maybe.

[00:01:30] Jim Polito: [00:01:30] I don't know, I hate to put you on this one, but you shared the story with me. And I said generally the motors developing a hydrogen fuel cell for airplanes.

[00:01:40] All I can say is, oh, the humanity. Oh, the humanity. So jealous my good friend. What? This is all about.

[00:01:51] Craig Peterson: [00:01:51] Sure. I'm really actually excited about this. I think an interesting idea. Yeah. First of all, the Hindenburg, there were some serious design clots, not the least of which the Hindenburg itself.

[00:02:05] Coated with rocket fuel fuel. The whole outside was coated with a blend of nitrate, and nitrate is used to make gunpowder. So they had the leak, they had a spark, and it went up like that because the whole thing was coated in rocket fuel. So it's not that hydrogen is not dangerous, cause it is.

[00:02:27] You've got to keep it under control. Yeah, but you have to weigh everything out. So what general motors is saying here is we're going to take some technology we developed for cars. Now there are hydrogen powered cars in California. There are hydrogen fill stations, frankly. Hydrogen is what excites me the most about all of these alternative fuels.

[00:02:52] Because what you do in a hydrogen fuel cell is you have some compressed hydrogen on board, many cities, run buses, trucks, and other things on compressor, liquid for LPG, you look at petroleum gas. We know how to contain it even in the event of a really bad accident, but the beautiful thing about hydrogen.

[00:03:15] Is there is only one byproduct when you're making electricity from hydrogen, with a fuel cell and that by-product is pure water.

[00:03:25]Jim Polito: [00:03:25] I've looked at it, no for like cars and things. Even 20 years ago, they were discussing it. This would be a great thing for cars, but to produce the hydrogen don't you expend an awful lot of fossil fuels to make that actual hydrogen.

[00:03:43] Craig Peterson: [00:03:43] You do, you need a lot of electricity to do it. And there's, and it's difficult to transport and lodge, large quantities, which you'd need for in for instance, driving a lot of cars around. And so there's been research into we can suspend it in ammonia. Ammonia happens to be pretty darn dangerous.

[00:04:00] Oh my God.

[00:04:04] Jim Polito: [00:04:04] Return in this thing. It isn't

[00:04:07] Craig Peterson: [00:04:07] itself. And but here's the cool thing. What GM saying is, Hey, we put all of this money, your taxpayer dollars, right? I seem to remember some sort of a quote to bail out on code for GM into developing the fuels. If the advantage in an airplane, if you've looked beyond the potential explosion, I see the advantage in airplane is when a plane takes off Jim.

[00:04:30] Yeah. It has two tons of water on board and your plane takes a lot of fuels to get that plan. And that's just two tons of water for drinking water, flushing, toilets, washing hands. We hope. Yeah. Yeah. There's the normal stuff. And they're also of course, as a need for electricity. So the electricity is being generated by a takeoff from the turbines, which means it's burning up the jet fuel to make electricity, the water, of course, entering two tons of launching that into the year takes a lot of fuel.

[00:05:02] If you can get a fuel cell that is considered to be intrinsically safe. Now you don't have to bring water with you because the by-product of generating electricity to power, like the cabin lights and other basic things. The power is going to create pure water. Years form. And so now you're saving fuel right?

[00:05:27] Left and center. Now, of course, how did you make the hydrogen? You brought that up. That's a great point and potential safety issues. And I don't think they'll make the same mistake as the German scientists.

[00:05:43] Jim Polito: [00:05:43] You're right. We're talking with Craig Peterson, our tech talk guru, Greg guy, about this possibility of general motors, developing hydrogen fuel cells. Now. We've talked about nuclear power before, so you need a lot of electricity to produce this hydrogen that you're going to use. Okay. In order to produce that electricity, you use fossil fuels, coal oil, mostly natural gas.

[00:06:11] Okay. We can talk about wind farms and all that, but please. What if we were to produce it with nuclear power? And the advancements that have been made in nuclear Prine. I know you're a big advocate.

[00:06:25] Craig Peterson: [00:06:25] Yay. Fantastic idea. We've got the generation. Nuclear plants. My son could tell you everything about them front back, but these things are inherently safe.

[00:06:39] They are the only real green fuel. Your solar cells pollute like crazy when they're made the same thing with the batteries and the lithium mines. There is a real big discussion now because we're looking to mine, lithium here in the us and an area of the desert that has those roots. Plant that only grows where there's high lithium in the ground.

[00:07:03] And so they don't want us to mind that lithium, but we want it for our batteries so we can get our electric cars so we can feel good about ourselves, but these new generations of basically thermal nuclear plants, but they're much different than the old ones are. Set up in such a way that they can not melt down.

[00:07:22] It's absolutely amazing. You can make a nuclear plan for cheap money. A million dollar range that will power a town. And it needs to be replaced every 20 years. They put it underground. They get up and off you go again, and it all recycled. And yet we are now still governing our nuclear power plants based on rules and regulations created in the 1950s.

[00:07:50] And people just don't want to pay attention to it. And so I'm so glad you brought it up. I know

[00:07:55] Jim Polito: [00:07:55] because of the advances, Hey Kathy and I. Flew from Milan to Paris two years ago, flew over the Alps, look down. I'm looking down because I want to see the Alps. But as I look down, I see nuclear power plants to, to nuclear power plant.

[00:08:12] You can't miss them because of the big towers cooling the steam. And these are the older nuclear power plants, but France, what is it? 70 to 80% of their electric. They produce through nuclear power and nobody seems to discuss that at all.

[00:08:29] Craig Peterson: [00:08:29] Yeah most of the European countries do, frankly it, it just makes sense.

[00:08:33] You, it's compact. You can turn a lot of electricity, you can drive your electric cars and everything else is designed to have central points for electrical generation, not to have a generator in all of our homes and things. And one of my sons is now been flying around the country. In fact, he just went up to Canada, just north of lake Charles.

[00:08:54] For a few days and they got special dispensation from Lauren Fowchee

[00:08:59] Jim Polito: [00:08:59] and oh, it's Pope Fowchee. We prefer to say Cole Fowchee.

[00:09:04] Craig Peterson: [00:09:04] Yeah, but it's a Canadian version. Oh, the

[00:09:06] Jim Polito: [00:09:06] Canadian guy, right? Yeah. And the Lord and the

[00:09:10] Craig Peterson: [00:09:10] Lord. Yes. And he went up there and they Ontario generates 30% of its electricity from these massive wind farms.

[00:09:19] But at any one time, so much of it is just out of production is not working. He's having to go service things. Other people are as well, nuclear. Whether the sun's shiny, whether it's a middle of winter, like in Texas or in nuclear works when it's

[00:09:36] Jim Polito: [00:09:36] dark. Yeah. Yeah. And why aren't we doing it? I just don't.

[00:09:40] I think too many people have seen the China syndrome and the Silkwood, those two old movies about, about meltdowns. Now, if you had seen the mini series Chernobyl, which I did see, which was fantastic you would realize okay. That's because that's what happens when you have a socialist communist country rushing to get power and and doing it in a way that's not safe.

[00:10:06] And yet people will see that and say, oh God, we can't have that. And that's not what we're talking about.

[00:10:12]Craig Peterson: [00:10:12] And with NIMBY, of course not in my backyard. Look at the cake, look at the windmills off of the Cape there. The Kennedy. It used to be the Kennedy compound. They donated it to charity because they care about the

[00:10:23] Jim Polito: [00:10:23] people.

[00:10:23]Hold on a second. Let's just make this clear. They donated it to their own charity. Okay. They all know that Victoria, Reggie now controls a Ted's widow. So she controls who can go in there, who can come? Yeah, yeah, they donated it to her charity. Sure. Very good. You know what? You're quite the comedian there.

[00:10:47]Craig, not only are you our tech talk guru, you are, you do good comedy bits.

[00:10:55] Craig Peterson: [00:10:55] Yeah. I'm feeling a little spicy this morning, I think is what I

[00:10:58] Jim Polito: [00:10:58] think. So I think so. Oh my God. Yeah, the windmills are not reliable and they're not that good when you get right down to it.

[00:11:07] Craig Peterson: [00:11:07] No, they're costly. They're obviously dependent on the wind. No, one's come up with a great solution.

[00:11:14] For this yet there's stuff where in Europe with the tides, I don't know if you've seen that, but they basically put up the dams that move and the use the tie to generate electricity and energy. But still today, the new generation of nuclear is a hundred percent. What I would suggest nothing's a hundred percent safe as we already know.

[00:11:36] I just saw a release or not a release, but a an update for fire departments. I'm putting up Tesla fires and because of the battery pack

[00:11:46] Jim Polito: [00:11:46] when they start on fire.

[00:11:48] Craig Peterson: [00:11:48] Exactly. So they're saying dump a lot of water on it. And so the fire departments would say what does that mean? There's somewhere around.

[00:11:53] I can't remember the exact number I'm going to get this wrong, but it was over 3000 gallons and the fire department came back and said w wait a minute, our fire truck only holds 500 yeah.

[00:12:05] Jim Polito: [00:12:05] Thousand gallons of water to stop this reaction, this fire.

[00:12:10] Craig Peterson: [00:12:10] Yeah. And it's all these batteries lithium-ion batteries and they are dangerous.

[00:12:16] So you've seen a phone. They get banned. Just catch on fire, laptop tape. If your laptop, I noticed this was one of mine. I had an apple laptop and I had it down on a flat surface. I noticed it was teetering pivoting a little bit from its middle. Cause the battery was swollen. Took it back to apple.

[00:12:34] They replaced it. But Keep an eye out on that because it can start a house fire people's people have had their phones charging by their head at night and thank goodness it was by their head because of the smell of the fire will come up because these are dangerous and it's always a balance, right?

[00:12:51] Should I code it? Yeah. Rocket fuel or shouldn't I

[00:12:55] Jim Polito: [00:12:55] go on that note? No, Craig, this has been very helpful as usual Craig Peters on our tech Docker or crank you folks want to get more information from you like I do every week. What do they do?

[00:13:09]Craig Peterson: [00:13:09] You can go to Craigpeterson.com. And you can subscribe right there.

[00:13:14] I'd like why now, too. Of course, I'm on the weekend here as well, but I have even more stuff that I brought every week and you can listen to that on your iHeart radio laugh. Just like you can listen to it down in New York city. Yeah, any way you can do that by just going anywhere, just go to Craig peterson.com/iheart, and that'll take you right to the iHeart radio lab and you can listen to my whole show and all my ramblings for the week.

[00:13:42] Nice

[00:13:43] Jim Polito: [00:13:43] Craig Peterson, everybody a great guy, a very smart guy, Craig. Thanks so much. We'll talk with you next week.

View Details

[2021-06-19 Week #1118]

The Columbia lawsuit. This is just amazing. I've been telling businesses for a long time that insurance companies just are not paying out on many of these claims, the insurance companies come back to you after you've been hacked, or you had ransomware and you try and file a claim and say, okay, so no problem.

[00:00:20] Now you met all of these qualifications, right? And they have this big checklist. Everything. And I bet you most companies, if you have not seen this list would be totally surprised by what the insurance companies are requiring of you now, the same thing's true of home users. If you look in your home policy homeowner's policy, you probably see something in there that says ransomware or computer failures, et cetera.

[00:00:53] And they will cover dependent on your policy. Some amount of money, maybe it's 10 grand, five grand could be a lot of different things and it's not terribly expensive. Now you got to ask yourself, why is it so cheap, particularly when there are so many viruses, ransomware, Trojans, fishing, all of these things out there in the wild.

[00:01:15] And from a business standpoint, it costs a lot more. I know my business is paying a lot of money for the insurance. But we go through in detail, everything that's right there in the policy. And we even ask for a list of everything kind of separate list, so that we know what exactly they want. So we've got to check the list and I can send it to, if you want, just go ahead and email me.

[00:01:40] So if you have a a hack, if you have ransomware and you have insurance, you're probably going to file against the insurance, right? Because looking at all of these numbers, a medium, a small, medium business is going to be. But not a pocket about one and a half million dollars. And that's, if they're not paying the ransom, it's really expensive is difficult.

[00:02:04] And if you're a home user, oh my, you are, will never get your information back. You have maybe a 50% chance if you pay the ransom of getting. Your stuff back. Think about all the photos you have on your hard desk, all of the letters, all of the emails, same trick for business and to business. It's not just all of the emails, it's your contracts, it's your plans, your intellectual property, everything that you can think of that's out there.

[00:02:33]Getting it back. So this is interesting when we look at this. Company it's called cottage healthcare systems. They filed a claim of more than $4 million against a breach. Now that is a fair amount of money, but it is not unreasonable for a medium-sized company. The SBA, the small business administration says that if you're under 10 million in revenue, then you are a small business under 200 employees, right?

[00:03:05] It has those levels. So think of it that way, right? A small business is not necessarily just some home users. You can have some serious money involved in a small business. So they had claimed here this again, cottage health care systems that they had been just totally protected. At least not from the cybersecurity standpoint, but from the insurance standpoint.

[00:03:32] And for years, software vendors have assume that they can take that security risk and push it on to their customers. We're seeing this a lot in the medical business with doctor's offices. They've got these HIPAA regulations and they've got all kinds of private information. Plus they have payment card industry regulations that they have to fall under or agreement because they have credit card and other billing information.

[00:04:00] And of course the billing information that's going to the insurance company has to be protected as well. And these doctor's offices are making a very bad assumption that somehow they don't have to worry about it. And the reason they don't have to worry about it is it's quite simple because I'm using a cloud service.

[00:04:20]Have you heard that before? Do you know anybody that said that? So I'm using the cloud thing now. Yeah. Yeah. I'm using salesforce.com for a regular business for your customer relationship management or all of these patient management systems that are out there. Now there's some, I'm just shocked that.

[00:04:37] Won't charge the doctor's office, anything. And yet they'll keep all of the client records for the doctor and supposedly keep it safe. Maybe they will, maybe they won't. And then also on top of all of that, they'll do the billing and that's how they make their money because they shave a percentage off of every bill that they issue to the health insurance carriers.

[00:05:03]So these doctors are sitting there saying I'm using these online services. I've got Microsoft office email. I've got whatever it might be. Google has of course their professional emails too. And when those guys get hacked on fine, because they had my data. Reality is no, that is absolutely not true.

[00:05:26] And we've seen software companies, ship products. We've seen these cloud services deliver services with known vulnerabilities and expect the customer using the service or using the software to absorb all of the risk. And then the vendor of the services or software is protected from loss by. It's insurer.

[00:05:50] So this is called shifting risk and the software companies can delay fixing vulnerabilities in their code and maintain their release schedules because they're sitting there pretty thinking, oh, I'm fine. There's no problem here. I got my insurance and it's fine that the customer, that shrink wrap agreement, or maybe even it's a contract that was signed, which is more true for doctors, offices and regular businesses.

[00:06:16] Says that the doctor's office has a liability. I'm afraid to have to inform everybody here that you cannot shift that liability. The insurance company is not on hook for covering the damage. And this is a very big deal. And what I'm talking about is this insurance company called Columbia casualty, their division of this industry giant called CNA, which is a course in the insurance business.

[00:06:47] Oh, that's what they do. So they had paid out. This four mill Morton for a million dollar claim and their suit that was filed by the insurance company against cottage healthcare systems said that they hadn't kept their security controls up to date. And. When a breach occurred, they tried to put the insurance company on the hook to cover all of the damages.

[00:07:15] I've got a copy up on my screen right now from health it security.com. Talking about this. This is a, an older articles is in 2015, but even then we knew that you cannot fall back on your insurance. And that's why, again, that's why the rates are so cheap, right? They're just not paying out. So the suit is still underway and it's something we've got to pay close attention to because the court case documents are saying that Columbia quote, six declaration, that it has no duty to defend our identity and indemnify cottage in the underlying action.

[00:07:55] Or the department of justice proceedings. Yeah. Okay. Yeah. They're DOJs in on this as well. So they had to end their practice of what they were doing and frankly, keeping systems up to date, having the minimum required practices, including yep. Replacing just basic stuff. Default settings in their it environment, checking for vendor supplied security patches, implementing the patches within, 30 days, something reasonable.

[00:08:25] Most of us delay putting patches in place for least a week. You guys you're the best and brightest, if you put a patch in. The Jess came out, it might make things a little unstable, right? So a lot of us wait for, I think good reason, frankly. So the bottom line is this is again, over the course of seven years here, insurers understand that not all breaches are inevitable.

[00:08:52] And that the companies here, the healthcare companies, the software vendors, the cloud vendors have to do more to protect their clients. But from what I'm seeing, it just is not happening. It's not happening at all. We are getting people who are looking at an equation differently than you or I do. Look at what happened with the colonial pipeline.

[00:09:17] What do you think was happening in the board of directors meetings before the security breach? The same thing with TJX, same thing with home Depot, same thing with that, that meat packer, all of these guys. What do you think they were saying? They were saying, okay, Mr. It direct director. How much is it going to cost us to have good cyber security?

[00:09:37] And the it director is going to say, okay we need some really great hardware. We need also software. We needed on all of the workstations. We need smart switches so we can trace things when they're inside the network. We need 24 hour manned security operation center with at least one person.

[00:09:57] So that means four people, right? Because three people, plus people have to have vacations people go on training. I know my people spend at least a quarter of their time in training. Let me see that, over the course of a year, it's probably going to be five to $10 million minimum. And so the board of directors says five to 10 million.

[00:10:17] Oh, okay. How much is it going to cost us? We get breached, oh, maybe 5 million. Forget it then we're not going to secure our systems. And I'm not saying that this is the conversation colonial had. I'm saying this is the type of conversations businesses are having and they should not be having, because frankly.

[00:10:37] It is not only illegal because you are supporting terrorists by paying these ransoms, but you're hurting yourself and your customers stick around.

[00:10:48]Craig Peterson: Tesla has a number of cars out. And these things I think are just totally cool.

[00:10:53] My daughter ended up buying one she's over Norway. So of course it was heavily subsidized by the Norwegian government. They get a 25% discount. Yeah. That actually is Tax. Yeah, so they don't have to pay the sales tax, which is 25%. Okay. No way is not as social as nation, but they sure tax the living daylights out of everybody, but they allow business to do what it needs to do and move with far fewer regulations.

[00:11:26] But anyway, so this isn't a political discussion. She loves her model. Absolutely loves it. They just drove it from Norway all the way back down to Belgium, which is where her husband's from. And they own I guess a condo bought an apartment down there, right on the sea coast in Belgium. It's really a beautiful area, but they love it.

[00:11:48] They had to stop twice to charge it up while they were on their way. You might've heard that the Tesla model S long range just got a rating of 405 miles of total range with a combined city highway MPG, E of one 20. So there's some things I need to explain here. First of all, this 405 miles and total range, it is not going to get that up in the Northern part of the United States when it's cold outside.

[00:12:23] You will be getting above 200 miles may be 300 miles out of it, because again, you're running the electricity through resistors in order to keep yourself warm and then you're not going to get it when you have the air conditioning on high. If you're living in the desert Southwest, for instance, or in Florida, trying to keep that humidity down.

[00:12:44] But the EPA came up with this MPG rating so that you could compare cars and how efficient they are. It's not going to give you any information about how much it's going to cost to run the car. It's just looking at these different cars and coming up with an idea of how much how efficient they might be, how much electricity they're going to use.

[00:13:06] So I'm looking right now at a chart. That's comparing side-by-side. These Tesla models. So the model asks long range is rated at 120. MPG. So that's miles per gallon electric. They have a really weird way of figuring this thing out. Let me tell you very strange. They're trying to figure out well, what is the amount of energy available in one gallon of gasoline?

[00:13:38] And then once the electrical leak. of that one gallon of gasoline, considering the gasoline goes from the tank out to the wheels versus an electric motor where it's right there at the wheel running that electric motor, they are not necessarily right at the wheel. Sometimes there's a drive train involved.

[00:13:57] Okay. So I don't want to get too technical on it. The model ain't. As long range plus is rated at 117. So it's pretty good, but you can use that now. Number to compare electric cars. It's not a comparison with a gasoline car, and it's not really telling you how much it's going to cost to drive because the EPA is using.

[00:14:20] Average costs of fuel across the United States is not what you are necessarily going to pay. All right. So you've got to pull all of that in. So very cool. Congratulations. If they really are getting 400, 500 miles on a charge, that's wonderful, but I know the way I drive, I w I will go down. For instance, we drove to Florida, not too long ago.

[00:14:46] And the drive to Florida took a couple of days in my car and, we stop and fill it up. A fill up, takes about 10 minutes. My daughter was saying her model three they didn't run the battery all the way down and they didn't fill it up all the way. And it was about 20 minutes stops. Now this is in Europe.

[00:15:06] And in Europe, they have a lot of recharging stations and these recharging stations can provide a lot of electricity. You're not just taking the car and plug it in into a wall socket. So when I'm driving down to Florida, I got, I have to stop at one of these rappers. But in charging stations in order to stand a chance of being able to get it to charge, but I'm going to a hotel.

[00:15:31] We stayed at a hotel at night that most of these hotels do not have the rapid charging stations at them. And if I'm lucky, I have some way to plug it in. I remember I was driving my Mercedes diesel. I was down in Connecticut and middle of winter. It was very cold out. And I couldn't find this was a big brand named hotel.

[00:15:54] I could not find a place to plug my old Benzin because remember I have 19 Haiti, Mercedes-Benz diesel, and I knew that if I didn't keep it plugged in, I'd never get it started the next day. So of course I wasn't able to get it started the next day. And I had the hotel, they found a 200 foot extension cord for me and they ran it out of a conference room over the hill, down to my car.

[00:16:17] We plugged it in and got the engine warmed up. So we're not as ready for it as they are over in Europe, but we have to start thinking about it. And one of the things that Tesla does is they charge you for pretty much every feature it's not. What you might call a menu list of options. Yeah. There are some options that you can get on it.

[00:16:42] And one of them is the autonomous mode and Tesla has continually cranked up the cost of this autonomous mode. I think it was like two grand initially. And now it's up to four or $5,000 for it. So the Tesla thinks while you will pay for it and we'll get the money from you all at once. Of course there's financing and stuff involved, but that's a different part of the transaction.

[00:17:07] To me, it makes sense. Tesla is a company that he is sitting now a little cash, but they're trying to be cash positive and they would rather have your money today for an option that isn't even really available yet. Then wait and get the money from you later. So that's, what's Tesla's strategy is on the opposite.

[00:17:29] End of that. Spectrum is Volkswagen. Of course the people's car it's been around for quite a while and it is made in Germany and they had a great meeting of their board very recently. And they're looking at how do we charge for things like autonomous mode? What do we do? If you look at what the computer industry has been doing for a very long time, I remember this one, our IBM 360 back in the early seventies.

[00:18:00] And. If you needed an upgrade, this wasn't just true of IBM. This is true of controlled data of everybody. If you wanted an upgrade, you want it to be faster or basic upgrades without rolling in more memory. Yeah. They used to roll it in on pallets to get another, a 64 K of memory. It was just crazy. Anyhow.

[00:18:24] If they were going to give you an upgrade. They would have a technician come in and effectively turn what we call affectionately in the industry. The golden key and digital equipment did the same thing. You could get a speed improvement by just having the technician come in and turn the golden key. In some cases it was actually located and it was a key hole right behind the main console on the front of the computer and other cases, it was a little bit of software that they.

[00:18:54] Installed and Volkswagen is saying maybe what we should do instead of yeah. What Tesla does and have an extremely expensive car that people can't afford. Not everyone can afford, we're talking 120 grand for that Tesla. I was just talking about it. The high end, maybe what we should do is give this golden key concept.

[00:19:13] I'll run. So they're saying maybe just like you would have an Uber driver drive you somewhere. Maybe the way to do this is charge you $8 and 50 cents per hour for you to use a Volkswagen's fully autonomous mode. I think that's a great idea personally, because you're going to be driving the autonomous car yourself.

[00:19:40] When you're in the city, most of the time, that's where I'm driving. It's just those trips to Florida. I'd love to have that autonomous mode stick

[00:19:48]Craig Peterson: Bitcoin has been around now for quite a while.

[00:19:53] I explained this week too, in my newsletter a little bit about what happens with Bitcoin. Oh, speak to the newsletter, make sure that you caught my newsletter this week. If you didn't send me an email me@craigpeterson.com, I can send it to you. But I sent out that video. I've been promising of how. To block this Russian malware ransomware by installing the rushing keyboard.

[00:20:21] And it's it's online. In fact, it's on my website. You can just find it@craigpeterson.com. If you don't have the newsletter, it's in there as well. But Bitcoin has been seized last year. There was this whole seizure of more than a billion dollars in Bitcoin. Yeah. A billion dollars. And again, wow. You can tie, you can't find out who has what or where it is.

[00:20:50] You can't. So you said, obviously that's wrong. This billion dollars last year was seized from something called silk. Road. This was a dark net marketplace and they specialized in mail order narcotics. They had all kinds of different things that they were selling. Basically, if it was illegal and shippable or viewable online, you could get it on the silk road.

[00:21:17] It was really that simple. They arrested this Ross Albridge guy. He was called dread pirate Roberts. And this was when he was working at Glen park branch library in San Francisco. They did that, so he couldn't shut down his computer. So they were able to maneuver some of the evidence that they found that allowed the FBI to seize 174,000 Bitcoins from him.

[00:21:43] It was worth about $105 million at the time. And they later sold the cryptocurrency at auction and he was sentenced to life in federal prison. Very big deal. And then now what we're looking at is something a little bit different. We're considering what happened with the colonial pipeline. And there have been some leaks, some people who are saying they've got some inside information, so we'll be talking about that as well.

[00:22:11] But apparently what happened at colonial is the one of these international police organizations, probably one of these Interpol countries or Euro poll had been tracking some of the bad guys who had been running this ransomware operation. And while they were tracking them, they seized some information, apparently unbeknownst to the hacker, they seized information about the Bitcoin wallet that this hacker was using.

[00:22:48] Oh, a Bitcoin wallet is something that has a password on it. It keeps your Bitcoin account numbers and these huge. They're not random numbers, but there are some random numbers for the passwords and your digital wallet number, but these huge numbers that are prime numbers that are used as part of the whole Bitcoin blockchain thing.

[00:23:11]Yeah. One of these international police organizations had the key to this guy's wallet. So when dark side was paid that four and a half million dollar ransom, the FBI was able to track what wallet it was. Cause remember the whole idea behind Bitcoin and blockchain. Is that not that it's secret. At all.

[00:23:37] In fact, there are hundreds of copies around the world about the transactions that are being conducted in Bitcoin. And that's why you have to use some of these clearing houses. But just trying to keep this simple, these ledgers are everywhere. So the FBI was able to track the money. It apparently moved three times the day after colonial pipeline paid the ransom.

[00:24:02] And they were able to see which wallets it went into as it was moving around. And then when it ended up in a wallet that they knew about, and in fact even had the password for, they were able to grab that money. And that's exactly what they did. So again the bad guys, aren't the smartest cookies out there.

[00:24:25] And apparently the other thing the FBI has been doing is watching the transactions when people are converting Bitcoin. Into hard currency, like us dollars or euros, whatever it is. So they're watching those transactions so they know, oh, okay. This wallet now took a half a Bitcoin out and converted it into cash.

[00:24:51] They're tracking this. And so they know who had the cash, what bank that cash went into, because oftentimes it's just your bank account number that's associated with it. And so the cash goes right there into the bank account and the FBI knows it. So later on, if you use your wallet for some transaction, they know you use the wallet it's in the ledgers that everybody that has part of that blockchain has access to.

[00:25:19] And they can now track you. So they've been a lot smarter about this when you are either converting your hard currency into one of these cryptocurrencies or you're converting your cryptocurrency into hard currencies. So they have been doing that as well. And it was the FBI office in, I think it was San Francisco, Northern California that kind of figured this all out law enforcement.

[00:25:46] The FBI have been really. Really good about some of his stuff lately. So the assistant director of the FBI's criminal investigative division, his name is Calvin shivers. Talked about an operation. They called Trojan shield at a press conference about a week ago in the Netherlands, in the hog. This is just amazing because what they were able to do is cry, criminals, encrypted communications.

[00:26:18] Now here's what they did. They came up with some software that they called a nom. A N O M. And in order to use this Anom software, you had to get as special phone and that phone had their cell leader disabled to have the GPS disabled. And then you could run this Anom on your phone. And so the bad guys were just totally in love with this, because it's everything that they'd want.

[00:26:50] It's a coconut dagger thing. Oh, I've got to get one of these special phones where cellular is turned off. So I can't be tracked by cellular GPS turned off. So I can't be tracked by GPS and run this special Anom software. And they were able to trick the bad guys into recommending this software to their friends.

[00:27:13] Guess what? It was software that the FBI had. They use it as a honeypot and they worked with a global network of different law enforcement agencies and they monitored every message written, every image, video that was sent across the service. So they decided, okay, we're going to do this the swoop now.

[00:27:38] And it's crazy because they knew everything that was going on. And the bad guys thought they had no idea. This is the large scale series of police operations, 16 countries, more than. 800 arrests, the seizure of more than eight tons of cocaine, 22 tons of cannabis and cannabis resin, two tons of synthetic drugs, six tons of synthetic drug precursors, 250 firearms.

[00:28:08] 55 luxury vehicles over $48 million in various worldwide currencies. And cryptocurrencies says zero pole. Wow. Hey, this is amazing led by Australian federal police and the FBI, as well as the Dutch national police and sweetest Swedish police. Absolutely amazing. Hey, you bad guys out there pay attention because the law enforcement may have been behind, but boy, are they catching up?

[00:28:40] They're going to get all of these scoffed laws.

[00:28:42]There are some amazing things, out there that's happening with self-driving cars.

[00:28:47] I am so excited about it. The future holds we're not that many years off considering what is it now? 140 years really since the automobile hit the road. And what's really funny is some of those very. First automobiles were electric. I was looking at some pictures this week of a show where they had all of these old vehicles.

[00:29:12] Like some of them, they called ancient and they initially looked like just a regular carriage minus the horse. And frankly, that's probably what they were a number of these companies are making them use to make carriages. And so they look funny and they had in them batteries. Lead acid batteries.

[00:29:33] So you'd charge these things out. They probably take you a few miles before the batteries ran out. They didn't go very fast. The first one was, I think it was like one in a quarter horsepower on the electric motor that was driving the vehicle. But that is pretty darn cool. Of course. It fell off of favor because it's so much more efficient and effective to just burn more fuel.

[00:29:59] And one of the very first engines ever made was a diesel engine, and they're just amazing technology fast forward to today. And we're going. Back to that. There are some real advantages to electric vehicles. Hey, you're not really reducing anybody's carbon footprint, but what you are doing is having a very clean vehicle going down the highway, that vehicle not considering as manufacturing.

[00:30:25] Not considering that they used coal or natural gas or even wood products to generate that electricity. All of that, aside that car going down the highway, it's nice and quiet. It's pretty darn safe. Tesla broke the testing equipment when they first were being tested for the crash impacts. And they're also.

[00:30:49] Oh, very clean. I don't mind following the electric car, Ryan. I'm not getting all those nasty odors. Did you get from like a Harley? That's been detuned by somebody that fought that allowed motorcycle made them even cooler than they were before. Yeah. Yeah. I have opinions about those types of writers.

[00:31:07] Anyhow. We have a big announcement this week. In fact, two of them from Waymo, Waymo started as Google's self-driving car project back in 2009, and then it was spun off. And that has had some amazing rounds of funding. They had a three and a quarter billion dollar fundraiser in 2020. Isn't that amazing. So that was the first time Waymo had turned to investors beyond Google and the round was over subscribed.

[00:31:43] If you know what that means. And then in other words, it was very popular and there are number of. Big names that really backed what Waymo was doing and were part of that three and a quarter billion dollar fundraising. They include Andreason AutoNation Canada's pension plan, fidelity, Magna Perry, crude Capitol, silver lake T Rowe price and others.

[00:32:09] It was just absolutely amazing. Now that was beyond the five and three quarters. Billion dollars raised from the two weeks journal round. Isn't that? Isn't that something? Just, they just announced this last week that they raised another. Two and a half billion dollars in the second external funding round, the Google's parent company alphabet says that shows investors are patient when it comes to commercializing autonomous technology.

[00:32:40]What is happening with Waymo? Waymo still is using LIDAR, which is phenomenal technology. We've had the LIDAR people on my radio show before where we talked about what the tech was and LIDAR. Now they've. Got it down to the size of a hockey puck, but it's different than what has been used by Tesla.

[00:33:02] Tesla's using cameras, a lot of them on the cars, and then it has to process it, try and figure out what they're seeing. And of course they have to be able to see it or in order to even process it. However, with LIDAR, you do have potentially cameras on the vehicle, but it's using a radar. Basically, and these lasers to have a complete map of everything down to in some cases, millimeters, but most of the time it's centimeters and resolution.

[00:33:34] So the car can see, they can dry everything out. That's on the road. They know that's a pedestrian or a cyclist or a car, et cetera. So it's very cool. And I'm looking at a picture right now. That's in the newsletter this week of. A truck. This is a Waymo truck. It's one of their test vehicles looks like it's a Peterbilt and they have the LIDAR on the truck as well.

[00:34:00] They've got two LIDAR units, typically on a car. You only have a single. I had our unit and they're very expensive to, at least for now, we'll see where this ends up going. So that's all well and good, but what is absolutely going to put the nail in the coffin of many competitors, frankly, at least for these massive amounts of fundraising is the announcement with JB hunt.

[00:34:24] If you've driven on our highways, you have seen trucks and trailers with the JB hunt logo on them. These guys haul cargo and a lot of it here in the United state and Waymo nouns that it's working with this trucking company, JB hunt to autonomously haul cargo loads in Texas. Now they're not completely autonomous.

[00:34:51] We'll get into that in a second, but these are the big Griggs. These are class eight trucks. They're really quick with this whole autonomous driving software and the hardware systems, Waymo calls, there's Waymo driver, and it's going to be running on I 45 in Texas. If don't know where that is.

[00:35:11] They're going to be hauling cargo between Houston and Fort worth. That is going pretty much all the way up the state, at least up to the neck of the state, not including the panhandle of Texas all the way on down, to of course the Gulf coast. That's where Houston is. So the trucks are going to have all of this new software they're going to have.

[00:35:34] Also cameras on them so they can record exactly what's happening. So that's part of the hardware package and they're going to have a train truck driver and Waymo technicians on board. And the idea is they're going to supervise it. They'll probably, log things as they're going, Hey, this didn't happen quite right.

[00:35:55] That didn't happen quite right. And there we'll be sending that information back to Waymo who will be making modified case into the software. So this is going to be an intuitive process, but Waymo has been testing these trucks in the Atlanta area since 2018. So that's phenomenal. And what is really making this week's news now?

[00:36:18] Announcement. Most noticeable is because they now have a partnership with a major truck operator, which is just phenomenal. So here is a statement from Craig Harper. He's the chief sustainability. Officer over at JB hunt. This will be one of the first opportunities for JB hunt to receive data and feedback on customer freight, moved with a class, a tractor operating at this level of autonomy.

[00:36:48] While we believe there will be a need for highly skilled professional drivers. For many years to come. It is important for JB hunt as an industry leader, to be involved in early involved in the development of advanced autonomous technologies and driving systems. I know this is just amazing. This is in an article from arts Technica, because I think JB Hunter's right about this.

[00:37:14] This is the future. Now how long will it be before these various autonomous vehicles are out there driving? How long will the truck drivers be able to have the types of jobs they've had for so long? I don't know, obviously JB hunt doesn't know whey Mo doesn't know, but we're suspecting that the first step here is going to be the long haul portion of the truck's journey is going to be autonomous.

[00:37:45] So you're going to be able to be driving down major freeways here in the us. And there will be truck after truck driving pretty darn close together, which is gonna make it tough for you on a two lane road to to pass them and going between them. Although they will make some space, but they will make our roads much less jammed by traffic because all of these autonomous trucks.

[00:38:12] Are going to move in or whatever the speed limit is. They're going to have minimal spacing between them, which is going to be really good as well. And they're not going to be doing stupid things like pulling out in front of you that causes you to hit the brakes. And when people hit the brakes, it causes the traffic jams, which cause accidents, which cause more traffic jams.

[00:38:33] So they're just going to stay in their lanes. They're going to be going the speed limit and our roads are going to be safer just because of that. But that last mile and that first mile or aware of things in me, different. So you're going to see staging areas, what we have in so many parts of the country where you are carpooling into a big city.

[00:38:55] So the truck will have a regular driver. Who's a short haul driver now and is going to drive that truck up to the staging area. Maybe he'll drop. The load, maybe he'll get out of the truck and take your Uber back to the the next assignment. And then that truck is going to get out on the highway.

[00:39:15] Obviously it needs to be inspected. And so there'll be inspection safety lists, and ultimately that'll be done by robots as well. And then the truck gets on the highway down. It goes. And it gets to its destination area again, the last mile, which might not be a mile, it might be 10, 20, 30 miles. Depends on how dense the population area is.

[00:39:38] And that's one of the interesting things about Houston. There's a lot of people in Houston and also frankly, in Fort worth more in Dallas, but in Fort worth as well. So that driver will then pick up. The truck right there outside Houston and we'll drive at that last mile to deliver their load to wherever it might be.

[00:39:59] This is going to be incredible when it actually happens is going to cut down the costs of driving on the highways. Taking all of our supplies that way, I'm a big fan of rail. I think rail makes a lot of sense, certainly for the route from Fort worth down to Houston. Cause there's already major rail lines, but we subsidized trucking so heavily here in the U S with our roads that I don't know that they'll ever come back.

[00:40:27]

[00:40:27]This whole cyber warfare thing has been really something, frankly, we are in a war and I've said that before it's a cold war.

[00:40:36] Hopefully it will never become a hot war, but we are being attacked like crazy now. We have attacked other people as well in the cyber realm. We certainly attacked Iran along with Israel, the two of us working together, and we've probably been involved in some other things. There's one or two attacks that happened in Russia.

[00:40:59] That were probably us, but we never really took credit for unlike the Uranian attack. We are being attacked by criminals and by government. So it includes governments like North Korea that really are attacking to get hard currency. It is one of the major ways they generate money in North Korea is by attacking either people and then not holding things rant.

[00:41:27] Doing various other things. They get the Sony breach, which was just absolutely amazing. And they hold it over your head. What are we going to do about it though? That's a big question. We all know we're constantly under attack and I'm going to by way of full disclosure here mentioned that I am working on something right along these lines for the small business and home user, but primarily the small business, very small business.

[00:41:55] 10 people or more, but let's talk about what I think the answer is. And of course, I think it's the answer. So that's what I'm going to do. But th these cyber attacks are constant. They're everything from annoying to devastating. I look at the logs on our machines and our clients' machines, and we're seeing hundreds of attacks, sometimes hundreds of attacks a minute.

[00:42:17] It's just insane. And these devastating attacks down. Parts of our infrastructure are really big deal. So what does president Biden do this week? When he's meeting with president Putin, president Biden gives him a list of what we consider to be our critical infrastructure. Yeah. Yeah. He said don't attack these please.

[00:42:41] Now of course, what's he going to do? He's going to attack those because they are a part of the critical infrastructure. Thank you, president Biden for giving me Mr. Putin, president Putin, a list of targets. I should go after. I I think that was just absolutely ridiculous, but he also seems to have been drawing a line in the sand, right?

[00:43:02] This red line. President Obama did that before and he kept shifting the line and president Obama, wasn't the first president to shift the line, but our message to Russia is not clear. There's nothing behind it. And it's bended knee time. And the same, thing's true with China because they're coming after us.

[00:43:21] They know so many of our military secrets look at their latest jets. Look at their ships. They are based on us designs. Engines on them are based on us designed because bottom line, we are not secure. So let's get into this. What have we been using for our cybersecurity? And the answer to that is for decades, what we call.

[00:43:50] A signature analysis. So basically think about the SARS cov two virus SARS. COVID two hit us and hit us fairly hard. No question about it. People died and that's not a good thing, but it did hit us pretty hard. Why did people. Why did we need to have some sort of a shot in order to help protect us from the SARS cov two?

[00:44:18]The answer is we did not have natural immunity. Now you could argue about the shots, right? But we didn't have natural immunity. If you've had a specific virus. The odds are very good that you have T cells, the T cells remember the old viruses that have attacked us in the past, and we can quickly Mount a defense.

[00:44:41] So those T-cells recognize it and say, okay, I know how to deal with this. This is a bad thing. It's got this Corona head on it and it's all. Yeah, this is SARS cov two. So it then starts to generate the right antibodies and off we go. That's what we have been using for decades. Now, these rules based systems, and they've been applied in cybersecurity to detect malware signatures.

[00:45:10] You got a virus. They would look at that virus. They'd find strings inside. No, but the strings could be, that could be a name, that's certainly happened before. It could just be instructions that are part of it, but some sort of a signature. Sometimes you can just check some something and then compare that check some as a signature against known malware that's out there.

[00:45:34] That's what your Norton does. That's what your McAfee does. That's what pretty much all of the antivirus software. Dies. And frankly, that's also what we see happening with our firewalls that we're using and all of the security equipment. It's very basic. Those signatures are designed to look for known insider threat pattern.

[00:46:00] So they look and they say, oh, okay, I've seen this before. I know how to respond to it. I'm going to cut it off. Hopefully that's at the firewall. Most of the time, we're not running next generation firewalls. So the firewall doesn't detect it. It gets onto the network gets onto a computer and hopefully the computer recognizes it.

[00:46:20] But the problem there is the one word known it's looking for known insider threat patterns. That's a real problem because what we're seeing now are unknown threats. The unknown, insider threat, someone who is working for you and is trying to exfiltrate some of your data. Maybe it's a salesperson who's thinking about leaving and wants all your client list.

[00:46:48] Maybe it's an engineer, man. Would have we seen that before? Just ask Tesla or many of these other big companies about it, someone sinking to leaving. So they might as all put a few things in their pocket, besides the pencil on the way out the door. Those are insider threats. How do you recognize them? And I've been working on that for years.

[00:47:09] I had a product that would look at all of the access to a file server, a windows file server, and would try and do some comparisons on it. And you know what, it did a half decent job, but that was years ago. I again, was looking for known patterns. So in other words, how they're pulling out data and they're not supposed to, why is that sales guy into the payroll?

[00:47:34] Those sorts of things. We need to move into AI, artificial intelligence, machine learning, whatever you might want to call it. We're not talking about Skynet here. We're talking about something that's really rather basic, just some form of an AI that looks for patterns. And that's what I'm working on right now at the low end, because we've got some of these, the very high end, but AI has the ability to do some self-love.

[00:48:03] And that's the big deal. They can learn more about malicious activity, about patterns that they're seeing. These insider threat patterns, external threat patterns, and these AI methods now can even learn based on data that could already have the threat activity. In it and it learns from that. And then it is it out to others.

[00:48:28] That's part of the reason we use the high end Cisco stuff for our clients that want real security because it learns, it, figures it out and it shares it with thousands of other of these high end, Cisco firepower firewalls with all of the other software that's in behind. This is a very big deal because AI can synthesize the difference between normal router outages, for instance, or it's a botnet attack.

[00:48:57] It's an attack from a Russian. Who might be trying to do distributed denial of service, which has been way up in the last year. So in, in this cyber cold war, we really have to assume that our defenses have been breached and our adversaries are already in our systems. The great article here, I just quoted that from dark reading, by Nancy Grady.

[00:49:23] She's the chief data scientist and solution architect. But here's the real big. She's a data scientist. That's where it's moving. That's why I'm putting together the software using other people's software. So these, this, for instance, advanced malware protection stuff, information that's coming out of an active directory server and feeding it into an artificial intelligence engine that I have already done some training on, and then have it look for things that I think is where we need to.

[00:49:59] We have to search for unknown patterns of malicious activity. Artificial intelligence really is the arms race. And China has said that by 2030, it will be the world leader in artificial intelligence. Remember Google you've heard of them. Alphabet, which is the parent company to Google decided it would move its artificial intelligence lab to China.

[00:50:22] Thanks, Google for giving away all of our advantage in the AI. Absolutely where we will end up with this cold war. Arms race is having artificial intelligence, trying to defend against artificial intelligence, trying to attack. Now, it's really interesting looking at how AI has been used in other fields.

[00:50:44]And in fact, w they've had AI generating fakes and AI trying to detect the fake. So going back and forth, improving both of them will survive. But right now we have to change our approach and change it in a very big way because our resiliency in our businesses and as individuals, we can't you, this is a costly option anymore.

[00:51:09] We can view this as just a mathematical equation. Hey, it's cheaper to pay the fines than it is to keep our data safe. We have to make it apart in a central part of doing business.

[00:51:22]There are some really interesting bills that are trying to pass through Congress right now that are designed to help protect us. And it's interesting because we're seeing these brick and mortar retailers, including home Depot, Walgreens, JC penny would support these bills versus the online retailers like Amazon.

[00:51:46] At C E eBay Poshmark and others who are arguing that this new legislation is going to hurt small sellers, particularly home sellers, great article from ours, technical by Tim to chant this week. And I've got it in my newsletter. So I'll make sure you double check the news. But these bills have come out now as brick and mortar retailers have lost ground to online retailers through the lockdown in 2020, 20% of consumer retail purchases were made online.

[00:52:22] Compared with 14% in 2019, but the legislation is also being proposed in response to this slew of counterfeit stolen and dangerous items that have shown up on these various online retailer websites. Now we know that there are problems with some of these. For instance, there are all kinds of fake reviews.

[00:52:48] And a while back, I talked about them here on the show, what you can do in order to tell if it's a fake review or not, you can just do a search for Craig Peterson, fake Amazon reviews, and you can listen to that segment that I did. It is usually not that hard to tell, but that's how we're valuing things.

[00:53:10]We go online. We're trying to evaluate most of the time when you're looking to get something you're not looking for all of these things that you want. Yeah. Yeah. Okay. There's that. But you're primarily looking to eliminate things. So you can I'll kill that one. It's not going to work for me. That was not gonna work for him.

[00:53:28] That was my coworker. Okay, good. So I only have this one thing left, so you're not really having to make a decision that when you go to Amazon, people are looking at that rating. How many people have rated it and how high is the rating? And you'll probably read a few of the reviews and Amazon will usually mix in some lower star reviews.

[00:53:52] Just to make it seem a little bit more legitimate, but many of these vendors are doing some frankly unethical things. For instance, they will go and say in your product when they're shipped to you, if you go ahead and give us a review and send us a copy of the review, we will. Shippy another one or the next one we'll give you a discount on or a lot of different things.

[00:54:16] And so people are incentivized to give reviews, which I guess isn't bad, but unfortunately, a lot of people are, have been incentivized to give bad reviews because. Even companies out there that you can hire to have people do reviews. So one of the ways to tell if a review is fake is read some of those reviews.

[00:54:37] Let's say that the review was for some I lash mascara or something. Okay. So it's for mascara and you're reading the reviews and it says yeah, this supports far more weight than I thought it would, or, yeah. Th this has been running really well for me. Do those sound like they're talking about mascara or something out because oftentimes these fake reviews are just generic ones that have they've hired people to go ahead and post them online.

[00:55:08] When we're talking about these bills, though, where we're really worried about is, or who is really the second. If you buy something from Amazon, you may not actually be buying it from Amazon. Amazon's become much more clear lately. If you look at something you can see it's actually shipped from company X or Y whatever it might be.

[00:55:35] And it's not really well, maybe it's shipped by Amazon, but it's provided by company X and the way Amazon's business model generally works is. You have a product that you want Amazon to sell. So you ship a certain amount of that product to Amazon. And usually Amazon dictate how many they want to have on hand.

[00:55:56] And now it's an Amazon's warehouses and that way they can ship it out in a day or two, depending on the product, et cetera, et cetera, they don't want to have unavailable. So that is handy for you, but it's coming in an Amazon box. It's coming from an Amazon web or not website but from an Amazon delivery center and warehouse.

[00:56:21] But if that product is counterfeit, if it hadn't been stolen, if there are dangerous items in it, we've seen that again. And again. I remember I did a television segment. These are cases that people were buying for their phones, the glitter cases, and how the fluid that the glitter was suspended. And, so you can turn it around and the glitter moves around.

[00:56:43] Isn't that cool. That fluid was actually burning people. If it leaked out. That's how bad it was. So who do you Sue? Who do you go after? If you need to recover the damages we get, you had to go and see the dermatologist maybe even had to have a skin graph just because you bought online from Amazon, who seems to be a reputable retailer online.

[00:57:09] And they certainly are just cause you bought a case for you. Many people have found out while it isn't Amazon and Amazon says they have no liability. Now here's the second part of this problem that anonymity. Provides cover for all kinds of fraudsters and criminals. It's really not uncommon to find uncommon, to find counterfeit and potential harmful things on these various online retailer sites.

[00:57:39] Back in 2018, the government accountability office ordered 47 items, including shoes. Travel mugs cosmetics phone charges from third party sellers on quote, popular consumer websites. So of the 47 20 of them were counterfeit. That's almost half that's what? 40% ish. That's crazy. They were counterfeit even non counterfeit items that are bought from these third-party sellers.

[00:58:09] Through these big websites have been implicated in consumer. Again, 2018 and 19 month old in Texas was injured after ingesting a battery that fell out of a loose battery compartment in the third party, apple TV remote. So the parents in that case in Texas, asked Amazon to stop selling this product that was obviously defective and requested the contact information for the seller.

[00:58:36] Somebody named who's EG. Who ran the Amazon store USA shopping 76 93. So that's the guy that actually sold the remode Amazon stock did in the warehouse, shipped it when the people paid Amazon. Hugely. Never responded. And Amazon said that they were never able to locate that person. So the parents sued Amazon in Texas state court, arguing the retailers liable for the dual factor product.

[00:59:07] Amazon. The other hand says, Hey, I'm just a middleman. I have no liability. That's the argument. And that's why we've got these brick and mortar retailers push. Back for changes. So consumer product laws, those, they hold businesses liable for injuries. If the stores don't take the sufficient measures to help keep these defective products from reaching consumers online, marketplaces have not had those types of rules in place.

[00:59:37] And they say we don't control third-party resellers. So we'll see what happens. We have a couple of different groups out there, some fighting against the bill. Some fighting for them. Keep an eye on this. You might want to contact your Congress critter and let them know. How will you feel about this?

[00:59:55] Because it is a problem. Absolutely problematic. No fewer, by the way than 17 states have proposed legislation about this

[01:00:05]let's talk about trick bot and this investigation, because it has now revealed the details of a massive crime organization. And when we think of these I often think of Tony soprano.

[01:00:20] Where you've got this one guy or gal as the head of the whole thing, and it's a mafia organization and you've got your lieutenants and everybody else in place. It's well organized and you know who you can trust and who you can't trust. And you bring in people slowly. That apparently is not how trick bot ran and is narrow.

[01:00:46] As we can tell, not how most of these criminal cyber crime operations actually work. It turned out that nearly a score of cybercriminals. This is from dark reading, allegedly worked together to create this trick bot mouse. And they were able to get it on computers and effected more than a million users.

[01:01:13] Now this is from an indictment that was just unsealed. This group that was behind it. It is fascinating, absolutely fascinating. They were able to infect this million systems in nearly a dozen countries, but how do you do that? Normally you use a zero day attack when we've talked about those before you might also be using an old attack that should be patched already, but people haven't bothered.

[01:01:41] Patching. But that's conceptual. When you get right down to it, you've got to have malware expert. You've got to have software developers, you got to have technical support people. You've got to have your money mules that can take the money and clean it up for you. That's called that's modern money laundering and they've got to have other people involved in all of it.

[01:02:06] And that's what this indictment against one developer said, this guy is a Latvian national, all a witty, I assume it's a guy, but a national from Latvia. And he's charged with being a developer with this group. That's fascinating because the indictment shows this, the sprawling, frankly. Ad hoc organization that expanded its operations to include 20 different people.

[01:02:42] And probably more think about that for a minute. This is not Tony soprano. These groups need to move and move fast. So it looks like what's been happening is someone has a bright idea of let's use the zero day attack and let's go make some. But how you do that because you need all of these people.

[01:03:03] I just described. How do you make it all work for you? Cause the group gave programming problems to potential developers. They discussed, which programmers suited their needs and used a variety of crime services to improve their operations. That's how they work. Can you believe it? It was just absolutely amazing.

[01:03:23] Apparently they could not find enough developers internally. So that's where they went over to Russia and Latvia and some of these other countries to try and find people and they would ask them these kinds of leading questions to see how they felt about being involved in cyber crime. And what's fascinating to me is a lot of these guys obviously had no problem with it.

[01:03:48] Now, some of them might not have known, they might have had a task to do this, make an installer for us, a basic task, or even make this software. Yeah. Easily find it on the computer. Guess what that's exactly what some of this antivirus software does it hides itself so that it makes it harder to find.

[01:04:09] So there's legitimate reasons for all of the different parts of what this malware does. No question about that. This here's a quote from this guy at Malwarebytes, his name's Adam Quad-A. And he's a director of the labs over there, Malwarebytes. He says, there is the group that compiles them out where then they pass it to the group that encrypts a malware, and then they pass it to the person who distributes the malware.

[01:04:40] The fact that these folks were reaching out via Russian job sites for developers means that their operation grew too large for the talent pool of the cyber crime world. Isn't that something. So not only are we having trouble in the U S hiring people, they're having trouble overseas as well. Now the operators of this trick bought malware, had some serious success and they got the attention.

[01:05:10] You, you can't do it. Yeah. In fact, a million computers in a dozen countries and not get attention. And so that us investigators were able to gain access to communications between a lot of the people behind the operation. Does that sound familiar? The FBI and others have been doing that successfully. And we talked earlier in the show about some ways they've been doing that.

[01:05:35] So they had some of these communications, they knew what was happening and they were able to combine the government agencies and industry to crack down on it. Now you've heard me talk about the FBI's InfraGuard program. And I'm a proud member of InfraGuard. I was involved with Intercar. InfraGuard pretty seriously for quite a while.

[01:05:59] I ran all of the webinars, all of the training stuff for a couple of years. And so I know those guys, this is. InfraGuard is about, it's about knowing what's going on out there, knowing what to defend against. It's not just computers, by the way. In fact, it's mostly not computers which annoys me, but it goes everything from terrorists, for physical security, all the way through various healthcare warnings and things that are going on to protect every part of our infrastructure, even lawyers are allowed to get into this law firms.

[01:06:34] Okay. But the whole idea behind InfraGuard is to get the government and industry working together. It's been around a long time. And I only found out about it myself within the last, I don't know, five or 10 years, but combined the government and industry were able to take down this malware group in October.

[01:06:57] This is absolutely amazing because the operators were able to recover really quickly as well. So there's this indictment a little bit redacted, so we don't know all of the details, but because they have. Access communications. They started to put the screws down on a couple of these people who were involved and the, by the way, two of these participants were talking about using a server based in the United States as a way to hide where they're coming from.

[01:07:29] And I've talked about that before, how they can hop from machine to machine and make it look like it's coming from someplace. It's not, which makes me wonder about some of this Russian invasion as whether or not it's really from Russia or perhaps it's from China, just pretending. To be Russian isn't that America just amazing.

[01:07:48] One of these guys in their email said, they should say, thank you to us that we are stealing money from the Americans. We should get the medal of valor, just chest. Absolutely incredible. These people, I, we got to understand what I think what they're doing in order to really be able to. Frankly.

[01:08:10] Okay. My by the way, it looks like we were able to recover money from these trick, bought guys so much for cryptocurrencies being absolutely safe for the bad guys.

[01:08:21]Again, I really appreciate you guys. And take a minute. If you would visit me online, Craig peterson.com.

[01:08:28] You'll find all of my newsletters. Not the newsletters, but all of our podcasts, everything we're doing every week up there, the newsletters, however, you will find the way to sign up there. And once you're signed up for the newsletter, I'll send you a few of my special report. You learn about passwords.

[01:08:46] Password managers the right way to handle it and which ones are available, which ones I recommend and a whole lot more. Plus you'll get my newsletter in email every week. I don't usually post them up on the website. Maybe I should. Anyhow, this is a story from Fox business. Daniella is Jenna surveys, Genevieve.

[01:09:07] Genevieve's yeah, there you go. It's probably hard to pronounce in English. This is really scary. Because it's showing that the private login information belonging to tens of millions of people was compromised after malware infiltrated over 3.2 million windows based computers during a two year span.

[01:09:34] Are you kidding? 3.2 million Windows-based computers over two years span. What are people doing with their windows computers? Or maybe the better question is what are they not doing with their windows computers? Or they're not applying the patches what's going on here? How can you have something like that happen?

[01:09:56] That should never happen. But it did. So there's a report out by Nord lock. That a custom Trojan type malware infiltrated the computers between 2018 and 2020 and stole 1.2 terabyte of personal information. So as a result, these hackers were able to get their hands on nearly 26 million log-in credentials, including emails, usernames, and passwords from almost a million websites, according to this absolutely crazy, isn't it?

[01:10:36] So the targeted websites include major companies like Amazon, Walmart, eBay, Facebook, Twitter, apple, Dropbox, and LinkedIn. You've heard of all of them. This is why I really stress everybody. You need to go to have I been poned.com. This is a free website. Have I been poned spelled P w N E D. Have I been poned.com.

[01:11:02] Check your email address. Now you can even put in your phone number and see if your personal information has been stolen. Now, if you've had an email address for any period of time, and if you've used it in the online world, I can pretty much guarantee it is out there. So double check, because what that's going to do now is let you know which passwords you're going to have to change.

[01:11:31] So if you had a user account at a site that was hacked and they did steal your personal information, obviously you can't get a new social security number. They will not give you one, but you can change your password because so many of these breaches nowadays are using brute force technique. So they'll look up these massive databases of all of the stolen credentials.

[01:11:57] And then they will try these email addresses along with the stolen passwords to see if they can get in. Okay. Now here's the software. This is particularly interesting. Many of us say I use, I'm not going to really say it. I use a windows cracking tool. Or, oh yeah, I don't have to pay for the Adobe software because I've got this cracking tool and yeah.

[01:12:23] Same thing with these games I'm playing. Yeah. They're all cracked. Okay. Guess what? That illegal well software, which included a pirated version of Adobe Photoshop, 2018 there's windows cracking tool and several cracked games had within it. This malware. So in order to steal the personal information, this malware was reported is reported to be able to take screenshots of a person's information and also their photograph.

[01:12:54] Okay. If the device had a webcam and among the stolen database, where two brilliant, 2 billion browser cookies and 6.6 million files. Now with those browser cookies that they've stolen, they can. Effectively log into websites because a lot of websites will set a cookie saying, yeah, this is a legitimate session.

[01:13:18] So all they have to do is use that cookie it's that easy, it's that easy. And so 2 billion browser cookies, 6.6 million files, including a million images. I wonder what some of those images were and more than 650,000 word and PDF files. All right. So even if they don't try and use the cookies to log into a website, they can use them to figure out the habits of people because the cookies are associated with a particular URL.

[01:13:48] So they know where you go online. They know that you use bank of America or whatever bank it is you're using. And now they can use that for fishing. Okay, this is just crazy. Don't use pirated slash cracked software. It's bad enough to use it software. Okay. Making up the bulk of the stolen database got into Fox business was 3 million text files, 900,000 image files and 600,000 plus word files.

[01:14:23] Some people, by the way, this is a, I just had a question about it this week from a listener saying, Hey, listen. And I put all of my password and then encrypted Excel spreadsheet. Is that okay? According to node or Nord locker, they said that the most concerning thing was that they found people even use notepad to keep their passwords personal notes and other sensitive information.

[01:14:49] So when we're talking. 3 million text files. Some of those text files had people's social security, numbers, names, bank, account numbers, passwords, everything. And I know some of you guys are saying, yeah, that's me. Maybe I'm like my man, I'm in trouble now. Yeah, you are sign up for my newsletter.

[01:15:10] Now, and I'm going to send you this report. It's about 10 pages long. It goes through some details you can skim over and also tells you what I recommend and how to. Okay, so you got to do it. Craig peterson.com. That's Peterson, S O n.com. And you'll see right there on any page. In fact, if you scroll up or down a bit, you'll see a sign up for my newsletter, or you can go straight to Greg peterson.com/subscribe and also.

[01:15:43] Make sure you go to have a been poned.com. That's have I been B E N P w N E d.com. Now, if you missed any of that, you can just email me@craigpeterson.com. That might be easier to remember. And remember, my wife had a horrible accident and my emergency surgery, and so I'm helping to take care of her so much.

[01:16:08] Normal a little bit delayed responses have been very delayed for about the last month and probably will be for another month or so. So keep that in mind, but you can email me emmy@craigpeterson.com and ask me any questions that you might have be glad to answer. And give you those URLs as well, but just go to Craig peterson.com, sign up for the newsletter.

[01:16:30] And then when you get the newsletter, you can just hit reply and it will go to me. So you can always ask a question that way to Craig peterson.com/subscribe. Now we're going to finish the show off with something else that is eyeopening. It was eye opening to me. It's gotta be to you too. This is again from dark reading.

[01:16:52] This is a new study by Symantec and they found in looking at iOS and Android apps that were released on apple and Google's app stores over the last five years that many of these apps are breaking. The protections that Google and apple have specified specifically breaking the encryption protection. If you go to a website like HDP ads, You by just doing HTTPS colon slash Craig peterson.com for instance.

[01:17:32]So going to my website, HTTPS colon slash Craig peterson.com. Do you realize that you have now set up a VPN between your computer and my cell? Yeah, you don't need a VPN from one of these companies out there, which is actually going to make you less safe. You don't need any of that at all.

[01:17:49] It's going to go all of your traffic's going to be encrypted back and forth. And the mobile apps are supposed to use the same type of encryption whenever they need to talk to a database or talk to one, one of those sources that the app might need, that's out there on the web. And it turns out as they were looking at this un-encrypted traffic coming to, and from these apps that it's transferring sensitive data that is completely open to interception and compromised by attackers.

[01:18:24] Now I know some of you guys just saying I would listen to the ad for the VPN software and it says it's keeping my data. Probably nine. So I'm safe. Even if the app is sending it in the clear, no, you're not. In fact, you are less safe. And if I did a webinar on this about a year ago, if you want a copy of it, I'll be glad to drop one to your links.

[01:18:49] You can watch it, but it was like an hour long just explaining what's happening and why and how and when it's appropriate to use a VPN, none of these commercial VPNs, the G here advertise really, you shouldn't be using those. So there's other things you should be doing. Symantec reasoning recently analyzed hundreds of thousands of these things, and it showed that 7% of iOS apps and three and a half percent of Android apps intentionally break in the encryption requirements from the app store.

[01:19:27] It's absolutely incredible. We'll see what happens in the future. Apple is cracking down right now. More and more. Google has been doing some crackdowns as well, but apple has a tighter infrastructure. They can lock down a little better than Google can. All right, everybody. That's it for today.

[01:19:48] Thanks for listening. Thanks for tuning in. Of course, you can find me online. Craig Peterson.com. Make sure you sign up for the newsletter. You'll get some free, special reports along with that. And if you have any questions, email me me@craigpeterson.com.

View Details

[As heard on WGAN on 2021-06-16-wgan]

Did you notice on your IRS tax forum this year? The very first question. Yes. The government is starting to crack down on cryptocurrency transactions. We just found out about what the FBI did. There's a whole lot there. And then also this morning, Tesla versus Volkswagen, completely different ideas and methodologies for your next autonomous and even electric car. How might things turn out for us? So here we go.

[00:00:35] Aaron Chadborn: [00:00:35] This is Aaron Chadbourne in for Matt on the WGAN morning news, and we are excited to be joined now as we are every week by Craig Peterson. Craig. Good morning.

[00:00:45] Craig Peterson: [00:00:45] Hey, good morning.

[00:00:45] Aaron Chadborn: [00:00:45] Sure. So with Biden meeting with Putin, obviously we've been dealing with the Russian hackers.

[00:00:51]One thing that I've always understood about cryptocurrency and why it's become so popular is because these payments are untraceable. And we've seen that these ransomware attacks they've asked for payment in Bitcoin, but now they're turning up and investigations with the announcement by the FBI that they've reclaimed the cryptocurrency that was paid.

[00:01:10] What's going on, Craig.

[00:01:11] Craig Peterson: [00:01:11] Yeah, this is a very interesting problem because initially Bitcoin value came because of a bunch of illegal maneuvers. These guys were trading Bitcoin back and forth to each other and would pay a little bit more every time. They were pulling money from the same pot, manipulating the value of bitcoin to try and get it to be worth something right? When you're paying thousands of Bitcoin for a pizza, it tells you something. So next up, what we had is the next major momentum for Bitcoin was ransomware. In fact, if you look at the value of Bitcoin and compare it to the amount of ransomware that's out there and how much people are paying in ransom, they go hand in hand because of what you just said, Aaron.

[00:02:02] People look at it and think, oh wow, it's "crypto" currency, it cannot be traced. Now I've sat in briefings with the secret service, where they went through exactly how they trace Bitcoin. And this time with the whole colonial pipeline hack, the FBI has actually come out and told us how they have tracked it.

[00:02:25] Bitcoin is moderately anonymous. It's like cash, frankly. It can be traced. It was traced. The Bitcoin from the colonial pipeline hack was found in California of all places. And the, these guys are not safe. So as soon as the FBI announced that they had gotten back more than half of what colonial pipeline had paid, the value of Bitcoin dropped, but then Bitcoin went back up again. Why?

[00:02:56] While the meat packing company that we've all heard about getting hacked and maybe losing our meat, we had a little bit of a rush. They paid $11 million Bitcoin, and we have businesses now who are putting in their public filings with the securities and exchange commissions indications.

[00:03:15] In fact, the absolute declaration. They have been buying Bitcoin in case they get hacked. There's a counter for, oh my gosh. Who got hack. Okay. We've already got the Bitcoin. All of this drives up the price and it is not secure in that you don't really know. Who has it forget about it? They can track it depending right there.

[00:03:39] There's some dependencies here

[00:03:41] Aaron Chadborn: [00:03:41] I wondered, though weather. There was this drop, obviously because it, the mystique and the idea that it couldn't be traced, but part of the hesitancy. Of, reputable finance authorities to, to acknowledge Bitcoin and say that they're going to accept cryptocurrencies was this idea that it could be used for these purposes, but this idea that it is traceable, maybe it speeds up the broader scale adoption of cryptocurrency.

[00:04:00]Craig Peterson: [00:04:00] It might absolutely. It has no inherent value. It's just the value people place on it, but you know what. I just described our U S currency. You can turn it in for silver anymore. You certainly can't do it. And for gold anymore, the value in it is what we place in it. And the whole idea behind cryptocurrency and the way the blockchain works behind it is to build trust in it.

[00:04:24] We trust it. We know about it. Governments are taxing it. In fact, this year, first question on your IRS. Forum was about Bitcoin, frankly. And have you had any of these transactions? The government is now going after all of these trading institutions that are dealing in it. And now these institutions are providing the IRS with information about any transactions, more than $10,000, in cryptocurrencies, not just Bitcoin, but any of them. So they are cracking down. China sees this as a huge opportunity and has been pushing their own cryptocurrency and they've been pushing it very hard. To become the international standard in trade of oil instead of the us dollar. So we're going to get something you saw on Facebook.

[00:05:13] They were going to do their own thing with a cryptocurrency that kind of fell by the wayside. Other companies have as well, but it is something that desktops and governments worldwide really want to do because it makes everything entirely traceable allows them to print money. Like that just by adding a little bit more into their crypto pipeline,

[00:05:35] Aaron Chadborn: [00:05:35] you're listening to the WGA and morning news.

[00:05:38] This is Aaron infer, Matt chatting with Craig Peterson, who you can catch every Saturday from one to three right here on WGAN Craig, another topic I know you wanted to dive into, has to do with. Automakers trying to figure out these advanced features for autonomous driving, how they can capitalize office and whether they can charge kind of software as a service type payments.

[00:05:57] What are you seeing with this announcement from Volkswagen?

[00:06:00] Craig Peterson: [00:06:00] Yeah, this is an interesting one because many people know about Tesla. There are other electric cars out there and there are regular. Cars, let go. A Cadillac did a few years ago with their high-end cars driving down the freeway.

[00:06:14] Basically it was a cruise control using radar to keep the proper distance Virginia and the cars in front of you. There was a lot of them out there and Tesla charges you for the autonomous driving. They said that from the beginning an extra fee. Do you want that feed? Do you want to pay for the Tesla?

[00:06:34] And that's what Volkswagen has been trying to figure out. And they just had a board meeting and the board they were discussing. Do we want to have a $50,000 of. Bill or check out underneath the hood of the car, if you will for features people don't want. And so they're saying instead of having this this new plaid version of the Tesla model S which is totally cool, by the way, at 120 grand, what should we do?

[00:07:01] Because we're the people's car. Volkswagen's looking at putting all of the features into their new cars, all these auto driving features and the fancy cruise controls and things, and then having a golden key. They're all there, but you can't use them until you pay for them, but they're taking an even different tact than Tesla is using.

[00:07:22] They're saying. How about if we charge by the hour for the fees, if you're driving your car around town, you're not going to be using the autonomous mode. It just doesn't work yet. Some estimates are it's going to be 20 years before it's entirely reliable around town, but when you're on the highway, Would you pay $8 and 50 cents per hour to have the car drive you somewhere?

[00:07:48] It's like an

[00:07:48] Aaron Chadborn: [00:07:48] Uber driver, right? Do you value your automatic driver at the same way? You would an Uber driver?

[00:07:53] Craig Peterson: [00:07:53] Exactly. You're right on

[00:07:55] Aaron Chadborn: [00:07:55] Aaron Craig. If our listeners want to hear more, they can catch you every Saturday. One to three right here on WGAN for a tech talk. This is Aaron Chad. We're on for Matt on the WGAN morning news.

View Details

[As heard on WTAG, WHYN, WHJJ 2021-06-15]

Hey, we've got this meeting between Presidents Biden and Putin, and I have some serious words for our President. I've got some opinions about our federal bureaucracy when it comes to cybersecurity and Mr. Jim Polito pulled them out of me this morning.

[00:00:18] Jim Polito: [00:00:18] So here we go. Hey, every week on Tuesday, we have the honor of my next guest.

[00:00:26] And he is the tech talk guru, as far as I'm concerned, Craig Peterson an all around great guy here, just in time, Craig to save Joe Biden, you're going to be the advisor to Joe Biden. How do you like that?

[00:00:44] Craig Peterson: [00:00:44] I already have a good job. I don't want to work.

[00:00:48] Jim Polito: [00:00:48] Listen. I know that Canada day is just two weeks away and you're preparing, you're stocking up on Molson and Labatt's and moose head.

[00:00:57] I know you're stocking up on all of that, and I know you've got a lot going on, but you could give Joe Biden some advice. He's going to sit across. And look into the eyes of Latta mere Putin. And as far as I'm concerned, Vladimir Putin knows exactly what the cyber hackers in his country are doing. So what does Joe Biden say to the man who's at the top of the cyber hacking, uh, pyramid.

[00:01:33] Craig Peterson: [00:01:33] By the way I am sending out an email today, I put together a little video training for everyone. Who's on my email list on how to stop these Russian hackers. It's 95%. Effective. Okay. But the here's the advice I would give him. First of all, he needs to pull back what he said to the bladder, because just a couple of days ago where president Putin came out and said, Hey, listen, you know, we'd be more than glad to extradite these people to the U S you just need to extradite terminals back to Russia as well.

[00:02:06] And Joe Biden seems to have given us tacit approval for that. The reason I say that is if you look at what we've done here in the us, We have indicted Chinese military officials for hacking into our computer systems. So when you hear president Putin say things like that, you are sure he has in the back of his mind.

[00:02:31] The same thing that we did, which is I'm going to ask you to extradite your military hackers, because we do have them, every branch of service had Packers. Absolutely. So I think what the president Biden should do when he's talking with gluten is say, Hey, listen, I'm going to reopen the Keystone pipeline over all the guy who was doing it says I've given up now.

[00:02:58] It's ridiculous. And I am going to continue to put pressure on Merkel and others to not allow oil. From Russia into their countries because it is war. We are at war we can continue or continue to just capitulate to these people. No,

[00:03:17] Jim Polito: [00:03:17] we're talking with Craig Peterson, a tech talk guru. And, um, while I said it in a joking way, I knew he would take it seriously.

[00:03:24] Yeah. Um, This trade of, I, I brought it up earlier, a trade of prisoners. I mean, Biden is running circles around him by, by bringing

[00:03:35] Craig Peterson: [00:03:35] that up. Yeah. Putin has really, really out of played a president Biden. It's very, very unfortunate. And when you look at a war, for instance, there's skirmishes, you have battles here and there and.

[00:03:51] People die. You are really trying to hurt the economy. Uh, I, I hate to say it, but that's why you shoot someone with a small caliber weapon. You want to wound the, the opponent so that they now have to have three to five people behind the lines to get that opponent back to help that soldier. Well, what happens here in the us, we lost, we were colonial pipeline for a week and say, goodness, near in the Northeast, we didn't really feel it because we had just, I mean, just had all of our tanks filled up by colonial.

[00:04:28] Down in New Jersey. Cause the way they do it, as they staged deliveries, the south didn't do that. So how much did they hurt us and our economy by doing that? I would say they heard us more than many of the skirmishes we've had over the years. Not in depth in lives loss, which of course is just completely incalculable, but certainly the damaged door.

[00:04:53] Yeah.

[00:04:54] Jim Polito: [00:04:54] I mean, it's been, it's been terrible. And so you see the thing is that, you know, and I know I'm asking you to step out of the tactical world into the world of international diplomacy, but you've got a guy sitting there who you and I both know has. Control over these individuals who Putin wanted them to stop.

[00:05:17] He could make them disappear, like, like, like that could make them disappear. So how do you, how do we just quietly? Behind the scenes continue to strengthen our offensive abilities as cyber attackers, and that we encourage all of our private industry to harden themselves to cyber attacks.

[00:05:46] Craig Peterson: [00:05:46] All right, here we go.

[00:05:48] Hopefully you're still sitting down Jaya.

[00:05:54] Here's the, here's the really big issue as I see it, I strongly suspect cause I've been watching what our government does and you know, I have a little bit of an insight track, not my battle. And that, that helps me to understand a little bit about what's going on. Is he, if the Biden administration can continue to literally approve of some of these hacks, let's just play this game through a little bit, a war games.

[00:06:26] If we are all worried that we're going to be attacked. And we're not seeing the software that does not protect you. People like, you know, the McAfee and the Norton antivirus, et cetera. It's not going to protect you enough. We've got Microsoft conditioned us now to the point where we don't want to install up.

[00:06:49] Because it's finished mess up her computer and we're going to be down for a week or two or three or four while we try and figure it out. Right. So if they can get us to the point where we're saying, this is a huge problem, and we've already been conditioned that if it's a big problem, it must be a federal government problem.

[00:07:07] Because it's a big problem. Yeah. So now we need this federal government to step in and take over all of our networks, take over all of our security monitor. Exactly what's going on because here's what I do. I write these, you know, I do cybersecurity and I am tied in with Cisco. That's, who we use. They are the best out there for so many things.

[00:07:31] And Cisco's looking at almost a trillion. Transactions a day. We're talking about emails, website visits, et cetera, et cetera. And the reason they're so effective is because they can take all of this data that they're gathering from their customers. Now, Cisco doesn't send any of your data, just sends what are called check sums up, but it's looking at what's going on across all of these networks.

[00:07:56] And it says, okay, Here's what's up right now. And it immediately tells all of the equipment, the Cisco equipment all over the country. Okay. Block this. Now, if you have the right system come in and it's blocked. So what would happen is if we get to the point where we're on bended knee and, and asking you, please president Biden protect us and they now decide, okay, well, we're going to propose.

[00:08:20] Correct. You quote unquote, they're going to have to provide robes that live on our computers, Jim, that computer there in your studio, the computer that's in front of everyone out there right now, even people listening on the iHeart radio app or whatever app or whatever website, those mobile devices are going to have federal government software on them.

[00:08:44] Wow. Where do you think that leaves us?

[00:08:48] Jim Polito: [00:08:48] Yeah, it leads us to more vulnerability.

[00:08:53] Craig Peterson: [00:08:53] More vulnerability. Yes, exactly. From maybe, maybe you trust president and Biden, but how about the next administration or the next illustration? Right. It's win, win. And I hate to bring up the national socialists in Germany, but when the national socialists took over, there were already lists of people who would have been prepared by the prior government that had guns that could defend themselves that were trained and they were rounded up.

[00:09:19] First, right? Yep. So the officials put into place. It makes it, so now we have a potential real big problem. So let's look at what's happened with China and Russia when it comes to very valuable information. For instance, wouldn't you, if you were a foreign adversary like China, what didn't you love to have all of the information from all of the background checks of every federal employee.

[00:09:46] Wouldn't you love to know who works for who, where they are, their family situation, everything, uh, China stole it from us already. Yeah, they have it. Okay. And, and that's the sort of thing that the bad guys go for. So if we don't pull up our socks ourselves, yeah. It's not going to change. So let's look at colonial.

[00:10:09] How long you were paid, how much ransom

[00:10:11] Jim Polito: [00:10:11] was it? 5 million, I think where you're talking about in Bitcoin. Yeah,

[00:10:16] Craig Peterson: [00:10:16] absolutely. It was like a four and a half give or take $5 million. Absolutely. Right. Yeah. And the meat Packers, you know, they paid about 11 million. Yeah. I read

[00:10:25] Jim Polito: [00:10:25] that. I read that. Yup. And which is, as you have said, that's the worst thing you can do cause you just painted a, a, um, a bullseye

[00:10:35] Craig Peterson: [00:10:35] on your back.

[00:10:36] And the Trump administration said, you pay ransoms, you are supporting terrorism, and we're going to come after you with the justice department. The byte administration says

[00:10:48] what's 5 million. Yeah. Look at an equation that of that of a perverted person would have in their heads. Uh, the equation is okay. So cost colonial, let's say $5 million plus obviously time and materials to get everything back in order. So that's call it 10 million. Okay. Uh, and if they were to put. The proper stuff in place.

[00:11:13] I'm not just talking about hardware and software for cybersecurity. I'm talking about the people to monitor, keep it up to date, keep the desktop up to et cetera. It would cost them easily, 20 to $30 million a year, cheaper to pay a ransom, keep your fingers crossed or to do cybersecurity properly. That's the same equation, the same equation we're seeing again and again, and again, look at the Equifax breach.

[00:11:44] Look at TJX to all of these big breaches in every one of them. There's been fingers pointed at C-level bean counters that said, well, it's just, it's cheaper. To pay the price when we're hacked the not to. And at the same time, we, as a people, our information is being stolen. We're being cheated. Our retirements are being stolen and we're seeing this.

[00:12:07] We've seen operating accounts and small businesses completely emptied, and we are starting to beg the federal government. To come in and fix this. This is a real problem. So I think Biden should tell Putin to take a hike a long one off a short pier and make sure he realizes we're taking this very seriously and do what the federal government was instituted for, which has helped to ensure our common defense.

[00:12:44] Jim Polito: [00:12:44] I just was waiting for the perfect moment. I think it's perfect. I think what you said today is spot on. And of course this will be podcasted because I hope that somebody. From the administration here is, it says you should listen to what Craig Peterson said on the Jim Polito show. And, um, you're absolutely right.

[00:13:07] It has to be done. And, uh, Craig, I know you said you're getting out that information about how to protect yourself from a Russian hack, which involves that virtual Russian keyboard. So how can folks get more information from Craig

[00:13:22] Craig Peterson: [00:13:22] Peterson? All right. If you sign up before this afternoon, they'll set up by noon today.

[00:13:28] Right now, go to Craig peterson.com/subscribe. Craig peterson.com/subscribe. I'm planning on sending it out when probably early the afternoon today. And it tells you exactly what you need to do and shows you how to do it for installing that keyboard. That's going to keep these Russian hackers out 99% of the time.

[00:13:51] And of course I have my weekly newsletter and everything else too, but this is critical.

[00:13:56] Jim Polito: [00:13:56] Right, right. Craig, excellent segment as usual. And I know you'll be watching the next 24 hours and maybe we'll be talking about this again next week or sooner. Great. Thank you, Craig. Craig Peterson. Everybody was a great asset to the show.

View Details

There is a simple way to stop most Russian Ransomware. I'm going to show you why it works and how to do it.

Ransomware is a bigger problem than we've seen in years. We're talking about triple the number of ransomware payouts this last year. And the cost of ransomware has doubled when we include what's your pain, as well as the loss of business. And the loss of reputation. It is absolutely huge, but you know what?

There is a quick and easy trick that I'm going to show you right now that will stop most of the ransomware. Hey, we know the ransomware's primarily coming from Russia. China has obviously some attempts to get into our networks. We've seen that before personally, but Russia is really the source of much of this ransomware.

And what's happening with the Russian ransomware is these guys just don't want to go to jail. They don't want to go to jail. So they don't attack any Russian countries or any of the affiliates to the Russian countries in order to do that, they have to make sure that when that ransomware gets onto your machine, there is no way for that ransomware to.

In fact of the machine, if you're in Russia, because they don't want to end up in Russian jails, but it's not just Russia. It's the OIC, it's all of these countries that used to be part of the Soviet union. So the quick and easy trick that they're using in order to keep themselves out of Russian prisons is to check to see if there is a keyboard that support Russian or any of these other.

Oh, I see. Languages. We're just going to stick with Russian. Cause that's the simplest. If you look right now on your screen, you'll see how you can do this. With windows and windows 10. So you're going to want to bring up your settings. You can see I've got them pulled up here on the screen. You're going to just select region and language, which is right under date and time.

And now you're going to look at the right side of that screen because what we want to do now is select a language. We're going to add a new language you can see on here. I've already got a U S English and Canadian English. Yes. There is a difference. And what you're going to do now is click on, add a language and you're going to select the language from any of these countries.

So it could be Bela Reuss. It could be obviously Russia. There could be Estonia Armenia. You need to have one of these languages on there. Now you might already have Spanish for instance, installed on your computer. That might mean, you know how to do it already, but just go right here. You're going to go ahead once you're there.

And select the Bosnian Serbian Azerbaijani. I would select Russian just because it's the simplest. What will happen now is if this Russian malware gets over onto your computer, the first thing it does is check. Is there, uh, an OAC keyboard? And is there a Russian, are there any of these other languages, if there is.

It immediately exits and it does not install the ransomware at all. Talk it about a cheap and easy to do, do this. And you're safe from probably 90% of all, all of that malware that's out there. Certainly almost all of the Russian malware. To find out more, just visit me online Craig peterson.com. And if you subscribe to my newsletter there, you'll be able to get my weekly newsletter that has all kinds of tips and tricks.

And what's in the news this week. Again, Craig peterson.com/subscribe. Thanks for being with me. Bye. Bye .

View Details

[As Heard On WGIR WQSO WKXL on 2021-06-14]

Hey, we just found out that Bitcoin is very traceable. So I talked about that this morning, as well as what's happening with autonomous vehicles -- big announcement from Waymo and JB Hunt with Mr. Chris, Ryan, just this morning. Here we go.

[00:00:16] Chris Ryan: [00:00:16] Joining us right now is Craig Peterson. He is the host of tech talk on news radio,610 and 96.7, 11:30 on Saturday and Sundays.

[00:00:27] Craig, how are you?

[00:00:28] Craig Peterson: [00:00:28] Hey, I am doing great this morning.

[00:00:30] Chris Ryan: [00:00:30] So we've been teasing Bitcoin with your appearance today. And one of the major attractions to Bitcoin was that it was viewed by many as being untraceable, right? You couldn't tell where the money went. And it was used to as a method of payment that was not traceable by governments, not traceable by individuals or entities, but.

[00:00:52] In the reporting that we saw on the colonial pipeline hacking Bitcoin was traceable. And a lot of that money, millions of dollars in fact, was retrieved from dark side. So how was it traced by the FBI? And is this something that signals to you that Bitcoin is in fact traceable and will be traced moving forward?

[00:01:17] Craig Peterson: [00:01:17] I had a really interesting briefing that was given by the secret service. And this was a couple of years ago and they talked about how they went ahead and did trace Bitcoin. So we've been able to do it for a while. It's been a little difficult, but we've been working on it. What really surprised me this.

[00:01:36] Time is the FBI has come out and given some serious detail on exactly what they did in order to track this Bitcoin. And in fact, a Bitcoin, wasn't a wallet in California. Not some foreign country and it's just fascinating to look at all the details, but yes, these cryptocurrencies are not completely untraceable.

[00:02:04] If you want to use the money that's in your wallet, then you have a problem because the basic concept behind it and the technology behind it is something called blockchain. And these blockchains require basically a ledger. It's like just like a book. He would have a ledger of all of the monies that he's owed or perhaps that he owes to somebody else that ledger isn't just in that piece, safe, hidden, underground somewhere when it comes to Bitcoin, that ledger is everywhere.

[00:02:34] There are multiple like a hundreds of copies of it. And that is how you can validate Bitcoin itself. You have to have this ledger. It has to be in a lot of hands. And now the FBI has figured out some very clever ways to reverse engineer that ledger to find out where the money is.

[00:02:55] Chris Ryan: [00:02:55] Another couple of things.

[00:02:56] I want to talk a little bit about self-driving trucks and self-driving cars. And, one of the main reasons that in my view, the technology has existed that self-driving cars and trucks have not been overly utilized to this point is that there is a fear that they're not going to be 100% effective.

[00:03:18] In other words, one may crash. And if one crash is particularly at the beginning and causes a problem, then that's going to create a ripple effect afterwards. And we're starting to see self-driving trucks. In fact, there's going to be a self-driving car. A truck we're going to be hauling loads in Texas D company J B hunt has announced that they're gonna be working with Waymo and they're going to have a driverless truck, which is going to operate on I 45 in Texas, taking cargo between Houston and Fort worth trucks is still going to have.

[00:03:52] Humans onboard a truck driver as well as technicians. So this in my view is the precursor to the future. And we're going to see driverless vehicles, which will still have the driver in it, but it's going to basically operate like a plane would where you can put the plane on autopilot. Cars will be put on.

[00:04:13] Autopilot, but we're going to have a individual who is going to be there. The driver's gonna be encouraged not to go to sleep, et cetera, but they are going to be able to do quote unquote distracted driving and have the vehicle, on autopilot and even think about the technology that exists.

[00:04:28] Today, just in terms of the cameras that allow for you to back up into the, a particular space or the sensors that let you know that there's a vehicle to your left or to your right, the technology exists within the vehicle for this to take place. Right now, the concern has always been. Would it be, 100% factive and would there be problems with the cameras?

[00:04:52] What if you lose your GPS signal? And the vehicle, it is in a state where it can no longer be driven and there's connectivity problems. But to me, we're there and this is an interesting experiment.

[00:05:03] Craig Peterson: [00:05:03] It's really interesting. And these autonomous vehicles have already driven millions of miles.

[00:05:10] So this is what we've always predicted to be the first step towards having really fully autonomous vehicles for all of us staff. Of course, we've got Elon Musk out there promising that. They're going to have fully autonomous. You can just have a nap, hypotonic Amos for his Tesla vehicles by the end of the year.

[00:05:29] And then the, his main technology guy poo-pooed it pretty quickly and pushed it out a couple of years with this, that the trucks and tying it all together, going between Houston Fort worth, which has quite a ways to go. We're seeing the very first industry that's likely to be completely automated.

[00:05:50] Now, Waymo, we know you've heard about this before has been operating a taxi service just outside of Phoenix. You might remember the car accident that happened, and the lady that was killed by one of these autonomous vehicles with a human driver behind it. But what we're looking at now is going to be phenomenal.

[00:06:10] This is pretty much a straight road. If there's any road in the U S it's a road between those two cities, Houston Fort worth and Texas. That is a great one to try. We're thinking that we will be seeing a long haul trucks. Driving themselves, except for the last mile, of course, being the tougher part.

[00:06:31] In other words, they would go to just like you might commute to Boston. For instance, they would go to a community area. They parked themselves, a local driver would get in and start driving. But this is huge and is completely different than for instance, what Volks and is predicting or hoping might happen do with the autonomous vehicles.

[00:06:53] Chris Ryan: [00:06:53] Craig. Thank you so much. All right. Take care. Craig Peterson joining us here on New Hampshire today.

View Details

A Whole Class of "Free" Apps Found Exposing You -- and Our Nuclear Secrets

As heard on 2021-06-09 on WGAN

Using some of these free apps can be a very bad way to try and keep your information private. So much of it ends up out on the internet where anyone can get their hands on it. And that's what we just found now about the military. Again. Now we've got nuclear secrets out. There. And apparently some of them have been out there now for almost a decade, just because some people were trying to use a free app to memorize things.

[00:00:29]I got into that this morning with Mr. Matt,

[00:00:31] Matt Gagnon: [00:00:31] 7:36 on WGAN morning news on Wednesday morning. Thanks for listening friends. It's time to talk to Craig Peterson who joins us at this time every week. And. You can always hear him on Saturdays at one o'clock for his own show on this ferry station, where he talks about these topics in more depth of detail.

[00:00:48] Craig, how are you this morning?

[00:00:49]Craig Peterson: [00:00:49] I am doing great. Matt,

[00:00:51] Matt Gagnon: [00:00:51] Craig, explain something to me please. On Monday, I was sitting here doing my job, trying to read the news. Going around the internet. And I came across a couple of things I wanted to read, clicked on them. CNN article MSNBC, article a few others. And I got this error message.

[00:01:10] I'm sorry, the internet doesn't work anymore. And I got it for about 10 different places. I was trying to go for a couple hours actually. So it was a pretty big outage. What happened? Why did it happen and how do we not have this happen again?

[00:01:23]Craig Peterson: [00:01:23] Frankly, I'm a little surprised it doesn't happen more often.

[00:01:26] Yeah. If you lived in the UK, the entire UK government websites went down, all of them, uk.gov or kind, I should say at one downer as well as gov is absolutely amazing. Actually, I got those backwards. It was anyways. What happened was one of the major providers of web hosting had a major problem, and this was not a hack.

[00:01:54] It wasn't ransomware, et cetera, by the looks of it at this point. But what happens when you go to a website is you're connecting to a server somewhere. Now, normally let's say you've got your local soccer club and they have a website that is hosted. Maybe it's on Amazon. Maybe it's just hosted locally.

[00:02:14] Somebody right here in Maine and they've got it in their little data center. So if someone in the UK or South Africa or California wants to go to the soccer club website, they're going to Maine in order to get at it because that's where the servers hosted. So the problem is that means you now have all kinds of delays because the data has to travel through much of the internet.

[00:02:40]What we've come up with is something called content delivery networks, and there's a number of them out there. Some are bigger, some are smaller. And what w what companies do is they put major portions of the website. So for instance, if you go to Craig peterson.com, that site, we hosted here locally, and.

[00:02:59] All of the graphics and all of the videos that are on that website are actually delivered to you over a content delivery network. So your in Portland, for instance, you will get those pictures from my website, those videos from my website, all of that large content from a, hopefully a data center really close to where you're at and someone in California is going to get it from a data center, close to where they're at.

[00:03:26] It really speeds things up. So the problem was all of these sites that weren't up and online were having problems because the content delivery network they were using, which consists of 80 servers centers all over the world, it had a bug probably from distributing a new release of software and it stopped working.

[00:03:50] So it was down for a little more than an hour. This was just a normal situation. I'm not going to use that acronym. And it's something that happens and happened before. It'll probably happen again. So this was not one of those attacks from Russia or China or anybody else.

[00:04:08]Matt Gagnon: [00:04:08] Speaking of attacks from Russia, that's maybe a nice little segue into the second question I had for you, Craig, because obviously we're seeing cyber attacks happen more frequently.

[00:04:17] And right now us intelligence is probing. Whether or not the Russians Vladimir Putin, et cetera, are testing the Biden administration. Of course, not even a year old yet. With a lot of these cyber attacks to see what's going to happen to see how they're going to react to it. And you're going to have a meeting coming up between Biden and Putin here.

[00:04:33]This is all part of a larger geopolitical context. Don't need you to comment on that, but I would love to get your thoughts on what exactly. Nation to nation, cyber warfare looks like these days and exactly what's going on here? What are they up to?

[00:04:46]Craig Peterson: [00:04:46] It really looks in fact, we are in a war, right?

[00:04:49] We've said that before the first shots of world war three have already been fired and it's online and we had energy secretary, Jennifer Granholm on Sunday. Warning us all that the us power grid is vulnerable to attack. So CNN is Jake Tapper and say to the union said, are we safe? Can our adversaries shut it down?

[00:05:13] And grand said, yes, they, they can. And in fact, They do. The first one I remember was back in 2004, I was down in Connecticut. Hadn't done in New York city and the power grid went offline. And apparently that was a task based on all of the research that was done after the fact they were seeing, can we get into the power grid?

[00:05:35] They actually didn't mean to shut it down, but they didn't really know what they were doing. And they brought it down so fast forward to today from 2000. Four. And we are seeing a whole lot of hacking going on against all kinds of infrastructure. We've got the meat packing plants, right? We've had the power, we've had water purification plants.

[00:05:57] We've had of course colonial pipeline. And in fact it's difficult to defend against now whether or not. Putin is testing us is a very good question. I suspect he is, we talked to him on my show and talked last week about using Russian keyboards to stop the ransomware attacks because.

[00:06:18] The ransomware, first thing it does is check to see, is there a Russian or Russia affiliated keyboard? If there is a short circuits, in other words, they don't want to attack Russian systems. They are definitely attacking our systems. And the attacks that I just mentioned were very directed attacks. These weren't the normal ones.

[00:06:39] These weren't the ones where they're casting a wide net. Pulling anything up they can, and then taking advantage of it. These were direct attacks against various parts of our infrastructure. They were coordinated. They were thought through very carefully. So I think the answer to that is, yeah they are testing us.

[00:07:00]The question is why.

[00:07:01]Matt Gagnon: [00:07:01] Good question. Finally, Greg, before I let you go, I want to ask you about the flashcard thing here. The U S soldiers were exposing nuclear weapons, secrets via flashcard apps. I saw this story a little while ago. And I meant to click on it to learn more, but I didn't.

[00:07:19] So you're going to educate me here a little bit on this and tell me a little bit about what happened. What is the deal here

[00:07:23] Craig Peterson: [00:07:23] about this? We have military personnel who have to memorize things and particularly those personnel who are around the nuclear. And so they've got to memorize it.

[00:07:34] And how do you memorize? You use flashcards, works really well. That's what I used in college as well. So this is all about rote learning. And the problem that we're seeing here is something we've seen before with the military. They're using standard apps for flashcards and those apps they've loaded in all of these questions about the locations of our nuclear weapons the disbursement patterns of them, everything you can think of about our weapon.

[00:08:05] This sounds like a great idea, by the way. That's a great idea. So there's something called open source intelligence, and I've worked with them quite extensively in doing my. BI InfraGuard webinars that have been running, but these researchers go and see what they can find online. They found stashes of these cards with our nuclear secrets in them.

[00:08:29] So it is a problem. It's a very big problem in the remind you of what happened with these these tracker watches that many people wear. That we're exposing where our secret bases were because these guys were jogging around the base, keeping track of all of that, to where they ran, how fast they ran, competing with their buddies, maybe on different bases or the same basis.

[00:08:53] And all of that was being posted online. So even though there's no official base there, for some reason, there's a lot of people who are running a pattern that really looks a lot like a landing strip.

[00:09:05]Matt Gagnon: [00:09:05] That's Craig Peterson, my friends. Thanks so much for joining us, Craig, as always, we appreciate you joining us and of course, make sure you listen to him on Saturdays as well.

[00:09:12] Craig, talk to you next week.

[00:09:14] Craig Peterson: [00:09:14] Absolutely. Take care.

View Details

[As Heard 2021-06-08 on WTAG, WHYN, WHJJ. Fastly CDN failure]

Hi, so glad you are joining me today. I was speaking with Mr. Polito about a couple of different things. One, this problem you might have noticed with all of these major websites, CNN, all the way through the government of the United Kingdom going offline. So I explain how sites work on the larger scale site. And I also got into what happened here. What was the problem?

[00:00:28] And then we got a little bit more into the question about Putin he's meeting with president Biden. As he been testing, president Biden. Some people really think that he has mean that Putin is trying to see how far he can go. So we get into that and I think I disprove the absolute certainty.

[00:00:51] Some people have been expressing.

[00:00:54] Jim Polito: [00:00:54] Right now, I want to get this guy on board. He is our good friend and tech talk guru, Craig Peterson. I think it was just recently the birthday of the man who's credited with inventing the internet. No, not Al gore. And I just want to remind you that if you're on the internet, you may be using, or part of your search on the internet may have.

[00:01:16] Some code that was written by the great Craig Peterson and he joins us now. Good morning, sir.

[00:01:24] Craig Peterson: [00:01:24] Good morning. Yeah. Back in the day. I remember when,

[00:01:29] Jim Polito: [00:01:29] so let's get to this. Yeah, let's get to this. I want to get to Putin Biden and cyber attacks. And your take on that. But first we just had a, some kind of a crash of of a cloud, what out on the west coast.

[00:01:47] But obviously when something like that happens, that affects all of these, right?

[00:01:53] Craig Peterson: [00:01:53] Yeah. Yeah. It's something that Trump of Aqua knows a lot about. And

[00:01:58]Jim Polito: [00:01:58] Please don't bring Tommy we'll be into this. It's certainly even, I know it's a different type of cloud.

[00:02:06] Craig Peterson: [00:02:06] Oh, okay. Yeah. Here's what the happened to have here.

[00:02:10]Let's talk about what happens with normal websites when things are working properly, there are distributed servers all over the world and this company, Fastly has 80 data centers located everywhere. And the idea is you go to one of these bigger websites and that website has a quick look at you saying, where are you?

[00:02:31] Oh, okay. You're in Western mass. So we have a data center close to you. So now it's feeding the website, which is, the pictures and the texts and everything. It's feeding that website to you from Western mass. Does that make sense to have it come from California? It's going to slow it down and it's just going to be annoying.

[00:02:54] Or if you're in Europe or South Africa, right? So these are all distributed data centers and they're called a content delivery network. And there's a few of them out there. I use one that Amazon provides Fastly has their own content delivery network, so that all of this content, particularly the big content, like if you're watching a video on CNN, that's going to be delivered.

[00:03:19] Through Fastly is content delivery network somewhere close to you. That's the whole idea behind it. And apparently what happened this morning is just tons of major sites like Reddit, Spotify, Twitch, the UK government, Hulu HBO for a PayPal Vineo goes on and on CNN, New York times, BBC Bloomberg financial times all went offline.

[00:03:43] And that was due to a problem with this content delivery network at Astley. And it looks like right now, according to everything I've seen out of Fastly this morning and researching it, that they had a bug and it wasn't a hack that they weren't hit with ransomware, but they had a bug in their content delivery network.

[00:04:05] They were able to get it up and running in about an hour. It wasn't a big, long outage, and these are the types of things that happen with these very complex networks nowadays. It's amazing. It doesn't happen more often.

[00:04:18] Jim Polito: [00:04:18] I'm glad to hear that from you that it's amazing to hear it doesn't happen more often.

[00:04:22] I'm glad to hear that. Now let's get to something that is happening more often. More and more attacks out of Russia. And which Putin

[00:04:31] Craig Peterson: [00:04:31] says, I don't know what they're all about. I have no

[00:04:35] Jim Polito: [00:04:35] idea ask squirrel, is protect, pretending he doesn't know anything about it. And but in fact he does is, and Putin and bind are gonna meet in the next few days is, the whole G seven summit is going on.

[00:04:50] Is this Putin testing Biden? Like how much can I get away with. This guy pops my dog, does he will test the limits? Like how much can I get away with until they say, Hey, No sit or whatever.

[00:05:06] Craig Peterson: [00:05:06] Yeah, this is this is a problem. W every time a president's coming to offer Obama was this way.

[00:05:14]It happened to a lesser degree with Bush and others, and it did not happen at all with Trump. The Russians, the Chinese and others have tested the president of North Korea. If you look at China right now, flying over Taiwan. And in their air space, threatening our country by taking over Taiwan.

[00:05:36] And we've talked about it before. That's where our major production of chips is when you're talking about this whole cyber security thing. And again, it smells like Russia. And the main reason that smells like Russia is this ransomware has killed switches in it. Let's say, if you have a Russian or one of a dozen other keyboards, then we will immediately stop and it doesn't install the software.

[00:06:06] So there's two, two reasons. And I'm sending out an email about that with a little video training on how to put a virtual fresher keyboard on your computer to everyone that's on my email list. So if you're on my list, You're going to find out how to do it. It's very easy. And it's going to stop almost all of this Russian malware, but here's the big question.

[00:06:28] Is it in fact, a the reason for this, because it's gluten and he doesn't want to mess around with all of these former Soviet states or is it bad guys saying I don't want to go to a Russian Gulag. We don't really know, but what we do know is what's your word just leading towards, which is we've had taxed against all of our major infrastructure.

[00:06:54] Yeah, every piece of it. And we're seeing releases from the FBI that none of the infrastructure is safe. We've in fact had some statements about that. Look at the statement on CNN did last Sunday, two days ago, where one of the secretaries of the byte administration I forget her name now said that we are not safe.

[00:07:16] Our infrastructure is not safe. And we've got rep Michael McCall from Texas saying that the cyber incursions absolutely are Poutine's way of testing, president Biden. How are we going to respond? Yeah. And it's a big, it's a big question, Jim, because if there's a missile that launches from Russian territory, we know where it launched from.

[00:07:40] We can send something in and blow up that missile silo or whatever it might be. If there is a hack. And if it's a somewhat indiscriminant hack, which many of these are, but maybe even more directed hack, all we know is the tools they were using. Look like they were Russian. What is China? It's trying to convince us that it's Russia and is using these tricks and Russian tools.

[00:08:08] Yes. You're getting it from

[00:08:09] Jim Polito: [00:08:09] China, James Bond on me right now. Like specter would always like in, from Russia with love, make the free world think it was the right, the Soviets and make the Soviet thing. It's the free world. When, in fact, right in the middle. It's specter. Yeah.

[00:08:25] It's it's right out of it's right out of the James Bond novels.

[00:08:29]Craig Peterson: [00:08:29] Then how about Carver? Where he, tomorrow never dies. He's launching his own metals, trying to get both sides to fight. And we were warned decades ago about the military industrial complex. Yeah, exactly. That this is going to be a problem.

[00:08:48] So let's throw that into the mix. Who's to say some nefarious guy, like the car for character from James Bond, isn't manipulated. We just don't know we can see fingerprints, but as we know for mission impossible, those can be faked

[00:09:07] Jim Polito: [00:09:07] as well. Yeah. We're talking with correct. Greg Peterson, our tech talk guru and all around great guy.

[00:09:12] And it is interesting. I know last week it was fascinating when you told us one of the ways to protect yourself from Russian hacking is to have this virtual rushing keyboard. And most of their hacking will ignore you because, okay. We don't want to go after one of our own, but you're saying, yeah, how do we know?

[00:09:30] That's not the Chinese making it look like it's the Russians, you can't trust anybody. In this and my fear is, and we step out of tech now and we go into politics. My fear is that Biden is not considered a someone who's going to be tough on Right nations for doing this, that he's going to be weak and they just want to know to what extent can we get away with it?

[00:09:55] And if they get away with it with this, then that's going to embolden them, say the Chinese oh, we're going to take time one. We're going to take Taiwan. What's she going to do? During the Obama Biden administration Putin took the Crimea. Boom just grabbed right now. This is ours, not yours. And we let it happen.

[00:10:14]Craig Peterson: [00:10:14] They did respond, Jim president Obama said that he told them to

[00:10:18] Jim Polito: [00:10:18] stop it. That was over the hacking of the election. Like I told them to stop it now. That's great.

[00:10:26] Craig Peterson: [00:10:26] That's great.

[00:10:28] Jim Polito: [00:10:28] Yeah. Yeah. We do know there's a response. Yeah, exactly. So

[00:10:33] Craig Peterson: [00:10:33] there's only one thing we can do here, Jim. And that is we have to protect ourselves.

[00:10:38]You were talking to earlier today. About the training that you're doing there. And other companies are doing that is ultimately important. However, the problem is it's never a hundred percent, nothing's ever 100% and there are. I hate to say this, the industry I'm in is I'm trying to protect businesses, right?

[00:11:00] And government agencies, counties, cities, everything from hackers. And the thing I hate to say is. It is full of charlatans. It's full of them. All of these people's shell

[00:11:14] Jim Polito: [00:11:14] oil. We can

[00:11:15] Craig Peterson: [00:11:15] help ya. Yeah. Yeah. We can help you get in. We got there.

[00:11:19] Jim Polito: [00:11:19] I got Charlie working on you, Ray, on your server over there. He's got it all hooked up.

[00:11:24] You're going to be fine. Nobody's going to be able to get in tight as a group.

[00:11:28] Craig Peterson: [00:11:28] Yeah. And includes the big names, you've got McAfee out there. John McAfee saying McAfee. Antivirus is useless. Yeah, he's on video saying that. Okay. Yeah. The Norton software, same problem. One of their senior executives admitted that their software's useless.

[00:11:46]You've got to have a full stack. None of this is good enough to protect you. I hate to say this, but Microsoft. And they're lying to you that you have been lied to and that's why you got hacked. Yeah. So Microsoft has some great tools. Now they're finally pulling up their socks. You can use Microsoft windows defender, make sure you have it.

[00:12:09] Make sure your software is up to date. This sounds like a broken record, shorty. Yeah, the majority of computers are not up to date and get a good next generation firewall. Cisco has the best at the high end, these firepower firewalls with the FMCs and stuff. No doubt. But the fact that major companies like colonial don't have these things in place blows my mind.

[00:12:37] But again, it goes right back to you don't know what you don't know. Yeah, you

[00:12:42] Jim Polito: [00:12:42] don't, you don't well, so how can folks get in touch with you? How do they do it? Okay.

[00:12:50] Craig Peterson: [00:12:50] It out this thing on how to do the Russian keyboard, I've got it recorded. I got to edit it, but how to put it onto your computer, the right ways to do that.

[00:12:58] And that's going to be in the newsletter and you can get that and stay in Todd fight, just going to Craig peterson.com/subscribe. That's Craig Peterson with an o.com/subscribe. And you'll get my weekly newsletter. I have these little three minute trainings that I'm putting together and you'll get all of it and that's all free.

[00:13:20]If you want to hire me, that's fine. But this is all free because we've got to stop these bad guys. All right,

[00:13:27] Jim Polito: [00:13:27] Craig, thank you as usual, always a pleasure. And we'll talk to you next week.

[00:13:32] Craig Peterson: [00:13:32] Thanks again, Jim.

[00:13:32] Jim Polito: [00:13:32] Thank you. Bye-bye.

View Details

[2021-06-07-WGIR-WQSO]

Apparently, I was a bit of a ratings Bonanza, yours truly? Yes, indeed. A couple of weeks ago when I was on the air and I told my story about my alien encounter with UFO. And the, we talked more this morning about UFO's and a little bit more also about the apparent this last weekend on CNN of energy, secretary, Jennifer Granholm, who talked about how our businesses are constantly under attack and our grid is in danger.

[00:00:36] She even admitted that our grid electrical grid could be shut down by a foreign adversary. So here we go with Mr. Chris Ryan

[00:00:47] Chris Ryan: [00:00:47] It's uh, Craig Peterson. The host of tech talk on news radio 610AM and 96.7FM Saturdays and Sundays at 11:30. Craig, how are you?

[00:00:54] Craig Peterson: [00:00:54] Hey, I am doing well.

[00:00:56] Chris Ryan: [00:00:56] Appreciate joining us. So let's start with this.

[00:00:59] I don't want to do aliens each time with you, but given the fact that the second to last time you were on it was a ratings Bonanza. When you talked about the fact that you had experienced a an encounter with a UFO and we Scott the report or the leaking of what's potentially in the report from the New York times, we're all waiting this congressional report and indicates that we still don't know.

[00:01:19]Is that problematic for you as somebody that has experienced a encounter and you have the documented visual evidence and the testimony of individuals in the Navy, or is it not? Because we can't make any clear determinations based upon the fact that we have. At least reportedly not have any evidence to indicate that there is extraterrestrial life on earth.

[00:01:46]Craig Peterson: [00:01:46] It depends on what you define as evidence, right? There's the Roswell theory that somehow we were able to capture a crashed UFO with potentially aliens on board. That would be hard evidence. These types of videos that we're seeing are all in fact not just a visual videos, but they also include various other frequencies like ultraviolet, infrared.

[00:02:12] They have really done some amazing things in the military in order to track potential enemy targets. So it's one thing to say that was a cloud. Formation or maybe it was the sun reflecting off of something that might be true in the visual spectrum, Chris. But when we're talking about all these other frequencies that we're also monitoring and we see things, and that includes like radar, for instance, which is not affected by any of these visual things that we might see in the sky ourselves.

[00:02:42] Chris Ryan: [00:02:42] And the personal testimony as well. There was the there was the individual that was captain of the Naval ship that said there's basically daily occurrences that they would, or I shouldn't say daily currency. It was regular that they would see these types of phenomena and the pilots and everybody else.

[00:02:58]In my view, the report is going to indicate that yes, these things are seen, but we can't clearly say who is responsible for it because we don't have the, that much evidence. I think that's the direction that the report is going. Your thoughts on that before we move on.

[00:03:14] Yeah. We'd have to have our hands on it.

[00:03:16] It's just like when I had the encounter I wasn't taking anything away from it. If all you're doing is observing it. Through multiple frequencies. Again, we know something was there. We know it could move in ways that we just can't imagine. Yes, absolutely. It's I obviously, I believe in these things, I saw them or I've seen them before.

[00:03:39] My mother has seen them before. I know people personally who have had muddle encounters. I know people who say they can summon UFO's. And have them come down and I've seen the videos that they've taken it. This is a very interesting topic, but I agree with you again, Chris. I don't think anything totally earth shattering is going to come out of this.

[00:04:01] It's going to be, yeah. We're seeing something, we have hard evidence that something was there, but there's no way to tell exactly what it

[00:04:08] was Beth. And I'm jealous of the people that can summon UFO's. Cause I don't feel like you have any real power until you can summon a UFO Avenger. Yeah. Yeah. I got you.

[00:04:17] You can do whatever you want. Like I could discuss policy with anybody go to any sporting event, but unless you can some on a UFO, I feel like I'm a failure in life.

[00:04:26] Craig Peterson: [00:04:26] Yeah, it's interesting the way they do it too. In, it's a mental thing. They feel that as well, they have a mental bridge with these people.

[00:04:34]The law of one people. I'm not sure if you're familiar with them or not, but some of the things that they've been doing and then they use lasers in order to help the UFO's kind of pick what exactly where they are and call them up. And. And I've seen videos of entire smaller, modest, if you will, of these lights in the sky coming down and various types of light patterns and movements and just disappear again with.

[00:05:02] With 50 witnesses, who all say it absolutely happened.

[00:05:06] Chris Ryan: [00:05:06] Let's move on to Russia and the most recent cyber hack involving a major meat producer Brazilian based JBS. So just the latest on that in your view. As we heard early on that the Biden administration was pushing the Kremlin as to whether they were responsible for this attack.

[00:05:26] We haven't seen a lot of reporting basically on the circumstance surrounding JBS. They're able to regain control of that. There wasn't any it would appear major supply chain issues at this point in regard to beef production and distribution. What are your thoughts on this?

[00:05:43]Craig Peterson: [00:05:43] JBS is a pretty standard case nowadays.

[00:05:47] And I talked over the weekend here on my show about something I'm going to be releasing. Hopefully I'll get it finished today, but it gives some real evidence. Again, evidence-based that this major set of attacks, including what we saw from colonial is in fact, coming from Russia and that is. That when the ransomware first gets onto your computer system, it checks to see if you have one of, about a dozen different keyboards.

[00:06:15] Now, those keyboards are keyboards of countries that are part of the OIC, these independent states, if you will. That used to be part of the Soviet union. So the way the ransomware works and I went into some detail, I'm going to send out some videos today or tomorrow to all of my subscribers. You can see how to do it yourself.

[00:06:36] But when most ransomware gets on your computer, Chris, the first thing it does is say, do you have a Russian keyboard or Belarus or Armenian a number of different keyboards that looks for, if you have a Russian keyboard immediately? It goes ahead and doesn't install itself just exits immediately. And the theory behind this, and by the way, it can be just a virtual keyboard.

[00:07:01] Doesn't have to be a real keyboard. The theory really now comes forward. Why would they do that? Is it because these bad guys are based in an area where the Russians. Have enough control that they could grab them and throw them into a Gulag somewhere. And that seems to be what we in the security community are thinking is happening.

[00:07:22] So yeah, it really looks like it's coming from Russia. And we just had the energy secretary yesterday on CNN, Jennifer Granholm, say that. Yeah, they're happening all the time. I see them all the time. My customers are getting attacked multiple times a second. Even they're getting scanned and.

[00:07:42] President Biden came out with two executive orders now that are mandating that the federal government and its suppliers start really locking things down. And we've been working with a lot of companies in order to do that, but it smells a lot of that. This was really a Russian thing. And as again, secretary Granholm said over the weekend, we cannot pay ransoms.

[00:08:07] All it's doing is encouraging them and to see colonial pipeline, give them four and a half million dollars. Just absolutely blows my mind. I agree.

[00:08:17]Chris Ryan: [00:08:17] It's one of the basic principles and basically, cyber attackers are terrorists. You don't pay the terrorists, you don't pay them. Because when you do the next time, they want more money.

[00:08:28] It also in create creates environment of like-minded individuals are going to start to perpetrate these crimes and it's pretty easy for them to do and it seems like a lot of government entities and businesses are running blind. Craig, we got to run. Thank you so much. Take care. Craig Peterson, host of tech talk. You're on news radio 610 and 96.7 Saturdays and Sundays at 1130.

View Details

2021-06-05 1116

Craig Peterson: This is a concerning report. At least it is concerning to me and it should be to everyone, frankly, but despite Colonial Pipeline to attack the likelihood of utility sector hacks has increased as was evidenced just this week.

[00:00:15] I wish I had thought of this one because it's just so simple and those are always the best, right? The simple ways to really work around a problem. And I've brought you a few before where we talked about some of the VPN stuff. We've talked about different types of security, this particular one, though, I think takes the cake.

[00:00:36] It's absolutely amazing. If you get right down to it and think about Russian hackers, real Russian hackers, not the fake ones, not just the white house saying that's Russia and it's really China. And then it sometimes frankly, between you and me, it's hard to tell because. The Russians can easily use

[00:00:57] chinese

[00:00:57] tools.

[00:00:58] They're available to almost any hacker out there that bothers to go out of their way to grab them. And the Russian tools are much the same way. So the way you figure out whether or not it might've been China or Russia, Or a particular hacking group or another is to look how they behaved when you're there in yeah.

[00:01:17] Your computer system. So let's say you think your computer got hacked. You might look for different pieces of software or names of files or where they went, how long they were there and what kind of ransomware might they've used on yours, computer, all of those types of things. Give you a serious clue as to who it was and where they came from.

[00:01:42] You can't really tell where they came from. You can look at the IP address and a lot of people say that. Why don't you just look at the IP address? The reason you can't obviously you can look at the IP address, but the reason you can't depend on that in order to determine where someone's coming from is just like they showed in the movies where.

[00:02:02] They're trying to back trace a phone call or back trace something, and it shows up on this big world map on this huge screen. That's bigger than. A 20 foot wall and it's showing a little dot. Okay. Here's OS and oh, and came in from Des Moines. Okay. Okay. Before that they were in London. Okay.

[00:02:22] Before that they're in South Africa, they were in Russia and they were in Vancouver. You've seen that. And it shows the dots popping up and the lines being drawn between them. That is not possible. Certainly not in real time, but it's really not possible at all. Because all you have to do is have a hacker take control of a few dozen computers around the world and use them to hack you.

[00:02:51] So that bad guy is now using dozens of people's home computers, which have no real logging. No, one's really paying attention to them. You're using it for gaming or maybe a little bit of work, email, web browsing, all of that basic stuff. So you're using it for all of those things, but you're not securing that computer tightly.

[00:03:16] So they'll just use it. If they want to attack from North Korea, they can easily hop through a few different computers and then end up on a computer in Russia. And now it was like, it's coming from Russia. It's really that simple. And they have these botnets to do that. Very thing. Yeah. That's why I keep telling everybody, make sure your computer is up to date that it is in fact patched up and the bad guys are less likely to be able to use it because your computer can be used to hack somebody else.

[00:03:51] It can be used to bring a denial of service attack against someone. The distributed denial of service attacks are way up this last year. It can do a lot of things that frankly, it should not be doing. So that's why I'm always warning you guys. Cause you don't want your computer to be used in a crime. So we can't tell where these hackers are necessarily coming from, but what Brian Krebs revealed this week, I thought was absolutely brilliant.

[00:04:24] Apparently many of these ransomware guys are in fact in the Commonwealth of independent states. And that includes a few different countries, Russia, Ukraine, Kazakhstan, Turkmenistan all of these stands over there. And some others

[00:04:39] basically

[00:04:40] Craig Peterson: it's the former Soviet union countries. So they're part of this Commonwealth of independent states.

[00:04:46] And if you're living in there, let's say you're in Russia and you're in Moscow. And you're using computers. You're sending out ransomware and you wanna make some bucks off of it by charging people a ransom. You need to be darn careful that you do not ransom any Russian computers or in fact, any of these Russian affiliate computers.

[00:05:11] Because if you do, you're going to have the gremlin coming down on top of you. They do not take kindly to it. And I don't know if you've seen any of these Russian. Prisons jails doesn't seem like place. Most people would want to end up at some pretty bad places and you don't stand a chance.

[00:05:29] Okay. So the bad guys are trying to be careful. So if you're sending them ransomware, that's indiscriminate, I'm not talking about a dark side going after colonial pipeline where they're aiming at colonial pipeline. There. Aiming at one specific business. Cause they know that business has money to pay. And you got to ask yourself, why did they aim at colonial?

[00:05:54] Was it just because of the money? Because they knew they could pay. Because we've had water plants, ransomed police departments, Ranson. We just had meat, the largest meat processor in the world. Branson is this a pattern where they're checking our critical infrastructure, the ability to put fuel in our vehicles.

[00:06:17] The ability to have electricity. I have food. Is that what's going on? I really don't know, but I can tell you almost all of the ransoms that are out there are indiscriminate. So you can't just sit there and say I'm not going to get ransom because I'm not colonial pipeline or I'm not a meeting.

[00:06:33] Packer, et cetera, et cetera. It's not gonna affect me. I'm too small. No one cares about me and I can get my business back online in a day, a week at the most. And you may be able to, okay, but you are still the target because almost all of this ransomware is random. Basically it's distributed in emails, sent out to millions of people that have no idea where it's gonna end up at.

[00:06:59] So let's say that you get this ransomware and you open it up and it's a business and all of a sudden you get ransomed. How does the ransomware know if you are in the Commonwealth of independent states? How does it know that your businesses in Russia or Kazakhstan or Armenia or one of these other countries.

[00:07:23]Basically it, it doesn't. And I'm I know I'm going to get, let me just double check Armenia here, because I know I'm going to get all kinds of flack from people. Yeah. All camera and yet Armenia is part of it. It doesn't know. Or at least it doesn't know if it doesn't check and that's the beauty of this, but Brian Krebs did Brian Krebs came out and said, and I think he got it from someone else too, but he's the one that really populated it, our populated popularized it.

[00:07:56] What this ransomware software parently does is it looks at your computer for something very simple. Now what could you look at if you were writing ransomware? What might you want to just check real quick? That's a real quick check. You can see if you are probably within the Commonwealth of independent states or maybe you're on a computer in a Russian embassy in the United States, which you also don't want to hack while why don't you just look at the keyboard?

[00:08:27] Apparently, that's what they're doing. They look at the keyboard of the computer when it gains control of the computer. And I'm not talking about the physical keyboard because many people worldwide use a us standard keyboard, but. What they're looking for is a keyboard. And when I'm saying a keyboard in this case, I'm talking about a virtual keyboard in one of a few languages, including Russian isn't that something.

[00:09:02] So they looked at this dark side, ransomware and cyber reason did some reverse engineering on it and he found. Which languages you can have virtual languages on your keyboard. Now you might already have them. I've got French on mine, as well as English. You might have Spanish. I don't know.

[00:09:23] There's the Chinese, there's a lot of the Mandarin. If you have Russian Ukrainian, Armenian, or a number of these others, Romanian, any of those languages that are part of, again, this Commonwealth of independent states as former Soviet union on your computer as a virtual keyboard. Yeah, it doesn't have to be a real keyboard, just a virtual keyboard.

[00:09:49] This particular piece of nastiness, this ransomware from dark side will immediately shut itself down. Isn't that amazing? So simply put, there are countless versions types, strains of malware that check to see if you have one of these languages installed on your system. And if they're detected, the malware will immediately exit and will not even install itself.

[00:10:20] Isn't that something. Yeah. So whether or not we can absolutely tell if something's from Russia or China or North Korea or someone somewhere else. We do know that having one of these Russian keyboards or again, one of the stands, et cetera, keyboards on your computer. Will short circuit, the ransomware and a won't even install itself.

[00:10:47] Isn't that just amazing. So look in your newsletter. That's coming out this weekend and have a look and I've put together a whole thing about this, a little video. You have to watch Craig peterson.com.

[00:11:02]This particular app is called citizen and we've seen apps. There's millions of them out there nowadays. The do almost anything. Absolutely. Anything, and this particular app, you can find online. I'm going right now to their website. It's called citizen.com and it looks like their initial idea was that they would have an app that would allow kind of citizen reporters.

[00:11:31] So you could just go and you could be like a journalist and take videos and post them up. And other people could go and look at what's happening with the house fire or, yeah. Fire hydrant that got crashed into rescues, all kinds of stuff. It's really cool. I liked that idea, but they're saying that they want you to connect and to be able to live more safely.

[00:11:58] This is a personal safety network that empowers you to protect yourself and the people and places you care about. It's really cool. They added into it. Some COVID-19 contact tracing real-time nine 11 alert, instant help from crisis to reap crisis reporters and safety tracking for friends and families.

[00:12:19] Now we use a, an app as well for safety tracking called life 360. And it'll know if you're in a car accident. And in fact my wife and I, we were out driving and we had a carb or our car broke down the. Whole front assembly of the car, the electronics, and it stopped working for some reason. So the fan wasn't blowing and it was fine though.

[00:12:47] We didn't notice anything all winter long, and then here comes summer and we're stopped in traffic and all of a sudden the car overheats. That's why. And so we called. Had got a hold of a tow truck who came and told us. And ultimately we got that whole thing fixed, but what amazed me was that this life 360 app sent a text to the family, letting everybody know that we were okay.

[00:13:15] The car's being towed. I'm not even sure how it knew the car was being towed, because we did not use the life 360 app in order to get a tow. It was really quite surprising because it's included, towing's included with this app. So there's all kinds of cool ones. There's lots of them out there that do this sort of thing.

[00:13:35] Of course, if you have apple gear or your family, you can automatically track them, see where they're at and what's going on. And. This particular app can do some of those same things, but they're really focusing in on safety. They have a cool site. If you go and check it out online@citizen.com and on their site, they're talking about you real time safety alerts for your neighborhood.

[00:14:03] So there's a Burr burglar that's just broken in and they're showing a picture of New York city, which I think it makes a lot more sense there than it does in Podunk new England. Okay, where we're yeah, things can happen, but they're very rare. And it's not as though you're going to try and avoid it because you're not in that area anyways.

[00:14:24] Anyways, they know it and they are saying, Hey know, the whole story faster. So that's the basics of this particular app. But. Here's where it has crossed that line with mission creep. Apparently they want to be in the police business. And this is from a website called tech dirt. They've got all kinds of great technology articles, Tim Cushing put it together, but he's saying that the app developers have purchased at least one fake police patrol vehicle.

[00:14:58]They're out in LA. They co-branded it with Los Angeles professionals security and they've been driving it around Los Angeles, California. Now take a look@thisonlinelosangelesprofessionalsecurity.com. I don't know if it's. If it's a blogs to those citizen guides, it's a nice site. So it might, they very heavy graphical site and showing their services.

[00:15:23] So I'm guessing it's not, I think this is a third party, so that they've co-branded it with them. But the question is how far should private companies be able to go in the business of enforcing the law? Because in most cases, I think most people would say, no, that's really not something private businesses should be getting into.

[00:15:47] Law enforcement is something a little tricky. And we know that now because of all of this stuff has been going on with law enforcement, should we, do you fund the police? Where should we put in our money? All that sort of other stuff? These guys are citizens. Apparently citizen apparently have always been willing to blur the lines between government employees police department and their app because it debuted as vigilante.

[00:16:18] That's where it started. It was an app developed by this American technology incubator back in 2015. And they changed it from vigilante to citizen. But apparently some of the motivation behind this just hasn't changed, which is scary when you get right into it. They are also one of these. Bug companies that is trying to have kind of an on-demand security force.

[00:16:49] Now, I don't know how much history you guys know, particularly in this case, I'm thinking about fire departments and in many cases, in many areas of the us, the government did not run the fire department. So for instance, we're talking about the You know your town, right? Nowadays your town probably runs the VAR department.

[00:17:11] You may have private or contracted ambulance services. But these guys are doing something that was done in New York city around the turn of the last century, where and before, where you would contract with a private organization that. You paid and they would provide you with fire department type services.

[00:17:37] So you'd put a medallion there on your front door or a door jam. And that medallion was for the fire department that you signed up with. Now, in some cases that fire department might be at the scene of a fire, but the place that's burning. Was not contracted with them, so they didn't bother doing anything.

[00:18:01] And the whole place burned to the ground. Interesting. Isn't it? Because you, you have to ask, what are the motivations behind it? If it's a public fire department that your town is running, they have one would assume an obligation towards all of the citizens of their town, but they would certainly go and help mutual aid.

[00:18:23] Another town. Same. Thing's true with ambulance services. Cause I was involved with it. So a little bit about it, but leaked emails. This is according to vice.com are showing that this crime app citizen is testing on demand security force. What could happen is you're using the app and you decide you want some security to show up just like he might rent private security, for an event that you're holding at your home, you could say, ah, here's an incident.

[00:18:57] Now think about the incidents that the police respond to. It's everything from his dog took a Wu on my lawn all the way through she's beating her husband. Okay. All kinds of things could be happening, but. We'll see what happens. I think that this is mission creep. I think it's gone a little too far.

[00:19:19] I don't think our police departments are getting the support they need from some areas of our communities. And thank goodness we don't live in the big cities or some of us live in the big cities that are listening, but most of us are in much more rural settings where we don't have the same problems.

[00:19:39]We've got fact checkers that are more like opinion enforcers and Florida has had enough of it. Florida has just passed a law, a ban on band. We're going to talk about that right now. And does it cross the line?

[00:19:55]Florida is pretty upset with what happened in this last election. And more importantly, they're upset. At least the lawmakers with these bands that have been going on. Of course by now Facebook and Twitter and others have decided that they, and they alone are the arbitrators of what is right.

[00:20:20] What is wrong? What is true? What is false? What is fake news? What is not fake news? And they have appointed a number of people. Most of them pretty darn young, who get to decide whether it's true now. They don't have to these truth moderators, if you will, don't have. To bother researching something.

[00:20:43] Oh, heaven, bad. Why would they want to research something that president Trump or some other conservative or libertarian would say? No, of course not. So they don't even bother doing a basic duck. Duck, go search little on a Google search to try and figure out whether or not something is. True. These fact-finders aren't finding fact and many people have had enough of it.

[00:21:15] So Florida had a Senate bill, 70, 72 that they passed and it provides several new checks. And balances on technology and social media companies. So I want to go through the top ones here. This is an article over on tech crunch, but they're saying number one, among other things, platforms cannot ban or de prioritize candidates for state office.

[00:21:46] Now that's a big one because they have been somewhat. Some of these districts, not just in Florida, but nationwide where it looked like the conservative was going to win all of a sudden a week or even a few days before the election. That's when they usually do most of their ad buying and spending.

[00:22:05] When people are finally paying attention in those last few days of a campaign, they get banned. So they are say explicitly saying you cannot ban state office candidates. Number two platforms. And remember mark Zuckerberg said that he was never going to do that. I remember that quite clearly, as long as my memory is still working, platforms cannot ban or de prioritize any news outlet, meeting certain size requirements.

[00:22:37] In other words, Hey, you don't have to report everything from Joe's media, but you sure as heck have to from AP or Fox news or any of these others. Platforms number three must be transparent about moderation processes and give users notice of moderation acts actions. Now this is a very big deal. Because the moderation processes are anything but transparent.

[00:23:07] As I said, near, as we can tell, it's a bunch of teenagers who don't bother doing any actual research on the facts or the science, they just go for it and band people in band things. One of my daughters last week. Posted a little article w actually, I guess it was a repost of an article and she made a comment on it and it disappeared from her timeline.

[00:23:34] Now I asked her what it was about and she said then this is what it was dad. And not a big deal. I don't know why they would ban it, but they did. And they did not notify her at all. So they didn't tell her. And apparently they're not telling, as we've heard from so many people, they're not telling anybody who is in political office, why they're being banned or that something was banned or quote unquote moderated.

[00:23:59] They, this is just getting crazy again. It has to do with companies getting to. Darn big. Now we'll get into that in just a minute. And then the fourth thing is users and the state will have the right to Sue companies that violate the law. Statutory fines could be as high as $250,000 per day for some offenses.

[00:24:22] I think that part of it, frankly, is probably a pretty darn good idea. So I'm I just said they get too big. They've gotten too big and I've been complaining about a number of companies for a long time. Most of these companies got started using nefarious techniques. They really did, and it's easily arguable.

[00:24:45] It has been argued in court and these bigger companies, they were talking about these tech companies, social media companies, they have lost their cases in court. Not every case, obviously, but they have lost in court. They do some pretty nasty things to get started. And then once they've got the momentum, they use the money in order to keep everybody else out of the business.

[00:25:13] It's crazy. We've talked about that before these multi-billion dollar valuations for companies that are starting to threaten Facebook's dominance. Now a company that should be worth maybe 10 or $20 million, Facebook pays over 1,000,000,004, just so that they can make sure they get their hands on it. So how do we deal with this?

[00:25:34]I don't think government regulators usually help a lot here because all the regulations they put in place just to make it better for the big guys, is he, it goes back to a barber's license. I want to go all the way back down to a barber's license. If someone knows how to cut a hair, why do they need a barber's license?

[00:25:53]Really, buyer beware, but a barber's license only does one thing. It's like a medallion for a taxi in the city. It allows. The group, the union of taxi drivers or the barbers who are in a state to say, we don't want any more barbers because that's going to drive the price down. So we are going to make sure the state limits the number of barber licenses.

[00:26:20] So it isn't really about we want to make sure that your taxi ride is safe in New York city. No, it's about. That medallion, that license, that taxi driver has to drive a taxi in New York city. It's about that medallion being worth $1.2 million. $1.2 million to have one cab in New York city. Tell me there isn't corruption there.

[00:26:44] So I don't like the idea of the government trying to regulate these huge tech companies, because the big companies can handle the regulation. It's Amazon's been out saying yeah, we need to tax the internet tax internet. And there are almost 10,000. Unique taxing entities in the United States of America.

[00:27:04] So how can you as an individual worry about all of these rules and regulations and withhold the right taxes and send them to the right people and fill out the right forms. You can't. That's why you have a store in Etsy, but Amazon can, and it keeps everybody else out of the market. A small company cannot compete because of the regulations that were put in place that Amazon supported and got put in place to keep all of the competitors out of the market.

[00:27:37] Absolutely. Very big deal. And so now we've got Florida saying. Hey guys, we've got to do something about this, but there are obviously some first amendment issues here. Although the first amendment is primarily for government. We do have a general right to free speech. I think a lot of conservatives get it wrong.

[00:27:59] It isn't, the corporations don't have to honor the first amendment because I think that is integral to everything we do

[00:28:08]Boy, Arizona has been in the news a lot. And I'm going to talk about another lawsuit that Arizona's involved in, and this has to do with Google tracking you, even when you turn off tracking.

[00:28:22]Amazon has all kinds of great devices. I talk about them. Quite frequently, I have a couple of echos in my home and I tend to use Apple's home kit based devices. When they're available. Siri has a completely different. Approach to how to process languages than Amazon or Google do. So for instance, what apple does with Siri is it tries to process what it's hearing locally.

[00:28:50] So when you're talking, when you're asking questions, et cetera, it's really running right there on your apple watch or phone or pad, tablet, or computer, whatever it is, they try and do the processing locally on your device. And

[00:29:04] that

[00:29:05] Craig Peterson: helps keep it private. Amazon and Google are quite the opposite. They want to know everything that's going on.

[00:29:13] So when you say Alexa, or Hey, Google, they both start listening. They record the audio and they send it on up. To the internet and once it's there and their servers, it turns it into of course text. And then it uses a kind of a machine language machine learning thing to figure out what it is you mean, and then give you the answer.

[00:29:37] And that's why many times the answers you'll get from either Google home or the Amazon Alexa family. Those answers tend to be a little better, much of the time than what you get from apple. Apple is continually improving their technology. But again, remember apple tries to keep our data private, which I think is very important to you.

[00:30:02] And to me, no question about it. So what is happening right now is Amazon says You've got a, an echo or whatever might be like one of those ring doorbells at Amazon now owns. And we've talked before about those being tied into police departments, thousands of them now across the country, where they can look at the video, coming from your doorbell to try and figure out who might be committing a crime in the neighborhood.

[00:30:31] And there's good and there's bad tobacco, just like most other things. So that doorbell. A ring doorbell has built into it, some wifi connectivity. So it will connect to the wifi in your home. So does obviously the echo device, we guess it doesn't even have anything net port on it. You have to connect it via wifi.

[00:30:55] So if you're connecting it via wifi, Amazon's thinking maybe what we should do is share your wifi with other people. Now, this concept is called a mesh concept and it's pretty common. It's pretty popular.

[00:31:13] There

[00:31:13] Craig Peterson: are many people who are thinking that the mesh is going to help ultimately with these automated cars driving around.

[00:31:20] But in reality, the whole mesh thing in this case is without your direct consent sharing, the data you have, not just with your own devices, but with anyone's. Amazon devices. Amazon's calling this Amazon sidewalk and this whole new mash network and service is going to share, a fairly small slice of your internet bandwidth with nearby neighbors who don't have connectivity.

[00:31:53] Don't have the connectivity you have. So obviously this is going to affect people more in dense. Urban areas or at least denser areas where there's a lot of people around and you want to have your Amazon echo, but you don't have internet service. No problem. You can just piggyback on somebody else's internet service.

[00:32:14]I'm not sure I like that very much. So I went in and turned it off and I'll tell you how to do that here in just a minute. So the other quest side of this is well, How helpful should you be? Could you be right? Aren't we all socialists now is not the idea. You've got the AOC driving her high-end Tesla, the one with the extended range.

[00:32:38] And yet at the same time, she's complaining about her mother in Puerto Rico who didn't get government funding because of what Trump did. So instead of selling her Tesla, in other words, instead of helping her mother out nano, she's just going to complain that the government didn't right. I guess that's your typical AOC, maybe your typical socialist, but here's what we're talking about here.

[00:33:00] All of the Amazon devices that includes the Alexa, the echo, the ring there's security cameras, outdoor lights, motion, sensors, and tile trackers are going to enroll. Into this Amazon sidewalk system. And since very few people, I mean like a handful actually take the time to walk through the default settings.

[00:33:25] That means millions of people are going

[00:33:27] to

[00:33:28] Craig Peterson: be automatically in this program, whether they know about it or not. It's I guess it's concerning, right? I think if it's informed consent, that's one thing. But I don't know on the other side now let's talk about the service itself here for a minute before we get into whether or not you should turn it off, but it is a shared network.

[00:33:51] And it does help. The various Amazon devices work better. Amazon's not charging customers for it, but other people, Amazon customers might use your bandwidth and Amazon is not paying you or compensating you new in any way for that bandwidth that you are paying for. It's going to extend the low bandwidth working range of all of these Amazon devices to help find pets, for instance, tile trackers, which is an interesting thing in and of itself because Amazon came out with the competitor to tile.

[00:34:26] That's going to be much, much more successful than tile ever was. I think this might be the main reason. Yeah. Behind this. It might be spurned it along. I have a friend who's a video videographer professionally. So what he does it for news networks and he was heading over to Israel to be stationed over there for one of these networks for number of years.

[00:34:51] Yeah. And he asked me about Tyler. He says, oh, I don't want to lose anything while I'm over there. So I get tile. The way tile works is it uses low power Bluetooth, and you attach this little device, it looks like a little tile. It's a small rectangle. You attach it to something you don't want to lose. And so the low powered Bluetooth.

[00:35:12] Is now used to connect to other devices that can talk to tiles. So if you have an iPhone and Android, whatever it might be, and you have the tile app on it and you walk by someone else's tile, it will go ahead and inform the owner of the towel. We found it's over here. That's cool, isn't it? But the problem is someone else with the tile app needs to walk by the tile that has been lost.

[00:35:45] Now, most of the time, we're just looking for our keys in our houses, but in his case, he was thinking I'm going to be in Israel, who knows where I'm going to end up leaving stuff because I'm a videographer and I might drop things as I'm going. And it could be a bit of a. Problem while it's not going to do you any good, unless someone that also uses tile walks by closely to your loss device.

[00:36:12] And that's the same way that it works with apple, with their new little tile type devices, but in the apple case, it works because every iPhone in the world participates in this little network to find your lost devices. That's a big plus tile doesn't have that. So now with Amazon sidewalk, Being able to now detect tile devices from many millions of devices more than they could have before.

[00:36:44] I think it's going to be a very big deal. So if you have a tile tracker, it's going to be good. And a lot of people use them also to find their pets that might take off every once in a while. It's going to help. Devices stay online, even if they're outside the range of the home. Why fi they're talking about having special sidewalk, enabled devices, like smart security and lighting and diagnostics, appliances and tools.

[00:37:11] So the biggest question I had when it came to sidewalk and whether or not I should turn it off really was is it secure and how much bandwidth is it going to use? The maximum bandwidth of a sidewalk bridge to the sidewalk server is 80 kilobits a second. So that's hardly anything, frankly. That's about a 40th of the bandwidth that you choose to stream a high Def television video.

[00:37:38] But remember too, that this bandwidth might be down. It also might be up and et cetera, but it's still, it's a very small amount. They also are capping the amount of bandwidth that's used by sidewalk per account per month at 500 megabytes. So that's streaming again, about 10 minutes of high definition video.

[00:38:00] It isn't too bad. We'll see. Now, as far as the security goes, that's where it gets interesting. It doesn't make things worse either. Amazon's published this white paper that details that technical innards of this. The sidewalk service and it looks like it is designed to protect the privacy and security of Amazon sidewalk.

[00:38:26] So the paper's pretty comprehensive. No, I haven't seen anybody. I did some searching for it. I haven't seen anybody complaining about encryption or other safeguards that may be were overlooked, but there's enough theoretical risk to really give. Me pause. So that's what I did. If you open your Alexa app on your mobile device, you can go into the settings and you'll find sidewalk in there.

[00:38:55] So you're going to go to the Alexa app. You're going to open more and select settings and then your account settings and then Amazon sidewalk. And you're going to be able to turn it off. That's what I did. I think maybe that's what you should do as well. And I've got that in this week's newsletter. Make sure you sign up.

[00:39:15] Craig peterson.com/subscribe.

[00:39:21]This is amazing to me. I can't resist these types of articles where we're using technology to substantially help people. And we've talked about people who are locked in and what we've done, that we being the technology community to help them in various ways.

[00:39:39] Of course, you're probably familiar with Stephen Hawking, just a great intellect in the science field. It doesn't sound like he was such a great person otherwise, but that's another story entirely. And what's been done for him. We've been doing a whole lot of research on brains brainwave patterns.

[00:39:58] How can we interfere? What can we do? So for instance, it's something you're probably familiar with rush Limbaugh before he passed. You might remember he was losing his hearing. And that caused his voice to change because he no longer had the ability to hear himself speak. In fact, right now I'm sitting here talking into a microphone and I have headphones on so I can hear myself as well.

[00:40:26] I actually don't feel comfortable not hearing myself. Isn't that something right. Oh way back. When I first started doing video stuff back in college, I didn't want to hear myself. And now I have to, so I can keep quality control right on volumes and home speaking, making sure I'm not popping the microphone.

[00:40:46] Okay. And you notice that it didn't pop very well. That's good. Or a hissing NASA's and other things. So he had a harder time. Being understood because of this. And he got a cochlear implant. Now I've been paying a lot of attention to the inner ear lately because I've been having some issues with my inner ear.

[00:41:07] I even got one of those huge charts. Like you might seem the doctor's office, naughty ologist office showing all of the working parts inside the ear. It's fascinating. What happened with him? I'm not entirely sure, but I do know how a cochlear implant works and that is you have, in his case, I've surgically implanted behind his ear, actually behind and above his ear, a little receiver.

[00:41:37] And that receiver then sends electrical signals into ultimately the brain. So it does it through the cochlea, just like the normal world, but he had to learn how to hear again. He had to learn how to speak again, but he already knew how obviously, and so having that cochlear implant made a huge difference to him.

[00:42:01] And then what he did is he would hook up externally. On this receiver on, that was in his skull embedded in his skull a magnetic interface that tied into some external equipment that had the microphones and things. So he could hear very cool. I'm looking right now at an article from ARS Technica, John Timmer about this gentleman who was blind.

[00:42:27] Kind of still lives, but he was absolutely blind. He could tell that there was a little bit of light, but that's all he could tell. He couldn't make out anything. And they did a whole bunch of tests before. And after that, I'll share with you that are just phenomenal, but they were able to do all of this using an engineered virus and some external equipment here.

[00:42:53] So looking again at how our nerves work throughout the body, you might remember you've got these electrical impulses that are created through these ion channels, which let the ions flow in and out of the cells, but controlling the flow of these ions can really give us some more opportunity to do things.

[00:43:14] We couldn't do any other way. There's some channels by the way, that are made by bacteria and other organisms that don't have nerves, but that's not what we're going to worry about right now, but they've discovered the channels that only allow ions to flow after being triggered. By light of specific wavelengths.

[00:43:35] What that means when we're talking about light and wavelengths, we are talking about yellow or blue or red, right? Each color has its own frequency. It's own wavelength. So when you're talking about late wave length, you might be talking about meters. If you're in the ham world all the way on, down through nanometers, if you're in the computer world, but every light, every shade has a specific frequency.

[00:44:05] So finding these ions that were sensitive to specific frequencies was a huge win and light activated nerve activity. Of course is part of everybody's normal biology and it's being done in our eyes. And then it goes through the optic nerve to the center in the brain that processes all of that stuff.

[00:44:27] In fact, some of it's even processed in that nerve and then the eyes itself, but they have used a life light, sensitive channel and some specialized goggles that allows someone who is otherwise blind to be able to locate objects. So we're not talking about yeah, that is a yellow lab, but. As in an, a dog they're talking about being able to.

[00:44:53] Identify where objects are and they did some tests on it, which is very cool. So this research team in France engineered a virus to carry this light sensitive channel and they marked the virus with a fluorescent protein. So researchers could figure out which cells the viruses were actually infected.

[00:45:13] Dean and they injected it into the volunteers. I of course, completely blind. So he didn't mind were there. Some of these infected cells included the nerve cells that carried the information through the optic nerve and into the brain. So you see what's happening here now. So basically what he's doing is infecting some of these nerves so that they can become sensitive to this light where they weren't sensitive before.

[00:45:43] Which again, just very cool what they're doing. So these aren't the same as these fancy cells, the rods and cones and things that we have in the back of our eyes to sense light, but it did convert these cells and delight sensitive nerve cells. And this particular channel, not too sensitive, too much light it's primarily yellowish colors.

[00:46:06] So what they did then is they hooked up the computer to it. They compensated for it. So think about old movies, black and white movies, or maybe SEPA movies. And. They're really, there's very few colors involved in various shades of gray or various shades of way back when, so they use the computer to process the visual information from the goggles through the goggles to match the frequencies that he could see.

[00:46:38]Very cool. So when they were, when they sat this guy down and I'm looking at a picture of him with a one of those hats on, that measures all of your brain waves about when they sat him down, after some of his visual perception was restored. He was able to reach out and grab objects with a 92% success rate.

[00:47:03] Now, when there were multiple objects on the table, he was able to count them correctly over 60% of the time, which is phenomenal because you remember all they could do before was see, yeah, there is light out or there is no light out or it's a very bright light, right? Or there's no light. So it's very cool.

[00:47:23] And the authors of this study are suggesting using the viruses fluorescent tag to really help explore this more. What other cells could they in fact, do they need to use a different type of virus? What are they doing? So even though I'm not into virus and manipulation and gain of function research, I think this is absolutely amazing.

[00:47:47]So speaking of technology, speaking about some of the problems that we have a very big reliant on electricity. Most of us don't have big generators. I think frankly, most of us don't have generators at all. I do. I've had generators since I moved back to new England.

[00:48:10] 35 years ago or so 30 plus years ago, because we do lose power here. We get these winter storms that get nasty, even in the summertime with these big thunderstorms, the big wind. Sometimes they'll blow over trees they'll cause nothing but headache for all of us. So it gets to be a real problem. Texas had a real bout of that.

[00:48:33] You might remember they had major problems with wind generation and even some of their other plants. Nuclear dropped a whole bunch of megawatt generation and they. Really we're in a tough spot, but it's now come out that they were in a tougher spot than any of us really fought their days long power outages during February or deep freeze, it could have easily stretched out into weeks or even months.

[00:49:07] Thanks to a failure of what's called black start. Generators now, you and I, we have a generator. If we cut over to it, we're obviously disconnecting ourselves from the street power. And now we are switching over to our generator and most of the time the generators are big enough to handle a few circuits in the house.

[00:49:29] So maybe it's providing power to the pumps in your, and fans and your furnace. Maybe it's providing power to a few light switches or TV or things. Most people don't have huge generators. Like I do. I've got a hundred kilowatt, three phase generator here set up for the house, but I also have a lot of equipment at the house, a lot of equipment, but we won't go into all the details, but I can run the whole house on the generator, which to me is an important thing to be able to do.

[00:50:04] How about when the grid loses power? How about when a plant goes down, whether it's burning things like wood waste products nuclear or gas turbines. Even of course we lose power from water generation plants. And what happens if those go out? What happens if the power? Cause we get a lot of power down from the LG projects up in Quebec.

[00:50:33] What happens if that power goes away? How do we turn it back on it? Isn't as simple as what we do in the house, because remember in the house, we're actually interrupting the power as we switch back and forth. And if much about electricity, That there is this sign wave, right? That goes up and down.

[00:50:50] And that side sine wave runs at 60 cycles per second, 60 Hertz. And that 60 Hertz signal gets interrupted when we switched from our generator to the street, because those frequencies don't line up. It has to be interrupted. There's other reasons as well, but for the home stuff, but it has to be interrupted because we are not.

[00:51:14] Synchronous with the power grid. Think about the power grid itself. All of the places we're getting power. We're getting them now from people's rooves, we're getting them from small windmills to large windmills were getting them from Canada in the form of DC that we have to then change over to AC and sync up with our power grids.

[00:51:38] There's still nuclear power coming from right out in the Portsmouth area, New Hampshire. We've got it all from a bunch of different sources and they all have to be. Absolutely in sync. If they're not, you're going to end up burning out some of these power generation systems and that's really a bad thing, right?

[00:52:01] You could melt wires. You're going to completely blow breakers and blow them in such a way that it's going to have to be replaced. Not just you blew it. And a trip Texas, who was in a position where they were just minutes away from losing the grid. Minutes five minutes or less. That's how close it came.

[00:52:24] Then their power. They were able to get some of it back and keep things going. But what happens when the grid fails and it does fail. Look at what happened in 2004 here in the Northeast, primarily affected New York city and New York state, but it did affect Connecticut as well as Rhode Island, parts of mass.

[00:52:46] We lost the grid. In order to get that grid back online, we have to synchronize everything. And that's what these black start generators are. And we have them in new England, ISO new England is the name of the grid that covers all of new England and they have all kinds of. Plans in place, you can get approved to be a black star generator.

[00:53:11] No, you and I aren't going to be approved. I'm pretty sure that cause the costs started about a million and a half and go up to about $30 million. But the idea here is these black start generators are extremely big generators and they are used to start synchronizing the grid. If the good word to go down, if it were to fail, we would start by having a black star generator that now is giving that 60 Hertz frequency that the next plant can start coming online and synchronize itself with that.

[00:53:49] And then the next one. And then the next one, that's why Texas is saying if we were to actually lose the grid, it would take weeks, right? Maybe even months to come back online. And that's because more than half of Texas is a 28 black start generators more than half of them. Which are absolutely crucial to bring a failed collapsed grid back online, more than half of them expected outage or experienced outages themselves.

[00:54:21] That's according to a new report by the wall street journal. So of the 13 primary generators, nine encountered trouble as did six of the 15 secondary generators acting as backups in case the primary backups failed. Now, why did they have problems while some had trouble getting fuel to run? Think about diesel, right?

[00:54:44] It gels up in cold temperatures. I don't know if they're using number one or number two down there, but they had problems getting fuel to the generator. Others were damaged by the cold weather. Think about the cooling systems for these big honkin generators. And they really had some serious problems.

[00:55:05]Very big problems. Here's a quote from Evan Wilner. He served as Delaware's public advocate for utility customers. He said having had experience for almost two decades with utilities, it's genuinely inconceivable to me, even in today's re massively deregulated environment. I cannot imagine how any oversight got itself into this position.

[00:55:31] And I have to agree with that. It would be absolutely terrible. Think even about the utilities now they're not generating money now. Of course they don't really care because most of the time, these public utilities get to keep it percentage of their costs. So the higher the cost, the happier they are because they get to charge you.

[00:55:51] More. So just before 2:00 AM is a frequency drop to 59.4 Hertz where we're supposed to be 60. And then to 59.3 Hertz grid operators began shedding load. In other words, they were cutting off power to portions of the grid, which reduced demand and brought the frequency back to the target. Of 60 Hertz. So if they've been unable to bring a back up power plants would have been forced offline to avoid damage to their equipment.

[00:56:21] As I had just mentioned, and I was speaking with someone who has some knowledge of this and new England, and apparently we are not much better off than Texas. We could have a massive failure of our grid.

[00:56:37]This is a concerning report. At least it is concerning to me and it should be to everyone, frankly, but despite colonial pipeline to attack the likelihood of utility sector hacks has increased as was evidenced just this week.

[00:56:53]Colonial pipeline was a huge wake up call to some companies. Now I got to say, most companies still aren't doing enough. They don't think it's going. You're going to hit them, not going to affect them. It's just going to be too expensive to do it. We have one client who we have had now for more than 30 years and a big company.

[00:57:17] And we were protecting one of their divisions and their division here in the. U S was pretty profitable. In fact, it was one of their few profitable divisions for many years, and we had installed some really good cybersecurity equipment and software, and it worked so well that when the entire company worldwide got hit with ransomware, there was only one division.

[00:57:50] That was able to stay up and stay online. The rest of it, then they lost hundreds of millions of dollars because of it. The rest of the company went dark. They had to shut everything off. They had to try and recover just a total nightmare. And it's a nightmare we've seen again and again and again, and remember.

[00:58:09] These bad guys. Yeah. They may target some specific businesses or industries, but the majority of the bad guys that are sending out ransomware are just doing it in a haphazard fashion. And according to the statistics here about a third of businesses can expect to get hit with ransomware this year. It's really that bad, we're just sitting here, crossing our fingers, saying, oh, backups are going to cover it for us.

[00:58:39] And they might. But you've got to detect these things early and you've got to be able to do something about it. Our friends at colonial were hacked by a group called dark side and they have since gone dark, their main control systems for their web server. We're over on the dark web are apparently the seized by law enforcement, their money that was in their account and they made over $30 million is gone.

[00:59:11] It's hard to say. Was it taken by law enforcement as well? Which they do using cryptocurrency doesn't mean that no one knows what you're doing because they do. So it might've been seized by the government. We've seen that happen before. We've seen the secret service seize funds before, or it might have been taken by the bad guys and put into other accounts, but.

[00:59:36] I think it's almost needless to say those people from dark side may have shut down dark side, but they came from somewhere. All of them were expert ransomware people and they went somewhere. Just because they shut down dark side doesn't mean that they're not still out there trying to hack us. And I saw a 300% increase in ransomware last year and we saw about a doubling in payouts by businesses.

[01:00:04] It's real people. It's real. Yeah. And the same, thing's true for you as an individual. I want to remind everyone that if you look in this week's newsletter, I have instructions on what to do. This will stop almost all Russian malware. It's just incredible. It's fairly simple to do. And by doing it, it's 15 minutes max worth of work.

[01:00:30] Any ransomware that gets onto your computer. Will not install. It's really that simple. All right. So the key metrics that we're looking at when we're talking about cyber attacks have to do with the window of exposure, and that is a key metric that indicates. The exposure to cyber breaches for software applications, and specifically, they were looking in this white hat security, you report at the utilities sector.

[01:01:04] And they're showing that the utilities sector, the window of exposure increased since the start of the year. What does that all mean? Bottom line, it said that the colonial pipeline ransomware attack also expose the risks for vulnerable software and quick quote here from white hat application.

[01:01:27] Specific attacks are equally, if not more likely than ransomware. What they're talking about here is people attacking a specific application. One of the ones that we've seen a lot that Microsoft keeps warning people about is Microsoft's very own remote desktop. That's an application. It has had a lot of security problems and they are continuing to release patches and people aren't paying attention to it.

[01:01:54] And we, we see that all the time where there's. Patches that are out there. And yet companies aren't installing them. I get it. I, this week I took my own medicine. I have a Macintosh. That is my main computers from 2013. Yeah. It's that old it's coming up on. What we won't be long. It's going to be a decade old and I have not upgraded the software on that Mac now to the latest release.

[01:02:23]Apple came up with big Sur and I hadn't upgraded it. So I bit the bullet. Cause I've been complaining about Microsoft. You might've seen it if he listened to my podcast, which you can get by going to Craig peterson.com/itunes or. Craig peterson.com/podcast. So I posted a podcast this week, where I was blaming Microsoft for these hacks and the reason I'm blaming Microsoft, isn't so much that they have bugs in their software that bad guys use.

[01:02:56] Consistently use. That's not why I was blaming Microsoft. Although I'd love to see them pull up their socks, spend some of those billions of dollars in cash that they have spend it on tightening things up a little more than they have been, but they have been doing some tightening up. Kudos to them for trying to do the right thing at last.

[01:03:16] So they've been trying to tighten it up, but here's why blame them. People are afraid to do upgrades and updates. And I can't blame people for being afraid of it. When you get right down to it, you look at it and say, wow, if I upgrade my windows machine, is it going to break my machine? In other words, will my computer become useless and I'm going to have to re-install and re-install all my software, right?

[01:03:44] That's always a pain or hopefully I have a backup and try and re-install from the backup. And that's why, when we're doing backups for businesses, And we actually have a backup that we can spin up in a virtual environment. So it's part of that ultimate business recovery that you need to be able to do to be able to survive something like a fire in the business or a major hack, et cetera.

[01:04:11] So that's part of what you have to be looking at. And people are looking at it saying, oh my gosh, the last time I did an upgrade, everything just went to pot and I can't blame them. Cause that happens. So I said, forget it. Big Sur is a big guy grade for the Mac. I'm going to do it. And I did it and I've got one problem.

[01:04:33] I just finished doing, I got one problem and got her resolve after the show today. But I ate. What does that make my own advice there? Go and did an upgrade. But I understand why you don't want to do an upgrade when they're talking about here, these white hat guys, application specific attacks.

[01:04:54] Think about it. How many of us, I'm sure. Every one of us, you could raise your hand right now and say, yeah, I don't want to upgrade windows because I'm using this program I've been using for years. And if I upgrade that program's no longer going to work. Who couldn't raise their hands. To that.

[01:05:13] And I can't blame you for that. And in many cases, if you're going to do an upgrade to new version of windows, you have to buy a new version of that software. You've been using whatever it is, right? Yeah. We have a customer who just this week we had to come in emergency do upgrade. So QuickBooks because their QuickBooks license was up and they could no longer licensed this older version of QuickBooks.

[01:05:41] So we had to come in and do emergency upgrades on their desktop machines and on their QuickBooks server to get it all done in time because somebody had been sitting on the license and all the information about it, but that's the truth. Isn't it. And the problem that Microsoft has created is we're all afraid to do updates or upgrades.

[01:06:05] And Microsoft of course, has been charging for them. At least apple hasn't been, some of them it's been charging for Microsoft has been judged for some of them. They haven't, but it's a real problem. So again, this report saying at least 67% of utility sector software has at least one.

[01:06:24] Serious exploitable vulnerability. That's up from 55% of the beginning of 2021. Solid. See that's five months. And the last five months. That is crazy. Yeah, two thirds of utilities. Software is vulnerable, serious exploitable vulnerability. So I really want to encourage everybody, whether you're a home user or utility, we fear public sector, private sector.

[01:06:56] Do what I did this week. Bite the bullet. And get a good backup of your computer and upgraded to the latest version of everything, of the operating system of all of the software that you typically use. And please go to the next step. Upgrade your firewall, upgrade your switches, but at the very least the firewall get something that's truly next generation.

[01:07:25] Get a top of the line as much money as you can afford and keep it up to date. I like the Cisco stuff, but there's some other pretty good stuff out there. Some people use Aruba networks. I'm not a huge fan, but they're okay. Some people on the low end. And we'll use a number of different just cheap firewalls, but get the ones that will keep themselves up to date.

[01:07:48] I'd like the Muraki go. I made an offer on that last year. It was a thousand bucks for a firewall. That did segmentation a switch that could do the segmentation and wifi that gave you guests networks and segmentation, everything for grant. And I can figure the whole thing for them and help them get it installed.

[01:08:09] So something to consider. Get it done by somebody or do it yourself. This is the week to leave vulnerabilities behind. At least the vulnerabilities you can afford to miss, which is do the upgrades, do them right away and visit me online. Sign up for the newsletters you get all of the latest in technology, security, tips and tricks, et cetera.

[01:08:35] Craigpeterson.com/subscribe. Take care, everybody. Bye-bye.

View Details

[As heard on WGAN 2021-06-02-wgan. The following is an automated transcript.]

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. Thanks for joining me this morning. I was talking more about this Commonwealth of independent states. In case you're not aware of it, these are the countries that were part of the Soviet Union. Now not all of them are in it, but the majority of them are. And why are the hackers going out of their way to avoid hacking?

[00:00:25] It might be a red herring, frankly, but it also might be because there could be some severe penalties for them and how you can use that in order to help save you from getting hacked. So all of that here this morning, as well as a little bit more about the meatpacking plant that had to close down here throughout.

[00:00:49] North America. So here we go with Mr. Matt, Gagnan

[00:00:54] Matt Gagnon: [00:00:54] 7:36 on WGAN morning news. A good time to talk to Craig Peterson, our tech guru, who joins us at this time every Wednesday. Of course, you also hear him on Saturdays at one. When he talks about all these topics and more in more depth, Craig, how are you this morning?

[00:01:12] Craig Peterson: [00:01:12] Oh, WGAN is always a good time. Not just when I'm on, I'd do a little something extra,

[00:01:17] Matt Gagnon: [00:01:17] a little something extra. Thanks so much for joining us here. Of course, for that little something extra right now, Craig Peterson, I do have to ask you first about. Meat hacking. I've been plugging it all morning here.

[00:01:30] Obviously, we had the oil pipeline hack. Now we have beef plants forced to shut down because of a cyber attack here. So these cyber attacks are happening with increased frequency. And are a problem. Tell me, sir, what's happening here and what it means for us?

[00:01:45]Craig Peterson: [00:01:45] We have a whole crew of people internationally.

[00:01:49] Some are in Russia, some are in China. Of course, we've talked about North Korea and others before who are trying to make money. And the way they can make money is by going after targets that are particularly rich that have the money to pay the ransom. And that's why they're going after these guys. It's like Sutton. Why did he Rob banks, supposedly? Because that's where the money was. And in this case, that's really what they're doing, Matt.

[00:02:20] Matt Gagnon: [00:02:20] It certainly is where the money is, and they're happening with, it seems like greater frequency or at the very least greater visibility because they're going after big stuff here.

[00:02:28]Do you expect this to continue? I know that there's been some talk hereafter the pipeline attack that we're going to reinforce our infrastructure and make sure things like this don't happen again. Any truth to that.

[00:02:37]Craig Peterson: [00:02:37] Yeah, there is there, there's a number of things that are going on right now to try and tighten things up.

[00:02:43] But I've got to say this JBS, which is the company that was attacked here, this meatpacking company, that basically a quarter of all of our beef and a fifth of all of our poultry is packed to there. They responded pretty darn well. They didn't, obviously, keep the hackers out, but nothing is a hundred percent.

[00:03:05] They immediately did something thing that solar winds took a not soldier cringe, but were a colonial pipeline, took a little bit longer to do. And that is, they shutting me down very quickly. Yeah. They started to look, see what was going on. They immediately brought in a team of people. This is what they do.

[00:03:25] They help bring companies back from a ransomware attack. They brought in a lot of people, so they could start restoring all of the systems. It looks like from backups and then starts turning things back on one at a time. I imagine they'll tighten up some of their security operations, which we. All need to do, which goes right into your question of are we going to do more?

[00:03:49] Is there more we can do? And the answer to that is absolute. Yes. Every one of us, that most of the time the bad guys are using what is called zero-day attacks initially, which means there is a vulnerability in something very often in Microsoft windows or in a firewall. And the bad guys know about it, but it hasn't been patched yet.

[00:04:15] But I got to tell ya that is only really used against these very big operators where there's a whole lot of money involved. Most of the time, we're getting hacked. Because we haven't patched. Now I know how painful it could be the patch. Okay. Especially when we're talking about Microsoft, you can apply their patches and then brick to your machine.

[00:04:38] In other words, turn your machine into something that's almost useless, and it's going to take you days to recover. So people are weighing that back and forth. Is it worth, potentially knocking myself off the air for a day or two or three? Because the patch was bad from Microsoft or from another vendor, or should I do the patch and take the risk of it not working very well or may be causing harm and then going further, I blame Microsoft budget.

[00:05:09] You blame

[00:05:09] Matt Gagnon: [00:05:09] Microsoft for a lot of things.

[00:05:11] Craig Peterson: [00:05:11] Greg terrible company. They really are. They're the things they've done to the industry, but the reason I'm blaming Microsoft here is, are you kidding me? They're sitting on billions of dollars in cash, and they released patches for their buggy software. Okay. I get that.

[00:05:27] Everybody releases patches, and the patches break systems. So people don't trust it anymore. So that's how I'm looking at it. Here. I read an article this morning from the New York times, and they were looking at this hack from a again, probably, maybe Russia, maybe China. And they're quoting, they're saying.

[00:05:50] President Biden says it's from Russia reading between the lines. Microsoft said their hack, which was the major part of the whole SolarWind attack was actually from China and the Biden administration went quiet on this, but it's hard to say we know Russia has been hacking a lot. We know China's been hacking a lot of little China's more behind the scenes.

[00:06:12] We don't really know where they come from, but Matt, we can do something about it. Keep your software up to date. If you can, don't use windows and switch over to a Mac, their patches work, and they have for years and be more security conscious. So

[00:06:30] Matt Gagnon: [00:06:30] speaking of Russian hackers, Craig, I do have to ask you whether or not there is something we can do a one weird trick, if you will.

[00:06:37] One of those eternal click baity items area, right? If there is one weird trick to stop these Russian hackers right there, out there, how do you do it?

[00:06:46] Craig Peterson: [00:06:46] This is the coolest thing ever. It's absolutely true. This comes from Brian Krebs and a few other people out there right now. There is something you can do right now.

[00:06:56] It only take you 10 minutes, maybe 15, and we're here. Here's what it is. We know that the Russian hackers are not. Attacking former Soviet territories. And the reason from that it, for that is if they are hacking from Russian territory and they hack a Russian company or another one of these companies that are part of the Commonwealth of independent state, which is again the former Soviet union for the most part if they hack a Russian company, they, and they get caught, they get to go to a Russian prison, which doesn't sound like much fun to me.

[00:07:35] And so what they've done is they've built into almost all of this soft, where a kill switch. We're talking about ransomware software, hacker software. If you install a virtual. Russian keyboard on your computer, just like a, you may have a Spanish keyboard or a French keyboard on your computer, install, a Russian or one of a few other languages keyboard on your computer.

[00:08:01] You don't have to use it. You don't have to type in rush and you don't have to learn Cyrillic. None of that when the software starts to run in your computer, almost all of it. The first thing it does is says, is there a Russian keyboard? And if the answer's yes, it's short circuits at shelf, and this is what we're thinking.

[00:08:21] And I think this is right. This is the way the Russian hackers are avoiding attacking Russian or Russian Commonwealth states is Commonwealth of independent states. It's a way they're stopping the inadvertent hack of a nation of a company that might end them up in Siberia because they still do have some fun stuff going on up there.

[00:08:43]Matt Gagnon: [00:08:43] Greg Peterson, our tech guru joins us at this time every week to go over the world of technology. Thanks Greg, as always good luck on Saturday. And we'll talk to you next week, sir. Hey, you're

[00:08:52] Craig Peterson: [00:08:52] welcome. And I'm going to put instructions on how to do this in this week's newsletter. So make sure you're signed up@craigpeterson.com and we'll talk a little bit more about it as well on Saturday.

View Details

[As Heard on WTAG, WHJJ, and WHYN 2021-06-01. Automated transcript follows.]

Craig Peterson: [00:00:00] Good morning, everybody doing well this morning course, Craig Peterson here, and I was talking this morning about two different things. One, and this sounds like one of these marketing things in part of these ads, right? One weird trick while I got one. This is amazing. This is from Brian Krebs and it is a trick that will stop most, if not all, frankly, Russian based.

[00:00:28] Ransomware and even hackers. So we went into that. I'm going to put more about that in my newsletter this weekend. So make sure you are on that list. Craig peterson.com/subscribe.

[00:00:42] And we also talked a little bit about this newest hack against the largest meat company. In the world, if you can believe that.

[00:00:53] Absolutely huge. So both of those of this morning with Mr. Jim Polito, here we go.

[00:01:01] Jim Polito: [00:01:01] Hey, this guy is on top of it all. I'm talking about our tech talk guru, Craig Peterson, and nobody. Smarter than this man. And he joins us now. Good morning, Craig. Hey, good morning. It's Jimmy P how you doing? I'm good, Greg. Thank you.

[00:01:20] Hey, can I just, I want to ask you about this simple trick that will stop most Russian hackers. And it's not hiding a bottle of vodka somewhere. No, the it's about Microsoft. I want to ask you about now that now what ransomware and a meat packing facility. So they went after power grids. They went after water.

[00:01:43] Now they want to go after our food. They're there, they went after the oil pipeline. They want meet what's this all about. They really are what we're talking about right now. The major organized hackers. So the guys that have gotten together that are working together that really want to go after targets that have money.

[00:02:06] Yeah. And even though those say things like we don't, I want to really affect the us economy. We really don't want to hurt people. That's what it tends to do in this case. This is a big company. It headquarters in Greeley, Colorado. At least the us headquarters are, they are both. They have operations in new, excuse me, new north America and Australia.

[00:02:30] And they noticed it. Now this. Is a beautiful example, right? There is nothing, 100% effective against a determined hacker. However, they noticed that what these hackers were doing. So they took the name of it is JBS USA. So world's largest meat supplier. They took immediate. Action. They automatically suspended all of these it systems and other systems that might be effected.

[00:03:02] They immediately notified the authorities, the FBI. That's what we do. Bri, bring them in as well. They brought in all of their it professionals that got them all together and they brought in some good third party experts like yours, truly. I tend to try and figure out what the situation was and how do we resolve it now it looks like it probably spread quite a ways inside this meat packing plant, because the company is saying that their backup servers were not affected.

[00:03:35] And they're working with an incident response firm to get the operations back as soon as possible. I think they're going to be back very quickly. But these bad guys are not gone. I mentioned dark side. These are the hackers that went after the colonial pipeline, probably part of the solar winds attack on and on.

[00:03:56] And they shut down that one operation, the dark side operation, but it also looks like. We may have been able to shut them down. We won't get it, all the details right now, but here's here's another side to all of this. We need to know when it's happening. So kudos to JBS USA. They knew when it was happening, they knew you and that's something by the way I'm working on, I'm actually starting a business.

[00:04:22] That's what it's going to do. I decided that's the most important thing, because people are not willing to spend real money on the right types of hardware, types of software, but let's look at what's happening on the network anyway, separate issue entirely. But the Biden administration.

[00:04:39] Refuses now to say that these dark side attacks and the the, what ultimately led to the solar winds and potentially colonial pipeline, they've been saying all along Russia, and now Microsoft came out and Microsoft is a company that the whole attack vector went through solar winds, which affected every American.

[00:05:04] Every one of us that attack because of the companies we deal with solar winds, I attack according to the byte administration came from Russia, or Russia. However Microsoft said we have confirmed it's China. And Microsoft has been saying that now for weeks. And we men president Biden was asked about this as was at a press conference.

[00:05:29]Jean, what Sakhi. And they say now nothing about it. They won't say that it's Russia. They won't say that it's China. If we don't know who's attacking, that's where it's coming from. And frankly, retaliate against them. We're never going to stop this. We're talking with Craig Peterson, our tech talk girl.

[00:05:51]I'm glad you're sounding the alarm and all this, and buying is going to meet with Putin. He's got a summit with Putin coming up within the next two weeks. It'd be nice if he would be on top of this. And say, just cut it out. Remember Barack Obama, when it went through the election hacking, he was telling a, but remember he said, I told Putin to cut it out.

[00:06:15]Yeah, exactly. But it's not potent. It looks like it's absolutely China. Yeah. All right. Great, lovely. Speaking of let's go back to Putin. A simple trick can lock out Russian hackers. You sent me this information. What is this? Yeah, I'm going to put this in the newsletter coming up on Saturday this week.

[00:06:38] So if you miss the details to make sure you get the newsletter, you can just get it on my website. This is absolutely true. You and I have talked Jim before about where the hacks are coming from and how we think some of these hacked are definitely Russian because. They're not attacking cause Dr. Stan Ukraine, all of these former Soviet countries, right?

[00:07:03]Yeah. They're there. They're taking care of their own. Yeah, they absolutely are. And they don't want to get in trouble either. Russia. Doesn't exactly take hacking lightly. If you have them or you hack one of their all-in guard buddies, they will come after you and you don't want to end up in a rush Russian prison.

[00:07:24] So that's the theory behind this. So here's the, this is simple, everybody. This is simple and I'll send you some links to it. All you have to do is install what are called a virtual keyboard on your windows machine. So for instance, I'm, multi-lingual I speak English and I speak French. Yeah. So I, cause I, my, my schooling was in print schools, so I have installed on my computer, a virtual French keyboard, so I can say, okay, now I'm going to be typing a note off to my friend over in Paris.

[00:07:55] And so I am going to now do an overlay on my keyboard. And so now I can use all those funny accents as things are French, too. So here's what the trick is. They look this nasty where most of it, most of the ransomware goes ahead and look to see if you have a. Russian virtual keyboard installed.

[00:08:19] Oh, okay. Yeah. Yeah. So it looks for some other languages to Ukrainian Belarusian, to jock and Armenian and some others, but Russian keyboard is the easy one. So here is a work around from getting hacked by some of this ransomware installed. A virtual Russian keyboard on your computer and what'll happen is if it gets the ransomware on it, the first thing it does is it looks to see, is this potentially someone in the Commonwealth of independent states, which of course are the former Soviet territories.

[00:08:57] And it's also, if you have a Russian keyboard, it will immediately stop what it's doing. Wow. That's simple. Yeah, that is cool. I'm sure they'll find a workaround, but in the meantime, that's pretty cool. How do you, no, it won't stop at all right. But yeah, go ahead and no, how do you do it? How do you install the virtual keyboard?

[00:09:21]You can actually do a duck, go search on it and it will show you there. One of articles, but it's just, it's a virtual keyboard, right? So if you've, if you speak Spanish, you've probably got an English and a Spanish keyboard on your computer. You probably already know how to do it. It's really rather simple.

[00:09:38] You can go into the settings, you can load the Russian keyboard in your, and you're off and running. But apparently is according to the research I'm looking at right now done by mandate act and a couple of others. This will help you against almost all of them. So just a Cyrillic keyboard. You can also, there's a specific registry edits you can do.

[00:09:58]We won't get into that just to keyboards. All you have to do it. Duck, go by the way I have been using it considerably. And there is such a difference between searching on duck, go versus searching with Google. I should do a podcast and do a side by side and yeah. In the blog, put the pictures of just putting in, one, two words and seeing what you get for results in Google and then seeing what you get for results in duck, go doesn't use politics, which is great.

[00:10:32] No, yeah, it's it is very good. There's another one you might want to look at. It's called Quan, Q w a N T. But I prefer dark.co. Wow. Greg, this has been as usual. Illuminating. Fascinating. How goes the recuperation of your lovely bride? It's going quite well. She's very frustrated. I would be right.

[00:10:55] And she can't do anything, and she's just sitting there, but thank goodness we have one of these chairs that even injects you, which helped initially. But now she's starting to get a little itchy and I'm wanting to get up and go around and do things, which is a really good sign. So my fingers are crossed.

[00:11:13] Yeah, I think she'll do well. It was the femur, right? Even though humorous funny bone, the big bone in your arm, how much fall. Yeah. Yeah, because there's a ball on top while her ball was split completely into two pieces, it was looking at attached scan. It's just incredible. It was such a mass for the top of her arm, ended up in, down in her armpit and it was very painful.

[00:11:43] Yeah. I thought it was the leg. I'm sorry, but I'm glad to hear she's doing better. I'm sure she's going to have trouble going through a metal detector for the rest of her life. Yeah. So anyway, we'll give her our best and Craig, how do folks get in touch with you? Okay. So I'm going to send out information on this keyboard trick and it's simple trick, right?

[00:12:06] Just like a marketing line. Correct. But it really is. I'm going to send it out on this weekend as part of my newsletter, like I do every week. You get that by going to Craig peterson.com/subscribe, Craig Peterson, S O N. Excellent Craig, thank you as usual. And we look forward to talking with you next week.

[00:12:28] All right, take care. Thanks. Hey, when we return a final word, you're listening to the Jim Palito show your safe space.

View Details

[Following is an automated transcript of Week 1115 podcast aired 2021-05-29]

Craig Peterson: [00:00:00] We've got these semiconductor shortages. What that means is various types of chips are just not available and it's been hurting us all the way across our economy. And that's where we're going to start the day with today. Semiconductors.

[00:00:15] Man, this has been so bad, these semiconductor shortages, because what it means is we just cannot get the types of devices that we want because those raw components just aren't available. I was talking with a gentleman earlier this week and he was telling me how he has a special little app that tells him when there is a Sony PS five available for sale anywhere online.

[00:00:45] It's gotten that bad. First of all, Why does he want a PS five so bad? I've never owned one or an X-Box or any of those gaming consoles? Since the original Nintendo, we had a we as well. Cause we had all the exercise stuff that went along with the week. But anyways, that's a different story entirely.

[00:01:04] I'm sure a lot of you guys play a lot of video games, but. There really are not Sony available. And we're finding much the same problem in even the car industry where some of these major manufacturers here in the U S have had to shut down lines. They've had, gone from three shifts down to a single shift every day.

[00:01:30] And in some cases it's gotten even worse where vehicle manufacturers are only. Making vehicles of few times a week. It is incredible. What's been happening and there a number of reasons for it. This isn't just one reason, but it does bring up the real problem we could have with our critical infrastructure.

[00:01:53] How critical is it that we have computers that can run our businesses, drive our cars, and fly our airplanes. I think it's pretty darn critical when you get right down to it. Yeah. You can probably get an extra year out of that computer, if you really need to many times that computer's just plain broken, you just can't use it.

[00:02:15] So you do need to replace it. But in reality, we've gotten a little bit soft. We are not making most of the chips here in the U S anymore. Yes, it's us technology. But most of this is in Southeast Asia, particularly in Taiwan. And do you remember what's happening with Taiwan with the threats from China?

[00:02:38] China is flying over Taiwan right now with military jets in Taiwanese air space, because China has never officially recognized that Taiwan is independent from the people's Republic of China. And do you know how socialists are? They're just going to go ahead and take that land. What would happen if they did.

[00:03:00] Remember China really wants to get their hands on our top chip technology because that helps them in the military. It helps them with all of these facial recognition systems they have in China, the social credit systems that they have in China, by the way, all built primarily by us companies and sold to China to track their people.

[00:03:23] Including the nasty things have been happening with the Wiggers over there. It's just absolutely incredible as well as Christian communities and others in China. So all of this tech has stuff they want to get their hands on. If they were to invade Taiwan, what would happen? The Biden administration.

[00:03:40] There they've been a little soft on this. Unlike president Trump, who said, yeah, the Trump administration, we're not going to tolerate any of this. And the Trump administration shipped all kinds of military systems to Taiwan, so they could potentially defend themselves because we don't really want to get drawn into a hot war, but.

[00:04:00] Oh, if they had taken over Taiwan, they would now have access to the U S technology on chip making. Now let me explain what that means from a technology standpoint, the chips that we have are. into a wafer of silicone. I'm going to try and keep this pretty simple. And then, and that silicone is grown. Cause you think of a crystal or maybe think of a still-life tight or it's like titers to leg might that you'd find in a cave.

[00:04:34] Those crystals are grown. They're humanly grown, and obviously you don't want any defects in them. So it's very hard to do to grow them. And we need those crystals for all kinds of things, including these solar panels that some people are so hot to trot about. I, Hey, I love the idea. Don't get me wrong.

[00:04:52] It's just right now, again, with solar panels, like so many other things, don't think you're green because you. Are or putting up solar panels. You're not right. There's certainly other advantages to it, but you're not being green by doing that. But what really matters is how much power does that chip use in order to do a certain number of computations?

[00:05:17] And how much heat is given off by the chip. Think again about the old Edison light bulbs that we've had and still have in some places and those Edison light bulbs, by the way, one of the original ones still burning in New York city and the fire department after over a hundred years, that one light bulb just incredible.

[00:05:37] But think about that Edison light bulb, it gives off light. Sure. But it also gives off heat. And the same thing is true with. Anything electronic the movement of the electricity through that conductor or semiconductor create heat. Heat is a waste. That's part of the problem with Edison bulbs. It'd be one thing if they were giving off just straight light, the, but so much of that energy is used to generate heat that we don't want.

[00:06:06] And then we have to dissipate that heat somehow, but that's another story. The same thing is true. When we're talking about these chips, the chips have a resistance to them. In fact, that's what a semiconductor does. It provide some resistance, so that resistance is going to. Do what create heat. So you feel your laptop when you're running it and so hot to get over time, the laptops have gotten faster and have actually created less heat, certainly poorer computational unit.

[00:06:44] They created a lot less heat. What we're looking at now is if we can make these chips even smaller. We can decrease the amount of electricity they need, because it doesn't have electricity. It doesn't have to flow as far through the conductors or semiconductors inside these chips. So that's what the race has been over the years.

[00:07:09] The race has been how small can we make them? And by making them smaller, You're doing a couple of things. You're making them faster because electricity has to travel less distance. Even though electricity is really fast. When you're talking about a billion transistors inside one of these chips or more, you are traveling through a whole lot of conductor and semiconductor.

[00:07:32] So you can make that chip faster by making it smaller and you can reduce the amount of power it needs, because you're not going to be giving off as much power via heat and heat generation. And that's important for everything, but particularly important for our mobile devices. Look at your apple watch or your iPhone or your laptop or your desktop.

[00:07:56] All of them need to consume less and less electricity as time goes on. So what we're talking about now are just teeny tiny measurement. We're talking about nanometers. So if you go online, you look up nano meter. Which is a foul. Yeah, there you go. 10 to the negative nine meters. It's a billionth of a meter.

[00:08:21] Isn't that something looking it up right now, sell it a 1E-9.000000000. Give or take, and it's a unit of measurement that is being used now in chips and chip designs. And we're seeing these faster and faster chips getting down into the five nanometer process that is incredibly small, incredibly.

[00:08:49] Fast potentially, but likely incredibly fast and uses a lot less electricity right now. We're seeing seven nanometers out of Taiwan and we're working on five nanometer, but we have such a shortage of chips right now that they're bringing some of these old 15 nanometer. Chip fabs online, even 22 nanometer.

[00:09:14] I'm looking right now online at some of these old chip fabricators that are being brought online and China really wants to get their hands on some of this technology, because at this point anyways, they really can't get to the seven nanoliter chips. China right now. I think is pretty much limited to 14 nanometer.

[00:09:39] So we're still, I had in that race, but because they're being made in Taiwan, these chips that we're using here in the us using us technology, and because we had the lockdown in Taiwan and pretty much worldwide, the whole supply chain got interrupted and these big car manufacturers just. Shut off the orders.

[00:10:01] So there's no reason for the manufacturers to continue to make these things are a little reason for them to make them for the car industry in the current street, he thought we can just turn it back on and we'll have the chips. And of course they didn't, but it's also been compounded by the conditions in Taiwan right now.

[00:10:19] Because the Taiwanese centers for disease control this week raised it's epidemic warning level and is strengthening their containment measures and making things even worse. Taiwan is in the midst of a severe drought. So they are. Rationing water in Taiwan. They're looking at cutoffs of two days a week.

[00:10:42] And water reduction plans are expected to decrease supply to all major manufacturers by as much as 15%. So there you go. In a nutshell, that's why we care. Nanometers and we're talking about chips. That's why we need to start making them back here in the U S. And the good news, apple and others are doing exactly that.

[00:11:03] Starting to bring some of this technology back from Taiwan, into the U S and I think that's going to help keep us safer in the long run

[00:11:12]All electric vehicles are I think very cool. And some people give me a hard time because I am not a fan of it.

[00:11:20] If you think you're being green, because you're not. And I went through the whole science behind that the life cycle of an electric vehicle is much more. Dangerous and hazardous and polluting in the environment. Then even a diesel truck is just to give you an idea of small truck. So that's, let's put that aside, but in reality, these things I think are potentially the future.

[00:11:50] Now there's a lot of things we've got to take care of, for instance. Our electric grid is not set up for electric cars. Our electric grid is not set up for us to have windmills in our backyard or to have solar panels on our roofs. It's set up to have a main power station of some sort, whether it's nuclear, which by the way is green or whether it might be.

[00:12:17] Be coal or natural gas or wood or trash. That's what the grid is set up for. So we have some problems there and there's another big problem. And that has to do with how much power one of these vehicles can hold, because I don't know about you, but having a, what is it? The brand new car that came out a Fiat or somebody and his electric vehicle and its range is 78 miles.

[00:12:46]In some places that might be okay, but progress. The problem is I'll write, let's say I'll put up with stopping every hour to recharge these cars, unless it's a rapid recharger, you're going to be there for an hour and a half or more. And even with the rapid recharger, you're going to be there for a least 20 minutes.

[00:13:07] Now Tesla had some innovative ideas on how to deal with that. Like the, I don't know if you ever saw it a battery pack, so you'd pull into the station and it would just trade battery packs for you. The idea was it's right in the center. GM has this concept of the roller skate, where the entire car really is built into this frame.

[00:13:29] That kind of looks like roller skate. And then on top of that, Goes your car and there's some thinking maybe we can make it so that you can just swap out your rollerskate. Make it nice and simple and hopefully relatively inexpensive, but we still don't see the range on the vehicles. And as of yet, we haven't seen any huge forays by any of the big auto makers.

[00:13:54] Of course, Nissan had it to leaf, which. Pretty well accepted GM had their entry. And I chuckled because it was in a lot of ways. It was a joke. And of course they're up with better stuff here in the future, but I want to play a little bit here. I'm going to play about 25 seconds worth of an ad.

[00:14:12] And then we're going to talk about it a bit.

[00:14:16] Unknown: [00:14:16] It's got a targeted 775 pound feet of torque. It's targeted to go from zero to 60 in the mid four second range. It's a driving experience. That's pure unfiltered exhilaration from the moment you hit the accelerator. Oh, and it's an F-150 introducing the all electric F-150

[00:14:40] Craig Peterson: [00:14:40] lightning.

[00:14:41] So you noticed there were no mentions in there of no birds were harmed in January generating electricity here. And of course, a little tongue in cheek because of course birds are harmed in generate electricity, particularly windmill, but anyways, they're not going for the eco greeny. They're not going for the Prius driver.

[00:15:01] You remember the stats on the Prius where they surveyed the drivers of Prius's. This was probably five. Maybe a little more years ago. And the number one reason they found people drove a Prius. 70% of the time in fact, was they drove a Prius because of what they thought other people would think of them.

[00:15:23] So there they are driving this car that they're driving it for one reason, because they, I think it's going to make other people think that they're just fantastic people. I obviously I disagree with that. I think that's little bit of a problem, but what is what they're doing here with that Ford commercial is they are working on mainstreaming.

[00:15:46] Yes. Electric vehicles. Can you imagine this a 700 plus foot point foot pound torque in a sub $40,000 truck? It's just amazing. And you can even use the batteries that are in this truck. Of course, there's a lot of batteries in that truck to run power tools while you're out at a work site. Which I think is a great idea.

[00:16:12] And you can even use it to power your house. They have a special adapter you can use to hook up to your house so that you can get up to three days. They say of electricity in your house. If the power goes out, No mention in here of, any of these greeny things, right? Oh, none of oases talking points are in that ad.

[00:16:37] At least I didn't hear him on, did you guys hear them, but this is going to be amazing. This of course is Ford's best-selling vehicle, the F-150 and I drove one for years. It was very handy with the horses and chickens and everything here. And I'm looking forward to this thing coming out. I don't think I'm going to buy one, by the way.

[00:16:58] They've also got this Mustang mark II, which is this electric Mustang thingy. And then they have an electric transit van. And the reason I don't think I'm going to buy one is it just doesn't have the range. Now you can get better equipped lightening trucks in that sub $40,000 one. You can also go ahead and get bigger batteries.

[00:17:22] You can do a whole bunch of things, but this range is a combined output here, a 426 horsepower estimated range of 230 miles. And the extended range of this F-150 lightning is going to get an even. Bigger horsepower rating, 563 horsepower and an estimated range of 300 miles. And 775 foot pounds of torque, which is just stump polling.

[00:17:56] It's absolutely amazing. So I don't know about you. I'm not in the mode for pain, 60 ish grand for an electric truck that is only going to take me 230 miles. That, but maybe that's me. And then looking further into the stats on this thing, it can do a bunch of towing. It can have a 77, a hundred pounds of towing.

[00:18:22] You can get Reduce cargo, excuse me, reduce cargo course. If you're getting the bigger battery and looking at an illustration of the F-150 lightening, what they're doing is similar to what GM had proposed way back with the roller skate. The entire drive train is underneath the truck. And it's just like an old frame.

[00:18:44] You remember, trucks used to have frames now? The F-150 is, I think still do have frames underneath, but the whole bottom of the truck is one piece. If you will, obviously there's little pieces to it, but one major component and then the cab and bed and everything else just sits right on top of it.

[00:19:03] It's amazing. Now with this truck, if you connected to 150 kilowatt fast charger, you're going to get 41 miles in 10 minutes. So how long does it take you fill up with gas? Probably about 10 minutes. How long is it good for? It was my car 400, 500 miles in this case that 10 minute stop. At the fuel station is going to get you 41 miles.

[00:19:29] And if you can find the, just the 50 kilowatt fast charger, it's going to take you 91 minutes to get 41 miles of range. It's not there yet, but it's very obvious that Ford is aiming for the truck driver. And more particularly if I was a construction guy and I was taking my truck out and I needed to plug in tools and I don't have to drive very far.

[00:19:56] I look seriously at that new F-150 lightning.

[00:20:00]President Biden . I've got an article in my newsletter this week about what he's been doing when it comes to the hackers, China, is it Russia? What's going on? He's been blaming. It looks like. Russia for some of the hacks that China has actually been carrying out, but no matter what the bottom line is, we are getting hacked and this is a very big problem.

[00:20:28] We have to modernize our technology strategy. Because this ideological divide between these authoritan or authoritarians, whether it's a dictatorship like the socialists have in China, where you have chairman Mao, who is chairman for life now, or Putin. President Putin, who is president for life over in Russia.

[00:20:53]It's absolutely amazing. They are coming after us. And so is North Korea, of course, again, socialist dictator for life over there as well, Iran not so socialist, but a very fascist in many ways, which is typically a form of socialism anyways. We need to be able to protect ourselves. It's a real problem, frankly.

[00:21:18] 1947 world war two was over and George Kennan, R yeah. Kennan introduced this concept of containment and that containment concept was used throughout the entire cold war. And of course you probably know what that is. At least, excuse me. I hope you do. But today we don't have that cold war anymore.

[00:21:45] What is it that we have? Why would China be attacking this? We know, for instance, a China comes after our intellectual property and they w they come after it because it helps them militarily. If they know what we're doing, what we're ordering. What's going on that we know they come after us as well, because they want to cause some havoc.

[00:22:11] There's no question about that. Some of these other smaller countries come after us because they need the hard currency. Ultimately they want to trade in those Bitcoin for us dollars, which of course can be spent here. But. This whole system that we have right now is really on the brink of a new economy.

[00:22:34] Look at the technology we've been using. Look at the number of people that have been working from home. We're sitting on the edge of three simultaneous bubbles. Right now we have the housing bubble. We have the stock market bubble and we have the cryptocurrency bubble and we've seen downs in all of those just over the last week or so.

[00:22:56]We'll see what happens, but there's no denying that they're bubbles are home values adjusted for inflation, have not been higher than the last 100 years as an example. So there's a lot for us to look at. And when these bad guys are under the same types of financial pressures we are under, because, collapses tend to be worldwide.

[00:23:21] What are they going to do? What's ultimately going to happen? Here is what president Biden thinks should happen with these two executive orders that came out really It, it has to do with federal government supply chains. And that is people who obviously are selling to the feds. And I want you to think mostly about department of defense here, and we deal with the department of defense contractors and tightening them up.

[00:23:50] But in getting them to the point they should be at. And there's a lot to be concerned about it from that standpoint, but they have been releasing some details over the last few months, really. They started in April this year, and they're saying that because of the supply chain problem that we had with solar winds, they are now.

[00:24:15] Pushing out some rules that require the people who sell to the federal government to keep a certain level of cybersecurity. We've talked a little bit before about CMMC, which is. Again, it's a cyber security maturity model that's out there and they are requiring certain federal contractors to meet that.

[00:24:40] We've also talked about some of the NIST standards, which is the national Institute of science and technology. In fact, we talked about their password standard and how a year and a half or so ago, they changed the way we need to do passwords. And if you don't know what that is, have a look at my. A special report on passwords.

[00:25:02] And I go through that in some detail, but there's an executive order on American supply chains that came out in February and it's leaning pretty heavily on these newer emerging technologies, including secure access to semiconductors. And we talked about them earlier in the show today, the high capacity batteries.

[00:25:24] Because again, if we're not innovating. In the, you name it. But in end in the automotive field, we're going to fall behind what's important automotive. We just talked about it. Last segment here. Batteries. So it's covering batteries and materials that are used to create them. So they both of these orders address the need for us to really work closely together with our allies economically, as well as national security.

[00:25:55] But that's exactly what we've been doing. Isn't it? What it really boils down to in my mind is democracy versus authoritarianism. It was so funny that they called president Trump and authoritarian a decade, her right. He was liking to Hitler constantly. I thought if you brought him up, you automatically lost the argument.

[00:26:18] But in reality, now we're seeing more of a hands-on from the federal government more authoritarianism. And I got a question whether or not that's what we really want. Do we need a digital politic. This guiding doctrine, that places digital considerations at the forefront of our national strategy. Is this something that should be handled by the state or the businesses involved?

[00:26:47]We've seen all kinds of mixed. Pros and cons to each one of those strategies over the years, we know government controls, centralized government control, ultimately causes serious problems serious as in the deaths of over a hundred million people in the last century alone. So I'm not sure that's the best idea.

[00:27:09] And I have to say work. I With defense contractors, even not really a defense contractor, someone that makes something that's sold to a defense contractor. Having a one size fits all cybersecurity policy, a cybersecurity czar, and these executive orders pushing everything down does not make sense. It doesn't make sense for a real small company that makes a wiring harness to have to meet the same.

[00:27:38]Cyber security requirements as a big BAE systems, they don't have the time. They don't have the money. It can cost a million dollars over the course of three years for even a small company to meet these federal standards that are required. If you take a contract from the federal government or from one of these contractors.

[00:28:04] So you are a subcontractor, all of those requirements that are put on that huge military contractor, all of those requirements get pushed down to you. So this just doesn't make a whole lot of sense to me. I'm very concerned about it. There's a bipartisan bill. That's moving right now called the democracy technology partnership act.

[00:28:26] And they're trying to get some collaboration and innovation amongst democracies. I think it's good now that there are rules in place that have changed, that allows competitors to talk with each other when it comes to cyber security.

[00:28:43]Internet Explorer was Microsoft's first major foray into the internet browsing world internet browsing didn't really take off until almost the mid nineties. And it was really cool. I remember when I first started using. Web browsing and websites and building them with NCSA mosaic. Oh my gosh. Those were the days heady days back then.

[00:29:09] And we were just thinking about everything that could happen, how great it would be. And there were no hackers to speak of online. You didn't have to worry about drive by downloads or so many of the other problems that we have today. And Microsoft took that NCSA mosaic browser code base and created something.

[00:29:33] They called internet Explorer. Now the history of internet Explorer, frankly. Is rather interesting when you get right down to it. Internet Explorer. Yeah. It's been around for a long time, but in genetics, Explorer was one of the worst browsers out there for a very long time. It was just terrible.

[00:29:57] And one of the things that Microsoft did that really got. With the whole internet community upset with them is they built it right into their operating system. Absolutely. They used the code here from again, mosaic, which was this early commercial web browser back in 2003. It, the whole project started in 1994.

[00:30:25]I'm looking right now, Wikipedia. I remember these things happening. It's just nuts to think about how far it's gone, but they took internet Explorer and they bolted it into the operating system. So the operating system now supposedly was dependent on internet Explorer. Now it's an interesting concept to think about if all they have to do is maintain a user interface.

[00:30:51] That's web based for the operating system. That's really cool. Microsoft internet Explorer is some 5 million lines of code that is a lot of programming to maintain. And then on top of that, of course you have all of the user interface code that's sitting there in the operating system. So I think this is my suspicion.

[00:31:12] What Microsoft is trying to do is make their life a little bit easier. But by doing that by hard wiring in internet Explorer, into the operating system, they ended up making it so that other companies like the Firefox guys, Mozilla, they could not run independently on inch, on a windows. And a third party, like Dell could not decide, Hey, I don't want to use internet Explorer because Google's paying me to install Google Chrome.

[00:31:43] So I want to put Chrome on windows. So you just couldn't do any of that. So they got a whole bunch of flack. The industry came after them and because of that, so did the department of justice. And the United States versus Microsoft case, very fundamental. And it was absolutely, it was essential, I think because Microsoft never would have done anything about this, but they developed Microsoft this thing called ActiveX technology, which is a security nightmare and remains one to this very day where you could effectively as a website.

[00:32:25] Tell the internet Explorer to do almost anything you wanted to do. And there were bugs after bugs. I don't have a count. It might be interesting to see what the actual count would be, but it was, it had to be in the thousands of bugs that were fixed security bugs that were fixed and internet Explorer because of active X and because of some of these other things.

[00:32:48] So it's just been absolutely terrible. One of the questions I get asked most often to this day. What do we do when we don't want to use internet Explorer or more commonly, what is the best browser to use while I'm online? And the answer to that kind of varies. It depends, right? That's the answer, but as a general rule using Firefox is a good idea.

[00:33:20] Now, one of the things I like about Firefox for an individual or for a, an extremely small business, like a small office home office, where you're not tying into a corporate network at all. One of the things that's really good is Firefox. Uses a version of DNS, which is the main name, service. It's what your computer uses in order to find websites online, Firefox uses a version of DNS that is.

[00:33:50] Encrypted and protected so that your internet service provider cannot see the website names you're looking up and cannot intercept it. And that's the bigger thing. You don't want it to be intercepted because one of the major hacks, and this is affected millions of people. Homed and businesses.

[00:34:10] One of the major hacks is let's just go in. We can hack the router and then we'll change the router DNS settings so that it uses our DNS and our DNS by the way is great because it redirects you. If you think you want to go to bank of America, it takes you to bank of America dot China. Okay. A fake site, not a real site.

[00:34:31] And you may not even know. You may not even be able to tell unless you look really closely. So that is a big plus for Firefox as well as it has all kinds of anti-trafficking technology. Anti-malware technology built right in, they've just done a bang up job. The reason I do not like it for bigger businesses is that same.

[00:34:54] Feature that DNS feature because what we do when we go into a business, and one of the things we do is we change their DNS servers to use some commercial DNS servers that we have from Cisco that get updated minute by minute for the sole purpose of trying to stop the bad guys. And they're very good at it.

[00:35:16] It stopped being ransomware just by DNS. If you're using Firefox inside one of these networks, the problem is Firefox is going to try and hide the DNS request. So it was not so much as I care that they're being hidden, except that might be going to a malicious site. It said, I can't see any of them.

[00:35:36] And I cannot tell your web browser or your computer not to go to that website because that particular site or that particular internet server is actually malicious. So there's the two sides for Firefox. So if you're a regular little home user, get Firefox, it's free. It's a great little browser. If you are a business, you can still use Firefox with things like Cisco's umbrella.

[00:36:04] But what you need to do is turn off the DNS over HTTPS or TLS in which gets a little advanced. You can probably find it. If you'd duck, duck, go search it online. And that'll get you the answers you need. So turn that off so that all of your DNS requests are going through the filter, whatever it might be.

[00:36:24] A Barracuda has a DNS filter. I don't like Barracuda. Don't think I'm endorsing them, but it's better to use the Barracuda DNS filter. If that's all you have, then nothing. Let me tell ya. And then there are also free DNS servers that are going to be fantastic for you to check them out. I talked about them this last week.

[00:36:44] I got a lot of emails, open dns.com open ope, N D N S the letters, DNS domain name service, or. Dynamic name server or whatever you want. How are you going to remember it? Open dns.com and there it's easy enough. You just set it up on your ad drought or, and you're off and running. So that's my general favorite.

[00:37:10] If you want something that's more secure, you can take a look at our friend, the epic browser, epi C. It has been very good in the past, and I assume it's going to continue to be pretty good in the future. Microsoft's newest ed edge browser. I think there's been three different browsers. They call ed just under what Microsoft, they call them all the same thing, even though it's entirely different code basis. And what were there? Seven different versions of windows that were entirely different? I was just, ah, drives me crazy. The current version of the edge browser from Microsoft is based on Google's Chrome browser. So keep that in mind, if you're using edge, Microsoft is looking over your shoulder.

[00:37:55] Google may be looking over your shoulder as well. A little bit. The edge browser also uses Google chromium base, but they've gone through and Labatt itemized it pretty seriously. If you're on a Mac, you can even do this on a windows computer. The fastest browser, generally speaking is safari, which is an apple product and it's available for free S a F a R.

[00:38:18] I. And it also like most apple products doesn't like you being tracked. And so it has a lot of anti-trafficking stuff. Built-in. And it also not this too. The safari browser has a whole bunch of anti-malware stuff built in. So whether you're using iOS on your iPhone or I panned or Mac iOS or windows, you can get safari.

[00:38:46] And I had recommended that. So Fari frankly, is the browser I use for a little bit more secure stuff. And then I also use opera, the opera O P E R a browser. You might want to have a look at it as well, but if you're looking for ease of use and compatibility, I think you're probably about right. Sticking with the Firefox browser.

[00:39:09] I do use that. So I actually use all of these browsers in different circumstances. I also use the brave browser and others. I just don't want to confuse you guys. Firefox stick with Firefox and you're probably going to be pretty well off on rare occasions. Firefox is not going to work for you. And in that case, you might consider a Google Chrome or the edge browser.

[00:39:34] If you're using a cloud-based to service a website that is obviously a website for something you're doing. And it does not work with Firefox. It might not even work with the default on the Microsoft edge browser. And that's because that website might've been poorly coded, had not written right. And requires the old Microsoft engineer Explorer.

[00:40:04] If so you can turn on compatibility mode so that the edge browser will act just like the insecure bug ridden internet Explorer, but try and force the vendor to upgrade their site so that it works with modern browsers rather than having to stick with that old piece of software. That's dangerous as can be internet Explorer.

[00:40:29]I have always been fascinated by it ever since I saw people who were communicating, using computers and it, I always thought it just. It would be so wonderful if we could help people out, particularly people who are locked in who have a brain that's functioning fully, and yet their body isn't cooperating, they can't communicate, or they can't communicate well.

[00:40:54] And of course, that comes to mind. Of course, one of the greatest scientific minds of our generation, Stephen Hawkins, who was in a wheelchair, he was unable to move. And later in life, other than just a little bit with his face and mouth, and he used that to communicate. And it's just an incredible thing. I can't imagine being in a position like that.

[00:41:19] So when I see these technological advances that help people out, even in a minor way, I am just overjoyed, really overjoyed. So we've got to, I want to talk about right now. One is a brain implant that ARS Technica is John Timmer was talking about here about a week ago. And he was talking about robotic arms.

[00:41:42] Now you might've seen them before. There's various types of robotic arms and they have different types of functionality depending. Right. Well, one of the problems that we've had with robotic arms is how much force can you put on them? I, again, I remember the first time I saw someone who had lost, uh, the forearm and of course the hand and he had on one of those kind of captain hook things, appliances with a rubber band on it to close it.

[00:42:13] And he was able to pull one of the muscles in his arms in order to open it and close it. I thought, well, that's really cool. Those have advanced now, and there are projects with 3d printers. I forget the name of the company. I had them on my radio show. Maybe a decade ago now been awhile and they were selling 3d printers.

[00:42:34] And when you bought their printer, they would give you the plans to make a specific artificial prosthesis for. Child that couldn't afford one. So it might be for a leg or an arm or so I guess something else. And you bought the printer, they would provide you with the material that you needed as well as the design specifically for that person.

[00:43:01] And that you could print it up. It might take a couple of days and you ship it off. And many of these kids were in Africa. There are some here in the us, and of course in Russia, and this was, I thought an amazing project. It was just so cool again, because they're helping these kids get a little bit of mobility.

[00:43:21] Then we came out with some of these robotic arms that can be controlled through your brain. I don't know if you've seen these. Arms, there's been also some major advancement in just thinking about moving a cursor on a computer screen and the computer can track your brain enough to be able to move that cursor around.

[00:43:46] And basically what you're doing is you've lost a limb or you've lost mobility. You think about moving your hand or a leg, and usually it's your arm and your hand. And that can be picked up. Of course, that's per person, that's programmable per person. Then they figure out what the pattern is in your brain.

[00:44:06] And then they tie it all in so that now you can control a cursor on a computer, which means you can communicate. Robotic arms a little bit different because what you have now is something that can reach out. These things have all of the joint and the flexibility and functionality of a regular hand, except for.

[00:44:30] The feedback loop and that's been really important. How do you know if you are actually touching something? How do you know if you're squeezing it too hard? Like that egg and early robotic arms? It was very visual. So you watch that arm and you'd see, okay. It now has a grip on that ball or that pencil or whatever you pick it up and you all visual.

[00:44:58] And so you're able to pick it up and you know that you've got it. Maybe you don't know how hard you're holding it, but that's okay. You had to track the arm visually as you moved it around and estimate really when you had that grip, that was strong enough on the object by looking at it. And obviously that's just an incredible improvement over a missing limb or potentially paralysis, but it's not very intuitive.

[00:45:25] And the question is how do you make things intuitive for the brain when they're obviously foreign? We're going to talk about an extra thumb here in a minute too, but this is just absolutely phenomenal. It's called propyl. Yeah. Prope re O ception proprioception. And it's a sense that we have, this has been difficult to reconstruct that ties the sense of touch and pressure and.

[00:45:55] Knowing where something is. So you can close your eyes. And on the side of the road, when the police offers is there and close your eyes, hold your arm out and touch your nose. Right. Hopefully you can do that. I'm doing that right now, here in the studio. I'm touching my notes with my eyes closed with my arm, starting out fully extended.

[00:46:16] That's the sense we're talking about. That's very, very difficult. How do you build that in? Because we've been able to build in a little bit of sense of touch feedback for these arms, a little bit of pressure feedback, but we haven't been able to really understand how the brain processes, all this information that's sent by these sensory nerve cells in the hand, in order to let you know where it is.

[00:46:42] And what it's doing. So for this new research at team and planted two electrode arrays into the part of the brain that specifically handles information coming from the skin, and they're able to activate these electrode and produce the sensation of something, interacting with the Palm of the hand, as well as the finger.

[00:47:04] So they've made a whole lot of progress here, and this is very cool. They were able to tie it into a robotic arm. They got a study together, got some funding for it. And they got a participant who had been paralyzed from the neck down. And this doesn't save as male or female, but. Default gender right in English.

[00:47:29] As he sold, say, he'd been controlling this robotic arm for about two years by using brain implant in the motor control region of the brain. And he could successfully use the arm even without sensation. He'd gotten pretty good at it. Uh, so for these experiments, they had some different tests because they wanted additional, tactile feedback.

[00:47:53] They wanted to be able to somehow tie into this perception that your body has, of where your body parts are. Have you ever tried to tickle yourself? Usually it doesn't work. Right. But a third person or a second person tickling you may, it's definitely going to work. That's all party, these same systems. So they come up with a whole bunch of tests.

[00:48:16] I'm not going to go into a lot of detail on the tests, but they did say that having a sense of. Touch and the ability to understand where that arm and hand were in space, dramatically improve performance. And that makes sense. Hold on a sense to me, it w it really increased or decreased actually the time it took to pick up something to move something, to drop it in every case.

[00:48:43] So. I am pretty darn excited about this, and I hope it's going to be able to help a lot of people very, very soon. This is the university of Pittsburgh medical center, by the way, that's been conducting these experiments. Now there's another one I want to talk about. And I thought this was really cool. I saw this about a couple of weeks ago.

[00:49:02] I think it was, and this is a robotic extra thumb. What they did is they placed a robotic thumb on a hand underneath the little finger. So if you're looking at your hand right now, I got my left hand out in front of me. I've got my thumb here on the far left side. I've got my four fingers pointing up and on the right hand side opposite where your real thumb is, they put.

[00:49:30] An extra thumb, like a robotic thumb that can, can bend up and down and a little other lateral movements. This study, I think was phenomenal. And there were 36 people that were part of the experiment. This was at Danielle Clode, university, college, London, and her colleagues. Uh, and it's, it's phenomenal. So when we get back, I'm going to play a little bit of audio.

[00:49:57] That is from a story over there in the UK about this. I'm going to tell you a little bit more about this thumb and the. Impact to the hat on the brain. One of the things I think it was fascinating to me anyways, was it did change the brain in unexpected ways, basically the brains of these people. And this was determined by cat scans and watching the activity when they were moving their hand, the brains were changed.

[00:50:27] Two, if you will, uh, look at the hands and as more of a single unit than individual units. I thought that was really fascinating and that extra thumb became part of the brains understanding of the hand. So this is the kind of thing we can be looking forward to. Now, this one is it's kind of cool. It's kind of fun.

[00:50:53] We're going to find a lot of different uses for, and it's part of what's fun is what they did in the experiments. So we'll talk about that as well. Hey, I want to point out if you have questions about cyber security, I might have the answers for you and you'll get those answers in the form of some stuff.

[00:51:13] Special reports. I wrote, if you subscribed to my email list, just go to Craig peterson.com/subscribe, and I'll make sure I send them all to you and get you on the right track.

[00:51:25]this is augmenting a human and I think this is the future. We are going to be augmented. And how many movies have been made about that movies where they're saying model? Yeah, we'll just tie basically Google into your brain and have Google site into your brain.

[00:51:41] That have as a thought. And you'll get a response from Google, which I think is scary. Look at Google now and how they're tracking you. Imagine if they get a copy of every one of your thoughts, but things like this that make us super human. I think are going to become more mainstream. So Google, for instance, had the Google glass, you might remember that these glasses type things that you wore, Apple's done some work on something similar.

[00:52:11] And the idea is they can project in front of you an artificial reality. Maybe that our official reality is just telling you to turn left, to get to grandma's house or where the best food in town is. Or maybe you're playing a game. All of which are cool. This that's going to happen. This is really something that is going to happen.

[00:52:30] And it's going to talk to you with a set of speakers that are right on those glasses. And it's going to be, I think, potentially amazing not reading your brain, but helping you to navigate a, read an audio book to you, do all kinds of things, and you can already get Alexa. Which is, of course Amazon's digital assistant in a lot of different configurations from your car all the way on out through these little mobile devices.

[00:52:59] In this case, we're talking about a third thumb and that third or second thumb, I should say, it's really a third one because you have two hands, right? Two thumbs, but a second thumb on one hand. And the pictures I'm looking at from the experiment had it on the right hand. I don't think it really matters, but it's opposite your normal thumb.

[00:53:20] It's not a fancy thing. It doesn't look human. It's close to the wrist. W on your hand, but it still is on your hand and you control this thumb and how it moves based on why our wireless sensors that are on your big toes. So you wiggle the toe and you can move the thumb in different directions and also have it clench the grip.

[00:53:49] And these experimenters gave the thumb to people for about five days and the participants were. Told to use the thumb in regular, old things in the world. So they use it in the labs, of course, and they wanted the participants to really push the envelope about what was possible. And they didn't want the lab to just think of all of the different experiments they wanted the participants to think of things.

[00:54:17] Maybe they hadn't thought of. So I'm looking at a video that's really cool people think of this guys. You can hold a cup of coffee and stir it all with the same hand, because you use that third thumb to grab onto the coffee and then your right thumb and forefinger. In order to stir the coffee. I think that's cool.

[00:54:42] There were other people did things like bloom bubbles, right? You hold the little bottle of the bubble soap, water. And in the fake thumb. And then again, use your fingers to hold the little thing that you are blowing into. So it's really cool. And it did change the brain. What this showed us, I think more than anything else was our brains are capable of controlling limbs and dependence pended, GS dependencies.

[00:55:14] Yeah, appendages. There you go. That, that you don't normally have, and it leads him into think about cats here in the Northeast. I don't know if you've ever noticed cats with a thumb. Have you ever noticed that it's really a Northeast phenomenon? And apparently the captains of these old boats loved these cats because they could go on the ship and chase the rats and kill the rat and hold on really well in the heavy weather and even climb up on the ropes because I had a thumb, we had a cat like that.

[00:55:52] And it wasn't the brightest cat one, a Fox caught it when it was in our yard one time, but that cat could pick things up off the floor and using the thumb. Now, cats don't normally have a thumb, but some of these cats here in the Northeast, they have a thumb. It's a real thumb. They really can pick things up.

[00:56:12] So they, this experiment proved that we can, as humans control an appendage, like an extra thumb. So let's play a little bit here about what happened a little bit of the report. The

[00:56:26] Unknown: [00:56:26] additional thumb could cradle a cup of coffee while the same hands, four fingers held a spoon to stare in milk. While some participants use the thumb to peel a banana, blow bubbles, or even play the guitar to understand how the extra thumb effected people's brains.

[00:56:40] The researchers gave them an MRI scan before and after the experiments.

[00:56:45] Craig Peterson: [00:56:45] Is that cool or what. And you can find more online. I duck goat it, you can just duck, duck go a robotic extra thumb, and you'll be able to find the video and more reports on it, but we will see what ends up happening. With our appendages what are we going to be attaching to our bodies in the future?

[00:57:07] We know we are going to be using those glasses like Google glass. We'll see what it ends up looking is it going to project right? Enjoy your eyes. What's going to happen here. We're seeing heads up displays in our cars where the speed you're going, the maps, et cetera, are projected right on.

[00:57:25] The windshield. So you don't have to move your head a big direction, in order to see what's going on. So lots of stuff. And we're starting to understand the brain a little bit better when it comes to some of this stuff, dark side. My gosh a little bit of, a little bit about the dark web, because you guys are the best and brightest, right?

[00:57:47] So the dark web of course, is that part of the internet that was created to keep things secret. No, not totally secret, but the identities of people posting things on the dark web are hard to determine. And it is in fact, something that is maintained by our military and was developed in order to allow people in other countries to communicate effectively with the CIA, with the military, et cetera, without.

[00:58:19] Being caught by their government. So the dark web is a pretty secure place, but because of that, it's a place where people go to conduct illicit transactions. This is the place where the. The major site that was out there that it's called silk road was man, I can't remember how many billions of dollars they say went through the silk road website, but they were selling everything you can think of for drugs or drug running, a gun running some of these military weapons.

[00:58:58] you name it? I don't even want to talk about some of the stuff that was being sold there on that website. Now there's other websites and taken over, but we caught that guy by the way. And all the transactions were in between. Coin. So those people that think that Bitcoin is somehow impossible to track you are wrong.

[00:59:19] And those who think that the dark web is a place where you can go and really be anonymous. Again, you are wrong. More technically we're talking about something called the onion network, the Tor browser, and it is an interesting thing. So when we get back. We're going to talk about a court case, a really weird court case involving the dark web.

[00:59:47] You've heard before about trust amongst thieves, this kind of throws it entirely out the window, shall we say

[00:59:56]You might've heard of DarkSide. I mentioned them here on the show before. DarkSide is a bad guy, right? It's a group of people that got together who had been experts at ransomware. And so what they ended up doing is deciding, Hey, we want to make a business. We're going to do ransomware. And because we're so good at it, we're going to sell ransomware as a service.

[01:00:28] And this ransomware is a service. All they did was they would take a cut of what you made off of their ransomware. They do things like provide tech support. So you ran some poor guy, some poor, small business, and that small business now is, a really hurting and you say Pay up sucker.

[01:00:50] It's going to be whatever it is. I think most of the time for very small businesses, about $40,000 and you need to buy Bitcoin and you can't how to have a lot. I don't know. Why do I buy Bitcoin? So you contact. To the DarkSide, a webs support site, and guess what they do at that point? They can help you.

[01:01:13] Okay. So go to this site. This is what you're going to see. Click on this. They have little user guides. They will help you when you're encrypted. Do you just give them the key and they'll tell you, okay. So use this key and this software to decrypt it. Just like a real business bottom line. They disappeared.

[01:01:32] You might've heard about this. Of course, DarkSide attacked the colonial pipeline. And if you live in the Southeast United States, you were hit perk too. Darn hard by this, because that shut down over a thousand gas stations, they ran out of gasoline because it was not getting shipped via the pipeline. So off they went and a DarkSide said there, I think there's a little too much heat here.

[01:02:03] At least that's what we were thinking. Initially DarkSide was trying to avoid prosecution. And so they shut down their website. Where was the website? Obviously? Wasn't out there for you on DarkSide.com. No, it was on the dark web while they shut down. And apparently they were not paying out these people that they were providing ransomware services to.

[01:02:32] Isn't that kind of interesting. So Russian speaking person, you use the handle darks up for DarkSide support had XSS dot IIS. Guess what that is. Yeah, a recruiting site for these bad guys. Now, you're not going to be able to get there. If you're not on the dark web, you shouldn't be able to get there just in general, but he was trying to recruit him affiliates for DarkSide and DarkSide was the new ransomware as a service kid in town.

[01:03:05]And it was looking for business partners until a partner could come along and say I have a hundred million email addresses or. I'm going to go after a company X like colonial pipeline. And so they become an affiliate of DarkSide. And as an affiliate, now they can send out the ransomware, try and get somebody at colonial to click on it.

[01:03:29] And then once inside then DarkSide takes over and they go ahead and download important files from the machines that are compromised. That's part of the one-two punch that they were doing. And the punch that we saw that happened on Metro PD down in Washington, DC, where the bad guys got in down there and threatened to not decrypt stuff unless a paid up.

[01:03:57]And then secondarily, you said. Since you're not paying that ransom, pay us this ransom and you have so many days, or we're going to start releasing information from the private police records. And they actually did end up releasing some of that information. All of that sort of stuff is part of the ransomware as a service.

[01:04:16]This is interesting and DarkSide has made a bunch of money. There's some newly released figures from a company called chain analysis and they track cryptocurrency. Trading. Yeah. Guess what? It's not completely private. So chain analysis said the DarkSide netted at least $60 million in its first seven months.

[01:04:44] That's a small fortune. Actually that's a pretty big fortune 46 million of it. Came in the first three months of 2021 and Darkseid made another $10 million this month with about 5 million coming from colonial pipeline. You probably heard about that. Colonial paid the ransom. And I saw an interview with the CEO of colonial, who said we didn't know if we'd be able to recover.

[01:05:13] And it's basically, it's a small business, my words, small price to pay to know we can get back in business. So they made the 5 million from colonial and 4.4 million from the chemical distribution company known as Brenntag. And then last week, DarkSide went dark. And I mentioned that on the show as well.

[01:05:37] And this guy, dark sub said that his group had lost control of the infrastructure and it Bitcoin. Does that mean that maybe Interpol the S somebody shut them down because. We have verified that there was a huge transaction where all of the money was taken out of their bit coin account. Okay, so the servers can the access to anymore the hosting panels to see panels been blocked and the hosting support service isn't providing any information, except quote, you ready for this at the request of law enforcement authorities.

[01:06:25] Okay. Yeah. And within a couple hours of the seizure funds from the payment server were withdrawn to an unknown account. And Darkseid hasn't been heard from since now DarkSide is supposed to be paying affiliates 75% of ransoms that are less than $500,000. And that cut rises to 90% for ransoms higher than $5 million.

[01:06:55] So DarkSide gets the money, right? Cause they're doing this whole thing. It's a service it's service provided to the bad guys out there, but apparently these affiliates have not been paid. Apparently the ransomware as a service provider of did not honor its commitment and the affiliates, these bad guys, I feel so sorry for them.

[01:07:22] Not they've been asking to be reimbursed from a deposit about a million dollars. The DarkSide was required to make with this website X access, which is one of these sites on the dark web, where they are setting up these deals. Okay. So there's three posts on the site. Where there are plaintiffs who have filed charges against the defendant against DarkSide.

[01:07:53] So here you go, honor. Amongst thieves, DarkSide did not honor its financial commitments. It did not pay the bad guys. The ransomed people. Like they were supposed to they've disappeared and apparently their servers have been seized and all have DarkSides, holdings have been taken. All right. Interesting.

[01:08:19] That's what you get DarkSide disrupted gasoline supply for the huge swaths of the U S about two weeks ago. And no doubt, the FBI brought full force of its might onto DarkSide. And I also know personally that historically the secret service has gotten involved too.

[01:08:40]Electric vehicles. We've talked about a lot. I had a lot of fun talking about, of course, that great Ford electric vehicle in the first hour of today's show.

[01:08:52] And they've got some cool looking cars, but they're coming out of everywhere. Now. You've got Italy with a few manufacturers that are now right. Pushing out the cars GM of course has had them for quite a while. The volt Nissan has had theirs. Ford has a couple, including the Mustang, the new electronic Mustang.

[01:09:14] There is some good things to say about them. I love the technology myself. I prefer to have something that can go a long distance. I can't really have two or three cars right now. And they might make a nice little car. If I was commuting just a few miles or maybe if it was cheap enough, I would use it to run to the grocery store.

[01:09:37] But looking at the cost of these vehicles like that, that Ford pickup truck fully maxed out, fully loaded. I looked it up. During the break it's $90,000. That's crazy money. And even though it starts at 40,000, well $39,999 95 cents. Even though it's a $40,000 start. That's a lot of money to pay for a car is especially with these batteries, there's next generation stuff coming out.

[01:10:09] That's going to be just phenomenal. That's what I'm waiting for, but here's part of the problem. We're looking at electric vehicles and there's so many things to talk about, but electric vehicles do not pay the taxes that are used to construct our roads and maintain our bridges and our roads.

[01:10:30] There is a per mile tax that is added on by the federal government and by the state governments. But it isn't computed as a per mile tax. It's computed as an add on to the price of gasoline and the price of diesel. What they're doing is they figure okay your fuel mileage may vary. And they had a big hit, of course, when fuel injectors came into cars, because they basically doubled the fuel mileage, but they say, okay, so the average car is getting 20 or maybe 25 miles a gallon and his pain anywhere from about 50 cents to a buck, a gallon in.

[01:11:14] Road taxes and those road taxes are supposed to be used to build new roads, maintain existing roads and bridges by the states and by the feds. And again, that's a topic for another conversation. So how about electric cars? They're not buying gasoline, they're not buying diesel. So those vehicles are really putting a major dent in the road budget for the feds and the state government.

[01:11:46] We've got states like California, Massachusetts, and New York who want to completely phase out any fossil fuel vehicles by 2035 and Washington state plans to follow the California rules and phase out sale of gas powered cars by 2035. But there's a huge hitch in those plans. How do you have these electric vehicles, including that Ford F-150 lightning hit the road?

[01:12:18] Because gas sales will continue to decline along with the revenue from taxing them. It's a very big deal. So what do you do while there are some bills that have been moving in? All of those states had just named, including Massachusetts, where they're saying we need to charge people. Per mile when they're driving within our state, how do you do that?

[01:12:48] Charging per mile means, how many miles they're traveling? You could certainly set up something like easy pass that covers the major highways, but the major highways are not where everyone's always driving. Think of the state routes we're on all of the time that have no toll ability. And of course, all of the side roads, how do you tax it while there are things that say maybe we use an easy pass type thing only on the bigger roads and we're charging by the mile.

[01:13:21] That's just going to drive people off of those bigger roads that are meant for traffic onto the side streets. I've seen that happen before in my own town. There are other things that are being proposed that include having the car report on miles driven within a state. So the car would have to have GPS information would know when it has crossed state lines and then keep.

[01:13:51] Tabs on how many miles it drove in the state and

[01:13:55] then

[01:13:56] Craig Peterson: [01:13:56] report that to the tax authority for you to be charged. How would that be to have at the end of the year, right? This additional tax burden based on how many miles you drove. Yeah, that would be a lot of fun. And then there are other proposals while we'll just look at all of the vehicles that are registered in our state.

[01:14:16] So again, in mass it would be when you go in for that mandatory vehicle check every year at your birthday, we will read. Your car's mileage every year and we'll discharge you by the mile. They don't care if you drove up and down to Florida most of the year or out to Texas, or most of the year back and forth to California from mass.

[01:14:40]All of that would be charged against you. So there are a lot of debates going on to try and figure it out. How can we make this work? The feds have a gas tax that hasn't changed since 1993. So the federal gas tax is 18. 0.40 cents per gallon. And then you have the state taxes and most states have increased their fuel taxes since 2010 to beginning to, to bring in more money and fix the roads.

[01:15:15] But this is going to be difficult. Some states, including California, Hawaii, Minnesota, Oregon, Utah, and Virginia have implemented road, user fees. A lot of questions there. It's so easy to collect a gas tax. It's hidden away in the price of the gasoline. Are they just going to put an extra tax on electricity and say, the average home is using so many kilowatts for their cars and do it that way.

[01:15:43] We really don't know. We just don't know. And our roads I think, are going to suffer until we figure that whole thing out. We've talked about some of these big hacks. And I was talking with a client this week about the whole solar winds hack. And where did it come from and what did they do? The solar winds hack.

[01:16:07] It looks like came in through Microsoft exchange server. There are a lot of patches out there for exchange server. If you don't have it. Pay close attention, try and figure that whole thing out. Okay. It this is a very big deal, but these reasons, cyber security instances in incident are really a reminder to all of us that public and private sector entities are being attacked from nation state actors and these big cybercriminals, like what we were just talking about.

[01:16:44] Here's our big question, who was behind the solar winds hack. Remember we talked about it here. The reports coming out of the federal government in the U S were, that was Russian intelligence was to be hunted it's Poot and blame Puente. Oh no. It's a Russian. Hacker gang, nothing to do with Putin.

[01:17:06]Maybe Putin was, giving them a little bit of a nod, it was a Russian hacker guy, gang. Things have changed a little bit. They announced here, but Microsoft being there. Microsoft announced in March that a detected multiple zero day exploits being used to attack the exchange server and a hacker group that they dug half a numb, which operates primarily from least virtual private servers in the U S so think about that.

[01:17:37] And what does that mean least. Virtual private servers. That's everybody from GoDaddy through Amazon all the way on out. Everybody now has these virtual private servers and they also installed additional malware so they could get long-term access to these victims networks. Where do they come from?

[01:18:00]Microsoft wrote in March that half of them operates from China. And this is the first time we're discussing its activity. And he called the Chinese hacker group, Microsoft here, a highly skilled and sophisticated actor that primarily targets entities in the United States. For the purpose of exfiltrating information from a number of industry sectors, including infectious disease, law firms, higher education institutions, defense contractors, policy think tanks and NGOs non-government organizations.

[01:18:37] Now, cause I've talked about it before that we've been called into organizations and D found indications of compromise that were coming from China. And that's what it looks like. It came from a huge attack. It, it hit pretty much every one of our lives in one way or another through the companies we deal with.

[01:18:59] But the Biden administration has been silent on attributing the attack to China. They won't say the China was doing this at all. And they are completely blowing it off. Yeah. All of the questions about it. So it looks like it was China that did this. The Biden administration is unwilling to say it was China for whatever reason.

[01:19:25] They are very willing to attribute it to Russia. And I don't know, maybe this is another, yeah. Russia, like we've seen before. Hey, everybody, I want to invite you. Make sure you get my newsletter. When you sign up, I'm going to be sending you some special reports on passwords and what to do with your cybersecurity.

View Details

[As heard on WTAG, WHYN, WHJJ 2021-05-25 - Automated Transcript]

Craig Peterson: [00:00:00] On with Mr. Polito this morning, and we gave a little bit of a eulogy to Microsoft internet Explorer. Finally, almost gone. And I don't know if it will ever be completely gone. So here we go with Mr. Polito,

[00:00:17] Jim Polito: [00:00:17] Our good friend, Craig Peterson, nothing like a little rage against the machine. To introduce our tech talk guru, the master of all machines, right?

[00:00:33] He is our tech talk guru here to talk about the death of Microsoft Explorer. What is that? Joining us now? Craig Peterson. Good morning, Craig.

[00:00:48] Craig Peterson: [00:00:48] Hey, good morning. Microsoft Explorer of course had been used for years by Microsoft in order to let you go online. And it was the source of a major lawsuit against Microsoft.

[00:01:02]Right now you're talking about what's happening with this whole apple lawsuit and what directions is going to go what's happening? Microsoft had this major problem years ago, and that is. It did not have anything to do with the internet at all. Microsoft was a very much a late comer to the internet and to all of the connectivity that comes from it.

[00:01:26] And so what they did is they stole, borrowed some software from NCSA, this lab over in Europe. And use that as a basis to create a web browser. And since of course, Microsoft didn't really care so much about the internet as they never put much thought or work into it. However, Many of these kids that are doing programming thought internet Explorer is the way to go.

[00:01:54] And the people who were running the businesses who had windows on their desks, they looked at it and said in genetics blowers, what we need to do. So a large percentage of businesses over 50% of businesses designed their website. To work with internet Explorer and never bothered checking any other web browsers out there to see if they were compatible.

[00:02:19] Yeah. So Microsoft got even more and more into this and Microsoft added things to internet Explorer made it the most dangerous browser on the internet. It allows a website to take control of your computer. It allowed websites to download malicious software and start running with it. It might be Microsoft.

[00:02:41] It just sometimes drives me crazy.

[00:02:44] Jim Polito: [00:02:44] Let's roll it. You've just put a lot out there. So let's just go back and take a look at it. First of all, Dan and I were laughing earlier and you just said it. Oh, Microsoft didn't think this internet was going to be a big deal. Yeah. So bill gates is our real genius.

[00:02:59]Something comes along like the internet. Eh, so Netscape was really the big browser in the beginning. Am I correct?

[00:03:07] Craig Peterson: [00:03:07] It was one of the early Browns. Yeah, very popular one. The internet didn't really start really going anywhere until the browsers came out. NCSA mosaic was really the first one.

[00:03:22] Wow. I used that one extensively way back when and yeah. Firefox has been around. Yeah, Microsoft. Yeah. As part of an incredible internal arrogance decided that it would wire internet Explorer into the operating system, for lack of a better term, you could argue that Microsoft has never had a true operating system until the latest ones, but it hardwired the men.

[00:03:51] So now. You had places like Firefox Mozilla project and some of these other like Google, et cetera. Say, wait a minute wait. We have browsers. And there is no way to delete internet Exploder off of your computer. Oh, I forgot about

[00:04:09] Jim Polito: [00:04:09] that. Nickname, internet Exploder. Greg you're, we're talking with our tech dog guru, Craig Peterson.

[00:04:15] We're having a little bit of a way care. He's performing the eulogy for internet Explorer. So they get rid of it. Does that mean that Microsoft is out of the browsing business?

[00:04:27] Craig Peterson: [00:04:27] Oh, I never very big way. See Microsoft decided that people fought that Microsoft was it, they're the go-to people.

[00:04:35] And so they said we've got to get rid of, first of all, we've got to get out of the operating system because the courts ordered it. And so they finally did. And so now there's some competition in the browser space and then they came up with. The edge browser, you could still use internet Explorer on your windows, computer, and still came with it because so many websites were so poorly programmed.

[00:05:02] They would only ever work with this one browser. So they came up with the edge browser, which was their answer to everything. And of course it didn't work so good and it didn't work with most websites that had any complexity to them. And so they came up with another edge. Browser and they called it an edge because it was a completely different browser.

[00:05:23] And then they went and said, okay this just isn't working so well. So nowadays Microsoft edge browser is, do you have a drum roll? Oh yeah. Hold on. Hold on a second. I got it. Ready. Alright. Here Microsoft edge is actually Google Chrome. Are you kidding? There you go. No it's based on what Microsoft did is Google had open source.

[00:05:55] In other words, it made available the source code, the program, and they call the chromium and chromium is the base for for the Chrome web browser, Google Chrome web browser. Wow. So now Microsoft edge, the latest versions of edge, they have completely benched all of them. Terrible software or web browsers anyway, still got plenty left.

[00:06:19]And they are now, if you're running Microsoft edge, you are actually running Google Chrome and Microsoft of course has made changes to it and is tracking you in different ways. And Jen number one question I have from listeners really is. What browser should I use? And

[00:06:38]Jim Polito: [00:06:38] Your answer to the question?

[00:06:41] Craig Peterson: [00:06:41] Sure. It depends but Firefox. Wow.

[00:06:47] Jim Polito: [00:06:47] I haven't been I haven't been using it. Here at work, I use Chrome. I didn't use it on my home laptop Firefox. But I hardly use my laptop at home. Anymore, because I use my smartphone or my tablet to do most things when I'm at home. So that's all very interesting now let's move on to something that came up earlier and you made the recommendation, is that Jim start using duck go.

[00:07:20] For your searching because they don't track you and they have a better rhythms. They don't get political with their algorithms. You said, Jim, if you're going shopping, yes, Google is still the best place to go. But if you want information, it's duck go. This came up earlier because we've been discussing the power.

[00:07:44] That Google exerts in politics. And, there's real evidence that if you search for a liberal candidate for office versus a conservative, you're going to get. Better results of the liberal or the liberals results are going to be at the top of results, as opposed to a conservative and Google will say it's the algorithm, it's based on hits and bologna, people make out algorithms.

[00:08:12] The algorithms don't drop from the sky, right?

[00:08:15] Craig Peterson: [00:08:15] Yeah. You're absolutely right. Yeah. And there is no such thing as artificial intelligence, at least not in this day and age, but here's the, I, I mentioned this to you before I think, but here's that quote from a study that was done in a top on this is student news daily.

[00:08:32] But he was talking about a study that I read. We found significant pro liberal bias on Google enough, quite easily to have flipped all three congressional districts in orange county, California for Republican to Democrat. Okay. Very big deal. And that the study looked at the 2016 looked at 2018 as well.

[00:08:57] I haven't seen any good studies out yet about 2020, but Google and in you. And I saw this Google goes in and. Purposely makes changes to the recommendations, their search results. So you can look for a story and hardly find any evidence of it. And yet that story was covered by all of the major news agencies, NBC, CBS, MSNBC, CNN, you name it, they all discuss it.

[00:09:28] And yet you look forward on Google and it just doesn't show up. So you're right. And now the rhythm of a computer program is written by a person. Computers are not writing the code and there are biases in everything you and I would agree. We're bias, right? Thousands of articles, of course, thousands of articles.

[00:09:51] And I put together six to 10 of them every week that I think are important. That's showing some bias why you thought they were important. And that's the reason you're talking about things today, George foil, and then other things, right? Because you think they're important. And so that bias leaks out.

[00:10:09] And when it comes to Google and almost all of these big tech, not only does it leaked out, they enforce their bias on. You, which is why I recommend duck go. And then for browsers, Firefox Mozilla Firefox is a good general browser. There are some reasons not to use it. And I still recommend epic API C if you want very private browsing, if not, quite as good as it used to be, but it's also okay.

[00:10:39] Based on chromium. It's basically Google Chrome that they ripped. All of the tracking code out of epic browser.com is where you can find it online. Oh, this has been

[00:10:49] Jim Polito: [00:10:49] fantastic. Very helpful as usual and Firefox and duck go. And that is Craig's opinion, his well-educated opinion, but that's his opinion.

[00:11:02] Look. Greg, I've got an example for you, and then I've got to let you go, Kathy and I went to a museum. With the boys in New York city this past weekend and the museum, the it's called the Frick museum. It's right near the met and their location is undergoing renovations. They're actually in an old mansion.

[00:11:23] And so they're in a temporary location where they couldn't show their entire collection. So they picked from their collection. What they thought was best, the curator. Came up with what they thought was best in their opinion, in their collection. And that's exactly what Google people are doing, except it involves politics, not art.

[00:11:51] Yeah. Politics. And that's the issue I have with it. I'll take the opinion of a curator who will say, this is what we think is the finest in our collection, but not Google. No, not it comes to politics.

[00:12:06] Craig Peterson: [00:12:06] Yeah, absolutely. Yeah. And you're right, doing that doctor go by the way, you can set it as your default search engine on your Android device, on your iOS device, on your computers.

[00:12:18] You can, it's integrated everywhere. It's just not the default. Yeah. I think

[00:12:22] Jim Polito: [00:12:22] it's great. Craig, how is your lovely wife doing? How is her recovery going from her fall?

[00:12:27]Craig Peterson: [00:12:27] I am totally amazing. You saw the doctor yesterday. And she is only three weeks now, post-op emergency surgery and she's doing better than most of the patients had six months.

[00:12:40] Wow. So amazing. Yeah. She's, I'm doing amazing. That's great.

[00:12:45]Jim Polito: [00:12:45] The center. Our best. And then how do people get in touch with you so that you can send them while your best?

[00:12:52]Craig Peterson: [00:12:52] If you'd go to Craig peterson.com/subscribe, you can subscribe, get the newsletter. I'm going to send you a bunch of little special reports there, five to 10 pages telling you what to do to help make your life safer. All it's all free. Okay. I'm going to try to squeeze you for anything, but you do have to sign up and I'll send those to you all automatically. You'll get my, not quite weekly with Karen down newsletter as well. And you can also get links right there to the podcast, so you can listen to my whole shows on the weekend.

[00:13:27] Great.

[00:13:27] Jim Polito: [00:13:27] Craig Peterson everybody, our tech talk guru, Craig, I look forward to it talking with you next week.

[00:13:33] Craig Peterson: [00:13:33] You too, Jim. Take care. Thanks.

View Details

[Following is an automated transcript of show #1114 aired on weekend of 2021-05-22]

Craig Peterson: Hi everybody.Craig Peterson here. We're going to start out with a couple of Tesla articles in the news this week. These things are really not self-driving. I don't care what Tesla calls them and some problems people got themselves into.

[00:00:21]Tesla has had all kinds of news. And sometimes I wonder what is happening here?

[00:00:28] Is this Elon Musk, just trying to get a little bit more notoriety? I don't think so. Because there have been so many negative articles out there. One of the reasons I would be extremely hesitant to buy a Tesla has to do with the door handles. Something as simple as the door handles, you probably know for a decade, I was a volunteer in our emergency medical squad here and was doing paramedic work for anybody that needed it.

[00:00:59]No charge. I wasn't charging the town wise, but. It was something where I got to see a lot of accidents and sometimes I was first on the scene, beat the fire department there sometimes even beat the police department there, although there were normally their first because they're out on the road and I'm at home in bed asleep in the middle of the night.

[00:01:19]I saw, as you can imagine some horrific things and all of you guys that are first responders listening, you've seen some just terrible things as well. And one of the things that really bothers me about the Tesla are the handles. The door handles the outside. Door handles to be a little more specific.

[00:01:38] Tesla has had some amazing crash tests. I don't know if you've seen them, but these Tesla cars broke the testing gear over the national highway transportation safety board. They had to come up with new tests because these Tesla cars just. Took those crashes and did extremely well. And seeing what Elon Musk's company space X has been able to do with these rocket ships, they have mastered the art of having a computer kind of predicted.

[00:02:10] What is going to happen in various circumstances. So it wasn't a huge surprise for me to see that they said, Hey, yeah, you're in a car accident. One of these things that these cars were scoring at 11, a 12 out of 10, they were just that good. But the problem I have with that handle is exemplified by an attorney.

[00:02:33] I think he was out in Los Angeles, who was in an accident. And I remember in the Tesla cars and all of these electric cars, there are batteries. And the batteries are typically some form of lithium ion, and there's a lithium glass. That's under development, all kinds of cool stuff going on with those batteries.

[00:02:51] But the reason they're using them is that they hold a huge charge because you don't want to just go 79 miles on a charge. Most of the time you don't. One of the reasons I'm not real fond of electric cars is when I'm going for a drive, I'm going for a drive, right? We'll drive to Florida.

[00:03:10] We'll drive to the middle of the country. We'll go up to Montana to British Columbia. So a lot of people are saying, okay, so you just go ahead and you get a gas powered vehicle for that type of driving, and then you can use an electric car for most of your driving. So if most of the driving that they're talking about is the number of times I get into the car.

[00:03:31]Then that would work, cause most of the time or money into the grocery store or running an errand here or there. So an electric car probably would be okay for that now. I have gotten many times before into the science behind electric cars and how they are nowhere near as green as even diesel vehicles are nowhere near.

[00:03:53] When you consider the entire life cycle, the manufacturing all the way through how many miles you can get out of these things. But the concern with this attorneys' crash was that the batteries were damaged in the crash. And you can imagine what that means, right? You get rear-ended, you get hit in a certain way that battery pack is impacted.

[00:04:17] Things can happen. And our friends over at MythBusters back when they were still on TV, did a little test on this. They built a rig in the back of a garbage truck, because there were stories about these garbage trucks getting caught on fire and catching on fire. And the theory was while it's lithium batteries.

[00:04:39] And we're talking about small ones, they're the type that you have in a small cell phone. So they built a rig in the back of the truck, the garbage truck. And the strapped a lithium-ion battery to the front of this rig, which was a wedge, right? Cause they wanted to make sure that it bent and bending that battery now, cause day short, remember these batteries are designed to hold as much power as they possibly can.

[00:05:07]If you have a short circuit inside of battery, what's going to happen. Think about a, an old light bulb, the Edison bulbs that we had for over a hundred years, and those bulbs had a filament inside. And that filament, when it was heated up, what did it do? It. God gave us light and it also gave us heat.

[00:05:28] The heat is the problem here because our MythBusters friends were able to get that battery to ignite in that rig. And of course it ignites inside a trash truck. Remember trash trucks are always compacting everything. If it goes ahead and ignites inside that maybe you catch the trash on fire. In fact, they were able to get it.

[00:05:49] To catch on fire. And this attorney's Tesla caught on fire in the accident. Now, when you have passers by who see an accident, usually they'll stop and they'll try and help. We're that kind of thing. People were all good Samaritans, at least almost all of us. And I have no remember remembrance at all of it, a single car accident where I got there.

[00:06:13] And there was no one there. Sometimes it was just the police officer, but there's always someone who tries to stop. So these people who stopped to try and help this guy who was in his Tesla could not open the doors. And the reason was that the Tesla has these recessed handles. Yeah. They look cool. GM.

[00:06:34] A lot of the GM vehicles have had those handles over the years. And again, it's not something I would drive because of that. There's nothing to grab onto because sometimes in an accident you need to pry that door open and by prying it open, grab a handle a good solid handle and pull hard on that handle.

[00:06:57] And if you can pull hard on that handle, you can open that door sometimes if it's just that the frame's bent a little bit and you can get that person out. And in this case, that attorney was not able to get out of that car. That battery was damaged and the battery heated up and caught on fire. And we'll leave it at that.

[00:07:19] You can imagine what happened. So the Teslas have done very well in crash tests, but. They have not done well when the batteries are damaged in a certain way. And that's why I have a bit of an issue with it. But we got two articles in the news this week. This first one's from Reuters and that'll be in the newsletter that comes out on Saturday, but a Tesla driver was killed in an accident out in California.

[00:07:46] And this guy was one of these tick tock people, tick tock, that's that website where you can put up these short videos. And oftentimes there's a theme. There's a whole series of themes. People, post videos using the same music or whatever it might be. And he had posted videos on what a beard to be his Tik TOK account in which he was driving with this hand off the route, the wheel.

[00:08:14] Now you can obviously take your hands off for a second or two and almost any car. And I don't know that I would consider that safe, it, it happens and it's happened before, but he was posting these pictures and praising Tesla's self driving. In fact, he said full self-driving features. May 5th and Tesla model three crashed into an overturned truck on a highway in Fontana, California, if Southern California, nowhere Fontana is there.

[00:08:46] You might anyways. And that crash, of course, as I mentioned, killed the Tesla driver, injured the truck driver and a motorist who had stopped to help him. So again, we're seeing the problem with these self-driving features. And you might remember a few months ago, I was talking about a little study that was done.

[00:09:09] They made police cars out of a balloon. It was just a big blow up car. That was a balloon. And they put it part way in a lane, just like a police officer might stop someone and being partially in the lane. And then they had different self-driving cars or cars that had, the autonomous semi-autonomous mode the follow behind mode, et cetera, go down that road and see what happens.

[00:09:34] And they kept hitting the cop. In this case, we're talking about an overturned truck on a highway. And apparently Tesla got it wrong. The associated press was citing. The police saying preliminary investigation determined that the Tesla's driver assistance system autopilot was engaged prior to the crash.

[00:09:58] And. I've got a problem with them calling it an autopilot because it isn't, it's not like an airplane where you engage the autopilot and then you just keep a basic eye on things. People are treating it like it's an autopilot as in you can go to sleep. And when we come back here in just a minute, I'm going to talk about something just like that with another Tesla driver.

[00:10:21] So there's no final determination as to what driving mode the Tesla was in. But there's a couple of videos of him driving with his hands off the wheel, posted on his alleged Tik TOK account, 35 year old, Stephen Hendrickson running Springs in California, and a couple of quotes from him. What would I do without my cell driving?

[00:10:43] Excuse me, full self-driving tests. After a long day at work, he said, I messaged them. One of them coming home from LA after work. Thank God. Self-drive best car ever. So when we get back, we're going to talk about this a little bit more. What are people doing with Teslas and what should we be doing? Where are we going?

[00:11:05]Frankly, I think we're jumping the gun here. Hey, you're listening to Craig Peterson. You'll find me online@craigpeterson.com.

[00:11:13]And we were just talking about Tesla, my biggest fear with Tesla, the biggest problem as I see it, the reason number one reason I won't buy a Tesla. Which has to do with the door handles and not being able to use them to easily pry out a door and occupant of the vehicle because yeah, they're supposed to pop open.

[00:11:38] Yeah. They're supposed to open, but in this particular case I'm talking about, they just did not do it, which is a real problem. Very problem. The national highway traffic safety administration has been investigating. This is according again to Reuters, more than two dozen crashes of Tesla vehicles, including this Fontana crash and a high profile crash in Texas last month that killed two men.

[00:12:06] Since 2016, at least three Tesla vehicles operating on autopilot have been in fatal crashes. Two involving a Tesla car driving beneath a semi-truck in Florida. The U S transport safety board said Tesla's autopilot system failed to properly detect a truck as it crossed the car's path, contributing to the accident.

[00:12:29] Also caused by a lack of driver attention and an adequate driver monitoring system. Now you can't say three or four crashes of a Tesla where there was a death involved represent much without knowing how many miles are being driven. It's like people saying yeah, it's way safer to fly in an airplane than it is for you to drive your car.

[00:12:57] And yeah, if you're talking about miles driven, that's very true. The airplane is safer than the car and yeah, at this point it actually looks like these Tesla cars might well be safe for then a car operated by human. It is borderline. You could argue some of the statistics I've seen them argued both ways, but it's not a bad vehicle from, from the general safety standpoint.

[00:13:27] But as I said, we've got another Tesla story this week, and this is from a guy his name's param Sharma 25 years old lives out in middle California and in the Bay area. And he has been arrested twice and he was booked into the Santa Rita jail on counts of reckless driving and disobeying an officer. So what was happening?

[00:13:55] What was he doing? He apparently was driving his Tesla the back seat. Yeah. Yeah, absolutely. It's absolutely incredible. So this is an interesting one, too. This is a KTV you Fox two reporting. You said perineum Sharma met KTV use Jesse Gary in San Francisco, Wednesday afternoon. Not far from his mother's high rise apartment.

[00:14:24] After getting out of jail on two counts of reckless driving, he pulled up sitting in the back seat of a Tesla with no one. In the driver's seat when asked to be purchased a new Tesla after the previous one was impounded, he said, yeah, I'm rich as beep. I'm very rich. I feel safer back here than I do up there.

[00:14:46] And that was him sitting in the right rear passenger seat of his Tesla being interviewed by the Fox affiliate TV station there in San Francisco. It's absolutely amazing to me. And he's saying how he's been brake checked before, which of course is something way more in California than you would out here in Northeast where I live.

[00:15:11] And that's where somebody slams on their brakes. Who's in front of you. Cause they don't like what you're doing. And he says, Oh, my Tesla came to a complete stop. Tesla's CEO really knows what he's doing. I think people are tripping and they're scared. It's incredible. The police officer that had arrested him said that he was sitting in the rear seat driving quote unquote, the Tesla. And when the police officer pulled him over, he climbed up into the driver's seat in order to stop the car, the guy even posted a video. Saying, I just got out of jail already got another Tesla. You feel me? I'm rich like that. It came out of the pandemic, a beeping millionaire and some more swear words that I won't repeat here.

[00:16:01] So the CHP California highway patrol spokesman told Vice's motherboard. It's just a website covers a lot of tech. That it's recommending charges to the district's attorney's office and conducted a thorough investigation that will consider the possibility of previous incidents and pop, obviously his social media.

[00:16:21] So here's your problem. According to Tesla, autopilot is a hand on driver assistance system. It's intended to be used only with a fully attentive driver. And I mentioned some of the problems that Tesla has been known to have consumer reports has also reported. This is just last month that Tesla's driver monitoring system not only failed to make sure the driver was paying attention, but it also couldn't tell if there was a driver there at all.

[00:16:57] Obviously if it could tell there is a driver there, it wouldn't have been able to be driven, quote unquote from the back seat. Tesla's full self-driving system has more capabilities, but again, this is from Tesla, both autopilot and full self-driving capability are intended for use with a fully attentive driver who has their hands on the wheel and is prepared to take over at any moment.

[00:17:24] Cadillac came out with a system. I liked this idea where it vibrates. If it notices that you're not paying attention, it'll vibrate, your seat. Some of these vehicles will vibrate your steering wheel. Just wake you up. Hey, wake up. There's various levels of autonomy.

[00:17:42] Level five is. You don't need a driver at all. And Elon Musk says that he expects Teslas will be available at the end of this year, perhaps in 2022, that we'll have full what's called level five automation, which means they can drive without any human attention. The California DMV says the Tesla's director of autopilot software told regulators that Musk's predict and timeline does not match engineering reality.

[00:18:16] Okay. So again, the it's somebody on the marketing side, that's overselling things a little bit, or maybe a lot a bit. I don't, I really don't know, but. They do have permits in California to operate these vehicles in full autonomous mode, as long as there's human backup drivers. And I think it's good.

[00:18:36] I think we're moving forward and the investigations into these crashes are going to make us, I think, ultimately a lot safer. So let's say that there's a crash where the human at a wheel of a normal car they'll then investigate, they'll say it was at a human's fault. And then insurance companies kick in and payments are made maybe a driver's license is suspended or removed from that.

[00:19:03] Person, but when we're talking about an autonomous vehicle, like a Tesla, when they do the investigation and they find a flaw in the assumptions made by the programmers, their software, that's in the computer, that flaw. Is probably fixable, which means that type of accident will probably not happen again.

[00:19:27] And that's where I'm looking at it and saying these ultimately are going to make our roads safer. Cause hairy men make a mistake and Harry May not make that mistake again. But Mary May make that mistake when she's out driving. But if the slow car has an accident, they fix the problem. Teslas are probably not going to have that accent again.

[00:19:50] So I'm looking forward to this in the future on not sure it's going to be this year, maybe next. Make sure you're on my newsletter. Craig peterson.com/subscribe.

[00:20:01]I've been talking about this Tesla driver, and I just absolutely loved this. Cause I, I did a little searching on him. I went to duck, go and poked around a little bit to find out who is the sky, this Sharma guy who's driving from the back seat. And remember he says, he's rich as bleep.

[00:20:20] And so he doesn't care that his car was impounded. He just went out and bought another one. His money apparently comes from his parents who apparently were in the banking business. And then he Rose to fame during the whole lockdown because he was posting videos of him driving his Tesla. From the back seat and making all kinds of outlandish statements.

[00:20:48] That's how he got rich. And the rest of us, what are we doing? We're busting ourselves, trying to get everything done that we can possibly get done and hoping people notice, oh man. I guess frustrating. Sometimes every year. Verizon publishes some cybersecurity stats. And I absolutely love these.

[00:21:09] I pay attention to them. I read them from cover to cover because they are absolutely. Correct. This is their 2021 data breach investigations report. And it helps me to understand what's happening out there in the world. And of course I follow the news stories every week and it also lets me know information about the surveys that they have done with business owners and it executives and everything else.

[00:21:41] So they came out with some new stats I would expect. That there was a change because so many people were working from home. And to me it would seem obvious that with people working from home on computers, that probably are not properly secured, they're probably in properly using VPNs that we would see an increase in ransoms.

[00:22:08] Now we know that we did right. 300% increase last year because of people working from home and businesses, just not having things set up properly. And that makes sense. Cause most businesses, they, it's not their business to do cybersecurity. They're just trying to stay in business. I had a meeting this week with one of my clients, a longterm client he's been climbed for, I don't know, 25, 30 years.

[00:22:34] And it was interesting to me to get his perspective. In fact, it was very informative because I live and breathe this cyber security stuff. He doesn't, and he has. Concern about cybersecurity. It would be inconvenient to have ransomware in his mind because he has a lot of stuff on paper and I could maybe use the backups.

[00:23:01] Now we were keeping reminding him, Hey, you're doing the backups yourself. You don't have us doing them where we automatically, at least once them once a month. We start your systems from backups. We do that in the cloud. We have our own little cloud. We don't do this up on like Amazon or anything, but we do it locally.

[00:23:22] And that way we know the backups. Good. Because if we can start your machines up in our little cloud, we know that we got a good backup. He has never tested his backup. We had, we had another client like that. And when we picked them up as a client, we went in and they were taking home hard desks every day, religiously, just like this guy is.

[00:23:45] And so he they would take the desks, bring in Monday's desk, plug it in Monday morning and leave it plugged in all day. So the backup would go on to that desk. And then Monday night he would take that disc home and then Tuesday he'd bring in Tuesday's desk. Now there's a lot of problems here. One is they never tested it ever.

[00:24:12] And they'd been doing this for least 18 months prior to us getting there, because that was the advice or somebody, somebody said, yeah, all you have to do install the backup software and. Plug in your disc every week. So number one, it had never been tested, right? You got to test these things end to end.

[00:24:29] You have to do full restores, which they weren't doing. The other thing that is a problem with these USB drives is you plug them in. Are they really working? How many errors are on that drive? Are you even checking the logs from the backup software? So they had a server, in fact, in both cases and all that, I think of it, they had a server and it had a raid array.

[00:24:54] It had three drives and a raid five configuration. For those of you who know what that means. And basically what that means is you could lose one drive and you'd still be okay. So the idea is that drive goes bad. You replace that drive, you re silver the whole thing and then you're off and running again, so you can lose another drive and you'd be okay.

[00:25:18] But in both cases, both of these businesses had a bad drive in the raid array. And they didn't notice it. They didn't know. And at least in this other customer they had never ever checked to see if their backup was working and in the second customer. So in both of them, they never checked.

[00:25:39]And they said, so how much would you charge us to. Verify it. And we said we'd want to spin it up. And that means you have to copy everything. We'd have a bunch of bench time, so it'd be 500 bucks and we'll make sure your backups are working. Oh no, we can't. We can't do that. We can't pay them 500 bucks, so who knows still, we don't know if the backups working. They think that they could recover from paper, that ransomware isn't going to be so bad and extortion doesn't matter. My head just spins with this stuff. It really does. It just spins. So looking at the variety doesn't report that comes out the data breach investigations report, they are seeing that ransomware, phishing and web application attacks all increased during this last year.

[00:26:27] And they also found that 85% of the data breaches involved. Human interaction. So what that means is you and I doing some stuff that maybe we shouldn't be doing, and some of this human interaction is installing malware, right? From fishing activity, where they're sending out these emails. A day, doesn't go by where I don't get an email every day.

[00:26:56] I get emails that are saying what's the biggest one right now. I've been getting Oh, it has to do with some signature software. I'm not going to name them because I don't want them to get in trouble. Cause I got a decent software, but it's a big deal. Okay. A very big deal. So they're saying that the median financial impact or so do you know what median is mean?

[00:27:18] Median and mode? Median and financial income pact of a breach last year was about $21,000 95% of the incidences incident. Costs the businesses somewhere between $826 and $653,000. Okay. So many breaches they say did not cause losses. And those that did cause losses. This is where it really gets big.

[00:27:50] Okay. 95% of the computer data breaches led to losses as much of 1.6 million. So it's getting expensive. So what do we do? How do we deal with this? I talked about this before you need to improve your windows, privacy and security. You need to harden your windows. You need to get good firewalls. And I talked about it this week.

[00:28:14] Again, you need to use something like open DNS, which is, it has a free version. There are paid versions, but this is going to get you. A long way towards being safe, open dns.com. That's where you find them online. If you can't remember you can't run it down. Just email me M e@craigpeterson.com. Ask your question and I'll be glad to point you in the right direction.

[00:28:41]I was just talking a little bit about the Verizon data breach, their incident incidents report. And I wanted to just bring up one other bit of data. And that is that the attacks that are going on are actually simpler. They're not as complex as the old ones and phishing attacks are now going hand in hand with the use of stolen credentials.

[00:29:09] What are stolen credentials while it is information that has been stolen from another website, typically? Now might be as stolen from your business. And so they know what your password is because they have all of the passwords in the business you're working for. But more often they're doing something called credential stuffing.

[00:29:32] So they're going to the dark web and let's say they want to attack colonial pipeline, which of course just happened. And colonial pipeline has their URL that all of their email is sent to. What they end up doing is they go to the dark web and they find. Credentials for people that have a colonial pipeline, email address, and those credentials are going to include things like your password on that website.

[00:30:04] Now, what happens is. They stuff that username and that password in as many sites as they can. So let's say they found that you're using Microsoft remote desktop, and maybe there's a zero day bug as there are many bugs in that software that people haven't patched yet. So they'll just use that to get on, but if they can, let's say you patched it and they found your email address and use over on website X.

[00:30:35] That has nothing to do with colonial pipeline. What they can then do is take that username, which is that email address and that password and try it at colonial pipeline. And guess what? It works more than 60% of the breaches involved, credentialed data. And 95% of organizations that we're experiencing this credential stuffing attack had to between 637 and 3.3 billion malicious login attempts throughout the past year.

[00:31:14] We see them all the time. We have a couple of internet facing servers and those servers we log when someone tries to log in and if they try and log in more than four times immediately, they are blocked at the firewall. So they can't even connect to the server anymore, period at all. And that stops this type of attack.

[00:31:39] So I'm sitting here. I'm actually, I was literally scratching my head because I cannot figure out how can you have 3.3 billion malicious log in attempts at one business over the course of a year and not do something about it. Not have them automatically blocked. This is just crazy because credentials are the key that the bad guys can use to get into the network.

[00:32:13] And they're not just using them to do ransomware into somewhere like colonial pipeline. They're using those credentials to go to your bank account. Yeah. So you, most people are using the same email I'll address as a credentials, which is ridiculous. I can't believe businesses are letting people use an email address as their login username, but most people using that same email address and those same passwords at multiple websites.

[00:32:46] So I want you to do something now, and I've asked you guys to do it before on the show. You may not have had a chance before you may not have known about it, but I want you to go. If you're not in front of your computer, go there right now, or grab something. You can write this down with, or send me an email just me@craigpeterson.com.

[00:33:06] What I want you to do is go to have I been poned.com. So that's like it sound have HIV. E I, the letter I been B E N P w N E d.com and put in your email address right there. And that will tell you what information of yours is widely available on the dark web. Now it doesn't have everything that's on the dark web.

[00:33:37] By any stretch, but it has all of the major stuff. And I can guarantee you if you've had an email address for any time at all, that email address is going to show up. It's going to show up all a lot. Okay. So check it out. Have I been poned.com and then trend, according to Verizon is towards simplicity.

[00:33:59] They're using passwords stuffing. They're using social engineering fifth. Dean X spike in misrepresentation, which is a type of integrity, breach business, email compromised, doubled last year, and a gain this year. It doubled again, 60% of business, email compromise attacks that successfully stole money. It's crazy here.

[00:34:27] Median lost $30,000. That's email coming in, pretending to be someone that they're not. And again, I've helped companies that this has happened to and help them tighten things up. That is the problem. Okay. There's huge medium was 30,000. And 95% of them cost somewhere between $250 and a million dollars.

[00:34:53]It's just amazing. So we've got to pull up our socks. We have to be careful. I have some free info that you'll get. If you sign up from an email newsletter, you're automatically going to get a few of the special reports that I put together. You're going to get my weekly emails. It's all for free.

[00:35:12] This newsletter. Most people can't believe they don't have to pay. I had someone just this last week say. Are you sure I'm not supposed to pay for this because a lot of newsletters out there, of course you have to pay for, but I send out all of this type of information for free and I have free little trainings and free guides, and I'm more than glad to offer them all to you guys.

[00:35:37] So check them out. Go right now. Craig peterson.com/subscribe. Now have I been poned is again a website juke should go to, but the other thing you need to do is make sure you're using a password manager. Now a password manager is something like one password. I wouldn't no longer use the last pass. I have pulled that off of my list of recommended password managers because of a major problem that they had.

[00:36:07] And it showed, they really didn't know what they were doing. Everybody makes mistakes. Nothing's a hundred percent secure. Believe me. I know that, but they really lost all. Of my trust with this huge hack that they had. So one password is the only one I'm recommending nowadays. That's a digit one in the word password.

[00:36:28] Use that. If you can use something other than your email address to log in. Do that change your account name to something out, something completely unrelated call it the human element or something. Use a login. That's not your name. That is not your email address in is not something that's easily guessed.

[00:36:50] And then use a fairly randomly generated password. Now, what I'm recommending now is the latest NIST guidance, and this does the national institutes of standards and technology, and the latest NIST guidance says. You do use some random stuff, but I'm not talking about random letters, numbers, special characters.

[00:37:13] I'm talking about taking three or four randomly chosen words, or even a phrase that are separated using maybe a digit or a special character, making sure there's a little bit of upper lowercase stuff going on, but it's something that can be remembered if you need to. And one password will generate these for you automatically, which is absolutely amazing.

[00:37:41] Okay. It's such a godsend. I was surprised when I looked the other day, I have 1400 different accounts in my one password. Yeah. That's how many I have that's a lot. And it'll also keep your notes in there. So you can put in bank account information, et cetera. It keeps it encrypted. It keeps it in their own little secure cloud.

[00:38:05] So knock on wood should be pretty darn safe. Now want to point out one more thing about these statistics here? Nearly all email servers, 96%. 96% of email servers that were compromised in these attacks or cloud-based once they've gotten into your email. They have control of you. I just got a call again.

[00:38:36] This is a friend of a friend who called me up because their email account had been compromised almost certainly because again, credential, stuffing there's password information out on the dark web, et cetera. Cause I ha I looked it up for him and sent him the link. Here's what have I been poned says. But once they have control of that email address, they probably have something that you're using for password recovery.

[00:39:05] So you go to the bank. So the right way to do this for the bad guys is they go to like bank of America. They try and put in your email address and say, I forgot my password. So where are they going to send your password? They're going to send it to your compromised email account. If they're, they'll try all of the major banks and they'll see what they can find.

[00:39:27] 96%. So it's just crazy. And people are using this. They, the cloud is just the name for someone else's computer and you don't know how all protected it is. And you still have ability if it's broken into, and in this case, Verizon saying that this led to the compromise of personal information, internal business information.

[00:39:54] Medical information, bank, account information. This is part of the challenge of moving a business to the cloud. It's incredible. All right. And not flip that make sure you do get all this info. You'll get all of my free, special reports by signing up. If you're not already on the list. If you have any questions, Craig peterson.com.

[00:40:17] Feel free to reach out me at CraigPeterson.com. That's my meal at that's my email address, and I don't use it to log into anything me@craigpeterson.com.

View Details

[The following is an automated transcript.]

Craig Peterson: [00:00:00] The lies and misinformation that are going on right now over in Israel, between Hamas and of course the Israeli government. This Tesla owner got bulled over sent to jail because he was driving the Tesla from a back seat. And a little bit more about the colonial pipeline with Mr. Matt Gagnon. We joined him of course, this morning.

[00:00:27] Here we go.

[00:00:28] Matt Gagnon: [00:00:28] Good to have you with us. 7:36 on a Wednesday means it's time to talk to Craig Peterson, our tech guru. He joins us at this time every single week. Craig, how are you this week?

[00:00:38]Craig Peterson: [00:00:38] Hey, I am doing quite well. I had a couple of my hives swarm. It's just been such a great day; over winter and a great spring.

[00:00:47] And so I was able to capture them. So I'm up two more hives. I cut two swarms.

[00:00:53] Matt Gagnon: [00:00:53] So I'm what are you talking about? Are you a bee person?

[00:00:56] Craig Peterson: [00:00:56] My honey bees. Yeah. You didn't know that?

[00:00:58] Matt Gagnon: [00:00:58] Well, yeah. Okay. I sort of remember that a little bit, but you wouldn't mean you caught a swarm. I mean, they like you, you go out there with a net, I mean, yeah,

[00:01:06] Craig Peterson: [00:01:06] Well,, the way it works is bees multiply by dividing. So if they're, if they're really, really healthy, they will go ahead and make some new Queens. And then when that queen emerges, the old queen will take about half of the workers and we'll go to try and find a new hive. So she'll go out and she'll just sit on a branch.

[00:01:28] And of course, all of these other workers that had 10 to 15,000 bees will swarm right around her. So they'll all be resting on this poor branch, which is almost always just sagging. So if you can touch them. So what you do is if you can get that queen particularly, and get her into another little hive or a box to begin with, then now you've got a whole new hive. So that's how they have new colonies. That's how the honeybees is started expanding. And I, I often just let them go because it helps with the whole diversity thing and they become wild honey bees, which we need because this year, about half of all of the colonies in the U S died. So that's how it works.

[00:02:14] There's a bigger than a football, but kind of shaped like it. And if you see one call a beekeeper in your area, so they can either go and grab them and help them make sure they're healthy because unfortunately our wild bees are dying at very high rates, but they can make sure they're healthy. They can capture them and they'll be happy.

[00:02:34] And hopefully they won't end up in somebody's Eve's over there that they then have to try and get those beat colony out of.

[00:02:43] Matt Gagnon: [00:02:43] Well, I learned something about bees today. Ladies and gentlemen, Craig Peterson joins us at this time. He also joins the program where we're joins the station, excuse me, on Saturdays at one o'clock where he hosts the show where he goes into many of these topics in more detail.

[00:02:54] I don't know if you're going to hear about bees, but I guess you're probably going to hear about the colonial pipeline. I know that we talked a little bit about this last week, but Craig, they paid a $5 million ransom. And from what I understand, they basically, I mean, what they got back for a key, they didn't even really use any way.

[00:03:09] And they ended up like using a, sort of a backup, uh, uh, of theirs to restore things. Anyway. I mean, first of all, tell me about what actually happened with that payment ransom. And second of all, what's the impact of this? I mean, does this not just incentivize more of this garbage happening? Yeah,

[00:03:24] Craig Peterson: [00:03:24] it really does.

[00:03:25] And that not only incentivizes it generally, but it incentivizes them to go after colonial dam, just like they've done with the city of Atlanta, where they paid a ransom. And of course they got hit again just weeks later. Another ransom. Right? They got hit again. So this is really bad. Under the Trump administration, the department of justice said you are supporting terrorism.

[00:03:51] If you pay ransoms. And we consider that to be a legal. Now under the Biden administration, they said, no, you know, whatever, do whatever you want. It's kind of, you know, up to you. Uh, they paid $5 million. The bad guys gave them the decryption key. And, and in fact, tried to help them decrypt to their data that wasn't successful.

[00:04:14] What colonial ended up doing is two things. One, they switched their pipeline over to manual. Control away from computer control. So they actually had to have people all the way up and down the coast. How long does that? It's like two, 3000 mile pipeline and all of the valves turn them on and off. That's how they had to deal with it.

[00:04:36] But pain, your ransom is a bad thing to do. Having a backup is a good thing to do, but you gotta remember. And I cover this in my backup. Of course that when we're talking about backups, something that's attached to your machine is also going to be encrypted as part of the ransom. So make sure your backups are remote and the bad guys can't get it them, but that's the easiest way to get them.

[00:05:01] Pass that first part of the ransom. The second part is what's going to be interesting here mind, because what they will do this group is they'll steal your data and then they will threaten to release the data. And, uh, when Zach shoe going to drop, and then also there are claims out there that the reason they shut the pipeline down, Matt was because their billing systems were offline.

[00:05:28] That was the part of their network that was attached, attacked by ransomware. And they wanted to be paid for the fuel. So they shut it down because they didn't want it to deliver fuel that they couldn't bill for.

[00:05:45] Matt Gagnon: [00:05:45] It's quite a mess, obviously, correct. Peter Sohn joins us at this time, uh, every Wednesday to go over what's happening in the world of technology or the big story besides this colonial pipeline issue, which is really more of a last week thing is what's going on in Israel with, uh, you know, obviously the, uh, the, the rockets being watched back and forth, the potential of a ground invasion, the conflict.

[00:06:04] At its worst point for the last probably eight years or so. Uh, social media has been a part of this story here. And one of the things that's interesting about that is that misinformation lies a bunch of garbage has been skewed around on social media. And there seems to be no stopping it. Craig Peterson.

[00:06:21] Craig Peterson: [00:06:21] Yeah. Yeah, exactly. And what we're finding now is really something that's been going on for a long time, all over the world. And that is, they are showing at official press conferences on basically on both sides of this conflict. There's showing videos. Of other past conflicts and representing it as it's happening right now.

[00:06:48] So this is a real big problem, frankly, these, this is a different world. Many of our news organizations are not investigating. They find a video, they use the video, even though it misrepresents it. And of course, a lot of people are familiar. With that at our U S border where they were showing pictures of kids in cages, when they were, those bridges are taken cherry, the Obama administration.

[00:07:15] And yet it is the Trump administration. They're complaining about same thing here. So we are able to do research online, please do the research, and it's disgusting to see the state of Israel. Using videos that are not particularly relevant and misrepresenting them in the same thing on the other side with

[00:07:37] Matt Gagnon: [00:07:37] Tomas.

[00:07:38] Yeah. That's not the first time that's ever happened. We're talking with Craig Peterson, our tech guru who joins us this time every single week. Lastly, just want to ask a little bit about Tesla. Uh, a Tesla owner who drives from the back seat got arrested recently.

[00:07:53] Craig Peterson: [00:07:53] Yeah. You said he apparently told the police officer that, uh, and this was in California highway patrol that he felt safer in the back seat.

[00:08:05] Matt Gagnon: [00:08:05] This is, this is the self-driving car revolution about to happen to us. Right? Do we are going to get a lot more stories like this

[00:08:11] Craig Peterson: [00:08:11] happening soon? It absolutely is traveling eastbound on the IAT or across the San Francisco Oakland Bay bridge. Uh, if you're familiar with it.

[00:08:21] Matt Gagnon: [00:08:21] Oh my God. He drove on that bridge.

[00:08:24] Seriously. Yeah, I know I've spent an awful lot of time out there and I've driven on that bridge more than once. And that's the last place I would be in the backseat, not driving my car. I guess. It's just my I'm terrified of Heights, but now that's insane. Yeah.

[00:08:37] Craig Peterson: [00:08:37] So people were reporting it to the police.

[00:08:40] The police pulled him over. You apparently climbed into the front seat and in order to stop the car and he actually got arrested, put in jail. He was released as is the norm in California. And so what does he do? He does it again. And he's caught again and arrested again. He says, I just feel safer back here than I do.

[00:09:02] Uh, there, uh, this is, yeah, this is what we're in for here. Remember, even though Tesla calls it full self-driving, it is not with autonomous,

[00:09:14] Matt Gagnon: [00:09:14] right. It's meant to be an autopilot while you're sitting there. Behind the wheel, just in case and, and directing things still really. I mean, it's not a full self-driving for real right now, Craig Peterson.

[00:09:25] Thanks for joining us as always good luck on Saturday on this very program one, o'clock make sure you tune in for that. And we'll talk again next week. Hey, take care. All right, we're going to take a quick break here. When we come back.

View Details

[A quick, automated transcript of my conversation with Jim Polito on WTAG, WHYN, and WHJJ on 2021-05-18]

Good morning, everybody. Craig Peterson here. I was on with Mr. Polito this morning, and we went through the colonial pipeline and why you don't want to pay a ransom. And then I went into the things you can do for free. That'll give you 90%, maybe a little higher protection. So some websites to go to some things to do on a windows computer.

So it went a little deeper, I think, than I usually. Go into, but I think a lot of great info. So here we go with Mr. Polito. 

If I ever got hacked, ransomware, whatever there's one guy had called, not the Ghostbusters. I would call our tech talk guru and good friend, Craig Peterson, who joins us every week at this time.

Good morning, sir. 

Hey, good morning, Mr. Jim. 

Craig, why don't you just say, I told you so because they, it looks like colonial paid the $5 million ransom, the stories I'm reading say that then the Russian hackers gave them the key to fix the encryption, and it didn't work. And then they eventually figured it out themselves.

Am I correct? Yeah. 

Yeah. That's pretty much what happened.

Brilliant guy because that's called colonial pipeline. So you said, and you have said many times before, the easiest way to get yourself in the crosshairs of a cyber hacker, ransomware criminal is to pay the ransom. Then you have painted a bullseye on your back.

Why don't you tell us about that? 

Yeah, we have a whole country thing. You might remember. There was an organization called the United States Navy. And the United States Marine Corps. And you remember, the Marine Corps Anthem, right? 

Oh yeah. From the halls of Montezuma to the shores of Tripoli, the barber.

Okay. And why did they form the Marine Corps? Why did the Navy come to be? It came to be in both cases to protect our merchants, our merchant leads; we were having some problems with some alumnus back 250 years ago. And we sent our Marines over. In fact, the whole thing about leather neck comes from that same period.

So they wouldn't get their heads chopped off. I hate to talk about that, but we've been facing this—type of thing, extortion as a country forever. And now we've got president and Biden out there. Know  I'm trying to do a hairy imitation. There might've been the Russians, but it wasn't the Russians; it wasn't Putin.

At this point, it seems very obvious that because of dark by the way, who shut themselves down over the weekend, along with two other major ransomware operations, it looks like they were at the very least under the protection of the Russian government. So they go out, and who do they want to target?

It used to just go out there, spray and pray. See who you can find now it's, let's go after the people with the bigger pockets, as much as we can, at least these professional groups of which of course are present, colonial or act by. But these professional groups now go after people.

Now, who are they going to go after? They want somebody with the big. Wallet, a big deep pocket. And they also want to have somebody that they know is going to pay. So let's take the city of Atlanta, for instance. This is a small city in the south, and Atlanta went ahead and got around somewhere and paid.

And what happened again? A couple of weeks later, they got ransomware and paid. And then what happened about a month later, they got ransomware and they. Multiple times now compare that, for instance, with the metropolitan police department down in Washington, DC. Now in Washington, of course, again, a small town, and they have a metropolitan police department.

And again, They didn't bother putting together the type of security they need. And we just did an audit in fact of a county who will go on named that their cybersecurity was almost completely non-existent, yet you talked to them, and they say it's absolutely there, but in Washington, DC, they got into the police department computers.

Now, if you are connected to one of these networks, you have what is called the feed, just requirements, which are really aimed at law enforcement. But they got on, and they were able to grab all kinds of data, and they said, okay, pay up. Watching the DC said, no, we're not going to pay. We're just going to restore from backup.

So they said, okay, we'll pay up now. Or we're going to release the names of all of your informants and their phone numbers and their home addresses. And what's ended up happening so far. Is. He still hasn't paid, but they did release the identities of the police officers within the department. At least some of them in this is a real problem.

We are, as a nation, allowing these foreign countries to get. Bitcoin typically, which by the way, has been the major motivator, driving up the price of Bitcoin and getting away with it. We are funding North Korean operations. This is one of their major sources of currency attacking us in the United States.

We're talking with Craig Peterson, our tech talker right now, generally, we're talking about things that are to protect your new gadgets, all this stuff, software, and that's generally what we discussed, but there comes a time when we have to open it up globally. And Craig Peterson is the man to do it two weeks.

Stand what's going on. The bigger picture, Greg Bitcoin, is the way. That they can fund themselves because you can't trace it. If I have money, I've got to have some way. If I'm asking for ransom and dollars, there's gotta be some way to get those dollars to me. And, financial institutions can say, we're not doing business with you.

Credit card companies can say we're not doing business with you. And so they get Bitcoin. It's like the wild west. It's like robbing the stagecoach and getting the pieces of gold. 

It is. I had a briefing by the secret service and went through the takedown of one of these dark web operations that were only using.

Bitcoin. And a lot of people have the con the idea that somehow cryptocurrency, because it has crypto in the name as in cryptography, they have the impression that somehow it's secure, they're never going to get caught. And yet, in fact, that's exactly what happened. So there is some speculation right now that because we can track many Bitcoin.

Transactions that these three major ransomware operations shut down over the weekend because of somebody getting a little bit too close. Okay. I don't think it was the call from president Biden that lasted what, three minutes?

Yeah. 

Please gimme a break, gimme a bread. 

Yeah. So there are some things that we should do as home users. And as a business, as small businesses, you can get better than 90%, probably close to 95% protection by doing just a full of things 90%, I'd say, but they're both free. Okay. If you have windows use windows defender, it's free.

It's part of your windows 10 installation. Make sure you keep everything up to date and use windows defender. All right. Don't bother with so many of these other antivirus packages that really aren't going to do you any good? So that's number one. Number two, what I teach in my courses and show you exactly how to do it is there's a professional version, but I'm going to tell you right now, get your pencils out.

I'm going to tell you right now the version that it doesn't do anywhere near as much the commercial, but this is going to get you way closer. This is going to get you on the higher side of the 90% range. There is a website out there called OpenDNS. No Cisco, who is the company that runs that makes hardware that runs the internet and is a company that we deal with.

When we install firewalls and switches and clean things up, it's always Cisco bought OpenDNS, and then they improved it. They call it an umbrella. But if you go to OpenDNS, it is simple and it is three. All right. They have paid versions. If you can afford them, get the paid versions, they are better.

They've got all of this consumer stuff and basically all you have to do is make a couple of changes in your network. Are you going to connect to your little firewall router or on your PC? You really don't even have to install any software. You see what happens is once the bad guys get their software on your computer.

Then you have your computer call them up. So essentially you're paying for the phone call, but call them up and say, okay, I've got a computer. What do you want me to do? And then they use your computer now to move around within the network and then install ransomware that et cetera. But if they can't call home, They can't do much or do anything.

And almost all modern ramps are more. If it gets on your machine calls home, can't get there. It just sits dormant. So by telling your computer to use OpenDNS instead of Comcast or whoever your local provider is, what happens now is it asks OpenDNS. Hey how do I get to bad guys.com internet bad guys.com.

And I want to challenge you guys right now. Go there on your computer, internet bad guys.com. And this is a demonstration site. All right. And what'll happen is how do I get your internet bad guys.com? Or how do I get to dark sky or whoever it might be. And OpenDNS will say,   what, where what?

And so they can't call home gym. So if you can. If you can get to that website, internet, bad guys.com right now on your computer. That means that your internet provider is not blocking DNS appropriately. So you can do this simply OpenDNS.com, install the software. If you want more professional stuff, let me know.

We're starting to do some more cybersecurity health assessment is I want businesses and individual to be able to protect themselves. This is the 90% solution. And sorry, I've been rambling for a while. 

Yeah. Oh, this has been great. Now, Craig, if folks want to get in touch with you how do they do it?

Just send me an email just to me@craigpeterson.com. It might take me a few days to get back to you. My wife, as you might know, at a serious activity, but just email me M E Craig peterson.com in the subject line. Just put what you're interested in. If you wanted to know more about OpenDNS or passwords or whatever, and I'll send your info, I'm not charging for any of this stuff and get you on the right path.

me@craigpeterson.com and you can sign up of course. On my website, which happens to be right. Peter som.com. 

I love that. Make, keep it simple for the stupid anyway. And that's me, me Craig, great segment as usual. And you've been in the forefront of this for quite a while. And and people need to hear more of what you're saying.

Craig, thanks so much. We'll catch up with you next week. All 

right. Take care, Jim. Thanks. Bye. Bye. Hey everybody take care. I have been very busy helping out small businesses and individuals to that cyber health assessment stuff I talked about. I've got a self administered. Cyber health assessment as well.

So keep your eyes out for that and make sure on that mailing list. So you can find out more about it. You can just do it yourself. You don't have to talk to me or my texts or anybody else. Craig peterson.com and sign up right there.

View Details

As Heard On WGIR - 2021-05-17

Hi, everybody, Craig Peterson here. I'm not quite sure how to describe this interview, but you're going to find out something about me you may not have known and it's not a bad thing. It's just, I've never really disclosed it. Certainly not publicly. Anyhow. So we talked today about the colonial pipeline what's happening with these ransomware groups and there are a number of them and why.

Why is it happening? And then also of course, over the weekend, there's a little bit of discussion with Marco Rubio and others on 60 minutes, I think it was about UFO's. So I guess there's a clue. So here we go with Mr. Chris, Ryan Stanford. 

I am Chris Ryan joining us right now is Craig Peterson. He is the host of tech talk.

On Saturdays and Sundays at 11:30 AM on news radio six, 10 and 96 seven Craig area. 

Hey, good morning. That's a nice kickoff there with the stones. 

Love to hear it. We really do. And there's nothing better. Little Keith Richards riff to get us into the mood here on this Monday morning cross the great state of New Hampshire.

So Craig. It's amazing how our news cycle works. We have the colonial pipeline is one of the biggest and maybe most significant stories that we've had so far this year. And we talked about this actually, Liz Cheney as well. When she joined us on Friday to me, there has to be a priority. And a predominance of focus placed upon cyber warfare and germ warfare and electromagnetic warfare.

We're hearing about, UFO's and that report from 60 minutes, which I think is really important as well. I It's clear now that there are. UFO's used to be. The question was, do they exist? The answer is, yeah, they do, because we have video evidence of them and people have seen him at firsthand accounts.

So those are the two things we're going to get delve into today. And I want to start with your takeaways from the colonial pipeline circumstance. 

I talked about it a lot on the radio show this last weekend. Cause it is a change. It really reflects a change in the way ransomware works too. And over the weekend we saw a big change yet.

Again, ransomware used to be just, they got software on your machine. Usually through. Phishing, which is sending you an email, getting on something, and then they'd encrypt all of your files and say, pay up sucker, if you want access to your files again. And then it moved to the next stage, which was people didn't always pay off because they might have backups and say we can just restore from backups for Canada better.

We're not paying you a dime. They decided maybe what we should do then is get a little more. Vance. And before we encrypt your files, we're going to steal all of your important data. And then we're going to hold that data hostage and threatened to release it just like they did with the metropolitan police department down in Washington, Jen DC.

And yes, indeed. They did release home information about the police officers in the metropolitan police department right down there in Washington, DC, because they didn't pay this ransom. Now, what we have is something called dark side, which is a group that's been around for almost a year. And they sell services to other bad guys who want to rent some people.

So dark side, we'll take a 25% cut all the way down to 10%. They have it on their website, depending on how much money you're able to get out of. People twenty-five percent cut on anything under about $5 million and they'll do tech support for you and everything else. So when you take over someone's computer and they are now trying to pay you buy Bitcoin, et cetera, in order to do that dark side, we'll do the tech support.

It turns out the dark side was behind this hack of the colonial pipeline. And ArcSight is now a little bit nervous. They brought their website down. Of course it's on the dark web has two other major operations that are again, ransomware for hire. So we've seen three major groups. Chris go completely dark over the weekend.

What does that mean as well? Are they nervous that what are they nervous about in particular? Are they nervous about the FBI? Are they nervous about, and does the FBI have. No jurisdiction over a cause that's one of the main challenges for whether it's for local police departments or for even an entity like the FBI, where there's a international type of a flavor to these many of these entities, how, who has jurisdiction over them?

How do you. How do you make them accountable? And how does things have to change in order for that to take place? 

Part of what drove up the value of Bitcoins so high and continues to our businesses who are buying Bitcoin in case they get ransom. So that obviously supply and demand limited supply of Bitcoin businesses buying right.

Bitcoin by the millions in case they ever get hacked. And look at what just happened with Tesla, buying all kinds of Bitcoin as a quote investment unquote, most of the time, these investments are to protect themselves who has jurisdiction. I have been to a lecture by the secret service where they were able to shut up.

Down a major black market operation that was running on the dark web and they were doing all of their transactions in Bitcoin that's cryptocurrency. And it is not. Safe. They were able to figure out who it was, where they were. Okay. And they were able to get an Interpol involved and get it all shut down and get most of the money back, which is interesting as well.

So here in the us, the FBI does get involved and I've worked with them on a number of cases. And there's the, of course secret service gets involved because they're talking about currency, staffs, international fashion, and then they. In the international community to round these guys up. So I suspect they're either very nervous because someone's getting awfully close to them.

And we've seen a lot of shutdowns lately of these bad guys, or maybe it's just good business. Let's just put up a different shingle and move on. I don't really know what's happening yet. And 

why out in the open, the way that they are to begin with, because you're going to draw attention. To yourself and they, as you were referencing, they basically opened up a business and put forward that business and said, here we are, we're going to supply a commission-based environment.

And that, to me says that they're not that fearful of repercussions because of being. Very much a international type of a, of an entity. And there being questions, about how you go about enforcement on this side. And there still are questions in regards to jurisdiction.

There has to be a lot of cooperation for arrests and for investigation and things of that nature to transpire. So why do they have this type of confidence in your own? 

So excellent question again. Look at their targets. They've been very careful not to target Eastern European countries, specifically countries or parts of the former Soviet union.

So it does make me wonder Chris about whether or not the Russians are actually involved and are providing them with some protection. And maybe Mako has said, Hey, get your heads down. 

Biden said there was no direct relationship. He did not say there was no relationship. He said that he did not believe that Latimer Putin was behind it specifically, but that does not mean that he is not behind the entity or that there is some sort of branch out to them as there are.

Many companies and all oligarchs and individuals who have not necessarily a direct association with Putin, but indirect ones. The final thing is on the UFO's Craig and your thoughts on this and how this also plays into what we're talking about with no technological warfare, as I've said before, based upon the evidence.

I am still not on board with the fact that the UFO's are from outer space. I'm on board with them being Chinese or Russian or another country has developed some sort of a technology that allows for these identified flying objects to get close to our aircraft carriers or be seen off of the coast of Florida.

And in other. Circumstance, as I've said before, I've seen UFO's flying over and as many other people have flying over our airspace here in New Hampshire things that just don't make sense, different colors and so forth. And now we know that they have been we've seen them on video. We know that they exist.

There's no question about that. The question is who is responsible, 

right? Yeah, absolutely. Chris, my experience with you at post goes back to 1982, when I had a close encounter. With the UFO, not just the movie back then, but I was driving up the central Valley there in California and I, all of a sudden saw this light that was blasting right into my car.

There was probably about a half a mile ahead of me. And then it came closer and I had my windows open. Didn't have air conditioning and it came right next to me. Now I know that helicopters make a lot of noise. We didn't have anything like drones back then. And it followed me and stayed right next to me as I went up that central Valley and took curves and everything else.

Wow. My mother also had an experience. Where do they come from? That's your right? That's the really big question. We certainly did not have that type of technology in the 82 or so when I saw it and when it followed me and that technology, I doubt existed 20 years before when my mother had an encounter with a UFO.

And it's it's a scary thing. It really scared the living daylights out of me that day, here I am on my twenties, a driving scene that there are some right now, some technologies that we do have that provide on an extremely limited scale. Some of the features that we've seen of many types of UFO's.

And at this point, Chris, I'd have to say again, we really don't know where they are. Come from, it would take an incredible breakthrough in physics in order to be able to have an aircraft or some forum that can hover make almost no noise. If any noise at all and change directions completely without causing enough.

Jeez G-Force to destroy the vessel itself, let alone everything inside. So it is a long way from anything technology wise, that's ever been exposed that we have control of the aliens. That's 

what I'm hearing. That's that is that Greg did not go that distance, but it sounds like that is where you want to go with this.

We don't have a lot of time here left, but I do have to follow up on this because you basically just described an alien encounter. Yeah. How did it end? Did the UFO go away? What do, were you abducted? What happened? 

No I thank goodness. I wasn't abducted, but that got my interest up. And as I've studied this a lot over the years it followed me along for 15 or 20 minutes or so.

And it, it just, it had this light on me on the car and the whole time I slowed down it load, I sped up it sped up. It was very odd. Let's settle this and put it that way. And yeah, I don't see any way it could have been from made by us or the Chinese at the time or anybody else.

It was, and they, I felt scared, really scared. It wasn't like a peaceful feeling like there's love coming here or something. But I do think that they're either extra dimensional there or, out from outside of this world, Greg, 

the amazing story there. Thank you so much. Take care, Greg Peterson, he is the host of tech talk here on news radio, six, 10 and 96, seven on Saturdays and Sundays at 11:30 AM.

Hey I'm going to be a little slow getting back to you guys. I want to schedule these cyber health assessments and get them all done for everybody that asked over the weekend. If you did not get a chance to ask it and make sure you do go on line, just send me an email. me@craigpeterson.com. Put a like cyber.

In the subject line and just let me know, you're looking for one of these health assessments. I got some that you can do yourself. You don't even have to talk to me or anybody out all the way through very deep ones that we do for businesses and others. So let me know, take care, everybody, and I should be back tomorrow.

Take care. Bye-bye.

View Details

2021-05-15 Show 1113 - How the Colonial Pipeline changed Ransomware forever

Craig Peterson: Hey, wherever you are, whatever you're doing right now. I know you're listening, and I appreciate you being with us. Of course, this is Craig Peterson. I've been in cybersecurity now for 30 years, and we're going to talk about what's really happening with this Colonial Pipeline ransom.
[00:00:16]This whole hack, if you will, of what's been happening with this Colonial Pipeline. Cyberattack is very upsetting to me. Let's just really briefly because I've talked about it before. Talk about what happened. What is ransomware? Ransomware is software that the bad guys get onto your computers.
[00:00:40] Now it's changed over the years. When ransomware first started hitting, I think most people still have this in mind, and the software gets onto your computer. Usually, you click on something. You download a zip file, and you open it up. Maybe it's a Microsoft word document and embedded inside that document.
[00:01:00] Is a piece of nastiness, and that nastiness is the ransomware. And what it'll do on your machine is it'll start looking for files that it can encrypt. And those files typically are things like your word documents, your Excel spreadsheets, all that sort of stuff. And. They would encrypt it and then pop up on your screen, a nice little red warning message that all your files have been encrypted.
[00:01:31] And if you really want to get those files back, what you're going to have to do is go to this particular website, send some Bitcoin to this specific Bitcoin wallet. And then hopefully, you'll be okay. Now, back in the day, it was crossing your fingers cause you didn't know what was going to happen.
[00:01:52] If I send the money while I get the decryption key, will the software work while I get all my files back. And frankly, the answer to most of those questions was no. In most cases, you would not get all your files back in this day and age. It's changed slightly, but we'll get into that and how it's changed and who has changed the ransomware.
[00:02:16] Industry. I want to give you some tips on what to do and how to avoid ransomware in the first place. And there are some automated things you can do. You can do some things just as a human being that you should watch out for. And I want to also get into it, so what do you do after the fact? I got a call from a listener this week who had a real problem.
[00:02:41] Actually, she sent an email to just me@craigpeterson.com, and I got her phone number called her back, and I had my lead tech and myself on the phone with her for probably about 15 minutes going through. Okay. So here's what you have to do to respond. So I think it's essential for everybody to understand this.
[00:03:01] This Colonial Pipeline cyber attack was ransomware, but it wasn't like that original ransomware that I saw all those years ago where you're crossing your fingers, et cetera. It has advanced to the point where this company has now made this cyber attack business an actual commodity for lack of a better term.
[00:03:25] Quite literally, it was called the DarkSide. They've been around for about a year. And apparently, the people that are involved with the DarkSide have been doing ransomware for much longer than that. But what they're doing now isn't just, Oh, take a gamble, and maybe you'll get your decryption key.
[00:03:44] Maybe the decryption will work. Nowadays, they have turned it into a truly professional organization. There are tech support people that you can talk to. You can call, you can have an interactive chat with them. The ransomware is very careful to make sure that you can still use the online chat features in your windows machine or whatever they might need to communicate with you.
[00:04:14] And the tech support people
[00:04:15] will
[00:04:15] Craig Peterson: say, Oh yeah, some, I'm sorry that happened to you. Let me help you fix it. What you have to do is go to this website and buy Bitcoin. First, you have to set up a wallet. All of this was just so complicated. People weren't able to figure it out. So they now, with their tech support, will help you.
[00:04:34] Find a place to buy the Bitcoin help you set up a wallet, help you put your more money into that Bitcoin wallet after you bought some fractional, probably Bitcoin, because they're worth quite a bit right now. And then. They'll help you to send that money from your Bitcoin wallet to their Bitcoin wallet.
[00:04:59] And then they'll help you run the software to decrypt your files. This is pretty complicated, and these guys, a DarkSide, understood that. And that's why they did all of this tech support type stuff, but they've taken it. I yet a step further, this gang-like DarkSide in there. They're not the only ones DarkSide.
[00:05:23] They're just the guys that we think went ahead and hacked the colonial gas pipeline, but they've taken it to the step now where they are selling ransomware as a service. You can approach to them and pay them. And quite a while, you've been able to buy ransomware that you could use. You had to find the email addresses.
[00:05:47] You had to send it out. You had to do this, but now for a down payment and a percentage of your take this gang will go ahead and do everything for you. Including sending it all out. They've really professionalized this whole Industry of crime, of ransomware crime, of course. And we've talked about this on the show before they also will go the next step and what the next step is in this day and age is.
[00:06:19] When they get into your machine before they encrypt anything, they have a human being who looks at your machine. So the machine calls home. And I want to tell you how to stop them from calling home. Because that's going to stop most of the ransomware, but it calls home and says okay. I got somebody.
[00:06:39] And so the bad guy now, because that connection's opened up to call home. Can now hop on to your computer, unbeknownst to you. It's not as though you're going to see the mouse moving or screens changing. It's all happening behind the scenes. And so they're on your computer. They look for files. They think might be of interest.
[00:06:59] Those files get uploaded to them and they try and spread laterally. And a lateral spread means that they see, yeah, here's some machine that we have compromised. This looks interesting. What other computers on the network? Is there an active directory server, some sort of a file server network-attached, storage, other computers what's out there.
[00:07:25] They will probe your network, which again, if you've got good network equipment, you're going to see that probe happening and you're gonna be able to stop it. But most people don't write. And including some of these big businesses that just aren't paying enough attention to how the bad guys operate. Now more than they knew.
[00:07:45] The Colonial Pipeline huge multi-billion dollar company. Okay. You now know more than they do in what order we eight minutes into their show today. So they will look around the network, spread laterally, take control of other machines. And they try all of the known ways of getting in. And of course, if you haven't patched your machines and haven't kept them up to date lately, it seems like Microsoft is releasing patches a couple of times a week, just like the old days.
[00:08:15]Microsoft fixed that problem. So you no longer had to patch once or twice a week? Yeah. How did they fix it? No, not by fixing their software. I know. No, I haven't forbid know what Microsoft fixer software. No, what they did is. They came up with this concept of patch Tuesday. So once a month, they'll just release all of the patches for all of the vulnerabilities that have been found that they know about and that they could patch readily.
[00:08:44] Is that insanity or what? So on average, they were leaving. You exposed for one, let's see, half of a month would be about 15 days. So there you go. About 15 days you were completely exposed. It's this whole thing is insanity. I just, I don't know why people aren't paying attention to it. And I talked to small businesses, and basically, they have their fingers crossed, and they don't think it's going to damage the reputation, even if they do get hit.
[00:09:14] But these guys are gathering all of this data from all of your machines inside your network, including your home network. Although they're not as interested in this. If it's just a little home network, other than if you are working from home. Okay. Are you silly enough to use a VPN? That's not configured right.
[00:09:35] Or the wrong kind of VPN. Okay. Hey. Yeah. So what we'll do now is we will spread laterally. Over to the business computers and all of the other people working from home that are also VPN in, in, properly into the business network. So they can just spread like crazy. It's, it is absolutely amazing that we're not doing more.
[00:09:58] I'm not calling for the feds to get involved with this cause they will almost certainly make everything worse. I'm just shaking my head here thinking about all of the potential problems they can't even get. This whole net neutrality thing straightened out, but DarkSide then has your files. And they do what I talked about a couple of weeks ago here in the show, they hold your files ransom by threatening to release them.
[00:10:24] Look at what happened to Metro PD, the Metro police department in Washington, DC, just a couple of weeks ago. Yeah, they got into Metro PDs, computers, they spread laterally. Hey, look at what we found. They threatened to release these files. They had found of all of the confidential informants there, phone numbers, addresses names, cases that they're involved with, et cetera.
[00:10:52] Yeah. Again, they're not taking it seriously. There's a lot we have to do.
[00:10:58]There is a huge problem out there right now. And the problem has to do with these ransomware gangs. And there are quite a few of these gangs out there, frankly. And one of them called DarkSide has nailed the Colonial Pipeline. What happened is the ransomware got into their network. We don't know the details yet.
[00:11:21] I've heard a lot of rumors. I'm not sure. And it started spreading inside the network. Again, you don't have a lot of details. I'm sure I'll find them out. And when I do, I will share them with you, but it spread. And the guys over at Colonial Pipeline said we better shut down the pipeline. Because we don't want the ransomware to cause serious problems thinking about what could happen with a pipeline, you could go overpressure, which could cause the pipeline to burst valves might not close that are supposed to be closed.
[00:11:56] It's going to really affect the whole flow of everything in the pipeline. And remember too, you have one pipeline that carries multiple different fuels, so they stop it. From carrying gasoline, for instance, it switched to diesel, they switched to jet fuel. They switched to gasoline. They switched to home heating oil.
[00:12:16] All of those are carried by Colonial Pipeline. I'm not sure if they're all in one pipeline, that's just send-up. Okay, we're sending gas now type thing. Or if there's actually multiple physical pipelines inside, I'm not really sure, but there is a lot that could go wrong. Either way, just based on the fact that they don't have the computers to control the vows, to control the flow, to monitor everything that needs to be monitored.
[00:12:44] Monitored. So DarkSide is at the very least holding their computers hostage. We don't know at this point, if Colonial Pipeline is going to pay the ransom, we don't know if there's going to be a backend ransom. As I explained a little earlier, we're seeing now these. Bad guys. Not only saying pay us now in order to get your files back, but pay us now, or we're going to release all of your data.
[00:13:16] I'm not sure Colonial Pipeline has that much data because they. Probably only have a very limited number of customers. So something might not happen there. The obvious data that they'd be concerned about is what I was contacted about just this week bank accounts, what happens if the bank accounts broken into stuff is stolen, what do you do?
[00:13:40] And how do you deal with this? So these. Types of attacks are becoming much more frequent and it's very concerning to all of us. For a couple of years, I ran the FBI InfraGard webinar program and we talked a lot about. Protecting our critical infrastructure, but the critical infrastructure is more than just the electric grid or the fuel pipelines.
[00:14:09] Frankly. It includes almost every business because if a business isn't critical, how could it possibly stay in business? Okay. You might argue how about the tourism industry? Is that critical? I don't know, ask the people that work in the tourism industry, if it's critical to their jobs or not.
[00:14:29] We have to defend everything and ransomware attacks, according to commerce, secretary Gina Raimondo. Are what businesses have to worry about now. So it's a real problem, but they've got a Homeland security involved in investigating this. They've got, of course, the FBI involved investigating it, and they've brought in some third parties.
[00:14:56] And w the one that looks to be the prime, I'm concerned about, cause this is not what they do, but they're saying it's an all hands on deck effort right now. She said we're working closely with the companies, state and local officials to make sure they get back up to normal operations as quickly as possible.
[00:15:17] And there aren't disruptions in supply. We already know. There have been some disruptions. I think it was South Carolina declared a state of emergency this week. There's a more than 1800 fuel stations, gas stations that are out of fuel. Some of it is attributed to what we're now calling the toilet paper response where people are saying, Oh no, there's not gonna be any gas.
[00:15:43] I better go buy gas now. And some people are bringing cans and cans to fill up as always filling up all of their vehicles. So it is a problem. Now, I'm going to talk a little bit more here about how ransomware gets in so that we can then give you some solutions. And if you have to drop out, I understand you can listen to this whole show as a podcast, just go to Craig peterson.com/podcast, and you can get all of the details there.
[00:16:19] I even post. These automated transcripts, they're not like an absolute type of transcript, but it's pretty darn close. So again, Craig peterson.com/podcast, and you can listen there if you miss part of it today. Ransomware has to get onto your machine. Now there's a few ways it can get onto your machine.
[00:16:42] There are a number of different types of attacks, but the biggest one that's typically used is called a Trojan attack. And a Trojan attack is kinda as the name implies. You think that it is something other than what it is, the Trojan horse. So the software that supposedly your friend sent you by email that you're downloading, it's not really good software.
[00:17:08] It's really ransomware disguised as maybe a Microsoft word document macro. There's a lot of things that it could potentially be, but. That's one of the ways and the most common way gets in there are other ways as well. They can exploit vulnerabilities in software that you're running. So if you're not keeping your machines patched up to date, it could get in using either a zero day attack, which.
[00:17:38] Yeah, there's nothing much you can do about those other than having a great firewall. So that's why I recommend having a real high end one, a good Cisco firewall. There are some other brands out there that are pretty darn good. And there's reasons that I like the Cisco over some of the other ones and it is what we sell, because I think it's the best out there.
[00:18:00] But having a real high-end firewall can talk. Stop these zero day attacks. Zero day attack is where thethe bad guys are using a vulnerability in your computer. That is currently unpatchable. The vendor, Microsoft, whoever it might be, has not come up with a patch for yet. So the bad guys say Hey, day, let's just get into machines and then they can remote control your machines, install the malware, usually the ransomware nowadays and go off on their own.
[00:18:34] That's the number one way they get in. Now, if you've been listening to this whole show so far today, that what has happened is once you have the ransomware that ransomware calls home, Now there's a number of different pieces or classifications of software that call home. One of them is ransomware.
[00:18:57] So it gets on your machine. It calls the bad guys up and says, Hey, here I am. What do you want me to do? And usually the bad guys. If it looks like a decent target, hop on your machine, poke around, try and spread laterally. As I explained, in some cases, what it does is it just uses your machine, particularly if it's just a home machine and there's nothing particularly valuable on it.
[00:19:20] It uses that whole machine now as part of a botnet, and it uses your machine that it's taken over to attack other machines. And unless you're paying a lot of attention, you probably don't even know that it's happened.
[00:19:37]What do you do here with ransomware? He gets in, it looks like it's something that it's not most often, it's a Trojan. Sometimes what happens is the bad guys are sending it all in because of a zero-day or more than likely because you haven't applied the patches to all of the software that you need to patch.
[00:20:01] So there's a few different things here, right? That, that you gotta be careful of. So do those, you hear it a million times. The next thing you can do to help prevent this from happening is to make sure your usernames, email addresses passwords are unique for every site you go to. Because some of these bad guys just go to the dark web, they can download for free your email, address your password from hundreds of websites.
[00:20:35] Yeah, it's available for them. It's been stolen, and it's been released in some cases, they have to pay for it, but, overall it's well worth their money spent to find out your username and password. So if you are working from home, let's say you're a homeworker for, let's say Colonial Pipeline here, making stuff up right now, a nonexisting company, and you're at home.
[00:21:01] He was supposed to be monitoring the pipeline, make sure the right valves are open when they're supposed to be open, make sure the fuel is flowing. Make sure all of the bills are getting paid invoices going out. And you're just doing it from home. And in fact, you got a nice little laptop set up in the corner of the bedroom, on a table.
[00:21:20]It's, it's the life. And then. All of a sudden you're losing control. Just what I, I know of two water systems where this happened. Yeah. Yeah. All of a sudden somebody finds your username and your password online and that email address. Yeah. Yeah.
[00:21:41] joe@colonialpipeline.com. Perfect. Okay. So let's look in the dark web. Oh, here's Joe's. Password that he used over on LinkedIn back when we stole all of those LinkedIn usernames and passwords and emails and everything else. So let's just try that because we see that at colonial pipeline. There's this remote desktop server.
[00:22:07] And we know that. Yeah, because we scan them in. There it is today, remote desktop server, you know what they eat the named it remote desktop, RDP dot colonial pipeline.com. Of course, we're talking about a fictional company here, but it's only now God, I use their name and email address and a password that has been used by Joe on one or more other websites.
[00:22:31] So what do they do? They say. I'm going to try. Let me see. Let me see. I'm going to connect right now to the Microsoft remote desktop server at colonial pipeline. And let's try and log in as joe@colonialpipeline.com and let's cut, copy and paste the email address that he was or a password he's using it.
[00:22:51] LinkedIn, you know what I just noticed he uses the same. Password even a few years back over at Facebook. So let's just try it. Oh, look at that. I'm in. I'm in. So what's the next step? The next step is, of course, they start to poke around a little, can I take control of this machine? Let's download my ransomware onto the machine.
[00:23:13] And of course this fictitious company known as colonial pipeline. They don't have a really great firewall that looks at it. Everything that's being put onto a machine downloaded. So it's not even going to notice that we're installing the most common form of ransomware on the internet today. So let's get that on his machine at work.
[00:23:35] Okay. At Tonya's machine at work and off. Okay. We got it. We're the remote controls working. So let's just connect from the remote. Desktop server and okay, so we're in now, let's see what other machines we can find on their network and off they go, this fictional company now because Joe had a username and a password that he has used before on another website, they were able to get into our fictional company.
[00:24:06]Does that make sense to you? So now they're inside, they're moving around. They're taking control. They're finding the computers that are used to control the valves, the flow of oil, or whatever's in the pipeline. This. Day and okay, so we're all set. So let's go ahead now because we've got all of their files, including all of their banking information while we were in there and
[00:24:31] we
[00:24:31] Craig Peterson: grabbed all yeah.
[00:24:33] All of the account numbers, all to their customer info. So let's let it loose. And now they start encrypting all of the data. And by the time this fictional pipeline company has figured out that they're on there. Guess what? Yeah. In fact, what happened was they found out that they had been hit with ransomware because the ransom messages came.
[00:25:03] So that is how it could happen. And that could happen to almost any company out there. And the reputation damage is enormous. The amount of money that is going to cost them is enormous. It's more than doubled in the last year. The cost on average now is over $1.2 million because of a breach and ransomware.
[00:25:29] And so now they're in big trouble. Really big trouble. So how could you have stopped this? That's where life gets interesting. And I have done a number of webinars on that very thing we've delved into in some detail, it's been about a year and I'm thinking what I'm going to do is just put together some little courses that if you're on my email list, you'll find out about just little free things in order to help you guys understand this a little bit better.
[00:26:00]So I'll make sure you're on my email list. Craig peterson.com/subscribe, and I'll explain it all. So here's what you can do. First of all, get a various smart, next generation firewall. Now, one thing about cybersecurity that you'll find is there are a lot of criminals out there. A lot of criminals and.
[00:26:25] I'm not just talking about the people that put ransomware on your machine. I'm talking about the people that are telling you to buy their VPN product because it's going to make you safe, and they're lying about it. And they're really lawyering their words. So that, that perception that you have is somehow you're going to be safe.
[00:26:43] I'm talking about the people that will sell you this. Anti-virus software that not only do not need but could potentially open you up to even more security problems, just like the VPNs can open you up to more security problems. It is full. Of criminals. They just haven't been convicted yet. Okay. So it, it's definitely a problem, a very major problem for so many people and you just don't know.
[00:27:14]So that's why I want to make sure you guys understand why it's happening and the how it's happening to can. Then go on to the next step and what do I need to do to keep it out? So a really good next generation firewall, by my definition, means that firewall is going to examine all data coming in and going out.
[00:27:40] So it's going to be able to look at anything that's encrypted at websites that are encrypted at data that's being downloaded at zip files that are being downloaded and check the payload to make sure. That it is legitimate traffic. Okay. It sounds easy, but again, there's so many criminals in the cybersecurity business.
[00:28:03] You have to look very closely stick around.
[00:28:06] So if the bad guys have control of a machine and they are trying to download some malware, in this case, ransomware, the firewall is going to see that and stop it right there.
[00:28:20]Most firewalls, all they'll do is block certain ports, or they will stop as someone on the outside from getting. To the inside, but what about you going to a website and downloading accidentally, or maybe purposely downloading some software? That's malicious. Or what about some guy the got onto your computer via your VPN connection or your remote desktop or team viewer, et cetera.
[00:28:51] And now has control of your computer. You have to watch all of the data coming in, going out, and it all needs to be checked for. Any sort of malware. So that's one of the first things we always do. Now. The next thing has to do with your computer. I'm going to focus in on windows because that's what most people have.
[00:29:14] Nowadays. If you have a Mac, you're relatively safe. If you have a Google Chromebook again, You're relatively safe. Just keep them up to date. All right. But windows, windows is a whole other world and you know how much I love windows. Yeah, not right. And I worked on it way back when in the empty days.
[00:29:39] Anyhow. Microsoft Windows has built into it. Now, some very good software that can help protect you. Windows defender, make sure windows defender is turned on and is up to date. If you have windows. And it's a recent version, and you need to be running a recent version of windows. Then you have access to windows defender, turn that on.
[00:30:08] And windows defender again, keeps an eye out for malicious software. Oh, really? Who knows windows better than Microsoft? I would argue there are some people, but as a general rule, Microsoft understands what they're doing here. They have kept it up to date, right? They have had major security problems in the past with windows, the vendor itself, but most of those are fixed now.
[00:30:33] And to me, the measure of success isn't, Hey, it's a hundred percent secure because you and I both know that's a load of cow stuff, because nothing's a hundred percent secure. And whether it's made by Microsoft or it's made by Cisco. There could potentially be problems. So Microsoft has fixed the known problems anyways, in windows defender.
[00:31:00] So make sure that is turned on. That's the first free tool I wanted to mention, and it is huge. The next one is, of course, make sure you're up. Dating your machine. I don't mean just windows, make sure all of the other software in your machine is being updated. If you're using a browser like Firefox or even Google Chrome, I have issues with Google Chrome from a privacy standpoint, but at least both of those browsers and many others that are based on either one of them, the both of those browsers do.
[00:31:36] Update themselves automatically. So that's like a huge win. So they'll keep themselves up to date, but most of the Adobe software won't keep itself up to date. Most other third party applications that you might've bought and installed on your computer or downloaded. They're not going to keep themselves up to date.
[00:31:56] So keep on top of that. That's the second thing you can do. That's usually free. I would say usually because Microsoft does sometimes charge you for upgrades. I'm not sure they're going to do that anymore. The whole naming scheme and everything else, numbering scheme for windows indicates that maybe they've dropped that idea.
[00:32:18] Yeah. But some of these other vendors might charge you for new release. So let's say Microsoft really decides I'm working on our climb down. We're not going to let this malware continue to give us a black eye. And so they changed the way parts of the operating system work. And so that software you're using for your customer management billing, whatever might be requires an upgrade, which of course that vendor's going to call a major upgrade.
[00:32:45] And now you've got to do the app. Great. And you've probably got to pay them in order to get your hands on that upgrade. So that's why I said usually free, not always free. Microsoft also comes with a firewall, and I use that term very loosely because it's an old style firewall. It is just protecting data on certain parts.
[00:33:10] And Microsoft does a very poor job of configuring that firewall. Basically, Microsoft doesn't want any tech support calls. So they pretty much turned on all of the features that you could possibly have. And when it comes to the firewall, they just leave them all wide open. To me, that's a huge problem. So yeah, the firewall is turned on by default on windows.
[00:33:38] It is by the way off by default on your Mac. And both of those companies take much different approaches on the Mac. Nothing is enabled that doesn't, isn't explicitly turned on. So there's not a whole lot of reason for a firewall because you don't have a file server running on your machine. SMB file sharing.
[00:34:00] You don't have a way a web browser running on your machine, et cetera, et cetera, all of that stuff you have to turn on manually. So on windows. I've I have a course that I haven't released yet. That talks about how to harden windows. I did my improving windows security course. I released that in April of 21 and a lot of you guys signed up for it and I've had nothing but great feedback, a few legitimate.
[00:34:28] Questions people have, but great feedback over the course. So I'm going to have to do one on specifically the firewall on, on windows and maybe the windows defenders as well, but you're going to want to turn off any services you're not using. And I do describe that in the improving windows privacy and security course.
[00:34:50] So if you took that. You've Oh, and you did it. You've got really your mission locked down. Noah came anyways. I'm rambling. Next up. Remember I said that the malware calls home, both ransomware malware, calling home to say, Hey, look what I found. You want to have a poke around. And another piece of nastiness called a botnet.
[00:35:18] Where the button that will again, call home to the bad guys and say, here I am, let me know what you want me to do. And very frequently they'll use your computer. It might be a home computer might be a business computer. They love business computers because usually they have a better internet connection.
[00:35:37] And they'll use your computer. Just send out a hundred million pieces of spam to any email address they can find. And once they've done that, of course, what's attached to that email while ransomware or other nastiness that's out there. So how do you stop them from calling home? Again, the non-paid or the paid, I should say option is a really good next generation firewall.
[00:36:05] So we had a client that has an office here and an office that's out of state. And what happened was one of their of state offices had connected in via a VPN that we had warned about. And being in properly set up and configured and protected. So they came in on that VPN, the bad guys did because they had control of these out-of-state computers and they found accounting files, and they started to upload them.
[00:36:38] So we had a really good next generation firewall from Cisco in place of firepower firewall. And we've got all kinds of equipment in our data center that, that controls all of that, but it saw, wait a minute. There's data being exfiltrated we're seeing in their account information potentially. So I would shut it right down.
[00:37:01] So they got a few megabytes worth of data out and that's it. We shut it right down. It was all automatic. And then it informed us, Hey, look at what we just did. You might want to have a closer look, which of course we did do. So having that next generation firewall that can recognize data coming into your network and going out of your network is crucial.
[00:37:27] The other thing that you can do, and you can do it for free or paid, the $50 a month charge that we have for endpoint computers. In other words for desktops is includes a paid version of this. Which is more advanced, but you can get it also for free. And it's obviously it's not as good and as many options, et cetera, et cetera, not men really for business, but checkout open DNS online.
[00:37:58] You can go there right now. Just open D N s.com. Open-domain name server.com. And you can find out how to do it there, but it is as simple as setting your name servers to the addresses. You'll find right@thebottomoftheopendns.com homepage. So you'd set it to two Oh eight 67 two two two-dot two, two, two.
[00:38:26] And. Let it do its thing. So what happens now, once you've set up your DNS using open DNS, and again, you can get it for free and the low end. And then at the higher end, it's called Cisco umbrella and a lot more features, but when the bad guys trying call home, they need to convert the name of their server.
[00:38:48] Into an internet address and open DNS is updated quite frequently. I know the commercial versions that we have are updated instantaneously 24 seven, whenever anything is discovered. And I think the free open DNS is pretty close to that. So put that in place. Do some of these other things I've been telling you about, and you're going to be 95% ish safe.
[00:39:17] That's pretty good. Isn't it for nothing plus the firewall, which can cost you some real money. Some of these real fast firewalls can cost over a hundred grand for a very large business, you can start at just a few grand anyways.
[00:39:32]Colonial pipeline. Of course it hit the East coast hard. It particularly hit the Southern state, some of whom declared States of emergency because of what was happening, panic buying. I don't know if you saw the pictures of people with a gap, with a gas in.
[00:39:51] Trash bags, clear trash bags, people buying every fuel can, they could fill it up with gasoline, somebody dangerous things. I remember back in the sixties, a friend of my dad's had this beautiful Corvette. I'd love to have one of those nowadays, and he needed to get some gas for the lawnmower. So we went down to buy it, and he had a gallon jug that he filled up with gasoline.
[00:40:17] Oh, my gosh. And we had this glass one gallon jug in the back with me. This was the Corvette where there was that little, a two piece window in the back. And that's where I was just a little kid. What happens if you're in an accident? It just, these people who are doing this are crazy. Plus the gasoline is almost guaranteed to break down that trash bag.
[00:40:43] This it's just not true. What people have been doing. No man, no wonder people have been calling it the latest toilet paper fear, right? Where everybody went out to buy toilet paper, but this is a real. Problem. We've got Saudi you do remember this Aramco. They were probably hacked by Iran about a decade ago, and we've seen hacks against all kinds of other utilities, these public service, if you will utilities that provide us with.
[00:41:14] Pretty much everything that we need for our daily lives. And colonial apparently had a cyber health assessment about five years ago, give or take. Now it sounds like it was the same thing that we do for businesses, a paid one versus the free ones. And I've got. A checklist that you can use.
[00:41:36]I'll send it to you. All you have to do is ask me for it. And you can use that to get an idea of what are the things you should be doing to prevent this. What are the things you can do as well? And if you listen to the first hour today, show of course, I went through some of the free things you can do as well to help prevent all of this sort of thing.
[00:41:56] So they did go through a cybersecurity analysis. Apparently, they did not follow through on all of the recommendations. And as I started out this segment today, one of the things that's really probable, probably behind this is because they didn't know what they needed to do. So many of us are using people who are great people.
[00:42:22] They love computers. They've been learning a lot about cybersecurity, but none of the snow, everything. And unfortunately, so many of us just don't know enough. And we're talking about over one, 1 million to 2 million open jobs in cybersecurity. So everybody's hanging up their hat. Everybody's putting out a shingle saying I'm a cybersecurity expert person.
[00:42:47] I've got months, even, maybe even years worth of training. That's all well and good, but you still need to have a third party come in and look, and then you have to follow the recommendations. That's the other big problem I found is businesses just not following the recommendations. And then we get calls back in on average.
[00:43:08] I think we figured it out a couple of months back. It was like eight months after we do a cyber health assessment for someone they come to us and say yeah, we got hacked. Can you fix this for us? And in some cases, we're able to close things up and help them out. Just like the phone call we had this week.
[00:43:25] And they had taken some of the right steps to make sure that they shut down these hackers. But there's a lot of things I just plain didn't do. And that's a problem, right? We have government contractors that are subs, and sometimes these guys have the primary contracts, and they're out there in the front line.
[00:43:48] They have potential prison terms. If data is stolen, Now this last week, this week, right this week. Okay. It's Saturday now, president Biden signed an executive order that is starting to put teeth into these laws. If you even sell something to someone that ultimately has a contract with the federal government, you've got some serious liability now.
[00:44:18] If data is stolen and we could get into a lot of details because it happens all the time and people have businesses and they say I just make X product, but the only customer for product X is the government. And you just had all of the purchase orders stolen. And think about Hogan's heroes, right?
[00:44:40] If you remember that show back in the sixties and early seventies and in the whole Cogans heroes, what ended up happening is they were looking at it all saying what should we do? What can we do? When we're were to get a little bit of information and they do everything they possibly could to get that information back to London.
[00:45:00] And sorry about that. A little phone ringing here. So they're trying to get all that information back to London. Some of it, they got back, some of it, they didn't get back, et cetera, et cetera. But just that little bit about wait a minute, now they just bought 50 of these. Therefore we're thinking that the military.
[00:45:19] Is now starting to expand and is going to be doing this or doing that in this area, that area, right? Those little bits of information are valuable, not just to someone like Iran or to Russia or to China, it's valuable to competitors. So president Biden's latest little executive order is really starting to.
[00:45:44] Bite into all of these contractors that have been, as we call a pencil whipping forms. Now the SPRs forums as the type of form, they have to go online. They have to report about what their compliance is for their cybersecurity maturity. They don't know what they're doing. They don't know what they're filling out.
[00:46:01]I'm thinking maybe I should go ahead and. Put one more little trick into this whole thing. And that is have a a service where we help businesses fill out their paperwork and understand it. But the reason I haven't done that is because the businesses that I know that have been lying on these forums, pencil whipping the forums, they don't really want to know.
[00:46:29] Cause then they have plausible deniability. So how do we solve this problem? It really bothers me, frankly. When we come back, I'm going to talk about these five urgent actions that are happening right now, where these 65 businesses, nonprofits, and NGOs have formed this ransomware task force.
[00:46:51] What this is about, what it's hopefully going to help everybody out with. But I want to really emphasize again, do you guys. Make sure you have a good cybersecurity health assessment. You have to have that. And if you get a cha cybersecurity health assessment, I'm more glad this end of the paperwork, you can do it yourself.
[00:47:14] Okay. The basics and you know what else I'm going to do. I'm going to have a training on this. That's available for free. I'll put that up on my website so that you know what each one of those questions really means. It's so that you can now. Have a good look at your cybersecurity. Cause I know a lot of you guys you're retired.
[00:47:34] You have some money that you're trying to protect from these bad guys. A ton of you guys are small business owners like me, right? I've owned and run small businesses for decades now. And. We just are focused on our businesses and just don't know everything we need to know. We don't even know what we don't know right.
[00:47:56] About cybersecurity. So I'm going to help you with that. But when we get back, we're going to talk about these fights. If you want to reach out to me, if you want a copy of any of these cybersecurity health assessment forms. I'll send them to you. No problem. Just email me. M e@craigpeterson.com or reply to tomorrow's email.
[00:48:17] If you're on my email list, I'll be glad to get that off to you. No problems, no questions asked. I'm not going to be harassing you. If you want us to do a deeper dive, where we look at your systems, we scan them all. We help you prioritize it. We put together a series of steps that you can take to make sure all of the is done in the order that it really should be done in.
[00:48:42] Yeah. Be glad to do that, to that, to pay the assessment. There are a number of companies out there that do it. There's about 1200 nationwide. So you should be able to find somebody if you don't trust me, I get it. That's fine. But get one done, get a very good one done and go deep into it. We're also hopefully going to be able to get into some of the other articles, and you'll find all of these, of course, in tomorrow's newsletter.
[00:49:09] And you can get that by just going to Craig peterson.com/subscribe by Google, wants people to use two factor authentication, which I think is a great idea. So it's going to start turning it on for you guys. App tracking. Apple has just gone above and beyond yet again in helping to keep our data secure.
[00:49:30] Thank goodness, not just secure, but. Private Peloton man. They're hurting again. Total mess up on their part again, cybersecurity, absolutely cybersecurity problems.
[00:49:42]Now we've mentioned here in the last hour about DarkSide ransomware, and these are groups. Both bad guys that have been doing ransomware for a long time and more lately, they've gotten together and built a company and this company actually sells ransomware services. Now I don't mean that if you've been hacked to go to the DarkSide and say, Oh my gosh, we got ransomware.
[00:50:10] Fix it for us. No, they are selling. Ransomware as a service and the hers there. There's a huge problem with this. It's just absolutely amazing, but there's some security researchers out there who have been trying to find out okay. Who. Is using them. So let's give you a couple of numbers here. So you have an idea of how much money DarkSide is making by selling this as a service.
[00:50:40] So they, they do everything. They write the software that holds your stuff ransom. They go ahead on that software, and we'll do tech support, not just for the people that have licensed their software, but tech support for you. The poor ransom me. Okay. All of that stuff, but according to what is in, let me see ZD net.
[00:51:05] They went and had some researchers check out the DarkSide, ransomware variants website, and there's some forum posts there that indicate that affiliation with DarkSiderequires 25% of the cut for ransomware payments under 500,000. And it has a sliding scale. So if you can ransom somebody. For more than 5 million, all they want is 10% of the money.
[00:51:36] Can you believe this talking about a real business? It's just incredible. So they are out there and they are really rampant now. And they've been doing it since last summer, this whole double extortion tactic and something they've really fine tuned where they say pay us. And we will decrypt your data. At least we'll give you the key and help you decrypt it, or don't pay us now, but pay us later.
[00:52:03] So we don't release your data. As I mentioned, that's what's happened with the Metro DC Washington DC police department that got the data out of the police department, and they're threatening to release it. If the DC police don't pay the right money to them. So these guys, these researchers and this particular cases, fire, I said, they have found five groups that are doing rants that are linked with the DarkSide, bad guys.
[00:52:36] And they've got these letters, numbers. It's not real names. It's just what they've been labeled. But the, I wanted to go through here. What these. Different affiliated DarkSide, ransomware gangs are doing so there's one where there's was to start with one we'll run through all five and what their tactics are.
[00:53:00] But this first one, which is identified as UNC 26, 28 has been active since February this year. Now, remember how I mentioned how they'll get into your network and then they'll start to move. Laterally within the network, they'll try and infect other machines. If they get onto your home machine, they'll go through the VPN that you're using to connect to the office.
[00:53:21] And. Once they're there, they'll start spreading between office machines. And there's some thinking that has actually happened in the case of the colonial pipeline. We'll know more details. I hope fairly soon I've been watching what the FBI has been saying. They send me updates, but I haven't seen anything.
[00:53:41] That's publicly shareable at this point in time. Anyways. So this lateral movement is where they're really going to kill you. And this first group tends to move quickly from the initial infection where they get the software on your machine. And they're only lurking on your network for two, two to three days before they start the encryption.
[00:54:06] That's all the time it takes for them to find all of your machines. Now they use suspicious authentication attempts, brute force attacks. Spray and pray tactics, all common spray and pray means they're just looking for anybody out there. They're not going after a specific target. They'll find your home, the computer and bam they're in and they'll just take bank account information, or they might use your machine for attacking other people, including by the way, attacking governments and governments don't take well to having your computer attack them.
[00:54:40] Okay. So they. Apparently, I'm just trying to summarize all of this as we're going, but they get their initial access through legitimate credentials for corporate virtual private networks. What have I been telling you for a long time? VPNs are not the panacea. Most people think they are, and they purchase it from other criminals.
[00:55:02] Next group, 26, 28. Is thought to partner with other of these services besides DarkSide and includes revival and net Walker. Another one has been active since at least January, they moved from initial access to ransomware deployment at an average of 10 days. So it used to be about two weeks. And that's where I've been saying for a long time, that most of the time when you get ransomware, They'll be in your network, poking around for a couple of weeks, but it's been so profitable.
[00:55:36] They may well hire more people and spread more quickly. So instead of 14 days is now down to three to 10 days. According to this report, I'm looking at right now, from what FireEye has said and fire, I do do investigations of these types of things. And in fact, they got involved in some political stuff, not too long ago as well.
[00:55:57] Team viewer home. My gosh, Microsoft team viewer. It's abused to maintain the persistence in connections. That's where they can continue to be on your machine. Get on a compromised machine, and then they exfiltrate your files before they encrypt them. Next one here, dating back for a little over a year.
[00:56:20] They use a phishing name. Emails to deliver this DarkSide ransomware, and they use a smoked ham net backdoor. So there go here. This group can wait on your network and lurk for months ahead of when they actually fire up their ransomware and our friends. Over at Sofo said that they've been called in to assist on five different instances of DarkSide ransomware infection.
[00:56:52] So there's a lot to know there's a lot to be concerned about, but remember they get in blocking them. The way I told you in the last hour is really going to help. It's going to stop more than 95% of them, and it doesn't have to cost you a dime. Mind you, the paid versions are going to be better, but that's the way that is.
[00:57:13] And we also now have these 65 businesses, which includes some nonprofits, government organizations, and formed this ransomware task force. So that's, I think good. News to all of us world economic forums involved in this as well. And they're just trying to really help. Now, what I get concerned about is the government's involvement, and it's one thing for the government to follow up after an attack.
[00:57:44] Okay. And it's another thing for the government to provide general information. In fact, you can find it. The small business association has quite a bit of stuff, not as detailed. I don't think it's anywhere near as good as the free cyber health assessment forms that I can send you. But they, we do have it.
[00:58:01] A lot of places have it, and it is well worth looking into. I, so yeah, here we go. Average downtime due to ransomware attacks, 21 days, get that thorough cyber health assessment done. Now whether you do it yourself, you hire somebody to come in and do it. Or we did 1100 of these last year for free for listeners and their businesses.
[00:58:29] So more than glad to do it as well. Just email me@craigpeterson.com and I'll get all the info out to you.
[00:58:36]Look at what's happening right now with.
[00:58:38] The whole colonial pipeline thing, and I am more than glad to help you guys out. And all you have to do is just go ahead and email me M e@craigpeterson.com. All right. Getting down to it here. Two factor authentication. A lot of people have started using. Text messages as part of two factor authentication.
[00:59:02] So for instance, you go to a website, you put in your username, which is usually your email address, which is a bad idea from these people that coded up this terrible software, right? You should be able to choose your own username, so you can have a different username on every website, and then you put in your password.
[00:59:19] And of course you guys. Best and brightest, you are using different passwords on every website, and hopefully you're also using a password manager to keep track of it all. I were really surprised. I looked at it. I had 1200, 1200 different. Accounts on different websites. So then you probably have more than you realize, but SMS, text messages are not the best way to do two factor authentication.
[00:59:53] The idea behind a secure system, just a regular login security is, do have something, along with something you have. So there's something, is your username and your password. Something you have. That's a lot different, isn't it? And having your phone with you that can receive a text message is not really going to protect you, especially if they are out to get you.
[01:00:17] So if you have a fair amount of money in investments, maybe you have some Bitcoin, et cetera, many. Times now there are a lot of examples I can cite of people who have had their phone number hijacked. So the bad guys remember the, all these data, leach data breaches, these leaks, where they've got your username, they've got your password, they've got your phone number.
[01:00:42] So if they really want to take over everything, all they have to do is. Grab ahold of your phone number, because most of the time, how do you recover your password on our site? Oh, I just go ahead and have it, send me a text message. What happens if instead of that text message going to you, that text message goes to a bad guy because they've taken control of your phone number.
[01:01:07] It happens. It happens every day. So Google has an idea that I think is a pretty reasonable one. And Google has for a long time, had an app called Google authenticator. And I used that when it first came out, and I played around with it a little bit nowadays I've been using duo, and I've got, go do all set up so that.
[01:01:27] I can put in a one-time password thing, but that changes every 30 seconds or so. And you might've used those before. Sometimes it's a token, et cetera. But what Google has done for two factor authentication is they have it set up so that when you go to login. If you have a Google program on your smartphone, it will have you open up Google, for instance, the app on your smartphone.
[01:01:55] And then you confirm that yes, it is me who is logging in. It's not a bad idea. They do it a little different on Android. Google's prompt is a full screen. Popup is built into every Android device as part of Google play services. So it's really pretty easy. This is going to be, I think, a good game changer because otherwise you're in trouble.
[01:02:20] I just got a call. This is just crazy. Yeah. What a week, this week from another listener, who's a church. This particular church had been basically hacked and their main email account was hacked into the bank account. It just goes on and on. And it smells like they may have access to his text messages, which are used for account.
[01:02:48] Recovery. So this type of two factor authentication thing that Google is pushing out. Yeah. I think is a very good idea. They're becoming a little more proactive and it's, I think it's going to be good. Yeah. Overall we'll see how this all goes. There are some other ways to do it. I think maybe some better ways, but this is not a bad way.
[01:03:14] Now speaking about privacy versus security, we've been talking so far about security. That's what two-factor authentication is all about. And if you want a little privacy, Android slash Google is not the way to go. You know that already. I say every time that you should be using duck, Go, not Google to do searches online, to find stuff well, Apple released their newest version of iOS, which is of course the operating system for the iPhone and for the eye pad.
[01:03:48] And I guess the iPod, right? Like the iPod touch and stuff, but this operating system has now code in it that pops up and asks you if you want to allow an app to track your activity across other companies, apps, and websites. This I think is a very good thing. At least, that they're trying to track you, right?
[01:04:13] So Facebook has been complaining about this for a long time. The experts said probably 40%, maybe 60%, let's call it. 50% of people will allow the app tracking. It turns out that 96% of users in the us have opted out of app tracking. In this latest version of iOS, which to me makes a lot of sense. In other words, only 4% of people said, yeah, you can track me.
[01:04:44] What does this mean? Obviously to you as a consumer, it might be good. It actually might be bad. Again, if I want to buy an F150 pickup truck, I wanna buy an F150 pickup truck. Now, maybe you could try and talk me into buying a Dodger Chevy or something else. I get it, but I want a pickup truck. I don't care about seeing ads for women's pajamas or you name it.
[01:05:16] I'm looking for a pickup truck. So I want to see ads that are aimed at me for something that I want. I you're probably the same way you remember those days on the internet, where you were constantly getting these male enhancement. Emails. And they went out to everybody because they had no idea who you were.
[01:05:38] They didn't have any information about you. And when Facebook and Google and some of these others came along, all of a sudden you were getting more relevant information. By not allowing them to track you, you are going to be getting ads that maybe aren't as relevant as they used to be. Now on the other side, it's nice not having them track you because it's none of their business.
[01:06:04]But it's, I think it's overall a good thing. Reminds me of Tom cruise in minority report where he's walking past those billboards, and they scan his eye. As all that's possible from that distance. And they recognize him as, what was it, Mr. Tadashi or something? Not definitely not him. And they were trying to sell him something that were tied into what Mr.
[01:06:29] Tadashi had purchased before. And the machines, just the billboard just thought it was Mr. DACI not the Tom Cruise character. So this is going to change quite a few things. If you are a. Business. You're going to have a little bit of a harder time trying to track people, which also means, by the way, and not distract people, but, find people that are of interest to you.
[01:06:53]I want somebody that's a white male in his mid forties who drives an F150 that is 10 years old, which means, okay, he's probably going to buy another one. You're going to have a little bit of a harder time with some of that tracking. So it's going to cost you a little bit more for some of the advertising, but I think it's also going to drive down the cost of ads on some of these platforms, because they're not going to be able to target as closely as they could be for all right.
[01:07:20] really we're everywhere. All you have to do is you can find the podcast. You can go to tune-in dot com and of course you can just ask your Amazon Alexa, Alexa, play. W G a N and off she'll go, there are so many articles to talk about this week.
[01:07:36] You will find all of them in my newsletter. And what I typically do in the newsletter is not only do I go through hundreds of articles and put together a collection of what I think are the most important ones, the best ones for you guys to be able to follow. But I also send you right to the person's website that put the article out.
[01:08:00] So they get a little bit of credit. Maybe they get a little bit of advertising revenue, that revenue we talked about in the last segment today. But I think that's the way it only fair to everybody involved. Although obviously I'm adding a lot of my own commentary. So if you want to hear what I had to say about it, Subscribe to my podcast.
[01:08:24] Just go to Craig peterson.com/podcast. You can listen to them there, or if you are a podcast listener, I'd really appreciate a comment. Hopefully I've earned five stars from you. Just go to Craig peterson.com/itunes, and we will. At that point be able to track it a little bit subscribing to the podcast really helps us.
[01:08:49] And that's how some of these podcasts are measured and I'm doing this all without any commercial content. On the podcast that I do, obviously here, there's some great companies that are supporting us and trying to get this message out. And I appreciate them for advertising, but on the podcast has used subscribing that really helps Peloton.
[01:09:12] You do remember Christmas, was it last year or the year before Peloton running these ads and this guy was going to buy this exercise bike from Peloton for his wife. And it seemed like a great Christmas gift for her. She seemed to be very excited about it. And then all of these snowflakes started saying, Oh, that's just terrible.
[01:09:35] I like it. Was you doing saying she's fat. What's going on? Obviously she wanted one of these Peloton bikes cause they are amazing. Peloton has done just a great job in tying it into internet training, and you've got a coach, and you've got some really good hardware. The only in the form of the bike and Peloton has some other things as well.
[01:09:57] So they really got nailed over that one and I think a little bit unfairly. And then we also had here within the last week, two weeks. Recall by Peloton on two treadmill models. And this was following the death of a six-year old child who was pulled under one of these treadmills is a terrible, I know I've gotten caught up in them before as well.
[01:10:24] And the consumer product safety commission said that the recall decision took some intense negotiation. Because they're, Peloton, they didn't want to get nailed for something and it wasn't really their fault. But the CEO of Peloton did admit that there was a mistake here, but this is just, it's a terrible thing to think of.
[01:10:48] In addition to this death, apparently Peloton received at least 72 other reports, according to ARS, Technica of adults, children, pets, and or objects getting dragged under. The tread plus treadmill 29 children suffered injuries. Second and third degree abrasions, broken bones, lacerations pretty bad all the way around, you've got moving.
[01:11:13] Parts stuff can happen. I don't know. It's do we really need a label on our lawnmower telling us not to use it, to cut our hair? It's bad. It's terrible in any of these things happen. Oh my gosh. I'm not going to read the details here, but this poor little boy's three-year-old son.
[01:11:32] No, I'm the parent involved. I'm sure he felt feels this terrible. So there you go. That's problem. Number one, Peloton had and within the last week obviously a major problem considering what happened, but also. Piling on to what happened at Christmas, with all of the snowflakes complaining.
[01:11:54]It's now come to light the Peloton exposed sensitive user data and continued to expose it even after it knew about the leak. So it's no wonder Peloton stock price closed down 15% on Wednesday. Now I've got to add to that, that because of the lockdown, starting to go away. A lot, fewer people I think are going to be exercising indoor on their Peloton, but it's still going to happen.
[01:12:23] They've got a lot of stationary bikes got a lot of treadmills, but 3 million members, according to their stockholder report and the data exposed include the user IDs, instructor, IDs, group memberships workout stats, their sex and their age, their weight. If they're in a studio or not There's apparently another piece of personal data exposed that the Peloton still hasn't secured.
[01:12:50] And so ours check Nicola where this article was published, said, we're not going to tell you about it because it's still being exposed. It's pretty bad. Apparently again, this is just bad programming. It's the API APIs, these application programming interfaces that are used by programmers.
[01:13:09] That are used to connect to cloud services, et cetera required no authentication before providing the information. I was reading an article this week, too. On an API might've actually been theirs, but again, no authentication says, okay, we'll lock it down. We're going to lock it down. So how do they lock it down?
[01:13:30]They put a username and password on it. Okay. That sounds reasonable. But if you had a username and password, you could access. Any personal information on any API call? I didn't just restrict it to yours. Oh my gosh. Yeah. Totally barked fixed. In fact that it looks like it was Peloton who botched that fix.
[01:13:53] Okay. Move onto the next one. We've got a lot of stuff here I RRS is, has been for a long time. Warning people. Hey, listen. If you have an asset. And you sell that asset. You have to pay taxes, and we've got President Biden now saying, Hey, if you invest in a company and you lose money, it's too bad, so sad. But if you make money, now you've got to pay taxes on it.
[01:14:19] And they're saying the same thing about, of course, Bitcoin investments and not just Bitcoin, any cryptocurrency trades. Now they have the IRS been granted permission by federal court in the Northern District of California to issue a John DOE summons. And what they have done is they've sent us summons off to this company called cracking and cracking is a us facing arm of something called pay word ventures, according to ZD Net.
[01:14:56] And what they've said is they want information on any us taxpayers who conducted at least $20,000 or the equivalent in cryptocurrency trades between 2016 and 20. 20 now they're not alleging that there's any wrongdoing. Cause we know every last person that did a cryptocurrency trade and made money on it, paid the taxes.
[01:15:22] And we already know president Biden is planning on increasing those taxes to over 30% right now. Say lovey. What are you going to do? According to the IRS convertible cryptocurrency. In other words, cur cryptocurrency that you can trade for Fiat currency, your affirms, your dollars such as Bitcoin may have tax liabilities.
[01:15:46] All in fact it does. So keep that in mind, everybody. That you sell these things, you owe money on them, just like if you sold anything else, frankly. So apples, I mentioned the last segment here, but Apple's new iPhone, anti-tracking feature. It is being called devastating for Facebook. And I agree with that.
[01:16:11] Absolutely agree with it. And this is from bgr.com. They've got a lot of great technical stuff up there. But Apple rolled out this new iOS update, and it's forcing developers to ask for consent before tracking users across your Apple apps, which I think is really great. But what's interesting is that Facebook is looking at a devastating loss in revenue.
[01:16:41] Lisa asked her, they're saying at this point, both Facebook and Instagram have come out and said that they might no longer be free. And if you block the tracking there, he might start charging you. So we'll see what happens obviously. Facebook and Instagram can still track you within their application.
[01:17:03] Although they're supposed to tell you what they're doing with your data, and if you go into the Apple app store and you pull up, for instance, the Facebook app, it will tell you right there in the app store, you scroll down a little bit. To the privacy section. It'll tell you what it is Facebook is doing with your data right now, that self reported, but we'll see what ends up happening.
[01:17:29] I'm looking at these opt-out rates cyst. It's crazy. There's a whole bunch of graphs here showing how people just don't want to be tracked. So it makes a whole lot of sense, frankly, a whole lot of sense. Let's see. And. Our last one here is really, I think the bottom line fought for the day. Ransomware is up dramatically.
[01:17:54] We've seen triple the amount of hacks ransomware hacks in the last year we have seen. Doubling of ransomware payments, the average business that gets ransomware, it takes them on average about nine months to get back to normal nine months. So I really want you guys to spend a couple of minutes. If you want me to send you, I'll be glad to a checklist of what you can do.
[01:18:27] For a self, some self audited here, cybersecurity assessment. I'd be glad to do that. I can send it to you. If you want to have one done by a third party, by all means, do it and then follow the instructions. That's something that we do as well. But I can send all of this to you. Just email me@craigpeterson.com please do it.
[01:18:50] An individual or a business. This is going to help you out so much. Just me, CraigPeterson.com. I got all kinds of free stuff. That's going to help you out.
[01:19:00]

View Details

Thanks for downloading Podcast 1111 - May 1, 2021.

Uber and Lyft have both sold their self-driving car divisions. Washington DC Police are in a lot of trouble due to Ransomware. The latest trend in Cloud Computing is hazardous. How to tell if your laptop is sick and how to fix it. Costs of Ransomware have doubled in 12 months. Why I think China is threatening Taiwan. Finally, Emotet has been taken down. SpaceX is winning the Satellite-Internet war.

For more tech tips, news, and updates, visit - CraigPeterson.com.


Articles for this week:

An ambitious plan to tackle ransomware faces long odds

Tile bashes Apple’s new AirTag as unfair competition

More US agencies potentially hacked, this time with Pulse Secure exploits

The saga of McDonald’s ice cream machines and why they’re out of order all the time - Right-to-Repair

Apple agrees to let Parler back on the App Store, citing improved moderation

Hacker hacks the Police hacking tool - and leaves a “bomb” in place

How to Secure Employees' Home Wi-Fi Networks

The Google Offices of the Future Has Privacy Robots, Meeting Tents, and Your Very Own Balloon Wall

---

Automated Machine-Generated Transcript:

Podcast 1111 - May 01, 2021

Craig Peterson: Self-driving cars have been all the rage. Well, at least talking about them for what are the last four or five years. Well, Lyft and Uber both had big projects when it came to self-driving cars, and both of them have changed their minds. We're going to talk about that.

[00:00:21] Good afternoon, everybody. Craig Peterson, here I've been out for the last couple of weeks. Sorry. I've been here on the weekend, and I'm here again today. We're going to talk about a lot of very interesting stuff that's going on. Hopefully, I can explain to you a little bit about the why that helps you understand the how of what's going on. It's just become so crazy complex.

[00:00:48]That also gets into Lyft, this whole self-driving car thing. Uber, you've got every major player kind of in the world getting into this whole game, including, of course, Apple and Google. They both have big projects going on. GM, Ford, and every major manufacturer, Fiat, has an electric car, and of course, they've got aspirations. Hey, by the way, if you really want to cause some problems with Fiat-Chrysler's finances, buy one of their little electric cars, a little E 500. I don't know if you've seen these little Fiats driving around. They're cool little cars, the type of thing you'd expect in a big city or maybe in Europe somewhere. Just these tiny things. Like the smart cars only slightly bigger. Fiat loses $20,000 for every one of these $33,000 little cars you buy. Electric cars. It only goes 87 miles on a charge. That's the killer, right? 87 miles. Are you kidding me?

[00:01:52] We'll talk more about this later on because there's some study information out now that talks about people that bought electric cars. How many went back to gas engines, and why? It's interesting when you get into the numbers, the people that are switching back, by the way. Tend to be women more than men, but anyway, so we'll get into that in a few minutes here.

[00:02:16] Lyft and Uber, both saw themselves as companies that should be in the self-driving car business. I have learned over the years that you have to focus your business on your business. So what is it? Make your business very narrow don't run after every little opportunity that comes up, don't take every potential customer that comes your way because you probably can't deal with it. It requires a focus, a real focus, in order to be very successful. Otherwise, you can't make your business grow. So because of every customer's different, if everything about the customer's different, you're going to have true experts.

[00:03:01] That's the problem I've had over the years because I've always enjoyed a little bit of a change, a little bit of a difference. So, we've helped all kinds of companies from multinationals with their cybersecurity all the way on, down through little guys.

[00:03:15] Now, when you think about that, I've been crazy. For all of these years, to quote Paul Simon and my craziness has to do with the fact that they're entirely different beasts.

[00:03:26]So, now we're putting together some standardized packages based on what we've been using and selling for more than 20 years now, just to make my life a little bit simpler so, we can handle more clients cause there's more and more them that need it.

[00:03:40] So, when we're looking at Uber and Lyft, how does it fit? What is Uber doing? What is Lyft doing? Really? What's the bottom line here. They're getting you from point A to point B. It's really that simple. Isn't it? You want to get to a place. Now, they've added some of these other features like the Uber eats, where you can get Uber to go to a restaurant, pick up a meal, deliver the meal for you. Then you're off and running. That's not bad, but it's still effectively the same business.

[00:04:15] When we're talking about autonomous vehicles, it's a completely different business. You're talking about major software development. Lyft looks like it's been spending about a hundred million dollars a year in order to try and develop self-driving cars.

[00:04:35] That's expensive. It sure is a lot different than managing people coming from point A to point B. I was out of state. I was down in Florida. Down in Florida, it's difficult to find a Lyft or an Uber driver because so many people are staying home. Why would I bother working when I'm making so much money on unemployment right now? Why would they?

[00:05:00]I'm not sure I could particularly blame them for not wanting to work. So Uber and Lyft are now saying, wait a minute. I got go find drivers. I'm going to have people that are going to deliver food that is going to take passengers from point A to point B. That's what they should be focusing on. Isn't it. Making sure the drivers safe. Making sure the passenger safe. I'm not talking about these lockdown-type restrictions. I'm talking about physically safe because we've seen people attacked before. What happens if they're in a car accident? Do we have contact information for the passenger? Do we know they're in a car accident? Can we reasonably get an ambulance there, get treatment, get the police, whatever needs to happen. There's a lot of things you have to worry about—background checks for the drivers. Maybe background checks for the passengers. You've got to collect the money. Maybe you want to put in an override system where people who refer another Lyft driver are going to be able to get a bit of an override on them, make a few extra bucks, make it worth their while to refer driver.

[00:06:04]Then you've got all of the streets, the street maps in every city, in every town. How far should you be going as a business like Uber or Lyft? Is your business mapping. Is your business autonomous vehicles? No, of course not. So I think they're smart in getting out of this business, but I want to mention a couple of things about why I think they got in the business in the first place.

[00:06:31] GM and Ford probably Chryslers have said that they are thinking the vehicle of the future isn't going to be something you buy. You're not going to go out and buy a car because they're looking at it and saying, let me see, what do you want? I want to get to the train station in the morning, or I want to get to work in the morning, or I might want to have some food delivered to me, or I might want to run to the grocery store. First of all, grocery stores and food delivery can both be done by Uber or Lyft, but getting you from A to B.

[00:07:08] They're looking and saying we make the cars, we make the autonomous systems. Why don't we provide vehicles when people need them? So it can take your kid to school in the morning. It can go in five different directions. Cause you're going to have five different cars. Maybe you need five cars this morning cause you've got four kids, and you and your wife and you're all going different places. Here come the cars. They're all scheduled the day before, the week before. However you do it. On Tuesday, all of the cars show up. They take you to where you want to go. That's the business model that the major car manufacturers are looking at. I think it makes a lot of sense.

[00:07:51] You don't necessarily need a pickup truck all the time, but I sure need one when I gotta get those sheets of plywood and go here, go there, do things. Frankly, Home Depot and Lowe's are both looking at it, saying we have rental trucks. Maybe they will have some of these in their fleet. Maybe autonomous, maybe not autonomous, but that's how they're looking at it. They don't think you're going to buy a car.

[00:08:15] I don't know if you saw the test Cadillac did down in New York City, of course, this was before the lockdown as well. Cadillac had put together this plan, where for now, what was it? $1,500 a month. I think give or take. You could drive a brand new Cadillac, and you'd have that Cadillac for a month. You could, of course keep it for longer, or you could just pay them more. But the idea was why Cadillac buy? Why even go through all of the trouble leasing. Effectively, what you're doing is renting it like you might rent a car from Hertz.

[00:08:51]In the future, they don't even think you're going to do that. It's Hey, I want a black car to pick me up from one, two, three wall street and take me to park Avenue, that I think makes a lot of sense.

[00:09:03] So Uber and Lyft are both looking at this plan and saying, Whoa, Wait a minute here. What's going to happen when GM and Ford both decide that they are actually in the getting people from point A to point B business. Now, they are stepping on Lyft and Uber's toes in a very big way. I think that's why they decided to get into the autonomous vehicle business. Both of them have gotten. Out of it now.

[00:09:37] Lyft sold as a self-driving division to a subsidiary of Toyota called Woven Planet for half a billion dollars. Part of the reason for that, I'm sure, is it takes a lot of money to compete in the self-driving area.

[00:09:53]Frankly, if Uber and Lyft can really focus on their core business, not mess around with all this other stuff. They might be able to beat GM Ford, Chrysler, et cetera at this game.

[00:10:07] Uber, who was Lyft's main competitor, sold its self-driving business to a startup called Aurora back in December last year. Both of them had been working on these projects for four or five, six years; obviously things are going to change.

[00:10:28] The self-driving vehicles are going to be on the roads starting next year. Ish. Ford's made some announcements, so has GM. We'll see ultimately what happens. Waymo, which is Google, of course, alphabet has a small taxi service in the Phoenix area. Nobody else is operating full driverless taxi services in the US yet.

[00:10:54]Congratulations to Lyft and Uber for getting out of the self-driving business that not their business.

[00:11:01] We see that more and more ransomware, not only is it way up but some police departments have gotten hit with it.

[00:11:09] So, we'll tell you what's happening there. You're listening to Craig Peterson. It has been going up and up and hurting more and more people. In this case, we're going to talk about a police department. There's a briefing that the Boston field office of the FBI's giving on ransomware. If you are an infra guard member, FBI Infragard, I ran their training for a couple of years.

[00:11:34] They've got another training. Coming up on ransomware and what's been happening out of the Boston field office, which covers all of New England. And I discovered and disclosed a huge hack. And it was the biggest one that the Boston field office said that they'd seen it. It was just absolutely incredible.

[00:11:57] What had happened and businesses are just not. Paying attention. They're not paying attention; it isn't just businesses. It's also municipalities. It's counties, its state government, and it's the federal government of all of those. I got to say the federal government is trying the hardest, I think, to pay attention to the problem besides cybersecurity; of course, they take more money from us.

[00:12:22] So they and Lee should have a better budget to do it with right. But there's a great little article this week in the newsletter. We usually get that on hold on Sunday morning, but this is by Dan Gordon. Over at ARS Technica. They will always have some great stuff, but some ransomware, bad guys have sand What they're calling stunning ultimatum to Washington.

[00:12:50] DC's Metro Politan police department. The police department that handled the massive insurrection on January 6th. He said with his tongue firmly in his cheek, the guys that really know what they're doing down there, Washington DC. Ah, boy. So here's the ultimatum. Pay these ransomware guys $50 million, or they'll leak the identities of confidential informants to street gangs though, this group is called Bulk Locker, at least that's what they call themselves.

[00:13:29] And they said on Monday that it had obtained 250 gigabytes worth of sensitive data after hacking. The metropolitan police department. Yeah, Washington DCS, metropolitan police department network. And this Babych site over on the dark web. When you go, there has dozens of images of what appeared to be legitimate, sensitive MPD.

[00:13:58] Documents now these have been slightly blocked out so that people don't know what's going on. Exactly. So they've been It's anonymized. Let me put it that way, but it looks like these legit. I'm looking at some of them right now on the ARS Technica site. One screenshot shows a windows directory called disciplinary files.

[00:14:24] Each of the 28 files shown lists a name and a check of four of the name shows. They all belong to Washington DC, metropolitan police department, officer's disciplinary actions, and looking at the dates on these files, they are from, they've all been modified anyways, within less well about the last year.

[00:14:50] Give or take a little bit less. So that was just the first page of them, by the way. It looks like kids, the officers whose names start with a through E and a few apps, other images that are on, again, this Babych ransomware group's website on the dark web seemed to show persons of interests, names, and photos.

[00:15:16] So they, these bad guys put up a screenshot of a folder named gang database, another chief's report lists of arrest and a document listing the name and address of at least one confidential informant. So it's got the date. It was entered, closed. The persons name, position, sex raised. Date of birth, social security number, mailing address, email phone number.

[00:15:46] Yeah, the informant. Okay. So they said we advise now there's spelling errors in this. There are grammatical errors in this, which is expected. We advise you to contact us as soon as possible to prevent leakage. This is again on their dark web website. Quote, if no response is received within three days, we will start to contact gangs in order to drain the informant.

[00:16:16] In other words, still let the gangs know who the squealers are. Her the informant within the gangs. Now this is classic. This next one. Just absolutely classic Washington. DC's. Public. This is again, metropolitan police departments, public information. Officer Hugh Carreyrou wrote in an email. We are aware of unauthorized access on our server while we determine the full impact and continue to review activity.

[00:16:51] We have engaged the FBI to fully investigate this matter. So he didn't answer specific questions about what details, but here's the classic part of this. I bet you dollars per four donuts that they don't have the proper security in place. If you are a city or a County, you have rules which are called CJIS, which is the criminal justice.

[00:17:18] I think information system rules for your securing. Of data and it has to do with the networks, how were they cannot be connected and can only be connected in certain ways and what you have to do. And you have to included in all of this log, everything. What do you want to bet they didn't log everything.

[00:17:40] So they're calling in the FBI and we've done that too. We've done that when, again, we're not mandated reporters. If we see something suspicious, we call up the client, whether it's a city, a County, a state, a business, a DOD contractor or dentist's office. And we say, we found an indication or multiple usually indications of compromise, which means.

[00:18:04] These things make it look like someone got into your systems. We then say this is not what we do here. This is a law enforcement issue, and we think that you should bring in the FBI and then they can talk to the FBI. We can work with the FBI to really figure things out. So the FBI can do the forensic work and make sure they capture everything needed to capture and how needed to be captured, et cetera, et cetera.

[00:18:31]It's amazing. What's happening. But they are looking into this. I'm sure the FBI is involved most recently when we've had. Reports where we brought in law enforcement. We worked directly with the FBI, with their data security information, security team, James, and it's just amazing. People were not maintaining good cyber hygiene in this case, Washington DC, metropolitan police department.

[00:19:03] Almost certainly. Was hacked by these hackers. They admit the MPD that they, something happened. I bet you, they don't know what happened. They probably broke these CJIS rules that every city, state and town and County has to comply with. It's absolutely amazing. And of course you remember now they've got this dual revenue model when it comes to ransomware.

[00:19:32] Pay up now or pay up later, we will extort money from you either way. It's a, it's amazing. Amazing. Apparently this is a Russian group who knows who exactly it is. It's sponsored by the Russian government or not. We really don't know.

[00:19:50]Cloud is a sensitive topic with me and it always has been it's hold, it holds a lot. Of promise. And the biggest promise to most businesses was, Hey, use cloud services, it'll save you money. And of course they have used cloud services and in some cases it's saved the money, frankly.

[00:20:14] It's rare that it saves them money. It really depends on a lot of things, but if you using a service like Amazon's cloud services, and I'm speaking in generalities here, but it's probably going to cost you more than running your own server. Why do a lot of companies use cloud services? When it comes to general computing.

[00:20:35] Now I understand. Why would you use Microsoft's? What does calls Microsoft three 60? It's because Microsoft is going to maintain it. They're going to patch it. I don't have to run a server. I don't have to worry about any of that stuff. Okay. I get that one. How about salesforce.com? I don't use Salesforce.

[00:20:54] I use an alternative, but I can see why you'd want to use that. Unfortunately. In both cases, those services have been hacked and the company's data has been stolen. And you got to remember too, that you still bear responsibility for that lost or stolen data, even though you didn't lose or steal it. So keep that in mind, if you are a business now, when you are moving on to what are called containers, the whole world shifts.

[00:21:25] Here's what's happening and been happening in computers over the last few years. There's something called containers. When I first heard about containers. I was thinking about these data centers that they put into shipping containers. And so you get a 20 foot or 40 foot shipping container, and all you do is plug in power and internet, and it's often running.

[00:21:50] It has racks of computers inside that has all the cooling systems, all the power regulation systems, like while UPS's et cetera, it's got that fans in there to keep the air moving. It's got the tape drives to do the backups, all of this stuff. It's right there. So I that's how I always thought of containers.

[00:22:11] That's not the case so much anymore. Those containers still exist. Some of them are used by Microsoft and Amazon still they'll throw containers into different areas, depending on usage. For instance, with the Olympics coming up, you can bet that there will be shipping containers. With huge data centers in them in order to record all of the video and move it around the world, broadcast it, et cetera, that's going to happen.

[00:22:41] There's another type of container. And this container has changed the way a lot of businesses do computing. It is just absolutely an amazing technology for someone that's been in this business. Now, since the mid seventies, I got to tell you, this is something that just really came to me out of a little bit out of the left.

[00:23:05] Field, because I'd been working with virtual machines since the seventies IBM has had VMs for what, 50 years now that it's not new that concept, but there's something called Kubernetes that is used in the container world. In the idea here. Is rather than having a big machine and that machine has its own operating system.

[00:23:30] And on top of that, you're running multiple programs. We've moved into more of a virtual world. So now even Microsoft has gotten into this game instead of having a Microsoft. Server and people trying to run everything on that one server, which Microsoft advises you not to do. If you have an active directory server, it should only be running active directory.

[00:23:55] Nothing else. If you have an exchange server, it should only. Be running exchange and nothing else. And the same, thing's true for the other major Microsoft servers. But what a lot of companies have done is they have one piece of hardware. And on that, they've got the one Microsoft server operating system.

[00:24:16] And inside that the running exchange and active directory and who knows what else? A whole bunch of other stuff, right? People put QuickBooks on these things, et cetera. Now, nowadays you can get. A virtual machine infrastructure. And this is what we've been using with our clients for 20 years now, more maybe, and there, of course it's advanced over the years.

[00:24:42] Now we use a virtual machine infrastructure called VMware. That's absolutely fantastic. Believe me. We've used them. All, and this is what we've settled on for our client, but the idea here is, okay, you buy one piece of hardware and that piece of hardware has a lot of memory, a lot of disc IO available. And you put on the very bottom of this, right on the machine, you run a virtual machine controller, basically.

[00:25:10] So something like VMware and then that VMware can run multiple operating systems simultaneously. So on that one piece of hardware, you could be running an exchange server, a whole thing. So you've got Microsoft server running and then on top of that, you've got exchange and then you have another.

[00:25:29] Microsoft server running. And on top of that, you have active directory and then you have another Microsoft server and you have something else around top of that one. And maybe you have a Linux server with something else on it. And another Linux server was something else on it. And with VMware, you can also set up virtual networks inside this machine.

[00:25:47] It's just absolutely incredible. So that's something I think most people understand. And if you're an it professional, you've probably worked with that before. Coobernetti's. Brings it to an entirely different level. And what's happening here. Is that again, we're using a virtual machine infrastructure, but the idea is each one of these machines, instead of running this huge Microsoft server software.

[00:26:17] So you got server version, whatever. And that server is software from Microsoft is using up a ton of resources because it's Microsoft and it's not very efficient. And might be causing you some headaches and some problems. There's all kinds of things we could talk about here, but the incentive doing all of that, maybe what you want is a web server.

[00:26:40] And maybe you want to tie the web server into some sort of a database. And that database is taking information from your front-end ordering system, which could be, who knows what, again, it could be a API to salesforce.com. It could be something else that you're using. You, again, name it. There's so many business management systems that could be tied into a lot of ERP stuff, et cetera.

[00:27:06] So instead of having running a big pig line, Microsoft exchange or Microsoft server, and then exchange on top of it or heaven forbid, you're running a Microsoft, a web server, which is in incredibly I would never do that personally. But you want to run a patch, et cetera. What you do is you use Kubernetes and it creates a small machine that does one thing and does one thing.

[00:27:34]And it's well tuned to do that one thing. And then you can tie these together. So on one machine, you can even do this on a workstation on that one workstation, you could have 20, 30, 40 machines, right? Each one of which is dedicated to one task. So one might be doing the web service and another one might be handling your database.

[00:27:57] Another one might be handling the API calls and it's all pushing data back and forth whole new world. Unfortunately there are security problems. So if you are using this stuff, make sure you spend some time considering the security, because Kubernetes is entirely API driven, which means application programming interface.

[00:28:19]I keep an eye open for that. Use a virtual private cloud instead of on the open internet.

[00:28:24]If you have a laptop and you've probably noticed a few things, first of all, that battery life.

[00:28:31] Okay. It's not like it was when it was new, his head, somehow those batteries do wear down. It's much better than it used to be. The nightcap ads and the nickel metal hydride ads. And now we've got various types of lithium batteries based on a few different technologies. There's going to be more stuff coming out.

[00:28:53] And I had a laptop, it was an Apple laptop, a Mac book pro. And on the bottom of it, it had four little legs, just little ones, a little rubber things. So it's a standoff. And one day I noticed that my laptop was teetering. Balanced in the middle. And I had a bit of a closer look and I could tell, wait a minute, and how this laptop is swollen in the middle.

[00:29:17] Now I knew exactly what had happened that battery inside had gone bad. So number one, I've got a one you guys with a lithium ion battery, if it starts to swell, and this is true for most batteries, but it's. Particularly nasty with lithium ion. If that battery begins to swell, what can end up happening is it will short itself out internally.

[00:29:48] Have you ever had that happen? You might be working on a car and you're right there and buy the battery and you put a wrench across the terminal somehow or between the starter. Hot side on the cars engine and the block, and, off it goes, there's a lot of power in that car battery, and there is a lot of power in these lithium-ion batteries.

[00:30:11] They make these hacks now that you can use to jumpstart cars, even small trucks with a little lithium-ion pack. So what happens is. As the swell up in your laptop or your phone, et cetera, we've seen this problem with every manufacturer of cell phones. As they start to swell up, they can and do short out.

[00:30:36] So think about how much power is in that battery, even an older battery, because it can provide your laptop with as much power as it needs. Four hours. And if you're lucky enough to have a brand new laptop with one of these great Apple chips in them that uses very little power, man, you can go better than a day on one charge easily.

[00:31:02] Unless you're like doing heavy graphics, et cetera, et cetera, but that's always been true. So I took my Mac book in and they replaced the battery, no charge. It was still under AppleCare, which I suggest people get. It's just makes life easy. You can always get the support you need and they'll fix things, replace them.

[00:31:23]That's the first step I had to mention that right out of the shoot, because it is very common with laptops to have that happen. I even had it happen with my little what's it called a little, my fi device, which hooks up. To the cell phone data network and then provides wifi to my laptop or other devices.

[00:31:46] And I noticed the battery pack compartment cover was swollen. So I took it off and sure enough, the battery was swollen. I just ordered a new one and. Properly disposed of the old lithium-ion battery. Cause again, it can cause fires right now. I think there's a recall out on some of those mi-fi devices because of the battery.

[00:32:09] So that's a serious problem. You can start your laptop on fire or you phone could start on fire with any of these newer devices. If it starts to swell, if it warps the case warps, then it's not because you're sitting on it. You can indeed cause of fire so we can have, and if you are sitting on it, you might cause of fire because if you bend that battery in the wrong place, you're in trouble.

[00:32:32] There was an episode of MythBusters where they took a lithium-ion battery. And they put it in a trash truck. Now they made this a worst case scenario. They actually built a wedge into the back of the trash truck that compresses all of the trash. It's got that big hydraulic Jack and pulls it and compresses it.

[00:32:53] So they put the battery with this wedge right in the center of the battery so that when the truck compressed it. The battery would get bent. So they bent that battery. Fair enough. The whole trash truck caught on fire, and we've seen that happen in the real world, too, where the whole trash talk truck catches on fire and it can be caused by lithium-ion battery.

[00:33:16] So be very careful with them and be careful of how you dispose of them. So let's get into some. Other things that you probably want to pay some attention to. First of all, there are a couple of programs you might want to have. Look at first off is Microsoft safety scanner, and they've got a. Page online, you can find it out@docs.microsoft.com.

[00:33:45] As in documents, docs.microsoft.com. It's called Microsoft safety scan, or they have a 32 bit version on a 64 bit version, depending on which version of windows you have, what you're running, but it goes all the way back to windows seven. It handles the windows servers versions, and all you have to do is download it and open it.

[00:34:09] Tell it, what kind of scan you want to have run and it will go. It has just the one executable file that you can delete if you want to. It writes out its own little log file that you can look at. So that's the things you might want to look at. Microsoft safety. Scanner. And you can find that a docs doc s.microsoft.com.

[00:34:32] The next thing you might want to look at, either on a Mac or on a PC windows is Malwarebytes. And I've used this many times. Neither one of these by the way, is a panacea. Neither one of these is going to find everything or fix any everything. But malware bikes is. Quite good. And it's something you should consider.

[00:34:56] Now we have packages of software. We do not include Malwarebytes because we have some better stuff, but it's a very quick and easy way to do a light scan. Very fast and you can do a few things. So that's the first thing you might, I want to look at. If your computer is sluggish and unresponsive, it's slowing down, it doesn't necessarily mean it's old.

[00:35:22] It might mean you have too much software that you've installed on it. So check your system. To see what is running on it and see if the stuff in the background, see if the stuff that you might want to remove, but it could also be a sign that a hacker has broken into your machine. And they're doing things like mining for crypto currency or using your machine as a launch pad for attacks against other people.

[00:35:51] Okay. So start with a thorough malware scan again on windows. They do have a pretty good little program that you can use that comes with windows, but first off, open the task manager. So you get that by clicking. Right down in the bottom left and the task bar and just type task manager, run it. See what happens, Mac Oh, S you're going to search for it with spotlight and it's called the activity monitor and you'll see all of these active programs next up.

[00:36:23] Persistent error messages. And this is something you can find over at popular science, this little article, obviously I'm adding my own little tips as we go through, but you might find it interesting in you'll also find it in this week's newsletter. That'll come out tomorrow. So make sure in order to get the newsletter, you sign up at Craig peterson.com/subscribe.

[00:36:45] So you'll get a link to this article that goes through all of these things. Computers, they often get error messages. Some of them are really hard to figure out. Many of them are just related to one program and the that's usually pretty easy just remove or uninstalled that program. And re-install it again.

[00:37:07] Some of these error messages are hard to figure out you can go and search for them. Now, I do not recommend Google for most searches, but and I use duck go, but what you might want to do here is use Google type in the exact error message that you're getting and see if they've got a result now.

[00:37:30] Macko Wes. Aye. Aye. Aye, man. It's so rare that you have to re-install Mac last, but you might have to, but windows, the default is Hey or back up and re-install okay. That should fix most of the error messages right there. Cause windows is a mess. If you've got pop-ups on your screen asking, let's say to make changes to settings, make changes for things.

[00:37:57] Be careful. These different types of infections can disable features. They might change your homepage on your browser reset your default search engine. I got an email from a listener this week, talking about that, and it just keeps to keep getting reset back to Google. Tumbled check your extensions in your browser.

[00:38:18] It might just be the browser itself can also be viruses can also be a hack, but roll back the changes, any changes that you've made, puts your browsers homepage back to the original one. Make sure you run again. The built-in tools. They're on windows. Web pop-ups same type of thing. Find a list of browser extensions you've installed.

[00:38:45] So if you're using Chrome, they sit under the more tools entry, have a look at those. See if there's any that it re recommends that you remove and then do it, or just go ahead and remove them all and see if your pop-up problem goes away. There's also the problem of strange noises. And this can be a problem that only the owner of the computer really notices because you're used to what the computer should sound like.

[00:39:16] If you start getting strange noises, have a checked out right away because those noises could be a fan and that fan could be keeping your central processing unit. Cool. And if that CPU fan. Goes, you could have a very expensive repair on your hand. So keep an eye out. It could be your hard desk. It could be a fan.

[00:39:40] There's a few different moving components in, but keep an ear out for those types of sounds that you're not used to hearing from your computer.

[00:39:51]Ransomware has been a huge problem for years now.

[00:39:56] And of course now we've got the whole double whammy where if you don't pay the ransom, then they come after you threatening to release your data. Just like what happened with that police department? I was talking about in the last hour. We've seen according to some statistics I've been reading, including some FBI stuff about a 300% increase in ransomware in just the last year.

[00:40:24] And we have. Also seen a doubling of how much it costs. If you do get hit with ransomware. Now, this is a pretty big deal. And of course these are big numbers and the doubling in cost has nothing to do with inflation. Okay, guys, this is not the sign of inflation. But it is driving up. The value of Bitcoin is people are fleeing to it concerned about the dollar and other currencies.

[00:40:53] We now have a tripling of ransomware payments and ransomware payments are almost always made in Bitcoin. What does it do when you have a scarce, commodity and money chasing it while the value, the price of something goes up. And so just like it, wasn't near the beginning. Ransomware has really been driving the price of Bitcoin.

[00:41:19] I'm not going to say value just because I'm not sure it's value that we're really talking about here, but certainly the price. According to Sofos the. Average total cost to recover from a ransomware attack has more than doubled. Now this is what we're talking about here, businesses. So over the last year, it was on average, about $760,000 for a business to recover from ransomware.

[00:41:48] Now, Nancy, if you could afford the $760,000 loss and we'll get into what. Numbers compose. You add them all up to get that $760,000. But if you are a small enough business that's not something you can even consider doing, odds are good. You will be out of business within months and most smaller businesses just close their door within a week of getting ransomware.

[00:42:19] It's really that bad because there's a lot involved. So last year, about a year ago, it was $761,106 on average. Okay. So now the average cost total for recovering from a ransomware attack is about $1.85 million. Now we're talking about the total cost of recovery. We're not talking about the ransom paid right now on average is about $170,000.

[00:42:56] Again. Can you afford a $170,000 payout? I would say of the small businesses in the world, basically under 20 employees. The answer to that is probably not, but wait, there's more. All right. This is from, Sofo says new survey, the state of ransom 2021, apparently only 8% of organizations managed to get back all of their data.

[00:43:28] After paying a ransom 8%, about five years ago, it was about 50% of organizations that got ransomware. Got, got it back. But now. 8%, only 8% managed to get all the data back. Now that's going to cover not just businesses, but that's going to cover you as an individual as well. If you're a small dentist office, this is going to nail you.

[00:43:52] And I got to say, just having a backup. Most cases is not good enough because of the double whammy, but also because of the fact that most businesses are not doing backups properly. And we could talk about that. I'm going to include that in one of the courses coming up about backups, a three, two, one method, and the best ways to make sure you do have a good backup.

[00:44:18] So 8% got all of their data back after paying the ransom and 29% received no more than half of their data. So it has gotten a lot worse. So these were 5,400. It. Decision makers in the information technology, business mid-size organizations, hence the amount of money involved or right. All the way across Europe, the America is everywhere really worldwide.

[00:44:50] And it found also that the number of organizations that experienced a ransomware attack fell. Now that was interesting at one from 51% of organizations that had knitted in 2020 that they had a ransomware attack. And I added the word admitted in there, right? That wasn't in the original survey results, but admitted because I know most businesses don't admit it and they say it fell from 51% of these organizations had a ransomware attack in 20, 20 and 37% in 2021.

[00:45:28] And few organizations suffered data encryption because of a significant attack. Now that's interesting because interesting when we're talking about significant attacks versus non-significant attacks, do you draw the line? But this Sofo study was focused on the moment, significant attack.

[00:45:49] These various organizations had. So folks researchers are saying that the impact of a ransomware attack is now more damaging and costly, even though there is a decline in overall attacks. We've talked about that before here on the show where we mentioned quite clearly that the ransomware guys are getting more laser focused on their targets.

[00:46:17] They're going after mostly targets with money. Now, there's still those ransomware people out there that are just opportunist. So you made the mistake of downloading some software of installing something and they just took advantage of you. So that's still going to be happening, but. When we're talking about bigger organizations, when we're talking about government agencies, County offices, city offices, and look at what's happened to Atlanta.

[00:46:43] What three times now, I think they've been knocked off the air with ransomware, Washington DC. In the last hour, we were just talking about their metropolitan police department. They're attacking these organizations that can't afford to pay, and they know that they can pay. And if they don't, then they hold it over their heads.

[00:47:05] So I've got this article in this week's newsletter comes out Sunday morning, usually. And it depends on when Karen and I can get it all together. So apologize for the last couple of weeks. Cause I was off at a retreat and just really couldn't handle any of that stuff. But. It really is an increase in these complex targeted attacks much higher.

[00:47:31] And you'll find this article as well as all of the others. Of course, in my newsletter. If you don't get the newsletter right now, make sure you just take a minute and sign up because there's information for you as an employee in a business for you as a business owner, there's information in there for.

[00:47:49] Home users as well, because almost everything we talk about when it comes to businesses also applies to home users. Now I'm going to be doing something different in the weeks to come. I'm hoping to start this next week. We'll see how the week kind of fleshes out. But the idea for this next week is I am going to start doing real releasing soon, but putting together the short training segments.

[00:48:18] And each one of them is going to be on a very narrow topic because most people, they want five to seven minutes worth of content. So I'm going to get very narrow. So for instance, if we're talking about backups, I'm going to get really narrow on one part of backups and I'm going to post them everywhere because we've got to get more people following the podcast.

[00:48:42] I am also, you might've noticed. Putting the podcast together as a one hour, we'll access closer to about 80 minutes podcast every week. And it is going up on my YouTube channel. So you'll find it on YouTube. You'll find it on my Facebook page. I have a Craig Peterson group over there on Facebook. I'm also putting up on LinkedIn.

[00:49:04] It's going in my Craig Peters on Twitter channel. It's going up all over the place. And the idea here is to help you guys understand things better. This is for everyone and everyone, then I'm going to start doing something else as well. And that is all of these little. Classes, I guess you might call them that I've been holding.

[00:49:28] And really, I haven't done anything since March of last year for some of these classes. I've done courses, trainings, but these classes, what I want to do for you guys is if you're online email list, I'll tell you what the next class is about. So for instance, backups, I'd say, and then if you give me a great question, something.

[00:49:51] That you want to learn about backups, then I'm going to give you access to that class for absolutely nothing. All right. So I'll use your questions to help put it together. So I'm coming from the right angle. I will then record it. I'm going to put it up on my navigating cybersecurity website for you guys.

[00:50:12] I'll send you a link to it and you can, at that time, Point watch it, which is really cool. So you'll have access to that class for a few weeks, couple of weeks. I'm not sure how we're going to work that out yet, but yeah.

[00:50:26]One of the big pieces of news that's been out there lately has been the migration away from Intel. We've seen. Our friends at Microsoft move away from Intel with some of their surface tablets. And for years they've been having various versions of windows that run on non-Intel hardware. I helped to way back in the day.

[00:50:51] Get windows running on a DEC alpha chip. You might, if you're a total geek, you might remember that. And I was in the team that was working on some of the kernel stuff for it. And what we ended up with is a 64 bit very fast chip that deck had created. And I think. That Oracle ended up with some of that technology and then they also bought sun for some of their hard work technology.

[00:51:20] But anyhow, it was an incredibly fast chip. I have one, if you look closely on, in my background on the videos, you might see it sitting on when one of the little cubbies behind me, one of these little outfit, chips, they were just absolutely amazing. Great job. Anyhow, DEC digital equipment corporation is no more.

[00:51:42] However, some of the technology that I worked on back then, some of these, what we call risk architectures, where I worked on the kernel, various types of Unix kernels back then. B, this is before Linux. Even these chip sets were designed to be inexpensive, to manufacture and very fast and very easy to use and integrate as well from a hardware standpoint.

[00:52:09] And when Apple came out with its iPhone, they of course used a non-Intel chip for the main processor. And it's a, an Apple chip quote, unquote, based on one of these more or less generic designed. So Apple licensed the core design of the chip and was able to take it and continually improve it. Apple has now released various devices.

[00:52:38] There's an iMac, which they, these things are so cool that you can't buy the latest ones. You all, you might be able to about time you're listening, but they're all different colors. It's a flash back to the old days before Johnny Ives took over in some of the hardware designs, but they've got the new IMAX.

[00:52:57] They've got the Mac box. They have a Mac mini like I have right in front of me right here. It is based on apples am one chip and it is a screamer. It is very fast. And it's, I think it was about 100 bucks, maybe a little bit less then the Intel box. So you can get a Mac mini Intel for a hundred and change dollars more than an Apple based chip set.

[00:53:29] And it's faster, which is just amazing. So it has the main chorusy beause. It has also of course, a GPU's that are built into it. It's very neat. Apparently this Japanese publication called the Nikkei claims that the next generation of Apple's custom designed silicone chips for Mac that are dubbed the M two.

[00:53:53] Entered production this month and how that is fast. They barely released the . So what that might suggest is the new max could be announced at Apple's developer conference on. June seven, at least that's when that conference start. And the sources are saying that this new chip will eventually be used in other Macs and Apple products, besides the Mac books, that M one is also destined to end up in various types of eye pads, et cetera.

[00:54:26] And it's bringing more and more rumors to the front. Then the, I F our iOS apps will run natively on all of these Macs and vice versa. You can run Mac software on the iPad. You can't do all of this yet. Okay. But some of it is almost certainly going to be coming. Now, I had a conversation. With an Intel exec.

[00:54:54] This was a number of years ago and I was teasing her because she worked for Intel. And she was all puffing up about how great Intel was. And I pointed out, Hey, I remember the early days in Intel, Intel was a memory company. And if it hadn't been for IBM looking for cheap, not particularly good processor, Intel probably wouldn't be where they are.

[00:55:19] Today. Oh, certainly they wouldn't be. And I also pointed out how Intel was now AMD compatible MD of course, advanced micro devices and historically AMD and other chip makers made sure their chips were completely compatible with the Intel chip sets. But what we ha, what we ended up with is Intel lagging behind on 64 bit technology.

[00:55:48] And because of that AMD one up them AMD came up with some really great 64 bit extensions to this Intel instruction set and. Intel came out with AMT compatible instructions. I thought that was just hilarious. And she was pretty happy about it, but she admitted. Yeah, you're right. Now we've got a very interesting problem.

[00:56:16] We've had China growing its presence in the South China sea, the South China sea is not part of China. There are various countries, the border that are in it, et cetera. And China has been building islands in the South China sea. So they can then claim up 200 mile territorial limit around those islands as well.

[00:56:43] They want control of it, but I can tell you what they're really after. And this is what's very scary. And there have been a lot of military analysis, people who have been looking at this and trying to decide what to do, and that is Taiwan. Taiwan is according to mainland China. And of course the communist party of China, which is more fascist than communists, socialist party in China it is a part of China.

[00:57:12] And it's just one of these, you have a state that kind of rebels. And so they're going to pull them back in and they've been flying over. China has been flying over time when these air space to make their point. Unfortunately, I don't know how this government's going to respond, that the current administration has been challenged, left, and center by some of these more major powers around the world. And the president Trump was hardly challenged at all. And I think that says something, but here's why they really want Taiwan. It's the technology. And China's had a very hard time with trying to get their chip fabs. In other words, these fabrication plants that make the silicone that make the chips that we use in our devices.

[00:58:05] We have some ability to do it still here in the U S but not much. And the goal then. W, what do you want to call it? The centerpiece the prize of right now of all manufacturing is five nanometre design. You might have heard of that before Intel is having troubles with some of this, but it's incredible.

[00:58:27] And Apple's doing a good job with it. While Taiwan semiconductor manufacturing provides. This five nanometre design technology for making chips to Apple and many others. So if China can get its hands on Taiwan, which are really wants, they are going to be able to manufacture. Chips that we don't want them to have and have a real leg up.

[00:58:56] So man, we may get into a Kinnetic war over Taiwan. And now, you know why, Hey, if you're not on my email list, make sure you get on that newsletter right away.

[00:59:08]Emotet is a huge problem. At least. It was a huge problem. It turns out that this bot was able to harvest 4.3 million email addresses. Now that's not a ton of email addresses in today's language because there are billions of email addresses floating around there in the dark web.

[00:59:34] But Emotet was used. As a basis for ransomware and spreading ransomware. And it was really nasty stuff. AML tech would get onto your machine. And once it was on the machine, it would start trying to brute force, crack your passwords on your machine. It would try and spread to other machines on your network.

[00:59:57] So in a. Business, of course, that means all of the other machines in the business might well get attacked by maybe even compromised by a motet. Same thing is true in your home and the machines that you had at home you're using for the office while they could get cross infected from your kid's machine and all your kid had to do, or you had to do is open a piece of email because amyloid pet also distributed the ransomware via.

[01:00:27] Email fishing. It was sending malware field spam to all of the email addresses. They could get their hands on. This is what your all Paul said was the world most dangerous bot met and been plaguing. The internet, as I mentioned is 2014. A bot net is where someone typically a bad guy has taken control of a number of computers.

[01:00:57] So they took control of your your home computer, right? Some windows, computer, whatever it might be. And now they installed a command and control system on it so that they could command your computer to do things for them. Nowadays, you might see botnets being used to mine cryptocurrency. So your machine gets really slow.

[01:01:21] Like I mentioned, in the first time or today about problems you might be having with your laptop, much the same applies guys to your mobile devices, to your smartphones as well. And particularly the Android has been hit very hard by some of this stuff. Again, Apple's able to keep up on it and we've discussed this enough times in the past.

[01:01:41] But what's happened here now is they have been able to stop it. Yeah. In January, this year, law enforcement in the Netherlands was able to take control of key domains. Again, ammo tat is a bot net among other things. And as a bot net, it had command and control. So it has servers. So it needed to contact the servers to see what to do.

[01:02:12] Hey, do you want me to send email? Who do you want me to send it to? Oh, here's this stuff that I've discovered on this machine. And it sends it all to those servers. So the Netherlands were able to get them. And Germany's federal police agency, the BK, a did some very clever reverse engineering. They looked at the emo type software.

[01:02:35] And they found some interesting things. One of them by the way, was that there was an uninstaller routine built right into AMETEK, which kind of surprised me and many other people, but the German please went through and looked at it thoroughly. If a machine had ammo tat on it, how could we get rid of it now that we have control of the command and control servers?

[01:03:05] So they found this remove routine and that this command that was built into it. And they also found that. Ammo Ted software could self update. I wish most programs would do a self update. Nowadays you see some of the Microsoft software or we'll go ahead and update itself. Firefox does that Google opera?

[01:03:30] Most of the, all of the chromium based browsers will say update, but this is malware that would self update. Okay. They found that since they had control of the command and control servers, and because Emotet could self update, they made a version of Emotet that would be pushed out to any infected machine, any machine that called home.

[01:03:58] And once it called home, they would send this version out. Now they, of course they muted it to you might a virus for a vaccine, but they muted that AMETEK virus. And it was no longer sending out the phishing attacks, et cetera, but it was still setting on everyone's machines because the thinking was, we want to get rid of this Trojan software everywhere at once.

[01:04:25] Just. Bam all at once. And so they put a date into the code that they pushed out saying on this day, at this time course, UTC. Go ahead and remove yourself from the machines. That is incredible. They were able to figure this out or what was happening get emo tap from its base, which is to conduct brute force attacks on accounts, trying to crack passwords, gain access to secure data, send all of that information.

[01:05:01] Out use it as a botnet to also attack other machines and send emails. It just incredible as well, of course has encrypt files and demand ransoms to something that just last week removed itself from any machines, it was on. Absolutely amazing. The FBI collected the email addresses from these AMETEK servers, following this takedown in January, where again, the Netherlands had control of the servers and it's just absolutely amazing here because they were able to take it down worldwide.

[01:05:44] Very dangerous botnet, but once they had those email addresses, they gave them to our friend Troy hunt. Do you remember him? We've talked about him before and it's something I emphasize in most of my courses because Troy hunt has a website called have I been poned. And they gave these email addresses the 4.3 million that they got from Emma and to Troy hunt.

[01:06:14] And he has included them in. Have I been poned now, if you were part of this breach by Emotet and do you registered on, have I been poned.com you now should have already received an email from Troy. So it's important that you do a couple of things. One, make sure you check your email addresses at, have I been poned.com?

[01:06:42] Poned dispelled P w N E D. It's. P O w N E D I, he might actually have it both ways. Let me just have a quick look as we're talking. How have I being, if I say P O w N E d.com, will it no. Okay. There is no such thing which makes sense. It's have I been poned as in P w N E d.com. Check your. Email addresses.

[01:07:10] See if they're there and register for this service. This is a free service. There are a lot of companies that are using it. Mozilla uses it with Firefox to see if your passwords might have been compromised. They've got 11 billion poned accounts. There at, have I been poned this guy knows the stuff. Okay.

[01:07:31] And it's been, this particular one has been tagged sensitive. You can find out more about that@havebeenponedbot.com, but make sure you do that right now, as you're sitting here listening to me because it's very. Very sensitive information important for you to know. And if you have been powned and it's a business email address, make sure you let your it people know.

[01:07:58]I was fascinated to chat with this guy from Ireland. He had course of pretty heavy accent. He's been living in San Francisco for years, but about the only word that he said that was Americanized was for, he didn't say it like you'd expect someone with a heavy Irish accent to say it quite that way. Then, I am really into accents and placing them.

[01:08:24] And I've pretty much gotten rid of my accent. Some people still pick up a little bit of it, but I was educated in French schools up in Quebec. So there's bound to be a little bit of it left. So I like to listen for those things. And in talking to him, he said that Ireland changed because of wifi. And I had to think about that.

[01:08:48] And he said, yeah, my, my parents, because of what they're just always on the news. And they're just totally freaked out about everything all of the time. And they're always were talking about how horrific Donald Trump was, because that's what CNN was telling them. And these other sites that they were going to.

[01:09:09] And of course, we've talked many times about. The literal censorship that is happening in much of our media. And these all are arcs out in Silicon Valley and how they're controlling the discussions. But that's not what I want to talk about. He was referring to wifi. He was saying, why is what's changed Ireland, wifi?

[01:09:31] And I'm trying to figure out what does he mean? And then I remembered another friend of mine. Who's from Ireland, his name's Dez. And. There's also was continually talking about wifi. And then I finally put two and two together, sometimes a little dense, and tuned to equaled wifi as the internet. So when he was talking about why fi he wasn't really talking about wifi, when I'm thinking about wifi, I'm thinking about why five, five wifi, six, the older protocols, right? G a, some of them, man, it goes way back a, B, G. Anyhow. That's what I think of. I think of the literal in the air, why that choosing radio waves in order to connect right. Beacons and everything else. And maybe that comes from my, having a ham radio background, having an advanced class ham radio license.

[01:10:26] I don't know at any rate, why fine is the intranet, at least in his mind. And also apparently the minds of his parents. I sat all of that because I want to talk about space X space. X has already won a battle. You may not even be aware of. You and I, when we have internet, where are we getting it? Most of us get it from the cable company or from the phone company, almost everybody with five G we're hoping mom, maybe the cost will go down and the speeds are going up and we'll be able to get our internet from the phone company.

[01:11:12] Just like we have cell service. And that is going to happen in some areas, some communities, but how about all of our rural communities and in Maine, New Hampshire, Vermont, North Dakota, South Dakota, Wyoming, Montana, Idaho. And then all the way down South. Yeah. There is a lot of territory that is not covered well by 5g.

[01:11:38] Yeah. Yeah. You see the maps from T-Mobile and from Verizon, but remember maybe you don't know. So I'm like I say, remember, but you have to know that those maps are just based on a mathematical formula. So just because an area is red does not mean that you have coverage there, 5g or otherwise. And you've probably found that before, too.

[01:12:04] I know I did. I looked at a coverage map and sure enough, bam right there in the middle of all of that red was my house. And yet I had no cell signal really upset me and the FCC was trying to fix that out. Pitt who the head of the FCC he had he was appointed by president Trump and he had put some rules in place that made those maps are a lot more reasonable.

[01:12:36] But we're still talking about the majority of the landmass of the United States, vast majority, not being able to get good 5g signals. So my good, in any, in many cases, so space X has been going after those people. I announced it months ago when it was first available, this beta test they were doing for.

[01:13:01] What they call their startling satellite service. Now this is a satellite service, unlike any you've seen before. It isn't putting up a dish for your television and you got to make sure it's aimed in the right direction. And hopefully it's not raining or snowing heavily. Cause you're going to lose your television.

[01:13:22]You guys had those types of problems before they happen. All of the time. And then of course you have summer summertime with the green attenuators, those leaves on the trees and other green things that are absorbed some of those radio frequencies. So your satellite dish works better in the winter than it does a summer.

[01:13:41]That's why you probably have some leaves or other greenery that's in the way space X has already launched a small, pretty large, frankly a whole set of satellites, broadband satellites, and they call these constellations when you have a whole bunch of them together. And then in 2018 space X got FCC approval to launch.

[01:14:06] 4,400 satellites and that permission and that license specifies. Okay. You have to be so far from the earth. It was about 1100 kilometers to 1300 kilometers above the earth. And then the FCC gave space X permission to use a lower altitude for more than 50. 1800 of those satellites. Now the idea behind this is the closer the satellites can be to the ground.

[01:14:37] The last distance, the signal has to travel. So some of the problems people have been having not enough bandwidth, maybe although the majority of them are reporting a hundred megabits down, which is just incredible and also the delay. And that gets to be a problem. When you're speaking to someone, you got a hundred milliseconds up a hundred milliseconds down that is noticeable when you're in the middle of a conversation.

[01:15:06] So the space X guys went ahead and petition the FCC again, and they got an order that granted space X is additional license change requests. So the altitude for all 3000 ish of the satellites. Can now drop their orbit basically in half in about the 550 kilometer range that is going to be. Huge.

[01:15:37] Absolutely huge. And obviously opposition from all of their the companies competing against them via S sat, Hughes, dish network, one web, and Amazon has another one called and they are all saying you can't do that. It's just not fair. But this is fantastic here because it corner the FCC statement.

[01:16:01] They said, based on our review, we agree with space X, that the modification will improve the experience for users of the space X service, including in often underserved polar regions. We conclude that the lower elevation angle of its earth station antennas and lower altitude of its satellites enables a better user experience by improving speeds.

[01:16:26] And latency not, I don't want to go into a whole lot of detail, but man, Oh man, this is huge. Now you may not be aware of it, but part of your telephone bill, some of those fees and taxes that are in that bill have been going into a pot. As though the federal government ever actually saves money, it's a lockbox that doesn't really exist. And there are about, I think it was 16. Billion dollars sitting there in this lockbox. So space X has gone after that money as well. And they've received the majority of that money. I can't remember the exact amount, but it's pretty big. So space X. Remember.

[01:17:18] Controls the whole thing. They're making the satellites themselves. They're launching the satellites on their own reusable rocket. So their cost is way lower than any buddy out and space. X is also seeking permission. For 30,000 more satellites and in about the same range, some of them a little bit lower, it's already received permission in November of 2018 to launch another 7,500 satellites at altitudes of about 340 kilometers.

[01:17:58] This is absolutely incredible because one is going to end up happening is we will get good. Coverage almost anywhere now. You're not going to be able to get the type of speed that I have. For instance, I have fiber coming into my home and it is, I have a gigabit and a three gigabit and it's gigabit up and down.

[01:18:22] A lot of people can get that now, but you're not going to be able to get that in a rural area or a polar region, but they are saying that with this testing there, they're seeing some amazing speed. So space X has already got 1300 plus satellites in orbit. It's in beta. It costs $99 a month. Plus $500 upfront for all of the equipment and the equipment is just amazing, super leading technology.

[01:18:54] It's just amazing what they're doing. And they've been advertising beta service speeds of 50 to 150 megabits latency of 20 to 40 milliseconds. That is very fast. And Elon Musk said in February that the speeds you're going to get, you'd be able to hit 300 megabits later this year. Per second and it'll be available to most of the earth by the end of this year.

[01:19:21] Absolutely amazing. Amazing. All right. Okay. I just found the numbers. They've been granted 885 million, not the billions over 10 years. In rural broadband funding. So there's hope for all of us by the end of this year. Yay. Space X take care of everybody. Make sure you're getting my newsletters. You can get everything today.

[01:19:45] And what we talked about every week. Craig peterson.com/subscribe. Take care, everybody.

View Details

Welcome!

For all of my listeners who purchased my course on Improving Windows Security - THANK YOU!

We have a whopper of a warning this week about what the Department of Homeland Security is planning under the Biden Administration -- They are going to let Big Tech and Private Companies create the NO-Fly and Terrorist Watch Lists on their behalf -- Scary beyond measure. Then Apple is doing more to protect your privacy. We have another hack of a Commercial VPN provider and there is more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

DHS Preparing to Use Private Contractors to “Scour Public Data and Social Media” To Compile Dissident Citizens for Watch List and No-Fly Lists

Another Reason to hate VPNs -- Feds say hackers are likely exploiting critical Fortinet VPN vulnerabilities

Mark Zuckerberg's cell phone number is among leaked personal data from 533 MILLION Facebook users, including two other founders that have been released for FREE by hackers

How scammers siphoned $36B in fraudulent unemployment payments from the US

Are self-driving cars safe? Will they ever be? Fender bender in Arizona illustrates Waymo’s commercialization challenge

Apple is enforcing its new privacy standards and rejecting apps - New wave of App Store rejections suggests iOS 14.5, new iPad may be imminent

My biggest complaint about Android? The lack of security updates. Google is trying to solve it -- What we’re expecting from Google’s custom “Whitechapel” SoC in the Pixel 6

NFTs Weren’t Supposed to End Like This

Embracing a Zero Trust Security Model

Turns out Most Manufacturing, Water Supply, and Power Companies Use Controllers with a Security Severity Score of 10 out of 10

Chromebooks outsold Macs worldwide in 2020, cutting into Windows market share

Clubhouse is the New Up-and-Comer but Security and Privacy Lag Behind Its Explosive Growth

New York sues to shut down 'fraudulent' Coinseed crypto platform

Former SolarWinds CEO blames intern for 'solarwinds123' password leak

WhatsApp will basically stop working if you don't accept the new privacy policy

TikTok breaching users’ rights “on a massive scale”, says European Consumer Group

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to be talking about a fender bender in Arizona and when will these autonomous cars be safe, at least measured safe.

We've got a new wave of app store rejections from Apple. That means a couple of things, including better privacy for all of us.

Hello, everybody. Craig Peterson here. Thanks for joining us today.

This is an interesting question, because we are looking at a future that we assume anyways is going to be full of autonomous vehicles. Why autonomous? What does it mean? There are various levels of autonomous, degrees, if you will. Everything from what we have today in a lot of cars, which is an assist cruise control, that'll keep you a certain distance from the car in front of you.

We've got assisted braking control, where the car notices, Oh, wait a minute. Someone just hit the brakes right in front of you. I should apply the brakes and it hits the brakes even before your foot is pushing down.

Another way to do this is if you slam your foot on the brake, the car assumes you know something that it doesn't, and it increases the force that you're pushing down with. So even though you might just hit the brake fast and not necessarily hard the car will make it hard.

If you think about these types of braking, for instance, you can start to realize where we're running into a problem when it comes to defining whether or not autonomous vehicles are safe.

Bottom line is autonomous vehicles, which are all the way on the other side of this scale, it started with the brakes and now is hopefully going to end with a car that just drives itself. That's everybody's goal, Ford and GM and Chrysler- Fiat, whatever they're called nowadays of course, these autonomous vehicle companies, such as Tesla. We're going to see a way of measuring them that's different than we've ever seen before.

Right now, if you have a motor vehicle, you have a driver's license, most likely. And do you have insurance. Again, most likely and you have insurance because stuff happens. You don't really mean to hit something. You don't mean to wander out of your lane and end up in the woods. Right?

There's a lot of different things that can happen to you, including having another driver get into your way. My wife has been rear-ended. I was rear-ended. She had a beautiful little car, a little MG, and I can tell to this day that she absolutely loved that little car and she used to drive it around and go down to work. I think it was at Baxter Travenol and she'd be driving down there, just having a great time in Southern California. While she was at a stoplight and somebody rear-ended her and totaled her car. Which is just an absolute shame that wasn't her fault. Was it?

I got rear-ended, I've been ruined it, I think two or three times, never to the point that she was at, where the vehicle had major damage, let alone have to be written off, but it happened right.

People aren't attentive. They misjudged the distance. It might be following too close for the conditions, rain or snow or fog or ice. There's a lots of reasons. So we have insurance and we have a driver's license to prove that we indeed at least understand the basics of driving. We passed a test, right? What is it? 70% pass rate, which frankly, isn't such a great rate if you get right down to it.

Anyway, how do we measure these cars? I mentioned the rear end collisions for a very specific purpose. These autonomous cars are racking up millions of miles on roads out West, really California, Arizona is a very popular place for them to be tested because they don't have a whole lot of weather conditions to worry about. The roads are there and they're not changing very much, particularly in Southern California. They've all been built and there's not another square inch that isn't paved, including people's front lawn, which just absolutely boggled my mind.

Why would you have a cement slab for front lawn anyways? That's California for you. These cars driving millions of miles in California are having accidents. They're not having these types of accidents you and I have.

There is a police report that was obtained by the Phoenix new times this last week that revealed a minor Waymo related crash. Now this crash occurred last October and it isn't the only one. This is, kind of, a pattern, but these have not been publicly reported until now. I'm going to read here just a quick paragraph from what the new times in Phoenix had to say, "a white Waymo minivan" Waymo, of course, Google's little spinoff, to make these autonomous vehicles. "A white Waymo mini-van was traveling westbound in the middle of three westbound lanes on Chandler Boulevard in autonomous mode when it unexpectedly breaked for no reason." "A Waymo backup driver behind the wheel at the time told Chandler police that all of a sudden the vehicle began to stop and gave a code to the effect of stop recommended and came to a sudden stop without warning." A red Chevy Silverado pickup behind the vehicle swerved to the right, but clipped its back panel causing minor damage."

No one was hurt. Overall Waymo has a pretty strong safety record. By the way, that was from an article over at ARS Technica. They have more than 20 million testing miles in the Southwest United States. If you think about it. I was adding these numbers up, 20 million miles. My wife and I, we have put well more than a million miles on cars. That's what happens when you have eight kids, right? Over the years you rack it up, 250,000 this car, 300,000 on that car. Yeah. It adds up. That's a lot of miles.

If you start looking at how many miles the average person drives a year and start doing some comparisons with the accident numbers, you'll see really that the autonomous vehicles are having far fewer accidents. Fewer accidents involving a death, which is actually very good, but the accidents it's having, even though they tend to be minor are usually the fault of the other driver. A large majority, in fact of the accidents where these Waymo vehicles, this is according to Waymo, large majority of those crashes have been the fault of the other driver.

So what is the fault of the other driver? Who was at fault here? If that red Chevy Silverado pickup truck hit that Waymo autonomous car, it's the Chevy's fault.

Why did the Chevy do it? It isn't just because he's driving a Chevy or because it's red or a pickup, he hit that car most likely, I don't know, I'm not talking to the guy, but most likely because the car did something unexpected.

If you read again, that police report it saying that even the driver quote unquote, in, in the Waymo car, this white minivan, who's sitting there to make sure the minivan doesn't run somebody over, that driver said, it was all of a sudden it began to stop. It all of a sudden began to stop and gave this code about a stop recommended and stopped with a warning. Put all of those things in a pot and stirred up and what do you have? You now have a different way of driving.

See that Chevy Silverado, if he's a good driver, he's looking ahead right down the road. If you look too close in front of you, you're going to be over-correcting. You're going to be steering all over the place. You're not going to go in a straight line. So with experience, you're looking down the road, two, three, four minimum car lengths ahead. Depends how fast you're going and that's where you're aiming.

You don't see an obstruction in front of that Waymo minivan. So you're not starting to slow down. It's just like I come up to your traffic light there's cars in front of me, and that light is red. I'm not going to be accelerating and then leaning on the brake, like so many people do. I see, there's a red light ahead. There's cars stopped at the light. I'm just going to coast to a stop. Right? Save some energy. You save some brake pads. Stop global warming by not heating up those brake pads.

It's not something most people expect. I've never been rear-ended by doing that, but I've certainly been given the finger for doing that even though I tend to get to the cars in front of me, right? About the time the light turns green.

It's fascinating to look at, but what's going to happen? What is ultimately the way to determine how safe these cars are?

We cannot use the types of assessments that our insurance companies are using. Rear end collisions, like this, rarely get anyone killed. That's where the real high expenses come in. The driver in the back is usually considered to be at fault.

But, what happens when the self-driving cars suddenly comes to the stop in the middle of the road. It's interesting to think about it, isn't it?

Waymo's vehicles sometime hesitate longer than a human would because they have to do all kinds of computations and consider complex situations that they're not used to.

If you've ever written code, say a hundred lines of code. It's going to be in case with cars millions of lines, but out of a hundred lines of code, about 90% of it is for the edge conditions. In other words, things that are unlikely to happen.

So when something weird happens that car's going to hesitate, and that frankly is a problem, the idiosyncrasies of self driving cars.

We're going to talk about a wave of app store rejections by Apple iOS for your iPhone, iPad, et cetera. We'll tell you why right here.

You're listening to Craig Peterson, online Craig peterson.com.

Apple is making another major change in order to give us more privacy. I just started this, Improving Windows Privacy and Security Course. If you using an Apple iOS device, you're halfway there.

Hello, everybody. Craig Peterson here. Thanks for tuning in . You can always hear me online@craigpeterson.com slash podcast.

Apple has been really the only major vendor out there in the smartphone industry to really have security as their prime motivation. Okay, you could argue money istheir prime motivation, right?

Apple has always tried to be secure. The hardware is quite secure. They haven't licensed their operating system to third parties and that gives them control. Like you can't have anywhere else.

Think about all of the different Android-based smartphones that are out there. There are thousands of different models. Within each model, sometimes there are dozens of different hardware configurations. So, Google comes out with a security patch and sends it on out to the vendors, well actually makes it available for the vendors to pick up. Then the vendors go and grab it, and they have to test it, and they have to work in their own code, and then they have to work in all of the device drivers stuff, and they have to package it up.

They have to test it on all of the different models. Just think about Samsung, how many models Samsung has, just by itself, a whole lot of models. It is almost impossible for Android phones to get security patches. Any Android phone that's more than two years old is guaranteed to not get security patches.

I talked last weekend about what Samsung is doing to try and solve this. Finally, they must be listening to the show. Samsung had been more or less supporting it's top of the line models for about two years. If you bought a top of the line Galaxy phone from Samsung or another real top hot model, you might get security updates for a couple of years, and that's kind of it. Forget about it beyond that, which is why I said, if you absolutely must use Android, there's only one vendor you can use in that Samsung.

There's only one model phone that you can buy, which is Samsung top of the line phone, and you have to replace it every two years. So Samsung has come out now and said, We're going to provide support security support for our phones for five years.

So they're trying to compete with Apple here. Apple has long provided support for five years. And as we saw just a couple of weeks ago with this big act of zero day attack against Apple iOS devices. They will actually provide security updates for much longer than five years, but it's way easier to provide security updates for 30 models of phones than it is for a few hundred models, which is what Samsung has. Expect Samsung to narrow down their product line and also to only really be providing support for the top models within their product lines.

Now, here's what Apple is doing right now. Apple is starting to reject some of these apps that have been in the app store for a long time, as well as new apps. They're rejecting them for a couple of reasons. The biggest reason is that as of iOS 14.5, Apple is requiring all of the vendors to tell you when you go to the app store, what information of yours they're storing, they're using, and they're selling. Okay. Pretty big deal. Isn't it? It's pretty bad deal, frankly, when you get right down to it for facebook and others. Facebook took out full page ads in major newspapers in the US saying, Oh, Apple can't do this. This is terrible. It's going to destroy a small business. They said, it's going to destroy small business because Facebook can't pry into our lives as much. You know how it is. People say all the time, they're saying, Hey, I, why am I getting these ads? I've never even searched for it and somehow it's coming up.

There's a number of reasons why, but the bottom line is called big data. These apps like Facebook use all kinds of big data to figure out what we might like and part of that is based on what our friends are searching for. So, it puts together this massive mesh and figures it all out. Something that the Obama campaign really pioneered when Facebook gave them all of the data that they had on everyone and anyone.

I'm sitting here shaking my head because somehow that's okay, but having this Cambridge Analytica company do some of it from a paid standpoint and not get wholesale data somehow that was the most evil thing that ever happened.

They forgot about Obama, but you know, I guess that's political. I criticize both sides of the aisle. I am an equal opportunity criticizer. They deserve it.

We've got Apple now telling Facebook and every other app developer, you have to tell the users. In fact, if you go right now to your phone, your iPad or your iPhone, or the iPod touch, you'll see if you go to the app and you scroll up. You can open a little tab and that tab will all of a sudden become a very big part of the screen because it's tell me what this app is doing with my data. If you don't tell it, Apple's going to block you from the store.

Google has, of course, a bunch of apps. You've probably used them things like Google maps, which I try not to use. Use the Apple maps its gotten much, much better than it was, and they're not tracking you and selling your data like Google does.

Google has its own little app for doing searches. Of course, you've got Google Chrome, all these different things from Google. Google stopped updating their apps on the Apple app store because Apple was telling Google, you have to tell people what your doing with their data. Google didn't want to do it. We just want to update the apps, kind of, loophole that was in this whole thing. They can't not update it forever. Now we're seeing rejections of these developers.

Here is a few lines again from ARS Technica, from a rejection letter that some developers received. "We found in our review that your app collects user and device information to create a unique identifier for the users, devices, apps that fingerprint the user's device in this way are in violation of the Apple developer program license agreement and are not appropriate for the app store."

Now, we're not talking about the fingerprint, as in the fingerprint reader, we're saying that they are looking for unique information about the phone, so they know it's you, they can put it all together. That letter goes on specifically, "your app uses algorithmically converted device and usage data to create a unique identifier in order to track the user."

Apple is really making it clear now to developers. To the ire of Facebook and Google and other companies who rely on that type of tracking to maximize the advertising revenue. I can understand that, right. I really can. It's also clear that this app tracking transparency means that apps that are trying to track you by any means without your consent are going to face rejection.

Bravo to Apple, yet again.

Now I'm not so happy about the statement they made this week. Yeah, Georgia. That's another thing entirely.

Stick around everybody. We will be right back talking more about technology. We're going to talk a little bit about what Google's planning to do in order to help with all of these Android developers and people that are selling them. Carriers, et cetera. How's Google is going to help them with their security updates. This is an interesting way to do it. It's exactly what Apple's been doing.

You're listening to Craig Peterson.

Apple's really gotten into the chip business and it isn't just because they wanted a chip for their iPhone that they could control. In fact, Apple has even gone further and looks like Google's going to do the same.

Hello, everybody. Craig Peterson here.

Google has been an interesting beast over the years. Remember they used to say that their motto was don't be evil. Then a few years ago they removed it from the website and evil seems to be their middle name, a little bit.

One of the things Google has been doing is offering an operating system that can be used and is being used to run almost anything. We're talking mostly, however, about smartphones, certainly by number. That's called Android. Android was a little operating system, of sorts, that was developed by a kid actually Google bought it from him. They have continued to develop on it. It's not a bad little platform. The biggest problems with it really have to do with what I talked about a little earlier, the security, right? Getting the updates.

I mentioned how Apple really has a walled garden. They have their own environment where everything is contained so they can control it all. Google cannot control anything other than the Google pixel phone.

It cannot control what Samsung is doing with the operating system, Android can run on pretty much any chip that's manufactured from Intel chips, through all of these, a little fast chips, these snapdragons and many others that have been used over the years. There's a lot of them.

One of the biggest problems, of course, is the chip set. I've mentioned that Google can come out with an operating system release to fix some security problems, and then those are pushed out, but nothing's done by the carrier or maybe the developer of the handset. What Google's decided to do is make their own walled garden.

If you buy an Apple iPhone, you buy an Apple iPad, or you buy a new Apple Mac, they're all using the same basic chip set that's designed by Apple. They have some fabs where they're making some of these components. Apple has done that so again, they can control it even better. They don't have to pay that exorbitant Intel tax.

Also over at Apple trying to figure out how can we avoid the Qualcomm tax. It isn't just a Qualcomm, you know, I say tax, as in you pay way more for Intel than you would for another equivalent or better chip.

In fact, I have an Apple right in front of me here, an Apple Mac. This is a Mac mini M1 based. It is way faster and cheaper than the Intel version.

You can still get the Intel version of the mini $200 more. There's your Intel tax. And it's about half the speed for some of these things.

For instance, Adobe said that this mac with the Apple chip set in it can be twice as fast as the Mac, same Mac with an Intel processor.

Apple is moving away from not just Intel now, but from Qualcomm. Google wants to move away from Qualcomm. In many of these smartphones, including the pixels, they're using a Qualcomm Snapdragon chip.

The Qualcomm makes a lot of different types of chips. They also tend to make the radio chips that are in our smartphones. The radio chips are used to talk to the cell towers, just send data to send our voice. That's what they're used for.

Apple is hiring developers right now to develop their own chip set. It might not be there for 5G. It might be 6G. In fact, that's what the advertisements for those jobs were about as 6G. But they're going to move away from all of these standard devices that are very expensive and hard to control.

Google is saying the biggest problem we have with making sure that users of the Android operating system get updates is Qualcomm. Interesting, isn't it?

Google is coming out with, what's known as a system on a chip, SOC. What that is, think of the motherboards of years past. One of my first computers was an IBM three 60 30 mainframe, and this thing was huge and not much power. It's just amazing to think about, but it really could sling data around even way back then. It was a nice little computer, if you will. Think about how big that motherboard was. Yeah. It had the main processor. You had the memory controllers, the bus controllers, you had everything right that needed to be there to support it. All of your IO stuff. I might have had serial UARTS built into it, et cetera, et cetera.

A system on a chip is basically you got one chip and that's pretty much all you need. Obviously you got to have memory and you're going to have some sort of storage, other more permanent storage devices, but that's the basics of what a system on a chip is. Google reportedly anyways, that the pixel six is expected to ship with Google custom white chapel is what it's going to be called system on a chip internally.

It's referred to as a GS101. And that GS could be for Google silicone. There's all kinds of people speculating that seems to be the kind of the big one. There is a pixel six in the works. We do know that. Nine to five Google, is a website out there and they've done a lot of little spying on what's going on, but apparently it's a, I'm not going to get into all of the details, but basically it's going to have three CPU cores in it and everything. It's going to be really quite nice. A large arm core for single threaded work loads and three medium cores for multi work.

We've had a problem over the years. How do you make your computer faster? And you can use Intel's approach, which is let's just throw more processors at it. That's great if the software you're using can handle multithreaded environments where you have multiple processors. Okay. You got multiple processors, but how about the access to the memory? What if the process is all one access to the same area of memory at the same time? Then you have to start blocking. It gets very complicated, very fast. Intel chips fade very, very fast. You don't have to get to too many CPU's before all of a sudden the addition of one more CPU cuts the performance of that new CPU by 50%. It really doesn't. It really doesn't take much.

They're all trying to get away from Intel. Many of them have, right? Obviously Google Android phones outside of Google as well have been based on non-Intel hardware for awhile, but they're also now trying to get rid of Qualcomm. And I think that's a good thing. Ultimately, it's going to help out a lot. We're going to see more of this thing in the future, and we're all going to benefit from it, right? With the Google having control over their system on a chip, at least their pixel, it's going to make their life easier, which means if you buy a pixel, you're probably going to be able to get the upgrades better.

Thinking in the back of my mind that maybe Samsung is looking to do the same thing. Maybe Samsung's looking to move away from the Qualcomm chips and move to Google's new system on a chip. I have no idea. I have no inside information, but that would seem to make sense for me, particularly if they want to provide support for years.

By the way, Google is in the embarrassing position of offering less support for Android devices than Samsung, which is now up to three years of major updates, which by the way, is Qualcomm's maximum. Samsung has four years of security updates for some of their devices as well.

Stick around.

You're listening to Craig Peterson.

You can find me online@craigpeterson.com. Don't go anywhere.

You've heard about the no fly list, right? Yeah. How about the terrorist and other watch lists? These lists that people have found it's impossible to get their names off of, even when there was no reason to be there in the first place?

Well, I got some news.

Hi, everybody. Craig Peterson here.

Department of Homeland security has been criticized for many things over the years. One of the things that's been criticized quite a bit about is this watch list that they maintain. They have a watch list for no fly. People get put on that watch list. It was originally intended to be, we know this guy's a terrorist, so we're going to put them on, right.

It's not always the way it goes. It starts out almost innocuous and before you know, it, there's all kinds of people getting caught in this big, big net.

That's what's been happening lately and it's going to get worse because the Department of Homeland security has decided that they are going to hire regular old companies to help develop this no fly list and also this terrorist watch list.

Apparently these companies are going to be looking through all kinds of public data, maybe some private data, social media in order to provide information for this new domestic terror watch list. So you look at that and say, okay, I can see that.

We've talked to before problem, man, 20 years ago, I think I was talking about these data aggregators and the problems they create. Cause they're taking public records, they're putting them all together. They're figuring out how it all meshes together and they come up with a pretty accurate picture of who you are.

Now, I've got to say when I've had them on my show here before I was talking to them and said, okay, I want to look up my own records. So I looked them up on their platforms. I did not see a single one that was more than about 30% correct about me.

Now, this was again, some years ago. I think it's been probably almost a decade since I last spoke with the data aggregators. They really are trying to blend into the background, nowadays. This data that's put together by these artificial intelligence systems is not necessarily that accurate and that gets to be a real problem.

So who is DHS gonna hire? Well, from the description that has been reported on here by the Conservative Tree House, it is going to be big tech, specifically, Google, Facebook, YouTube, Instagram, Snapchat, Twitter, and more.

DHS is going to put them under contracts to hire and organize internal monitoring teams to assist the government by sending information on citizens, they deem dangerous again, what could go wrong?

Our government is not allowed to spy on us. How many times have we talked about this? You have of course the five eyes and then they added more and more. These are governments that spy on each other's citizens for each other.

So for instance, US cannot spy on US citizens. So we have an arrangement with the United Kingdom, New Zealand, Australia, Canada, to spy on the US citizens for us that makes sense to you. Can you believe that?

We spy on their citizens for them and they spy on our citizens for us and all is good.

What's happening here is The Department of Homeland security realizes it cannot spy on us directly. This is what they've been doing for very long time, they go to the data aggregators and they pull up the data that they want.

They want to see if this guy maybe selling illicit drugs and they pull up public records. What cars does he have? How many homesdo they own? Who's he dating? Has she all of a sudden been buying diamonds and mink coats? What's going on here?

So now we're seeing that the US intelligence apparatus. It's really now going live quickly, to put together lists of Americans who could be potential threats to the government and need to be watched.

Now it's all well, and good. It's just like president Biden this week saying, Oh, we're going to have these red flag laws. We're going to stop the sale of certain types of firearms and things. It all sounds good. The reality is we have known about some of these people before, right? This is all just a red herring that the federal government is doing right now because the real problem is these terrorists, the domestic and otherwise that have shot up schools have almost always been reported to law enforcement as dangerous people. Some of them have even been on lists that say they cannot buy firearms, and yet they get firearms. Bad guys.

It's like here in the US. Where does our fentanyl come from? We're not making a domestically. Our fentanyl is coming from China often through Mexico, and it is killing people here in the US. The whole George Floyd incident, and what's happening with fentanyl in his system, right. The question is, did the police operate properly? What killed him? According to the coroner's report? It was the fentanyl. that killed him.

One way or the other that fentanyl got here from China and is being used on the streets and people are dying from it. Fentanyl's illegal. How, how could they possibly get it?

It's illegal for a felon to be in possession of a firearm. How did it felon get the firearm? The police were warned about people in San Bernardino, California, they were warned. The people in that business told the police. We were calling. we're really worried about this guy and nothing happened.

So now what are we going to do? We're going to cast an even wider net, when we cannot take care of the reports that come in right now. We're going to get even more reports and they're going to be coming from these AI systems. Again, what, what could possibly go wrong here? It's absolutely incredible.

They look at these reports, they try and determine are these actionable, the FBI or other law enforcement agencies. They've been deciding no, it's not actionable. They've been right sometimes and they've been wrong other times. This is a real problem.

What shocked me is NBC news with Andrea Mitchell, NBC news. Not a centrist news organization, very far left. NBC news is even reporting on this. They're realizing the consequences. Here's a quote from NBC. "DHS planning to expand relationships with companies that scour public data for intelligent and to better harness the vast trove of data it already collects on Americans."

"The department is also contemplating changes to its terrorist. Watch listing process." Absolutely amazing. "Two senior Biden administrative administration officials told NBC news that Homeland security whose intelligence division did not publish a warning of potential violence before the January sixth Capitol riots, is seeking to improve its ability to collect and analyze data about domestic terrorism, including the sorts of public social media posts that threatened a potential attack on the Capitol."

"DHS is expanding its relationships with other companies that scour public data for intelligence. One of the senior officials said, and also to better harness the vast trove of data it already collects on Americans, including travel and commercial data through customs and border protection, immigration, customs enforcement, the coast guard, secret service, and other DHS components". There you go from NBC news. So remind yourself what the FBI contractors with access to the NSA database already did in their quest for political opposition, research and surveillance, and then get everything we were just talking about.

The director of national intelligence declassified, a FISA judge's ruling. So this is judge James Boasberg, 2018 ruling, where the FBI conducted tens of thousands of unauthorized NSA database queries. Do you remember that story? Very, very big deal. This judge obviously passing these things out like candy and the FBI misusing its power and authority. Again, what could possibly go wrong?

By the way, President Obama apparently has been telling us that we should use the no fly list to keep people from owning guns.

There's already a database maintained by the FBI. This whole thing is, as I said, a red herring things are going to get really bad if law enforcement does this. Frankly, they're going to do it. There's no two ways about it.

We have to be more careful about keeping our information, our data private. That's what this whole course that started last week was all about. Improving your Windows privacy and security. Locking it down because the way Microsoft ships windows and the way it installs and configures itself by default does not keep your data private. That's a problem. So that's what we're going through. Hopefully, you were able to get into that before we closed it Friday night.

Remind yourself of this and just keep chanting nothing bad could happen here, right? Ah, the joys of all of these computers and databases and the way the work in nowadays.

By the way, if your information is out there at all, even if you use fake names and numbers and addresses and things like I do when it's not required. Right.

I don't lie to the bank. I don't lie to the IRS. Nobody else needs to know the truth. Even if you have been, keep it private, good chance that they know who you are and where you are. Crazy. Crazy.

Hey, visit me online. Craig peterson.com.

Make sure you subscribe to my weekly newsletter.

Hi everybody. Of course, Craig Peterson here. We're going to talk today about these drone swarms, your personal privacy risk tolerance breach highlights here over orgs individuals. What's going on? Ransomwares way up.

As usual, a lot to talk about. Hey, if you miss part of my show, you can always go online to Craig peterson.com. You'll find it there. If you're a YouTube fan CraigPeterson.com/youtube.

This is really an interesting time to be alive. Is that a good way to put it right? There used to be a curse "May you live in interesting times" Least that was the rumor.

One of the listeners pointed this out, there was a TV show that was on about five years ago, apparently, and it used this as a premise. I also saw a great movie that used this as a premise and it was where the President was under attack. He was under attack by drones.

The Biden administration has a policy now where they're calling for research into artificial intelligence, think the Terminator, where you can have these fighting machines.

These things should be outlawed, but I also understand the otherside where if we don't have that tech and our enemies end up having that tech, we are left at a major disadvantage.

Don't get me wrong here. I just don't like the idea of anybody doing Terminators, Skynet type of technology. They have called for it to be investigated.

What we're talking about right now is the drone swarms. Have you seen some of these really cool drones that these people called influencers? Man, the term always bothers me. So many people don't know what they're doing. They just make these silly videos that people watch and then they make millions, tens of millions, I guess it's not silly after all.

These influencers make these videos. There are drones that they can use if they're out hiking, you might've noticed or mountain biking or climbing. They have drones now that will follow them around, automatically. They are on camera. It's following them. It focuses in on their face. They can make the drone get a little closer or further away. As long as the sky is clear there's no tree branches or anything in the way that drone is going to be able to follow them, see what they're doing and just really do some amazing shots. I've been just stunned by how good they are.

Those drones are using a form of artificial intelligence and I'm not going to really get into it right now, but there are differences between machine learning and artificial intelligence, but at the very least here, it's able to track their faces.

Now this is where I start getting really concerned. That's one thing. But they are apparently right now training. When I say they, the Chinese and probably us, too, are designing drones that not only have cameras on them, but are military drones. They have without them having to have a central computer system controlling them or figuring out targets, they're able to figure out where there's a human and take them out.

These small drones, they're not going to take them out by firing, a 50 caliber round at them. These drones can't carry that kind of firepower. It's just too heavy, the barrels and everything else -- it's a part of that type of a firearm. We're talking about small drones again. So obviously they're not going to have a missile on them either.

What they do is they put a small amount, just a fraction of an ounce, of high explosives on the drone. The idea is if that drone crashes into you and sets off its explosives, you're dead, particularly if it crashes into and sets off explosives right there by your head. Now that's pretty bad when you get down to it.

I don't like the whole Skynet Terminator part of this, which is that the drones are able to find that human and then kill them.

Think of a simple scenario where there is, let's say there's a war going on. Let's use the worst case scenario and, enemy troops are located approximately here. You send the drones out and the drone has of course, GPS built into it, or some other inertial guidance system or something in case GPS gets jammed.

That drone then goes to that area.

It can recognize humans and it says, Oh, there's a human and it goes and kills the human. Now that human might be an innocent person. Look at all of the problems we've had with our aerial drones, the manually controlled ones, just the ones that we've been using in the last 10 years where we say, okay, there's a terrorist here. Now they fly it in from, they've got somebody controlling it in Nevada or wherever it might be, and they get their strike orders and their kill orders. They go in and they'd take it out. There are collateral damages. Now that's always been true.

Every war.

Look at Jimmy Stewart. For example, a younger kids probably don't know who it is. Mr. Smith goes to Washington was one of his movies. He had some great Christmas movies and stuff too. Anyhow, Jimmy Stewart was a bomber. I think he was a pilot actually in World War II. He flew combat missions over Germany. Think of what we did in Germany, in Japan, where we killed thousands, tens of thousands, hundreds, probably of thousands of civilians.

We now think, Oh we're much better than that. We don't do that anymore. We're careful about civilian casualties. Sometimes to the point where some of our people end up getting in harm's way and killed. For the most part, we try and keep it down.

A drone like this that goes into an area, even if it's a confined area, and we say, kill any humans in this area, there are going to be innocent casualties. It might even be friendly fire. You might even be taking out some of your own people.

They've said, okay we've got a way around this. What we're going to do is we're going to use artificial intelligence. The drone doesn't just pick out, Oh, this is a human. I'm going to attack that person. It looks at the uniform, it looks at the helmet. It determines which side they're on. If they're wearing an American or Chinese uniform, whatever, it might be programmed for it again, it goes into the area, it finds a human and identifies them as the enemy. Then it goes in and hits them and blows up killing that person. That's one way that they are looking to use drones.

The other way is pretty, scary. It's, you can defend yourself against a drone like that. You've got a drone coming. You're probably going to be able to hear it. Obviously it depends. That drone gets close. I don't know if you've ever had the kids playing with drones, flying them around you, or you've done the same thing. You can always hit it out of the air, can't you?

If you're military and you have a rifle in your arm, you can just use the rifle and play a little baseball with that drone. There's some interesting stories of people who've been doing that already.

What happens if we're not talking about a drone, we're talking about a drone swarm. I don't know that you could defend against something like that. There have been studies that have been done. So think, you think there nobody's really working this suit? No, they sure are.

What's going to happen? Well, the Indian army is one that has admitted to doing tests and they had a swarm of 75 drones. If you have 75 drones coming after you, let's say you're a high value target. There is no way you're going to be able to defend yourself against them, unless you can duck and cover and they can't get anywhere near you with their high explosives. The Indian army had these Kamikaze-attack drones. They don't necessarily have to even have high explosives on them.

This is a new interpretation under Joseph Biden. Mr. President of the Pentagon's rules of use of autonomous weapons. We've always had to have "meaningful human control." That's the wording that they Pentagon uses meaningful human control over any lethal system. Now that could be in a supervisory role rather than direct control. So they call it "human on the loop" rather than "human in the loop." But this is a very difficult to fight against.

The US army is spending now billions of dollars on new air defense vehicles. These air defense vehicles have cannons two types of missiles, jammers. They're also looking at lasers and interceptor drones, so they can use the right weapon against the right target at the right time.

That's going to be absolutely vital here because it's so cheap to use a drone. Look what happened. What was a year plus ago now? I'm trying to remember, Central America, Venezuela, somewhere in there where El Presidente for life was up giving a speech. I'm sorry. I didn't mean that to be insulting, but that often is what ends up happening. A drone comes up and everybody's thinking: Oh, it's a camera drone, wave to the camera thing. It got very close to the President and then blew up. On purpose, right? They were trying to murder the president. That's a bad thing. He was okay. I guess some of the people got minor injuries, relatively speaking.

When we're looking at having large numbers of incoming threats, not just one drone, but many drones, many of those drones may be decoys.

How cheap is it to buy one of these drones? Just like the ones that were used in China over the Olympic stadium, where they were all controlled by a computer. You just have these things, decoys, all you need is a few of them that can blow up and kill the people you want to kill very concerning if you ask me.

We're paying attention to this as are other countries as they're going forward.

We're going to talk about building your privacy risk tolerance profile, because if you're going to defend yourself, you have to know what you're going to defend against and how much defense do you need?

Hey, we take risks every day. We take risks when we're going online. But we're still getting out of bed. We're still going into the bathroom. We're still driving cars. How about your online privacy risk tolerance? What is it?

Hi everybody. Thanks for joining me.

We all take risks, and it's just part of life. You breathe in air, which you need. You're taking the risk of catching a cold or the flu, or maybe of having some toxic material inhaled. We just don't know do we?

Well on any given day, when we go online, we're also facing risks. And the biggest question I have with clients when I'm bringing businesses on or high value individuals who need to protect themselves and their information is: okay... what information do you have that you want to try and protect? And what is your personal privacy risk tolerance? So we build a bit of her profile from that and you guys are going to get the advantage of doing that right now without having to pay me my team. How's that for simple?

First of all, we got to understand that nothing is ever completely safe. When you're going online, you are facing real risks and no matter what people tell you, there is no way to be a hundred percent sure that your data is going to be safe online or that your individual personal, private information is going to be safe while you're online. And there's a few reasons for this.

The most obvious one, and the one we think about, I think the most has to do with advertising. There are a lot of marketers out there that want to send a message to us at exactly the right time. The right message too obviously? So how can they do that? They do that by tracking you via Google. So Google that's their whole business model is to know everything they can about you and then sell that information.

Facebook, same thing. Both of those companies are trying to gather your information. They're doing it when you are not just on their sites, but when you are on other people's sites. Third party sites are tracking you. In fact, if you go to my website @ craigpeterson.com, you'll see that I do set a Facebook cookie. So I know that you're on Facebook and you visited my site and you might be interested in this or that.

Now I'm not a good marketer. Because I'm not using that information for anything, at least not right now, hopefully in the future, we'll start to do some stuff. But that's what they're doing. And the reason why I don't think it's a terrible thing don't know about you.

I don't think it's bad that they know that I'm trying to go ahead and buy a car right now. Because if I'm trying to buy a car, I want advertisements about cars and I don't want to advertisements about the latest Bugatti or Ferrari, whatever it might be. I want a Ford truck, right? Just simple something I can haul stuff around. You already know I have a small farm, and I need a truck because you need one. I'd love to have a front loader and everything too, those costs money and I ain't got it. So that makes sense to me.

And now there's the other side, which is the criminal side. And then there's really a third side, which is the government side.

So let's go with the government side here. In the United States our government is not supposed to track us. Now I say "supposed to," because we have found out through Edward Snowden and many other means that they have been tracking us against the law. And then they put in some laws to let them do some of it, but our government has been tracking us.

And one of the ways it tracks us is through the "five eyes" program and now that's been expanded and then expanded again. But the five eyes program is where the United States asks the United Kingdom. Hey, listen. Hey bro. Hey, we can't and we're not allowed to track our citizens, but your not us. How about we have you track, Trump and his team? Yeah, that's what we'll do.

So there's an example of what evidence is showing has happened. So they go to a third party country that's part of this agreement,d where all of these countries have gotten together, how signed papers and said, yeah, we'll track each other citizens for each other.

And that way the United States could say, Hey, we're not tracking you. And yet they're tracking because they're going to a third party country. And the United States, if you are going out of the country, then again, they can track you. Any communications are going out of the country. So that's the government side.

And then of course, there's governments that track everything. You look at China and how they control all of the media. They control all of the social networking sites. They basically control everything out there.

We have to be careful with all of that stuff because it can and will be used. And we've seen it has been used to really not just harass people, but do things like throw them in prison disappear them. Look at what just happened in China, with the head of China's biggest company, basically the Amazon competitor over there. And he disappeared for months and then came back, just praising the Chinese Communist government and how great it is to have all of these people over there. Just telling them what to do and how to do it.

We obviously don't live in China. We obviously, I think have oligarchs nowadays. We have people who are rich, who are running the country. They're giving money to campaigns, they get the ear. You seen all of the bribery allegations against the Biden crime family, or his brother, his son, other members, himself as well, based on a hundred Biden's laptop.

So I don't trust government for those very reasons.

The hackers let's get into the hackers here. When it comes to hackers, there are, again, a few different types. You've got hackers that are working for governments. And what they're doing is in the case of a small government, like North Korea, they're trying to get their hands on foreign currencies so that they can use those currencies to buy grain, to buy oil, coal, whatever it is they might need to buy.

You have governments like China and Russia that are trying to basically run World War three. And they're out there with their hacking teams and groups and trying to figure out how do we get into the critical infrastructure in the United States? Okay. So this is how we get in. Okay. We're in over there. So if we ever want to shut down all of the power to New York City, this is what we do.

Now remember, that's what happened back in, in when was that 2004, I guess that was, yeah. I remember I was down in, I was heading actually to New York city and then all of a sudden, all of the power went out.

That apparently was an accident, but it didn't need to be an accident. There are all kinds of, allegations about what actually happened there. But that's why China and Russia are trying to get into our systems. And then they obviously want to play havoc. Look at the havoc that was caused in the U S economy by this China virus that came obviously from China for Huan. if they wanted to shut down our economy, they now have proof that's all it takes. And they are working on the genetics of some of these viruses over there in China. And they're trying to modify the genes and they are the running experiments on their troops to enhance them, to make these super soldiers that maybe, need less sleep or less food are stronger or et cetera, et cetera, they are doing that.

So China is a real threat from just a number of different ways. What would it be like if they could shut down our banking system or make it so we don't trust it anymore?

Okay. That's part one of your Personal Privacy Risk Tolerance Profile. Stick around because we're going to talk more about this and what you can do to help you have privacy.

What is your online, personal privacy risk tolerance? It's going to vary, I help high value individuals. I help businesses with this, and now I'm helping you as well. So let's get into part two.

Craig Peterson here.

When people ask me, what should I do? That is a very nuanced question. At least it's a very nuanced to answer because you could say something like: if you want to be private, use Signal for messaging and useTorr for web browsing, that's fine. And it works in some ways and not in others. For instance, Tor is a web browser that is like a super VPN. It is set up so that you're not just coming from one exit point, you're coming from a whole bunch of different points on the internet. So it's hard to track you down. The problem, however, with Tor is the same problem that you have with VPN services. And I talk about this all the time.

VPN services do not make your data secure. It does not keep it private. And in the case of VPN services that you might get for free or even buy, and also the case with Tor. Using those VPN services that can make you less secure again. Why did Sutton rob banks? He robbed banks because that's where the money was, where he is a bad guy going to go. If they want easy and quick access to lots of peoples. Private information?

They're going to hack a VPN server aren't they? Yeah. And if they can't hack the VPN server, why not just have server space in the same data center that VPN provider is renting their space from and then hack it from there, try and get in from there. Or maybe get into the service; the data centers will logs or the VPN servers logs, because even when they say they don't log, they all log, they have to log, they have to have your information otherwise, how can they bill you? And the ones that say we don't log, which are those people are "lieing" by the way. But those guys that have these VPN servers and they're trying not to log, they're trying not to log where you're going. They get fooled all of the time as well. Because their servers have logs, even if they're deleted and disappear.

So I just wanted to make it clear that you, I, if you have a low risk tolerance, when it comes to your privacy, Tor is not going to do it for you. VPN services are not going to do it for you. You have to look at all of the individual things you're doing online and then decide based on those. What is it that is the most. Beneficial for you in that particular case. Okay.

So Signal, I brought it up. So let's talk about it for a minute. Signal is the messaging app to use bar none. Signal is encrypted and do, and it is known to be highly secure, which again, Doesn't mean it's a hundred percent, but with Signal, you can talk to people on other platforms. You can have a Mac and talk to somebody on a, on an Android or a windows device.

But another consideration is who are you talking to? If you're talking to other people that have Macs and you don't want your information to get out, but you're not horrifically worried about it, right? You want it to be private. You want end to end encryption. You're better off using iMessage on your Mac.

If you're on Windows or Android, there are not any great built-in messaging apps. WhatsApp. If you listened last week and I've got it up on my website, WhatsApp is not great. They claim it's not horrible, but why would you use it if there's a question use Signal instead.

All right. So there's just a lot to consider when we're talking about it, but here is your big bang for the buck thing. That you can do. And that is use password manager. Now we talked about how Google Chromium Google's Chrome and of course now Microsoft edge. Actually it was the other way around Microsoft edge came up with it first and now Google's adding it.

But Edge has this password manager built-in. That's all well and good, but I don't know, trust those. I use a third party password manager that is designed for password management and that's all the company does. They're focused on the security behind it, which is why I recommend 1Password and lLastPass. 1Password being my absolute favorite. Use those password managers. That's the biggest bang for your buck if you have a low tolerance for your information, getting out. All right?

Now that will help to enforce good password habits. It will generate passwords for you, both of those, and it'll generate good passwords and it'll keep them for you, which is really great.

If you don't want to be tracked while you're browsing online, you can use an ad blocker. I have a couple of webinars I've done on that. If you want a video of one of those webinars to go through that talks about these different blockers ad blockers and others. I'd be glad to send you a link to one of them, but you're going to have to email Me@craigpeterson.com.

And I will send you a link to one of those webinars I did on that stuff. No problem. But some websites are going to break when you use an ad blocker. So sometimes you have to turn it off and you have to turn it back on. The ones I tell you how to use and how to configure, I actually show you a step-by-step we walked through it. Those allow you to turn off that particular ad blocker on an individual site that was broken because of the ad blocker. So pretty straightforward. You don't have to remember to turn it all on and all off. All right.

Now studies are showing that people are concerned about their privacy. In fact, I believe last I saw said that I think it was about 70% of Americans believe that their smart phones are being tracked by advertisers, and the tech companies provide them with the information. May, 2020 Pew research report talked about this, but 85% of consumers worry, they can trust corporations with their data. So what do you do? Because. Most people don't have the support or the tools. They don't have. I have the money, they didn't get a big inheritance. They're not a high value individual that needs my help and can afford it -- where we go through everything that they do and make sure they have the best solution for each thing, including banking, including going online and trading stocks, all of that stuff.

You gotta be very careful with all of that stuff. I'm really sad that I have to say this here, but there are no online privacy solutions that will work for everybody. And there are no solutions that work in every situation either.

So what you need to do is understand what you care the most about. And I think for all of us, what we should care the most about is our financial situation and anything associated with that: our intellectual property, if we're businesses, our bank accounts, all of that sort of stuff is stuff we really should be concerned about. And that means you need to watch it. Make sure you're not sharing stuff that you really don't want to share.

Okay?

So even privacy experts like myself, don't lock everything down. We locked most of it down. Particularly since we have department of defense clients, we have to maintain a very high standard.

All right. Stick around and visit me online. CraigPeterson.com. Make sure you sign up for my newsletter.

You'll get all of the latest news and the tips I send out every week.

I don't want to leave you hanging. We're going to get into a few more things to consider here, because obviously we are going to share some of our personal information. So I'm going to tell you how I share my personal information and it might be a bit of a surprise.

Hello everybody. Thanks for listening.

We all enjoy products and services, and that's what I'm saying. When when I talk about security experts, we don't lock everything down. I've used 23 in me. I did that thing, of course, I'm sending in my DNA. That's been an issue in some cases, but that's what I did.

I use these online map programs. I use Google maps. I use weighs more than Google maps. I use Apple maps cause I'm trying to figure out how do I get to where I want to go in a reasonable amount of time. But what I do is I lie about the answer to the security questions. Okay. I don't want them to know my dad's name.

My mother's maiden name, the street. I was, I grew up on my first school, my first car, none of their business. Because it's a lot of that information is actually publicly available. How many of us on LinkedIn have right there in our profile? Yeah I went to McGill university or I w I grew up here's pictures of my childhood home, and that picture has GPS coordinates in it.

So if we use the real information. We are giving away way too much. I use a little phrase I coined here, which is lie to your bank. And you might remember. I did a show on that sometime ago. And the idea here is in your line to the bank about your financial situation, it's nothing like that. You're lying to your bank about this personal information.

They don't need to know these personal questions. They give you for their security questions. It's really important to understand all of this stuff. Okay. For instance, this is Jennifer Granick, she's at the ACL, you and she said her dad died recently. And the accountant said it's really important to report the death to credit companies because the answers to many of the security questions are on the public death certificate.

So answers to security questions really can be a nightmare, but that doesn't mean you have to give them the right answers. So for instance, I found a site online. I should try and dig that up again, but it generated fake identities. And I had a generate like 5,000 of them for me thinking, okay, they might go at some point and it even generated fake social security numbers, fake phone numbers, names, addresses, everything, everything you'd need for a fake identity. And the idea here isn't to cheat anybody out of anything. The idea is, Hey, Mr. Website, you don't know, you don't need to know who I really am. So on some websites, I'm female some websites I've, I'm only 30 years old on other websites. I'm 80 years old. It doesn't matter.

You can call it a lie if you want. But in reality, you're just trying to keep your information straight not and another advantage. Of these password managers. Cause you're trying to keep your information straight, right? It's hard to remember a lie and you have to tell a lie to enforce a lie. You're not, all that stuff your mother told you.

And she's right about that too, by the way. But if you're using a password manager, what I do is I create a unique email address. In fact, my email addresses are extremely unique, so I'll use a plus sign as part of my email address and my mail server knows. Oh, okay. That's just Craig trying to track who is using.

That email address. So I'll have Craig plus YouTube for instance, or@mainstreamdotnetorcraigpeterson.com. I actually have a whole bunch of domains that I use as well. And if you want a secure email service have look at proton mail. They're actually very good from a security standpoint. So there's nothing illegal about giving them this information.

Yeah. You're lying to them, but you gotta keep your lies straight. Another reason to use a password manager because I have the password manager generate my. My password I put in the email, which is unique for every website I go to, I never use that same email address twice if I can avoid it. And then I, and I use aliases too in my email server.

And then I go and in my notes section for that website in my password manager, I put in the answers to the security questions and I just make stuff up nonsensical stuff. So it's asking what my first car, it might be a transformational snooze. There you go. I just made something up. So I'll put those notes into my notes in my password manager and save them.

So if I ever have to do some sort of a recovery with those guys, it's going to be simple. Because I just look in my password manager, I got to go in there anyways to get my password right. And my email address or username to login. And there it is, there's my security questions. And then the password manager, cause I'm using one password.

It has a little database, it keeps and everything in there is encrypted. And the only way to decrypted is with my password, my one password, that's it. You only have to remember one password and that's the password to one password so that you can decrypt that little vault of a database of all of your information.

So I have, I bought a, I think it's a 30 plus character password I use for one password because yeah, I'm a little bit paranoid about all that sort of stuff. So that's a really good way to be able to keep your information safe. I talked last week about a friend of mine. Whose wife went on Facebook to get some help, some tips on selling her investments investment anyways, and the disaster.

That was okay. So a lot of people have regrets about what they've posted on Facebook, and there's a really cool thing out of CMU. Carnegie Mellon university, where these, how many, it's six guys and gals. They put together this special report. I regretted the minute I pressed share a qualitative study of regrets on Facebook.

Very interesting. So they looked at all of this stuff as best they possibly could. And what did they find? Some examples, just think for yourself what regrets you might have. I know friends of mine in the grads that they have had. But there are a lot, so they go through privacy risk. I can send you a copy of this article if you're interested.

It talks about their methodology. They analyze comments on the New York times website and others Craig's list to regroup people. They, so they've got all of the stuff. Here you go sensitive content. Number one. So alcohol and illegal drug use. Think about that. Think about your employer, your next employer or the police.

They got a report on you. Oh my, this is a bad person. So they go onto your Facebook page and they find. Oh, photos posted from a party with some very non unflattering photos in it. And even maybe mentioning a illegal drug use, what it thinks is going to happen. How about if you get stopped at the border coming back from Canada, Mexico, Europe.

And they decide to do a little deeper look into you and they find this stuff online. The next one sexual content, you can imagine what that is. Think of a Congressman from New York, in fact, religion and politics apparently is one of the things people have regretted posting online, profanity and obscenities, personal and family issues.

Working company here, negative or offensive comments it's arguments, lies and secrets, venting frustration, good intentions intended purposes. I didn't think about it. Hot. State. Yeah. Oh, my this thing just goes on and on, but keep all of this in mind, when you are trying to keep your information private, whether you are a business or an individual, you have to have eternal vigilant watch when your emotions are high, right.

It's like drunk dialing. Don't do it. Or your emotions are high. Something's been going on. Don't put it online. So that's I think a real good bottom line about your. Personal privacy, risk tolerance profile. Okay. Be very careful. , don't put stuff that you don't want other people to see. It's not true that once it's out on the internet, it's there forever.

It's not true that once you've posted it, it's there for anyone to discover. None of that's true. Not at all. Okay. But be very careful cover up your laptop cameras. In fact, in the improving windows security course, I go into this in quite a bit of detail, what you can do, what kind of cameras you can and should use, what sort of microphones you can or should use.

Many people just cover up the laptop cameras with the sticky note. When they're not using it disable automatic image loading in your mail program. That's important. I do that as well, because that image that's in the email is usually being used to track you. It's really that simple. You've got new privacy laws in many States and in Europe, they are really not going to work or help you with your privacy, except with the really big companies out there.

So keep all of that in mind. All right, everybody. I want to encourage you go to Craig peterson.com. You'll see all kinds of great information there. You're going to be able to also listen to my whole show, pick up all the little training tips and even find out about the courses that I'm offering. Craig peterson.com

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

I was on WGAN this morning with Matt Gagnon. He jumped right in with a question about the problems with the internet and why are there so many outages. Will they continue? What can be done? Then we talked about the Facebook hack and release of the personal information of 533 Million users and we wrapped up with a discussion about how long it will be until we have fully autonomous vehicles. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: Good morning, everybody. I was on with Mr. Matt Gagnon this morning and he is in Maine, as you probably know. I'm carried there through there are stations in Maine and parts of eastern New Hampshire and Southern Maine. Because of an outage, they had on the internet that hit parts of New Hampshire, as well as Maine he asked me about the internet backbone and much of it was kind of surprising to him. Frankly, I don't think it's really good news.

[00:00:31]We also talked a bit about what's happening with autonomous vehicles. Why aren't they just everywhere already? When are we going to consider them safe? So here we go with Mr. Matt.

[00:00:44] Matt Gagnon: So Craig, let's get to your topics and what we need to talk about with you here this morning, sir. Okay. So we had a huge power outage recently. We had a huge internet outage recently. Are we worried about this? Like in the future is this a sign of things to come? What caused it? I mean, what's going on here?

[00:01:00] Craig Peterson: Yeah. There's well, there's a couple of different reports. One talks about breaks in two different fibers. There's a power problem. Here's, what's really going on behind the scenes. The major internet providers have multiple connections to the internet. Let's explain what the internet is to help really understand it.

[00:01:19] The internet is an interconnected network of networks. There is no internet. It doesn't exist as you don't pay your bill to the internet.

[00:01:32] Matt Gagnon: A United States Senator once called it a series of tubes as you recall. Right.

[00:01:40]Craig Peterson: What happens is all of these different providers that we get it from, like spectrum, for instance, that had the outage. They all get internet connections to other providers. The idea is that the internet can have thousands of networks that are almost, you might call them backbones, but none of them really are right now.

[00:02:02] Most of the data on the internet is actually being routed through Amazon who is running these big data centers. Spectrum will have a connection to a network provider over here and another provider over there. There are some major central hubs, if you will, of this internet connectivity. If you lose one piece of fiber and you are connected to the internet at different points using the other pieces of fiber, you're still okay.

[00:02:33]If you only have two fiber connections to the internet itself, then you lose both of them. You are off the air. Whether it's because of a break or because of a power failure, it doesn't really matter. If you're going to be really reliable as an internet provider, you have to remember that upstream from you they could go down.

[00:02:54] To now the big problem we're seeing now, nowadays. The internet was designed to withstand a nuclear explosion anywhere in the United States. We could lose the entire city of New York and the internet would still run. That's because again, all of these small networks together.

[00:03:13] However, as time has gone on, we've seen happen to the internet that's happened in many other industries, there's been consolidation.

[00:03:20] I mentioned Amazon handles much of the traffic for the internet, and frankly, Netflix is about half of the internet traffic on any given day. We now have, instead of thousands of these networks connected together, in reality, just a handful.

[00:03:37] There's only really about a dozen that you might call backbones that almost everybody connects to. If you lose one of those, we're in big trouble. So, to answer your question, yes, this is something we can continue to expect more and more of.

[00:03:53]One of the more troubling things is just within the last year a minor player in the internet backbone business. A small business bought one of the biggest companies out there and they just haven't been taking care of the internet. They were trying to keep the price low. They have people working for them. Some of them are brilliant. We've got a lot of them. This is brand new to them. They have brought the internet down a number of times over the last even six months. This is growing pains. I think it's going to get a little bit worse and I'm not sure it's going to get that much better.

[00:04:31] Matt Gagnon: Well, that's a happy thought. Thanks a lot, Craig. Appreciate it.

[00:04:33] Craig Peterson, our tech guru. You hear him not only here at this time, every Wednesday, but also on the same radio station you're listening to right now on Saturdays at one o'clock WGAN of course. Check out that for some more in-depth analysis and talk over many of these same topics.

[00:04:47] Craig also, the Facebook hack. I have to ask you about here a little bit as well. Apparently, everybody now knows Mark Zuckerberg's phone number because of this. So tell me what happened and what's the fallout from it?

[00:04:58] Craig Peterson: Yeah, it's about 533 million Facebook users. Their data was stolen and it has been sold and reused.

[00:05:08] Now this type of data is data that is used for phishing, which is trying to fool us. They got all kinds of information about all these half a billion Facebook users. They had Zuck's name, his location, his marriage information, date of birth, Facebook user ID, his phone number.

[00:05:28] But they had it on half, a billion, other people as well.

[00:05:32] Absolutely crazy, what happened?

[00:05:35]The hackers have been selling this information to other bad guys if you will for about two years. They no longer have any, any buyers for this data, you know, half a billion people's personal information. So they posted it openly on the internet for anyone to download, not just their network of friends that have been paying them.

[00:06:00]You've just got to love the response that came from our friends over at Facebook when they were asked about it. This was the Daily Mail that asked by the way. The Facebook spokesman said, this is old data that was previously reported on in 2019. Okay, but don't you care that you've got half a billion people's personal information.

[00:06:23] It's been resold, sold for quite a while, and just on Saturday, it was posted for free for anyone on the internet.

[00:06:33] So, it's okay. Obviously, the same old stuff, right? Make sure you change your password. Use two-factor authentication, get one password as a password manager, but what's really upsetting to me is the nonchalant attitude.

[00:06:49] All of these things, businesses have, including the Equifax's of the world. Remember they didn't just steal your basic in personal information, Equifax, they stole everything. They show your income, your job history, they stole your social security number. According to reports out there, it was all of this information and more. No one is going to prison over this. There have been no charges, one or two people lost their jobs. That's the extent of it.

[00:07:19] We have to get these large companies to really honor our data, keep it private and respond in a reasonable way. Not, Oh, it's yesterday's news.

[00:07:35] Craig Peterson joins us at this time every Wednesday to go over what's happening in the world of technology really quickly.

[00:07:40] Matt Gagnon: Craig, we only have a couple of minutes left maybe, but I wanted to ask you about self-driving cars. Does the question continue to remain about these things if they're ever going to be safe? I continue to believe that someday none of us are driving anything any more. Am I right?

[00:07:52] Craig Peterson: Yeah, you are absolutely correct. The Jetson's world might come our way.

[00:07:56] There are now autonomous cabs, basically, uber's in some cases that will fly. So yeah, it'll eventually be there. The problem we're seeing is how do we evaluate them as you mentioned, are they safe? Well, how do you define safe? One of these autonomous cars is going to react differently in a situation, than a human driver.

[00:08:19]That's the problem we've had. Most of the accidents that have happened with the autonomous vehicles that are already on the road have been rear renders. Not them rear-ending somebody, but somebody rear-ending them. We have as drivers, certain expectations as to how another driver's going to behave on the road and these cars do not behave the same way.

[00:08:42] So its going to be a little while. If they were all autonomous now, that probably would go away. This is going, this problem, for a good 20 plus years, I think.

[00:08:51] Matt Gagnon: All right. Well, Craig Peterson, our tech guru. You can hear him here, not only every Wednesday but on Saturdays at one o'clock.

[00:08:56] Thanks a lot, Craig. Appreciate it as always. . We'll talk to you again next week.

[00:08:59] Take care, Matt. Bye-bye.

[00:09:00] Hey, one last reminder. I have discount coupons for people who are signing up for my Improving Windows Privacy and Security course.

[00:09:10]If you haven't signed up yet, you don't have much time because this is closing on Friday night at midnight.

[00:09:17] It is a phenomenal course. It is designed for basic users all the way through intermediate. Of course, as usual, I've got the whole guarantee thing going on. I think you're really going to like it.

[00:09:29]We're probably gonna do a couple of phone calls as well. Maybe a little webinar you can call in if you'd rather, but all of that is on my email. You know, if you don't sign up right now, you're not going to find out about it.

[00:09:41]When it goes onto my site, it is going to be full price. It's only now that you can get the coupon. So you might want to email me M E@craigpeterson.com. If you haven't signed up already, or if you want more details.

[00:09:54] I am more than glad to send them to just open your email and send it to me. M E@craigpeterson.com. I'd be glad to send you all the details you'd like.

[00:10:04]Of course this weekend I will be back as well.

[00:10:07] Take care everybody.

[00:10:10] Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. Jim had been discussing doing his Show prep and how frustrated he was that he could not find more attributions for a story he wanted to discuss. I hopped on the phone and explained to him what was happening. Then when I joined him we continued the conversation about how Google is controlling your searches and what you can do about it. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hello everybody. Boy, did I have an object lesson for Mr. Jim Polito this morning! It was actually a whole lot of fun. We talked about Yemeni terrorists. That doesn't sound like much fun, they have snuck across the border. Terrorists on the terror watch list. At least we apprehended these guys.

Do a Google search and you're getting crickets. So, I explained why. I explained how they are obviously suppressing it. The right search engines to use out there. We spent the whole time talking about just that. So here we go with Mr. Polito

Jim Polito: [00:00:38] Tomorrow is national beer day, in the United States, it's not a Canadian holiday. See, it goes back to April 7th, 1933, where President Roosevelt, in turning over prohibition, said people could make and brew their own beer as long as it wasn't more than 4% alcohol.

How about some of those microbrews out there, Danny, like 10.2%? There's one from the Trappist 10.2%.

Danny : [00:01:10] I think it was high as 15 now, yeah.

Jim Polito: [00:01:12] It's crazy. Anyway, speaking of beer, which is the national beverage of Canada, we are joined now by our good friend, tech Talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:26] Hey, good morning. Canada had prohibition too.

Jim Polito: [00:01:30] Oh, they did? I didn't know that.

Craig Peterson: [00:01:32] Yeah. A few times that you had these municipal bands in the late 19th century provincial bands in the early 20th and national from 1918 to 1920.

Jim Polito: [00:01:44] Wow. I learned something. Listen,

Craig Peterson: [00:01:47] I love those Trappist beers, by the way.

Jim Polito: [00:01:50] Those Trappist beers are great. The problem is they're made under strict rules and there have to be Trappist monks working in the process and there aren't enough Trappist monks to produce the beer for the demand. It's a great beer. I just want you to know that every July 1st I do have a Molson on Canada day.

Craig Peterson: [00:02:10] All right. Labatts is acceptable.

Jim Polito: [00:02:14] Yeah, Labatts. I used to like Moosehead was a good beer too. Moose. Head was a good beer.

Craig Peterson: [00:02:20] Yeah.

Jim Polito: [00:02:20] All right. Let's get to this. We're joined now by Craig Peterson and all kidding aside. Craig Peterson, our tech talk guru helped us earlier in the show. We're going to talk about Facebook and the hacking of personal data.

But let's get to something that just came up. I'm talking on the show about two Yemenis who are on the terror watch list. It's not getting a lot of attention. They walked across the border, they entered the country illegally and they're on a terror watch list. One of them had a SIM card hidden in his shoe. Some AP reported on it, but you try to find this story through Google and actually social media. It's not there. Craig, could you please explain to me why it's not there?

Craig Peterson: [00:03:08] It's very simple. If you do a Google search and there's no real results, it's obviously fake news.

Jim Polito: [00:03:19] Folks are mice. Danny's having trouble getting the actual document. That was the release. The folks from the border patrol said Monday, two men who were on the US government watch list for terrorism and also on the no-fly list. They walked across the border. They're Yemeni men and we all know what's going on in Yemen right now.

Craig Peterson: [00:03:42] Yeah, it's a real problem. And again, all kidding aside on my part. There is a huge problem that almost no one is aware of in this country. That is, we are now living under an oligarchy. We don't really have any form of democracy anymore. This isn't a Republic. This is an oligarchy that is funded by the tech giants.

You might call them tyrants, frankly. We complain about Russian oligarchs, yet we are allowing companies like Google to not only have all kinds of lobbyists in Washington, DC, making sure that their favorite politicians become millionaires, but they are covering for them.

If you do Google search this morning on these Yemeni men to try and find out more, almost nothing comes back. There are some good search engines and I talk about these all of the time, but the one that I think right now is one of the best and it's the one that I use for everything except for technical searches. If I'm doing a search on how to do this in programming or whatever I might use Google for that.

If there might be any sort of a slight political bent to it, I use duckduckgo. As you saw this morning, There's a huge difference in the result.

Jim Polito: [00:05:06] Yes, Danny, you've encouraged me to use duckduckgo and, just like my doctors encouraged me to lose weight and you're both good experts and have my best interests in mind, it doesn't become a priority. I'm telling you, after this morning, I won't be losing any weight, but I will be using duck go from now on, in a lot of my show prep because I really think it was an accident that I found this story. I do intense show prep I'm everywhere. I found this story and again, I don't know, maybe Fox is running with it today. Maybe it'll get a little traction. I don't know.

But that these two guys crossed the border. This is exactly what we were talking about.

Craig Peterson: [00:05:48] The influence that Google is having on elections is astounding. There was, I should pull up this article here, but I'm not going to Google it. I'm going to duck go it. Who looked at voting in Orange County, California. Now Orange County has always been known as a conservative bastion. The only one other than Northern California in the state of California.

So he had a close look at what was going on and the way he looked at it is he spent some time on searches as though they're coming from Orange County. So, he is using the VPN to do that stuff. He was searching on Google and he found a huge manipulation going on. I think is the word he used were 90 to 95% of all the results favored the Democrat. No matter what you were searching for when it came to the issues in the election. It was absolutely amazing.

We've also seen Project Veritas, which of course everybody's heard of before. They had an expose, just this is October last year. I think it was. They exposed Google's election influence where senior Google executives named Ashwin Agrawal said there are many ways to influence elections, I think ads are one way another is through search results.

YouTube is going to be another one. He said this is a quote from him via ProjectVeritas. The truth is the deep platform is influencing you in a way you didn't sign up for. Okay.

Jim Polito: [00:07:24] Wow.

Craig Peterson: [00:07:24] It's absolutely insane that we're allowing these oligarchs to run our lives. You were talking earlier today about what's happening with baseball and the major league and where were we going to play. Georgia's evil. We're seeing people now reading a headline and the headline can be absolutely false.

Joe Biden's actually getting Pinocchio's, now. Washington Post.

Jim Polito: [00:07:51] Oh, yeah. He said you weren't going to be able to vote after five o'clock. Lie. You couldn't get water in the line. Lie. You just can't get water in line from a political party candidate or a movement. Okay. You can get water in line from anybody else. Okay. There wasn't going to be voting on Saturdays. Lie. Two Saturdays are mandated. Lie.

It just everybody's not a big deal.

Craig Peterson: [00:08:16] They retweet it. They talk about it. They saw the headline, what Joe Biden said. We know that a falsehood repeated enough times, all of a sudden becomes the truth.

Jim Polito: [00:08:25] It came from the Nazis. It literally, came from the Nazis. It was Goebbels and Hitler. Repeat the lie enough and it becomes the truth.

Craig Peterson: [00:08:36] The bigger, the lie, I don't even want to get into it right now.

Jim Polito: [00:08:40] Cause you never want to drag the Nazi card in. This is appropriate. That's the Nazi card that isn't it.

Craig Peterson: [00:08:47] You mentioned Hitler and you lose.

Jim Polito: [00:08:49] I try not to, other than the Seinfeld episode with the Soup Nazi, I try not to, I try not to do that.

Craig Peterson: [00:08:57] We're we are being governed by Oligarchs, because we're using Facebook, we're using Google. We're using some of these platforms that we're getting our news from, quote-unquote, that we're getting our information about the election, about what's happening with our government. In fact, we're being manipulated in a very big way.

Yeah, I'm glad. I'm with duck duck go, that's it.

You know what, we can get to the Facebook stuff some other time. I know your recommendation is going to be to people. Hey, by the way, you should be changing your password for Facebook and making it a difficult one and using one of those great password management systems.

You know what really upsets me about that just real quick. They expose over half a billion people's personal information, including phone numbers, everything. Here's Facebook's response to it when they were asked, you gave away names, phone numbers, email, home addresses. What's going on here, it was all stolen from you? The response. Yeah, that's old news that happened in 2019. You kidding me?

That's where the fraud comes from. That's where our information is sitting out there. We've got the phishers out there who are trying to get at the information. We're not keeping our privacy straight, which is why I've got this course started this week on improving your windows, privacy, and security. We have to take control of this.

How many people do you know Jim? How many people, the Equifax hack, right? Hundreds of millions of people whose information was exposed. We've got this huge Facebook hack. How many people are serving federal prison sentences of 10 years or more?

Jim Polito: [00:10:37] I'm just checking here.

Nobody.

Craig Peterson: [00:10:43] Exactly. You cannot get a new social security number. They won't give you one. You're not going to move. You bought this house. You're going to be there for a decade and more, your address isn't going to change.

We are in so much trouble and the government doesn't care. They're not doing enforcement on this stuff. People are not going to prison.

Companies are looking at it as a risk analysis. We've talked about this before. It's just crazy. What's going on and Facebook's response should be enough for everybody to just cancel their account.

Yeah. That's Mark Zuckerberg.

Craig, this is great. Tell us quickly about how folks can be part of and participate in this great program that you're doing. All right.

Just go to Craig peterson.com/subscribe. You'll get my weekly newsletter. You'll get all the show notes that I sent Jim, that we didn't talk much about them today.

My whole radio show, which of course airs here as well on Saturday and Sunday. Make sure you're listening to that weekend. I'll let you know about this course on improving your windows privacy and security it's for home users. It's for beginners up to intermediate. I'm trying to help out the people that really aren't techies

Jim Polito: [00:11:52] Sounds great. Craig, no, listen. This is while you're invaluable because you can come together with us and show us. Today was a perfect example of that and that's why we really appreciate your time.

So, sir, you have a great day and we'll talk to you soon.

Craig Peterson: [00:12:07] You too, Jim. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. We discussed first the big data dump of 533 Million Facebook user accounts available now for free online. Then he hit out of the park with this new news from the DHS who are now going to contract BIG TECH data and private contractors to compile lists of dissidents and create watch lists -- OMG what could possibly go wrong with this? It is outright dumb! Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Well, there's another animated Monday morning with Christopher Ryan. We had a chat let's say, you can tone it down a little bit here, about two different things. One, the hackers that leaked the 533 million Facebook users online just posted it up there. We talk about why? What happened? Why aren't they selling it? We talked about, as well as I think Chris understood what I meant when I sent him this article. He hit it out of the park Homeland security. They're going to be using private contractors, big tech, it appears here to help them track down citizens that they feel might be dangerous. What are the repercussions of that?

We're getting into it all here with Mr. Chris Ryan.

Chris Ryan: [00:00:54] It's right now Craig Peterson. He is the host of Tech Talk, which comes up at 11:30 AM on Saturday. So, I am the opening act for Craig Peterson.

Craig Peterson: [00:01:05] Wow. I've got to follow you.

Chris Ryan: [00:01:08] Yeah. Me and Gucci. Yeah. Good luck, pal.

So let's start with this, Mark Zuckerberg's cell phone number was among leaked personal data for 533 million Facebook users. Hackers were able to get into Facebook and get a hold of Zuckerberg's cell phone, along with personal data from 553 million users. Quite a story there.

Craig Peterson: [00:01:35] You heard about that? Yeah. Did you see the response from this Facebook spokesman? He said this is old data, we fixed it in 2019, in August 2019?

Yeah. I think is a very, very big deal. It has been sold and resold amongst cybercriminals for quite a while. It's a lot of data. Saturday's leak that happened makes it all essentially free now. That's probably because the hackers just can't sell it anymore. Anybody that wanted your personal information already has it. Right.?

Chris Ryan: [00:02:13] It also shows the lack of transparency from Facebook. Right? I mean, that answer is wanting to make it seem like, Oh yeah, everything's fixed now. That was two years ago. But they In my view and to my knowledge did not release that they had been hacked in this substantive way in 2019. If memory serves and now it's like, Oh yeah, this has happened a long time ago. Now that the information has been released because of the lack of ability to sell it. Only now, are they making a public correct?

Craig Peterson: [00:02:42] Yeah. That's exactly right. This is information from people, Facebook users in 106 countries. It includes their phone numbers, Facebook IDs, full names, locations, that's addresses, by the way, birthdate, and email addresses.

What this data's been used for, are these phishing scams that we've talked about so many times where people are getting an email, it looks legitimate and it sounds legitimate and it might even be happy birthday from Facebook. In reality, it's a Nigerian Prince that's behind that kid.

Chris Ryan: [00:03:17] What do you do if you feel like you've been hacked? You're getting these types of emails. We all get phone calls or text messages, at times, from scammers. What do you do in those circumstances where you feel like you are in jeopardy, but you don't feel like there's a recourse. You call the FBI and you'll be like on hold for eight years and then no one ever gets anything. Local police don't have jurisdiction. Is there any recourse for a person that feels that they're vulnerable and that they've been hacked and that they're getting these types of scams set in their direction?

Craig Peterson: [00:03:51] Well, this is just you and me talking here, Chris. The reality is there's not much you can do. There are apps that you can put on your phone to help stop those calls. Things like, Hiya, H I Y A that's what I use. That has a scammer database. You can go to the internet. Crime complaint center online. This is the FBI's center, and you'll see that at ic3.gov. IC3.gov, again. All you have to do is go there. You can report an internet crime, but the reality is there's not much it's going to happen. It's very, very upsetting to me. Sometimes I felt like screaming about this and we'd talk about it frequently on my weekend show, but the problem is you have lost your personal private information.

Most of us, don't move every few months. So, that address that they have of our home, that we may have lived in for years, that's not going to change. Our name's not going to change most likely.

The social security administration will not give us a new social security number, even when it's been stolen. By the way, probably all of ours have been stolen. Right?

So, all you can do is grin and bear, keep an eye out, watch out for your privacy. In fact, this week, I'm starting a course on privacy for windows users, what to do to lock down your windows machine.

All you can really do go to I c 3 dot gov report it.

If you have had money stolen, it'll tell you about this on this FBI site, but you're going to have to file a police report depending on what has happened.

Overall, almost all of our information is out there and you know what, maybe it's okay because all of those people from Equifax, they're all in prison now, aren't they for like 20 or 30 years?

Oh, well, nothing happened to them. There were no teeth behind these laws. Our lives are getting just upturned, and then not to add one more thing to this. Chris, we are now looking at some of the use of other ways of authentication. Right? They're talking about having these passes for the Coronavirus vaccine. They're looking to use things like our eye scans, retinal scans, face scans, fingerprint scans.

Look at the people at the airports. You might remember that from a year plus ago would go through them, the super-fast lane. Right. Just go up and it would scan their eyes. Well, you think it's hard to change your social security number? How hard is it to get new eyes? Right?

We're now in Tom cruise territory here where you can't change your eyes. You can't change your fingerprints. You can't change your face. And yet we're going to use those as identifiers. We should have learned just by having our social security numbers, et cetera, stolen and no real consequences, not just for the people that stole it, but from the people that weren't protecting it.

Chris Ryan: [00:06:52] Right. I want to get to a huge story that NBC News is reporting on, but we have not really seen a rise to the forefront of the public consciousness. That is the US Department of Homeland Security. Is getting set to hire public companies and individual contractors outside of government to get data and information on individuals to compile new terrorist watch lists. DHS is going to pay big tech, Google, Facebook, YouTube, Instagram, Snapchat, Twitter, the contracts to hire and organize internal monitoring teams to assist the government by sending information on citizens, they deemed to be Quote dangerous.

NBC says that the developments are taking place. The US intelligence apparatus is preparing to go live with the assembly of lists of Americans who could be potential threats to the government and need to be watched. Again, the question here is in regards to where the line is drawn. Are you a dissident, if you use language that is in opposition to the government? The current administration? The past administration? In regards to the president, if you don't like the way the government operates or if you are vociferous in regards to that? Where does the line get drawn? To me, this is a significant piece that the US Department of Homeland Security is engaged in.

Craig Peterson: [00:08:14] You hit it out of the park, absolutely. As you're out of the park. The red Sox couldn't hit it out. You just did.

The problem here is where is that line? You know what that line of, Oh my gosh, you're obviously a dissident cause you're planning on bombing the world trade center using an airplane. Okay, that's an obvious line, but as it continues to slide, that's a matter of interpretation.

So if you have somebody making the decision about something that someone else said, and deciding, well I'm, I'm the decider and I think this is hurtful. This person might be a terrorist. This doesn't work.

Look at what we've already had for proof. Some of these horrific things where there have been shootings at school, et cetera, where that shooter, that murderer had been on the police radar. It had been reported. They were threatening to kill people and nothing happened.

So now we're going to take an action here that we've never before really done much with and we're going to apply it to the entire nation. We're going to use algorithms that are going to look at what people are saying and classify them as to the degree of risk and then what are we going to do with those people? Are people gonna end up like the Uighurs in China and end up in camps?

This is absolutely huge.

Chris Ryan: [00:09:41] We got to run, but, I look at this from my perspective as an individual that is often critical of the government. I also am an individual that will use social media and Google in order to do research. So, if there's a pipe bomb that is laid outside of the RNC or the DNC after the insurrection of the US capital during, or actually before, I'm going to research that well. What is a pipe bomb? How does it go about being assembled? What's its lethality? So, now I am a potential dissident who is doing research online about pipe bombs. See what I'm saying, see where this is going.

I am Chris Ryan. This is New Hampshire today. Craig Peterson is with us. Thank you so much.

Craig Peterson: [00:10:16] There's a hard cut. Hey, you should check your email box. If you haven't already. If you are interested in Improving Your Windows, privacy, and security, I have a course we've been working on it for months. We've gone through multiple iterations. We wanted to make this the best course you have ever had. If you're on my email list, you already know. If you were on it before this whole thing started that I am, in fact, giving you guys a great, great, great, great, great deal. So, check your email box. If you haven't already.

Let me know, respond to me, this isn't a click-through autoresponder type thing. This is Karen and I that write these. I want to make these things personal, and I have a communication with you guys, right?

I'm tired of all of this tech stuff and trying to twist people's arms and fool them into buying things. So, that will not happen. It does not happen with me. In fact, we were already working on what are we going to do next? We've got some great ideas in place, but right now it's Improving Windows Security. Of course, privacy is the emphasis here in this first set. It is five modules we're releasing over the course of about a month and you can get all of that. I'm even going to throw in, and I haven't told anybody yet, but I'm going to have a couple of live Q&Acalls too, for people if you are a member of this course. If you've bought it you can be on those calls and I'll answer your personal computer questions that is live and on a webinar, you can call in on your phone too. If you're not into the whole, how do I use my camera? I don't even want to use my camera. Isn't this a privacy course? Why are you making me use my camera? You can just go on your phone as well.

All right. Everybody keep an eye out for that. If you are not on my email list, if you don't know about this, you can just go to Craig peterson.com/subscribe.

You'll get on my list and you'll get some follow-up emails. But this is going to be a busy week for me and I am going to be out for almost two weeks coming up the week after. So busy, busy, busy times.

All right, everybody, take care and we'll talk again soon.

View Details

Welcome! We have had a very busy week this week so this is a reply of the show aired the end of February. I'll be back next week.

It was also another busy week on the technology front and we are going to delve into what actually caused the energy problems in Texas. There is a new type of malware that is affecting Macs and it is has a different MO. Then we are going to discuss Apple and their ventures into automated electric cars and what we can expect. Why are states having issues making appointments for vaccines? In a word, it is bureaucratic incompetence. Then we have a new type of hack out there. It is called Buy-to-Infect and there is more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

This Basic Math Shows How Wind Energy Failures Contributed To Texas’s Deadly Power Loss

An Insider Explains Why Texans Lost Their Power

New malware found on 30,000 Macs has security pros stumped

Report: Nissan shot down Apple deal to avoid becoming Foxconn of cars

N.Y.’s Vaccine Websites Weren’t Working

Apple is already working on developing 6G wireless technology

Owner of an app that hijacked millions of devices with one update exposes the buy-to-infect scam

Mount Sinai study finds Apple Watch can predict COVID-19 diagnosis up to a week before testing

Malware Exploits Security Teams' Greatest Weakness: Poor Relationships With Employees

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] You probably know I've been doing cybersecurity now for 30 years in the online world. Yeah, that long. I'm afraid I have some confessions to make about our relationships here, cybersecurity people, and employees.

Hi everybody. Craig Peterson here. I'm so glad to be here. I'm happy you're here as well. There are so many ways to listen.

I got pulled into this whole business of cybersecurity quite literally, kicking and screaming. I had been already involved in the development of the internet and internet protocols for a decade before. In fact, one of the contracts that I had was with a major manufacturer of computer systems.

What I did there was design for Unix systems a way to check for malware, a way to manage them remotely. Yes indeed, I made one of the first RMM systems, as we call them nowadays. We also tied that RMM system, of course, into Windows and a few other operating systems. Unix was where I was working at the time.

I am what they called an OG in the industry. My gosh, my first job with computer networks was back in 75. Believe it or not a long time ago. Back then, of course, it was mainframe to mainframe basically and some of the basic protocols, the RJE, and stuff. I know I've got a lot of older people who are listening who are saying, yeah, I remember that. It brings back memories.

In fact, I got a note just this week from a listener who was saying his first computer was a Sinclair. Do you remember those things? Oh my gosh. It brought back so many memories for us older guys. But it was just such a cool little device with the keys and much different than I'd ever seen before. The XZ81. I just looked it up online so I can remember what the model number was. That was made by Timex. If you can believe that too. It's just. Wow. It had a Z 80 CPU, which of course was like an 8080, which was Intel's, big chip at the time, running at 3.25 megahertz. Yes, indeed. Very cool. I love that computer anyways. I digress.

The whole industry at the time was non-existent, yeah. You had antivirus software. We started seeing that in the eighties and we had some terrible operating systems that many people were running like Windows, just absolutely horrific.

Remember windows three-point 11 and XP and the millennial edition just some of the most terrible software ever. That's what happens when you have interns? A lot of the code, it came out in one of the lawsuits, for one of these versions of Windows.

It was a different world and I had to figure out what was going on because I had some servers that were Unix servers. This was the early nineties and I was hosting email for companies and websites and doing some filtering and things with some kind of precursor to SpamAssassin. It was really something. I had some DECservers, Digital Equipment Corporation. Remember those guys and all of a sudden customers started calling me because the email wasn't working. It turned out it was working, but it was extremely slow and I had to figure out why.

I telneted to my server. I got on, started poking around the servers.

I had a computer room and the first floor of the building that I owned and I was up on the second floor. Off we go looking around trying to figure out what is going on. It was me actually. I said us, but it was really me. Cause I knew the most about this stuff.

There were these processes that just continued to fork and I was trying to figure out why is it creating all these new processes. What's going on? What has happened here? Back then, The internet was a much different place. We trusted everybody. We had fun online. We would spam people who broke our almost unwritten rules of the internet about being kind to other people. What spam was, where the whole term comes from is you would send the script from Monty Python spam and eggs, spam and ham spam, spam, spam routine.

You just send it to somebody that was breaking these unwritten rules, like trying to sell something on the internet. Absolutely verboten. What a change to today.

I saw some of this stuff going on. I was trying to figure out what it was, but, we trusted everybody. So my mail server was Sendmail, at the time. We still maintain some instances of Sendmail for customers that need that.

Nowadays. It's usually more something like postfix in the backend. You might have Zimbra or something out front, but postfix in the backend. We allowed anybody on the internet to get on to our mail server and fix some configuration problems. They didn't have full access to everything. Firewalls weren't then what they are today.

In fact, one of our engineers just had to run out to a client who did something we told them not to do. They were using the Sonic wall firewall on their network as well as they had our stuff. So we had a really good Cisco firepower firewall sitting there, and then they have this SonicWall so that they're people, remotely could connect to the Sonic wall firewall, because it's good enough. SonicWall says it's compliant. The SonicWall firewall was being used to scan the network and load stuff. Does that sound familiar? Much to our chagrin.

So he had to run out and take care of that today. It sounds like we might have to do a rip and replace over there restore from backups. You have no idea what these bad guys might've done. We've seen Chinese into these networks before, Chinese malware. It's been really bad.

Boy, am I wandering all over the place?

Back to this, we would allow people to get onto our network to fix things. If something was wrong, if we were misconfigured, they could help us and they could get on and do it because Sendmail configuration was not for the faint-hearted.

In the days before Google, right? Eventually, we had Archie and Veronica, and Jughead. They did basic searches across FTP servers. That's my kicking and screaming story. I was trying to run a business where we hosted email for businesses, which we still do to this day, and where we had some, back then we didn't have websites. The web didn't come in into play until a couple of years later, but we did host FTP sites for businesses so that they could share files back and forth.

That's what I wanted to do. That was my business.

Later on, I ended up helping 80% of my clients find the other web hosts after, these $8 Gator hosting things. We just got a call on that this week. Somebody who'd been a client of ours 20 years ago, went with a guy that charges $5 a month for web hosting. They have personally identifiable information on that site if you can believe it. He was complaining because it wasn't working he was getting a C-panel error anytime he went to the site. We said, Hey, listen, this problem is the guy that you're hosting from. We did a little research and we checked the IP address and how many sites we're at that IP address. This guy that was charging them $5 a month had 150 different websites at that one IP address. Now that's not bad. He was hosting all of these 150 at a site, the charges, the eight to $10 a month for web hosting. He had all of these sites on top of a machine that was already split up hundreds of ways. It's just amazing what people do.

Man alive. We got rid of 80% of those customers, the ones that wanted cheap, that's fine, get cheap, and see what happens to you. Some of them, we still maintain a good relationship with and so we help them out from time to time, right?

What am I going to do? So somebody calls me, I gotta help them. That's precisely what we do now with this malware problem.

What's going on here? We talked already about the Great Suspender and how Google has said, Hey, this now has malware in it, so we're removing it from your web browsers. That to me makes a ton of sense. Why not do that?

This is another example of what happened with SolarWinds. This is an example of a supply chain infection. What happened with that? Somebody bought Great Suspender from the developer and then added in this basically malware to the Great Suspender. Just it's a terrible thing. Very surprising, but one of the biggest exploits that are being used by the bad guys right now is the security team's poor relationship with other employees within the organization.

I promise we'll get to this a little bit more and explain the bottom line here. What's going on and it goes back to this customer that we just had to run out to.

Why did they do what we told them not to do?

Stick around.

We're getting into the battle between cybersecurity senior officers in companies, owners, business owners, and the, even the employees. There has been such a battle going on. I saw two examples this week.

Hi, everybody, it's a difficult world out there, but I find some comfort in listening to, of course, news radio. It keeps me up to date on what's going on. It helps me to really understand the world a lot better.

I mentioned that one of my guys just had to run out to a client who did something we absolutely told them not to do. They had been using this company that was a break-fix shop, I guess is the way you would put it. They had a business that would respond to problems and they charge by the hour. I think right now their hourly rate is like 160 bucks or something. It is not cheap, but anyhow, That they would sell people equipment and then move on, right? Your problems aren't my problems. Just leave me alone, go away. It's a beautiful model because their employees at this break-fix shop don't have to understand much. They just have to know more than you do as a customer.

There's one level of understanding that you have, and for someone to appear to be an expert, all they have to do is have slightly more understanding.

That has bothered me so many times listened to the radio and they talk about somebody that's just this great expert, in reality, of course, they are not. But you don't know. That person talking about the expert doesn't know either because they just don't have enough knowledge. Of course, the person that's labeled the expert isn't going to say anything about it.

They were doing what most companies do, which is okay. We know we need a firewall, so let's get a firewall. They went out and they talked to this company and they did their Google research because of course, Dr. Google is an expert on everything. Even with those differing opinions, you're going to go with the opinion that you like the best. That's what they did.

They bought a Sonic wall firewall from this vendor, which was a break-fix shop. Now that's all well, and good. The sonic wall is not terrible stuff. They've got some amazing stuff as well.

The problem is this device has been out of support for more than two years now. Even though they're not as advanced as some of the systems we can install, not that we always use the most advanced systems. It's not a bad, a little thing for a small business. We warned them that because they were using an out-of-date firewall that they could not get fixes for known vulnerabilities. Now that's a big deal too. Most people are not aware of the vulnerabilities that are on their machines.

Do you go out every month and check the firmware versions on your firewall? You should be, even if you're a home user. Are you checking to make sure the firewall that the cable company provided you with is up to date, configured correctly? You've changed the password and the admin username, right? No?

Most people haven't. He hadn't, right. He didn't know. We told them we did a little research and said here's your problem.

That's part of his cyber health assessment. We told them what kind of firewall do you have? What's the version of software on it and we do that. We have a bunch of people that have asked for cyber health assessments. We've got them on a list because we're busy. So we have to schedule these and make them happen.

So we said, do not plug that machine in. Of course, what do they do? They plugged it back in again. So now all of a sudden this morning, we get a wake-up call from our monitors that are running they're on their Cisco firepower firewall, where we have their extensive suite of additional software. This isn't just an off-shelf, Cisco firewall.

It's telling us that the SonicWall or something through our, via the SonicWall. Is going through all this customer's network. It's actually attacking the Cisco firewall from inside the network. Absolutely amazing.

Why does that happen? In this case, the business owner, and it is a very small business. It has about 5 million in revenue per year, I would guess. It's a small business by every stretch. The owner just doesn't want to spend the money he doesn't absolutely have to spend. He's not looking at this saying I could lose all my intellectual property. I could get sued by these people. I could lose my clients who find out that their data was released. Their orders were released. Everything was stolen.

He looks at it and says, Oh wow. It's 200 bucks a month. Wait a minute guy, you have how many employees? You're worried about 200 bucks a month. I personally, I don't understand that. Why would you do that?

Now, you're in a poor country. Okay. I get it right. That's a lot of money to spend, but not here in the United States. Doesn't make sense.

A lot of this is really the reason I brought it up. It's showing how there is a disconnect between business owners, C-level people, and cybersecurity people. Basically, if you have less than 200 employees, you cannot afford to have your own cybersecurity team. It's impossible. It's way too expensive.

Then the numbers start to change outsourced cybersecurity, which is what we do. We do this for this customer and. The in-house cybersecurity people, but we all have the same basic problem. The owner has a problem too, right? He has to weigh the costs of cybersecurity against the risks involved, which is what Equifax did.

What so many of these big companies do, right? There's this, the norm Equifax said it's going to be way cheaper to just pay out $10 million in fines. When we get fined by the federal government for losing everyone in the country's personal financial information then it is to do this or we're not going to bother.

Man, I'd love to see the smoking gun email on that, where they made that final decision, probably doesn't exist. They're smart enough to know that they would get sued and they have been sued because of this.

We've got another problem right now because of people working from home. I mentioned, in fact, this week, you should have gotten an email from me on Thursday. That was a little audio thing that I put together. We call these things, audiograms, and it's a kind of a video that'll play.

This particular one is about part of this problem. We've talked extensively about that water plant in Florida, that was hacked for lack of a better term. It might've been an insider thing. It might've been someone external, et cetera, et cetera. The reason it happened is that business, the water plant for a town of 15,000 people, which would be in a normal world, a small business. That small government operation was all of a sudden faced with lockdowns. What do we do? They didn't have a plan. They didn't have a business continuity plan, which is so important. I talked about it extensively last week as well. They had no way to manage this. So what did they do? They went out and bought team viewer licenses for everybody in the business. That put, well not the business, in this case, the agency, that put the agency at risk.

That is putting our businesses at risk too, in such a big way. That's what the audiogram I emailed out on Thursday explaining this a bit.

So stick around. We're going to continue this conversation.

Of course, you're listening to Craig Peterson online@craigpeterson.com.

We have people working from home. We didn't really plan for this. We're doing it because of the lockdown. Maybe, you found that it's actually better for your business, from whatever angle. What are the risks here of people taking computers home?

Hello. Everybody Craig, Peterson here. So glad to be with you today. Glad you're taking a few minutes out of your day as well to listen in.

Now I am very concerned about people using computers that they're taking home. I want to make a definition. Maybe there's a better way of saying this, computers that are used at home, home computers should never be used for work.

I'm going to explain why. Computers that are at work probably should not be taken home. We saw the example of this, just this last couple of weeks.

I was talking about this wonderful plugin that I've been using and recommending people use here for a very long time, called the Great Suspender. We've talked at length really about what happened there with the company being bought and then becoming evil, right? Just buying their way into 2 million people's computers.

Sometimes these Chrome extensions that are installed on personal computers get automatically installed and synchronized to your work devices. In fact, that's the default. If you log into Chrome and you're using Google Chrome as your browser and you log into it on your home computer, and when you log into your same account over on your business computer. All of a sudden, now it's syncing. It's syncing things like passwords, which you should not be having Google store for you. You should definitely be using a good password manager and there are a few out there.

If you're not familiar with them or don't know which one to use or how to use them. I have a great little special report on passwords and using password managers. I'd be glad to send it to you. Just email me@craigpeterson.com and I'll send that on-off, right? I'm not making a dime off of that. I want to make you safer.

I don't want to have happened to you what's happened to millions of Americans, including my best buddy who had his information stolen. I've been after him to use password managers. He never did it. I don't know why.

Until his paycheck got stolen. Then he came over and I explained it and set it up with them and really helped him out.

Maybe we should do a whole webinar showing you how to use these password managers, how to get them set up because it is a little bit tricky. It's certainly different than you're used to. Many people are using their browser Chrome in this example, to save passwords. When you go to a website, you'll automatically have the password there. Maybe you've got it set up so that it'll automatically log you in with all kinds of cool stuff. But there is a very big problem and that is that there is a huge risk with running these extensions, like the Great Suspender. The Great Suspender was approved by Google. It was in the Google store. You could download it from their app store. Absolutely free.

In January of this year in 2021, we had someone out on Twitter, tweet that there was a problem with the security on the Great Suspender. It had been changed. It was being used now to send ads out and other things. That's pretty, pretty bad. The extension wasn't banned until about a month later and you as an end-user had no official notification that this extension was potentially malicious.

Apparently, they could, with this malicious software they embedded, not just show you ad, not just insert their own ads to generate revenue onto the webpage as you were visiting, they could also grab files from your machine. That's a very bad thing.

Now, presumably, if you're at work, you have a team that's helping you outright. The IT security team, there may be different teams and maybe the same person who also is the office manager, who knows. It does vary. Businesses cannot know what you're doing when you're starting to install those extensions and they are pushing their way onto your office computer because you're using the same Google account in both places.

Now, despite the risks, of course, I installed this Great Suspender used it for years and I was pretty happy using it. I know many other people who were in the same boat. Security teams have some great tools. I mentioned my son who's one of our team members got called out to a client. During the break, I was just chatting with him briefly. What had happened is they plugged in this firewall we told them not to plugin. It was apparently hacked from the outside. It had known security vulnerabilities. He had not, this small business owner had not yet paid for maintenance on his little firewall, so he was not getting security updates.

In fact, my team member looked at this and found that it had been three years since the firmware on his firewall had been updated. The bad guys got into his network through this secondary firewall, which we told them not to have not to plugin. Our firewall only noticed it because this malware started scanning everything on the network. Of course, it scanned two of our machines, one being the firewall.

Remember this isn't a regular firewall that we put in there. This is a firepower firewall with a whole bunch of extra software on top of it. In our data center, we have some huge machines that are sitting there watching what's going on remotely. On our client's networks via that firepower firewall.

We started getting all these notices as to what was going on, but this is a great example. We're not updating some of that software. He had a security team and he ignored the security team. We were the security team. We're outsourced cybersecurity that's what we do, but that happens many times.

Many business owners and others look at the cybersecurity situation as having many different shades of gray. What should you do? What shouldn't you do? The teams that are working in these businesses, including us. We have to tell them, Hey, don't use that firewall. Do not plug it in. You don't need it. If you plug it in, it's going to make it way easier for some of your people to work from home. This is not set up correctly and you're going to have problems. That's a difficult conversation to have with a business owner. We had it and he ignored it much to his peril.

In this case, this one is hard to tell how much data was stolen from his business. The impact from this could last for months, and there could be investigations who knows what's going to end up happening here. That business owner and I, because I spoke to him as well about this whole situation before this particular event happened just about two weeks ago. In fact, that was a reminder cause they had plugged it in again. Six months before that we had told the business owner, you can't plug this thing in, you cannot be using it.

How do you do that? How do you let an impacted employee, somebody who's working from home, maybe using their own computer to do work for the business? How can you approach them and tell them, Hey, you cannot use Google Chrome? You cannot save your passwords on your browser. You cannot install extensions. Even if you had a list of extensions today that were bad, that list is going to be out of date tomorrow, which is going to be a very big problem.

Individual users do not have the ability to check this. Frankly, most businesses don't either. Again, that's why a business under 200 employees cannot afford to do this yourself. You just can't. This is a specialty.

We were talking yesterday with a prospect who had been brought to us by a break-fix shop and trying to get this concept through. We're going to talk a little bit more about that. What should you be doing? How can you pay attention? How can you even be safe in this day and age?

Hi everybody. Craig Peterson here. We've been talking about supply chain problems. That's a technical term for it, but the software that we rely on becoming evil, and what can we really do about it?

Hello, everybody. You're listening to Craig Peterson.

How do you talk to a business owner and help them understand? That's a problem. Isn't it? Look at what happened a few years back with TJX stores. Them as maybe TJ max, that's one of their stores. They have a number of others.

Their cybersecurity guys did something I have seen done before. That is, they went to the management of this massive public company and said, Hey, TJX, we need to get this hardware. We need to get this staffing. The hardware course pretty expensive and it sits there and it does much the same stuff. Even back then. Nowhere as good as today. It's exponential, as to how much better it gets every year, but it was good hardware. It really could have stopped the hack that happened and it did.

Here's what it did. It noticed the hack was going on. The problem was they were able to say yes to the hardware, the senior management said yes. They got the hardware, but senior management would not get the security technicians that were needed to monitor and run that hardware. They were short-staffed.

That's another problem we're seeing. That's why the companies you're dealing with, whether it's Equifax, with who you do not have a direct business relationship with, and yet have all this information about you and sell that. Or maybe it's just some other website. That's why they lose your data. It's a real bad idea. The bad guys are just waiting out there just siphon all of your data. In many cases, when you're talking about a business and a business website, or even your home computer, they're looking to redirect you to malicious websites.

What they'll do is for instance, again, the Great Suspenders' an example, that they claim it's been fixed now. With something like an extension or a plugin that you put in your browser, they could rather easily code it up so that you are going to a website that's malicious.

It could look like Bank of America's website and you go there and you enter in your information. You put in your username, you put in your password, it asks you a security question. Maybe maybe not, but your username and password. Then it says incorrect. Then your screen refreshes while your screen just refreshed because you were not at the Bank of America, originally. You were at a malicious website and you entered in your username and password. Now the bad guys have your username and password to your banking system, to your login, to your bank accounts. They got that. That's all they needed. They didn't want you to know that this was going on so they just went ahead and redirected you over to the real bank website. Hence, the supposed reload.

It's a very big weakness here in how IT and security teams operate because too few security teams really can relate with the CEO and vice versa. I've seen that all of the time with people working for me in cybersecurity, you've got a really good idea of what needs to be done, how it needs to be done when it needs to be done. To you, it's the most important thing in the world, right? You don't want the business to go under, you're going to lose your job, maybe your pension retirement plan is tied to that business. You don't want it to happen, but have you got the trust built up with the senior management?

Then how about the other side of this relationship? How about if you're a cybersecurity person? Even if, again, you're not a professional, you're just the person tasked with it in the office or you're the person tasked with it at home. How do you go to the other employees and tell them you can't use your Google Chrome account here in the office? How are you going to enforce it? How are you going to tell your husband or wife, Hey, that's dangerous? I don't want you installing any of these extensions on your computer. One of the really bad things that people do with their browsers is they put on these real fancy little extensions that give all kinds of extra wonderful information. It ends up as a toolbar and it lets you do searches on this site or that site. Maybe it keeps you up to date on the stocks that you have in your portfolio. You're telling hackers what stocks you own, really? It might be legitimate, right. But who knows? That's the problem. Something like that can really mess you up and send you to malicious sites. You know that your spouse is using that or your kids are using that. How do you talk to them? How do you solve those problems? It's a real problem.

There are some interesting tools that you can use, as professionals. There's a Slack channel I can send you to, if you're interested, actually, it'll be in the newsletter that comes out on Sunday. At least it should be under one of those articles. It is a problem.

Netflix, by the way, is really trying to help you out too. Not only did the Netflix security team provide some feedback for what's called the honest security guide, but it's also made some of its user tools, the tools that you might use at your home to find a movie, et cetera, it might help really to secure you.

Git Hub has this. It is called, this is a Netflix skunkworks, the stethoscope app. It's a desktop application created by Netflix that checks security-related settings and makes recommendations for improving the configuration of your computer. It doesn't require central device management or reporting. You can have a look at that. If you are interested, let me know. I can probably point you in the right direction to the stethoscope app. That's what we want to see in this honest security guide. You'll find it online. At honest security is a guide to your devices, security, which in the biz we call endpoint security and it is cool. You can run through all of this list is a big checklist and talking about why honest, and they're saying dishonesty stops you from doing the right thing.

That's why in my courses, I spend a lot of time, more time in fact, on the why than the how. I want you to understand honestly, why you should or should not do something.

There are so many people who are out there yelling and screaming, jumping up and down. Particularly your antivirus companies. You fake VPN companies who are trying to get you to buy their products that not only do not need in most cases but will actually make your computer less secure.

So we have to be careful about all of this stuff. We have to make sure we are talking. We've got to have a trust relationship set up with the owners of our business. Cause you guys, some of you, I know own businesses, some of you work for a business. We've got people listening to this all over the world and every continent I've even seen a listener down in Antarctica. I really can say every continent. It's important that we know how to work with our fellow employees, with our management, with our family members, to help them to know what they need to do. There is no time to wait. We have never seen as many attacks as we're seeing now. We've never seen the government using its resources to attack us more than we have now.

We've never seen more billions of dollars stolen per year by the bad guys. There are some basic tenants that you can follow that will make you way more secure. And that's why you're listening. That's why I go through some of these things to help everybody understand.

That's also why I go ahead and make sure that I answer your emails. If you have a question, make sure you go ahead and ask. You can just email me at me@craigpeterson.com. If it's something urgent, I have a form on the bottom of my homepage @craigpeterson.com. You can give me a little bit more information. I tend to keep an eye on that a little bit better than my general email, although I do use some amazing email software that helps me to keep track of the real email and get rid of the spam and put things in boxes and stuff craigpeterson.com. It's that simple email me me@craigpeterson.com. If you have questions.

I hope that Google is going to continue to improve itself. I love the fact that they found out that this one extension was malicious.

For those of you who might've just tuned in, we're talking about something called the Great Suspender something I've used for years, it became malicious, but they need to do more.

As people who are concerned about security, we just can't wait for the next incident. Just again, this client of mine, who we've been warning about this for months, he's stopped doing what we told him to do, and then decided well it's just too difficult. That's something we hear a lot from businesses. Oh, it just hampers the work. It hampers it because now we have to get permission from it in order to mount this particular drive or gain access to those files or materials. Yes you do, because we have to stop the internal spread of all of this malware and all of these hackers.

It is absolutely worth it.

All right, everybody. Thanks again for joining me today. I really hope you've been enjoying this. I have years' worth of podcasts out there and you'll find all of those at craigpeterson.com/podcast or on your favorite podcast platform.

If you subscribed under iTunes, you might've noticed, ah, yeah, I just released a whole batch there too.

I expressed concerns about owning an Apple watch. I held off for a long time. I want to talk about these devices now, the security concerns, but also the amazing health tools that are built right in.

Hey, welcome back. This Apple watch is really fascinating. It has been around now for six generations. There are a number of other watches that have had, or tried, I should say, to compete with Apple. They haven't been very successful. You might've noticed that. I have a friend that bought some watches for his family and to him that monitor all of the basic vitals and record them and send them up to his phone. It's a 20-ish dollar watch. He got it from South Korea probably are parts made in China, but it is an inexpensive watch and it does some of the basics at the other end of the scale.

Let's have a look right now. I'm going to go to apple.com online, and we're going to click on watch. Here we go, Oh, my they've got special watches so you can buy their watches. It looks like the new one, the Apple watch series six for starting at 400 bucks or they have two different sizes. . They have a more basic watch called the Apple Watch SE that starts at about $300. You can still get the Apple watch series three. Now, these all can monitor high and low heart rates. They can give you irregular heart rhythm notification, but it's only a-fib atrial fibrillation, I think is the only one they can monitor, but all three of those can monitor that.

As I said, my buddy's watches, he got for his family at 20 bucks apiece are able to do most of that as well.

These are water-resistant to 50 meters, which is really cool. The series six also has an ECG app. That is very cool. You open the app, you put your finger on the crown of the watch and it gives you an EKG right there on the watch and it feeds it to your phone.

On your phone, you can turn it into a PDF. You can share it with your doctor on and on. It's just amazing. It's a three-lead type, I was in emergency medicine, right? A med-tech EMT, EMT-PD can't remember. I had a whole bunch of different certifications back in the day. But it's fantastic for that.

It also has a blood oxygen app that monitors your blood oxygen levels. It ties all of this into their new exercise app, which is amazing. That ties into your phone or your iPad. I will go down in the basement onto the treadmill and I'll select your treadmill workout. It has dozens of them.

Have you seen this really fancy treadmill? A couple of years ago they got in all kinds of trouble because they advertised it around Christmas time and apparently this woman really wanted a treadmill and she got one and she was all excited. All of these people jumped out of the woodwork. All your you're saying she's fat, et cetera. No, she wanted a treadmill.

These are amazing treadmills because they have built into them. These streams and you can join classes, et cetera. With the Apple Watch, my iPad, and a subscription to this iHealth app, which you can get as part of this Apple plus thing you can buy for 30 bucks for the whole family, 30 bucks a month.

I don't know how many I have seen probably a hundred different workouts on there. It has different workouts, different types of weightlifting, running, jogging, treadmills, elliptical machines, everything. You can pick your pace. You can pick your instructor, you can pick everything.

Then your Apple watch is monitoring your body. As you're working out. So it's telling you how many calories you've burned. What's your heart rate is to help keep your heart rate in the best range for you, depending on what kind of a workout you're doing. It also lets you compete against other people.

Does this sound like an ad for the Apple watch?

You can compete with other people your age doing the same workout and see where you're at. I was really surprised because typically I am at the front of the pack when it comes to my treadmill workouts. That's really cool as well.

Those are some of the basics. There are other things too, that Apple is doing. We've found, right now, that Mount Sinai just came out with an announcement and they said that the Apple watch can predict COVID 19 diagnosis up to a week before testing can detect it. Yes. Isn't that something? Not only can the Apple watch help with certain heart arrhythmias, but it can predict that you have COVID-19 too a week before testing normal testing. Those swabs can find it out.

This is from the journal of medical internet research, which is a peered review journal. And they found that wearable hardware and specifically the Apple watch can effectively predict a positive COVID-19 diagnosis up to a week before the current PCR-based nasal swab tests.

They called this the warrior watch study. They had a dedicated Apple watch and the iPhone app, and they had some participants from the Mount Sinai staff and it required, of course, these staff members to use the app to turn on the health and data monitoring and collection, and also asked them to fill out a survey every day to provide some feedback about their potential COVID-19 symptoms. As well as other things like stress can obviously make your heart rate, go up your blood pressure, go up, et cetera. Oh. By the way, Apple, supposedly the rumors are, we'll have a BP sensor in the Apple seven that'll be out later this year, most likely.

So they had several hundred healthcare workers and the primary biometric signal. I know that the studies authors were watching was heart rate variability. This is fascinating to me because it's something that I learned about fairly recently. Then when I got my Apple watch, I read up more about this, but basically, heart rate variability is what it sounds like. It's your heart rate. Let's say your heart is beating at 60 beats per minute. It is not beating once every 10 seconds. It is not beating once a second. Your heart rate will vary over the course of that minute. If you're healthy. Obviously, a beat every 10 seconds isn't 60 a minute.

Let's use that as an example. Somebody who's almost dead and has six beats per minute. The first heartbeat might be at 10 seconds. The second heartbeat might be at 22 seconds because your heart is supposed to vary its rate of contractions based on immediate feedback. It's not just that you're going out in your running and now you've driven up your heart rate and you're doing your cardio and it or you just walked up a flight of stairs or you stood up, which is another test, by the way, what we're talking about here.

You might just be sitting there, but your cells have a different need for oxygen or for the blood. The heart slows down slightly or speeds up slightly. This heart rate variability is something built into the Apple watch and into the iPhone app that you attach to the Apple watch. Isn't that useful without an iPhone, frankly? Then you can look at your heart rate variability right there.

They said, combining that with the symptoms that people reported, these Mount Sinai staff, that the symptoms that they reported that were associated with COVID-19 including fever, aches, dry cough, gastrointestinal issues, loss of taste and smell corresponded with changes in the heart rate variability. I thought that was just absolutely phenomenal because heart rate variability is considered to be a key indicator of strain on your nervous system. COVID-19 obviously is going to put a strain on the nervous system. Just very neat. It says here that the study was not only able to predict infections up to a week before tests provided confirmed diagnosis but also revealed that participants' heart rate variability patterns normalized fairly quickly after their diagnosis or turning to normal run about one to two weeks following their positive tests. That's from a TechCrunch, that particular quote.

I am very excited about this, but I am also on the concerned side. I'm concerned because they are collecting vital data from us. All of the major companies, Google and Microsoft and Apple want to be the company that holds all of your personal medical records.

We're going to get back to that when we come back here. What is happening? How is your doctor managing your medical records? I was really shocked to find out how that industry is working.

Of course, you're listening to Craig Peterson. Check it out online. Craig peterson.com.

Welcome back. What are you doing? Are you asking your doctor how they are handling your medical records? Because I think you probably should based on what I learned just this week.

Hi everybody. Craig Peterson here. Thanks for joining me. We were just talking about health. We're talking about the Apple watch and the fact that there's a lot of competitors out there, some of them, a fraction of the cost. If you buy the Apple watch on terms, you're going to pay less in one month's payment on terms to Apple than you would for some of these other watches out there, but Apple watches do have more features.

Mine even has a built-in cellular modem. Even if I don't have my phone with me, phone calls come through to my watch and text messages, and I can respond and answer. It's really nice. Medically I am very impressed. It has been good at motivating me to do some exercise, to get up, and about just to do a bunch of things I had never, ever done before. Consider that.

It is collecting our data. Apple now has potential access to all of my cardiac data. They've got EKGs that I have run on my watch. They know about my heart rate. They know how often I exercise, and how hard I exercise when I exercise. They know all of this stuff about me. I had a conversation with someone just saying why does that matter? Maybe it's Apple, maybe it's somebody else. Why does it matter?

It does matter. Think about an evil genius, right? The thing about somebody that might want to target Americans and might want medical information about Americans. They can gather it in a number of different ways. We're going to talk about medical records here in a little bit.

One of the things they could certainly do is grab all of our watch data. Some of these watches, including my Apple watch, have GPS built into them. When you're out running or jogging, you know where you went, you can plan your route and it'll remind you, Hey, turn here, turn there. That's one of the things I love about the Apple Watch when I'm using it with Apple maps out driving, it taps me on the wrist and reminds me, Hey, in 500 feet, you got to turn.

If I look at the watch, it'll even show me the turn I need to make coming up in 500 feet. It's really amazing. All of this information is being compiled and hopefully, it's being compiled by a company that we can trust. At this point, we can probably trust Apple. Hopefully, they're not going to be broken into. Now, their margins or profit is high enough that they certainly can afford a security team, one capable of defending them and defending our data. I hope they are. I suspect that they are for the most part.

How about some of these others? We know Google, for instance, is in the business of collecting and selling our information, is having all of our medical information. Not just the stuff from our watches, but the stuff from our doctors. Are they to be trusted with that kind of information?

Going back to that bad guy, that mad scientist we can, and probably do engineer viruses that are targeted at specific things. In fact, the Russians have been doing it. The Soviets' started it, they came up with a phage. That can attack certain viruses and it acts like a virus it gets in and does this little thing. We've got right now, these COVID-19 vaccines and they act like a virus they're messing with, well effectively, the DNA. In fact, it's the RNA, but it's pretending, Hey, I got a message from the DNA, here it is.

What if a bad guy knew that are a certain population in a certain area, and that area was right by this important military base or whatever they came up with something that would target them and they'd have all of the data to do it now. That's obviously an extreme example. A more common example would be that your medical data is there. It's being sold to advertisers and you're going to end up with something.

For instance, there's a company, very big company out there and they sell baby products. What they did was they tracked and they bought this information, but they tracked women who were purchasing certain things. Now, they weren't purchasing things that were directly related to having a baby, right? They weren't purchasing diapers or little jumpsuits or whatever it is. They were purchasing things that were not directly related maybe people wouldn't even think they were typically related to having a baby. Yet they were able to figure this out. They got that good with the data. So they thought, Oh, okay let's get wise here. Let's send out a postcard, congratulating them on their pregnancy and offering them a discount on something. Yeah. Not a bad idea, frankly.

However, in this case, some of these moms I hadn't told anybody that they were pregnant yet and didn't want to tell anybody that they were pregnant yet. It fell on its face. Didn't it?

How about these ambulance-chasing lawyers that are out there? Are they going to want to gain access to this, to your medical records?

How about your employer? Your employer wants to know I'm going to train this person. Hopefully, they'll stick with us for a while, but is he going to be a burden on our medical plan? Keyman insurance, health insurance, life insurance. Have access to everything about you. That's what really concerns me about these, all of these devices.

Right now, pretty confident that I can give Apple this information and they will keep it pretty safe. But, I said the same thing about the Great Suspender, right? I don't know about the future.

Then I found something out this week that was in my mind extremely disturbing. We have a new clinic that we've picked up as a client. They needed to have security. They had a couple of little security issues. They were worried. They knew they were not HIPAA compliant. They approached us because they know that's what we do is cybersecurity and audits and remediation. Fixing the problems. We pick them up. They're a client. We're in there. They had told us in advance that all of their medical record systems were on-line. It was on the web. All they needed was a web browser to run their business. Okay. That could be a problem. It might be okay. The medical records manufacturer might have good security on all of the records. So we may be safe, although in HIPAA unless you have a business process agreement in place with that vendor if that data is lost, it falls back on the doctor's shoulders.

Anyhow, what I found out was, first of all, it wasn't completely web-based, which just shocked me. I'm not talking about they have to scan records or they got the x-ray machine or whatever. It really wasn't web-based and secondarily the company they were using for the medical records was a free service.

The doctor, that clinic, was not paying for their medical records management software. The way it works is this medical records management company when the doctor prescribes something when the doctor performs a procedure and bills and insurance company, it's all done through this one company and that company takes a chunk of their money.

In some cases we found seems to have been inflating the bills that went off to the insurance companies and that, as it turns out is a common practice in the industry. According to the doctors at this clinic, I was shocked, amazed.

Something you might want to look at. Ask your doctors where are your records kept and are they secure?

Now we had HIPAA. We thought that would secure it, but it doesn't.

Stick around.

Hey, we got a name now for what happened to the Great Suspender and QR code scanner apps over on the Google stores. One at Google Play, the other one over on the Google Chrome store. It's become that popular.

Hey, everybody, I wanted to mention this whole new category of malware really, and they're calling it, right now, Buy to infect. What happens is a bad guy, a malware guy buys a legitimate app and then starts infecting it. We know, obviously, about the one that I've been talking about a lot the Google extension that I used to use all of the time, the Great Suspender. I mentioned this one a few weeks ago, it's called QR code scanner. It's been on the Google play store for a long time, had more than 10 million installs and then all of a sudden it became malicious.

This is a little bit of a different angle on it because, with the Great Suspender, the ownership of that software actually transferred to somebody. With QR code scanner, they were working on a deal with a company and this company wanted to verify the Google play account for QR code scanner. This is all according to the owner, the original owner of QR code scanner. They said that what had happened is part of this purchase deal. I let them have a look and gain access to the software's key and password prior to purchase so they could confirm the purchase, which doesn't sound too bad. Apparently, as soon as they got a hold of the software's key and password, forget about the purchase, we're going to start infecting it right away. It ended up getting that app, the QR code scanner app, pulled right from the Google play score store. Of course, now you don't need that quite as much because most of the phone apps when you go to take a picture, the camera apps have built into them, a QR code scanner.

I thought that was fascinating what they did. They totally cheated the company. They didn't even bother buying it. So a little word for the wise out there.

Got another Apple story cause this is showing how the computer industry is really shifting. We've talked about some of the shortages of chips and the shortages of computer chips are so bad that General Motors has had to shut down two-thirds of its manufacturing lines in at least one plant. Every major automobile manufacturer is having problems making cars because they can't get the chips.

Remember nowadays, a car, a truck is essentially just a computer on wheels. Not really actually computer on wheels. It's really dozens of computers all linked together with a network on wheels.

Apple has been worried about that, right? Supply chain. That's one of the things you're supposed to worry about as a public company. What are the risks going forward including to my supply chain? Obviously your supply chain matters. You gotta be able to make something you need parts, right? Apple has been upset with Intel for a while. You might remember Apple. When it first came out, was using a Motorola chipset, which was exceptional much better than the Intel chipsets. Of course, that's my opinion, a lot of people agree with me. You had the 68000, 68010, and 20, et cetera. Very good chips.

When Apple started getting into the laptop business, that's when the problems started to happen. These Motorola chips gave off a lot of heat and used up a lot of electricity. At the time Apple looked around and said our only real alternative right now is Intel. Intel has a whole line of chips, different speeds, and they have mobile chips. Those mobile chips use much less power than the Motorola chips for the main CPU. They also use less battery. Those two go hand in hand and generate less heat. That's it all goes hand in hand. So they said, we'll start working with Intel. They did. Intel really disappointed them more than once, which is a shame. They disappointed them with the 64-bit migration. AMD, advanced micro devices, beat Intel to the punch. Shockingly Intel started making AMD compatible CPUs right. The 64-bit extensions to the CPU were AMD extensions. They had problems with some of their other chips as well. Mobile chips getting the power usage under control, the heat dissipation problems under control, and they never really lived up to what Apple was hoping for. What everybody in the industry was hoping for. In many ways, Intel has been a huge disappointment, which is really a shame.

We'll look at what they did to the industry, with these predictive instructions, the hyper-threading, and stuff. Where bad guys were able to bring a computer to its knees. What does Intel say? Here's a firmware patch you can apply to our CPU, those little CPUs you pay upwards of $2,000 for a piece for one chip. Those CPU's and by the way, it's going to, cut its performance by a minimum of 20%, maybe 50%, that's okay.

What are you kidding me? A lot of people were upset with Intel and Apple and Microsoft and everybody released patches that use the new Intel microcode. You might've noticed when this happened a couple of years ago that your computer slowed down. I certainly noticed, actually, it was little more than a year, anyway, I noticed it because I own a data center. That has a lot of Intel chips in it where we're running mostly Unixes, Linux, and BSD, but we're also running Windows. So the only way to work around this bug was to apply the patch and slow everything way, way down.

Imagine how Apple and Google felt with their huge data centers. IBM too. IBM has Intel-based data centers, as well as its own chips, and boy talking about phenomenal chips, as far as processing power goes, IBM, man, they are still the leader with the power chips and their Z series. That just wow. Mind-blowing.

Most of us are stuck in the Intel world. Apple said we can no longer trust Intel. So what are we going to do? Apple said we've been developing this chip for a long time. Apple took the chip design, they licensed it from this open sourcee type of company that has a number of members. They took this arm architecture and were able to improve it, and keep adding to it, et cetera. They're still part of this Alliance. They started using these in their iPhones. The iPhones have been using these chips the whole time and they started improving them after they released the first iPhones. Intel didn't really get them upset until a little later on, too.

They came up with newer ones, faster ones, better ones, right to all of these A10 their bionic chips. They've got AI chips, machine learning chips, all Apple designed. Chips, of course, manufactured by third parties, but that's what Apple is using. Apple has now said we expect all of their Macintosh computers to be based on Apple's CPU within the next two years.

There's already some really good ones out there right now that people like a lot. We've been using them with some of our clients that use Apple. Not everybody has had great luck with them, but Apple is not only ditching Intel, that's not the big story here. Apple's got some job listings out there looking to hire engineers.

So when we get back, we'll tell you more about what Apple is doing and what frankly, I think the rest of the industry should look at. Guess what? They are.

It's been Intel versus the rest of the world. They've been winning for years in many categories, but now they're starting to lose, as major manufacturers are starting to leave Intel behind. But there's more to the story still.

Hi, everybody.. Craig Peterson here. Thanks for tuning in. We're glad you're here. In the last segment of the day, I want to point everybody to the website, of course. You can get my newsletter. It comes out every Sunday morning and it highlights one of the articles of the week. It gives you a pointer to my podcast. So you can listen right there. There's just a lot of great information. Plus I'm also doing little training. I'm sending out, hopefully, next week, two little training sessions for everybody to help you understand security a little better, and this applies to business. However, it's not. Strictly business, much of what I talk about is also for home users. So if you want to go along for the ride, come along, we'd be glad to have you. There's a lot to understand and to know that you won't get from anywhere else. It's just amazing. Many other of these radio shows where they are just nothing but fluff and commercials and paid promotions. I'm just shocked at it. It goes against my grain when that sort of thing happens. Absolutely.

We were just talking about Apple and how Apple got upset with Intel, but they're not the only ones upset. We also now have seen a lot of manufacturers who have started producing Chromebooks and surface tablets that are based on chip sets other than Intel's.

This is going to be a real problem for Intel. Intel has almost always relied, certainly in the later years has relied on Microsoft and people bought Intel because they wanted Windows. That's the way that goes. It's just like in the early days, people bought an Apple too, because they wanted a great little VisiCalc, the spreadsheet program.

Now, what we're seeing are operating systems that do not require a single line of Microsoft software. Google Chrome is a great example of it. Linux is another great example and people are loving their Google Chrome laptops, and you can buy these laptops for as little as 200 bucks. Now you get what you pay for and all the way up to a couple of grand and they don't have a line single line of Microsoft code. Yet you can still edit Word documents and Excel documents, et cetera. They do not contain any Intel hardware. What was called, well, they might have a chip here or there, but not the main CPU. What used to be called the Wintel monopoly. In other words, Windows-Intel monopoly is dying. It's dying very quickly.

Apple is not helping now. Apple, they've had somewhere between seven and 10% market share in the computer business for quite a while. Personally, I far prefer Apple Macintoshes over anything else out there by far. I use them every day. So that's me. I don't know about you. There's a little bit of a learning curve. Although people who aren't that computer literate find it easier to learn how to use a Mac than to learn how to use Windows, which makes sense. Apple has really done a great job. A bang-up job.

With these new chips, it's getting even faster. We are now finding out from a report from Bloomberg who first started these, that Apple has been posting job listings, looking for engineers to work on 6G technology. 6G, right now we're rolling out 5g, which hasn't been a huge win because of the fact that if you want really fast 5g, like the type Verizon provides, you have to have a lot of micro-cell sites everywhere. They have to be absolutely everywhere. Of course, it's just not financially reasonable to put them up in smaller communities. If the Biden administration continues the way they're going with the FCC and the open internet type thing of a-bits-a-bit, then there will be no incentive for any of these carriers to expand their networks because they can't charge more for better service. If you can imagine that. Ajit Pai fought against that for many years, Trump's appointee as chairman to the FCC, but things are changing. The wind has changed down in Washington, so we'll lose some of those jobs and we're not going to get all of the benefits of 5g. If he keeps us up. 6G is coming.

What that means is Qualcomm, who is the manufacturer of record for most of the modems that are in our cell phones. Qualcomm has also missed some deadlines. Apple is tired of dependencies on third parties because Qualcomm might have somebody else that buys way more chips. It might be able to sell the same chip to the military of whatever country for a much, much higher price. They can sell it to consumers. Maybe they just change the label on it and call it a mill spec, and often goes right, who knows? What they're doing out there, but Apple doesn't want to do that anymore. They are looking for engineers to define and perform the research for the next generation standards of wireless communications, such as 6G The ads say you will research and design next-generation 6G wireless communication systems for radio access networks with emphasis on the physical Mac L two and L three layers. Fascinating, eh? What do you think? I think a huge deal as Apple continues to ditch, many of its vendors that have not been living up to the standards Apple has set.

Apple has moved some of the manufacturing back to the United States. More of the assembly has been moved here. The manufacturing, it's starting to come back again. We'll see the Trump administration really wanted it here. We need it here, not just for jobs, we needed it here for our security.

We've talked about that before, too, right? I want to also point out speaking of Apple and manufacturing, China, of course, does most of it for Apple and Foxconn is the company in China that makes almost all of this stuff for Apple. It's huge. Foxconn owns cities. Huge cities. They have high rises where people basically don't see the light of day, these high rise factories. You live there, you eat there, you shop there, you work there.

Like the old company store who is it, Tennessee Ernie, right? Owe my soul to the company store. That's what's happening over there. And Foxconn has kept its costs low by bringing people in from the fields, if you will, out there being farmers and paying them extremely low wages. On top of all of that, in some cases they're using slave labor. I found this article very interesting, from Ars Technica's, Timothy B. Lee. He's talking about a potential partnership between Apple and Nissan. Let me remember. I mentioned Apple talking with Kia and Kia is denying it.

The financial times reported on Sunday that this potential deal between Apple and Nissan fell apart because Apple wanted Nissan to build Apple cars, they would have the Apple logo on them. They all be branded Apple. It wouldn't say Nissan unless you took something seriously apart you might find it inside.

Nissan wanted to keep the Nissan brand on its own vehicles. Bloomberg reported last week that the negotiations with Kia and of course its parent companies Huyndaiin South Korea had ended without a deal. The Financial Times said that Apple has also sounded out BMW as a potential partner because Apple doesn't make cars.

So how are they going to do this? Apparently the talks faltered with Apple and Nissan because Nissan had a fear and apparently this is true of Kia too, of becoming quote the Foxconn of the auto industry, unquote, which is a reference to this Chinese well it's Taiwanese technically, but a group that manufacturers are while actually assembles the iPhones. Fascinating. Isn't it fascinating.

When you start to dig into this self-driving technology and the numbers behind it, that's where you wonder, why is Apple even trying at this point, Apple's test vehicles only traveled 18,000 miles on California roads. Between 2019 and 2020, or over the course of about a year, late in both years. 18,000 miles in a year. Heck, I've done that before with my own car.

Waymo, which is Google's self-driving project put on more than well, about 630,000 miles in California. Likely a lot more in Arizona where they doa lot more testing. Cruise, which is this startup that was put together by GM and Honda logged even more miles than Google's Waymo, 77,000 miles on California roads.

So this is going to be interesting. Apple sitting on 77 billion dollars in cash and short-term investments. That's more than the market capitalization, the entire market gap of a number of major market car makers, including Nissan, Ford. Actually, you add those two together and you haven't reached the amount of cash Apple has on hand and Stellantis, the parent company of Chrysler Fiat. They have the money potentially they could buy out one of these companies. We'll see what happens, the automated cars market's going to be huge. I'm looking forward to it. We're going to have a lot of struggles between now and then.

Hey everybody, if you haven't done it go right now to Craig peterson.com/subscribe. You'll get my newsletter. You'll get these trainings. You'll get to listen to my appearances if you miss them. You can find my podcasts on almost any platform out there.

Just check it out. Craig peterson.com. If you have a minute, leave a hopefully five star review for me. I'd really appreciate it.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. I talked about the Suez Canal blockage by the M/V Ever Given and what really runs the Suez Canal. Then we got into Scams that people fall for and the conviction of the Celebrity Twitter Hacker. Then we talked about Bitcoin and its meteoric rise in price and who now will take Bitcoin as payment in a commercial transaction. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Fun with Mr. Matt Gagnon this morning is we talked a little bit about Tesla. Again. I had to bring up this whole thing with the Suez canal and of course, wedging that cargo ship. We also talked a little bit about this teen who hacked some blue check Twitter accounts and is now serving time.

So here we go.

Matt Gagnon: [00:00:24] We are back again, at seven 36 on Wednesday morning, which is a great time to talk to Craig Peterson, our tech guru. He joins us at this time every week, Craig, how are you?

Good morning, sir.

Craig Peterson: [00:00:34] It is a great time. I'm doing well.

Matt Gagnon: [00:00:37] Well, Craig, let's be honest. Is it ever a bad time to talk to Craig Peterson?

Craig Peterson: [00:00:43] Probably not. You know, I have three kids in the maritime industry and you probably heard about the Suez cargo ship and what is going on.

Matt Gagnon: [00:00:52] I don't know. I must've missed it. Didn't I don't know. I do know that I ordered something from Amazon, which was delayed and I'm guessing maybe it was on the boat.

Craig Peterson: [00:01:00] Maybe it's fascinating too, to talk to my kids about this because one of my daughters was in fact, commanding a ship going through the Suez canal five years ago on the very day that ship managed to get stuck. Interesting conversations with her not just about the whole idea of saving all of that money from fuel. The way it works is they charge a million-plus bucks to go through a canal, either the one here in America or the one over there. It costs more than that in fuel to go around the Horn or the Cape, depending on which you're in. These ships go through and just like any Harbor in the world, they have pilots.

These pilots are well-trained. We got a lot of them, Mariners, here in Maine, listening to the show. I got an email from one this week.

In fact, my daughter and I were talking, to her and her friends and they were saying, I'm not sure that any of these pilots that run the ships through the Suez canal could actually get a Maine boating license.

It doesn't matter what you're hauling. There's two things you have to haul on your ship if you want to make it through the Suez canal. And that is cartons of Marlboro Reds and bags of M&Ms because you have to bribe these guys in order to take you through the canal. I was not surprised. When I saw this massive ship having run aground right there in the canal.

Matt Gagnon: [00:02:29] See, I was making lots of jokes about teenagers, parallel parking. To me, that's what it kind of looked like, right? Like, Oh no, I gotta get outta here. Oh no, now I'm stuck right here.

Craig Peterson: [00:02:38] Exactly.

Matt Gagnon: [00:02:40] Well, Craig Peterson can be heard on this very station on Saturdays at one o'clock. If you want to hear any of this stuff in more depth and detail, and we have a few things to get to Craig, so let's move on.

Look. Not that this was ever something that I thought was a good idea, but I think we now have ample evidence that hacking into famous people's Twitter accounts is probably not going to give you a good time, right? Some prison for the hackers that got into a couple of really prominent accounts.

Tell me about the story.

Craig Peterson: [00:03:05] Yeah, this was a big deal. What happened is this guy managed to get into president Obama's account, Elon Musk's account, Joe Biden's account back when, and he said that he listened to everybody we're just so excited about everything and how well things are going. If you send me Bitcoin, I'll send you back triple. What it is that you sent me.

So send me 10 Bitcoin. I'll send you back 300. Amazingly, this guy collected more than a hundred grand worth of Bitcoin. People were sending him fractional Bitcoin too. Turns out it was a teenager. The kid was about 17 years old. He hacked these accounts using the good old-fashioned way.

In other words, they had terrible passwords.

Matt Gagnon: [00:03:57] Yeah.

Craig Peterson: [00:03:57] He got into these things and was able to just con people out of money. It's totally amazing. We still apparently fall for this Nigerian scam. It basically what it is. Who is going to do that Matt?

Matt Gagnon: [00:04:12] Don't know, but people clearly do because this is continually a problem and so they definitely do.

Craig Peterson: [00:04:18] Yeah, it is. Now we've got a new version that they've started up. You were talking about what happened a year ago. We only have them lockdown for about two weeks. So the rest of this is just all our imagination. But because of that all of this personal protective equipment and stuff, there were scams going on, hospitals, the federal government buying hundreds of thousands of dollars worth of personal protective equipment. That was completely not up to spec. It was trash. California spent millions of dollars on stuff that wasn't even delivered.

Scammers are out there. Everybody we've got to be careful and they're going after us to another way. That is many of us are lonely. So we're looking for friends online. We're finding friends online and they're scamming us another way by saying, Oh my, you know, my mother she's been really ill, of course, they build-up to this right over the course of weeks. So you say, Oh, how is she? It's not really a joke, but says, okay, well she needs this surgery and it's going to cost $5,000. They con people now particularly our more seasoned citizens into sending them money.

The FBI has been warning about that one again, too. So we've gotta be really careful. Look at everything. Inspect that email pay close attention to them. Phishing training needs to happen for employees because of business email compromises.

But this kid is going to serve time as a juvenile. Cause he was 17 at the time he reached a plea deal and there was a minimum 10-year mandatory sentence for what he did. Apparently, he's going to serve about three years in the juvenile facility.

Matt Gagnon: [00:06:05] Craig Peterson joins us at this time every Wednesday to go over what's happening in the world to technology. You mentioned Bitcoin, quite a bit in that little story you just told me here.

I can't resist asking about Elon Musk. And the fact that they're going to be apparently accepting Bitcoin and he's not going to convert it. He's going to keep the Bitcoin itself. Is he's going to use it as currency more than just an investment? I had a really interesting conversation with somebody about this recently about whether or not someday in the future, there might be a possibility that a Bitcoin or other cryptocurrency type of thing could actually serve as true currency and not just an investment.

Which a lot of people are doing it right now. This is, to me, this is the thing that's required for that to work, right? Is that people are using it as a mechanism of trade on its own, as its own thing, rather than using it as a sort of an intermediary.

What do you think about this decision by Musk?

Craig Peterson: [00:06:56] Currency our government issues only has value because you can spend it places like you were saying. Right? Correct. Where can you spend Bitcoin? Well, the number one thing Bitcoin has been spent on is paying ransoms. Elon Musk recently bought a billion and a half dollars worth of Bitcoin, but that's not uncommon.

We're finding more and more companies, particularly over the last year where ransomware payments have tripled in 2020, companies are buying Bitcoin as insurance in case they get ransomware.

So rather than cleaning up their technical act. Yes. Let's just get some money to set aside for paying a ransom when that time comes because we're incompetent.

I don't know it's part of their planning, right? So he bought some. Hard to say why Bitcoin and a lot of people are saying it's going to go much higher than it is. Other people are saying it's going to fall. I'm certainly not an investment advisor.

By having Musk now say we will accept Bitcoin as a means of trade as you said, I think it gets it a lot closer. You know, we started out, with the pizza story. You might remember the Bitcoin's very first purchase, 10,000 Bitcoins for two Papa John's pizzas. Now it's one Bitcoin for an electric car from Elon Musk. We've got this whole new genre of people buying digital artwork for millions of dollars that can be replicated duplicated like that perfectly. It's not like the Mona Lisa. This whole world's going crazy.

Governments are very big into trying to come up with a cryptocurrency. The part I don't like is that it obviously all trade, if it was forced onto one of these cryptocurrencies is more readily tracked, which is what the government's after. So that they can tax it and they can track transactions. They can track everything, including what might be an illegal transaction for drugs or things. Although, drugs are getting more and more legal every time you turned around. We'll see what happens. Governments really want this, but they haven't figured out how to master yet.

Elon obviously thinks it's worthwhile to take Bitcoin. Maybe he figures a Bitcoin at 50,000 today is going to be a hundred thousand next year and it's a great investment for Tesla. It's hard to say he hasn't announced it.

Matt Gagnon: [00:09:27] Indeed. All right. Well, Craig Peterson joins us on Wednesdays to talk about all these ends. So many more stories, Craig, good luck on Saturday talking about these very things.

We'll talk to you again next week.

Craig Peterson: [00:09:38] Take care, Matt Thanks a lot.

The drama continues. I, and Karen worked all day, Monday, Tuesday to do what we thought would just take an hour or two in getting everything ready for this course, the final stuff, getting it up in a membership site, and everything.

It is now 99% ready. I have a couple more things to do. You'll be getting emails about the Improving Windows Security course. I'm going to throw in a couple more bonuses, we will schedule a couple of phone calls, to answer any questions you guys might have, or maybe webinars, probably the better way to do it so I can show you stuff if we need to.

We're thinking we might want to include a couple more little things too. So we'll see how that all goes. You might actually get the email about the course before you listen to this podcast if everything goes okay.

Take care, everybody. We'll be back this weekend.

Bye-bye.

Oh, and I should probably tell you, in case you're just a podcast listener and you're not on my email list.

It's Craig peterson.com/subscribe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. We discussed not only that Elon Musk's Tesla Organization is now accepting Bitcoin for payment but an additional interesting twist to that. Then we talked about the Suez Canal and the problems with the Ever Given. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Mining equipment. It's like those guys that you watch on the discovery channel, where they're mining for gold up in Alaska. The guys that make the money, they've got these massive machines moving all of this stuff and they're making lots of money. Well, there's specialized equipment as well for mining for Bitcoin.

Good morning, Craig Peterson here. Of course, I was on with Mr. Jim Polito this morning. I had to talk about the Suez canal, this blockage. So we did, we got into that. Then also a little bit about Tesla and Bitcoin. What is Elon Musk doing? What what's he thinking? I had a couple of ideas and we talked about them with Jim.

Here we go.

Jim Polito: [00:00:44] You can buy now a Tesla with Bitcoin. There are organizations that will accept Bitcoin. Here's what's different here. Most of those organizations take the Bitcoin converted to regular currency and then that's it.

Well, Elon Musk must be betting on Bitcoin. I don't know. I need a guy much smarter than me here, which doesn't take a lot of work. That is in no way to take anything away from our next guest, who is our good friend and tech talk guru. Craig Peterson. Good morning, Craig.

Craig Peterson: [00:01:20] Hey, good morning, Mr. Jim. Yeah. What a different world.

Jim Polito: [00:01:24] Yeah. You can buy a Tesla with Bitcoins, which is that crazy currency that we talk about frequently here. When he takes the Bitcoin in, unlike other businesses, he's not then converting it. Like when you go to Europe and you're converting your money into euros. He's not converting it. He's keeping the Bitcoin.

Does that mean he thinks Bitcoin is viable?

Craig Peterson: [00:01:50] Yeah, boy does he ever. He's been talking about it and promoting it for a while. He bought one and a half billion dollars, of course, that sends the price up. It isn't just ransomware now being used for Bitcoin. Everything's going crazy.

Look at this musician Grimes. I don't know if you heard about this, but he sold the collection of digital work for 6.3 million.

Jim Polito: [00:02:19] The digital artwork just makes me laugh. Somebody makes a piece of digital artwork, which, unlike the Mona Lisa, you can't go there and just pick it up and say, I'm going to bring it home, or I'm going to take a copy of it. You can't do that digital artwork as far as I'm concerned is worthless.

Craig Peterson: [00:02:37] It's a perfect copy, right? It's not like the Mona Lisa a forgery.

Jim Polito: [00:02:42] It's actually right. You're right. If you copy a piece of digital artwork, it's exactly the same.

Craig Peterson: [00:02:49] It absolutely is.

They filed at Tesla here. This is a regulatory filing with the securities and exchange commission about a month ago now saying that they would begin accepting Bitcoin as payment for Tesla cars.

Now, I'm not sure who they're going after or what they are gonna use bitcoin for, maybe he sees a Bitcoin going up even further. We've certainly seen some major runs in it. You referred to it as a currency. I think that's an interesting word because of what is. What is the currency?

We have dollars that we have right now that has the full faith and credit of the government just laughable in and of itself. But anyway, everybody takes it right from the pizza shop, that first took 10,000 Bitcoin for two pizzas. They're the first Bitcoin transaction ever. So figure out how much they were worth then far less than a penny. Now, Tesla saying, yeah, you can bring in one Bitcoin and I'll give you a full car.

Jim Polito: [00:03:57] I don't know. I'm just not getting it, you know what, as they say, that I think the chance to get in on the ground floor was a long time ago. I'm just not getting in on the ground floor. I'll stick with all that stuff.

Craig Peterson: [00:04:09] My son and I started doing mining, years ago, Bitcoin mining. It was just so expensive to do because we didn't have specialized mining equipment.

It's like those guys that you watch on a discovery channel where they're mining for gold up in Alaska, the guys that make the money. They've got these massive machines moving all of this stuff and they're making lots of money. Well, if there's specialized equipment as well for mining for Bitcoin, and with the cost of electricity here in the Northeast, it's just not worth doing.

If you go to eBay right now, You could do a search for Bitcoin mining equipment and you would find all kinds of used stuff for sale because the next generations out. And the only way they can stay effective is to get the next generation. So right now it is cheaper to mine a Bitcoin than to pay for the electricity. It's about 25 to $30,000 for one Bitcoin.

If you're trying to mine it, it's going to vary. It's a little bit of a luck of the draw too, by the way, the Bitcoins they're in the $50,000 range. Okay, that makes some sense to do some mining. But again, you've still got to have this specialized equipment.

That's going to cost you a lot of money and get busy. He's obviously betting on it going up. Yeah, he may be just saying, I'll convert it to a hard currency, when I hit the hundred thousand dollars a Bitcoin, he really hasn't said.

Jim Polito: [00:05:37] There really are people who believe that it will too.

Craig Peterson: [00:05:41] Oh yeah.

Jim Polito: [00:05:42] Eric Bolling who used to be on Fox. He's a former investment person who then worked at the business channels. Then it gets a Fox. Then he had a sexual harassment allegation against him he's out. He does work for Newsmax now a few others. I listened to a podcast with him talking about it and he's betting on it.

He's not a stupid guy, he's betting on it.

Craig Peterson: [00:06:06] I wish I had money to bet on it. I just don't right. I'm trying to build a business and raise a family, support a wife, kids, chickens, by the way, the Fox got four or two foxes came by this morning I got four my chickens, but, we get it.

Jim Polito: [00:06:22] We gotta talk about that after, but keep that thought in mind. Cause I gotta tell you a good story. Go ahead.

Craig Peterson: [00:06:28] It's that time of year. We'll see what happens, Bitcoin. I just don't know. I've never had the trust in it. It takes trust to buy Bitcoin.

The major drive driving force behind Bitcoin has been corporations buying Bitcoin so they can pay for a ransom when they get ransomware. They're buying Bitcoin in advance. That's part of their plan for disaster if they get hit with ransomware.

Then the other thing that's really driven up Bitcoin over the years is people buying it to pay ransoms themselves.

And that's a real big deal. That's something we're covering on the improving windows security course this week too. You got to keep yourself safe. How do you mitigate it?

There just aren't that many places that accept it. Maybe Elon saying while we've got all of these total geeks that mine Bitcoin, now they'll trade it over.

The fact that he bought a billion and a half drove the value of Bitcoin up. Is he playing the market? Is he gaming it by buying it? Driving it up, testing it, which will drive it up, right? The value just keeps going up. Who knows maybe that's even illegal.

Jim Polito: [00:07:41] Well, he's been in trouble before with the SEC. Remember some of the statements he made. He should stop smoking pot, live on a podcast. He should maybe start with that. You have to give him some credit though for what he's done was SpaceX and other things. The very fact that he bought $1.5 billion worth of Bitcoin, right after that purchase is closed. The price goes up because people seem to just see that Elon Musk bought Bitcoin maybe he's part of the whole thing and like old man, Joe Kennedy used to do. He knew when to get in the market and when to get out. Maybe Elon Musk got a little bit of that. I just think it's fascinating.

Craig Peterson: [00:08:21] Hey, I gotta bring up those Suez canal thing here too, Jim.

Oh no, go

Jim Polito: [00:08:25] Go ahead. Go ahead.

Craig Peterson: [00:08:26] I've got two kids in the maritime industry and you know that. It was three actually that have been. One of whom is a Master Mariner. She has unlimited oceans, unlimited tonnage command vessels for the US Navy and merchant vessels. And she's been through that very Suez canal before.

She's told me some stories about it. I'm not sure that the pilots, now remember pilots when it comes to ships, are the specialized people, that know the harbors.

Jim Polito: [00:08:59] Usually, they come out to the ship. Bring them out, they climb up the side, get in. They know the local waterways they take over for the Captain.

Craig Peterson: [00:09:09] Those are the guys. You know what nepotism is, right?

Jim Polito: [00:09:12] Oh yes, I do. We have quite a bit of that in Rhode Island and Massachusetts. We have a little bit of that going on.

Craig Peterson: [00:09:19] I'm not sure these ships pilots over there by the descriptions I have heard. From the family members and others, I'm not sure those ship pilots are actually even qualified to get a Massachusetts voters license.

Jim Polito: [00:09:35] No.

Craig Peterson: [00:09:36] They are the least competent people I have ever heard of, nepotism runs rampant. If you actually want to get through the canal, you have to make sure when you go over there that your ship, you might be hauling oil, you might be hauling it doesn't matter what, but you better be hauling Marlboro Reds and M&M's because that's what powers the Suez Canal..

Jim Polito: [00:10:01] You know what, that's great. One of the busiest waterways in the world, what is it? How much of the trade of the world? 11% of the world's trade goes through and you're telling me that if you don't have the Marlboro Reds, forget about the Marlboro lights but if you don't have the Marlboro Reds and some M&M's, it's all over.

Craig Peterson: [00:10:20] Forget about it. You're going to end up blocking that Canal.

Jim Polito: [00:10:25] That's very, very interesting. There's a cool little app out there right now that allows you to put the ship anywhere that you want. Like, you can drop it on a map anywhere. You can drop it on your street on the map.

Craig Peterson: [00:10:42] Boston public library curator. It's called when the Suez.

Jim Polito: [00:10:48] I'm seeing quite a few online of people taking it and putting it in interesting places. Hey, you mentioned it and then maybe we should just now close with is that program that you're putting on. We always ask you at the end, how can folks get more information from Craig Peterson?

Craig Peterson: [00:11:06] Absolutely. Now's the time to do this. This is an Improving Windows Security course. You probably also got an email if you're active on the email list. I don't want to bother people who aren't that interested.

First of all, Big big problem right now with iOS Apple's operating system for its mobile devices, you should have already received and installed a patch from Apple, even an old Apple phone. Okay, good.

Jim Polito: [00:11:38] Yeah, I saw

Craig Peterson: [00:11:42] Android. That's why I don't like Android. Apple gets it out even for old, old phones,

Number two, this Improving Windows Security course is starting this week. I hope to get the email out this afternoon with all of the details. It is going to help you tighten up your windows computer. If you're not on that email list, get on it now. Credit Peterson.com/subscribe, because I send out tips and tricks and training.

We do free webinars, just all kinds of stuff. You'll only know if you go to Craig peterson.com/subscribe

Jim Polito: [00:12:17] Craig that is great. Good. Good to hear from you. Thank you as usual for making the very complex simple, and we'll catch up with you next week.

Craig Peterson: [00:12:28] Bye-bye

Jim Polito: [00:12:28] Bye-Bye. Craig Peterson.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation with regards to vaccines. I might disagree a bit with Chris on this subject a little. Anyway, then we got into the Conviction of the teen Twitter hacker who hacked accounts of celebrities, Elon Musk, Joe Biden, Barack Obama, and Kanye West for Bitcoin. He will be doing 3 years in Prison for this escapade. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here on New Hampshire Today with Mr. Chris Ryan. We talked about a friend of mine who passed some years ago, in fact, quite a few years ago now, and a little bit about vaccines, cause he's talking a whole lot about it. I certainly disagree with him on some of the things he was saying this morning, but there are some interesting effects of that really have happened here over the last one.

When did Jonas Salk come up with that first one? A hundred or so years ago? We chat a little bit about that, as well as that kid that hacked all of these blue check accounts on Twitter, including President Obama's, Kanye West, Joe Biden, and Elon Musk's accounts. Do you remember that? Then he was giving away free Bitcoin? Well, he just got sentenced. We'd talked a little bit about that as well. So here we go.

Chris Ryan: [00:00:56] Craig Peterson, right now, host of tech talk on news radio 610 and 96.7 Saturdays at 11:30 AM.

Craig Peterson: [00:01:04] Hey, I'm doing well. This brings back a memory of a friend of mine. His name was Gordon MacDonald and he died from complications of polio. I remember it ever so well, right around 1970.

This whole thing now with the vaccinations. We have pretty much eliminated a lot of these diseases that were terminal back in the day.

Chris Ryan: [00:01:24] Right. I think that whenever, even before COVID, I would hear anti-vaxxers talking about why people should not get vaccinations and the potential side effects and a wide range of conspiracy theories about why certain things are happening and trying to assign them to vaccines.

You think about Franklin Delano Roosevelt who we talked about earlier in the show. You think about smallpox and other things that were eradicated were such a predominant part of American culture. Where that you did not think that your life was going to go on for a long period of time, based upon smallpox outbreaks, based upon polio and its prevalence.

So. Vaccines have had such an incredibly positive effect on our culture as is the case with everything there are trade-offs. There is no perfect thing. I hate to break it to people, there are trade-offs. At times it's not exactly the way you want it to be, but where would we be as a country? Where would we be as a civilized society?

You think about the AIDS vaccine and how it was distributed in Africa in the early two-thousands and what that has done there. There has been such incredible work that has been done by medicine, and we give so much credence to crackpots who want to come out and talk about various conspiracy theories on vaccines. There are negatives, there are side effects, there's no question about that. There is no perfect thing, but vaccines have had such an important part

Craig Peterson: [00:02:54] Just because you're paranoid, Chris, doesn't mean that they're not coming after you.

Chris Ryan: [00:02:58] True.

Craig Peterson: [00:03:01] Oh my.

Chris Ryan: [00:03:01] So let's talk a little bit about things in your realm here over the last few days.

I want to start with this, We have seen various hackers have success as of late. One individual that hacks the Twitter accounts of Elon Musk, Barack Obama, for Bitcoin. That person has been given three years in prison for hacking into the accounts of Obama, Musk, Kanye West, as well as Joe Biden.

What are your thoughts on that?

Craig Peterson: [00:03:32] Yeah, you might remember this. What he did was, he was able to hack these accounts. He was at 17 years old at the time, so he was a minor and he entered a plea deal. He hacked these accounts, the so-called blue check brigade, right? He was able to post on those accounts and say, Hey, listen because I'm giving away lots of money here. If you send me a thousand dollars worth of Bitcoin, I'll send you back $3,000 worth of Bitcoin and people fell for it and he got more than a hundred thousand dollars worth of Bitcoin for this whole scam. But because he was a minor at the time, and he's entered into a plea deal, he is going to be getting three years in prison for this. It brings up a couple of really good points.

One is we have to be careful if something's too good to be true it probably isn't, even if it might be a Nigerian Prince, right, which is how this whole mess started. So be careful of that.

We're seeing it all of the time. We're seeing it with business email compromises, which is our cost and our businesses billions of dollars. We're seeing that now with ransomware and extortion. Where you have tripled in the last 12 months the number of ransoms we're paying out here in the United States. It's crazy. Stop. Read what it says right now and ask yourself. Does this seem legitimate?

Chris Ryan: [00:05:02] Right. I think that in those circumstances, it's very different than when you get an email that says your cousin is being held in the UK, and we need money.

Obviously, those have gone down a little bit with the lack of travel, but there's various scams that are out there. But when you see Kanye West or a celebrity, Elon Musk saying to do this, that's something that really is it would seem to make sense to somebody, right? That's something that they would definitely fall for. I think In these times, you always need to be cognizant.

Going back to the vaccines again, do your due diligence. I'm not telling people to get the vaccine or not get the vaccine. I think it's a good idea and I'm going to do it, but you need to do your due diligence and to go through and become educated and to listen to people about the vaccine. Listen to people about what's taking place in this environment, regards to hacking, and make your own best decisions.

Craig Peterson: [00:05:54] Yeah, absolutely. In this case, he was facing a 10-year sentence. A lot of people fell for this. He entered into that plea deal. Unfortunately, Chris, we're not seeing enough prosecutions of this because so much of, it's hard to prove. Hard to track down. When it comes to hacking these accounts that are very prominent, they showed up the next day at this kid's house and arrested him. He wasn't being very careful about it.

We do have to be ultra-careful. Particularly, now we have hospitals that fell for these scams for personal protective equipment. Where it was being sold supposedly. They paid the bills, it never showed up. We're getting anxious about things. We're even seeing it now with vaccines. Just like this morning, Justin, how much did you pay to get that vaccine registration?

Chris Ryan: [00:06:44] At least a hundred dollars

Justin McIssac: [00:06:47] Yeah. $0.

Craig Peterson: [00:06:50] That's a scam it's happening right now, too. So be careful everybody.

Chris Ryan: [00:06:54] Craig, as always. Thank you so much.

Craig Peterson: [00:06:57] Take care.

Chris Ryan: [00:06:58] Craig Peterson, joining us here on Hampshire day. He hosts Tech Talk at 11:30 AM on Saturday.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

I know that I have been telling you about this course that I have been making for you -- Guess what it is done and this week, I will be making it available. It has taken a lot of work for both my wife, Karen and me but it is well worth it to get you this information on how you can Improve your Windows security. I walk you through all the basics of tightening up your security on Windows 10 and not only that but why you have to. his week was quite busy for me with meetings and presentations for my business. If you have not yet signed up for my email list do so today and you will be getting a large discount coupon for the course. This will be the only time that we offer this type of discount so be sure you are on my list before we release the course.

Craig

Welcome!

Today we will talk about Intel and its war with Apple and what they did that they believe will give them an advantage but might just backfire big time. Then we will talk about DDoS attacks, BEC attacks, and Ransomware. Then we will discuss how hackers are trying to get into Apple by trying to attack their developer's computers. If you have been breached -- what did you learn you might be surprised. Then what can you do if the Feds buy all your location data from one of their security consultants? How much do you trust your security vendors? All that and even more, so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Intel hires Justin Long to mock Macs in throwback to 2000s “I’m a Mac” ads

~4,300 publicly reachable servers are posing a new DDoS hazard to the Internet

Ransom Payments Have Nearly Tripled

Attackers are trying awfully hard to backdoor iOS developers’ Macs

What CISOs Can Learn From Big Breaches: Focus on the Root Causes

FBI: Business Email Compromise Cost $1.8B in 2020

One company wants to sell the feds location data from every car on Earth

Tech Vendors' Lack of Security Transparency Worries Firms

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, I did a webinar this week for the Massachusetts society for healthcare risk management. I thought there were some things that everybody needs to know, not just healthcare providers.

Hi everybody. Craig Peterson here. Thanks for joining me today. There is so much to talk about. I have such fun doing it too, which is great. We will be discussing this in some more detail and the ransomware numbers are just scary.

I was approached to give this webinar. You probably know if you've listened for the long time that I have done hundreds. If not thousands of webinars over the years. I have been doing them for our friends at the FBI InfraGard program.

I did them many times, two, three, four a month for years with them all on cybersecurity. Plus, I do the free webinars for. People who are on my email list. I send out little audio grams every week as well, where I do a deeper dive, three minutes or so into a specific topic. It's really fun. I enjoy doing it. So I get approached all of the time, as I'm sure you can imagine doing these webinars for different organizations.

I am always glad to do them. It might take me a little bit of time to schedule it into the schedule. You know how that goes, but I always end up doing them. This particular one was about risk mitigation because that's what these guys do, right? There's this society for healthcare risk management. How do identify the cyber threats? What are they preventing unauthorized access to PHI, which is your patient health information?

Now, we all have personally identifiable information that's supposed to be protected and so is our healthcare information. So that's what we talked about, it was really fun to get into some detail, but there are a few things I wanted to bring up here with you guys. We're going to be including them this week.

By the way, if you haven't noticed in my emails, I've been mentioning this Improving Windows Security course that is starting this next week.

If you responded to one of my emails over the last few months where I said, Hey I'm going to be doing this course on Improving Windows Security. I would have probably responded to you saying, okay great. I'm working on it. We have been for months and because of has been months, what we're going to do for people who have asked for this already in responding to the newsletter that what I am going to do is give you guys coupons for this.

So keep an eye on your email box. Everybody else. Okay. You're not going to get quite the deal. Actually, if you sign up today or tomorrow and get that newsletter should be going out a Sunday morning. Just respond and say Improving Windows Security so that you can get the full course, not just the free stuff that we're going to be giving.

Man, you're going to love this anyway. It's just Craig peterson.com. If you want to sign up for that. I do these all of the time.

One of the things that really stood out to me and I thought I would talk about actually, there's a few things is the security breaches in healthcare, because we all have some form of health care.

If it's Obamacare, and guess what? Obama isn't your doctor. He's not seeing you, right? You've got a local doc. Sure. You go in, you talk to your doctor or they examine you. Maybe you have to go to the hospital, outpatient, whatever it might be. There are records of yours that are private, and there are people who want to get their hands on those records.

Why is that? First of all this statistic just absolutely blew me away. A research company called black book market research, and surveyed about 3000 security professionals from healthcare provider organizations. 96% of those people who were surveyed believed that the bad guys are outpacing healthcare security, 96% of them. Isn't that just amazing?

56% are relying on medical devices using Microsoft windows seven. Seven hasn't been supported in quite some time. Eight isn't supported 8.1 has some support for it, but nowadays you pretty much have to be on Windows 10. If you want any support that is astounding. When you get right down to it.

We also have the problem of medical internet of things, devices, M I O T think about, again, all of the devices a doctor uses. Now they might have an iPad that's relatively safe, but have you noticed there are Bluetooth thermometers now that they might use to check your temperature? Did you notice that even people who are in intensive care might be hooked up to an IV those things are connected via wifi and Bluetooth? The x-ray machines, the cat scans, everything now in the doctor's offices. Practically everything is electronic is hooked up to computers.

We're helping a medical office right now doing a bit of a transition on their phone system so that they have integrated with their phone system. Now, automatic text reminders. If someone calls in or the office calls out, all of that is logged in the patient records, screen pops that come up and tell them, Hey okay is calling in and it shows all of the records before they even answer the phone.

56% of healthcare providers are using unsupported operating systems. That's just on their computers. Most organizations don't even know what is inside their machines. Cause you remember almost every machine nowadays has a computer on it. Then on top of it, they're using this 20-year-old antivirus software and insecure systems. They're really not vetting things, failure to access. It's just absolutely crazy.

Now the bad guys are able to get in about 86% of the time. That's according to Verizon's 2020 data breach investigations report. That's just crazy. 86% of them are about money. The attackers usually take the easiest route to obtain all this information that they need.

43% of the breaches are due to the cloud. How many of our businesses are saying Oh, I'm going to use the cloud. I'm going to use salesforce.com. This is an example. I'm not trying to pick on salesforce.com. They've had their problems, but so has pretty much everybody else it's. We're gonna use salesforce.com for all of our client records and emails going out to et cetera, et cetera.

That's just a word for someone else's computer, the cloud. It is a computer. It is still existing out there. You cannot, whether you're in healthcare or you're a regular business, you cannot just push off the responsibility for your data to a third-party cloud provider.

Now in the medical business, they have these business process agreements, BPA partner agreements that say, okay, you Google, I'm going to be paying you extra for this special healthcare version.

So they pay extra and they get that special healthcare version. And Google says we will keep your data safe. Oh, okay. That's well and good, but you have to pay for that version.

43% almost half of the breaches were due to people trying to use. What's called the cloud.

27% were attributed to ransomware. It is running rampant and we'll get into some of those stats here in a minute.

This is the part that I would think everybody needs to hear and that is your patient health information worth 20 times more than credit cards are worth. Did you hear that? 20 times more, 2000% more than credit cards.

So you might ask yourself why does that matter? What's the big deal with my patient information? If they have your credit card, they can use it a few times, hopefully, you'll notice it pretty quickly. You're using something like a credit monitoring service to notice, Hey, wait a minute. What's going on here.

If they've got your social security number, they could potentially buy a house or a car in your name. You don't know that they bought a car in your name until the tow truck shows up asking for the car back. Because it's now being foreclosed on, but guess what? You don't have it. It's not yours.

You have to spend 300 hours trying and straighten it all out and clear up your name? But when it comes to PHI this patient's health information, probably has your social security number. Remember when you fill out those forms when you go to the doctor's office, criminals can pull off stealing your identity that can go undetected for months, but it's even worse than that, frankly, because if they have a child's information, Oh, so again, we're talking about a birthday to name and address a social security number because you remember the government's forcing us to get social security numbers for all of our babies as they're born.

Yeah. So they've got that social security number, which will never be used to track us. Will only ever be used for social security and can not be asked by anyone outside of the federal government and the social security administration.

Another promise from the federal government was completely ignored.

That child's personal information can now be used for at least 10 years, probably closer to 15 years by a bad guy. It can be sold to illegal aliens who now have a name social security number and maybe a fake birth date because they're really a little bit older than they appear to be on that birth certificate. That's why it's worth 20 times more.

It's really something's going on.

All right. You are listening to Craig Peterson. We're talking about our health care information. We're going to talk a little bit more about that.

We all have healthcare records and they have some of our most personal information. That's what we're talking about today in follow-up to a webinar that I did last week for the healthcare industry. We're going to talk right now a little bit more about your privacy.

Hey everybody. Thanks for tuning in, Craig Peterson here.

Getting right down to the real hard stats here on our healthcare records, a lot of them have been stolen. We covered that, of course, in the last segment. If you miss that, you can catch that online on your favorite podcasting app. I'm pretty much everywhere, nowadays.

It's just crazy to think about because, in reality, we have had millions of records stolen, 300 million healthcare records stolen to be exact since 2015, which is pretty bad.

I'm looking at a chart right now that I showed to this healthcare industry group that showing that the hacking event has almost doubled over the last three years, year to year, every year. So in 2018, 164 major hacks, 2019, 312. That's a good double. 2020, 430, which isn't quite a double. So we are seeing a lot of data being stolen. Of course, stolen data means misused data, which is a very big problem.

Now, in the healthcare industry, they've got a separate problem. That is these HIPAA rules. Now HIPAA has been in place for quite a while. It's supposed to have been provided portability of our records. Does anybody have any real luck with that? I know there are some I haven't.

Portability, I don't even know where my health records have ended up. Frankly, cause my doctor ended up closing up shop and I just have no idea. But it's supposed to be portability and privacy. Well, the most common violations of these HIPAA regulations revolve around professional hackers.

Then you've got business associate disclosure. Remember I mentioned that. The cloud is not an excuse for not protecting your data. You cannot hand that off to a third party. There's many more that I go into in the presentation.

Of course, I talk about some of the ransomware that's been going around the fines they can get from some of these.

Then here's the next thing I wanted to talk with you guys about. And that is the amount of ransomware out there. I'm going to have a little bit of a ransomware offering. Take a look in some training and stuff here. Take a look at your emails. If you get my newsletter, it'll probably, I'm going to try and get this in for tomorrow's newsletter.

The one that comes out on Sunday, if you're not a subscriber right now, go to craig peterson.com/subscribe. You'll actually see it on the site @craigpeterson.com. If you scroll around, do a few things on the site, it should pop up automatically for you.

I'm going to make a note to myself here about the ransomware stuff. So you guys can hop on and get more information about how to protect yourselves too.

Now we're just talking about healthcare and of course, this is every business and every person out there.

I talked about this Conti gang. I don't know if you've heard of them. C O N T I.

Now, remember what I've said before about ransomware. It used to be that you'd get ransomware. Your computer would now have it's data encrypted, and then it would pop up this big red screen up that said you've got ransomware in order to get to all of your data back because what the ransomware did was encrypt it. You need to go to this website. You need to pay this amount of Bitcoin to this Bitcoin wallet and off it goes, right? That's the idea.

According to the FBI, about half of the time, you'll get all your data back half the time. That's even if you pay the ransom. And now, too, that the. The State departments might come after you, and the FBI, if you pay a ransom because now you are supporting terrorist organizations, not just criminal enterprises very big deal.

Now the other side of ransomware, and this is what just hit with a few different medical providers here. What I talked about was the Rehobeth McKinney Christian health center services, New Mexico, because now it's much more advanced instead of just getting on your computer, encrypting your files, demanding a ransom to get the decryption key. They even pre-install the decryptor for you. Isn't that handy? Yeah.

What they are doing is they get onto a computer and then they start East-West spreading. Now we've seen that for years. I remember one of our clients, a car dealer, and this was five-seven years ago. They got some ransomware. Somebody clicked on something that they shouldn't have, and all of a sudden their machine gets ransomware. The machine, of course, is hooked up to the network and. It is also not just hooked up to the network, it is in fact, mounting drives from their file server. So his machine has access to all of these files. This guy was a manager over there at this car dealership. So he had access to all of the files.

Think about that for a minute. What his machine did back then is it said, Oh great. Here's some network drives. It started encrypting the S drive and the H drive and the K drive. All of these different letters for these SMB mounted drives from the file server.

We were in there beforehand and we installed our security stuff. When his machine got this brand new strain of ransomware, and of course he didn't want us looking at what was on his machine. So we couldn't install all of the antivirus software because then we would have access to it. We've got another client that's like that too, where the owner of the business doesn't want us installing software to really keep his machine clean.

I don't know why people do that. It just, are they just trying to play their cards close to the chest? Is that what they're trying to do? Are they looking at something they shouldn't be looking at work or ever? Why do people do that?

If you got hints, let me know. Cause I would love to know me@craigpeterson.com. Why do people do that?

Anyhow, his machine got the ransomware. It tried to start spreading to the file server. Now, we had special hardware and software installed. So we saw that spread start. We immediately shut down. It was all automatic. It was just shut down. I shut down his network port, in fact, so his computer can go anywhere.

His computer had the ransomware. We were able to just go ahead and restore from backup. The bad guys know that if all they're doing is encrypting your data, then who cares? You restore from backup.

Now, hopefully, you're following a three-two-one backup scheme. Most places don't. Hopefully, you're testing it as well. We test every backup that we make for our customers every day. We usually about once a week, will, if it's a server or even a workstation, we will spin up the servers in a virtual environment and make sure that it can boot so that we know we have a good backup. I got to tell you guys, most of the time the backups are not working and it gets to be a real problem.

What these guys have figured, including this Conti gang is we're not going to be able to get as much money out of them by just encrypting their discs. We need to do something else. So while they're trying to spread East-West inside, what they're doing is okay, so they got a hold of this manager's computer. They start scanning for other computers and scanning for vulnerabilities scanning for ways it can gain access.

Unfortunately, the statistics show us that most of us have file share turned on our windows machines. That's one of the things I talk about in my Improving Windows Security course, what to do, how to do, how to turn that off because that is the second target of ransomware. Once it gets onto your machine.

You've got to turn off those file-sharing services. So we'll tell you what Conti and these other guys do once they're there in, and they have found another machine. Maybe it has filesharing services. Maybe it's good old-fashioned vulnerability because nobody patched.

Man, I can't believe how fast this computer is. We just did an upgrade on my iMac here in the studio. It is blindingly fast now.

But we're talking about. Ransomware and what's the Conti gang and others doing, nowadays.

Hello everybody. Craig Peterson here.

Thanks for joining us today. Appreciate you spend a little bit of time and I enjoy helping to bring you guys up to speed on what is happening. There's just so much of it. You wouldn't believe what I have to filter out.

The Conti gang have been very successful, but their money started to dry up fairly recently when people figured out if they had a decent backup, they could just go ahead and ignore the ransom demand. Instead of paying that ransom, just go ahead and restore from backup. So they had to do something different.

What the Conti gang did, as well as pretty much everybody else in the ransomware business, is okay, what we're going to do now is we're going to find all of the other machines we can find on the network. Then we're even going to have real people get onto these computers remotely that they've compromised and have a poke about. See is there patient healthcare information? Are the bank account numbers on this machine? Are there plans on what to do? Where to go? What's the business going to do next week?

But particularly stuff they can sell right away. If you take credit cards, you know that the payment card industry is all over you if credit card numbers are stolen. Those are nowhere near as valuable as patient health record information. As I mentioned a little bit earlier, we're talking about 2000% more than 20 times more value to your healthcare records.

Now what happens is the Conti gang says Oh looky. We've got patient information here. It has names, addresses, social security numbers. It has birth dates. It has diagnostic information, and then they upload it.

We had something like this happened with one of our clients. It wasn't a ransomware attack, ultimately may have been. They came in through an unsecured VPN and that they would not let us shutdown. We told them to shut it down and they didn't.

In come the bad guys, they actually were coming up via Mexico in this case. Although I doubt they were located in Mexico. They took that VPN connection, they used it now to get on to the computer and found something interesting. So they started to exfiltrate the data.

In other words, Take that data and send it out. That's exactly what the Conti gang and others are doing now.

We noticed, wait a minute, this is all automatic. Why is data going out from this host at that speed to this address at this time of day? It wasn't a normal pattern. So our hardware-software that's sitting there in their network automatically shut it down hard.

They were able to exfiltrate just a tad bit of data and then it was stopped instantly.

That's what they're doing nowadays. So the Conti gang gets your data and then they try and say pay up from an extortion standpoint. Instead of just holding your data ransom, they're extorting you. Saying, if you do not pay us we will release this data. The Conti ransomware gang has its own website out there. It's called a leak site. There are many of them out there.

If you go to that site, I'm not going to give you the URL. It's right there. There's their logo. Conti gang has a logo and it says Conti news. It's talking about how you can make your payments to them and what data was released and that this person paid up, but it was too late. We don't have the data anymore, which means it was released and too bad. So sad. I wouldn't want to be you.

Here's another ransomware gang. I've talked about with the Massachusetts society for healthcare risk management in this webinar, and that's the Avedon ransomware gang. So again, they had stolen personal information. They had health information and they had not just the ransom side, but the extortion side built into it. This was in relation to an attack on the Capitol medical center in Olympia, Washington.

They have leaked some of it they're threatening to leak even more. If Washington Olympia capital medical center doesn't pay up.

Now, I went through here with Karen, helped me out with Karen and we got some other stats.

First of all, 70% of the time now, ransomware results in data exfiltration. In other words, 70% of the time, your data is stolen prior to the file encryption. Pretty bad. Pretty bad. Things can get particularly harmful because these ransomware attacks are a growing concern. They're disrupting patient care and healthcare, right?

Disabling critical systems because they have been even holding ransom some of the diagnostic equipment, MRI machines that were connected to the network. There were running Windows. Who would use Windows in the machine that's healthcare critical?

Obviously interrupt revenue flow and they had to now go get involved with real expensive remedies. It really puts him in a very bad spot, very bad.

We've had almost double the number of healthcare institutions attacked this year versus last year.

I'm not going to go through all of these things here. I explained to them the difference between some of these real sites and fake sites and how you can get access to it.

By the way, if you're interested in this, I did record this, I'd be glad to send it out to just let me know, just email me@craigpeterson.com and I can send you some of this healthcare stuff, the slide deck, or whatever you might like.

Phishing campaigns, way up. You probably heard about that. I gave some examples of that emailing patient information without encrypting it. Wireless infusion pumps are, of course, compromised because they're running an operating system that hasn't been patched. Usually Windows. Think of that there's Windows in that infusion pump, but it could be a version of Linux. It's not patched. It's crazy. Vital sign equipment. Oh my gosh.

We're also seeing that this patient's health information being stolen now is being used to create fake insurance claims.

You might've been wondering in a previous segment here, I was talking about how. Much this is worth and it's worth a lot while this is one of the reasons it's worth a lot, your personal, private patient health information.

If you have a diagnostic info and that diagnosis has been stolen, and then they can file a health insurance claim. Yeah. You see where I'm going with your information as though you received some treatment or some care for the diagnosis that was in your healthcare records. It's just that simple.

The average cost of a data breach right now, by the way, if you are a regular business, it's $158 per record for non-healthcare and it's $408 per record. If you are in healthcare at all.

That's a doctor's office. That's not just hospitals, it's anybody. And by the way, mobile breaches are really big 43% of healthcare organizations who reported a mobile breach, said the mobile breach caused long-lasting repercussions.

Now, think about this. If you're a patient. How well are your records protected? I can tell you based on what I've seen and talked with healthcare, people have seen statistics they're not protected very well at all.

People will start going to jail over this. People in the healthcare industry that is.

So just in case, you were thinking that couldn't happen to you.

I'm gonna spend a couple of minutes now talking about what happened a long time ago, in February. 2021 with healthcare records. This is amazing.

Hi everybody. This is not the healthcare network. No, it is not.

I'm looking at these slides that I had put together, of course, based on research that I did, for the Massachusetts society for healthcare risk management.

It was an online webinar. I do webinars all the time. I do them for listeners where we talk about something that's hot in the news. You might see me doing various lives. I haven't done one in a little while.

Do you think I should be doing Facebook lives or YouTube lives? I know a lot of people have a real problem with Facebook. That's certainly understandable from my standpoint, but do you think it's worth it?

Get on and I can answer questions and things. Let me know me@craigpeterson.com. I've done them before. I usually get a handful of people on. I'm not sure how much it's worth or not.

They are coming for you when we're talking about the health organization. So as healthcare organizations. So we're focusing on the bigger ones because that's who I was presenting to. I always make these slide decks. This one took me a week to put together right. Karen and I because there's so much research and I know I shouldn't spend that much time on these things, particularly if I don't charge for them, but I've got to do it.

I was talking to a friend of mine who's an attorney. He said, do you know what? You would be one of the richest men in America if you did not have morals. Oh my.

February 2021, we had Gore medical management out of Griffin, California, with 80,000 people affected. Nevada Orthopedic and spine center. Las Vegas, 50,000 people. UPMC life-changing medicine out of Pittsburgh and only 40,000 people there. Remember, this is February. 2021. Oh, wait. There's more Grand River Medical group out of Dubuque, Iowa, Harvard eye associates out in Laguna Hills, California, Texas spine consultant out of Addison, Texas.

UPMC Health plans out of Pittsburgh, PA. Granite wellness centers, Grass Valley California. Granite is Northeast, people. Aetna Hartford, Connecticut. Isn't this something, February 2021. 12 Oaks recovery center, NAVAIR Florida. Pennsylvania Dalton teen challenge in Pennsylvania. Data Logic software, Harlington, Texas.

Yeah, it goes on here. The house next door, Deland, Florida. Project Vita health center, el Paso, Texas.

Just in February.

Lake Charles Memorial health system, Lake Charles Louisiana. UT Southwestern medical center, Dallas, Texas. Hackley community care center out of Michigan. Rainbow Rehab center, Lavonia, Michigan. Jacobson medical hospital care center Elgin, North Dakota. Pitkin County, Colorado. Piedmont health services, North Carolina. Hope healthcare service, Fort Myers. I like Fort Myers. Jacobson Memorial hospital and healthcare in Elgin. You getting you guys getting the gist here and you pick it up what I'm putting down.

Jacobson Memorial hospital. This was a data accident involving an employee email account potentially exposing current and former patient data to authorized individuals.

You know what, the number one question I had. I got to put that together. Let me just jot this down so I don't forget. Gmail. Doctors.

The Number one question I had was how do we stop doctors from using their Gmail accounts? That's the same type of thing that happened on February 23rd, 2021, right here, where they were forwarding email and this happens.

We see this all the time. Somehow doctors think, I dunno, they're immune to these things, or it's not going to happen to them. I don't know. An email comes in and it comes into a secure email system. Then the doctor configures it to forward his email that comes into the secure clinic, his doctor's office, whatever it is, forwards it to Gmail.

What happens at that point? It's now in Gmail, it may or may not be secure. If you're not paying Gmail for your account, you can be pretty sure it's not terribly secure.

There is an encryption standard, an email called TLS and Gmail does not provide TLS services, guaranteed, for free accounts.

In fact, I don't think they provide them at all for Gmail accounts other than the paid accounts. This is an absolutely huge problem. The FBI and the Department of Homeland security CISA came out with another warning here about healthcare. This is affecting all of us because this is our personal information.

Why are healthcare records so much more valuable? I mentioned earlier a couple of things. One is they usually have a social security number, name, and address, so it can be used now to steal someone's identity. They often have diagnostic information. So that means it can be used to file fraudulent insurance claims.

What else can you do with some of this medical data that is stolen? If they have your medical data, it's so much different than your credit card, because credit card you can cancel.

In fact, even if you don't cancel, if you notice you get a new credit card, every what is it - three to five years, new credit card here it is. There's a new number, at least a new code on the back, right? CVC code. You look at that and say new card okay, whatever.

It's such a pain because you have to go and change it on any website or with anyone that's doing an automatic ordering.

But when you get right down to it, What can happen if your credit card numbers are stolen? They can run up your credit card. You can, before you pay it, file a claim and say, Hey, someone stole my credit card number. That is bad. I did not authorize these charges and they will back out the charges for you, right? You haven't put a dime of your own money out there.

Now, a debit card. Yeah. They've taken your money and now you got to fight a bit to get it back, but you can get it back from all the major credit card issuers, but you get a new credit card number.

What happens if your social security numbers are stolen? Did you know that the social security administration will not issue you a new social security number? Is your number stolen? Did you know that?

How about the rest of your information? Most people live in a home for at least 10 years, not longer. That's a lot longer than your credit card number's going to be around so they can now again, continue to file for loans under your name, your address, your birthdate, maybe for the rest of your life. This is our personal information.

And as you probably noticed early on, I was talking about how upsetting it is to me that we have a national ID stamped on our forehead effectively.

We have a social security number that we now have to use for everything it's called a social security number because it was put in place for this Fake insurance program that the federal government put together because it's not an insurance program. It is not run like an insurance program. They put it together and they called it social security. They gave you a number because they had to keep track of your account. And really it was your account number. Now it's used everywhere. There's proposals out there. Hey, let's come up with a digital ID, a digital identifier. A digital passport, if you will, as though that's going to solve the problem. The problem is we now have our data stolen. It's already out there. It's everywhere. Can you imagine what China might be thinking about doing with it? China has been, it's been verified now. China has stolen the records of pretty much every federal employee, every background check record of every background check that was done for clearance via the FBI. What's going to happen if they decide they really don't like us anymore and they just let loose?

What a great way to shut down our economy. Like overnight, by all of a sudden creating millions of fake accounts. Using real identities, our identities. This is just nuts, it is absolutely nuts.

We've seen these hacks and we just ran through some of the healthcare hacks that happened in February of 2021 one month. These are the ones we know about. Most of them are in fact, probably not reported at all. Add on top of that, now we have doctors that are working from home that are using what we're calling loosely, telemedicine. They're getting onto platforms that were never designed to keep our data safe is not HIPAA compliant. They are exposing our data even more than ever before.

I don't have the answer for this, because they are not, I can guarantee you, they are not pounding down my door to have me come and help them. I could. That's what I do. They're not. In fact, when I reach out to most of them they hardly care at all. Not a big deal, right? Not going to happen to me, can't afford it. Yet they're pushing all of this burden onto us. It is extremely upsetting. Something has to be done. Something has to be done about healthcare. We need to enforce these HIPAA rules and regulations, and people need to go to jail for blatantly ignoring what they've been saying, by signing these forms, blatantly ignoring what they've been saying. They've been doing now for what 20 years?

Visit me online. Craig peterson.com. Make sure you get on that newsletter so that you don't miss a thing.

I think we beat healthcare to death in the last hour.

We're going to be getting into a bunch of new topics here. This whole thing about Intel hiring Justin Long has stuck in my craw too. So we'll start with that.

Hi everybody, Craig Peterson here. Of course, it sounds like its a stuck in my craw week, but we got to keep you guys informed and it just really irks me, that so many businesses are trying to do the right thing. They are spending money. They're getting training for their people. They're getting the right kinds of equipment. They might be buying stuff from me or whomever. It really doesn't matter. They're trying to do it right. That costs them. There's no question about it.

They are competing against people who don't care. That's what really bothers me. They're competing against people that are barely spent a dime. Maybe they bought a SonicWall firewall 10 years ago, but that's the last time they did anything for security.

To me, that is a sin and should be a crime. If you've got a company, like maybe you've got a DOD contractor, and they've spent 200,000, maybe as much as a million dollars if their really quite a bit bigger on just trying to secure their networks and okay they sell to the DOD, but they sell to a lot of other companies as well.

How do they compete? How do they compete against somebody that just hung up a shingle and is out there selling a competing product?

Nowadays, you can't tell. This is an old one, right? Do you remember the Lycos commercials on the internet? No one can tell you're a dog. That's exactly what this is about. No one can tell going to the website. How good are you? How long have you been around? How much have you spent on cybersecurity? Is it any good? It's just nasty. It is really bad, bad stuff.

We are getting attacked so much. Ransomware attacks have tripled in 2020 and remember ransomware isn't just ransomware anymore. Most of the time it's also got extortion built-in. It's just crazy.

Make sure you are on my email list. If you're a home user, that's great. There's lots for you to learn. If you're a business that's great, there's lots for you to learn as well, and I'll let you sort it out. But even when I have stuff specifically for business or targeted to business concerns, there's stuff you can learn from it as an individual.

I want you to pay attention to it, but you can only do that if you have my newsletter coming to you every week. Of course, the best way to do that is this go to my website, Craig peterson.com. You'll find it all there.

I appreciate you guys. I, again, I just can't say it enough. You have been great. I appreciate all of the feedback I get and I answer all of the emails. Again. It might take me a little while it usually takes a few days. But I do answer them and I answer them personally. Most people are really shocked when they get a newsletter, they hit reply. I replied to them. Thinking that I must be some big internet marketer, which I'm not, I'm here for you.

I appreciate everybody that signs up for the list. You guys referring to people. It's interesting. Every time I send out my weekly newsletter, I get even more people signing up for the newsletter. So you guys must be forwarding it to your friends. Who is then signing up? I really appreciate that too. Cause I want to get the word out. 99% of what I do, what I say, is absolutely free to anybody who will care to listen. It's there for you. I really do want to help.

You might remember these commercials from way back in the two thousand in the double ots, triple ots. Hello, I'm a Mac and I'm a PC.

Hey Mac. Did you hear the good news PC choice chat? Sorry, I didn't hear you there. What'd you say, allow me to introduce the top-of-the-line PC? Okay. What are you doing in a pizza box? Go on, rip it in half. And since it's beautiful that he needs an upgrade and I'm having a very difficult time finding pictures of my friend. I couldn't hear you through my virus-proof mask. Bongiorno. Hello. Let's go to the commercial. We are a commercial. Let's go to another commercial, your first class, all the way PC and Danesh. You are banished.

I have to chuckle when I hear those. Isn't that great? Those are just excerpts from some of those commercials from years ago. Of course, get a Mac.

What Apple was doing at the time performed by John Hodgman. He was the guy that did the PC side and Justin Long, who was the guy that did the Mac side saying I'm a Mac. It's fascinating to me now that Intel has decided to go ahead and hire Justin.

Now what's most fascinating about it is that Intel hires Justin. Wait, what are we comparing here? A PC is when you think of it, it's Windows, right? You're not thinking about Intel inside. You're buying a Windows machine. You're not buying a computer because of the chip it has in it, most of the time, right? You might buy this is when I said faster chip or that one has a slower chip. That makes a lot of sense.

You're buying a computer so you can run an application. I remember very well back when the Apple two came out, the two-plus and people bought them in droves because of an application. You could get VisiCalc on there, a spreadsheet program. It was the first, it was the best. It was the most popular at the time. Then others came out that were arguably a lot better. But it still sold. VisiCalc still sold and went over to the Windows platform.

So Justin is now doing commercials talking about Intel. So he's saying on the Mac, you can't touch the screen, which by the way, you can if you get a touch screen for the Mac, No two ways about it.

I have one sitting right in front of me. I use this on my Mac it's a touch screen. I use it for doing presentations. I can highlight things, move things around, touch things, open them up, click on them with my finger right there on this screen.

None of those have anything to do with the fact that inside that might be an Intel processor.

We've got Intel now out there with I think misleading, but potentially you could argue, that they're misrepresenting Intel. All Intel is doing is providing the main processor maybe some other support chips on there. Maybe it's using Intel memory. I don't know, but in reality, what we should be comparing is our Mac, our Intel-based Mac versus our Intel-based Windows computer. Remember Macs will still run Intel.

I just gave it away. Did you catch that?

What's really going on here. What's really going on is, Apple is upset with Intel for some very good reasons. Intel has been massively overcharging for its processors for a very long time. Intel processors have never been that great, frankly, but because of what was called the WinTel monopoly.

Intel really went along for the ride. They went along with the ride with Microsoft because people bought Windows so they could run Excel or whatever the other applications were, that they wanted to run.

So what has Apple done? When Apple came out with the iPhone, it never had an Intel processor in it.

The same thing's true now, with all of the new Apple equipment that's coming out. So your I-phones don't use Intel processors, your iPads, don't use Intel processors. I have sitting right in front of me, a Mac mini that has an M1 processor from Apple. And in fact, Apple right now is trying to get rid of Qualcomm as well. It can help increase their profit margins, but these things are not easy to design and implement.

It took Apple years to get to the point where they had one that was really quite a good processor. I can buy a Mac mini with an Apple processor in it that is better than a hundred percent faster than a Mac mini with an Intel processor, for less money.

The Apple chip costs me less money than the Intel-based processor and it's twice as fast according to Adobe, who just released their performance metrics on illustrator and Photoshop.

Intel is getting very nervous because they're seeing their business go down the tubes. Intel has not been able to deliver on lower power processors. It has not been able to deliver on faster processors other than going to multiple cores. It's also having problems with manufacturing, the smaller, thinner, and thinner processors, which help with of course, using less power that makes them faster and they have less heat.

Intel is saying, Oh my gosh, we're in trouble here because even Windows runs without Intel processors now. You can get a surface tablet that doesn't have any Intel in it and run windows on it. So they're in trouble there.

They're seeing to the market share that's being taken from Microsoft by these Google Chrome tablets. Chromebooks, which are laptops, which are very inexpensive, very fast, very user-friendly, and very secure.

Although, Google does spy on you a bit and they don't use Intel.

What does Intel do? We're going to hire Justin and make people very confused about what's really going on.

Don't worry about those ads, stick with anything you need to use. If you can get out of the space of windows. Get out of this space of Apple. Go with something as simple as you can. Maybe Linux, maybe ChromeOS.

Hey, it's 2021, and ransom payments have nearly tripled then targeting many factoring healthcare, construction and the average ransom is now $312,000.

Hi everybody Craig Peterson here. We were talking a little bit earlier about ransom and ransomware gangs. We've talked about how it can just totally destroy somebody.

If you're a home user and let's say that they get onto your computer and they encrypt all of your photos your grandpa, grandma, your parents. You've got pictures of the kids and grandkids, great-grandkids, whatever it might be on your computer. Now, they're demanding $10,000. If you ever want to see your pictures again.

That is a very good reason to have your photos and other documents you care about somewhere else, not on your local computer.

I know far too many people who hook up a local hard disc to their computer and then back up to it.

They're backing up to a USB drive that just isn't going to cut it. That USB drive is attached to your computer. If your computer gets ransomware on it, it's going to encrypt your USB drive.

That's why I advise people if you are going to have to use a USB drive, let's say you've got a database that you have to open, but you don't have to have it open all day long. Put it in an encrypted volume and only mount it up and decrypt it when you're using it. Then go ahead and re-encrypt it when you're done.

That's called data at rest. The idea is when you're not using it, nobody has access to it. That's what you should be doing. Remember too that if you still have that disc plugged in, and if that disc is encrypted, they can still encrypt it and hold you ransom. But they're not going to be able to do the extortion because the data they have is encrypted. They have no idea what they have. They may not even grab it because some of this ransomware software is just that smart.

Ransomware gangs now that are aiming at businesses are grabbing even more money than they've ever been able to get before. The average amount that's paid, jumped 171% in 2020.

There's a new report out from Palo Alto Networks. They provide all kinds of networking equipment. You probably know, I already use Cisco primarily we've used some Palo Alto. We've stuck with Cisco. I like that integrated environment, but Palo Alto is good. Just not great.

Palo Alto uses data from ransomware investigations, these data leak sites, as I mentioned earlier, where some of these ransomware gangs post to the data that they have stolen from people. Those are called data leak sites. They looked at some of those things to try and figure out what's going on out there in the industry.

They found that these main industries, which are manufacturing and healthcare, construction companies had almost 40% of all ransomware attacks in 2020.

It's just amazing because again, the ransomware attacks are being fine-tuned to go after organizations that have data that is very valuable. The highest ransom paid that we know of was $10 million. Isn't that amazing. The highest ransom demand was $30 million.

Almost a third of the average demand paid more than $312,000. So it's just crazy. When you start looking into this and these ransomware groups are really getting ahead of the defenders.

They are using all kinds of different types of innovation, which is again, why antivirus software does not work. I put that into my presentation. In fact, I had in the presentation here, some slides with John McAfee, I had him for one of them, and then I had a quote from now trying to remember what he was. He was a high-end guy in Symantec which makes Norton, and both of them said this, "their software is just useless" bottom line. It's useless because these ransomware gangs are using different techniques, different styles, they're improving things, pretty dramatically, frankly, and getting these ransoms up higher and higher. By the way, they are still being paid using cryptocurrency and that surged 311% last year.

By the end of 2020, ransomware payments began to decline. A lot of that seems to be because the victims don't believe they're going to be able to get their data back, which is correct as I've mentioned before.

Be very careful out there. If you are a victim of ransomware, realize guys, you're probably not going to get your data back even if you pay. Also, realize that there is another extortion coming your way in most of these cases. That extortion is to pay up or I'm going to release your data to everybody. Then you're going to have to decide what to do. Cleaning up after ransomware isn't cheap. The average cost of forensic engagement is over $73,000 for enterprises and 40 grand for small and medium businesses.

It's pretty bad what they're doing right now. All right next up here. We've got attackers who are going after specific targets. Now I mentioned that just now, but in this case, what they're doing is they're trying to get back doors into iOS developers' Macs. Here's how it works.

If you have an iPhone or an iPad that is running an operating system. That's based on a Unix kernel called iOS that's Apple's operating system for those mobile devices. It behaves differently than the desktop operating system. That makes sense, right?

Windows trying to shoehorn in the touch screens without really considering all of the implications of that, I think was a huge mistake. If you want to go back many years in Windows eight when they introduced tiles. On my archive, you will find me saying that very thing. However, If you are a developer for iOS, you're not going to be using Windows. You are going to be using a Mac.

What the Mac developers use is something called X code. This is a developer tool that Apple makes available to developers who are writing apps for iOS or Mac OS, as well. The bad guys are doing a supply chain attack and they are putting fake libraries that are being used by the developers, into the developer pool. The idea behind that is if they can get this fake little library in there, they can then take control of any machine that's running that library.

I don't want to get into this too techie here and have people zone out, but it tells you something here that the bad guys, rather than attacking iOS head-on like they do with Windows. They are trying to get into the developer libraries and get in that way.

Now they are, don't get me wrong, they are trying to do this with Windows. It's just usually so easy to use a new zero-day on Windows, as opposed to going into all the trouble to try to get into developers' machines in order to install these back doors. It's also known as a home watering hole attack, and they send this to targeted developers.

There's a visual studio project that's available right now with a proof of concept exploit for some of this stuff, but we're aware of it. We're trying to deal with it. Apple is trying to deal with it. Windows eight is happening in that area as well.

GitHub has seen a whole lot of problems with this type of injection and the whole industry is working hard to stop it. I think that makes a whole lot of sense. All right.

Let's talk about selling the feds, location data from every car on earth. Does that make sense? I don't know.

Apple made a change in its podcasts. We'll talk about that as well.

Hey, are you somebody who listens to podcasts as well as the radio Apple figured something out to the most other podcasters really figured out some years ago? So we're going to talk about the one-word change. Apple just made it.

You're listening to Craig Peterson here on news radio, WGAN AM 560 and FM 98.5. Thanks for joining me today.

As we've been talking about some of the great articles out this week that I was going to say the great questions that have plagued humanity, but. I don't think that's quite true. There certainly are questions we all need to have answered and I answer your questions as well.

Make sure you go to Craig peterson.com. You can right there. Sign up for my newsletter. You can send me a question if you'd like to right there, or you can just email me M E@craigpeterson.com. I'd be more than glad to answer them. It is a wonderful thing to be able to help you guys out. I appreciate you so much for spending these two hours here with me on your Saturday.

Podcasts are something that Apple really kicked into gear. I've been for more than 20 years doing what today we would call podcasts, and that is making available audio from our radio show. Audio from interviews. All kinds of audio for people to listen to. Many other people do. It has become a huge thing. Now there are millions of podcasts out there covering every topic you can think of talking about long tail, just microscopic and lead nailed down different topics.

Apple had the iPod. You might even remember that. And I still use an iPod to this very day. I still have my iPod classic and I that's the one I use. So it is how old now? 12, 13, 14 years old. I don't know, pretty old. And I've had to replace pieces in it. But I really liked that user interface. It's pretty easy to use.

I have over the years, I've put a lot of different music on there and I've also put podcast. It is an iPod with video, which means that it can play certain videos. It has been a wonderful little device. Because of the iPod and the popularity of people listening to the audio, like my show, Apple was able to really dominate that market. They became known as podcasts because of the Apple iPod. People could carry them around with them.

Nowadays we stream, for instance, you can listen to WGAN on tune-in, which is available as an app. It's a website. You can listen any time anywhere. It just couldn't get much easier for any of us. It's fantastic. You can certainly download them into the app. You can download them into the Apple podcast app that's there on your iPhone. On Android with Google play. In fact, you'll find my podcast on all of those platforms, but what is really different about all of this is that now Apple is no longer the leader.

It looks like Spotify is about to take over the leadership position in the podcast if they haven't already. I've made sure my podcast was on Spotify. I hadn't had it on there. They had changed the rules. I don't know some time ago might've been last week. I really don't know. But they changed the rule since the last time I looked. It was easy enough to get mine on there. I think they wanted me to pay before.

Now I have a podcast that's in the top 10% of all podcasts worldwide, which I think is pretty darn cool, frankly. We're having thousands of people listen every week and that just does my heart good. I stopped doing the podcast for a while and it really hurt me, while it was like a year and a half- two years and I wasn't releasing content.

I really lost traction because I had 20 million-plus downloads of the podcast, which I can still say, because that's true, but I've only had about a quarter-million downloads in the last little while still top 10% of all podcasts worldwide.

What Apple is trying to do now, is try and help people understand a little better and get rid of fear by changing one word in podcast land. If you go to Apple for instance, if you go to Craigpeterson.com/apple. That's what it is you'll see. It'll take you automatically to the Apple podcast page.

Once you're on the Apple podcast page, you'll see that you can listen right there on the page. It might open your podcast app or on your Mac. It might automatically open your music player, they keep changing the names of some of these things and let you subscribe.

If you do, I would really appreciate it.

The word is "subscribe." That word has been a problem apparently for Apple because most people when they think of subscribing they're thinking they have to pay for something. You see where they're coming from. So a lot of people didn't want to subscribe because they didn't want to pay.

Podcasts are free. No one charges you for them. Now, there are some subscription models. Don't get me wrong, but in general, podcasts are free. What Apple has done now is they changed the word, subscribe to follow. Which they think most people will understand. Following someone doesn't cost you anything. That comes from all of the social media platforms that have really changed things up for them. This change to the Apple podcasts app is going to come with the release of iOS 14.5 and. We'll see if it actually makes it in there.

It was noticed by PodNews, which is a website that reports on the podcasting industry. They were showing, Hey, look at this beta version of iOS where they're changing it. So that's how we know it's coming. I think it makes sense.

Edison research I've quoted them before they're a market analysis company. They found that 47% of people who don't listen to podcasts thought it cost money to subscribe to podcasts.

That's true with most of these apps nowadays, you can get it for free, but they also have paid versions. In Tune-In the paid version, lets you pause, live radio, and go back and listen to it later. I used to use that a lot back in the day. You also have different features on these different podcast listening apps.

Most people are confused about it. 47% think it costs money to listen. So Edison research vice president or senior VP Tom Webster said the reason for this is because of the one word subscribe. That's a huge problem with nearly half the people surveyed. Won't listen to a podcast because they think they have to pay for it.

Now, Spotify, which is edging up, if not surpassing Apple with the number of people who listen to podcasts has already switched. They're using the word follow to describe the feature that adds your favorite podcasts to your playlist. Spotify has also played around with this idea of paid podcast subscriptions, which could be separate from the idea of a paid podcast offering. It's a premium paid music and everything else. So it's I think it's going to be interesting. We'll see.

Apple has switched pretty clear to help get rid of some of the confusion on its platform.

Have a look for me, Craig Peterson in your favorite podcast app. Sometimes the easiest way to find me is just to go to Craig peterson.com/the name of your favorite podcast app.

All right we've got one more segment here before we leave for the day.

So don't go anywhere.

We've got one company that wants to sell the U.S. Federal government location data from every car on earth. Did you even know that was possible? We're going to talk about what's going on.

Hey everybody. Thanks for listening. This is, of course, Craig Peterson.

Man, we have a problem coming our way and then get another one. This has to do with our cars. You might have heard, I heard that Massachusetts decided that they would start charging attacks based on how many miles you drove in the Commonwealth, and the reason behind all of this, supposedly, and it probably is, was that we have cars that don't burn any gas, electric cars, and they are using the same roads. They need the same law enforcement people. They need the same bridge repairs as everybody else, but they're not paying any gas tax. So how do we make them pay as they should? Mass it hasn't gotten very far with that yet.

There's this port in your car called an ODB port or ODB2. This is a port that was mandated by the Federal Government I think in the late seventies when they started this whole mess up.

That port gives them access to the onboard computer. That's there in your car? Hint. ODB, onboard computer. Important there in your car. There's so many three-letter abbreviations that sometimes I kind of mess them up.

So Mass was saying, we can just hook up your car now we're hooking it up anyways when we're checking the emissions cause your car squeals on you. It's not like the days back in the eighties where they would stick a sensor up the tailpipe. To see what your emissions were like. They just ask the computer. What are the emissions like? What's the NOx? The CO2 emissions? How fast is he accelerating?

That same port has been used to give trap traffic tickets but in different areas. Yeah. OBD port, I just looked it up just to make sure I had the right name for it. And it's been used to give tickets up in Canada and Montreal. There's a report that came in of somebody that was racing up and down one of the main streets in Montreal and the police got there and nobody was racing up and down. But a car by the description was there. So they pulled the car over, they hooked up the OBD reader to the port in the car. The car said, yeah, I have been going at this speed recently. The cops gave the guy ticket just based on that.

Our cars had been squealing on us for a long time. Mass wants to use it to say, how many miles has the car driven? Then there's questions about can you charge people mileage, not in your state? Obviously, they are already. If you live in New Hampshire and you happen to drive into Mass one time and you buy gas there, you are paying mass gas tax, which by the way, Charlie Baker apparently wants to double. There are some limits, but I don't know how far they go.

There's a lawsuit right now in the Supreme court between New Hampshire and Mass, over Massachusetts charging income tax to New Hampshire residents that never even stepped set foot in the state of Mass. So it's really convoluted.

We have over 9,000 different tax jurisdictions here in the United States, and that makes things really crazy. When you think about all these different government agencies that want to put their hands in the Till and want to do stuff.

How does that tie into the cars? Our cars are getting smarter and smarter. This port that was put in decades ago was the first step. The car's squeal on ya and the tell information that should be private. Some of the cars now, these better, faster, smarter cars, like the Teslas keep track of everywhere you've gone. Where you're driving? How fast you're driving? The cameras are actually recording all of the activity, everything that they see. There's seven cameras on these cars and all of that stuff is stored and could be pulled out, certainly in a court of law. We're seeing in some jurisdictions that their police want to get their hands on it. There is something going on right now.

There's a company out there called Ulysses. They are a surveillance contractor, and they're claiming that they can remotely geo-locate vehicles in nearly every country, except for North Korea and Cuba on a near real-time basis. That's from Vice motherboard.

So Ulysses is obtaining vehicle telematics from data that's coming out of these embedded sensors and communication centers that are in our cars and in the roadways. Some of these cars are now sharing data. This is a technology that was pioneered by NASCAR and formula one so that the cars could avoid accidents with each other. So the cars could be much safer for the drivers. That makes sense. The cars all talk to each other on this mesh network.

Now we have these companies that have these autonomous features self-driving cars if you will, that are doing much the same thing. They are looking to use mesh communications and some of them already are. By grabbing things from these connected cars, like the engine temperature, your acceleration, where you started your journey, where you're ending the journey, it is a real problem.

There are more new cars now being added to cellular networks. The new cell phones. Here's an article from ARS Technica from a couple of years back, it says in particular, this Shanta Sharman Consulting noted that AT&T has been adding a million or more new cars to its network each quarter for the last 11 quarters. While they didn't break out the numbers for other service providers. It also revealed that Verizon is set to make at least $1 billion from the internet of things and telematics and previous research from Gartner suggested that in this year, a few years back, 98% of new cars will be equipped with embedded modems. It's probably close to a hundred percent by now, by the way.

Our Teslas and pretty much any other self-driving car is guaranteed to be called home because they use that call home function in order to upload new software for the car in case there's some sort of a problem to upload driving data so that they can figure out why did the driver have to hit the brakes or grab the steering wheel to make it smarter?

So our cars are recording all of that data is coming together. Ulysses claims it can currently access more than 15 billion vehicle locations around the world each month and estimate that by 2025, 100% of new cars will be connected and transmitting gigabytes of collectible data. Definitely a concern here. Definitely concern.

Keep an eye out for that. Maybe, I'm gonna keep my 1980 Mercedes diesel. I chuckle because it's rusting out, rusting up pretty badly, but I don't know that I want one of these cars getting tracked everywhere. Bad enough having an easy pass on the cars.

Let's talk about tech vendors and their lack of security. I really picked on healthcare for the first hour of today's show, but a majority of companies are saying they're more likely to buy from suppliers that are open about security issues.

The federal government is now enforcing this SPRS, which is a score that is from zero to 110, that it has to be self-generated at this point by DOD contractors to indicate how secure they are. Then the Department of Defense can look at that and say, okay it's a nut or a bolt and we only buy this once a year. I really don't care if they score highly or not. All the way on the other side.

We don't see this for regular businesses. An increasing number of companies have identified security as a major consideration in their decisions to purchase hardware, software, and services. We just had this conversation with a manufacturer. We had this conversation within the last week with, again, some of these medical providers, the Ponemon Institute says that nearly two-thirds of the people, that were polled in the survey, consider it very important for their technology providers to be transparent about vulnerabilities, security, updates, and ways to patch security issues. But most vendors failed to offer that transparency. According to 47% of the people who say they're not satisfied with the security information provided by vendors.

I was really harping on this near the beginning of the show today that it is bothersome to me that so many businesses are trying to do the right thing. They're pouring a lot of money into cybersecurity, and yet they have to compete with businesses that don't care. That don't know how to do it. They don't care to learn how to do it. That's what I mean by don't care.

I think everybody cares to some degree about cybersecurity, but in reality, if you're not doing enough about it and you just don't care enough.

So I really want to extol to everybody. Take some time, make sure you are on my email list. Cause I have a lot of stuff I send out over all kinds of free tools, third-party tools, right?

Not everything I send out is from me, about me, buying me. I send links to other websites and things, and I do that every week to help keep you informed.

I also have some special programs that I do and this next week I am starting a course for Improving your Windows Security.

If you let me know by sending me an email Craig at me, me@craigpeterson.com, and tell me that you're interested in Improving your Windows Security. I'm going to be giving you a special coupon that nobody else can get for this core course that you need for cybersecurity.

So check it out online, make sure you are on my email list. So you get all of this great free stuff you find out about paid stuff.

If you can do it. If you can't, don't worry about it. I want to help. Craig peterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig Peterson: [00:00:00] Ooh, what a week final preparations are in place for the improving windows security course, which is starting next week. My wife has put her foot down. We're going to make it happen. Today I was on with Mr. Matt gag now, and we spent a little bit of time talking about business, email, compromise, how that is.

[00:00:20] Talked about also ransomware, and it's near tripling and just in long, Hey, I'm Mac and how Intel's newest ads are absolutely ridiculous. It's obviously Apple and Intel going at it. Intel is just mad. That's the only explanation I can come up with. So here we go with

[00:00:47] Matt Gagnon: [00:00:47] Mr. Matt. It is 7:36 on the WGAN morning news. Craig Peterson, our tech guru, joins us now every week.

[00:00:54] And guess what? He's here again, Craig. How are you this morning?

[00:00:57] Craig Peterson: [00:00:57] Hey, good

[00:00:58] Matt Gagnon: [00:00:58] morning. Pleasure having you as always, of course, you hear Craig also on the weekends at one o'clock. If you want to hear about all these topics and more in more depth and detail, listen up Saturday at one o'clock, and you'll hear Craig Peterson's voice right here once again.

[00:01:10] So Craig, lots of stuff to get to here. Maybe a fun one to begin with. Apparently, Intel has hired Justin Long. And if you don't know who Justin Long is if you think back way back to the early two-thousands, he was doing these ads, the I'm a Mac actor. Remember that guy?

[00:01:26]Now he's in an ad to mock Macs. Yeah. And I, I've seen this in a, I think it didn't. Was it Verizon that hired the sprint guy or sprint hire the Verizon guy? I don't remember. Many of these actors were in these iconic roles, for some of these tech companies are getting snapped up to either make fun of or argue against their old essentially.

[00:01:46] It's funny to see this kind of thing

[00:01:47] Craig Peterson: [00:01:47] happen. Yeah, it is that I think you're thinking of the can you hear me now? Exactly. Yeah, this is interesting. And it's showing, I think, frankly, of some concern, maybe even fright on the part of Intel, you see what's been happening over the years, not just with Apple, but with other manufacturers is Intel processors are getting dropped.

[00:02:12] Out of our devices. We started seeing that with smartphones. If you have a smartphone today, it doesn't matter if it's Android or based on Apple's iOS. It does not have an Intel processor score. And we've seen more of that surface tablets without Intel. Some of them have them, some of them don't.

[00:02:32] And of course, all of these Google Chromebooks at all. So don't have it. So Intel has always been struggling to be recognized, and that's why they came up with a whole Intel inside campaign. However, they have also been one of the most expensive little CPUs little processor. If you want a professional Intel processor, it can cost you as much as $8,000.

[00:02:59] Just for the CPU. So Apple has decided we're getting rid of Intel entirely after Intel missed certain benchmarks for performance and battery usage and heat and everything else. And Apple started developing its own chipset here a few years ago, or the CPU is now completely moving away from Intel over the next two years.

[00:03:23] And in fact, if you buy a Mac mini, I have one in front of me right now. That doesn't have an Intel CPU in there. It has the new Apple, one chip Apple is just abandoning them. So they hired Justin Long. The I'm a Mac guy to show you, Oh, this is a, an Intel. Computer. And of course, it really has nothing to do with Intel, and he touches the screen and moves this finger around, and it isn't that neat.

[00:03:52] It pops up and, oh, look at this. We've got two screens on this computer, and I can touch them both. But this Mac book, I can't touch the screen and have it do anything. No, that has anything to do with him, Joe, Matt. It's crazy.

[00:04:07] Matt Gagnon: [00:04:07] Indeed, while we were talking to Craig Peterson, our tech guru, who joins us on Wednesdays at this time to go over what's happening in the world of technology in a more serious perhaps story here.

[00:04:16] the knowledge here that ransom payments have more than tripled is a pretty big deal. Ransomware gangs are apparently out there roaming around the internet and successfully milking. Many people out of cash, basically taking them hostage or taking their machines hostage, if you will. And then promising to give it back.

[00:04:34] If only you give them cash. Talk to me a little bit about the story.

[00:04:37] Craig Peterson: [00:04:37] Yeah. That's really driven up the price of Bitcoin because the ransomware gangs are demanding Bitcoin and payment. It's a little bit harder to trace, but it is still traceable depending on what it is and the FBI just yesterday. Yeah.

[00:04:53] Released another warning about ransomware attacking businesses, government entities, just on and on, but it has a huge impact on anybody that gets ransomware, and a man, the tripling of rent more attacks go hand in hand with people working from home. And that's why I've got this improving windows, securities core starting next week for everybody where we're.

[00:05:19] Helping you to clean it up because we're working at home. We're not as careful as we were at the office. Because of that, it now makes it even easier for them to get valuable information. So the best thing you can do is make sure your computer's patched up. Unfortunately, Windows does not. Ship a hasted care re-secured version of windows out of the box.

[00:05:44] You've got to go in; you have to do a bunch of things. That's part of what we cover in our newsletters every week. And then some of these courses, but these attackers are improving their techniques. 2020 was a great year for them. They've got this whole double extortion thing now where they will get on your computer.

[00:06:03] Particularly if it's a business-related computer, if you're on a VPN connection to the office, they will. Spread is not only inside your home to other computers but across the VPN to the office. And they'll start stealing your data before you even know it's happening, and they might be doing that for a week or more.

[00:06:23] And then once they've got your data, They'll go ahead and encrypt your machines so you can gain access to it. And then they'll say, okay, pay up sucker. And if you don't pay up, you don't get your data. If you do pay up, there's only a 50%. Yeah. Only half the time will you get your data back, even if you pay them.

[00:06:42] And by the way, their justice department says, if you pay them, you're supporting terrorism, and you might get criminal charges against you and to make matters even worse. They'll then say, Oh, okay. By the way, where we are another organization, we have your data. If you don't pay out, we will post your data online, and then you'll be in real trouble.

[00:07:06] Matt Gagnon: [00:07:06] And Craig, the other thing that's worth mentioning here in terms of. Businesses and people that are experiencing some financial extortion, if you will. A business email compromise is also a huge deal. And frankly, I've gotten the emails here about that in this Berry station; make sure that your email is being protected and that you're not falling for phishing scams and all this other stuff. And a lot of email compromised does happen and apparently accounts for a lot of money.

[00:07:30] Craig Peterson: [00:07:30] Yeah, it does. We're talking billions of dollars worldwide. Right now, the FBI estimates that this has cost over 16 billion.

[00:07:39] We're seeing here last year in the us almost $2 billion, and there are some easy ways to deal with this. And I'd put it in my newsletter here a couple of weeks ago when you can always email. Me@craigpeterson.com. I'll send you a link to it, but Google has a free website that you can use, and it has some examples of fishing it's designed for training.

[00:08:04] You can use it for yourself at home. It's wonderful. It gives you a real interactive. Pieces of email that you can see on your screen. It is not going to compromise you at all. This is all online because, with these latest business email compromise attacks, people are getting extortion. It might be tech support romance scams, which have been very big here during this lockdown because people are frankly lonely.

[00:08:35] And they'll do things like being friends. People will be friends, you may be, and we'll say, Hey, listen, my aunt really needs surgery. Eventually, get around to asking you four or five grams to help with this whatever family problem is. And you're romantically involved online, maybe even had a video chat with them.

[00:08:57] So you don't realize that some kid in a basement somewhere over in Eastern Europe, but man, it has gotten awful. So be careful with this BC-type attack and take a minute. You can even Google's phishing scam website, and it'll really help you out a lot. All

[00:09:19]Matt Gagnon: [00:09:19] That's been Craig Peterson, our tech guru who joins us on Wednesdays at this time.

[00:09:22] Thanks a lot, Craig, as always, appreciate it. And we will talk to you again, sir, next week.

[00:09:27] Craig Peterson: [00:09:27] Take care. Bye-bye. You bet. No, my dad used to say you bet all the time. I haven't heard that expression in a very long time. Hey, if you are a windows user, you've got to make sure you spend a few minutes and sign up on my newsletter list, and you can get that to go into Craig peterson.com.

[00:09:49] I will be doing. Windows training here. I've got a course coming up. This is a phenomenal course. I think I explained the why behind what you're doing. So you understand it, you understand the reasons. And then I get into the details of the how, so this is a course. I think everybody needs to get it. So I've got some special deals for you guys.

[00:10:18] If you. Request information on the course, if you've already requested it by responding to one of my emails, my newsletters, and saying, yeah. Tell me more about improving my windows security. I'm going to be giving you guys a coupon that is going to give you two-thirds off. And those coupons are going to be good for you to share with your friends as well for two months.

[00:10:47] Okay. So this is going to be a real quick launch next week. It's only going to be open. You can only buy this course. I think Monday is when we're planning on opening, and it will. And Thursday night. So you guys that asked about it beforehand, you signed up before you will get this coupon to help out your friends.

[00:11:09] So when they're saying, Hey, how do I improve this window security thing? You can give them that code. And as I said, it was good for 60 days. Nobody else is going to get that code. So if you're on my regular email list, you are not going to get that code. The only people who will get it are the people who have already expressed interest by responding to one of my newsletters in advance of me starting this course on Monday or opening the cart on Monday.

[00:11:41] So it's going to be a huge win for you. It's going to be $200. Off. Okay. I'm trying to make this affordable for everybody. And on top of it all, I have promised this for four months. Again, talking about Karen, putting her foot down, she said, I got to do something for all of these people have been asking for it.

[00:12:02] And I haven't got it out yet. So this is going to be great. It is months in the making, and I really think you're going to enjoy it. I'm finishing, loading it all up. Bye, I'm actually reactivating all of the videos because I wouldn't say I liked the way the captioning was working. I have all of these videos captioned.

[00:12:24] So if you can't, I can't hear it. Or if you want to have it running without the sound on at work or wherever it's burned right into the video. Okay. But the captioning, which is a transcription of me speaking. Okay. That captioning was getting cut off at the top. So I thought that might be distracting.

[00:12:45] So I'm, re-editing all of the videos to put the captioning a little bit lower down on the screen. And the way I did it is the desktop slides. All of the examples are below the camera optioning. So the captioning is not going to block—any part of the video. So you'll be able to see the screenshots and see the slides and everything else with the full caption because I know a lot of you guys like to sit there in front of the computer and do this, and of course, you're able to do it on as many computers as you want, because you're going to have access to this program for six months.

[00:13:28] And I think that's going to be an excellent thing. And it's about five-week. Program is how it's designed. And anyway, so w so if you sign up in advance, there's a little bit of a trick. You can get the coupon; you can share it with anybody good for it. Two months. Nobody else gets that. All right.

[00:13:50] Everybody take care, and I'll be back on Saturday. And then Monday, expect the opening email to let you know that I'm opening the cart to improve Windows security. Of course. All right. Take care, guys.

View Details

Craig Peterson: [00:00:00] Hello everybody. Craig Peterson here. I was on with of course, Mr. Jim Polito, and with him on parts of Vermont central and Eastern Mass, Rhode Island, Connecticut. He has a big show that covers all kinds of territory. And so we're covering new England. What can I say with all of these different stations, I'm on in Vermont directly and all throughout New Hampshire and Maine and stuff. So it's just really cool. And without you guys, it just wouldn't be happening. So thank you. Thank you to you. And also I got to mention playing my podcast. Listens are way. Oh, and again, thanks.

[00:00:42] Thank you to all of you guys. I so appreciate it. And to that end I am going to, as of next week on Monday going to be opening up a course that I've put together. Yes. That core is the one that promising now for how many months. And so this is as a thanks to you guys. I am going to be giving. A, I hope you're sitting down basically two third, all in fact, exactly.

[00:01:14] Two thirds off on this, you're gonna be saving 200 bucks. I'm making it cheap under a hundred dollars. It's going to be 99 and it is going into the Y. And the how of doing your windows security, the basic security windows, that configuration settings you need to be doing. So keep an eye out for that on Monday.

[00:01:38] And by the way, here's the, a little secret and it's going to be a surprise to a lot of people, but if you respond beyond to my email newsletter, if you responded to my email newsletter and you told. Me that you were interested in, improving who wouldn't know security. If that happens before Monday, I'm also going to be giving you a special coupon that only you guys will get.

[00:02:04] And that coupon, it will be good for two months. And you can share that with your friends, so that your friends can get. A two-thirds discount on the improving windows security course. So it's really important that all you guys get this course, it is so important. And it's going to help, prove to my wife that it's worth me spending all of these hours every week.

[00:02:32] And in fact, a at least a day, a week dedicated to. And putting together all this stuff, the newsletter and the radio show and all these other appearances. So to convince her that it's worth it to do all of this, did you guys appreciate it? And it's a great way to show it. So if you go to one of my newsletters, even an older one, and you say, yes just hit reply and put IWS in the subject line.

[00:02:56] I'll tag you. And you'll get one of these coupons you can share with your friends. So when you're talking about what you've done to improve windows security, you'll be able to say, and by the way, you can do it too with this coupon. Good for two months for them. Anyhow, take care guys. Here we go with Mr.

[00:03:17] Jim Polito.

[00:03:18]Jim Polito: [00:03:18] It appears that there's a company who can they can track where your car is. And they want to sell this data to the government. What. This, by the way this news comes as we hear that the Chinese don't want Tesla in China anymore, because they think that Tesla is basically a CIA backed company.

[00:03:46] That's spying on the Chinese. All right. Let's sort all this out. And just bring in the voice of reason and the voice of real intellect. I'm talking about our tech talker ruin good friend, Craig Peter song. Good morning, sir.

[00:04:01] Craig Peterson: [00:04:01] Hey, good morning. How you doing

[00:04:03] Jim Polito: [00:04:03] Mr. Jim? I'm very good Craig. We can get into the Tesla thing and the Chinese saying you're spying on us and kicking them out.

[00:04:10] And meanwhile, they're trying to they're building components for R F 16 fighter jet, but that's all right. Let's get to this company. You sent me this as a company. Who collects this data tracking cars. First of all, I didn't know my car could be tracked, but, anyway and then they want to sell it.

[00:04:27] They're trying to sell it, bundle it and sell it to the United States government. Yeah,

[00:04:32] Craig Peterson: [00:04:32] they are. Wow. This is pretty concerning here. This is a contractor that has been doing surveillance for a long time for the government. It's told you lyses, which is an interesting main site, but yeah. Wherever we're going to this gym is a whole new direction.

[00:04:50] Pardon the pun with our cars. We now have cars that are moderately smart to mention Tesla, but there are more and more coming online. And the idea is to have a web of. Cars, sensors and cars talking to each other. We already have that basic technology existing in NASCAR and in formula racing where the cars actually talk to each other, they know how far apart they are is, and that's something that's really.

[00:05:26] That's what we're going to need for the cars on the road today. So I was watching this British show where they're racing around the world. It's like the amazing race, but they mispronounce words.

[00:05:43] They were in China and and they were just as shocking to me to see some of these things. I don't know if you've seen the pictures, but there's this one road it's 20 lanes in each direction, coming up to a toll booth. Backed up for miles. The traffic there is crazy. And I lived in Los Angeles for about eight years.

[00:06:03] I had a client that I used to go to the largest savings and loan company in the country and their headquarters were, Oh, not even 40 miles from where I lived. Public goes to the 30 miles from where I lived out there in LA. I was actually just over the line in Ventura County for those that know that area out there.

[00:06:24] But the problem that I faced was to go that 30 to 40 miles, Jim would take me more than three hours. So I was on the road. For six hours a day. And most of the congestion that we see on the road is caused by people, the sole person in the fast lane and people weaving in and out of traffic. All of the things you've heard over the years.

[00:06:52] So what we've been doing is putting sensors in the roadways. You see them a lot. West and they have, if you go on and on ramp, there is a stop light, right before you merge. Have you seen those before? Yes. Yes. So you have to come to a full, to come to a full stop. Yeah, it's crazy. What they're trying to do is when the light goes green, only one car can go through.

[00:07:15] These sensors are detecting where the cars are, how fast they're going. So where we're going to is embedded sensors, everywhere communication, sensors on all of our cars, just like they are at the races so that we can now have two to three times more vehicles on the road safely. And at the same time in decrease the amount of time it takes.

[00:07:40]

[00:07:40]Jim Polito: [00:07:40] No, go ahead, Craig, finish your thought.

[00:07:43] Craig Peterson: [00:07:43] I'm looking forward to that sort of a thing, because it's going to be huge, but it brings up the point that you just brought up. Yeah.

[00:07:51] Jim Polito: [00:07:51] You weren't talking with Craig Peterson, our tech talk guru. And so Craig. Yeah. I go for all of that. Anything that can make a safer Noah, hold on a second.

[00:08:00] I don't want to give up privacy for these things, moving cars along on the highway. Better Mo you know, making traffic flow better. We learn every year, these things, but you're right. It reminds me of the movie demolition man, which is, supposed to be in the future. And they say, okay Where is he?

[00:08:19]No, we'll just go two, two, two, two, two. And everybody's chipped, but also every vehicle is chipped and everything else you can find and cameras are all over the city. So you can find anybody just by the press of a button and yeah. I that part, I don't like I don't want I fat because I just think that it's inappropriate for the government to be able to do that.

[00:08:42]I don't trust it being in the hands of people, especially after what happened with the old P dossier, the thing that they, the Russian collusion thing, they brought up against Trump, which turned out to be. Absolutely false. You're going to hate anything you want about Trump, but that thing was false.

[00:09:00] And yet the FBI ran with it. And when the, when I find out that the FBI, the leadership of the FBI will run with something like that, I don't trust them with the other stuff.

[00:09:12] Craig Peterson: [00:09:12] Yeah let's have that issue. So here's what we're looking at right now. You've got this OBD port in your car, every car mandated by Congress.

[00:09:22] It's in there now. It's been in there for decades now. And when you go to the car repairs shop, they plug it in and the car said, tells them the technician. Why that check engine light came on. And they are now taking that to the next step, which is they are transmitting it, transmitted that information, that OBD port, that onboard computer knows everything about your car.

[00:09:49] It knows if your seatbelts are fashion, but are fastened. It knows. You're the engine. What's the temperature? What are your emissions? How hard are you accelerating? And so let's put all of this in a pot and stirred up a little bit. They are obtaining already this company called Ulysses what's called telematics data.

[00:10:10] It's all of this data about the cars already from embedded sensors, from communication sensors that are embedded in the roads. That are reading our license plates as we drive under bridges or pass these little cameras and pull yeah. Pulling it all together. So these cars, a hundred million new cars manufactured worldwide every year are increasingly conscious to the manufacturer and match part of the problem China has with Tesla.

[00:10:41] Jim Polito: [00:10:41] Wow. Craig. Here's the thing. There's not going to be any way for you to block this. If you worry about on your. Desktop computer or your laptop computer. If you worry about the camera being on like the cameras they sell now, even have that little thing, you slide over covers up the lens.

[00:10:59]You can unplug the microphone. You got, you knew all those things so that you can't be monitored. But you can't do anything with this stuff. If they put it out.

[00:11:08]Craig Peterson: [00:11:08] Your Tesla and part of what China is complaining about is you hear you're driving a car around with what is it? Seven cameras on it, including a camera aimed at the driver, and then Tesla calls home every night on why fi.

[00:11:22] What state is it transmitting? What does it know? What pictures has it taken, talking about a hat target don't China's concerned. Hey the CIA NSA, FBI, who knows what TLA three letter agency might be tracking this stuff and you know what. They're not

[00:11:40] Jim Polito: [00:11:40] wrong. Yeah. I hate I hate to agree with the but the Chinese communists on something like this, but they they are, right there.

[00:11:49] They don't want it. They don't want anyone. Taking pictures of things that went well, that basically that's what you have in a totalitarian state.

[00:11:58] Craig Peterson: [00:11:58] And I want to twist this to okay. And that is Jim. Okay. Have you noticed that I noticed this when I was young, my parents blamed me in doing things I never did.

[00:12:11] What did they did? And the Democrat blame Republicans for things Republicans never did, but they did hence the Russian hoax against president Trump, where they were saying president Trump, collusion, Russians collusion, Russians. What we're looking at now is the Chinese saying we don't want your technology because it's spying on us because that's how you something.

[00:12:34] Jim Polito: [00:12:34] Yeah. It really does. I do know that they don't want people freely taking video of anything in their country because they want to control any information about their country. That leaves, God forbid somebody in a Tesla drive by one of the Weger concentration camps where they're committing genocide against that.

[00:12:55] Muslim minority. Somebody might pick it up on a Tesla camera and it might end up in the hands of the the public. But you're right. Craig, this was a fascinating segment is usual how to folks get more information from Craig Peterson.

[00:13:12]Craig Peterson: [00:13:12] I got to let everybody know next week. I am starting that improving windows security course.

[00:13:18] I've been promising for three, four months. It starts on Monday. You'll find out more, but you only find out if you are on my newsletter list. You can get all of the details, but you've got to go to Brent peterson.com. Make sure you sign up to the newsletter letter. You'll get the show notes, including stuff that I send to Jim.

[00:13:38] You'll get that every week. You'll find out about the free trainings, about the courses, about everything that I'm doing to try and help people understand where we're at and where we're going.

[00:13:52] Jim Polito: [00:13:52] Craig, thank you so much. Always a pleasure. And we'll catch up with you next week or. There's a big tech story maybe before.

[00:14:01] Craig Peterson: [00:14:01] Indeed. Thank you, Craig.

View Details

Craig Peterson: [00:00:00] Good morning, everybody Craig Peterson here. And I was just talking with Mr. Chris, Ryan about some of the impact that we are beginning to feel with the remote hackers, right? Was this China was this Russia. And I thought it was interesting because Chris was obviously going online and. Doc going some of these different topics that we were talking about and 19 administration officials that were saying things that I don't think were true, frankly.

[00:00:36] So here we go with Mr. Chris Ryan.

[00:00:39]Chris Ryan: [00:00:39] The program right now, Craig Peterson, host of tech talk here on news radio 610 and 96.7, which airs on Saturdays at 11:00 AM, actually 1130, Craig, how are you?

[00:00:52] Craig Peterson: [00:00:52] I am doing fine. And yeah, there's only one right lane.

[00:00:55] Chris Ryan: [00:00:55] Thank you. Thank you at score another one for Chris.

[00:00:59] He's not just sucking up to me because I'm the host. He is legit in this circumstance. Craig, I got a lot of important things to talk about with you and I want to start with what the United States is doing in regards to cyber attacks reportedly against Russia and retaliation for what Vladimir Putin has done in regards to election interference.

[00:01:17] And also. Some of the cyber attacks that they've perpetrated against this country. What's the latest on this. And what do you see as being the state of play?

[00:01:25]Craig Peterson: [00:01:25] There have been outages of course, here in the us and a lot of them attributed to just us making mistakes. So a lot of people businesses that are running parts of the internet that.

[00:01:37] Did the wrong thing. So remember, again, the internet is not run by one organization. It isn't run by the federal government. It is a whole bunch of networks that are connected together. Now that said, we have seen some major strikes against outs here in the U S from both. Russia. And from China, frankly, China has been much, much worse at this, but the Biden administration has decided to really try and single out Russia.

[00:02:07] In fact, president Biden came out and criticize them and said, we are going to retaliate. We had a problem in Russia where the Russian main Russian government websites were shut down and they went off the air is that as he sent them down on purpose and we've seen similar things before. So Chris, I suspect we have been involved.

[00:02:30] Chris Ryan: [00:02:30] Yeah, the Biden administration, according to Yahoo news is preparing a series of aggressive cyber attacks on Russia. I'm in a major shift in tactics designed as a warning shot to rival powers. They are saying that they're not going to target civilian structures or networks, but the hack will instead serve as a direct challenge to Vladimir Putin and his cyber army, according to the telegraph.

[00:02:56] Craig Peterson: [00:02:56] Yeah, but the one to really worry about is China. I, there's this whole Russia thing has really gone overboard here. All of the. Real cyber experts are saying that China's the big one. We just had two major attacks that attacked and compromised tens of thousands of businesses here in the United States, as well as government agencies, as well as our schools, stealing our information, grabbing bank account information, personal information, personal health information.

[00:03:26] And none of that is attributed to Russia. It is entirely including the federal government Homeland security and the FBI it's entirely attributed to China. But yeah, it looks like we've done a little saber rattling, according

[00:03:41] to what the American government has said, the agencies believe that the attack was the solar winds attack was actually perpetrated and they have traced.

[00:03:50] Back to the Kremlin and this is going to be retaliation for that. So you do not believe that's the case. You believe it is China.

[00:04:00] Yeah. Most of what we're seeing with solar winds is actually originated with Microsoft and Microsoft office three 65 system, and more particularly with Microsoft exchange servers and apparently. Both countries, there's all, some others have been involved in this. No, I don't say that it was not Russia at all, because there is some evidence that they were involved in it, but the most dramatic stuff has been caused by China has been coming from China.

[00:04:29] Now I've got to explain one other thing here. Sure. The reason there are questions about this isn't because people are trying to hide things or cover up or blame a country that had no involvement. The reason it's so hard to figure this out entirely is we don't know where it really originates. No, we can track down a little bit.

[00:04:50] We know, okay. There's an IP address that came from, but that IP address was someone's home computer that had been compromised and as part of a bot net, and then that home computer, if we get our hands on it, we can see, Oh, that was compromised from this machine in India. Oh. And that compromise came from here or there, the way we tell.

[00:05:10] Whether or not a machine has been compromised from a certain place is by looking at how it was done. And I've worked with the FBI on these cases before. And so I can tell you what we're looking at is a fingerprint. What tools did they use? How did they use them once they got into the network?

[00:05:29] How did they spread? And it is easy enough. For the Russians or the Chinese or the North Vietnamese now to come in and do something just as though they are someone else. And it's much like these people that commit crimes and they, the police look at it and say, okay, this has the same ammo.

[00:05:52] Motorcyle Rhonda, is this other crime? Therefore they're probably related. That's what we're doing here, Chris. So there's no hard and fast rules that this was, or was not Russia on. And you're talking about one specific part of one specific tack. We do know most. Countries were involved. And we do know that China has been doing most of this over the last really 15 years,

[00:06:20] Chris Ryan: [00:06:20] U S national security advisor, Jake Solvan who's from New Hampshire was a part of the delegation that met with the Chinese in Alaska.

[00:06:27] And that wrapped up over the weekend. It began with a very tense. Standoff between the two nations, which was supposed to be a photo op and instead they engaged in, as you referenced before, or some saber rattling between the two sides. And I'm interested in what your takeaways were from that. As Mr.

[00:06:46] Sullivan has continually. Said that traditional sanctions are not going to be what the Biden ministration uses in these circumstances. And there's going to be different elements as the United States. Again, looking at the cyber side of things in regards to attacks and and following up from previous attacks, perhaps perpetrating new ones in a new type of response.

[00:07:11] Craig Peterson: [00:07:11] Yeah, there are many options available. We do in every branch of the armed services, have people who are not just there to defend, but to attack. And we are continually looking into that. Of course, the NSA we've seen before for tools that were offensive. Cyber warfare tools we've seen them used. And we just saw China here last week, how Tesla, but it cannot be selling cars in China because it has seven cameras and it has all of this other computer equipment.

[00:07:44] And they think that we might be using it to steal information. Of course, Elon Musk came out and said, no, that's not the case. But that's the sort of thing we really could be doing. If we wanted to do it, you can be sure we're probing their networks. You can be sure we're into them as much as we can be. So how we resigned, it's hard to say, but there are a lot of options available and we have been shooting around the corners in shutting down power plants in Russia, in shutting down some of the infrastructure in China an hour.

[00:08:20] Fingerprints are all over those things, just like it was in Iran with those centrifuges that were being used reportedly to make nuclear fuel for bombs. We have a record of doing this sort of thing. Preston. So in saber rattling might well be backed up by something. That's a very, obviously from the UK.

[00:08:41] Chris Ryan: [00:08:41] And I think it has to be, I think that talk particularly in the current world, climate only goes. So far and it has to be followed by reciprocal action where we'll be seen as just being talk. Craig, thank you so much. And I look forward to chatting again next week. Take care, Chris. That is Greg Peterson.

[00:09:01] He hosts tech talk on news radio six, 10 and 96, seven Saturdays at 11:30 AM.

View Details

Sorry guys, this week was quite busy for me with meetings and presentations for my business. We will be back next week with a new so but for today this is a re-air of the February 20th Podcast. Check out the website for the latest articles I found for you to read.

Craig

Welcome!

We lost a Radio Icon this week and he had a big impact on me, I have a short tribute to him but it was also another busy week on the technology front. We are going to get into the differences between Backups, Disaster Recovery and Business Continuity, often these get tossed around in discussions as one in the same - they are not. Then we will discuss Bitcoin and it metoric rise and why that happened. Next we'll discuss Apple and Google and why Google is trying to play hardball but may end up getting burned. Then we are headed to Space and NASA space travel and a discussion on Rocket Fuel for future missions to Mars and there is even more, so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Breached water plant employees used the same TeamViewer password and no firewall

As Prices Surge, Bitcoin Now Reportedly Consumes More Electricity Than Argentina, Netherlands, And UAE

Google flags its iOS apps as “out of date” after two months of neglect

White House hastens to address global chip shortage

Report: NASA’s only realistic path for humans on Mars is nuclear propulsion

A Windows Defender vulnerability lurked undetected for 12 years

Hackers try to contaminate Florida town's water supply through a computer breach

Barcode Scanner app on Google Play infects 10 million users with one update

SolarWinds Attack Reinforces Importance of Principle of Least Privilege

U.S. Unprepared for AI Competition with China, Commission Finds

Brave Launching Privacy-Focused Brave Search

Hackers are finding ways to hide inside Apple’s walled garden

Apple changes 'subscribe' to 'follow' on Podcasts because people think subscribing means paying

Russian government websites go dark after the U.S. vowed retaliation for SolarWinds hack

Exchange servers first compromised by Chinese hackers hit with ransomware

Google must face $5B lawsuit over tracking private internet use, judge rules

Want to borrow that e-book from the library? Sorry, Amazon won’t let you.

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] I've got to say the big story of the week is this breached water plant and how it really affects all of us. Not just because our water could be poisoned by a hacker, but it gives us a bit of a lesson on what we should be doing and what we did.

Hi everybody. Craig Peterson here.

There are many things that we did over this lockdown. Things we did. In fact, the lockdown itself to try and help stop not just the spread of the virus, but remember it was a two-week lockdown just so that we did not overwhelm our hospitals. Who could disagree with that, right?

We all stayed home for two weeks that make sure that we're flattening the curve, that we're not going to have a lot of. People in hospitals. Unfortunately, other people who couldn't make it into the hospitals needed it. That two-week locked down to flatten the curve has turned into what? Now, almost a year later we are still seeing these lockdowns. These lockdowns have caused havoc.

We've talked about many of them. Of course, you hear them all the time on the radio. Everything from suicides of our children. Through our parents dying in these homes and without the comfort of their family and without human touch for almost a year. It's just so, so, so sad to see.

Now I'm not going to get into the political sides of this and what should we have done? What shouldn't have we'd had done? I've got my opinions on some of this. What I want to talk about is what we did with our jobs? What did we do with our businesses? I think we did some terrible things there, too.

What I'm talking about is we need to stay home, but we have certain businesses that need to stay open. Now, frankly, every business needs to stay open. It's a business because it's fulfilling a need, right? It is so basic. It's hard to think that people don't understand this, but obviously, they don't.

We shut down businesses. Businesses that will never, ever come back. People's lives destroyed. People whose entire savings, their entire retirement plan, everything was based on the business. That's where their money was. The people working there were counting on having that money to pay the rent, to pay the electric bills and other utilities. To pay for all of the things in life that we need to pay.

It's one thing to have credit card bills that you can't pay because they're not a whole lot they can do about unsecured debt. They can certainly harass you. When it comes to things like your home or whatever it is, you're renting, whether you own it or not, how can you make those payments if you don't have money coming in. The money that the government is issued has just been a mere pittance. I get it.

In some cases, people had just incredible amounts of money compared to what they were normally making with unemployment, with the federal subsidies, et cetera. That didn't last. PPP money, this payroll protection money, lasted for about six weeks for those businesses that could get it. Those that qualified.

My business didn't qualify for PPP money. Not because it's too big, but because it's too small. Most of what happens in my business are done by my family members. I've got myself, I've got my wife, of course, you've probably seen Karen mentioned in some of my emails that go out.

I've got my eldest son involved. He loves security. He's great at it. He's been working with me now for more than 10- 15 years on this. I've got one of my daughters working with this on me. So it's primarily a family business. We've got contractors who will do different things for us. We have a lot of suppliers and we have to pay those bills, but no payroll per se. You know what? That's a lot of businesses. The number of businesses that were in the same boat as I is huge. That's how things get started in this country.

All of these companies could have started. The companies that had started had entered into lease agreements. That had started to provide services for their customers. Whether it be B2B like mine, business to business, or business to consumer they were all stifled.

What have we done to ourselves? Really? What have we done? The virus itself is obviously pretty nasty and can be lethal in a lot of cases. It has been. Now we found out that people like governor Cuomo apparently just cooked the books. Cooked the books, something awful.

We went home, we started working from home. Our businesses said, what can we do? We had people getting very, very busy trying to figure it out. There are a lot of little remote programs that you can use in one of those is Team Viewer.

Now there's nothing particularly wrong with Team Viewer. I'm not fond of the idea of things like Team Viewer, remote desktop, and others, but sometimes it is the best solution for a particular problem. Team viewer in this case was used by a small government agency. Think about what would have happened. You had to shut down, you still had to do work. What did you do as a business?

You probably got something like Team Viewer, one of these logins, remote login programs. Maybe you set up a remote desktop so people could get in remotely. Maybe you set up a VPN because that's going to solve all of your problems. Which of course it causes almost as many as it solves, but most people don't realize this.

That's the case here. We're talking about a small town, 15,000 people, called Oldsmar. I don't think it's because they're a small town. I think this problem happened because they did what most of us did. We were not ready for a shutdown.

As businesses, we weren't ready for a shutdown. In fact, the year before they did the shutdown, they had this massive pandemic planning session about eight months before. They all agreed that a shutdown was the wrong thing to do in the case of a worldwide pandemic. They also redefined pandemic. I think maybe getting the angle I'm coming from here. Right.

They decided no, we're not going to do that. They did not plan for pandemics. In fact, they didn't plan for a lockdown.

Obviously, you don't. Well, I don't know, maybe you do plan for a pandemic. If you're coming up with a virus you're going to release it, but they were not planning for a pandemic. They were not planning for the lockdown and neither were businesses. Most businesses, government agencies, and NGOs had no plans in place, even for disaster recovery or business continuity. You may or may not be aware of this, but there are different levels.

You've got basic backups and you should be doing backups because hard disks fail. One of my customers' CEO thought that hard desks never fail. She was really upset when a disc crashed that we'd been warning her about because we keep an eye on things called smart stats on the disks. We said you've got this disc it's going to fail. You probably need to fix things because you're not in a raid array. You've fallen out of that already. Things didn't just get worse.

You have a backup. You hope that Mac going to work. If you get ransomware and I got to tell you, nowadays, the answer's no. There's two sides to ransomware, but we've talked about that before. I'm not going to get into it right now.

You've got the backup mainly in case the disk fails, or you accidentally delete a whole bunch of files and you want to get them back.

The next step that you have is disaster recovery. You have a disaster like there's a massive snowstorm that caused a water main to break in the roof. All of your computer equipment is covered with water and none of it will work anymore. In a disaster recovery situation, you now take your backups and you get new machines and you load it all on, and hopefully, your backups are remote. They weren't damaged by the water. Unfortunately, most businesses, again, not thinking this through just hoping, crossing their fingers, that they're not going to be one of that 50% of businesses that is out of business because of a disaster. Actually is closer to 75%.

It depends on whose numbers you're looking at. So they're hoping. No, no, I'm going to be part of your disaster. Disaster recovery. Is just think of that, of a snowstorm and the roof collapses of a fire and the computers have burned. Can you get your business back in business?

Then there is business continuity. That's a whole other level of planning and business continuity is where you say, Hey, I need to make sure my business continues to conduct business. If you have a hundred, 200, 300 employees, You're much better off being able to let's say the computer room burns down as an example that or that roof caves in because of the snow and you've lost those computers. You're much better to be back in business in four hours or less. We've had business continuity solutions where we had equipment on site in a different part of the building. If there was a problem in one part of the building, we could failover to the other part. Now this is an awfully big building and we had fiber links between them, but they could be back in business in less than 10 minutes. It's just that quick. That is business continuity, right?

If you are a public company or you are a division of a public company by law, you cannot be out of business for more than four hours. Now, that's just public companies. By the way, those same rules are in place for doctor's offices, for hospitals, any medical personnel you have to be able to get at the patient's records within four hours.

How many of us are ready for that? Then along comes a shutdown, remote workers. We're going to get into this a little more detail. We're going to talk about these SCADA systems, supervisory control, and data acquisition. What does that mean? And why is this a problem for all of our infrastructure? How did this guy poison or at least try to a town of 15,000?

You're listening to Craig Peterson.

What happened to that town, a Florida city of about 15,000, Northwest of Tampa when hackers got into their water supply and hacked up the amount of lye by a factor of 100.

Hello everybody. Craig Peterson here.

This whole concept of having a backup versus some sort of disaster recovery plan versus business continuity is something most businesses really don't pay enough attention to. Now, we've got another problem which is really a business continuity problem. What do you do when your employees can't get into the business?

When we've set up business continuity for businesses, in the past, what we've done is I mentioned earlier this data center where we duplicated part of it in another part of this massive building. If there was a problem with something, could just be some of the core switches go down or something, we could automatically failover and continue running within 10 minutes. That's one way to do it.

But how about if the rest of the building went away? How about if your main servers okay, but the roof collapses or there's some sort of a fire? What happens if your employees can't come to work because there's a lockdown? There are so many reasons you need to have business continuity in place.

We didn't have it right. Not we, as in me, but so many people, so many companies didn't have that. That's what happened in Oldsmar, Florida. They have a water plant. Of course, they have all of the normal things any city of 15,000 people would have. They had in their water treatment plant these devices that are called SCADA devices that are used to control valves. These valves are exactly what you think of a water plant. They're used to control the mixture of various chemicals to divert water around the plant. The source of the water, the type of filter switched over to a new filter so that the older filter can be replaced. In many cases, the main filtration is just done through sand and it has to backwash every once in a while. This is all controlled by computer, nowadays.

They were running a Windows seven machine. No, I know you're saying, well, I've got Windows seven I'm okay. The problem is Windows seven is no longer supported by Microsoft unless you're paying them ungodly amounts of money. I'm talking about $50,000 a year per machine sort of money. It's just crazy amounts of money. Most companies don't have that, right? I don't know anybody outside the federal government that actually has that. There's probably some, but they will not release it to the general public.

Sometimes they'll release a few little security patches because something was just so apparent that they had overlooked. But most of the time, no. Most of the time these security patches just aren't available for older versions of Windows. So they had a Windows machine that was controlling this network with all of these valves on it.

They had that machine hooked up to something called Team Viewer. The idea behind Team Viewer is, Oh, this is really handy. I can put Team Viewer on our control machine. Then I can have my employees be at home and then use that control machine remotely over Team Viewer.

That's what Team Viewer is designed for, isn't it? Well, as it turns out, they were using Team Viewer throughout the water district. That became a bit of a problem because they did not have proper firewalls to protect it. And they were all sharing the same password.

The interesting advisory that came out about this particular problem from the Commonwealth of Massachusetts, if you can believe it. This cybersecurity advisory for public water suppliers is talking about how water suppliers can guard against cyberattacks on water supplies. It goes through a lot of these basic things that I've talked about. They should listen to my show every once in a while, right? Or attended the briefings that I had put on for the FBI's InfraGard program. It would be pretty simple for them. The state of Florida came out with some guidelines, et cetera, after the fact. As did Massachusetts.

They were running Windows seven. They were remotely accessing plant controls. The computer had no firewall installed. Well, that's what they're saying. In reality, Windows ships with a firewall installed, but that doesn't mean it's going to do any good. I talk a lot about that in some of my courses, but the computer was visible to the internet apparently. Okay.

They all shared the same password. What do you want to bet it was a bad password and employees could remotely log into city systems using this Team Viewer application. It was really that simple.

Now this actor's here apparently is more than one and they are unidentified. So we don't have a whole lot of information on it, but I did get a notice. It's called a pin, which is a notice from the FBI it's labeled green, which means I can share it with everybody. It's saying that they obtained unauthorized access to it.

Now, here's the most important part. These cyber actors likely access the system by exploiting cybersecurity weaknesses, including poor password security and outdated Windows seven operating system to compromise the software used to remotely manage water treatment.

The actor also likely uses the desktop sharing software Team Viewer to gain authorized access to the system. We've seen this, not only with Team Viewer, we have seen this with remote desktop and many other systems that people have been using to allow their workers to get in remotely. All of this because of the lockdown, people working at home. All of this should have been handled properly by having a business continuity plan in place. It's really that simple.

Now the putting the plan together, isn't that simple, frankly, but we've got to think about what happens here.

No. I also think about this particular hack and who did it. Well, it could have been the Russians, right? It could have been the Chinese or the North Koreans. We know Vietnam has gotten into the game lately. It could have been any of those guys.

But do you know who the most likely people are to do this sort of thing? It's somebody who works for the company or in this case, very likely that it's a disgruntled employee. They all shared the same password. They use Team Viewer. I said, I'm not blaming Team Viewer here, but this is not good. This is really bad. This is not just something that could happen at a water plant where they're moving the amount of lye from a hundred parts per million to 11,000 parts per million. They're using it in drinking water to change the Alkalinity, the acidity of the water.

I don't know, I don't know. We've got to do something about this. I'm going to have some training on this, what you should be doing for remote workers.

If you're interested, let me know I'm going to plan some, but I'm not going to do it until I hear from you to know it's worth my time to put it all together. Email me M E at Craig Peterson. Let me know that you'd like to know about remote workers or maybe this whole business continuity idea. Again, email me me@craigpeterson.com. Let me know.

Hey, you'll find a whole lot of stuff. If you go to Craig peterson.com and it's all good information that you need. Make sure you sign up for my newsletter right there. Craig peterson.com

Hey, we can't go without talking about Bitcoin. It has surged surged surged. It may go up, it may go down. I'm not somebody who advises on investments, but we're going to talk about what it is and why people are mining it.

Hello everybody. Craig Peterson here.

Well, we have a really big thing to talk about when it comes to Bitcoin, but first I have to take a minute and honor a man who has inspired me in broadcasting for decades. A man who has changed the whole face of radio. AM radio was pretty much dead. Then he started his national show. Of course, I'm talking about Rush Limbaugh.

Whether you agree with him politically, and I think most of you guys probably do. We all have our differences, or not, he is a man that deserves great respect. He changed the face of American politics. He literally single-handedly saved AM radio. He created this whole concept of a nationally syndicated talk radio show, and it has helped to educate millions of people.

I started listening to him back in the late eighties, quite a while ago. I was just amazed with him and the way he did it. One of the things that inspired me about it is he took callers, but they weren't the guest, he was the guest. They were asking him questions. That is so topsy turvy from how, even today, most radio shows are.

People would call him up and they would ask him questions and he'd be able to answer them. He also asked them some questions, obviously, in order to figure things out, he also was not afraid to take opposing calls. He would look for those and he would put those at the top of the queue. He would take those callers that disagreed with him before he took callers that agreed with him, his ditto heads, as they like to call themselves.

When I heard this week that he had passed, I knew it was coming, but it hit me hard. It hit me really hard. He's not that much older than me. Although I remain in really good health, knock on wood here I am just flabbergasted. I don't have words for his passing. So it would not be right for me not to have mentioned a man who inspired me, who educated me, and played a role in my life, such that when he passed, I was just gobsmacked.

It's absolutely a sad, sad time. I really wish my best, obviously to his wife. I guess Catherine is his fourth wife, so I'm guessing he didn't have the best home life out there. Things obviously didn't do well on that front. I think he's a little bold and brash and maybe that's part of it.

But my memories of him being down in Cambridge, Mass. I was working as a contractor for about a year and a half at the Open Software Foundation. I was working on the operating system and that was rewriting the TCPIP stack. If you know what that is, it's the basis of the internet today and the Open Software Foundation provided its code to pretty much everybody out there. That's how I can say with a high degree of confidence, the code I wrote is still in use today to help run the internet. I was working down there as a contractor for about 18 months. I also put in the i18n, the internationalization code into many of the Unix libraries and at lunchtime. I had a small radio with me and I would go out and walk around for lunchtime and listen to Rush Limbaugh while I was out walking around. He had been quite the companion for me, gave me a lot of things to think about, disagree with him on, and agree with him on. Conversations were spurred with other people. I've come to realize, I mentioned this to my wife, as well, this week after he passed that as someone who's on radio, call us personalities or whatever you might want to call us. But as someone on the radio, this is a very personal medium. I've come to realize that Rush taught me something. I realized it when he passed, I've never met the man. I have a photograph of him signed by him around here, somewhere. He taught me something else and that is, I never met the guy, yet I felt an attachment to him that I had never felt really to anybody else.

Certainly, I've never felt that way about a movie actor that died. I've never felt that way about an author whose books I loved. I've missed some of them, some of these books where there a series of books and the author died. You could tell mid-book that the voice changed and it was being written at that point by someone else. I was just disappointed by that. I didn't feel that sense of loss that I felt this week. It helps me to realize. How important it is for me with you guys. Without you guys listening, we wouldn't have a radio station. Without you guys buying from the advertisers it couldn't afford to, pay for the electricity and all of the people that are involved. It's the listeners. Right.

I have an obligation to you to present the information that you need in a way that you can understand and hopefully in a way that you can use it, right?

What good is a show like this? If I'm giving you stuff that there's nothing you can do about it? You notice, I always try and do that, but that's the way Rush was too. Rush wouldn't just sit there and complain. Rush would talk about the facts, what's happening, where he thinks it should go, and what we should be doing. What we should be doing as a nation and what we should be doing as individuals. To me, that was very inspirational. Frankly, that's how I've patterned this show. I've had this radio show for over 20 years and I've patterned it that way, where I try and help. If you've ever sent me an email you get a personal reply from me because I am here to help. And I felt that way about Rush.

I've sent him emails. I'd never gotten responses, right? But you, I feel this attachment to these people. That's part of the beauty of these smaller radio stations, where there are people, we are local, we do care about you. These advertisers tend to be local as well. Certainly, local businesses advertise locally, and we really have an obligation to you, to every one of you. So I appreciate you. I really do. I really do want to help. I am beginning to understand some of the responsibilities that I have it isn't just to help you understand technology a little better to keep your machines clean, to stop your businesses from being stolen from, by hackers, or by Snowfall that might bring your building down.

It is to help you as best I can, as often as I can. So that's why I do it. That's why I do these courses, the newsletters, everything else. Rest in peace, Rush. We're going to miss you.

Visit online as well, Craig peterson.com, and sign up for my newsletter so I can help you a little more.

Well, we really, are going to talk about Bitcoin in this segment. So stick around. I had to talk about Rush this last time around. Bitcoin, the prices are surging. People are mining. What does that mean? And why are they using more electricity than the country of Argentina?

Craig Peterson here.

Bitcoin has been around for a while. I don't think anybody out there has not heard about Bitcoin. It is a power in and of itself. We don't know who actually came up with this whole concept. There's a concept behind Bitcoin called blockchain technology. Blockchain technology is based on the concept of ledgers. Where you have ledgers, just like a bank ledger that keeps track of every transaction. There are hundreds of thousands. Just so many ledgers in the world. In order to verify transactions, half of those ledger entries have to agree. So it's pretty basic on that level.

What is Bitcoin itself, which sits on top of this blockchain technology? Well, if you want to look at it, simply take a look at prime numbers.

Hopefully, you can name the first five prime numbers, right? What do we get? One, three, five, seven, 11. There you go those are the first five prime numbers and a prime number a number that is only divisible by itself and one, which is why one is a prime number.

We use prime numbers a lot nowadays. Most of the encryption that you're using is based on prime numbers. If you go to a secure website, you're using something called SSL, which is the secure socket layer and that's what shows up in your browser, in that URL line as a little lock, if you see that lock that you have effectively a VPN, a virtual private network between your browser and that remote site.

Guess what? You already have a VPN, right? Why use one of these VPNs that spies on you?

That is encrypted data and it's very difficult to encrypt in between. How does it do that? It's using something known as public-key technology, the RSA algorithm. We're not going to go any further down that, but basically, it allows someone to have a public key and use that public key to encrypt a message. then you, the person who's receiving the message whose private key was used to do the encryption can decrypt it using their private key. So the public key side, and the private keys side, it allows the encryption from end to end. That's what the SSL is all about.

Well, when we're talking about Bitcoin, we are talking about something that goes and uses some of the similar technology. What it's doing is using these prime numbers. That's what the RSA algorithm is using this encryption algorithm, using these very large, very complicated prime numbers because you get past 11 and let us see 12. That's not a prime, right? Uh, because it's divisible by. Two and six and three and four, and then let's see 13. Okay. That's a prime 14, no 15, no 16. No. It gets more difficult.

I remember way back when, writing a little program that just found prime numbers and it looked for prime numbers and the easiest way to do it was I would start, first of all, you take a number, divide it into. There's no reason to go any higher than that when you're trying to figure out if it's prime or not. Then I would start looking at some of the base numbers to try and figure it out. Of course, real mathematicians were able to figure out better ways to find primes.

Well, when we're talking about Bitcoin and some of these other cryptocurrencies, they are also using these very large prime numbers, just like you're being used for this public key encryption. They also have some other parameters around some of these prime numbers.

To have a Bitcoin is to have this digital number that represents a unique prime number. If you want to mine, what you're doing is you are trying to find a prime number that no one has ever found before, just to oversimplify things a little bit. You find that prime number and Tada now you have a Bitcoin. Sounds easy enough, sounds quick enough. It is not easy and it is not quick.

It's not just based on the prime number algorithm, but we're keeping this simple here. We have found millions now of these Bitcoins. I should look that up and find out exactly how many, but there are many Bitcoins. The whole algorithm, the whole system is set up to do some restrictions here, there's only a certain number of these Bitcoins that will ever be mined.

It's estimated that something like 20% of the Bitcoins that were found has been lost because the encryption was used to keep the keys. People forgot it.

You probably heard about this guy that has a quarter of a billion dollars in Bitcoin in this wallet. He only gets eight tries before it auto destructs. He hasn't found them yet. There's a quarter of a billion dollars that's unreachable, but that's what we're talking about here.

Bitcoin mining. In this day and age, Bitcoin mining is so hard and it takes so much computing power that it is using a couple of things. First of all, the thing that bothers me the most is it's using up these GPU's these graphical processing units, because GPU, which we typically use for graphics processing is set up so that we have are hundreds, thousands of processes that can be happening on that card simultaneously, various small little tiny processes that can be set up to somewhat be optimized for Bitcoin mining or mining, any of these other cryptocurrencies.

Then the people who really want to make money on mining these cryptocurrencies have machines that are special machines. They are designed specifically to mine, one type of coin, one of these crypto coins. We're talking about Bitcoin. There are machines that are designed to mine bitcoins, go to E-bay and look for Bitcoin miners. They used to have them on Amazon. I haven't checked in a while, but you'll find them in both places. At least you used to be able to, you can certainly still find the money bank. You'll find some that are old, that are used and some brand new ones.

Well, it is expensive to mine them. One of my sons and I, decided years ago to try and do a little mining. We probably should have tried harder but we gave up. It was a, who knows what's going to happen with Bitcoin.

There are so many cryptocurrencies and today there are people introducing new cryptocurrencies all of the time. I avoid those like the plague because you never know what's going to happen.

Bitcoin is definitely the 800-pound gorilla out there. We were able to mine I guess my son said he mind a couple of other little currencies they're worth a penny or two, not a very big deal.

We have now so many people in China that were doing Bitcoin mining China could not produce enough electricity to mine Bitcoins. China went around and shut down anybody that was mining Bitcoin. We have something called the Cambridge Bitcoin electricity consumption index. This is an index designed to figure out how much electricity is being used in order to mine Bitcoin.

This is, of course, over in England, the University of Cambridge the judge business school. I'm looking at a graphic right now that they have, and this is showing the electricity and Bitcoin mining. They actually have all of the data for downloading, if you ever wanted to do some serious analysis. It's showing there was hardly anything, if anything, back in 2016. Summer 2017, when it started to jump up and that's, of course, when the price of Bitcoin started to go up.

Why? Well, mainly because of ransomware. People having to pay ransomware and buy Bitcoin in order to pay that ransom.

In terawatts. Now we are showing at about, okay, this is Wednesday, February 10, 2021, 288 terawatts of electricity on that one day. Isn't that something? The amount of electricity that's being used has been surging because, of course, the price of Bitcoin has been going up. Just been going up in crazy, crazy rates. The amount of mining going on has doubled, almost doubled since October last year. We're talking about using more electricity than the entire country of Argentina, the Netherlands, and the United Arab Emirates. It is absolutely amazing, amazing how much we're using. People are alarmed by this. Countries are having major problems in trying to figure this out.

What else is funny about it? They talk about Bitcoin being one of these so-called green technologies. Well, it turns out that Bitcoin because of the electricity that it's using for people to mine now has a carbon footprint comparable to the entire country of New Zealand. It's producing about 37 megatons of carbon dioxide per year. I think that's funny, frankly, because they call it green. Right?

It's like green cars that are electric. Well, guess what? They aren't green in so many ways. They're cool as heck don't get me wrong, but don't think they're green because they're not. A lot of reasons for that. I've talked about it many times in the past, on my radio show.

If you go to my website, you can just look that up and you can find out why, and I've got hard numbers there, anything else?

All right, everybody, make sure you visit me online. We have started some new stuff. If you are a frequent reader of my, now Sunday newsletter, which has my show notes. You are getting also one or two other newsletters during the week just short pieces of training.

I'm trying to help you out, but if you're not opening that newsletter if you don't download the images. That's how I tell that you opened it, then you're not going to get all of the supplemental material, including some audio programming that you can't get anywhere else. So make sure you go to Craig peterson.com and sign up for the newsletter. Open the silly thing.

So you get all of this free training and more. Craig peterson.com.

Apple has been really busy trying to make sure we know who's using our data and what they're using it for turns out Google's not too happy about that. You'll be surprised what they did this week.

Hi everybody. Thanks for joining me.

I've talked here about how Apple is really taking some major steps up in trying to defend our privacy. Apple does not make money off of our data. They don't sell it. They don't compile it and then sell it, Google, however, is trying to be the repository of all of our information. So much for the don't be evil thing. Right?

Well, Apple's got these almost like nutritional labels. You remember when the CDC or it wasn't the CDC, it was some federal agency, I can't even remember forced food companies to put labels on the packaging, telling us about calories, fat, various other types of things. You could make a bit of an informed decision by looking at that.

Obviously, there's other stuff that I don't know what this word means. I don't know what that is. What's red dye number two, all of those types of things, but at least it brings it to your mind. You can also see how many servings there are. It'll say this muffin is 500 servings and only a calorie a piece, right.

The reality is that box is really meant to be two or three or four servings, including that Coke that you might be drinking. I am more of a Pepsi man, but I haven't drunk either in years now, frankly.

Well, Apple is trying to do kind of the same thing. They've got millions of apps up at their app store. In the app store, of course, you can not only find the apps, but you can download them. You can buy them depending on what the app is. Most of these apps that are free, are really not free right? We've talked about that before. I don't know that we need to get into a lot of detail, but it goes back to that saying of if it's free, then your, probably the product.

That's been very true. Apple and Google both have caught a lot of companies. Who's been trying to steal our information successfully in some cases. Obviously, that's a bad thing particularly when you don't know about it.

So these labels that Apple is having app developers put on their apps have got a whole bunch of people upset, Google ran full-page ads in newspapers, complaining about it and how it's going to hurt small business.

The reality is, it is going to hurt some small businesses that do advertising. That's very, very narrow. It's going to hurt me if I'm doing that type of advertising no question about it. I don't do that. But one of these days, I hope to be able to do it.

What it is doing now, is stopping companies like Facebook. Facebook has always been doing tracking, not just when you're running their app. Facebook has been getting information from other websites from web pages like mine, for instance, I've got a Facebook pixel on my website so I know if you came from Facebook, what you're interested in and in what you're doing so that I can present information to you based on your interest.

I'm doing now for the very first time, this week, a similar thing. With my newsletter. If you have, for instance, said that you're interested in my improving windows security course, the newsletter isn't going to bother you about that anymore because I have this little signature at the bottom, here are a few things that I could do for you. If you want a little extra help. Some of it's paid, some of it's free, obviously, but. I think it's annoying personally to keep getting the same message every week. I've put into my email program, some conditional stuff so that if you've asked for the improving windows security course, I'm not going to bother you about that anymore. By the way, no, the course hasn't started yet. It's a labor of love. What can I say?

There are a lot of different types of tracking that are done and not all of them are bad. For instance, I just gave you an example of something that I've started doing, and I am doing some tracking in order to do that because I don't want to annoy you. I want to give you the information you need when you need it, right? Bottom line. It's like, I've always said, if I'm interested in buying a Ford F150, then I don't mind seeing ads for it, but if I'm not interested in buying a pickup truck or a Silverado, why would I want to see a GM ad when I'm going to get a Ford, right? It's really that simple.

Google, as I mentioned, has been complaining. They've done the full-page ads. They've complained to congress critters they've spent so much money. Lobbying, it's a real problem and a difficult solution to it. If you want to get rid of lobbyists, obviously the bottom line is you have to get rid of the money going to, and coming from Washington DC. If they don't have control over our money. If they don't have control over our lives. Then the lobbyists aren't going to be going there.

I don't care which side of the aisle you are on, or if you're right in that middle of the aisle. Lobbyists do not represent our interests as a nation. That's the bottom line.

Google's down there spending money saying, Oh, you're going to hurt the small businesses. When in reality, the biggest target that's going to be hurt by Apple cracking down on people taking our information without letting us know is Google.

It's going to be a problem for Google, so how to get around it. One of the things that Apple has for its apps that are on your iPhone and on also your tablets is a tracker. When was the last time that app was updated? Of course, when the app gets updated, Apple has a look at it and tries to see if there's anything malicious going on.

Now it's impossible to catch everything. Some of the stuff is very well, obfuscated. I can't blame Apple or Google for letting some of this malware through. But the bottom line is they want to know. When did you update it? What's going on?

Google apparently flagged its own Apple apps. The apps designed for iOS.

Think about the Google apps, obviously. There's the Google app itself. There are Google maps. Apps can be very useful, including Waze. I was so upset when they bought Waze, but that goes into the anti-trust stuff that is going on right now in Congress.

But I was looking at the phone and looking at the app and they were flagged as out of date. It had been two months since Google updated iOS apps. It has been updating its apps in the Android space, but not the iOS apps. The theory is that Google has not been doing updates on its Apple apps because of this new privacy labeling that Apple's come up with.

You see back in early January, Google could have said, we haven't been updating our apps because of the lockdown. The engineers are busy trying to handle this and that. We just had the holidays and I would have accepted that you would have accepted that. Well, that was what now six weeks ago. Google has, every year around the holidays a code freeze, which means no one can make any changes, that is done with right now. The company Google should have released two new versions, particularly since they come out with the new versions for the Android operating system, Gmail, Google Maps, Google search, Chrome, drive, photos, keep and Duo have all been frozen since Apple launched these privacy requirements.

What do we think is going on? Well, it looks like frankly, Google just doesn't want us to know what data they're trying to get at. What they're doing? What they're selling? What they're tracking, the inter-app tracking.

Google's been doing as well as Facebook and many of these others. What's the easiest way to not have to worry about that don't have a new release so that you don't have to abide by the new terms from Apple, which include, Hey, what information are you gathering? How are you gathering? What are you doing with my personal information?

It looks like Google took the easy way out again. It's phenomenal. I'm looking right now at, Gmail and it has not been updated on iOS since December 1st. The Android version of Gmail has had four updates since then. That's a pretty big deal, frankly.

Apple's definitely got people's attention. The app developers' attention. I am glad they're doing it as a user. I'm not so sure. I'm glad if I decide to try and do targeted marketing through some of this online pay-per-click and some of these other ways of reaching people. But you guys, already how I feel about you and I'm going to be giving you lots of good information.

Some of you guys become my clients because your businesses and you need that little extra help for your poor overworked IT people internally.

Lots of what's going on with Google. We'll see when they do come up with the next update, but it's a real problem.

Hey, if you want to get my weekly email where I have my show notes.

Now, these show notes are what I use here on the show. That's what all of these stations pick from, my show notes. The only way you can get them and get information about what's going on in the world and things you have to do right now is by signing up for my email.

Craig peterson.com.

Boy, I love space stuff. I have for years. I was so excited to play an extremely minor role, but to get involved with the NASA space shuttle program. Let's talk a little bit about what's next up for it.

I remember that day. I can't remember what day of the week it was, but that day when we landed on the moon watching it live. It was just mind-blowing. Of course the newspaper, the first time I had ever seen a color cover on a newspaper and it was a picture of our astronauts there on the moon. It was just so incredible.

Of course, you're listening to Craig Peterson.

NASA has been trying to get back to the moon for a long time. We haven't been funding them. Priorities have changed. A lot of people say why don't we spend the money domestically rather than on the space program?

The space program has provided us all kinds of benefits over the years. It's benefited mankind, not just by giving us things like Tang, for instance. It's given us all kinds of technology and science that we would never have had any other way. I'm looking right now at a report that was put together by AIESEC, which is the international space exploration, coordination group. It just a top-level executive summary. Numerous cases of societal benefits, new knowledge and technology from space exploration, things like solar panels came from the space program, implantable heart monitors. Cancer therapy, lightweight materials, water purification systems, improved computing systems, global search and rescue systems, course rockets as well. There's so much more, things we just weren't expecting. Thin materials, power generation, energy storage, recycling, and waste management, advanced robotics, health and medicine, transportation, engineering, computing, and software. Not just the $800 hammers. Okay.

Culture and inspiration. As you can tell I find this very, very inspiring. We've got all kinds of things that we are using just day-to-day that we don't even think about it. As space scientists, engineers overcome obstacles, in some cases, we never even realized were there and I think that's another phenomenal thing.

Well, right now, what we're doing is having private organizations competing to send our missions up. For many years now, since the space shuttle program was ended and it lasted far longer than they expected it to. But now that the space shuttle program has been over.

We've mostly been using Russian rockets to get our astronauts into space and also to get things to things like the international space station. What are we going to end up doing in the future?

We already know who was it, Bob and somebody, right? A couple of astronauts. They went up on the Elon Musk rocket and docked with the space station.

It was again, one of the most amazing things ever. I sat there glued watching it on the computer. It was just, wow. To see that.

We're looking at going to Mars. Now, we're looking at exploring some of Mars's moons more than we have in the past, doing all kinds of things that are just going to make a huge, huge difference to humanity.

It's been quite a while since that Apollo program of 50 years ago took humans to the moon and they were using chemical propulsion. What that means that you had rocket engines burn liquid oxygen and hydrogen in a combustion chamber. Nowadays we're playing around with hydrogen peroxide in order to get that oxygen.

They use to have their advantages and that gives NASA the ability to start and stop an engine really quickly. Back in the sixties, this was the most mature technology for space travel. We'd been using rockets. They were really piloted in world war two. It made a lot of sense back then.

However, now we've got some other problems we've gone to prepare for. We're going to be sending four or more astronauts to Mars. We want to colonize Mars, but relying on chemical propulsion to get beyond the moon, bottom line, it just won't cut it. The main reason is the amount of rocket fuel. Most of that rocket fuel is going to be consumed getting out of the atmosphere.

It's crazy how much we're talking about $2 billion for a flight of one of these huge rockets. These block one B configurations, NASA's SLS or space launch system rocket, is going to be able to carry 105 tons to lower earth orbit. That's a lot of money. They're not going to be able to get that many of them up there. That only takes it to lower earth orbit.

Now, of course, the idea is to do what in fact, the Apollo mission had looked at, which is get the fuel up to orbit and then have a rocket up there that maybe is assembled an orbit and is refueled in orbit. Then it goes to the moon. That was actually the plan NASA was originally going to pursue.

We're looking at that now when we're talking about going to Mars while we're talking about going even further out there. What can we do? Just for the fuel, by the way, $20 billion just to get the fuel up. That's just absolutely crazy.

There were some tests that were done, some studies that were done on behalf of NASA for a mission to Mars in 2039. So this one's quite a ways out. Of course, Elon Musk wants to do it even sooner. He is relying on these chemical rockets. By the way, to get back home from Mars, he's relying on being able to make rocket fuel right there on the surface of Mars and then charge up the rocket engines in the launch vehicle and then launch back up to get back to earth.

It's going to be really, really interesting to see what we end up doing. They are looking at a nuclear propulsion system. It's going to be interesting. NASA has had a budget for this. They got $110 million for nuclear, thermal propulsion development. We know a lot about nuclear fuel nuclear propulsion. We'll see what happens.

This starship concept that space X is building to send humans to Mars using chemical propellant. They're countering the costs involved with the chemical propellant by having this low-cost reusable launch system. We just saw one blow up here a few weeks ago, but that's okay there was no intention of having astronauts sitting on that candle. That was just a test system. We've seen him repeatedly now land successfully.

All of those boosters and it's amazing what's been happening now. They're not the only ones. We've got a number of other companies that are working on these types of systems. Space X, ultimately we're talking about pushing the boundaries of reuse and heavy-lift rockets to extreme limits which is exactly what space X is trying to do. They're looking for some other answers.

Hey, make sure you sign up Craig peterson.com. I want you to make sure you have all of the latest materials.

Craig peterson.com.

We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up killing people. Yeah. Yeah. Death by a police officer. Here we go.

If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information that I have available my podcasts, and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter.

I just want to get the message out is my bottom line.

We have these home cameras that we have welcomed into our homes. And one of the ones that have been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them live Real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring doorbell cameras

Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because why does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.

The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead, a 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently, they believe the report was an act of swatting where.

Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of these emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

The color also said he had a handgun that had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead or Injured nor taken hostage. His family told local media, he was not involved in online gaming.

Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that those hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

His revenue, his pay from the work he was doing, delivering food to people's homes were stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.

In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, causes death, many examples of that, and we're still reusing passwords. Give me a break.

We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

But anyway our businesses and government got broken that's what we're going to talk about right now.

Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.

Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because, I didn't tell you guys this, but I do love the fact that I was right again.

How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce Schneider.

You've probably seen him before. He is also, I think he writes for the Washington Post. But remember when this came out the word about the SolarWinds hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

In other words, going out after other countries in the cybersecurity realm. And we benefit from the lack of norms that are in cybersecurity. But here's what I really liked that Bruce said and I agree with it entirely. I'm glad, he must listen to the show. The fundamental problem is one of economic incentives.

The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely inexcusable, right? Inexcusable. So this is happening with SolarWinds right now, but it's going to be happening with other places out there.

We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican-born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from the tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure agency CISA, the department of Homeland security, the US department of state, the department of justice, the national nuclear security administration, the US department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others.

I use two of those.We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem.

How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody to use a password manager and I will have a course on that this year.

Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have email coming in and going out SMTP Imap.

They should be controlled and controlled pretty tightly. According to the department of justice, apparently, their email accounts were compromised about 4,000-ish people's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email me@craigpeterson.com and let me know, be glad to send you stuff.

ME@Craig peterson.com.

Take care guys.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. We discussed the new Amazon, ebooks, libraries, digital rights management and what some States are demanding from Amazon. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] In Rhode Island have bills as well as New York that would require Amazon, as well as everybody else, to sell eBooks to libraries with quote reasonable terms endquote.

Jim Polito: [00:00:13] Okay.

Craig Peterson: [00:00:14] Hey everybody, Craig Peterson here. Just got off the phone with Mr. Jim Polito and we had some fun talking about libraries, Jeff Bezos and even George Orwell, got into the act here. Anyhow, here we go with Mr. Jim Polito.

Jim Polito: [00:00:34] Hey, Amazon started off as a place to sell books. You know, online books and they basically destroyed the bookstore. I mean, we contributed to it. But now it seems that they're out to destroy libraries. Taking over the world, isn't enough for these folks.

I don't know, that's the accusation. Well, let's see if we can confirm it. Let's bring in our good friend and tech talk guru of Craig peterson.com. The man that website is named after, Craig Peterson.

Good morning, Craig.

Craig Peterson: [00:01:13] Good morning, Jim.

Jim Polito: [00:01:14] Oh, so here's the deal? We were just talking a little while ago about Jeff Bezos, started with his garage selling books out of there. Then mail order, then all of a sudden they sold everything.

They basically changed retail. They made what we told online shopping would be like 25 years ago. People said, Oh no, you're going to be buying everything online. We said, sure we will. But we are, COVID helped that.

Now there's talk that he's gonna close libraries and I went wait a minute. Is this a wild accusation?

Craig Peterson: [00:01:48] Well, it is kind of wild, and certainly an accusation. Unfortunately it's also true. If you look at the libraries work over the years, Jim, you go in and you borrow a book. Well, where did that book come from, right? The library bought it. Libraries for a long time, have been paying more for a book than you would. You might go into the bookstore and you pay 20 bucks for the book, but the library is going to pay a lot more for that same book. 50, even a hundred dollars sometimes.

So Jeff Bezos is doing right now. Is okay great. You've been paying for these books over price sometimes as much as a hundred dollars for one ebook and it can only be lent so many times, that ebook can. If you want to have five copies of that book out for people to read, you have to buy five licenses, that's what it's been.

Jim Polito: [00:02:44] All right. So wait a minute. Let me just make sure, because make sure I understand this. So in the old days before we had, you know, you bought a book online and you read it on your nook or whatever.

Hold on a second. So if I was buying a book for a library. I paid a higher rate because the library knew you were going to be loaning that book out, yada, yada, yada. Almost like the publisher said, Hey, we want a little bit more than the average person for this book. Is that true?

Craig Peterson: [00:03:14] Absolutely.

Jim Polito: [00:03:15] Okay. All right. So now I get this, you have intellectual property. You have a book that is virtual. I mean it's online. If you are a library and you want to let people be able to read that, download it and read it. You're going to have to pay a pretty penny to Jeff Bezos?

Craig Peterson: [00:03:38] Yeah. If he will sell it to you. See that's the change that's happened more recently? Jeff Bezos has decided, well, Amazon, right? I'm not sure it was him personally, but they decided that it will not sell, at any price, downloadable versions of it's more than 10,000 eBooks it publishes.

Think about an acquisition that Amazon made a few years ago, I have been an Audible subscriber for many, many years. Of course, Audible is the company that sells audio versions of books. Amazon bought Audible. Amazon has said, okay, you used to be able to go and borrow tapes at the library, and you'd listen as you're driving or whatever. You kept up on the latest business book or history or whatever he wanted.

So Bezos also owns Audible , which is number one for audio books. They say, Hey, listen, not only, are, we not going to sell any of our eBooks to libraries, but we're not going to let them get any audio books either.

Jim Polito: [00:04:43] Wow. Now that is pretty bad. Look from a business perspective, I understand. You're selling a product that now, why would someone buy it, if they could just join the library and download the book.

There's gotta be somewhere in between. So libraries will be destroyed. I mean, libraries are great places for research and other things and talented librarians can help you out quite a bit. A talented librarian sometimes is a lot better than what Google will tell you. When you go into a search about a certain topic. Librarians are much better, and don't, usually have an agenda, like Google. You should buy this while you're researching that, you know what I mean?

This could completely destroy libraries.

Craig Peterson: [00:05:35] Of course, we're on in Rhode Island and right now. Lawmakers in Rhode Island have bills, as well as New York, that would require Amazon as well as everybody else to sell eBooks to libraries with reasonable terms and quotes.

So we'll see, we'll see what happens, Maryland's already passed a law like that, but this is a real problem as you go forward.

Now, remember, Amazon is the one you mentioned, the Kindle, or actually you mentioned the Nook

Jim Polito: [00:06:06] That'sBarnes and noble, isn't it? Yeah.

Craig Peterson: [00:06:08] Yeah, it is whoever they are. Yeah.

Jim Polito: [00:06:12] Wait a minute. Hold on. Barnes and Nobles is on the phone.

Danny DME. Don't take that call. Yeah.

Craig Peterson: [00:06:21] Yeah. So whoever they are. Amazon has the number one ebook reader. Now, for those that have never done this, and ebook reader allows you to keep hundreds of books right there in this little almost like a display. They're fantastic. That's how I read 99% of my books.

So they've got the number one ebook reader out there. And because of that, they kind of control the whole thing.

But if you bought George Orwell's 1984, you might remember this was a few years back, Amazon decided you couldn't have that book anymore and removed it from everybody's ebook reader. All of the Kindles, they remove copies of 1984.

Jim Polito: [00:07:05] What is the reasoning behind this, because I thought that 1984 was no longer under copyright, but I could be wrong.

Craig Peterson: [00:07:10] Yeah, it is. The copyright holders told Amazon. That they didn't like the terms Amazon was putting the books under. So Amazon pulled them all back.

That's another problem with eBooks, especially with digital rights management, they can take them away, that copy that you have in those Dr. Seuss books could disappear from your Kindle, because you don't own it.

You see, if you buy a book and you read the book and you want to have a yard sale and sell the book for a buck or whatever it is, you can, because you own that book.

If you get a book from Amazon on your Kindle, or any of these other places, you don't own that, in almost every case. You're just getting a right to read it and. They can pull it back.

Jim Polito: [00:08:02] You know, it's interesting. My, my neighbor across the street, when he retired Dominic, Dominic, and his wife, Lucy, she's a school teacher. She's still working. He built one of those beautiful boxes that looks like a really big bird house with a glass door and it's for the neighborhood, put a book in, take a book, whatever. He can do that because people own the books. You own it.

Craig Peterson: [00:08:25] Right.

Jim Polito: [00:08:26] Good. Hey, whatever happened while we're on this topic with Apple and Apple music, when I downloaded a song for 99 cents and I thought I owned that song, I technically, did they change this? I technically didn't own it.

Craig Peterson: [00:08:45] Yeah, you never have actually. That's the way they're doing it, nowadays. Apple said, Hey, listen, we're going to do this. And Amazon did too. It's going to be much cheaper for them to distribute it. But again, think back, you and I both remember albums, records, the black vinyl, you know, or that, of course the acetate and other things and we switched over to CDs. The compact disk. People don't know, those are thesedays either. Right? It was much, much cheaper for the record industry to produce a CD than it was to produce a record. Their costs went from a couple of bucks down to just a dime, but they charged more for the CD.

What Amazon did. Yeah. More margin. Is, they said, Hey, listen guys, your distribution costs are going to be nil because all you're doing is copying digital books around. You're not going to have to have a warehouse. You're not going to have to ship these. You're not going to have trucks or anything else. We expect you to sell them for less. And the Amazon using its market power strong armed these publishing houses to lower their prices.

Now the publishing houses are really pushing back and saying, no, you can'ttell me I can only sell it for $10 and make $9.99 cents. Whereas before I was only making $2, now I want more money and it's a shame, but that's, what always happens.

Jim Polito: [00:10:11] And then your Don Quixote and you're going after windmills. Because you're going up against Amazon.

This is one of the dangers of a big success, like Amazon. You know, what's sad is in the whole thing. 1984, isn't it ironic that George Orwell's book about big brother and this and that you can't get it on Amazon.

When in fact the people who are using Amazon should know a little something about big brother, and it would be a good book for people to read right now.

Craig Peterson: [00:10:46] You can get it.

Yeah, it was just temporary. You can get it. You can get it.

All right. Good. I'm glad his descendants have, and they've worked at it. Craig fascinating is usual with you.

Folks. We always podcast segments. Which you can get on the station website, go to the Jim Polito show. On that page, you'll see Jim's podcasts on the right hand side. Just click there and this will be podcasted.

Craig, if folks want to get more information from you, how do they do it?

Well, just go online to Craig peterson.com and I also have my iHeart podcasts and tolisten to those things, just go to Craig peterson.com/iheart. That'll take you to the right spot.

I was listening, in France, iHeart, so I can pick up my safe space.

Jim Polito: [00:11:37] Nice. Craig as usual. Thank you. You always bring great stuff to the table. We'll talk with you next week.

Craig Peterson: [00:11:43] Take care, Jim. Bye-bye.

If you're in the healthcare industry, I am speaking for the big Massachusetts association this Friday. I am conducting a webinar for them on, of course, cybersecurity, particularly in the healthcare industry. If you are a member of an organization of some sort, and you'd like to have me on and do a webinar for you guys to let me know, I do make some time available for that and I may be able to help you out.

Just email me M E@craigpeterson.com. I know of few of you guys are going to be there on Friday at 10:00 AM. I think it is as we go over healthcare industry stuff. Then I'm also going to be doing a few more webinars afterwards, delving into some of these topics a little bit deeper.

All right, everybody take care.

We'll be back tomorrow.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation in regards to the irresponsible way that the States and Federal Government have been going about creating websites to schedule and distribute the Covid-19 vaccines. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Instead of going out to the private sector and say, you know what, booking an appointment for a vaccine. That's a lot like booking an appointment or a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent and just modify that slightly. Have that company modify it.

Well, you're familiar with the debacle that was and is. It's still there. It's just crazy. The problems with healthcare.gov. We got the Feds now rolling out their own websites. We've got States rolling out their own websites.. What can we expect from that? That's exactly what we talked about this morning, Chris Ryan and I on NH Today.

Chris Ryan: [00:00:45] Craig Peterson joins us on the show, now from tech talk that you hear on news radio 610 and 96.7 Saturdays at 11:30 AM. Craig, how are you?

Craig Peterson: [00:00:54] Hey, good morning, doing pretty well. You mentioned power, we lost it a couple of times over the last two days. Its no fun with all this wind.

Chris Ryan: [00:01:03] Indeed.

I could go into my pitch for the automatic standby generator from Generac, which you should get one of those. I'll refrain from going all in on it.

Justin McIssac: [00:01:11] Nicely done.

Chris Ryan: [00:01:12] But we do, we do recommend that, particularly in this given environment.

I want to ask you about the prevalence of scams and the prevalence of identity thefts and things of that nature. How much of that has to do with our usage of phones and hackings and things of that nature? We heard last week, from the States aspect of securities, regulation and protection. We've talked a lot about this outside of just your appearances. Has there been a sizeable uptick as in regards to that area?

Craig Peterson: [00:01:48] Yeah, there has been. What's interesting too, is it's been both directions. We've seen a huge uptick in finding some of these problems. Some of them have existed now for many months, maybe as much as a year or more. We only recently found out about, and this includes hacks from the Chinese and from the Russians, and of course that's nothing new, but the depth of these attacks has been brand new.

It's just astounding how they have really come after every last one of us, particularly businesses. They've been very, very targeted. Government agencies have been hit hard. DOD, Department Of Defense contractors have been hit hard.

You mentioned things like our smartphones that we're using all of the time now. Those are also starting to get hit. We've seen some responses. Samsung has said, Hey, we are going to support our phones now with security updates for three years or more.

It looked like maybe we did something in return because these Russian government websites all went offline after we vowed, President Biden said, we're going to retaliate for some of these attacks.

Chris Ryan: [00:03:08] That's really interesting. Whenever these things take place, whether there's an outage of a particular server or a website goes down, one of the first things that comes into my mind. Is this a glitch? Is this a problem? Is this an upgrade? Or they hit their their capacity. Or is this something a little more nefarious? Generally, is it just when a website goes down or a server is having some problems. Is it generally not nefarious or a lot of times is it well

Craig Peterson: [00:03:36] It's a little bit of both.

A lot of times it is. I've got to say that more recently, over the last year or so, we've been seeing something that we'd never seen in the Internet. That is that the internet was designed to be able to withstand atomic blast. It was very, very decentralized. The decentralized internet tended to be a very stable internet.

What's been happening more recently is that there have been acquisitions going on. We've got more and more the internet concentrated in individual hands. Look at how Amazon is running about 60% of the internet traffic, nowadays. Some of it, it's generating, et cetera.

We have seen, frankly, companies and Amazon is not one of them, but companies who are less and less able to understand what the consequences of their actions are. They're making changes to the internet and the networks.

These big outages we've seen over the last year, almost all of them were due to, let's just call it incompetence on the part of small companies that have been buying large parts of control of the internet. That's going to be continuing for quite a while.

So, it's not necessarily nefarious when something goes down. In fact recently, it's been a lot less nefarious than it used to be. It's just the normal course of things. More and more power concentrated in fewer and fewer companies that have less and less ability to do what they shouldn't be doing.

Chris Ryan: [00:05:13] The Washington Post had a really good article this weekend about the rollout of the new vaccine website and the federal website. Intalking with Kathleen Sebelius, who was the Health and Human Services secretary during the Obamacare and healthcare.gov roll-out, which of course was a disaster.

This website rollout is obviously significant. Every aspect of this is significant because Biden has called his shot. He has said, this is when things are going to take place. He has set a date. He has given that date. And, some may view it as being ambitious. Some may say we're already on that glide path, anyway.

The aspect of pushing forward, a website of this nature, how do things go wrong? How could they go wrong? Particularly in light of what happened with healthcare.gov, which was delayed for weeks, as a result of various glitches, despite spending millions and millions and millions of dollars on it.

Craig Peterson: [00:06:11] Yeah, my, I predicted that correctly, by the way. I had said it will take the about three years to get healthcare.gov to be working properly and that's exactly what it took.

We had massive outages. The problem I see here with this Federal Government roll out, this new website that was announced. Americans, all being eligible for the vaccine by May first. It's all part of a strategy that has been around a while.

The problem is that somehow businesses think that we're different. My business is entirely different from your business. Yet all businesses are 96-98% exactly the same. We have the same problems. The same concerns. Governments doing the same thing instead of going out to the private sector and saying, you know what? Booking an appointment for a vaccine that's a lot like booking an appointment for a ticket to go see a concert. Why don't we just use something that already exists. There's dozens of them, like Cvent. Just modify that slightly, have that company modify it. No, instead of that, we've got all of these people working for these government agencies, spending tens of millions of dollars of taxpayers' money to roll out something that is going to have major problems. We've seen that again and again, it's to me, Chris, just ridiculous what we're doing.

We could have this thing rolled out in a week from start to finish and have it cost of maybe a couple of hundred grand total with all the modifications and have it working day one.

Chris Ryan: [00:07:51] Yep. I mean this is the same thing that happened with healthcare.gov. If you had gone to, and that was in my view, a simpler website than this one is, you got to connect people with the location, the availability and all that the healthcare.gov in my view was a little bit easier. There was, not as much of a time constraint and there were best practices about those types of websites that already existed and could have been done at a fraction of the cost.

It'll be fascinating to see how much this vaccine website plus, I mean the state of New Hampshire just rolled out their own website on this. Now you have duplicity as well, where you can go to your state website, you go to the federal website. Could you go to both and shop for a better date? Are they both drawing from the same, you would assume from the same locations, right?

You go to the federal website, you go to the state website, you're going to get your vaccine still at the same spot, I assume. We've spent money, federal money on a state website, and now we're going to spend federal money on a federal website where they're both going to be doing the same thing.

Craig Peterson: [00:08:53] Yeah. Yeah, this is a problem and frankly, the biggest problem they've got is the back end integration. I inferred from what you were saying, which is how do we tie it in with the local Rite Aid store? All of these different tie-ins that have to occur. It gets very, very, very complicated.

Frankly, this is simpler than what they did with healthcare.gov, which had a lot more tie-ins to insurance companies in the backend. Leave it to the feds if you want something to get really messed up

Chris Ryan: [00:09:23] As always, I appreciate you joining us here on New Hampshire today.

Craig Peterson: [00:09:27] Take care.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

It is now up to 100s of thousands of organizations that have been affected by this Microsoft Exchange Server Vulnerability and it was so large that you could drive a freight train through it. Oh yes -- Microsoft did issue a patch but that did not fix the problem which was the backdoor that the bad guys installed. Nation-states, especially China and Russia have been spying on us an it will take a lot of research to determine what information they were able to get their hands on and what damage they can do with that information. We have deep fakes in the news again and there is more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Tens of thousands of US organizations hit in ongoing Microsoft Exchange hack

Samsung just out-Googled the Pixel at guaranteeing Android updates

Google’s Getting Rid of Third-Party Cookies, But Their Replacement Is a Terrible Idea

Google claims it will stop tracking individual users for ads

Tesla asks fans to lobby the government on its behalf

Make Deepfake Videos of Your Ancestors, But Consider Your Data Privacy When Making MyHeritage 'Deepfakes'

China’s and Russia’s spying sprees will take years to Unpack

A new type of supply-chain attack with serious consequences is flourishing

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] If you've been listening to me for a while, you may not believe this, but I've got a recommendation here on Android phones. Coming up we're going to talk about Google's new replacement for cookies, and a little bit about what Teslas' been up to. I don't like this.

I have never been a fan of Android phones, and you know why I haven't been a fan? The biggest problem with Android phones is the lack of security updates. That really does concern me a lot. Google also has not been the best when it comes to the Playstore and making sure that everything on the store is actually safe.

Here is some very promising news for people who like the Android platform or maybe dislike the Apple platform for one reason or another. Frankly, there's a lot of reasons there too.

Samsung has always been the leader when it comes to keeping their number one phones updated in the past. I've always said, make sure you can get updates. Samsung with its Galaxy phones has been good for about two years. They provide you with the security updates you need with some patches.

Even if Google comes out with a patch, most of the phones out there that are running Android, do not get the updates. Ever.

Some of these phones are older, they don't bother supporting them. Some manufacturers drop support within months after you buy the phone.

Samsung has been good for about two years. So my rule of thumb has always been, if you're going to buy Android, if you gotta do it. Stick with Samsung and stick with their number one model.

It is now promising four years of security updates for more than 130 Galaxy phones. That's pretty big when you consider that frankly, Android phones have been the butt of many a joke over the years.

Samsung is working pretty hard to make sure that they are really able to deliver for the Galaxy owners. Now, this is cool because Samsung just early, I think, this year it was that the Samsung promise that most new Galaxy phones would be getting about three generations of Android version updates. Now, that amounts to a few years, as a rule, the generations in the Android world are pretty much about a year.

Google has been providing updates for its own phone that it has. They provided to these other companies, like Samsung, to then take it and modify it to fit what they want and then they provide it to you. So, three generations are good. Now, they have said four years of security updates. Now, that's a pretty impressive promise. What they're trying to do is compete with Apple that has historically provided about five years of support. There's a big difference, obviously between two years and five years, but there isn't as much of a difference between four years' worth of security updates, and the five, six, seven years that Apple has been doing depending on what kind of security updates. That's very impressive.

Of course, Samsung just a year ago wasn't guaranteeing anything in terms of updates. Most new phone purchases were good for a year or two of updates, but only the Pixel, which is made by Google and Android. One base phones were on the record about how long you could be getting updates from the manufacturer.

Now Samsung is doing one better than Google. Remember, Google is the guy that actually provides the Android operating system. Google's only guaranteed three years of version and security updates for Pixel phones and that's not very many phones.

Frankly, Google Pixel is not been selling well. It's the standard that all of the Android manufacturers use in order to have a kind of proof of concept. So this is what it should look like. This just should be how it acts.

I'm looking at this list here. This thing is huge of all of these phones from Samsung that is going to be supported, here.

You've got the Galaxy foldable devices. The whole family of folds. The Galaxy S series and starts at the S 10 plus moving on to the S 20, S 25 G, S 20 plus blah, blah, blah. A bunch of different S 20 models and the S 21. That's pretty darn good. That's a lot of phones. Also, the Galaxy Note series, starting at the Note 10, all the way up to the current Note, 20 ultra-five GS the Galaxy AA series. Again, certainly, the 10 going up to eight 45, the Galaxy AMS, the up through the Galaxy X covers series and again tab series, which has been pretty popular for a lot of people.

If you're thinking about picking up one of your Android phones here soon, maybe you should give a second thought to the Galaxy. Now, they're guaranteeing that they're going to provide these security updates for you for four years. Yeah. Yeah. Okay, a guarantee we'll see how long that lasts. The other problem is how quickly are they going to get it out?

You'll see Apple devices, who just this week they had a security patch, they pushed it out and they expect to see 70, 80% of all of the phones with that security patch installed within a week. That's your Apple iPhones.

Google comes out with a security patch. They push it out. It has to go to the vendors like Samsung and then the vendor like Samsung has to take that add the device drivers that need for all of these models. Think about that for a minute. That's a lot of device drivers. That's a lot of different models. I think it's going to take them a while to do that and then they'll get it to you.

That security update that comes from Google, we've seen takes six months in the past before it gets on to your phone. If you're looking at. Security, if that's a real concern of yours and sure should be particularly after this disaster of a company called Microsoft and their windows products. Particularly now this Microsoft exchange server bug.

I'm so upset with Microsoft, but you know what? We'll get into that a little bit later.

The Samsung, the galaxies, the Google Androids are not designed for all of the safety and security that you really do need, frankly. When you think about the models were talking about 130 models that Samsung is going to be providing new updates for. Okay.

When we look at Apple and the iPhone models let me see how many iPhone models are there out there. I'm going to Google that right now, even as we're talking. So 2007, that is when they first came up with them. Okay. So since the very first iPhone, according to the pho iPhone Wiki, there have been 29 models of the iPhone. 29. Two nine. How many did I say Samsung is going to be updating? 130. So who has an easier time of providing updates, security, updates, testing the updates, pushing the updates, having people install the updates, the company that in the last, how many years has been making iPhones yet since 2007? Okay. So all the way up to 2021, that's a lot of years. Versus the Android who has been making these Galaxy's for many years, but is only going to be providing updates back to the Galaxy S 10 from 2019. That covers the 130 models. Are you getting what I'm selling here? Are you buying it? Yeah, it's impossible. Really? For Samsung, even with all that, they're trying to do here. They're trying to help out. It's impossible for them to keep up with security-based unless they have this massive team. I don't expect that they do have a massive team that's going to be working in parallel. 130 teams, one for each phone. That just isn't happening.

So again, if security is a concern, Android is not the way to go.

If, for some reason you morally, ethically, religiously cannot use an iPhone and then have a solid look at Samsung because of this promise they came up with, here in the last two weeks, of four years of security updates for more than 130 phones.

Finally, there is an Android phone that will have security updates at some point in time, versus what we've had over the years of really, you can only count on it for one or two years. It's just not worth it. Not a good thing.

Hey, I am sending out on my newsletter, not just my show Notes, but I have also been sending out one or two other emails a week that have some very narrow training. What I've been doing is making audiograms for you guys. This is a video that is of me speaking, explaining something. On that video, you can see all of the words you can read along, which is great for people who are hearing impaired, or maybe you want to have that computer muted for whatever reason. It makes it easy.

You can find me on YouTube, just go to Craig peterson.com/youtube, and you can catch those audiograms.

You can also get them. If you are an active subscriber to my newsletter, active means you open it. You read it. I know you do. If I don't consider you active you just don't get this extra information. So, make sure you open those emails.

A lot of us have been complaining about cookies and tracking for a long time. Google has finally heard us? I'm not sure about this. We're going to talk about third-party cookies, right now.

Hi, everybody. Thanks for joining me, Craig Peterson here.

Well, third-party cookies are where you go to a website, and that web browser kind of squeals on you, shall we say.

What happens is Google, for instance, is trying to track you as you go online. As you go between websites. They're calling this kind of an advertising surveillance industry on the web.

Frankly, this third-party cookie has really been an important part of this whole surveillance industry. What it does now is it allows a website to have a look at where you have been online. When I say it allows a website, it's really Google, that's doing the tracking. Obviously, you're going to a website, Google doesn't own every website out there. In fact, it barely owns any, when you look at the number of websites that are out on the internet.

So Google has this whole concept of if you're visiting this site and you have visited this site and this other site, I know something about you. So it sells that information because it's seeing the pattern, right? That's the whole idea behind the advertising.

Phasing out these tracking cookies and these other persistent third-party identifiers have been something people have been trying to get rid of for a very long time. The Electronic Frontier Foundation you'll find them online@eff.org has been jumping up and down trying to get everybody to pull up their socks if you will.

One of the first players to really jump into this was Apple. Apple has pretty much told the whole industry, you got to stop doing some of this tracking. Some of the tracking is okay.

Again, how many times have I said, if I'm looking for a Ford F-150 then I don't mind seeing ads for the Ford F-150. Why would I want to see ads for a motor scooter when I'm looking for a pickup truck. Frankly, if I'm looking for an F-150, I expect to see ads maybe for a Chevy Silverado or a Dodge truck, does that make sense to you? I'm looking for something and that's when I'm interested in seeing it.

Google is now jumping on this bandwagon because Apple has said we are going to be doing a couple of things. We are going to be forcing you, app developers, to tell everybody exactly what you are doing with their information, what you're tracking, who you're selling it to, what it's being used for. That's a very big deal.

It's got the whole advertising industry very worried. Google is coming along saying, okay, Apple will do you a little bit of one better. Of course, the biggest complaint from Facebook who ironically has been buying newspaper ads, if you can believe that. Google has been destroying the newspaper industry and now it's going to newspapers to try and get people to stop Apple from destroying Facebook's industry by blocking some of the advertising tracking that Facebook has been doing.

Now, what Google is doing is looking to replace these third-party cookies. How were they going to do that?

They are already doing a few rather sneaky things. For instance, they fingerprint your browser. Your browser has a fingerprint because you have certain extensions on your browser that you've added. You have your computer, which has an operating system that has a certain version. It has a certain amount of memory. It has a certain amount of disc storage. A lot of the private information, personal information about your computer can be gleaned by a website.

One of the things they've been doing this, you're blocking cookies. No problem. I can still figure out who you are and they don't necessarily know exactly who you are, but they have a very good idea.

One of the proposals Google has come out with is called the federated learning of cohorts, which is very ambitious and could be the replacement, if you will, for these third-party cookies that could be the most harmful. What it is is a way to make your browser do the profiling. Itself.

Historically they've been able to track your browser as you go around and then they have to pull all of that information together. They pull it together and they come up with a picture of you and who you are. Yeah. You're interested in buying a pickup truck, particularly an F150. This is an example.

That picture gets detailed about you, but it's something that the advertisers have to put together. What this flock or federated learning of cohorts is doing is it's boiling down your recent browsing activity into a category. They're calling this a behavioral label, and then they're sharing it with websites and advertisers.

The idea is basically your web browser itself is going to put you in one or more buckets and the websites that you're visiting and the advertisers that are advertising on those websites will be able to get that label that your browser has put on you. Yeah, you like that?

So what EFF is saying is that this could exacerbate many of the worst non-privacy problems with behavioral ads, including discrimination and predatory targeting. You can guess what those things mean, right? They're calling this a privacy sandbox, right? It's always the opposite.

If Congress is passing a bill, that is a COVID relief bill, you can bet that there's very little to do with COVID relief in the bill. Wait a minute, actually, that's true. There's only 9% of the money in this almost $2 trillion spending plan. 9%, that actually goes to COVID relief. Instant COVID relief bill.

Same thing here with Google, right? This is the privacy sandbox and it's going to be better, Google says.

In the world, we have today where data brokers and ad tech giants, track and profile everybody with complete impunity. Just like Equifax has. Just like Equifax lost our personal identifiable information, our social security numbers, or addresses or names or date of birth, et cetera, et cetera. Yeah. Yeah. Okay. We pay a small fine. Yet. We go on.

Are they out of business? Have they lost business? In fact, they gained business because people have been paying Equifax to monitor their credit. Oh my gosh.

That framing that Google is talking about is based on a false premise that you have to choose between tracking and new tracking. Does that sound familiar? Yeah. It's not an either-or. We really should be rejecting this whole new federated learning of cohorts proposal Google has come out with.

You can bet that Apple is going to reject this outright because it's really rather terrible.

If you care about your privacy on the other hand again, I look at it and say I want an F-150. I don't mind ads for pickup trucks, so what's wrong with that? Okay. There's two sides to this.

I just don't like them calling me by name when I walked past a billboard.

Stick around, we'll be right back.

I'm a fan of much of what Elon Musk has done, what he's trying to do when it comes to technology, and being a proponent of technology.

I'm not fond of Elon Musk taking over $3 billion from the taxpayers though.

Hi, everybody. I appreciate you spending a couple of hours with me here on the weekend. There's so much to cover.

Elon Musk it was $3 billion that he had received in government subsidies. Now we're looking at this, according to good jobs, first.org. We're looking at $4.9 billion dollars that Elon Musk has received basically from the taxpayer.

It's really sad when you get right down to it. Now, Tesla got money from taxpayers he's paid some of it back. It's really the government trying to name a winner.

There's a lot of competing technologies. There's even non-electric cars out there. How many of you even aware of this? That use, for instance, hydrogen instead of electricity. Now there's, of course, with any technology there's complications here and there. Hydrogen is absolutely amazing. It's an electric car. You fill it up with hydrogen and the only byproduct of the burning, if you will, the hydrogen, is water. In fact, it doesn't burn the hydrogen. It combines it with oxygen to make the water and produce electricity all at the same time. Very cool.

There are some prototypes out already on the roads out in California and some other places around the world.

When the government's giving out billions of dollars to electric cars, they're effectively naming a winner. Aren't they? Does that make sense? I don't think so. We've got to have a free market and this is not a way to have a free market.

It's just like with solar, wind, some of these other technologies where the government is taking our tax dollars and is saying this particular technology, and even worse, look at Solyndra, look at some of these others just absolute debacles.

Now, even worse they give money to a specific company within a certain industry. That is not a good thing. Government has a terrible record at picking winners. Even investors, you look at people who are angel investors and who are venture capitalists. They are lucky. If they make money in one of 10 of their investments. It is not a great way for them to make money.

A professional investor does terribly. Imagine how poorly a politician does. The politician is going to be listening to the people knocking on their door, saying here's some money for next time you run for the house or Senate. Or locally, in local elections, it even happens. That is a very bad thing.

It's been proven again, and again over particularly in the last about 140 years. Governments' terrible about picking winners. Yet they do it every day of the week. Tesla has gotten money, right? Some, of its tax benefits, some of it is actual cash. The bottom line, they've some great technology.

Now what's happening is Tesla is asking Tesla fans to lobby the government on its behalf. Great article by Rachel Kraus over on Mashable about this week. I love it.

She says a Tesla fan. Your mission. Should you choose to accept it is to go to bat politically for the company. Check this out online. You might want to too because Tesla has launched a new online portal called the Tesla engagement platform. CNBC spotted this about a week ago, and this is a hub where Tesla posts actions its users can take like contacting government officials when there is a potential law that would affect the company.

In fact, it says in a blog post on this hub Tesla built. Engage Tesla is a new platform for both Tesla's public policy team and Tesla owners clubs. Its goal is to create a digital Homebase for all of our work and to make it easier for Tesla community members to learn what's top of mind for us. Take meaningful action and stay in the loop. We hope you'll enjoy our, excuse me, will we hope you'll join us in getting involved? Oh my gosh.

So, I'm on Engage Tesla, it is at engage.tesla.com. Very pretty pictures. By the way, of some of these new Tesla cars, very cool cars. I would absolutely drive one of these things.

One exception, I don't like the handles. I talked about that a couple of years back. About door handles on the outside. Having been in emergency medicine for a while. EMS, I can tell you, in accidents, you want something you can grab onto and have serious leverage. The doors get bent, things happen. There's at least one case I'm aware of where someone got trapped inside the car that was involved in an accident and then burned to death because the people who were trying to rescue him could not get him out of the car because there are no door handles to pull on.

Yes. I know the handles come out automatically when everything's working right. I'm talking about the most extreme of problems here. Anyhow, I'm digressing again.

Uber is doing much the same thing, by the way. It isn't just Tesla. Uber is, in fact, they had their drivers this was October last year, sue Uber over what these drivers called pressure to vote and advocate for the proposition in California. Not a good thing when you get right down to it.

It is it's a real problem when you look at this in detail now. I'm not sure it's a terrible problem, but I do have a serious problem with companies soliciting the government in order to get things like tax subsidies in order to get special favors.

A lot of people do too. Look at all of the people who were upset with Tesla for trying to get a tax holiday for its battery plant and for some of its other facilities and things that they're doing.

By the way, there is currently a post on this Tesla engagement platform asking Nebraska residents to contact lawmakers about a law coming up for a vote that would enable Tesla to open showrooms and service stations in the state where it's currently prohibited.

Now I brought that one up, particularly because I think again, free market. There's no reason in today's world. No legitimate, let me put it that way, reason to have dealerships. I think we should be able to buy a vehicle directly from a manufacturer. If they want to have certified repair shops, knock yourselves out, but we don't need somebody sitting there anymore in a dealership. Same thing with most of these distributorships. I think we have been shown that a car can be ordered online, configured, online shipping to us. We can be pretty darn happy with it. By the way, that they are shipping it to us in our state gives them what's called a legal nexus. So, they do have a presence in the state. They can be sued in the state if there is a problem. This whole thing in Nebraska, I don't think there should be dealerships that are exclusively provided the right to sell vehicles within the state.

My opinion. All right. Hey, stick around. Cause we will be back.

We're going to talk a little bit about deep fakes. This is cool because MyHeritage is doing something that's scaring a few people.

You're listening to Craig Peterson.

Make sure you check out my website, Craig peterson.com and sign up.

You might've seen some of these deep fakes out there. Videos where it's putting Elon Musk's face on people or others in videos. Did you know that there's audio as well? They're using it to bring back our ancestors.

Hi guys. I really appreciate you listening to me.

There is a website out there called MyHeritage and it's very popular. It's a site that allows you to do a genealogical examination of yourself, a little look at DNA, they'll look at your family tree. They've got some research stuff up there. They have something new called Deep Nostalgia and I think this is very cool.

It really introduces some interesting problems, frankly. This allows you to animate a face in a photo. It's unnerving. When you have a look at this thing. You can check it out, again. MyHeritage.com/deep-nostalgia N O S T A L G I A. In case you're wondering how to spell it. They require you to create an account on their site and then you upload the photograph.

It takes that photograph and it has them pose it's really uncanny. I'm looking at a picture black and white that was taken it's right there on their site of a couple. I would guess this is a 1960-ish-era photograph based on the hairstyles and the glasses. It's just so weird because they have this photo. It's a head-on face-on photo and they've animated it so that the woman in this photo she's moving her head around. She's smiling. This is a really great smile. She blinked. She moves her head up and down and looks over to her and looks back again. Wowsers. It is absolutely amazing. You might want to check it out. It's a form of artificial intelligence that's doing this.

Of course, it has to make a bunch of assumptions. So if you look, you don't even have to look that closely, but if you look fairly closely at the picture, you'll see some detailed problems with her hair, the ends of her hair. At the top of her head, because you can't see the whole top of her head in the original picture. You can obviously not see both sides of her face or her head because that particular picture just a straight-on shot. It's making it up as it goes.

We're seeing deep fakes more and more. We're going to see a real problem, coming up in another couple of years, certainly by the time 2024 arrives with deep fakes.

We've already got Russians influencing our elections. Of course, not as much as the oligarchs out in Silicon Valley have been influencing our elections, but they are already influencing us in a very big way.

China, as well, imagine what'll happen when they start producing deep fakes of our presidential candidates saying things or doing things that they have never said nor done.

What I did is. I figured I want to give you guys an example. Audio seems to be a little bit harder for the deep fakers than some of the videos. At least the technology and audio hasn't quite come as far. I'm going to play for you right now. A deep fake of my voice.

This is not my voice, you're about to hear. Then I'm going to play a completely computer-generated deep, fake. So let's go here. I'm going to play my voice right now. This is an example of a deep fake using my voice. Did you catch that? That wasn't me. That was a computer again. I'm going to play it for you one more time.

This is an example of a deep fake using my voice. Now you can hear some of the problems with it. If you listen really closely that it's not really me, but it's close enough that if you weren't paying a whole lot of attention, you would not notice that it really wasn't me saying something.

Expect within the next year, that type of technology to get to the point where you won't be able to tell.

So think about it. What would happen? If a tape was released, talking about, Mitt Romney for instance, saying half of the voters that are never going to vote for me anyway, and that was recorded. I guess, by one of the waiters, it was at an event.

If you took this voice of mine and you created a deep fake, cause all you need is about five seconds worth of someone's voice to make a deep fake. You had politician X, let's say that Hillary is running again for precedent, okay in 24. You could have her say almost anything. The audio quality might not be up to it, but with most of these recordings that are made on people's cell phones either, is it.

I want to play another deep fake. This is a completely fabricated female voice. This is an example of a deep fake using a completely generated voice. Yes, indeed. I created that. I can make her say anything I want to.

Help me. Craig is holding me hostage inside his computer. Yeah. This is going to be a huge problem in the future.

There are concerns about what they are doing over at MyHeritage. Look at some of these pictures. Here's one it's cool. It's unnerving. Here's again, a guy with a family, this one's in color, he's got a right ear, the really pops out there, but he's looking around.

Have you used an iPhone and taken a picture and they call them live pictures. You can see the person right before the shutter is closed. You can see the person moving around. It's really a little video right in front of the picture. That's what these things look like.

Ah, here's this little kid he's looking around. Here's one, a very old one. Oh my goodness, it is creepy. You got to check this out online. MyHeritage is.com/deep nostalgia.

Now here's where the concern comes in. In an article on Life Hacker. By David Murphy, he is talking about taking these old pictures could be very old pictures of somebody sitting around somewhere, uploading it to the site. Then you get a little bit of nostalgia. I get creepy nostalgia that only comes from this static image now moving around on your screen.

I don't get it, really, I don't myself. I think that it's just plain creepy, but if you decide to do it, cause it is cool. Okay.

You probably should use a temporary account to make it to make your account over on MyHeritage and maybe also delete the photos that you upload and turn into these deep fakes. So many other websites out there, if you do go ahead and upload it, they go and claim the rights to it because it's a derivative piece. They made this little video from your photos. So, that's not your photo anymore. It's now theirs. It gives them a royalty-free worldwide perpetual and non-exclusive license to host copy, post, and distribute the content. It could be a problem, but I can tell you one thing that definitely would be a problem, that is if you use a username and the password you've used elsewhere.

Now, I have to bring this up because most of us are using the same password on every website or maybe, yeah we're really smart. We got three passwords and we vary them. I did that for years, but that was many decades ago. We just can't do that anymore.

If you are going to make an account on MyHeritage or anywhere else, make sure you don't use a password that you've used anywhere else because it is a problem.

Ultimately, it's a real problem for you and you can't believe your eyes or your ears anymore.

You share these pictures. I don't know that they allow you to download them because I did not put my own pictures up there. If these pictures are watermarked. Delete your account. Click that blue link under the big grid text to get started. That's supposed to delete anything anyways. You can figure it out but have a look anyway, it's in my newsletter that comes out on Sunday morning. There'll be a link in there that you can click on and see what they've been able to do.

Remember. When it comes to particularly things coming up in this next election where it really matters who we vote for, it really matters. Other countries have a very big opinion about who we should be electing to office.

Look at what happened with Rep Swalwell out in California. Here's a guy who was running for mayor the Chinese socialist government decided they would put a honeypot into his campaign. So they got this woman who was trained in seducing people. They seduced Swalwell and she raised money for him, for his campaign as mayor and stuck with him over the years, all the way until he was in Congress.

Then in Congress, she helped him get onto the very influential committee in Congress, where he had full access to our government secrets. Certain secrets that are. She apparently was feeding all the information right back to China. That is not a good thing, not a good thing at all. It goes to how much. China is willing to do to directly influence and infiltrate our government and our businesses.

If they will assign one of their spies to seduce a mayor of a small city in California, and then help elevate him to Congress and to the chairmanship in Congress. By the way, The speaker of the house, Nancy Pelosi has not removed him from that seat. She's got a Chinese spy problem herself. That's another story.

They're willing to do anything.

It's going to be a rough little time here going forward. Let me tell you these deep fakes are getting more and more real.

I'll be right back with a whole lot more.

You're listening to Craig Peterson.

I've been talking about this on the radio all week, at least since midweek. I want to talk about it now, and why I am so upset with Microsoft. I can hardly contain myself. This is crazy.

This is Craig Peterson here. You heard it right. The guy that's very upset with Microsoft. What shall I say? We're going to be getting into that in just a couple of minutes.

This is a real problem. What are we supposed to do? We have bad guys now doing what is called supply chain attacks.

The simple way to explain this is you have someone who is supplying software for you. It could be Microsoft. We heard about something, that happened very recently with SolarWinds and how they had software that they were providing their customers, which included government agencies. All kinds of them. It included many businesses. A lot of managed services providers were hacked by this.

A very, very big problem, because they were trusting the software that came from SolarWinds, and that software had been digitally signed, so they knew it was legitimate. Everything's good. Nothing to worry about here, let's go on with our lives.

However, the reality was that the SolarWinds software had been hacked many months prior to anybody really noticing. It was hacked in such a way that when SolarWinds provided their software to their customers were now infected.

Now, you might look at it and say SolarWinds, they should be signing their software. They should be watching the chain of custody for their software. They did, in both cases, they were signing it digitally so that their customers knew, okay, this is legit. This is really from us. You can install it. It's good.

But you're checking the signature didn't do any good. You were still going to be hacked because it was in SolarWinds software.

Microsoft has been providing us with software for many years. I helped develop some of the Windows NT code ways back when. Their new technology, that's what the current versions of Windows are based on. I can remember way back then, just what a mess it was I couldn't believe the way they did so many things. It was just absolutely crazy.

Of course, David Cutler, VMS guy, for those of you who remember all of that, really spearheaded that NT project. There were a lot of VMS systems in it, but then Microsoft ripped them out. They ripped them out because they didn't want to have to support an operating system that enforced security. VMS has been a very secure operating system is written by true programming professionals, not interns, as it was exposed with Microsoft, having interns develop one of their versions of their operating system, like 80% of it. It was crazy. That was only found out because of discovery.

Yet Microsoft is sitting on cash. A whole lot of cash. It's billions of dollars. Let me see. I'm looking up right now. Microsoft is sitting on $136 billion in cash, right now, according to MacroTrends. Now, were they using that cash, that $136 billion in cash, to make their products more secure? Doesn't look like it does it.

They had such a huge hole. You could drive a freight train through. The Chinese were able to infiltrate, in fact, many of our machines. This isn't tens of thousands of our machines, this isn't just something like ransomware, where you know about it because Hey, they're asking a ransom, right? They're threatening they're going to release our secrets, our software, our personal information. If we don't pay up it wasn't one of those things.

What they did is they got onto these machines in education. In other words, school districts. Hospitals, doctor's offices, government agencies, including defense department guys, Homeland security guys. Okay.

Our businesses all the way across the world. They put back doors on. What a backdoor is. it is something that allows them to go to your machine anytime they want? In this case do pretty much anything they want it to.

Microsoft comes out with fixes this last week. This is specifically for the Microsoft exchange server. By the way, if you're running Microsoft Exchange server, either locally in your business or in the cloud, you have this bug. They released a patch that supposedly closes the hole. It was used by the Chinese to install permanent back doors and what did they not do? They didn't remove the back doors that the Chinese had put in.

What's Microsoft saying to us then, are they saying, Hey, listen, you're fools for buying our software. I don't think they're saying that.

I am at the point now where I'm saying that we are fools for trusting Microsoft. We're fools for trusting these companies that have a product to sell. All they're trying to do is sell the product.

Look at what's been happening with some of these antivirus products. Look at what's happening with these VPN products. They have the software to sell and they're going to sell it.

They're not going to tell you the whole truth, nothing but the truth. Forget about it. They're going to do anything they can to sell you the product. So are Microsoft people.

Are people getting fired for buying Microsoft? It's like IBM in the seventies and the eighties, you never got fired for buying IBM.

People should be fired for buying Microsoft.

If you have a Microsoft Exchange server, not only do you need to make sure you install all of the patches. There were four critical Microsoft exchange servers, zero-day vulnerabilities patch.

In other words, things that they hadn't been able to patch it and know about yet. Supposedly, right? There are articles I've read that say they've known about at least one of these vulnerabilities for a year plus. There are other vulnerabilities Microsoft knows about that they haven't bothered closing the door on.

They are in our supply chain. They are getting us the software that we need and they're signing it and it's installed in it.

We're upgrading our machines. Sometimes the upgrades that they provide, the security patches actually work, in this case. It may close the door. What it's not doing is providing us with a way out of this huge mess.

Velma agrees with me here. Okay. No, she absolutely does.

They released fixes on March 2nd. Microsoft has been saying they've been used in limited and targeted attacks against law firms, infectious disease researchers, defense contractors, policy think tanks among other victims. Yeah. Yeah.

How is it a problem? I don't see it.

Oh, my goodness. Companies are seeing abuses of these Microsoft exchange server problems starting in January. There are reports that I found out there online. There are three clusters of vulnerabilities. Tens of thousands of US-based organizations are running Microsoft exchange servers that have been backdoored by these threat actors, who we are thinking are Chinese. They are stealing administrative passwords. They're exploiting these critical vulnerabilities in the email systems and calendaring application.

They've done nothing, Microsoft to disinfect the system's already been compromised. Can you believe this?

I got this from Krebs on security. They were the first ones to report this mass hack and Krebs has got some great stuff they have had for many years now, frankly.

Brian Krebs put the number of compromised US organizations, at least at 30,000 worldwide. Krebs said that there were at least a hundred thousand hacked organizations. Now, an organization is a government agency. It could be a hospital, could be a doctor's office, could be a business, right? Anything is an organization, tens of thousands in the U. S. This is the real deal. This is a very big deal.

You have to assume if you are running a Microsoft Exchange server, this is the server that is used for email. This is how small businesses often run. Their email is an exchange server. This is how hospitals and government agencies, et cetera, run their exchange server, which is ridiculous.

I have never purposely used an exchange server, right? If there's any way around it I've always has gone to something better, a Unix-based system.

Postfix, almost anything rather than the incredibly buggy software from Microsoft. It is just horrible.

Anyway, you have to assume that you were compromised between near the end last week of February and the first week of March.

Absolutely incredible limited targeted attacks. This isn't something that was just absolutely widespread. They went after companies because they knew they could get something out of the companies, a very skilled hacking group from China.

They're focused primarily on stealing data from US-based infectious disease researchers. As I said, law firms, right? Higher education institutions, defense contractors, policy, think tanks and NGOs. It's absolutely incredible what they've been doing and we cannot put up with it anymore.

I want to put a little word here. If you are a business and you have been using Microsoft exchange server restore from a backup. I would say in the January timeframe, you'd probably be safe. Probably, didn't have any back doors in January. Hopefully, you've got a backup that goes back that far. Okay.

Then find something else. Don't use this. Microsoft does not care. You cannot have $136 billion cash on hand, and not spending serious amounts on security. You can't tell me they care. Because frankly, I don't think they do.

Hey, go online. Craig peterson.com get some of the free training, other things, and I'm offering right there. Craig peterson.com.

Hey, welcome back everybody we're talking right now about InfoSec, information security. Have you thought about maybe taking up a bit of a new career? Well, there are some estimated 2 million open jobs in this one?

This is Craig Peterson. Thanks for joining me today.

This article appeared in dark reading. Now, dark reading is an online magazine, right? It's a website. And they had this article that I absolutely had to read because it reminded me of someone I know. One of our listeners, who decided he needed a new career. He'd lost his job. He'd been out of work for over a year and he had been managing a retail camera shop and they shut it down. He was stuck. What do I do? He'd been listening to the show for a long time. He decided he wanted to go into information security. He took some courses on it and he got himself a job. A full-time job being the chief IT security guy for this company after just a few months.

So that tells you how desperate these companies are. Kind of jerking his chain a little bit, but not right, because he just barely had any background. If you want me to connect you with him, if you are serious about thinking about one of these careers, I'll be glad to forward your request to him, just to see if he's willing to talk to you. Just email me M e@craigpeterson.com and make sure you mentioned what this is all about. So I know what's going on.

Ran Harel, who is security principal and product manager over at Semperis said, when I was growing up, I was quite an introvert, by the way, that sounds like a lot of us in it. I didn't realize until much later on in my career, just how great the security and tech community is looking back. I realize how quickly I could have solved so many issues, by just asking on an IRC channel or forum.

IRC is an internet relay chat, a bit of a technical thing, but it's an online chat.

I would tell my former self, the problem you are facing now is probably been dealt with multiple times in the past year alone. Don't be afraid to ask the InfoSec community and then learn from them.

That's absolutely true. I found an online IRC channel basically, and they were set up just to talk about CMMC is this new standard that department of defense contractors are having to use.

As you probably know, we have clients that are manufacturers and make things for the Department of Defense and they have to maintain security. It's been interesting going in there answering questions for people and even asking a couple of questions. It is a great resource. This particular kind of IRC is over on discussion.

You can find them all over the place. Reddit has a bunch of sub- Reddits. It's dealing with these things, including, by the way, getting into an InfoSec career. So keep that in mind.

There's lots of people like myself that are more than willing to help because some of the stuff can get pretty confusing.

All right. The next one. Is from Cody Cornell, chief security officer, and co-founder over at swimlane. He said, apply for jobs. You are not qualified for everyone else is.

Man. I have seen that so many times everybody from PhDs all the way on, down throughout a high school and who have sent me applications that they were not even close to qualified for.

Now, you can probably guess with me, I don't care if you have a degree. All I care about is can you do the work. Can you get along with the team are you really going to pull your weight and contribute? I have seen many times that the answer to that is no, but I've seen other times where, wow, this person's really impressive.

So again, apply for jobs you're not qualified for because everybody is. Security changes every day. New skills techniques and the needs of organizations are always shifting. And to be able to check every box from an experience and skills perspective is generally impossible. Looking back at 20 years of jobs in the security space, I don't believe that I was ever a hundred percent qualified for any of them, but felt confident that I could successfully do them.

So keep that in mind. Okay.

Again, imposter syndrome, we're all worried about it. This applies to more than just InfoSec. This applies to every job, every part of life, we all feel as though were impostors and that we're not really qualified, but the question is, can you figure it out? Can you really do it?

Next up here is Chris Robert, a hacker in residence, he calls himself over at Semperis and he says, overall, the most important lessons that I'd tell my younger self are not tech-based. Rather they focus on the human aspect of working in the cybersecurity industry. I think cybersecurity professionals in general, tend to focus on technology and ignore the human element, which is a mistake and something we need to collectively learn from and improve.

I agree with him on that as well. However, we know humans are going to make mistakes, so make sure you got the technology in place that will help to mitigate those types of problems.

Next up, who's got, Marlys Rogers. She's CISO over at the CSAA insurance group that's a lot of four-letter acronyms. You are nothing without data. Data is queen. Coming from an insurance person, right? Without hard data, you can only speak to security in more imagined ways or ways. The board and C-suite are aware of in the media cost-benefit is only achievable with related data points. Demonstrating how much we are fighting off and how the tools, processes, and people make that happen.

Next up we have Edward Frye, he's CSO over at our Aryaka. When I first started out, I was fairly impatient and wanted to get things done right away. While there are some things that need to be done right now, not everything needs to be done. Now have the ability to prioritize and focus on the items that will have the biggest impact.

I think one of the biggest lessons I've learned along the way is while we may need to move quickly, this race is a marathon, not a sprint.

Patience is essential for security pros. I can certainly see that one.

Chris Morgan, senior cyber threat intelligence analyst over at Digital Shadows, despite the way that many in media liked to portray cyber threats, not everything will bring about the end of the world.

For those getting into incident response and threats, try to have a sense of perspective and establish the facts before allowing your colleagues to push too quickly towards remediation mitigation, et cetera.

Expectation management amongst senior colleagues is also something you'll frequently have to do to avoid them breaking down over a mere phishing site. The quote, one of my former colleagues try to avoid chicken, little central.

I've seen that before as well.

The next one is things are changing daily and the last one is a perception of security is still a challenge.

So great little article by Joan Goodchild. You'll see it in my newsletter, which we're trying to get out now Sunday mornings.

You can click through the link if you'd like to read more.

As you can see. 2 million open jobs while between one and 3 million, depending on whose numbers you're going at in cybersecurity.

You don't have to be an expert. As I said, one of our listeners went from not knowing much about it at all. He can install windows. That's it. To having a job in cybersecurity in less than six months, stick around. We'll be right back.

I'm doing a special presentation coming up next month for the New England Society of Physicians and Psychiatrists. We're going to be talking a little bit about what we will talk about right now. What can you do to keep your patient information safe? What can we do as patients to help make sure our data's safe.

Hi, everybody. You'll also find me on pretty much every podcast platform out there. Just search for my name, Craig Peterson. I have a podcast and it makes it pretty easy. I've found some of them don't understand if you try and search for Craig Peterson, tech talk, some of them do.

I've been a little inconsistent with my naming over the years, but what the heck you can find me. It's easy enough to do.

I've got this new kind of purple-ish logo that you can look for to make sure it's the right one. And then you can listen to subscribe, please subscribe. It helps all of our numbers.

You can also, of course, by listening online with one of these devices, help our numbers too. Cause it's you guys that are important. The more subscribers we have, the way these algorithms work, the more promotion we'll get. I think that's frankly, a very good thing as well.

What do you do if you need to see a doctor, that question has a different answer today than it did a year ago. I won't be able to say that in about another month, right? Because mid March is when everything changed last year, 2020, man, what a year?

To see a doctor nowadays, we are typically going online aren't we. You're going to talk to them. So many doctors have been using some of these platforms that are just not secure things like zoom, for instance, which we know isn't secure.

Now, the fed kind of loosens things up a little bit under the Trump administration saying, Hey. People need to see doctors. The HIPAA PCI rules were loosened up a little bit in order to make things a little bit better. Then there's the whole DSS thing with HIPAA. All of these rules are just across the board are loosened up.

That has caused us to have more of our information stolen. I'm going to be talking a little bit about this FBI, actually multi-agency warning that came out about the whole medical biz and what we need to be doing. Bottom line, Zoom is not something we should be using when we're talking to our doctors.

Now, this really bothers me too. Zoom is bad. We know that it's not secure and it should not be used for medical discussions, but Zoom has been private labeling its services so that you can go out and say, Hey, zoom, I want to use you and I'm going to call it my XYZ medical platform.

People have done that. Businesses have done that. Not really realizing how insecure Zoom is. I'm going to give them the benefit of the doubt here. You go and you use the XYZ medical platform and you have no clue of Zoom. Other than man, this looks a lot like Zoom, that's the dead giveaway.

Keep an eye out for that because a lot of these platforms just aren't secure. I do use Zoom for basic webinars because everybody has it. Everybody knows how to use it. I have WebEx and the WebEx version of it is secure. In fact, all the basic versions, even of WebEx are secure and I can have a thousand people on a webinar or which is a great way to go. It's all secure end to end.

Unlike again, what Zoom had been doing, which is it might be secure from your desktop, but it gets to a server where it's no longer secure. That kind of problem that telegram has, frankly.

If you are talking to your doctor, try and use an approved platform. That's how you can keep it safer.

If you're a doctor and you have medical records be really careful. Zoom has done some just terrible things from a security standpoint. For instance, installing a complete web server on a Mac and allowing access to the Mac now via the webserver. Are you nuts? What the heck are you doing? That's just crazy. Just so insecure.

This is all part of a bigger discussion and the discussion has to do with Zero trust architectures. We're seeing this more and more. A couple of you, Danny. I know you reached out to me asking specifically about zero trust architectures. Now Danny owns a chain of. Coffee shops and his family does as well.

He says, Hey, listen, what should I do to become secure? So I helped them out. I got him a little Cisco platform, and second Cisco go that he can use as much more secure than the stuff you buy the big box retailers or your buying at Amazon, et cetera, and got it all configured for him and running.

Then he heard me talk about zero-trust and said, Hey, can I do zero-trust with this Cisco go, this Muraki go, is actually what it is and the answer is, well so here's the concept that businesses should be using, not just medical businesses, but businesses in general and zero trust means that you do not trust the devices, even the ones that you own that are on your network. You don't trust them to be secure. You don't trust them to talk to other devices without explicit permission.

Instead of having a switch that allows everything to talk to everything or a wifi network where everything can talk to everything, you have very narrow, very explicit ways that devices can talk to each other. That's what zero-trust is all about. That's where the businesses are moving.

There's zero trust architecture, and it doesn't refer to just a specific piece of technology. Obviously, we're talking about the idea that devices, and even on top of that, the users who are using the devices only have the bare minimum access they need in order to perform their job.

Some businesses look at this and say that's a problem. I'm going to get complaints that someone needs access to this and such. You need that because here's what can happen. You've got this data that's sitting out there might be your intellectual property. You might be a doctor in a doctor's office and you've got patient records. You might have the records from your PCI your credit card records that you have. I put on. Those are sitting there on your network that is in fact a little dangerous because now you've got something the bad guys want. It's dangerous if the bad guys find it and they take it, you could lose your business. It's that simple.

They are not allowing you to use the excuse anymore because of COVID. That excuse doesn't work anymore. The same thing's true with the credit card numbers that you have the excuse of I'm just a small business. It's not a big deal. Doesn't work anymore. They are taking away your credit card privileges.

We had an outreach from a client that became a client, that had their ability to take credit cards taken away from them because again, there was a leak.

So we have to be careful when you're talking and you have private information, or if you don't want your machine to be hacked, do not use things like Zoom. I covered this extensively in my Improving Windows Security course. So keep an eye out for that as well. If you're not on my email list, you won't find out about this stuff.

Go right now to Craig peterson.com. If you scroll down to the bottom of that homepage and sign up for that newsletter so you can get all of what I talk about here and more.

Hey, thanks to some hackers out there. Your application for unemployment benefits might've been approved and you didn't apply for it in the first place. Turns out somebody stealing our information again.

Hi everybody. Craig Peterson here. This is a big concern of mine and I've often wondered because I have not been receiving these stimulus checks. I did not get the first round. I did not get the second round and I contacted the IRS and the IRS says depends on when you filed for 2019.

Oh my gosh. Of course, I was a little late filing that year. They still haven't caught up. I guess that's good news, right? That the IRS data processing centers are terrible.

It goes back to aren't you glad we don't get the government we pay for is the bottom line here, but I've been concerned. Did somebody steal my refund?

Did somebody steal my unemployment benefits, did somebody steal my stimulus checks? It is happening more and more. There is a great little article talking about this, where someone had stolen the author's John personal information again. Now we probably all have had our personal information stolen, whether you're aware of it or not.

As usual, I recommend that you go to have I been poned.com and pwnd is spelled, pwn, D have I been poned.com and find out whether or not your data has been stolen and is out there on the dark web.

They have a really good database of a lot of these major hacks. Many of us have been hacked via these credit bureaus and one in particular Equifax who have all kinds of personal information about us, had it all stolen.

It's easy enough for people to steal our identities file fake tax returns. That's why the IRS is telling you, Hey, file your return as soon as possible. That way when the bad guys file, we'll know it's the bad guys' cause you already filed it. As opposed to you file your tax return and the IRS comes back and says, Oh, you already filed. We already sent you a refund or whatever. You already filed it.

That is a terrible thing to have to happen because now you have to fight and you have to prove it wasn't you. How do you prove a negative? It's almost impossible. At least in this case, hopefully, the check was sent to some state 50 States away, another side of the world. So you can say, Hey, listen, I never been there, then they can hopefully track where it was deposited.

Although now the bad guys are using these websites that have banks behind them, or maybe it's a bank with a website that is designed for people to get a debit card and an account just like that. That, in fact, is what was used to hack my buddy. My 75-year-old buddy has been out delivering meals and had his paychecks stolen through one of those.

These fraudulent job claims are happening more and more. It's really a rampant scam. We've had warnings coming out from the FBI and they have really accelerated during the lockdown because now we've had these jobless benefits increased, people, making more money staying in their home than they made on the job. Disincentives for working, frankly.

He's saying here the author again, John Wasik, that a third of a million people in his state alone were victims of the scam. This is an Illinois. This is where he lives. A third of the people in the state of Illinois, including several people that he knew.

We've got some national tallies underway. I don't know if you've seen these. I've seen them on TV and read about them, California. It is crazy. People were applying for California unemployment that didn't live in the state at all, would come into the state and once you're there in the state pick up the check, right? Cause that's all they were doing. Some people have been caught with more than a million dollars worth of California unemployment money.

Of course, it wasn't a check, it was actually a debit card. The same basic deal and California is estimating that more than $11 billion was stolen. Can you imagine that tens of millions of people could have been scammed because of this?

This is the third time the author had been a victim of identity theft and fraud. He wanted to know how could they get his information.

Well, I've told you, check it out on, have I been pwned. It'll tell you which breaches your information was in. It does it based on your email address. It'll also tell what type of data was stolen in those breaches. So it's important stuff. I think you should definitely have a look at it.

He is very upset and I can understand it. Data breaches last year, more than 737 million data files are ripped off according to act.com. Frankly, that was a digital pandemic, with more and more of us working at home.

I just talked about the last segment. Your doctor's office and you are talking to your doctor. How now? Cause you don't go into the office. There are so many ways they can steal it.

The FBI's recording now a 400% increase in cybercrime reports that we had this mega hack of corporate and government systems.

This whole thing we've talked about before called the SolarWinds hack, although it was really more of a Microsoft hack, and it went out via SolarWinds as well as other things. Be careful everybody out there. If you find yourself in these breach reports, have I been pwned make sure you go to the website. Set yourself up with a new password. At the very least use a password manager.

I just responded to an email before, when it went on the air today, from a listener who was talking about two-factor authentication. He's worried about what you're to use. I sent him my special report on two-factor authentication, but it is the bottom line, quite a problem.

Again, Use one password, use two-factor authentication with one password. Don't use SMS as that and you'll be relatively safe.

I don't know I can't say do this and you'll be safe. I don't think there's any way to be sure your safe.

Having these organizations, businesses, government agencies hacked all the time that don't seem to care about losing our data, right? Oh, it's a cost of doing business, some of these businesses, and I've talked to them, they'll look at it and say, how much will it cost us in fines if our data is stolen? Versus, how much will it cost us to keep our data relatively safe? For even a larger small company, a hundred employee company, you're talking about something that is going to be costing you about 25 grand a month. That's if it's outsourced.

If you're trying to do it yourself and a hundred-person company, you can easily be spending a hundred grand a month. It's expensive to do. They'll look at it and say, okay, this is going to cost us a million dollars a year, odds are, it'll be two years, maybe three before we're hacked. That's this statistic, although you're rolling the dice, it might be tomorrow that you get hacked. $3 million versus our fines are going to be about a million dollars. We'll just take the fine.

That to me is just disgusting. How can these people live with themselves? I don't know. Maybe it's just me. I'm going crazy.

That leads us to this New York Times article I was talking about on the radio this week. The New York Times article talking about how the United States, really, we are losing control of information warfare. Our warriors have been working at the national security agency and the FBI. They leave those agencies and go to work for private contractors. The tools that we've been using to hack other people have been stolen. The tools that we're paying to be developed, we meaning the US taxpayer, the tools that we have paid to develop aren't even being used, and that mega attack I was just talking about. That's an example of one of these attacks that would have been stopped had we been using the tools that the federal government paid for. It's just crazy. What's going on?

So here's the bottom line, everybody you can't trust most of these vendors that are out there. They have a product to sell. They don't have the best solution for you, right? They really don't. If they cared about you they would not be selling you antivirus software because it does not work.

If Microsoft cared about you, they would have come out with their anti-malware stuff. Windows defender, years and years ago. They would have redesigned Microsoft Office and Microsoft Windows, as well, because those were huge security holes.

Look at Adobe. They've been the source of the most security problems of anything out on the market, bar none. Flash was terrible. Java, another example of something that's been a terrible security hole for years. These businesses are trying to get a product to market as quickly and as inexpensively as possible. Quick is usually the number one goal. It has to be inexpensive for them to develop it. That means now they go out and they sell it because they got it. They're going to sell it. It doesn't matter if it's good. It doesn't matter if it even works overall for you.

That's why I'm doing these courses, these classes, these emails, I'm recording special stuff for you each week. I've got special emails that are going out for you each week.

We've got these radio show podcasts. This stuff is all free. All of it.

Now I charge for some courses, but everything else is absolutely free. Now I hope I have some clients that come from some of this stuff and I do get them, but most of the clients I get are by referrals.

I really believe in this. I'm putting my time, my money, my energy where my mouth is. But you have to take a step. You have to go to Craig peterson.com and you have to sign up right there. Craig peterson.com. Scroll down to the bottom of this screen. You'll see a little signup thing and I will start sending you my weekly newsletter.

Some of these little micro pieces of training that only take you a few minutes and information on courses and more. Craig peterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. Matt asked right off the bat about one of my soapbox subjects, Microsoft! I told him I have had it with them and their reluctance to fix their software when they have the means to do so. Then we discussed Russia and China and their spying and hacking activities. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] China and Russia spying on us. We knew this for a very long time. It's going to take years to unpack. We had the SolarWinds hack. Now we've got this Microsoft exchange server vulnerability. The most incredible drive a freight truck through it, vulnerability possible. I have had it. I think Matt Gagnon figured that out this morning when I was on the radio with him. So here we go with Matt Gagnon.

Matt Gagnon: [00:00:28] It is 736 on the WGAN morning news, which is a perfect time on a Wednesday to talk to Craig Peterson, our tech guru. He joins us at this time every Wednesday. Also, you can hear him on this very station on Saturdays at one o'clock because he talks about these subjects and more in more depth and detail.

Craig, how are you this morning?

Craig Peterson: [00:00:46] I am doing great. My bees were flying yesterday. All of my hives overwintered, which is like a first for me. It is just, wow. This is so great.

Matt Gagnon: [00:00:56] I'm sorry. I wasn't aware that you were a beekeeper.

Craig Peterson: [00:00:58] Yeah, bees. I got chickens. I used to have horses, and we got cats and dogs.

Craig Peterson, you also have technology-related equipment, gadgets galore and we're going to talk about some of that stuff right now.

Matt Gagnon: [00:01:09] I want to kick things off maybe, if you will, Craig with me, by talking about the ongoing Microsoft exchange hack. What exactly is this?

Craig Peterson: [00:01:19] This is an absolutely huge deal and it's not that difficult to understand.

I am, bottom line, fed up with Microsoft. This is just the latest in a long string of major vulnerabilities. In this particular case, we're talking about probably right now, the numbers are over 100,000 businesses that have been hacked. It's just crazy.

We know of about 30,000 give or take. Here's what the problem is. People in business need email. That's the life of a business. Many people made the mistake of trusting the Microsoft exchange server, which is something that you can get in-house. You run it on a little exchange server and aren't I great cause I got it set up. It's a little confusing. It also is offered in a hosted environment. Then Microsoft also has what used to be called office 365. That's now. Microsoft 365 also has email built-in. Okay. That's one of the core features.

However, yet again, we had major vulnerabilities. Remember a mail server has to be exposed to the internet to allow it to receive mail and allow it to send email. It should really be one of the most secure machines you have and well protected.

Many of us use bastion host. That's what I use for all of my clients. So that none of this nasty software or hackers get direct access to a complicated system, like Microsoft exchange server.

They got into machines. They were able to, at that point, install a backdoor. Which allowed the hackers, and this is almost certainly China based on kind of the fingerprints involved, it allowed them to spread throughout organizations, including government agencies. Major government agencies, our school districts, local government, the retail, small business, you name it have been compromised.

Microsoft, last week, came up with some patches that they released that kind of closed the door. The problem is the horses are already out of that barn.

What happened is they've installed the back door and Microsoft didn't close it. Microsoft released patches for this major vulnerability, in the Microsoft exchange server, which you run again for your email and they did not fix the compromised machine.

My advice to everybody, if you're a small business, if you're running an exchange server, you have to immediately patch it or have your service provider patch it. You should restore from backup from who knows how long ago, because there were backdoors installed.

There's multiple types. This is a major mess up Matt, absolutely major. It's going to have consequences for years to come. 80% of Americans, now it's expected, about 80% of us have had all of our personal information stolen and in the hands of Russia and China. This is going to bring her closer to a hundred percent.

Matt Gagnon: [00:04:39] Talking to Craig Peterson, our tech guru, who joins us on Wednesdays at this time to talk over the world of technology.

I saw a news piece today, actually on China and Russia cooperating to build a moon base of some kind, which is perhaps a subject in and of itself that I could ask you about.

That's actually not where I was going because China and Russia also in the news for their spying sprees, shall we call them. Where they're engaging in a whole bunch of different spying tactics. I'd love for you to break this down for us a little bit. It's a very interesting story.

Craig Peterson: [00:05:09] It really is. We had this SolarWinds hack, and I've been talking about that for a couple of months now on this show. This SolarWinds is what's called a supply chain attack where SolarWind software is used by businesses to monitor their networks, to control systems that are within their networks to put this rather simply.

SolarWinds issued a patch and it was an upgrade, right? It was the new features and some fixes and you got to install this. Apparently, over a year ago their software, SolarWind software had been compromised. SolarWinds then started distributing all of this Russian and Chinese malware to all of its customers. Again, including government agencies, businesses, et cetera.

Now you have a supply chain risk. In other words, I'm using SolarWind software. I trust it, they signed it. I checked the signature and I got hacked bottom line.

They have gotten into all kinds of systems, but SolarWinds said, Hey about a third of all of these tens of thousands of companies and agencies that have been hacked about a third of them don't use SolarWinds.

It turns out now that they came in through Microsoft bugs. In this other third of the cases, almost certainly including this latest one we found out about last week.

It is going to take years for us to try and figure this out, fix this problem. I am so upset. So upset with Microsoft. They are sitting on billions of dollars in cash, Matt, and they're not spending it to try and protect their customers. Small businesses, what are we supposed to do? It's nuts when our supply chain with our software providers giving us software that is hacked, already. We install it and now they are into all of our systems.

All the Russians have to do is spray and pray. They just send it all out. We're just sitting there with our fingers crossed. It's not going to hit us. Oh, I trust Microsoft or I trust Apple, whatever it is.

We have to hold these companies accountable. How about Equifax? They're still out there. They're still in business. They still have all of our information and they gave up about 150 million Americans plus Canadians plus some European data to the bad guys. They sit there and they say it's going to cost us ten to 20 million if we get hacked. To really fix this problem is going to cost us 30, 40, 50 million. We'll just sit here and won't spend the money.

We have to stop this now.

Matt Gagnon: [00:08:04] Craig Peterson, you hear his voice here every Wednesday at this time. You also hear it on Saturdays at one, o'clock talking about these issues and more.

Craig, I appreciate it as always. We will talk to you again next week, sir.

Craig Peterson: [00:08:15] Take care, Matt.

Matt Gagnon: [00:08:16] All right.

Craig Peterson: [00:08:16] Oh me. Oh my. Hey, Karen and I spent a bunch of time. In fact, the whole day, trying to get this membership site all up and running so we can put the courses in there for you. So you have the one place to go. So the free stuff that I'm going to be doing will be in there for you.

Plus some of the paid courses we are getting close, I know I've been promising this forever, but I've got a business to run. I got eight kids, grandkids, right? My bees, as I mentioned, and chickens and all these other animals running around. So it's just taking me time. I have to apologize for that, but anyhow.

I am very excited about what we're doing there because this is going to open up a whole new universe for us.

All right. Everybody take care. We will talk again soon. Probably this weekend.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. We discussed the new deep nostalgia app available from MyHeritage and some of the neat and also scary aspects of it. Then I got in a quick plug about the Microsoft Exchange Server hack that has affected 100,000 businesses. If you are using Microsoft Exchange Server, patch it and then wipe and restore your machine from backup because this hack leaves a back door in your system. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Many of us have these pictures. I have pictures of family, of course, from the 1800s, and lots from then on. There are technologies now that are using a form of artificial intelligence. Right?

Good morning, everybody. A very cool new, deep fake website that will take your old pictures and animate them. Yes. Those photos you've had for all of these years, you can now put in and it will turn them into a live living person video. It's amazing, but there's some risks. That's what I talked with Jim about this morning. Also, of course, I had to bring up this Microsoft hack.

I have had it with Microsoft. So here we go with Mr. Jim Pollito.

Jim Polito: [00:00:48] There is a warning using this could come back to haunt you. Joining us now, the man with all the answers, our tech talk guru friend, Craig Peterson. Good morning.

Craig Peterson: [00:01:00] Hey, good morning, Mr. Jim. Man, I remember LaVale myself. It's a small world.

Jim Polito: [00:01:07] You know, Roger LaVale.

Craig Peterson: [00:01:10] Yes, the name is just crazy familiar. So I'm sure we've met.

Well, maybe it's another one.

Jim Polito: [00:01:16] Roger did work in high-tech weather systems, satellite communication systems, weather systems. Your paths may have crossed at one time. He traveled the world. He was a great man and a terrible loss. Thank you. I appreciate that.

So tell me, people experiencing a loss because say they never met a grandparent. This was a great idea, right? You've warned us about how they can take my face though and make a video of me saying things that I would never say, and that's pretty bad. But this was a nice heartwarming application. No?

Craig Peterson: [00:01:55] It really is. By the way, it's too late to worry about these things. I see the next election cycle being full of these fake videos.

My heritage, you can go there. It's a very cool site. Kind of genealogy. There's so many people that are really interested in that. I have a son that is. We've traced our genealogy all the way back on both my mother and my father's side back to the seven-hundreds.

Jim Polito: [00:02:22] Wow.

Craig Peterson: [00:02:23] My mother's side, like a nine-hundreds or so. Once you hit a Royal line, it's just really easy. They really keep track.

Jim Polito: [00:02:33] Royal Peterson. Listen, be careful, because Megan Markle and Harry will be saying terrible things about you. So be careful.

Craig Peterson: [00:02:45] Well, did you ever seen that TV show Vikings?

Jim Polito: [00:02:47] Yeah.

Craig Peterson: [00:02:48] Yeah. Actually, some of those characters are my ancestors. The guy with the bad legs or whatever it is, right. I'm related to him. It's really weird. Now I have a daughter living in Norway, so it's a small world.

Many of us have these pictures and I have pictures of family, of course, from the 1800s and lots from then on.

There are technologies now that are using a form of artificial intelligence, that don't just take your photo, and I have software that does this.

For instance, I use some software that uses artificial intelligence and the machine learning that's built into the Apple devices now in order to really clean up pictures, make them look absolutely amazing beautiful pictures from the thirties and forties.

What my heritage is doing with their deep nostalgia is taking that to a much higher level and it makes some assumptions. If you've got a picture of someone that's maybe taken a little bit from the side or head-on it doesn't really matter.

It looks at that picture and it mirrors it because in most cases, our faces are almost the same on both sides. Right. You draw a line down the middle of your face, Jim, the right side is probably pretty similar to the left. The top of your head is probably fairly easy to figure out what's there. What you can do with this deep nostalgia app here, which's available online, is upload a photo and it will have that person come to life. Their head will move around, their eyes blink. They will smile. It does all kinds of amazing things.

It is, as you said, it's kind of cool to think about what my grandpa or grandma or whoever have looked like back in the day. A little video.

Jim Polito: [00:04:39] So what's the problem with it.

Craig Peterson: [00:04:44] Ahh. Well, we've had this problem for a while. Most of these deep fake apps that are available are from, you guessed it. There's this big country, like a billion-plus people. You have an idea, China.

Jim Polito: [00:04:59] Oh, I know where you're going.

Craig Peterson: [00:05:05] A lot of these are Chinese-based. They are taking our photos and doing basically whatever they want with them. We've seen this problem more and more, as people have paid more attention, and that is what rights do you have to that photo or video. Then once that photo has been modified, by an AI or something else, what rights do you have to that modified version?

This is really easy to do. You can upload your picture, you hit the animate button, you set up an account. If you leave it on that website, they have access to it and the rights to it.

We've seen many times that people there are doing malicious things with some of these pictures. I don't even want to go into that.

Jim Polito: [00:05:55] So you basically cede ownership of that intellectual and physical property because it's a photo to them to be able to do this.

Craig Peterson: [00:06:09] Yeah, absolutely.

Here's the second problem that most people have, and that is they're not using password managers, which means they are reusing passwords.

You go there, you can set it up using, for instance, in this particular case of MyHeritage. You can use your Google login, in order to log in. They have premium services. Most people are going to be reusing their passwords. They're reusing them across sites and that's been just an absolutely huge problem.

Then you might've decided to submit even more personal data to my heritage than just the basic information you have to give to create an account. Yeah. You see where it's going, right?

So it's never a bad idea to reduce your digital footprint. Adding this in. Giving up our photos may be good, may be bad. If you want to try it, it is kind of cool. They say that if you delete that little video off of their website they're not going to use it.

Jim Polito: [00:07:11] Can we be sure of that?

You know who we're dealing with, a year ago they were telling us, no, we don't have any problem over here with COVID. With any kind of weird pneumonia or more people die in by all means though, everything is A-okay.

Well. It's not. Craig. I really appreciate that. I've got a longer final word coming up today. I thought that this was very, very important because you will click on it. You see other people's stuff and you're so thrilled and It's always good to hear from Craig Peterson about these things.

Craig, in other ways to hear from Craig Peterson, His Highness, his Royal Highness HRH. We're going to have to put HRH in front.

How do we hear from his Royal Highness Craig Peterson in the future?

Hey, I sent out something real quick word of warning hundred thousand or more businesses have been hacked apparently by the Chinese because they're using Microsoft exchange server.

Okay.

Craig Peterson: [00:08:18] Government agencies have been hacked by this. Retail, education, our schools have been hacked. Hospitals have been hacked. Microsoft just released a patch for it, but it does not remove what it did, which is put a back door on your machine.

They're taking everything from all of these businesses, government agencies.

If you're using Microsoft exchange, patch it up now and then restore it from a backup because they may have compromised your machine.

If you are someone who's been using Microsoft exchange, find options. I've had it with Microsoft. I have had it with them. This is the final straw. Forget it.

Anyway, Craig peterson.com. You'll find out about this and so much more. There is so many little pieces of training. I have started giving them every week. Multiples. I got big stuff comin' up. Craig peterson.com.

Jim Polito: [00:09:11] Craig, thank you so much as usual. What a great contribution you make to the show.

We'll catch up with you next week or who knows maybe before.

Craig Peterson: [00:09:22] Take care, Jim

Jim Polito: [00:09:23] Thanks. Craig Peterson. Great guy.

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. I jumped right into a conversation that he and Justin were having about the Royal Family and because I am from Canada, I had a bit of a different perspective. Then we hopped up on one of my soapbox topics - Microsoft. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Installing the patches will not get them out. It will not even remove the back door that they've installed on your server. If you can believe this right. Its incompetence is running rampant yet again.

Hi everybody. Craig Peterson here. We started out by talking about the Royal family because Chris Ryan over on NH today has been talking a lot about that. What's going on with the Royal family? I have a little experience with that. Well, we talked about it.

Then we got into a soapbox for Craig, which was Microsoft exchange server. I could not be more upset with Microsoft. I have not liked them for decades, now. They are incompetent, if you ask me, in so many ways.

I'm sitting here pounding on the table. I don't know if you can hear it, but anyhow, We get right into it. I mean the down and dirty of it, because once again, we have had our data stolen this time by the Chinese.

Chris Ryan: [00:01:07] The queen does not have any power, Justin. These are all ceremonial positions. She has to sign off on the laws. She just does it. She's supposed to sign it.

Justin McIssac: [00:01:17] If she decided she felt like having some power.

Chris Ryan: [00:01:20] You can't. The prime minister controls all of the key roles of government. Going to war. Things of that nature. All of her roles at this point are ceremonial. For over the last number hundreds of years the monarchy has diminished and power based upon their incompetence.

Justin McIssac: [00:01:38] It's time to take the power back.

Chris Ryan: [00:01:39] The power has been taken back. But maybe she shouldn't sign it. Maybe she shouldn't ceremonial signing things anymore. Is that what you're saying?

Justin McIssac: [00:01:45] No, just declare war on somebody.

Chris Ryan: [00:01:47] You can't do that.

Justin McIssac: [00:01:47] No, I think she can.

Chris Ryan: [00:01:48] She can't declare war.

Justin McIssac: [00:01:49] As I understand that she can.

Chris Ryan: [00:01:51] You don't understand it.

Justin McIssac: [00:01:53] That may be the case, but as I understand it she declared war.

Chris Ryan: [00:01:56] She can not declare war, she holds no real power in the British government, none zero.

Justin McIssac: [00:02:02] You're just trying to minimize her. That's what you're doing. You're hitting on the Royals and I won't stand for it.

Chris Ryan: [00:02:06] Right now in the program. Is Craig Peterson. Craig, how are you?

Craig Peterson: [00:02:10] Hey, I'm doing well.

You know, power in the Commonwealth.

Chris Ryan: [00:02:14] You have as much power in the United Kingdom as the queen does.

Craig Peterson: [00:02:19] The queen, she appoints the governor-general in all of the Commonwealth countries.

The governor-general has the power in the Commonwealth countries like Canada, New Zealand, Australia, et cetera. The governor-general has the power to dissolve parliament effectively firing the prime minister.

She has quite a bit of power outside of the UK itself. The governor-general is a post that's above all of the elected officials in every Commonwealth country.

Chris Ryan: [00:02:52] Australia, Canada

Yes, that is true. In the United Kingdom itself, she does not have the power to declare war, to change the laws that are signed, she is a ceremonial figurehead. However, she maintains that position and influence outside of.

Craig Peterson: [00:03:06] Yeah, she does. She gets a stipend too from the government.

Chris Ryan: [00:03:09] It's good to be The Queen

Justin McIssac: [00:03:10] Sun never sets the British empire, Chris.

Chris Ryan: [00:03:12] You wonder though, we are going to continue on this Craig since you've indulged me. Which may be the biggest mistake that you make today. The question though is as we start to hear more and more about things that are taking place. Whether it's with Prince Albert and I don't understand why that continues to get brushed under the carpet, while the circumstances with Harry and Megan received this type of attention.

But appropriately so. Now we're hearing claims that there was racism, within the crown and there were questions about how dark the complexion of their child was going to be, to Harry. That was relayed to Megan. As an individual interested in this, do you see anything changing in regards to less ceremonial roles? The crown diminishing even more with the questions, around Charles, as well and his ability to lead?

How do you see this affecting the crown as they seem to decrease in terms of what their actual power is but their influence increases? The intrigue in them increases on a continual basis.

Craig Peterson: [00:04:14] Well, parliament's never particularly liked them because they don't like the budget money going to them.

But I can tell you that throughout the Commonwealth and the UK, the Royal family is like the center of the conversation. I have an aunt who has passed now, Anna Hanna was her name and she lived for the Royal family. Everything about them. She knew all of the details.

Chris Ryan: [00:04:38] Right? It's insane.

Craig Peterson: [00:04:41] I think it's a little crazy, but we got the same thing here.

People talk every day about these stupid artists that can't even sing. These actors and actresses can act. Follow everything they do. Look at the people that are famous for being famous. The Kardashians, what did they ever do? Well, they built some big empires that's for sure.

It's the same type of mentality.

Chris Ryan: [00:05:06] It's true, but I have a lot more respect for it. I have a lot more respect for any actor, musician, or influencer than I have for the crown. Basically, all that you did was be born into a circumstance. That is no reason for me to be interested in you other than the fact that you have a tremendous lineage. That is what upsets me more than anything else about those particular individuals.

Now, certainly, there has been the benefit of nepotism for some folks in acting and sports and music and all that. Those folks have interest-based upon talent. Whether that's the talent of just drawing attention. Then, therefore, monetizing it, the Kardashians, as an example, there. I have a lot more respect for Kim Kardashian than for the queen of England. I'll just put that right out there.

Well, let's transition here before we get into more trouble, right?

We'll get you into trouble.

Tens of thousands of US organizations hit in an ongoing Microsoft exchange hack. At least 30,000 compromised US organizations as a result of this hack. What took place? What concerns should average Americans have about that?

Craig Peterson: [00:06:17] This is an extremely big deal. I did a video on this. Everybody who was on my email list, you should have gotten a little copy of this last week when it happened.

If you are a business, Chris, you have to have email. That's kind of the lifeblood of a business is email. Many companies have made the mistake. I've called it a mistake for decades, of using Microsoft exchange server.

Microsoft is a company that happens to sell software and usually, it's not particularly good software. I've got a little bit of an opinion on that. For years, I helped develop windows NT early on in Microsoft history. I've used it all. I've developed on it all. I'm talking about the operating systems here.

Here's what happened recently. Businesses have been using Microsoft exchange server, as have government agencies, as have retail, our educational institutions. No one gets fired for buying Microsoft.

That just drives me crazy cause they got some really bad stuff. The bottom line and I have a friend who loves the Microsoft stuff because he'll always have a job trying to fix it. That's beside the point.

Right now, there was such a huge hole that freight trains are driven through. Anyone could easily gain control as the server over any sessions in any data. So last week, Microsoft issued an emergency patch for all of its exchange servers, that kinda sorta fixes the problem.

The problem is they've gotten into, probably over a hundred thousand computers at this point, and they have put back doors into the computers. They're using the computers now to attack other computers, to grab all of your passwords, all of your history, all of your files and you have no idea.

Because people are not doing the right stuff, which is blocking outbound connections from things like their exchange server. They're exposing it directly to the internet which you have to do, cause it is your main email gateway. This is just incredible.

The federal government has jumped on this. Expect congressional investigations, which will solve nothing. By the way, if you install this patch, Chris, you may close the door.

The problem is the horses are already out of the barn and you may already be infected. The odds are really good. If you're running an exchange server that you have been attacked, that they are inside your network.

Installing the patches will not get them out and it will not even remove the back door that they've installed on your server. If you can believe this, right.

Incompetence is running rampant, yet again, and we're losing all of our critical data.

This is probably China, by the looks of it, and it just a scary, scary thing. Patch right now if you're a business, if you're a school, if you're a nonprofit, right. Patch. You've made the mistake of running a Microsoft exchange server, patch it and look at alternatives.

Chris Ryan: [00:09:37] I think that there's always a cause for concern and diligence in regards to our information. Let's be honest, we're being a little bit more open with that than we have in past time periods.

Evolution over, not just the last couple of decades, but over the last few years has been pretty significant. In how frequently we use our credit card information or personal information. You think about the explosion in delivery services and ordering things online with that each time you are putting your personal information there.

What should it be people's concerns on that?

Craig Peterson: [00:10:11] Well, things like credit cards, aren't too bad. If you have a visa or MasterCard check with your bank or the issuing company. What I do, if I have to give a credit card online is I have an individual unique credit card number for every website. That's absolutely a free service from all of these credit card companies. Every one of them has it. So check it out, find out more about it. You can install it on your browser. You probably want to use a secure browser. At any rate that's a whole other topic for discussion.

You've got to give your information nowadays, especially with us being locked in for the last year. Use unique credit card numbers, and you can get those for free from your credit card company. It's just a little plugin for your web browser.

Businesses, you've got to pull up your socks. Cannot let these people's personal information gets stolen. Remember this includes doctor's offices with your personal health information. Hospitals. It goes on and on. The C levels, Chris, I think are the biggest problem here in all of these companies. You give you a credit card number to a quote to secure server. It's not really a secure server. It's just that your data is encrypted, going to the server. Once that company has your data, is it being stolen?

Is the CEO looking at this, like Equifax apparently did, from some of the articles I read and said, Oh, well, let's see, it's going to cost us, 10-20 million if we get hacked? It's gonna cost us 30-40 million to fix the problems. We're not going to bother fixing them. We're going to cross our fingers. We can no longer do that.

Chris Ryan: [00:11:54] All right, Craig. Appreciate your time and look forward to talking again next week.

Craig Peterson: [00:11:58] Take care.

Chris Ryan: [00:11:58] All right. That is Craig Peterson with tech talk here on Newsradio 610 and 96.7, Saturdays at 11:30 AM.

I am Chris Ryan. We shall return with more after this.

Craig Peterson: [00:12:09] Woo mama. Keep your eyes on your email, because Improving Windows Security is about to launch. I think what I'm going to end up doing is we're going to do a couple of classes live and available for anybody for free before we get into the paid course.

Keep an eye on your email. Also, I'm going to let you know people who've already signed up for the Improving Windows Security course, I'm going to give you a massive discount. You'll get a coupon for that.

We'll be back Craig Peterson.com, of course. If you're not on the list better sign up soon because this course is starting.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

I am sure that most of you know about the problems Texas experienced with its energy infrastructure well there is more bad news for our nations' infrastructure and that comes from a vulnerability in the programmable logic controllers that many of these large infrastructure providers use to control the flow of product. (i.e., water, electricity, natural gas, etc.). Also this week Google Chromebooks outsold Apple but that is not the whole story. We also dug into processors and the importance of them and how it affects what you do daily. Then we discuss Clubhouse and why it may not be the best platform to get on and there is more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Embracing a Zero Trust Security Model

Turns out Most Manufacturing, Water Supply, and Power Companies Use Controllers with a Security Severity Score of 10 out of 10

Chromebooks outsold Macs worldwide in 2020, cutting into Windows market share

Clubhouse is the New Up-and-Comer but Security and Privacy Lag Behind Its Explosive Growth

New York sues to shut down 'fraudulent' Coinseed crypto platform

Former SolarWinds CEO blames intern for 'solarwinds123' password leak

WhatsApp will basically stop working if you don't accept the new privacy policy

TikTok breaching users’ rights “on a massive scale”, says European Consumer Group

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Apple just got passed by Google's Chromebook. We'll tell you more about that. Clubhouse the app everybody seems to want, and it's invite-only. Sound familiar? That's happened before has got some serious privacy problems.

Hi everybody. Craig Peterson here. Thanks for joining me today.

There are a lot of things to talk about and I'm going to start with this article from ARS Technica, talking about programmable logic controllers.

Now I can see you sitting there saying, what are you talking about, Craig? Who cares? Here's, what's going on. You heard about the solar winds hack? It's been something we've talked about pretty much every week here for the last Oh a month or so since it really happened. And we found out some more stuff about it this week, by the way, we know who the group is that actually did the hack very professional group. This means, of course, nation-state, but.

They were going after different types of companies, that help the different types of companies, as well as government organizations. In other words, they were targeting MSPs managed services providers. And unfortunately, most of them failed because it's rare, very rare to find an MSP that actually takes care of security.

And I'm not going to blame them. I'm not going to blame you for using one of these MSPs that got compromised. Because ultimately, security is a long tail thing. It is an industry in and of itself. It's hard to keep up. It's hard to keep moving forward. But I brought this up because I wanted to tie it into something we also talked about a bit for the last two weeks, and that is that water plant in Florida.

This water plant in Florida had the amount of lye added to water, turned up 100 fold. Not 100%, a hundred times more lye in the water and somebody noticed and all well and good.

Who did it? We don't really know, but here's the problem I want to talk about today.

And that is the SCADAs systems, these PLCs, in other words, The computers that are controlling the valves in these various businesses and government agencies, the water plants, the electric plants, et cetera. You had valves. Those were these tubes. Remember that, and then transistors for a little while. Anyhow.

This is something that's a very real problem because Rockwell automation you've heard of Rockwell before. I am sure of that because Rockwell has been a government contractor forever. They've done a whole lot of stuff in the military space and they do a ton also in the civilian space.

Rockwell makes hardware that's used to control equipment in factories, a lot of equipment in a lot of factories, as well as all of these other places out there. And it is what's called generically a "programmable logic controller." They're selling them under this logix brand. You'll see them everywhere. They control everything you can think of out there.

Some of them are very small. There might be a, like a toaster that you'd have on the countertop for instance, or something as big as one of those little pizza ovens you can put on the counter, but then they can be a whole lot bigger than that. But they help control equipment. And. Oh, the manufacturing and the processes on assembly lines and other manufacturing environments.

You might remember what happened in Iran, where they had these PLCs, programmable logic controllers, that were part of this whole SCADAs system. It's all together. And in Iran, they were using them to control centrifuges and those centrifuges were being used to refine nuclear material eventually to make nuclear bombs. At least that's what we said. That's what the UN said, et cetera, et cetera. And then it makes sense, right? They have to refine the yellowcake. So that's what they were doing. And what did we do?

Apparently, we got together with this country called Israel. It's over there in that same neck of the woods. And with them, we came up with some software to break into the computers at the Iran facility. Now, these computers were what we call air-gapped. They were not directly connected to the internet. So how did we hack it? We hacked the old-fashioned way. No, we didn't use a little honey bait. What happened with rep Swalwellout in California, who I don't understand how he's still sitting on the number one top secret committee in Congress, even though he spent years with this Chinese spy who obviously would have been feeding all of this information that he got back to China. I don't understand Nancy Pelosi. Sometimes this is just crazy. What's going on in Congress?

It wasn't that? Okay. It wasn't a honey trap. It was a honey trap. I guess what they did is they developed this piece of malware, knew that they had to get it on to the machines that controlled the manufacturing process there in the plant that did the refining in order to make the nuclear bombs.

How can you get it in if it's air-gapped, how can you get it in if those machines are not connected to the internet? But it doesn't matter if you break into the firewall because they're not behind the firewall. They're not on a network that is accessible from the outside. However, they were networked and they have to be networked inside the building so that you can have one computer that's monitoring the spin rates of all of these different centrifuges and just kind of keeping tabs on everything. So they went ahead and they put this little virus onto a thumb drive. And then, in fact, they made dozens of these thumb drives. They found out where the engineers who worked at the plant went for coffee, where they went for lunch and they scattered these around.

And then a coffee spot at the lunch spot. And so now all of this stuff is scattered around these little thumb drives people, pick them up, Oh, a free thumb drive and they take them into the office. And this particular piece of malware was specifically crafted for this programmable logic controller. So if you plugged it into your computer as an accounting puter computer, it would say, Oh, wait a minute this is an accounting computer. I don't care.

But these guys brought it back into their manufacturing facility and it did work there and it took over control of the machine that controlled all of these centrifuges. And fuges, it keeps saying fuses, centrifuges and it spun them out of control.

And while it was spinning them out of control, it was showing a perfectly Greenlight status to the people who were trying to monitor it. They resist, it was a stroke of brilliant, but that is the type of system that we're concerned about. That's what we're talking about right now. These kinds of logic controllers that are used all over the place you can use them for almost anything you used on ships. They're used in government facilities. They're used everywhere.

There was a vulnerability found and it was a, "I can't believe you did this" vulnerability. Now with solar winds, we found out it was a, I can't believe you did this vulnerability because apparently, solar winds had a password of solar winds one, two, three. Who wouldn't guess that perfectly good password? And man, we see these types of passwords all of the time. That's why I use a password manager. That's why you generate passwords or you come up with key phrases. Three or four words strung together with maybe a digit or something else in the middle somewhere and some upper lowercase characters. Right? That's how you generate a password. It's not supposed to be solar winds one, two, three. So that's problem. Number one, that's a big problem.

This particular vulnerability has a severity score of 10 out of 10. Why? Why is this the worst level it could possibly be? Number one, it requires a very low skill level to be able to exploit it.

Now that's interesting. Why is that?

It turns out that these program, programmable logic controllers have a hard-coded key built into them. In other words, whoever programmed these things, and I'm looking at this list, there are a lot of them. Logix is the name of the company, the name of the product, and you'll see Logix in their names. And it is a whole bunch of compact Logix control, Logix drive, Logix a guard, Logix, guard on me. Now that wasn't supposed to provide cybersecurity support. All of those, okay. Then they have a hard-coded password.

What that means is built right into the software is a back door with a password that can not be changed.

Now, even if you bought one of those cheap firewalls from the big box retail store, you are going to be safer. Because at least it lets you change the password and you should be changing the password on your firewall. And in some cases, it also lets you change the username and you should change the username as well.

But no. These Rockwell devices have a hard-coded password and Rockwell apparently is not going to issue a patch that directly addresses the problems that come from having a hard, coded key. So instead of that, they're saying, Oh, use these mitigation techniques.

Isn't that what Iran did, isn't that? Why they had themselves? Nice little air gap network that was still breached?

Oh, man. Oh, man. So it's a problem. It's a very big problem and they're just not paying much attention to it.

Hey, stick around. We're going to talk about Chromebooks versus Mac and Windows right here.

It looks like the Wintel monopoly continues to die on the vine because of what Apple's been doing, what Google has been doing. In fact, Google is really stepping up their game here, getting rid of Intel.

Hi everybody. Craig Peterson here. Thanks for joining me.

We know that Intel's been around for a long time. You probably remember Intel used to brag about it. There were ads where Intel would kick in a couple of bucks if all they'd said was Intel inside. In fact, they are still doing it on machines. You buy a machine it'll probably have a little sticker if it has an Intel processor saying Intel inside. Intel had a problem, they made components that people didn't buy.

Well, they bought them, but they bought them as part of something else. They did not buy an Intel processor for the fact it's an Intel processor. Makes sense. Some of them did. I certainly looked at them. I bought AMD and some others instead,. Some of the power PC stuff from IBM, just absolutely incredible, as well as others.

I have done a whole lot over the years when it comes to processors, you've heard already I helped develop operating systems and implement them and the internet protocol. I've got a lot of experience with processors, no doubt about it. A lot of machine coding and assembly work over the years. I wrote C, which is a programming language used largely for a high-speed stuff like operating systems. I did a lot of that.

I look at this processor from Intel as a massive failure. Marketing-wise. In the industry, it's been really great, but when I get into it from the prospect, or from the side of being an architect, of operating systems, and an architect of user interfaces. I cannot believe Intel. It's just been terrible. Part of the problem with the Intel processors and their instruction sets. The way they do the memory access and the way they do all of their IO to other devices has to do with their legacy code.

They've tried to remain compatible with all kinds of older processors over the years. I can understand that I can see why they might want to do that. They're afraid that people might leave them. They started out as a memory company and through. I was going to say no fault of their own, but no luck of their own or anything else. I don't know. Another company came to them and said, Hey, can you make a cheap processor?

Remember IBM looking for a cheap processor to put into this PC right. A personal computer that they didn't think would sell very many, certainly wouldn't be a great business thing. They went and said, okay what are the cheap processors we can get and put into here? Intel, 8080. That's what we'll do. All of a sudden is born the XT and the PC XT and the PC AT came. Some of these others over the years on the 8286 and the other chipsets. Anyhow, I'm getting awfully geeky on ya. Started really falling behind. One of the ways they fell behind was in 64-bit design.

In fact, Intel is AMD compatible. Now, if you can believe that. Talk about falling behind. I don't think it's the engineers, there's some brilliant people there. It's entirely business decisions that drove them to the point they're at. They continued to increase the price of the processors. They were getting a little faster, but they still had the corner on the market because people bought Wintel they bought Windows. If they're going to get Windows, they're going to get Intel. Make sense. There were some others over the years that competed including AMD, which is Intel-compatible for the most part.

They really managed to keep people out of the marketplace so they could jack-up the cost. The price structure, just keep jacking up, jacking up, jacking up. Many companies got fed up with it, including some companies that had the ability to do something about it. One of those companies is Apple.

I mentioned in my newsletter last week, I had an article talking about how Apple is now apparently about to make 6G chips. 6G at the next generation of wireless and Apple's getting rid of Qualcomm and gonna make in themselves. A company like Apple, when they want a million parts, they want them to arrive. They want them to be there on the day they ask for them and they want them to do what they asked for.

Qualcomm has fallen down on that. They have not been able to meet Apple's demand. Intel has fallen flat on that. They have not been able to meet some of Apple's demands that have to do with the amount of energy they use the temperature they give off of course cause they want them on mobile devices.

What did Apple do a decade ago? They said fine, forget about it. We're going to not use your Intel processors in our iPhone. They started using some other processors, some arm processors. Apple joined this community like an open-source manufacturing alliance that came up with a chip design that they could use as a basis. Apple took that and ran with it.

Today it has run so far with it that Apple has an amazing chip. Now you can see these amazing chips in your newest I-phones and your newest iPad. That's what they have in them these new Apple processors, but Apple also now has their new M series processors, which are effectively the same things they've been using in the iPhone, iPad, but beefed up in order to handle the load you'd expect to have on a laptop or a desktop with a Mac mini. I'm just so impressed with these. I was playing with both of those. One of our clients wanted them.

We had them ordered and shipped to our place. We put them on benches and we loaded them up and got them all running. We played with them a little bit just to see what they were like. Very impressive machines.

They don't have Intel processors. Apple has switched processors a few times over the years, it went from the Intel or the Motorola over to the power PC then to the Intel, and now to its own chip design. It looks like completely new chipsets for the iPhone 13 hopefully, maybe the 14, hopefully, when that comes out. That'll probably be later this year.

By the way, the 13 is just going to be an incremental update to the iPhone 12. They're saying is probably going to be like an iPhone 12S, really.

Processors. Apple doesn't need to pay the Intel tax on these processors out there. I'm going to look right now, purchase price, Intel, a laptop CPU, just to get an idea. I'm on there right now and I see coming right up, here's an Intel core i9 $400. Just for the CPU and that's from B&H photo and B&H has a lot of this sort of thing. Most of these Intel CPUs that are on laptops cost over $400. They're branded as core this, that, or the other things.

The real expense of one, just start getting into the Xeons. Those Xeon processors can be just through the roof. Here's one here right now an Intel Xeon platinum, 8180 $11,000 while actually, it's 10,995.

If Apple can make its own processor, do you think they can do it for less than 400 bucks? Of course, they can, and that's going to save them a lot of money in making some of these devices.

We're going to get into those devices, like the laptops. What do you need in a laptop? Why would you go with Windows, maybe one of these other operating systems, including Mac iOS? We'll talk about that.

That's going to lead us into the conversation about Chrome. Why is Chrome OS becoming so popular? Why has it surpassed now market share of Apple and where did that market share come from? People have been buying PCs, but what's going on?

Stick around, you're listening to Craig Peterson and you can find me online. Craig peterson.com.

We're talking about chips. Yeah we're getting maybe slightly technical, but chips matter nowadays in a way that they haven't before and yet they matter even less. I'm going to explain that.

Hello everybody. Craig Peterson here. I just said something that might've sounded confusing. Cause I said, CPU's matter more than ever. Yet they matter less than ever. Here's why.

If you're looking at an Apple computer, you are looking at either an Intel processor, at least for the next couple of years or the Apple processor.

If you're looking at a Windows machine for a little while Microsoft was really on a bit of a kick, trying to get Windows running on multiple platforms. In fact, it actually did. There were some amazing things they were able to do, but really if you're getting Windows, you are going to be on an Intel platform.

How about your phone? Do you have a clue as to what kind of processors in your phone? Now, you guys are the best and brightest. So yeah, you, you might, okay. You might know the exact model number and CPU clock rate and everything else about your phone, but the vast majority of people have no idea and you don't need to know. You don't need to know because it is now like a utility. You don't really know how that electron is delivered to your house. Where that came from? How that was produced? You just turn on that light switch and hope it works, right?

Unlike when there's big wind storms and your power goes out, that's what you're hoping for. That's what's happening now, you buy a phone, you don't care if there's Intel inside. The same thing's true with tablets. You buy a tablet, if it's an Apple tablet guaranteed it doesn't have an Intel CPU. If you buy a Surface tablet, you can get them with Intel or without Intel. A lot of times you can tell just based on the price of the tablet now.

As we move forward, we're starting to see more and more devices powered by arm chips and others. You see the idea behind Unix, which is this operating system that's underneath all of them. Unix lives underneath MacOS. Unix lives underneath Android. It lives underneath pretty much every cell phone and every device programmable device that exists today has Unix underlayment, which is the main operating system. It's fantastic.

The whole goal behind that when it was designed by At&T was to make it so that this one operating system could run on anything and it did. Universities adopted it because it would run on anything and universities were getting equipment donated to them from everybody. That was anything, right? This mini-computer, that mainframe, all of these pieces of equipment got donated. They standardized on this Unix platform and the whole thing worked out quite well. Linux is a type of Unix for those who are wondering. The whole idea behind it is that the processor doesn't really matter because there's a version of Unix that will run on really pretty much any processor that's made today or has been made for the last 40, 50 years.

Now, when you start getting into the useful computers that you and I use every day. What's underneath it? If you run a Mac, I don't think you really care. If you're on a Windows computer, I don't think you really care. What you care about is can I do that task at hand? Can I go ahead and open word, document editor. Even then you don't even care if it's Word for the most part. Word, you're going to get around it a little bit easier, but if you are over on a Mac, you could use pages. It doesn't have to be word and it doesn't have to be Windows and it doesn't have to have Intel inside.

I am not giving stock advice, but I can tell you, I would not be out there buying Intel right about now. Hopefully, they got some other stuff going on. I know they're looking at some new chip designs that they can provide to people that make it pretty darn simple.

Now there is another big player we haven't talked about yet and that is Google. Google's got Android, which is underneath again, a Unix operating system. It has also on top of that, this big Java virtual machine, which has been the source of many headaches, a lot of chagrin here for developers. The beauty of it is again, Java was designed so that you can write your program once and run it on anything. You see where I'm going.

We're getting to the point where the competition is going to be crazy. When it comes to the devices we use to get online or the devices that we are using for work, and it's going to get cheaper and cheaper. I'm not talking about the cloud. The cloud is not cheaper. In most cases, the cloud can present all kinds of additional problems.

We just got an email from a listener Danny today. In fact, he bought one of the little packages that we'd put together for the listeners. About 18 months ago of a special, it was a little Cisco firewall and Wi-Fi switch with security built into them, something you can't buy off the shelf. It had the firepower basic stuff in it. Anyhow. So Danny was asking because he uses G suite. How does he do a three, two, one backup? You can't with Google's G Suite. With office three 65 or Microsoft three 65, in both cases, they have lost their client's data. So Danny was asking, so what do I do? How do I do a three, two, one backup, like you advise we do?

Basically what we said is you've got to download all of your data from those cloud services, back them up properly at that point, and do it all in a format so it can be restored. So if it has to go back to the cloud, it can. It keeps your data safe. All of that stuff is, again, just it's everywhere. It's cheap. There are pros and cons to different ways of doing it. Dan is not there thinking I'm using G suite or I'm using Microsoft three 65. What processors behind it, right? You don't care.

Google has said here's what we're going to do. We make a phone now, the Google smartphone isn't well adopted. It's more of an example of here's a way you can implement the Android operating system. It's a proof of concept for them. It's not a bad phone. They've tied in with some other carriers in order to provide cell phone service.

They are coming out with a system on a chip. You used to have this big motherboard and if you go way back, I have a very big motherboard with all kinds of discrete components. Nowadays, all of that gets squeezed into one chip and Google has decided that they are going to make their own chip. They call it the white chapel. That's the name of the whole program. It was reportedly made using Samsung's nine millimeter process technology. In other words, it's going to be fast. It's going to be power efficient, and initially, they are going to be putting it into their smartphones. That's not a bad idea. In their pixel smartphone sometime late this year.

We haven't quite made it yet to Chromebooks, but I promise we'll get to that in just a couple of minutes. I wanted to make sure everybody had a decent understanding so that you can make the right decision for yourself and your business when it comes to what kind of computing to use.

Stick around.

So what kind of computer should you get? What's gonna work for you? Should you worry about the chip that's inside of it? What do you do? It just gets so confusing sometimes. That's what we're going to get into finally right now.

Hi everybody. Craig Peterson here. Thanks for joining me today.

Now, there are options when you are looking at a computer and I know some people don't even have a regular computer anymore, so let's start there. Really quickly many people are just using their iPad and that's what the goal was behind the iPad. I think that's what Steve Jobs had in mind.

Apple always wanted it to be a replacement for your computer. It is not as flexible as a computer is by any stretch. Frankly, it's gotten a lot better, especially the iPad pro because of the faster CPU and it has a few more capabilities. It's a good little unit. That's what I use by the way is the iPad pro.

If you are just going online and you're doing a little browsing, maybe editing a few documents, getting on a zoom call or a WebEx call, whatever it might be, doing all kinds of the regular stuff that iPad's going to work for you. If you have an iPhone, you can link your iPad to the iPhone. If someone calls you on FaceTime, you can actually answer, take the call on your iPad.

If someone calls you on with a regular phone number, if someone does that anymore you can take that as well, right there on your iPad. iPads are inherently very safe. They have done a great job in trying to keep things pretty tight from the cybersecurity standpoint on the iPad.

If you need to use Windows applications, then that's where the surface tablet might come in for you. I know some people who like their surface tablets and I know people who really don't like their surface tablets. Personally, I don't think I would buy one. There's not a huge win, but again, some people like them. They're more portable than some laptops.

Now, you can get laptops in the Windows world that are as small and lightweight as an Apple laptop.

Now, which would I get the Apple laptop versus a Windows? I would absolutely without a doubt, no question get the Apple. The main reason for that is that it's cheaper. Yes. I said it was cheaper. It's cheaper because that Apple laptop is designed using high-quality components and is manufactured using high-quality stuff versus that PC.

You might find a laptop PC laptop for maybe 350 bucks, and you look at the Apple laptops and they start at just under a thousand dollars. They're small the Apple ones and they are very functional and they will last. If you get the same component in your windows laptop, the same quality, the same speed, the same buses, IO, everything else, same display. You are going to pay more in the Windows world than you would on a Mac.

If all you can afford or all you want is something inexpensive then I've got an option and it isn't Windows. Okay.

Unless you have to have Windows, if there's a specific program you have to use that only runs on Windows while you're stuck aren't you.

There is another option out there and it is called a Chromebook. It has been doing very well. 2020 was the first year that these Chromebooks outsold Apple Macintoshes. Now, that's a big deal because Apple's always been a kind of a minor player, seven to 10% of the marketplace. To see Chromebooks actually beat Apple is impressive. Now, part of the reason they're beating the Apple is what I just explained to you. They are inexpensive.

Many kids are at home, right? They're going to school from home virtually and the schools need them to have a computer. What do they say? Get a Chromebook. Here's a $300 Chromebook. Go ahead and get this for your kid or here's $300 and or $300 Chromebook. In some cases, the school just buys it for the kid. Great for that.

Now, remember it's Google, you're storing most of your documents up in Google's cloud. Depends on how you feel about Google and having Google with full access to all of your information.

I have a big concern with Google having access to my kids' information, but that's a wholly different story out there. No question about that.

Chrome is an operating system again, that is based on Unix. It's actually Linux, which is again, a version. It is something that you just won't see. The odds of you directly interacting with the operating system just keeps going down and down.

Now, Windows, you still got a muck around sometimes you got to get into the registry editor. You got to do weird-ass stuff.

With your Chromebook or with your Mac, you're not going to have to do that. It's not an antiquated design. It is a very modern design. Very easy to use.

Now, I started the segment out by saying that CPUs matter more than ever, and yet they matter the least they've ever mattered. Here's why I said that the manufacturers now are able to choose the CPU they want to use. Unless, of course it's a Windows target, but for anything else for Chromebooks, they can use any CPU from any manufacturer. They might have to do some porting and do some work involved in that, but it's moderately minor.

You can't say the same thing for Windows. Windows is locked into a couple of different architectures and you can bet Microsoft is pretty busy trying to make it so that it will run across even more CPU architectures. It matters more to the manufacturers and matters more to you what CPU they're using, because it keeps costs under control. It gives you longer battery life. It lets them put a smaller battery in and still have longer battery life. Lots of good things.

It doesn't matter at all anymore because you only care about the web browser. You only care about the text editor, right? What is it that you care about? It isn't, what's underneath all of this.

Chromebooks, you can find for 150 bucks at a big box retail store and you get what you're paying for. That hardware is not going to be stellar that's for sure. But it's going to work and is going to do a decent job for you. If you don't have any money, really, but you can afford to crack 150 bucks, look at a Chromebook. Chromebooks go all the way up into the $2,000 range.

Those higher-end ones have more local storage. They're faster. There's a bunch of different benefits to them.

Now, you've got the options.

Apple is going to almost certainly stay with its own chipsets. It lets them keep control over the entire investment. Now, you might say that's bad. I don't want to get locked into Apple. Well is not really going to matter that much, but you are going to get locked into Apple. The reason it's not such a bad deal is looking at the marketplace, Apple has a few dozen different designs. They have to maintain the operating system for all of their software, their device drivers, everything has to work across a few different, a few dozen models. Think about it. You've got how far back your iPhones', I know they still put out some patches for iPhone fives and sixes, they might have even older ones. So there you go. Then they had the larger versions of some of the iPhones and they had the ASCE versions. Look at that.

Compare that to the Android space. Where you have hundreds of manufacturers using Android and building smartphones with it. Thousands of different models of phones each with their own device drivers and all kinds of little things. Some of these manufacturers will go ahead and grab whatever's in the parts bin today and throw that in. Okay.

This is true too, not just to the smartphone manufacturers, but if some of these PC manufacturers. Dell has been known to do this. Where it's okay, we're making a laptop today. Okay, we promise them this CPU, but this USB controller that we normally put in, we don't have it right now. I'm going to put this other one in there. It gets very confusing when you're trying to repair these things each one of those USB controllers has a different driver for Windows.

So Apple, the part of the beauty of this is they only have to worry about the security and reliability of just a few dozen different designs versus Google having to worry about again, thousands and thousands of them.

That's why also with Android you do not get the patches when they come out. If they come out, it can take an easy six months for a patch that's issued by Google to show up available for your phone. It typically takes Apple a matter of a week or so. It's just there. There's no comparison. That means your cybersecurity is going to be better when you can get patches.

If you have an Android phone, that's more than two years old, forget about it. You're not going to get patches. If you really are insistent, like some people I know in fact, Danny were just talking about it. He really likes his Android. Don't first of all, always buy the top model. It should probably be as Samsung. It should be never any more than two years old. You got to trade it in every one to two years so that you're pretty sure you're going to be getting security updates in a timely fashion.

There you go. That's the explanation of it. I love my Microsoft stuff for specific Microsoft apps. I really love my Mac for all the graphics and everything. It just works. It doesn't crash. The applications all just work.

I use my iPad for some just general basic stuff, and Chromebooks are probably the way to go for most home users. As we just talked about for schools as well.

Hey, visit me online, CraigPeterson.com. You'll find all kinds of great information there. Craig peterson.com,

Look for my podcasts.

I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

Hi, everybody. Thanks for joining me. Of course, you can always go to my website. Yeah. Pick up all of the podcasts in case you missed something today or another week, you'll find them right there@craigpeterson.com. You can also sign up for my email list and we're going to be doing a couple of different things here.

I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago, and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's a checklist of all the security things you should be worrying about.

Now, if you are a home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there. I'm going to start sending that out as well to everybody cause some people want my actual show notes.

We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there. Then the course improving windows security.

It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

It's been over 20 years. Karen and I went to an event he had down in Boston and this was one of his firewalk or events. We actually got to walk on hot coals it was the weirdest thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was really hot. They were really red. It was really something that at the very end they had grass, a little square . Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being if you had any hot coals stuck to your foot. You probably didn't want those just to stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it. You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know it that we've got it ready for you? We will have it already for you, hopefully with the next couple of weeks.

So that's that I'm told the different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two-thirds when we're measuring it by the number of people affected.

Now, of course, if a company is breached and an organization is breached, it's counted as one. One person, if you will affect, obviously it can affect hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach plummets. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks.

We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that needs to keep all of their data safe and they are constantly being gone after.

They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently, China knew about this hack potential knew about this bug and was using it.

And apparently, it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscriptions, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

Information was stolen, not just the people that were hacked but it is a huge drop of 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blankets. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook, and their Supreme court.

Stick around.

The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court? This is interesting.

Craig Peterson here. Thanks for joining me.

People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives. I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

Facebook decided it needed to have its kind of its own version of the Supreme court. You see what happened? Bins are you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off-color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

And they use these bots to pretend that there is an incredible rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kinds of artificial intelligence, bots to flood Facebook with complaints.

And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously, not everybody's on every day.

But some percentage of them. And I've seen it's in the hundreds of millions of posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

Hey, you're listening to Craig Peterson.

Visit me online Craig peterson.com.

Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

Craig Peterson here. Thanks for joining me.

My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

Facebook and Zuckerberg have been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows, and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever about what they've been doing in order to harvest your information. Now you might have noticed if you go in.

To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

You want to click on more info project early if it's Facebook because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is the stuff that happened. Figure it out either electronically or by getting people involved.

I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

Under settings users will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings as you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about the microphone and you can turn them off.

Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for the DOD, department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies to do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

And it was a huge box of three-inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they pay a million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

And Facebook apparently has been buying full-page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently, also Facebook has decided to rewrite its apps. So no longer even requests to access, cross-app access to your personal information.

We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

We're probably going to increase our volume from one email a week to three so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go to every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for the electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast's case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long. It's because they're streaming TV. They've got kids working from home.

Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi. It goes through the internet, it goes to her phone carrier's network. Then it goes to the call centers network. So there you go.

What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirements, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

They let a group of 71 different Massachusetts lawmakers urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, the government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

Let's see here, SolarWinds hack.

I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently, many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something? Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, the total volume of $350 million.

Cyber criminals are moving to crypto locking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files, and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses, and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

Take care and make sure you sign up @craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. I went into a little detail about what a Zero Trust Security Model is and how it differs from a traditional network design and why you should be considering this type of system. Then we discussed the future of computing and why Chromebooks are so popular. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Morning, Craig Peterson here.

Hey, if you've ever wondered about Chromebooks and if you should get one, talked with Matt about that. Matt Gagnon, of course, I'm on every Wednesday morning with him. Also zero trust. Why is the national security agency pushing a whole new way of thinking? When we're talking about our computers. So here we go.

Matt Gagnon: [00:00:26] Seven 36 WGAN morning news on a Wednesday morning. That means it's time to talk to Craig Peterson, our tech guru. You hear him on this very station on Saturdays at one o'clock to hear more depth of detail about these very stories we'll be talking to him about right now. Craig, how are you this morning, sir?

Craig Peterson: [00:00:41] Hey, I am doing really quite well. I'm looking forward to spring. It's been actually a nice winter.

Matt Gagnon: [00:00:48] What are you doing, man? You're tomorrow, there's going to be some sort of blizzard because you just said that you are now tempting fate. I already had to walk outside yesterday.

I got gas in my car. Sadly, I had to, I had no choice. The wind hurt my face. Okay. That happened yesterday,

Craig Peterson: [00:01:03] We were outside pouring diesel into our generator because there was no power and it was really cold.

Matt Gagnon: [00:01:10] It really was. It was frozen. Terrible. I was actually reminded of my old college days. March in from the perimeter parking lot and the wind and the cold just beating me to death on my way in. It was not good yesterday.

Craig Peterson: [00:01:24] I keep reminding people where that comes from. It comes from Russia. They blow it over the North pole in order to destroy our economy.

Matt Gagnon: [00:01:31] Yes, they do. And there's so many things that those Russians do, those pesky Russians.

Craig Peterson: [00:01:34] Canada gets caught in the cross hairs. It's just not fair to them,

Matt Gagnon: [00:01:38] You might say, Craig, that I have zero trust in Russia. See where I'm going with this one. Could you tell me what a zero-trust security model is and why it perhaps should be something that people embrace?

Craig Peterson: [00:01:50] This is a concept that's relatively new, at least to most people. The whole idea behind it is we have. To assume in this day and age that our systems have already been compromised. Not just that they might get compromised, but they have.

So when we're setting up networks for businesses, we look at things in a much different way. It's no longer about the perimeter. Trying to keep people out. The NSA, the national security agency, used to call it no such agency. The NSA has come out with a warning to be bold and also a description of what to do.

The idea is you've got things inside your network. You've got a printer, that's connected to the network. You've got laptops, desktops, a server. None of them should be able to talk to anything else on the network that it doesn't absolutely need to talk to. It's like the lowest privilege type thing.

So for instance what I do on my office network is the printers are on a completely different network that is firewalled from the servers, which are firewalled from the desktop which are firewalled from the laptops. The printers can not get to anything else on the network unless first someone's trying to send them a print job. It's just an example of it. You don't want the laptops to be able to scan.

We have a customer who just this week, he has a little SonicWall firewall and SonicWall's are okay, but he hasn't been updating it for three years. It hasn't been supported in years either. That little SonicWall firewall was then used to get into his network and start spreading. It got around the firewall because he was using it for a VPN controller. Then it started crawling all the way through this network and playing all kinds of havoc, internally. Again. If that firewall couldn't have gotten to a machine and then that machine starts probing everything else, it couldn't have spread.

In other words, the zero-trust only allows machines to talk to each other that absolutely need to talk to each other and only using the protocols that they're supposed to. I've seen many times, which is the sales guy is tinkering around and is getting into the accounting data. Why are you doing that? They should not be allowed to, so that's the bottom line.

This is a real big deal. We've got to start building our networks with the assumption that they have already been compromised. How are we going to control it? If it's compromised?

Matt Gagnon: [00:04:34] Craig Peterson tech guru joins us at this time on Wednesdays going over to the world of technology.

Another interesting story that I saw here this morning, Craig, was that Chromebooks apparently outsold Macs worldwide in 2020. That's something that surprised me a little bit here. I didn't realize that the market penetration, if you will, of the Chromebook, was that deep, but apparently, it is. What does this mean for the industry?

Craig Peterson: [00:04:54] Yeah, it's interesting because you're talking about it surpassing the Mac and it sounds like maybe Chromebooks are leaning into Apple. In fact, these things are very lightweight computers. They're typically a tablet, maybe a laptop and they're running an operating system that comes from our friends at Google called Chrome OS.

It is really designed for being online, although you can store files locally. Where it's been eating into is people that have been running Windows for years. Those Windows machines have been getting more and more expensive. Intel is just not keeping up with everything, particularly from the price standpoint. Putting a chip into Chromebook that is a non-Intel chip. It is way cheaper than Intel, we're talking to 10th or less of the price allows them to make these devices very inexpensive. You can go to a big-box retailer. You can get a little Chromebook device for 150 bucks at the low end. Now you've got a computer that can go online, get edit word documents, or spreadsheets, whatever you might want to do. Can talk to the grandkids or get on a business call, all right there from the Chromebook.

It is hurting the Wintel monopoly, which is the Windows-Intel, a monopoly, if you will, that has been around for so long. It's a direction that Apple is following the Apple's computers will all be using non-Intel chips within the next two years, all of them. They already have computers out with these new chipsets.

That's the bottom line, they really have gained some significant market share. People love them. I've got also mentioned here, not just regular people security researchers love the Chromebooks. They are very secure, but remember, we're talking about Google, their business is selling your information. They're not going to sell your files, but they're going to keep track of you.

The other big driver of the Chromebook sales is schools because now we have so many kids at home going to school, the school says, Hey, you got to buy a $300 Chromebook for your kid for school. That's much easier to swallow than a thousand-dollar Mac or a $700 Windows laptop.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. We discussed his newest foray into the social media platform, TikTok, and some of the problems with using TikTok. Then we got into a question from one of his callers about Home Title Lock. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, Craig on with Mr. Jim Polito this morning. He made his first TikTok videos just this week. Then he gets an email for me talking about some of the privacy issues now. Still with TikTok. Yes, they were not sold. We did double-check. We also took a few minutes to talk about a home title lock because he had a caller asking some questions. So here we go with Mr. Jim Polito.

Jim Polito: [00:00:28] I mentioned earlier that I published on TikTok for the first time. Look I'm not a kid. I'm on TikTok, the social media platform just because I wanted to register my name. I always like to get Jim Polito on every new social media one, so if I ever use it. I did it with Instagram a long time ago, when just the kids were on the gram and now I am a Jim Pollito on the gram at Jim Polito.

So I published a couple of videos. Now it's not me dancing. Now. I'm having second thoughts because our good friend tech talk guru, Craig Peterson says there's some issues with TikTok again, even though it's not owned by the Chinese. He joins us now.

Good morning, Craig.

Craig Peterson: [00:01:13] Hey, I thought the Chinese owned everything everywhere.

Jim Polito: [00:01:17] They do basically. You're absolutely right. They basically do own everything. But they don't own right. They don't own TikTok anymore. There was that big bidding war in the company. What's the name that, that nobody knew or that everybody thought was washed up?

Craig Peterson: [00:01:34] Yeah. There was a whole bunch of people. You had Microsoft on in with Oracle. They thought, okay, that's what's going to happen. I actually don't think that they sold it. It all got stopped when the Biden administration went in.

Jim Polito: [00:01:49] Listen, you would know better than it's still owned. Yeah. That they're trying to sell it to Oracle and Walmart, but it hasn't been sold yet. Oh, great. So the Chinese know what I'm doing.

So I published two videos on TikTok, and actually, they were funny what? No, they're not dance videos. Nobody needs to see that. They're not dance videos. They're funny little videos that I made in Boston the weekend before last. They're they're cute. They're funny. They're about the founding fathers. If you want to see them, they're funny. I think they're funny, but anyway, what's going on with TikTok.

Craig Peterson: [00:02:29] TikTok is a kind of newcomer. Of course, they've been around a while. There've been a lot of complaints about TikTok because it has been routing data to China, including location data. Remember, that's all part of the pictures and videos that we take.

It's amazing when you get right down to it. For instance, the number one manufacturer of these little drones with cameras on them that fly around is also Chinese-based. Apparently has also been sending stuff back. So we're giving them a very good map of the United States everything everywhere it is, which is scary.

We've got some consumer groups now complaining in the UK. We know under the Trump administration, they started looking into TikTok and found it lacking, if you will. There are complaints over there now about, okay, so people are making these videos. They're putting a lot of work in. Most videos, don't go viral. Most people don't have a real platform on it. Then some do go viral. If you look at the fine print of what TikTok has you click through, one of these groups. Yeah. Yeah. I agree with your terms, whatever the heck. They were, cause I didn't bother reading them. It says that you are giving TikTok an irrevocable right to use, distribute and reproduce the videos that you are publishing without any remuneration. So unlike YouTube, right? YouTube, if you're doing pretty well, they'll start paying you.

Then if you look at TikTok, even though there's some old guys on TikTok, It's largely kids who are using it. When we're talking about kids, of course, we're talking about under 18. They haven't reached the age of majority. In the US, and also the European Union, there are special rules for those younger adults. They cannot publish some of these things without the parents getting involved and unfortunately, parents haven't been getting involved. TikTok has no real policies on it. I expect that they will really come under some serious scrutiny.

Jim Polito: [00:04:44] We're talking with Craig Peterson, our tech talk guru. Here's the thing when a kid signs up for it, that's a contract, but if you sign a contract and you're under 18, it's generally not enforceable.

Then the second part of this is the Europeans are saying, you're allowing these kids access to inappropriate material. You're not doing a good enough job policing yourselves like Danny and I was talking during the break. How a group he was part of, a relatively benign group on Facebook got, as he said, Zucked, as in Zuckerberg, got caught because they didn't like what was going on there, which maybe Facebook is policing a little too much.

Whereas on the other end of the spectrum, TikTok is allowing kids access to this stuff that they shouldn't have access to.

Craig Peterson: [00:05:37] Then, of course, the videos, in this case, they're being uploaded. TikTok has a policy that users must be 13 years of age or older in order to join. Okay. There seems to be very little if any enforcement of it and that's where we're really starting to get concerned.

We're working to try and protect our kids and then things like this come along and it's concerning. Also, they don't have some of the defaults that other social media platforms have. So for instance, if the kid admits that they're 15 when they're signing up for TikTok, it does not automatically make that account private by default, which makes a whole lot of sense.

There's a lot of things we did as kids and as adults that we don't want to have following us around for the rest of our lives. This is exactly what could be happening.

Jim Polito: [00:06:31] Yeah. Not good. All right let's move on to something else. I want to ask you about this because a listener called about it.

We have LifeLock and all these services that say they will monitor for you. You have explained to us, Hey, look, you can go to the three major credit reporting bureaus. Turn off your credit and only turn it on when you want to use it. That's one way to protect yourself. That's inexpensive and you don't have to pay one of these companies. The question was brought up about a title for your home for your property. Now there were those services out there saying, we'll protect your title because people can steal your title, go out and get a mortgage, a second mortgage on that property and then disappear. All of a sudden you're saying, wait a minute. I know I didn't take out that mortgage. But my understanding was that all those agencies do is try to prevent that from happening. Ultimately if your title is stolen, are you're not going to be responsible for that loan, correct?

Craig Peterson: [00:07:33] You're going to have to do a little bit of fighting, but it's a rare occurrence that people's home titles are stolen. It certainly can happen. Frankly, it's a waste of money. They're probably a sponsor of the show.

Jim Polito: [00:07:46] No, I've heard the ads. I think Bill O'Reilly, he does his own stuff now. He does an endorsement for them and I certainly don't want to tell somebody wants extra protection or whatever. As you said, you're going to be protected. All it's saving you from is some work.

Craig Peterson: [00:08:02] You said that earlier, too, the caller as well, Jim.

What it is it's insurance. Insurance does not stop the tree from falling on your house. Insurance, once you have it, of course, it can help repair the damage caused. That's what most of the LifeLock types are in the world. These home lock companies are doing is making it so if the event, it's very rare when it comes to title lock, if that event happens, they help cover you.

There's another angle on this and that is most homeowners insurance policies have a rider on them that if your identity is stolen, then they start using your credit or if your home title is stolen, they will pay for all of the cleanups. That's just part of the normal home policy. So you might want to have a look at your home policy.

Then one other thing is specifically when we're talking about home title lock, and that is the caller was saying, Hey, the County used to let us know, cause you remember what happens is you buy a home all the paperwork is filed with the County. What happens when someone steals your home title. Typically, they file something called a quick claim deed. They basically say I just bought the house and here's his signature or her signature right here in the document then they file it with County. What the counties can do when you have to contact them is most of them have a system where you can register for notification on activity. They may not be doing it automatically, anymore. Double-check with the County and they will then notify you.

There's often a little charge it's not much. They'll notify you if there is any activity occurring on your title. So it makes sense. Our home is our biggest investment for many of us that's what we're hoping to use for retirement.

Jim Polito: [00:09:56] Wow. Interesting. Very interesting. Now, as usual. Folks, Craig Peterson's here every week, but that doesn't mean that you can't interact with the tech talk guru during the week.

How do people do that? Craig?

Craig Peterson: [00:10:12] Oh, we get a lot of people just send an email to me, ME@craigpeterson.com. I answer every one. It might take me a couple of days, but I answer every one of the emails. You should be on my email list. So you get the newsletters, the show notes, little bits of training that I do. Find out about courses that you need to know, and that you can find that my website @craigpeterson.com, craigpeterson.com

Jim Polito: [00:10:36] There you go.

Craig. Thanks so much for your time, buddy. We'll catch up with you next week.

Craig Peterson: [00:10:42] Take care, Jim.

Jim Polito: [00:10:42] You too. See a wealth of information there.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. He wanted to discuss what is the best technology to buy. We got into some details of the benefits and drawbacks of each. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, have you thought about whether you should get one of these Chromebooks, maybe Android tied into it, or a Mac or a Windows, computer laptop, or surface tablet or otherwise. That's exactly what I talked with Chris Ryan about this morning. So here we go with Chris. A little bit of insight on computers and the whole market behind it.

Chris Ryan: [00:00:23] I am Chris Ryan. Appreciate you joining us for the show. Craig Peterson joins us right now in the program. He hosts tech talk on Newsradio 610 and 96.7.

Craig Peterson: [00:00:32] Hey, good morning. Doing well.

Chris Ryan: [00:00:34] Good. Thanks for joining us for the show. I want to talk to you today about decision-making in regards to what tech to use. Whether it's a cell phone, whether it's a Chromebook versus a Mac and this off of a story from geek wire.com, which indicates that Chromebooks outsold macs worldwide in 2020. So in your view, why did that take place? How do you go about if you're a consumer differentiating using a Chromebook versus using a Mac versus using another type of tablet?

Craig Peterson: [00:01:09] Apple is moved to their own chips now really indicates what's going on in the marketplace.

Many years ago, there were just a few different chips that were competing manufacturers. Motorola was winning this game. IBM had their chips for the mainframes. Then along came this little startup, known as Microsoft and helped Apple out. In fact, in the very beginning and moved on from there to really focus in on one hardware platform and that's the Intel platform.

For years it was known as Wintel monopoly, meaning Windows and Intel. Those two were in lock step, went hand in hand. The default for people to buy was always Windows because that's what they knew. That's what they might've used at work. Although it might be a different version. So they just go ahead and use it at home.

Now we have options. Intel has been falling by the wayside for years. Even 64 bit chips, Intel lost the whole lead on that. AMD advanced micro devices beat them. So when we're looking at it, as a consumer, now we have more choices. We can decide that we want a simpler machine, a more secure machine and get something like a Chrome or web based tablet. This is an operating system that is designed for mobile devices.

We can get a chromo S based laptop, a desktop. There's even rumors that there's some more phones in the work. The Chrome OS will even run android and it's way cheaper because you don't have to use that expensive Intel chip, which is part of the reason Apple has decided to ditch Intel as well.

Now we're going to the real benefit of Unix machines. Unix has been around since the early seventies. It's what I've used in data centers and all big businesses use in data centers. The real benefit to Unix, Chris, is it will run on anything. So now you can go out for $150, buy a half decent little tablet or laptop using Chrome OSwhich of course is coming from Google.

Have that thing updated for you all the time, just automatically. It has all of the features on it you probably want, you can go online, obviously, you can edit document and it is cheap. Although, you can get more expensive ones. It's secure. Chrome OS is what many security researchers use. As you mentioned for the first time ever Chromebooks out sold Macs. That's a little misleading because it's not eating into Apple's market share. It's eating into Microsoft market share and along with that, of course, Intel.

Chris Ryan: [00:04:05] I want to ask you about. Where Google kind of caught up to to Mac. Most individuals purchased what the optimal item was the Apple phone. It was the different Apple products. That was pretty much seen as being the market's view of things.

Now, it seems that there's been a change and a lot of that has to do with, as you referenced, Google's technology and products and the alignment with Android and other types of phones. So at what point did Google get to the stage where they were on par with Mac, in your view, or perhaps surpassing it?

Craig Peterson: [00:04:38] There's really two different things here. The on-par right now, as far as sales go is in the Chrome OS side. When we're talking about phones it's a different thing. These smartphones smart devices. There are many more mobile, sometimes more android based smartphones out there, then there are I iPhones. The main reason for that has to do with price. Google made the operating system, the Android operating system, available effectively for free for any developer that wanted to use it

Chris Ryan: [00:05:13] The public perception is that the iPhone was the thing and kind of still is.

Has that changed at all? Or is the technology with obviously the Chrome OS different? Has the technology with Google caught up to where Apple is in the view of the public, and in actuality,

Craig Peterson: [00:05:28] In the view of the public, it's hard to. Say a lot of people you start using Windows, you say, you start using Android, you stick with it, et cetera.

That's a little hard to tell, but I can tell you what Google thinks, obviously, Google's beta right now for the Android operating system is trying to copy more and more features from Apple's iOS, which is their operating system for their smartphones.

Google thinks that Apple is still the market leader. They are still playing catch up. They are nowhere near, orders of magnitude, nowhere near Apple, when it comes to security. Android is far behind, still.

Justin McIssac: [00:06:06] When it comes to actual Chromebooks versus Macbooks. Do you think a lot of this on the sales side, Craig, is driven by schools? For my school system in Rochester, if they're looking at $300 Chromebooks versus a $1,700 Macbook for their students, no contest.

Craig Peterson: [00:06:19] Yeah, and that's absolutely true, Justin. The cost is something that a lot of people consider and it's a legitimate consideration. In the case of, should I get a cheap Windows machine or should I get a cheap Chromebook? The Chromebook is a much better option for most people. When you're talking about schools who have widely adopted the whole Chromebook and Chrome OS operating system. Schools, it's just a huge win. It's so much less expensive. It's much easier to tell Justin to buy a $300 Chromebook that the $1,800 Mac.

Where the Mac comes in useful, let's run through those three platforms really quickly. The Mac comes in useful when you want something secure, easy to use that can run bigger applications. If you have an app, like you're trying to do video editing, maybe more photo editing, you might want to use a Mac.

Windows is great, if the app that you need to use only runs on Windows. Or you only know Windows and you just don't want to bother learning an even simpler operating system. Then Chrome OOS is wonderful when you need primarily to go online. You're going to use a web browser. You need some simple applications. Maybe you want to edit some Word documents or Excel from time to time, nothing terribly fancy. That's where Chrome OS comes in. That's why it's been such a hit in schools, too.

Chris Ryan: [00:07:44] Well, Craig has always I appreciate you joining us for the show and we shall chat again soon.

Craig Peterson: [00:07:48] All right. Take care, Chris.

Chris Ryan: [00:07:49] All right. That is Craig Peterson joining us here on New Hampshire today. You can hear him on Saturday and Sunday on news radio 610 and 96.7 with tech talk. Always good to talk with him about what's taking place in the tech marketplace.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

It was also another busy week on the technology front and we are going to delve into what actually caused the energy problems in Texas. There is a new type of malware that is affecting Macs and it is has a different MO. Then we are going to discuss Apple and their ventures into automated electric cars and what we can expect. Why are states having issues making appointments for vaccines? In a word, it is bureaucratic incompetence. Then we have a new type of hack out there. It is called Buy-to-Infect and there is more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

This Basic Math Shows How Wind Energy Failures Contributed To Texas’s Deadly Power Loss

An Insider Explains Why Texans Lost Their Power

New malware found on 30,000 Macs has security pros stumped

Report: Nissan shot down Apple deal to avoid becoming Foxconn of cars

N.Y.’s Vaccine Websites Weren’t Working

Apple is already working on developing 6G wireless technology

Owner of an app that hijacked millions of devices with one update exposes the buy-to-infect scam

Mount Sinai study finds Apple Watch can predict COVID-19 diagnosis up to a week before testing

Malware Exploits Security Teams' Greatest Weakness: Poor Relationships With Employees

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] You probably know I've been doing cybersecurity now for 30 years in the online world. Yeah, that long. I'm afraid I have some confessions to make about our relationships here, cybersecurity people, and employees.

Hi everybody. Craig Peterson here. I'm so glad to be here. I'm happy your here as well. There are so many ways to listen.

I got pulled into this whole business of cybersecurity quite literally, kicking and screaming. I had been already involved in the development of the internet and internet protocols for a decade before. In fact, one of the contracts that I had was with a major manufacturer of computer systems.

What I did there was design for Unix systems a way to check for malware, a way to manage them remotely. Yes indeed, I made one of the first RMM systems, as we call them nowadays. We also tied that RMM system, of course, into Windows and a few other operating systems. Unix was where I was working at the time.

I am what they called an OG in the industry. My gosh, my first job with computer networks was back in 75. Believe it or not a long time ago. Back then, of course, it was mainframe to mainframe basically and some of the basic protocols, the RJE, and stuff. I know I've got a lot of older people who are listening who are saying, yeah, I remember that. It brings back memories.

In fact, I got a note just this week from a listener who was saying his first computer was a Sinclair. Do you remember those things? Oh my gosh. It brought back so many memories for us older guys. But it was just such a cool little device with the keys and much different than I'd ever seen before. The XZ81. I just looked it up online so I can remember what the model number was. That was made by Timex. If you can believe that too. It's just. Wow. It had a Z 80 CPU, which of course was like an 8080, which was Intel's, big chip at the time, running at 3.25 megahertz. Yes, indeed. Very cool. I love that computer anyways. I digress.

The whole industry at the time was non-existent, yeah. You had antivirus software. We started seeing that in the eighties and we had some terrible operating systems that many people were running like Windows, just absolutely horrific.

Remember windows three-point 11 and XP and the millennial edition just some of the most terrible software ever. That's what happens when you have interns? A lot of the code, it came out in one of the lawsuits, for one of these versions of Windows.

It was a different world and I had to figure out what was going on because I had some servers that were Unix servers. This was the early nineties and I was hosting email for companies and websites and doing some filtering and things with some kind of precursor to SpamAssassin. It was really something. I had some DECservers, Digital Equipment Corporation. Remember those guys and all of a sudden customers started calling me because the email wasn't working. It turned out it was working, but it was extremely slow and I had to figure out why.

I telneted to my server. I got on, started poking around the servers.

I had a computer room and the first floor of the building that I owned and I was up on the second floor. Off we go looking around trying to figure out what is going on. It was me actually. I said us, but it was really me. Cause I knew the most about this stuff.

There were these processes that just continued to fork and I was trying to figure out why is it creating all these new processes. What's going on? What has happened here? Back then, The internet was a much different place. We trusted everybody. We had fun online. We would spam people who broke our almost unwritten rules of the internet about being kind to other people. What spam was, where the whole term comes from is you would send the script from Monty Python spam and eggs, spam and ham spam, spam, spam routine.

You just send it to somebody that was breaking these unwritten rules, like trying to sell something on the internet. Absolutely verboten. What a change to today.

I saw some of this stuff going on. I was trying to figure out what it was, but, we trusted everybody. So my mail server was Sendmail, at the time. We still maintain some instances of Sendmail for customers that need that.

Nowadays. It's usually more something like postfix in the backend. You might have Zimbra or something out front, but postfix in the backend. We allowed anybody on the internet to get on to our mail server and fix some configuration problems. They didn't have full access to everything. Firewalls weren't then what they are today.

In fact, one of our engineers just had to run out to a client who did something we told them not to do. They were using the Sonic wall firewall on their network as well as they had our stuff. So we had a really good Cisco firepower firewall sitting there, and then they have this SonicWall so that they're people, remotely could connect to the Sonic wall firewall, because it's good enough. SonicWall says it's compliant. The SonicWall firewall was being used to scan the network and load stuff. Does that sound familiar? Much to our chagrin.

So he had to run out and take care of that today. It sounds like we might have to do a rip and replace over there restore from backups. You have no idea what these bad guys might've done. We've seen Chinese into these networks before, Chinese malware. It's been really bad.

Boy, am I wandering all over the place?

Back to this, we would allow people to get onto our network to fix things. If something was wrong, if we were misconfigured, they could help us and they could get on and do it because Sendmail configuration was not for the faint-hearted.

In the days before Google, right? Eventually, we had Archie and Veronica, and Jughead. They did basic searches across FTP servers. That's my kicking and screaming story. I was trying to run a business where we hosted email for businesses, which we still do to this day, and where we had some, back then we didn't have websites. The web didn't come in into play until a couple of years later, but we did host FTP sites for businesses so that they could share files back and forth.

That's what I wanted to do. That was my business.

Later on, I ended up helping 80% of my clients find the other web hosts after, these $8 Gator hosting things. We just got a call on that this week. Somebody who'd been a client of ours 20 years ago, went with a guy that charges $5 a month for web hosting. They have personally identifiable information on that site if you can believe it. He was complaining because it wasn't working he was getting a C-panel error anytime he went to the site. We said, Hey, listen, this problem is the guy that you're hosting from. We did a little research and we checked the IP address and how many sites we're at that IP address. This guy that was charging them $5 a month had 150 different websites at that one IP address. Now that's not bad. He was hosting all of these 150 at a site, the charges, the eight to $10 a month for web hosting. He had all of these sites on top of a machine that was already split up hundreds of ways. It's just amazing what people do.

Man alive. We got rid of 80% of those customers, the ones that wanted cheap, that's fine, get cheap, and see what happens to you. Some of them, we still maintain a good relationship with and so we help them out from time to time, right?

What am I going to do? So somebody calls me, I gotta help them. That's precisely what we do now with this malware problem.

What's going on here? We talked already about the Great Suspender and how Google has said, Hey, this now has malware in it, so we're removing it from your web browsers. That to me makes a ton of sense. Why not do that?

This is another example of what happened with SolarWinds. This is an example of a supply chain infection. What happened with that? Somebody bought Great Suspender from the developer and then added in this basically malware to the Great Suspender. Just it's a terrible thing. Very surprising, but one of the biggest exploits that are being used by the bad guys right now is the security team's poor relationship with other employees within the organization.

I promise we'll get to this a little bit more and explain the bottom line here. What's going on and it goes back to this customer that we just had to run out to.

Why did they do what we told them not to do?

Stick around.

We're getting into the battle between cybersecurity senior officers in companies, owners, business owners, and the, even the employees. There has been such a battle going on. I saw two examples this week.

Hi, everybody, it's a difficult world out there, but I find some comfort in listening to, of course, news radio. It keeps me up to date on what's going on. It helps me to really understand the world a lot better.

I mentioned that one of my guys just had to run out to a client who did something we absolutely told them not to do. They had been using this company that was a break-fix shop, I guess is the way you would put it. They had a business that would respond to problems and they charge by the hour. I think right now their hourly rate is like 160 bucks or something. It is not cheap, but anyhow, That they would sell people equipment and then move on, right? Your problems aren't my problems. Just leave me alone, go away. It's a beautiful model because their employees at this break-fix shop don't have to understand much. They just have to know more than you do as a customer.

There's one level of understanding that you have, and for someone to appear to be an expert, all they have to do is have slightly more understanding.

That has bothered me so many times listened to the radio and they talk about somebody that's just this great expert, in reality, of course, they are not. But you don't know. That person talking about the expert doesn't know either because they just don't have enough knowledge. Of course, the person that's labeled the expert isn't going to say anything about it.

They were doing what most companies do, which is okay. We know we need a firewall, so let's get a firewall. They went out and they talked to this company and they did their Google research because of course, Dr. Google is an expert on everything. Even with those differing opinions, you're going to go with the opinion that you like the best. That's what they did.

They bought a Sonic wall firewall from this vendor, which was a break-fix shop. Now that's all well, and good. The sonic wall is not terrible stuff. They've got some amazing stuff as well.

The problem is this device has been out of support for more than two years now. Even though they're not as advanced as some of the systems we can install, not that we always use the most advanced systems. It's not a bad, a little thing for a small business. We warned them that because they were using an out-of-date firewall that they could not get fixes for known vulnerabilities. Now that's a big deal too. Most people are not aware of the vulnerabilities that are on their machines.

Do you go out every month and check the firmware versions on your firewall? You should be, even if you're a home user. Are you checking to make sure the firewall that the cable company provided you with is up to date, configured correctly? You've changed the password and the admin username, right? No?

Most people haven't. He hadn't, right. He didn't know. We told them we did a little research and said here's your problem.

That's part of his cyber health assessment. We told them what kind of firewall do you have? What's the version of software on it and we do that. We have a bunch of people that have asked for cyber health assessments. We've got them on a list because we're busy. So we have to schedule these and make them happen.

So we said, do not plug that machine in. Of course, what do they do? They plugged it back in again. So now all of a sudden this morning, we get a wake-up call from our monitors that are running they're on their Cisco firepower firewall, where we have their extensive suite of additional software. This isn't just an off-shelf, Cisco firewall.

It's telling us that the SonicWall or something through our, via the SonicWall. Is going through all this customer's network. It's actually attacking the Cisco firewall from inside the network. Absolutely amazing.

Why does that happen? In this case, the business owner, and it is a very small business. It has about 5 million in revenue per year, I would guess. It's a small business by every stretch. The owner just doesn't want to spend the money he doesn't absolutely have to spend. He's not looking at this saying I could lose all my intellectual property. I could get sued by these people. I could lose my clients who find out that their data was released. Their orders were released. Everything was stolen.

He looks at it and says, Oh wow. It's 200 bucks a month. Wait a minute guy, you have how many employees? You're worried about 200 bucks a month. I personally, I don't understand that. Why would you do that?

Now, you're in a poor country. Okay. I get it right. That's a lot of money to spend, but not here in the United States. Doesn't make sense.

A lot of this is really the reason I brought it up. It's showing how there is a disconnect between business owners, C-level people, and cybersecurity people. Basically, if you have less than 200 employees, you cannot afford to have your own cybersecurity team. It's impossible. It's way too expensive.

Then the numbers start to change outsourced cybersecurity, which is what we do. We do this for this customer and. The in-house cybersecurity people, but we all have the same basic problem. The owner has a problem too, right? He has to weigh the costs of cybersecurity against the risks involved, which is what Equifax did.

What so many of these big companies do, right? There's this, the norm Equifax said it's going to be way cheaper to just pay out $10 million in fines. When we get fined by the federal government for losing everyone in the country's personal financial information then it is to do this or we're not going to bother.

Man, I'd love to see the smoking gun email on that, where they made that final decision, probably doesn't exist. They're smart enough to know that they would get sued and they have been sued because of this.

We've got another problem right now because of people working from home. I mentioned, in fact, this week, you should have gotten an email from me on Thursday. That was a little audio thing that I put together. We call these things, audiograms, and it's a kind of a video that'll play.

This particular one is about part of this problem. We've talked extensively about that water plant in Florida, that was hacked for lack of a better term. It might've been an insider thing. It might've been someone external, et cetera, et cetera. The reason it happened is that business, the water plant for a town of 15,000 people, which would be in a normal world, a small business. That small government operation was all of a sudden faced with lockdowns. What do we do? They didn't have a plan. They didn't have a business continuity plan, which is so important. I talked about it extensively last week as well. They had no way to manage this. So what did they do? They went out and bought team viewer licenses for everybody in the business. That put, well not the business, in this case, the agency, that put the agency at risk.

That is putting our businesses at risk too, in such a big way. That's what the audiogram I emailed out on Thursday explaining this a bit.

So stick around. We're going to continue this conversation.

Of course, you're listening to Craig Peterson online@craigpeterson.com.

We have people working from home. We didn't really plan for this. We're doing it because of the lockdown. Maybe, you found that it's actually better for your business, from whatever angle. What are the risks here of people taking computers home?

Hello. Everybody Craig, Peterson here. So glad to be with you today. Glad you're taking a few minutes out of your day as well to listen in.

Now I am very concerned about people using computers that they're taking home. I want to make a definition. Maybe there's a better way of saying this, computers that are used at home, home computers should never be used for work.

I'm going to explain why. Computers that are at work probably should not be taken home. We saw the example of this, just this last couple of weeks.

I was talking about this wonderful plugin that I've been using and recommending people use here for a very long time, called the Great Suspender. We've talked at length really about what happened there with the company being bought and then becoming evil, right? Just buying their way into 2 million people's computers.

Sometimes these Chrome extensions that are installed on personal computers get automatically installed and synchronized to your work devices. In fact, that's the default. If you log into Chrome and you're using Google Chrome as your browser and you log into it on your home computer, and when you log into your same account over on your business computer. All of a sudden, now it's syncing. It's syncing things like passwords, which you should not be having Google store for you. You should definitely be using a good password manager and there are a few out there.

If you're not familiar with them or don't know which one to use or how to use them. I have a great little special report on passwords and using password managers. I'd be glad to send it to you. Just email me@craigpeterson.com and I'll send that on-off, right? I'm not making a dime off of that. I want to make you safer.

I don't want to have happened to you what's happened to millions of Americans, including my best buddy who had his information stolen. I've been after him to use password managers. He never did it. I don't know why.

Until his paycheck got stolen. Then he came over and I explained it and set it up with them and really helped him out.

Maybe we should do a whole webinar showing you how to use these password managers, how to get them set up because it is a little bit tricky. It's certainly different than you're used to. Many people are using their browser Chrome in this example, to save passwords. When you go to a website, you'll automatically have the password there. Maybe you've got it set up so that it'll automatically log you in with all kinds of cool stuff. But there is a very big problem and that is that there is a huge risk with running these extensions, like the Great Suspender. The Great Suspender was approved by Google. It was in the Google store. You could download it from their app store. Absolutely free.

In January of this year in 2021, we had someone out on Twitter, tweet that there was a problem with the security on the Great Suspender. It had been changed. It was being used now to send ads out and other things. That's pretty, pretty bad. The extension wasn't banned until about a month later and you as an end-user had no official notification that this extension was potentially malicious.

Apparently, they could, with this malicious software they embedded, not just show you ad, not just insert their own ads to generate revenue onto the webpage as you were visiting, they could also grab files from your machine. That's a very bad thing.

Now, presumably, if you're at work, you have a team that's helping you outright. The IT security team, there may be different teams and maybe the same person who also is the office manager, who knows. It does vary. Businesses cannot know what you're doing when you're starting to install those extensions and they are pushing their way onto your office computer because you're using the same Google account in both places.

Now, despite the risks, of course, I installed this Great Suspender used it for years and I was pretty happy using it. I know many other people who were in the same boat. Security teams have some great tools. I mentioned my son who's one of our team members got called out to a client. During the break, I was just chatting with him briefly. What had happened is they plugged in this firewall we told them not to plugin. It was apparently hacked from the outside. It had known security vulnerabilities. He had not, this small business owner had not yet paid for maintenance on his little firewall, so he was not getting security updates.

In fact, my team member looked at this and found that it had been three years since the firmware on his firewall had been updated. The bad guys got into his network through this secondary firewall, which we told them not to have not to plugin. Our firewall only noticed it because this malware started scanning everything on the network. Of course, it scanned two of our machines, one being the firewall.

Remember this isn't a regular firewall that we put in there. This is a firepower firewall with a whole bunch of extra software on top of it. In our data center, we have some huge machines that are sitting there watching what's going on remotely. On our client's networks via that firepower firewall.

We started getting all these notices as to what was going on, but this is a great example. We're not updating some of that software. He had a security team and he ignored the security team. We were the security team. We're outsourced cybersecurity that's what we do, but that happens many times.

Many business owners and others look at the cybersecurity situation as having many different shades of gray. What should you do? What shouldn't you do? The teams that are working in these businesses, including us. We have to tell them, Hey, don't use that firewall. Do not plug it in. You don't need it. If you plug it in, it's going to make it way easier for some of your people to work from home. This is not set up correctly and you're going to have problems. That's a difficult conversation to have with a business owner. We had it and he ignored it much to his peril.

In this case, this one is hard to tell how much data was stolen from his business. The impact from this could last for months, and there could be investigations who knows what's going to end up happening here. That business owner and I, because I spoke to him as well about this whole situation before this particular event happened just about two weeks ago. In fact, that was a reminder cause they had plugged it in again. Six months before that we had told the business owner, you can't plug this thing in, you cannot be using it.

How do you do that? How do you let an impacted employee, somebody who's working from home, maybe using their own computer to do work for the business? How can you approach them and tell them, Hey, you cannot use Google Chrome? You cannot save your passwords on your browser. You cannot install extensions. Even if you had a list of extensions today that were bad, that list is going to be out of date tomorrow, which is going to be a very big problem.

Individual users do not have the ability to check this. Frankly, most businesses don't either. Again, that's why a business under 200 employees cannot afford to do this yourself. You just can't. This is a specialty.

We were talking yesterday with a prospect who had been brought to us by a break-fix shop and trying to get this concept through. We're going to talk a little bit more about that. What should you be doing? How can you pay attention? How can you even be safe in this day and age?

Hi everybody. Craig Peterson here. We've been talking about supply chain problems. That's a technical term for it, but the software that we rely on becoming evil, and what can we really do about it?

Hello, everybody. You're listening to Craig Peterson.

How do you talk to a business owner and help them understand? That's a problem. Isn't it? Look at what happened a few years back with TJX stores. Them as maybe TJ max, that's one of their stores. They have a number of others.

Their cybersecurity guys did something I have seen done before. That is, they went to the management of this massive public company and said, Hey, TJX, we need to get this hardware. We need to get this staffing. The hardware course pretty expensive and it sits there and it does much the same stuff. Even back then. Nowhere as good as today. It's exponential, as to how much better it gets every year, but it was good hardware. It really could have stopped the hack that happened and it did.

Here's what it did. It noticed the hack was going on. The problem was they were able to say yes to the hardware, the senior management said yes. They got the hardware, but senior management would not get the security technicians that were needed to monitor and run that hardware. They were short-staffed.

That's another problem we're seeing. That's why the companies you're dealing with, whether it's Equifax, with who you do not have a direct business relationship with, and yet have all this information about you and sell that. Or maybe it's just some other website. That's why they lose your data. It's a real bad idea. The bad guys are just waiting out there just siphon all of your data. In many cases, when you're talking about a business and a business website, or even your home computer, they're looking to redirect you to malicious websites.

What they'll do is for instance, again, the Great Suspenders' an example, that they claim it's been fixed now. With something like an extension or a plugin that you put in your browser, they could rather easily code it up so that you are going to a website that's malicious.

It could look like Bank of America's website and you go there and you enter in your information. You put in your username, you put in your password, it asks you a security question. Maybe maybe not, but your username and password. Then it says incorrect. Then your screen refreshes while your screen just refreshed because you were not at the Bank of America, originally. You were at a malicious website and you entered in your username and password. Now the bad guys have your username and password to your banking system, to your login, to your bank accounts. They got that. That's all they needed. They didn't want you to know that this was going on so they just went ahead and redirected you over to the real bank website. Hence, the supposed reload.

It's a very big weakness here in how IT and security teams operate because too few security teams really can relate with the CEO and vice versa. I've seen that all of the time with people working for me in cybersecurity, you've got a really good idea of what needs to be done, how it needs to be done when it needs to be done. To you, it's the most important thing in the world, right? You don't want the business to go under, you're going to lose your job, maybe your pension retirement plan is tied to that business. You don't want it to happen, but have you got the trust built up with the senior management?

Then how about the other side of this relationship? How about if you're a cybersecurity person? Even if, again, you're not a professional, you're just the person tasked with it in the office or you're the person tasked with it at home. How do you go to the other employees and tell them you can't use your Google Chrome account here in the office? How are you going to enforce it? How are you going to tell your husband or wife, Hey, that's dangerous? I don't want you installing any of these extensions on your computer. One of the really bad things that people do with their browsers is they put on these real fancy little extensions that give all kinds of extra wonderful information. It ends up as a toolbar and it lets you do searches on this site or that site. Maybe it keeps you up to date on the stocks that you have in your portfolio. You're telling hackers what stocks you own, really? It might be legitimate, right. But who knows? That's the problem. Something like that can really mess you up and send you to malicious sites. You know that your spouse is using that or your kids are using that. How do you talk to them? How do you solve those problems? It's a real problem.

There are some interesting tools that you can use, as professionals. There's a Slack channel I can send you to, if you're interested, actually, it'll be in the newsletter that comes out on Sunday. At least it should be under one of those articles. It is a problem.

Netflix, by the way, is really trying to help you out too. Not only did the Netflix security team provide some feedback for what's called the honest security guide, but it's also made some of its user tools, the tools that you might use at your home to find a movie, et cetera, it might help really to secure you.

Git Hub has this. It is called, this is a Netflix skunkworks, the stethoscope app. It's a desktop application created by Netflix that checks security-related settings and makes recommendations for improving the configuration of your computer. It doesn't require central device management or reporting. You can have a look at that. If you are interested, let me know. I can probably point you in the right direction to the stethoscope app. That's what we want to see in this honest security guide. You'll find it online. At honest security is a guide to your devices, security, which in the biz we call endpoint security and it is cool. You can run through all of this list is a big checklist and talking about why honest, and they're saying dishonesty stops you from doing the right thing.

That's why in my courses, I spend a lot of time, more time in fact, on the why than the how. I want you to understand honestly, why you should or should not do something.

There are so many people who are out there yelling and screaming, jumping up and down. Particularly your antivirus companies. You fake VPN companies who are trying to get you to buy their products that not only do not need in most cases but will actually make your computer less secure.

So we have to be careful about all of this stuff. We have to make sure we are talking. We've got to have a trust relationship set up with the owners of our business. Cause you guys, some of you, I know own businesses, some of you work for a business. We've got people listening to this all over the world and every continent I've even seen a listener down in Antarctica. I really can say every continent. It's important that we know how to work with our fellow employees, with our management, with our family members, to help them to know what they need to do. There is no time to wait. We have never seen as many attacks as we're seeing now. We've never seen the government using its resources to attack us more than we have now.

We've never seen more billions of dollars stolen per year by the bad guys. There are some basic tenants that you can follow that will make you way more secure. And that's why you're listening. That's why I go through some of these things to help everybody understand.

That's also why I go ahead and make sure that I answer your emails. If you have a question, make sure you go ahead and ask. You can just email me at me@craigpeterson.com. If it's something urgent, I have a form on the bottom of my homepage @craigpeterson.com. You can give me a little bit more information. I tend to keep an eye on that a little bit better than my general email, although I do use some amazing email software that helps me to keep track of the real email and get rid of the spam and put things in boxes and stuff craigpeterson.com. It's that simple email me me@craigpeterson.com. If you have questions.

I hope that Google is going to continue to improve itself. I love the fact that they found out that this one extension was malicious.

For those of you who might've just tuned in, we're talking about something called the Great Suspender something I've used for years, it became malicious, but they need to do more.

As people who are concerned about security, we just can't wait for the next incident. Just again, this client of mine, who we've been warning about this for months, he's stopped doing what we told him to do, and then decided well it's just too difficult. That's something we hear a lot from businesses. Oh, it just hampers the work. It hampers it because now we have to get permission from it in order to mount this particular drive or gain access to those files or materials. Yes you do, because we have to stop the internal spread of all of this malware and all of these hackers.

It is absolutely worth it.

All right, everybody. Thanks again for joining me today. I really hope you've been enjoying this. I have years' worth of podcasts out there and you'll find all of those at craigpeterson.com/podcast or on your favorite podcast platform.

If you subscribed under iTunes, you might've noticed, ah, yeah, I just released a whole batch there too.

I expressed concerns about owning an Apple watch. I held off for a long time. I want to talk about these devices now, the security concerns, but also the amazing health tools that are built right in.

Hey, welcome back. This Apple watch is really fascinating. It has been around now for six generations. There are a number of other watches that have had, or tried, I should say, to compete with Apple. They haven't been very successful. You might've noticed that. I have a friend that bought some watches for his family and to him that monitor all of the basic vitals and record them and send them up to his phone. It's a 20-ish dollar watch. He got it from South Korea probably are parts made in China, but it is an inexpensive watch and it does some of the basics at the other end of the scale.

Let's have a look right now. I'm going to go to apple.com online, and we're going to click on watch. Here we go, Oh, my they've got special watches so you can buy their watches. It looks like the new one, the Apple watch series six for starting at 400 bucks or they have two different sizes. . They have a more basic watch called the Apple Watch SE that starts at about $300. You can still get the Apple watch series three. Now, these all can monitor high and low heart rates. They can give you irregular heart rhythm notification, but it's only a-fib atrial fibrillation, I think is the only one they can monitor, but all three of those can monitor that.

As I said, my buddy's watches, he got for his family at 20 bucks apiece are able to do most of that as well.

These are water-resistant to 50 meters, which is really cool. The series six also has an ECG app. That is very cool. You open the app, you put your finger on the crown of the watch and it gives you an EKG right there on the watch and it feeds it to your phone.

On your phone, you can turn it into a PDF. You can share it with your doctor on and on. It's just amazing. It's a three-lead type, I was in emergency medicine, right? A med-tech EMT, EMT-PD can't remember. I had a whole bunch of different certifications back in the day. But it's fantastic for that.

It also has a blood oxygen app that monitors your blood oxygen levels. It ties all of this into their new exercise app, which is amazing. That ties into your phone or your iPad. I will go down in the basement onto the treadmill and I'll select your treadmill workout. It has dozens of them.

Have you seen this really fancy treadmill? A couple of years ago they got in all kinds of trouble because they advertised it around Christmas time and apparently this woman really wanted a treadmill and she got one and she was all excited. All of these people jumped out of the woodwork. All your you're saying she's fat, et cetera. No, she wanted a treadmill.

These are amazing treadmills because they have built into them. These streams and you can join classes, et cetera. With the Apple Watch, my iPad, and a subscription to this iHealth app, which you can get as part of this Apple plus thing you can buy for 30 bucks for the whole family, 30 bucks a month.

I don't know how many I have seen probably a hundred different workouts on there. It has different workouts, different types of weightlifting, running, jogging, treadmills, elliptical machines, everything. You can pick your pace. You can pick your instructor, you can pick everything.

Then your Apple watch is monitoring your body. As you're working out. So it's telling you how many calories you've burned. What's your heart rate is to help keep your heart rate in the best range for you, depending on what kind of a workout you're doing. It also lets you compete against other people.

Does this sound like an ad for the Apple watch?

You can compete with other people your age doing the same workout and see where you're at. I was really surprised because typically I am at the front of the pack when it comes to my treadmill workouts. That's really cool as well.

Those are some of the basics. There are other things too, that Apple is doing. We've found, right now, that Mount Sinai just came out with an announcement and they said that the Apple watch can predict COVID 19 diagnosis up to a week before testing can detect it. Yes. Isn't that something? Not only can the Apple watch help with certain heart arrhythmias, but it can predict that you have COVID-19 too a week before testing normal testing. Those swabs can find it out.

This is from the journal of medical internet research, which is a peered review journal. And they found that wearable hardware and specifically the Apple watch can effectively predict a positive COVID-19 diagnosis up to a week before the current PCR-based nasal swab tests.

They called this the warrior watch study. They had a dedicated Apple watch and the iPhone app, and they had some participants from the Mount Sinai staff and it required, of course, these staff members to use the app to turn on the health and data monitoring and collection, and also asked them to fill out a survey every day to provide some feedback about their potential COVID-19 symptoms. As well as other things like stress can obviously make your heart rate, go up your blood pressure, go up, et cetera. Oh. By the way, Apple, supposedly the rumors are, we'll have a BP sensor in the Apple seven that'll be out later this year, most likely.

So they had several hundred healthcare workers and the primary biometric signal. I know that the studies authors were watching was heart rate variability. This is fascinating to me because it's something that I learned about fairly recently. Then when I got my Apple watch, I read up more about this, but basically, heart rate variability is what it sounds like. It's your heart rate. Let's say your heart is beating at 60 beats per minute. It is not beating once every 10 seconds. It is not beating once a second. Your heart rate will vary over the course of that minute. If you're healthy. Obviously, a beat every 10 seconds isn't 60 a minute.

Let's use that as an example. Somebody who's almost dead and has six beats per minute. The first heartbeat might be at 10 seconds. The second heartbeat might be at 22 seconds because your heart is supposed to vary its rate of contractions based on immediate feedback. It's not just that you're going out in your running and now you've driven up your heart rate and you're doing your cardio and it or you just walked up a flight of stairs or you stood up, which is another test, by the way, what we're talking about here.

You might just be sitting there, but your cells have a different need for oxygen or for the blood. The heart slows down slightly or speeds up slightly. This heart rate variability is something built into the Apple watch and into the iPhone app that you attach to the Apple watch. Isn't that useful without an iPhone, frankly? Then you can look at your heart rate variability right there.

They said, combining that with the symptoms that people reported, these Mount Sinai staff, that the symptoms that they reported that were associated with COVID-19 including fever, aches, dry cough, gastrointestinal issues, loss of taste and smell corresponded with changes in the heart rate variability. I thought that was just absolutely phenomenal because heart rate variability is considered to be a key indicator of strain on your nervous system. COVID-19 obviously is going to put a strain on the nervous system. Just very neat. It says here that the study was not only able to predict infections up to a week before tests provided confirmed diagnosis but also revealed that participants' heart rate variability patterns normalized fairly quickly after their diagnosis or turning to normal run about one to two weeks following their positive tests. That's from a TechCrunch, that particular quote.

I am very excited about this, but I am also on the concerned side. I'm concerned because they are collecting vital data from us. All of the major companies, Google and Microsoft and Apple want to be the company that holds all of your personal medical records.

We're going to get back to that when we come back here. What is happening? How is your doctor managing your medical records? I was really shocked to find out how that industry is working.

Of course, you're listening to Craig Peterson. Check it out online. Craig peterson.com.

Welcome back. What are you doing? Are you asking your doctor how they are handling your medical records? Because I think you probably should based on what I learned just this week.

Hi everybody. Craig Peterson here. Thanks for joining me. We were just talking about health. We're talking about the Apple watch and the fact that there's a lot of competitors out there, some of them, a fraction of the cost. If you buy the Apple watch on terms, you're going to pay less in one month's payment on terms to Apple than you would for some of these other watches out there, but Apple watches do have more features.

Mine even has a built-in cellular modem. Even if I don't have my phone with me, phone calls come through to my watch and text messages, and I can respond and answer. It's really nice. Medically I am very impressed. It has been good at motivating me to do some exercise, to get up, and about just to do a bunch of things I had never, ever done before. Consider that.

It is collecting our data. Apple now has potential access to all of my cardiac data. They've got EKGs that I have run on my watch. They know about my heart rate. They know how often I exercise, and how hard I exercise when I exercise. They know all of this stuff about me. I had a conversation with someone just saying why does that matter? Maybe it's Apple, maybe it's somebody else. Why does it matter?

It does matter. Think about an evil genius, right? The thing about somebody that might want to target Americans and might want medical information about Americans. They can gather it in a number of different ways. We're going to talk about medical records here in a little bit.

One of the things they could certainly do is grab all of our watch data. Some of these watches, including my Apple watch, have GPS built into them. When you're out running or jogging, you know where you went, you can plan your route and it'll remind you, Hey, turn here, turn there. That's one of the things I love about the Apple Watch when I'm using it with Apple maps out driving, it taps me on the wrist and reminds me, Hey, in 500 feet, you got to turn.

If I look at the watch, it'll even show me the turn I need to make coming up in 500 feet. It's really amazing. All of this information is being compiled and hopefully, it's being compiled by a company that we can trust. At this point, we can probably trust Apple. Hopefully, they're not going to be broken into. Now, their margins or profit is high enough that they certainly can afford a security team, one capable of defending them and defending our data. I hope they are. I suspect that they are for the most part.

How about some of these others? We know Google, for instance, is in the business of collecting and selling our information, is having all of our medical information. Not just the stuff from our watches, but the stuff from our doctors. Are they to be trusted with that kind of information?

Going back to that bad guy, that mad scientist we can, and probably do engineer viruses that are targeted at specific things. In fact, the Russians have been doing it. The Soviets' started it, they came up with a phage. That can attack certain viruses and it acts like a virus it gets in and does this little thing. We've got right now, these COVID-19 vaccines and they act like a virus they're messing with, well effectively, the DNA. In fact, it's the RNA, but it's pretending, Hey, I got a message from the DNA, here it is.

What if a bad guy knew that are a certain population in a certain area, and that area was right by this important military base or whatever they came up with something that would target them and they'd have all of the data to do it now. That's obviously an extreme example. A more common example would be that your medical data is there. It's being sold to advertisers and you're going to end up with something.

For instance, there's a company, very big company out there and they sell baby products. What they did was they tracked and they bought this information, but they tracked women who were purchasing certain things. Now, they weren't purchasing things that were directly related to having a baby, right? They weren't purchasing diapers or little jumpsuits or whatever it is. They were purchasing things that were not directly related maybe people wouldn't even think they were typically related to having a baby. Yet they were able to figure this out. They got that good with the data. So they thought, Oh, okay let's get wise here. Let's send out a postcard, congratulating them on their pregnancy and offering them a discount on something. Yeah. Not a bad idea, frankly.

However, in this case, some of these moms I hadn't told anybody that they were pregnant yet and didn't want to tell anybody that they were pregnant yet. It fell on its face. Didn't it?

How about these ambulance-chasing lawyers that are out there? Are they going to want to gain access to this, to your medical records?

How about your employer? Your employer wants to know I'm going to train this person. Hopefully, they'll stick with us for a while, but is he going to be a burden on our medical plan? Keyman insurance, health insurance, life insurance. Have access to everything about you. That's what really concerns me about these, all of these devices.

Right now, pretty confident that I can give Apple this information and they will keep it pretty safe. But, I said the same thing about the Great Suspender, right? I don't know about the future.

Then I found something out this week that was in my mind extremely disturbing. We have a new clinic that we've picked up as a client. They needed to have security. They had a couple of little security issues. They were worried. They knew they were not HIPAA compliant. They approached us because they know that's what we do is cybersecurity and audits and remediation. Fixing the problems. We pick them up. They're a client. We're in there. They had told us in advance that all of their medical record systems were on-line. It was on the web. All they needed was a web browser to run their business. Okay. That could be a problem. It might be okay. The medical records manufacturer might have good security on all of the records. So we may be safe, although in HIPAA unless you have a business process agreement in place with that vendor if that data is lost, it falls back on the doctor's shoulders.

Anyhow, what I found out was, first of all, it wasn't completely web-based, which just shocked me. I'm not talking about they have to scan records or they got the x-ray machine or whatever. It really wasn't web-based and secondarily the company they were using for the medical records was a free service.

The doctor, that clinic, was not paying for their medical records management software. The way it works is this medical records management company when the doctor prescribes something when the doctor performs a procedure and bills and insurance company, it's all done through this one company and that company takes a chunk of their money.

In some cases we found seems to have been inflating the bills that went off to the insurance companies and that, as it turns out is a common practice in the industry. According to the doctors at this clinic, I was shocked, amazed.

Something you might want to look at. Ask your doctors where are your records kept and are they secure?

Now we had HIPAA. We thought that would secure it, but it doesn't.

Stick around.

Hey, we got a name now for what happened to the Great Suspender and QR code scanner apps over on the Google stores. One at Google Play, the other one over on the Google Chrome store. It's become that popular.

Hey, everybody, I wanted to mention this whole new category of malware really, and they're calling it, right now, Buy to infect. What happens is a bad guy, a malware guy buys a legitimate app and then starts infecting it. We know, obviously, about the one that I've been talking about a lot the Google extension that I used to use all of the time, the Great Suspender. I mentioned this one a few weeks ago, it's called QR code scanner. It's been on the Google play store for a long time, had more than 10 million installs and then all of a sudden it became malicious.

This is a little bit of a different angle on it because, with the Great Suspender, the ownership of that software actually transferred to somebody. With QR code scanner, they were working on a deal with a company and this company wanted to verify the Google play account for QR code scanner. This is all according to the owner, the original owner of QR code scanner. They said that what had happened is part of this purchase deal. I let them have a look and gain access to the software's key and password prior to purchase so they could confirm the purchase, which doesn't sound too bad. Apparently, as soon as they got a hold of the software's key and password, forget about the purchase, we're going to start infecting it right away. It ended up getting that app, the QR code scanner app, pulled right from the Google play score store. Of course, now you don't need that quite as much because most of the phone apps when you go to take a picture, the camera apps have built into them, a QR code scanner.

I thought that was fascinating what they did. They totally cheated the company. They didn't even bother buying it. So a little word for the wise out there.

Got another Apple story cause this is showing how the computer industry is really shifting. We've talked about some of the shortages of chips and the shortages of computer chips are so bad that General Motors has had to shut down two-thirds of its manufacturing lines in at least one plant. Every major automobile manufacturer is having problems making cars because they can't get the chips.

Remember nowadays, a car, a truck is essentially just a computer on wheels. Not really actually computer on wheels. It's really dozens of computers all linked together with a network on wheels.

Apple has been worried about that, right? Supply chain. That's one of the things you're supposed to worry about as a public company. What are the risks going forward including to my supply chain? Obviously your supply chain matters. You gotta be able to make something you need parts, right? Apple has been upset with Intel for a while. You might remember Apple. When it first came out, was using a Motorola chipset, which was exceptional much better than the Intel chipsets. Of course, that's my opinion, a lot of people agree with me. You had the 68000, 68010, and 20, et cetera. Very good chips.

When Apple started getting into the laptop business, that's when the problems started to happen. These Motorola chips gave off a lot of heat and used up a lot of electricity. At the time Apple looked around and said our only real alternative right now is Intel. Intel has a whole line of chips, different speeds, and they have mobile chips. Those mobile chips use much less power than the Motorola chips for the main CPU. They also use less battery. Those two go hand in hand and generate less heat. That's it all goes hand in hand. So they said, we'll start working with Intel. They did. Intel really disappointed them more than once, which is a shame. They disappointed them with the 64-bit migration. AMD, advanced micro devices, beat Intel to the punch. Shockingly Intel started making AMD compatible CPUs right. The 64-bit extensions to the CPU were AMD extensions. They had problems with some of their other chips as well. Mobile chips getting the power usage under control, the heat dissipation problems under control, and they never really lived up to what Apple was hoping for. What everybody in the industry was hoping for. In many ways, Intel has been a huge disappointment, which is really a shame.

We'll look at what they did to the industry, with these predictive instructions, the hyper-threading, and stuff. Where bad guys were able to bring a computer to its knees. What does Intel say? Here's a firmware patch you can apply to our CPU, those little CPUs you pay upwards of $2,000 for a piece for one chip. Those CPU's and by the way, it's going to, cut its performance by a minimum of 20%, maybe 50%, that's okay.

What are you kidding me? A lot of people were upset with Intel and Apple and Microsoft and everybody released patches that use the new Intel microcode. You might've noticed when this happened a couple of years ago that your computer slowed down. I certainly noticed, actually, it was little more than a year, anyway, I noticed it because I own a data center. That has a lot of Intel chips in it where we're running mostly Unixes, Linux, and BSD, but we're also running Windows. So the only way to work around this bug was to apply the patch and slow everything way, way down.

Imagine how Apple and Google felt with their huge data centers. IBM too. IBM has Intel-based data centers, as well as its own chips, and boy talking about phenomenal chips, as far as processing power goes, IBM, man, they are still the leader with the power chips and their Z series. That just wow. Mind-blowing.

Most of us are stuck in the Intel world. Apple said we can no longer trust Intel. So what are we going to do? Apple said we've been developing this chip for a long time. Apple took the chip design, they licensed it from this open sourcee type of company that has a number of members. They took this arm architecture and were able to improve it, and keep adding to it, et cetera. They're still part of this Alliance. They started using these in their iPhones. The iPhones have been using these chips the whole time and they started improving them after they released the first iPhones. Intel didn't really get them upset until a little later on, too.

They came up with newer ones, faster ones, better ones, right to all of these A10 their bionic chips. They've got AI chips, machine learning chips, all Apple designed. Chips, of course, manufactured by third parties, but that's what Apple is using. Apple has now said we expect all of their Macintosh computers to be based on Apple's CPU within the next two years.

There's already some really good ones out there right now that people like a lot. We've been using them with some of our clients that use Apple. Not everybody has had great luck with them, but Apple is not only ditching Intel, that's not the big story here. Apple's got some job listings out there looking to hire engineers.

So when we get back, we'll tell you more about what Apple is doing and what frankly, I think the rest of the industry should look at. Guess what? They are.

It's been Intel versus the rest of the world. They've been winning for years in many categories, but now they're starting to lose, as major manufacturers are starting to leave Intel behind. But there's more to the story still.

Hi, everybody.. Craig Peterson here. Thanks for tuning in. We're glad you're here. In the last segment of the day, I want to point everybody to the website, of course. You can get my newsletter. It comes out every Sunday morning and it highlights one of the articles of the week. It gives you a pointer to my podcast. So you can listen right there. There's just a lot of great information. Plus I'm also doing little training. I'm sending out, hopefully, next week, two little training sessions for everybody to help you understand security a little better, and this applies to business. However, it's not. Strictly business, much of what I talk about is also for home users. So if you want to go along for the ride, come along, we'd be glad to have you. There's a lot to understand and to know that you won't get from anywhere else. It's just amazing. Many other of these radio shows where they are just nothing but fluff and commercials and paid promotions. I'm just shocked at it. It goes against my grain when that sort of thing happens. Absolutely.

We were just talking about Apple and how Apple got upset with Intel, but they're not the only ones upset. We also now have seen a lot of manufacturers who have started producing Chromebooks and surface tablets that are based on chip sets other than Intel's.

This is going to be a real problem for Intel. Intel has almost always relied, certainly in the later years has relied on Microsoft and people bought Intel because they wanted Windows. That's the way that goes. It's just like in the early days, people bought an Apple too, because they wanted a great little VisiCalc, the spreadsheet program.

Now, what we're seeing are operating systems that do not require a single line of Microsoft software. Google Chrome is a great example of it. Linux is another great example and people are loving their Google Chrome laptops, and you can buy these laptops for as little as 200 bucks. Now you get what you pay for and all the way up to a couple of grand and they don't have a line single line of Microsoft code. Yet you can still edit Word documents and Excel documents, et cetera. They do not contain any Intel hardware. What was called, well, they might have a chip here or there, but not the main CPU. What used to be called the Wintel monopoly. In other words, Windows-Intel monopoly is dying. It's dying very quickly.

Apple is not helping now. Apple, they've had somewhere between seven and 10% market share in the computer business for quite a while. Personally, I far prefer Apple Macintoshes over anything else out there by far. I use them every day. So that's me. I don't know about you. There's a little bit of a learning curve. Although people who aren't that computer literate find it easier to learn how to use a Mac than to learn how to use Windows, which makes sense. Apple has really done a great job. A bang-up job.

With these new chips, it's getting even faster. We are now finding out from a report from Bloomberg who first started these, that Apple has been posting job listings, looking for engineers to work on 6G technology. 6G, right now we're rolling out 5g, which hasn't been a huge win because of the fact that if you want really fast 5g, like the type Verizon provides, you have to have a lot of micro-cell sites everywhere. They have to be absolutely everywhere. Of course, it's just not financially reasonable to put them up in smaller communities. If the Biden administration continues the way they're going with the FCC and the open internet type thing of a-bits-a-bit, then there will be no incentive for any of these carriers to expand their networks because they can't charge more for better service. If you can imagine that. Ajit Pai fought against that for many years, Trump's appointee as chairman to the FCC, but things are changing. The wind has changed down in Washington, so we'll lose some of those jobs and we're not going to get all of the benefits of 5g. If he keeps us up. 6G is coming.

What that means is Qualcomm, who is the manufacturer of record for most of the modems that are in our cell phones. Qualcomm has also missed some deadlines. Apple is tired of dependencies on third parties because Qualcomm might have somebody else that buys way more chips. It might be able to sell the same chip to the military of whatever country for a much, much higher price. They can sell it to consumers. Maybe they just change the label on it and call it a mill spec, and often goes right, who knows? What they're doing out there, but Apple doesn't want to do that anymore. They are looking for engineers to define and perform the research for the next generation standards of wireless communications, such as 6G The ads say you will research and design next-generation 6G wireless communication systems for radio access networks with emphasis on the physical Mac L two and L three layers. Fascinating, eh? What do you think? I think a huge deal as Apple continues to ditch, many of its vendors that have not been living up to the standards Apple has set.

Apple has moved some of the manufacturing back to the United States. More of the assembly has been moved here. The manufacturing, it's starting to come back again. We'll see the Trump administration really wanted it here. We need it here, not just for jobs, we needed it here for our security.

We've talked about that before, too, right? I want to also point out speaking of Apple and manufacturing, China, of course, does most of it for Apple and Foxconn is the company in China that makes almost all of this stuff for Apple. It's huge. Foxconn owns cities. Huge cities. They have high rises where people basically don't see the light of day, these high rise factories. You live there, you eat there, you shop there, you work there.

Like the old company store who is it, Tennessee Ernie, right? Owe my soul to the company store. That's what's happening over there. And Foxconn has kept its costs low by bringing people in from the fields, if you will, out there being farmers and paying them extremely low wages. On top of all of that, in some cases they're using slave labor. I found this article very interesting, from Ars Technica's, Timothy B. Lee. He's talking about a potential partnership between Apple and Nissan. Let me remember. I mentioned Apple talking with Kia and Kia is denying it.

The financial times reported on Sunday that this potential deal between Apple and Nissan fell apart because Apple wanted Nissan to build Apple cars, they would have the Apple logo on them. They all be branded Apple. It wouldn't say Nissan unless you took something seriously apart you might find it inside.

Nissan wanted to keep the Nissan brand on its own vehicles. Bloomberg reported last week that the negotiations with Kia and of course its parent companies Huyndaiin South Korea had ended without a deal. The Financial Times said that Apple has also sounded out BMW as a potential partner because Apple doesn't make cars.

So how are they going to do this? Apparently the talks faltered with Apple and Nissan because Nissan had a fear and apparently this is true of Kia too, of becoming quote the Foxconn of the auto industry, unquote, which is a reference to this Chinese well it's Taiwanese technically, but a group that manufacturers are while actually assembles the iPhones. Fascinating. Isn't it fascinating.

When you start to dig into this self-driving technology and the numbers behind it, that's where you wonder, why is Apple even trying at this point, Apple's test vehicles only traveled 18,000 miles on California roads. Between 2019 and 2020, or over the course of about a year, late in both years. 18,000 miles in a year. Heck, I've done that before with my own car.

Waymo, which is Google's self-driving project put on more than well, about 630,000 miles in California. Likely a lot more in Arizona where they doa lot more testing. Cruise, which is this startup that was put together by GM and Honda logged even more miles than Google's Waymo, 77,000 miles on California roads.

So this is going to be interesting. Apple sitting on 77 billion dollars in cash and short-term investments. That's more than the market capitalization, the entire market gap of a number of major market car makers, including Nissan, Ford. Actually, you add those two together and you haven't reached the amount of cash Apple has on hand and Stellantis, the parent company of Chrysler Fiat. They have the money potentially they could buy out one of these companies. We'll see what happens, the automated cars market's going to be huge. I'm looking forward to it. We're going to have a lot of struggles between now and then.

Hey everybody, if you haven't done it go right now to Craig peterson.com/subscribe. You'll get my newsletter. You'll get these trainings. You'll get to listen to my appearances if you miss them. You can find my podcasts on almost any platform out there.

Just check it out. Craig peterson.com. If you have a minute, leave a hopefully five star review for me. I'd really appreciate it.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. We really got into the power distribution issues in TX and it appears that the Energy department was really "asleep at the switch." Then we talked about the nightmare that these bureaucratic states are having with their vaccine scheduling websites. We discussed why they are having a problem and what they could have done, but didn't. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hi everybody. Craig Peterson here. I'm laughing because I just had to run over to another computer, shut off the speaker because here it was on the air with Mr. Matt Gagnon, and all of a sudden my computer, which was rebooting came up and decided it was going to play Johnny Cash Ring of fire. See if you can hear it in the background, it shouldn't be too loud. Cause I've got a decent microphone here, but man, did it distract me?

Anyhow, we got into New York's vaccine website. What's going on there?

This math that talks about wind energy shows what really happened down in the great state of Texas.

A little bit about what's going on in Maine and of course, a little bit of ring of fire. So here we go with Mr. Matt Gagnon.

Matt Gagnon: [00:00:46] It's WGAN morning news on a Wednesday, which means it's a good time to talk to Craig Peterson, our tech guru. You can hear him on this very station on Saturdays at one for his own show where he talks about a lot of these same topics, but why wait, he's here with us now, Craig, how are you this morning?

Craig Peterson: [00:01:01] Hey, good morning back. Doing really well.

Matt Gagnon: [00:01:03] Lots of stuff to get to with you here. One of the most topical topics, if you will, that we could deal with here, which is interesting to talk to you about. But something that we've talked about on the show quite often here in the last week, or so is about what's going on in Texas, right?

With the energy failure. What's been going on with power outages and how cold has affected it and what I would consider a brewing controversy about, what's really. The ultimate culprit here, initially a lot of people were blaming sort of wind farms that had frozen and were unable to be producing any sort of electricity.

Others have pointed the blame at natural gas facilities, also not being able to transfer a lot of electricity, et cetera, but you gave me an article that to read, which I thought was very interesting about the basic math behind all this showing how frankly wind energy actually is a pretty big culprit in this whole story.

So just tell us a little bit more about what we've learned here.

Craig Peterson: [00:01:54] Yeah, It's interesting when you get beyond kind of the emotions and the political arguments and get down to the real facts behind it all. Texas, of course, this is just a terrible thing. We had people die. Every year, in fact, of course, people end up dying from the cold and heat as well.

Having the ability to heat our homes, our businesses, and cool them in the summer, particularly in Texas is really important. Texas focused on the summer where of course everything gets hot, they need a lot of electricity. They're four main ways of generating electricity. Natural gas, of course, they have a lot of that thanks to fracking, coal, wind, and nuclear.

When we look at the numbers, the actual hard numbers of megawatt-hours produced in Texas. We see about a 20% drop across the board in the amount of electricity that they are generating by each of those four categories. That's not a good thing, right? Because you need more energy. In every case, the amount of energy produced dropped, because those systems were not set up to handle the cold.

What's really interesting is you look at natural gas. For instance, it was about 44,000 megawatt-hours before this whole thing happened.

That 44,000 number dropped down to 30,000 when we had, of course, the coldest part of the winter. Some of that was because control valves in some cases were not winterized. They weren't ready for the cold. There are other reasons as well. It dropped because, of course, now we have people demanding it to heat their homes. So there was less natural gas available for these power plants.

Coal even dropped. It went from 10,000 megawatt-hours down to 8,000, but you pointed out something that's really dramatic and that is the wind power.

We have all kinds of jets, but let's just use a small one as an example, a little Bombardier jet, they fly in and out of these smaller Maine airports all the time.

How do they fly? Well, they fly because of the lift, right? The aerodynamic lift. If you get ice on those wings, all of a sudden you lose that lift, and the plane crashes.

How are we not having planes crash all the time? It's that bladder on the leading edge of the wing. In the smaller planes, you use a bladder and that bladder expands, which now breaks up all of the ice it's on that wing and then contracts back down so that you maintain that aerodynamic shape.

The same type of principle is in play when it comes to windmills, you basically have the wing of an aircraft in each one of those blades on the windmill. When that windmill gets coated with ice, it all of a sudden the blade does not grab the air anymore.

So wind power generation in Texas dropped from about 8,000 megawatt-hours of production down to 650. Just dramatic.

Even nuclear power dropped from about 5,000 megawatt-hours down to about 3,800. A lot of these were caused really by Texas, not paying attention to what would happen when it gets really cold.

What most news outlets are not reporting, in fact, I haven't heard this on any news outlet, so you're hearing it first, probably right here.

Is that Texas was minutes away from potentially being months away from recovering from this whole thing and back to the old normal.

Matt Gagnon: [00:05:36] Yeah, I would say it to interrupt you there. I saw that same report and, it looks to me like a salacious headline but reading through the actual story, that's not an exaggeration. It was really a disaster waiting to happen.

Craig Peterson: [00:05:47] It really was because again, natural gas doesn't like, oxygen. What happens when you're using a lot of the natural gas up? Well, the pressure drops. What happens for the pressure drops to a certain point where the pressure in the pipeline is about equal to that in the air? All of a sudden you get oxygen back into the lines and you get explosions. It's incredible, all the way across the board.

Now, in Maine, we're not really heating all that much by electricity or natural gas. Nearly two-thirds of the households here in Maine use fuel oil as their primary energy source. Of course, most of that comes down from the great white North, say from Canada.

That's the largest share of any state in the union, frankly. In 2019 80% of Maine's electrical need here was fulfilled from renewable energy sources, which includes, hydroelectric power, which provided the largest shared of about 31%.

We've got some interesting things going on, including wind power generation, because Maine leads New England in wind power and ranks sixth in the nation. We built it to be able to handle these cold snaps.

Matt Gagnon: [00:06:57] Speaking with Craig Peterson, our tech guru. He joins us at this time every Wednesday to go over the world of technology.

Craig, also, another thing I've been talking an awful lot about on the show here is about the various problems in the state of New York and exactly what they've been doing wrong for quite a while, as it relates to COVID-19 stuff. Specifically Andrew Cuomo and all of his friends. You know, another story to talk about here, the vaccine website's not working in New York, again.

Craig Peterson: [00:07:23] Yeah. It's incredible. The amount of difficulty, there's something called over-engineering. You've heard of that before. I'm sure, Matt. That's where you need to move a Boulder, so you get an engineer. The engineer comes out and designs a bulldozer when all you need was a fulcrum and level. Which would make life a whole lot easier for you.

There's a lot of things to consider when you get right down to it. The bottom line is it is a major problem in New York. People are not able to get onto the website. Same problem in Massachusetts. They got the same thing going on. You could do all of this from these websites, just by hiring their commercial service like Cvent, or in this case, one guy for about 50 bucks built a website that would handle New York city's registration for COVID vaccines.

Matt Gagnon: [00:08:11] It's incredible. Yeah. That kind of stuff that continues to be an issue and that New York always seems to lead the way and incompetence here.

Craig Peterson, our tech guru joins us on Wednesdays to go over the world of technology. You can also hear him on Saturdays as well at one o'clock.

Craig, appreciate it as always. And we'll talk to you again next week.

Craig Peterson: [00:08:27] Hey, take care, Matt.

Hey, everybody, take care. Have a great day. We'll be back this weekend. Of course.

I'm having a little trouble with some of the software we're trying to use here to help. With you guys going through this Improve Windows Security course. I had set up an appointment with the vendor and they just bailed on me because the lady that I was going to be working with at her family just came down with the COVID-19. So she can't help.

Lockdown affects us again, as well as apparently the virus. Anyhow, the course is all done. It's in the can. But we got to set it up in a way that you guys can get to it and can use it because we're covering 22 major topics here. I want you to be able to progress through it and understand it, use it, have all of the notes there, and everything. The only real way to do that, frankly, is with kind of a membership site.

We're getting there, although we're not there yet. Man. What a year?

I don't know about you. I was talking, actually, I was on the air. I was talking with somebody on the air, Oh, it was a television interview I did this week.

I should post that up on the podcast.

Anyhow, I was talking about the last year I said, my brain was saying this was last year. It was 2019 that was what I was talking about. Something that occurred in 2019. Here it is 2021. It was as though 2020 never happened.

Maybe, I wiped it out of my brain. Which is a good thing.

One of those years that you wish hadn't happened and apparently did end up happening.

All right, everybody, take care. Thanks for being here.

Love you. Appreciate you.

Man, I love getting those notes from everybody. Me at craigpeterson.com.

Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning, everybody.

I was on this morning on WTAG with Jim Polito. We discussed the power situation in Texas and then brought it home to Mass and talked about whether we could be in for anything similar. We also discussed Green Energy and Nuclear Energy. Then we got into 6G -- yes that is not a typo, Apple is developing their own chips and ditching Intel and Qualcomm to run on 6G. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, Craig Peterson here.

I've had a great day today. So far, anyway, and I was on with Mr. Polito this morning. We covered of course Texas stuff but from a Massachusetts angle. The electrical generation in Mass and what the numbers look like. It's actually quite a bit different in all of the new England States. It's amazing when I did the research on this.

Apple. They're working on 6G. I explain how Apple is trying to divest itself of some of these vendors it had for years, that just aren't cutting it anymore. So here we go with Mr. Polito.

Jim Polito: [00:00:36] It's time to bring in our good friend, the man who has the answers to all the questions. We may have our tech talk guru. Craig Peterson. Good morning, Craig.

Craig Peterson: [00:00:48] Hey, good morning, sir. How are you doing?

Jim Polito: [00:00:51] I'm good. Thank you. Actually, it's getting much nicer outside now. So, I'm feeling good. My friend Bob in Texas tells me it's going to be in the seventies today. We still need to talk about Texas. It was great last week having a conversation with you about them. Just about the failures and well the good old-fashioned green energy.

Then I want to talk about 6G.

Let's start with this, basically, energy failures contributed to the deadly situation in Texas, isn't that true?

Craig Peterson: [00:01:31] Yeah, absolutely is. When we look at Texas and the Department of Energy and how much generation they have, they rely pretty heavily on wind power.

In fact, Texas was generating, let's put it this way about 8,000 megawatts of electricity before the storm hit from wind power.

Then the next day at the height of the storm, it went from 8,000-megawatt hours down to 650. It just completely wiped it out.

What this is really indicative of is a general problem, that Texas seems to have, just like Massachusetts we're looking at our electrical generation and where does most of our power come from? Number one by far here is using the natural gas resources and burning that to make electricity. Well, that is also number one down in Texas.

They had about 44-megawatt hours before the storm that dropdown to 30,000. So natural gas, coal, wind, and nuclear in Texas all dropped about 20% because of the storm. Man, did that cascade, but wind, it got wiped out.

Jim Polito: [00:02:50] There you go when you need it the most, it's not there. I mean, we really need, we need Scotty from Star Trek to get the dilithium crystals to make us some, a power. I mean that's what we need. Then if Texas has another crisis, he can say I'm giving it all I got Captain. Not to make light of the fact that people actually died, but these types of things Chuck Schumer is saying, well, this is what happens when you don't pay attention to climate change. That's a nice thing to say to people who, you know, a state where people died. You get what you deserve. This is what happens or you don't want to join the feds. Unbelievable.

Craig Peterson: [00:03:32] Well here in Mass, about one-fourth of Mass's total generation of electricity, comes from what are called renewable resources. The largest chunk of that in Mass is small-scale solar panels, less than a megawatt of generating capacity.

So here, what we're talking about when we're talking about the renewable stuff, obviously wind is something they call renewable. Solar is something they call renewable, but you have to have sun. You have to have no snow on the solar panels.

If you're going to do wind, you have to make sure that just like the leading edge of a wing on an airplane, you either have a bladder that expands and contracts to break the ice off or you have these things heated. There's a video going around from, I think it was 2017 of a helicopter in Texas with a spray unit hanging underneath it. Like we use here on our jets and it was hovering around these wonderful windmills spraying them trying to melt the ice off of them.

If we're going to try and do this, you got to try and do it right. Again, let's talk green. The manufacturing of solar panels is anything, but green, the manufacturing of these lithium-ion batteries, even the nickel, the metal of batteries is anything but green.

We talked before about how a Hummer, an H1 running diesel, and burning diesel for its entire lifetime is greener than a Toyota Prius because of all of the pollution that's caused by the Toyota Prius.

The fact that your car, if you've got one of these electric cars, you know, God bless you, that those things are so cool. I would love to have one. But don't let it get stuck in your head that somehow it's green because it is not. It doesn't just have to do with the production of electricity.

In Mass, we've totally gotten rid of these coal power plants. Our biggest nuclear plant down on the Cape has been shut down in May 2019. I was going to say last year because I'm not sure 2020 actually happened.

Jim Polito: [00:05:48] Yeah. we skipped it. It's like the 13th floor in a hotel. Yeah. No, go ahead. Yeah, we've got to think about nuclear and we've got to think about all these other things.

Craig Peterson: [00:05:57] Yes. Yes. You know what the biggest problem, if you ask me, with nuclear is that we are using standards at the nuclear regulatory commission that were established in the early fifties. They don't take into account these six-generation nuclear plants.

Right now, extremely safe nuclear plants are on the drawing board and are being tested. That you could stick one right in your hometown. You have your own nuclear plant. The things buried underground. There's basically no moving parts other than, a couple. If it was to have a massive failure there'd be no leak of any nuclear material. That little plant, you can get them that'll produce one megawatt all the way on up from there.

We can have them all over the place. We don't have the nuclear waste problem. It's using very low radioactive materials. In fact, it can take some of these radioactive materials from these old plants that we have from Pilgrim, et cetera and reuse them.

The result would be something that even lower nuclear problems. So, uh, it's crazy. We're not thinking.

Jim Polito: [00:07:07] Yeah, no that's because Bruce Springsteen in the no nukes concert back in the late seventies, you know, kind of solidified it all. You got to hate nuclear power yet when Kathy and I flew from Milan to Paris over the Alps. I looked down and saw two separate nuclear power plants, and France gets the majority of its electricity from nuclear power. By the way, they're not doing it really with the sixth generation nuclear power plants. Um, they still have older power plants and it works.

We're talking with Craig Peterson our tech talk guru. Great guy.

Craig, I think you made the point, I think they have a lot of thinking to do in a lot of these places.

I want to talk about Apple already working on 6g. Now, first of all, I got a 5g phone over the holidays and 5g availability it's not as available as one would think and we're already talking about 6G.

Craig Peterson: [00:08:05] Yeah. Yeah. 5G unless you're carriers T-Mobile, 5g is unavailable throughout most of the United States.

Now we won't have time to get all the technical issues and I'll probably get into it a little bit this weekend as well on my show.

Apple has decided they've had it with these third-party vendors. They've had it. I'm talking about the chip manufacturer. So for instance, when Apple came out with its iPhone and its iPad, it was using chips, and today chips completely designed by Apple. There's some licensed technology in there. No doubt.

Apple is ditching Intel for all of its computers. It's already selling computers, if you buy a new Mac book air, or a Mac mini, or some of these others, very shortly including a small Mac book pro, it no longer has that Intel chip in it.

Well, they want to get rid of Qualcomm chips that are in the phones because they don't meet their specs. If you're using 5g on your new iPhone 12. You'll notice your battery looks like it has a leak. It uses so much electricity just to do this 5g because of the way 5g works, but more particularly because of the way Qualcomm makes that little modem chip that's inside the phone.

So Apple has said, okay, we're already making the main CPUs for the computers let's get busy let's make our own ship sets for cellular data. I'll let you in on a secret. Apple is really moving towards having these chips in every device they sell. So if you get an iPad, you get a laptop, et cetera, you're going to be connecting to the 6G probably some 5G's as well, initially to this new 6G network.

Apple wants to be an absolute leader there. Let me tell you, they will be. They've done some amazing things and they're not stuck with the silicone they designed 10 years ago like Qualcomm is. They're starting from scratch and they can do it.

Jim Polito: [00:10:09] Yeah. Well, that's interesting. Cause I'd like to see that and if Apple does it fine. I am on the Verizon network and I've just found that there's no big deal here with me other than it not being all that available. I don't notice any difference between the 5g and the 4g LTE, I just, I don't.

Craig Peterson: [00:10:31] Well, many carriers are kind of spoofing it a little bit. They're calling a more advanced version of 4g, 5g. Ajit Pai who was the Trump administration guy over there at the FCC was starting to come down on these guys.

The whole Biden switch up here has made it so that they're just letting it run wild right now. So, 5g isn't 5g isn't 5g and it's just not generally available, particularly not available on the Verizon network.

Jim Polito: [00:11:01] Craig, this is great as usual. How do people get in touch with you?

Well, if you go to Craig peterson.com, you're going to find all kinds of stuff right there. We have courses that we have started sending out little training every week.

We got bigger pieces of training coming up to keep you up-to-date on security. Step-by-step what you should do. Right? I've got 50 different special reports that we're going to be sending out. You can only get it, if you go to Craig peterson.com. Slash subscribe, sign up there. I'll send you a few of them, right out of the shoot to get you started.

Craig Peterson: [00:11:38] Then every week I'm going to be sending you more and we have deeper courses and deeper dives and webinars. I really want everybody to understand what you have to do to stay safe. Particularly our small businesses, our elderly, everybody out there.

Jim Polito: [00:11:53] Again, Craig peterson.com. That's great, Craig. Thank you so much. As usual and thank you for the extra time last week you gave us. We look forward to talking with you again soon.

Craig Peterson: [00:12:05] Take care, Jim. Thanks.

For those that have been following here on what is happening with my Improving Windows Security course, you'll be happy to know it is finished and we're putting it all up. We're making a little membership site for y'all where I'm going to be putting all of these different things, make it easy for you to digest it. That's the whole idea, right?

Little reminders and bookmarks, you can put into the video, text and screenshots, and everything.

So it is almost there. Keep an eye out on your emails, take care of everybody.

We'll be back on the Morrow.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. This morning I was on with Chris Ryan on NH Today. We talked about what is going on in Texas and Why? What did they do? What assumptions did they make? Where do they go from here? Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Justin McIssac: [00:00:00] Texas had a problem with this in 2011, just as the power company decided, it's going to cost too much to fix. With virtually no regulation, isn't that the issue, more than wind power itself,

Craig Peterson: [00:00:10] Almost a total grid collapsed down in Texas. I get into that. All of the statistics, the real numbers. Let's prove what's right here when we're talking about some of these renewable energy resources. I get into it all with Mr. Chris, Ryan, here we go.

Chris Ryan: [00:00:28] To be our new newscaster here on New Hampshire today. As we move to a little bit more serious topic, certainly for individuals involved down in Texas. I think this, obviously, when you see things happen in other States, you start to think about what could happen in my state. What could happen here in New Hampshire? The energy failure in regards to the grid in Texas is deeply concerning. What have you seen in regards to that and what do you attribute it to?

Craig Peterson: [00:00:53] Chris, we talked a few weeks ago here about what could happen with even something like a massive solar flare. That it really could knock out our electric grid. This would be a major problem, because even as we're burning oil You still need electricity in order to get that heat flowing through your house, whether it's via water or by air.

Obviously, what's happened in Texas is not terribly unique and it's a little different than the rest of the country.

First of all, Texas has its own power grid. Texas has been very independent over the years. They are not connected to anyone out in the country. So they're making their own, they're using natural gas, coal, wind, and nuclear power. In fact, they've had a very, strong move towards wind power because normally speaking wind is a very big deal.

I'm looking at the production numbers, for electricity here in megawatt-hours in Texas. Number one is natural gas, then coal, and then wind. The wind production went down from over 8,000 megawatt-hours down to 649. But so did everything else, Chris?

Justin McIssac: [00:02:07] So, Craig, isn't this more of an issue of Texas, the Texas power company, didn't get its turbines ready for winterization. Rather than wind power is an issue of wind. Turbines running the North sea. They're running in Antarctica, Canada, other places. Texas had a problem with this in 2011. The power company decided that it's going to cost too much to fix. So with virtually no regulation, isn't that the issue more than wind power itself.

Craig Peterson: [00:02:30] Yeah, it is. Everything went down. Natural gas went down from 43,000-megawatt hours down to 30. That's a pretty dramatic cut looking at it, lost almost a quarter of the natural gas. Nothing in Texas, including the wind power was ready for this type of cold weather.

They had valves that were exposed to the elements out there. They just had an almost perfect storm and it's worse than I think many people realize.

If the grid had gone offline and they were minutes away from losing the entire grid, it would have been months before everything could have been fixed.

Let me explain all of that. Bottom line is you need to reboot your electric grid in much the same way you might reboot your network at the office. You need to have extremely large generators of some type that can provide that frequency, that clock in order to get all of the other parts of the grid online.

Now there's other problems, too. You look at natural gas, which is again, number one in Texas for feeding homes and electrical generation with natural gas. If the supply starts to run out and dwindle, which it did because of frozen valves. Much the same problem that wind had. But because of frozen valves, the pressure continues to drop. Natural gas mixed with oxygen is very, very bad. The pressure drops to a certain point where all of a sudden there is more atmospheric pressure or almost an equal amount than there is in those pipelines. You're mixing air with gas. Now all of a sudden you have gas lines blowing up all over the place. In addition to having pipes freezing.

Yeah, Justin, you're right. This is a failure of wind, but it's also a failure of everything else. Even the nuclear power went from over 5,000 megawatt-hours down to 3,800. They just were not prepared for this at all.

By the skin of their teeth, they're going to manage to survive something where people could have been without power for months in a worst-case scenario.

Chris Ryan: [00:04:50] This has been a big discussion in regards to renewable energy versus fossil fuels and which works. A lot of folks have pointed to the wind issue, here where you're right they all lost considerable amounts down, 20 to 25% in natural gas, coal, and nuclear. But winds lost obviously the most during the height of the storm. So, in your view, is it more about renewable versus traditional fossil fuel type of an argument, or is it an infrastructure piece where they were not prepared for wind to be able to be functional in this environment. Where wind has proven to be functional in other cold-weather areas?

Craig Peterson: [00:05:31] Well, there's a, quite a few problems, frankly, with wind and the technology we're using. These windmills did not totally freeze up. The big problem was the same problem you have with icing on the wing of an airplane. These windmills are a lot like airplane wings. They rely on the surface sizes and shapes in order to be able to get the most effective bite, if you will, into that wind. So those surfaces got covered with ice.

Was that a problem that could be solved? Oh, you bet. Look at our airplanes. Even the small ones they have on the leading edge of the wings, little bladders, and those bladders in icing conditions swell up. They blow up and they go down, up and down, up and down so that they keep all of the ice off.

So, no question at all, this problem could have been solved before it even happened.

Wind, I kind of like. I'm not a big wind fan. There is so many problems long-term. They're expensive to maintain. There are people who've had to move out of the areas with windmills, because of the low-frequency vibration. It was driving them crazy. Then there's the bird kill.

There is a problem with everything, frankly, when you get right down to it from the natural gas on out.

They could have done something about it. They are probably going to doing something about it. Right now, here in New Hampshire, we have a, I think, a better system, but we're thinking about what is our problem?

The largest nuclear power reactor in New England provides us with 61% of our electrical grid generation power. Again, it is winterized. We have a lot of biomass for generating electricity here in New Hampshire. That's about 17% of New Hampshire's from renewable resources and we still have two of our three coal-fired plants operating here in New Hampshire.

So, add all of that up we are a little better off. We're also set up for winter. We do have, by the way, electricity from wind here. In fact, 2016 was the first time that we had more electricity in New Hampshire from the wind than from coal. It's something that can be managed. They just didn't bother managing it. Now they're talking about connecting to the rest of the grid in the United States for a couple of different reasons. It's probably a smart thing to do. Just like here in New Hampshire, we don't have our own grid. We have a grid that covers new England, so we can feed electricity back and forth.

Chris Ryan: [00:08:15] As always, I appreciate you joining us for the show.

Craig Peterson: [00:08:17] Thank you.

Chris Ryan: [00:08:18] All right. That is Craig Peterson. Joining us here on Hampshire today. I am Chris Ryan. You can hear tech talk with Craig on Saturdays and Sundays,

Craig Peterson: [00:08:25] by the way. We're almost finished up with those cyber health assessment worksheets for everybody. I'm going to record a little bit of audio to kind of explain them. Anybody that asked for the cyber health assessment stuff of that will be coming your way in a couple of weeks.

And as I've mentioned before, I think I'm expecting next week-ish, to be able to have out that Improving Windows Security course.

All right. Everybody, take care.

We'll be back tomorrow.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

We lost a Radio Icon this week and he had a big impact on me, I have a short tribute to him but it was also another busy week on the technology front. We are going to get into the differences between Backups, Disaster Recovery and Business Continuity, often these get tossed around in discussions as one in the same - they are not. Then we will discuss Bitcoin and it metoric rise and why that happened. Next we'll discuss Apple and Google and why Google is trying to play hardball but may end up getting burned. Then we are headed to Space and NASA space travel and a discussion on Rocket Fuel for future missions to Mars and there is even more, so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Breached water plant employees used the same TeamViewer password and no firewall

As Prices Surge, Bitcoin Now Reportedly Consumes More Electricity Than Argentina, Netherlands, And UAE

Google flags its iOS apps as “out of date” after two months of neglect

White House hastens to address global chip shortage

Report: NASA’s only realistic path for humans on Mars is nuclear propulsion

A Windows Defender vulnerability lurked undetected for 12 years

Hackers try to contaminate Florida town's water supply through computer breach

Barcode Scanner app on Google Play infects 10 million users with one update

SolarWinds Attack Reinforces Importance of Principle of Least Privilege

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] I've got to say the big story of the week is this breached water plant and how it really affects all of us. Not just because our water could be poisoned by a hacker, but it gives us a bit of a lesson on what we should be doing and what we did.

Hi everybody. Craig Peterson here.

There are many things that we did over this lockdown. Things we did. In fact, the lockdown itself to try and help stop not just the spread of the virus, but remember it was a two week lockdown just so that we did not overwhelm our hospitals. Who could disagree with that, right?

We all stayed home for two weeks that makes sure that we're flattening the curve, that we're not going to have a lot of. People in hospitals. Unfortunately other people who couldn't make it into the hospitals that needed it. That two week locked down to flatten the curve has turned into what? Now, almost a year later we are still seeing these lockdowns. These lockdowns have caused havoc.

We've talked about many of them. Of course, you hear them all the time on radio. Everything from suicides of our children. Through our parents dying in these homes and without the comfort of their family and without human touch for almost a year. It's just so, so, so sad to see.

Now I'm not going to get into the political sides of this and what should we have done? What shouldn't have we'd had done. I've got my opinions on some of this. What I want to talk about is what we did with our jobs? What we did with our businesses? I think we did some terrible things there, too.

What I'm talking about is we need to stay home, but we have certain businesses that need to stay open. Now, frankly, every business needs to stay open. It's a business because it's fulfilling a need, right? It is so basic. It's hard to think that people don't understand this, but obviously they don't.

We shut down businesses. Businesses that will never, ever come back. People's lives destroyed. People whose entire savings, their entire retirement plan, everything was based on the business. That's where their money was. The people working there were counting on having that money to pay the rent, to pay the electric bills and other utilities. To pay for all of the things in life that we need to pay.

It's one thing to have credit card bills that you can't pay, because they're not a whole lot they can do about unsecured debt. They can certainly harass you. When it comes to things like your home or whatever it is, you're renting, whether you own it or not, how can you make those payments if you don't have money coming in. The money that the government is issued has just been a mere pittance. I get it.

In some cases, people had just incredible amounts of money compared to what they were normally making with unemployment, with the federal subsidies, et cetera. That didn't last. PPP money, this payroll protection money, lasted for about six weeks for those businesses that could get it. Those that qualified.

My business didn't qualify for PPP money. Not because it's too big, but because it's too small. Most of what happens in my business is done by my family members. I've got myself, I've got my wife, of course, you've probably seen Karen mentioned in some of my emails that go out.

I've got my eldest son involved. He loves security. He's great at it. He's been working with me now for more than 10- 15 years on this. I've got one of my daughters working with this on me. So it's primarily a family business. We've got contractors who will do different things for us. We have a lot of suppliers and we have to pay those bills, but no payroll per se. You know what? That's a lot of businesses. The number of businesses that were in the same boat as me is huge. That's how things get started in this country.

All of these companies that could have started. The companies that had started that had entered into lease agreements. That had started to provide services for their customers. Whether it be B2B like mine, business to business or business to consumer they were all stifled.

What have we done to ourselves? Really? What have we done? The virus itself is obviously pretty nasty and can be lethal in a lot of cases. It has been. Now we found out that people like governor Cuomo apparently just cooked the books. Cooked the books, something awful.

We went home, we started working from home. Our businesses said, what can we do? We had people getting very, very busy trying to figure it out. There are a lot of little remote programs that you can use in one of those is Team Viewer.

Now there's nothing particularly wrong with Team Viewer. I'm not fond of the idea of things like Team Viewer, remote desktop, and others, but sometimes it is the best solution for a particular problem. Team viewer in this case was used by a small government agency. Think about what would have happened. You had to shut down, you still had to do work. What did you do as a business?

You probably got something like Team Viewer, one of these login, remote login programs. Maybe you set up remote desktop so people could get in remotely. Maybe you set up a VPN because that's going to solve all of your problems. Which of course it causes almost as many as it solves, but most people don't realize this.

That's the case here. We're talking about a small town, 15,000 people, called Oldsmar. I don't think it's because they're a small town. I think this problem happened because they did what most of us did. We were not ready for a shutdown.

As businesses, we wern't ready for shutdown. In fact, the year before they did the shutdown, they had this massive pandemic planning session about eight months before. They all agreed that a shut down was the wrong thing to do in the case of a worldwide pandemic. They also redefined pandemic. I think maybe getting the angle I'm coming from here. Right.

They decided no, we're not going to do that. They did not plan for pandemic. In fact, they didn't plan for a lockdown.

Obviously, you don't. Well, I don't know, maybe you do plan for a pandemic. If you're coming up with a virus you're going to release, but they were not planning for a pandemic. They were not planning for the lockdown and neither were businesses. Most businesses, government agencies and NGOs, had no plans in place, even for disaster recovery or business continuity. You may or may not be aware of this, but there's different levels.

You've got basic backups and you should be doing backups because hard disks fail. One of my customers CEO thought that hard desks never fail. She was really upset when a disc crashed that we'd been warning her about, because we keep an eye on things called smart stats on the disks. We said you've got this disc it's going to fail. You probably need to fix things because you're not in a raid array. You've fallen out of that already. Things didn't just get worse.

You have a backup. You hope that Mac going to work. If you get ransomware and I got to tell you, nowadays, the answer's no. There's two sides to ransomware, but we've talked about that before. I'm not going to get into it right now.

You've got the backup mainly in case the disk fails, or you accidentally delete a whole bunch of files and you want to get them back.

The next step that you have is disaster recovery. You have a disaster, like there's massive snow storm that caused a water main to break in the roof. All of your computer equipment is covered with water and none of it will work anymore. In a disaster recovery situation, you now take your backups and you get new machines and you load it all on and hopefully your backups are remote. They weren't damaged by the water. Unfortunately, most businesses, again, not thinking this through just hoping, crossing their fingers, that they're not going to be one of those 50% of businesses that is out of business because of a disaster. Actually is closer to 75%.

It depends on whose numbers you're looking at. So they're hoping. No, no, I'm going to be part of your disaster. Disaster recovery. Is just think of that, of a snow storm and the roof collapses of a fire and the computers have burn. Can you get your business back in business?

Then there is business continuity. That's a whole other level of planning and business continuity is where you say, Hey, I need to make sure my business continues to conduct business. If you have a hundred, 200, 300 employees, You're much better off being able to let's say the computer room burns down as an example that or that roof caves in because of the snow and you've lost those computers. You're much better to be back in business in four hours or less. We've had business continuity solutions where we had equipment on site in a different part of the building. If there was a problem in one part of the building, we could fail over to the other part. Now this is an awfully big building and we had fiber links between them, but they could be back in business in less than 10 minutes. It's just that quick. That is business continuity, right?

If you are a public company or you are a division of a public company by law, you cannot be out of business for more than four hours. Now, that's just public companies. By the way, those same rules are in place for doctor's offices, for hospitals, any medical personnel you have to be able to get at the patient's records within four hours.

How many of us are ready for that? Then along comes a shutdown, remote workers. We're going to get into this a little more detail. We're going to talk about these SCADA systems, supervisory control and data acquisition. What does that mean? And why is this a problem for all of our infrastructure. How did this guy poison or at least try to a town of 15,000.

You're listening to Craig Peterson.

What happened to that town, a Florida city of about 15,000, Northwest of Tampa when hackers got into their water supply and hacked up the amount of lye by a factor of 100.

Hello everybody. Craig Peterson here.

This whole concept of having a backup versus some sort of a disaster recovery plan versus business continuity is something most businesses really don't pay enough attention to. Now, we've got another problem which is really a business continuity problem. What do you do when your employees can't get into the business?

When we've set up business continuity for businesses, in the past, what we've done is I mentioned earlier this data center where we duplicated part of it in another part of this massive building. If there was a problem with something, could just be some of the core switches go down or something, we could automatically fail over and continue running within 10 minutes. That's one way to do it.

But how about if the rest of the building went away? How about if your main servers okay, but the roof collapses or there's some sort of a fire? What happens if your employees can't come into work because there's a lockdown? There are so many reasons you need to have business continuity in place.

We didn't have it right. Not we, as in me, but so many people, so many companies didn't have that. That's what happened in Oldsmar, Florida. They have a water plant. Of course, they have all of the normal things any city of 15,000 people would have. They had in their water treatment plant these devices that are called SCADA devices that are used to control valves. These valves are exactly what you think in a water plant. They're used to control the mixture of various chemicals to divert water around the plant. The source of the water, the type of filter switched over to a new filter so that older filter can be replaced. In many cases, the main filtration is just done through sand and it has to backwash every once in a while. This is all controlled by computer, nowadays.

They were running a Windows seven machine. No I know you're saying, well, I've got Windows seven I'm okay. The problem is Windows seven is no longer supported by Microsoft, unless you're paying them ungodly amounts of money. I'm talking about $50,000 a year per machine sort of money. It's just crazy amounts of money. Most companies don't have that, right? I don't know anybody outside the federal government that actually has that. There's probably some, but they will not release it to the general public.

Sometimes they'll release a few little security patches because something was just so apparent that they had overlooked. But most of the time, no. Most of the time these security patches just aren't available for older versions of Windows. So they had a Windows machine that was controlling this network with all of these valves on it.

They had that machine hooked up to something called Team Viewer. The idea behind Team Viewer is, Oh, this is really handy. I can put Team Viewer on our control machine. Then I can have my employees be at home and then use that control machine remotely over Team Viewer .

That's what Team Viewer is designed for, isn't it? Well, as it turns out, they were using Team Viewer throughout the water district. That became a bit of a problem because they did not have proper firewalls to protect it. And they were all sharing the same password.

Interesting advisory that came out about this particular problem from the Commonwealth of Massachusetts, if you can believe it. This cybersecurity advisory for public water suppliers is talking about how water suppliers can guard against cyber attacks on water supplies. It goes through a lot of these basic things that I've talked about. They should listen to my show every once in a while, right? Or attended the briefings that I had put on for the FBI's InfraGuard program. It would be pretty simple for them. The state of Florida came out with some guidelines, et cetera, after the fact. As did Massachusetts.

They were running Windows seven. They were remotely accessing plant controls. The computer had no firewall installed. Well, that's what they're saying. In reality, Windows ships with a firewall installed, but that doesn't mean it's going to do any good. I talk a lot about that in some of my courses, but the computer was visible to the internet apparently. Okay.

They all shared the same password. What do you want to bet it was a bad password and employees could remotely log into city systems using this Team Viewer application. It was really that simple.

Now this actor's here apparently is more than one and they are unidentified. So we don't have a whole lot of information on it, but I did get a notice. It's called a pin, which is a notice from the FBI it's labeled green, which means I can share it with everybody. It's saying that they obtained unauthorized access to it.

Now, here's the most important part. These cyber actors likely access the system by exploiting cybersecurity weaknesses, including poor password security and outdated Windows seven operating system to compromise the software used to remotely manage water treatment.

The actor also likely use the desktop sharing software Team Viewer to gain on authorized access to the system. We've seen this, not only with Team Viewer, we have seen this with remote desktop and many other systems that people have been using to allow their workers to get in remotely. All of this because of the lockdown, people working at home. All of this should have been handled properly by having a business continuity plan in place. It's really that simple.

Now the putting the plan together, isn't that simple, frankly, but we've got to think about what happens here.

No. I also think about this particular hack and who did it. Well, it could have been the Russians, right? It could have been the Chinese or the North Koreans. We know Vietnam has gotten into the game lately. It could have been any of those guys.

But do you know who the most likely people are to do this sort of thing? It's somebody who works for the company or in this case, very likely that it's a disgruntled employee. They all shared the same password. They use Team Viewer. I said, I'm not blaming Team Viewer here, but this is not good. This is really bad. This is not just something that could happen at a water plant where they're moving the amount of lye from a hundred parts per million to 11,000 parts per million. They're using it in drinking water to change the Alkalinity, the acidity of the water.

I don't know, I don't know. We've got to do something about this. I'm going to have some training on this, what you should be doing for remote workers.

If you're interested, let me know I'm going to plan some, but I'm not going to do it until I hear from you to know it's worth my time to put it all together. Email me M E at Craig Peterson. Let me know that you'd like to know about remote workers or maybe this whole business continuity idea. Again, email me me@craigpeterson.com. Let me know.

Hey, you'll find a whole lot of stuff. If you go to Craig peterson.com and it's all good information that you need. Make sure you sign up for my newsletter right there. Craig peterson.com

Hey, we can't go without talking about Bitcoin. It has surged surged surged. It may go up, it may go down. I'm not somebody who advises on investments, but we're going to talk about what it is and why people are mining it.

Hello everybody. Craig Peterson here.

Well, we have a real big thing to talk about when it comes to Bitcoin, but first I have to take a minute and honor a man who has inspired me in broadcasting for decades. A man who has changed the whole face of radio. AM radio was pretty much dead. Then he started his national show. Of course, I'm talking about Rush Limbaugh.

Whether you agree with him politically, and I think most of you guys probably do. We all have our differences, or not, he is a man that deserves great respect. He changed the face of American politics. He literally single handedly saved AM radio. He created this whole concept of a national syndicated talk radio show, and it has helped to educate millions of people.

I started listening to him back in the late eighties, quite a while ago. I was just amazed with him and the way he did it. One of the things that inspired me about it is he took callers, but they weren't the guest, he was the guest. They were asking him questions. That is so topsy turvy from how, even today, most radio shows are.

People would call him up and they would ask him questions and he'd be able to answer them. He also asked them some questions, obviously, in order to figure things out, he also was not afraid to take opposing calls. He would look for those and he would put those to the top of the queue. He would take those callers that disagreed with him before he took callers that agreed with him, his ditto heads, as they like to call themselves.

When I heard this week that he had passed, I knew it was coming, but it hit me hard. It hit me really hard. He's not that much older than me. Although I remain in really good health, knock on wood here I am just flabbergasted. I don't have words for his passing. So it would not be right for me not to have mentioned a man who inspired me, who educated me and played a role in my life, such that when he passed, I was just gobsmacked.

It's absolutely a sad, sad time. I really wish my best, obviously to his wife. I guess Catherine is his fourth wife, so I'm guessing he didn't have the best home life out there. Things obviously didn't do well on that front. I think he's a little bold and brash and maybe that's part of it.

But my memories of him being down in Cambridge, Mass. I was working as a contractor for about a year and a half at the Open Software Foundation. I was working on the operating system and that was rewriting the TCPIP stack. If you know what that is, it's the basis of the internet today and the Open Software Foundation provided its code to pretty much everybody out there. That's how I can say with high degree of confidence, the code I wrote is still in use today to help run the internet. I was working down there as a contractor for about 18 months. I also put in the i18n, the internationalization code into many of the Unix libraries and at lunchtime. I had a small radio with me and I would go out and walk around for lunchtime and listen to Rush Limbaugh while I was out walking around. He had been quite the companion for me, gave me a lot of things to think about, disagree with him on, and agree with him on. Conversations were spurred with other people.I've come to realize, I mentioned this to my wife, as well, this week after he passed that as someone who's on radio, call us personalities or whatever you might want to call us. But as someone on radio, this is a very personal medium. I've come to realize that Rush taught me something. I realized it when he passed, I've never met the man. I have a photograph of him signed by him around here, somewhere. He taught me something else and that is, I never met the guy, yet I felt attachment to him that I had never felt really to anybody else.

Certainly I've never felt that way about a movie actor that died. I've never felt that way about an author whose books I loved. I've missed some of them, some of these books where there a series of books and the author died. You could tell mid book that the voice changed and it was being written at that point by someone else. I was just disappointed by that. I didn't feel that sense of loss that I felt this week. It helps me to realize. How important it is for me with you guys. Without you guys listening, we wouldn't have a radio station. Without you guys buying from the advertisers it couldn't afford to, to pay for the electricity, and all of the people that are involved. It's the listeners. Right.

I have an obligation to you to present the information that you need in a way that you can understand and hopefully in a way that you can use it, right?

What good is a show like this? If I'm giving you stuff that there's nothing you can do about it? You notice, I always try and do that, but that's the way Rush was too. Rush wouldn't just sit there and complain. Rush would talk about the facts, what's happening, where he thinks it should go, and what we should be doing. What we should be doing as a nation and what we should be doing as individuals. To me, that was very inspirational. Frankly, that's how I've patterned this show. I've had this radio show for over 20 years and I've patterned it that way, where I try and help. If you've ever sent me an email you get a personal reply from me because I am here to help. And I felt that way about Rush.

I've sent him emails. I'd never gotten responses, right? But you, I feel this attachment to these people. That's part of the beauty of these smaller radio stations, where there are people, we are local, we do care about you. These advertisers tend to be local as well. Certainly local businesses advertise locally, and we really have an obligation to you, to every one of you. So I appreciate you. I really do. I really to want to help. I am beginning to understand some of the responsibility that I have it isn't just to help you understand technology a little better to keep your machines clean, to stop your businesses from being stolen from, by hackers or by Snowfall that might bring your building down.

It is to help you as best I can, as often as I can. So that's why I do it. That's why I do these courses, the newsletters, everything else. Rest in peace, Rush. We're going to miss you.

Visit online as well, craig peterson.com and sign up for my newsletter so I can help you a little more.

Well, we really, are going to talk about Bitcoin in this segment. So stick around. I had to talk about Rush this last time around. Bitcoin, the prices are surging. People are mining. What does that mean? And why are they using more electricity than the country of Argentina?

Craig Peterson here.

Bitcoin has been around for a while. I don't think anybody out there has not heard about Bitcoin. It is a power in and of itself. We don't know who actually came up with this whole concept. There's a concept behind Bitcoin called blockchain technology. Blockchain technology is based on the concept of ledgers. Where you have ledgers, just like a bank ledger that keeps track of every transaction. There are hundreds of thousands. Just so many ledgers in the world. In order to verify transactions, half of those ledger entries have to agree. So it's pretty basic on that level.

What is the Bitcoin itself, which sits on top of this blockchain technology? Well, if you want to look at it, simply take a look at prime numbers.

Hopefully you can name the first five prime numbers, right? What do we got? One, three, five, seven, 11. There you go those are the first five prime numbers and a prime numbers a number that is only divisible by itself and one, which is why one is a prime number.

We use prime numbers a lot nowadays. Most of the encryption that you're using is based on prime numbers. If you go to a secure website, you're using something called SSL, which is the secure socket layer and that's what shows up in your browser, in that URL line as a little lock, if you see that lock that you have effectively a VPN, a virtual private network between your browser and that remote site.

Guess what? You already have a VPN, right? Why use one of these VPNs that spies on you?

That is encrypted data and it's very difficult to encrypt in between. How does it do that? It's using something known as public key technology, the RSA algorithm. We're not going to go any further down that, but basically it's allows someone to have a public key and use that public key to encrypt a message. then you, the person who's receiving the message whose private key was used to do the encryption can decrypt it using their private key. So the public key side, the private keys side, it allows the encryption from end to end. That's what the SSL is all about.

Well, when we're talking about Bitcoin, we are talking about something that goes and uses some of the similar technology. What it's doing is using these prime numbers. That's what the RSA algorithm is using this encryption algorithm, using these very large, very complicated prime numbers because you get past 11 and lets see 12. That's not a prime, right? Uh, because it's divisible by. Two and six and three and four, and then let's see 13. Okay. That's a prime 14, no 15, no 16. No. It gets more difficult.

I remember way back when, writing a little program that just found prime numbers and it looked for prime numbers and the easiest way to do it was I would start, first of all, you take a number, divide it into. There's no reason to go any higher than that when you're trying to figure out if it's prime or not. Then I would start looking at some of the base numbers to try and figure it out. Of course, real mathematicians were able to figure out better ways to find primes.

Well, when we're talking about Bitcoin and some of these other cryptocurrencies, they are also using these very large prime numbers, just like you're being used for this public key encryption. They also have some other parameters around some of these prime numbers.

To have a Bitcoin is to have this digital number that represents a unique prime number. If you want to mine, what you're doing is you are trying to find a prime number that no one has ever found before, just to oversimplify things a little bit. You find that prime number and Tada now you have a Bitcoin. Sounds easy enough, sounds quick enough. It is not easy and it is not quick.

It's not just the based on the prime number algorithm, but we're keeping this simple here. We have found millions now of these Bitcoins. I should look that up and find out exactly how many, but there are many Bitcoins. The whole algorithm, the whole system is set up to do some restrictions here, there's only a certain number of these Bitcoins that will ever be mined.

It's estimated that something like 20% of the Bitcoins that were found have been lost because the encryption was used to keep the keys. People forgot it.

You probably heard about this guy that has a quarter of a billion dollars in Bitcoin in this wallet. He only gets eight tries before it auto destructs. He hasn't found them yet. There's a quarter of a billion dollars that's unreachable, but that's what we're talking about here.

Bitcoin mining. In this day and age, Bitcoin mining is so hard and it takes so much computing power that it is using a couple of things. First of all, the thing that bothers me the most is it's using up these GPU's these graphical processing units, because GPU, which we typically use for graphics processing are set up so that we have are hundreds, thousands of processes that can be happening on that card simultaneously, various small little tiny processes that can be set up to somewhat be optimized for Bitcoin mining or mining, any of these other cryptocurrencies.

Then the people who really want to make money on mining these cryptocurrencies have machines that are special machines. They are designed specifically to mine, one type of coin, one of these crypto coins. We're talking about Bitcoin. There are machines that are designed to mine bitcoins, go to E-bay and look for Bitcoin miner. They used to have themon Amazon. I haven't checked in a while, but you'll find them in both places. At least you used to be able to, you can certainly still find the money bank. You'll find some that are old, that are used and some brand new ones.

Well, it is expensive to mine them. One of my sons and I, we decided years ago to try and do a little mining. We probably should have tried harder but we gave up. It was a, who knows what's going to happen with Bitcoin.

There are so many cryptocurrencies and today there are people introducing new cryptocurrencies all of the time. I avoid those like the plague because you never know what's going to happen.

Bitcoin is definitely the 800 pound gorilla out there. We were able to mine I guess my son said he mind a couple of other little currencies they're worth a penny or two, not a very big deal.

We have now so many people in China that were doing Bitcoin mining China could not produce enough electricity to mine the Bitcoins. China went around and shut down anybody that was mining Bitcoin. We have something called the Cambridge Bitcoin electricity consumption index. This is an index designed to figure out how much electricity is being used in order to mine Bitcoin.

This is, of course, over in England, the university of Cambridge the judge business school. I'm looking at a graphic right now that they have, and this is showing the electricity and Bitcoin mining. They actually have all of the data for downloading, if you ever wanted to do some serious analysis. It's showing there was hardly anything, if anything, back in 2016. The summer 2017, when it started to jump up and that's, of course, when the price of Bitcoin started to go up.

Why? Well, mainly because of ransomware. People having to pay ransomware and buy Bitcoin in order to pay that ransom.

In terawatts. Now we are showing at about, okay, this is Wednesday, February 10, 2021 288 terawatts of electricity on that one day. Isn't that something. The amount of electricity that's being used has been surging because, of course, the price of Bitcoin has been going up. Just been going up in crazy, crazy rates. The amount of mining going on has doubled, almost doubled since October last year. We're talking about using more electricity than the entire country of Argentina, the Netherlands and the United Arab Emirates. It is absolutely amazing, amazing how much we're using. People are alarmed by this. Countries are having major problems in trying to figure this out.

What else is funny about it? They talk about Bitcoin being one of these so-called green technologies. Well, it turns out that Bitcoin because of the electricity that it's using for people to mine now has a carbon footprint comparable to the entire country of New Zealand. It's producing about 37 mega tons of carbon dioxide per year. I think that's funny, frankly, because they call it green. Right?

It's like green cars that are electric. Well, guess what? They, aren't green in so many ways. They're cool as heck don't get me wrong, but don't think they're green because they're not. A lot of reasons for that. I've talked about it many times in the past, on my radio show.

If you go to my website, you can just look that up and you can find out why, and I've got hard numbers there, anything else?

All right, everybody make sure you visit me online. We have started some new stuff. If you are a frequent reader of my, now Sunday newsletter, which has my show notes. You are getting also one or two other newsletters during the week just short trainings.

I'm trying to help you out, but if you're not opening that newsletter, if you don't download the images. That's how I tell that you opened it, then you're not going to get all of the supplemental material, including some audio programming that you can't get anywhere else. So make sure you go to Craig peterson.com and sign up for the newsletter. Open the silly thing.

So you get all of this free training and more. Craig peterson.com.

Apple has been really busy trying to make sure we know who's using our data and what they're using it for turns out Google's not too happy about that. You'll be surprised what they did this week.

Hi everybody. Thanks for joining me.

I've talked here about how Apple is really taking some major steps up in trying to defend our privacy. Apple does not make money off of our data. They don't sell it. They don't compile it and then sell it, Google however, is trying to be the repository of all of our information. So much for the don't be evil thing. Right?

Well, Apple's got these almost like nutritional labels. You remember when the CDC or it wasn't the CDC, it was some federal agency, I can't even remember forced food companies to put labels on the packaging, telling us about calories, fat, various other types of things. You could make a bit of an informed decision by looking at that.

Obviously there's other stuff that I don't know what this word means. I don't know what that is. What's red dye, number two, all of those types of things, but at least it brings it to your mind. You can also see how many servings there are. It'll say this muffin is a 500 servings and only a calorie a piece, right.

The reality is that box is really meant to be two or three or four servings, including that Coke that you might be drinking. I am more of a Pepsi man, but I haven't drank either in years now, frankly.

Well, Apple is trying to do kind of the same thing. They've got millions of apps up on their app store. In the app store, of course you can not only find the apps, but you can download them. You can buy them depending on what the app is. Most of these apps that are free, are really not free right? We've talked about that before. I don't know that we need to get into in a lot of detail, but it goes back to that saying of if it's free, then your, probably the product.

That's been very true. Apple and Google both have caught a lot of companies. Who've been trying to steal our information successfully in some cases. Obviously, that's a bad thing particularly when you don't know about it.

So these labels that Apple is having app developers put on their apps have got a whole bunch of people upset, Google ran full page ads in newspapers, complaining about it and how it's going to hurt small business.

Reality is, it is going to hurt some small businesses that do advertising. That's very, very narrow. It's going to hurt me if I'm doing that type of advertising no question about it. I don't do that. But one of these days, I hope to be able to do it.

What it is doing now, is stopping companies like Facebook. Facebook has always been doing tracking, not just when you're running their app. Facebook has been getting information from other websites from web pages like mine, for instance, I've got a Facebook pixel on my website so I know if you came from Facebook, what you're interested in and in what you're doing so that I can present information to you based on your interest.

I'm doing now for the very first time, this week, a similar thing. With my newsletter. If you have, for instance said that you're interested in my improving windows security course, the newsletter, isn't going to bother you about that anymore because I have this little signature at the bottom with, here's a few things that I could do for you. If you want a little extra help. Some of it's paid, some of it's free, obviously, but. I think it's annoying personally to keep getting the same message every week. I've put into my email program, some conditional stuff so that if you've asked for the improving windows security course, I'm not going to bother you about that anymore. By the way, no, the course hasn't started yet. It's a labor of love. What can I say?

There are a lot of different types of tracking that are done and not all of them are bad. For instance, I just gave you an example of something that I've started doing, and I am doing some tracking in order to do that because I don't want to annoy you. I want to give you the information you need when you need it, right? Bottom line. It's like, I've always said, if I'm interested in buying a Ford F150, then I don't mind seeing ads for it, but if I'm not interested in buying a pickup truck or a Silverado, why would I want to see a GM ad when I'm going to get a Ford, right? It's really that simple.

Google, as I mentioned, has been complaining. They've done the full-page ads. They've complained to Congress critters they've spent so much money. Lobbying, it's a real problem and a difficult solution to it. If you want to get rid of lobbyists, obviously the bottom line is you have to get rid of the money going to, and coming from Washington DC. If they don't have control over our money. If they don't have control over our lives. Then the lobbyists aren't going to be going there.

I don't care which side of the aisle you are on, or if you're a right in that middle of the aisle. Lobbyists do not represent our interests as a nation. That's the bottom line.

Google's down there spending money saying, Oh, you're going to hurt the small businesses. When in reality, the biggest target that's going to be hurt by Apple cracking down on people taking our information without letting us know is Google.

It's going to be a problem for Google, so how to get around it. One of the things that Apple has for its apps that are on your iPhone and on also your tablets is a tracker. When was the last time that app was updated. Of course, when the app gets updated, Apple has a look at it and tries to see if there's anything malicious going on.

Now it's impossible to catch everything. Some of the stuff is very well, obfuscated. I can't blame Apple or Google for letting some of this malware through. But the bottom line is they want to know. When did you update it? What's going on?

Google apparently flagged its own Apple apps. The apps designed for iOS.

Think about the Google apps, obviously. There's the Google app itself. There are Google maps. Apps can be very useful, including Waze. I was so upset when they bought Waze, but that goes into the anti-trust stuff that is going on right now in Congress.

But I was looking at the phone and looking at the app and they were flagged as out of date. It had been two months since Google updated iOS apps. It has been updating its apps in the Android space, but not the iOS apps. The theory is that Google has not been doing updates on its Apple apps because of this new privacy labeling that Apple's come up with.

You see back in early January, Google could have said, we haven't been updating our apps because of the lockdown. The engineers are busy trying to handle this and that. We just had the holidays and I would have accepted that you would have accepted that. Well, that was what now six weeks ago. Google has, every year around the holidays a code freeze, which means no one can make any changes, that is done with right now. The company Google should have released two new versions, particularly since they come out with the new versions for the Android operating system, Gmail, Google maps, Google search, Chrome, drive, photos, keep and duo have all been frozen since Apple launched these privacy requirements.

What do we think is going on? Well, it looks like frankly, Google just doesn't want us to know what data they're trying to get at. What they're doing? What they're selling? What they're tracking, the inter app tracking.

The Google's been doing as well as Facebook and many of these others. What's the easiest way to not have to worry about that don't have a new release so that you don't have to abide by the new terms from Apple, which include, Hey, what information are you gathering? How are you gathering? What are you doing with my personal information?

It looks like Google took the easy way out again. It's a phenomenal. I'm looking right now, Gmail and it has not been updated on iOS since December 1st. The Android version of Gmail has had four updates since then. That's a pretty big deal, frankly.

Apple's definitely got people's attention. The app developers attention. I am glad they're doing it as a user. I'm not so sure. I'm glad if I decide to try and do targeted marketing through some of these online pay-per-click and some of these other ways of reaching people. But you guys, already how I feel about you and I'm going to be giving you lots of good information.

I some of you guys become my clients cause your businesses and you need that little extra help for your poor overworked IT people internally.

Lots of what's going on with Google. We'll see when they do come up with the next update, but it's a real problem.

Hey, if you want to get my weekly email where I have my show notes.

Now these show notes are what I use here on the show. They're also what I send to people like Matt Gagnon who I am on with every Wednesday morning. That's what he picks from. That's what all of these stations pick from, my show notes. The only way you can get them and get information about what's going on in the world and things you have to do right now, is by signing up for my email.

Craig peterson.com.

Boy, I love space stuff. I have for years. I was so excited to play an extremely minor role, but to get involved with the NASA space shuttle program. Let's talk a little bit about what's next up for it.

I remember that day. I can't remember what day of the week it was, but that day when we landed on the moon watching it live. It was just mind blowing. Of course the newspaper, first time I had ever seen a color cover on a newspaper and it was a picture of our astronauts there on the moon. It was just so incredible.

Of course, you're listening to Craig Peterson.

NASA has been trying to get back to the moon for a long time. We haven't been funding them. Priorities have changed. A lot of people say why don't we spend the money domestically rather than on the space program?

The space program has provided us all kinds of benefits over the years. It's benefited mankind, not just by giving us things like Tang, for instance. It's given us all kinds of technology and science that we would never have had any other way. I'm looking right now at a report that was put together by AIESEC, which is the international space exploration coordination group. It just a top level executive summary. Numerous cases of societal benefits, new knowledge and technology from space exploration, things like solar panels came from the space program, implantable heart monitors. Cancer therapy, lightweight materials, water purification systems, improved computing systems, a global search and rescue systems, course rockets as well. There's so much more, things we just weren't expecting. Thin materials, power generation, energy storage, recycling and waste management, advanced robotics, health and medicine, transportation, engineering, computing, and software. Not just the $800 hammers. Okay.

Culture and inspiration. As you can tell I find this very, very inspiring. We've got all kinds of things that we are using just day-to-day that we don't even think about it. As the space scientists, engineers overcome obstacles, in some cases, we never even realized were there and I think that's another phenomenal thing.

Well, right now, what we're doing is having private organizations competing to send our missions up. For many years now, since the space shuttle program was ended and it lasted far longer than they expected it to. But now that the space shuttle program has been over.

We've mostly been using Russian rockets to get our astronauts into space and also to get things to things like the international space station. What are we going to end up doing in the future?

We already know who was it, Bob and somebody, right? A couple of astronauts. The went up on the Elon Musk rocket, and docked with the space station.

It was again, one of the most amazing things ever. I sat there glued watching it on the computer. It was just, wow. To see that.

We're looking at going to Mars. Now, we're looking at exploring some of Mars is moons more than we have in the past, doing all kinds of things that are just going to make a huge, huge difference to humanity.

It's been quite a while since that Apollo program of 50 years ago took humans to the moon and they were using chemical propulsion. What that means that you had rocket engines burn liquid oxygen and hydrogen in a combustion chamber. Nowadays we're playing around with hydrogen peroxide in order to get that oxygen.

They use have their advantages and that gives NASA the ability to start and stop an engine really quickly. Back in the sixties, this was the most mature technology for space travel. We'd been using rockets. They were really piloted in world war two. It made a lot of sense back then.

However, now we've got some other problems we've gone to prepare for. We're going to be sending four or more astronauts to Mars. We want to colonize Mars, but relying on chemical propulsion to get beyond the moon, bottom line, it just won't cut it. The main reason is the amount of rocket fuel. Most of that rocket fuel is going to be consumed getting out of the atmosphere.

It's crazy how much we're talking about $2 billion for a flight of one of these huge rockets. These block one B configurations, NASA's SLS or space launch system rocket, is going to be able to carry 105 tons to lower earth orbit. That's a lot of money. They're not going to be able to get that many of them up there. That only takes it to lower earth orbit.

Now, of course, the idea is to do what in fact, the Apollo mission had looked at, which is get the fuel up to orbit and then have a rocket up there that maybe is assembled an orbit and is refueled in orbit. Then it goes to the moon. That was actually the plan NASA was originally going to pursue.

We're looking at that now, when we're talking about going to Mars while we're talking about going even further out there. What can we do? Just for the fuel, by the way $20 billion just to get the fuel up. That's just absolutely crazy.

There were some tests that were done, some studies that were done on behalf of NASA for a mission to Mars in 2039. So this one's quite a ways out. Of course, Elon Musk wants to do it even sooner. He is relying on these chemical rockets. By the way, to get back home from Mars, he's relying on being able to make rocket fuel right there on the surface of Mars and then charge up the rocket engines in the launch vehicle and then launch back up to get back to earth.

It's going to be really, really interesting to see what we end up doing. They are looking at a nuclear propulsion system. It's going to be interesting. NASA has had budget for this. They got $110 million for nuclear, thermal propulsion development. We know a lot about nuclear fuel nuclear propulsion. We'll see what happens.

This star ship concept that space X is building to send humans to Mars using chemical propellant. They're countering the costs involved with the chemical propellant by having this low cost reusable launch system. We just saw one blow up here a few weeks ago, but that's okay there was no intent of having astronauts sitting on that candle. That was just a test system. We've seen him repeatedly now land successfully.

All of those boosters and it's amazing what's been happening now. They're not the only ones. We've got a number of other companies that are working on these types of systems. Space X ultimately we're talking about pushing the boundaries of reuse and heavy lift rockets to extreme limits which is exactly what space X is trying to do. They're looking for some other answers.

Hey, make sure you sign up Craig peterson.com. I want you to make sure you have all of the latest materials.

Craig peterson.com.

We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by police officer. Here we go.

If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information that I have available my podcasts and a little articles that we've written, and you'll also have the opportunity to subscribe to my newsletter.

I just want to get the message out is my bottom line.

We have these home cameras that we have welcomed into our homes. And one of the ones has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with ring that gives them alive. Real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming peoples ring, doorbell cameras.

Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened in a number of occasions and far more than we like to talk about is that there are.

The bad guys or people who don't like their neighbor and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting prank led police to shoot dead 28 year old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently they believe the report was an act of swatting where.

Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of this emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

The color also said he had a handgun at had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

When Mr. Finch came to the door, they said one round was released by the officers after the 28 year old failed to comply with verbal orders to keep his hands up. Why would he, what did he done wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead. Injured North taken hostage. His family told local media, he was not involved in online.

Gaming. Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the, that hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells have allowed hackers to steal pet network passwords, et cetera.

In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

But anyway our businesses and government got broken thats what we're going to talk about right now.

Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them was we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering client the compromised programs.

Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached to, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWinds hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of economic incentives.

The market rewards, quick development of products. It rewards new features. It rewards spine on customers, end users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

It doesn't reward reliability past a bare minimum, and it does not reward resilient at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWinds right now, but it's going to be happening with other places out there.

We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cyber security, and infrastructure.

Agency. SISA the department of Homeland security, the US department of state, the department of justice, the national nuclear security administration, the US department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody use a password manager and I will have a course on that this year.

Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an it security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email me@craigpeterson.com and let me know, be glad to send you stuff.

ME@Craig peterson.com.

Take care guys.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. He wanted me on to discuss the problems that Massachusetts was having with the rollout of their Vaccine Scheduling website. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Dah, dah, dah, dah, dah. He had a special command appearance this morning to answer a major question that's been bothering people in Massachusetts. Their state just yesterday came out with a COVID vaccine registration site and a million people ages 65 and up became eligible that had not been eligible before.

Of course, it did not work. They were getting errors like bad gateway error or this application crashed. It's just incredible. Incredible. Talk a little bit about what should have happened and the ways to really think about putting together something for your business. Should you, should the state be developing these systems from scratch?

I give some alternatives here. You might know. I built one of the first large-scale websites in the world. The whole thing, including the data center for the silly thing, way back when. It was for Big yellow. I don't know if you remember that or not, which was the predecessor to Superpages. We were able to get it up and running in a matter of weeks from scratch, which was a database of every business in the entire region, multiple, multiple States. In fact, we ended up covering the entire United States before we even launched. We managed to get it finished at 2:00 AM. 9:00 AM they had a press conference down a New York City, and the site was released to the world and everything worked. It never crashed, which is absolutely amazing.

In fact, we ended up after 18 months deciding maybe we should start rebooting some of these servers because they've been online yeah. For a year and a half. Of course, I was not running windows. Right.

I have some credit here. I know what I'm talking about, kind of the bottom line. I think you might find this a little interesting if you're wondering about these government projects. Cause I also bring up Obamacare and what ended up happening with this $600 check that people were getting for being laid off over the whole lockdown thing.

So here we go with Mr. Jim Pollito.

Jim Polito: [00:02:27] Charlie. Baker's not having a great day. Didn't have a great day yesterday. The governor of Massachusetts because his computer system to register people to get the COVID vaccination crashed. It's been opened up to people 65 and older, and apparently, 1 million people to log on to set up appointments for the COVID-19 vaccine.

It just crashed. It crashed.

Joining us now to sort this all out is our good friend. Who's usually you're on Tuesday, but this is why he's such a great asset to the show tech talk guru Craig Peter song. Good morning, sir.

Craig Peterson: [00:03:06] Hey, good morning, Jim. Hey, not only was the site unavailable but if you called2-1-1, the vaccine hotline, it also failed, they couldn't transfer through. So, the frustration level was just out of this world.

Jim Polito: [00:03:22] It reminds me of the old days when you were calling and trying to get tickets to see the Rolling Stones when they went on sale and the systems would just crash to try to get through. I have advertisers who really attempt to crash their systems because I want to send them so many people for their system. That's a good thing. Like they say, Oh my God, all these callers from the Jim Pollito show were all of these people trying to log onto our website. What happens? Why does that happen?

Craig Peterson: [00:03:53] In one-word incompetence. We remember the rollout of course, of the Obamacare website. I said, Hey, listen, this is going to take about three years for them to get right, after what is already online. It took about three years for them to get right.

I have done some amazing things and seen some amazing things done when it comes to websites over the years. You just can't find competent people in some of these organizations, particularly some of the larger ones.

It is easy enough in this day and age. In fact, it's very easy in less than a week you could put together a website that is effectively crash-proof that will automatically scale itself up. The question about why does it crash, has to do with the components that they're using and the way they're spreading the load.

It's not as though all of a sudden yesterday a million more people were eligible for getting shots and they should've been concerned about this. There just weren't enough computing resources behind all of this is kind of the bottom line.

Jim Polito: [00:05:01] It's like you got a bag that's rated for 10 pounds and you're trying to put 20 pounds in it.

Craig Peterson: [00:05:07] Think about having a Toyota Prius and all of a sudden you want to get a hundred people into it. You should have known that since there were a hundred people that were going to line up, a Prius just wouldn't have done it. You needed a couple of buses. That's why it goes back to incompetence.

Let's not even look all the way back through the Obamacare website. Let's look at what happened with unemployment, where people were getting these $600 checks, right? We have the exact same problem.

All 50 States had it, but there's an even simpler solution besides designing this properly using sites like Amazon web services or Microsoft Azure, which both have systems to make sure that you can handle the load. It's something called queuing.

They had something that many States adopted for their unemployment site. Very easy to add. I mean very easy to add. I looked into it because of problems I saw States having thought, well, maybe I could put a product together for them. I found Florida was using something and it took them all of about half an hour to put it in place.

What this queuing system does is you go to the website and the queuing system says all the backend systems are pretty busy right now. So I'm just going to give you basically a line in number and when the backend systems are ready for you, then little it'll all be well and good.

Now, I've got to give them a little bit of leeway here, Jim, because I'm not sure what's actually behind all of this. Are they actually trying to tie into all of these pharmacy's computer systems from that front-end website, ultimately, because there are so many pieces?

Jim Polito: [00:06:59] No.

Craig Peterson: [00:07:00] Okay.

Jim Polito: [00:07:01] No, I don't think so.

It's the super sites that they've set up, but I'm fairly sure that's how it is. Frankly, I have been suggesting, why don't we just put this in the hands of the people who've been doing it all along, and then it's their problem. Say to CVS, Walgreens, Stop and Shop, Wegmans, Price Chopper, all these places where you can get vaccines. Send them to them, pay them and say here.

Craig Peterson: [00:07:32] Yeah, exactly. Why do you build a website in the first place to take appointments? There are dozens of calendaring and scheduling websites out there.

You talk about these events, getting rolling stone tickets. Well, there's a website called that is designed to do exactly what the state is trying to do right now. The cost of this is like next to nothing to use it. I've used it before for events. We use it for the FBI InfraGard events. It's so simple. Yet, no, we've got a bureaucracy. We have people who are here on phony-baloney jobs, as Mel Brooks would say. They need to design it.

No. All we're talking about is some basic calendaring functions. To your point, why set up these sites? Walmart has pharmacies, and so do most grocery stores, as you've just mentioned. Let them do it. Maybe have one of these things like the event or one of the other scheduling pieces of software or websites do the scheduling. Just let them do it.

We don't need a whole new bureaucracy. They can't get it done.

Jim Polito: [00:08:45] Yeah. See, here's the thing though that's different with Charlie Baker versus when Deval Patrick was governor in Massachusetts. As you alluded to the Obamacare exchanges and that site kept crashing, but not just from demand, it just wasn't designed well. It was a mess but different Deval Patrick just made excuses about it.

Charlie Baker went out. I think Wednesday and said, yep, it's all ready to go. Which knowing what I know about Charlie Baker when he ran Harvard Pilgrim health care, he went to the person said, is this ready to go? Are you sure? Okay. He went out there.

That's why, yesterday, he actually used the word I'm pissed, which I think is better for him to say and he will say I own it. I'm pissed. It's gotta be fixed. I would not, Charlie Bakers' a really nice guy. Some people say too nice. I wouldn't want to be the person who told him, it's ready to go. It's all set.

Craig Peterson: [00:09:45] The other side of this is the testing involved because again, you can put these systems under load test and you should, and in the regular non-governmental space, we do put them under load tests and make sure they're going to work.

Obviously, none of this happened. I can see why you're saying his hair is on fire and he's really upset, but so were all these other people.

The design of the site was you went to the site, you filled out a PDF form online, and this form went on for pages and like you, so you're filling it all out, which I don't get either, right? Government paperwork and all of a sudden the site crashes. It does not keep any of the information that you just spent all your time filling out. Pages and pages form so that the design of it, even from that standpoint was ludicrous. What there is going to be a problem. The person's internet could go down, their computer could crash. Your website might not be able to handle the load. Then what are you going to do? Because now everybody has to start from scratch again.

Jim Polito: [00:10:58] My goodness this is why you're the great resource. Hopefully, the state was listening and Rhode Island is listening to, and they'll call in and they'll say we got to get this Craig Peterson guy.

Craig, by the way, while you're here, how would people get you through a system that would not crash?

Craig Peterson: [00:11:16] Well, you can always just email me me@craigpeterson.com and I have all of my podcasts and everything up at my website, which of course is also. craigpeterson.com. If you have any questions or anything me@craigpeterson.com and I'm always happy to answer pretty much anything that comes my way.

Jim Polito: [00:11:36] There you go.

Craig. Thank you very much. I appreciate it.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. We began talking about the shortages of Semiconductor Chips, what caused it, what is being done about it and why did it happen. Then we got into Space and fueling rockets for trips to Mars. Of course, we had to get into the hack of the water plant in FL and what happened. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Matt Gagnon: [00:00:00] From what I understand about this story, they were using an unsupported version of windows with no firewall and everybody had the same password. Am I right about that?

Craig Peterson: [00:00:10] Good morning, Craig Peterson here had a great little chat with Mr. Matt Gagnon, as we discuss some of our favorite things, including NASA. We talked a little bit about their new rocket propulsion using nuclear fuel.

We also talked about our breached water plant, which is a bit of an issue, and why our car manufacturers are cutting back on manufacturing by a factor of two-thirds. So here we go with Mr. Gagnon.

Matt Gagnon: [00:00:41] We're talking to Craig Peterson, our tech guru. He joins us at this time every Wednesday to talk about the world of technology, Craig, how are you, sir?

Craig Peterson: [00:00:48] Hey, good morning doing well. I actually saw the sun this morning.

Matt Gagnon: [00:00:52] You saw the sun. Amazing. Yes, it does exist. It is out there. Although I heard it's going to be a pretty cold night tonight, so we shall see. Craig, I was reading something this morning. It was in the press Herald and it was talking about how everybody is in fact able to buy toilet paper.

Today and all those global shortages of the commodities that we saw early in the pandemic are mostly solved. There is still a pretty huge need in some areas. Some places where you need to get some stuff that you can't really quite get. One of those is interestingly enough, computer chips.

This is something that we're seeing, in a lot of different industries. I think I remember you saying to me a few weeks ago that this might be one of the ultimate culprits for why the PS5's aren't coming out like gangbusters, and some other things as well. Tell me a little bit about the shortage itself and what the white house wants to do about it.

Craig Peterson: [00:01:39] This is really interesting, especially that last part, what the White House wants to do about it. Because of the lockdown, we had companies trying to guess what are we going to need inventory-wise? The manufacturers of these various types of chips based it on the orders that were coming in. They ordered these things months in advance. That is part of the problem we're having with the Sony PlayStations and others.

We've got our major manufacturers of cars, like Ford, for example, that has cut back from running three shifts to one shift because they cannot get the chips that they need inside of our cars.

Our cars today are not just computers on wheels. They are dozens of computers on wheels, each car. It's been a real problem. That inventory is catching up. It will catch up pretty quickly. We can manufacture these things. It's not like the problem we had with hard drives being manufactured in Indonesia, where they had massive flooding and it took all of these hard drive facilities offline.

This was just because people didn't order at the right time and the supply chain got messed up. Now, what the White House is going to do about it? They're going to talk about it. They are going to identify potential choke points in the supply chain, according to the White House press secretary.

Bottom line there's nothing for them to do. There's nothing that they're going to do. This problem will fix itself. This is going to lead to shortages in cars and basically anything with a chip in it.

Matt Gagnon: [00:03:16] Talking to Craig Peterson, our tech guru. He joins us now as he always does on Wednesdays, of course, can hear him on Saturdays in some more depth and detail on these various stations for his show which you can hear at 1:00 PM.

Now Craig, my favorite topic to chat about with you is always something space-related and there's. Always some news and tidbits to sink your teeth into, as it relates to, to, to those types of stories. Elon Musk wants to go to Mars and developments and engines, all kinds of stuff.

I did, however, read with great interest this tidbit that you had from ARS Technica about NASA thinking that the only realistic plan for humans actually on Mars is with nuclear propulsion. Talk to me about this a little bit.

Craig Peterson: [00:03:54] Yeah, isn't this kind of neat. I just love to think about this, because it's the future.

Elon Musk and NASA both are using chemically fueled rockets, these are the rockets that we've had in use now for a very long time.

Matt Gagnon: [00:04:09] Rocket fuel, right? Yeah.

Craig Peterson: [00:04:11] Yeah, exactly good old chemical rocket fuel. The problem that we have is the cost involved. You have to use tons, thousands of tons of rocket fuel in order to just get pounds of payload up into space. The biggest problem is of course from the ground until orbit. So NASA originally planned our first moon launch to have a base that was circling the globe. This was back in the sixties and it was basically going to be a refueling stop. The astronauts would go up there the fuel would already be ready. It would be loaded into the rocket. That's going to take them to the moon.

There's still a whole lot of work on that concept when it comes to these Mars flights. When you get right down to it, carrying a hundred tons to low earth orbit. In other words, just to go around the earth, not to go to the moon or Mars, a hundred tons, which is a lot of payload. That's going to cost about two billion dollars using these chemical rockets.

So NASA back in the sixties was also looking at nuclear propulsion. They've been getting a budget for nuclear propulsion now for a long time. It looks like we're talking about a dramatically different way of doing it instead of having to have 4,000 tons of propellant to get up there. We're just talking about a few hundred when we're talking about nuclear.

This is very fascinating. We've been using nuclear in space. The Russians have as well to run some of their satellites. In many cases, it's really worried us. The biggest reason NASA has not been a big proponent of this is the risk involved. If you've got all of that nuclear propellant on those rockets, you could have an accident, just like we've seen with some of Elon Musk's rockets, as he's trying to figure this whole thing out, and that could spread nuclear waste. There's concerns involved. Right now it looks like the only long-term solution we have for getting lots of colonists and supplies to Mars and beyond.

Matt Gagnon: [00:06:26] Craig Peterson our tech guru joins us at this time every Wednesday to go over what's happening in the world of technology. Final question for you, Craig, there's some utility stuff in the news, obviously with all the power outages going on down South. There was also this story of the Florida water treatment facility that had a disastrous computer system failure. Apparently, from what I understand about this story, they were using an unsupported version of Windows with no firewall and everybody had the same password. Am I right about this? What could possibly go wrong?

Craig Peterson: [00:06:57] This is what we're seeing as a result of the lockdown again. People working from home. That happened in this small Florida community, about 15,000 people, right outside of Tampa. They, of course, had the lockdown, but people still want water coming out of their taps.

So what do you do?

We're going to put Team viewer on all of our computers so that people can get in from home. What happened was, as you said, they were running Windows seven and you can't get patches for it. They didn't have it configured properly. This is by the way, why I'm doing this Improving Windows Security course in a couple of weeks.

They moved quickly to get people to the point where they're able to work from home, sounds familiar. Because of that, they didn't lock things down. They didn't do it properly.

The sharing of the password thing is just absolutely unreal. Are you kidding me?

Inside many of manufacturing plants, and pretty much all of our critical infrastructure are what are called SCADA systems. These are systems that open and close valves and control the physical properties of the plant.

Somebody got on to this computer that was used to control the lye mix and increase the amount of lye being added to the water by 100 fold. Just incredible. It could have caused very severe sickness to anyone that used the water. Maybe even death.

Now the good news is some people who work from home are actually working. The guy that was monitoring this computer. Saw wait, somebody else is on this computer and changed screens and increased the lye by a factor of a hundred. He immediately turned it down. Nobody was injured by this, but it does bring up again this problem.

We moved very quickly to work from home. We didn't think it through. We didn't put proper safeguards in place. If they listened to WGAN, Matt, they would know what to do. The simple stuff here. Sometimes that's the stuff we overlook the most.

Matt Gagnon: [00:09:10] Indeed. Craig Peterson, our tech guru joins us this time every Wednesday. Thanks a lot, Craig. Appreciate it. We will talk to you again next week, sir.

Craig Peterson: [00:09:16] All right. I'll be back Saturday, of course, at 1:00 PM.

Matt Gagnon: [00:09:19] Indeed. All right.

Craig Peterson: [00:09:21] Hey everybody. I figured out what had been going on. I just noticed maybe a week or so ago, the feed at Apple podcasts was not working. I was trying to figure out why hasn't it updated since November?

It was like November 2nd or something. I couldn't figure out why. I ran my podcast feed through a bunch of these online feed aggregator checkers, cause it was working everywhere else.

I had to do the process of elimination and figured out the problem was Apple didn't like the dimensions of my artwork. They apparently are very picky. They want your artwork to be square somewhere between 1500 by 1500 pixels and 3000 by 3000 pixels.

I made a little piece of artwork. I'm not terribly happy with it, but whatever that was 2000 by 2000 pixels and lo and behold, the next day. It shows up. So I think that's pretty darn cool.

My podcast download numbers went way up. So welcome back all you guys. Sorry about that. I didn't even notice that it wasn't working. I'm sure some of you guys complained. I might've missed that email,

Take care, everybody. I'll be back this weekend.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a couple of interesting topics. First was the hack of the FL water plant and how that happened and why. Then we got into NASA and how it plans on propelling the spacecraft to Mars. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] The Russians have been using them for years in space. We've been concerned about it because of what happens when that Russian bird comes down. There's issues right with all of that. These nuclear propulsion plants really tend to make a whole lot of sense.

Hi, everybody. Craig Peterson here. I was on this morning with Mr. Jim Pollito. We talked about the NASA space program and I love this thing. You probably know listening for a while that I actually helped just a teeny tiny bit with NASAs program called the space shuttle. That was really cool. I did some engineering way back when. Also, we talked about this breached water plant, what happened there? Who did it? Why and how can we avoid this sort of thing happening in our lives? So here we go with Jim.

Jim Polito: [00:00:52] Hey, what's team viewer. Apparently, I guess it's something like Zoom. Guess what? Hackers busted in through it. Almost polluted water in Florida. This is the stuff we were worried about. Joining us now to discuss all of this, our good friend and a very popular guest tech talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:20] Hey, good morning. Yeah, this is a bad thing, Jim. You're right about that.

Jim Polito: [00:01:25] Apparently in Florida hackers broke into the computer system and just a smaller system. A smaller water system in Florida provides water to about 15,000 people, but they were able to, I think, turn up the chlorine in it so that the water coming out of your tap would basically be Clorox. Contaminating the water with the very agent we use to purify it. It seems that as usual, they're not listening to Craig Peterson down there, the people running this water system.

Craig Peterson: [00:02:00] Absolutely. You know that I set up the FBI InfraGard webinar program and I ran it. I conducted the webinars for a couple of years and the whole idea behind InfraGuard is that it's infrastructure protection, right? It's everything from heaven forbid lawyers get hacked, all the way to these types of systems.

In this particular case, we're talking about a technology called SCADA. These are devices that are everywhere. These are devices that control valves, they'll open and close valves.

On the electric grid, for instance, right now in Texas, right? They were foolish enough to go to wind power and so all of a sudden now all of the windmills are frozen solid.

I saw, by the way, a video of this drone that applies D-ICER to these windmills. Anyhow, they're frozen just like an airplane. If it's flying through the sky and it gets ice up and they don't have anything to stop that ice. Of course, in commercial planes the wings will no longer have lift. The same sort of problems happening with those windmills down there, Florida.

What happened, now is they have to shut down parts of the grid. Throughout Texas, Oklahoma, Arkansas, they are now shutting down parts of the grid doing rolling blackouts. That's all controlled by these SCADA systems.

Now you mentioned something called team viewer.

Jim Polito: [00:03:29] Yeah.

Craig Peterson: [00:03:30] Team viewer is something that people have been using as part of this lockdown thing. We're not going in to work. So how do I get to the computers at work? Well pulling all of this together, this water plant, as well as every other water plant in the country uses these computer-controlled mixing valves and on-off valves. They are controlled by computers there in the plant.

In this case, the computer they figured man, we still got to have people monitor this right. We don't want our water to go offline. We don't want the quality to go down. So some guys sitting there at home and are connected to the computer in the plant using team viewer.

Now there's a few problems here, obviously. Team viewer isn't necessarily the best thing in the world. There are much more secure ways of even setting up Team Viewer than what they did.

They were running windows seven cause that's the controller for all of these mixing valves there in the plant. Windows seven, of course, was an unsupported operating system. No firewall.

They shared the same team viewer password amongst everybody there in the plant.

They released something called sodium hydroxide. That's lye. That's the stuff that'll burn your hands off. Whoever got on to it, increased the amount of lye in the water by a factor of 100. It could have caused sickness or death. At least the guy who's working from home, who's using team viewer saw, wait a minute, somebody just changed the lye setting to death. I'm going to turn it back down again.

Jim Polito: [00:05:17] Okay. We're talking with our tech talk guru, Craig Peterson, just about the things that we do worry about which is, World War Three will not be fought with conventional weapons. It'll be fought over the internet. We see this in a hack into a water plant in Florida. Craig, do we have any idea where this hack came from? Is it as they say the usual suspects?

Almost certainly Russians. No, we don't know yet, but I thought I'd throw that in there.

In fact, there's an advisory out right now from the state of Massachusetts about this. They're talking about what the problem was. We know how they got in. We aren't sure who it was yet.

The old-style hack. This is not using what we call a zero-day vulnerability or anything else. The people who set it up were, I would say stupid, but I'm not going to say that. I would have said stupid if I had said something. They should know better if they had attended any of the briefings that I conducted for the FBI InfraGard program, they would have known that. We don't know it could be anyone, anywhere. It could be another employee at the water plant that just wanted to prove his point that the system's insecure.

Yeah, not good. Not good. This is not good. Just fix it, so we won't worry anymore.

Craig, to go to Mars help me out with this, cause you are a smart person. We need nuclear power. Wait a minute. Wait a minute. So you're saying that it's going to be like the starship enterprise. You're going to have, dilithium crystals in there. Scotty's got, "I can't give it no more, Captain". Are we really talking about a nuclear-powered spaceship to go to Mars?

Craig Peterson: [00:07:09] Obviously we've got Elon Musk. He's the guy out front and he has the standard chemical rockets. If you've ever watched the movie Snowpiercer or the TV show, Snowpiercer, which causes global catastrophe. Okay.

Jim Polito: [00:07:24] Yes, I saw the movie. I don't watch the series. The movie was just not all that great. I love SciFi, but I don't watch the series, even though one of my favorites, Jennifer Conley is in it. No, I don't watch it.

Craig Peterson: [00:07:37] Of course, completely fiction the way they've done it.

Elon Musk is looking at using chemical rockets. NASA is looking at, in fact they're planning on using chemical rockets. In both cases, NASA is can use them to go to the moon. It gets very expensive.

Our first moonshot, you and I both remember it in the sixties, I can remember watching it live on TV. It was just mind-blowing. The very first time I had ever seen a color newspaper was the day after. They had a color picture of our men there on the moon. It was just such a great time.

We were planning on something different. We were planning on having boosters to get the main rocket supplies up into orbit around the earth. Then filling those up with fuel, having fuel there, and then using the rocket that we assemble in orbit around the earth to then go to the moon.

There are plans to potentially do that for Mars missions and other deep space-type missions. The biggest problem we have is getting out of earth's gravity. When you get right down to it, NASA is expecting its big space launch system to cost around $2 billion for a flight to go on up, to get the fuel up, and other things. It's just very expensive.

Some technology that we looked at in the sixties was nuclear technology where we have a small nuclear power plant. We know how to make these things. The Russians have been using them for years in space. We've been concerned about it because of what happens when that Russian bird comes down. There's issues right with all of that.

These nuclear propulsion plants really tend to make a whole lot of sense. We'll cut way back on the cost because the amount of nuclear material we have to haul in space is a tiny fraction of the chemical propellant we'd have to haul in space. NASA is looking at it again. Congress has been funding, nuclear, propulsion experiments, and stuff now for many years.

We'll see where it all goes. It's a different way to do it. We've got a lot of proposals on the table still. I think the first missions to Mars are going to be chemical rockets because Musk is doing a pretty darn good job with that. Our missions to the moon in the near future will be chemical.

We're going to end up with a space station in earth orbit that is going to essentially be a fueling station for our continued missions to Mars, even to the moon. Mars's moons and maybe some deeper space.

Jim Polito: [00:10:23] That's amazing. We've got to make sure that the death star. We don't have an exhaust portal on the vessel two meters wide that you could get, some type of a weapon into, and then the whole thing is gone.

We just gotta make sure we

Craig Peterson: [00:10:39] we found out about that though. Do you remember? What we found out is the guy that designed it, built that flaw into it, on purpose

Jim Polito: [00:10:46] He did that was great.

Craig Peterson: [00:10:48] Rebels could. Yeah. Was that a little backstory explanation?

Jim Polito: [00:10:53] I love that. That was Rogue One. I love that. Love it. Our good friend who knows everything.

Craig Peterson, tech talk guru. Craig, how do folks get in touch with you?

Craig Peterson: [00:11:03] I am starting up here this next week, in fact, this week, this morning, you'll get an email from you, a little bit of training a whole bunch of training programs just to help you guys understand this, but you've got to be on my email list and that means go to Craig peterson.com slash subscribe. You can subscribe right there. You can listen to my podcasts.

Of course, they're my articles. You can even get the weekly email, similar to what I sent to Jim, my show notes every week, as well on Sunday mornings, I've actually pulled it together. Jim, just Craig peterson.com.

Jim Polito: [00:11:37] Nice, nice. That's right. Get everybody informed, Craig. Thank you very much. We'll talk with you next week.

Craig Peterson: [00:11:44] Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about some of the misguided legislation being pushed by Amy Klobacher regarding big tech with her regulatory solution to anti-trust. Then we got into Facial recognition and expose.ai. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] We would be tossed back to 1800 with no electricity, no computers for months and years in some locations.

Hey, another week, another dollar. Hi everybody. We got in this morning to this problem Ford, another car manufacturers' are having it isn't just these video game manufacturers. Like I talked about over the weekend on my show and we also got into the security of our infrastructure and all of that with Mr. Chris, Ryan. So here we go.

Chris Ryan: [00:00:35] I mean, he is Craig Peterson, Craig, how are you?

Craig Peterson: [00:00:38] Hey, good morning. Doing well,

Chris Ryan: [00:00:40] A couple of things we want to get to with you today. I want to talk a little about our grid and the security of our grid and how technology plays into that because this has been one of my major concerns for a period of time. Whether it's the breach, a breach water plant which took place recently in Florida had their computer system potentially exposed to a hazardous breach last week. Whether it's our overall technology infrastructure, our lights, our emergency response, our electricity all tied into the grid. What is your general sense about the safety of our infrastructure?

Craig Peterson: [00:01:19] Well, I'm not very happy with it, frankly, all the way across the board. You might know that I ran for the FBI, their InfraGard program which is for protecting our infrastructure, I ran webinars for about two years. Trying to help businesses, government and organizations, NGOs, et cetera understand the risks involved here.

One of the really big risks we're seeing with some of this infrastructure, including in this case as water plant is that we have these computer-controlled systems are called SCADA systems and they are designed to allow you in the plant to open this valve close, close that valve, spin up the centrifuge, which is how we destroyed a third of the Iranian centrifuges.

These type's of systems security is an afterthought. They've been in now for a few decades. You look at this breached water plant down in Florida, that you mentioned, this was a simple mistake that should never have been made.

What they did is they were using team viewer, because everybody has to work from home now and they did not set everything up properly at all. Nobody really thought it through. There were no security experts because security expertise is a very narrow field that really a regular IT person is not qualified for. They set it up incorrectly. They shared passwords. A third party got onto the control computer, which had again the screen-sharing software so you can work from home and increased the amount of lye going into the system by about a hundredfold.

Okay. Now the good news is. Somebody else at home who was working at the plant, who was also attached to this computer, noticed the change before anyone got sick or died because of what happened to the water treatment plant.

These sorts of things are happening, not just in a smaller city, like what happened in this particular case but our electrical grid. There's a lot of studies out that show that's why we lost power back in 2004 in the Northeast. It was a probe that was being conducted by most likely the Russians. It could have been the Chinese. Chris the bottom line is I'm not happy with the state of cybersecurity with our infrastructure.

We could be in serious trouble. I don't know how far I should go with this, but we look at our electrical grid. We have these super transformers. If you will. There's only about half a dozen of them countrywide. We lose one of those. They have to be manufactured from scratch. Right? Overseas. We can't even make them here anymore.

If we had an electromagnetic pulse or even a massive solar storm like we have had before. We had the Carrington event, about 150 years ago, we would be tossed back to 1800 with no electricity, no computers for months and years in some locations.

Chris Ryan: [00:04:26] Yeah. If you'd asked me five or 10 years ago, what our biggest security concerns were. One would be a pandemic. The second would be our overall grid and technology infrastructure. It was getting built up without the appropriate safeguards. We continue to pile dollars, upon dollars, upon dollars into traditional defense mechanisms and that infrastructure, i.e., aircraft carriers, planes, missile defense, and those types of things. The proportional threat from cyber and from a pandemic has been significant for a period of time and really goes on. We continue to focus dollar after dollar after dollar on a traditional military defense. It's really maddening.

Craig Peterson: [00:05:14] Yeah, I have to agree with that. It's very upsetting. This is not that hard to do but our businesses aren't doing it.

Of course, the government isn't doing it. It has to be done because if you get right down to it, it's simple enough to bring our economy to its knees. If they're able to infiltrate. Look at what happened with Rep. Swallwell out of California. Look at what happened with both of their senior senators. Over the years, in all three cases, they had Chinese plants that were either their body people working with them, maybe doing some other things with the body. Now they had access to information.

What would happen if somebody was involved with, let's say wall street, maybe they had access to some of these things inside of wall street. They got in just like with, this water plant, and they had access to a computer they were able to take it over, bring down just destroy wall street, even if they only knock it out for a few days, it would be a huge impact on our economy.

Chris Ryan: [00:06:20] One more thing, before we let you go. The Biden administration has pledged to take immediate action to address a global shortage of semiconductors that has forced the closure of several us car plants. This is due to a global chip shortage.

They have said, they're gonna take immediate action, but they have made it unclear as to what exactly that action is, other than engaging in conversation about what to do, in regards to the shortage of chips as a result of the amount of demand that there has been for the for these chips.

We are now behind. In being able to address it and be able to provide the chips for these car makers. What's your take on that and how does it get solved?

It goes back to China. It's being reported that as a result of the US sanctions on China that we are unable to get the chips. That kind of also, brokes the question of, do we want to have Chinese chips in all of our vehicles and electronics, et cetera.

Craig Peterson: [00:07:17] That's a big deal. We've got all of the major manufacturers, Ford cutting production at Chicago's facility from three shifts down to one. Cause they can't get the chips. They, of course, blaming it on the Trump administration, makes sense, right. It's the predecessor's fault. Always is. Doesn't matter who you are.

In reality, what happened here is there was a complete miscomputation of our need for chips based on the lockdown worldwide so they stopped making them. There are of course companies out of China that is no longer able to provide chips. To answer your last question there, Chris, I'm really concerned about these Chinese chips.

We had chips delivered to us, for our fighters, for our jet fighters, and we were able to get into those have closer look at the very last minute we found the Chinese had modified those chips they had sold to us.

They looked on the outside like they were the right chip. They ran like they were the right chip, but they had certain vulnerabilities built into them by the Chinese. Our jet fighters.

They're doing this all of the time. Supermicro. Huge, huge story here about a year and a half ago, where one of the major manufacturers of server components found a little chip about the size of a grain of rice hidden on the motherboard. Apparently, it was calling home to China to get instructions and it was installed in thousands of places, including Google, including Apple, many, many regular businesses.

We can't trust it. We need to get more and manufacturing here in the US. I have to say the highest-end manufacturing of chips, Chris is done here in the US and not in China.

We've got a bit of a leg up here going forward.

Chris Ryan: [00:09:13] Well, Craig I always appreciate you joining us here in New Hampshire today.

We encourage folks to check out Craig Peterson's at tech talk, which is on Saturdays from 1130 to noon. Also airs on Sundays as well from 1230 to one. Craig, appreciate your time.

Craig Peterson: [00:09:27] Take care

Who knew that putting together one of these courses would be as much work as it's turned out to be. Oh my gosh, but we want it to be right. We want it to just work for you guys. So we've got 22, short modules as part of this Improving Windows Security course. They are now. All edited already.

We are putting it up on a new site that has some learning management software on it. So it makes it easier for you guys. Then over time, we're going to be continuing to release training, kind of long-tail ones. This one's Improving Windows Security, which covers a lot of topics. But. , do things on VPNs, and other stuff.

We'll see how this all goes. Man. Is this take taking just so much longer than I had hoped initially I'd hoped it would be out in January and now we're looking to hopefully have it out by the beginning of March. Oh my gosh. Once we got it set up the first time, you know how that goes, it's going to be easier for a future time.

So all you guys who asked to be notified about when the Improving Windows Security course is coming out, keep your ears to the ground because it is coming.

I haven't given up and I think it's really quite a good little course.

All right. Take care, everybody. We'll be back tomorrow.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

It is another busy week on the technology front. We discuss Facial Recognition and some of the problems with false positives and how you can see if your pictures are included in some of these websites. Then we discuss Amy Klobachers anti-trust legislation against big tech. Then we get into Info-Sec Careers and something you might want to know before considering a career move. We also discuss Zero-Trust and why you must be thinking about that if you want to be secure and there is even more, so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Strengthening Zero Trust Architecture

Here’s a Way to Learn if Facial Recognition Systems Used Your Photos

Scalpers aren’t the main reason you can’t find a new console

What I Wish I Knew at the Start of My InfoSec Career

Chrome users have faced 3 security concerns over the past 24 hours

Klobuchar targets Big Tech with biggest antitrust overhaul in 45 years

I Fought the Dark Web and the Dark Web Won

How the United States Lost to Hackers

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to talk a little bit about scalpers. They're not the main reason you can't find a new gaming console. I've had a number of people ask about getting into information security. I'm going to give you some tips about what I wish I knew at the start of my career.

Hello everybody. Craig Peterson here.

I want to start out by talking a little bit about the facial recognition systems and there are a lot of concerns, legitimately, a lot of concerns because now our privacy is getting worse and worse.

I'm going to talk next week a little bit, at least it's on my schedule about what's happening with GPS and pros and cons to it because there are some very concerning things about GPS. Much of our business and private lives is based on GPS, nowadays. You're in a plane, you're in a boat, trains, I guess don't use GPS a whole lot, but we depend on them in our cars, everywhere. We'll talk a little bit about that next week.

When it comes to facial recognition, it has come to the forefront. Now we know that, for instance, London, England was probably the most surveilled city in the world. I don't think that's anywhere near true now, considering what the Chinese have been doing to their citizens. No, I probably shouldn't call them citizens. I'm not sure what the right thing would be to call them, but the people living over there in China are under a constant eye. They're even watching them over there for jaywalking and they use facial recognition systems to automatically send them a ticket. Oh, also this social credit score they have over there where if you do jaywalk or do something else, you get points taken off of your social credit score. If your score reaches a certain point, you can't even take public transportation anymore. That's how they're controlling people. One of the many ways that they're controlling people in China.

These facial recognition systems are used there. We know they've been in use in London where they're trying to track people and reverse engineer crimes, someone commits a crime.

There are sensors that listen for gunshots, for instance, and then they will just backtrack all of the people that were in the area. Okay. Watching them where they work, as you remember, it's being recorded. So you're here now, where did you come from? Some of that same type of technology was used in Washington, DC for what happened on January six, with the riot of well, 80 people. Some riot. We're also now aware of what was done in Oregon and in Washington state and New York City where they were tracking people as well now. Did they get charged? Did they go to jail? They were using facial recognition systems and they were figuring out where they were, where they had been.

They were also looking forward to the fact, because unlike China, where they want to know where everybody is and they've got this whole social credit system. What we were doing is finding people who were committing serious crimes. The police obviously don't want to go into that area because there are so many rioters and they were armed with all kinds of things, the baseball bats, but they had frozen bottles of water.

No, I don't know. I threw a bottle of water at him. You had. That thing, deep, frozen, in a deep freeze, below zero degrees, which is way cold Fahrenheit. You brought it with you and you use that liter bottle to bash someone over the head. We saw this again and again. So you find those people. You don't arrest them right away. You don't send the police in. No reason to put their lives in any more danger than they are everyday, normally. Then what you do is track them as they leave. Now when they were leaving, they were using facial recognition to figure out who was there and where did they go? That facial recognition technology then was able to track them down. Once they got into an area where there weren't a lot of rioters or no rioters about to get in their car, or however it is, they got there, they arrested them. Of course, some of these rioters, real rioters, right? Where there's hundreds of people rioting, not 80.

They were able to track them down. Some of them were arrested, some of them were charged. In a lot of these cases, the mayor said, no, don't do anything. Just let them I was going to set them riot, but that's not how they phrased it. I'm trying to remember how they phrased it.

So we are seeing. Facial recognition used in law enforcement. It's one thing to track them either. What happens over in London where a crime is committed and they now track everybody back to figure out where did they come from? What car did they get into? Did they get out of it initially? Then what was the license plate number and who owns that car? Crime-solving that way, where they don't necessarily recognize your face. They don't know it's you.

However, now we're finding more and more of that happening, where the systems recognize your face and they know it's you, and they know what your social media accounts. They know obviously where you live, it's all tied in. A lot of cases is tied in via your driver's license or now these federally mandated national ID cards that so many people are carrying around.

Apparently, I'll have to carry around to next time I get my license because my state has finally decided they are not going to issue regular driver's licenses anymore, which definitely bothers me.

I'm sure you can figure that out too. How were they identifying people? It's one thing to see a face and okay. There's the face here. Okay. There's a face there. There's okay. Here. Okay. So he just got into this car to leave. That's one thing, right? I think that's pretty legit. You don't have a particular right to privacy when you're in a public place. In fact, you have no right to privacy when you enter a public place. So I don't have a problem with that.

Now we're using artificial intelligence and we've talked about some of them before, Clearview is a great example, clearview.ai. Here's a company that some would argue illegally captured scraped. What kind of her kind of wording you want to use pictures of people all from all over the internet and the police can subscribe to their service and Clearview says, Oh no, we only let police at it, although there's evidence that would suggest otherwise. They're allowing all kinds of third parties access to the database, but you can put a person's picture into their software. Their software, by the way, includes a mobile app, so it can be done on the street and you know who they are.

Now, this is getting RoboCop-ish. If e you've ever seen the movie Robocop. Actually, there's a series of these things with the Ed two Oh nines. What happened is the police officer could go out and he'd be patrolling in the streets and he come across some people in the computer in that kind of the heads up display would figure out, okay, that's this person they've been arrested 20 times a felony, this and that, and okay that person was shoplifting with their names and addresses and things right there in the screen. That's been a theme of science fiction movies for very long time.

I interviewed probably about a decade ago, a guy out at the consumer electronic show who had a very cool device that you could wear. It was designed for policemen and it was like a pair of big goggles back in the day, right? This is before Google glass and some of these other things came out, but they were able to with this the heads-up display put anything you wanted on it. So it's coming, it's not here yet. It's going to be here even more in the future.

If you want to check if your photo is part of all of this stash and there are billions literally of photos that Clearview AI has out there, but you can check at least the basics.

So many of us use this website online that allowed us to upload our photos and share them with friends and relatives and family, and put it together, and have a really great little album that you could share with people. That was on a site called flicker. Today, many of us are uploading our photos to Amazon or to Google. Apple, of course, has many of them. What happened with flicker is they went out of business. They got sold and resold few times. What they ended up doing is selling the pictures online. There's people I talked about this a couple of years ago, this guy driving down the highway and he sees a billboard with his picture on it, not the sort of thing that he was expecting that's for sure. It's probably not something you expected when you uploaded your photos to flicker. So take a minute. Go to a website called exposing.ai.

This particular website is specifically aimed at flicker photos. It'll tell you if it has found your picture. So you can, you put in your flicker username and they'll let you know if your flicker photos have been taken and used for facial recognition by a few different companies.

Dive face, face scrub, mega phase Pippa, VGG face, and many others. You can just put in your username. You can put in a tag that you tagged that photo when you uploaded it, or the URL of a photo. If you have a photo, it is online and it's yours and you want to see if anybody else is using it somewhere on the internet.

The easy way to do this is to go to Google image search. You can upload the image, you can give it the URL of the image, and it'll tell you if it finds matching images or at least images that are close to it online.

Stick around. Visit me online Craig Peterson dot com.

During the lockdown, we've had a lot of things that have become difficult to get your hands on. Turns out that includes various types of games like your PS5's, but it extends a whole lot further than that.

Hi everybody. Craig Peterson here.

Here we go, man, another fallout from the whole lockdown thing. This is a pretty darn big deal because it's affected the entire computer industry. We've heard a lot of complaints about how difficult it's been to get a Sony PlayStation five or a Microsoft X-Box series SX. They both hit store shelves last year, but they have been almost impossible to find at any of the major retailers.

There's a great little article that was in ARS Technica, and they put together a graph based on some data obtained from E-bay. This data was looking at the availability and costs specifically of the PS five. Now, this is a fairly advanced computer, frankly, in order to play these video games, of course, it's got a lot of graphics capability built right into this silly thing. It seems that there were a certain number of consoles sold on certain days at certain prices. You can see this massive price increase. It just jumped right up in November. Pretty much stayed up there in the thousand dollars plus range. Isn't that amazing. It went down in January and is more or less flat right now. You can get them on eBay for about 380 bucks right now. Why is that? What's been going on here. We've got scalpers. Obviously, a thousand dollars is a lot higher than the $380 you can get it for right now.

It turns out that there is a huge problem and the problem we're seeing is affecting the entire computer world. There are certain chips for which there is a shortage. Why is there a shortage? Well, it had to do with the lockdown. Companies were trying to figure out, okay, how many of these devices am I going to sell when everybody's locked down? They miscalculated, frankly.

It wasn't a problem with supply. It was that these companies that had been ordering these components cut their orders back or stopped them entirely.

You've got Sony and others out there, Microsoft's console as well, trying to find the parts. They have had a very hard time. Well, what happens when it's hard to find something? Either the quality is going to go down to keep the price the same or the price is going to go up. There's only a couple of ways that it really can go.

They're estimating right now that these constraints on the supply chain are probably going to last for a few more months. We've seen it big time in the computer world, particularly in the storage space. You may not be aware of it, but there are, of course, hard disks that aren't really disks called SSD, which is a solid-state disk.

Okay. You probably know about that. I wrote up a thing, in fact, Because people were asking me about what to buy, to upgrade their computers. If you have a slower computer, putting an SSD in is usually a very good idea, but there are many grades of SSDs.

In fact, I've got a little document. If you want it to send an email to me@craigpeterson.com. I'll be glad to send you a copy. I wrote this for one of our clients. It drives me crazy. They need a new computer, in this case, a desktop. So they say, Hey Craig, can you guys go ahead and work us up a quote? So we look at what they're using the computer for. We look at the longevity of that computer so that they get the best bang for their buck and usefulness. How useful is it going to be? Is it going to be offline just five minutes a day, by the way, adds up to over $2,000 a year for just an average salary of a data entry worker. It adds up pretty quickly if it goes down.

We put together this proposal and this was for a customed Dell machine and we specify all of the components that go into it. That's an important thing to remember because these components all have varying levels of quality. We sent them the quote and we've done this before, right? Who's the fool here, them or us. They said no. I went to the Dell site and I got this special going on and then I can get the same computer for 300 bucks.

Not true. It's not true. Now, you guys are the best and brightest, right? This sort of stuff, you can't compare a Yugo to a beautiful Cadillac right there. There's no comparison between the two, but that's what they were doing. They needed an F150 in order to haul stuff but instead of getting the F150, they just got a little hatchback that they can maybe throw a couple of things in the back, but they needed a big bed pickup truck. That just drives me crazy.

So I wrote this probably three or four-page long, a thing explaining why you need to buy the right kind of hardware. Why the stuff that they're selling you at a discount isn't going to work for you and things need to be included, include things like the hardware encryption and SSDs.

Again, I'll send you this report if you want it. Just let me know, call me@craigpeterson.com.

I started this whole thing because we're talking about SSDs. SSDs are not all created equal. Some of these SSDs store one bit per little bubble, if you will. Some of them store two bits on them store three-bit bits. They're all constrained in their lifetime based on how many writes are occurring to that disc.

You've got to look at that as well to figure it out. Now, of course, I got into SSDs because we were talking about the capacity in manufacturing and the shortage that we're seeing right now. If some of these game consoles, there is a shortage in all of these types of disks, there's even a shortage of memory and certain CPUs.

The disc shortage started a few years ago when there was massive flooding in Indonesia. That's where a lot of the hard disks are made. Now, these are the things that spin, right? Now we've got new technology that lets us pack more data into the SSDs.

Whereas we were seeing the hard disk go up in size. I remember my first one was, I think it was five megabytes. It was just, Whoa, how could I have used five Meg and then 10 megabytes? Of course, hard disks, reasonably priced ones tend to 12 terabyte drives and again, multiple different types of drives.

There's the more server-oriented that if there's an error on the disk, the disc stays alive and it repairs itself in real-time in the background. Then there's the stuff you get as consumers where if the disc starts failing, the whole disc goes offline until it fits fixes itself.

Then there's real crap. The ones like these green drives from Western digital, that I do not like. I just had confirmation on that this week that are even cheaper, but all of these are hard to get right now.

We will see eventually all of these supplies back in line. The manufacturers can make them. The whole lockdown hasn't really been a problem for them. The problem has been that people aren't ordering because they're afraid during the lockdown that people wouldn't be buying computers. Of course, we found the opposite to be true. Didn't we. People were buying these consoles to play video games. Buying computers to work from home. Trying to buy network security stuff as well. That's really changed the whole thing.

When we get back, let's get into we'll get into the InfoSec career a little bit later if you miss it. If you're thinking about getting into information security. Make sure you go online to Craig peterson.com. So you can catch that.

We'll talk about that, but let's do something I think that might affect a lot of people and that's Chrome users, three security problems in the last week.

Hey, you guys are the best and brightest. You know what I think about Google and Google Chrome? Just this last week, over one 24 hour period, Chrome had three security problems. We're going to talk about that right now.

Hi, everybody. Craig Peterson here.

Google is evil. I've established that I think, before, the things they do, the things they have been doing to us.

Remember their motto used to be, don't be evil. They removed that from the website a couple of years ago. Now, no longer don't be evil. Nowadays they're doing pretty much everything they can to, maybe be evil is a little strong a word, but they're pretty much-doing everything they can to get as much information about you and sell it.

Do you remember his goal? Larry Page when they were starting it up. The goal was okay, where we are going to get all of the world's information and democratize it. Make it available for everyone, anyone out there who wants to get at it. Frankly, it's been pretty good until fairly recently. At which point I switched over to duck duck go.

Chrome is another one of their products. Microsoft frankly, jumped right onto the Chrome bandwagon. What they ended up doing over Microsoft is taking Google's open-source version of the base of Chrome. They call it chromium. It's the guts, if you will, of the Google Chrome browser and they made it available to anyone that wants to get their hands on it. So Microsoft got their hands on it and messed around with it a little bit. As Microsoft is wont to do. They came up with their Edge browser. The latest Edge is really Google Chrome in disguise.

There are others out there too. You probably know if you've been through one of my courses when I'm talking about browsers. The Epic browser is a pretty good browser. It is designed to be more or less safe. But we go into that a lot more detail. In which cases is it not et cetera.

Some people have used the Tor browser, which ties into the Onion network that provides even more anonymity. So there are options. Of course, Safaris available from Apple for almost every platform now. It is a very fast browser and it does a lot to try and keep your data secure.

The same thing's true with Firefox. In the Improving Windows Security Course, I go into the problems with each one of these, including Firefox and what you have to consider.

This past week we had a bit of an issue. If you attended my webinars last year. This would have been in 2020. I went through some of the privacy plugins that you can use for your browser. You might remember that one of them was something called the Great Suspender. Highly recommended at the time. Got to add that in there because I don't want you to just go grab it. It was recommended. I used it, extensively on a bunch of different browsers, because what the Great Suspender did is save your machine's memory CPU, frankly, even a little bit of disc I/O when you were on a tab on your web browser, your tab would just respond.

Normally everything looks good, but if you're like me, you probably opened another tab or maybe another window and then another tab or another window. You just dig deeper and deeper as you're looking into something, trying to figure something out.

You might have 20 or 30 or 40 or 50 tabs. Open each one of those tabs represents a different thread, a different process, basically on your computer. That means it's using memory, it's using CPU and it might be also hitting your disk, using your disk. The Great Suspenders said wait a minute, now you haven't used this tab in whatever you set it for, I usually had it about 15 minutes. What I'm going to do now, Yes, I'm going to take a snapshot of this page. I am going to just release all of the resources that were associated with the page. If you go back to that tab, all you have now is a snapshot, just a picture of what was on the page. You can see what was on the page and depending on how you configure the Great Suspender, I had it set up so that if I activated a tab again, it would automatically reload that page. You could have had it so that if you got to that picture and you really wanted it, you'd click on it and it would reload the page. Very. Handy. It allowed you to have hundreds of potentially of tabs open quote-unquote, when in fact they weren't open and they weren't using hardly any resources at all.

The Great suspender this last June was sold. The original person who wrote this thing, and it's a great little really great, actually a little piece of software decided that he wanted to make some money off of it. Why not? He sold it. It's unclear as to who actually owns it or controls it right now and who he sold it to because the name of the account, the developer account, is the Great Suspender. So that's not going to help you at all.

It started showing some signs of what Google and what people are calling malice, under this new ownership. There was a thread in GitHub that was published in November and GitHub is where so much of this code is stored, right. It started to show some signs of frankly, of malice under this new ownership. They said that a new version contained malicious code that tracked users and manipulated web requests.

Now the Great Suspender did normally manipulate web requests, in order to keep everything flowing and smooth. So you might go to a website and then it suspends it, and it might use a different URL and the URL is going to cause the Great Suspender inside your browser to be called. Okay.

So I'm not sure what they mean about the manipulation here, but Google removed it. It's gone like that and no warning or anything else just within the last week. They completely removed the Great Suspender, not just from the store, they removed it from your machines where you were using it.

It said this - the extension contains malware, that's the only warning they gave. That is the only background they gave. They really haven't said a whole lot. People, by the way, who were using the Great Suspender were really left in a lurch because any suspended tabs when Google went bye-bye, any suspended tabs you had were a lost. How's that for a terrible thing? Absolutely terrible.

There is a Reddit thread out there that you can see. They talk about how you can get your tabs back. So if you had followed my advice back then and put it on, good for you. However, the problem is that it turned out to ultimately be malicious. So that's a big deal.

Remember I said three security problems in 24 hours, Google on Thursday, released a Chrome update that fixes what it called a zero-day vulnerability in the browser. This is another buffer, overflow problem. If you're programming, you know what that means in version eight, which is Google's open-source Javascript engine, and they rated it as high.

Again, Google didn't say much about what the vulnerability was. Probably didn't want to encourage people to try and use it, but they said it was existing in the wild. That's not very good. Then sync abuse, a security researcher reported on Thursday as well. Hackers were using malware that abused the Chrome sync feature to bypass firewalls so the malware could connect to command and control servers. Not good.

If you are using, if you have Chrome, I have it because I have to, cause I have to test things out.

If you are using it, make sure it is up to date. Most of the time Chrome will update itself, but this week is one where you should double-check Chrome and make sure it really has been updated. Cause these are some pretty nasties. All right.

I'm sure you're familiar with Senator Amy Klobuchar. She ran for President, under of course the Democrat ticket, this last election cycle. She is targeting big tech, at least. That's what she says. We'll talk about the reality.

Hello everybody. Craig Peterson here. Thanks so much for joining us today. I really appreciate it. And I appreciate hearing from you as well. Any questions? I have so much information to give you guys we're starting some training courses, free email training, just everything me@craigpeterson.com. Any questions as well and visit me online at Craig peterson.com.

Senator Amy Klobuchar, is a Democrat from Minnesota and she has introduced a bill here in Congress and supposedly big tech is in her crosshairs. Now I think that's really funny because it's not in reality. Okay.

Here's an article from ARS Technica a very good website, by the way, on some of the tech. It says not only our major firms, such as Apple, Amazon, Facebook, and Google under investigation for allegedly breaking existing antitrust law. A newly proposed bill in the Senate would make it harder for these and other firms to become so troublingly large in the first place.

If you've been listening to me for a while, I have friends that have been absolutely destroyed by some of these big tech firms. Where companies have gone ahead and then announced a product because they found, Oh, wait a minute. These guys over here, they're doing pretty darn well with that product. Let's see if we can't figure out if there's really a market forward or not end up, they're competing with us. So here's what we'll do. Let's go ahead and announce. We're going to have a product and it's going to be better than their product, and you can get it from us and you can rely on us. Don't pay attention to that small company over there. They are entirely unreliable.

All of a sudden that small company's sales plummet because people are waiting for big co to come up with their version of whatever it might be. Then they'll compare it to and maybe buy it a bit later on.

That's a way that many of these companies have grown and grown in a very big way.

Senator Klobuchar introduced this bill called Clara. Should have called it Clarice. The competition and anti-trust law enforcement reform act. This would be the largest overhaul to the US antitrust legislation in almost 50 years if it became law. It's interesting because her statement says while the United States once had some of the most effective antitrust laws in the world. Our economy today faces and massive competition problem.

I'm a little confused here. It looks like she is asking for competition. I don't know. I don't understand it. I thought she was one of these far-left ones. I remember the debates quite well. They're looking at expanding resources. In other words, give them more money at the federal trade commission, the department of justice in their antitrust division. They're looking to pursue a review of more mergers, more aggressively.

Now my knee jerk reaction is, these big companies usually we'll fail. They usually just keep getting greedier and bigger. Look at what happened to GM. They went bankrupt and unfortunately, they use tax dollars to bail them out. Chrysler has gone bankrupt twice, and they've used our tax dollars to bail them out. I don't think that's a good idea.

Remember our tax dollars mean our time. We have to put in our time, we can't spend with our families. Time, we cannot spend on vacation. Time we cannot spend relaxing. It takes our time now, where we have to work to make money, to give to the government, to bail out companies that are failures.

What the government decided to do rather than let these bigger companies fail as they ultimately always do. If you're old enough, you'll remember back in the seventies and eighties, IBM, too big to fail. They owned the business, the computer business in the sixties and seventies, and they just fell off the edge. Didn't they? That usually happens.

I'm not sure a hundred percent is going to happen with the social media companies but I suspect they are. Look at what's happening right now. If you have kids that are under 20, do they have a Facebook account? Even in their thirties, under 20-year-olds, they don't use Facebook anymore.

Facebook is likely to die off unless they change in a big way. So what's Facebook do? They buy competitors. They buy WhatsApp. We've talked about WhatsApp before and my thoughts on that. They buy Instagram. They buy competitors and they use competitors too. Change their business model a little bit and move laterally rather than vertically. That's not a bad idea in business. Frankly, most businesses expand their product line, expand their way of doing things by acquiring successful small businesses. So I get that. I think that's wonderful.

But what the Senator is proposing is that we have the government decide if a business should be allowed to acquire another business. There is a line in there where I agree with her. I'm not a hundred percent sure where that line should go.

We've had antitrust laws here in the United States since 1800s, a very long time. The Sherman act short and simple back then it made it illegal to monopolize or attempt to monopolize or conspire to monopolize the market. I liked that one.

How about if you're defining the market? There's two sides to this, one side often overlooked.

You've got the side of the supplier. You've got Facebook or GM or whoever. You say Facebook is the 800-pound gorilla. They own this market. So what should you do about Facebook?

That's what she's trying to figure out here. What should we do? They're saying we should have a government regulator decide if it's a monopoly or not. We know how well that ends up working. You end up with a revolving door, the regulators working for the corporations, and then going back to the regulators right back and forth. It's absolutely crazy. That side of it.

There is another side and this other side is frankly not that new, but it has gotten worse more recently. It's called a monopsony. What this is where you have a lot of suppliers. So you'd have a whole lot of Facebook' for instance, but only one purchaser.

You said, Craig, what are you talking about? We're the best and brightest. I'm not quite sure where you're going with this.

Here's where we're going. Monopsony is typified by Walmart. Walmart is well-known as a company that you do not want to sell to. If you're a small business, you look at it, say, Oh yeah we got Walmart. They're going to sell our product. Okay. Okay. Great for you. It's not wonderful. Walmart took out every rubber hose they had, and they beat the supplier over the head and shoulders and back until they capitulated.

Walmart was routinely criticized for this forcing vendors to lower prices until it became unsustainable. I can think of a few of these products right off the top of my head. Do you remember Rubbermaid, right? It was the. The dominant force for those rubber containers at Walmart. Then all of a sudden it wasn't there anymore. Do you remember that? Because they couldn't sell it to Walmart at the prices Walmart wanted it at. That's one way Walmart keeps the prices low.

With this monopsony problem. We're talking about a lot of companies that make competing products, but there's really one 800 pound gorilla. That's buying it. Walmart has a huge share of the US retail market. Of course, now they've been one-upped by our friends over at Amazon. Amazon is there now in that kind of the same position.

If you're going to sell something, you pretty much have to have it on Amazon. Amazon's basically going to dictate how much you can sell it for. Isn't that interesting. By the way, that word monopsony dates back almost a hundred years as well. Antitrust laws have never addressed the idea of this kind of anti-competitive behavior from the bottom-up direction. It's an interesting way.

So what do I think is the way to go on all of this stuff? First of all, we'll see if it ever becomes law. They tried something similar with a bill back in 2019, and it didn't get very far. With the Democrats controlling the white house, the house of representatives, and the Senate. The idea of reform being passed is more feasible, but there's one other side to this.

This goes back to my friends who have had their businesses effectively stolen by large companies. That is when we're looking at more regulation, which is exactly what she's proposing. More regulators, more money going to the regulators. They're making the entire marketplace harder.

If you're a small company and do you have to comply with all of these new rules, you now have to make all of these regulators happy. What are the odds? You're going to be able to do that compared to the big guys. The big guys can quite easily afford all of the attorneys, all of the regulatory compliance people, everybody that's needed. But you can't.

So the big companies love this sort of thing because the regulations make it easier for them to keep competitors out of the market. They're keeping competitors out of the market. We've already established that they're buying competitors, so they don't have to compete with them.

Now we're going to make matters worse with this Klobuchar bill. By doing what? By increasing regulation, making it harder to compete.

I propose that we'll actually have more monopolies after this. I would much rather just keep it simple and watch out for monopolies. If a company makes mistakes and is going under, let it go under. Any parts of that company that have any value will be sold. That's what bankruptcy laws all about.

If, someone who's thinking about maybe getting into an information security career. Or maybe you're looking at another career because right now there are millions of jobs open in InfoSec. We're going to talk about it. What do I wish I knew?

Hi everybody, Craig Peterson here. Thanks so much for joining me.

You probably know that I have been in information security for a very long time. It started out as I had to protect my own company. When I got nailed 30 years ago with what was called the Morris worm. If you've been on any of my webinars where I do a little background, you heard my story there. It just scared me to death. I almost lost a bunch of clients because of this worm.

The worm is a piece of software that gets onto a computer and then spreads to other computers. Nowadays, we have a lot of things that act like worms. For instance, ransomware gets in and starts to spread. We have all kinds of bad guys that are doing the same thing. They'll get onto a machine in your network. Then they'll manually start looking around and seeing what you have, what file servers you have. Oh, let's connect to the G drive or whatever you call that file server drive or shared drive. They will look through your files and just the rest of the story, right?

You guys are the best and brightest. You really are. So here's where I come down. I think there is a lot of opportunities here and I did a little presentation for a mastermind group. I'm a member of last week. I talked about a guy that became a friend of mine who is in his late fifties is right around 60 years old and decided he needed a new career. His prior career had literally disappeared. They had just been destroyed. He was in retail and he was managing a store and he had a lot of clients. Of course, that job went away and he was looking for, what do I do next? He's been listening to me for a very long time on the radio and decided that maybe he should look into an InfoSe career. So he did.

I used him as a case study with my mastermind group. What should people be looking to do and how can I help them? So I figured let's do this because I saw an article in Dark Reading. That's one of my favorite websites for all of these articles on security. They were talking about exactly that, what should I be doing now, if I want a security career? What are the things I should know and do?

The author of this is Joan Goodchild, an easy name to pronounce. What happened to her? She points out, do you know information security can be really rewarding? I absolutely agree with that. It is a thankless job, you miss one thing and something gets in. Someone brings it from home you don't quite have everything in place or everything up to date.

The biggest problem I've seen and I see with this friend of mine that I talked about in the mastermind is that we don't think we know enough. It's something called imposters syndrome. You've probably heard of it. It exists in a lot of different facets of our lives, not just in careers.

So he has imposter syndrome, as do a lot of people who are in cybersecurity because there's so much to know. That's why I've said forever businesses cannot do cybersecurity.

Antivirus isn't going to work for you. Basic firewalls are not going to work for you. Even if you have the right equipment in place if you don't know how to manage it and set it up. All of this stuff, it's just not possible to do.

Maybe you should look at a security career, cybersecurity.

Let's run through some of the things that she put in there. Of course, I'll add my little side things, but she asked a bunch of people in cybersecurity, specifically what do you wish you would have known when you first started. Here's Gregory Touhill, president of Applegate, federal Brigadier general retired in first, us CSO under president Barack Obama, CSO is the chief information security officer for the federal government.

He said. I love this quote. Cybersecurity is a full-contact team sport. There is no single person who is an expert on all of the various aspects of the area of the discipline. Once I got over myself and recognize that I couldn't do it all, I focused on building the right team of experts to solve issues before they become problems. That revelation triggered great future success. So there you go.

I think that's absolutely phenomenal to remember. You're going to have imposter syndrome if you decide to go into this, but the bottom line is to work with a team. If you can find a vendor like me, that knows what they're doing, that has people that can help you out because you cannot just be out there yourself.

Next point here. This is from Wayne Pruitt, cyber-range, technical trainer in North America. I've seen him before. He's been on one of my webinars where I was teaching about cybersecurity. To be effective in cybersecurity you need to have an understanding of all areas of information technology. Boy, is that true? If an analyst does not understand how a web application communicates with a database on the backend, how will he know if the traffic he's seen is normal or malicious? Without this understanding, analysts are just relying on security tools to make the determination. Hopefully, those tools are configured correctly.

Sometimes you have to learn the basics. Don't understand the more complex. Again, this goes into you've got to have a team. You have to have multiple people who can help out at different levels because frankly, you can't know it all. Going back to that the general Brigadier general, he had such a good point.

Next up is a chief strategist at Point 3 security. Her name is Chloe Messdaghi. I really wish I knew how little diversity and inclusion were practiced. When I first entered the industry, many of us in our current organizations are now working for to improve the situation are gaining ground. But within my first year, I felt like I had entered the 1940s. I personally think this is ridiculous.

Men are attracted to certain things and certain careers, women, the same thing. There are some careers that are dominated by women and some that are men. One of my daughters works with me and she is a cybersecurity analyst and she's just finishing some more training. In fact, our people tend to spend about a third of their time in training and she's very good and it has nothing to do with the fact that my daughter's a girl. So come on, quit seeing sex and seeing the race everywhere. It's just crazy. It's out there and she's right there aren't many women that are in this career.

Next up here, Lakshmi Hanspal. She is CSO of a company called Box whom I have used before. They've got some very good products for file sharing. I switched over to Dropbox. I like some of the stuff a little bit better having come from a traditional stuff background.

It was not until I entered higher leadership roles and began formulating hiring strategies that I realized the more diverse teams solve the toughest challenges, skills, such as critical thinking, how to manage risk trade-offs and cybersecurity not being a zero-sum game are extremely fundamental and understanding and thriving in the security industry. It is obvious she spent some time writing that and trying to put in lots of big words.

She is right. We when we're talking about diversity in this case, what she's talking about are the diversity of skills, critical thinking, managing trade-offs, and understanding that we all have to work together on a team in the cybersecurity field. I thought she had a really great point.

Next up, we have Josh Rickard security research engineer over at Swimlane. I wish I knew and understood that an organization's priorities are guide rails for information security teams, as with most starting in InfoSec. I wanted to solve all the security issues I came across, but this is impossible.

Understanding business priorities while communicating potential risks is critical. Okay. But helping the business with those priorities gives you credibility. Wow.

I'm going to save that one, frankly, because that is something that we all need to remember. I've had people on my team that was just a hundred percent focused on doing the right thing, quote unquote, on the cybersecurity front, and to them, the right thing was to make sure there are no holes. So I can see that from a certain perspective. And again, back to the diversity of thought, having someone like that on your team is a good idea, but it does have to be tempered.

Mary Writz VP product development over at ForgeRock. When I started 20 years ago as a penetration tester at IBM. I wondered how I even got the job because I did not feel qualified in hindsight. No one was truly qualified because it was such a young domain. I was hired because of my technical background, my curiosity, my interest, fast forward, 10 years, I was teaching a technical audience how to build hunt teams and I expect everyone in the audience knew more than me. A gentleman in the audience raised his hand and said, you're assuming we know what we're doing, but we don't. After we all laughed, we shared our notes and learned from each other.

Wow. So insightful here, because again, she's pointing out. The curiosity requirement. I think if you're not curious, you're not going to spend the time it takes to investigate and to learn more.

We're going to cover a few more.

You're listening to Craig Peterson and online@craigpeterson.com.

We're talking right now about InfoSec, information security. Have you thought about maybe taking up a bit of a new career? Well there are some estimated 2 million open jobs in this one.

Of course, this is Craig Peterson.

We were just talking about this article that appeared in dark reading. Now, dark reading is an online magazine, right? It's a website. And they had this article that I absolutely had to read because it reminded me of someone I know. One of our listeners, who decided he needed a new career. He'd lost his job. He'd been out of work for over a year and he had been managing a retail camera shop and they shut it down. He was stuck. What do I do? He'd been listening to the show for a long time. He decided he wanted to go into information security. He took some courses on it and he got himself a job. A full-time job being the chief IT security guy for this company after just a few months.

So that tells you how desperate these companies are. Kind of jerking his chain a little bit, but not right, because he just barely had any background. If you want me to connect you with him, if you are serious about thinking about one of these careers, I'll be glad to forward your request to him, just to see if he's willing to talk to you. Just email me ME@craigpeterson.com and make sure you mentioned what this is all about. So I know what's going on.

Ran Harel, he's a security principal and product manager over at Semperis said, when I was growing up, I was quite an introvert, by the way, that sounds like a lot of us in it. I didn't realize until much later on in my career, just how great the security and tech community are looking back. I realize how quickly I could have solved so many issues, by just asking on an IRC channel or forum.

IRC is an internet relay chat, a bit of a technical thing, but it's an online chat.

I would tell my former self, the problem you are facing now is probably been dealt with multiple times in the past year alone. Don't be afraid to ask the InfoSec community and then learn from them.

That's absolutely true. I found an online IRC channel basically, and they were set up just to talk about CMMC is this new standard that department of defense contractors are having to use.

As you probably know, we have clients that are manufacturers and make things for the Department of Defense and they have to maintain security. It's been interesting going in there answering questions for people and even asking a couple of questions. It is a great resource. This particular kind of IRC is over on discuss.

You can find them all over the place. Reddit has a bunch of subreddits. It's dealing with these things, including, by the way, getting into an InfoSec career. So keep that in mind.

There's lots of people like myself that are more than willing to help because some of the stuff can get pretty confusing.

All right. The next one. Is from Cody Cornell, chief security officer, and co-founder over at swimlane. He said, apply for jobs. You are not qualified for everyone else is.

Man. I have seen that so many times everybody from PhDs all the way on, down throughout a high school and who have sent me applications that they were not even close to qualified for.

Now, you can probably guess with me, I don't care if you have a degree. All I care about is can you do the work. Can you get along with the team are you really going to pull your weight and contribute? I have seen many times that the answer to that is no, but I've seen other times where, wow, this person's really impressive.

So again, apply for jobs you're not qualified for because everybody is. Security changes every day. New skills techniques and the needs of organizations are always shifting. And to be able to check every box from an experience and skills perspective is generally impossible. Looking back at 20 years of jobs in the security space, I don't believe that I was ever a hundred percent qualified for any of them, but felt confident that I could successfully do them.

So keep that in mind. Okay.

Again, imposter syndrome, we're all worried about it. This applies to more than just InfoSec. This applies to every job, every part of life, we all feel as though we're impostors and that we're not really qualified, but the question is, can you figure it out? Can you really do it?

Next up here is Chris Robert, a hacker in residence, he calls himself over at Semperis and he says, overall, the most important lessons that I'd tell my younger self are not tech-based. Rather they focus on the human aspect of working in the cybersecurity industry. I think cybersecurity professionals in general, tend to focus on technology and ignore the human element, which is a mistake and something we need to collectively learn from and improve.

I agree with him on that as well. However, we know humans are going to make mistakes, so make sure you got the technology in place that will help to mitigate those types of problems.

Next up, we've got Marlys Rogers. She's CISO over at the CSAA insurance group that's a lot of four-letter acronyms. You are nothing without data. Data is queen. Coming from an insurance person, right? Without hard data, you can only speak to security in more imagined ways or ways. The board and C-suite are aware of in the media cost-benefit is only achievable with related data points. Demonstrating how much we are fighting off and how the tools, processes, and people make that happen.

Next up we have Edward Frye, he's CSO over at our Aryaka. When I first started out, I was fairly impatient and wanted to get things done right away. While there are some things that need to be done right now, not everything needs to be done. Now have the ability to prioritize and focus on the items that will have the biggest impact.

I think one of the biggest lessons I've learned along the way is while we may need to move quickly, this race is a marathon, not a sprint.

Patience is essential for security pros. I can certainly see that one.

Chris Morgan, senior cyber threat intelligence analyst over at Digital Shadows, despite the way that many in media liked to portray cyber threats, not everything will bring about the end of the world.

For those getting into incident response and threats, try to have a sense of perspective and establish the facts before allowing your colleagues to push too quickly towards remediation mitigation, et cetera.

Expectation management amongst senior colleagues is also something you'll frequently have to do to avoid them breaking down over a mere phishing site. The quote, one of my former colleagues try to avoid chicken, little central.

I've seen that before as well.

The next one is things are changing daily and the last one is the perception of security is still a challenge.

So great little article by Joan Goodchild. You'll see it in my newsletter, which we're trying to get out now Sunday mornings.

You can click through on the link if you'd like to read more.

As you can see. 2 million open jobs while between one and 3 million, depending on whose numbers you're going at in cybersecurity.

You don't have to be an expert. As I said, one of our listeners went from not knowing much about it at all, he can install windows that's it, to having a job in cybersecurity in less than six months.

I'm doing a special presentation coming up next month for the New England Society of Physicians and Psychiatrists. We're going to be talking a little bit about what we will talk about right now. What can you do to keep your patient information safe? What can we do as patients to help make sure our data's safe.

You'll also find me on pretty much every podcast platform out there. Just search for my name, Craig Peterson. I have a podcast and it makes it pretty easy. I've found some of them don't understand if you try and search for Craig Peterson, tech talk, some of them do.

I've been a little inconsistent with my naming over the years, but what the heck you can find me. It's easy enough to do.

I've got this new kind of purple-ish logo that you can look for to make sure it's the right one. And then you can listen to subscribe, please subscribe. It helps all of our numbers.

You can also, of course, by listening online with one of these devices, help our numbers too. Cause it's you guys that are important. The more subscribers we have, the way these algorithms work, the more promotion we'll get. I think that's frankly, a very good thing as well.

What do you do if you need to see a doctor, that question has a different answer today than it did a year ago. I won't be able to say that in about another month, right? Because mid-March is when everything changed last year, 2020, man, what a year?

To see a doctor nowadays, we are typically going online, aren't we? You're going to talk to them. So many doctors have been using some of these platforms that are just not secure things like zoom, for instance, which we know isn't secure.

Now, the fed kind of loosen things up a little bit under the Trump administration saying, Hey. People need to see doctors. The HIPAA PCI rules were loosened up a little bit in order to make things a little bit better. Then there's the whole DSS thing with HIPAA. All of these rules are just across the board are loosened up.

That has caused us to have more of our information stolen. I'm going to be talking a little bit about this FBI, actually multi-agency warning that came out about the whole medical biz and what we need to be doing. Bottom line, Zoom is not something we should be using when we're talking to our doctors.

Now, this really bothers me too. Zoom is bad. We know that it's not secure and it should not be used for medical discussions, but Zoom has been private labeling its services so that you can go out and say, Hey, zoom, I want to use you and I'm going to call it my XYZ medical platform.

People have done that. Businesses have done that. Not really realizing how insecure Zoom is. I'm going to give them the benefit of the doubt here. You go and you use the XYZ medical platform and you have no clue of Zoom. Other than man, this looks a lot like Zoom, that's the dead giveaway.

Keep an eye out for that because a lot of these platforms just aren't secure. I do use Zoom for basic webinars because everybody has it. Everybody knows how to use it. I have WebEx and the WebEx version of it is secure. In fact, all the basic versions, even of WebEx are secure and I can have a thousand people on a webinar or which is a great way to go. It's all secure end to end.

Unlike again, what Zoom had been doing, which is it might be secure from your desktop, but it gets to a server where it's no longer secure. That kind of problem that telegram has, frankly.

If you are talking to your doctor, try and use an approved platform. That's how you can keep it safer.

If you're a doctor and you have medical records be really careful. Zoom has done some just terrible things from a security standpoint. For instance, installing a complete web server on a Mac and allowing access to the Mac now via the webserver. Are you nuts? What the heck are you doing? That's just crazy. Just so insecure.

This is all part of a bigger discussion and the discussion has to do with Zero trust architectures. We're seeing this more and more. A couple of you, Danny. I know you reached out to me asking specifically about zero trust architectures. Now Danny owns a chain of. Coffee shops and his family does as well.

He says, Hey, listen, what should I do to become secure? So I helped them out. I got him a little Cisco platform, and second Cisco go that he can use as much more secure than the stuff you buy the big box retailers or your buying at Amazon, et cetera, and got it all configured for him and running.

Then he heard me talk at about zero trust and said, Hey, can I do zero trust with this Cisco go, this Muraki go, is actually what it is and the answer is, well so here's the concept that businesses should be using, not just medical businesses, but businesses in general and zero trust means that you do not trust the devices, even the ones that you own that are on your network. You don't trust them to be secure. You don't trust them to talk to other devices without explicit permission.

Instead of having a switch that allows everything to talk to everything or a wifi network where everything can talk to everything, you have very narrow, very explicit ways that devices can talk to each other. That's what zero trust is all about. That's where the businesses are moving.

There's zero trust architecture, and it doesn't refer to just a specific piece of technology. Obviously, we're talking about the idea that devices, and even on top of that, the users who are using the devices only have the bare minimum access they need in order to perform their job.

Some businesses look at this and say that's a problem. I'm going to get complaints that someone needs access to this and such. You need that because here's what can happen. You've got this data that's sitting out there might be your intellectual property. You might be a doctor in a doctor's office and you've got patient records. You might have the records from your PCI your credit card records that you have. I put on. Those are sitting there on your network that is in fact a little dangerous because now you've got something the bad guys want. It's dangerous if the bad guys find it and they take it, you could lose your business. It's that simple.

They are not allowing you to use the excuse anymore because of COVID. That excuse doesn't work anymore. The same thing's true with the credit card numbers that you have the excuse of I'm just a small business. It's not a big deal. Doesn't work anymore. They are taking away your credit card privileges.

We had an outreach from a client that became a client, that had their ability to take credit cards taken away from them because again, there was a leak.

So we have to be careful when you're talking and you have private information, or if you don't want your machine to be hacked, do not use things like Zoom. I covered this extensively in my Improving Windows Security course. So keep an eye out for that as well. If you're not on my email list, you won't find out about this stuff.

Go right now to Craig peterson.com. If you scroll down to the bottom of that homepage and sign up for that newsletter so you can get all of what I talk about here and more.

Hey, thanks to some hackers out there. Your application for unemployment benefits might've been approved and you didn't apply for it in the first place. Turns out somebody stealing our information again.

Hi everybody. Craig Peterson here.

Hey, this is a big concern of mine and I've often wondered because I have not been receiving these stimulus checks. I did not get the first round. I did not get the second round and I contacted the IRS and the IRS says depends on when you filed for 2019. Oh my gosh. Of course, I was a little late filing that year. They still haven't caught up. I guess that's good news, right? That the IRS data processing centers are terrible.

It goes back to aren't you glad we don't get the government we pay for is the bottom line here, but I've been concerned. Did somebody steal my refund?

Did somebody steal my unemployment benefits, did somebody steal my stimulus checks? It is happening more and more. There is a great little article talking about this, where someone had stolen the author's John personal information again. Now we probably all have had our personal information stolen, whether you're aware of it or not.

As usual, I recommend that you go to have I been poned.com and pwnd is spelled, pwn, D have I been poned.com and find out whether or not your data has been stolen and is out there on the dark web.

They have a really good database of a lot of these major hacks. Many of us have been hacked via these credit bureaus and one in particular Equifax who have all kinds of personal information about us, had it all stolen.

It's easy enough for people to steal our identities file fake tax returns. That's why the IRS is telling you, Hey, file your return as soon as possible. That way when the bad guy's file, we'll know it's the bad guys cause you already filed it. As opposed to you file your tax return and the IRS comes back and says, Oh, you already filed. We already sent you a refund or whatever. You already filed it.

That is a terrible thing to have to happen because now you have to fight and you have to prove it wasn't you. How do you prove a negative? It's almost impossible. At least in this case, hopefully, the check was sent to some state 50 States away, another side of the world. So you can say, Hey, listen, I never been there, then they can hopefully track where it was deposited.

Although now the bad guys are using these websites that have banks behind them, or maybe it's a bank with a website that is designed for people to get a debit card and an account just like that. That, in fact, it's what was used to hack my buddy. My 75-year-old buddy has been out delivering meals and had his paychecks stolen through one of those.

These fraudulent job claims are happening more and more. It's really a rampant scam. We've had warnings coming out from the FBI and they have really accelerated during the lockdown because now we've had these jobless benefits increased, people, making more money staying in their home than they made on the job. Disincentives for working, frankly.

He's saying here the author again, John Wasik, that a third of a million people in his state alone were victims of the scam. This is an Illinois. This is where he lives. A third of the people in the state of Illinois, including several people that he knew.

We've got some national tallies underway. I don't know if you've seen these. I've seen them on TV and read about them, California. It is crazy. People were applying for California unemployment that didn't live in the state at all, would come into the state and once you're there in the state pick up the check, right? Cause that's all they were doing. Some people have been caught with more than a million dollars worth of California unemployment money.

Of course, it wasn't a check, it was actually a debit card. The same basic deal and California is estimating that more than $11 billion was stolen. Can you imagine that tens of millions of people could have been scammed because of this?

This is the third time the author had been a victim of identity theft and fraud. He wanted to know how could they get his information.

Well, I've told you, check it out on, have I been poned. It'll tell you which breaches your information was in. It does it based on your email address. It'll also tell what type of data was stolen in those breaches. So it's important stuff. I think you should definitely have a look at it.

He is very upset and I can understand it. Data breaches last year, more than 737 million data files are ripped off according to act.com. Frankly, that was a digital pandemic, with more and more of us working at home.

I just talked about the last segment. Your doctor's office and you are talking to your doctor. How now? Cause you don't go into the office. There are so many ways they can steal it.

The FBI's recording now a 400% increase in cybercrime reports that we had this mega hack of corporate and government systems.

This whole thing we've talked about before called the SolarWinds hack, although it was really more of a Microsoft hack, and it went out via SolarWinds as well as other things. Be careful everybody out there. If you find yourself in these breach reports on, have I been poned make sure you go to the website. Set yourself up with a new password. At the very least use a password manager.

I just responded to an email before, when it went on the air today, from a listener who was talking about two-factor authentication. He's worried about what to use. I sent him my special report on two-factor authentication, but it is the bottom line, quite a problem.

Again, Use one password, use two-factor authentication with one password. Don't use SMS as that and you'll be relatively safe.

I don't know I can't say do this and you'll be safe. I don't think there's any way to be sure your safe.

Having these organizations, businesses, government agencies hacked all the time that don't seem to care about losing our data, right? Oh, it's a cost of doing business, some of these businesses, and I've talked to them, they'll look at it and say, how much will it cost us in fines if our data is stolen? Versus, how much will it cost us to keep our data relatively safe? For even a larger small company, a hundred employee company, you're talking about something that is going to be costing you about 25 grand a month. That's if it's outsourced.

If you're trying to do it yourself and a hundred person company, you can easily be spending a hundred grand a month. It's expensive to do. They'll look at it and say, okay, this is going to cost us a million dollars a year, odds are, it'll be two years, maybe three before we're hacked. That's this statistic, although you're rolling the dice, it might be tomorrow that you get hacked. $3 million versus our fines are going to be about a million dollars. We'll just take the fine.

That to me is just disgusting. How can these people live with themselves? I don't know. Maybe it's just me. I'm going crazy.

That leads us to this New York Times article I was talking about on the radio this week. The New York Times article talking about how the United States, really, we are losing control of information warfare. Our warriors have been working at the national security agency and the FBI. They leave those agencies and go to work for private contractors. The tools that we've been using to hack other people have been stolen. The tools that we're paying to be developed, we meaning the US taxpayer, the tools that we have paid to develop aren't even being used, and that mega attack I was just talking about. That's an example of one of these attacks that would have been stopped had we been using the tools that the federal government paid for. It's just crazy. What's going on?

So here's the bottom line, everybody you can't trust most of these vendors that are out there. They have a product to sell. They don't have the best solution for you, right? They really don't. If they cared about you they would not be selling you antivirus software because it does not work.

If Microsoft cared about you, they would have come out with their anti-malware stuff. Windows defender, years and years ago. They would have redesigned Microsoft Office and Microsoft Windows, as well, because those were huge security holes.

Look at Adobe. They've been the source of the most security problems of anything out on the market, bar none. Flash was terrible. Java, another example of something that's been a terrible security hole for years. These businesses are trying to get a product to market as quickly and as inexpensively as possible. Quick is usually the number one goal. It has to be inexpensive for them to develop it. That means now they go out and they sell it because they got it. They're going to sell it. It doesn't matter if it's good. It doesn't matter if it even works overall for you.

That's why I'm doing these courses, these classes, these emails, I'm recording special stuff for you each week. I've got special emails that are going out for you each week.

We've got these radio show podcasts. This stuff is all free. All of it.

Now I charge for some courses, but everything else is absolutely free. Now I hope I have some clients that come from some of this stuff and I do get them, but most of the clients I get are by referrals.

I really believe in this. I'm putting my time, my money, my energy where my mouth is. But you have to take a step. You have to go to Craig peterson.com and you have to sign up right there. Craig peterson.com. Scroll down to the bottom of this screen. You'll see a little signup thing and I will start sending you my weekly newsletter.

Some of these little micro training that only take you a few minutes and information on courses and more. Craig peterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-555

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. We began talking about Facial Recognition and some of the drawbacks and the rush to use it when it has not been thoroughly tested and vetted. Then we talked about the reasons for the shortage of Gaming Consoles and other computing equipment. Finally, we got to how we are losing the war against hackers and why. Here we go with Matt.

And more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, Mr. Matt Gagnon and I got into a few things, including why you just can't find some of these game computers out there anymore. Facial recognition, some more warnings about the future here, frankly. Also, what the United States is doing to help protect itself, and the short answer is not much. So here we go with Mr. Matt Gagnon.

Matt Gagnon: [00:00:26] It's Wednesday morning. Thanks so much for listening. We've got Craig Peterson with us right now, as he always is at this time on Wednesdays. He's given us all the technology news we could possibly dream of. Thanks a lot for coming on. Craig, and how are you this morning, sir.

Craig Peterson: [00:00:39] Hey, Oui c'est un bon matin

Matt Gagnon: [00:00:42] Oh God, don't speak French to me. We're going to lose people if we do that.

Craig Peterson: [00:00:46] Going well, my schooling was all in French schools entirely. I didn't, which as a second language, not too bad today.

Matt Gagnon: [00:00:53] Yeah. I was reasonably fluent back in high school and 20 years later, not so much anymore, unfortunately.

Craig Peterson: [00:01:03] Yeah.

Matt Gagnon: [00:01:03] Craig getting into the actual topics of the day, though. One of the interesting things that we have seen in the last 10 years or so in the world is the development of this facial recognition software.

I remember back in the day when Facebook actually came out with their first algorithm that started doing this. I don't know if you remember this where they would even start to like auto-tag your pictures. This must have been like six or seven years ago. It started to do that. That was my first. I think that was my first indication that, Oh, the future's coming.

They're just going to start doing facial recognition. And they know who I am at pretty much at all times. Anyway, a lot of people got creeped out by that. And now, many, I think, are wondering whether or not there's your facial recognition. Your photos are being used out there for this type of software here. So if people are a little bit interested in, shall we say whether or not. They've been exposed to the world like this. What do they do?

Craig Peterson: [00:01:53] Yeah, this is a difficult thing, frankly, but the easiest thing to do to find out if some of your pictures have been taken online, if you have a picture you're specifically wondering about, you can just go to Google images and upload your picture or give it a link to your picture, and it'll tell you where it can find it online.

There've been people who've been driving down the highway and saw their picture on a billboard. It's gotten that bad. Of course, now we know Clearview AI and other companies have been harvesting pictures, quite literally stealing them on websites. Then using that information out to sell your location and who you are just based on your face. It's like minority report, right? Pass that billboard and say hello, Mr. That's where we're going. So that's one way you can do it. There's also a really cool site called exposing.ai.

exposing.ai. You can go online.

Flicker, which is a site that we use to upload pictures to. A lot of people did. It's a great place to share your photos, right? And they have, of course, now being sold two or three times, maybe more over the years and millions of their photos are now online, are now being used by who knows who to promote, who knows what, or to track you down.

China and Russia are apparently are using these photos as well. So if you go to exposing.ai, you can just type in your flicker user name, and it'll do a search and tell you where your photos are found. Now, of course, flicker was very popular at one point because it would help organize the photos, as you talked about here? Probably about six, eight years ago. They started doing recognition of photos.

Think about what we're doing today. We're giving our photos to Amazon photos. But we're putting them in Apple I photo. We're putting them still up on all of these websites. What's going to happen in a few years when those companies decide to do more with them?

Now we know Apple has a commitment to keeping them private, but we also know Google has a commitment to making money off of anything they can get from us. So these AIs' artificial intelligence are learning more and more. The tags we already put onto photos are being used by Google to make their programs better as they try and track as more and more.

Matt Gagnon: [00:04:29] Talking to Craig Peterson, you hear him on this very station on Saturdays at one o'clock going over all these topics and so much more. He joins us now, of course, to go over technology topics.

Craig, my son, asked me for a PlayStation five for Christmas, and I laughed at him and told him that was not going to happen. Although I did make one attempt. I will admit. I made one attempt to maybe try to see if I could snag one. I think a Walmart or something had opened up an online thing, like at 8:00 PM. I got on at 7:59 PM and tried, but the site crashed. I had no chance of getting one then. That was when I basically said, we'll just get one later, if at all.

But a lot of people are blaming scalpers. Like people who ended up picking them up, they found some way of winning the lottery, and they got one, and now we're selling them for Three grand or something. A lot of people are blaming them for the supply problem because you still can't get one right now. That's not really the real reason why you can't get one. What is?

Craig Peterson: [00:05:22] The real reason is who needs anything more than Donkey Kong on your original Nintendo 64.

Matt Gagnon: [00:05:29] Absolutely.

Craig Peterson: [00:05:30] Yeah. Exactly.

Matt Gagnon: [00:05:31] See some of the things that I bought on both my PlayStation and the old WiiU and everything else. I got a ton of nostalgic games from back in the day.

Craig Peterson: [00:05:39] It is really quite an industry, and you can play so many of them now on your phones and other devices. But the real reason actually is industry-wide in the computer industry. Right now, we're having trouble getting our hands on some of these chips that are major components for computers and gaming systems.

That's what happened here around Christmas time. If you wanted to buy one of these things, it was almost impossible, and it isn't just the PlayStation. Of course, it's the X-Box and, as I said, computers like laptops, et cetera.

I'm looking at a graph right now from eBay and prices that these Xboxes were selling for and the PlayStations. There's just a huge jump. Of course, the main reason for the shortage of the chips has to do with the lockdown.

Many companies decided we're probably not going to sell as much inventory as we expected, so they cut back their orders. Remember, these orders are made months in advance. Of course, the opposite was true. People were locked down, and they played more video games. They needed more computers to work from home. Those two waves hit together, and we got this huge tsunami of prices on them. All kinds of computer equipment. That's what's happened. It's not permanent. They are ramping up. The orders are back up. I suspect they'll have a bit of a glut here in a couple of months.

Matt Gagnon: [00:07:08] And Craig, before I let you go, I have one final question to ask you. It's perhaps the question of the hour. The question of the day, the question of the century. Has the United States lost the battle against hackers?

Craig Peterson: [00:07:18] Oh my gosh. Yeah. I'm going to talk about that this weekend on Saturday at one. I'm going to talk about it next weekend too. This is a very deep subject because we see now major warfare going on. There is an article in the New York Times that I'll be putting in my newsletter this week. That talks about what happens.

We've got ISIS out there. They've laid siege and back to Mosel, Tikrit, and many other places. We had a Michelle Obama. Her team over there going into the middle East. We have just all kinds of people from our secretary of state, through the president that's gone over there. We've been very concerned about them physically. That makes a ton of sense.

The other side of this has to do with computer security. We are not taking it seriously enough. Look what happened this week. We had a water treatment plant in Florida that was hacked remotely, and the hackers increased dramatically the amount of lye that was being added to the water. Now that is something that should never be able to happen, but it's because we just don't seem to care.

Even this massive SolarWinds attack that happened, Matt. We spent, the United States taxpayer, millions of dollars to have the software developed to help protect these systems that would have been protected if we had been using the software.

Our government agencies have been hacked. Our businesses have been hacked. We're getting hacked. Our power plants, our water plants are getting hacked.

You know what. We're hardly doing anything about it.

Matt Gagnon: [00:09:09] That's been Craig Peterson, our tech guru, as he mentioned, Saturday one, o'clock tune in for more information on what you just heard and so much more.

Craig, appreciate it as always. We will talk to you again next week, sir.

Craig Peterson: [00:09:20] Take care, Mr. Matt.

Cut them off there. By the way, I am editing right now, the final edits on the last five or six. I think it is videos as part of our Improving Windows Security course. Yay.

Finally, gonna have that done. It is phenomenal. I think anyway, and we've been doing a lot to try and help you guys out.

So keep your eye on your email box, and we will talk again.

We'll be back, of course, for our weekend podcasts. Oh, and by the way, I have six or eight stations now on the weekend that I am carrying my radio show, which is really cool. We are getting the word out it's because of you guys, you recommending people pay attention to all of these points I'm bringing up and having them sign up for email list and listening on podcasts and, of course, also on these radio stations.

So thank you. Very much everybody. We are going to stop those bad guys, and we're going to do it together.

Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a couple of interesting topics, but we started off with the new James Bond movie and why they are re-shooting some of the scenes. We talked about our arrogance and why we may lose the war against hacking. Then we discussed an infrastructure hack against a water plant here in the US. Then we talked about how President Biden has responded to the SolarWinds hack and why that response may create a huge problem. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] All of those tools went online. Now all of a sudden, we're getting hacked by our own tools that were developed by us to hack them. They're them in this are getting smarter and smarter.

Good morning, everybody on with Mr. Polito this morning, we talked a little bit about movies and the new Daniel Craig, James Bond that might come out sometime within the next five years.

But we also went into this really interesting article over in the New York Times. It's titled how the United States lost to hackers. We get into that, and what can you do? What should you be doing in order to help prevent them from getting you as well? So here we go with Mr. Polito.

Jim Polito: [00:00:46] Welcome back. Here he is. It's just one of our most popular guests. He is the Tech-Talk guru, and he's just a wealth of information. For our new listeners in Rhode Island, Craig Peterson actually wrote code for the internet that is still in use today. Unlike Al Gore, he has proof that he invented the internet. Joining us now the Superman of the internet because he's also fighting for truth, justice, and the American way.

Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:22] Morning, did you notice you must-have? They removed and the American way from his last movie so that it would play well in China.

Jim Polito: [00:01:30] Come on, doc, Craig, please. I know you listened to the show, please. Don't get me started on China again.

I just want to talk right now. They do all of that, Disney, all of them, and they all, except for Fox, every major news organization in this country, has an affiliation with an entertainment organization that wants to sell products in China. Yes,

Craig Peterson: [00:01:57] Look at the newest Mulan. Not only filmed in China, but went through Chinese editors, and they had to change things in it.

Oh, Bond, the new Bond movie. Did you hear about this one? First of all, I'm so excited about it. I didn't think I'd like Daniel Craig, but I ended up liking Daniel Craig. They are reshooting parts of that movie right now.

Jim Polito: [00:02:17] What? Because it's so, they can sell it in China because it's offending the Chinese censors.

Craig Peterson: [00:02:22] You got one word, right? Sell. Do you know product placement is how these movie guys make a lot of their money? They shot this thing. What now? Two years, three years ago. And the problem they found is the sponsors were all upset because they delayed it again. It was going to come up like May, and now it's going to come out in the fall. So they are reshooting scenes for product placement for the newest versions of the products because the ones that are in the movie are like old hat now.

Jim Polito: [00:02:55] Yeah, look, here's the thing. I thought Sean Connery was the best, and I still think he is the best, but Daniel Craig is close. From the very beginning, this is one of my few luxury indulgences. I have a Rolex watch. It is the Oh God, and I can't even think of the this is COVID brain. It's the, no, not a submariner. Thank you, Danny. It's the submariner black-faced one. Oh, I do have it. The black-faced submariner. That is the one that Sean Connery wore cause I always loved that watch.

I've had it for over 20 years. Anyway, they switched to Omega, remember. You know Rolex didn't need the sponsorship. Omega said we want to be the official watch of James Bond. There you go, Omega is now the watch.

When people see a movie, did you ever notice when somebody takes a drink? That the label is perfectly pointed toward the camera. Like all that stuff, bologna. Listen, I make my money off of advertising, too, so I can't complain.

I can't believe they're doing all that for product placement. So you have the latest version of the product.

Craig Peterson: [00:04:04] Yeah. It's not like you're listening to Jim Polito and Jim says, Hey, listen, I have these guys out and do this for me, and I love this product, and then you run advertisements versus let's have a cold one and the out come's the latest famous beer or something anyways.

Jim Polito: [00:04:21] Yeah. Suppose James Bond is drinking spiked seltzer. It's over for me with Bond. If he's drinking, if they're reshooting this so that he can, I have a bud light spiked lemonade. It's done. It is over.

It's shaken, not stirred. Hey, while I got you. Tech Talk guru and see, as I said, folks, Craig Peterson is a plethora of this kind of information.

Talk to me about we are really losing the hacking war? You sent me some material. As I read through it, it made me nervous because the stuff that you sent me is implying that we're losing the hacking war. I don't want to hear that's like losing the space race. That's like losing the nuclear weapons race or like having a missile gap, as John F. Kennedy said. Is that true?

Craig Peterson: [00:05:14] Yeah, it is actually. Now that November 6th as the path of the New York times is coming out and talking about this, in a different way. But what they're saying, and this is just, I love this article by Nicole peroxide and what she's talking about is how we as a nation now, and particularly as a government, really have too much hubris over cyber warfare. That's what it really is. We've talked before about how we are already in world war three. It is a cyberwar where they're sending things out.

Just this last week, we had a water plant here in the United States. It was taken control of by a remote hacker. Now you think about water purification plants, and there's nasty stuff in there. For instance, in this case, basically lye, right? Think of lye and how nasty that is, but all of the chemicals compounds are involved. Yeah.

The hackers got in and dramatically increased the amount of lye going into the water supply in that water plant that fed the whole town.

Now the good news here is that somebody noticed, how come we're using so much lye? They shut it down almost immediately, which is really good. Enemies are out there. You mentioned China already. And, of course, we've got North Korea involved. Vietnam's now involved. Russia is involved, but they want to be able to control the US to hold us hostage, just much the same way. Ransomware is holding businesses hostage.

We've been so busy over the years, hacking them that we haven't paid enough attention in the US to protecting ourselves.

In this article, she goes into a discussion she had with a former NSA contractor, many of these guys and gals like the blackwaters' of the world. These third-party companies will do hacking on behalf of the government. She was talking to some of these people and what they were doing.

We only recently found out about the hacking of the American citizens that was going on when all of these tools that the national security agency was using to hack foreign powers and apparently hack us to, and at least in some cases, all of those tools went online. Now all of a sudden, we're getting hacked by our own tools that were developed by us to hack them.

The them in this are getting smarter, and we're just sitting there. That's why I am so adamant that people get on my email list because we're doing training. I've got brand new emails we're putting together now. It's literally a year-long series where every week you get a little bit of training on different parts of this because our businesses are not taking this seriously.

That's the hubris. Our government's not taking this seriously. The Solarwinds attack that happened. We already, as US taxpayers, funded the development of a system, millions of dollars that would have stopped this problem, and it wasn't in use. Okay.

We're not taking it seriously on any level. The same thing's true with us as individuals. Now I understand individuals, right? This stuff is confusing. What should I get? What should I buy? We've had discussions about what kind of firewalls should you have? Don't use these paid VPN's.

I've done all kinds of free training on that for people, but we're not. Taking it seriously. And I'm looking at what the Biden administration is doing and planning on doing right now. I don't think any of it's going to make it any better. And yes, right now, we have pretty much lost this battle in this war, but I think we can pull up our socks as time goes forward.

But again, there's just no real incentive.

Jim Polito: [00:09:29] I was glad to hear you end on that note because already I had crawled under the table while you were going on. I kept my headphones on so I could still hear.

So is there any difference now, or is it too early to tell in the way that the previous administration under Trump and now the current administration under Biden is dealing with this?

Craig Peterson: [00:09:52] It's still a little bit too early. There's been a ton of saber-rattling by our President. Who's been out there saying we got hacked, the Solarwinds hack. We're gonna attack back. This is basically asymmetric warfare. This is not something where you can easily identify who it was and then drop a missile down their chimney as we did with Kadafi. This is much more complicated, much more difficult.

I'm afraid having a President like Joe Biden when he's saying we're going to attack back. We're going to retaliate, I think were his actual words. It really worries me because that's the sort of thing that could get us into a full-scale cyberwar and maybe even a hot war.

Jim Polito: [00:10:38] Oh boy. I think we're going to wrap it up right about there.

Craig, it was much better when we were talking about the upcoming Bond movie, which I, too, like you, am looking forward to. I'm a big Daniel Craig fan. I think he does a great job with Bond.

Craig, you were talking earlier about why it's so important, and folks should get on board with you.

How do folks get on board with you?

Craig Peterson: [00:11:02] Yeah, absolutely. I am not a big marketer at all. In fact, that's probably one of my biggest failings. I've done work, as we've mentioned for NASA, the FBI, you name it in pretty much every Fortune 100 companies, right?

But it's the individuals that are having problems at the small office, home office, the small businesses. Those are whom I'm helping.

Make sure you go right now to Craig peterson.com/subscribe because we're probably starting this next week. I'm thinking more training. More stuff. Just some simple stuff that you can do in a matter of a few minutes. The only way you'll be able to get that is if I had the email and you got to sign up, Craig peterson.com/subscribe.

Jim Polito: [00:11:47] All right, Craig is usual. Excellent work. Always a pleasure. And we'll catch up with you next week.

Craig Peterson: [00:11:54] Hey, thanks. Take care, Jim.

Jim Polito: [00:11:55] You too, Craig Peterson, great guy, and if you want to hear that again, we likely will podcast it, and you can get to that podcast on the website of the station. You're listening to now just go to the Jim Polito show. A final word, actually, a web poll and a final word when we return. You're listening to the Jim Polito show your safe space.

The Jim Polito show feels free to laugh, cry, or simply enjoy by screaming out. We don't want to tell you how to do it.

Craig Peterson: [00:12:22] I had to play that last part because what are you kidding me? Anyhow. Thanks for being with me today. I am dead serious. We are doing a whole bunch of training. That's going to be really phenomenal. I think. I think for pretty much everybody, it covers a bunch of different things, but I assume since you're on my podcast, you're already on my email list.

If you're not, you now know how to get on.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about some of the misguided legislation being pushed by Amy Klobacher regarding big tech with her regulatory solution to anti-trust. Then we got into Facial recognition and expose.ai. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Now we also see that many other companies have entered into that marketplace without our permission to use our faces. So if you want to check right now, this is a great thing that the New York Times did. They have exposed this a little bit, but go to exposing.ai. Senator Amy Klobuchar has introduced some legislation to try and hold big tech a little bit more accountable.

I'm afraid I have to disagree with her approach. Also, we talked about an article in New York about facial recognition and some of the things we're doing that we probably shouldn't be doing. So here we go with Mr. Chris Ryan.

Chris Ryan: [00:00:44] Joining us right now in the program is Craig Peterson from Tech Talk you hear on Saturdays at 11:30 AM. Craig, how are you?

Craig Peterson: [00:00:52] Hey, good morning. Doing well

Chris Ryan: [00:00:54] Appreciate you joining us for the show.

I want to talk to you a little about some of the legislation I was reading from Amy Klobuchar, as she looks to get anti-trust legislation to take away some of the security of entities like Facebook and other large tech companies. It doesn't appear there's a tremendous amount of appetite for this type of antitrust legislation at this point. In your view, does there need to be a look at this?

Craig Peterson: [00:01:22] Yeah, there's two different sides to this whole anti-trust activity. Of course, it had started way back in the 18 hundreds. Then you had all of these massive barrons, and they wanted to stop them from controlling the economy effectively is what they were doing at the time.

Now we're looking at these almost oligarchs. We've got these people running these huge corporations like Facebook and Google, and Amazon, although there's been a bit of a shakeup at Amazon. Those guys and gals have an incredible amount of market power. That's one side of it. We understand that because if there's no competition, we're not going to be able to get a good value for our dollar.

The other side of that is how about if there's really only one buyer for your goods? You've got the one side where there's only one seller of particular interest, but what if there's one buyer. We see that more and more, particularly with companies like Amazon.

People complained about Walmart with that years ago. When Walmart just had such a monopoly and frankly still does in many cases. Walmart beats their suppliers over the head and shoulders to get the price down to a point where the supplier basically can't support it anymore.

What we're looking at now is a situation we haven't had in a long time. She's looking at having more and more regulations, adding more regulators to the various entities and the federal government that regulate business.

I look at this as saying I've had so many friends who have been destroyed their businesses that are destroyed by these big tech companies and their market manipulation to drive competitors out of business. That really bothers me.

I see a real big problem here because we do not allow the big guys to fail anymore. There's this concept of too big to fail. When we're talking about a free market, the idea is, if you want to buy some other companies, knock yourself out, but you're going to reach a point where you are not going to be able to afford to survive anymore. We've seen that many times look at the car industry.

We've seen bailouts now twice of Chrysler in my life as well as GM. There are serious problems with having more and more regulations because it will make it difficult for more competition to enter the market. That could potentially drive these big guys out of business. That's where I really start getting concerned.

Chris Ryan: [00:03:59] We focus a lot here in this segment about how, whether it's Facebook or other social media mechanisms and the usage of our phones as well, that we're spying on ourselves. It's a fascinating article in the New York Times last week. Actually, I think it was the weekend before, about facial recognition systems being used on our phones. What are they, and how are they used?

Craig Peterson: [00:04:21] There are a few companies out there you've probably heard of. I've talked about Clearview before, which is this clearview.ai company. This computer vision for a safer world. I love the way they put this. Actually couldn't have written it any better.

Clearview has raped all of our pictures on the internet. What that means is any publicly available picture, Clearview downloaded and started to look at. We also see that many other companies have entered into that marketplace without our permission to use our faces.

If you want to check right now, and this is a great thing that the New York times did, they've exposed this a little bit, but go to exposing.ai. Online, exposing.ai as artificial intelligence. It'll let you check to see if the photos you uploaded to flicker are now being sold and used online.

Our faces. We are uploading our Pictures. We're getting these free photo services, but all your photos on flicker, back in the day, nowadays upload them to Amazon photos or Google photos or Apple photos.

We know Apple does not make money off of our personal information. Google sure does and so do some of these others. If you go to exposing.ai, you can type in your flicker username or a photo URL that it'll compare. It'll show you if they're using the pictures that you posted for facial recognition systems.

This is where we're starting to see arrests coming out of Washington, DC. Where they are scanning the internet for photos or using companies like Clearview and others. We even have had the FBI issue, a legal document here. I don't remember exactly how far I got along the line. The FBI using a big photo that they found online that had been doctored.

Is your face online? Are they using it for nefarious purposes? Like this guy who ended up getting charged by the FBI for this January in Washington, DC, and he had nothing to do with it.

Chris Ryan: [00:06:39] Craig, as always appreciate you joining us for the show. I look forward to chatting again next week.

Craig Peterson: [00:06:43] All right. Take care. Chris.

Chris Ryan: [00:06:44] Craig Peterson, joining us here in New Hampshire today from Tech Talk. You hear at Saturday's on news radio 610 and 96.7 at 11:30 AM.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

It is another busy week on the technology front. We delve into the Military's use of drones and AI. We will discuss why Facebook thinks Apple has declared war. Ransomware is up. It turns out that many of those who were victims of the SolarWinds hack did not use their software. They were breached because they had misconfiguration. Well, just a taste of today's topics, and there is even more, so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Drone Swarms Are Getting Too Fast For Humans To Fight, U.S. General Warns

Building Your Personal Privacy Risk Tolerance Profile

Breach Data Highlights a Pivot to Orgs Over Individuals

Facebook “Supreme Court” overrules company in 4 of its first 5 decisions

State reps try to ban Comcast data cap and price hikes until pandemic is over

Every crazy thing that happened in Apple and Facebook’s privacy feud today

30% of “SolarWinds hack” victims didn’t actually use SolarWinds

Ransomware Payoffs Surge by 311% to Nearly $350 Million

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hi everybody. Of course, Craig Peterson here. We're going to talk today about these drone swarms, your personal privacy risk tolerance breach highlights here over org's not individuals. What's going on? Ransomware is way up.

As usual, a lot to talk about. Hey, if you miss part of my show, you can always go online to Craig peterson.com. You'll find it there if you're a YouTube fan CraigPeterson.com/youtube.

This is really an interesting time to be alive. Is that a good way to put it right? There used to be a curse "May you live in interesting times" Least that was the rumor.

One of the listeners pointed this out, there was a TV show that was on about five years ago, apparently, and it used this as a premise. I also saw a great movie that used this as a premise, and it was where the President was under attack. He was under attack by drones.

The Biden administration has a policy now where they're calling for research into artificial intelligence, think the Terminator, where you can have these fighting machines.

These things should be outlawed, but I also understand the other side where if we don't have that tech and our enemies end up having that tech, we are left at a major disadvantage.

Don't get me wrong here. I just don't like the idea of anybody doing Terminators, Skynet type of technology. They have called for it to be investigated.

What we're talking about right now are the drone swarms. Have you seen some of these really cool drones that these people called influencers? Man, the term always bothers me. So many people don't know what they're doing. They just make these silly videos that people watch, and then they make millions, tens of millions. I guess it's not silly after all.

These influencers make these videos. There are drones that they can use if they're out hiking, you might've noticed, or mountain biking or climbing. They have drones now that will follow them around automatically. They are on camera. It's following them. It focuses on their face. They can make the drone get a little closer or further away. As long as the sky is clear, there's no tree branches or anything in the way that drone is going to be able to follow them, see what they're doing and just really do some amazing shots. I've been just stunned by how good they are.

Those drones are using a form of artificial intelligence, and I'm not going to really get into it right now, but there are differences between machine learning and artificial intelligence, but at the very least here, it's able to track their faces.

Now, this is where I start getting really concerned. That's one thing. But they are apparently, right now, training. When I say they, the Chinese and probably us, too, are designing drones that not only have cameras on them but are military drones. They have without them having to have a central computer system controlling them or figuring out targets. They're able to figure out where there's a human and take them out.

These small drones, they're not going to take them out by firing a 50 caliber round at them. These drones can't carry that kind of firepower. It's just too heavy, the barrels and everything else -- it's a part of that type of a firearm. We're talking about small drones again. So obviously, they're not going to have a missile on them either.

What they do is they put a small amount, just a fraction of an ounce, of high explosives on the drone. The idea is if that drone crashes into you and sets off its explosives, you're dead, particularly if it crashes into and sets off explosives right there by your head. Now that's pretty bad when you get down to it.

I don't like the whole Skynet Terminator part of this, which is that the drones are able to find that human and then kill them.

Think of a simple scenario where there is, let's say there's a war going on. Let's use the worst-case scenario and, enemy troops are located approximately here. You send the drones out, and the drone has, of course, GPS built into it, or some other inertial guidance system or something in case GPS gets jammed.

That drone then goes to that area.

It can recognize humans, and it says, Oh, there's a human, and it goes and kills the human. Now that human might be an innocent person. Look at all of the problems we've had with our aerial drones, the manually controlled ones, just the ones that we've been using in the last 10 years where we say, okay, there's a terrorist here. Now they fly it in from. They've got somebody controlling it in Nevada or wherever it might be, and they get their strike orders and their kill orders. They go in, and they'd take it out. There are collateral damages. Now that's always been true.

Every war.

Look at Jimmy Stewart. For example, younger kids probably don't know who it is. Mr. Smith Goes to Washington was one of his movies. He had some great Christmas movies and stuff too. Anyhow, Jimmy Stewart was a bomber. I think he was a pilot actually in World War II. He flew combat missions over Germany. Think of what we did in Germany, in Japan, where we killed thousands, tens of thousands, hundreds, probably of thousands of civilians.

We now think, Oh, we're much better than that. We don't do that anymore. We're careful about civilian casualties. Sometimes to the point where some of our people end up getting in harm's way and killed. For the most part, we try and keep it down.

A drone like this that goes into an area, even if it's a confined area, and we say, kill any humans in this area, there are going to be innocent casualties. It might even be "friendly fire." You might even be taking out some of your own people.

They've said, okay, we've got a way around this. What we're going to do is we're going to use artificial intelligence. The drone doesn't just pick out, Oh, this is a human. I'm going to attack that person. It looks at the uniform. It looks at the helmet. It determines which side they're on. If they're wearing an American or Chinese uniform, whatever, it might be programmed for it again. It goes into the area, it finds a human and identifies them as the enemy. Then it goes in and hits them and blows up, killing that person. That's one way that they are looking to use drones.

The other way is pretty scary. It's, you can defend yourself against a drone, like that. You've got a drone coming. You're probably going to be able to hear it. Obviously, it depends. That drone gets close. I don't know if you've ever had the kids playing with drones, flying them around you, or you've done the same thing. You can always hit it out of the air, can't you?

If you're military and you have a rifle in your arm, you can just use the rifle and play a little baseball with that drone. There's some interesting stories of people who've been doing that already.

What happens if we're not talking about a drone, we're talking about a drone swarm. I don't know that you could defend against something like that. There have been studies that have been done. So think, you think there nobody's really working this suit? No, they sure are.

What's going to happen? Well, the Indian army is one that has admitted to doing tests, and they had a swarm of 75 drones. If you have 75 drones coming after you, let's say you're a high-value target. There is no way you're going to be able to defend yourself against them unless you can duck and cover, and they can't get anywhere near you with their high explosives. The Indian army had these Kamikaze-attack drones. They don't necessarily have to even have high explosives on them.

This is a new interpretation under Joseph Biden. Mr. President of the Pentagon's rules of use of autonomous weapons. We've always had to have "meaningful human control." That's the wording that the Pentagon uses meaningful human control over any lethal system. Now that could be in a supervisory role rather than direct control. So they call it "human on the loop" rather than "human in the loop." But this is very difficult to fight against.

The US army is spending now billions of dollars on new air defense vehicles. These air defense vehicles have cannons, two types of missiles, jammers. They're also looking at lasers and interceptor drones, so they can use the right weapon against the right target at the right time.

That's going to be absolutely vital here because it's so cheap to use a drone. Look what happened. What was a year plus ago now? I'm trying to remember, Central America, Venezuela, somewhere in there where El Presidente for life was up giving a speech. I'm sorry. I didn't mean that to be insulting, but that often is what ends up happening. A drone comes up, and everybody's thinking: Oh, it's a camera drone, wave to the camera thing. It got very close to the President and then blew up. On purpose, right? They were trying to murder the president. That's a bad thing. He was okay. I guess some of the people got minor injuries, relatively speaking.

When we're looking at having large numbers of incoming threats, not just one drone, but many drones, many of those drones may be decoys.

How cheap is it to buy one of these drones? Just like the ones that were used in China over the Olympic stadium, where they were all controlled by a computer. You just have these things, decoys. All you need is a few of them that can blow up and kill the people you want to kill very concerning if you ask me.

We're paying attention to this, as are other countries as they're going forward.

We're going to talk about building your privacy risk tolerance profile because if you're going to defend yourself, you have to know what you're going to defend against and how much defense do you need?

Hey, we take risks every day. We take risks when we're going online. But we're still getting out of bed. We're still going into the bathroom. We're still driving cars. How about your online privacy risk tolerance? What is it?

Hi everybody. Thanks for joining me.

We all take risks, and it's just part of life. You breathe in air, which you need. You're taking the risk of catching a cold or the flu, or maybe of having some toxic material inhaled. We just don't know, do we?

Well, on any given day, when we go online, we're also facing risks. And the biggest question I have with clients when I'm bringing businesses on or high-value individuals who need to protect themselves and their information is: okay... what information do you have that you want to try and protect? And what is your personal privacy risk tolerance? So we build a bit of her profile from that, and you guys are going to get the advantage of doing that right now without having to pay me, my team. How's that for simple?

First of all, we got to understand that nothing is ever completely safe. When you're going online, you are facing real risks, and no matter what people tell you, there is no way to be a hundred percent sure that your data is going to be safe online or that your individual personal, private information is going to be safe while you're online. And there's a few reasons for this.

The most obvious one, and the one we think about, I think the most has to do with advertising. There are a lot of marketers out there that want to send a message to us at exactly the right time. The right message, too, obviously? So how can they do that? They do that by tracking you via Google. So Google that's their whole business model to know everything they can about you and then sell that information.

Facebook, same thing. Both of those companies are trying to gather your information. They're doing it when you are not just on their sites, but when you are on other people's sites. Third-party sites are tracking you. In fact, if you go to my website @ craigpeterson.com, you'll see that I do set a Facebook cookie. So I know that you're on Facebook and you visited my site, and you might be interested in this or that.

Now I'm not a good marketer. Because I'm not using that information for anything, at least not right now, hopefully in the future, we'll start to do some stuff. But that's what they're doing. And the reason why I don't think it's a terrible thing don't know about you.

I don't think it's bad that they know that I'm trying to go ahead and buy a car right now. Because if I'm trying to buy a car, I want advertisements about cars and I don't want to advertisements about the latest Bugatti or Ferrari, whatever it might be. I want a Ford truck, right? Just simple something I can haul stuff around. You already know I have a small farm, and I need a truck because you need one. I'd love to have a front loader and everything too. Those costs money, and I ain't got it. So that makes sense to me.

And now there's the other side, which is the criminal side. And then there's really a third side, which is the government side.

So let's go with the government side here. In the United States, our government is not supposed to track us. Now I say "supposed to," because we have found out through Edward Snowden and many other means that they have been tracking us against the law. And then they put in some laws to let them do some of it, but our government has been tracking us.

And one of the ways it tracks us is through the "five eyes" program, and now that's been expanded and then expanded again. But the five eyes program is where the United States asks the United Kingdom. Hey, listen. Hey bro. Hey, we can't, and we're not allowed to track our citizens, but you not us. How about we have you track Trump and his team? Yeah, that's what we'll do.

So there's an example of what evidence is showing has happened. So they go to a third-party country that's part of this agreement,d where all of these countries have gotten together, how signed papers and said, yeah, we'll track each other citizens for each other.

And that way, the United States could say, Hey, we're not tracking you. And yet they're tracking because they're going to a third-party country. And the United States, if you are going out of the country, then again, they can track you. Any communications are going out of the country. So that's the government side.

And then, of course, there's governments that track everything. You look at China and how they control all of the media. They control all of the social networking sites. They basically control everything out there.

We have to be careful with all of that stuff because it can and will be used. And we've seen it has been used to really not just harass people, but do things like throwing them in prison disappear them. Look at what just happened in China, with the head of China's biggest company, basically the Amazon competitor over there. And he disappeared for months and then came back, just praising the Chinese Communist government and how great it is to have all of these people over there. Just telling them what to do and how to do it.

We obviously don't live in China. We obviously, I think, have oligarchs nowadays. We have people who are rich, who are running the country. They're giving money to campaigns. They get the ear. You have seen all of the bribery allegations against the Biden crime family, or his brother, his son, other members, himself as well, based on a hundred Biden's laptop.

So I don't trust the government for those very reasons.

The hackers, let's get into the hackers here. When it comes to hackers, there are, again, a few different types. You've got hackers that are working for governments. And what they're doing is in the case of a small government, like North Korea, they're trying to get their hands on foreign currencies so that they can use those currencies to buy grain, to buy oil, coal, whatever it is they might need to buy.

You have governments like China and Russia that are trying to basically run World War three. And they're out there with their hacking teams and groups and trying to figure out how do we get into the critical infrastructure in the United States? Okay. So this is how we get in. Okay. We're in over there. So if we ever want to shut down all of the power to New York City, this is what we do.

Now, remember, that's what happened back in, in when was that 2004, I guess that was, yeah. I remember I was down in, I was heading actually to New York City and then all of a sudden, all of the power went out.

That apparently was an accident, but it didn't need to be an accident. There are all kinds of allegations about what actually happened there. But that's why China and Russia are trying to get into our systems. And then they obviously want to play havoc. Look at the havoc that was caused in the US economy by this China virus that came obviously from China for Huan. If they wanted to shut down our economy, they now have proof that's all it takes. And they are working on the genetics of some of these viruses over there in China. And they're trying to modify the genes, and they are running experiments on their troops to enhance them, to make these super soldiers that maybe, need less sleep or less food are stronger or et cetera, et cetera, they are doing that.

So China is a real threat in just a number of different ways. What would it be like if they could shut down our banking system or make it, so we don't trust it anymore?

Okay. That's part one of your Personal Privacy Risk Tolerance Profile. Stick around because we're going to talk more about this and what you can do to help you have privacy.

What is your online personal privacy risk tolerance? It's going to vary. I help high-value individuals. I help businesses with this, and now I'm helping you as well. So let's get into part two.

Craig Peterson here.

When people ask me, what should I do? That is a very nuanced question. At least it's very nuanced to answer because you could say something like: if you want to be private, use Signal for messaging and use Tor for web browsing, that's fine. And it works in some ways and not in others. For instance, Tor is a web browser that is like a super VPN. It is set up so that you're not just coming from one exit point, you're coming from a whole bunch of different points on the internet. So it's hard to track you down. The problem, however, with Tor is the same problem that you have with VPN services. And I talk about this all the time.

VPN services do not make your data secure. It does not keep it private. And in the case of VPN services that you might get for free or even buy, and also the case with Tor. Using those VPN services that can make you less secure again. Why did Sutton rob banks? He robbed banks because that's where the money was, where he is a bad guy going to go. If they want easy and quick access to lots of peoples. Private information?

They're going to hack a VPN server aren't they? Yeah. And if they can't hack the VPN server, why not just have server space in the same data center that VPN provider is renting their space from and then hack it from there, try and get in from there. Or maybe get into the service; the data centers will logs or the VPN servers logs, because even when they say they don't log, they all log, they have to log, they have to have your information otherwise, how can they bill you? And the ones that say we don't log, which are those people are "lieing" by the way. But those guys that have these VPN servers and they're trying not to log, they're trying not to log where you're going. They get fooled all of the time as well. Because their servers have logs, even if they're deleted and disappear.

So I just wanted to make it clear that you, I, if you have a low risk tolerance, when it comes to your privacy, Tor is not going to do it for you. VPN services are not going to do it for you. You have to look at all of the individual things you're doing online and then decide based on those. What is it that is the most. Beneficial for you in that particular case. Okay.

So Signal, I brought it up. So let's talk about it for a minute. Signal is the messaging app to use bar none. Signal is encrypted and do, and it is known to be highly secure, which again, Doesn't mean it's a hundred percent, but with Signal, you can talk to people on other platforms. You can have a Mac and talk to somebody on a, on an Android or a windows device.

But another consideration is who are you talking to? If you're talking to other people that have Macs and you don't want your information to get out, but you're not horrifically worried about it, right? You want it to be private. You want end to end encryption. You're better off using iMessage on your Mac.

If you're on Windows or Android, there are not any great built-in messaging apps. WhatsApp. If you listened last week and I've got it up on my website, WhatsApp is not great. They claim it's not horrible, but why would you use it if there's a question use Signal instead.

All right. So there's just a lot to consider when we're talking about it, but here is your big bang for the buck thing. That you can do. And that is use password manager. Now we talked about how Google Chromium Google's Chrome and of course now Microsoft edge. Actually it was the other way around Microsoft edge came up with it first and now Google's adding it.

But Edge has this password manager built-in. That's all well and good, but I don't know, trust those. I use a third party password manager that is designed for password management and that's all the company does. They're focused on the security behind it, which is why I recommend 1Password and lLastPass. 1Password being my absolute favorite. Use those password managers. That's the biggest bang for your buck if you have a low tolerance for your information, getting out. All right?

Now that will help to enforce good password habits. It will generate passwords for you, both of those, and it'll generate good passwords and it'll keep them for you, which is really great.

If you don't want to be tracked while you're browsing online, you can use an ad blocker. I have a couple of webinars I've done on that. If you want a video of one of those webinars to go through that talks about these different blockers ad blockers and others. I'd be glad to send you a link to one of them, but you're going to have to email Me@craigpeterson.com.

And I will send you a link to one of those webinars I did on that stuff. No problem. But some websites are going to break when you use an ad blocker. So sometimes you have to turn it off and you have to turn it back on. The ones I tell you how to use and how to configure, I actually show you a step-by-step we walked through it. Those allow you to turn off that particular ad blocker on an individual site that was broken because of the ad blocker. So pretty straightforward. You don't have to remember to turn it all on and all off. All right.

Now studies are showing that people are concerned about their privacy. In fact, I believe last I saw said that I think it was about 70% of Americans believe that their smart phones are being tracked by advertisers, and the tech companies provide them with the information. May, 2020 Pew research report talked about this, but 85% of consumers worry, they can trust corporations with their data. So what do you do? Because. Most people don't have the support or the tools. They don't have. I have the money, they didn't get a big inheritance. They're not a high value individual that needs my help and can afford it -- where we go through everything that they do and make sure they have the best solution for each thing, including banking, including going online and trading stocks, all of that stuff.

You gotta be very careful with all of that stuff. I'm really sad that I have to say this here, but there are no online privacy solutions that will work for everybody. And there are no solutions that work in every situation either.

So what you need to do is understand what you care the most about. And I think for all of us, what we should care the most about is our financial situation and anything associated with that: our intellectual property, if we're businesses, our bank accounts, all of that sort of stuff is stuff we really should be concerned about. And that means you need to watch it. Make sure you're not sharing stuff that you really don't want to share.

Okay?

So even privacy experts like myself, don't lock everything down. We locked most of it down. Particularly since we have department of defense clients, we have to maintain a very high standard.

All right. Stick around and visit me online. CraigPeterson.com. Make sure you sign up for my newsletter.

You'll get all of the latest news and the tips I send out every week.

I don't want to leave you hanging. We're going to get into a few more things to consider here, because obviously we are going to share some of our personal information. So I'm going to tell you how I share my personal information and it might be a bit of a surprise.

Hello everybody. Thanks for listening.

We all enjoy products and services, and that's what I'm saying. When when I talk about security experts, we don't lock everything down. I've used 23 in me. I did that thing, of course, I'm sending in my DNA. That's been an issue in some cases, but that's what I did.

I use these online map programs. I use Google maps. I use weighs more than Google maps. I use Apple maps cause I'm trying to figure out how do I get to where I want to go in a reasonable amount of time. But what I do is I lie about the answer to the security questions. Okay. I don't want them to know my dad's name.

My mother's maiden name, the street. I was, I grew up on my first school, my first car, none of their business. Because it's a lot of that information is actually publicly available. How many of us on LinkedIn have right there in our profile? Yeah I went to McGill university or I w I grew up here's pictures of my childhood home, and that picture has GPS coordinates in it.

So if we use the real information. We are giving away way too much. I use a little phrase I coined here, which is lie to your bank. And you might remember. I did a show on that sometime ago. And the idea here is in your line to the bank about your financial situation, it's nothing like that. You're lying to your bank about this personal information.

They don't need to know these personal questions. They give you for their security questions. It's really important to understand all of this stuff. Okay. For instance, this is Jennifer Granick, she's at the ACL, you and she said her dad died recently. And the accountant said it's really important to report the death to credit companies because the answers to many of the security questions are on the public death certificate.

So answers to security questions really can be a nightmare, but that doesn't mean you have to give them the right answers. So for instance, I found a site online. I should try and dig that up again, but it generated fake identities. And I had a generate like 5,000 of them for me thinking, okay, they might go at some point and it even generated fake social security numbers, fake phone numbers, names, addresses, everything, everything you'd need for a fake identity. And the idea here isn't to cheat anybody out of anything. The idea is, Hey, Mr. Website, you don't know, you don't need to know who I really am. So on some websites, I'm female some websites I've, I'm only 30 years old on other websites. I'm 80 years old. It doesn't matter.

You can call it a lie if you want. But in reality, you're just trying to keep your information straight not and another advantage. Of these password managers. Cause you're trying to keep your information straight, right? It's hard to remember a lie and you have to tell a lie to enforce a lie. You're not, all that stuff your mother told you.

And she's right about that too, by the way. But if you're using a password manager, what I do is I create a unique email address. In fact, my email addresses are extremely unique, so I'll use a plus sign as part of my email address and my mail server knows. Oh, okay. That's just Craig trying to track who is using.

That email address. So I'll have Craig plus YouTube for instance, or@mainstreamdotnetorcraigpeterson.com. I actually have a whole bunch of domains that I use as well. And if you want a secure email service have look at proton mail. They're actually very good from a security standpoint. So there's nothing illegal about giving them this information.

Yeah. You're lying to them, but you gotta keep your lies straight. Another reason to use a password manager because I have the password manager generate my. My password I put in the email, which is unique for every website I go to, I never use that same email address twice if I can avoid it. And then I, and I use aliases too in my email server.

And then I go and in my notes section for that website in my password manager, I put in the answers to the security questions and I just make stuff up nonsensical stuff. So it's asking what my first car, it might be a transformational snooze. There you go. I just made something up. So I'll put those notes into my notes in my password manager and save them.

So if I ever have to do some sort of a recovery with those guys, it's going to be simple. Because I just look in my password manager, I got to go in there anyways to get my password right. And my email address or username to login. And there it is, there's my security questions. And then the password manager, cause I'm using one password.

It has a little database, it keeps and everything in there is encrypted. And the only way to decrypted is with my password, my one password, that's it. You only have to remember one password and that's the password to one password so that you can decrypt that little vault of a database of all of your information.

So I have, I bought a, I think it's a 30 plus character password I use for one password because yeah, I'm a little bit paranoid about all that sort of stuff. So that's a really good way to be able to keep your information safe. I talked last week about a friend of mine. Whose wife went on Facebook to get some help, some tips on selling her investments investment anyways, and the disaster.

That was okay. So a lot of people have regrets about what they've posted on Facebook, and there's a really cool thing out of CMU. Carnegie Mellon university, where these, how many, it's six guys and gals. They put together this special report. I regretted the minute I pressed share a qualitative study of regrets on Facebook.

Very interesting. So they looked at all of this stuff as best they possibly could. And what did they find? Some examples, just think for yourself what regrets you might have. I know friends of mine in the grads that they have had. But there are a lot, so they go through privacy risk. I can send you a copy of this article if you're interested.

It talks about their methodology. They analyze comments on the New York times website and others Craig's list to regroup people. They, so they've got all of the stuff. Here you go sensitive content. Number one. So alcohol and illegal drug use. Think about that. Think about your employer, your next employer or the police.

They got a report on you. Oh my, this is a bad person. So they go onto your Facebook page and they find. Oh, photos posted from a party with some very non unflattering photos in it. And even maybe mentioning a illegal drug use, what it thinks is going to happen. How about if you get stopped at the border coming back from Canada, Mexico, Europe.

And they decide to do a little deeper look into you and they find this stuff online. The next one sexual content, you can imagine what that is. Think of a Congressman from New York, in fact, religion and politics apparently is one of the things people have regretted posting online, profanity and obscenities, personal and family issues.

Working company here, negative or offensive comments it's arguments, lies and secrets, venting frustration, good intentions intended purposes. I didn't think about it. Hot. State. Yeah. Oh, my this thing just goes on and on, but keep all of this in mind, when you are trying to keep your information private, whether you are a business or an individual, you have to have eternal vigilant watch when your emotions are high, right.

It's like drunk dialing. Don't do it. Or your emotions are high. Something's been going on. Don't put it online. So that's I think a real good bottom line about your. Personal privacy, risk tolerance profile. Okay. Be very careful. , don't put stuff that you don't want other people to see. It's not true that once it's out on the internet, it's there forever.

It's not true that once you've posted it, it's there for anyone to discover. None of that's true. Not at all. Okay. But be very careful cover up your laptop cameras. In fact, in the improving windows security course, I go into this in quite a bit of detail, what you can do, what kind of cameras you can and should use, what sort of microphones you can or should use.

Many people just cover up the laptop cameras with the sticky note. When they're not using it disable automatic image loading in your mail program. That's important. I do that as well, because that image that's in the email is usually being used to track you. It's really that simple. You've got new privacy laws in many States and in Europe, they are really not going to work or help you with your privacy, except with the really big companies out there.

So keep all of that in mind. All right, everybody. I want to encourage you go to Craig peterson.com. You'll see all kinds of great information there. You're going to be able to also listen to my whole show, pick up all the little training tips and even find out about the courses that I'm offering. Craig peterson.com

I guess this is a little bit of good news. If you're a home user, not a business or some other organization, like a state or County or city office, but we've got some breach numbers that have just come out for 2020. We're going to talk about right now.

Hi, everybody. Thanks for joining me. Of course you can always go to my website. Yeah. Pick up all of the podcast in case you missed something today or another week, you'll find them right there@craigpeterson.com. You can also sign up for my email list and we're going to be doing a couple of different things here.

I think in the near future, we're going to be sending out some reports that we made as part of the security summer thing I did a couple of years ago and each one of these reports and there's 30 something of them. Some of them are like five to seven pages long, but it's checklists of all the security things you should be worrying about.

Now, if you are home user, you'll find a lot of these to be interesting. But if you're a business person, you work in an office, you help to run an office. You own a business. You need to make sure you get all of them. So make sure you are signed up Craig peterson.com and we'll be glad to get those out too.

Plus we're also going to start something new every week. I usually have six to eight, sometimes as many as 10 articles in the week. I spend hours going through finding what I think are the most important things that interest me as well, but that I think will interest you guys.

I put them in an email, it is it's not very long, but it's just a few sentences from each one of the stories and I have a link to the story as well, right there. I'm going to start sending that out as well to everybody cause some people want my actual show notes.

We're going to have the newsletter once a week. Then we're also planning on having a little video training as well. So it might just be straight, like straight audio. That's part of a video, but it'll be training on a specific security task or problem that's out there. Then the course improving windows security.

It's been taking us a long time. Blame it, mostly on me. Karen's also busy with babysitting grandkids at least a couple of days a week, and I'm trying to run a company as well. So it's, forgive us, but it is taking some time, but you're going to love this. I think it's turning out really well.

I am about halfway done with the final edits. So I'm recording them. We go back and forth. They ended up recording them twice so that we get all of the points I wanted to cover into them. Karen's come up with a whole bunch of great screenshots and other pictures to go in with it so it's not one of these death by PowerPoint things.

And we've got 21 different talks, if you will, on locking down windows and I go into the why's as well as the hows. I think that's really important, because if you don't understand why you're doing something. You're much less likely to do it. I picked that up from Mr. Tony Robbins, none other, the Anthony Robbins man.

It's been over 20 years. Karen and I went to an event he had down in Boston and this was one of his firewalk or events. We actually got to walk on hot coals it was the weirdess thing ever. Karen was totally freaking out and I was just, wow, this is going to be weird, but we both did it. It was phenomenal. Cause it of gave you an idea of, even if you have this mental block that you can't do something you probably can. We actually did and nobody's feet were burned or anything. It was real coals. It was real hot. They were really red. It was really something that at the very end they had a grass, a little square. Grass, maybe two, three feet by three feet and they had a hose running onto it. So you'd walk over it all. Then you'd just walk in on the grass and the idea there being, if you had any hot coals stuck to your foot. You probably didn't want those just stay on your foot. You'd probably want those, they get put out and taken off, so that's where that did.

Anyhow. One of the things I learned from Tony was you need to have a strong reason why. We see this all of the time, Stephen Covey, if you read his stuff, you know it as well, you got to know why you're doing something. When it comes to computers and technology and security, you need to understand the why. Because it isn't just a rote thing. There are so many variations on what to do, but if you understand the why you're doing it, then I think it opens up a whole new world. You can explain it to your friends. You can help them understand it because finally you will understand it. You'll be more motivated to do the things that you should be doing because you know why you're doing them, what it involves, what it's going to solve for you.

This should be a really great course. And I spent some time in it going through the whys, give you some examples of problems people have had and what that solves.

It's available hopefully here within a couple of weeks, man. I thought I'd be done by the end of January and here it's looking like it'll be the end of February. But be that as it may, keep your eyes out. If you've already emailed me to let me know, you're interested. That's great. I've got you on a list. I'll have to try and send out an email this week or sometime soon to let you guys know about it that we've got it ready for you? We will have already for you, hopefully with the next couple of weeks.

So that's that I'm told different way of doing things that's me. I like explaining things I've been told I'm good at it. So let's I think a good thing too.

I started out the segment by talking about this probably good news for end users. Because in 2020 breaches were down by 19% while the impact of those breaches fell by nearly two thirds when we're measuring it by the number of people affected.

Now, of course, if a company is breached and organization is breached, it's counted as one. One person, if you will affected, obviously it can affect a hundreds of thousands, millions of people, depending on what happens like a breach of Equifax. Are you counting that as one or you counting that as 300 million?

Because that's how many records were stolen? I'm not sure it doesn't say it doesn't go into that much detail, but because the number of data breaches went down and the number of individuals affected by the data breach is plummeted. It's telling us something, then that is okay. That these hackers have moved away from collecting massive amounts of information and are targeting user credentials as a way to get into corporate networks to install ransomware.

We've got even more news out this week about the solar winds hack. We talked about this before, and this is a company that makes software that's supposed to help manage networks, which means it's supposed to help make those networks safer. No, as it turns out, they weren't making it safer and it looks like maybe four years bad guys were in these networks that.

We're being managed by solar winds, not with software, right? It's not as though solar winds was managing the network is solar winds sold software services so that you could manage your own networks or in many of these cases, they were actually managing networks of third-party businesses. I do work as well for high valued in value individuals, people who have a high profile that need to keep all of their data safe and they are constantly being gone after.

They're trying to hack them all the time and the way they're trying to do it. And I talked about this really the first hour today is by this password stuffing thing. So they're trying to get in and they were successful and now it looks like it wasn't just Russia. Apparently China knew about this hack potential knew about this bug and was using it.

And apparently it also was not. Just solar wind software. Now they're blaming some of this stuff on Microsoft office. If you have an office three 65 subscription, apparently they were using that to get in. So the bad guys are getting very selective. They want to go against companies and organizations like government agencies that have information there's really going to help them out.

That is absolutely phenomenal. So these are stats from the identity theft resource center. And I was thumbing through as I was talking here. So it's saying that more than 300 million individuals were affected by data breaches in 2020, which means they must be counting the people whose.

Information was stolen, not just the people that were hacked but it is a huge drop 66% over 2019. And the number of reported data breaches dropped to about 1100, which is about. 20% less than 2019. So it's good. It's bad. I think the mass data collection thing is over with now.

They're not as interested in it, but they are very interested in strategic attacks as opposed to just these blanket. Let's grab as much data as we can because they want to get it into these government networks, which now we've, we know they've gotten into. And then you've got this double extortion thing going on with the ransomware, where again, the going after businesses and people who they know can pay.

So that's good news for the rest of us, right? The home users. It's not good news so much for some of my clients, that's what we take care of. That's why we get paid the big bucks. Now how that works. Downright stick around. When we get back, we're going to be talking more about the news this week in particular, of course, security, Facebook and their Supreme court stick around.

We'll be right back.

The United States has a Supreme court. Our States each have their own Supreme courts. In fact, there's probably Supreme courts all over the world. But did you know that Facebook now has something that people are calling a Supreme court. This is interesting.

Craig Peterson here. Thanks for joining me.

I'm not sure if you've seen this or not, it's very small and it's designed to go into your car and then it will hook up like Bluetooth to your car. It'll use your phone for data. So the data is going back and forth from your phone over to them. They're a little device and that way you can talk to it and you can play music, whatever you'd like to listen to right there from your Alexa.

People have been complaining about Facebook and what they've been doing for years. One of the things people have really been complaining about lately is how Facebook has been censoring people, particularly according to them anyways, conservatives. I've certainly seen evidence of that. No question don't get me wrong, but there's also left-wingers who are complaining about being censored.

Facebook decided it needed to have its kind of its own version of Supreme court. You see what happened? Bins is you have a post on Facebook that is questioned. And usually what has to happen is somebody reports it to Facebook as being off color or whatever it is, the reporting it as. And if two or three people report it, then it goes to the moderators.

That same thing is true for some of the artificial intelligence. Some of it's reviewed by moderators as well. Here's your problem. Particularly when it comes to conservatives because you post something conservative on Facebook. And if you are noticed by some of these liberal hacks that are watching Facebook accounts, they will gang up on you.

And they use these bots to pretend that there is incredible. Rage that there are hundreds of people who are very upset by what you just had on Facebook. When in reality, no, one's upset and they're just trying to shut you down. And there might only be two or three people who actually know about it, but they'll use these kind of artificial intelligence, bots to flood Facebook with complaints.

And they're doing that on Twitter. The left is doing it all over the place. So what happens next? The big challenge for Facebook is there are 2.7 billion users. Can you even wrap your head around a number like that? That is just massive. So they've got 2.7 billion users, and now, obviously not everybody's on every day.

But some percentage of them. And I've seen it's in the hundreds of millions posts every day on Facebook and they log in and look around. Facebook only has 15,000 moderators. So for 2.7 billion people, 15,000 moderators just isn't a lot. And the other problem is that the moderators are suing Facebook.

And they came up. This was about a year ago. With a $52 million settlement with moderators and the moderators are saying, Hey, first of all, we're crazy overworked. And then secondarily, we've got PTSD. Post-traumatic stress disorder. And they're saying that they have this because of the stuff that they've had to see, they alleged that reviewing violent and graphic images, sometimes stuff.

My gosh, I might've gotten mentioned here on the air, but they had to view these. For Facebook. And they said, this just led us to PTSD. I can see that particularly since they have to have so many every day. So many of these different posts that they have to look at. And they are clocked and they are third-party contractors.

They're just, all this stuff adds up. Doesn't it? Moderators who worked in California, Arizona, Texas, and Florida from 2015 until last year, every moderator will receive a minimum of a thousand dollars as well as additional funds if they are diagnosed with PTSD or related conditions. So they're saying there's about 11,000 moderators that were eligible for this compensation.

But this is a very big deal. It's difficult. How do you deal with that? They've got now 15,000 moderators who are reviewing the posts of these 2.7 billion users. There is a little bit of an escalation procedure, although it's a very difficult and because there are so many people who are. Complaining and trying to take care of everything.

It is a very tough situation, really for everybody involved. So they've decided what Facebook needs Facebook's decided this themselves is they've got to moderate themselves a little bit better, and the way they are going to do all of this moderation is they're going to have this kind of Supreme court that supervises.

All of the moderation going on within Facebook. So they call him the new to an oversight board and. Obviously with just one board, without very many people on it, it is only going to be able to handle a small number of cases. So they have been paying attention to some of the cases. And they're trying to set precedents that will be followed by the moderators and millions of other cases.

It's basically the same thing that the U S Supreme court does, where they review cases that come up from the federal district court. They can have cases that are coming up from individual States as well. And then they set standards and, without going into all of the detail of disputes between district courts, et cetera, we'll see what happens in Facebook, but lower courts are treating these us Supreme court.

Rulings and dicta as binding precedents for everything in the future. So it's not easy to do in our courts. We're certainly not great at it. And there are a lot of complex procedures. And even if you're talking about moderation where you bring a moderator in. And there are some standards for that in disputes between businesses where you'll pull in a neutral third party.

And they'll just usually split things down the middle. But those are going to be difficult for Facebook to put in how they reviewed five decisions. These are pretty substantive. Sixth case apparently became moot after the user deleted the post.

We have an uprising and Miramar right now. You might've seen it on TV. If you're paying attention. I know a couple of channels have been talking about it. But this is an interesting problem because the military has overthrown the potentially properly democratically elected government.

What do you do if there is massive cheating going on in the election? We faced that question here ourselves.

In Miramar, they went ahead and the military took over and imprisoned the president. There was a post talking about that and talking about Muslims in France and China.

Another one about Azerbaijanis. I don't know if you've seen what happened with Armenia and Azerbaijan and lots of history going back there with the Soviets and they created this whole problem because they didn't like the Armenians, but anyways, of all of these five, they disagreed with the lower moderators opinions and they overturned them. I think it's really good.

I looked at these cases and I was shocked. I think they're doing the right thing here. Isn't that weird?

Hey, you're listening to Craig Peterson right here on news radio.

Visit me online craig peterson.com.

Hey, did you know, there is a war, if you will, between Facebook and Apple? It is getting nasty. What's going on over there. That's what we're going to talk about right now. Your privacy, Facebook, Apple, and Android.

Craig Peterson here. Thanks for joining me. My golly. You know what I think about Facebook when it comes to privacy, right? Facebook and Google. I think Facebook is worse than Google, frankly. They just don't respect your privacy. They will go ahead and look at anything that they can get their hands on.

We'll at that point, just go ahead and pull it together and sell it to anybody that's willing to pay. I am not fond of that. And I think you can probably guess why, and I doubt your fond of that at as well. You're not fond of that either. Apple did something. If that has really upset.

Facebook and Zuckerberg has been making a lot of noise about this, but Apple announced plans about a week ago to finally roll out a change that they were putting into place in iOS 14, which is the operating system for the iPhones and iPads that Apple has. They had announced that they were going to add it the late last year.

And there was huge pushback from Facebook and a few others as well. What's going on here? Bottom line is that Apple is trying to force. Apps to be transparent. What privacy do you have? What data are they taking? And in the case of iOS, as well as Android and windows and Macs, there has been the ability for certain applications to be able to look at other apps that are on the device.

And by doing that, it can get data from it. They can figure out who you are. They can give a unique fingerprint based on what apps you have and what versions they are. They're pretty clever what they've been doing in order to harvest your information. Now you might have noticed if you go in.

To the app store that there's been actually a big change already. This is the Apple app store. If you go in there and you pull up an app, any app, so let's pull up Facebook and then in the app store, and then you click, obviously on Facebook, you scroll down the app store page about Facebook. And partway down, it already has privacy information.

You want to click on more info project early if it's Facebook, because it doesn't fit on that homepage for the Facebook app. And it will tell you everything. Everything that Facebook wants access to. Now, some of it's self-reported by the app developers. Some of it is stuff that happened. Figure it out either electronically or by getting people involved.

I would like to think that when it comes to something as big as Facebook, they really are going that extra mile. And making sure that yes, indeed, this information is valid, it is what it is. They may not, and I'm not quite sure, but look at all of the stuff Facebook is gaining access to with you.

So that was a bit of a hit people were pretty excited. Oh, wow. This is great. And although Google doesn't do what we're talking about here quite yet, I'm sure they will be not in the way that Apple is doing it, but because remember Google makes money off of you and your information, Facebook makes money off of you and your information.

So if you want privacy, you cannot use Google products like Android or. Chrome. And if you want privacy, you can't use Facebook. So it's as simple as that. Of course, the big question, and we talked about this earlier in the show is how much privacy can you expect? How much do you want? What's legitimate, right?

All of those types of questions. So what Apple's doing now is they said that in early spring of 2021, they are going to release this new version of iOS. And here's what happens. They've added something and this is according to a white paper and Q and a that Apple sent out. They added something called app tracking transparency, and this is going to require apps to get the user's permission before tracking their data across apps or websites owned by other companies.

Under settings user will be able to see which apps have requested permission to track so they can make changes. As they see fit. You might have noticed that already under settings, like you can look at the microphone settings, it'll tell you. Okay. Here's the apps that I have asked about microphone and you can turn them off.

Here's the apps that have asked about the camera. You can turn them off. So they're adding more functionality. They also, in the FAQ, they said that app developers will not be able to require users to allow tracking in order for those users to gain access to the full capabilities of the app. Now, you know how I've talked before extensively about how, if it's free your, the product.

So what Apple is doing is they're saying, Hey guys if the user says, no, you can't try it. Track me across apps. No, you can't get it. This privacy information, which Apple's letting you do, they cannot Labatt automize. The app is what it comes right down to. So it was in September last year that they first said they were going to do that.

Then they delayed the implementation of this tracking policy. So the businesses and app developers could get more time to figure this out. One of the things that I think is fascinating here is what Facebook's doing with fighting back. Oh, and by the way, Apple has not just gotten complaints from Facebook.

There are other marketers and tech companies that frankly it makes Apple more vulnerable to some of these antitrust investigations that have been. Started really against some of these big tech companies. Although, I don't really expect much to happen under the current administration in Washington because frankly, big companies love big regulations.

Because they can afford to comply with them, but startup little companies who are competitors of theirs cannot afford the lawyers for the paperwork and everything out. I look at the CMMC, we do a lot of work for DOD department of defense contractors, where we secure their networks. We secure their computers, we secure everything.

We put it all together. And we also, for some of them there's guys, there's a 50, $50,000 upcharge for this. And that's because we're cheap. Believe it or not, it is a lot higher for other companies do it, but we do all of the paperwork, putting together all of the policies, all of the procedures, what they have and.

Auditing everything for them. And we're talking about a case and a half of paper thinking of the big cases of paper, right? 500 sheets and the ream and how many reams in a box? 10 20. I'm not even sure, but literally cases. And we. Printed it up, we wrote it all up, printed it all up, delivered it to a client just a few weeks ago.

And it was a huge box of three inch ring binders. It was all in and they didn't all fit in there. They're the big guys in the department of defense probably love this because they, they pay a million million bucks to the people, the generate the paperwork for them internally. And they know the little guys can't afford to have full-time paper pushers.

And so that's why, even though we're talking about months worth of work, why we charge 50 grand, which is a heck of a lot cheaper, believe it or not. And it's a huge discount for us. So I don't expect that the fed you're going to come up with a solution. That's truly going to help the little guy here, but Apple's announcement praised by privacy advocate nonprofits as well.

And Facebook apparently has been buying full page newspaper ads claiming it's going to hurt small businesses in a way it will cause it can make advertising. Just a little bit harder. And apparently also Facebook has decided to rewrite its apps. So no longer even requests to access, cross app access to your personal information.

Welcome back. We're going to wrap up, talk a little bit about Comcast data cap, and some of these SolarWinds hack victims that didn't use SolarWinds, and ransomware payoffs have surged, even though the number of people affected has gone down.

Make sure you get on my email list so that you get all of the important news. You're going to get some of this little training I'm doing and the courses that we've developed. The only way to do that is to go to Craig Peterson.com/subscribe. That's how you get on those lists and I'm not sitting there and pounding you or anything else, but I want to keep you informed. So there you go.

We're probably going to increase our volume from one email a week to three, so that we can provide you with a little bit more training. I want to keep these down to something that just takes you a few minutes to go through, but could save you millions of your business and tens of thousands, your retirement, if you are a home user. So make sure you are on that list. Craigpeterson.com/subscribe.

Comcast. I know many of us have Comcast, I certainly do, is imposing data caps on many people in many parts of the country. That includes people to the South here, Massachusetts residents.

What do you think they're doing down there? The state lawmakers have proposed a ban on data caps, a ban on new fees, and a ban on price increases for home internet services.

The idea from their standpoint is we have a lot of people who are working at home because of a lockdown. What are they supposed to be doing?

I'll take my daughter, one of my daughters, as an example, she's working at home. She used to work in a call center she'd go in every day. Now she's working at home. Are they paying a wage differential for her? Are they paying for electric bill? They're not even paying for the phone bill or the phone. She has to provide her own phone. She takes inbound calls for a call center.

Can you believe that? It's just amazing what's happened. The company is saving just a ton of money because people don't have to go into work. You can bet they're going to dispose of some of this space that they've been. What's happening here, we are using more bandwidth than we've ever used because more people are at home and it isn't all business related many are watching Netflix or you've got Netflix on in the background while you're working on stuff. It's just so common to do that.

What data caps are doing is they say you can only use so much data a month. Then there's usually a penalty of some sort. In Comcast case, they said for the first quarter of 2021, I believe is what they had come up with. We'll just warn you that you go over your data cap then they'll charge extra. I have a friend who has Comcast and he said, I think it took him like three days before he went over the data cap. That's not long. It's because they're streaming TV. They've got kids working from home.

Then you've got meetings that they're going to, that are now streaming. So I can see this, but from Comcast side, they now have to handle more data than they've ever had to handle before.

Because we are using it, like for my daughter, she actually has a cell phone, but all of the calls are routed over the internet. Cause her cell phone hooks up to the wifi in the house and the calls come in and go out via that wifi. It goes through the internet, it goes to her phone carriers network. Then it goes to the call centers network. So there you go.

What does that need? That needs to make sure there's no jitter. You don't want voice packets to be dropped because then it sounds terrible. It's very obvious when audio is dropped. I don't know if you've noticed if you're streaming something from one of these online streaming video services, but sometimes. It will hiccup a little bit, but have you noticed that with the smaller hiccups, the audio is fine and the problem is in the video. Now they do that for a couple of reasons, obviously video uses more bandwidth than audio uses, but the other reason is people tend to get more annoyed by audio fallout and audio problems.

Comcast is saying, Hey guys, look at what we have to do with our networks. We have to expand them. We have to increase them.

Now I've got to bring up again the Biden administration because of what they're planning on doing with this fairness doctrine on the internet. What they're planning on doing is saying, Hey, Comcast, just because this person uses five terabytes of data a month, you should not be charging them more than grandma that uses 10 gigabytes a month. Thousands of times more bandwidth requirement, you're not allowed to bill them differently. Cause a bit is a bit which is absolutely insane. I don't know how they can justify this sort of thing.

So what's going to happen is you get companies like Comcast or other internet providers who are going to say. We are not going to invest any money into expanding our capacity because we can't charge for it. Doesn't that make sense to you? It makes perfect sense to me. By getting the FCC involved, it's just going to be crazy.

Ajit Pi resigned when President Trump was leaving, he used to be the chairman. He actually had a head on his shoulders, but these new people President Biden put in there, it's insanity what they're trying to do with our networks. It's going to make it much worse.

Comcast is putting data caps in. You hit the data cap it, they're just going to slow you way down. That happens too, with a lot of our cell phones, our cell phone carriers, if you use more data than they've allotted to you, they'll drop you back. So most people have 4g. Yeah. Okay. Your phone's 5g, but really guess what? You're not getting 5g. It's very rare unless you are on on the T-Mobile slash Sprint plan. T-Mobile more specifically because nobody else has the coverage that T-Mobile has for 5g.

So you're using 4g LTE, you hit your data cap. They're going to drop you back to 3g, which is really slow comparing the two together, all the three of them, frankly, but it's very slow compared to a 4g LTE. In mass, by the way, I should mention Verizon files and RCN. Do not impose the data caps. It's just our friends at Comcast that are doing that Vargas and Rogers.

They let a group of 71 different Massachusetts lawmakers who urged Comcast to halt the enforcement. By the way, the data cap is 1.2 terabytes per month, which is actually quite a bit of data. You'd have to spend a lot of time streaming TV. The cap does hurt low-income people is no question about it. If you are being forced to work from home because of the lockdown, government's forcing you to work from home. They put their fingers in anything, and that just never seems to work out anyhow. We'll see what happens down in mass with Comcast and these guys.

Let's see here, SolarWinds hack.

I mentioned this just in passing a little bit earlier in the show today, but CISA, which is the US cybersecurity and infrastructure agency said that nearly a third of the organizations that were attacked by these Russian and Chinese hackers had no direct connection to SolarWinds. Apparently many of the attacks got in by using password spraying to compromise individual email accounts at targeted organizations.

There's your tie into Microsoft. Obviously major flaws in Microsoft's cloud services. Another one of the targets was CrowdStrike, which is another company that does security. They do remediation after the fact, as well, which we've had to do for many companies over the years too. We'll see, it looks like these Microsoft flaws may have been these bad guys first vector into some of these systems. That's pretty bad.

Ransomware, things have changed because they figured out a better way to do it. Nowadays we're calling it a double extortion. Payments to ransomware gangs that are using cryptocurrency now, more than quadrupled in 2020. Isn't that something. Less than 200 cryptocurrency wallets received 80% of the funds. 80% of the payments went to 200 wallets, which may or may not represent individual ransomware gangs. It's just incredible. The payments using this cryptocurrency stuff, surged 311% last year, total volume $350 million.

Cyber criminals are moving to cryptolocking is the easiest way to turn compromised computers into cash. Then the other thing that they're doing this double whammy is before they encrypt your files and then demand you pay up in order to get the encryption key or decryption key, they're double whamming. They're saying, Oh, Yeah, by the way, we grabbed a bunch of your files and if you don't want us to, and they'd try and figure out what's the most what's the best way for them to sneak the files out and then tell you which ones are the most valuable, right?

They have people look at it, which is really bad. If you don't want us to release them out onto the open internet or onto the dark web, you have to pay us. They'll sometimes pretend they're a different company. That's where I was saying. When you look at the 200 different crypto wallets that are used, they will often go in, at first it'll look like a ransomware attack. People will pay the ransom, much less so in the United States than any other country. Then they will use a different crypto wallet, pretending they're somebody else saying, we have your files, you better pay up. Law enforcement, by the way, can target these deposit addresses here for the crypto wallets. They've done it before. We'll see what happens. About half of all of the funds went to 25 different crypto wallets. That's not a lot.

Make sure you sign up. You'll be getting some of the new newsletter stuff. Some of the free training, the courses and other things. I'm really devoting myself here 2021's going to be the year that we really help you stop the bad guys.

Take care and make sure you sign up @craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553.

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon. I started this morning talking about Drone swarms and how the military in different countries are considering using it, and the concerns about this technology. Then we talked about Hyundai and Apples' electric autonomous vehicles. We discussed the problem with Ransomware. Then we talked about Amazon and my thoughts on the transition. Here we go with Matt.

And more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] We survived the nor'easter well, actually it came from the West. The big snowstorm, good news, maybe more snow on the way I use, shouldn't have been complaining about the fact that we didn't have much of a winter this year because it sure did hit us. Here, up in New Hampshire, we can get snow, even in early April, which is not something to look forward to. It does go away quickly if it comes at the time of year.

Hey, I was on with Mr. Matt Gagnon this morning. He and I talked about a number of subjects, including what's going to happen with Jeff Bezos stepping down and on day-to-day operations over there at Amazon. So here we go.

Matt Gagnon: [00:00:46] It's all things technology tech talk with Craig Peterson right now on News Radio 98.5 FM and AM 560 WGAN.

Craig Peterson joins us on Wednesdays at this time to go over the world of technology, and today being no exception to that. We welcome Craig onto the program. How are you, sir?

Craig Peterson: [00:01:06] Hey, good morning. Rowe, of course, one of the sponsors. They have the Hyundai dealership. Did you hear about it? Apple and the Hyundai actually they're Kia brand, and it looks like they might be coming out with one of these smart self-driving cars. Electric, of course.

Matt Gagnon: [00:01:23] I did not see that. That's the future, though. Isn't it, right? We're going to be having 10, 20, 30 years from now. I'm not driving my car anymore. Am I right about that?

Craig Peterson: [00:01:31] Yeah, I like that. I'll be old enough at that point that if I'm smart, I won't be driving myself.

Matt Gagnon: [00:01:38] Take a nap behind the wheel. It'd be great.

Craig Peterson: [00:01:40] Yeah, exactly. I'll be able to look between the dashboard and the steering wheel as I'm driving down the road.

But yeah, and the new cars too, that have come out now from Tesla, they've got brand new models. They don't even have a steering wheel anymore. It's got a yoke. They almost like an airplane. I don't know if you've seen those too, but they're starting to really move fast. Although Tesla they're saying maybe not the winner that everyone's been predicting, they're so far ahead with some of these technologies.

There's a lot of reasons they're concerned about the fact that they don't have LIDAR on the cars, which gives a really great view of what's ahead on the road. They're also looking at it saying you've got those cameras, isn't that wonderful, but when Ford and GM and. Hyundai Et cetera, et cetera, really go forward on this they say, they're just going to swamp, and Tesla is going to be left on the road behind them.

Matt Gagnon: [00:02:41] We're speaking with Craig Peterson, the tech guru that joins us every Wednesday. You also hear him on Saturdays on this very network, doing a show where he goes into all of these stories in detail in depth here.

Now I do want to touch on this one, which I find fascinating envisioning these swarms of drones and whether or not they're getting too fast now. And whether or not we're going to be able to deal with this whole swarm issue in the future. So what is a drone swarm, and how does this impact us?

Craig Peterson: [00:03:07] You might've seen this at the Olympics over in China. Where they had the opening ceremonies and overhead, normally they're shooting up all kinds of fireworks, which they did do, of course, but they had all of a sudden this display in the sky. It was all of these drones, it was thousands of drones that were synchronously flying, and they had lights on them. So they could put up all this different optics, basically, almost like a screen, a computer screen in the sky.

We've got these types of drones right now. They are used in these types of events, like the Olympics or big games like this weekend. I'm sure there'll be something going on, but there's another side of this.

That's the darker side that you're referring to, which is you've got these drones. Now, a lot of these drones can fly by themselves without any human input or computer external computer input. They have cameras in them. Of course, we know that. We've seen all kinds of beautiful photos of the forest or cities from these drones with cameras, but they're building artificial intelligence into them now. Where concern really comes in is that this artificial intelligence is able to determine if someone is an enemy soldier or if their face matches someone that they want to attack.

Now, it's one thing to have one little drone come after you, excuse me, with a small amount of high explosives, right? Because you can just bat it out of the way and get out of there.

Where they're really concerned about is a swarm of like 75 drones coming at you, kamikaze style. The Indian army just generated this, and they're coming up with these thousand drones, strong little armies. If they're aiming at you, if they're coming for you and they have just a fraction less than an ounce of high explosive on them, there is no avoiding them.

A US Navy has also looked at some of this. They've been demonstrated numerous times, and this is really scary. Especially the whole autonomous idea where they identify someone that might be a suspect, a terrorist, or whatever. Instead of bringing them in and having even a military trial. The drone recognized you, and they attack you and kill you right there. Even if it's not a battlefield,

Matt Gagnon: [00:05:42] We're speaking with Craig Peterson, our tech guru here. He joins us every Wednesday at this time to talk a little bit about the world of technology.

Ransomware payoffs are now surging and are nearing 350 million. From what I understand about these ransomware things and you've been talking about this for quite some time on this very program. Basically, companies are held hostage by ransomware, and people that are held hostage by ransomware essentially paying off the people holding them hostage. This is a crazy story.

Craig Peterson: [00:06:08] Yeah, it is. If you look at the different countries out there, these different countries, different payoff amounts, and the percentages of businesses that will payout, the US is the lowest in the nation when it comes to will we payout. Of course, the US says we don't pay for hostages. We don't. We don't have the trade of hostages very often. We can talk about some really bad trades, but at any rate, we just don't pay ransoms.

We now know that the federal government might come after us as a business if we do pay a ransom because we're supporting terrorism. Other countries, like in Europe, many of the countries versus the US, will pay two to three times more than us, but now we're seeing huge payoffs that are just surging right now. Three times plus over the last year. They're doing it because that's where the money is. People are paying the ransoms more and more. That is the main reason that these Bitcoin and other blockchain currencies have been surging over the last 10 years. It really is because of ransomware payments.

We're not protecting our systems. They're getting in. The other side is this, Matt, is they're holding our data hostage. It isn't enough that they go onto the computers, encrypt everything and say, I hope I have a good backup.

What they're doing now is first, before you even know anything's going on, they take all of your stuff. They steal your files, your spreadsheets, your documents, and then they hold it ransom. Then after that, they say, Oh, and by the way, here's some samples of some of the files of yours we have, unless you pay us even more, we're going to release those out there, which of course includes the family jewels, your intellectual property, and other things.

So these bad guys have gotten very bad, and countries like North Korea are using it to get hard currency. To get the money that they can spend in other places. Iran doing the same thing.

So it's not just some little kid in the basement of their parents' home over in Eastern Europe. It is countries that are coming for us, and we're just not protecting ourselves.

Matt Gagnon: [00:08:32] Craig, before we let you go, one really quick question here for you before you sign off Amazon is now making a transition. Jeff

Craig Peterson: [00:08:39] Bezos

Matt Gagnon: [00:08:40] is no longer going to be the CEO moving forward. Obviously, the company will go on and just like Apple, as I was joking with earlier with Danny on the program here, just like when Apple was Steve jobs, it's not as if one human being is that important to the success of the company. But I would like you to reflect really quickly on the legacy of Bezos. He was pretty much there from the very beginning when they had a really terrible garage-based office, right? All the way to the point where he's got $185 billion and is the most the wealthiest person in the world. Just reflect a little bit on what it means that he's stepping away.

Craig Peterson: [00:09:12] I looked at some statistics on comparing what's happening with Amazon and with Google, both of them have. Cloud services, right? Amazon had to build up all of this computing infrastructure in order to support their stores, which started, of course, like a bookstore. They had massive infrastructure, and they designed it themselves. Did just a marvelous job. The guy that's taking over from Bezos is the guy that's in charge of cloud services over there at Amazon.

Compare that to our friends at Google, who also have cloud services, and Google, on about $13 billion of revenue for cloud services, lost about $6 billion. That is crazy. It's terrible. Google just is not doing the cloud well. The guy that's taken over from Bezos has defined cloud services in the entire industry.

Amazon has about 60% of the marketplace. So I think things are just going to continue. Frankly, this guy knows what he's doing, and he ran a huge division of Amazon.

Matt Gagnon: [00:10:25] All right. That is Craig Peterson, our tech guru. Again, you can hear him on Saturdays at one. O'clock here to get more in-depth on many of these same topics.

Thanks a lot, Craig. Appreciate it. We'll talk to you again.

Craig Peterson: [00:10:34] At that point, I was cut off. So, Matt, you're welcome. All right, everybody, have a great day.

We'll be back this weekend. Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about how you can stay secure and private while using the Cloud and then we talked about Contact Tracing, privacy, compliance, and government tracking. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning. I was on with Mr. Chris Ryan this morning and I gave, I thought it was a pretty good explanation of the risks when it comes to online trading. I'm not really a trading expert, obviously, and I'm not talking about which platforms to use. I think it was a bit of an eye-opener. I got a lot of time to talk this morning. I did a decent job. Anyways, here it goes. I gave a couple of examples too, from close friends and family and how they got messed up.

Chris Ryan: [00:00:32] Craig Peterson joins us right now on the program. The host of tech talk. Craig, how are you?

Craig Peterson: [00:00:38] Hey, I am doing well this morning.

I'm not going to resign, anymore.

Chris Ryan: [00:00:41] Nor am I going to ask you to resign? I like your spot in the show here. Enjoy talking to you. So there you're not in that consideration at this point, we'll see how the segment goes. So let's start with this.

Craig Peterson: [00:00:53] Is it, Justin?

Chris Ryan: [00:00:54] No, I've already no, you don't get to ask me. He will just, it will be another process which will take place there, which will be outside of a resignation.

So let's start with this. There's been a lot of discussion about, online trading and, getting involved with different aspects of trading outside the traditional methods.

I'm curious as to what you think of that from a safety perspective, when you're thinking about using apps, you're thinking about using entities that are the non-traditional trading mechanisms, in light of the game stop situation. What should individuals be cognizant of?

Craig Peterson: [00:01:32] There's two different parts of this.

Chris. I want to tell you two stories, personal stories, friends, and family members of mine. And we'll start by just saying, this is a new technology and when you get right into it, I've looked at the analysis of some of these trading apps, including some of the big ones, including Robinhood and others.

And many of them are not encrypting our data. And that's just crazy. Like some of its encrypted account balances might not be encrypted, but here's the bottom line on this, frankly, there's always going to be security problems. If you are going to be doing online banking trading, doesn't matter. Make sure you're using, what we would call a secure platform or a more secure platform. This means, do not ever root your phone.

People are using their iPhones or Androids all of the time, Androids, particularly people try and gain master control if you will, over that phone. So they can do anything at that point, you've gotten around even the most basic security measures. So don't do that.

The other thing that you can and must do with these online trading apps is using two-factor authentication. Now there's a few different types.

The most simple is to have it send you a text message when you go to log in, but I have to warn you that is not safe. It's not safe because it's sending it to your phone and your phone number is attached to that.

We've now seen. Because so many people are trading everything from Bitcoin through stock, that they have very large portfolios. What'll happen is it's worth it to them to steal a hundred thousand dollars from you or even 50 or 20,000. In some cases we've seen it as low as. 5,000 it's worth it for them to go to the trouble to get the phone company to switch your phone number to the bad guy's burner phone. Now when they go to log into your account.

Guess what people aren't doing the basics, they're not using unique passwords, in many cases.

What will happen is they'll go to your account online and it'll ask for the username. They'll try to use a name they found on the dark web for you. They'll try the password they found on the dark web for you. Maybe they'll try a few different passwords. They've compromised other machines so they can try different passwords in different places. So they don't get caught. Now it sends a text message, but it's not coming to your phone. It's going to the bad guy's phone.

Use an authenticator app, or use a hardware token. Some of these online trading places and banks, including Chase, is a good example. They've been doing this for 15 years.

They'll send you a little key fob, a little thing that goes on your key chain and it has a display with a number on it. That number continually changes it's every 30 seconds and you have to type that number in, that's much, much safer. That's real two-factor authentication.

Now real quickly, two people in my life have been affected by this right now. One of them had an account, an online brokerage account and her stock had gone way up and she decided that she needed to sell her stock.

She didn't ask me, she didn't ask her husband. He's a bit of a techie guy. She was going to do it herself. She went to a Facebook group. She went to a Facebook group that she found online about how to go ahead now and cash out. They asked her, in the Facebook group, there's a few things we're going to need to do in order to help you out.

First of all, what's your account number? Secondly, what's your password? She gave it to them. She instantly lost $6,000 from her account by just doing something. I'm sorry here, but dude, you don't go to Facebook to get help with training. Don't ask how do I get Robin hood? What do I do with it and all that? It is not the right place.

Go directly to the company. Picked up a phone. You can't trust some of this stuff online.

Another example is a friend, family member, a close friend where he had been using Robinhood for trading. He had bought a bunch of stock and it included AMC. Of course, this is a movie theater chain and it had been targeted if you will, by these people on this subreddit. AMC had finally gotten up to breakeven point and so he decided to sell. He sold and okay, great, fine. He now regrets it. That's a big problem. I've seen him before. Now, he's a millennial and nothing personal guys, but.

Chris Ryan: [00:06:33] I'm going to take it personally. I'm gen X.

Craig Peterson: [00:06:35] So he trusts these platforms. He trusts what they're saying on the subreddit and he's putting money he cannot afford to lose into this Robinhood app that lets him buy and sell a stock. That to me is a huge concern.

So, Chris, there's a couple of examples. Make sure you know what you're doing. Day traders, lose money. Most of them lose money. It's that simple. Maybe buy and hold long, maybe follow what the real professionals do. Do check out the basics. Don't just buy it because it's going up.

Also, just basic security stuff guys use a password manager. Unique passwords for every site and full two-factor authentication. These apps are not completely to be trusted, so don't use it on a computer that you use for everything else.

If you're running windows great. Okay. There's a lot of problems with windows and I've got a course coming up on improving windows security. That's one thing.

Try and have a machine that you don't use for anything else, and if you can.

I don't make a dime by saying this but use Apple equipment. They don't make money off of you. They're trying to keep you safe.

Get an iPhone, get an old iPhone. If he can't afford a new one there rather than inexpensive, usually free. Get a Mac and don't use the same computer for online trading that you use for going to Facebook and everywhere else online, because it might be compromised.

Chris Ryan: [00:08:08] Craig, I appreciate your time and encourage folks to check out tech, talk on Saturdays at 11:30 AM here on news radio six, 10 and 96, seven. We'll chat again on Monday.

Craig Peterson: [00:08:17] All right. Take care guys.

I should have mentioned this, but in case you were wondering he was talking about asking someone to resign. He said I never asked anyone to resign. So that's what that was all about. What does it mean? Is it Justin?

Anyways, everybody, take care. Have a great day.

We'll talk later. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

With the rapid pace of change unleashed this past week through Executive Orders, we are now a lot less secure than we were just a month ago and it is going to get a lot worse. But there are somethings you can do technologically to protect your privacy and stay a little more secure. Cloudjacking is possible mainly due to the failure to use secure passwords and a different password for every site and every application you use. Just doing that makes it almost impossible for hackers to carry out their trade. Chrome and by default Microsoft's Edge Browser have put something in their browser to help -- not alleviate but help with this problem. You can do better by using a true Password Manager and we will get into that as well. Speaking of privacy, the US government is going around its own requirements and buying your location data and other personal information they are not allowed to collect from Data aggregators. We will get into that as well. Then did you know that the new administration has put subliminal messaging into the White House website -- Yes they have. Well, just a taste of today's topics and there is even more so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Cloud Jacking: The Bold New World of Enterprise Cybersecurity

Chrome and Edge want to help with that password problem of yours

Military intelligence buys location data instead of getting warrants, memo shows

US administration adds “subliminal” ad to White House website

Why North Korea Excels in Cybercrime

Speed of Digital Transformation May Lead to Greater App Vulnerabilities

Waymo CEO dismisses Tesla self-driving plan: “This is not how it works”

What’s the technology behind a five-minute charge battery?

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, there is a new company out there on the forefront of passwords. We're going to talk about that and a few weather things. Of course today.

Hi everybody. Craig Peterson here.

The biggest problem, pretty much all of us have, has to do with our passwords, what we're doing with them, how often we're changing them, how we are storing them. It is being used for quite a few things out there right now. We're seeing a real emphasis on a term you might not have heard before it's cloud jacking.

This is where someone gained access to your cloud services and then does nefarious things with them. What do you expect them to do now? What does this all mean? It means if you are using something thing, like maybe you're using salesforce.com, maybe you have online banking with your bank.

Most people do. There are so many cloud services that we use nowadays. And cloud jacking is where someone gained access to that online account. You might ask, how do they do that? How do they gain access to it? The simplest and most common way of doing it is something called password stuffing. Now, I know I'm throwing a lot of terms out there for everybody, but basically, cloud jacking means that cloud service is being used without your permission, your cloud service.

So again, think about clouds as just a word for somebody else's computer that you have no control over. Cloud services. Generally speaking, are dangerous. Now I know a whole lot of people who think I don't know much about computers. I'm probably a lot better off having some third party manage my computers for me.

And so I'll just go to Amazon or I'll go to Microsoft or IBM or whomever and have them run my server for me. And in fact, that's what most companies are doing nowadays. Initially, it looked like it was going to save them money. It was going to be a big saving because you didn't have to maintain that data center anymore.

You didn't have to have the personnel who know the systems who did the updates and stuff. In reality, that's turned out not to be true. Most of the slightly bigger businesses, those smaller to mid midsize are moving their stuff. Out of the cloud because of cloud jacking, because of all of the supposedly expenses that we're going to be saved, not only not being saved but because they don't have control over their computer anymore and they don't have control over the network because remember the cloud is somebody else's their computer it's their network. it's something you have very little control over, so they're moving it back into their business. I think that makes a whole lot of sense. In the meantime, we have many more businesses that are saying you cannot buy our software anymore. You have to use it in the cloud.

You have to use our cloud license, which to me is just frankly, mind-boggling. Now I can see how it makes it simpler for them because they only have to have one version of the software, maybe two or three as working on the development and they can roll it out a little bit more slowly. They don't have to worry about it.

People having problems with windows, which is always a nightmare. And we'll try and do support because when it comes to windows, Microsoft, themselves tell you don't run more than one app, one service on that machine. We can't guarantee it. It's not going to work. And then you have to pay them 300 bucks when there's a problem.

And that 300 bucks don't go very far because they don't guarantee they'll solve that problem. So all of these things have led us to move to the cloud and now some moving back away from the cloud and our cloud servers and our cloud services that we're using on our businesses. Are being hijacked.

Now I mentioned that one of the things that these hijackers are doing to take over is something called credential stuffing. Another one is fishing. We're not going to talk a lot about fishing right now, but you probably know this already. It's where you get in the email that looks legitimate. It's from somebody that looks legitimate.

But in fact, it's trying to get you to do something that is going to now give them access to your systems. And in fact, that's what happened to a buddy of mine. I've talked about him before, just a couple of weeks ago. Yeah, he lost his whole paycheck. It's gone and he's not getting it back. And the company is not going to reimburse him for it, which is really a shame, frankly.

So once credential stuffing, it's something that's been used for cradle quite a while. In fact, way back when. They used to use credential stuffing to try like a thousand, 10,000 most recent passwords, or, most popular passwords. Now that's a problem. Isn't it? What is it? Why are they doing it?

Back when life was simpler and people use password as their password, or, ABC one, two, three, or the whole top of the keyboard. There were only a few thousand, maybe 10, 20,000 passwords that were in common use, and we've gotten way smarter since then. Haven't we. No, we haven't.

And I would ask right now that you just take a minute and you go online to have I been poned.com and you can type into, have I been poned your email address? And it'll tell you if it found it anywhere. On the internet. So not just on the internet, but more or less on the dark web on the dark internet, but there's another feature on, have I been poned is spelled P w N E D.

Have I been poned and that's in the passwords tab. So if you click the password. Tab here. It's saying that right now they have a database of 613 million real-world passwords that have been previously exposed in data breaches. And obviously, this exposure makes them unsuitable for ongoing use. Why does it make it unsuitable?

Let's type in right now. We're going to type in P an actually we're going to get fancy P at Sein S w zero R D. So it's a great password, right? Because it's a password with an additional sign instead of an eight and a zero instead of an O. So we're going to type this in and they hit return and let's see what it says.

Oh my gosh. This password has been seen almost 55,000 times before. Okay. So it's not such a great password out there. It has been breached in data breaches and should never be used if you've ever used it anywhere before change it. And it's going through giving you this list. There are a lot of places.

Yeah. 55,000 times it's been used. So check it out, go there, check it out. Make sure your password that you're using. Hasn't been used before. And the question is why? That's where we get into. Okay. Problem with credential stuffing. What they'll do is they will use your email address and your passwords that they found online.

And then they'll try and log in to critical websites like your bank, for instance, we mentioned the bank, so they will try and break into your bank account because they've got your email address and they've got, or password that's what credential stuffing is all about. So they'll just try it on across all kinds of different websites until they can get in.

So this ties back into our cloud jacking problem. And with cloud jacking, they just go to these online services. Again, it's like your bank or might be Salesforce to get access to your client information or QuickBooks. Maybe there's a whole lot of them are out there and they'll try and log in as you know, most of these websites have.

Controls on this. So they limit the number of times you can try and log in. So the bad guys know this and they know the ways around it. And some of the ways are just to do it really fast. One of the ways are to do it from different IP addresses. And they do that using, of course, hijacked computers. We called botnets people's home computers, business computers.

They use them to do their dirty work for them. And now they have control over your systems. Multifactor authentication. That's something I go into in some detail. In my improving windows security course, that's coming up. So if you need more information, that's the place to get it. If you want to find out how to sign up, make sure you just go to Craig peterson.com and sign up for the newsletter.

I'll let you know when that course is ready. Karen and I are finishing it up now. There's just been too much stuff going on. So I apologize. It's been taken a little longer than I had hoped it would take. But it'll be out pretty soon, but multifactor authentication or two-factor authentication is really becoming a standard and you're foolish if you don't need it.

Microsoft, Google, and others have been trying to do away with passwords entirely with some whole new technology, which is. Going back and forth. It may come into play. It might not. We'll see how it all goes. There's been some adoption, but it certainly has not been universal, but multifactor authentication absolutely.

Is universally adopted. So when we get back, we'll talk a little bit more about this. What does it mean? This two-factor authentication multi-factor authentication. How can it stop our cloud accounts from getting hijacked, which is really big? Then we're going to get into Chrome and edge a brand new feature designed to help you with this very problem.

You're listening to Craig Peterson and of course, that's all you will find me online. Craig peterson.com.

We know about credential stuffing and cloud jacking, and we mentioned multi-factor authentication. So we're going to talk a little more about it, but now

hi everybody. Craig Peterson here.

There are a lot of things that we have to understand and take care of when it comes to our computers. But frankly, one of the things that we have to be the most concerned about, and yet, so many of us just haven't been paying that much attention. Is our password. We are hearing stories every week of people who have had their accounts hijacked, who have had people take their bank account money right out.

We've seen that for a couple of years, but it's getting worse and worse. I'm not exactly sure why you guys are not using unique passwords. For every one of your accounts, I really don't get it. It's easy enough to do use 1password. I don't have any money invested in these companies unless you buy 1password through me which I don't sell.

I'm not going to make a dime off of it. Use 1password or LastPass, same thing there. I know the CEO of LastPass had him on the show before I don't make a dime off of it. So use them. It's just so easy to do, but yeah. Two-factor authentication. That's a little bit of a different thing. And we want to get into here in just a minute and how you can use that, how to tie it in.

As I mentioned, I do go into it quite a bit of detail in my course. So if you are interested in that, the improving windows security course, we talk a lot about it. Our friends over at Google have decided they're going to help us out. And here's what they're doing. Number one, they are tying into, have I been poned.com, which you can go to yourself.

You can get an alert from them. If your account shows up in any of these password dumps that are out there on the internet, very handy. So Google is going to have I been poned on your behalf. And if they notice that your account has shown up on the dark web, they're going to tell you, and they're going to recommend that you change your password.

So the easy thing to do right now is. Go to Google. If you're using Chrome that is and check your security preferences. And once you're new security preferences, it'll tell you about the accounts that it knows about that you have that have been hacked. Now, when I say it's been hacked, it doesn't mean your account has been hacked, but your information has been stolen usually via some form of a hack.

If you're using 1password, it has something called Watchtower, which does the same thing. I've got about 2,500 user accounts in my 1password vault. There's actually multiple vaults it's across all of those vaults. So we have some for the business person we have some other stuff that we use for our business clients because we have to maintain the highest levels of security for ourselves, because we have clients that have to have that level of security as well.

So we in fact have better security than most of our clients do, frankly. And that's a little bit sad, many how. 1password will remind me as well. When one of my accounts, email addresses of passwords show up on the dark web. And it'll also tell me, for instance, if I've got my Craig peterson.com to log in and it shows up somewhere on the dark web, it will tell me that.

They found Craig peterson.com out of the dark web, whether or not my password was stolen. So it's really nice. 1password can help you with that and it can generate new passwords and you can use it as well for keeping private notes. And when you are generating. Passcodes for two-factor authentication.

Many times it'll give you a one-time pad. So it'll be a number of single-use passwords that you can use in the event that you don't have your two-factor device with you, as I said, but go into that in a lot of detail in my improving windows security course. But Chrome has done something else and I have to apply them for doing this.

I am not a big fan, already of Google and Chrome, they make their money, their whole living off of you and your information. And I think that a little bit on the dishonest side, frankly. But that's what they do. Okay. They have added now something that's really quite nice and because Google has added it to Chrome, that means that these Chrome-based browsers will also be picking it up.

What are the chromium based browsers? Of course, Google Chrome itself is a chromium-based browser, which means it's a certain codebase Microsoft's Edge browser. The latest version of Edge is not a Microsoft product anymore. They're using Google Chrome as its base. They're using chromium. So in both cases, you now have a strong password generator that you can use when you're signing up for a new account or account, or when you're changing an existing password, again, If you've heard me talk about this before that I'm not fond of having a web browser, remember your passwords because who knows, it's not designed for security. Google Chrome usually does a pretty good job. That's why it's such a popular web browser, but I much prefer an application that's specifically designed for security and they know what they're doing. And that's why I recommend the whole 1password thing. So here's what happens when you are on a web page and you are entering in a username and a password, or you're putting in a new password for your account, how it pops up and says, do you want me to save this password?

Now it is giving you another option here. So rather than having to think up a password, that's really unique. That's a difficult one to guess that is not used anywhere else on the internet. You can now have the generator. Do it for you and generate a very good password. So you're going to look for the browser, suggested password dropdown in the password field, and you can select that and it's going to automatically save your new password to the browser, sync it across all of your other devices.

If you are signed in to your Google account from all of those other devices so that you can use it in the future. There's another feature called password monitor and it's being added to adjuncts already there in Chrome. And it is a password monitor. Again, most of these guys are using, have I been poned would nothing wrong with that?

Although have I been poned isn't being paid by these guys for doing it, but checking your passwords can be difficult. But have I been poned has free signup that you can use that will let you know if your username has shown up on any of these hacks out there. And frankly, that's all of these other people are using.

They've got some very good encryption by the way, for keeping track of your passwords in Epic, they're using homomorphic encryption is what it's called. It's. Pretty new, but it allows computing on encrypted data without decrypting the data first. So that's really cool. It has this hash function that only the server knows they're doing a lot of neat stuff here and Google Chrome team.

Unveiled their own version of this as well. And they've got a fuller featured password manager now built into the browser. So keep an eye out for those on your chromium based browsers. And have a look at, have I been poned P w N d.com online, if you want some more help on passwords, just drop me an email. me@craigpeterson.com or sign up for my improving windows security course.

You can keep up to date with all of the latest news courses, little training, webinars, by going to Craig peterson.com and signing up right there.

Hey, I got a quick update here on secure communications. You might've heard about what happened. What's going on there and let's talk about alternatives.

Hi everybody. Craig Peterson here.

You might've heard about WhatsApp, WhatsApp used to be really popular. I've had a listener before, ask me about using WhatsApp overseas. It was a family member who was serving in the military and they wanted something that was secure. They asked about WhatsApp and I said, I don't know. A little bit of moaning and groaning there that I, I don't like WhatsApp because of Facebook.

Facebook, our friends over there decided that they were a couple of weeks ago going to come out with new terms of use. And that new terms of use have language that made it sound like maybe they'd be spying on us. Now that Facebook has come out and said, no, we're not going to break the end to end encryption.

In other words, we won't be able to decrypt your conversations. However, we are going to start sharing your information with advertisers, et cetera. Sharing your information about using WhatsApp, which is an encrypted, supposedly secure chat app might cause some problems, right? You can imagine someone knocking on your door and saying, why are you using encrypted communications?

And in fact, you have every right to, it is the best thing to do. You don't want bad guys getting their hands on it. And in some parts of the world, the governments just can not be trusted and they are trying to monitor everything that's going on. So that's why I've never been a fan of WhatsApp. And why so many people have migrated off of WhatsApp.

Facebook finally realized what a mistake it was to send out that press release w wasn't as the press release, actually, it was something that came up when you used WhatsApp became right up on your screen. You hadn't to accept it. So it is concerning. Where do we go? Now I think that I suggest you use signal and we cover this quite a bit in a bit of detail in the improving windows security course.

So in the course, we talk about all these different types of messengers, which ones are the best ones to use and when and why, but I want to point out something about Telegram. Telegram has picked up. I'm looking at some numbers right now, but tens they're saying tens of millions. Wow. Of people have moved over to telegram.

They said that earlier in January, telegram announced it had hit a milestone of 500 million active. Monthly users and pointed to a single 72 hour period, one 25 million people had joined the service. Now, obviously, this is people who are fleeing some of these censored services that are out there. People who are fleeing from WhatsApp, because who knows where it's going.

Ultimately. But I want to point out something about Telegram. So first of all, don't use it. All right. Not if you want to be secure, but here are the problems with Telegram. First of all. End-to-end encryption is what you want. So if you are talking to someone over one of these encrypted apps, you want that message, that voice conversation, that video to be encrypted from the time it leaves your device.

Until it arrives on the person you're talking to his device. It's almost certainly going to go through a server or two or three or four. It's going to go through routers. There are ways to intercept it, but if it's encrypted end to end, it won't do much good to intercept in the middle. Our encryption today is really quite good.

Now, if the government wants to get its hands on it, they're on your communications. There are ways around it. However, when it comes to just cast casting, a big fishing net, nothing's going to happen. And they're just going to cast a net. They're going to catch all of this stuff and there's nothing in it.

We know that various intelligence agencies around the world try and keep copies of everything in case, later on, they want to go back and examine it and see what was said after the fact. Whatever, more power to them, Telegram by default does not have an end to end encryption. So by default, yes, it has encryption, but the encryption goes from your phone to their server.

And once it's on the server, it is no longer encrypted. And then on the remote side for the person you're talking to, it's encrypted from the server to that person that you're talking to on the far end. See where the problem can come in here. Particularly if you are in a country that does not treat its citizens, residents, whatever you might want to call these people from serfs on up, that doesn't treat them well. They can potentially force telegram to give them a complete copy of everything that was said or done. That is a problem. That is a very big problem. You are not going to get by default end encryption. However, you can turn it on. On telegram now on Signal. It is by default.

It is end to end. It's always end-to-end. Okay. So telegram only encrypt by default messages between your device and the telegram server and the telegram server and the other person on the other end. However, the group messaging feature that telegram has offers no end to end encryption at all. None. So we have a group of people.

Who've got family members that you're talking, or maybe it's some investors, and you're talking about buying some more real estate for your investment trust, or you are talking with your accountant about, bank numbers and things, and yeah. You've got the attorney on, or maybe you're just talking to some friends and you don't have anything you want to share with those prying intelligence agencies in some of these countries out there, you are not secure because right in the middle, you have your messages in cleartext.

So where is Telegram located? It is based in the United Arab Emirates. That is scary. When they have servers over in the United Arab Emirates, you already know that you don't have much of a sense of security over there. And you certainly don't have privacy. So don't use Telegram. If you want to be secure, we've got tens of millions of WhatsApp users who flee the service.

Many of them went to Telegram. No doubt. They were attracted by Telegrams claims of heavily encrypted messaging. But in fact, it's not true. Okay. People do not want to exchange privacy for free services. Now the nice thing about Signal is it is open source and they are not trying to make money off of signal it's available freely.

Anyone can grab the source code and the signal encryption methodology. Is used by WhatsApp as well, but we already expressed some of my concerns about WhatsApp.

Hey, if you want to learn more about this, more about improving windows security, more about communicating securely, I've got it all covered in my improving windows security course that's coming up in a couple of weeks.

Make sure you sign up. Just go to craigpeterson.com. You can sign up anywhere on that website or go to Craig peterson.com/subscribe. And you'll get my weekly newsletter as well.

Shortly after Joe Biden took office, we started seeing some subliminal messages right there on the White House home page.

Hi everybody. Craig Peterson here. Thanks for joining me.

Let me tell you I'm not trying to start some sort of a rumor here. This is absolutely true. You might've heard about Easter eggs before? No, I'm not talking about the type that you know, that little bunny comes with the colored dyed hard-boiled eggs, or maybe they're little plastic aides with candy inside. Some of that Candy's kind of yummy. Of it's just horrific it's at least it's not as bad as mean with those little corn things that are nasty.

Anyhow Easter eggs are in movies. Have you seen them in the Marvel movies? For instance, they use them quite a bit. These are little things that are hidden away so that people who are watching super fans can find them. It might be just something on a shelf. Behind in one of the movies. So it's on a set and it's something from another movie.

It might be a movie that the director loves, or maybe it's another movie. That's part of the series. Those are Easter eggs are hidden away. They're there, but they're hidden. I think those are cool to try and spot sometimes. The White House added an Easter egg, this subliminal ad to the White House website shortly after president Biden took office.

It's really just absolutely amazing, but one of the most famous Easter eggs in software history and this was pretty complex as well as in Microsoft Excel 97, Microsoft Excel, that's their spreadsheet software. And this is from 20 plus years ago, 23, 24, whatever it is back in 97. You could open a new workbook, hit F five type in L 97, colon X 97, enter and then tab and then control shift, click on the chart, wizard icon.

And all of a sudden you are in to. Flight simulator. You didn't have to buy a flight simulator pretty cool. And you flew using the mouse and then when you were done, you hit escape. And that was cool. I thought it was phenomenal, frankly, but this wasn't. Just a hidden, a game is hidden inside of some commercial software.

There was a version of Tetris that was hidden in a spreadsheet as an Easter egg. They had something called boss mode control B. So it was quick to type and it. Popped it up, it a dubious sort of Easter egg intended as decoys, coy. And it had a spreadsheet app as well. She could pop back and forth as the boss is looking over your shoulder.

No, just pop, hit a button and it's a spreadsheet. In this particular case, what happened. Someone at the White House, decided that they would add in some job information isn't this is cool. So if you were looking at the source code for the website, you would see hidden away in there, a job application, Google's done something similar before they have had some.

Coded messages up on billboards, out in the San Jose area, out in California, and people that we're able to decipher it. They, it told you how to apply for a job. Obviously, they want to have a little bit of fun Microsoft edge, by the way, if you go to edge colon slash. Surf as you are AF and it's only available over on the Microsoft edge thing.

You have a surfing theme game when you're offline. All you have to do is type in edge colon slash surf. And it's like the windows game ski free. And it challenges you to ride through the water while avoiding islands. Those can be tricky. Very easy to do. Marvel has an interesting one too.

If you're really totally geeky, you can grab the headers from Marvel.com's website. And the hatters will have a server nickname, field, and call like she helped. Cause I don't know if or not, but Marvel is coming out with a female Hulk. And so this is a. A promotion Ford very geeky stuff.

Here's another one you can go to naked security.sofos.com. And again, if you look at the headers, which you're not going to see just by going there regularly, there is a header in there. It says, if you're reading this, you should visit blah and apply to join the fund. Mention this header. This 2021 White House website added a job ad as well.

Presumably they're trying to get some publicity and to attract job applicants to the US digital service. Done it. And it describes itself this USDS as part of the public service, that quote aims to use design and technology to deliver better services to the American people and its goal is to attract some of these technophiles.

Yeah. That might otherwise be alerted to join the commercial big stuff out there, but you can go there online, directly at usds.gov. And there's a picture there. Fascinating picture. If you ask me because out of one, two, three, four, five, six, seven, eight, nine, 10, 11, 12, people that are in this picture, there is one white male.

Half of them are females and of the males. And about half are males and of the males. Five of them are not white, which is, it's just interesting. It's such a change from what you normally see advertised online. So it's fun. Cobalt call in an older language, something, I wrote a lot of code in back in the day and you've got new.

Languages out there like rust. I don't want to get into all of this right now, but it's geeky kind of fun. I also, by the way, wanted to point out going back to Telegram, which we talked about a little bit earlier in the show today. If you want to use end-to-end encryption with Telegram, you have to turn it on for each and every individual you are going to talk to. Okay. That's a real big deal here. It's what they call their secret chats feature. Every individual has to turn it on. So be very careful in order to do what you have to. Tap the contacts name then hit more and then hit start secret chat, and then confirm one prompt asks whether you're sure. So the conversation history from the default chat does not carry over to the secret one. You have to initiate that encryption option. Every time you pick a conversation with a contact. So it isn't like you can set it once and forget it. This isn't a romp appeal thing. It's if you're using telegram every time you have to you want to start a conversation with someone, you have to go into that more menu than the secret menu, and then are you sure?

Okay. Not good at all. I love this. This comparison saying that this is a guy named. Would you rather go for the car where airbags work every time you get into a crash or going to go for a car where every time you have to turn it on by typing in a pin to enable airbags, why not have them on by default?

I think the idea is. Pretty obvious why they're doing that right. UAE. They're not trying to really keep secure. And speaking of security here, before the hour's up, I wanted to mention this military intelligence is buying location data instead of getting warrants. Now, this is from a memo that came out. We know Homeland security has been doing that.as well, the DIA, the defense intelligence agency, it's like the CIA, but they provide military intelligence to the department of defense confirmed in this memo that it purchases commercially available smartphone location, data to gather the information that would otherwise require the use of a research warrant.

How's that for? Interesting. So they have the ability to get information on you just because you are giving it for free. He just gave it right to these app developers, to Google, et cetera. And Google has decided because of what Apple has done. Apple now has said, if you are an app and you are going to be tracking people.

Apple is going to pop up a permission screen where it informs you that this Google app or whichever app it is asking for permission to track you even across other apps. And you have the ability to say no. Apparently, that really scared Google off. So Google has decided. That they're not going to play that game at all.

And they changed their code Google maps and some of these others, they change their code so that it does not gather that data, but only on iOS, only on Apple devices, because they were concerned, afraid, whatever word you might want to use, that Apple's disclosure of the fact that they are tracking you.

Would turn people off from Google. I think that people should have been turned off from Google a very long time ago. I go into search engines as well in my improving windows security course and how to set the right search engines for your browsers and stuff. But bottom line, I like duckduckGo. They have gotten to be very good.

I've had their founder on the show before it has been, I think, a bit of a godsend because you don't have to use Bing, which of course tracks you. That's Microsoft's search engine. You don't have to use the Google search engine. Just use duck go. It's just harder to say.

Yeah, I'm going to duck duck go that.

Okay. Media also, by the way, found out that customs and border patrol buys, license plate, scanner data to track individual movements. They buy cell phone location, data, they all get it. So remember if you have a smartphone or even a cell phone, that data can be sold and used by whoever cares to use it, it's really that simple.

You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about?

We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what is called swatting attacks.

Then Solar winds there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to these SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

And one of the ways Microsoft realizes to stay secure is by keeping its source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our were residents pay.

So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employers can save overhead costs on those expensive square footage and high-demand cities look at what's happened right now in San Francisco.

For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive,, and people are moving to Maine, to Montana, dial in from the woods, or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer based in their state.

That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

We're going to talk about that and how we now have people being only wrongly accused, but arrested, spent jail time. It's a crazy world out there.

The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go.

So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well.

Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that have been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board.

Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or other devices. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, Arthur smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

  1. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's reports or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that.

Yeah, absolutely true. We'll be talking about that.

You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by police officer. Here we go.

If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a few articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me ME@craigpetersohn.com. I'd love to know, do prefer to get all of my show notes every week, or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list.

I just want to get the message out is my bottom line.

We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live, real-time access to all of the Ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate, the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened on a number of occasions and far more than we like to talk about is that there are.

The bad guys or people who don't like their neighbors and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting a prank led police to shoot dead 28-year-old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth.

You can have teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. Apparently, they believe the report was an act of swatting where somebody makes a false report to a police department that causes the police to respond with a SWAT team.

Now the audio of this emergency call had been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

The color also said he had a handgun and had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

When Mr. Finch came to the door, they said one round was released by the officers after the 28-year-old failed to comply with verbal orders to keep his hands up. Why would he, what did he do wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

They said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them were dead, injured or taken hostage. His family told local media, he was not involved online gaming.

Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the hackers are out there who do this swatting maneuver on somebody. Then they have the hacked Ring camera at that house and they watch the SWAT team respond. Can you believe that?

The FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices.

How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address.

Yes, to log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells that have allowed hackers to steal pet network passwords, et cetera.

In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

But anyway our businesses and government got broken that's what we're going to talk about right now.

Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly, since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

And in fact, That's a big problem still, but we'll talk about this right now. SolarWinds is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWinds. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

We dropped SolarWinds as a vendor, and the reason we dropped them and we made it very clear to them as we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWinds a couple of years ago, and they wouldn't do anything about it.

So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWinds. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presume now to be the hand of a Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

He said SolarWinds, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWinds websites stopped offering the client the compromised programs.

Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached too, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of the economic incentives.

The market rewards, quick development of products. It rewards new features. It rewards spying on customers, end-users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram, or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

It doesn't reward reliability past a bare minimum, and it does not reward resilience at all. And this is what happened with SolarWinds. SolarWinds ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure it.

It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWinds is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from Tech Beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the US treasury department was hacked the US Department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cybersecurity, and infrastructure.

Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the US Department of energy, three US state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody - use a password manager and I will have a course on that this year.

Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an IT security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email me@craigpeterson.com and let me know, be glad to send you stuff.

ME@Craig peterson.com.

Take care guys.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553.

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started this morning talking about Cloud Jacking what it is and how it is done. Then we discussed how to prevent it and that is by having good strong passwords that are different for each site you visit. We discussed password managers. Then we got into how the Government is getting around laws on tracking you -- they are buying data from Data aggregators. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: Hey, good morning, everybody. Craig Peterson here. I've got my early morning voice on this morning. It's a little cloggy. I was on this morning with Mr. Matt Gagnon. We talked about a few different things, including the new Chrome and Edge browser. Features and why Microsoft edge picked it up.

[00:00:20] Also, the military intelligence is buying data on you. Where are they getting it? Why are they getting it? What's with cloud jacking and the rise of cloud jacking. Here we go with Mr. Matt Gagnon.

[00:00:35] Matt Gagnon: It's all things. Technology tech talk with Craig Peterson right now on news radio 98, five FM and am five 60 WGAN seven 36 Wednesday morning.

[00:00:49]Craig Peterson joining us as always on this time at this day, Craig, how are you this morning? Hey,

[00:00:55] Craig Peterson: I'm here now. I'm ready to go.

[00:00:59]Matt Gagnon: Well, let's get going on the topics of the day, if you don't mind. So you need to explain to probably the audience and myself, what cloud jacking is.

[00:01:07] Why don't we start there?

[00:01:08] Craig Peterson: Sure. This is a whole new problem. The cloud is just another word for somebody else's computer that you have no control over. It just amazed me how many companies thought, we'll just rush to the cloud. We'll use these cloud services and there's a lot of them out there now, and we don't have to worry about anything anymore. In reality, you do.

[00:01:33] Microsoft does not guarantee that if you're using their windows, their Microsoft three 65 and their licenses and their email. They don't guarantee that data is not going to be lost or deleted accidentally. In fact, there was a huge problem with Microsoft dropping all of the conversations in Microsoft teams for one of these fortune 100 companies and just shrugging their shoulders.

[00:01:58]The other problem has to do with security. You cannot assume that these cloud services are secure. Most of the businesses nowadays, and this is just no end of frustration to me, on trying to be first to market, they're not worrying about the longevity, the backups, the security, or anything that, really, they shouldn't be caring about. They're just worrying about having a product that mostly works and it's almost always in the cloud.

[00:02:30]That brings up this cloud jacking problem, even though we've got all of this great cloud computing and it's going to save the world. The bottom line is the hackers are going after it.

[00:02:43]They're going after it in a very big way. They're taking over business accounts that are up in the cloud. Remember, what about passwords, Matt? We've talked about it before, people are not using good passwords are not using password managers. I have a friend who he's in his seventies now. He drives for grub hub. That's how he makes a little bit extra money. So he has his online cloud account with grub hub. This is true for so many things. I'm just using this as an example. He noticed that he was due 700 and change payment. This was his wonderful paycheck coming in from delivering groceries in his seventies.

[00:03:25] He's climbing stairs, he's bringing stuff around, he's working hard for it. What had happened is someone went ahead used the email address that they found in one of these dumps from one of these hacks. Used his password that they found in one of these dumps from one of these apps and hijacked his account.

[00:03:46]There goes $700 of hard labor. It went right into the account or the bad guys, and he's kinda clamoring and I helped him out. I go ahead and go in with one password. You got to use a password manager.

[00:04:01]The bad guys have now access to over 1 billion accounts with email addresses and passwords. They are all online people. Check them out. You can go to a website called, have I been poned pwn ed check there. Put in your email address. It'll tell you if the bad guys know your password.

[00:04:26] They're just stuffing them in, Matt, and their cloud jackin. They're taking over your cloud account because if it had been on his computers, his business computers, or had been on Grubhubs computers, it would have been harder for people to break into. But because it's just on the web, I was just like, "I'm going to use, why I have three passwords that I use across the internet." It drives me crazy.

[00:04:50]Matt Gagnon: We're speaking with Craig Peterson, our tech guru, who joins us on Wednesdays at this time.

[00:04:54]Speaking of passwords, if you're having trouble with those passwords generating a good one, remembering them, et cetera. There is perhaps a solution with Google Chrome and Edge.

[00:05:04] Craig Peterson: Yeah, there are a lot, a lot of companies that are trying to help us here with this problem, because this is a very big problem. Microsoft and Google both have a goal of completely eliminating passwords and not a bad idea, but we're nowhere near that right now.

[00:05:21] So remember Microsoft Edge browser, isn't really Microsoft Edge. It is actually now Chrome under the hood. And both of them now, because Chrome has added it so guess what Microsoft gets it for free. They've added a nice little feature that tracks your passwords, what you're using, and also now helps you generate new passwords, safe ones, secure ones, and Google has gone an extra step, and I've got to praise them a bit for this. If you are saving your passwords using Google Chrome, it keeps an eye on the websites that are hacked and it keeps your an eye on your password and will let you know if your account has been effectively exposed with a username and password.

[00:06:13]Using this new password generator, I think is a good step. If you're not going to get a real password manager again, get one password or last pass. Chrome and Edge are going to come to the rescue, give you this password generator with passwords that are hard to guess.

[00:06:31]By the way, the current thinking on good passwords has nothing to do with an uppercase character, a lowercase, a special symbol, and number. Now a days the best passwords are little phrases that are joined together. You might have three words, problem challenge, solution, all separated by like the number two or a dash. That's one of the best passwords you can get.

[00:06:56] This is great built in strong password generator. It could save you your paycheck and it would have saved the paycheck of my buddy.

[00:07:06] Matt Gagnon: We're speaking with Craig Peterson, our tech guru, who joins us this time every Wednesday to go over what's happening in the world of technology.

[00:07:12] You can also hear him on Saturdays at one o'clock for many of these very same topics in more depth. Finally Craig, the military intelligence buying location data, instead of getting warrants, according to a recent memo here. Tell me more about this story.

[00:07:26] Craig Peterson: Ooh, this is something I've been warning about for a long time, right? If it's free, your probably the product. That's very, very true because so many of these free little apps are doing things in the background you may not be aware of including keeping track of where you are.

[00:07:44] So Homeland security and now military intelligence agency, the defense intelligence agency have both been caught, if you will ,going to the data aggregators that are taking all of the data from all of these little apps that you have. That are they fun, they're free.

[00:08:04] You know, the I have a hundred apps on my phone and I only use six of them, which is pretty common, by the way, those other apps are leaking information about you. Even some of the ones that you are using are leaking it. So this is a very, very big problem.

[00:08:19] In the United States, they cannot monitor you , or your location without a warrant with some exceptions, but this is allowing them now to get full access to you where you are, where you're going. Thats sort of what Homeland security has been using it for.

[00:08:37]Now it turns out that's what the defense intelligence agency has been using it for as well. This is a big fat loophole. That they are driving massive trucks through. It's just incredible. Oh, and by the way, there are all the license plate scanners out there. You might not be aware of it, but in some areas, if you get tickets, they will issue a warrant for your car after a period of time.

[00:09:04]There's tow truck operators driving around that have license plates scanners on your cars and they'll drive to a parking structure or through a mall. They'll find cars that they can go ahead and tow and make some money on all of that license plate data. It Is also being set into this and many of the cities and towns that have license plate capture cameras or also selling it.

[00:09:29]Your data is out there and we've got to take this back, Matt, we've got to stop allowing them to collect all this data on us. Apple's taken a very good step towards that. Now in the app store, they're the first to show you everything that any app is collecting on you right there in the app store.

[00:09:49] Matt Gagnon: All right. That's Craig Peterson, our tech guru. Joining us at this time every Wednesday to go over the world of technology. Thank you as always, Craig, appreciate you joining us here and we will talk to you again next week, sir.

[00:09:59] Craig Peterson: Thanks again, Matt.

[00:10:00] Matt Gagnon: You bet. All right, so coming up next, we're gonna take a quick break here.

[00:10:03] Craig Peterson: I got some good news too on this course. Oh my gosh. It's been a labor of love. But this improving windows security course, it's almost done. Been busy recording. 21 different modules are covering every aspect of windows and security. We're probably going to do some other stuff too, as part of this on VPNs and firewalls and stuff too.

[00:10:29] Cause I think that's all needed. We may be a little longer than I had hoped, but I want a really, really great course when we're done with this. It's not going to take us much longer.

[00:10:40] All right. Everybody, have a great rest of the week and we'll be back on the weekend.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We had an interesting discussion about North Korea and their extensive hacking efforts, who is supporting them, and why. Then we got into Social Media censorship and Birdwatching and how the left has succeeded in shutting down conservative opinion. Here we go with Jim

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here this morning, we talked about Canada being a big hacker nation and the other big one, there's really top three if you will. So that's what we got into today. A lot of people just weren't expecting what's happening. It's crazy. So we get into why Mr. IL is out there hacking and it was a surprise to Jim, anyway.,

Hopefully, you got my email this morning. I got another one Thursday. We've got some little training things coming up that I want you to pay attention to all part of this launch of the finally the improving windows security course.

No, we had a name. We had like working names, everything else, you know how that goes, but the whole idea behind the course is how to improve your windows security to that next level. All right, everybody, take care. And here we go.

Jim Polito: [00:00:59] Craig Peterson, the Tech-Talk guru and our good friend who joins us every Tuesday at this time.

Good morning, sir.

Craig Peterson: [00:01:06] Good morning.

Jim Polito: [00:01:08] Hey, we're going to get some Some of your, Canada like weather, just a little bit, little snow. Hey, a little snow.

Craig Peterson: [00:01:17] Have you seen this? A Northwest territory's Buffalo airways show. They have it on the weather channel at times at night, sometimes. They're up in the Northwest territory up in Yellowknife. They're flying to places, Calgary, Edmonton, red deer, that's south to them. I never moved this far North as those guys. Yeah.

Jim Polito: [00:01:39] You might as well be in Alaska seriously.

Craig Peterson: [00:01:43] Yeah. Yeah, exactly.

Jim Polito: [00:01:48] Here's something I want to talk about still more about social media and censorship and everything else that's going on, but I do want to ask you about. The country in the world that is probably the least high tech or one of the least high tech. You see a satellite picture of this country at night and there aren't many lights on, and yet they couldn't be one of the best hacking units in the world.

I think I'm giving it away as to who it is, Craig, but I'll let you, yeah.

Craig Peterson: [00:02:25] Yeah. It's Canada.

Jim Polito: [00:02:27] No, that was pretty good because if you get, if you see a picture of the Northwest territories at night, there aren't any lights up the other than the Northern lights.

Craig Peterson: [00:02:41] The Northern half of Canada has a total of just over a hundred thousand people that said something like two-thirds of the population lives within a hundred miles of the US border.

But no, that's not it here. We're talking about cybersecurity and cybersecurity has become a real problem. In fact, Rhode Island. Now you can call 211 to report cybercrime in Rhode Island. In Mass, there is a 211 is you probably could, but Rhode Island has been really leading this somewhat and setting this up.

For cybercrimes and includes cyber-stalking, identity theft, financial fraud, cyberbullying. They've been trying to stay ahead of this game. So what we're talking about right now is this state-sponsored hacking.

Now countries, if you look at Russia, you look at China, they're hacking us as part of what kind of world war three right.

What's the easiest way for us to attack the United States. It's via cyber. We've seen power outages in some of these countries, including Iran lately. There's a lot of speculation that it's us doing that to them.

Although Iran says the reason that they've had power outages is that too many people are trying to mine Bitcoin cyber currencies. They use too much electricity and we didn't allot for that then. They shut down 1600 cyber mining facilities within Iran.

There are countries like Iran that want the cash and North Korea, believe it or not, is one of the leaders out there because they want their hands on money. They have a number of different groups out there. There's a Lazarus group, which is probably the best known, Hidden Cobra is another one of them. They do all kinds of extortion and ransom and just general online so that they can get their hands on money.

There's an estimated of I've seen various numbers, about three to 6,000 people in North Korea that are very advanced technologically. They have gone to foreign universities.

Look at current leader of North Korea. He went to school over in England, and it's just amazing. Some of the things we let these other countries do.

Now they have what Kim Jong himself calls an all-purpose sword that guarantees North Korea military capability to strike relentlessly. The main reason they're doing this is getting their hands on hard currency.

Jim Polito: [00:05:32] That makes sense. We're talking with Craig Peterson, our tech talk guru. So Craig, the expression if only you had used your powers and skills and talents for good. This type of high-tech hacking, that requires smart people requires some hardware, requires software, all of this, they're doing it just to steal, so that they can fund them, shall we say, hermit nation. As I said, you take a satellite picture of the nation at night and there's hardly any lights on because there's just, the people are living in a primitive society. So that's their motivation.

When you look at Yosef Stalin when he first became a communist, this was before they had over three around the czar, he was a bank robber, robbing banks for money, for the Bolsheviks, for the revolution.

Isn't that basically what they're doing here in North Korea, although they've already had their communist revolution.

Craig Peterson: [00:06:40] Yeah, they are. That is what they're doing. They're trying to fund this so that they can feed their people. Remember people are starving in North Korea. These are defectors their medical conditions are just insane, crazy.

They're also directly tied into China. So even though they're obviously playing not even second fiddle there they're way in the back in a different auditorium, from China.

China is a huge cyber threat and frankly. Russia and China and then North Korea is right behind them. China is actually providing them with some of this technology to do the hacking as well, which is absolutely fascinating to me. China is continuing to support North Korea, but it's doing it by giving them technology, giving them training, allowing North Koreans into their universities. Specifically, so that they can learn how to hack computers in the United States, as well as other countries, and fund themselves. So they don't have to keep coming back to China for more money and grain and oil and everything else for free at the very least they'll be able to pay for it.

It's like the kid in the basement you're trying to get rid of, and not everyone can get on that hermit out of the basement and put them into the white house.

Jim Polito: [00:08:01] Wow. We're talking with Craig Peterson tech talk. We will tell you how you can get in touch with him at the end of this segment.

But Craig, we just got a few more minutes here. Anything new in social media? I heard Twitter invented, what is it? Bird something or bird catcher or whatever. This system that's supposed to identify tweets that are inappropriate. Does this really mean anything?

Craig Peterson: [00:08:34] Yeah, they've been doing it for quite a while. It's called birdwatch and this is a community-based. Here's what's really been going on and no one, I don't understand why, but I haven't heard anyone else talk about this. Jim.

This is a first in the media, but the problem we have out there is that Twitter and Facebook, they don't have the time. They don't have the resources, even the artificial intelligence to be able to monitor all of the tweets and catch the bad ones.

The way they find the tweet that they want to shut down is they get people reporting them. So now they've made this more formal by calling this community, birdwatch and doing all of this stuff. Here's what happens, you post something online that is maybe slightly questionable, especially if you'd take it the wrong way. There are people who are sitting there again in the basement I'm running for president, or maybe they've never gotten a job, or maybe it's both. They're watching a few social media accounts.

They think of these hacking communities overseas, where you have all of these people. Pretending to be someone else. As they're pretending to be someone else there, they're posting and trying to change our opinion, right? So much of these bots, et cetera, we're not going to get into that right now. The reason Twitter shuts things down is that somebody reports.

Now you or I, we looked at a tweet and say that guy's an idiot and we move on. But the people on the left, particularly the far left, all see a tweet and they will say, okay, we can get them on this one. They then have a few hundred of their fellow community members report that person, tweet to Twitter. Twitter then has to respond based on his community standards because so many people were complaining. You got a 24-hour ban or demonetization. That's the big secret behind all of this?

It's these kids, bad guys obviously not all of them are young kids who are sitting there watching certain accounts reporting on mass. People w via different people and different bonds. That this is really offensive to them and now Twitter has something to fall back on.

Jim Polito: [00:11:09] Yeah. And you know what? They destroy a lot of conservatives and I've had it. I've had it happen to me. That's why everything I write on Twitter, anywhere else, is something that I would not be afraid to say to a priest, my late mother, when she was alive, anyone like that is.

I have my political opinions, but the way in which I convey them, I do it in a way that's not offensive, but even doing that, they keep reporting.

You can get hurt and that's scary. That is scary. Craig.

If folks want to get more information from you what do they do?

Craig Peterson: [00:11:52] I sent out this morning, in fact, a video to everyone that's on my email list, and I've got another email going up Thursday. I've got some more training coming out. This is all training stuff, people, and you can get on that list.

Just go to Craig peterson.com. You can subscribe right there. Craig Peterson.com/subscribe. If you'd like. All of my podcasts are up there. You can get copies of these special reports. Like the one, I released today and much, much more just Craig peterson.com.

Jim Polito: [00:12:25] All right, Craig. Thanks so much, great information. We'll catch up with you.

Craig Peterson: [00:12:30] Take care. Thanks. Jim.

Jim Polito: [00:12:32] Thanks. Bye-bye, all a final word. When we return.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about how you can stay secure and private while using the Cloud and then we talked about Contact Tracing, privacy, compliance, and government tracking. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] This morning, I was on with the new host of New Hampshire today, Mr. Chris Ryan. I like the way he does interviews a little different than most of the interviews I do. He really drives to get involved. He understands the stuff I send him. It's kind of fun. Actually, it makes me look good. Anyhow, here we go this morning, of course, talking about the latest in tech security. In fact, right where he went. When I was just editing it, I noticed they had a bit of a running joke going on this morning. I think you'd probably figure it out. It has to do with traffic here. There is no traffic here, frankly. Well, okay, a couple of days out of the year, but that's it.

Chris Ryan: [00:00:41] Joining us right now on the program. Craig Peterson from tech talk here on WGIR. I can hear it. 1130 on Saturdays. He joins us right now on the program. Craig, how are you?

Craig Peterson: [00:00:50] Hey, speaking of tyranny, doing pretty good.

Chris Ryan: [00:00:52] Good for the show. One to talk to you a little bit about your thoughts on where things are headed with cybersecurity at this point in time, particularly as we're utilizing clouds more. We're putting our pictures up on the cloud, we're putting information up on the cloud. It's a great way to share information with relatives and things of that nature. But when you're putting it out there, the question is - how secure is it? Particularly for individuals that are not quite sure exactly how to utilize the cloud and to keep it safe.

Craig Peterson: [00:01:24] Yeah. And that extends frankly, over to our businesses our bigger ones, our smaller ones. People are looking for just an easier way to do things. You've got your pictures you've taken of the kids. You've got the videos from the holidays and you just stick them up there in the cloud and keep your fingers crossed.

When it comes to businesses, they look at the cloud and say, Oh, isn't this wonderful because I don't have to do anything.

They don't have to have a server anymore. I don't have to worry about backing up. None of that is true in either case. We've seen many, many times, including recently, for instance, Microsoft teams lost all of the conversations from one of the major corporations out there.

Chris Ryan: [00:02:07] Justin, we should talk to Tim about this, and cancel our promotions meeting today. On Microsoft teams so we don't have to do that.

Justin McIssac: [00:02:13] I like the canceling the promotions aspect of this.

Chris Ryan: [00:02:15] No, but you're right. We're utilizing, using these platforms, whether it's zoom, whether it's Microsoft teams, and we don't know how safe they are. Are there ways do you utilize the platform? Let's say zoom, as an example, everybody used that, Microsoft teams, people use that.

Is there ways to make sure that those conversations are safe because a lot of times if they're even being recorded and people don't know it.

Craig Peterson: [00:02:37] Yeah. In the case of Zoom, it's been routed through China and Chinese servers are out of the country, it seems to happen a lot with zoom. Zoom has been caught absolutely lying to us.

Talking about fake news, they say, it's secure end to end. We have end-to-end encryption. They did not have it. We're not actually sure they have it right now, either. They're saying that they finally do, after years of saying their conversations were secure.

Going back to, how do you have secure conversations? How do you know your data is securing the cloud? Well, there are some platforms that have been certified as being secure. When you're talking about teams, there's only one and that's WebEx teams. Microsoft is not there. Zoom is not there. WebEx allows you to have secure conversations end to end, but let's just talk about the simple stuff.

If you want to have your stuff be secure or not lost, at the very least back up your cloud services. Don't just trust the phone calls that you've recorded or your pictures or your home videos or your business documents or your emails. Don't trust that they're not going to get lost, which is probably going to be most people's biggest problem because they do get lost.

These big guys say, well, we're not responsible for that. I don't care if it was 10 years of all of your important emails. Back them up from the cloud.

Use some of these tools that are out there, like Signal. If you want to have a small meeting with a few people with friends. Signal is what the big-time experts on security use. It is secure end to end.

It comes right down to this, Chris, you just can't trust the providers because they're trying to sell what they have. They're not trying to develop what exactly we need for security, safety, and making sure that stuff we care about doesn't get lost.

Chris Ryan: [00:04:37] I want to talk a little bit about big tech and government. There was a conversation back in the start of the pandemic between Dr. Fauci and I believe it was Rolling Stone that I read. He was talking about South Korea versus the United States and how South Korea was able to get control of the pandemic because of the fact that the government could spy on its citizens. Basically, and determine who had COVID when and where they were, who they're with and tie all these things together. He said the government can't do that here and frankly doesn't have the capability of doing that but if we were to work with big tech, then the potential exists for there to be real contact tracing versus, the type of contact tracing that's discussed right now.

In your view, how often does the government work with big tech on these types of endeavors? Is there some sort of legal minutia or middle ground where the government can work with big tech in order to provide information to them where the government itself cannot quote-unquote spy on you in certain circumstances,

Craig Peterson: [00:05:44] Oh, that's got to be difficult. Bottom line. The government has been worked with big tech a lot.

We've seen tens of thousands of cases where the government has issued blanket warrants for a location. So for instance, what happened on the sixth down in Washington, DC. They can, they do, and they have sent a warrant off to Google being their favorite target because their information is gathered from all kinds of devices. They say, who was in this area? They get this blanket warrant and tada, Big tech will produce that information, but that's when they have a warrant.

We found now that various parts of government, including the military. Homeland Security has been doing this as well. They go to big tech and say, Hey, I want to know where this person is, where they've been and big tech tells them that, without a warrant, because what they're doing is harvesting your data.

You know, that free app that you have, Justin. That app isn't as free as it seems to be. Because they are.

Chris Ryan: [00:06:51] What do you know about Justin, that I don't know?

Craig Peterson: [00:06:53] Yeah. Well,

Justin McIssac: [00:06:54] Which app you talking about?

Craig Peterson: [00:06:56] The traffic one that you're using.

Chris Ryan: [00:06:58] Oh, the traffic one. Yeah, that's it. Justin, we need, we'll get back to that. After. I'll handle that myself. I don't need your help, Craig.

Craig Peterson: [00:07:10] They're not providing you with a free service. They are charging you and they're charging you by getting your information. Government and military intelligence and other agencies, go to these data aggregators that are taking all of this data and putting it together.

Now there's the next step when you're talking about, well, let's making sure that we got the social distancing going on. And what if I came in contact with someone that had some form of a terrible disease. The type of tracking that's done by our phones is not accurate enough for the government to go in and say, where are you within six feet of this person that came down with whatever it might be.

Chris Ryan: [00:07:49] They can tell you the same place, but they can't tell if you are within even, a hundred yards of the individual. You could have been in the same shopping mall. It could have been the same restaurant, but you don't know exactly the proximity.

Craig Peterson: [00:08:00] Yeah, exactly. Right. Because once you get inside now they've lost all of the resolutions and even outside there's a reflection and other things that cause problems. Ever tried to use GPS and downtown, well, Manchester is a little different but Boston, New York, some of these bigger cities, it just doesn't work.

So the type of tracking that's used for this contact tracing is different. It requires an app on your phone. That app basically uses Bluetooth to see if there's any other phones around that it's compatible with or even any other phones around.

When you get into South Korea. If you get it, certainly in China. They will push an app to your phone, they have control over it in many cases. Therefore they can force the app onto your phone. People tend to be a little more compliant in South Korea than they are in the US.

I don't know if you've noticed that or not, but they'll download these phones themselves, will keep tabs on, who's close to whom and that will help with our contact tracing. Even in the best of cases, they've only found that there's usually about 50% compliance.

If it's done by the government saying, Hey people, just go ahead and download an app so we can all be safer. The only place where we have very high compliance are places like China.

Chris Ryan: [00:09:19] Craig as always appreciate you joining us for the show.

Craig Peterson: [00:09:22] All right. Hey, thanks.

By the way, for those of you, who've been asking Karen and I are getting really close to having this Intro to Windows Security course done and out. Yeah, and we've already caught another three or four together.

This is going to be life-changing. I really do think so for so many people, because you've been trying to solve some of these problems. You're worried about what's positive to do, what's negative to do because some of the things that these vendors, advertisers are trying to get you to buy will actually make you less secure.

So keep your eyes on your mailboxes, cause that's coming soon. Take care. We'll be back tomorrow.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

A lot has gone on this week with the installation of new US leadership and the ramp-up of security theater by the Democrats. That aside we have lots to talk about on the technology front. We will begin with the NSA and their warning to businesses in relation to DNS resolvers. Then we will talk about Law Enforcement and Smart Phone encryption, New safety regulations for automated vehicles, WhatsApp and Facebook, Signal secure messaging, Warren Buffett's thoughts on cryptocurrency, and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

The NSA warns enterprises to beware of third-party DNS resolvers

How Law Enforcement Gets Around Your Smartphone's Encryption

Trump team modernizes car safety regulations for the driverless era

WhatsApp clarifies it’s not giving all your data to Facebook after surge in Signal and Telegram users

Signal recovers from a day-long service outage

Warren Buffett blasted Bitcoin as a worthless delusion and 'rat poison squared.'

The Guy Who Built The World Wide Web Is Building A 'New Internet', Where You Control Your Data

Superfast 5G in the US still a work in progress

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We all want to have a little privacy. So what should you be using? What are the apps that you can trust? We're going to talk about that. WhatsApp, Signal. iMessage, messenger, all of that stuff. That's our focus for today.

We have really gone around the bend here.

Just as far back as the federal government has been trying to get access to encrypted communications. This has been going on forever. Look at our constitution. Look at the amendments to the constitution, also known as a bill of rights. Trying to protect us. We're supposed to be secure in our papers among other things.

So what does that mean? Why was that put into the constitution? It was because an authoritarian government is always trying to look over our shoulders and at the time that authoritarian government was their British monarchy and frankly parliament as well. And they just waltz in, they would break in a door if they had to.

And they would start grabbing papers, trying to find someone that was an insurrectionist who was going to overturn the government. And of course, it didn't stop there. That's just one example here in America of what happened to us when we had a boot on our neck is what it's called. And so we established part as part of our country here in the constitution.

Prime right to privacy, the absolute right to privacy. And over the years, we've had all kinds of invasions of our privacy. Of course, you know what happened with Wiki leaks and leaking of Hillary Clinton's emails, at least to some of them. I'm not sure we saw all of them. We saw the break into the NSA and the leaking of the tools that the national security agency had, that they were using to spy on us.

You might even remember the Church commission back in the early seventies. And they found that the federal government had been given a direct pipeline, this massive pipeline since I think it was the late forties.

But after the second world war ended, they had a direct pipeline from A T and T directly to our intelligence agencies. They had access to all of these conversations that were going on and who knows what they were doing with it. And so that's what the Church commission found out, frankly. I think we need another church commissioned to look into this.

You remember J Edgar Hoover and what was happening with the FBI where he was using it to spy on people he perceived as enemies. I think he was even spying on mistresses and things, too, trying to figure out who was sleeping with whom and how might that be used in order to gain control over someone, to extort them. This has gone on again and again, and now we have the findings that came out of the house. From a subcommittee where the house Republicans released the findings on this Russia probe and that Russia probe ended up showing a: Hey, nothing happened. There was no collusion between Trump and Russia.

In fact, The collusion existed on the left, on the Hillary Clinton campaign, which was basically something she had put together in order to use it against some other people. It wasn't originally intended to be used against Trump apparently. So now we fast forward to bill Clinton, the next, really big thing that happened.

And that was, he was pushing our government to force people who made devices that use encryption to use something called the Clipper chip. And this Clipper chip was going to guarantee security guarantee privacy. And the idea was, by the way, there's a backdoor in there and we could not inspect the source code for this chip.

We could not inspect its innards if you would. We had no idea what was going on, but it did come out. Yes, indeed. There was a back door, the back door was only there for law enforcement. Don't worry about it. People it's not, it's not going to be misused, but any time there is a back door, there's a hacker trying to get access to that back door, correct?

Yeah. Yeah. Very correct. It happens all of the time. Our information that we are sharing with anybody just isn't safe. Look at the federal agencies that have been breached almost every one of them, including the federal agency that maintains all of the employee records for all the people that work and worked overtime for the federal government that was hacked. China apparently stole that. And that was the records of, for everybody, including their background check information, you name it. And of course, when the FBI is doing a real background check, they really dig. So what information did they get from that?

Our information is not secure. And with this Clipper chip that was being pushed. I don't want to blame bill Clinton here. I'm not pointing a finger at Bill Clinton. Okay. Get me, right guys. But. W what happened was, again, the government's obsession with gaining access to our private materials.

I'm not trying to hide something. I just don't have anything I want to share. I love that saying and it is so true. I am not trying to hide anything.

Now, there are people that are trying to hide something. So what do you do about those people? That's always the argument, isn't it. And has been for. Ever, frankly, I'm sure it goes way back to the first community of two caveman families, right?

Trust yet verify and verify means sneak in, look through the iPad, the iPhones, right? Look through anything they want to. Now I've got some information on that too, coming up. So that was the next, really big thing. Here was the Clipper chip and we're all gonna use the Clipper chip. Fast forward.

We had, of course, the terrible incident in New York City on September 11th. I remember it. I had the news on, I could not believe my eyes watched it happen in real-time. Live. It was just shocking what had happened. And so in response, we pass something that we called the Patriot act and that Patriot act was there to protect us, but it gave these agencies more and more power.

And we found out later on, they had been collecting all kinds of information on US citizens illegally. Illegally, not just unconstitutionally, which is, bad, very bad, but against the laws that were in place, the rules or regulations. They started ignoring them. So we just put it into, we codified it in law with the Patriot act, right?

They can spy on us because heaven forbid, we talked to someone in another country without it being monitored. Now I want to make it clear. I am not against monitoring someone if you have a court order. And it's a legitimate court order, not one of these kangaroo courts where you don't get to represent yourself.

No one in fact represents you. And as it turns out, lies are told. This whole Russian collusion thing where they started spying on the Trump Administration now that the transcripts are out from shifts committee, where he came out every day and bald-faced lie to everybody about how they had found all of this stuff on Trump and how terrible it was and how a lot of people were going to prison.

Looking at the transcripts, now we see he was absolutely lying and knew he was lying and he still he's still in Congress. Oh, two cycles later. I don't understand these people, but they had testified to these FBI officials and others that if they had known then what they know now, they would never have signed off on having this.

Kangaroo court effectively, this court that has minimal oversight, they would never have signed off on these applications to the court. In order to track the movements of the Trump campaign, what they said, what they did, everything you might remember. Soon after Trump came into office, he was informed that he was being spied on that he has his offices were tapped, et cetera.

Do you remember that? And they had set up a skiff there for him, which is one of these secure Faraday cage things where you can't monitor electronically through this thing. So they had to set it up. And then they told the president that other agencies were spying on him. Continuing to spy on him nothing was ever found.

When you can read transcripts now that came out of that committee and yet somehow they managed to impeach him anyway. Completely political process. It's just. It's insane where we have gotten. And so I am concerned because how many times are we going to say I have nothing to hide. I don't care if they have access to this information because a lot of this information could be used against us.

And if the government has it or the government can collect it. The bad guys can too. That's what I was just saying that the federal government, I think pretty much every agency, certainly, all of the major ones have been hacked. So if they have our information, it's now in the hands of the bad guys, it's in the hands of China.

We know that. Our backgrounds are out there. Even the people that got secret clearances and higher, it's all out there now. So how can we make sure our data has a modicum of success and being secure in private because privacy is guaranteed to us in the constitution.

You're listening to Craig Peterson.

The right of the people to be secure in their persons, houses, papers, and effects against unreasonable searches and seizures shall not be violated and no warrants shall issue, but upon probable cause, the rest.

We're taking a little time to talk about privacy and security. What kind of rights do we actually have when it comes to privacy and security? And what does it ultimately mean to all of us? It's getting crazy out there.

I just read a little bit from the fourth amendment and we talked in the last segment. About what does this mean? Why were we trying to protect ourselves? And of course, things have changed a whole lot since those days. You had people who might break in the government, might steal, sneak a peek, et cetera.

We know from some of these hearings we've had in Congress that all envelopes were steamed open and their contents examined. Okay. We had people who were being examined by the FBI for no reason. Other than that, their political views. It gets very difficult over time in history. After nine 11, they started spying on us even more and they started collecting more and more information about us.

And part of what they set up was this secret court where they could get a court order. Too spying on you. And it was a secret order. You wouldn't know. No one would know, and they are spying on you. Now it's supposedly the FBI or whoever it is who's presenting this case to the court is supposed to represent your interest as well.

They're supposed to present evidence that might show that you, in fact, are not guilty. You couldn't be guilty of what they're accusing you of. But we now know how that went. At least in some of these cases, it didn't go well. And in fact, people were charged and considered effectively guilty and warrants were issued without anybody knowing now.

Oftentimes warrants are issued without people knowing anyway, whether or not it has to do with terrorism, whether or not you're a US citizen. Obviously, you're going to find out that there's some sort of a warrant and then you'll have a right to defend yourself. No, unfortunately, you probably don't have the resources that the federal government has in trying to defend.

Defend yourself. The federal government effectively has unlimited money. The same thing's true for state government. They can spend $10 million investigating you. Look at what they did with the Russia hoax, where they spent $35 million investigating, just investigating President Trump and his team.

Not finding any. Evidence of Russian collusion and it came out with, what was it, two indictments, neither of which had anything to do with Russian collusion. It basically trapped that were set up. We have less right. To be secure in our papers. Then we had not too many years ago and certainly not since when I grew up, but we do have the technology today.

And that's where there is a bit of a win. You know that I have continually said, don't use Android if your phone is lost or stolen, but that phone can probably be pretty easily hacked into depends on how old it is and what version of the software you're running. But we're now. When our computers and our phones adding something called a TPM.

And I discussed those in some detail in one of my more advanced security courses. But this module is designed in hardware to help protect. Everything on that computer. So it isn't just an encrypted desk. So the machine starts to boot up, asks you for the password, and now it can finish booting off of that encrypted desk and keep your data relatively safe.

As long as it computer's turned off. If the computer is on that data is accessible and hackers can still get into your computer remotely and get it all to that data. So there's the whole thing of data at rest. Then data in flight that we deal with all of the time in the business community. And frankly, we have that same problem as individuals, but most of us can't do anything about it.

So these manufacturers have included in their higher-end computers, these TPMS, and they're not that expensive when you order a computer. If you're buying it from Dell or some of these other places, you're going to pay less than $30 for this little module. If you buy an Apple computer, It's already there.

It's been built in for quite some time into Apple models, but most of the stuff, if you're buying it from a big box, retailer is not going to have this module, but this modules designed to keep the secrets, like your secret keys, et cetera, in the module and that module. Cannot be broken into physically or electronically.

The hackers cannot get into it. That is a very good thing. And the same, thing's true with some of our cell phones. So if it's an Apple phone, Yeah, it's built-in, if it's an Android phone, it depends, right? Android, isn't Android, isn't an Android, right? They all use different hardware. They may use the same central processor, but they also have controllers and then device drivers for those controllers, et cetera.

So it's out of Google's hands as to how secure your phone is going to be. And then you're lucky. Consider yourself lucky if you get actual updates for your Android phone. For security problems, because most people cannot get them, even if they wanted to get them, it says serious problem. So you are now more likely to be able to have the hardware.

That's going to keep things safe for, and you see some evidence of this with the thumbprint readers nowadays, you've got the facial recognition technologies, again, depending on the tech, you're using a lot of the Android devices, easy to fake the thumbprint thing on also on a lot of Android devices, easy to fake the facial records.

Ignition much harder on some of these others, but some of these TBMs, some of these security hardware modules have been hacked, and that is now true of Apple equipment. If they can get your hand, their hand on that equipment, they may be able to break the way into it. Now Apple's continually improving the equipment, you go to a country and let's say you go to China and you are trying to get something manufactured there.

You have your intellectual property from your company in the us. Some of it's there on your laptop. And you're thinking you're safe. There have been numerous documented instances where China gets their hands on your laptop or your phone. Whether you know it or not, sometimes they sneak in fact there's a whole security term just based on the evil maids.

But they'll get into your room and then they will hack into your computer and they'll steal your intellectual property it's being done even in the United States. Look at what's happened here. Representative stall wall out in California has been carrying on a long-term relationship. Physical relationship with a female Chinese spy.

We had both senators from California, who we had senators, Feinstein and Boxer, both had Chinese spies on their payroll, including one who was her driver for 20 years, was listening in on her conversations and relaying them back to China. Stonewall, believe it or not, is still not only in Congress, but it is on a secretive committee.

If you can believe this. I'm, my mind is I'm rubbing my head here. I had to go to explode. And in this improving windows security course, I have and in fact, a slide when I had in duct tape so that it just doesn't explode because it's just unbelievable to me. So Apple is equipment, some of the newer, slightly older equipment.

Is hackable. If they can get their hands on it. So what should you be doing? I want to get into, cause we're going to lose some of our listeners here. So when we come back, I'm going to get into WhatsApp and signal and I message and messages. I go into a great deal of depth in the improving windows security course, make sure you're on my email list. Craig peterson.com. So you get all of this training.

So I think we've established the government spying on us means they're collecting data anywhere. There's data. You're going to find bad guys trying to get at it. And that means our data gets exposed when there is the inevitable government hack.

I have been talking here about really constitutional rights.

Should the government be able to spy on us? When do they have the right to examine our papers? Our homes, our persons, our effect as is under the fourth amendment, I'll leave that to a legal show, but we do have that right. And it is guaranteed to us. For very good reason. So ultimately, what can we do to stay safe?

Because it isn't the government. That's a big worry, frankly. The big worry is the bad guys. It's the hackers. This is like a really good friend of mine. He just turned 76 right now. In fact, this last week. And he makes money by drugs, driving for Uber eats. And I think he does one other as well, but that's how he makes money.

And he came to me with a problem because of his last paycheck. Which I believe was about $700 for one week. That's a lot of work, right? That's a pretty big paycheck. His last paycheck did not end up in his bank account. So he did some investigation. I did some investigation. He called up the company. He was doing some of this work for, and.

It found out that the money that he had earned had gone into a hacker's bank account. Yeah. So there he is working really hard. He gets this paycheck and it doesn't show up and it's in the hands of a bad guy. The money has been transferred. They couldn't scrape it back. And here he is stuck. Now in his case, the problem was that he was not using secure passwords.

So I set him up with one password, which is a password manager and we used it to generate. Passwords for his bank account. And also for these apps, he was using in order to get the orders for the food, et cetera. So we locked them down and I helped him on the phone when he called up the company because the bad guy had also grabbed his email account.

So anytime you try and do an account reset the reset. Code was sent to the email that he no longer had access to an email he had for better than 20 years, a Hotmail email address, something I told him also should get rid of. So we had to play those games and then. And we went to Google and he didn't have a secondary reset ability here because his Google email account was tied into his Hotmail.

So any reset for Google went to Hotmail. He didn't have access to the Hotmail account. And so he lost access to the Google account. See the problem here that was created all because he knows, we can tell he was using the same password on a bunch of different accounts. One of those businesses that he was using had been hacked.

And that information was then used to break into his email account. And they found from his email account that he was delivering food on the sidewall, heck he's retired his only way to generate any extra income. And so they then took over his account. They changed his bank account number. In the Uber eats app and they changed it to one of theirs.

And the account number was for one of these places that will issue you a debit card. No questions asked. And once the money hits that debit card, they pulled it out and moved it overseas. It's it is a bad thing to have to happen. And by having that information, they were able to take over his identity, at least in this case, and start receiving his paychecks.

This is happening every day. What do we do? Already, I tell you, you got to use a password manager. It's just so important. And we go into that and I talk about them in my improving windows security course, because you've got to do it. You got to understand how to do all of that sort of stuff.

But there are other ways that you can be spied on. For instance, sending text messages, we're seeing more and more a technique that's been used by police for years now being used by bad guys, they've set up something that's generically now. Called a stingray device. It's actually a device made by one company.

There's multiple these types of devices, but it pretends it's a cell tower. It doesn't have to be up on a tower or anything. It just pretends it's a cell tower. So anybody's cell phone in the area is going to try and relay through them and they do literally let you relay through. So it goes from your phone to this fake cell tower.

And then from the stage. Fake cell tower. It forwards it to the real cell tower. So now they have access to information about who you're calling, but they also now have access to your text messages, your SMS messages, and they're using that to commit scams. What do you do really? These prescriptions I'm giving here are pretty darn straightforward.

They're not that difficult to do, but I understand they, they can be difficult to figure out. So that's why I'm doing these courses. I have these free courses, these emails I send out pretty much every week also had this free information in them. And then I had the more advanced courses too, but If you're using an end-to-end encrypted did messaging app.

These stingray devices cannot pick you up at all. Okay. Yeah. Okay. They're going to see there's data being transferred, but they're not going to be able to get their hands on the actual messages they'll just see some data. So what do I recommend you use? I'm going to make this quick because we are almost out of time here on some of these stations, but here's what I use, but let's just leave it at that for now.

We're going to get into more detail a little later on. If you get cut off of the show gets kinda off, make sure you go to Craig peterson.com. You can see the podcast there. You can listen to the whole thing. But what I use is an app called signal and. That's Signal. If the police have a warrant and they're coming for you, it's not going to really stop them.

And in many cases, okay. There's other ways to get access to your data, but it is going to stop the bad guys, which is who we are really trying to stop here. We want to stop the casual viewing of our person's paper's effect. From the federal government and state and local governments, because unless they have a valid warrant, They have no right to monitor us.

Okay. So it's going to stop that, but it's probably not going to stop them if they have a warrant, which is fine, because if they have a legit warrant, that's all well, and good. I am not against that at all, but it is going to stop. 99.99, nine, 9% of the bad guys, because they don't have the technology. They don't have the ability to decrypt or to put special malware on your phone or other things.

So signal, it's an app that had an outage. We're going to be talking about that this last week because so many people started using it after Elon Musk advised people to start using it. So how's that for something right. It's just absolutely amazing. It's worth doing, let me tell you in the course, I go into some more detail on how to set it up and what to do and why it is the best option.

Make sure you are on my newsletter that I send out pretty much every week. Craig peterson.com/subscribe.

What are our options when it comes to some of these messaging apps? So we're going to talk right now about how they work. What's the bottom line SMS versus some of these apps. What should you look at? What should you use? You know what I use.

I use something called signal, which is an app that's been out there for a little while. Moxie Marlinspike is the name of the guy that put it together and designed really the most secure messaging interface earlier. I mentioned how you can with some, something like a stingray. Intercept cell phones and cell phone signals.

And one of the things that you can intercept is what's called SMS, which is a simple messaging system. Now to my surprise, in the course of the window, improving windows security that I have, I go into some detail about how SMS came about and where it is, but for now, let's just talk about the basics of SMS.

It is obviously. Text message. That's what we call it. Very typically it's a very small message limited in the number of characters that you can send. In fact, that's what Twitter did. Twitter's a limit of the number of messages is based on the length of these SMS messages. Okay. I get that. And Assa mass was just designed as an afterthought as part of the new cellular technology.

It really wasn't an integral part and they were smart to say, Hey, wait a minute, we've got a little bit more bandwidth here. And so they took that bandwidth and used it for messaging apps. When you send a. Text message from your cell phone, your sending it in the clear, which means that anyone can intercepted and that's no surprise.

Anyone can pretty much intercept anything. But your message is not encrypted at all. So if your message is being intercepted, it is at that point now completely vulnerable to being read so bad guys that decide they're going to set up a sting raid type device can now listen into your conversations, frankly, they can inject things into it.

The other thing about it is the. Phone company is also listening in. So remember how much I've complained about people, businesses, government agencies that collect our data. And one of the reasons I complain about it is they've got the data, that means they are going to be targets of the bad guys.

Think about Sutton, right? Robbing banks. Why did he Rob banks? And the answer of course is supposed to be that because that's where the money is. Why would you Rob a bank? If there was no money, it doesn't make much sense. So why would they not go then and try and break into telephone companies or other places that have your messages stored?

Remember? How my friend here just a couple of weeks ago, had his paychecks deposited into a hacker's account. If they can gain access to your text messages, they now have the ability. To potentially use that to recover an account. Now recover an account. Isn't really what they're doing. They're recovering your account.

They're pretending they are you. So when you get that two factor authentication message coming in from whatever website it is out there that you've been using that two factor authentication messenger message is. Yeah, going to them because they can see it. So it really is that easy. I hope that's not too confusing.

So you send a message to somebody using SMS using regular text message. It can be seen. It can be read. It is stored by everybody in that route. And they can include bad guys that are sitting there watching what you're sending. Then when it gets to the other side is still in the clear and that person goes ahead and reads it.

So that's the basics of messaging, right? That's your very basic, your bottom line text message. If you move upscale a little bit. You now have some apps that can be used for messaging. And I don't want you to confuse Facebook messenger here because Facebook messenger of course, is used by Facebook.

They are watching what's going on and what you're saying, and it's not a secure platform. I was going to say at all, it is secure, but it's not really secure enough for messages you want to send back and forth to friends. And it's definitely not good for account recovery because most of the account recovery stuff, and two factor authentication.

Is not two factor authentication. So make sure you keep an eye out for my improving windows security course, which should be released and knock on wood in about another week or so I had said January, and I think we'll make the January deadline here of having it out there. Yeah. But in that I explained two factor authentication.

Why you don't want to use SMS or text messages for it. And also some workarounds, including a free workaround that you can use. So that's all in the course, but let's stay basic here right now. Messages from Facebook or not considered secure what's happened is something that about 2 billion people in the world that is pretty dramatic.

Yeah. And it is designed as an end to end encrypted. Did communications channel. It can be used for little short text messages, longer messages. You can have voice calls on it. You can have video calls on it, et cetera. We use at the office, a WebEx phone system. It's made by Cisco. It is encrypted. It is what on the president of the United States desk right there.

Although he has a net, an extra encryption module on it. Just really cool. Plus he can turn off physically disconnect the microphones and things makes a whole lot of sense to be able to do that, but it set up so we can have secure communications. We have one that's called compliant and we use it inside the business and it has cameras on the phones and displays and stuff.

It's really quite cool and ties into the computers. So that's probably not something you guys are going to be able to have. So a lot of people use WhatsApp. And the WhatsApp app has been known to be quite secure. It is also using that algorithm, that software that was developed by Moxie Marlin spike. So it is end to end encrypted.

So when you send a message from your smartphone using WhatsApp, It's encrypted on your phone and then it is transmitted over the regular internet. So that internet connection may be coming from the phone company. It may be over, a 5g or 4g or 10 G in the future, whatever it might. Be over their network and then against to the other side, by bouncing around in a whole bunch of networks, remember internet is interconnected networks.

It's a whole bunch of them. So it'll bounce around. It'll get to the other side. And once it's on the other side, it will be decrypted and there are. Session keys. There are. When you're using signal, there are keys specifically for individual conversations, individual users, and even individual packets.

It's really quite involved. You might have noticed about. Two weeks ago, as I did that, WhatsApp came up with a message and you read that message. And to me, it was scary because it looked like Facebook who bought WhatsApp for what was it? A couple of billion dollars. It was over a billion, I think about eight, nine years ago.

They bought it. And they gave people until 2016 to opt out of having Facebook take copies of all of their WhatsApp contact. So the message you got from WhatsApp via, or from Facebook via WhatsApp here a couple of weeks ago said okay. So we are going to be basically gathering information about you.

Now that really worried about a lot of people, myself included. So I made sure I had signal set up with everybody that I'm planning on talking to. Because signal is much more secure than what's happened. Some of these others. Don't know, a lot of people jumped ship. The stats that are out there right now are saying that we had millions of people sign up for signal.

They left WhatsApp because of the, what Facebook is calling confusion over this message they sent out. And Facebook is saying, Hey we're not breaking encryption. We're not going to watch what you're saying, but we are going to keep track of information about you and about your contacts and who knows how far they're going to go with it.

Odds are that they'll start pushing in. Advertising into your stream and other things, which also really concerns me because all they need is a bug and that bug could potentially allow bad guys offers to get into your machine into the app. When I say offers, it There could be a bug in the advertising interface that allows now access to private messages.

So I would be cautious about it. And a lot of people have apparently about 25 million people over the course of just three days signed up for signal. On the app store, which is just amazing. Oh no, excuse me. That was telegram, which is another secure communications piece of software. I'm not a big fan of telegram, much bigger fan of signal.

That's the only one I really trust out there. Hopefully this was clear enough for you. I do go into this and I have some diagrams and other things in my improving windows security course. Put together that helps you, of course improve security on your windows, computer. But because windows computers now are also tied in with surface tablets, which are people are using.

And I understand why if you're stuck in the windows world, why you'd get a surface tablet and those surface tablets have built into them cell modems. I had to go and do the two factor authentication, more and messaging and how that all go. So hopefully understand all of that. Make sure you are on my newsletter list.

So you get all of the latest above the courses that are going on. I've been trying to put. A little bit of training. I bought a three minute training into the emails over the course of the last couple of months. Really? And it's easy. All you have to do is go to Craig peterson.com and sign up when you get there.

Craig peterson.com/subscribe. We'll take you there.

The internet phone book, if you will, or address book is beyond repair right now. It's not beyond repair. There are some things going on right now to make you more secure. We're going to talk about that. So stick around.

When we go online, use something known as a URL, right?

You're familiar with that. That's that part of the bar up at the top of your browser, it's got the name of a site. It might have a slash and. Slash subscribe, like when you subscribed to my newsletter@craigpeterson.com slash subscribe. That first part of that URL, the Craig Peter sawn.com known as the left-hand side.

And it's the part that comes right after the HTTPS colon slash. So that's the domain name? Craig peterson.com. Easy enough to just type that in. How do you end up at my website? DNS is something that's been a mystery of black box for a lot of people, but it has been hitting the tech news lately because of some problems, basic problems. One of them is that requests, that DNS requests, they request your turn. Craig peterson.com into an internet address is transmitted in the clear. The other problem is many times our ISP are taking that DNS request and fulfilling it themselves. Those are both problems. So the first problem where we have our ISP PS intercepting, our DNS requests means that they know what we're looking for, where we're going online.

So your ISP, it could be Comcast or Verizon, or who knows who, depending on where you live. Your ISP sees that DNS requests and those Oh, okay. He's going to Craig peterson.com or Google or TD bank or whatever might be. They know it. Okay. That's some problem enough. The other problem I mentioned is it's in the clear, because it's sent in the clear your ISP can intercept it.

No problem. Some RSPs are not only intercepting them. They are changing things and they're giving you different results. Which to me is very frustrating. So if you're trying to do a search, for instance, instead of sending it to duck, duck could go or whatever your favorite search engine is. Your ISP is going to grab it and fulfill it itself and give you advertising different advertising as part of the search results.

And in some cases as well, if you try and go to a website that does not exist rather than telling you. Oh, Craig Peterson without an O a doesn't exist. It will send you to their own webpage that has advertising on it. So all of those things are rather annoying. Bad guys can also mess around with your DNS settings.

Most small businesses and home users have a router at the edge of the network that handles a protocol called DHCP. It's DHCP is a protocol that hands out IP addresses. So for instance, if you look at the IP address for your machine, the odds are pretty good. It saying the one nine two.one six, eight.one dot something range.

That's the most common address on the internet is called a non round-table address and they use nav at the network edge and stuff. But that server that is sitting in your router slash firewall is. Providing data to your computer or your other devices like your television, the Roku, et cetera.

It's providing information to your devices, telling it which DHCP server to use. So if you're on your web browser and you type in Craig peterson.com, it knows your web browser, your computer knows what the IP address is too. Resolve that name, the DNS server it should be using. So another thing bad guys have been doing is they break into your router slash firewall at the network edge.

And then they change the DHCP servers address in your router slash firewall. So you can imagine what happens now, if you're trying to go to a website, the bad guys can send you wherever they want. And in some cases, they are sending you to their own version of your bank's website, or they're sending you to their own version of Google three.

They are completely hijacking your computer by just changing these DNS settings in your Rotter and firewall at the edge of the network. That's all they have to do. So yet another reason to make sure your router firewall has the latest firmware in it. Hopefully it doesn't have security problems. They're going to nail you.

I have this in my course as well, more advanced networking course on what to do, how to do it, et cetera. How do you solve these problems? Some of these companies and organizations have decided they're going to use their own protocol, their own way of doing it. So instead of sending out the name request to the standard DHCP server that your computer was told, when it was powered on to use it, you're going to use theirs.

And here's how they're doing it. They have in Mozilla, for instance, Firefox product. If you're using the Firefox browser, it is ignoring the DNS settings that are on your computer. And it's opening an encrypted session to a DHCP server that Firefox knows and loves. That can be a problem. It's not necessarily a problem.

It's probably a better thing to do than what most people are doing in their homes right now, which is just leaving everything at the default and letting their ISP kind of decide which DNS server to use and how to use it and everything else. So I'm not going to blame them for that. I think from that aspect, it's a pretty good idea.

But because it's encrypted, it's called deal H by the way, which is short for DNS over TLS, which is meaning it's encrypted. And DNS traffic is sensitive traffic. So why not encrypt it because they. The default protocol doesn't have encryption. So they now send the request directly from your browser to one of these cloud services that are out there.

One of the common ones is one.one.one.one. Which is a very common nowadays site that you might see CloudFlare. There are some others as well. So the, your ISP cannot see the DHCP request. The bad guys can change the settings on your firewall. All they want. They're not going to be able to redirect your you via DHCP.

And they cannot spy on where you are going online. All very good, right from that aspect. So for regular people using this inside of Firefox great idea very easy, very simple. The other nice thing about this system, because CloudFlare is looking at the records of DNS records and identifying potentially.

Banned websites you don't want to go to it can, and it does filter them out. So you have that extra layer of protection. If there's a website, that's a bad site. It is getting filtered out. When you're trying to go there. However it doesn't do any good to a cause it can't filter applications that you're running.

If there's malware on your computer, trying to phone home, not going to help with any of that. I do cover all of this, by the way, in the introduction to windows security course, that's coming out here. Of course you can sign up@craigpeterson.com and I'll let you know what's going on with it. But I do cover that.

And how do you do it? However, here's the problem. If you are a business that is trying to stay secure, this is going to make you less secure because a business like mine or my clients that have information, that's valuable, they have bank accounts, they have intellectual property that they don't want to have stolen.

So their information is valuable. They want to intercept. These DHCP requests, because you don't necessarily want your random user inside your business network. The sales guy or gal going to the dark areas of the web and you know what those are, where there's a whole lot of bad stuff without your knowledge, because you don't know.

If they try and type in playboy.com and it gives them the IP address and they can get their you're none, the wiser. Because that request is encrypted. So one of the best things to do in a business network is to use something like Cisco's umbrella that we explained in the introduction to windows security course.

And we also explained some free versions that you can get and you can use. So this is actually. Dangerous in some situations, DOH, it is much more or secure another situations, but I think there are better ways to deal with this and we covered in the course. So make sure you keep your eye out for the introduction to windows security course.

That is coming your way very soon. And if you are on my newsletter list, you'll find out about it as well as weekly. Little micro trainings that we're doing. Craig peterson.com.

The internet phone book, if you will, or address book is beyond repair right now. It's not beyond repair. There are some things going on right now to make you more secure. We're going to talk about that. So stick around.

hello everybody. Craig Peter Sohn here. You're listening to us on news radio five 60 am and 98.5 FM w G a N. And you can listen also on your Google home device. Just say, Hey, Google play. W G a N. And it'll take care of the rest for you. It makes it easy. We, when we go online, use something known as a URL, right?

You're familiar with that. That's that part of the bar up at the top of your browser, it's got the name of a site. It might have a slash and. Slash subscribe, like when you subscribed to my newsletter@craigpeterson.com slash subscribe. That first part of that URL, the Craig Peter sawn.com known as the left-hand side.

And it's the part that comes right after the HTTPS colon slash. So that's the domain name? Craig peterson.com. Easy enough to just type that in. How do you end up at my website? DNS is something that's been a mystery of black box for a lot of people, but it has been hitting the tech news lately because of some problems, basic problems. One of them is that requests, that DNS requests, they request your turn. Craig peterson.com into an internet address is transmitted in the clear. The other problem is many times our ISP are taking that DNS request and fulfilling it themselves. Those are both problems. So the first problem where we have our ISP PS intercepting, our DNS requests means that they know what we're looking for, where we're going online.

So your ISP, it could be Comcast or Verizon, or who knows who, depending on where you live. Your ISP sees that DNS requests and those Oh, okay. He's going to Craig peterson.com or Google or TD bank or whatever might be. They know it. Okay. That's some problem enough. The other problem I mentioned is it's in the clear, because it's sent in the clear your ISP can intercept it.

No problem. Some RSPs are not only intercepting them. They are changing things and they're giving you different results. Which to me is very frustrating. So if you're trying to do a search, for instance, instead of sending it to duck, duck could go or whatever your favorite search engine is. Your ISP is going to grab it and fulfill it itself and give you advertising different advertising as part of the search results.

And in some cases as well, if you try and go to a website that does not exist rather than telling you. Oh, Craig Peterson without an O a doesn't exist. It will send you to their own webpage that has advertising on it. So all of those things are rather annoying. Bad guys can also mess around with your DNS settings.

Most small businesses and home users have a router at the edge of the network that handles a protocol called DHCP. It's DHCP is a protocol that hands out IP addresses. So for instance, if you look at the IP address for your machine, the odds are pretty good. It saying the one nine two.one six, eight.one dot something range.

That's the most common address on the internet is called a non round-table address and they use nav at the network edge and stuff. But that server that is sitting in your router slash firewall is. Providing data to your computer or your other devices like your television, the Roku, et cetera.

It's providing information to your devices, telling it which DHCP server to use. So if you're on your web browser and you type in Craig peterson.com, it knows your web browser, your computer knows what the IP address is too. Resolve that name, the DNS server it should be using. So another thing bad guys have been doing is they break into your router slash firewall at the network edge.

And then they change the DHCP servers address in your router slash firewall. So you can imagine what happens now, if you're trying to go to a website, the bad guys can send you wherever they want. And in some cases, they are sending you to their own version of your bank's website, or they're sending you to their own version of Google three.

They are completely hijacking your computer by just changing these DNS settings in your Rotter and firewall at the edge of the network. That's all they have to do. So yet another reason to make sure your router firewall has the latest firmware in it. Hopefully it doesn't have security problems. They're going to nail you.

I have this in my course as well, more advanced networking course on what to do, how to do it, et cetera. How do you solve these problems? Some of these companies and organizations have decided they're going to use their own protocol, their own way of doing it. So instead of sending out the name request to the standard DHCP server that your computer was told, when it was powered on to use it, you're going to use theirs.

And here's how they're doing it. They have in Mozilla, for instance, Firefox product. If you're using the Firefox browser, it is ignoring the DNS settings that are on your computer. And it's opening an encrypted session to a DHCP server that Firefox knows and loves. That can be a problem. It's not necessarily a problem.

It's probably a better thing to do than what most people are doing in their homes right now, which is just leaving everything at the default and letting their ISP kind of decide which DNS server to use and how to use it and everything else. So I'm not going to blame them for that. I think from that aspect, it's a pretty good idea.

But because it's encrypted, it's called deal H by the way, which is short for DNS over TLS, which is meaning it's encrypted. And DNS traffic is sensitive traffic. So why not encrypt it because they. The default protocol doesn't have encryption. So they now send the request directly from your browser to one of these cloud services that are out there.

One of the common ones is one.one.one.one. Which is a very common nowadays site that you might see CloudFlare. There are some others as well. So the, your ISP cannot see the DHCP request. The bad guys can change the settings on your firewall. All they want. They're not going to be able to redirect your you via DHCP.

And they cannot spy on where you are going online. All very good, right from that aspect. So for regular people using this inside of Firefox great idea very easy, very simple. The other nice thing about this system, because CloudFlare is looking at the records of DNS records and identifying potentially.

Banned websites you don't want to go to it can, and it does filter them out. So you have that extra layer of protection. If there's a website, that's a bad site. It is getting filtered out. When you're trying to go there. However, it doesn't do any good to a cause it can't filter applications that you're running.

If there's malware on your computer, trying to phone home, not going to help with any of that. I do cover all of this, by the way, in the introduction to windows security course, that's coming out here. Of course you can sign up@craigpeterson.com and I'll let you know what's going on with it. But I do cover that.

And how do you do it? However, here's the problem. If you are a business that is trying to stay secure, this is going to make you less secure because a business like mine or my clients that have information, that's valuable, they have bank accounts, they have intellectual property that they don't want to have stolen.

So their information is valuable. They want to intercept. These DHCP requests, because you don't necessarily want your random user inside your business network. The sales guy or gal going to the dark areas of the web and you know what those are, where there's a whole lot of bad stuff without your knowledge because you don't know.

If they try and type in playboy.com and it gives them the IP address and they can get there you're none, the wiser. Because that request is encrypted. So one of the best things to do in a business network is to use something like Cisco's umbrella that we explained in the introduction to windows security course.

And we also explained some free versions that you can get and you can use. So this is actually. Dangerous in some situations, DOH, it is much more or secures other situations, but I think there are better ways to deal with this and we covered in the course. So make sure you keep your eye out for the introduction to windows security course.

That is coming your way very soon. And if you are on my newsletter list, you'll find out about it as well as weekly. Little micro training that we're doing. Craig peterson.com. Make sure you follow along there.

Before he left President Trump made sure that the rules for our electric vehicles were overhauled because the federal government safety regulations were based on 1910 type of technology. We're going to talk about that.

The Trump administration has done a lot with regulations and just before he left office, we saw a number of things, hit that they'd been working on for years.

And until just the last week, really the federal government's car safety regulations were based on assumptions that came out of the 19 hundreds here. 19 zero, zero, they assumed that a vehicle had people inside and they also made a big assumption that one of those people will be the driver.

That is not necessarily what's going to happen in the future. We've all had these beautiful dreams of what these autonomous vehicles are going to be like, where we're cruising down the road. Just sitting there reading a book or heaven forbid scrolling through social media or something. And the car's driving itself.

There may or may not be a steering wheel. So in fact, that's one of the problems let's say there is a steering wheel. Who's the driver. Because you might want to have it so that you've got the driver and the passenger and they're looking forward and there you are doing a little bit of something else and all of a sudden they notice something, the cars misbehave, or maybe that last mile.

As were, when you get off the highway and we're doing some parking and it's a little confusing for the car. W why not have the passenger takeover? Okay. Why have a steering wheel, why not have a joystick that either the passenger or the driver could control? Why not just have something that the passenger complaint and the car can sense the finger and where the fingers pointing and that's where the car goes.

There are a lot of options that just are not. Built into our transportation code, federal or state. That's a very big deal. There are a number of vehicles out there that are designed for hauling cargo. You might've seen some of them deliver pizzas and beers on campuses of universities and they drive around by themselves.

They avoid obstacles and they're really cool. And then when they get to the right person, Or at least to the right building, it sends a little text message off to the person that ordered it. They come down, they punch in a code, it opens up and there's their pizza and beer for the night. Okay. I can see that.

But in that case, those vehicles are on a sidewalk. They're not covered by the same rules as vehicles that are on public roads. How about some of these vehicles? Like the neuro. And you are, Oh, I assume I'm pronouncing that right. This thing is very cool. It's almost like a little bigger brick, right?

But it's fairly rectangular in shape and it has a couple of compartments inside. It has a refrigerated area. It has an area for general groceries and it is designed to haul cargo and go on the roads. It doesn't have any people inside. So why does it need to abide by the regulations that are based around people?

It doesn't have a driver. There's no driver's seat. There's no steering wheel. There's no need for a windshield because the whole thing is enclosed. This is really a very big deal. And this is all part of the federal motor vehicle safety standard that requires every car have seat belts, airbags, his steering wheel, a brake accelerator, even a driver's seat.

It has minimum standards for everything from not just the fact, you have to have a windshield, but what the strength of that windshield is how it's supposed to break crash, test performance, all of those sorts of things. But the whole, all of those assumptions are already frankly, out of date. And they're going to get more and more out of date.

Remember how I said regulation, strangled technology. They strangle innovation, no matter what, whether it's technology or otherwise because they make assumptions based on old things. So the rules and regulations always tend to follow technology. But in some cases, they really squelch technology. Look at the nuclear regulations.

There they're locked into the nuclear power plant designs of the 1950s. That's something President Trump tried to straighten out and had some success at. And now we're talking about regulations for motor vehicles that almost applied to the 1890s. When the first vehicles hit the roads out there. So one of the things the Trump administration did before it came to a close is it had the national highway traffic safety administration publish a new version of these vehicles, safety standards that recognize that some cars don't have drivers and some vehicles don't have.

Any people inside at all. So thank goodness for again. So many regulations were updated under the Trump administration and a number of them. I mean like thousands that were useless, it didn't add anything. We're completely gotten rid of written off the bucks, but neuro is one of these companies that's really going to benefit from this.

This is a startup, a very cool little delivery robot. You can look them up. Bond line and you are, Oh, they're designed to operate on-street rather than the beer and pizza robots that are operating in the universities on sidewalks. So very cool ARS Technica has a good article on this and the Herald.

Neuro excuse me, neuro hailed. This new regulation is a quote, significant advancement that will help neuro commercialize our self-driving delivery vehicles. How's that for corporate speak. So it's actually very good. These requirements that were in these vehicles, safety standards make things worse in some case for delivery vehicles and are completely useless and make the vehicle heavier.

Now, remember a heavier vehicle. Is potential if it's in an accident going to cause more damage, right? So requiring airbags requiring seat belts requiring a driver's seat just makes things worse for a vehicle that has no passengers makes things worse for everyone, including a pedestrian or a cyclist that might get here.

We saw that just terrible accident that occurred here or a year or two ago. So we've got to be careful. Late last year, they asked for special exemptions for some of the rules because they don't have windshields. They don't have the right passengers, et cetera, et cetera. And the traffic safety administration waived the requirements.

And also by the way, w way rules about the design of door locks and seats. These vehicles don't have to meet crash worthiness standards since they're already gonna have. Pizza or groceries on board. Very interesting. You're going to have classes of vehicles that are little delivery vehicles. You're going to have them that have passengers on board and you can have big trucks.

They all require different standards. Glad Trump did this before he got out of there. I hope that this continues. Okay. Hope it continues. And we don't get a repeat of what happened in Tempe, Arizona. Back in 2018, when a new Burr self-driving cars, truck, a cyclist stick around.

The lockdown has changed a lot of things, including some of these restaurants, why even have a physical restaurant, if everybody is ordering Uber eats or some sort of delivery mechanism, why. Just like that restaurant has been hard. Hit it just a terrible thing. I remember I went to get my shoes fixed. I went to a cobbler.

I took a shoe in it. He fixed it for me. And yeah, I'm one of those guys, who knows where the cobbler is. And I went to pick it up my shoes up. And right next door was an older restaurant and this restaurant was really, in a little bit of a rundown area of town. Where else could a cobbler be nowadays?

There's not as though it's a high-volume or high-profit business. And. He was, this guy was opening a bar and it was an Irish-themed bar and it was going to open on St. Patrick's day 2020. So think about that for a minute. St. Patrick's day in 2020 was not, I would say the best day to open. Up a bar.

So let me see. Last year, 2020 St. Patrick's day was Tuesday, March 17. Do you remember what happened the day before? On March 16th. That's when the lockdowns started going into effect. That is not a good thing, frankly, because that lockdown meant that this poor guy who was, he was in there, he was by himself.

He was painting repainting and stuff like that. The headline they're all green out in front of the bar and getting everything set up inside all of the taps for the beers and everything already. So he had put, I don't know, what does it cost at least a hundred grand open a restaurant. And most of them failed as like any other business.

So I would imagine he's out of business and out of luck he'd been saving. He was a younger guy, probably his mid-thirties, maybe late thirties. And he'd been saving up to put this restaurant together. That's just one story. There's many stories of other restaurants that have been family restaurants in some cases for generations that just could not.

Survive and you and I obviously with the lockdown we're not going to these restaurants like we used to, and I really miss it. I've never been a big restaurant guy. I usually make meals at home or my wife feeds me at home and right. I get taken care of that way. It's been a wonderful life.

Let me put it that way. Okay. But I do enjoy going out to a restaurant and talking with my buddies and just enjoying it, talking with my wife, going out with the kids, which we've done for many years and was a bit of a surprise sometimes when there'd be 10 of us, which is generally considered a large party.

But no, that was just my wife and I and our yeah. Kids. People I'm going to sit down in restaurants at least right now. And with 20 to 50% of restaurants maybe never coming back. Where are we going to end up Pat? So there's been a whole new type of business. That's sprung up from this. And I had noticed this years ago, at least something similar to this where you would go into a restaurant and you'd find that they had in fact been sharing a kitchen.

So that's very true in a lot of smaller hotels. You go to some of these little niches, hotels, and room services, really the restaurant next door. So you order something and it comes from that restaurant. That whole concept has just grown like crazy. And there's a great article in Forbes magazine about what are called ghost kitchens.

A ghost kitchen is a kitchen that doesn't really have a restaurant attached to it. Very cool. And what I think coolish about it too. Maybe the coolest part about it is that these ghost restaurant might be making Chinese food and Thai food and Mexican food and American food all in one kitchen.

And all you have to do is just start one of these. As you have a kitchen, let's say you're an existing restaurant, and you're trying to figure out how to stay in business. You get some of this software like Nimbus, and I M B U S. And Nimbus's just an example. I'm not recommending them, but an example of one of these companies that has software to allow you to.

Really run these things. So now you put up a website saying in my town USA is this wonderful Mexican restaurant. And you've got all of the wonderful things about it and the testimonials and the menu, and people can go there and order whatever Mexican food they want. Very nice. I like that. But you also have a menu up for your Chinese food and it's a different website obviously, and it's got Chinese food and it's again, testimonials about how great Chinese food is.

And you've got your Chinese menu there where you can select a little of this and a little of that. And you might have another w. Or another restaurant, quote, unquote selling Japanese food, whatever it might be. They're not even related in most of these cases. That is absolutely fascinating because it has altered a whole industry.

Now you can have pizza in there too. So if you've got a kitchen, you could now set up a website for a number of different cuisines and you now have just one place. It's just a kitchen and you keep it busy. How's that for simple. All right. Do your chefs hopefully know how to make all these different types of foods, right?

You gotta make sure the food's right, but you don't have to worry about seeding. You don't have to worry about all of the cleanings you'd have to do of the seating areas. You don't have to have someone out front greeting people as they come in. And the Uber food or whatever might be drivers, just show up at the door, they pick up the food and they deliver it.

So that's a whole new type of business. It's called ghost kitchen. You'll see them out there. There are other things like Total food, this Nimbus thing, which is a hybrid breed between the traditional commissary kitchen and a ghost kitchen that got some bells and whistles on them. But this is fascinating.

It is something you might want to look into if you own a restaurant or a bar because now most States are allowing the delivery of mixed drinks in these vehicles. It could be a savior for you. Okay. Oh, I absolutely love it. I think it's a great idea. Obviously. It's not going to replace everything a traditional restaurant's going to do.

You're not going to be able to sit down with your buddies at a ghost, titch your kitchen. And at that ghost kitchen. Be able to very simply just have your meal, right? Cause it's, it doesn't really exist. The restaurant doesn't exist. The kitchen, obviously. That's so very cool. Very cool. Fran posts is another one, FRA, N P O S, which gives ghosts kiss kitchens, the power to monitor, manage their individual locations while removing all of the administrative burdens associated with running the kitchen.

They have really made this a lot easier. So keep an eye out for that Fran posts again, by the way, it also consolidates multiple menus, automatically reports, revenues owed to each brand associated with the kitchen. I'm not sure if any of these. Ghost kitchens are franchise operations with brands, right?

Could you do a taco bell in a ghost kitchen? I guess you could, but I would imagine that the contract you have with taco bell has a number of different restrictions on it. So we'll see. And with the lockdowns raging in so many. Date's still absolutely insane by the way. This is something that may save some, at least of the restaurant business stick around.

When we get back, I got to tell you what Warren Buffett's been saying about Bitcoin Warren buffet. Of course, the investor that everybody watches, because he's really made a lot of money.

Have you been a Bitcoin investor? Have you been wondering about it? I'm going to let you know right now what Warren Buffett has to say about it. We'll explain a little bit about Bitcoin. That is something I had some interest in early on, but I just dropped out of it. I had other things to do.

Bitcoin has been a commodity. If you will. It's not even a commodity, is there's nothing physical about Bitcoin.

Is only supported by the willingness, the faith of the people that buy and sell Bitcoin. I was talking to a friend of mine and he had his wife in vast. What was it? I think she bought one Bitcoin. It was at about. $8,000. I think it was last year sometime. And they decided when it hit $42,000, that it was time to sell it.

So that's a pretty darn good profit margin, frankly. And it's, anyway, long story on my part, but he. Found something out and that is, he had a very hard time trying to sell it. In fact, he still has not been able to sell his Bitcoin. He has his Bitcoin wallet. He has his. Password, unlike that guy that had lost $250 million worth of Bitcoin.

Cause he can't remember the key to his little vault and the tragic that one, but he's been trying to figure out, okay how do I sell this thing? And he's been going to the exchanges and the exchanges have been making it very difficult for him. To sell that Bitcoin. Now, the reason Bitcoin has value is because people will pay that much money for Bitcoin.

And of course, it's dropped away down from its high and it's continuing to go down and then it goes up, it goes down and it goes up. And so originally Bitcoin was. Driven up by these guys that started it through artificial means. In other words, they cheated and they cheated in the very, very big way to get Bitcoin up to the point where it was worth about a thousand dollars.

They were trading Bitcoins with each other and paying more and more for it each time so that this worthless Bitcoin would have some value. And then Bitcoin. Because it's using blockchain technology and that blockchain technology is difficult to trace who the person who owns it is. So it became very prominent in the Cracker, a Hijacker hacker community.

So these bad guys that were holding your computer ransom. Used Bitcoin, you had to buy Bitcoin and then send it to them. You're buying a limited commodity. The price is going to go up, right? It's just the way it goes. How much money is chasing a limited commodity or limited number of Bitcoin in this case?

So it drove up the price and the value of Bitcoin paralleled very closely. The number of ransomware attacks that were underway at the time. So I looked at all of that in five. It's just not worth getting into Bitcoin. I did not have any money that I could really put at risk and I would rather spend the money on the family or remember money is time.

I'd rather spend the time with the family. I'd rather spend some time relaxing. Then I would. Putting money into something that might just totally collapse. Warren Buffett, it turns out, agrees with me. Okay. Business Insider has a great article. I love this headline Warren buffet, blasted Bitcoin as a worthless delusion and rat poison squared.

All right. He has repeatedly criticized Bitcoin and other cryptocurrencies as risky and worthless. You might remember that Facebook was coming out with their own blockchain cryptocurrency as they call it. There are many others out there. Bitcoin isn't the only one it's just the most prominent, most popular quote.

I can say almost to a certainty that they will come to a bad. Ending, although Bitcoin skyrocketed as much as 350% in the past year to record highs, he still doesn't like it. Okay. I agree with him on so many things here, a quote from February 2020. I'm Warren Buffett. Again, cryptocurrency is basically have no value and they don't produce anything.

They don't reproduce you can't, they can't mail you a check. They can't do anything. And what you hope is that somebody else comes along and pays you more money for them later on. But then that person's got the problem in terms of value zero. Now, many people argue a federal reserve note has no value either.

Remember, we used to be on the gold standard. And then we slipped to the silver standard. We had both at play and we had gold notes and silver notes. And then during the next administration, we completely detached from the hard currencies and the dollar became worth what we said it was and what other people would pay for a dollar.

But ultimately a dollar does have value, unlike Bitcoin, because it is accepted worldwide, generally accepted. Some people are saying yeah, obviously eventually, but Colin's going to be universally accepted well, NABI, but remember too, that these governments all over the world, aren't going to want to have all of these cryptocurrencies floating around.

It's pretty darn hard to tax them pretty hard. Darn hard to track. Down people who are committing crimes, serious crimes in some cases, and are using the cryptocurrencies to pay for it. So it's a Mirage. It's definitely not a currency. He doesn't own a Warren buffet. Any Bitcoin, any cryptocurrency? He says he never will.

He says, ah, I may start a warn currency. Maybe I can create one and say, there's only going to be 21 million of them. You can have it after I die, but you can't do anything with it except sell it to somebody else. That's the bottom line. Isn't it. That's what really what's going on with Bitcoin. So obviously I am not a financial advisor.

I am not your financial advisor, but I'm telling you what I do. And I'm telling you also what Mr. Warren buffet does. And that is both cases we have avoided. Coin and other cryptocurrencies because there's no inherent value, man. I had such an argument with this one lady once I can remember it now is probably about three years ago and she had come up with their own Bitcoin or it wasn't Bitcoin.

It was a cryptocurrency. And how cryptocurrencies were going to take over the world. And I was full for not wanting to invest in it. And I spoke out at the conference. We were at. Where she was promoting the cryptocurrency. And I spoke on and said, listen, this isn't legit. It is just not legit. And it's not a valid currency.

And she got really upset with me, very upset. It was a little surprising with me, but she was confident was going to take off. Of course, her cryptocurrency just completely crashed and went away a long time ago now. So frankly, that's where it's at. Hey, speaking of crashing, how about that? 5g 5g is now in most new phones.

What is it what's going on? There are a number of different 5g networks that are out there right now. And the marketing pitches that you're seeing on television and held swear are. Absolutely bullish. They're talking about the superfast 5g telecom networks, but in reality, it's not reality yet. You've got companies like T-Mobile and Sprint who are now one team mobile has the widest 5g network coverage.

In the United States, it is in most places, they are using a lower frequency than Verizon or anybody else. In fact, and there have been lawsuits over that because they want some of T-Mobile's frequency spectrum. And so far they haven't been successful at taking it. And we'll see what happens with the next administration, but anyhow rise and can say.

They have higher speeds than T-Mobile, which is true because they're using a higher frequency. They have more bandwidth, therefore they can provide more data and provide it faster. But the problem with higher frequencies is. They don't go as far. So you have to have more antennas or more cell towers at those higher frequencies like Verizon's using.

And you also have a harder time with your signal penetrating inside of business. Some of these frequencies glass will stop it. It's just incredible when you get right down to it, you guys probably know if you've listened for a while. I have an advanced amateur radio license. And so I know a little bit about this stuff and a bit about propagation.

I've had to study in order to pass some of these exams, but veraison is out there. They have 5g. But it is extremely limited. It works great if you are in certain neighborhoods in certain cities. In fact, these cities that they've deployed it in are only big cities and they're having problems with getting around corners.

So of course they are right. You've got these big buildings that are made of steel. Deal. That's the main structure, superstructure inside and concrete with rebar, which is steel and glass, et cetera. So if they put a cell site for five G on one street, this perpendicular to it is not going to get much of a signal.

So there you go. This is a real problem. We'll see what happens. I'm glad T-Mobile is ahead of the game here. 5g. Doesn't just provide higher speeds. It provides access for. More devices, smaller devices, and nationwide coverage with 5g. It's expected to add maybe one and a half trillion dollars to our gross domestic product over the next five years.

Okay. Very cool. But it's very fragmented. There's a whole maze of local regulations and agencies that these telecon comm companies have to navigate across all 50 States. This is tough. It is very tough and they need a lot more sites sell sites for these little sites, because now the five G site, they just fit in a box.

It can hang on the side of a building, but they need a lot of them for those higher frequencies. So there you go. Oh, pretty easy. Pretty cool. Thanks for joining me today. Make sure you join me in my Improving windows security course got to keep an eye out for that and read my emails. Cause every week I'm giving you some tips on how to stay safe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We had an interesting discussion about how Facebook works, their methods of making money, and how they are going about censoring everyday people on their platform by acting "in parentis" for the Federal Government. Here we go with Jim

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hello everybody. Craig Peterson here. You may have noticed this as well. Jim Pollito's friends had sent him some screenshots. He had a few of them. In fact, that said, you can't post on Facebook, that they counted being temporarily suspended. We got into the reason behind this, some things he didn't know, didn't realize, and I think that might be true for you as well.

So here we go with Mr. Jim Pollito.

Jim Polito: [00:00:30] So no time, like the present to have one of our greatest resources and a great guy, by the way. Even though he's from Canada, our good friend in tech talk guru, Craig Peterson. How are you, sir?

Craig Peterson: [00:00:44] Hey, doing well when, by the way, is winter going to start

Jim Polito: [00:00:49] For you this is actually, this is bordering on summer-like weather.

This is, you're accustomed to, you know, you grew up in, well, this was basically getting ready for putting down grass seed when the temperature was like this, you know, prepare.

Craig Peterson: [00:01:06] Nice winter, I like it.

Jim Polito: [00:01:09] It has Tommy B says, one of the few times that the climate prediction center, that's part of NOAA has been correct,. They said temperature-wise, we would have a milder than normal January.

Of course, that can turn any time. Even Canada is warmer than usual. Your friends up in the old country even though that's where the jet stream has the coldest air. It's still not a very bad winter up there too.

Craig Peterson: [00:01:41] It hasn't been, it's a whole Russia thing. Russia's been just sending that cold air over the poles.

Jim Polito: [00:01:48] It's Russian collusion

Craig Peterson: [00:01:51] Yeah. Yeah, because Biden's now president. So there's no reason to send that cold weather over the north pole over there.

Jim Polito: [00:01:58] Listen, that is believable. That could show up in an article. So don't even joke about it. But speaking of articles, I sent you, a screengrab of a message that someone received who's on Facebook. I can guarantee to you that person never discusses politics, never. Uses Facebook the way people used it in the old days, pictures of family, pictures of meals, pictures of fashion, that kind of stuff. They received a message from Facebook that said, you cannot join any group or create an event on Facebook until I think it was Saturday, the 23rd at like 6:28.

I have a dear friend in Texas who received one, two, and we joked, I said, because he's typically the voice of reason, you know, when people get into political arguments on Facebook, he's like, look guys here's the deal? You know, like he's the King of compromise. He got one and we just don't get it.

Yet, Jim hasn't received one.

Craig Peterson: [00:03:03] Well, Jim's got a voice here. I think that might be part of it. Here's a big problem, Facebook was designed to do one thing and that is collect information about you. Not just on Facebook, but on every website that you go to. Then put it all into a big pot or using a form of artificial intelligence.

They know what you're going to buy sometimes before you even know what you want to buy it. It's just absolutely amazing what Facebook has been doing.

It was not set up for censorship. I think we're seeing some of the results of that problem right now. Problem the left, anyway, looking at it as a problem because they are blocking Facebook users from creating events near the White House, various State Houses, and Capitols, as well.

So your friend might've gotten caught up in something being near a State House. Are they near. Um,

Jim Polito: [00:04:07] You just gave me the answer on why. He is probably, as you said, Facebook collects information on where you go. He is in Texas, a competitive shooter. Dresses up like a cowboy and goes to these events with a six-shooter. He's not a professional, it's just a hobby. He goes to these events and competes, just like people go and compete in other things. I said, you know, most of the stuff that he posts on Facebook is just videos of that. However, he is a second amendment supporter and probably goes to websites that are supportive of the second amendment. He is not, as people would say a gun nut, but he supported like I do the second amendment. That could be it.

The woman, I don't understand it. I don't know any websites that would be controversial.

Craig Peterson: [00:05:07] Well, he physically goes to shooting ranges in order to do the cowboy shooting.

And yeah. So I remember

Facebook and many other apps are tracking you and they know where you go. You play these fun little games that you download for free, right? Who one-step pay for a game, an app to play Tetris, or whatever it is you might like to play. Nobody. I don't want the free one. Why are you charging me for this?

How would they then go to make money? Apple is actually clamped down on this, just within the last few weeks, and has got Facebook and Google and others very upset.

Here's how it works. You've got that little app there on your phone and you're playing a game and you're at the range or you are driving by the State House, running Google maps. Remember now, unfortunately, Waze is owned by Google. So it falls for Waze as well. All of that data is now stored and sold. That's how they make money for most of these free quote-unquote apps, again, your, the product.

So all of that data is there. Facebook gets their hands on it on purpose. That's what they try and do. Remember, they're trying to collect all information about PayPal. Google is trying to collect all information about everything. pulling that all together, which is exactly what Facebook does. Putting it into a pot.

Now they have information about you. If you go to the range and you have one of these apps in that app is you now have disclosed where you travel, or if you're using Google Maps, you've disclosed where you traveled. I searched and searched and searched, and I could not find anything specifically online about this, other than the fact that Facebook has been blocked in users from creating new events, near state capitals, the white house, et cetera.

But this is how it works. So I wouldn't be surprised if they've gone to that next level and use the information they have about you to put some filters in place and block people.

Jim Polito: [00:07:15] See, now here's the thing. Here's the great assumption. He travels, not this time of year, he hasn't done it as much, but he travels almost every weekend on a Saturday to do one of these events, to compete in one of these events. I mean, especially, cause you know how hot it is down in Texas, but he'll even go to Oklahoma.

He lives in the Dallas area he'll even go up to Oklahoma. It must be every time he goes to a range, they're making the assumption, that because you go to a range because you support the second amendment, you're going to be more likely to storm the Capitol than someone who doesn't. I mean, that's my assumption.

Craig Peterson: [00:08:01] Yep.

Jim Polito: [00:08:03] I knew If I went to you with this, I would get the answer. I actually said that to my friend, as this happened, I said, I'll find out on Tuesday. I said this is a great, great subject for the show. And then I heard from other people. The same problem.

Craig Peterson: [00:08:20] They've cast a very big net, Jim.

It is absolutely censorship. There's no question about it. I want to point out too when we've talked about some of this stuff before, we've mentioned the first amendment. It controls the government and its control of speech. In this case, they are acting "in parentis " where you give your child to the school system during the day, they are the parent.

They can, and they do take them into another room and drill them with anatomically correct dolls from time to time. Right. They do some terrible things to our children because they have the rights of a parent. What's happening with Facebook and Google and others, right? These big tech guys, they're acting "in parentis " on behalf of the Federal government. Free speech has always been something that is honored and respected. It's part of our society.

These people are showing the fact, I think that they have no morals, whatsoever. They're not honoring it. They are doing it on behalf of the government here because they don't want the people to show up and protest. Heaven forbid, well, unless they are a part of one of these anarchists, BLM groups.

Jim Polito: [00:09:42] Yeah.

Craig Peterson: [00:09:42] Then I think they're going to get nailed. You look at the numbers. You've seen now, some of these other social media sites as Signal, for instance, we're going to be talking about, a lot, in this little course I have on improving Windows security, but Signal is an app. It's available for every platform. It's absolutely phenomenal.

It went down over the weekend because they could not handle the volume. We're seeing tens of millions of people leaving these other platforms and moving on to Parler, which is supposed to be backed up this week.

Signal, which is the only app you can use that you can be really strongly confident that your information is staying safe and it's not being shared with anybody out there. So Signal's kind of taken off. Telegram's another one that's become very popular. People are waking up, Jim and it's going to hurt the bottom line of these tech tyrants.

Jim Polito: [00:10:44] It will. Twitter. I'm not super active on it. I had like 5,100 followers. I lost about 200, just all of a sudden. I just looked at him, said, Oh my God. Then I said, what did I tweet? Cause, I don't tweet that often. What did I tweet now? Oh no, I didn't tweet anything. These are people just bailing. I'm talking like in the course of a week, probably. I may look at something like that once a week, in the course of a week, maybe to 200 people, right away, actually 200 plus right away, gone. Interesting.

Craig Peterson: [00:11:26] That's legit. On the left, they use bots, in order to really up their numbers. You look at President Obama's account and more than half of them were suspected bots. In other words, not real people, they were just computers.

But on the conservative side, like with you, these are real people and they're deleting accounts. Yeah.

Jim Polito: [00:11:50] All right. Talk about how people can get in touch with you quickly. Obviously, about this, a great program that you're putting together.

Craig Peterson: [00:11:57] All right. Yeah. I've got this course. We're finishing it up right now.

It's about improving your Windows security. I go every part of Windows, what you should turn off, how you should use it.

Make sure you're on my email list. I've been doing training every week and just a training email going out. Go to Craig peterson.com and you'll see, you can subscribe right there.

These great little courses, right? Craig peterson.com/subscribe.

Jim Polito: [00:12:24] All right, Craig, as usual, I mean, what a great asset you are every week, but especially during these crazy times.

We really appreciate it. We'll catch up with you next week. All right.

Craig Peterson: [00:12:36] Take care. Thanks, Jim.

Jim Polito: [00:12:38] Thanks, Craig. Appreciate it. All right.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about how you can stay secure and private while being online and how Facebook works. We also discussed Gen Z's propensity for sharing everything on social media and why that is not the best idea. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning. I was on with Chris Ryan this morning, the new host over at WGIR. And my gosh, I think I'm on like six different stations simulcast all over the place. Anyway, we chatted this morning about your security. How to keep your info safe, a little bit safe, from at least prying advertisers this morning.

So here we go.

Chris Ryan: [00:00:23] I've often said here on the show that we use our phones to spy on ourselves. That could be in many different circumstances, whether you are, writing things that shouldn't be written on social media. Whether it's your searches. Whether it's, you don't realize, how your searches are being detected. My phone has done way too much spying on myself, I've determined.

Welcome to the program right now. Craig Peterson, who hosts a tech talk here on news radio, 610 and 96.7.

Craig, how are you?

Craig Peterson: [00:00:50] I am doing well. Yeah. They've cut all kinds of new sensors in them, including these back hair centers. It's amazing.

Chris Ryan: [00:00:57] How does my phone know that I have back hair?

Justin McIssac: [00:00:59] How much did Chris have talk about his back hair, in order for the ad to pop up?

Craig Peterson: [00:01:03] Okay. This will never end.

Chris Ryan: [00:01:07] It's crazy. But in all honesty, we have these ads which are targeted towards us or this ad is clearly just mistargeted, obviously. We are constantly putting in information. I think a lot of times individuals don't realize how much they're putting in.

I remember back when the internet first came in back in 1995 and you had the AOL thing and you hit the button down for three seconds, and then you went finally connected to the internet. Parents always said We're not going to put anything of any significance on the internet, our credit card numbers, and social security. You're never going to do anything like that because it could have bad things to happen.

Now we're constantly putting in information. We're buying things on Amazon. Our credit cards would appear to be available on online, as well. So what are we giving away in this trade-off for more information? For more access. What fail-safes are there?

Craig Peterson: [00:01:59] This has become really something very old, I think everyone's heard by now. We are the product, right? If you're using a free app, it is not free. If you're using a free site, like Facebook, it is not free. The only thing that really is free out there, are some of these open source products. What are we giving away? Things like our credit cards, you mentioned we're putting online.

Look at what GoDaddy did with some employees last fall. They wanted to have employees stop[clicking on these phishing emails that are sent out to get you to do something that you really shouldn't be doing. So they sent a thing out to about 500 employees in emails saying, Hey guys, it's time for the annual bonus. If you click through here, you'll get the $560 bonus, you just got to fill it out.

So these people working there for GoDaddy clicked on that email and they filled it out. They gave all of this personal information, Chris, and then all of a sudden they were in trouble. Now that's evil. That is frankly evil. That was the company doing it. To them, this is a big problem.

If you look at a generation Z, they have security in mind, just so much, that they've done some studies and found the generation Z will give away personal information, like their email address and their name in exchange, for a donut.

That's all it takes, Chris.

Chris Ryan: [00:03:27] So let's take a look at, say Facebook as an example, or what is the business model for Facebook? Obviously, they have some ads that run. This is a multi-billion dollar company and, you don't see when you're going through Facebook, the mechanism by which they would be able to generate the type of revenue that they do.

So take us through what the business model is for Facebook, and how they go about having success with that model.

Craig Peterson: [00:03:57] For everyone's information, I have worked with clients who advertise on Facebook and I have set up the Facebook pixels all the way through, just the whole thing. Okay. So I do understand this.

The advertising mechanism inside Facebook tracks you, what you're saying within Facebook, and all of Facebook's properties, which by the way is why people are concerned about WhatsApp, which is a secure messaging platform that Facebook is messing with. They not only track you on their own properties, they also track you when you are on other parts of the internet.

They know where you're going. They know what you're doing on websites that aren't owned by Facebook or affiliated with Facebook.

The reason that happens is these third- party websites also want to know what your interests are. So that the marketers can now put it all into a big pot and stir it up and say, Oh he was over at this website. He was looking at this and he was looking at that and he went here, he went there.

So Facebook now gives these advertisers the ability to retarget these people that are visiting other websites.

So if you went to a website and you look to purchase something, an advertiser on Facebook can say, Oh, he was at my website earlier today. So now when you go to the website or any of the advertising properties and Facebook is helping to provide advertising on it will now show you an ad specifically for you and it's gotten so good, Chris, that people think that their phones are listening in on their conversations.

They think that somehow they've been listening on a phone call or just on the other side of the room. No, it, most of the time these ads are popping up for us because of the tracking, the mechanisms, the artificial intelligence behind it, being able to know basically everything you're doing online, putting into a pot can predict before you even want it.

Amazon is using similar mechanisms right now where they pre-ship things. They think that you, Chris Ryan, are going to buy. They shipped them to a distribution center near you. So their business model is to know everything about everyone. Be able to predict what they want to buy and then sell that information to interested advertisers.

That's how they're making billions of dollars. They really have a corner on that market.

Chris Ryan: [00:06:32] They really do. It's incredibly smart and intelligent. The algorithms are good. From an advertising standpoint. You look at just where digital advertising is at this point, what they're able to do? What they're able to focus on? It's flat out remarkable.

So let's say that I wanted to avoid being tracked, but I still want to use the same products, but I don't want back hair ads popping up in my feed. How do I go about doing that? Can I do that? Can you Google things? Cause Google is another big one, as well. Can you go and do your searches and not be inundated with ads that kind of freak you out.

Craig Peterson: [00:07:10] There are some ways to do some of this right now. Our friends over at Mozilla who make a browser called Firefox, have a special mode in their browser that kicks in automatically when it comes to Facebook. For example, So if you're using Firefox Mozilla, and there's a couple of issues with that, but generally speaking, it's a good internet browser.

It actually builds a wall around Facebook. So that Facebook can start poking around saying, what else is he doing? Okay. Where else is he going? So that's your first trick out there is to put that in place.

Apple has gone a long way now they have a special advertiser ID. Facebook and Google are really upset with Apple right now because of this release of Apple's operating system iOS, which blocks them from doing most of the tracking and tells you exactly what they're doing and will ask you if it's okay.

If Facebook is tracking you while you're looking at your favorite Zappos site shoes and whatever you might be looking at online. Firefox combined with something like Signal.

If you are trying to communicate with someone, Signal and iMessage are great ways to go. I Message is very simple its Apple-centric. Obviously, they don't track you. Apple does not make money off of you by selling your information, which is a big deal.

There's a few other things that you can do.

I do some training on some plugins that you can put into your browsers to block what is called cross-site keys. That's a big one as well.

Justin McIssac: [00:08:51] I've got some friends convinced that they've got to throw a couple of weird searches in there now, and then just to disrupt the algorithms. So they'll look up like a Scandinavian candy shop. They'll Google that now just to try and throw Bezos off, but I don't think that works.

Craig Peterson: [00:09:05] No it does actually to some extent.

Yeah, Justin, you, there is a plugin that will automatically put random searches out there into Google to do exactly what you're talking about. It does it automatically. Don't use Google use duck go, which is hard to say, that's Duck Duck Go something search engine. Yeah, and it doesn't track you. It doesn't tie into the Facebook trackers and particularly when you're using Firefox. We're being tracked everybody.

Chris Ryan: [00:09:37] Craig has always, appreciate you joining us for the show.

We shall chat again next Monday.

Craig Peterson: [00:09:41] All right. Take care. And I'll be back of course, Saturdays at 1130,

Chris Ryan: [00:09:45] 1130 tech talk here on news radio, 610 and 96.7

I am Chris Ryan.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This has been quite the week for Tech news with Big Tech lowering their Iron Fist on any opinions with which they don't agree. Social Media censorship is here and it has taught us that if you want to communicate freely you cannot and must not use their platforms or services. I will introduce you to a new service that is out of their control and completely decentralized -- like the original internet. Plus we will talk about Elon Musk, What'sApp and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

WhatsApp gives users an ultimatum: Share data with Facebook or stop using the app

Insurrectionists’ social media presence gives feds an easy way to ID them

Elon Musk is the world’s richest person

What to expect from the first-ever virtual CES

Google, Apple, and Amazon bans Parler

Mastodon is the Only Open Social Network Remaining

Malware Developers Refresh Their Attack Tools

How the Shady Zero-Day Sales Game Is Evolving

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hi. Hey everybody. Craig Peterson here. Thanks for joining me. We're going to talk about that. WhatsApp. What are the alternatives to WhatsApp that you might want to use to have private communications? We're going to talk about zero day attacks. This is a very big deal, particularly for us regular users and businesses and what.

Does that mean to you? What does that mean to me? The whole thing about in these insurrectionists on social media, what happened down at the white house? Not the white house, but excuse me. The Capitol building. And what are the federal and local police doing to track down the people they are using tech, which should not come as a surprise to anybody.

Ilan Musk is the world's richest person. Now we'll go into a little bit about him and what's going on. We are in the middle of the virtual CES. This is the first time that consumer electronic show has been virtual because of the lock. Down. They couldn't have all of these people out in Vegas. I can't imagine what the finances are like in Vegas right now.

That place has to be destroyed. Oh my gosh. What's been going on. People just aren't going out there. I was listening this morning to an interview with the head of the Manchester, Boston Regional Airport. And he was saying that, they had a peak, during the holidays, people were traveling no matter what the advice was, and they had a decent time of it.

They were able to handle the volume. But now that those travel days are over with we're just basically Thanksgiving and then around Christmas, they're now seeing just a glut. Because nobody's going to Vegas. Right now they'd be pretty busy. Today they probably wouldn't because most people will be in Vegas for the consumer electronic show, but they built up Vegas, Las Vegas in order to handle this show.

It's the second biggest show in the world and the largest consumer show in the world. And it's not even happening this year. At least not the way it's happened in years past. I'm so glad I'm not out there. I used, I loved going to Vegas. I really did, because you could do people watching. I'd usually bring a roll of nickels and it's hard to find the nickel slot machines, I'd blow every nickel I had that was running joke of mine for a few decades.

Yeah. Boring guy.

But the rest of the time I was watching people enjoying the restaurant. I loved walking around Vegas. Absolutely loved it. It was so much fun because it's just an exciting place to be. But now, Oh my gosh.

We have some clients out in Vegas, a medical client actually. We will have to comply with the HIPAA regulations and all of these, obviously that's part of what we do, is hip hop because we help businesses with their regulatory burdens. And I saw a mountain Vegas and we were taking care of this client and we just hop over to this trip. And in talking with them, some of these different clients out there, none of them go to the strip. If you're a resident, you just don't go.

Unless you're going to meet a friend from out of town and you go to a great restaurant. And I remember this last time I was out there, we went to Like it was Gordon Ramsey's new restaurant at the time, and it was a kind of an English pub theme. And I had, smashed peas and bangers and potatoes.

I forget what they called the potatoes. But that's for those of us who speak American English, it's sausages and peas and potatoes. It was actually very good. What's happening now because so many of these restaurants are shut down the casinos?

We just had a major casino owner just passed away this week as well. What's going to happen there?

So CES. It was what kept that whole economy really in the black frankly, and it's not even happening. So we'll, anyways, we'll talk a little bit about what's happening out there at the first ever Virtual Consumer Electronic show.

And if you don't hear it, make sure you go check it out. Online. Craig peterson.com got lots of great stuff there. For you a Google banning parlor from the Android app store. We're going to talk a little bit about that. What does it mean? Not just Google. Of course now we have Apple has banned them from their app store.

We've got Amazon who's kicked them off of their platform. We actually know a fair amount about this right now, but where are things going? How the biggest decentralized social network is dealing with its Nazi problem. We'll talk a little bit if we can get to it today, but about something called Mastodon. And I'm going to probably try and bring a Mastodon server up online, and it's designed for your own social network and these servers can tie together and each server can have its own standards in a way people can say and do and whatever online.

And Gab, which is where a lot of the people have gone that have been disaffected from Twitter and other places, and Gab had kicked them off. And so they went over to Mastodon and of course, Gab's has been having problems now, too. I guess a president just opened a gab account, just Gab, gab.com this week for people to follow him.

We'll see how that works out. It's just incredible. I mentioned this week on the air. I'm want, I consider myself anyways to be a, I'm the regionalist particularly here when we're talking about the internet and internet originalists. I firmly believe that the internet was intended to be just a free and open place, not just for exchanging ideas, which is.

Ultimately incredibly important. And it's so important that I think the only real way to solve problems isn't to find a new energy source or whatever it might be. I think that ultimately. It's the human mind, the human intellect, that is the most valuable resource on earth because we've been able to solve every problem that has come along.

So having this ability to communicate was what we saw the internet capable of back in the early 1980s, and then in the nineties. And when Berners Lee came out with the concept with NCSA, Mosaic of the web browser was just, Oh my gosh, that's just brilliant. Again, it was a simple step, but a brilliant idea that he was able to implement and he gave us the web.

And I was just so excited then, because what I thought was, what would happen is we would all be able to communicate and we'd see each other's ideas. And at the time the internet was probably about 90, 95% conservative, because remember where it came from, it was all of us working on government funded projects, many in universities.

But we were libertarian, we were conservative and this is going to be wonderful. We're going to get our libertarian message out about government control. In fact, I had a signature back in the day that I wrote a little bit of code in order to generate a new signature. Every time an email went out and it had all of these NSA buzzwords in it.

I was going to solve this problem all by myself by just making the NSA monitor my email. Now the stupid things we do is kids. But that's what we were seeing. We were originalist. This was just so exciting. So you had the free speech part of it, but you also have the freedom of development of you taking your ideas.

Finally, now you could connect with anyone in the world, anything in the world. Ultimately, of course we couldn't when it first started, right? How many of us were on the internet? My node is listed on some of those early maps of the internet. It's fun. Look at it. Oh, there I am. That's me. That was my machine. That was my company. That's what I was doing at the time.

Looking at it today. That excitement that we had of being able to develop software and new protocols and new technologies. And we weren't even thinking about competition because there was no competition. It was just a wonderful time to what we have today.

We've got our friends primarily at Facebook and Twitter, but also at Google, but maybe Facebook and Twitter are some of the worst offenders I'm going to lump Google into. Okay. But where we had all of these people, having free conversations and disagreeing with each other about political things and technological things and ways to move forward and how much security do we need, and should we be sending these commands in-line as just text real texts that you could read?

Just like the protocol that runs our email today. It says, hello, literally. Hello. When it connects. Nowadays the more advanced version say E H L O, but anyways you send real text commands to the machine so people could watch what was going on and debug it and figure things out. And talking about email, our email servers, the earlier versions of sendmail that we had were set up so that a remote person could get onto your server without your knowledge or permission even, and fix a configuration problem and debug a problem.

Think of that world, what that world was like. It was so exciting. We were in on something that just had never, ever happened before. And what Facebook and Twitter have done is completely turned the tables on this whole thing.

And I'm going to tell you what they did to turn the tables and we'll get into also what is going on with social networking? Where is it ultimately going to end up at? So we've got a lot to talk about today and I hope that you can stick around and pick up on all of this stuff.

How did we get there from here? Really don't know. I'm my head's still spinning, but here's, what's happened. You had Facebook start and Facebook's whole business model is to have you be the product.

You've heard this a million times before. And so Google. Oh, and Facebook and Twitter all want you to use their services. And they're going to, you pay the highest bidder for you, right? For your eyeballs. Okay. That's all fine. I understand that. But in order for them to make more money, what do you have to do?

As a business person, you know what you have to do, either get more customers, you have to increase the volume of purchases by the customers you have, or perhaps you need to increase your prices or cut your costs. There's only so many metrics that are available to a business. Two that you can manipulate in order to really come out.

I had to have the game so that you can create more jobs and more opportunity for people by hiring them. If Facebook is going to be able to sell your information to more people, they need you on the platform for longer periods of time. That basically gives them more product to offer. Again, remember you are the product.

So if they're going to try and keep you on Facebook, what are they going to do? They have on staff, all kinds of psychiatrists, psychologists, and sociologists who try and figure out how to really pull your strings. That's what they want. They want you on there. They're going to have colors that are designed to keep you on the website.

Again, going back to the Vegas thing from the prior segment, you go into Las Vegas and do a casino and you are going to be completely oblivious as to what time of day it is. You have no idea. There aren't any windows. The light is always the same. The flooring the weird patterns they have in the carpets on the floors are designed to slightly disorient.

You. So you're just sitting there playing the slots, getting free booze, because that's going to keep you playing because you don't make the best decisions when you are on the tipsy side. You are not going to be an effective gambler. Get, you might stay there all night and you have no idea.

Use your Apple watch in order to remind you when you should be leaving right, or whatever, watch out. The same types of things have gone into all of these social media sites. And now one of the things that they have found out is if you get pissed off, if you're very angry at something, you are going to leave.

Now you may just go and do something else because you're so upset, right? You're steaming over. You're boiling. You might leave the site permanently, just so many Twitter users have done thousands of them here after president Trump. Had decided he wasn't going to post because he couldn't on Twitter anymore.

And moved over to Gab.com, as I mentioned. So what should they do? They want more product. They need more eyeballs that they can sell. So they're going to show you things that you want to see that are going to keep you on their site. So they're going to upset you. Yeah they want to upset you because if you are a little upset, you're going to pay more attention, right?

Your eyeballs are going to be drawn in as it were. So they're going to show you things that effectively you want to see, but it's really more than that. It's really, they've got to get your hormones flowing to such a degree at such a level that you are going to stay on this site. And you're going to share content with your friends and.

You're going to comment on a tweet and they're going to show it to the people that it's really going to upset in, but not so much that they're going to get off of the site for the day, but enough that they're going to want to jump in because their opinion matters. And in reality on these social media sites your opinion really doesn't matter that much, right?

None of us are as important as we think, like to think we are. So they have sucked you in. And how many times have we seen people who are stuck in these sites all day long? They have a spare moment. They are just flipping through headlines and those headlines are designed to get you. To stick on the site to share stuff.

That's what it's designed for. I didn't see that common. I really didn't and a really good friend of mine. He pointed out something the other day, cause he was asking about, what's the ultimate outcome going to be of what we've seen with president Trump and. Social media and banning conservatives, et cetera, et cetera.

And so we had a great little chat about that and he pointed out Craig, normally you don't think this way. I don't think like the people that are trying to shut us up. I don't think like the people that are trying to take control, I'm I am not a socialist. I'm not a national socialist.

Also called Nazi the German word for national socialists. I'm not a communist, which is again, an international socialist. You notice they're all socialists. And I just think everybody should have reasonable freedoms. Obviously we need laws and the right for me to swing my fist, stops somewhere before your nose.

And I understand all of that and I believe firmly in all of that. And I was raised remember in a socialist country that there has discussions about some of this stuff.

But I really am very libertine I think is maybe the way to put it because you have the Libertarian party, the uppercase L. I am a lowercase L I think that people have the right to privacy, for instance, which used to be something that the Democrat party talked about.

And that used to be something the Democrat party cared about. But now with these massive businesses, That want your eyeballs that are keeping your eyeballs, it's all changed. And part of the reason it's all changed. And this is what I explained to my friend is if you're a big company, you don't want competition, right?

So you get Facebook buying Instagram, you get Facebook buying WhatsApp because they were competition to them. What's another great way to get rid of competition if you don't have any morals? And we know from all of the stories we've seen about Zuckerberg and how he stole photos from Harvard university of all of the co-eds that were there and put them up and had people rating their them based on their looks. That story would tell us the Zuckerberg doesn't have those morals, but if you don't have any morals and you have enough money to get the attention of Congress or State legislatures, then what can you do? And I think that's where our problem has come in. Frankly, these guys want legislation.

So when we get back, I'll tell you why I think they want this legislation. Why they want the types of enforcement they have, because many times you might be scratching your head.

I know I used to do saying why would this company be lobbying for legislation to regulate themselves? I think there's a pretty simple answer here.

I mentioned how I am an intranet originalist because I was around in the days of the founding of the internet. Absolutely. So I was looking forward to all of this freedom, to all of this open space, to the ability to communicate back and forth with anybody, to be able to develop applications, whatever I needed to do, whatever I might want to do.

It was just an incredible day. Incredible time to where we're at today. So you have these big businesses, Facebook and others who are doing the nasty, frankly, where they are controlling us. They really are because they're controlling the content we see, and we are no longer able to distinguish between something that is being fed to us.

Because they think it'll keep us on the site longer. They think it'll make us talk about an article or something. And the difference between that and something maybe we need to see, which is most likely an opposing opinion now, just because there's an opposing opinion doesn't mean that it's a worthwhile opinion, right?

There are some seriously crazy people out there, but we're not making that decision anymore. That decision is being made by the tech tyrant and the tech tyrant's love to have government intervene. If the tech titans, the Facebooks and Googles and Twitters of the world can get the government to put various controls in place because "in this industry, we have not done a great job of controlling ourselves. So we need the government to control us."

When the government starts "controlling," it's quote unquote, right? These big tech giants and puts rules and regulations in place saying thou shall do this thou shalt not do that. We all chair many of us anyways, chair. And we cheer because the problem solved.

And of course, as we know, anytime government quote "solves" unquote, a problem they've created three, four, five, six other problems. So government loves it because there's more problems to solve, but the original problem was never solved, but here's the trick. These tech tyrants or tyrants of other kinds, we'll talk about some others in just a minute, are now under new regulations. But they can afford those regulations. Who cannot afford to comply with those regulations? It's a little guy, isn't it? The small companies is small startups. That, that I was so excited were coming our way because we had this new internet technology.

This wonderful tech that was going to change our lives. Those companies are squashed. They're stepped on. They are little gnats that are flying about their heads that are now starved because they can't comply. Now, let me give you an example.

I deal with regulatory compliance. My business is all about cyber security right now. We're not a law firm. I don't give legal advice, but I help them comply. And how do I help them comply? We'll go in and we'll do audits on their networks. Figure out what it is that needs to be done on their network. How can that work? What problems might we have? What problems might they have and then move forward right to the next step.

And that is solve the problems. Just this week we delivered a case of paper to one of our clients. Now this is a moderately small client there. They're not huge. They are considered a small business by the Small Business Administration. So they're not a particularly big customer or business, but here's, what's happened in their industry.

There are rules called CMMC, which are based on some National Institutes of Standards and Technology requirements or guidelines that were put in place. And anyone that manufacturers anything or provides anything to the federal government has to comply with these rules. And compliance is very expensive.

We're talking a half, a million dollars upfront for a small business. And then if you really are complying probably about 300,000 a year, if you're trying to do it all yourself, okay. Very expensive.

Now I look at these cybersecurity rules and say you know to me anyways, being a cybersecurity guy, these are legitimate, they're reasonable. But most of these small companies are looking at it and say it's easy enough for one of these major contractors that you probably heard, their names is places like Boeing or BAE. And those types of places it's easy enough for them to comply because they've got great profit margins and they have thousands of people working for them.

Tens of thousands. It's easy for them. It's hard for us. So we delivered. A case of printed paper, where we had gone through and written up all of the documentation necessary for them to comply with the CMMC rules. Now this documentation set that we wrote up for them is, as you can guess, Thousands and thousands of pages long, and it's all stuff that they're supposed to comply with. And it goes into every level. What should happen from the physical security, which the fed call ITAR all the way through the computer security and password changes. When should they happen, et cetera, et cetera. And this is a $50,000 project. How is a small company going to be shelling out this kind of money?

Now we try and make it easy for them because we will rent them the equipment as opposed to sell them equipment. And we'll, we will do the documentation for them at this cost because the 50,000 frankly, is cheap. If they had done it themselves it would have been closer to 200,000. But because we do it for so many businesses and so much of it, the same.

we're able to give it to them at a savings, but how can a small business comply with all these regulations? A startup business comply. It's very difficult. If not impossible to be able to comply with this stuff. And there are some market opportunities for us that we're pursuing where they, these customers are actually using our systems in order to help stay safe.

And I think that might be a good way for them to get around that initial quarter million, half a million dollar investment in upgrades that they have to do. But it makes it difficult to enter the market, right? Investors they're always looking at what's the barrier to entry here for potential competitors?

If you can get the federal government's ear, if you are a big contractor, you can get regulations put in place that you could comply with. No problem. I'll just add it onto my bill, which they were able to do by the way. If the regulations were written so they could bill it back to the federal government, but for various reasons, very small businesses and startups just cannot bill it back. How's that for our scary situation?

We don't like the fact that frankly, Google Facebook, Amazon, Twitter, you name any of these big companies. We don't like the fact that they are able to control the market that they're in. Now we had this whole antitrust system set up, you might remember the robber barons and what they were doing, which was just totally immoral and really hurt a lot of people a hundred years ago.

This is the modern version of the robber barons. If you can't beat them, join them. And as I mentioned in the last segment . They love the regulations and the regulations love them.

Now, the reason I say the regulations love them is because the regulators love them.

Mel Brooks. You remember with the the movie, it was just absolutely fantastic. And they're all sitting around the table with the Governor and they're talking about their phony baloney jobs. That's really what so many of these regulations are. Do we really need them, do we really need all of these laws?

And the answer is obviously no. We just cut back on tons of regulations, tens of thousands of regulations that were just absolutely not needed, but the regulators love it.

If you are a regulator and you are sitting behind a desk and you'd like to earn more money. And of course, who wouldn't like to make a few extra bucks, and maybe take a vacation for once. But you're sitting behind a desk as a regulator. How are you going to justify a higher salary? Obviously more work would help justify that. And you're probably looking, as part of that raise to maybe move up the ladder. In order to move up the ladder and manage people, you have to have more people.

So the more work you can make for yourself and for your department, so that the department has to grow, the better, the chance of you being able to move up the ladder and get that extra salary bump. You see how that works. I know you guys. You're the best and brightest and you're like me. We don't think that way, but many regulators do think that way.

And I know there's some great, honest people out there that are trying to do the right thing. We work with a number of State organizations from school districts to counties. We've done it for years to State governments, in fact, and we always try and do the right thing, but the tendency. The gravity is towards these regulatory agencies growing and just grabbing more and more power and authority so that they can justify more and more.

And the big companies don't actually really complain about it much because that helps them keep the small guys out. That's what I've been talking about. They don't want those small guys. They don't want the startups. They don't want what the internet had so much hope and opportunity held out for.

They want to stay in their phony baloney positions as well at the head of some of these things. So they've made it very difficult for us to get in. Then on the state and local level, look at what's happened. Again, government likes to control government likes to regulate, which is controlled. That's what it's all about.

Remember, regulator was the brand name for a clock because it helped to regulate the time. Ball was the first watch. That was good enough for the railroad to keep track of time. And we have our time zones today because of the railroad, nothing to do with what the real time of day is. If we were at noon, when the sun was high overhead, when it was directly overhead, we'd have an even amount of time in the afternoon as we do in the morning.

In other words, the sun would rise at 8:00 AM and set at 8:00 PM. But that doesn't happen. Does it? And that's all because of regulation or just because of the railroad who was huge at the time. So State and local think about the licenses that are required in so many places. Do we really need to have a business license?

Did you know, Singapore does not require business licenses. They hardly have any licenses. In fact, in Singapore, and they have one of the best economies in the world and have had for a very long time, because a simple idea might be a great idea, but it might not work in the real world. Look at the numbers coming out of the small business administration.

Most businesses fail.

And the best way to fail is to fail fast before you spend all of your money, your savings. Hopefully you have something after this whole lockdown, but that's the best way to figure out if an business idea is a good one. Failed. You got to try it, but if you have to have a license from the town for the business, you have to have an occupancy permit for the office space.

You have to have an, a license to run it out of your house nowadays, right? Because we're working from home and then consider things like a license for a hairdresser for a barber really. Really you need a license for that? It is great because it keeps people out of the business. It keeps the number of barbers down, the number of hairdressers down there aren't as many because you need a license, but do we really need a license for that?

So I wanted to use that as a lower end example because barbershops and hair salons tend to be much, much smaller than trillion dollar companies. So we have to be very careful about our tendencies growing up, my father and my mother, they would continually say, ah, there ought to be a law about that.

Really do we need a law? How long has murder being illegal? Go back to British common law where a lot of our laws started from anyways. It was illegal. Then it was illegal to cheat somebody out of something. It was illegal to do these various things, but the lawyers, the whole law community has built it up.

Along with the politicians, so that everything's become incredibly complicated, which benefits who again, does it really benefit you? If someone cheats you? Those laws had been on the books since the Magna Carta. Okay? So do we really need to have a specific law about cheating on the internet using this type of achieved against this type of a person that applies to this type of a company?

Really? Do we really need that? Isn't that what the whole courts were about is to interpret the law. We have come so far from our founding. And I'm referring to the internet here, not just the country, but it applies to both. So we are now faced with this problem of the internet and these mega-monopolies effectively, when you control 60% of the online servers and data processing storage that's pretty much a monopoly and that's the position Amazon is in right now.

How do you get rid of those monopolies while we've tried legislatively before? But those laws don't work. They've worked a way around those laws. They've said, okay, we're going to actually use the laws to protect our monopoly. And they go to the government and they say, Hey we want to buy Instagram or we want to buy WhatsApp.

And we're not gaining any sort of a monopoly position by doing this because we do have laws in place that require these big companies to go before a federal bureaucracy who by the way, is going to regulate them and has that additional incentive hidden away in their back pocket.

If we have this bigger company here, we can regulate it easier than all of these little companies. So they go and they get permission to buy these competitors. And they were competitors because Instagram was taking those ever valuable eyeballs that are needed by Facebook, away from Facebook.

WhatsApp was taking people away from messenger and WhatsApp was great at the time because it was end to end encrypted used MarlinSpike's algorithms. It just was a nice little product. But Facebook already had a competing product called Messenger, and yet they were able to buy it anyways and become bigger and get more regulations in place, which keeps the small guys out.

It keeps the best ideas, ideas we never saw because frankly they never saw the light of day. So how could we see them? Are you willing to put all of this money into something and find out there's all these regulations in your way where you have to hire a company like mine and hire me because you need to do an audit.

You need to comply with the HIPAA regulations. You need to comply with these CMMC regulations. And in some cases it makes sense. And I got to say, I think in most cases I've seen these regulations do nothing but preserve and create monopolies. So not that I have an opinion on the matter, but I thought it was while in these turbulent times to explain what I think is going on.

And these calls for further regulations I think are going to ultimately have the exact opposite effect. That these new regulations that people are calling for more regulations from the FTC, from the FCC Pitt and PI I should say and company did not do enough regulations. They got rid of regulations.

And we don't have free speech that gamer, he can't get internet cheap because he's using a lot of internet compared to what that granny next door who wants to send a nice picture of her cat or get pictures of the grandkids. She has to pay the same as him. That's what they want. That's what they want.

And I think it's going to be destructive

Let's talk about secure communications right now. And I'm talking about talking to your kids at school or grandkids, or, any type of communication you might want to have, including of course, business communication that you want to be.

Relatively / reasonably secure. You can't expect to using just regular hardware to have military grade security. It's just not reasonable. Apple went to all of the trouble and they got their iPhone certified for certain types of data. And I think it's great that they did because it's helping all of us.

But in, in, unless you are a spy working for a foreign government or something, Really these things are going to work for you. So when the number one out there is an app called WhatsApp and it is an app that was designed using a very good base. There's a guy out there by the name of MarlinSpike.

Probably not the name he was born with. And he designed a end-to-end state-of-the-art encryption mechanism. And it was used, it still is used in an app called Signal. And another app called WhatsApp. I got about a week ago, a notification on WhatsApp because we use WhatsApp for a mastermind group on men.

And the idea is we don't want people spying in maybe competitors who knows who. And so we wanted something that was secure end to end and remember that's what zoom was telling us. Yeah. It's secure end to end. And of course we find out later on that it wasn't, they were absolutely lying. Big surprise there.

But when we're talking about secure communications, it has to be end to end. And what that means is you type into your phone for instance, and it's in the clearer right there on your phone and then the app, whatever it might be will encrypt it. Send it to the remote site. Now we obviously, it's going to go through a bunch of routers on the internet.

It may end up in a server or two, depending on the app and how it's written, and then it'll end up on the other person's smartphone or desktop, whatever it might be end to end means that anyone in the middle who is capturing the data only sees it as random letters and numbers. That's the idea behind this.

So it won't prevent someone from listening in on your conversation because they can certainly listen in, but it will prevent them from listening intelligibly to your conversation. In other words, they've got all of the data. It's encrypted data, it looks like trash and they have it now. Is that any good for people?

Again, it depends on how spy worlds you want to get here? Is it something where knowing that there's a communication going on means something right there. There's a lot of stuff you can read into it. How active is it? You might remember in world war II, we were listening to German communications and you could tell something's ramping up here because we've got more units, transmitting unit codes, and we use that as did our enemies in the war to fool them as well. We had pretended we had a whole tank divisions that didn't actually exist as well as various other things. So secure communications means a lot of things, but when we're talking end to end, all it means is when you send it is basically garbage one is being transmitted. And then it's in the clear when it arrives at the far side. So that's end to end communications what app has had and then communications encrypted, which is why people have been using it. If you listen to the first hour, you heard me complaining about Facebook and how they've been buying their competition, and then the competition that they can't buy that doesn't even exist yet.

Before it gets started, they've been using government regulations to suppress them and make sure they just don't become competitors. One of the apps that was bought by Facebook, because it was taken away a lot of eyeballs, is called WhatsApp. It's a messaging app. It has, or at least used to have privacy coded into the way it was designed.

Now, Facebook owning it means who knows if it still does. We don't have the source code that Facebook is using, who knows what they've gotten into it, but we're talking about 2 billion users. Worldwide. And I got this message from WhatsApp saying that if I don't concede to these new terms of service, I'm not going to be able to use WhatsApp anymore.

While these terms of service include. And I had to look at this and now I have it up on my screen right now. They are changing WhatsApp service and the way they process your data, how businesses can use Facebook hosted services to store and manage. There are WhatsApp client chats, how they partner with Facebook to offer integrations across the Facebook company products.

So guess what that all means. And they said, if you don't agree to this by February 8th, you will no longer be able to use WhatsApp. Now remember they paid $19 billion for WhatsApp in 2014, and it's really going to make you wonder what they were thinking. All right. They have not been making money off of WhatsApp.

They haven't been able to track you what you're doing, insert ads, et cetera. And there have been a lot of people over the years who have said to guests, what's going to happen here. Our friends at Facebook are going to start monetizing WhatsApp. If I paid $19 billion for an app, I'd want a mob monetize it as well.

This is getting scary in 2016. WhatsApp gave users the ability to pull out of having your account data transferred over to Facebook. So it took them about. Two years after the acquisition to say, okay, now we're going to grab all of your count data. And now this updated privacy policy is changing.

Everything you will no longer have that choice. Like you had four years ago. So some of the data that WhatsApp collects is going to be available and open to Facebook. So that includes user phone numbers, other people's phone numbers that are stored in your address. Book, profile names, profile pictures, status messages, indicating when you were last online diagnostic data collected from app blogs.

Now. The diagnostic data can tell them a lot. And it isn't just used to fix broken programs. This diagnostic data oftentimes contains things like passwords or user account names, other websites that you visit. It's got. Just a ton of stuff. So under these new terms, Facebook is saying they have the right to share all of this data with its family of companies.

So think about what that means. They've got the Facebook payments. Family member. And part of the reason that they're probably doing this is Facebook really wants to get in the money business. You might remember. We talked last year about how Facebook wants to have their own cryptocurrency and manage it.

So be careful here they have the right to collect purchase information, your financial information, location, contacts, user content. So what should you use? I'm not going to delve into more about what this problem is. I think it should be pretty obvious. If you want something that's quick and easy to use.

If you're following in my advice so far, you're using an iPhone because that is your best bet, generally speaking out there right now. And when it comes to security and even for some of these regulated industries that we serve with these services, like doing the documentation. Fixing up networks doing audits, all of that sort of stuff.

It's good for them too. It works for them. And on your iPhone and also your Macs. There's something called I message. And I message is end to end encrypted. And Apple is not using it for advertising. It is not using it for your financial transactions and spying on you. Okay. You had another reason to use your iPhone.

If you're on an Android, we've got something for you here in a minute as well. So iPhone problem with iPhone and iMessage is, the recipient has to have an iPhone or a Mac in order for it to be encrypted. So what do I recommend overall? I use I message when I want something easy, maybe talking to family members and I use Signal it's called Signal messenger.

It's fantastic. It is end to end. It is what. The pros you, so check it out.

you are not hearing the truth. The algorithms at Facebook and Twitter and every other place was social media.

Those programs are not designed to show you the truth. They're just designed to manipulate you. And I explained what that was all about, how it works and why. So if you missed that, make sure you check out the podcast, CraigPeterson.com/podcast, and you'll see them all there. Or just in your favorite podcast app, just search for Craig Peterson.

You should be able to find it that way. We have had a lot of turmoil lately and I chalk a lot of it, much much of it to the social media sites that are out there because these social media sites are doing a disservice. By dividing us up even further. They are just letting us know things they think we want to know and you know what, they're not wrong.

We do want to know those things and it gets to be a problem certainly. But how do you deal with that problem? Yeah. I was just thinking of the sound of music. When I said that you can deal with this problem in a number of different ways, but social media is not helping the matter at all. These people that broke into the Capitol building on Wednesday, we're not very subtle about what they were doing.

There were filming themselves, actively tweeting, actively posting things on Instagram, on and on. And they were uploading them to websites. It was pretty obvious where they were and many people, of course, they don't know how to, I don't maybe, maybe you don't know, but the photos you take, the videos you take, they have information embedded into them that tells you where and when the photo was taken.

That frankly is a huge problem for these people. So law enforcement agencies are now trying to track down these people. They're calling insurrectionists who have done things that I guess you could call a bit of an insurrection. The Washington DC attacks seem to have been mostly conservative people that may have gotten caught up.

There could be people who were embedded into the crowd just to rile them up and get them in and get them going. Many of these BLM and Antifa protests, of course they are actively burning and looting and mugging and shooting. It there's a huge difference here, but in both cases, local police and the FBI are trying to find out who these people were.

I got an email from the FBI earlier in the week where the FBI was asking, Hey here are some posters that we put together and we're trying to identify these people in it. It had what they had identified as kind of leaders of what was going on. They had pictures of them.

And of course, people have been reporting them and saying who it is because they were allegedly actively instigating violence. There were thousands of photos also in videos taken by some of the media who were on site. But several police departments here recently, like my Miami, Philadelphia, and New York city of Portland, Seattle they've turned to facial recognition platforms.

Now, in some cases, these cities have said it's illegal, but the police have been using it. And one of them is something we talked about last week and that's this clear view. A I. We've got to keep an eye on that one clear view, AI, for those who don't remember, maybe you haven't heard of it before is a company that went online and against the policies of these websites scraped all of the pictures.

It could find. And scraping in this case means downloading the photographs. So they downloaded them. They put them into a database. There were billions, as I recall of these photos, and then they had some facial recognition software they were using to try and figure out who's who there. Now they use this for these demonstrations by the BLM and the Antifa people.

And they were able to find a lot of the people and arrest them and charge them. So they used in Philadelphia , Again protest footage against Instagram photos to identify and arrest restaurant protestor there in November. The Washington post reported that investigators from 14 local and federal agencies in the DC area used it more than 12,000 times since 2019. So over a two year period, and they haven't disclosed who it was, et cetera. And in many cases they odd few skate where they got the photo from the, this is a technique that the police department have been using more recently, like over the last decade or two, where. They don't want to disclose the way they found out about something.

And a good example of that are these stingray devices, which are fake mobile towers that the police will put in place. Now they're not a tower, it's a mobile, it's a a cellular site. And so any phone that comes within that cell sites area is going to link up to the stingray device.

And then the stingray device is going to monitor everything going through it, which means, by the way, remember your text messages, your SMS messages can all be grabbed by a stingray device, which is really a huge problem. So they were trying to hide the source of the stingray as being the source, because they didn't want to reveal that these stingray, these fake cell sites they were using were actually in use that they even existed.

They were denying even the existence for a long time. And eventually we found out, yeah, that's what. They were doing until that's over with. But anyways, what they do oftentimes when they don't want to reveal the source is they'll lie about it. So they'll use that source, like a stingray device to identify someone, and then they'll go the next step and investigate that person a little bit and try and find something else and say yeah.

Someone at this diner reported this person, or we were at this diner having lunch, and we saw this person walk in knowing full well that the only reason they're there they're at that diner, which is 20 miles off of their beat, if you will, was because the stingray device had grabbed that person's phone number and they knew that they had been communicating and in fact, maybe planning some operation. Or another. Okay. So they'll lie about the source and we've seen that again and again many times. So the law enforcement now is using also something called geo-fence warrants. And they take them to companies like Google who is collecting data on us and where we are.

If you have an Android phone, it's guaranteed, the Google is tracking you. So one of these geo-fence warrant is issued saying, I want to know. Everyone that was within this area. That's geo fences and they will look in their database and check and see, okay. Who was in that area at that time. And then they'll give it.

This list of all mobile devices that were within that geographic carrier during the given time, they'll give it to law enforcement, then we've seen how people have been arrested and even charged for no good reason other than they got caught up in one of these geo-fence warrants.

Now, I don't want you guys to get the wrong idea here. The reason I'm telling you this is these tools for identifying people are not just in the hands of law enforcement. They are in the hands of bad guys. They're in the hands of advertisers. They're in everybody's hands. Remember Google, their whole business model, is making money off of you by you being the product. So if you are using Google maps, even if it's on an iPhone, Google knows where you are.

They may not know exactly what you're doing, but they probably have a pretty good idea. And they're willing to sell this to absolutely anyone, the data aggregators, the same sort of a thing that free app that you play. Isn't it fun? Yeah. Yeah. Well, Apple shut down the ability of many of these apps now to track you because that's how they were paying for themselves.

It wasn't that, you know, Hey, I made this free app out of the goodness of my heart. Isn't this wonderful look at this. No, no, no. It's because they were tracking you. Some of these were even malicious, particularly in the early days of Android screensavers that were downloading everything. It was just, it was crazy what was going on back in the days.

But our social media, the pictures that we're posted are available, not just to law enforcement, but to bad guys, nation States like China, uh, Russia, North Korea. Now we've got Iran and Vietnam involved in some of these things. And when we're posting the pictures, some of these sites will remove the geo information from the pictures and the videos. Others do not.

So be very careful with them, you might want to double check it. And it's handy sometimes, right? Like you can look at that beautiful trip to Disney world that you talk just by the geo codes on those pictures. Putting it all together. That's how some of these services, like if you have Amazon and you're uploading your photos to Amazon, they will put together a little photo book for you because they know, okay, from this day to this day, you were in Disney world and off it goes, and you can make your nice little photo book.

So be very, very careful about this because you, the identities that we have are not so secret and letting all of this stuff go, letting it become effectively public knowledge, I think is potentially a big problem. It isn't that I have anything to hide. It's that I have nothing to share. It's a great concept.

Remember, on, on all of that stuff, people were reporting what they were doing in DC and at these other riots around the country. Including, putting them up on Parler, which is offline, going to be online, probably would be offline. Gab is another big one, Telegram's, another one. But we gotta be very, very careful.

Okay. Be careful. Uh, there's home, honey. So many things we could talk about here. It's it's just absolutely crazy. Uh, but I want to get into Elon Musk here for a quick minute. He has been absolutely amazing. This man has taken some huge, huge risks. He said moving to the United States was the best move he ever made.

And I can see that. And he says, it's because of the freedoms we have here. Again, my cautionary tales here about regulation. You got to be very careful. He's now, Elon Musk, worth more than $180 billion looking at his shares. Isn't that crazy? And that of course is mostly because of Tesla. He has a lot of great ideas, including he's got this whole thing about going to Mars and he also has the, uh, the boring company, few other things, including a little thing called Space X, uh, stuff you might've heard about before too.

He's got some amazing rockets, but that is just, just amazing this week, at least on one point, Tesla was valued at almost $800 billion, which is several times more than any other car company. Which means that investors are thinking that Tesla is going to be worth more than any other car company and you know what? I think they're probably right.

I think Tesla is going to pretty much own the automobile industry and just a few years from now. Oh. And speaking of that, I don't know if you saw this, but apparently Apple is in talks right now. The very preliminary stage with Hyundai, who is a huge manufacturer, not just of cars, like the Hyundai and Kia brands, but of ships.

And that's how I've known them too, in the shipping industry. Having some kids in that industry. But think about this just over a year ago, 2020 Musk was only worth 27 billion. It's just, just absolutely amazing. So Tesla is really winning the game. They have the most miles they have the most cars. Uh, we'll see, and we'll see how this goes.

And by the way, mosque is making a lot of his money. From stock options that he gets based on the valuation of the company, which is not a bad way to incentivize these people. I mentioned earlier Parler. It was banned and is banned from the Android store, from the Apple's store. And also from Amazon, which was a major platform they were using.

We have seen over the last week, a ton of conservatives just being de-platformed and Parler was this free speech app. No, it wasn't the wild, wild West. They had restrictions on speech and it was clearly spelled out and Parler had committees that would look at things that were questionable. That had been reported. And were we moving things and because of that and the wording in what was said by these trillion dollar tech companies has got Parler now suing them.

So we'll see how that ends up going.

But this is just absolutely amazing to me. There is. Or at least there was no true free speech outlet online until Parler came up. Well, recently, right? Until Parley came along, we used to be a lot of free speech online, but you know, it gets, gets a little troublesome sometimes.

Google, it's just, it's incredible what they did here. And what Amazon did. Amazon pulled all of their servers. All of the services Parler was using and knocked it offline. So there are some lawsuits underway, expect more lawsuits over time. We'll see what happens.

A lot of libertarian as well as conservative people have had their platforms yanked. Ron Paul, who has never been one out there saying anything about an insurrection. Ron Paul's account was also yanked. So it's, I don't know. It's just crazy. What's going on. Guess we'll see, keep up, keep watching, keep listening.

Many people have gone over to some other sites like Gab right now is a Twitter replacement and good for them too. Pretty decent Twitter replacement, frankly, but there's another one out there called Mastodon.

This is really an interesting one. I like it. It's open source. Everybody can view the source. Anyone can run their own Mastodon server, which I think is just absolutely amazing here. And the idea behind Mastodon is all of these Mastodon servers can talk to each other, can share things so you can have the large conversations, but each server can have its own set of rules.

That's the part that makes it really interesting. And that's why I want to try and bring a Mastodon server up on the line

And I am looking for someone right now who loves to correspond to people and do some follow-up because I get a lot of inquiries and I want to make sure that I am getting back to people and getting back to them in a timely manner, because frankly, I get distracted as well .

So if you are someone that has a question, or if you think you might be able to help, wanna little bit of work and you know, every day to, do some follow-up and some tracking, make sure you just email me me@CraigPeterson.com. I'd absolutely love to hear from you.

Before the break we were talking about some of these social media sites and how conservative voices have been shut down. What's interesting is that Gab has picked up a lot of people, including president Trump, but Gab's had a problem too.

Gab has been kind of taken over by some of these. People might call them far right. Wingers, but that's not true. The United States has a different political scale than any other country, really in the world. In the United States, if you are on the right of the political scale. The far right is complete libertarian small "L" Libertine that's on the far right.

And then you start moving left to get into the conservatives, and then you keep moving a lot further left. You ended up in the Democrats and then further left from them you have the communist and further left from them you have the Nazis, right? All different forms of socialism. On the left. So left is socialism, right is freedom is kind of how you boil it down. That's the way it works in the United States.

In Europe, it is a different scale. In Europe. The scale is entirely socialist. The assumption has in Europe has gotten to the point where everyone wants to be socialist. It's just what kind of socialist. So on the right hand side of the European political scale, you have the national socialists, IE, the Nazis.

So the national socialists are on the right side of the scale. And on the left side of the European political scale, you have the communists, which are the international socialists. And then in the middle, you have these socialists that are, you know, kind of pro their country , maybe a little bit more international.

So think of a communist as it's my, my union brother, uh, in Minsk. And I am here in Detroit. That's what a communist would be. It's international. It's kind of what the United Nations is doing. It's an international socialist organization. And then you have over on the far right of the European scale these people who are Nazis, which is, I am in Detroit. I am a union member. I am making automobiles. And that's all that matters, you know, forget about Minsk. You know, I don't forget about it. Right. So that's the big difference nationalist versus internationalist.

Well, when we're talking about Gab.com, which is one of these social media sites out there, there have been many people who are national socialists who have been prominent on gab.

Of course, the people that make the most noise, the people that are the least appealing, the people that are the most offensive are the squeaky wheel by definition. And they're the ones who are going to be talking about right. So I think that's a, that's a good thing. And so a lot of these people migrated, these people on the socialist scales, the national socialists and the international socialists, both of whom want to control your life.

They started going over onto Gab and the. Only real free and open social network right now is something called Mastodon, M A S T O D O N. And it is based on originalist internet views of the internet. And I explained that last hour as well. I'm an internet originalist. I believe the internet should be open. It should be freedom to speak and speak our mind. And obviously there's a line there and that is where it's legal to speak our minds. Right. You can't be, be plotting. Things are going to result in imminent death or destruction, et cetera. Um, But that's where I sit. And I also think that anyone should be able to make anything and have it go on the internet for anyone to use and compete freely.

Well that complete freely is not a big part of the internet nowadays. Unfortunately. So with Mastodon, you can put your own server up and there is a map out there right now that's showing this is unofficial, but showing about 2,500 mastodon servers that are out there. That's pretty huge. That's a very, very big deal.

And it is kind of a friendlier social network, but some people have moved there that have these extremist ideas like BLM and Antifa, uh, who are, you know, obviously facist organizations in both cases. In other words, national socialists. And Mastodon's admins have been forced to deal with this problem, but the beauty of Mastodon.

Is it as completely decentralized kind of like the internet was designed going right back to what I was saying about being an internet originalist. You don't want any single point of failure, so I'll, I'll let you know how it goes here. I'm going to put a Mastodon server up. And maybe we can try it. Maybe I'll invite you guys to it once I kind of got at work and we can see how it does and how it all works, but you can find it out there right now.

There's lots of apps that speak this protocol that is used by these Mastodon servers, which have apparently been also integrated into other websites and network, but it's essentially a way to host a social media website. Users can post 500 character messages called "toots." Uh, and you can repost or boost messages on your own timeline, follow, or privately message other users.

But instead of it being a single site run by a company it is software built on open source freely available and using this Activity Pub protocol. So we'll see how this all goes. I will let you guys know.

Consumer electronics show. I am just disappointed . It was canceled due to the lockdown.

And that means that we aren't out in Vegas. And the beautiful thing about it was you could wander around the floors for days, seeing new gadgets, seeing new technology improvements, dramatically new ones. There's so many things. And it's just not happening this year. Now they have this virtual version that I signed up for, and I've got a lot of emails from people who are promoting the different products and, you know, the all well and good.

But when you get back down to it, um, It's just not, it's not the same. Right? How can you get excited? How can you have buzz? It just doesn't make sense, but some of the things that people have pointed out, like CNET has a lot of coverage this year, they have been the official coverage platform for the consumer electronics show for quite a while. But it is not like it used to be because they got caught with some bribes and other things.

So here's a few things just for you to keep an eye out for remember oftentimes stuff shown at CES doesn't show up for six months or a year, but foldable phones are one thing, but LG has shown off.

A rollable smartphone. Yeah, really the expecting to release it later on this year and you roll it up and you stick it in your pocket. I'm looking at a picture right now of a company called TCLs new phone. This is a Chinese company and it has a 6.7 inch phone that can expand into a 7.8 inch tablet.

And actually. Pretty big tablet looking at this picture here. They also have a 17 inch. That's what I'm looking at. 17 inch printed, OLED scrolling display that can be unfurled and has a 100% color gamut. So I'm looking at this thing. It's basically a rollout think of your blinds in your windows, where you pull it out.

That's what it is. And it rolls out to a 17 inch wide screen. Absolutely amazing. Now we are giving some of our clients, um, we actually haven't handed them out yet. This was an end of year gift and it took us until now to get it together. But these little devices that you can put your phone in, and it has an inductive charger, it creates ozone. And also has ultraviolet light. So in other words, it kills germs.

There's a company that introduced an ultraviolet light treatment system for your car to kill pathogens. This man, this frame TV from Samsung is amazing. This thing is only 25 millimeters thick, which is crazy. It's the smallest ever. And 75 inches, seven, five inch display. Is that something or what?

A bunch of a wireless phone chargers that came out. There is a kind of a neat little, um, Bluetooth shower speaker from AMP that is powered by the water that flows through it. Right? So it's stealing some of the water energy.

This Cold Snap you might've seen. They won an innovation award this year. It kind of was like a career machine you'd use for making coffee, but it makes single serve. Pod dispensed ice cream. It's just amazing.

An infinity table game. This kind of reminds me of Ms. Pac-Man and the table version that you can use for running games.

Samsung has new robots for the home. They have three of them. They've got one that's for helping to clean the house. One's a personal assistant and also acts as a security camera.

OWC I love these guys, Other World Computing. I've had them on the show a lot of times. They got a new charging port again, uh, it's amazing what these guys were able to do, but there's, there's lots of cool stuff that's coming out this year.

I think it's going to be a bit of a slower year than usual for some of these innovations. But, I expect next year we'll be back in full swing.

Thanks for listening today. Make sure you are on my email list. I've been sending out trainings about what to do with VPNs, how to lock down your Windows computer, and much more.

And you only get that if you're on my email list and I send out that email once a week, Craigeterson.com. And you'll find my podcast there. The articles I talk about my appearances on radio ,TV, everything. CraigPeterson.com and have a great week.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started this morning talking about some interesting developments that happened involving one of Jupiter's moons. Then we discussed how Gen Z is sharing so much on Social Media and how it is being used against them in some cases by law enforcement. Then we talked about secure communications. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here. Ganymede my gosh. I've been watching this space opera, but I absolutely love it. They've done such a good job that was actually written. These books were written by a group of people who got together and they have a pseudo gnome that they're calling themselves, but it's just, it's amazing.

Anyway, when I saw Ganymede in the news and this is probably why it made it to the news, frankly. But when I saw Ganymede in the news, which is one of the moons of Jupiter and FM radio signals coming from it, it blew my mind. Absolutely blew my mind.

So I talked to Matt about that because I'm a bit of a space geek, and of course we got into what's the problem right now. What's going on in technology-wise with this internet shutdown on conservative voices and being able to track people who were down in the Capitol. What are they doing? What's the FBI and everybody else up to? So here we go with Mr. Matt Gagnon

Matt Gagnon: [00:01:03] Speaking of things that are usually done on Wednesdays, how about Craig Peterson? Our tech guru who joins us now as he always does. Of course, you can hear him on Saturdays at one o'clock, as well, for his show where he goes into greater depth on all of these questions that we're about to ask him right now on the show. Craig, how are you this morning?

Craig Peterson: [00:01:21] I'm doing well. We're on Newsradio 98.5 FM as well as am 560.

I don't know if you heard this one or not. This just absolutely amazed me. I'm a science buff. You may not know it, but I was actually one of the contractors or subcontractors to the RCA Astro space people and help design parts of the subsystems for the space shuttle back in the day. So a bit of a space fan.

But you know what Ganymede is?

Matt Gagnon: [00:01:51] Yeah Ganymede is a Moon of Jupiter, right?

Craig Peterson: [00:01:53] Yeah, exactly. Yeah.

Matt Gagnon: [00:01:54] You're do know who you're talking to don't you?

Craig Peterson: [00:01:55] That's true too. We can talk about the show.

Matt Gagnon: [00:01:57] We can nerd out all. If you don't want to talk about technology, we can talk about space and just have everybody turn off the dial. That's fine.

Craig Peterson: [00:02:03] We have a satellite that is circling Jupiter right now and it picked up an FM radio transmission from Ganymede. It was about a five-second burst. It was frequency modulating. And they're saying it probably wasn't ET. It was probably just the clouds in Ganymede and the electrons creating the cyclotron thing, but anyway. Totally geeked out. I loved it.

I wasn't sure if you heard,

Matt Gagnon: [00:02:35] Are you kidding? I knew the moment you said, Ganymede. I knew exactly what you were talking about. I did see it. I did see a news article was written on it that said that scientists are explaining it as probably a natural phenomenon, but they have absolutely no idea what it is, basically.

Craig Peterson: [00:02:48] So cool. Anyway.

Matt Gagnon: [00:02:50] That could in fact be an alien base on Ganymede and they were about to invade us. That's, 2021, right?

2021.

All right. Craig Peterson certainly while that is a technological topic, we have earthbound technological topics to get to, and we can't get away from the fact that the big story of last week was of course what happened on Capitol Hill.

One of the interesting stories that you and I were chatting about before that I'd like to ask you about a little bit more here is about the stupidity of some of these people because the social media feeds for many of the people that participated in this is giving all the police, the feds, everybody who's investigating this just tons and tons of evidence to go after them.

I'm thinking of the picture of the guy who had the podium walking away Hey, look, there's my face just waving at the camera. The Viking guy, everybody else, all seemed to gleefully and happily share all the information about all the laws they were breaking on social media, making the law enforcement job pretty easy. Isn't it?

Craig Peterson: [00:03:44] Yeah, it's really easy. We talked about some of the alternative social media sites out there as well, like Parler, Gab, and Mastodon and some of these others. Did you also see that this one lady a programmer? She wrote a piece of code that was 400 lines long now, for those of us, that aren't total geeks. That means it's a very simple, very small program and she was able to pull down everything off of Parler. That includes, this is before Parler went offline, the videos, the photos with all of the GPS information still embedded in them. Apparently, this is just a treasure trove of even more information.

Like you were just talking about people that we're sharing it over there on Parler, and it wasn't stripped of any of the identifying information. You're right. This is just making it so easy for law enforcement to find all of these people and that's where it's going to get really interesting. Obviously, these people were among the more extreme out there.

Matt Gagnon: [00:04:52] So speaking of Parler, I do have to ask a little bit about what's been going on this, and frankly, we could probably take up an entire segment or two or three on this topic alone here, but Google, Apple, Amazon, and others. All banning Parler. It's only one of many recent moves that have had greatly concerned me about what's going on with the tech giants and how they're essentially sensor censoring an entire ideology away from their app stores and their social media feeds and everything else.

Talk to me a little bit about this move and what you think the ultimate implications of it are.

Craig Peterson: [00:05:23] I'm sitting down, which is good because it's absolutely incredible. I call myself an internet originalist, right? You've heard of constitutional originalists. We believe in why it was created and the internet.

Remember, I've been on the internet since about 81, 82. Before it was, frankly, the internet, and back then it was exciting because finally, we had a way to communicate. We had free speech online. We didn't have to buy a $200,000 printing press in order to share stuff, including silly little poems that we add back then. We were into Monty Python.

It was a different world. It was really evolving, nicely. Although the internet was designed to resist a nuclear attack, so we could lose an entire city, major city, you name it doesn't matter. We could still continue to communicate because it was designed for these research institutions primarily, at the time universities, to be able to communicate with each other. And also with the military for all of the research they were doing.

It was just a beautiful design, amazing what was done with it. Now the problem that we're seeing. Is that we have companies like Amazon that are in literal control of a good 60% of the internet. Part of the reason the internet was just so resilient is it is by definition interconnected networks.

It was, I've got my network of computers and I might be a small company, I might be a big company and we all get together and we pass each other's data. That's how it works. It's not like there's one big pipe somewhere that nobody's paying for because it's all free and the internet should be free, all of these crazy ideas. It's you name your local internet provider these cellular providers, all of these different companies, they all connect to the networks together and they then route data for other companies through their networks. That's been part of the problem with Netflix, for instance, that at times is consumed more than half of the internet bandwidth. People got upset because, Hey, listen, I'm just a small rural internet service provider and I'm pulling all of this data through my network not even for people who are paying me. For other people's customers and it's been back and forth and we'll have those discussions again in the future I'm sure with the new Biden administration.

But where we've now run into the problem, that we're seeing, is what happens when Amazon has 60% of the internet, based in Amazon?

Now I'm not talking about people buying and stuff for Amazon.

Matt Gagnon: [00:08:27] Are you talking about their cloud servers and stuff?

Craig Peterson: [00:08:29] Exactly. Exactly. Then with those cloud servers, they built their own extra services. So again, let's pick on Parler. Parler was not only using Amazon to host computers, which is what a lot of companies do.

They were using Amazon to host their name service so people could find them. They were using Amazon to do queuing for people's posts. Completely using the queuing services. They were using. Amazon's database services. They were using Amazon storage services. So now when Amazon kicks them off, all of a sudden they're out of business because they were a hundred percent dependent on Amazon services. Specifically, Amazon.

Twitter's in the same boat. Twitter is almost entirely inside the Amazon services.

So you now have these huge companies and GoDaddy's other example, right? Who pulled many conservative sites DNS, domain name service, but these huge companies control so much of the internet. They can say, no, we're deplatforming you.

If enough of them get together, and frankly, sometimes all it takes is Amazon. Even Amazon saying we're not going to allow your data to pass through our networks can put you out of business. It's great that some small internet service provider up in Idaho said forget about it. We're not carrying Facebook's traffic or Twitter or some of these other sites anymore.

But they really aren't going to impact anyone except for their customers. We're in big trouble.

Matt Gagnon: [00:10:12] All right. That's Craig Peterson, our tech guru. He joins us at this time every Wednesday, as he always does to go over the world of technology, including technology in space.

Thanks a lot, Craig. Appreciate it. Good luck on Saturday, as always. Make sure you tune in and listen to that here on WGAN one o'clock and we'll talk again next week, sir.

Craig Peterson: [00:10:27] Take care, Matt.

Matt Gagnon: [00:10:28] All right. Thanks.

Craig Peterson: [00:10:29] Can't believe it's been another week. Man, time is just flying now. It seemed like the election was years ago.

As well as of course, all of these things that have been going on, it was dragging for so long, because of the lockdown. Now things are just flying. It's just, wow, incredible.

Have a great day.

We are finishing up on what we're now calling our Introduction to Windows Security course.

That will be out very soon. Keep an eye out for that.

Take care, Everybody. We'll be back.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We had a lively discussion about the inner workings of the Internet and the decisions that Parler made that may have cost them their business. Censorship, Collusion, and Anti-Trust. Has Big Tech, the Sultans of Silicon Valley, become like the Robberbarrons of yesteryear?

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey everybody. I was on with Mr. Jim Polito this morning and we had a great discussion here. If you want to know what's going on with the internet, and why I call myself an internet originalist, and why you should stick around because here we go with Mr. Jim Polito of course.

Jim Polito: [00:00:19] You know what, right now, you want to be right here. We got our guy standing by who better to have with us right now than the tech talk guru. Craig Peterson.

Craig Peterson: [00:00:36] Tis I. Good morning.

I wanted you to get all excited, and say woo I'm here. I just want it. We have, we're w we're in Providence now we have expanded and the Providence audience doesn't know this and they might think I'm joking.

But Craig Peterson actually did help to invent the internet, Al Gore likes to take credit for it. But Craig Peterson wrote code for the internet that is still in use today.

Okay. He didn't invent it, but he was like one of the guys at NASA. Who got the Apollo program to the moon? There were many of them and Craig Peterson is one of the many people who get the internet to work. So I just want to make sure people understand those credentials.

Jim Polito: [00:01:28] Today we're going to talk about the internet. What perfect timing to have you here today, when there's craziness. There are how many businesses that really could, how many large corporations, big tech, very few who control the whole thing right now. Isn't that correct, Craig?

Craig Peterson: [00:01:51] By the way, one more thing for you. I also designed systems that helped to build design and fly the space shuttle. I don't know if you knew that.

Jim Polito: [00:02:02] Woah, Woah.

Craig Peterson: [00:02:07] Yeah, years ago. I don't think I mentioned that too before. Way back when I was down in New Jersey as a contractor consultant and I wrote this code. It was my company that was hired and we put together systems for RCA Astrospace who was building part of this. One of these days we'll have to talk about it. It was cool.

Jim Polito: [00:02:26] I want to hear about that because getting the shuttle to fly, they said was like getting a brick to fly. That's the way that the pilots who piloted it, explained it. So we need to hear that.

But look, here's what I'm bothered about. That Apple, Google, and Amazon can say, you know what Parler you're done now. They can say it's because of some disturbing material, but we all know it's because of competition. Come on. That's three companies. That sounds to me like the old robber barons and why we have antitrust laws.

Craig Peterson: [00:03:02] Yeah. This is really interesting because we've had so many people, libertarians on out, say it, remember the first amendment, the right to free speech only applies to government.

But the concept of free speech is part of the basis of this country. It doesn't just stop at the edge of the first amendment, frankly. I want to point out something else related to this. And that is I am an internet originalist.

So speaking about the Constitution and the Supreme court, I'm an originalist. The internet was designed to be decentralized. You could say and do almost anything, as long as it wasn't illegal online. The whole idea behind it was to create and implement new ideas. Anyone could now connect anything to anything.

Heck, we even got light bulbs now on the internet?

It was an open, free, fair society. It was initially used by the military research people. It was used by universities to communicate with each other. That kind of evolved into the ARPANET. And then they were connected together and it became the internet.

Even the term internet tells you what it is. It's an interconnected network of networks. It had no one place that was vulnerable. We could not have Russia blow up a city in the United States and have the internet disappear. It was entirely designed to be decentralized and still pretty much is. The problem is we have these companies, like you mentioned, who are so big, and ultimately so powerful that they can shut things down.

So when you talked about Parler as an example of how it was shut down. There are attorneys looking into antitrust regulations because of this. Amazon pulled access to their systems. Now Amazon runs about 60% of the computers in the United States of America. And certainly at a minimum of 60% of the computers that run the internet today.

What's happened is they have all of this computing power. They have all of this network connectivity. Remember I said, these are interconnected networks. So someone like Amazon can block data from Parler from even traveling over their networks.

Now the internet there are protocols like BGP and others. We won't get too technical, that are designed, well if Amazon goes off the air, or won't route the packets for Parler, we'll send them around another way. It's just like water seeking another way around and it can do that. It does do that. The real problem Parler seems to be facing right now is Amazon doesn't just provide computers. It doesn't just provide network bandwidth. Amazon has quite a number of services.

You can register with Amazon, for instance, and have it handle what's called your DNS, which is the internet addressing system. Parler did that. You can have Amazon handle the queue processing, automatic load balancing. Can manage your databases, can manage all of your data storage, but if you're going to have Amazon do these things, you have to write your program, your code, so that it knows how to use all of this stuff on Amazon. All of a sudden now, You are 100% dependent on Amazon. If you're a company that made the mistake of being Amazon, not just centric, but Amazon dependent, like Parler apparently is, if Amazon pulls the plug on you, you are out of business.

And then to top it off, you've got apple pulling the plug on Parler's app and you've got Google pulling the plug on Parler's app.

Parler was smart enough to say what would happen potentially if the apps were pulled.

Parler could be used via a web browser, except for the fact that they're a hundred percent dependent on Amazon and Amazon pulled the plug.

Jim Polito: [00:07:36] We're talking with our good friend, tech talk guru, Craig Peterson.

So Craig, look you and I could start up a small business right now and with nothing to do with the internet. Craig and Jim's coffee shop. Okay. There's a lot of red tape to go through, but we could start it up and we could do it and we wouldn't be dependent on these corporations. Some people may say you may be dependent to promote it.

But what I mean is we could actually start a coffee shop and if we were on a busy enough corner, be okay. We would have certain entities that would have to go to like banks. Okay. Yeah. Small business administration. Yeah. But still, there are ways to do that.

Craig Peterson: [00:08:21] There's no real way to do it.

You need truckers. You've got to buy the coffee. You have to have the truckers delivered every day. You have to work with a conglomerate, which is distributing cream that you would buy, right? You're not buying it from the local farm. By the way, that truck is probably driven by a union member. So any one of those people. Even if you want to compare what's happening now to starting a printing press and printing your own newspaper broadsheet, whatever it might be, you still have to get the paper. You still have to get the ink. Those suppliers when they are big enough can stop you from competing. They look at newspapers today, for instance, how many newspapers are printed by the New York Times, The Boston globe, including local newspapers. It's one company. Nobody has all of these presses, anymore.

I think we've just become far too reliant on these big companies.

Now there are some options. There's something called Mastodon out there that is a completely decentralized kind of Twitter, Facebook replacement.

Some people have moved to MeWe. The same type of thing can happen if they didn't plan, Jim.

Jim Polito: [00:09:40] Yeah, I guess I understand that, but there's no one thing that can shut you down. Like they can shut you down. They can really shut you down. You're done. You want to be in the world online. You're done.

Now. My question is so Parler signs a contract with Amazon and less, the Department of Justice decides to go after. Amazon and Apple for and others for antitrust. It's probably not that much Parler can do. Cause you know, I'm a free marketer and a free marketer is Hey Craig Peterson, and his amazing work. He can do business with whoever the heck he wants to.

That's Craig Peterson's prerogative and you can't force him to do certain things. I'm not one of those people. When you have this kind of power, I think robber baron, I think back to John Rockefeller and Standard Oil, it reminds me of that.

Craig Peterson: [00:10:42] Apparently, by the way, Amazon did violate the terms. Parler every time Amazon has asked us to remove something. We have removed it after, we double-checked it all. We have removed it and they have a 30 day period, according to the contract with Amazon, that if Amazon complains about something, there's a 30 day period where they have the ability to remove it and negotiate with Amazon, et cetera, et cetera.

None of that was honored. This all happened over the weekend. Basically with all of these companies. So now we're looking at collusion here. This is fascinating.

Then Ron Paul now, it's reported in the Washington Times, Ron Paul says I'm not calling for anything illegal and he's blocked by Facebook.

Jim Polito: [00:11:38] Yeah. Yeah. In the weeks to come, I'm sure we'll be discussing this more, but I'm glad you were here.

Craig Peterson, how do people get more from Craig Peterson?

Craig Peterson: [00:11:50] The best way is just to go to Craigpeterson.com. You'll see right there, the ability to subscribe. You'll see all my podcasts.

You'll see a lot of the articles and I've got training starting here in about two weeks on improving windows security. So it's step one. I have these all planned out. We're going to be doing VPNs and everything. Make sure you sign up.

Jim Polito: [00:12:17] You can find out about Craig peterson.com. I love it.

Craig as usual. Thank you for your expertise. I can't wait till we'll have to talk, NASA someday. About how you taught a brick to fly. But we'll get into that. Thank you very much, Craig.

Talk to you soon.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about Online censorship and the flurry of de-platforming that is going and the effects it is having and will have on our society. We also discussed if removing Section 230 protections for these Internet publishers will make it better or worse. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here, I was on with Chris this morning and I think was very interesting because I was able to explain section two 30 of the communications decency act. I know there is a lot of confusion out there, particularly among some of the people who are more towards the right, but it's all the way across the board.

What's censorship? When is it legal? How about libelous content? How does this all work? Would things actually be better or worse, if we got rid of section two 30? So here we go with Chris

Chris Ryan: [00:00:37] NH today, I am Chris Ryan appreciate you joining us for the program. Craig Peterson hosts tech talk. He joins us here each Monday on New Hampshire today.

Obviously. A lot to talk about with tech and censorship, after what happened this past weekend. Joining us right now on the program is Craig Peterson.

Craig, how are you?

Craig Peterson: [00:00:53] Hey, good morning. I'm not sure if you would have noticed what was going on with censorship. It's been quiet, frankly.

Yeah. Really heard anything about it. It's been really, as you mentioned in the backdrop of what's taken place. I think a significant figure was dropped from social media this past weekend. I can't remember who quite offhand. In regards to that, I'm interested in your thoughts. Because to me, whenever we use any of these platforms for free, whether it's Facebook or Twitter or Instagram or whatever the case may be TikTok.

We, in my view, are utilizing a product and there are individuals that can make a determination as to whether we get to use that or not. I, whenever I use this or I'm always thinking about what is their model and how do they make money off of this? We have a very good idea as to how that takes place.

What are your thoughts? Do you view a large tech company, such as a Twitter or a Facebook, differently than another media platform, such as iHeart, or the New York Times, or other entities that long have established gatekeepers who determine content? Who is on the air? Who is not on the air? What gets discussed? What doesn't get discussed? To me, there's this false notion that Twitter or Facebook is different than that and that there is as a first amendment, right, because you're getting to say whatever you want and putting it out there. That when that gets stopped all of a sudden, the first amendment jumps in.

Of course, to start this whole thing out, we are the product. If you're using something for free, like you're using Facebook or Twitter or whatever it might be, they're making money off of gathering your information and selling your information, right?

Yeah. Yeah, absolutely. And when you start talking about the next step here. Which is okay who's censoring? What's going on? What rights do we have? What rights do they have? The bottom line is there, there's always censoring. There always has been censoring. There's a huge difference between these online companies and your regular media companies.

That comes from, what there's been a lot of talk about over the last few weeks, which is section two. 30 of the communications decency act. These companies, specifically the Twitters and the Facebooks of the world, have been granted immunity from lawsuits where people are saying I was defamed.

If you are a newspaper, if you Chris on the radio, say something that you don't have any real backing on, you don't add the word alleged or alleged depending on how you want to pronounce it, to something that you're talking about. There's some personal liability. There's a liability against the radio stations, et cetera, et cetera.

Then there's the opinion pieces and various other things. So, this is really rather convoluted.

Although you have the first amendment yeah.

Chris Ryan: [00:03:45] When you're making the argument in regards to section two 30, you're making the argument for not you specifically, I'm talking about you in general. I'm sure you're making an argument for more censorship. One in which I think it was worth listening to and worth discussing because very often individuals are defamed on social media.

There's it's basically social media to a large degree has become, as I mentioned, you're spying on yourself. You're putting your true thoughts out there. The conversation that maybe would just take place with you and a couple of friends at the bar. Then all of a sudden is up on social media.

You're talking about coworkers, you're talking about other people, at times, and you're going after those people and saying things that are inflammatory, in my view by instituting two 30, that increases the censorship. In some circumstances that might be something that makes sense.

Craig Peterson: [00:04:34] You're right. Chris getting rid of two 30 does change the whole conversation about this. Now if without section two 30, and I think this is a mistake that many conservatives and libertarians even have been making, if you get rid of section two 30, now you will have more censorship.

Chris Ryan: [00:04:54] Yeah.

Craig Peterson: [00:04:54] Now without two 30, there is no wall between these big tech companies and lawsuits that are going to come their way. So they're going to say, okay we're going to tighten it up even more. So I'm not sure why people are thinking that get rid of section two 30 is somehow going to allow more free speech, it's not.

It gets back to these platforms again. Where are you talking? What are you doing? What rights do you have? Frankly, the rights that you have to say things are based on the platform. What the platform says. For instance, we have Parler, which was a complete free for all.

Pretty much anybody could say pretty much anything on this app and website. Google and Apple both removed it because of their standards. The restrictions they put in place. Amazon removed them and have removed some of these others.

So now the Parler is scrambling to try and find all kinds of new services. They're going to have to rewrite some of their software. This is going to be a big hit on them. There are other more diverse social media platforms that are out there, like Mastodon that people will be moving to.

Some of these conversations are going to move to the dark web. They're going to be even harder to find than they are right now, which goes again, back to something I've been saying for a long time, I'd rather know somebody is a real racist or is an actual fascist, et cetera, et cetera. The way I know that is because they're in the town square, marching around in a bearskin hat on with horns, whatever that was. We know what they're saying. We know where they're coming from versus having them all hiding everywhere. But, Chris, it goes right back to, again, your point.

This is, these are platforms. They are owned by businesses. They grant you certain abilities, I wouldn't even say. If you go beyond those, they have every right to knock you off.

Chris Ryan: [00:06:56] Yeah. Two things off of that. One - I feel that if these conversations are taking place in public, A, as you mentioned, who's who, I think that's a good thing in a lot of ways.

B, it's also easier for law enforcement to track what's taking place. People may think that things are safe and the FBI and other entities may be able to work behind the scenes to figure out what's going on. The conversations are happening, on the dark web and individuals are gathering and, setting things to come into fruition things may not be as safe from a law enforcement perspective.

The other thing on two 30. Is that we as broadcasters or media individuals self-censor and are also censored, but litigation is such a significant determinant in what people do. Whether it's from a medical perspective, whether it's from a broadcasting perspective and just the sheer threat of potential litigation would change the way that Facebook and Twitter operate in an incredible way.

In my view that the censorship that we're seeing now would be nothing as compared to what would take place in an environment where two 30 was taken away.

Justin McIssac: [00:08:06] How many libelous things I'd say if I couldn't get sued. Just about Chris, forget about everybody else, or slanderous, however, that works.

Chris Ryan: [00:08:13] Well as we well know, since I am. Public figure and a celebrity. Pretty much people can say whatever they want. So, Justin, you're free to go wherever you want.

Justin McIssac: [00:08:20] Let me make a list here. I'm going to get back to you.

Chris Ryan: [00:08:22] Go ahead, Craig.

Craig Peterson: [00:08:25] Yeah, we're looking at something that's very difficult to remember.

Everyone self-censors. Every news organization self-censors. You decide what's worth talking about on your radio show and that is a form of censorship. So it's been with us forever. It'll always be with us. Some of the things that happened that were printed in newspapers back near the founding of this country were absolutely incredibly libelous.

This is normal. It goes back and forth. Let's not totally freak out about this. Frankly, if you want to say something, maybe you should start your own little newspaper or this day and age a website or an app. You are going to be throttled. It just doesn't matter. It throttled by people who just don't care what you have to say, all the way through these platforms.

Chris Ryan: [00:09:16] Craig, always appreciate you joining us for the program. We shall chat again next week.

Craig Peterson: [00:09:20] All right. Take care of Chris.

Chris Ryan: [00:09:21] All right. That is Craig Peterson. You hear him on Saturday at 11:30 AM with Tech Talk replayed on Sundays on news radio, 610 and 96.7. I am Chris Ryan, Chuck Zada from the financial exchanges is next.

Craig Peterson: [00:09:32] Of course, right after I recorded this, I had a coughing fit. So thank goodness I was off the air at that point. All right, everybody, take care. We'll be back tomorrow.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started this morning talking about Tax Time and the surprising effects that may come in April for many of us. Then we got into changes in the way Hackers are attacking businesses and then we got into Facial Recognition Technology and how it is being used. Here we go with Matt.

And more tech tips, news, and updates visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, Craig Peterson here.

Today, we talked a little bit about distributed denial of service attacks. I explain what they are, how they're hurting businesses, particularly small businesses as the bad guys are doing more and more of them. We talked also about this problem with facial recognition software that has just completely gotten out of hand.

So here we go with Mr. Matt Gagnon

Matt Gagnon: [00:00:30] Tech talk with Craig Peterson right now on news radio 98.5 FM and AM 560 W G A N seven 36 Wednesday morning. Great time to talk to Craig Peterson, our tech guru, who joins us at this time every single week. And you can also hear him on Saturdays at this very station at one o'clock.

So thanks for joining us as always. Craig, how are you this morning?

Craig Peterson: [00:00:54] Hey doing well, coming out fighting to my Rocky theme.

Matt Gagnon: [00:00:58] Indeed. It is 2021, sir. Nice to talk to you in the new year. Hopefully a better one than last year, certainly. 2021 means that it's probably about time too, start doing my taxes and you had some information here that I found very interesting about how the pandemic boosted remote workforce might in fact be in for a bit of a shock when it comes to tax time.

What do you think about this?

Craig Peterson: [00:01:21] We've seen so many people leaving the big cities, moving out into the suburbs, into the burbs. In many cases, just moving a long way away. People from New York City and other major metropolitan areas, Boston of course. Many have ended up right here in Maine. Just all kinds of people all over the place, even like North Dakota in places.

But the thing that is really starting to scare people, especially accountants, is the lawsuits that have had to been brought to bear. Some of these States have decided that even if you have never, ever set foot in their state if your employer is in one of these high tax States. Every one of them, by the way, Democrat-controlled States, then you have to pay.

Taxes in your state now, Maine, and not your state, but their state main and math have an agreement in place that allows a little flexibility there. But if you started working for a company, even part-time as an employee, for instance, out of New York City, or even New York state, or some of these other different areas that you have to pay in New York City.

There's city tax, income tax, county tax, and state tax for your income that you earned from that state over the course of the year. As I mentioned, there are a number of suits in play right now saying, Hey, this isn't fair. We don't work in that state. We've never worked in that state.

But those regulators they're going to come after like crazy. I, one time exhibited as a vendor at a trade showdown in Connecticut. I started right then about a week later and for the next three years having to continually fight with the State of Connecticut department of taxes or whatever, they call it down there because they said you were down here, you had a presence here. You now have to pay corporate taxes on anything you sell.

Even if it isn't in the state of Connecticut. So double-check with your Accountant. This is going to get a little nasty this year.

We're speaking with Craig Peterson, our tech guru. He joins us at this time every Wednesday to go over what's happening in the world of technology.

Matt Gagnon: [00:03:46] Another interesting thing here is about this facial recognition story that you sent to me as well. Another arrest here. Based on bad facial recognition matching, which is fascinating. Cause it's an interesting technology and it's becoming more increasingly used in law enforcement and for other purposes as well.

Maybe not perfect though.

Craig Peterson: [00:04:07] No. We think about fingerprint technology that's been around for well over a hundred years and it's based on all the little swirls and imperfections that are on our fingerprints. And initially when it came out. There were a lot of questions. The science wasn't totally proven.

Now it's pretty well proven. And we can say with 95%, 8%, whatever, it might be the certainty that those fingerprints belong to this individual. However, what we've been finding with facial recognition is something quite a bit different. It's still early on that technology. Many people have the same basic features and that's where the problem comes in.

We found people who have been arrested spent time in jail, had to defend themselves, hire an attorney because their faces matched a person who committed the crimes face according to facial recognition technology.

Now we spoke a little bit, Matt, last year about this company called Clearview. This company has been going through every picture that we have posted on social media now. It's, we're on the internet and grabbing them. Then it tries to find landmarks on those pictures. Those faces is what's interesting. Yeah. Now when the police run your face through this Clearview database, which by the way, anybody almost can do with just an app on their phone.

So they take a picture of you, at a traffic stop or on the street and run the through the database. They look for those same types of landmarks, try and line them up. They may or may not match if they match. Boom. All of a sudden you're a suspect in a case.

There's a case that I just shared this week of a gentleman who was accused of shoplifting candy. This guy had to spend five grand to defend himself and they ended up dismissing the case for lack of evidence. Are you kidding me? Did anybody bother to look at the pictures? The one that Clearview or one of these other organizations companies said - yeah, it matches him or her. Did anybody bother to look at them? In some of these cases? No.

The police are sent in with an arrest warrant to arrest someone. Those police officers are not double-checking all of this data all of the time. That gets very concerning and it isn't just minorities. We've heard of, for instance, black people's faces, particularly black men. This software has a hard time recognizing. The same thing's true for Asians and many other minorities, but it's also true for us white guys.

This is not technology that's really ready yet. It might give people the police, et cetera, an idea of who it might be, but we're putting far too much trust in it. Places like Portland, Oregon, and others have said, we are banning facial recognition technology in our city. In some cases, States are taking this up because of how inaccurate it is.

Matt Gagnon: [00:07:24] Finally, Craig, before I let you go, the denial of service attacks have become a little more sophisticated, a little more complex in 2020. So that's a great harbinger for 2021. Tell me more about this.

Craig Peterson: [00:07:36] In case you're not familiar with it, these are attacks that are used for a different type of ransom. And many times they're used by these quotes, social warriors, unquote. So here's what happens. A business has a website online that website is used for disseminating news or maybe for selling products online. What'll happen is one of these bad guys will say, Hey, if you do not pay this. Ransom. If you will, we're going to hold your website hostage. They will use. Home computers, tens of thousands of them to send web requests to the website. So what's happened is these home computers have been compromised and they have a remote control on them.

So that's your own computer because you did not keep it up to date. So they'll have thousands of these computers now say give me your homepage or give me the checkout page on the website. Of course, the website now becomes completely overloaded and no one can legitimately get to the website or checkout, et cetera. It's become very prominent this last year because of the number of bot networks out there.

But also due to companies like Amazon, and others are now renting computers by the hour. Some of these bad guys come in the rent a bunch of computers. Again, they could rent a thousand of them spend maybe a thousand dollars on them and ultimately end up with tens or even hundreds of thousands of dollars in ransom payments.

So it did go up, as you mentioned this year, Matt, in a big way. It's particularly harmful to small businesses that have no way to cope with these denial of service attacks and they are increasingly expensive to protect against and more and more of them.

Hard to believe. It's 2021. It's one of these, Thank God it's 2021 because hopefully, things will be a little better, no matter what happened with the election, maybe we can get these things cleaned up.

We are idiots for using technology like this in our elections.

But anyway, that's it for now? I'll be back again this weekend.

Take care, everybody.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This has been quite the week for Tech news with Big Tech lowering their Iron Fist on any opinions with which they don't agree. Social Media censorship is here and it has taught us that if you want to communicate freely you cannot and must not use their platforms or services. I will introduce you to a new service that is out of their control and completely decentralized -- like the original internet. Plus we will talk about Elon Musk, What'sApp and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

DDoS Attacks Spiked, Became More Complex in 2020

Mobile Endpoint Security: Still the Crack in the Enterprise's Cyber Armor

Amazon still hasn’t fixed its problem with bait-and-switch reviews

Pandemic-boosted remote workforce may be in for a shock at tax time

Another Arrest, and Jail Time, Due to a Bad Facial Recognition Match

How to Build Cyber Resilience in a Dangerous Atmosphere

Hacked home cams used to livestream police raids in swatting attacks

Microsoft Says SolarWinds Hackers Also Broke Into Its Source Code

Google, Apple, and Amazon bans Parler

Mastodon is the Only Open Social Network Remaining

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hi, everybody. We're going to talk about the latest type of attack that's coming in. What you need to know about it. What's going on with this endpoint security with so many of us working from home and Amazon still has not fixed its bait and switch review problem.

Craig Peterson here. Thanks for joining me. Hey, this is all about technology. Of course. If you're new, I do a lot of work with security. In fact, I've been doing it for a very long time. I have had training that I've conducted here for most of the fortune 500 companies. Federal agencies, almost all of them. In fact, and more than 5,000 small businesses have turned to me to help get their stuff done. So we tend to talk about security, but we'd talked about a lot of other technology subjects here on the show, and I really bring a different look to it, frankly.

It's all about results. It's about what it means to you. I hope you understand a little bit better. I don't know about you, but I'm not real fond of just here's a list of what to do with no reason behind it. I want to know why I'm doing it. I remember going to a Tony Robbins event some years back, and one of the things he pointed out was, Hey, it's one thing to put it into your calendar. It's another thing, of course, to make a goal. But if you really want something to happen, you have to have your big, why.

So what is your big why do I need to do this? That's what we're doing with our course. That's coming up here just in probably about two weeks. We're finishing it up. Now we spend a lot of time on this. It's an introduction to Windows security and helping you to lock down your Windows machines. I think it's a course, everybody should take, everybody should know about, and this is geared towards consumers. The things we need to do as just a regular person who might be working from home in order to tighten up Windows.

Now we have much more advanced courses too, but this is all of your basics. So keep an eye out. I'll publicly do a couple of webinars as part of this. If you want to know more about it and get in on some of these free webinars and get this information, just send an email to me@craigpeterson.com and in the subject line. Put in Windows hardening or Windows course. Whatever you want so that I can figure out what's going on.

Also, by the way, if you're listening to me, you might be the right person because I'm looking for someone to help me with handling all of these emails that I get. I have all kinds of filters in place. That's not what I'm worried about, what I'm worried about is getting answers to the people that need help. I tell people all the time, just email me@craigpeterson.com. I get tons of people every week, just hitting reply from the newsletter. I would like to be able to make sure that we have people who, or at least a person who's really responsible for this and who is going to, in fact, let everybody know that we are paying attention and rattle my cage.

What, I haven't gotten an answer back to you because, right now it takes me a week, sometimes longer. To get back to you, so I got to apologize for that. If you're interested in that, if you're somebody who is really big into helping people and likes to understand the computer stuff a bit, maybe knows a bit about security. Maybe you're already on my email list, just signed up@craigpeterson.com. Send me an email me@craigpeterson.com. Let me know you're interested and why you're interested in it. I'll send you a little bit more information because I do try and give back to everybody, but I have a business to run with some very big clients and small clients, but a lot of work to do all of the time. It might take me a little while to get back to you until I find this perfect person who hopefully is sitting out there and wants to do a little bit of work from home, no matter where they are, as long as they can get and send emails. That's probably about all the bandwidth they'll need, so you don't need a whole bunch of it. Me@craigpeterson.com for any questions or comments or anything else.

Getting into our first article of the week. This one's from reading. And they're talking about the denial of service attacks. In fact, more specifically distributed denial of service attacks, spiking, right? This year, well in 2020, and it became more complex as well.

So I wanted everyone to understand what a denial of service attack is because it is probably the number one reason that the. Quote internet, isn't working unquote denial of service attacks or where a bad guy decides that they want to hold a company hostage. How do you do that? In this day and age, people are all over the place.

You're not about to walk in the front door armed and tell everybody, Hey, pay up or I'm not leaving. That's just not going to happen. Is it? When will you get right down to it? You don't have to do that anymore. You don't have to have a real hostage. All you have to do is say, Hey, we're going to hold your servers hostage.

Now you probably know already about ransomware and ransomware is a real big problem. It is growing. It has been out there for a long time and we're, ransomware where they gain access to your systems. And they do one of two things, or even both one is. They will grab all of the data that looks interesting to them.

So they'll look through your spreadsheets. I'll look through the documents that you have out there. They'll try and find information that they think that they could extort you with. And then the second thing they'll do is encrypt your files and say, pay up if you want to get your files back. And unfortunately many companies, many organizations, including healthcare organizations, government agencies, state, as well as federal.

And locals have all been hit by this. And they find that their backups are not good enough. They either weren't working properly and they thought they were working or many times what happens is a, just weren't doing it at all. And so all of a sudden, all of their files are. Encrypted do you know the important ones and they just can't conduct business anymore.

Of course, the first step is they've got to clean up all of these machines that have been infected before they even can do the backup. So in many cases, people are paying the ransom, even though it's been made clear by the state department and others that pane the ransom is supporting terrorism. And what they're doing now is.

Bringing charges against some of these companies who should have been secure, because if you are a public company or even if you just have basic shareholders, not even a publicly-traded company and you are effectively out of business and by the way, getting one of these ransomware attacks can put you out of business.

Most of the time it does put you out of business. And so they get. Sued and civilly and potentially criminally as well for sending a hundred thousand dollars, $10 million to terrorists around the world, which of course encourages them to go ahead and ran some more companies. Also lets them know that, Hey, you'll pay a ransom.

So why not ransom you? It seems like a good idea. Doesn't it? And Oh, guess what they do ransom you and they'll ransom you again. You get the double whammy where you now have to try and get back into business so you say, okay it's going to be way cheaper to pay the ransom, which is what they want.

That's part of the reason they looked at all your files to see if they can get the County records. How big a company are you? How much could you pay? Cause they're not going to charge a ransom of $10 million to some poor person who's retired. Just trying to go online and. The next step is they say, okay guys, you haven't paid the ransom.

If you do not pay this extortion fee, we're going to release all of your files online. So now you're going to get. They extorted. And in other words, they'll say, Hey, we grabbed all of these files and they'll give you the names of some of the files Neil just gasp. Oh my gosh. That's our business plan for next year.

That's our competitive analysis. Oh, that's our intellectual property. Those are all of the designs we've been working on for the last few years or decades in some cases. And I probably should do something about this. What can I do? Pay up this extortion money and we won't release them online.

Now of course, sometimes they release them anyway. And the other big problem that people have with this sort of thing is if it does get out, you might actually be breaking a law. You might have what's called CUI or other information that really could nail. You legally with the federal or state government.

So there's a whole lot of problems there. So that's one of the ways the bad guys are ransoming and extorting money from people, but there is another very big deal. And that's what we are talking about right now, which is a denial of service attack. And one of the beautiful things. Form from the standpoint of the bad guy with a denial of service attack is it's almost impossible to trace the source of the attack and it puts the company that's under attack out of business.

So how would you like that when you get attacked by someone you don't know who's attacking you, you may not even know? Why because many times these types of attacks, which are increasingly cheaper for the bad guys to do many times, these types of attacks are conducted by social activists. Yeah, our green warriors out there and others who will start attacking in these inexpensive ways.

Of course, you can find all kinds of information online, subscribe to my podcast as well. You'll find it on your favorite podcast platform and online@craigpeterson.com.

We were just talking about ransomware, how it's being used to hold hostage, various companies, as well as being used for extortion. Pretty bad things. Now we're going to talk about a cheaper and easier way. The bad guys are. He didn't us.

Hi guys, this is really a fun world, a scary world, all rolled into one because the bad guy's methods are becoming more effective and cheaper for them to conduct. That's the scary side of this whole thing. Because these bad guys are out there making many millions of dollars.

It used to be difficult to do. They used to have a bad guy that really understood programming and understood the bugs that were existing in our networks and in our computers. Pulling all of that stuff together, trying to make the whole world really a worse place. It was just a very few people and then the dark web really grew where the bad guys that we're writing the software. Now we're selling it on online forums.

You can go online and for 10 or 20 bucks, you can buy software that does all of the ransom stuff for you. If you don't mind giving away five or 10% of your illegal proceeds, all you have to do is. Sign up for an online service that will do everything for you on the backend of the ransomware. They'll do the tech support for the people who have been ransomed. They'll go ahead and yeah, they'll even take phone calls when the people are saying, okay, so how do I pay this? How do I buy Bitcoin in order to pay you? How do I make any of this stuff work? How do I put in this key that you sent me? It doesn't seem to be decrypting. What do I do? Absolutely amazing. It is really quite an industry.

Then there's obviously pretty complicated and there are simpler ways for the bad guys to nail us. This is what's happened over the last year. 2020 set records over what are called distributed denial of service attacks. How they're used to harass organizations, extort them as well.

The basic idea is you as an organization, have a website and it might be a federal government website. It might be your local soccer team or state or federal. It doesn't really matter. The extorter will say unless you do what we tell you to do. Which might be to pay a ransom or stop oil drilling in Alaska? It might be anything right.

Some of these anarchists are out there and if you don't do it, what we're going to do is we're going to shut down your website. For a lot of businesses shutting down the website is a terrible thing because so much of their profit comes from the website.

So many people mis-think profit. I was just thinking about this last week. Profit is not bad. It is not evil. Profit is what pays for the light bill. Profit is what pays for the medical plan. Pays for the employees. Pays for the physical facilities. Pays the employees electric bills for the home, for the cars, for everything. Okay. Profit is not evil. Profit is absolutely necessary in order for us to live.

If you're getting money. You are getting the proceeds from a profit that was made by somebody. Now, obviously, if you work for a government agency that is taking money from people, I wouldn't consider that profit. If you are a regular person and entrepreneur or an employee, that profit is absolutely necessary.

When one of these green warriors says, you got to stop drilling, or you've got to stop manufacturing this, or you need to free this person, et cetera, et cetera. You are worried because what are they going to do to you? Then you find out they're going to put you out of business. Then what do you do?

So many companies have been complying. You see it all of the time, the people are extorting, various media outlets saying unless you stop taking or stop advertising on this program. It might be Glenn Beck. It might be Rush Limbaugh might be met any of these conservative radio programs. You'd like to listen to. Unless you stop advertising on those we're going to shut your website down. Most of these businesses concede. They give in to these terrorist demands that are made by these organizations. What they're afraid of is if these organizations do a denial of service attack, that their website's going to be unavailable and they are no longer going to be able to conduct business.

That's just one of the things. There's other things that these bad guys do to extort businesses. When you go to a website and you go to the checkout page on that website, what's really happening? Obviously, you're sending a request to the webserver and it's a request for a page and it has to go through an encryption-decryption. Then it has to go into the back end that keeps track of everything in your cart. Then it has to go when they accept the payment, which might be a credit card, et cetera, et cetera. These web servers can only handle a certain amount of traffic. You've heard it before. Oh, my server crashed because I had just this heavy load on it. Too many people are trying to buy my product, which is actually not a bad thing.

There are also problems with the amount of bandwidth. So you have a server. Great. It can handle a thousand requests per second. Let's say, which is pretty darn big servers is probably actual little server farm and the network connection to that server or server farm can only handle a hundred requests a second.

So you've wasted money on the backend. So you tend to try and size that all appropriately. So you're not just pouring money down the drain. What happens with a distributed denial-of service attack is they get dozens, hundreds, or even thousands of computers to try and go in into the cart, try and do a checkout, trying and pull up pages that maybe have a lot of heavy graphics on them so that the server now has a huge load as does the network connection.

So they're saying, okay, so what do I do about it now? There are some ways to deal with these types of attacks. Are some companies out there I can point you to, if you want to just drop me an email. If you have a web server you're concerned about maybe this happening to you, I can point you in the right direction to CloudFlare or some of these other ones that are out there.

Just email me@craigpeterson.com. Be glad to let you know a little bit more about it. But it is hard to shut down, particularly if you are a very small business and your internet provider has never really heard of you before. And the people who are maintaining this server you're in the same boat.

You're paying me. How much am I? $8. Yeah, no, sorry. We're not gonna, we can't really help you. And in fact, they don't help you. And that can be, even if you're paying couple-hundred bucks, depends on the quality of the people that you're working with. So what they'll do then is have all of these computers hit it's called hitting the web server, trying to gain access to things and shut it down.

Now, there are some services, as I mentioned that you can use to help stop these things once are underway. But the barrier to entry for performing a denial of service attack is extremely low. There are all kinds of, hire services that allow attackers to launch bigger and more consequential attacks.

And it's pretty simple to orchestrate. So we've gotta be very careful. Global pandemic drove a sharp increase in these types of attacks. And they're going to continue. They're going to continue because they make money. Man. I'm looking at the FBI advisory on this too. It's frankly, pretty scary.

We're going to talk about the crack in businesses' cyber armor and it might be you.

Verizon's 2020 mobile security report has found that foreign 10 companies were breached through a mobile device. With so many of us working from home, frankly, this is really bad news.

Mobile endpoint security is a real problem, frankly. It's the crack in our organization's cyber armor. We have mobile devices. Many of us are using Android, which you guys already know. Then I say you probably should not be used because of a few problems. The biggest problem, frankly, with it Android is that the security updates just don't make it onto most Android phones when you get right down to it.

Big problem is that the manufacturers do not take the updates from Google, for Android, for security problems and put them on all of their devices. In fact, in most cases, you're looking at a six-month window before most of these devices have the security updates installed on them. If they ever get installed and looking at some of the statistics about which version of Android these devices are running, it's frankly very scary.

So it's a huge problem. It's why I always recommend iOS Apple devices. The I-phones the eye pads for most businesses. If you need the utmost insecurity while there's some other things you probably need to look at, however iOS and the iPhone was certified by the military a couple of years ago. It's reasonably safe.

Of course, nothing's perfect. But. Bottom line, a combination of these best in class technologies, like the I-phones and following some instructions I'm about to give here are really the front line in helping our organizations, our businesses, and you from falling victim to these ever-growing threats.

These bad guys are extremely well-funded. We just saw Vietnam enter into the league of nations that are known as hackers attacking us. No, we've known about North Korea, China, Russia, Iran. Now we've got Vietnam. And many of those nations have a whole lot of money and their goal is not necessarily to extort all of that money from us.

In many cases, the goal is just to cause havoc and confusion, and man, have they been good at doing that? So if they develop a tool. And then they share that tool with hackers all over the world. They've accomplished their goals, haven't they? Because they're causing havoc now. And in the case of North Korea, they do want hard currency.

No question about it. But these tools that are for sale for cheap out on the dark web are being developed. By Russian and Chinese hackers for the most part official ones, they're working for their governments. Mobile devices have really been at the core of many of the 2020s. Highest profile attack.

So for instance, we talked about this attack against Amazon CEO. Bezos's I phoned compromise incident. And what happened when a mobile device was penetrated by. Just using some bugs in an application and a video that was sent and opened. Okay. So you got to be careful about these things. That's another reason why in my windows hardening course, my introduction course, I really stress removing apps.

You don't absolutely need it. And another thing that I talk about in this introduction to a windows security course is. The problem we have of the apps we use to communicate. And that's what nail Jeff Bezos. The guy got a divorce and it was just amazing the amount of money that was part of that divorce settlement.

But he was using an app that he didn't need to be using, and that's how they got onto his phone and were able to grab other things. So just removing those apps, but. I'm really concerned right now about WhatsApp because so many people are using it. I've gotten questions. I've received questions from some of our listeners who have family members who are in the military overseas, and they're asking, Hey, can we use WhatsApp in order to have a secure chat with my daughter or husband, wife, whomever, it might be overseas in the military.

And although WhatsApp is the most popular communications app it's got over. I think it's 2 billion users worldwide and it has had end ending encryption remember Facebook bought it a couple of years ago. And that makes it dangerous. And the new terms that have to be accepted for using WhatsApp in the future, indicate that Facebook really is starting to play some games here with how secure WhatsApp really is.

So I go into a lot of detail in one of the modules on how to communicate securely, but there you go, Jeff Bezos, which was very expensive to him. Came in from a mobile device, simple fishing, most common way, mobile devices get compromised. And this is where you typically get an email that looks like it's from the bank or Amazon.

And you click on a link and unfortunately, Because of the lockdown. So many of us are working from home using our own devices. And what that means is many of these devices have not been vetted by any form of security, professional. Okay. It's really bit of a problem and there's been a 37% increase worldwide.

And according to this Verizon report in mobile fishing, Just between the last quarter of 2019 and the first of 2020 now add to that, the whole lockdown. And it's gotten a lot worse and that's according to the lookout who tries to keep tracking some of these things. We've also got the problem of a malicious wifi hotspot.

So don't connect to those. What I advise you to do if you're out. On the road you're maybe at the airport or coffee shop? The good old days, right? Don't use the local wifi. Use your cell phone, use your data plan and have your cell phone. Tether your computer to go online. That's much safer than using wifi hotspots.

And we go into quite a bit of training on that as well, in my introduction to windows security courses. So what happens if their security fails. That's where again, you've got to be using something that's moderately or fairly secure, like the iPhone, by the way. Oh gee, Phil Zimmerman. They started another company.

I don't remember what it was called now. If you're interested, drop me an email. I'll look it up. But they have. Phones that are designed to be highly secure and they're actually Android-based, which they would have to be because Apple doesn't really so source code, unlike Android, you can get most of that source code.

Anyways, worst outcomes here. Number one, some of these are very hard to detect some of these intrusions. They're hard to get rid of in many cases, and these are real problems. Rule number one, never jailbreak your phone because that's going to open you up to all kinds of problems. There could be spy where payloads that are put onto your phone, but the bottom line don't jailbreak them.

Keep them up to date. Don't use Android. If you must use Android. The simple rule is to stick with the major manufacturers like Samsung and use their state-of-the-art phone, whatever the best one is that they have, and upgrade your phone at least every two years. If you're using Android. If you're using iOS, you got five years, which is why I phones tend a lot cheaper, frankly, and require encryption.

All right. Lots more to talk about.

I use Amazon all of the time, but there are some things to be very cautious about when it comes to Amazon. It's really not the trusted platform that I started using more than a decade ago. So we're going to get into that right now, bait and switch.

If you miss any part of today's show, you can also find it online@craigpeterson.com. Amazon has a lot of problems. In the last segment, we're just talking about how it's CEO got hacked via a message that came in through a messaging app. It was actually a video and it is a problem, right? So you've got that sort of a problem.

You have the problem of being a small business and trying to compete with Amazon. I will admit that I use Amazon a lot for buying things. It's just simpler. The first thing you have to remember when you're using Amazon is they don't necessarily have the best price.

In fact, many cases, they are not even close to the best price, both Amazon and Walmart have some amazing, huge stores online target, of course, does as well as some others, but. When you compare the prices between them. I think you might be a little surprised. One of the things Amazon's done to lock us in is this Amazon prime membership, which is really handy.

You get some of the best deals because they have their prime day. Plus they have some special deals that are just for prime members at different times of the year. That's going to cost you more than a hundred bucks a year for that prime membership. But frankly, it makes up for it in shipping if you use a lot.

And I'm sure that's part of what they're thinking here, right? And they also now because of courts and really being forced into it, they have a little notice saying that this price might not be the best price and it's available from other sellers. So you can click through and it'll show you other sellers that are there.

On Amazon's website who have products that are, Amazon's also selling, but yeah, they might be cheaper. Usually when you add that less expensive price, plus what that other vendor on amazon.com wants to charge you for shipping. It's usually about the same price as what Amazon's going to offer it to you for.

So keep that in mind when you're shopping, the price might not be the best. What looks like a great deal with the price. Mark might not be such a great deal after all. So buyer beware, right? But there's another problem. I, this last year for present got one of those massagers. Now I've really been into massagers for many decades.

Now I used to get them a Brookstone. They always had the best selection. And so I just buy it from them. Since I got to try it in the store. And it was it was really great. And Brookstone in fact, was headquartered right in my hometown in Merrimack, New Hampshire. I thought that was cool too.

Cause it's a supporting a local business. Of course, they were purchased. I think it was SIM bought them. And then I have no idea what they're doing nowadays. It closes most if not all of their stores, but anyway, so I've always liked the massagers. They help with those aches and pains that you get at any age.

And particularly as you get a little bit older and. There was a massager that my massage therapist was using. And they just, one of these little percussive handheld things, it almost looks like a gun and it has a bunch of different attachments you can put on the end and it goes back and forth and just percussively massages.

It does an amazing job. It gets the muscles that are tight to let go to loosen up. And so I went online and I found what I thought was probably the massagers she was using. She told me, and then of course I forgot what it was and there were dozens of them available on Amazon. So what do you look for social proof, right?

Isn't that the normal way? So I look in for social proof, which is, Oh, here's the one with the thousand reviews and with the. Oh, five stars or four and a half star raining. Great. Let me just stop. I'll do that. Let me buy that. And you can always return it if it doesn't work. So I did buy it and it did work.

And let me tell you, I'm just so happy with it, but what I noticed inside the package, it was a little card and I've been seeing this more and more on products that I buy from Amazon. Where the person who's actually fulfilling this order, send you a little notice and maybe ask for some feedback or says, Hey, don't complain to Amazon.

If you have problems, go directly to us and we'll make sure it gets resolved because they want those five-star reviews from you legitimately. You can't blame the moment. If something happens, which it can happen, nothing's perfect. And they'd tear, take care of it. Lickety-split. I'm still going to give them that five-star review that they frankly deserve because it's a good little product.

It wasn't necessarily their fault that there was some form of infant mortality, which does happen. And it happens with anybody any time you buy any sort of technology. So I. What did the card a little more closely at to see what it was and guess what they were doing? They said, Hey, listen, if you go on to Amazon and review our product, now they didn't say you had to give us a five-star review, but that was almost implied.

If you go on to Amazon and review our product and you send us a picture of the review that you made by email. You can choose one of these gifts. And one of the gifts was a battery. For that massager. There were a couple of others that I don't remember cause the battery is the most appealing to me and I thought what the heck?

I'm going to review it anyway. So I did and I sent them a picture of my email and it's been over a month and I haven't gotten my free battery. They got me to wondering what's really going on here. And I found an article here by Tim Lee over at ARS Technica. Saying that he bought for his kids, this little $24 drone very cool drone.

And he gave it to his daughter to play with. And I'm not sure who the other kids were, but one of the propellers got stuck in her hair after the kids were playing with it for a few hours. It's really a cool one. It's got four propellers, but the whole thing is enclosed inside a little cage so that the kids can't really get their fingers into it and potentially get hurt.

Although most of these little tiny drones, you can get whacked with those propellers, and it's not going to hurt at all. Really. They had fun. They were able to play around with it. But after that first few hours, it just basically stopped working because it got caught in the hair and that's going to happen.

So he went online on Amazon and decided to do a search and he found a great review here. He searched for children's drone and sorted them by average customer review. Which makes sense to me. And he found a $23 drone with 6,400 reviews and an impressive five-star average rating. So let's promise you, that's what I would do, right?

How about you? I, I think that's what most of the, most of us are doing. There's your social proof. But then he started to look at the five-star reviews. And this is something I talked about on the show about a year ago. How do you tell if the reviews are legitimate or not? While you can do a few things, one is looking for major grammatical errors, which a lot of these reviews have, but here's what he found now.

Remember. This is supposedly a review for a drone. It says wonderful texture and great taste. Five stars. Absolutely love this, honey. It's quite different from any supermarket purchase, honey out tried. It's rich, thick, fragrant, and tastes wonderful. It's on the expensive side. Yes, but also worth it. The packaging is paper metal and glass in the jars.

Definitely, be reused or recycled. There we go. There's a grammatical error, but not a lot of them. It goes on and on raving about this honey. This is a drone. So what's going on here? This is a real problem. Here's another review that he found. If you're looking to have a taste of Greece without making the journey, this honey does the trick.

That was another customer, supposedly that same month, the third one wrote that it was dark luxurious pine honey, not too sweet, absolutely fantastic. With strained, creaky, yogurt and extra cream. Now he said, when you read the reviews on Amazon by date, he saw that the most recent reviewers actually had.

Bought a drone and they were overwhelmingly not giving it five stars. Bought this from my grandson, a customer wrote on December 26. He played with the, for two hours before broke and it's no longer working. He gave the drone one star. But all these older reviews were for honey. So apparently the manufacturer had tricked Amazon and just thousands of reviews for an unrelated product below its a drone, helping the drone to unfairly rise to the top of Amazon.

Search results. So there's, I think a very big word of caution. There's a lot of examples on Amazon about this sort of thing. This iPhone 10 battery case listing used to be for a leather wallet, phone case. Another battery case was formally listed for lightning charging cables, a Wi-Fi router that was listed as nanocomputers previously.

Been by the way that one collecting reviews since 2003, here's a neck brace. It was formerly a shower caddy listing. Guitar string action gauge is now a page for magnetic glue, free eyelashes. So Amazon does say that they have clear guidelines about one product that should be grouped together, and they have guardrails.

They call them in place to prevent abuse, but this is one type of abuse. And it's pretty obvious because a drone is not honey. So if you were actually to read those reviews, which obviously this guy that wrote this over to our set, Anika, Timothy Lee had not done before you started having problems.

But if you actually read the reviews and they're all for the right product, then what. What about this back massager that I got this little massager. Is that gonna show up this way? No, it's not because people are going to give it the five-star reviews because they want the gifts are going to be headed their way.

So be very cautious. Amazon has not solved this problem yet.

We still got a lot to talk about, including taxes here. For those of us working from home, a big shocker coming.

You might be in for a bit of a shock if you have been working remotely due to this whole lockdown thing. In fact, millions of us are going to have a bit of a shock coming up soon.

We have been busy here for the first hour. Talking a little bit about the Amazon bait and switch reviews. What I do when I'm online shopping and how you can help keep yourself not just safer, but make sure you don't get ripped off.

We went through an article from ARS Technica about how he did get ripped off for gifts this season. We also talked a little bit about mobile endpoint security, some of the problems that frankly we've had with our mobile devices. How Jeff Bezos in fact got a massive problem. I got involved with his divorce and everything else because of his mobile device and denial of service attacks. What that is all about?

We're going to talk this hour a bit about our remote. Workforce the tax implications. We've got another arrest and jail time. So we're going to talk about bad facial recognition and what's going on there. Cyber resilience. And what can we do this year? I really want to get into these hacked home cameras used to live stream police, weight raids in what are called swatting attacks.

And then. Solar winds mine. I was just because me, cause there are so many ways this massive hack could have been avoided. Our federal agencies have been compromised. Microsoft now says that due to this SolarWinds, hack somebody God into Microsoft source code. Those are the key to the kingdom.

And one of the ways Microsoft realizes to stay secure is by keeping it source code secret. And of course we, no, that's work. Microsoft has never had any vulnerabilities. So we'll get into that a lot to talk about this hour. First off, let's talk about this problem with taxes. Many of us have problems, if you work in Maine and you work in Massachusetts, you could have a little bit of a tax problem, but there is a reciprocal agreement that's in place.

So if you had been working in mass and you live in Maine, Okay. I can see that you're driving down to mass every day and you're living in Maine. So the reciprocity agreement covers that. But how about if you have never stepped foot in Massachusetts? How about if you started working for a company out of New York or a company out of California?

Did you realize that many of these, all of them, by the way, Democrat administrations are now going to require you to pay state taxes, Connecticut, you name it. All of these, it is very concerning to me. And when we get right down to workforces and the fact that this whole lockdown has really accelerated this trend of working from home.

And because of that, we've got employers who are letting their workers perform their jobs remotely from home most, if not all of the time. So where does illegal nexus tie in? So they're saying, Hey, listen, your employer. And you both knew exactly where you live and work, but the state departments of taxation can have some very different ideas about where here is.

So as a result, Texas, Utah, Arkansas workers who are working for New York or Massachusetts based companies will have income taxes with health in the paychecks, even if they've never set foot in the home office. Or never set foot in this state. How about that one? The thing for New Hampshire if you live in Maine, of course.

Yeah. A lot of these states that have state income taxes, will go ahead and say, okay you don't have to worry about paying our state income tax as well. Or in some cases, they look at it and say, Oh, you pay less state income tax. Then we charge our residents. I don't want to call them citizens because we are not being treated like true citizens anymore, but you pay less in your home state than our residents pay.

So you don't have to make up the difference as well. So we've gotten dozens of major companies out there all the way through little guys who have been increasing their support from working from home permanently. And I think that's great. We have businesses closing offices. Thank goodness. I don't own business space.

We've lent our leases laps counting on physical distance, flexible workforce was going to reduce real estate needs. I know one of my daughters is in that boat right now. And in many ways it can be a win-win employer can save overhead costs on those expensive square footage and high demand cities look at what's happened right now in San Francisco.

For instance, they are a great example of San Francisco. The city has lost 43% of its tax revenue. So you look at it until K while they've lost a lot of tax revenue because of the lockdown and people aren't going out shopping. They're not buying stuff. No. According to the San Francisco economist and yes, indeed the city of San Francisco has its own economists.

Know that a 43% drop in revenue is due to people moving out of the city. New York, San Francisco, Los Angeles, all expensive, and people are moving to Maine, to Montana, dial in from the woods or get a nice little place down in Florida for instance. But as far as the state's concerned, your beachside can banner might.

Just as well be right in the middle of downtown Manhattan and you're going to be taxed as such. So we've had these problems for a long time, but living in one state, working in another, but typically it's been adjacent States, just like again, Maine and Massachusetts, right? DC, Maryland, Virginia, maybe Pennsylvania, West Virginia, Delaware.

Kansas City itself goes across two States. You've got Kansas City, Kansas, and Kansas City, Missouri. So traveling across city limits can mean crossing state lines as well. So any major city near a border has lots of workers that go over the lines back and forth every day. And that's always been tricky from a tax perspective.

Because both the state where you work and the state where you live is going to want to try and tax your income, but still typically only one state at a time has been able to tax you for your income. And most jurisdictions with a lot of overlaps have agreements, as I said, main and mass and New Hampshire doesn't really have that agreement because they don't have any state income tax or of course sales tax on almost anything.

But. This is really going to be a problem, frankly. So keep in mind that if you are working for a company that is headquartered or even just has a presence in Arkansas, Connecticut, Delaware, Massachusetts, Nebraska, New York, and Pennsylvania. All of those States have convenient rules on the books that require any work performed for an employer-based in their state.

That it be taxed as if the worker performing the job is actually. In the state, no matter where the employee is actually located now, New Hampshire is one of the nine states that does not have an income tax. And it's right now in the process of suing Massachusetts over its convenience rules and for other States, by the way, New Jersey, Connecticut, Hawaii, and Iowa are supporting the suit.

So we'll see what happens there in federal courts. As you probably already know going to court doesn't mean the right thing is going to happen. It's gotten really bad, but at any rate, something to be careful about, if you are working remotely for a company, many of these States are going to become an after you for tax dollars.

We got a couple of things to get in. I want to talk right now about facial recognition. We what a year, maybe more ago talked about this company called clear view AI Clearview. And what they've been doing has been questionable. They've gone online and done searches. They've combed through social media.

And they've found and downloaded every picture. They can get the grubby little paws on, and then what they've done is they've put together some facial recognition software. So they've violated laws. They've violated platform rules. It's almost like Facebook when it got started, where apparently Zuckerberg went ahead and stole.

All of the records of all of the kids that were there, going to school at Harvard and including their photographs and put together this little Facebook thing, the Facebook, and had people rating other people by their looks, et cetera, and just basically stole. To get his business started Facebook. That's the allegation that's been out there.

There'd been a whole movie by this, about what he did. So that's what Clearview did too. They went ahead and decided we'll just steal all of the photos we can of people. They tied facial recognition software into it, and they perform scans of these images that were scraped from the internet and created a biometric database of the images.

We're going to talk about that and how we now have people being wrong, not just accused, but arrested, spent jail time. It's a crazy world out there.

The allegations are that Clearview stole your picture without your consent and without the consent of the websites you put them on. Now they are being used in this biometric database by the police and others with wrongful arrests.

Hey, if you want to hear the whole show or an older show, you can find them, just go online to Craig peterson.com. You'll see the podcasts there. I podcast the whole radio show, as well as my appearances on radio and television right there. So you can listen to them as podcasts there or on your favorite podcast app. There you go.

So we were talking about Clearview using these images that were scraped from the internet illegally. In some cases against obvious usage agreement, as well.

Now is that they've got this biometric database of the images and they can use that database to match an image of one person to one of these preexisting images that has been analyzed and scanned and maybe stolen, right? Depending on how you want to look at it, the allegations are all the way across the board.

Now neither you nor anybody else whose image was scraped from the internet, even know that it happened. Let alone give Clearview permission to use your image, right? They didn't get permission to take it, and they're not going to get permission to use it.

So the details of these practices are not well-received by anybody out there. Even the New York Times came out about it last January, which is when I really started talking about it as well. Within three days of the New York times talking about what this Clearview company did, there was a federal class-action suit that was filed.

And the complaint opened with a quote from justice Brandice that the greatest, dangerous to Liberty lurk in insidious encroachment by men of zeal well-meaning, but without understanding. So it's very interesting. There's a whole bunch of cases. I'm looking at the list of them right now. These will take a while before everything is finalized on them, but here's something we absolutely.

Do know for a fact. And that is that there have been arrests that have been made due to this database. Anyone who identifies as a policeman can go ahead and download the app onto their iPhone or another device. And can then just take a picture of someone casually on the street. There are people who are making police cameras that are constantly streaming video.

And on the backend are trying to do facial recognition. I've had a couple of them on my radio show a few years back, and it's cool because it gives the policemen an idea of, is this a bad guy or not? There is this somebody who we should trust somebody we could trust. I'm not really that worried about it.

Just. Think about the most dangerous thing most pleased officers do, which is a traffic stop. They have no idea who's in the car. If that person's going to try and attack them, et cetera. So having a live stream, thinking about Robocop, which didn't end that well, and what was happening there with the ed two Oh nines as well as Robocop himself, being able to see a person and be able to tell right away what this person's background is if there's any wants or warrants, et cetera, out there.

That's all well and good to a certain degree, but we just had another man. This is a New Jersey man who was accused of shoplifting and trying to hit a police officer with a car. He was wrongfully arrested based on facial recognition. Now, in this case, it's a black man and these facial recognition software programs that are available.

Tend to do poorly with any minority, frankly. And or do terribly with some and do poorly with any of them and also do rather poorly with the good old, regular Caucasian in phases like mine. Okay. So this is a third person who's arrested for a crime. He did not commit. He spent 10 days in jail and paid around $5,000 to defend himself.

So this is a guy that had nothing to do with it. The police got lazy, they said, Oh, we got a facial recognition match. It's this guy because they ran it through some software that had scraped some photos from the internet. Do you see where I'm going with this? And those photos from the internet say it's probably this guy, Nigeria parks.

And we know his social media is saying it's Nigeria parks. This is where he lives. This is where he posts most of his pictures because you remember our pictures. When we take them, our smartphones have embedded GPS information. Oh, my gosh. And in this particular case, he was apparently 30 miles away from the scene of the crime.

Okay. Pretty sad. Pretty sad. They dismissed the case because of a lack of evidence. Isn't that wonderful? But the department is now getting sued along with the prosecutor in the city of Woodbridge for false arrest, false imprisonment, and violation of his civil rights. I think he should absolutely win on that.

  1. And this is an article that came from the New York Times. They're saying a national study of over a hundred facial recognition algorithms found that they didn't work as well on black and Asian. Faces, as I said a little bit earlier see an ACL or attorney named Wessler believes that police should stop using facial recognition technology.

I am okay with it to a degree. I don't think you should be issuing any sort of an arrest warrant based on facial recognition. I think you might get a clue from that and. From that clue, you can look at the phases and decide for yourself and interview the suspect, do some good old fashioned police work, but this facial recognition arresting people, putting them in jail and then costing them thousands of dollars plus their time and their reputation and what it does to your nerves and everything else is just absolutely insane.

And bad arrests. So this article in the New York times goes through what happened. Apparently, the officers had been presented with a fraudulent driver's license, one of the officer's report,s or did that. They saw a big bag of suspected marijuana in the man's prof pocket. They tried to handcuff him and that's when he ran, he had a rental car just goes on and on, but.

It was a problem. And even though Mr. Parks had been arrested twice and incarcerated for selling drugs release back in 2016, doesn't mean that he's the guy that did all of this. So let's be careful. I'm not fond of what Clearview has done, obviously, just based on how I described it and who I quoted. And I don't like the idea of using this facial recognition technology to arrest people.

Bottom line. So speaking about arresting people, when we get back, we're going to talk about what is called swatting attacks. I don't know if you've heard of these before. They're pretty common, unfortunately, and some of the technology that we've been bringing into our homes to keep us safer is now being used to put our lives in danger if you can believe that.

Yeah, absolutely true. We'll be talking about that.

You can also follow me online. Just go to Craig peterson.com. You can subscribe to my newsletter. I'm not an active poster in Facebook or anywhere else, so the newsletter is the best place to get my weekly show summaries.

We're going to talk about how some of our technology we're bringing into our homes to keep us safe is actually ending up in killing people. Yeah. Yeah. Death by a police officer. Here we go.

If you want to see my show notes, all you have to do is subscribe. Craig peterson.com. And once you're there, you'll see all of the information. That I have available my podcasts and a little articles that we've written, and you'll also have the opportunity to subscribe to my newsletter. So I'll keep you up to date with the latest, most important articles of the week. I don't send all of my show notes anymore.

I found that a lot of people. Just don't open them cause it's overwhelming. So I've been lately trying to focus on one tip in particular. So we'll see how this all goes in the future and you can always let me know what you think. Just email me ME@craigpetersohn.com. I'd love to know, do prefer to get all of my show notes every week or do you prefer what I've been doing lately, which is a deeper dive into one topic. That seems to be pretty popular, but I'm getting about a 40% interaction rate, which is really good on such a large list.

I just want to get the message out is my bottom line.

We have these home cameras that we have welcomed into our homes. And one of the ones that has been getting a lot of heat lately is the ring camera. I don't know if you've seen these things. They've been advertised on television and it's basically like a little doorbell. You put it out there by your front door, side door, whatever, and it has a doorbell button.

And it also has a camera and a speaker that's built into it. Then the microphone, obviously. So someone comes to the door or rings to the doorbell. There's an app that you can have on your phone. So you could be at the beach. You could be at the DMV. Someone comes to your home and hits that button. You can now converse with them and tell them to leave the package or go away or whatever it is you want to do.

There have been some problems. One of them that has been rather controversial is that there are a number of police departments that are part of a program with Ring that gives them a live real-time access to all of the ring doorbells in neighborhoods. And the idea there is the police can patrol the neighborhoods without having to spend money on cameras that might be up on telephone poles, et cetera.

And they get their feeds alive from people's doorbell cams, these ring doorbell cams. So that could be considered good. It could be considered bad, just like about almost anything. Now we're seeing that they have been hacked. Yes, indeed. There is a hack that's out there that has been used and hijackers have been live streaming people's Ring, doorbell cameras.

Now where this gets really dangerous and where it hasn't been really dangerous is something called swatting. You probably know about SWAT teams, the police have, and unfortunately, most federal agencies have their own SWAT teams, which just constantly blows my mind because of why. Does this little department or that little department need of full SWAT team, it should really be a police department of some sort, but at any rate the whole idea behind a SWAT team is they have special weapons and tactics that they can use in a situation where there might be a hostage or maybe there's a report of a bomb or something else that they have to take care of.

And thank God these teams exist in, they do drills. They'll do drills in schools. I know my police department does that fairly frequently and I was involved with some of those when I was a volunteer on the ambulance squad here in town. All make sense, but what has happened in a number of occasions and far more than we like to talk about is that there are.

The bad guys or people who don't like their neighbor and call in hoaxes. Okay. Yeah. Yeah, exactly. So there here's an example in Wichita, Kansas, this happened a couple of years back where a man had been arrested after allegedly swatting prank led police to shoot dead 28 year old man. So this guy, 28 years old, Wichita, Kansas, please surrounded his home.

After they received a hoax emergency call from a man claiming to have shot dead his father and taken his family hostage. And this call apparently stemmed from a kind of a battle between two online gamers playing call of duty online. The way these games work is you can talk back and forth. You can have.

Teams and you or your team members can be from almost anywhere around the world. And you sitting there with headphones on and talking back and forth. You've got these teams and in some cases, this is just one person against another. And apparently they believe the report was an act of swatting where.

Somebody makes a false report to a police department that causes the police to respond with a SWAT team. Now the audio of this emergency calls been made public, a man can be heard telling the authorities. This is according to the BBC that he had shot his father in the head and claimed to have taken his mother and siblings hostage.

The color also said he had a handgun at had poured fuel over the house and wanted to set the property on fire. Sounds like the perfect thing for. A SWAT team to come to. Please say they surrounded the address. They called her given and we're preparing to make contact with the suspect reportedly inside.

When Mr. Finch came to the door, they said one round was released by the officers after the 28 year old failed to comply with verbal orders to keep his hands up. Why would he, what did he done wrong? Obviously. The police ordered you to put your hands up. You probably should put your hands up.

And they said he appeared to move his hands towards his waist multiple times when she probably did. Please say Mr. Finch was late found to be unarmed and was pronounced dead at a local hospital. A search found four of his family members inside. None of them dead. Injured North taken hostage. His family told local media, he was not involved in online.

Gaming. Gaming is a little different than the call of duty and stuff. Gaming typically is gambling. Now we're finding that the, that hackers are out there who do this swatting maneuver on somebody. And then they have the hacked ring camera at that house and they watch the SWAT team respond. Can you believe that?

And the FBI is saying that this is the latest twist on the swatting prank, some prank, right? Because victims had reused passwords from other services when setting up their smart devices. How many times do I have to warn about this? My buddy, I was just telling you guys about a couple of weeks ago, he's done that his.

His revenue, his pay from the work he was doing, delivering food to people's homes was stolen by a hacker because he was using the same email address. Yes. To log in and the same password as had been stolen before. Absolutely incredible. There's also been reports of security flaws in some products, including the smart doorbells have allowed hackers to steal pet network passwords, et cetera.

In one case in Virginia. Police reported hearing the hacker shout helped me after arriving at the home of a person they had fought might be about to kill himself. That's swatting that using technology you've brought into your home, it causes death, many examples of that, and we're still reusing passwords. Give me a break.

We were busy trying to defend the election this year and had the, what did they call it? The most secure election in history, which baffles me.

But anyway our businesses and government got broken thats what we're going to talk about right now.

Let's get into our big problem here this week. And this has been continuing for what now about two or three weeks we've known about it? This is a hack of a company called SolarWinds. This hack apparently allowed intruders into our networks for maybe a year and a half. But certainly since March of 2019, this is. A huge deal. We're going to explain a little bit about that here.

Who got hacked? What does it mean to you there? And I'm going to get into it just a little bit of something simple. It could be, haven't been done, right? That I have been advising you guys to do for a long time. Does this, like earlier I mentioned, Hey, change your passwords, use different passwords.

And in fact, That's a big problem still, but we'll talk about this right now. SolarWindss is a company that makes tools to manage networks of computers and the network devices themselves. And my company mainstream was a client of SolarWindss. Sorry. I want to put that on the table. However, about a year and a half to two years ago, it's probably been about two years.

We dropped SolarWindss as a vendor, and the reason we dropped them and we made it very clear to them was we had found security. Vulnerabilities in their architecture, the way they were doing things. We reported these security vulnerabilities to SolarWindss a couple of years ago, and they wouldn't do anything about it.

So we said goodbye, and we dropped them as a vendor. Yeah, we were customer SolarWindss. We were using their stuff, but then we abandoned them when they wouldn't follow what we considered to be basic security guidelines. It turns out they weren't and we got it as a country. This has been called the Pearl Harbor of American information technology.

Because the data within these hack networks, which included things like user IDs, passwords, financial records, source code can presumed now to being the hand of Russian intelligence agent. This is from. The United States of America's main security guide general Paul NACA sewn. It's just incredible what he's admitting here.

He said SolarWindss, that company that the hackers used as a conduit for their attacks had a history of lackluster security for its products. What did I tell you, making it an easy target interviews with current and former employees suggest it was slow to make security a priority even as its software was adopted by federal agencies expert note that our experts noted that it took days after the Russian attack was discovered before SolarWindss websites stopped offering client the compromised programs.

Microsoft by the way said that it had not been breached and initially here, but now this week it discovered it had been breached and resellers of Microsoft software had been breached to, and we've got intelligence officials now very upset about Microsoft not detecting it. It's just absolutely incredible here.

This wasn't something like we had with Pearl Harbor, but this attack may prove to be even more damaging to our national security and our business prosperity. This is really fast. I love the fact. I'm not going to say I told you because I, I didn't tell you guys this, but I do love the fact that I was right again.

How unfortunately I'm right too often when it comes to security and it is very frustrating to me to work with some clients that just don't seem to care about security. And I want to jump to an opinion piece here from our friends over at CNN. This is an opinion piece by Bruce.

Schneider. You've probably seen him before. He is also, I think he writes for the Washington post. But remember when this came out the word about the SolarWindss hack, president Joe Biden said we're going to retaliate which I don't know that makes a whole lot of sense in this particular case for a number of reasons.

Not the least of which we're not a hundred percent sure it's the Russians, but how are we going to retaliate? Cyber espionage is frankly business as usual for every country, not just the North Korea, Iran, Russia, China, and Vietnam. It's business as usual by us as well. And that it States is very aggressive offensively.

In other words, going out after other countries in the cyber security realm. And we benefit from the lack of norms that are in cybersecurity, but here's what I really liked. The Bruce said. And I agree with entirely. I'm glad he must listen to the show. The fundamental problem is one of economic incentives.

The market rewards, quick development of products. It rewards new features. It rewards spine on customers, end users collecting and selling individual data. Think of Facebook when we're saying this, our Instagram or any of these services that we're using all the time. So back to the quote here, the market does not reward security, safety, or transparency.

It doesn't reward reliability past a bare minimum, and it does not reward resilient at all. And this is what happened with SolarWinds. SolarWindss ended up contracting software development to Eastern Europe where Russia has a lot more influence and Russia could easily subvert programmers over there.

It's cheaper for Russia, not just for SolarWinds short-term profit. That's what they were after here was totally prioritized over product security, and yet their product is used to help secure. It just drives me crazy out there. Just absolutely crazy what some people are doing. I read a little quote down.

I'm looking here to see if I've got it handy on my desk and I just don't see it. But they are prioritizing everything except. Security. And that is, I think, frankly, completely in excusable, right. Inexcusable. So this is happening with SolarWindss right now, but it's going to be happening with other places out there.

We have probably 250 federal government agencies that were nailed by this. Can you imagine that? The man who owned SolarWindss is a Puerto Rican born billionaire named Orlando Bravo. His business model is to buy niche software companies, combine them with competitors, offshore work, cut any cost he can and raise prices.

The same swapping corrupt practices that allowed this massive cybersecurity hack made Bravo a billionaire. Another quote here. This is from tech beacon. Hey, this is just crazy. Okay. So we know. Okay. I've established it. Craig, stop the stop. The monotonous. Okay. But I got to mention, we've got the U S treasury department was hacked the U S department of Commerce's national telecommunication infrastructure administration, department of health, national institutes of health, cyber security, and infrastructure.

Agency. SISA the department of Homeland security, the U S department of state, the department of justice, the national nuclear security administration, the U S department of energy, three U S state governments, the city of Austin, many hundreds more including Microsoft, Cisco, Intel, VMware, and others. I use two of those.

We use Cisco and VMware. We use Intel, but only peripherally and we actually prefer other processors. So this is a real problem. How are we going to change it? I don't know that we can, you and I, but I can tell you what you can do. Just like I keep reminding everybody use a password manager and I will have a course on that this year.

Absolutely guaranteed using a password manager, use a password manager and generate different passwords for every website using the password manager, use the manager to log in. Okay. So that's step number one. That's the best thing you can do right now for your cybersecurity next to keeping all of your soccer up to date.

The second thing that we can do. Is block this malware from getting out of your network. If you are a business, and if you consider yourself an it security person, you need to block all outbound connections. All of them. Only allow connections where they are absolutely mandatory. For instance, your accounting department may need access to some form of cloud services out there.

Heaven forbid. Okay. Maybe you're using an Oracle product, et cetera. Only those people that need access to that cloud service should have access to the cloud service. Does that make sense? Email? You should bring it in through a single server. So you only have 1.4 email coming in and going out SMTP Imam.

They should be controlled and controlled pretty tightly. According to the department of justice, apparently their email accounts were compromised about 4,000 dish. People's accounts were compromised through this hack. So from a professional standpoint, there's a lot of things you could do, but it costs money.

It takes time. How about the rest of us? What can we do to protect ourselves? Use open DNS or Cisco's umbrella service. Umbrella, we sell the professional version that's used by businesses. That's what you need because it allows you to tune it to the people and what they need access to? Umbrella and open DNS will stop most malware from getting out. Most of it, not everything. That is huge defense.

Hey, if you want more information, if you want to go to my initial here, Microsoft security course, that's coming up in a couple of weeks. Just email me@craigpeterson.com and let me know, be glad to send you stuff.

ME@Craig peterson.com.

Take care guys.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito who is back from his convalescence. We got into a discussion about AI and how it is not as trustworthy as people might think.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. I was on with the now recovered. Mr. Polito. Yes, indeed. He was in the hospital, this whole COVID thing. Oh, nasty. We got into some depth here on facial recognition. It is gotten pretty bad here when governments using it and misusing it. There are people in jail that just shouldn't be there. It's just not so nice.

We talked about that and a little bit about the weather in Canada. So here we go with Mr. Polito.

Jim Polito: [00:00:35] You know what? Let's put it all aside. Let's not even play his intro cause he requires no introduction.

I'm talking about our tech talk guru and great friend Craig Peterson. Good morning. Sir

Craig Peterson: [00:00:50] Hey, good morning, Jim.

Jim Polito: [00:00:52] You got to get to facial recognition, but I got to tell you something that Tommy B mentioned. Of course, you being a Canadian, you understand the jet stream and how the jet stream dips from Canada in the winter. That brings us the cool weather. He said first of all, that the jet stream is flat across the country, with no troughs.

He said Canada is warmer than usual right now. Could you define what warmer than usual and what it means for Canada to be warmer than usual in January?

Craig Peterson: [00:01:26] I imported an article on Montreal and which is not that far North and the different sounds snow makes in the winter. It was saying, when it hits 30 below, you get a crunch. Eskimos, I don't know if you know it, but they have what is it like 10 or 12 words for snow, depending on what kind of snow. It is

Definitions it's different. There's an injun word called a Chinook. And if you are out in Alberta, which is in Western Canada, a chinook is where you get a bubble of warm air. I can remember going to school as a kid being all bundled up because it was, whatever degrees below zero.

And that. Back in the Fahrenheit days. And then as she would come in and you could see the temperature go up 50 degrees in the matter of less than an hour, but cold weather, warm weather in Canada depending on where you are. Yeah, it's not warm.

Jim Polito: [00:02:33] It's all relative. Tommy B has talked about the phenomenon of the Chinook and just how weird that is.

It's almost like. A bubble of oil floating through the water or vinegar. It's the weirdest thing. Yeah, he has, he has described it, right? Yeah. Tommy said that you actually see it coming and wow. Pretty cool. All right. Let's get to look. We know that. Facial recognition. Technology has been an issue with race in that individuals say it miss identifies people of color.

Now we've been told, let's start with the Las Vegas casinos, which were really the early adopters of this, other than the government that Hey, no facial recognition technology works. It makes certain measurements. That's why knows who you are. You can put a beard on and glasses. It's still going to know who you are, but you're saying that in criminal cases and this just isn't just race or minorities. This is everybody that facial recognition technologies had issues.

Craig Peterson: [00:03:49]I think we're falling into a trap here, unfortunately, and it's a very common one. People seem to think that computers somehow are better and less error-prone than people.

The bottom line is that computers are at least no better than the programmer. That becomes a real problem here because it's people, you watch even a shy guy movie, and the computers say that and such, and therefore it must be the way to go. It's almost like watching Fauci, right?

He might be correct when it comes specifically to one extremely narrow area, which is a problem with almost every Ph.D. I've ever known in my life, is just too narrow. But when you start to consider other factors you're wrong. What's happened now is the police department is believing the results that are coming back from these facial recognition systems.

We know that they were used for instance, out West in the peaceful demonstrations that happened out in Portland, in Seattle, when they were burning when they were demonstrating against this terrific president

Jim Polito: [00:05:06] the peaceful demonstration. I love the guy Baghdad, Bob the CNN reporter in front of the fire.

Craig Peterson: [00:05:12] This is mostly peaceful. So they were using it to try and track people. But we've got a real problem here. It really was exposed the last year with this company called Clearview. Do you remember these guys?

Jim Polito: [00:05:26] Yeah.

Craig Peterson: [00:05:27] What happened there is. They were scraping the internet. They were going onto the internet. They were finding people, posting pictures of themselves, their friends or families on Facebook, et cetera. They were pulling all of this into a database and then they have the computer do some analysis on it. Folks, AI-artificial intelligence is not intelligence.

Machine learning is not learning like the way we learn and the results that come out of these systems just can not be trusted. The really bad thing about this is they're using the results. And so they'll take a picture that they got off of the ATM or some other monitor and they'll take that picture, they'll plug it into the Clearview or some of these other systems. It says it's Joe blow and they believe it. And they go and arrest Joe blow.

There are cases now where they've thrown Joe blow in prison or jail, I should say. Then they try and prosecute him and he's trying to defend himself. It turns out that in some of these cases, nobody even looked at the pictures, they just trusted the computer.

Jim Polito: [00:06:37] We're talking with our good friend, Craig Peterson, tech talk guru. Craig, you know what this kind of worries me about, but I do think it's because there has been too much trust in the system. But there are systems now that try to duplicate the work of a, so we all know, you get an x-ray like, believe me, I was just sick. I had plenty of chest x-rays okay. A radiologist reads that x-ray goes through it and yeah, this is okay. Here's what I see. There are just like facial recognition. There are these systems to try to duplicate the work of a radiologist and they haven't been successful. They can be used as a backup. They can be used as a check, but you still need a human being, a man or a woman in front of that image, looking at it.

There are certain things that the computers, when you do 3d technology and there certain things with a mammogram that sometimes a computer is very effective at finding a certain pattern of blood vessels and whatever.

But I don't know the eyes of a real person to me make the difference.

I'll put like money into a bill counter. Trust that, but that's about it.

Craig Peterson: [00:07:58] Yeah, that's it. Yeah. And AI has been used a lot in medicine lately. Some of this computer stuff doesn't make sense. You mentioned one example, counting money, right?

Another example that seems to be pretty good is finding cancerous skin cells. So it's basically just taking a picture of your arm. You can get an app for that by the way, and it'll check it out. Some are other types of diagnosis, certain types of cancer in different parts of the body can be detected fairly well by computer.

And again Fauci narrow areas they are actually better than the human is. But right now, I don't know. It's in the far 90% of the time, a person's going to do a better job.

Will that flip, he says. The type of AI's that we're looking at for the next 10, 20 years, they are going to get better in certain, very narrow ways. We're not going to be able to see a true tricorder that gives a full diagnosis for many, I think decades.

Jim Polito: [00:09:09] Well, hold on a second. You dropped a star Trek reference thinking that I would not pick up that Dr. McCoy and his tricorder that I would not pick that up. I know you did that. Just to test me. You drop that in there.

Yes. He had the little thing he opened up and then he had the little thing he would hold over you. And it basically diagnosed everything.

Craig Peterson: [00:09:35] Yeah. That's the one I remember too. Dr. McCoy said that he wasn't a bricklayer. He, all he understood was this one narrow part of medicine. And yet we are at pastor Fauci.

Jim Polito: [00:09:52] Yeah. Wait a minute.

Didn't he once operate on a Vulcan, remember that one, and the ship was under attack. And I, it was either Spock's father or something. He operated on a Vulcan. Jim his blood is green. Jim, I don't know what to do. On that note, this has been too hard. This is fascinating.

Obviously, folks, we have a great show from our tech talker, Craig Peterson on the weekends.

But Craig, how do folks find out more about all of your great work?

Craig Peterson: [00:10:23] Oh, and this year, things are much better. I am now publishing at least weekly, a little training you can take. It's absolutely free. In addition to getting my newsletter and finding out about the live little training I do and the bigger ones, just go to Craig Peterson, song.com.

All of the stuff you need to know. I post there right in the homepage, sign up to that email list. I am not going to harass you. Just Craig peterson.com.

Jim Polito: [00:10:52] I can assure you that he will not. And he does this segment with us out of the goodness of his heart. Craig, always a pleasure, and we will catch up with you next week.

Craig Peterson: [00:11:04] Bye-bye

thank you, Craig guy, Craig Peterson. Everybody. Yeah. Yeah. Go to Craig peterson.com. No, he doesn't try to sell you anything. Anyway, a final word when we return. You're listening to the Jim Pollito show. Your safe space.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online. I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Were into SolarWinds and our federal government network since 2019.

Good morning, everybody. Craig Peterson here. I was on with Mr. Chris Ryan. He's the new host of New Hampshire today, which is heard throughout the entire state and large parts actually of Maine and Vermont. We had a chance this morning to talk a little more about the SolarWinds hack.

We went at it a different angle. It's interesting with the different hosts, right? It's just like when I hold a live webinar, the different hosts have different questions, different opinions, and it drives me in a different direction. That's exactly what happened this morning.

We talked about why is it happening? Not why is Russia or China or any of these other countries attacking us? That's not the question, but why can they? Why aren't we doing enough? That's what we talked about. I think that of course, I think I was right there. It was really, it was a lot of fun. So stick around, you're going to find out a little bit more about why I say this hack happened and how it actually ties in with COVID. So here we go with Mr. Chris Ryan.

Chris Ryan: [00:01:19] Craig, how are you?

Craig Peterson: [00:01:21] Tis I. Doing well this morning.

Chris Ryan: [00:01:24] Good. Appreciate you joining us for the show. So I have a couple of topics I want to get to with you today. As we address the issue of cybersecurity, there was this huge story about Russia and what they're able to do in terms of infiltrating our government's websites and entities and so forth.

Then that story went away. To me, it is an incredibly significant story and one that's, I think that we need to be cognizant of. What were your big takeaways from that and the message that it sends in regards to our overall cybersecurity as entities and individuals?

Craig Peterson: [00:01:59] Yeah. Boy, this is really a big deal.

I think the reason a lot of people stopped covering it is that, frankly, it's a very scary thing and a little hard for most people to understand, so I'm glad you brought it up. But I'm looking at this as an absolute wake up call. How many of these we had, Chris? Three years ago, we had Equifax was, do you remember that? It was huge. Basically, everybody in North America's information was stolen.

We decided, okay, we got to lock things down a little bit. In this case, SolarWinds, these guys had made multiple huge mistakes. Now SolarWinds software, this Orion software that we're talking about is used by businesses and government agencies to basically command and control their own network computers internally. They are used for security. SolarWinds says it's probably 18,000 of our clients that ended up getting hacked.

Delving into this a little bit more because in the biz we have been paying attention, right? It looks like the Russians, whoever was, were into SolarWinds and our federal government networks since 2019.

Now, for far more than one year. Those 18,000 organizations that were affected by this hack, weren't just government agencies. They were what are called managed services providers. Chris, these are businesses that provide IT, outsourced information technology support for businesses all over the country, basically small businesses. So take that 18,000 and multiply it by a minimum of 100 and you start to get an idea of what the impact of this thing is.

The fact they were in our federal agencies just is absolutely incredible. I'm putting out a little video this week for anyone who's interested in seeing it, I'll send out a link to my email list and we've got a few thousand people on that. I'm going to explain the basics here.

How you as a tiny business could have protected yourself from this kind of a hack. For our federal agencies to not do the very, very basics here is absolutely astounding. It proves a point I've been saying for decades, which is bottom-line people in every industry just aren't paying attention to security at all. Incompetence runs rampant in every industry, including IT.

We have to pull up our socks. We have to tighten our firewalls, just the basic stuff.

To pull these tricks like GoDaddy pulled on their employees here about a week and a half ago is absolutely wrong.

What GoDaddy did. Once they said, okay we're going to make sure our employees don't open emails that might be phishing attacks that are really emails that are trying to attack us. GoDaddy sent out an internal email saying a $650 employee bonus. So if you want the $650 employee bonus click here and fill out this form.

They sent it to 500 employees. They did click. They did fill out that form. I can't imagine anything crueler than what they did.

Now the GoDaddy employees aren't going to be opening an email. Their businesses aren't going to be able to be conducted the way it always has been because they're afraid of opening the email.

There are much better ways to do this. Chris, my brain is exploding. I got to find the duct tape before my headaches.

Great. Craig Peterson, joining us here on, New Hampshire today.

Chris Ryan: [00:06:03] The final thing. You mentioned the deficiencies and we have heard about them. We have known about them in regards to our federal infrastructure. It has been discussed for years, but seemingly little has been done about it.

Senator Shaheen talked about Kaspersky. I believe is the name of it. Which is a Russian firm, which does some cybersecurity. She had concerns about that being used by government entities and private citizens and it has. What is the concern that you have in regards to this deficiency? If it's continually discussed, why is it not substantively addressed?

Craig Peterson: [00:06:38] She is absolutely right about Kaspersky. There've been a lot of concerns. They have been a leader in certain parts of cybersecurity,

But, there was an order that the Trump administration put out that it had to be removed from all of our federal networks. So she's absolutely right about that. We've got to pull our socks.

These orders again by the Trump administration to pull out some of this Chinese equipment that is embedded into some of our networks is absolutely right. Businesses are just playing fast and loose with this.

I've been trying to figure out the mentality behind that. What is it? Why are they not really paying attention?

I think the bottom line is even with federal contractors, because I'm not sure if you know it or not, but I've been running training for two years for the Federal Bureau of investigation, for FBI, I'm the guy that ran all of this InfraGard training. I worked with government agencies. I worked with NGOs, private organizations, and I think it's pretty simple from a business standpoint.

If I'm going to remove Kaspersky, some of this Chinese equipment. If I'm going to comply with the federal regulations that are already in place that come with a 10-year prison sentence. If I don't comply and I get hacked and come with tens of millions of dollars in fines. If I'm going to spend half a million dollars on that and my competitors are not going to spend a dime on it. How could I stay in business?

So until we've got, just like the inoculations, right? Where until everybody is basically immune or we have herd immunity, we're not going to get past this COVID infection. Much the same in cybersecurity until most businesses are doing it or building it into their business costs and can compete with other businesses because they're all on equal footing. This is just going to continue going on.

Chris Ryan: [00:08:40] I appreciate your time.

Craig Peterson: [00:08:42] Thanks

Craig Peterson with tech talk joining us here on - New Hampshire today. I am Chris Ryan, along with Justin McIsaac. Chuck Zada joins us up next from the financial exchange still to come, governor Sununu as well as Senator Hassan, Jacoby Meyers from the Patriots.

This is New Hampshire today on news radio six, 10, and 96 seven.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This week I am spending a bit of time discussing why you should not use VPNs and why Google removed an Android VPN from the PlayStore. Then some tech predictions for the coming year and Ransomware and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Google Removed Shady Android VPN App That Allowed MiTM Attacks

Don't use VPN services.

Kazakhstan spies on citizens’ HTTPS traffic; browser-makers fight back

Twitter repeals retweet roadblocks, Facebook follows suit

2021 Cybersecurity Predictions: The Intergalactic Battle Begins

Russia’s hacking frenzy is a reckoning

FBI says DoppelPaymer ransomware gang is harassing victims who refuse to pay

Intel falls on report Microsoft plans to design own chips for PCs and servers

Facebook Repays News Industry It Destroyed With Print Ads Begging You to Hate Apple

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] I mentioned on the air earlier this week, a friend of mine who got hacked, he's trying to make some money. He's retired doing a little grub hub type delivery service, and all of his money was going to a bad guy. So we're going to get into that.

Hi everybody. This of course is Craig Peterson. Oh, I hope you guys are having a great week weekend. Hopefully a few have the week off next week. And we'll get back to it after the first of the year.

The hacking frenzy is just not, I talked about it last weekend, where we've got now the bad guys, assuming it's the Russians.

There seems to be a lot of speculation that it really is. However, I want to explain why you never really know who does a hack. There are. Tools out there that are used by hackers. And most of these tools are just shared within their little community out on the dark web. And you can go right now if you know how to get onto the dark web and which site to go to you can go right now and grab almost any of those tools that the hackers are using to break into your computer, Mike and beater.

Everybody's computer out there. That is a problem. And it's a problem with trying to identify who's doing the hack because if you are using the tool that is usually used by China, for instance, there's a whole bunch of tools that are named after pandas because that's China. And it's just, the name is the name.

It's doesn't necessarily have a whole lot of significance. Okay. But the tools China uses the techniques they use are used potentially by other countries as well. So Russia could be using tools that are usually used by the North Koreans. And, so how do you know by the tool you don't and then on top of it, you have the problem.

Of people hopping around. You've seen that before. Remember war games, Matthew Broderick, man, when was at 80 sometimes sometime, and it was showing how it was hopping through different machines. And different modem banks in order to get where it wanted to go. And you've certainly seen that in bond movies and everything else where they're hopping from server to server.

And so they're trying to trace who is this? Where are they coming from? Because we're going to go catch them. And they'll show a little graphic up on the screen and it shows, okay. Boom. Okay. Argentina, and then it's Brazil. And then it went over to Moscow and then over to Beijing and then over to Montreal.

And then you can't do that, that, that technology does not exist. There's no way for you to know. Because if you don't have control or access to all of these servers that are all over the world, how can you know, you just can't and then to make matters, even worse, the bad guys have compromised, small business computers and home computers as well.

That really creates some problems because now what we're talking about is the bad guys getting on to your home computer and using that as a base of operations. We've had many times where someone's home computer was used to attack the Pentagon and it had nothing to do with that poor person whose computer was being used.

We've talked before on the show about how some of these terrorists have been taking over. Business servers, just regular web servers. Hey, it's my server. And I use it for whatever might be e-commerce nowadays. And didn't realize that Al-Qaeda was using my server to share a video of Americans being beheaded.

That has happened. So if China wanted to attack the US would they necessarily want the US to know it was China, might they want the US to think it's Russia? All of these bigger countries have that ability and now even smaller company countries. We're seeing Vietnam now. One of these nation-state hackers.

And we're seeing, of course, as you already know, North Korea and China and Russia have been hacking for a long time and it seriously looks like they interfered potentially even directly in our elections because this big hack, these solar winds hack that happened solar winds software that was used to penetrate.

All kinds of federal agencies, businesses, infrastructure, et cetera. Also penetrated the election systems in some States. It also penetrated the company that makes the election software for most of our elections here in the United States, it is really that bad. So we can't say for sure that this was Russia.

It might be, it might not be the full assessment of what even happened from that hack is still probably months or frankly years away. We know the department of Homeland security. Commerce treasury state, all founded their systems had been breached and they're saying it was Russian hackers and it may well be Russian hackers.

I don't have access to any of the hard data to be able to tell you for sure that's who it was, but. These hackers, Russia or whomever, it might be we're in our government systems for months, including some of our election systems. Now, is that a big deal or what now? We're thinking that this is Russia's cozy bear. And they are basically turning business software into a Trojan. And that's what the solar winds thing hack was all about. They had software that is used in networks to monitor and control networks, and it had been turned into a Trojan. Now a Trojan is like a Trojan horse. It's a piece of software that looks like it's something other than what it is.

That technique has been used for many years, but what did they do while they were in these networks? It's absolutely crazy to look at FireEye, which is the company that discovered this was using solar wind software. They discovered the hack on their own networks and the networks as some of them.

Clients as well, FireEye is a three and a half billion dollar security company. They are huge. And they said that they had been hacked by a nation-state, and it goes through what the software was. It's a Ryan, which is one of the SolarWinds products. We have used their products before we stopped using them because of some security problems that we had found in their software.

So we stopped using solar winds 18 months or so ago, and now it has come out that one of the people inside solar wind warned the company about the way they built the software and distributed it and that their software could be used for hacks, which is. In fact, it absolutely was, but this is really bad news because since March they've been in some of these systems, government, and otherwise they've been in our election systems.

I saw this study. I don't know if you've seen it. That was reported out of, I think it was Michigan, where they had been looking at what's happened with the voting systems. One of the systems was given to a security team who looked into it and found, yeah. There are some serious problems here. It was misattributing votes and it was rejecting.

What was it like 35% or more of the ballots that should not have been rejected and just open to everything up to total hacking? It's very bad. So are we at war with Russia? Because they have gotten into things like our water systems as part of this hack, our critical infrastructure, our government agencies.

What's going on? There is a system in place that the federal government's been using is called Einstein patrols. Yeah. Just that Einstein. And what it does is it looks on the networks to see if they're being hacked, but just our software that so many of us use that we should not be using anymore.

That is the antivirus. That's looking for signatures. Einstein only is effective at identifying known threats. So it's like a bouncer. If you go to a nightclub that has a list of people not to let in, and yet he, he lets him all of these people with knives and guns who are swearing. They're going to kill everyone inside because they're not on the list.

All right. So this is very inadequate. This Einstein system that the federal government's using in the face of these types of sophisticated hack attacks, and they use these hackers that solar winds or Orion backdoor to gain access to these networks, they wanted access to one of the things that we are trying to get really moving here for smaller businesses is.

Logging, because if you're not logging, what's going on, you don't know what the bad guys got access to. And you got to keep those logs. Those logs have to be searchable. And if your security company is doing their job, they should be keeping all of the logs from all of these machines for at least two weeks, if not months.

And you might want to ask them that. Because what happens, frankly, with these things is there's a lot of retrospective work that goes on. Just like with my buddy who got hacked, just trying to make a few bucks over at grub hub. We'll talk more about his specific case in a few minutes, but. I had to spend hours going through forensic information. I can get my hands on him to figure out exactly what happened and what do we need to do to mitigate this problem for him.

We're going to talk about that exactly. On one guy, trying to make some bucks gets hacked. What can you do to stop it?

So how did my buddy get fooled or what happened here? That his accounts got hacked. He was locked out and the money that he was trying to make from driving for GrubHub just disappeared. We're going to get right into that.

So let's get into this problem and it is a problem. It's a very big problem with hackers.

We've been talking a lot about the nation-state stuff that's been going on, and frankly, the way this latest hack. Hit us all frankly, is very hard to address. This is like the attacker beams themselves into the business's network. But what about my friend?

What happened to him? How did this all work? He has, and I understand this man. He has not been following all of my advice and I'm sure this is true for most people out there because much of this is confusing. And I'm thinking I should probably do a little bit of training on this one as well for you guys.

And if you're interested, I need to know. And the only way I'll know is if you email me ME@craigpeterson.com and let me know, you're interested in protecting your online account. I'd be glad to put something together, believe me, and we can have a little bit of free training available for you guys. So again, me@craigpeterson.com, but this was a wake-up moment for so many people.

In the case of my friend, here's what happened. He was expecting a payment from GrubHub and it could be anybody, it doesn't have to be GrubHub and it was going to go straight into his bank account. How does the configure where he's paid his password, his username, his email address? All of those are configured either in the app or on the website for GrubHub.

All well and good. Isn't it. It should be pretty easy to do. And in fact, it was, and that's exactly what he did now. Let's talk about the mistake he made. He got an email with a link in it to GrubHub, and he clicked on that. You are you getting what's going on here now? So he clicked on the link for supposedly GrubHub and it wasn't GrubHub. But that's all he had to do. Cause now what he did is he confirmed that people are in fact, or that he in fact had a grubHub interest or GrubHub account. Now sometimes what'll happen is you click on it. It'll take you to a website of a bank or GrubHub in this case, and it's not the real website.

It'll ask you to verify your username and your password, and you'll type it in. Between you and me, I think he probably did that, but he wouldn't admit to it. So what'll happen is that point is they now have your username and password. Cause you just typed it in and they'll will oftentimes say invalid password, please try again.

They'll just. Automatically redirect you to the real website, assuming that you gave them your proper username and password, but they can still get you in many cases, even if you don't give your username and password. Rule number one. Remember when you are on your email account and you're looking at the emails and somebody says Hey, you've got to click here in order to verify something, or someone's trying to break into your account.

So click here so that we can get, get things straightened out and taken care of and blah, blah, blah, rule number one, don't click on that. Rule number two is in. And if you do click on it, don't give any information about yourself, like your username and password, but by clicking on it, you gave a little bit of information.

So here's what happens. The bad guys send out these. These are like Nigerian scam emails. They have a list of over right now. I think it's about three or 4 billion email addresses. So they'll send out emails to this list of addresses and people will randomly respond, even though they know they should not be responding.

So they randomly respond to the email by clicking on it. Now they know that my buddy's email address is a valid email address and he was clicking through to do something like it. Might've said, Hey GrubHub, you got to verify your account information or your delivery route or something. Something that's compelling to people who deliver for GrubHub to click on.

And frankly, even if you don't deliver, if you have a GrubHub account and you have a credit card, a credit card tied into it it might be worthwhile for them to steal that credit card information. Okay. So you collect and that's all you did was you clicked on that email. What happens next is then our friends will have the bad guys we'll say, Oh, okay.

So that was email account xyz@hotmail.com and that's where his account email account was xyz@hotmail.com. Okay, great. Let's have a look online. So I took my body to a website that I recommended you guys use many times and it's called, have I been poned.com? So I want you right now, whether you're on your phone or in front of a computer, go to have I been poned.com and that's spelled like you'd expect it to be it's.

Have I been B E N P w N E d.com. Have I been polling.com and then type in your email address, I'm going to type in his right now. So this is the email address he was using. I'm not going to tell you exactly what it is. His email address don't embarrass him, but yeah. It says that he was postponed in eight data breaches and found no pastes.

So here's what that means. Data breaches are where his data was Nolan from a third party. In his case, I'm looking@thelistandyoucangetthislisttojustgotohaveibeenponed.com and it says for him, Adobe and October 23rd, Teen 153 million Adobe accounts were breached. Okay. Funny. And so the compromised data from Adobe in 2013 was email addresses, password, hands, passwords, and usernames.

Now they were, the passwords are encrypted, but it was done very poorly and easy to resolve back to plain text. Okay. So Adobe had his username and his password. And again, between you and me. He has not changed his password in at least 10 years. Okay. So that means they had his email address and his password from the theft from Adobe.

Oh. But there's more, they also got his email address and password along the way with the email addresses and passwords of 164 million other people from LinkedIn in May, 2016. Oh, and by the way, LinkedIn was hacked also in 2012. So data's out there. It's you can just buy it. Let's see. Aluminum PDF. I don't use that, but apparently he does.

It was hacked last year, 15 and a half million records of user data appeared for download. Included authentication tokens, which means they don't even have to log in. They can just hack it using a special web browser code, email addresses, genders names, passwords spoken languages and usernames river city media spam list 1.4 billion.

Records that was in January, 2017 and share this 2018 41 million sTraffic it's a Israeli Mark marketing company at a database, 140 gigabytes of personal data, all kinds of stuff. And it goes on and on. So we'll tell you why clicking on that email is bad when we get back and how they use that. Along with this data that's available out there on the dark web.

We were talking about our hack, a friend of mine whose account got hacked. His paycheck got stolen and he could not get anything back. So we're going through what happened, why and what I did about it.

Don't forget, you can also go online. Craig peterson.com. Subscribe to my newsletter, get all of my show notes and warnings and information about trainings, all of that stuff. Craig peterson.com.

We established that my friend had his information stolen multiple times within in fact, the last year online.

Now that's a bad thing, frankly, especially when they've got your email address and your passwords. So they sent an email to him and he admits that they did, and that email had a link in it to click on and he admits that he clicked on it. And as I mentioned before, just clicking on that email becomes a problem.

Because now all they have to do is they track who it is that collect. So they know it was xyz@hotmail.com because it's tracked. If you look at most links and emails, including the emails I send out, it actually doesn't take you to the ultimate destination. It takes you to another site that is tracking.

What you're doing is tracking the. Number of clicks and what people are interested in. And that makes sense for people like me, where I'm trying to find out what are you guys interested in so that I can help you out and give you more of that type of information? In the case of the bad guys, they now know that X, Y, z@hotmail.com clicked on this email about the drivers for grub hub.

All they have to do is look into one of these online databases of stolen identities and find the email address the email for in this case, right? X, Y, z@hotmail.com is that email in there. And the answer is going to be, yes, the email is in there and then they say, okay, X, Y, z@hotmail.com. What's the password and they've got the password right in there.

So now all they had to do is use his email address and his password over at grub hub. So now they're in there in his account or grub hub, and these people were smart enough to know. All they have to do now is go to the account information pages and change the deposit to account. And that's exactly what they did.

So they changed the deposit to account. So his payment for delivering all of these different things that GrubHub delivers from local restaurants, et cetera, that payment is now. In their bank account and they have what are known as money mules. I don't know if you saw that mule movie with Clinton sword.

It was absolutely fantastic. But these money mules are people in the us that fall for the scam of hay. We have a few accounts and we can't have a us bank account. So what we're going to do is we're going to wire you the money in, let's say PayPal, and then I want you to split it up and wired into these other accounts.

So now you are mule. You are money laundering for them. And a lot of people have fallen for that scam and the FBI and the secret service have arrested a lot of these ringleaders over this type of nastiness that they've been really perpetrating against all of us. So it's a bad thing. So what happens now is he goes to log in to his account.

It still works. They didn't change his password. Life was still good for him. And he's able to do his work still. However, he notices that his money didn't show up and GrubHub says, yeah, we deposited the money in your account. No problem. So he goes in, he looks at a double-check see, count, just being thorough.

And he finds, Whoa, wait a minute. This is not my account number. So now we start to get a little bit worried and that's when he calls me up and he comes over and we spend about four hours tracking this down and fixing it. What the bad guys ended up doing is he had changed his password. So now what can they do?

They're out of luck, right? No, they're not because remember they still have access to who is X, Y, z@hotmail.com. Email. All they do is go to grub hub and say, forgot password and grub hub dutifully sends a password reset to his Hotmail account who has access to his Hotmail account. They do. And so he then says, Oh my gosh, I can't get into my GrubHub account anymore.

So we go back and forth on this. Ultimately the bad guys. Turned on two factor authentication on his Hotmail account, which is Pinedale by Microsoft outlook.com nowadays. And with two factor authentication, you have to have an authentication app in order to. Change passwords, or even in sometimes now in his case, he was lucky because he was still logged in to outlook to his Hotmail account.

And we were able to use that to get around some problems. I'm not going to get into all of the gory little details of it, but we managed to reset everything. Thank goodness. So he's now getting his money from grub hub, but ultimately what I ended up having to do is set him up with a one password account.

Now I have done this for him before, and he has never used it because it is confusing. You gotta really pay attention when you're doing this stuff, because I had to do two or three times with some of these online services that he uses and his banks. But one password is what I recommend. He bought the family version, which is $5 a month.

There's a one week free trial. I don't get any money from this. One password doesn't pay me anything. Give me anything, nothing. They don't even acknowledge. I exist. All right. We do use it for some of our clients as well, and we do use it for some of our internal stuff too, but what happened is, I got one password set up. We set it up to use two factor authentication.

One password will act as an authenticator now. I like one password. It just spelled literally one, the digit one password.com. You'll find them online. With the two factor authentication, what happens is when you go to log in, you're going to give you a password.

And then it's going to ask you for six digit number and that six digit number changes every 30 seconds, which is really a good thing, frankly. We obviously changed his passwords. Now he was very concerned because he doesn't want to have to remember a different password for every website. That's what one password is there for.

And we use one password to generate fairly memorable passwords, at least easy enough to type in for all of his websites who went through them. One by one, we changed the passwords. On those website, we using one password, had one password. Remember them, those websites that could use nothing indicator for verification, we set up the two factor authentication and now he's cruising along.

Everything is reset. He has good passwords, different ones on each one of his accounts. And he only has to remember one password, which is that. The password, which is really a passphrase that he uses to get into one password. It makes life much, much easier. And an automatic automatically synchronizes between his iPhone and his desktop computer.

It also runs on Android and windows and stuff too. So it's very good software. Check it out. If he had done this a few months ago. He would be in pretty good shape as it turns out he didn't, but thank goodness we were able to recover. And by the way, if he didn't have the two factor authentication, because remember the bad guys set it up, he'd have to wait 30 days.

Another warning and a deletion from the Google play store this week for a VPN service. We're going to tell you about that as well as explain why you should not be using VPN services in most, but not all cases.

Craig, Peterson here. You can visit me online@craigpeterson.com. Hey, thanks for joining me today.

VPNs, I think are one of the least understood technologies that many of us use almost every day. VPNs are used for us to connect to the office. Many people use VPNs to try and keep their information private. It's not as though there's anything to hide in most of these cases, it's just that it's nobody else's business.

It's not something that people want to share. So they do use VPN. So how do they work? How do they not work? What are the issues involved? That's a little bit about what we're going to cover right now, but let's start with Google. There's a VPN called super VPN free. Now this is a VPN client and the way VPNs work is you have a server, which you can think of as the end point, and you have your client.

So the client resides on your computer or your mobile device, and it connects to the server. If you're a business and you are trying to use a VPN in order to allow your no, usually not customers, but suppliers or employees to connect into the office. I hope that you're using a model called a zero trust model because what it is really is an Excel.

to your network. So you're extending that employee's home network or that provider's network office network, you're extending it into yours and you're joining them together, which is obviously a very scary thing to do and can be a very bad thing to do and allow. Some of the malicious software to spread onto the networks.

Okay. So we've talked about that a lot over time. In this case, the super VPN free VPN client. Has something that is called man in the middle. Now, the way this works is just think of broken telephone. If you've ever tried to play that before we used to do it with a cans, tin cans and strings. Between the cans.

And so you'd have three people and one person would talk into the can and the person in the middle would hear the message and then would relay it through another can to another buddy who's down that piece of string. And that allowed us to go greater distances. It wasn't, it was a lot of fun. And then of course the old broken telephone game.

That we used to play the, you might have 10 or 20 people and you try and pass a message from one person to the next and not mess it up. Now, some people of course would mess it up on purpose, but you really can have some fun with those games. In this case, the man in the middle was the VPN server.

Cause you remember the data's going from your device over an encrypted, hopefully secure connection over the internet. And then it arrives at the VPN server and what this server was doing. And unfortunately, what far too many VPN servers was we're still doing is known as a man in the middle attack. Yeah, the data is going from your device to their server.

It is encrypted and hopefully using good encryption. And then the next stage is it's decrypted at their server. So you're trying to go to the bank, you're entering account information. And, but that VPN server in the middle of this whole conversation is monitoring everything you're doing. So it gets onto their server.

They can see your usernames, they can see your passwords, they can see your account numbers, and then it opens a connection from their server to your bank. Yeah. Dangerous. So if you had. This shady VPN app from the Google play store called super VPN free. You might want to remove it, but this is a more generic problem than just one single VPN app.

This problem is in fact very common. So I want to run through some other reasons why you probably don't want to use VPN services. Remember number one. There might be a man in the middle attack going on and we've even got countries doing that. Now China does that, so they can monitor everything. Even when it's encrypted, we've got cows Exton right now, spying on citizens, HTTPS encrypted traffic.

And it's a, it's a bad thing. Bottom line VPNs that we're normally using. Now, this does not mean a VPN. That's a private network. That's used internally inside of businesses, but the types of VPNs that consumers are buying, and unfortunately, far too many businesses are buying unknowingly.

Number one logging, many of these VPN say that the services, Hey, we don't log, which somehow is supposed to make you feel better about it. Some of them say we only logged for 30 minutes. Remember that it's rare for the VPN servers themselves to be in a data center. That's owned by that VPN provider.

So we have other servers on that same network and that provider that's giving or leasing or renting of that VPN server. Space in that data center is going to be logging all that. So remember, it's in the VPN providers best interest to log their users. It lets them deflect blame to the country. If the customer's doing something that's illegal, if they get a DMCA, take down notice, et cetera, et cetera.

So if the VPN provider is logging, now, they. If they got into legal trouble would have a little bit of a leg stand on. Even if you're paying $10 a month for the vPN service, it doesn't even pay for their expenses. Most of these VPNs are making money off of you. Okay. Bottom line. And there's a number of ways they're doing it.

I have a whole webinar on VPNs. And if you want, I'll send you a link. To the copy of my last VPN webinar. Be glad to let you know a little bit more about that. Now there are some VPNs that servers and services that have gone out of business. Recently, one of them is called hide my ass. They went out of business and they gave up all of the information about their users years ago.

And this was w. We talked about, in fact, on my radio show, this was a G almost 10 years ago. And they handed over evidence that resulted in the arrest of some some of their clients, frankly, who were doing some things that were pretty nasty. Guess what? That provides us with another reason not to use VPN services because we are being lumped in with.

Every type of evil person you can think of, right? There are the majority of these VPN users. They might be like you and me, and just trying to keep prying eyes from our ISP, from Comcast, from whomever, keep those prying eyes away from our. Our systems, our data is none of their business, and I don't want to share it with them.

However, the criminals that are out there, the arch criminals that are out there, they are using these VPN services. So the IP addresses of most of these VPN services are actually blacklisted. By some of these providers that are out there and blacklisting is bad because have been using the VPN services or services like tore, for instance, in the onion network are you're going to be blocked at, in quite a number of different banks and other websites.

We block them routinely for our. Clients as well, because we can't really tell, are you a bad guy? Are you a nation state like China or Russia trying to hack in or are you just using a VPN to try and stay safe? Okay. So there's another reason not to use VPNs. And you might say, Hey, listen, I'm paying anonymously.

I'm using Bitcoin, whatever might be in order to pay for it. You remember, you're still connecting to the VPN service using your own internet address, and they can log that and it can be traced. VPNs. Don't provide security. Frankly, they are what we call in the business of proxy. And that means that you connect to a server that connects to another server and there might be cashing proxies, et cetera, in order to cut down on their bandwidth.

But that's what they are. They just are not providing more security. If you think you want more privacy, remember VPNs, don't provide privacy with a few exceptions. They are, again, just a proxy. They're effectively a middleman. Sometimes you're even using this man in the middle attack. We talked about early, earlier.

If somebody wants to tap your connection, they can still do it. They just have to do it at a different point. Now, remember that the VPN service you're using does not take you to that bank website that you want to go to. That VPN service takes you to some point in the U S or Italy or Sweden, wherever it might be.

And at that point, now it's out on the open internet. If they want to tap your connection, they can still do it. They just do it a different point. And these major nation States that are trying to spy on people, they also rent. Server time and data from the exact same places that these VPN services are renting from.

So they then launch attacks against the VPN servers so they can get it, all that information. They can decode. They can do the man in the middle attacks, whatever they want to do. So you're not getting more privacy because all they have to do is monitor at a different point. And although your internet service provider might be tracking where you're going online and selling some of that information, most of these VPN services are doing that exact same as well.

Now, if you think that you want more encryption and that's why you're going to do it well, you know what? Just using HTTPS on your web browser, that is enough security for almost anything you might be doing. So make sure you using HTTPS colon slash. The websites you want to go to because that website is now connected to you via a VPN provided by that server, like your bank or wherever it is, you may be going online.

I'm going to do more about VPNs after the first of the year, drop me an email me@craigpeterson.com, if you'd like to find out more.

You are probably fairly familiar with all of the normal tips about shopping online. We're going to get into little more detail here and what you should do while you're shopping and after your view have been shopping.

You can find almost all of this stuff up on my website@craigpeterson.com. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.

There are a lot of tricks they're going on right now when it comes to online shopping things that we have to be very aware of. And you've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't and I want to.

Play it a little bit of audio as well from my daughter. And this is really sad, but she got this phone call and it came through on regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from social security administration.

I'm literally trying to apartment (509) 524-9631. I think it's (509) 524-9631. Thank you. Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud.

So don't call those numbers. I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And so they wanted to follow up with you and you, they wanted you to call back.

So obviously. Don't do that. My daughter got this phone call just this Thursday and it was in her voicemail. Don't call these people back. I have a friend who he will see a phone number coming in, right call come in. Oh, I don't recognize that call. And so he'll just let it go to voicemail and he doesn't listen to the voicemail.

He just calls the number back. Hi, you called. Don't do that. And there's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers.

Sometimes they even use phone numbers of police departments, which is really funny. There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now.

And she's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? And she knew it was a fraudster. So we have to be very careful with these people. And so many of us, particularly the older generations are trusting, and that can be a bad thing, but it's not just them.

It's the young people too. I am shocked at what they will do, what they'll get away with and how they just don't. Care about cybersecurity. Really don't care. I had a discussion with one of my, one of my sons and he didn't care. He was just, he was pushing back as hard as he possibly could. So maybe it's a dad thing.

Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades. And he is just rebelling. And he's how old is he now? He's probably 24 or something like that, but I know a lot of us rebel and push back against this stuff. Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't.

So watch out for those scammers. One time I was. On the floor of a trade show. And I was actually exhibiting there at the trade show and talking with people and everything back and forth. And I thought it was going pretty well. And then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was.

And I knew it was just totally fake because the IRS doesn't just call you out of the blue, the social security administration. Doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam.

I know it's a scam she was asking for. I think it was Apple gift cards were really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy. Apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands on.

I just don't know. So it is happening and it is going to happen even more this year. And many people ask why would someone do that? Right there? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?

In another cases. And of course the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is rip people off, which is just a shame. And. Between you and I see this all the time in the it world, where there are a lot of businesses out there that are scam artists, they put up a shingle saying I'm a managed services provider, or I'm an it professional because there's money in it.

And they're not, we have a client. This was absolutely fantastic on Thursday this week. One of our texts. One of our senior texts, one, one of my sons in fact, was out there. And he said that we were the best, it support people he has ever seen. And he's been in business for about 40 years and he was just ever so grateful.

I was at to everything that we're doing for him and his. Team his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it.

And we're helping them, we get the right equipment. So he doesn't have to. Buy it again, when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful. And so am I frankly, for what he's done for us, which is pay his bill it's right.

So yeah. They're very good people and made me feel very good about that. But anyhow okay. So I am going on and on here, but let's talk about the online shopping and the safety for online shopping. There is a great article that I picked up from Cece. Which is a federal government agencies called the cybersecurity and infrastructure security agency.

C I S a.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look. And I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store.

So I always stop and look at it. And number one thing to look for is the grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker. Okay. Now you say, great. And there's all kinds are wonderful people who aren't here, English speakers in.

That's true. Okay. There are multiple things to look at. We're just talking about one of them here right now, which is, are they native English speaker or is this very poor or grammar? Because most businesses are not going to send out an email. They're just full of grammatical mistakes or spelling mistakes.

Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. And that's not something that you want to have happen. So that's the first thing to do next. Double check all of the URLs. So that email from address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O n.com or is it a M Z O n.com?

Any of these. Misspellings common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of awareness. And what we're trying to prevent here are what are called phishing attacks, or even spear phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously.

Is not when you get right into it. So in most cases, when I get an email from somebody, what whomever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? And if it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.

There's usually most banks have the. Messages thing and you can right there in that messages say, yeah, okay, no problem. Here it is this the same message that they sent me via email. And if you do that, then, it's legit. It's just You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book and yet, and you look them up online, right?

Who has books anymore? You call that number, not the number that they gave him. All right.

Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.

Let's talk about these devices that we're going to be buying this year and in next year. 2020 is going to come to an end. I'm really hoping some of this stuff's going to spill over into next year. There's a few things you really should be doing, especially with your bank or Amazon, anywhere where you have financial data. And one of those things is called multifactor authentication.

A lot of these businesses have this called also two factor authentication. You might see it abbreviated as. To FFA or MFA, but what that allows you to do is have something, and combine that with something you have. That's always been the best practice when it comes to security. Now, obviously there's even more stringent stuff that you could potentially do, but that's your basics of the best stuff.

So what is this two factor authentication? In many cases, businesses are using a text to message that they'll send you when you log in. So you go into your account. Normally it's where you would set your password and you'll see something there about multi-factor authentication or two factor authentication.

You'll go to that. And in most cases, they'll ask for your. Phone number and they'll send you a text message to verify it. And. You're off and running. So now the next time you go to log into that site, it's going to want your username or email address, and it's going to want also your password. And hopefully you're using a different password on every website out there.

And then it's going to send you a text message and that text message will have a number that you can then type in on the website. And then this is okay. This is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed.

People stole their phone number. So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's get into your Bitcoin account, whatever it might be. And they find out what your cell phone number is. And then they call up your cell phone provider and they say, Hey, I've got a new phone.

And then they give the, all of the information for the new phone and they can bamboozle them. To get them to switch. And before you know it, cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. In fact, it's wonderful that people haven't been bothering me on the phone, but what has actually ended up happening is they now have your email address.

They have assumed. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.

So when they go to log into that bank account, They've got the email address. They got your password. Cause you, you have used that same password elsewhere. And when the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone. So here's an important tip.

Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you what's the password for the account. Now this is going to be a different password than you'd use on the website. But it's going to be a password. In some cases, it's a pin. So come up with something that you don't use anywhere else and set it up with your cell phone provider.

All right. So that way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.

We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does. So duo allows you to have a different type of two factor authentication. You can also use Google authenticator, which is free. You can use last pass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for last pass.

And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about one PA password and last pass and what you should do a little bit about two factor authentication. So I use duo. I also have Google authenticator, although I don't really use that at all.

I tend to use Google or do I should say. What happens with that is they'll display a QR code when you're setting up the two factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few old 30 seconds, and it'll give you a six digit code that you can use.

And that code is only good for 30 seconds. So now when you go to login, you're going to give you username or email. You're going to give your password. And then it's going to ask you for that. Code so you can use again with duo, I have adjust automatically. It comes up, it's integrated with my one password as well.

So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification for two factor authentication. Now there's one more trick that you could play if you wanted to. And I have done this more than once.

Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two factor authentication, other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone.

So I have a phone number that I got years ago from a company that Google bought nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? First of all, I can filter calls that are coming in and text messages and everything out.

And then Google will forward the text message to my phone. And remember it's Google. So it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use. Something like Google voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number.

Because they can't and they won't. Okay. It's very important. The, the SIM card that you have in your phone nowadays, some of these devices have virtual SIM cards. That SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers.

So some really important tips there. I hope you took some notes.

If you didn't, you can find this online. I post these as podcasts that you'll find right on my website @craigpeterson.com. You can listen to them, take notes. My wife even provides a transcription of these things most of the time. Bless her heart she spends a lot of time doing that and she'd appreciate it. Check it out online craig peterson.com.

We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some real surprising things for you guys.

One of the things that we have to do, and this is again, over and over again, but better than 60% computers have windows, computers are not up to date. Remember we're buying nine devices that are basically computers. Do you remember that whole Barbie thing from not too long ago?

I, in fact, was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously it's a very big problem because it's your kid's information. Voices being sent up in the Barbie was interacting. Dope now Mattel cleaned some of that stuff up and that's always a good thing.

But the point behind this whole computer in a toy or other device thing is that their computers we're talking about mobile phones. And Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones.

They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date. In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good in generally speaking, I'll remember it's Google.

Okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers. Use Chromebooks and use them exclusively because they don't have the same security problems as windows. What's one of the reasons apples don't get attacked as much as windows computers.

Don't because the Macs frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than windows is. And Microsoft is starting to FY fall in behind Apple's lead, which I think is a good thing.

So those computers update them immediately. If you're still running windows seven, make sure you get 10 cause seven. Isn't getting the updates anymore. If you're running windows eight, 8.1, make sure again, you upgrade to windows 10, but brand new computers. Shouldn't come with those. Another quick word of warning about computers that you're buying the home edition of windows does not have the same features as the business additions or enterprise additions of windows.

So you might want to, when you're buying something, look for windows professional, it has more options. And one of the options that could save your bacon is the ability to put off update. Now, you're I hear you saying Craig, you're always telling us to update. Early and update often. Yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild, bad guys are actively using it to exploit you to exploit your fault.

Okay. So there's some very good reasons to stay up to date, but. Hey, here's a problem. I had a law office call me up because right in the middle of them, putting together some documents for the court that were due in less than two hours windows and they were running home edition, decided it was going to force them to do an update.

You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem. But even if you're not an attorney, you're not dealing with the court. When the windows professional does give you the option to schedule the. Dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device secure most, if not all of the time.

Okay. So let's move on to the next tablets again. You look at something like the Amazon Kindle, the firearms and the here's my watch talking hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things.

Yeah. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. And I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the. The front screen was just cracked all the way down.

So I returned it, they shipped me another one and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. And I also got with the Amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.

So a little kids come over grandkids, and they want me to play baby shark, which is an annoying song that the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love ah, jeepers. What was a gummy bear? That's what it was. Gummy bear.

Remember that song was incredibly annoying too. And he, in fact, I ended up getting the guy who wrote the sock on radio show with me to talk a little bit about it. It was fun actually. Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances.

Like I remember five years ago, I think it was out of the consumer electronics show. I saw a, another one. Before, your home that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or Rosa told you to cook in the oven at 5:00 PM, I'm going to be late.

Okay. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. That's all well and good, but that appliance has a computer in it and it's sent into wifi. I have you updated it. And does it self update and for how long are they going to be providing updates for that oven?

Or, I'm sure my now five years later, there's no more updates for it. So you now have a, an appliance, a device that is frankly dangerous on your network, because if somebody, again, they come over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.

Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. And now they are used as launching points to infect everything else.

You network. Check the update, make sure everything's up to date. And in some cases it's pretty hard to update, but it's worth it. You have to do it even your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IOT wifi network, internet of things.

All right. You're listening to Craig Peterson. Make sure you visit me online at craig peterson.com and sign up for my newsletter.

We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. Now we're going to go into a couple more good points.

So we did talk about multifactor or two factor software update. Now, once you've purchased an internet connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password.

Now, in most cases you can connect to the device, just using a web browser that makes it very simple. So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, a little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet connected and your washer dryer, a almost every even light bulbs have little web servers built into them and you want to connect to them and change the default password.

So look up the manual. It's probably not going to tell you how to do it with. The information that's in the packing, but if you go online and search for that device, you can find out how to change it and use this is just normal recommendations, right? Use different passwords for every device and always use complex passwords.

Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be. Three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best. And in order to do that, you're probably best off.

Using a password manager to help out. So that means using something like one password or last pass. And once you've got that in place, it'll generate these passwords for you automatically it'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for.

The password manager now, in my case, I've got it set up with duo again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via duo on my smartphone. So there's a multifactor three factor authentication. Okay. So important for all of these devices that connect to the internet.

Also check the devices, privacy, and security settings. And a lot of times the manufacturer will. Let you set up an account on their website. And from there, you can tell it what information you want to share and don't want to share. Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you.

That you have in deed, given consent for this information or that information to be used by that app developer and sold. But you can go to the Mattel website, set up an account for your device or the Samsung or whatever it might be. And right there, you can examine. Your privacy settings and what do I want to allow the vendor to gain access to?

Okay. Make sure you're not sharing more information. Yeah. Then you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.

The latest version of the software. Usually tells you that it has the latest security fixes. Hopefully it does, but it also helps to ensure the manufacturer still support it. Because if you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it.

And that way, the latest patches are going to be out there, but if you're not getting the updates and nobody else is the manufacturer is not going to have a lot of incentive to give you security updates, then there's the normal stuff about, don't use public wifi. Yeah. That's generally a good idea.

But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So purpose personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared.

Turned off and I am going to do. Class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.

How to harden windows, so that even if you are on a public wifi somewhere, you're going to be relatively safe and the same. Thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.

These ISP internet service providers are not completely on top of all the security. Okay. All of the basic stuff don't provide personal information, financial information. I tend to use. These one time, if you will use credit card numbers. So every time I, if I go to a site and I want to buy something let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site.

Each one of those, I use a different credit card number with, so check out your credit card provider, all of the major ones, visa and MasterCard. They have the ability to create virtual credit card numbers. And that way that credit card number can only be used on that website. So you give this, you create this credit card number.

It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. And now if somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. And then the other advantage is if someone starts to miss using it, then you can just turn off that virtual credit card number.

It's really that simple. So have a look at that. Then one time use credit card numbers or these virtual credit card numbers, which is what I like. Where you can use it multiple times on that site, you don't have to create a new one every time, a available from most banks and all major credit card companies.

Okay. Also be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds. Whenever I'm on a website, I'm going to a website. I'm reading email, just making sure that it is correct. I spelled Amazon Houghton, or the email address that sent it to me.

Is legitimate. I can't believe how many times I get an email. It's a phishing email and it's from somebody@gmaildotcomasthoughamajorbusinessisgoingtousegmail.com. And that's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.

I've seen so many people doing that got even proton mail. Proton mail is quite secure and it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter bought a month ago. With what that's all about. And if you want it, just let me know, just email me@craigpeterson.com and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it, but you can always search.

If you don't delete my newsletters, you can always search for that information, but you can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store, gmail.com. Okay. It looks much more legitimate. Let's see offers obviously be careful with those don't click links or download attachments, unless you're.

Really confident. Again, I tend to go to the website as opposed to click on the email that I got, there always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock, if it's closed or your information's encrypted, which is really good.

If you can use a credit card. Don't use a debit card there's laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card.

And then you have to wait for the money to be credited back to your account. And in the meantime, your checks are bouncing or. If you use the debit card for other things, it is being Denine. Okay. So be very careful with that. Insufficient funds are always going out there. So there's a lot of it's of other things.

And I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online. Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe.

Online. Just visit me online. Craig Peterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.

Take care, have a great weekend. Join me again next week.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG on Jim's show this morning with Steve Fourni and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. Here we go with Steve

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hi everybody. Craig Peterson here. I was on Jim's show this morning and we had, I think, a really good discussion about security, privacy, what Mozilla's doing, why Firefox people are praising Apple, new anti-tracking technology. How you can take advantage of this no matter what kind of. The system you are using and about law enforcement here shutting down VPN services, people going to jail over this.

So again, yeah, I told you how many years ago, how long have I been talking about VPNs and how dangerous they really are? So we got into that and I explained what types you shouldn't use, et cetera. That's what this is all about. Hope everybody has a great week. I am going to air the best of we'll call it and showing this weekend and cover a few different topics.

So I, I really hope you guys had a great holiday season and have a fantastic new year take care.

Steve Fourni: [00:01:04] All right. Here's Craig Peterson, Craig. It's Steve Forni here in Springfield. Good morning.

By the seat of our pants today, Craig, so welcome and welcome into the mess.

Craig Peterson: [00:01:14] Yeah. Hey, Danny's a true professional here.

You, I understand. Dan,

Steve Fourni: [00:01:19] He gets paid more than I do. Oh, man.

Craig Peterson: [00:01:22] Yeah. It is the week between, so we get a break today. There are no sweeps this week so we can, we can take it a little easy.

Steve Fourni: [00:01:29] Yeah, absolutely. And speaking of taking it easy, it looks like Apple has stepped up its anti-trafficking privacy features.

And Mozilla. Is it Mozilla? I always never know how to pronounce that, but I do use Firefox Mozilla regularly and they are

Craig Peterson: [00:01:44] yeah. And yeah, this is really cool. You're right. Your Mozilla is how you pronounce it. Congratulations and gee, man, I just can't let them, I'm sorry. I D I can't help myself this morning.

It's Firefox. And if you're using just a standard browser and you want to stay safe, it's a good idea to use Firefox and Firefox has really been getting a lot of advertisers upset. They have a special little fenced-in thing that they put in place automatically. If you go onto Facebook, Where it restricts Facebook from accessing any of the data from any of the other websites you went to.

Of course, Facebook really hates that. And Mozilla's Firefox is also with the next big release. Having a new feature where it blocks every website from knowing what any other website has done is see because these guys out there that are trying to track you. We're talking about mostly advertisers here, not the criminals, but they've gotten really smart.

So they'll say, Oh, I know if you go to iheart.com. That I, heart.com is going to have their logo on the page. And the URL for that logo is iheart.com/logo,dot JPEG, for instance, so that they know that's the case. So now you go to X, Y, z.com and at X, Y, z.com. And you have your cookies blocked.

So they'll say, Oh, okay no cookies. Okay, fine. Fine fine. Done. Let me try and download iheart.com/logo.jpeg and so it'll put the request out in a time how long it takes it to get that graph. Is it, this stuff is just so advanced Steve, and the graphical shows up in a couple of milliseconds because it's cast because you been to the iHeart radio site.

And so even without cookies, That website, like it could be, Facebook could be anything knows where you've gone online because they can check to see if you've got the iHeart logo cached. They can check to see if you've been to X, Y, or Z site. So Firefox from Mozilla. Is going to really tighten down, not just on fire, not just on Facebook, like they have been, but on Firefox doing it for every website that's out there.

But now these guys that Mozilla, very privacy-conscious, very security conscious. They're now praising this new release of Apple's operating system iOS for the I-phones and iPads. And Apple's really got Facebook in a tizzy right now. The Zuck is really upset because what Apple is doing is changing the way it allows advertisers to track you. When you're online there are these little tags that Apple has put in place that you could change in their advertising tags, and you can go into your settings and you can change it. And that kind of blows who's out of the water. Anybody that's been tracking you?

Apple has changed it again, now. They're saying, Hey, listen to Facebook or whatever sites. Wants to track you. And they're in putting it in place too, for the apps. There've been all kinds of complaints about apps, for instance, and the tracking. Our friends over the department of Homeland security have been accused of and admitted to buying information from app developers about people who might be illegally in the country and track where they are located.

This isn't just on iOS. This is way worse over on the Android side. So there are all of these companies that are data aggregators that are getting data from everywhere they can that have been paying the app developers to use their libraries.

Apple is going to be tracking that, stopping it, letting you know somebody is trying to track you. And it's a free app, Steve, that you downloaded. It ain't free. Okay. They are, many of these are tracking you.

So Apple is really raising the bar here on stopping the tracking. Improving security, which Apple's always been far better at than Android, which is why one of the reasons why I say never ever used Android.

Hopefully, I had enough ever since there for it.

Steve Fourni: [00:06:17] How about. Google. Are they going to do anything in terms of, cause one of the biggest issues? I have a big issue with Google. I'm still convinced they put one of my local flower shops out of business because when you Google it, all you get are ads for pro flowers.

But I, I feel Google itself is the one that again when I say into my phone, boy, I could really use a new toolset. All of a sudden I get ads on Google for toolsets, and obviously they have Google Chrome, which competes with Mozilla. I know we're talking about something different, but are they approaching Google sort of the same way, or is there any sort of connection between Mozilla and Apple against Google?

Craig Peterson: [00:06:51] Yeah. Google Chrome, as you mentioned, the Chrome browser very popular. It's probably the number one browser out there. Just generally speaking is a big contractor. They love to track you what you're doing, where you're going. Remember Google is business is selling information about you. So if you're using Mozilla, if you are using a browser from a company, and Firefox from a company that doesn't want to share your data, Google not only wants to share it, they want to sell it. They want to put it together. They want to make them the center of your life.

You might remember Steve, back in the day, Google has a motto. I shouldn't say was, don't be evil. Do you remember that? You can't find that on their website anymore?

It's the definition of evil. Now, when it comes to this sort of thing about your information. So the safest browsers, if you're using Firefox, Steve like I said, that's probably the safest ish, depending on what we're talking about. But from your privacy standpoint, it's definitely the safest, it's one of the safest from a security standpoint, another one that's very good is one Apple puts out.

And if you're using an Apple device, you're already using it probably by default, you are it's called Safari S A F A R. I. Your little blue round logo and it's available on their desktops, the Apple desktops, but it's also available for Windows and Apple is very good about not again, tracking Apple does not make money by selling your information.

Apple makes money by selling you hardware and services versus again, Google, which is the, as I said, the definition of evil. There are studies that have been done about how Google this last election cycle made major changes to the way people voted some interesting studies came out, looking at orange County in California which has been a very conservative County for years, and studies showing that in that one County, Google changed 30 to 50,000 votes just by doing what you talked about, Steve, which is my local florist run out of business. And I'd bet it was Google showing ads for these national flower shops. That's what they've done. And that's what they did during this election cycle as well to promote candidates they liked.

Steve Fourni: [00:09:29] That's scary. And I know I've heard you talk in the past about this, but I guess while we're on it if people want to search something, but they don't want Google, I know you've said duckduckgo. Which again, to me, I have a hard time with just, cause it sounds childish. Like Google works cause you could just say, yeah, just Google it. Like it works. It flows off the tongue.

I think marketing is a big part of that saying yeah, just DuckDuckgo. It doesn't really fit the lexicon, very well.

Craig Peterson: [00:09:55] You could use Quant as well, Q W A N T that's another one you can just quantify. It sounds cooler than a duck.

I say doc and Qwant is another one that's pretty safe. It's out of Europe. It's out of France more specifically. But I really liked Duck Duck Go. In fact nowadays. It's rare that I use Google. If I'm looking for something really technical, I actually use something called Devon think, which is a.

A database system and search engine that searches search engine just called a metasearch and it runs on my own hardware here. So I have a watch, certain sites for things, and puts it all together. But that's my first. And then you use Google if it's very technical, and if it has anything to do with anything else, I use duck go because they don't even use your search queries in order to feed you results which of course Google does.

Duck go just takes general advertising and they do all of this on purpose because they want you to have a safe, fair online search experience.

Steve Fourni: [00:11:04] Very interesting. We're talking with Craig Peterson, our tech guru, and maybe we can just sneak this in a quick here because. VPN services enabling cybercrime and law enforcement agencies trying to crack down on it. How's that going?

Craig Peterson: [00:11:20] People who listen to my show, know I am no fan of these VPN services. And in fact, most of them, they are almost always let me just put it this way. Almost always.

They make your data last year. And there are quite a few reasons I talk about it. And I got a really nice note this week from one of our listeners saying that she stopped using these services because they do make it much less safe. But this case here, global law enforcement agencies now, including the FBI have shut down some more of these.

VPN services that were being used by criminals to launch ransomware campaigns, phishing attacks men in the middle attacks, where they have now access to all of your data. So you're using this VPM service, Steve, in order to be safer to keep your data encrypted, all of the lies and promises that they tell you in these ads that they run.

And in fact, what's happening here is these VPN services, because they were shut down here by operation Nova. I led out of Germany. In fact, they're pleased agencies over there, operation Nova, they were decrypting, everything you were sent over the network. So you're going to your bank. They've got your bank account information.

They've got your login. They've got your password. They've got it all. The only way to be really safe. And you know what, one more thing on that this is the way the campaigns stayed safe. You wonder why we haven't seen campaign emails leaked to, because of this one trick that I'm about to tell you, and that is, they used.

Two-factor authentication. Now not the type that sends a text to you, your phone, but one of these fobs, one of these keys that are available now, Google actually sells one. Surprisingly enough. Now they use it internally. I like duo, D U O, which we use professionally. And there are also YubiKeys, which we really like. Y U B I K E Y S

So when you log into a website using one of these things, What happens is it's something, which is a username and password, along with something you have, which is a six-digit code that changes every 30 seconds. And that's why we haven't seen the Democrats' email leak. The Republican's email leak this time around, and that's what can defeat.

These VPNs are actually grabbing your information and selling it on the dark web and people's bank accounts are being emptied because of it. But Interpol Europol the FBI has been shutting some of these down stoned use. Oh,

Steve Fourni: [00:14:10] scary stuff. Craig, this is all good information for the people. If they want more information now, obviously you got the show.

What else? How else can they get all the resources that you offer?

Craig Peterson: [00:14:21] I have, of course, a weekly newsletter that you can catch and you can just get that by going to Craig peterson.com and sign up as you've probably guessed. I'm not one of these heavy marketers, but if you're ingesting VPNs, et cetera, I've done some webinars.

I can send you a link to watch them. Just email me. M E @Craig peterson.com and in the subject line. Put in VPN so that I know what you're looking for. And me@craigpeterson.com. I can send you info on that or anything, but if you go to the website, you can send it, you'll get my newsletter and you'll find out about future training, too.

Great stuff as always, Craig, really appreciate the time. Have a great new year and we will catch up in 2021.

Looking forward to it. Hey take care of Steve and Danny, both and Jim listening at home.

Steve Fourni: [00:15:11] Yeah, no doubt. We appreciate the time and we'll catch up. There goes our buddy Craig Peterson, great stuff is always taking things and breaking it down for us all to understand which is right.

Craig Peterson: [00:15:22] And a happy new year to everybody out there take care. We will be back after the first of the year more stuff. Of course, we'll be talking about now. Hopefully, it'll be a bit of a better year. I think I'm going to come out with something too for businesses, small businesses on okay. Post-COVID.

How do you get your remote workers secure? We've got to pull up our socks on now and really let's make this a business and no longer just to hack. Anyway, let me know if you're interested in that. You can always email again, me at Craig peterson.com. Let me know. That's how I come up with these ideas. You guys ask you have questions about things.

And I always put together a response. Sometimes it's on the radio. Sometimes it's a little, a special report and sometimes, of course, it's a full-court, so would take care of everybody. I so appreciate you being with me.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hi guys, Craig Peterson here.

I meant to post this and we managed not to. So this is from last week, actually. It's a week old now. It's my explanation of what happened with this nasty, big hack with Mr. Jim Pollito. Here we go with Jim from about a week ago. Oh, there's Velma barking. What does this all mean?

Jim Polito: [00:00:26] Oh, yeah, this is the guy, everybody, especially after what happened yesterday. Massive security problems affecting thousands of businesses and government agencies and who was on top of the whole thing. Our good friend and tech talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:00:46] This is pretty bad news.

Jim Polito: [00:00:48] Yeah, very bad news.

Danny yesterday at one point said to me, Hey, Google's not working, then it came back. YouTube was down, then it came back. Then we found out, Oh, it's almost like the matrix when there's a little bit of Deja Vu in the matrix, you notice it, that means they changed something.

Craig, so what's going on? What happened?

Craig Peterson: [00:01:08] This is really, really big for the fifth time. Only the fifth time in five years we've got an emergency security order coming out from this new national office for cybersecurity. This order is for all government agencies, as well as ordering federal civilian agencies to power down any of these SolarWinds devices, that are out there in their networks. Power them down.

Now SolarWinds is something that over 300,000 businesses use. It includes all 499 of the Fortune 500 companies, includes 22,000 managed service providers. What happened here was really tricky.

It was discovered by this company called FireEye, who found out that they had been breached. Now, FireEye is one of these big cybersecurity companies and they were using SolarWinds software.

Now this real quick, if you are really trying to be secure and you can't really do this yourself. If you're a smaller company, like under about 200 employees.

You have what's called Red team-Blue team trials. This, if you're in the military, you know what that is. So you have a red team attacking your computer systems and a blue team defending your computer systems. It's a drill. It's a really good drill. Fire Eye's red team tools, the tools for attacking businesses and government agencies, which is what they do all day long, were stolen from this hack.

They looked a little bit further and they found out is that what came through was this SolarWinds technology, which is used by almost every fortune 500 company.

It's been out there for, I think it was since May, this year. They managed to get their malicious code into SolarWinds product that they were shipping out to people. They even got them signed properly with the proper checks.

So now the US cybersecurity and infrastructure security agency, called CISA issued this directive on Sunday. Specifically, we're talking about SolarWinds Orion products.

Now my company, I am a master managed security services provider. That's what we do. We are the top of the heap, right? We went through all of these warnings. We got them from the FBI and every other three-letter agency that exists. We went through everything that we had. It looks like the problem was they had misconfigured the software. Not follow the manufacturer's instructions. Thank God we had done it. None of our clients got compromised.

This couldn't be bigger.

Jim Polito: [00:04:14] We're talking with Craig Peterson, our tech talk guru, about a massive hack, yesterday. Who did it?

Craig Peterson: [00:04:20] That's the question, right now? Fingers pointing at Russia. But.

Jim Polito: [00:04:25] What a surprise.

Craig Peterson: [00:04:27] Yeah. Russia. It could be almost anyone it's so hard to tell. I don't think we'll ever know, definitively. We've seen the Chinese hack into systems through Russian servers and we've seen the opposite happen. Now even, Vietnam has gotten into this game. Let me tell you, this was some serious hacking that happened here. People that really knew what they were doing.

So we don't think it's a cybercriminal gang. We think it's a nation-state.

Jim Polito: [00:05:01] That's the thing. They're not looking for credit card information. Isn't it interesting that they went after? Infrastructure, which would be the power grid. We all know what could happen should the power grid be hacked and shut down.

Was this simply either the Chinese or the Russians, whoever, basically an act of war, but testing out and trying to figure out a way to shut down our utilities.

Craig Peterson: [00:05:32] Absolutely. Absolutely. Our utilities use this software too, but you know what? They're going to get even more out of this than just control of the utilities. Federal agencies have now been compromised Gar-on-teed.

That means that they've got whatever information on FBI criminal cases. I'm not saying for sure, we know the FBI was hacked, as part of this. But I'd be shocked if they weren't, right. All the way through everything in the Department of Justice, everything in our military, you name it. Okay. Our power grid, our water control systems, these things are controlled by the software.

It drives me crazy because there are so many companies out there that hang up a shingle, saying we are a managed security services provider. They've got this flashy website and they've got some really cool looking seals on the site. People fall for it. We get called in. Every one of our clients that we have today had previously had a managed security services provider that failed them.

Now we're seeing the federal agencies, these people that we're paying top dollar to. They are supposed to protect our information and our government appears to be incompetent. Yes, I said that, incompetent. If you got hacked by this, you didn't even read the freaking directions.

Jim Polito: [00:07:03] We're talking with our good friend, Craig Peterson, tech talk guru.

This is not to get everyone concerned the sky is falling. But something has to be done here.

Let me go in the opposite direction. Please tell me, Craig, that we're doing exactly the same thing in China. In Russia. In Vietnam. In North Korea. Please tell me that we have, look, we made the vaccine, we're smarter than them. Please tell me that we're smarter than them and when they turn around, they'll realize, wow, there's been a gun pointed at our head the whole time. We didn't even realize it. Is that mutually assured destruction. What kept the peace in the cold war?

Tell me that's happening.

Craig Peterson: [00:07:47] It is happening. Every branch of the military and our Justice department, have hackers that are breaking in. In fact, I'm glad you brought it up because there was an unprecedented major leak quote, unquote of official records of 2 million members of the Chinese communist party, many of whom are now living and working all over the world, including Australia, the UK, the United States.

We now have and its public information, now, because I'm guessing we leaked it. The data has the names, the party positions, date of birth, National identification number, ethnicity telephone numbers of communist party members that have been set up inside Western companies, as well as our Congress and our military infrastructure and our federal government.

So the answer's yes. We now have details of 79,000 communist party branches as well.

So yes, we are fighting back.

Jim Polito: [00:08:54] Now, I want to bring you to another portion of this. I know you're not big into the James Bond stuff, but we have a James Bond type situation. We had Christine Fung, a spy, a student who was a spy from China with a member of Congress. We find out this is not an isolated incident. That they are cozying up to young and up and coming politicians. And she did with Swalwell, probably slept with him. Although he won't say, he says it's classified. That's a very good excuse. The bill Clinton should have used that one. I'm sorry, it's classified. That she slept with other, mayors or whatever, that this is going on quite a bit.

Yeah. Diane Feinstein had a driver who was a spy for years.

Now, isn't it time to say, Hey, no more students from China? At least to pause it. To send a message, because obviously we're letting them come in and to our faces, they're slitting our throats.

Craig Peterson: [00:09:53] They absolutely are. Detailed analysis of these records revealed that Pfizer and AstraZeneca. You've probably heard of those companies lately. Those companies employed 123 Chinese communist party loyalists. More than 600 party members across branches working at British banks, HSBC, Standard Chartered, Rolls Royce.,Airbus, Boeing. Yes. They come to our schools. They learn from us, which is all well and good, typically speaking. Then they take it and they try and replicate it in China and compete with us.

We are funding these schools. In so many States, a hundred percent and we're training them. We are teaching them. They are then moving up through the ranks.

So look, Swawell. Look at him. This little honeypot when he was mayor. You get about up and coming. And so they're taking our technology. We are losing our place in the world, right now. One of the biggest up and coming technologies is artificial intelligence. Guess where Google moved their AI research? To China.

Jim Polito: [00:11:05] Don't say it. That's a great place to be.

Craig Peterson: [00:11:08] In China. It's a great place to be. It's up and coming. Isn't it? Wouldn't it be wonderful if the Chinese get a leg up on the rest of the world with artificial intelligence technology? To do the types of things we are seeing them do now, and I keep pounding on the table, I'm gonna hurt my hand, but it absolutely ridiculous.

Jim Polito: [00:11:26] I just don't know, without getting into politics. I just don't know-how. First of all, I feel like knowing all this, I wish Trump had done more. I don't know what he was doing behind the scenes.

The second part of this is, I don't see how Joe Biden has any kind of a policy to deal with this, and secondly, he's compromised. His son is compromised. He's a friend of China. He's compromised.

Craig Peterson: [00:11:51] Yeah, I have to agree with you there. I want to add a nice little word to this. We're talking about Congressmen Swalwell and what happened with him. Senator Feinstein. This information about this unprecedented leak of the 2 million Chinese communist party upper echelon people who have been planted in foreign governments, came out two days ago.

What do you want to bet? Our hacking got this stuff. We started going through it and that how he was exposed with his girlfriend.

Jim Polito: [00:12:22] Yeah.

Craig Peterson: [00:12:23] Intelligence committee. Are you kidding me!

Jim Polito: [00:12:28] Craig, it's just crazy. The fact that Nancy Pelosi covered it up. I'm sorry if you've had any kind of a relationship with someone who was a spy and you're now on an intelligence committee and you weren't taken off of that intelligence committee. You weren't investigated. You got a defensive briefing. General Flynn didn't get a defensive briefing. He got a " we're going to try to catch you in a lie to the FBI" briefing. Swalwell got a "we're going to give you a defensive briefing."

We found out the girl that you're Fang bang your girl. We found out she's a spy. You might want to stop seeing her. =That's it. That's it? No, really? That's it. Oh. Stopped dating her.

Craig Peterson: [00:13:10] We've got to pull up socks. President Trump kept saying that he was trying to clean up the swamp. The swamp is now, definitely including, these members of the Chinese communist party.

We already know, I've talked before. About clients that I've gained. These clients had active Chinese back doors that were stealing their information. Now we find, over the weekend, that we had 18,000 organizations, government agencies, and businesses that were almost certainly compromised in this massive cyber attack.

Jim Polito: [00:13:42] Sickening.

Craig, I appreciate it. Craig Peterson, folks. Craig, what is the website? So folks can always be in touch with you.

Craig Peterson: [00:13:51] Go to Craig peterson.com. I'll send out an email a little later today, going through this. What happened if you were using SolarWinds, or if you're using an IT vendor, the questions need to ask them I'll get that out today.

And probably, maybe not till tomorrow with some of these lists. But I'll keep you informed Craig peterson.com and make sure you subscribe.

Jim Polito: [00:14:14] Yeah, it's good, it's a great thing to do.

Craig, always always a pleasure to have an expert like you, and when something like this happens and we'll catch up with you.

Craig Peterson: [00:14:22] All right. Take care, Jim.

Jim Polito: [00:14:23] You too.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Steve Fourni We discussed VPNs and Man in the Middle Attacks (MITM,) Here we go with Steve.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning everybody. I was on with Mr. Steve Forni this morning, Jim Polito is out. He is sick. Oh my gosh. This COVID thing apparently got them, but anyway, I don't think that's secret information, but It might be insider stuff. But anyway, I spoke with Steve Forni, who is one of the producers he's in central mass this morning.

And we really got into this whole VPN thing. And how Google now has removed another. VPN that uses a man in the middle attacks. So explain what that all is and everything else. And if you are interested in finding out more about VPNs, just email me@craigpeterson.com. I can send you a link to a webinar I did about VPNs.

All right, take care. Here we go.

Steve Fourni: [00:00:50] Steve Forni here in Springfield. Danny is in Worcester and that music, that means it's time to hang out with our tech talk guru, Craig Peterson, to give us high-tech information at a like a fourth-grade reading level which is easy for us all to digest, which is great. Craig, thank you so much for taking the time today, buddy. Appreciate it.

Craig Peterson: [00:01:09] Hey, glad to be here. No, I try and aim high or at least seventh grade.

Okay.

It had a problem. I don't know if you've used some of these online sites. I love Grammarly by the way. If you've never heard of it and you ever have to write anything and you want to make sure it's correct.

Use Grammarly. It is just amazing. I've subscribed to that for a while now. There are other sites too, that tell you what grade level you're writing is at? I was consistently writing at like grade 13 or something, the first year of college. I use those tools to get it down to about seventh grade. Just the seventh grade so that most people can understand it, because who here is really going to go for a college degree in computer security and technology. Okay. You nailed it. I'm just impressed. Steve. You understand what I'm trying to do?

Steve Fourni: [00:02:01] Well, I appreciate that. I admit I am a word nerd and I even refuse to end my tweets with a preposition.

Craig Peterson: [00:02:07] But

Steve Fourni: [00:02:07] I know I'm a little different maybe, but I also, I can't do math, so there's that.

Craig Peterson: [00:02:13] So here's that to boldly go where no man has gone

Steve Fourni: [00:02:15] before.

That's right. So obviously a lot of people working from home trying to figure out the whole deal of getting it done here. Preferably on the fly for a lot of people and VPN has become an issue here. Can you tell us at least about the one that Google had to shut down?

Craig Peterson: [00:02:31] Oh, this is a real problem, frankly, for everybody I've done a whole course on it. And I promise I am going to do another course after the first of a year because of the VPNs or something, people really don't understand very well.

With this whole lockdown thing that we've been doing, it's been a problem because we all of a sudden started using VPNs, remote desktop, and all of these things. They have been a very real problem. And we've seen it now. In a few different places out there. And one of them is what you just mentioned with our friends over at Google.

And Google has removed that shady Android VPN app. They've removed, not just one, but multiples of these that were in the place store. It's called the super VPN. Free VPN clients. Now the problem to just make this really short and simple. Now. After the first of the year, probably early February, maybe late January, maybe we'll try and do it earlier, but we'll have more details on VPN and how to use them, how to set them up, and everything else.

But here's the bottom line. This VPN allowed what's called a man-in-the-middle attack. We've seen governments doing this now around the world. And what that means is think of the days of the string telephones that we'd make the little kids with the cans. Have you ever played this where you have a friend who's talking into the queue one, can it transmit over the string to the other cans? They have that up to one ear and then you have another friend with another string and another set of cans. So you hear it from a friend a and you speak into the can to friend B to relay it along so that you can go long distances 30 feet and that's a man in the middle.

So you're relying on that man in the middle to relay your message properly like a broken telephone, a game we've all played. And what happens with this? A man in the middle attack is the VPN that you're using is actually being used. There's somebody in the middle using your VPN that you thought made your life safer.

But in fact, They are intercepting everything. They're decrypting, everything. They're looking at everything. And now they have your usernames, your passwords, the whole nine yards. So Google just removed it yet. Another one of these VPN apps. It routed the place store. These things exist. There are so many reasons not to use a public VPN bottom line just don't use VPN services.

And if you want more on this, I did a webinar earlier this year on VPN, and I can send you a link to be able to watch this. Cause I did record it on VPNs. And what are the risks? In most cases with most of these VPN services, you're actually making your data and do you less safe, not safer. So how is that Steve?

Steve Fourni: [00:05:42] Craig, it brings me to what I guess we opened up with was bringing things down to a level. People can understand I'm wondering if. If any of this own onus falls on it department for whatever company you work, for which again, can't really tell at your average employee, everything that they need to know about the VPN instead, they're just like, okay, here's the icon put in your username and password and hit connect.

That's all you need to know. Don't worry about anything else. As opposed to telling them things, to look out for updates, like using this, you don't use that. Taking that from an elementary level and bringing the knowledge to the employees up a little bit. So they know what to look out for.

Maybe that's a conversation that's not being had.

Craig Peterson: [00:06:25] I think you're right about them, but it still gets so complicated. So quickly. I one, I'm using an example here, a friend of mine yesterday, a really good friend. He and I ride motorcycles together all the time. And I got a call from him, Steve yesterday morning and Hey, can I come over?

I said, okay, why do you want to come over? You? Nothing personal love to see you. And he says I gotta talk about he's retired. And he's delivering for grub hub and people have ordered from that's this food service where you can have a, buy something from a local restaurant habit delivered right to your home.

So he drives around in his little Volvo and picks up from the restaurant and then delivers it to the home and makes a few bucks from it. He even does it to me. And so I spent four hours with him yesterday, cause his account was hacked. All of his pay was going to somebody that hacked into his Microsoft email account.

And had gone in and changed his grub hub, paid to account to another bank account that was owned by the hacker. And then the hacker also took over his email account. So that any time now, because he's using the same Microsoft email account for everything, same password for everything, or at least almost everything.

Do you see the warning flags going up, Steve? They took it over. It took us four hours for me to figure out what had been going on, what happened. And I got him using a password manager yesterday. One password is what I have them using. It's five bucks a month for a family of five. You can share passwords, you can have your own individual passwords and it creates new passwords, but I got him all cleaned up.

And when you're talking about this problem, Steve, with VPN and businesses, and do we understand all of this? Here's the guy that hangs out with me. Okay. I'm talking to pump his stuff all the time. I don't just play this on the radio. This is what I do. And he still hadn't done it cause it was April, it was very confusing for him to try and figure this all out.

So the businesses that have their own VPN. That are properly protecting those VPNs with what's called nowadays zero trust, but those ones, Steve are quite safe. The ones that are not safe are these public ones where you sign up, you, you hear them advertise Norton VPN or this VPN, or that VPN uses our VPN super VPN free.

As we just found out, got removed from Google. Those are the ones that get really dangerous, but even the VPN services, the businesses are using internally have problems because a VPN is just a network. And anything attached to it can potentially get through. So businesses are really now finding the problems they have with the VPN because they're using just a low level one.

They don't have a really good next-generation firewall. Steve and the bad guys have taken control of home computers like my buddy's computer and have gone from the home computers through the VPN, and now attacked the business itself. And we're finding that more and more. We've got FBI warnings and everything else anyway, blah, blah, blah ramble.

Steve Fourni: [00:09:59] Oh, cause one more quick question on that before we get to another topic because I'm wondering if there's a way that, that people might be able to tell if one is legit or not. Like for instance, our company wifi is honestly, it's a pain in the rear to get on the thing. I have to put in this password, then they have to send a notification to my

Craig Peterson: [00:10:15] phone.

Then I have to hit it

Steve Fourni: [00:10:16] on that thing. And then I got to go back to the computer and I got, it's like a four-step process just to log on. Whereas maybe some of these places are just like, Oh, what's your name, Steve. Okay. You're in. Yay. Like maybe that's a, is that a flagger or are they all making it intense?

Craig Peterson: [00:10:31] There's just something I think is a norm across every industry. And that is incompetence around runs rampant in every profession. So at a company like iHeart, of course, you've got some really good people who are doing it right. Most of the time. And that's all I'm asking for is most of the time, but yeah, you're, I think your point is a great one.

If it's just, I log in with this password, if you're using Microsoft remote desktop to connect. Wow. That is being used like crazy by the bad guys out there. And then of course we have the huge act from last week where now it looks like Russia got into the federal government agencies. Tens of thousands of businesses affected here.

It's crazy

Steve Fourni: [00:11:17] talking with Craig Peterson, our tech guru, and one other topic before I wanted to let you go. Cause we are, we're talking about Russia and China. And now it looks like Kazic Stan wants in, on the action. What is happening over there?

Craig Peterson: [00:11:29] This is true in China as well, but yeah, Tasic Stan.

What they've done here now is they have it set up so that you have to install it. Some software from the government in order to go online. And what that software does, is it installs a key in the very least, you have to install this key on your computer. And that I was like, sound government, see everything anybody is doing now.

On ongoing, online, any of their citizens, anybody that installed stops on Google Mozilla. Those are the guys that make Firefox Apple and Microsoft have all joined forces now. And all of those browsers received updates recently that blocked this trick that the Kazakhstan government is playing on it. I'm going to use the term citizens here residents at the very least because it was sending all of their data in the clear for the government to read.

And just real quick, Steve. Met in the UN embassy last Mueller earlier this year, I got down in Washington, DC with an African government and they have a data center that is, was built by the Chinese. And we can talk about this one for hours. But they wanted to secure it in the bottom line is there is no way because governments like this Kazakhstan government, Chinese government that is now by the way, providing computer equipment all around the world have completely infiltrated all of those systems.

And now as part of this recovery, economic package out there, they are going to be helping smaller internet service providers. And that means some of our listeners here, Steve, and this area in the Northeast, they are going to help them buy plane pain, to rip and remove this Chinese equipment that has been found to be spying on all of us.

So that, I guess a little bit of good news, a trillion here, a trillion there, maybe some of it will go to good use.

Steve Fourni: [00:13:35] And if they put these efforts towards things like infrastructure, maybe the country of Kazakhstan would be in a little bit better shape. They just need to focus all this energy elsewhere, but that's another topic for another day,

Craig, you provide a wealth of knowledge and helpful information for folks, where can they go to get more of that information?

Craig Peterson: [00:13:55] The best place is probably to go to is Craig peterson.com. You'll see lots of stuff there. My podcasts are pretty much everywhere and of course, you can listen right here on TAG and W H Y N I think just those two stations right now, but you can listen right here. On Saturday or Sundays at 11:00 AM.

I knew I could get it straight. I haven't had my coffee yet.

Steve Fourni: [00:14:18] You know what that 11:00 AM on H Y N and leads right into sports Sunday with Steve Forni at noon. How about that, Craig? You and me back to back? How about that?

We'll talk we're, we're going to talk this week about Canada, not wanting to come to the US to play hockey.

So maybe you want to tune in for that one.

Craig Peterson: [00:14:31] Cause they don't want to. Your folks up there,

Steve Fourni: [00:14:35] Craig Peterson. Thanks so much for the time. We'll catch up.

Craig Peterson: [00:14:38] All right, bye-bye.

Steve Fourni: [00:14:39] And Merry Christmas too, by the way, Craig. Yeah, Merry Christmas. My friend there goes our buddy, Craig Peterson. Good stuff there. As always,

Craig Peterson: [00:14:45] I am planning on recording a new show for this weekend, so I'll keep an eye out for that and be back tomorrow.

Take care, everybody.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This week I am spending a bit of time discussing The huge hack on SolarWinds Orion Software and why we will be feeling the repercussions for years -- and yes it could have been prevented. Then we will talk a little bit more about Election fallout and how this hack might have something to do with it. Then Fire-Eye hack and New and Improved (well -- another variation) of Ransomware and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Gaming Over the Holidays? 7 Important Security Tips

  **Looking at Using a Contact-Tracing App? Contact-Tracing Apps Still Expose Users to Security, Privacy Issues**

          **Cyber Actors Target K-12 Distance Learning Education to Cause Disruptions and Steal Data**

  **Knowing What the Enemy Knows Is Key to Proper Defense**

Major Cybersecurity Vendor FireEye Breach -- Fallout Yet to Be Felt

New AdWare Silently Modifies Search Results

Ransomware gangs are getting faster at encrypting networks. That will make it harder to stop

                 **---**

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] In case you didn't hear, we have had a massive hack. We're going to be talking about that and what it means to you. What it means to the federal government. What it means to organizations that are using SolarWinds. Oh my

Hi everybody. Craig Peterson here. Had a great discussion this week with Mr. Matt Gagnon Wednesday morning, as we usually do, and we're going to continue that now. Let's get into it in a little bit more depth.

You probably heard me pounding on that table and it was just unbelievable because the bottom line here is these particular hacks were effective because these supposedly "Professional Security People" did not follow the basics. They didn't have the software configured according to the manufacturer of the software's specifications.

So number one, read the directions.

Number two, they didn't use the most basic of security controls that are out there.

You've got to watch these domains, capabilities, practices, processes. That's what we are always talking about in the cybersecurity business. They were not monitoring outbound connections. They didn't stop the call home stuff.

What I keep telling you guys, the easiest way to stop the spread of some of this nasty software is to use Cisco Umbrella. It's just that simple. Cisco Umbrella for just regular people is free. How could you get better than that?

When you get into the business level, which you cannot buy on their website. You can buy some very good stuff from the Umbrella website, from Cisco then you get a lot more features and fine-tuning and granularity and stuff.

If they had just been using Cisco Umbrella, that probably would have stopped the call home. That's what it does. Okay.

These are professional organizations that got hit here. Professional organizations.

We do not allow Willy nilly, outbound connections.

Some of these pieces of software pretend that they are a web browser and they just want to go to this website. If you're allowing your employees on your network to go Willy nilly, wherever they want online, you got some problems.

If you're just filtering for instance, Oh I'm not going to let them go to porn sites or something. Violence sites or Netflix to watch TV movies all day long. Instead of working, that's not good enough. That might help to keep them paying attention a little bit more to their work. I've found frankly, much of the time, they spend trying to figure out how to get around those filters. We catch people doing that all of the time. You have to talk to them and explain why the most dangerous parts of the internet, from a security standpoint, are the parts of the internet where you are going to have some of that nasty content that they might be looking at for. Once they understand that, usually they wake up and smarten up, et cetera, et cetera. But if that's all you're filtering for.

How are you going to know that there is a piece of Chinese back door software on your network, that's trying to get out? How are you going to know that there's a Russian back door trying to get out? Or there is a hacker that's in your network who is exfiltrating all of your data and then they're going to hold your data. Not quite hostage to where it used to be, but they're going to extort you and say, Hey, if you don't pay up, we're going to release all of this intellectual property to the internet.

The right way to do it is you only allow outbound connections to places they have to go for work.

We have a company, our client, just as an example, who is in the Department of Defense space. They are a subcontractor and they deal with parts for airplane engines, certain parts. As such, they have all kinds of federal regulations and those regulations mean that they can't have data that gets stolen, that gets exfiltrated, right? That's the whole idea. They're supposed to be secure. So what do we do in a case like that?

The people that work there can only get two websites that are approved. There websites of their suppliers. Their websites of their clients and that is all. They cannot go anywhere else. Why? Because part of the problem here is what just happened this week.

What happened this week with this massive order? This has only happened five times before in all of history. We'll talk about that, as well. What is this order? What happened is they tried to go out to some other websites.

Let's say they got infected, and their computer had some nasty-ware on there that was trying to call home. Just do its ET thing, call home. It tries to get out of the network using what looks to be an innocent little web connection. It gets there normally. But if we block everything except the website that they absolutely have to go to, that software is not gonna be able to get out of their network, is it?

This is not rocket science. Yet we've got 18,000 organizations that look like they got hit in this massive cyber attack. Massive. There's a company out there called SolarWinds. Now, SolarWinds we have used in the past. We stopped using them because of some of their practices. We just couldn't, in good conscience use them. Knowing what they were doing and how they were doing it.

But SolarWinds has this network management software. They have sold it to government agencies, massive companies, 499 of the Fortune 500 companies use SolarWinds. They have this network management product called Orion. Apparently, they like any other good little software vendor-provided updates.

The updates between March and June 2020 apparently had a little extra payload.

Now, the way these actors, the bad guys got this payload into SolarWinds software really shows that it was a Nation-State.

Now of course the media is out there saying Russia, which is what they usually do. You'd think it was probably more likely to be China. But you know what we'll probably never know because these people were very sophisticated. They basically reversed engineered a one-way hash function called SHA-1 which you should not be using anymore. It was thought to be relatively safe. They combined that with another vulnerability in a web server and in some software that supports the web server and is supported by the web server and bam they're in.

SolarWinds sent out updates to their clients. Those updates included updates and went to government agencies, all, but one Fortune 500 company, and over 22,000 managed services providers.

Now, we're going to talk about MSPs some more, and we've talked about them in the past. This is a big deal. Most businesses don't do the information technology function themselves. They might have somebody that's in charge of it, but that person is the person who goes out and tries to find somebody to take care of the systems or do an audit or whatever it might be that they're trying to do. That makes sense, I think. So that's what they're trying to do. But do they really know what they should do? What they shouldn't do? What should be done? What shouldn't be done? That's a subject that we'll take up a little bit later.

This compromised software was distributed as a software update to SolarWinds customers by SolarWinds. It turned out that their software had this payload in it that now allowed an as yet unknown bad guy to get into the networks.

Now there's a statement that was filed with the securities and exchange commission. I'm looking at it right now by SolarWinds corporation and talking about the Orion products. They say that SolarWinds believes that the Orion products downloaded, implemented, or updated during the relevant period, starting in March this year, contained the vulnerability. Orion products download implemented before the relevant period and not updated, did not contain the vulnerability. It goes on and on. It says SolarWinds values of privacy and security of its over 300,000 customers.

I can't believe that this would happen. So not only was SolarWinds caught up in this but so were many of their customers and you will find it interesting to know who some of their customers are because they have also been in the news lately for different reasons.

This is just fascinating. The biggest hack in recent history, and one, that's going to have consequences for years, literally years.

Make sure you visit me online. Craig peterson.com.

We've established that there was a hack. We've established that the media thinks Russia did it and so do many security consultants. We're not absolutely sure. We probably never will be.

What is this hack doing? How is SolarWinds tied into Dominion?

This hack has been absolutely scary as heck. One of the congressmen who got a briefing on Tuesday about what had been going on. Called this absolutely terrifying. Now that is a terrifying statement to make and the accusations are that Russian government hackers are responsible for this.

Now we've seen since March this software by SolarWinds called Orion, which was in place in 18,000 organizations, was compromised. Once it was in the network, it gave bad guys access to that network. Coming out this week on Thursday, we found that the feds have, in fact, said that yes, we were affected by this. Now affected, what does that mean? Ultimately, the pros and cons to this.

The list of affected US government agencies and entities include the Commerce Department, the Department of Homeland Security, the Pentagon, the Treasury Department, the US postal service, and the National Institutes of Health. Isn't that amazing actually it is institutes, right?

This is a long list of suspected Russian hacks into the US as well as many of our allies and other nations out there. This is very scary to hear that because Russia has been using hackers, they have been using bots, and they have had other means to try and influence elections in the United States and elsewhere.

Before this latest election, we had the Democrats saying our election that elected President Trump there was influenced was hacked by the Russians. And of course, as you know of investigations for four years, they never really found that Trump was colluding with Russia.

I think the focus was absolutely wrong in those investigations. It should have been on what happened with our elections? How safe is our election software? How about the hardware? How about the mechanisms that are in place? The federal government does have guidelines for this election vote tabulating software and hardware. They have error rates that are allowed just like they have so many mouse parts that can be in peanut butter. They have error rates that are far lower than are being reported, right now. Oh, thousands of times more ballots were rejected than were allowed by law. But nothing is happening. Nothing happened.

They investigated one person, one, man, basically President Trump. A number of other people were caught up in this investigation as they laid traps for people.

We did not do a major investigation into these systems. To me, that is absolutely inexcusable. Now we're seeing some other evidence that is something that I think we should be paying some attention to and that ties right into this hack of SolarWinds.

As I mentioned, all but one, of the Fortune 500 companies use their software. 18,000 different organizations installed the version of SolarWinds Orion products that were in fact known to not just be vulnerable, but have built into them hacking tools, which is just astounding to me.

Are we going to look into this now? Because looking right on this is from the Gateway Pundit.com. They went to dominion voting software. You can go to the homepage. They probably removed it by now, but it was there when I had a quick look on their website.

This emergency directive 21 dot 01. Very rare. Only has been issued five times in the last five years is saying remove all of this. Yet Dominion Voting is apparently a customer of SolarWinds and Dominion Voting brags about how they use SolarWinds. That is scary, very scary to me. Let's talk about what it does mean.

It does mean that our friends Dominion Voting, who has been accused of having terrible software, all the way through having major backdoors in their software. Our friends over Dominion Voting could well, have been completely compromised by that is SolarWinds attack. Completely compromised.

We don't know if they were but we do know that they were using it and they are the ones with our voting machines. This goes back to what I talked about last week, where I think there is only one solution to being able to be confident about votes.

Obviously, it's too late now to deal with all of the potential voter fraud, software errors, hardware failures that have occurred in past elections. It really is too late based on the evidence I've seen, to quote Attorney General Barr. But how about the future? How about we do an investigation into these companies that are providing us with the hardware and software. Or better yet, my solution is we have ballots printed. Those ballots have serial numbers on them with a very good check sum. All we do with those ballots is we scan them on regular commercial, industrial scanners that keep pictures of those votes. So we have a hard copy that we can go to at any time of the votes. We can analyze them. We can compare it to the vote counts, et cetera. We take those pictures now and we run them through very inexpensive software.

Very inexpensive, under a thousand dollars to buy a license for some of the software. What that software does is it looks at the images that were taken by these scanners. And it goes ahead and tallies votes. If we use two or three different software packages, they should pretty much agree. Our error rate should be less than one in a hundred thousand or maybe even a million. Should be pretty darn low. Then we hand tabulate a few of these just to double-check, make sure everything is all right. We now have hard counts.

People add up the counts and as always, you have election observers from the two major parties and the minor parties they're watching this whole process.

I am for absolute transparency here. I think all of those images of the votes should also be made available to anyone who wants to download them. This is the age of the internet. Why are we not making the images of the votes available for anyone who wants to look at them? Private individuals can tally the votes and come up with what should have happened, what the count should be.

You expect a little bit of variance, but absolute transparency. People add up those votes. It's all audited. There are cameras running, webcams 24 seven watching the voting machines. Watching the election workers. Streaming to anyone who cares to look. Now we have absolute transparency. Now we can believe the vote.

That I think is the only way we can handle this.

We're going to run through some checklists here about what gamers should be doing. If you're giving a video game or one of these consoles to maybe some of your kids. I don't dunno. Maybe your husband, maybe they are kids. We're all kids. What should they be looking for this year?

We are talking about this massive hack we've been talking about, and we're going to get into some other stuff right now. I wanted to mention one more thing. When we were just talking about this major hack may have been Russia, maybe China. Sometimes it's really hard to tell who it is. If these are good hackers and these are by the way were very good hackers.

SolarWinds I just can't hold them a hundred percent responsible for this hack because part of the problem was people not reading directions, not doing just the very basic practices that are established in the industry for trying to keep things safe.

So keep that in mind as well. But it is a huge problem. It's something we all have to pay a little bit of attention to.

I had a great question this week when I was on the radio, I was asked, Hey, please tell me that there are people in our government who are trying to do the same type of thing to other governments.

And you might've heard about what is it? I would call a person hack, right? This is what is called in the industry a honeypot. You probably heard about US Representative Eric Swalwell. He is a California politician, which makes a lot of sense. He has been in office since 2013 and he is also on a very. Interesting committee.

When we are talking about Representative Swalwell, his committee assignment includes him being on the Select Committee on Intelligence. Okay. Ranking member of its central intelligence agency subcommittee. He also retained his seat on the United States House Committee on science space and technology according to Wikipedia.

This is very scary because he fell for the oldest trick in the book. It also tells us just the links China will go to in order to hack our people, our country. Don't worry, we're going to tie all of this into our hackers. Okay.

He, as well as another politician from California. Yes indeed sitting us Senator she had a driver, I think it was for about 20 years who was a Chinese spy.

Eric Swalwell had this girlfriend and apparently, this happened when he was just a mayor before he had moved up to the house. Then, of course, moved into the intelligence committee. A lady who became his girlfriend was doing everything you might expect of a honeypot, a Chinese lady who was trying to get information out of him. I don't know what information he got she got out of him. He had a lot of information.

Now. If this were to happen to a Republican, of course, just by default, the morals of a Republican would be well. I really messed up. I'm sorry. I resign. At least resign from the intelligence committee, but I resign from Congress. That has happened before. Much different response. It's just amazing to watch from a Democrat and Republican.

Nancy Pelosi should have removed him from his very sensitive government positions. This guy has demonstrated that he can't keep his well, you know what I mean, and not reliable when it comes to secrets. Why hasn't the FBI said, I don't care what you say, Ms. Pelosi, we want this Congressman removed?

The big question is how did we find out about this? What ended up happening that brought us to the point where we realized that Eric Swalwell was a major security risk and was on the select intelligence committee? On oversight committees. Okay. It's scary, isn't it?

This ties into this whole hacking agenda. It looks like we might have been hacking, as well. I'd be shocked if we weren't. We have teams, red teams, in every branch of government, basically, that hack. That's what they do. They're hacking in order to see what weaknesses we have. But this has been barely reported at all.

This also happened last week. A major leak of official records from the Chinese communist party. Many of these Chinese communist party higher-ups are living and working in other countries, including the United States, Australia, United Kingdom of course, and this list that's been uncovered has about 2 million members of the Chinese communist party.

Now, remember these people have sworn an oath to do everything they can to protect and build up the communist party. Okay. This database lists names, party positions, dates of birth, national identification numbers, ethnicity, telephone numbers of these members.

Now. Australia Sky News on Sunday reported that the database quote "lifts the lid" on how the party operates under president and chairman Xi Jinping. The leak shows that the party branches are embedded in some of the world's biggest companies and even inside government agencies. Communist party branches have been set up inside Western companies, allowing the infiltration of those companies by CCP members who if called on are answerable directly to the communist party. To the chairman, the president himself.

So apparently along with the personal identifying details of almost 2 million communist party members, there are also details of 79,000 communist party branches. Many of them inside companies. Now there was some analysis done of this member, we've only had it for what about a week now, but the analysis has been done so far has been interesting, cause that's revealed that both Pfizer and AstraZeneca, both companies who have vaccines for this COVID virus both of these companies together employed 123 party loyalists.

There were more than 600 party members across 19 branches working at British banks, HSBC and standard chartered.

In 2016, in addition, the Daily Mail's reporting that firms with the defense industry interests, like Airbus, Boeing, and Rolls Royce employed hundreds of party members.

Now, when I found interesting is the response by the US media and the response by some of these companies. It's been reported that some of these companies, when they were alerted to the Chinese party membership of some of their people said "we're not interested in the political parties that our employees belong to."

Which is just shocking. We're not talking about basic parties here. We're talking about what effectively is an enemy of the United States and frankly, we're also looking at this hack as a declaration of war by Russia, by China.

China's done this before, too. In fact, we think they were behind another major hack you've heard of just a few years ago.

The PS five and Xbox series X apparently are almost impossible to get. Best Buy just can't get restock. But assuming you got one, what are some of the tips that you need to know? If you are playing games or your kids or grandkids are.

Video games, I've never gotten into them, but it's probably my generation. Back when I was a teenager, we had these text-based games that we would play sometimes. You're sitting in there on a teletype and you're typing into this computer over 110 bod modem. Oh, my gosh.

It was fun, so you were in a twisty maze of tunnels? I can't remember the exact wording and then you'd go left or right. And I never spent a whole lot of time on those things. Because I basically considered it a waste of time. I've played like Mario cart a couple of times when we got it for the kids and that's probably the extent of it. I've played with some of these video games that Apple has released now as part of their arcade product. I am shocked at how good they are. How good the. Resolution is. And the movement of the phone itself can be read by the game. Your phone is your controller. So if you play games on these video devices or on a PC of some sort or even a Mac. You're not too worried about availability because the software is easy, right? It doesn't cost much to duplicate that software. Probably doesn't even cost a penny, nowadays for the guys to download the game to someone. Of course, there are other charges and stuff involved, but it's just so easy to do.

So we're going to have a lot of them this year. Many of the people who are playing these games are the younger millennial generation, the Z generation, and both of them really have issues when it comes to security.

I mentioned this before in talking with my youngest son, about two weeks ago, about security. He just didn't seem to care. Now, we had given him a really good firewall router and a wifi system built into it. All kinds of processing that was going on. It was a Cisco device. Cisco firewall. It was analyzing everything coming into his network, everything going out from his network. It does a very good job of it. It had a limit of, I think, it was 250 megabits worth of data flowing through it. He said megabytes, and I'd have to look at the specs on it. Actually, I do think it's two hundred and 50 megabits and that particular device was great.

You're cruising the web. You have software of a machine gets infected, trying to get out. It'll shut it down just as all of this. His roommate, who calls himself a gamer, didn't like that at all. So he ordered a gigabit network coming in. It's a gigabit over RF cable modem, which is crazy. Cause you're not going to get it and we had previously explained, Hey, listen. Your biggest problem is going to be latency turnaround. It's not going to be the bandwidth. We showed him these statistics that our router had gathered that he never used more than 10 megabits of the worth of bandwidth, which is, pretty normal.

I've read some studies on it and 10 megabits, 20 megabits. That's the max that is used by these video games. He knew better, cause he's in his twenties, and he's a professional gamer, almost. Not that he makes money from it, but he's a professional gamer and he has been talking in the gaming community.

So rule number one is they don't need as much bandwidth as they think they need. What they need is a, basically a jitter-free line so that they can talk to their friends without any problems while they're playing the games. They need a very quick turnaround, so the round trip time needs to be fast.

I brought up with my son, Hey, listen. You realize that he went out and upgraded the line and then ripped out, while you were gone, the firewall. He put in a better one than handles a gigabit and of course, yeah, no better. The wifi that he has in the house that his friend purchased as his roommate, does not provide gigabit over the Wi-FI. It just doesn't happen. It can't happen on any of this consumer stuff when you get right down to it and you look at it hard, right?

Many companies are lying to us. They publish these specs. They give all of this data and it is so misleading. I said, this is a problem now because you have security at the bottom of the pile, when it comes to your network now. Anything that gets onto his machine is going to get onto yours. The firewall was actually a zero-trust basis and would not allow his friend's gaming computer to access his computer or anything else on the network that it wasn't explicitly allowed to access. And you do you know what he told me? He said he doesn't care.

Now. I don't know. So if this is your dad and you've been doing internet cybersecurity for 30 years, and you're just getting carried away type thing that you get from an under 30 five-year-old son.

I've got kids that are actually that age too. There certainly is a difference, a major difference. I don't know what it is, but the stats that I've seen in the studies I've read are showing that these younger millennials and generation Z, which this of our kids is right on that cusp, don't care about cybersecurity. Part of the reason is that they just have given up. Now, I've been fighting it for over 30 years. I haven't given up yet, but they have, it's just a fact of life.

Just like you have to be on social media and you have to post these pictures of your wonderful life. It's just crazy.

Here are seven tips and I got these from dark reading, a great website, but obviously, I'm going to comment on them a much different way than Dark Reading's approach to it.

But I really liked these points.

Number one, we've got to make sure our kids and ourselves understand that personal information needs to be kept personal. Now, I know every one of us in this country has had our data stolen. It's guaranteed. It hasn't all been stolen and it's from a snapshot in time.

For instance, the Equifax hack. Yes, indeed. That's pretty much everybody in this country, Canada, much of Europe's personal information. Our salaries, our home addresses, our social security numbers. Everything was stolen, but that's years ago. By the way, that was probably done by the Chinese communist party. Remember that they're socialists. We talked about this last week. They steal stuff. That's what they do because they just can't compete. They don't like competition. They want to sit on their hands for the most part. Now, China's done some interesting things. With trying to combine the ability to have some free trade with the government-controlled economy, right?

They're not just like we are. Not capitalists, they are not communist there. There's never, ever even with the Soviet Union and what happened in Venezuela and Cuba, they have never actually achieved pure communism.

We don't have pure capitalism here either. Don't let them share personal information, make sure they realize that every little bit of information they share, they may be sharing with a hacker. Someone that's going to break in. We had break-ins in our neighborhood. This was probably about five years ago. A bunch of break-ins bunch of stuff stolen. Our house at that time was never broken into. It turned out that it was a kid from the neighborhood whose family had moved out and he knew things about people in the neighborhood and when they worked and when they were taking vacations. So he came back in and he started stealing from the houses, he'd break into them and steal stuff. In some cases, apparently, kids had given him codes to be able to enter houses. It's amazing.

It reminds us again of another, a best practice. That we should be exercised in business and you need to exercise in your home as well. That is when someone leaves a job. What do you do? You shut down their accounts, do it all automatically. That's the way it should work. You archived their data so they can't get back in. Now we've seen instances where network people who had been doing network work at a business left and stole just tons of things, shut down networks, change passwords because that hadn't happened.

And in this case, It's a good idea to change the code on your door lock pretty frequently. Keep track of who has what code, right? Doesn't that make sense to you? Then on top of that, with these fancier new ones where you can use the Bluetooth, the cell phone To program it.

So you just bring the phone close to the door and it automatically unlocks, it gets more complicated. It's easy to set up, but we've got to make sure we erase them.

So number one, don't share personal information. The next one, obvious as heck. We talk about it all the time but take care of your home network. Don't do what my son did and put in a cheap router. My son's roommate did make sure it's secured using multi-factor authentication. Now there are some ways around some of this, so that's why I recommend you do not use texting for multi-factor authentication. Use something like DUO or 1password or Last Pass or Google Authenticator. It's really going to help.

Stay away from chats. Now, this is difficult because much of the social stuff that goes on with gaming is over chats that are built into these games. So just be careful when they're in chats because it is used by these honeypots and others to get personal information. Kids don't realize, Hey, listen, dad is a high up in this company and I probably shouldn't be talking about that because honeypot to go after our kids, to get at us.

Avoid third party stores, apps, turn off Universal Plug And Play. (UPNP) If you still have it on your network and beware of scams when playing online. So some good tips for the kids.

This latest declaration of war as it's been called may be bad enough for government agencies and bigger companies, and 22,000 managed services providers. But man ransomware.

Then follow up to our last hour, DNI, the Director of National Intelligence Ratcliffe was supposed to have come out with a report as of yesterday about the elections and about foreign interference. Because of disagreement within the National Intelligence Community, it did not get released, at least not yet. It should be out fairly soon.

The big talk and the disagreement between various people who are in the organization, one of those jobs for life things, right? The deep state as President Trump has called it. Is that how much involvement did China really have? How much involvement did Russia have? I strongly suspect. Russia had a lot of involvement here in hacking. In fact, even our voting machines, as we talked about in the last hour because of the SolarWinds hack. How about China? They're saying it looks like it could be a major influence and have had a big impact on the election, in a number of ways, but we're not going to get into that right now.

Those big hacks have been very successful against larger companies all, but one, of the Fortune 500 apparently was affected and some 22,000 managed services providers countrywide use it according to SolarWinds, about 18,000 businesses. Were using the affected or infected, depending on how you want to look at this, but using the affected software. That's a real big deal, frankly. How about you and me? What does it mean to us as business people, as home users, et cetera? I want you guys to understand this a little better, so I'm going to explain it and I appreciate all the comments I've had about how much you guys appreciate me doing a little deeper dive into this far deeper than most anyone else can. You get these guys on the radio that just talk about absolute fluff in technology. Mainly because they don't know any better. I've just been doing this for too long.

One of these commentators, a lady who's had her own radio show for years. Just amuses me to know she was a marketer for years before she got on the radio. Maybe that's why she's a lot more successful on the radio than I am, but I'm much more successful in tech than she is.

You as a regular end-user, you're probably not badly affected by this hack, this SolarWinds hack, and all of the subsequent hacks that happened. It's probably not a huge deal for you because your home computers were not running this Orion software from SolarWinds, and you're probably not using any of the other software that's out there. I'm continually reminding everybody and I'm covering this as well in my Windows Hardening Course, which's coming up soon.

When I was recording this week, it made me think about this a little bit, that you and I, as home users know better than to buy things like Norton and try and use them or some of these other antivirus products, because in this day and age with Windows 10, just not considering anything else in the network, but just the computer itself, you are probably best off using Windows Defender and making sure your computer stays up to date.

You also know if you want to spend a couple of bucks. There is some other good stuff out there that's going to help and one of those is Malwarebytes. In fact, I'm going to try and include a link to some of them Malwarebytes stuff this week. Malwarebytes is another good little piece of software to have, and how much I like Umbrella.

You'll find that online, of course, umbrella.com and you can get the free version. You can get the paid version. If you are a business, you need to talk to a reseller, like me, and have them set you up with the business version. Those three things are going to go a very long way.

Obviously, you need to lock down Windows and harden it. That's why we're doing this whole little course coming up here soon. If you are a business now you might be in some trouble. I have been saying now for three, four years, as well as the FBI has been saying this and I covered it in some of the FBI InfraGard webinars that I hosted. If you're an MSP, if you're a managed services provider or break-fix shop, in other words, if you take care of other peoples and more particularly businesses computers, you are a major target. You have to pull up your socks.

Now, the Department of Defense with this cybersecurity maturity thing that they've come out with CMMC. They have made it very obvious because he specifically says it that if you are a managed services provider, you have to meet the requirements that the Department of Defense is putting on to their customers or their suppliers. I think that makes a lot of sense.

If you are a managed services provider, you probably have pretty much, if not completely full access to your customer's computers and networks. So if you have a customer, that deals with the Portsmouth Naval shipyard, for instance, that is a Federal Government DOD facility and if those DOD contractors that are out there on base have to meet certain requirements for cybersecurity, you would expect that you as a managed services provider have to meet those same requirements.

The answer is yes, absolutely you do. We're talking about some serious policies and procedures, some serious hardware to help make sure everything's working right. Some serious monitoring of the hardware and the software and the alerts. It's a lot of work.

We've talked about it before. Basically, if you have less than 200 people, you probably can't afford it. There is no easy button when it comes to the NIST 800-171 or the CMMC standards. So you turn to one organization, that's a managed service security services provider and you expect that they are going to be able to take care of you. I don't think that's unreasonable.

What should you be doing? How can you have these guys take care of you? The answer is almost none of them can. No, they'll say so. They'll put a nice little logo up on their site and, Oh my gosh, aren't we just, Mr. Wonderful, Mrs. Wonderful. In reality, many of these companies know the buzz words. They know the key phrases, but they are not up to snuff when it comes to doing security or including their own security.

So they'll go to other vendors. They go to distributors, try and get some help. This goes back to how I started out here, talking about these tech shows, where the host really knows very little about the actual technology. You want someone that understands. If you want a good meal, you're going to go to one of these celebrity chefs. They know the business and they know the business from the start to the end. You're not going to go to a fry cook for Wendy's, in order to get a great meal. Now, you might get a decent meal.

So the Department of Defense is now pushing all of these standards down to the MSSP's. This is why we are actually a Master Managed Security Services provider. We provide security services through and for these Managed Services Providers, I think that just makes a whole lot of sense, but these companies have access to other businesses.

Computer networks have been under attack forever and this now proves my point I've been trying to make for years. Which is the SolarWinds attack was directed at 22,000 companies that call themselves Managed Services Providers. Why? Because that's where the money is, that's where the access, the keys to the kingdom are for so many companies and so many government agencies are these managed services provider.

Now, this is difficult because I promise this week to get something out about selecting a managed services provider. I have something, if you want a copy of it, make sure you email me ME@craigpeterson.com because I got a little checklist that I put together. It's one of these generic ones.

I'm not trying to say, Hey, you got to hire me. You know how that goes? Where they put out an RFP, requests for proposal and there's only one company in the whole world that could possibly meet all of those specific requirements. Been in business for 30.6 years, is located within two miles of us, et cetera, et cetera. No, that's not what this is. This is a real nice generic list that you can use to help evaluate anyone out there that is going to be helping you out with your security.

So whoever it was, the Russians, most likely knew what they were doing. So they got not only the 22,000 managed services providers that got them in their site, but they also got all of these government agencies, and all, but one, of the Fortune 500 is right there in their sites.

They are not stupid. This was a very difficult hack and they pulled it off. They would have been continuing to pull it off, frankly, for a very long time.

So if you outsource your IT, which you have to do, because that's the only easy way to get some real talent part-time, which is what most small businesses need. They don't need necessarily full-time on their staff, but they need full-time attention. and you got to pay attention.

Drop me an email. me@craigpeterson.com. I'll be sure to get it back to you.

Ransomware is no longer just the domain of basic hackers or even NationStates. Like what we saw with this massive SolarWinds hacks and targeting managed services provider. It is now changing ransomware in a big way.

What is behind the headlines and really helping people to try and understand it a little bit better? I've always been told I'm good at and something I do enjoy doing. I guess that's a good thing, right? For you guys, as well as for me.

Ransomware has been evolving over the years. We've talked about it here on the show before, but the idea behind ransomware that those people who aren't familiar with has changed from really one idea, now, to two core ideas.

So the first idea is the one you may be familiar with which is they get some malware on your computer. However, it might be, they might be sending an email phishing email, trying to trick you into clicking on something and then installing some software. It might be via a worm or a remote hack, right? It could be a little virus that gets in, but the idea behind ransomware is that it gets on your machine and then it phones home.

Some of this stuff is very fancy. You can go onto the dark web and you can find ransomware for cheap money. You can even buy ransomware as a service. So what you do is you send out the ransomware to email addresses, right? The ones you've bought or stolen or harvested from the internet. Another reason, by the way, you should never have your email addresses up on a website where it's easy for software to grab.

Ransomware as a service does everything. Some of these companies, my gosh, you pay them either a fixed fee or a fixed fee plus a percentage of your take and they'll run the whole gamut for you. They'll provide tech support for people who get ransomware.

Here's what will happen. That person clicked on that email. They installed that software that got the virus. There was a drive-by worm, whatever it might be and in the background now starts encrypting all of the major files. It looks for things like word docs and Excel spreadsheets, et cetera and it encrypts them all. It calls home first, nowadays, for instructions and tells the bad guys, "Hey, here's the key I'm using to do the encryption." It gets really fancy today. We'll get into that one in a minute.

Then it pops up on your screen. "Hey, all your files are encrypted. You got ransomware to contact us." It gives you an email address or something else to contact them with. It has a big takeaway. It says, "Hey, you've only got so many hours to contact us, or the ransom goes up and goes up" To try and get you to move, and then you will pay via Bitcoin. Almost always.

Which, by the way, has been driving up the value of Bitcoin. Because people have been buying it in order to pay ransoms. So that's what we're used to.

The newer ransomware does things a little bit differently. So it gets onto your machine in much the same way. But the next step that it takes once it's on your machine, is it starts looking at files and finding files and usually it'll wait because what it's doing at that point now is it's pumping, poking a hole out of your network, back to the main controller for the ransomware guys.

So it gets on your machine. It grabs the names of some of the files. It then connects back to home. It calls home. Once it's called home, it sends the names of your files and then it sits there. Now the ransomware guys are pretty busy actually. Cause so many people to fall for this stuff and haven't done what they needed to do to keep the ransomware out. The ransomware guys, usually within a few days, will then remote control your computer and they'll poke around and they'll find, Oh wow, here's client lists. Oh my gosh, personal information. I can sell that for as much as $20 a record. That's a lot of money, right? Especially for someone in Eastern Europe, which is where most of these things come from. Then what will happen is they will look around some more and they'll start trying to spread laterally, East, West, inside your network. So now they're inside your network and they say, Oh my gosh, there's 20, 30, 40, 50 machines in here. It'll try and infect these other machines using the same or different techniques where it tries to spread like a worm, or a little virus, going around inside your network. And then it says, Oh my gosh, this is a medical office. Oh my gosh, this is a Department of Defense manufacturer. It's. Oh, wow. Wow.

When they got all of these records, all of these data. They might find things like also bank account numbers and transfer numbers, ACH accounts. All of this stuff. That's what it's looking for. Now. It's doing all of this in the background. You don't realize what's happening. Your computers just work in a way at this point that is probably not even slow. Then the next step that they take is they decide, okay, what are we going to do? You know what? I think that we can extort money from this person if we pull these files. So they'll grab a bunch of files. They don't remove them from your computer. They just make a copy of them from the computer, from your file server or wherever they are in your network. It may be all of your files and may just be a few of them. Once they're done with that, they will either encrypt everything and hold for normal ransom or not.

If they hold you for normal ransom, the same normal stuff applies a little red screen comes up. Oh, you've got ransomware. We can help you fix it. Contact us, give us a copy of this number. Take a picture of the screen and then off you go buying Bitcoin and paying them off.

Remembering because you listened to this show that the Department of Justice may come after you if you pay the ransom for supporting terrorists and terrorist demands, but that's a separate issue.

Now you get your key to decrypt and according to the FBI, about half of the time, you'll get all your files back.

Okay. So far that all sounds pretty normal, but the next part is what they've been doing more recently, which is. Okay guys, thanks for paying that, by the way. We are a different company. We're a different group of bad guys, and we have copies of some of your files and unless you pay us. We're going to release those files out on the internet, the dark web, or maybe the regular web put them up in a paste bin or wherever they might want to put them.

Pastebin is a website that hosts these files, zip files, and other things with all kinds of information in it. That is obviously sensitive because why would you pay extortion otherwise? So that's what they do.

Secondarily, they try and get you to pay them to not release your data. Okay. So in many cases, you have paid twice, you paid once to decrypt the data you paid a second time in order to gain access to that data. Or excuse me, just stop other people from gaining access to your data.

Does that make sense to you guys? That's what they've been doing.

Now we've got a new scale that these ransomware guys have. They are really catching up quickly with the Nation States that we've been talking about earlier. These are called advanced persistent threat groups. Just the regular gangs now have stepped it up.

You can get this show and many others via podcast. Just go to my website, Craig peterson.com.

Ransomware has gone from being opportunistic over to the other side, where they may spend months or even years on a network and a business and a government. So we're going to talk about the East-West spread of ransomware.

We've had a major hack this week that has affected federal government agencies, all but one of the Fortune 500 agencies. It's affected 22,000 of these managed services providers potentially at least 18,000 organizations are confirmed with being affected by this.

We're thinking it's Russia, but who knows? You cannot really tell. In the last segment, we went through the major changes in ransomware over the years. As I mentioned, the intro, opportunism, that's been the name of the game. They just send out a lot of feelers. They do a lot of scanning and they find somebody that is just vulnerable. That's the bottom line. They want vulnerable businesses. Once they find a vulnerable business, they move to the next step. That next step in the past has been just encrypting everything so that you and I really have no way to respond to it.

It has gotten fancier. These advanced persistent threats are what the name implies. They're an advanced attack method. They're persistent. In other words, once they're on a network or on a machine, they stay there and there is a threat because of these ransomware groups, such as DAPL, painter, and revival. Have gotten on to the networks have been very targeted at what networks are trying to get onto.

They want networks of businesses and these cyber-criminal hackers find vulnerabilities on the networks as they move around inside the network. That's what East to West is moving around inside finding other vulnerabilities. They often spend months laying the groundwork to compromise the systems with ransomware before finally unleashing the attack and encrypting the network.

They've found that phase two, which was let's get on the network. Let's find the valuable files. Let's hold them for ransom. That just takes a long time. If they've stolen people's credentials, if they've stolen, social security, numbers, bank, account numbers, credit card numbers, et cetera. It takes a long time to sell them and get their money back. So they really aren't trying and to speed things up, frankly, spending months on a network isn't unheard of and it's become more and more common.

These threat groups will hide for even years before they are detected, if they're detected at all, their goal is surveillance of the network. Finding all of the weaknesses and then stealing sensitive data, rather than just making money right off the bat with ransomware. These groups are making millions of dollars per attack. It's become so effective that many businesses if you look at their filings with the security and exchange commissions, are buying Bitcoin in preparation for a ransom. Isn't that something, in other words, they expect a ransom to happen. So they're just buying Bitcoin. So they have it to pay if it happens. Okay.

So the there's been this transition from being opportunistic. Into the types of threats, we've seen from NationStates here for years. It is much more profitable for these bad guys to completely cover an organization with ransomware. Now, remember that's not necessarily the primary target, but it's also a really good cover for them because now you're trying to deal with the ransomware threat.

So what do you do if you have ransomware? The best thing is don't get it in the first place. We've gone over that quite a few times here on the show, but the basics: Make sure you're running windows defender, Make sure that you are using Umbrella, so they have a hard time calling home.

Make sure you go on to the next stage as well. Maybe add Malwarebytes.

You also have to protect that network. I am a Cisco reseller and we have techs that are fire jumper certified. We know what happens. We can come in afterward and do clean up. This, unfortunately, is how we pick up most of our customers. Or we can go in beforehand and help to protect you because you want to stop them from getting in.

The regular email filters just aren't enough. So we run it through just all kinds of tasks. We had an email from one of our clients here just about a week ago saying, Oh, I got this email. It seems to be fishing. How did that get through? Yeah, we stopped a thousand of those. It's types of emails and one snuck through. Nothing's perfect.

We've got to remember that as well. So if it does get in someone bringing in a thumb drive from home or using the VPN into the office, that hasn't been properly protected. Most of them aren't, by the way, everybody that gets in, what do you do then? Hopefully, you have a good backup. You're probably going to have to wipe all of your machines. Depending on the threat involved, that might be pretty difficult because they can get into different parts of the machine that you just can't get them out of.

The next evolution of ransomware is that these groups gain more experience with these successful attacks. That time where they're taking between that initial compromise could be months or even years, that amount of time will become much shorter. Meaning there's less time to potentially detect this suspicious activity before it's too late.

We know from what Talos has been reporting, as well as others, that the compromise timeframe where they poke around inside your network is nowadays somewhere between three and five days. So you have a few days to catch them in your network.

Now, if you don't notice them, well it's probably a little bit too late, but again, hopefully, have good backups.

Having good backups means, by the way, the three, two, one principle on backups. It means that you need to be testing them as well. Make sure you can restore your business from backup and you might even want to do what we've done for our bigger clients, a one a multi-national where we had backup hardware there at their facilities. So if something were to happen, let's say that there was a fire in the front part of their building, where their main data center was, we could transfer all operations to the back part of the building, where we had our own servers sitting there that could take over at an instant notice. Then we also have servers in the cloud that have all of their data. In an attempt to keep them up to date in almost real-time so they can stay in business. That's what you need to do. If you're going to survive ransomware.

Now there are also normal things. Make sure you're applying security patches to everything. Make sure you are using multiple network segments that can not communicate with each other. So for instance, your building control systems should be on a completely different network than your office workers' computers, and those computers should be on a completely different network than this server. They should be going through a firewall to get to the server and an internal one.

You should have multiple layers of firewalls. In this company, I'm thinking of, this multi-national, we have seven layers of firewalls that you have to pass through in some cases, depending on where you are. That helps keep them out. Okay.

The security patches you got to do, you've got to patch all of your internet of things devices.

You cannot let people bring personal devices in. It just goes on and on.

These are the types of controls, the best practices that we need to have. All right.

You've probably heard of contact-tracing apps. Who knows what's going to happen with that virus over the next year or two years or what viruses might be coming after that. We're going to talk about the safety of the apps themselves.

One of the big things that have been pushed in many parts of the world is contact tracing. Some states require us if we go to a restaurant to give our name, right? To give our phone number for contact. If there was someone at the restaurant who calls up the restaurant and says, "yeah, Hey, I came down with COVID-19 symptoms", then the restaurant's supposed to call up everybody who was there at the restaurant. Now, how effective is that? I really don't know.

It's people, I would not want to give my information to people. I think we should just assume that we're living in a world with viruses and we should take precautions. If I was in the groups, one of the groups that were very susceptible to the virus. I think I would take a lot more precautions and frankly, isn't that the way it should be. If you are susceptible, then maybe you should lockdown. Not shut down - locked down, everybody else.

We've never done anything quite this way before. You find typhoid Mary, and she gets quarantined, not everybody else. That's always the way we've done it. And it just makes a lot of sense.

One of the proposals that have come out that they're saying, Hey, this is going to help us in the today and into the future, are these contact tracing apps? I'm looking at an article right now that was over on dark reading saying that they tested nearly 100 contact tracing apps. Now, these are apps that are on your smartphone that might use Bluetooth for proximity detection to another phone. They might use some other technologies. I've seen some that actually start to squeal and make noise. If you get close to somebody else that's running one of these apps. So that, okay, I'm within the one-meter limit.

Of the nearly a hundred they tested, they found 40% had significant security issues. Either using GPS locations or Bluetooth proximity detection in order to determine your potential exposure to somebody else. Now, these are mostly apps that are not using this new Apple and Google exposure notifications protocol. I found that kind of interesting Apple has been very good at trying to preserve our privacy. In fact, there's a huge fight already going on between Facebook and Apple. If you have the latest version of iOS, you can go into the app store, look at an app, and I would challenge you to do that.

If you've got your phone right now, iOS phone, and you're up to date, open up the app store search for the Facebook app. Then once you're on the Facebook app page, scroll down a little bit and it'll have a section in there on security that goes on for pages and pages. Yeah. More button. Okay. Read more of what it is that Facebook is doing with your data. So Facebook's pretty upset about that saying this is going to hurt small businesses who need to micro-target, and they're not wrong about that. Apple is saying, Hey, we're trying to preserve the privacy and security of people who use Apple equipment, which I absolutely do agree with.

Well, a company known as Guardsquare, which is a mobile security firm analyzed 75 contact tracing apps, 52 Android apps, and 43 iOS apps and found that 40% did not use the Apple Google protocol that Apple and Google worked together on this to come out with.

The bottom line here, what is it is going to be safe? How can we protect user privacy? This protocol is designed to protect it. Most of those applications used GPS system data too. Figure out your location of other people and linked it to the phone numbers or in some cases, passport identifiers.

Now, GPS can be fairly accurate, but if you want it really accurate, you have to add to some other data that is transmitted by all major airports, because there's a variance. The density of the atmosphere, which can vary depending on whether it's raining, how much water is in the air, snow, and other things. They transmit variances that can be used in conjunction with GPS to get an actual, accurate location. Once you get into a building or have you ever been inside a big city and found all of a sudden your GPS data is just terrible. Your automatic map stuff just isn't working, right? Those big buildings are blocking the signals from some of the satellites that you are depending on. That's what they have found with these apps. Many of them are trying to use GPS. They are gathering that and keeping the information and selling the information, which is a bad thing. It's not terribly accurate. Okay.

So first off don't use these apps at all. If you're in one of the risk groups, You are also now relying on other people to have the same app or the same protocol being used in order for your app to do any good at all, because they are combining the data from everyone that's self-reporting in an area to figure out if there's potential exposure. If they're not self-reporting, if they don't have that same app, you're not going to get any information.

So in June, Guardsquare looked at 17 different Android apps and found only one that fully encrypted and obfuscated data.

They have done a survey here in the last month and it has gotten a little bit better, but of those 95 apps, they found 32 Android apps and 25 iOS apps actually use the official API of the exposure notification system created by Apple and Google.

So bottom line, don't use these contract contact tracing apps. They're not useful. They're not useful, if not enough, people are using them. Then to top it off, they are not encrypting the data and anonymizing the data.

FireEye, man, this is the company that found out about that SolarWinds breach that we spent the first hour talking about today. FireEye is a security research company. Part of what you should be doing and is required to do is to have red team blue team exercises. What that means is you have people who are attacking your network, and then you have people who are defending the network. So you have a team of people whose goal is to break in and another team whose goal is to defend. You might remember. I talked to him about a company that hadn't been hired to do this out. Where was it? Missouri or something. They tried to break into the courthouse that they had been hired to test. Then there was a dispute over turf and everything else, and these guys went to jail and they had to go to court. The whole thing was quite the mass. Okay.

That's a red team- blue team type strategy. We don't do physical incursions ourselves. It's just a little bit too risky for us. It takes more people more time, but we do the type of Computer incursions and FireEye has red team tools that are used to break in. That is a problem because FireEye was compromised as part of this SolarWinds hack. Their tools were stolen. These are the FireEye red team tools that are used by their security teams to break into businesses. This is the gift that's going to keep on giving.

You might remember the NSA was broken into and their red team tools were stolen. The tools they use to monitor foreign governments and officials hack into computers. Well, this is a real problem. Okay. Many of these red team tools that were stolen from FireEye have already been released to the community and there's even an open-source virtual machine called commandoVM. Just absolutely unreal.

Apparently, none of the red team tools that were stolen by the attacker contain zero-day exploits and they apply well-known methods to break in. In other words, if you had been patching your systems, taking care of it, unlike what happened with so many companies out there. Right?

Home Depot, what happened to them? The TJX community of businesses, Equifax on and on Who did not keep up with best practices or even patches you might be okay. But if you are more of a security guy, like I am they have released hundreds of countermeasures that you can use, including things like Open IOC, Yara, Snort, ClamAV, all tools that we use here as well. There's a whole FireEye git hub repository. Git Hub is where people can distribute software and things. It's usually used by the open-source community and they've got directions and what you can do and everything else. So I think FireEye has responded extremely well to this. It's going to hurt their business. No doubt. It's going to hurt a lot of other businesses. No doubt, but I really like what they have done and you can look it all up online.

If you want a little more information. Just email me ME@craigpeterson.com and it might be time for me to put together with other, a little course, Oh, maybe a big course on how to use these tools to test your own security as well as to defend your security.

That's it for today. Thanks for joining me. Make sure you join me online as well. craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Chris Ryan on NH Today. We talked about the Lockdown and the effects it is having on our kids and the amount of time they are spending online. I shared some tips about staying safe online, for kids, yourself, and our senior parents. Here we go with Chris.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Bad guys know this as well. And they've been taking this as an opportunity to get our kids to do things that, as parents, we really don't want them to do.

Hello everybody, Craig Peterson here. I was on this morning on New Hampshire today. I didn't realize it. There are actually got five stations or six stations in the network. It's pretty good.

Chris Ryan. He is a new host here. I don't know that he's permanent. I'm not sure they've found one permanent, yet. He's been doing radio for a lot of years. Pretty good guy. I've been listening to him this morning.

We had a quick chat about what should be going on with our kids and what are they doing online?

Many of us are looking to get them some of these online games and gaming. What should you do to really protect yourself. What's the one thing that you could do that's going to make all of the difference from a security standpoint, whether you are a home user or a business user.

So here we go with Mr. Ryan.

Chris Ryan: [00:01:02] Joined right now on the program by Craig Peterson joins us to discuss what's taking place in regards to technology, as well as, gaming here on the program today. Your kids, boys, and girls, or anything like mine, the appropriate screen time went from one hour to 12 hours per day during the course of the pandemic. As Craig joins us.

Craig, how are you?

Craig Peterson: [00:01:23] Hey, good morning. There's a whole lot of screen time going on. A lot of bandwidth getting eaten up.

Chris Ryan: [00:01:28] There is. It's been both a blessing and a curse I think for most parents. It's been great that my 10 year has been able to talk with his friends and maintain levels of communication as they have not been able to partake in activities. But most parents have very little idea as to what their kids are doing. They're doing such at a much younger age with kids have tablets. They have the ability to communicate via the Xbox or PlayStation, in addition, to using messenger or other items as well. Parents or grandparents are mostly just in the dark and they don't know what to do about it.

Do you embrace it? Technology is so important. Kids learning how to code and to utilize those skill sets can be extremely beneficial down the road. Many times I think of our parents or grandparents, when they don't understand something. They want to be apprehensive about it.

Craig Peterson: [00:02:19] Well, first of all here, we've got the little gift-giving season coming up. Many people are looking for these video game consoles. The bottom line is pretty much all of them are sold out already. So if you're looking to get someone one of these video game consoles to play online, you might have a very hard time getting them. Many of them are being sold at a substantial premium over even the list price.

When we're talking about these kids and going online and being younger and younger. We actually have a problem starting primarily with generation Z, which is now in their twenties and going all the way down where they just don't understand the reality of the world. Their world is very, very focused on this online world.

Talking with friends, chatting with friends while they are on playing these games and they are ready to share information. In fact, Chris, you or I, we would look at giving away our email address twice or three times, our personal private information. But studies have shown that these younger kids would give away their email address in exchange for a donut.

So, yeah, you're right. We gotta be very careful about what they're doing online and the basic tips of don't share your personal information. Make sure that your home network is relatively safe, that means to keep everything up to date. Have a good firewall. Use multi-factor authentication. This is a hard one because, man, I don't know what's going to happen to these poor kids because of the lockdown. They want to reach out. They want to chat. Bottom line, bad guys know this as well and they've been taking this as an opportunity to get our kids to do things as parents we really don't want them to do.

Chris Ryan: [00:04:14] And I think that's across the board. In some cases, I think that I trust kids more with maintaining information and not talking to individuals than I trust my dad to be in cyberspace and exposing himself.

Not exposing himself physically, but exposing his information and things of that nature to various individuals. I think that's a good point and not just for kids, but across the board, as we have moved into a virtual environment. You have individuals in many different business aspects working from home.

I think that we all have to be cognizant of making sure that our information is safe. So what in your view are some of the best ways to do so. Basically cause I think that hackers, as you mentioned, a tremendous knowledge of what's taking place. What's vulnerable and things of that nature. What can we do to protect ourselves in your view?

Craig Peterson: [00:05:04] Well, you mentioned for instance, your father. And I had an instance with my dad who was having problems with his computer and he had gone online. He did some searches and he called a phone number. It turned out it was hackers who had a website up that looked like it was Microsoft support. It wasn't. They got onto his machine with his help. He keeps all of his usernames, passwords, bank account information in a spreadsheet, which is such a no-no. That's what these guys were looking for.

My stepmother called me up almost right away and said, wait a minute, this is what your dad is doing. We had them cut the conversation. We got on his machine, remotely, and removed this malware that was grabbing all of his documents and spreadsheets and everything. It would have been absolutely horrible.

I think that's one of the biggest tips I have for people, besides all of the normal up-to-date and good firewalls is to use multi-factor authentication. Use a password manager. I recommend looking at LastPass is one of them. The other one, the one that I use, and I use for my business is called one password.

Both of those will generate passwords for you for each website. They will store the passwords, highly encrypted. So that it's almost impossible for the bad guys to get access to it. You only have to remember one password and that's the password to this little vault that has been created, and they also provide this multifactor or two-factor authentication.

So that's probably the best tip for the holidays. Do yourself a favor Last Pass and one password, both have free versions. Start putting all of your passwords into that kind of a vault. Have it generate a random password for you and you'll be much, much safer.

Chris Ryan: [00:07:01] Well, Craig, I appreciate your time. Look forward to chatting again soon.

Craig Peterson: [00:07:03] All right. Take care. Chris

Chris Ryan: [00:07:04] Craig Peterson, joining us here on Hampshire today. I am Chris Ryan. Justin McIssac joining across the great state of New Hampshire.

Craig Peterson: [00:07:12] Karen and I spend time this weekend going through some of the coursework. What we should be doing. You probably noticed some changes in the newsletter. I did not get one out. I'm so sorry on Saturday, but it's just been absolutely crazy around here.

we're trying to do some new things for the new year. We'll be starting as soon as we possibly can. Including some of these courses that we've been talking about you. Might've noticed last week in my newsletter, I talked about the new hardening courses.

We're also, by the way, this is something new. We're what's called a Master Managed Security Services Provider. What that means is we are providing security services through these break-fix shops and these managed services providers for their clients. We've been doing this now, effectively for a room six months, maybe a bit longer, and have had just amazing results. Have really helped our partners that are providing security services. we're kind of the man behind the curtain if you will. Because the cybersecurity stuff can just be very, very difficult to do.

We're going to have a newsletter for those people who are following me, and that's going to be a different one than the main one.

If you are interested in this security partner newsletter where we're going to be doing some basic training, but specifically on providing security services for businesses. If you're interested in that, let me know, just email me M E@craigpeterson.com and I'll get back to you soon.

Take care, everybody, and we'll be talking again real soon.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This week I am spending a bit of time discussing H1B Visas and Facebook's war on American Workers, Extortionware, and how it is the death knell for Companies. We have a Cybersecurity Pandemic underway courtesy of the Covid-19 pandemic and More so be sure to Listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

---

Facebook Hires Foreign Workers Over US Workers - Breaking the Law

  Security's Worst Fore? Adobe Flash Finally Killed

          Business Email Comprise vs Email Account Compromise

  Extortionware Gains Traction and Kmart is Hit

          Alaskan Voting Servers Hacked

  Local Police Live-Streaming Amazon Ring Cameras

  A Cyber Security Pandemic Has Started

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Feds are saying that Facebook broke US immigration laws. Flash, finally dying. Goodbye and good riddance Adobe. We're going to talk about business email compromise versus something a little bit newer and different, EACs.

Hi everybody Craig Peterson here. No, we're not going to get crazy with talking about some of the problems we're having with email. I really want to talk a bit about this because fear only goes so far.

A great, great article this week in the Wall Street Journal. We will be getting into it in a little bit.

How we can really help our family and our business associates when it comes to security. We're always hearing about, Oh my gosh, business email compromise. It's just been terrible. It's destroying our businesses, which it is. But the problem that we've been facing because of the way we've responded is that people are much less able really to get the work done because they have fears every time they turn around.

So we'll get into that a little bit more as well. I love this thing about the Nazi Enigma cipher machine that was found in the Baltic sea. At the end of world war two, the boats, the submarines particularly were all ordered to destroy them. So they threw them overboard thinking that would probably be good enough. Of course, we already had broken their cipher, no big deal there.

Kmart here. National business got a lot smaller and it just suffered a ransomware attack from a new form of ransomware. We'll talk a little bit about that.

We've got hackers now breaking into an Alaskan voter database. Grabbing information on a hundred thousand voters. Very big deal. We'll talk about that.

We'll also be talking about police and this program in one community. We talked about something about six months ago, that was spreading a little more nationally. One community and what they're going to be doing with ring cameras and live streaming your doorbell to the police department.

Then we are going to get into the next global crisis, which is a cybersecurity pandemic. It has gotten really bad out there. a shame, frankly.

Hey, you're listening to Craig Peterson. welcome. Did you know if you have one of those smart home devices you can listen right from there? I've got my Amazon echo tied in via Bluetooth speakers that we put into the roof of the kitchen. We had a water leak. We had to replace the roof in the kitchen. So while I was in there, let's put in some good speakers and I did. I've got a little Bluetooth module that I got in fact from Amazon that hooks right up to an amplifier that drives the speakers. I have an Amazon echo there in the kitchen too. very handy. So I've got it configured to use Bluetooth so that it uses the speakers up in the roof.

it's just, it's phenomenal. I do that all of the time.

let's get into our friends here over at Facebook. I have been talking for years about this whole H1B visa problem. It's been a problem in the tech industry. Primarily now there are other types of temporary worker visas that are used in other industries. For the most part, I think in most other industries, they're not misused. But in the US, it is very misused. It's crazy, frankly, when you get right down to it.

We have some of the top consulting companies in the country bringing in foreign workers. When we have US citizens that really could do the job, should do the job. By law, it has to be given to our US citizens versus these foreign workers. So really what is going on? Well, the justice department, just this Tuesday, alleged that Icon systems were routinely discriminating against US workers by posting job ads specifying a preference for applicants with temporary work visas. That company failed to consider at least a single US citizen applicant. This one person who applied to this discriminatory advertisement. It's a very big deal. Last week, the feds come out and sued Facebook in a very big way. They were arguing that Facebook hiring practices truly discriminated against US workers.

Now you might be asking yourself, first of all, why would they discriminate against US workers in preference for a foreign worker? the big answer to that, number one is these workers don't fall under all of the same rules and regulations that US workers do. You can mistreat them pretty badly. I've seen it done many times. That poor person who has been brought over from overseas at some potentially third world country, most likely a third world country is afraid to say anything because they don't want to lose their job. We know of cases that have been reported online again and again, where there were half a dozen, even a dozen people staying in a single apartment, working for some of these major giants. We're talking about big companies that can and do pay good money for US workers and certainly charge a lot.

I have really ranted and raved about some of these consulting firms who have gone in, have overbid on some of the stuff. This one that I'm thinking of, there was a proposal out, an RFP, basically from a company that had been a client of mine for 20 years. They were looking for someone to run their Microsoft infrastructure if you will. Mainly, their email server. They wanted this email server to be hosted by the company and maintained by the company.

Now, if you know how to do that stuff, it's pretty darn easy. This one consulting firm whose name you would recognize if you're in the computer business came in and bid twice. what we bid, twice as much. I really had to question it. I poked around and I found that, yeah, indeed, they were out golfing with the head of the division and we're buddy with them. So they got the job. Then I dug into it more and found out that they had one of the top rates of bringing in foreign workers on H1B visas. Those foreign workers were being paid up a fraction of what the US workers would have been paid then I would have paid.

So there they are charging twice what I was going to charge and paying their people about a fifth of what I had to pay my people.

In my case, my people are somewhere around a third of their time is spent in classes. Is spent on training. Is spent on exercises, red team, blue team stuff.

In these cases, they bring somebody who probably lied on their application. I certainly know a couple of them that absolutely misrepresented their skills. Can you tell, I'm just spitting mad here.

Off they go now saying, yeah, we can do all of this. Then they bring in the people to do the job cause they didn't even have the skills in-house.

come two months later, they, after having had that contract awarded this firm, had still not been able to get Microsoft's email server working. Two months later.

If much about this, it is not that hard. A few months after that, they finally had it all working and they were bouncing emails and wondering why are we bouncing emails?

They had us have a look at it. It was completely misconfigured. They didn't have some of the stuff done that needed to be done, like double reverse lookups and things because people don't want spam.

So if your email server is not properly configured, your emails are going to bounce. My head is throbbing just thinking about this, something we could have had up and running for them in a matter of a couple of weeks and would not have had any of the problems that they had.

Oh and by the way, their system crashed this exchange server, this email server, and they had no good backup at all.

What we had proposed to them was a complete failover where if one of the exchange servers went down, the other one would take over. They would actually both be running in parallel the rest of the time. So performance would have been better and we were still half the price. It just drives me crazy.

In this lawsuit against Facebook, that justice arguing that even though there are requirements to advertise the job, make sure Americans can apply and do apply for the job. You need to hire Americans first, apparently, that's not what they did. are required to place ads for permanent jobs in print publications. Candidates are supposed to submit their applications and they go into HR, that whole trick right?

The jobs had an average salary of more than 156,000 dollars a year, which by the way, is the poverty level out in the Bay area. Yet out of 1100 jobs posted between July 2018 and April 2019, 99% received no applicants or just a single applicant, which means, yes indeed, they were hiding these specific jobs.

It's just crazy. They had another one where they had done it correctly and they had more than 2,600 applications for 22 jobs shows you what's going on over there. All right.

We've got a lot to cover today, but we're going to talk about something that changed the internet and is now going away.

Hey consider this, we're now close to the end of Flash. That software that we've used to watch little videos online and even training and two and a half percent of internet users are still using it every day.

Craig Peterson here. Thanks for being with me. I appreciate the time you're spending today.

A little bit of breaking news as the day turns here is a way to look at it apparently. I don't have a lot of information on this right now. We'll probably have a lot more next week, but the Federal Trade Commission along with 48 other States has filed suits to break up Instagram and WhatsApp from Facebook. Facebook bought both of those companies. We'll see what happens, This is probably not something that would change under a Biden administration, since it is 48 States that are suing. This is not the federal government suing them.

This has really been long-awaited. This whole antitrust lawsuit against Facebook because the allegations I think are pretty clear that Facebook has abused its power in the marketplace. It has neutralized competitors by acquisitions, as we have just seen here. I just mentioned, WhatsApp and Instagram. Buys them and then prevents anybody else from getting really into the market. What are you going to do? have a competitor that's great for Facebook and if you do, I'd love to hear from you.

But wow. How do you do this? Facebook isn't going to sell you information about their customers. How are you going to advertise? Facebook will take some advertisements for some competitive things, but overall there's been a lot of allegations that Facebook in fact will basically block any competitors from advertising.

So here's a quote from it. "By using its vast troves of data and money. Facebook has quashed or hindered what the company perceived as potential threats". That's from New York attorney general Letitia Ann "Tish" James who was the head of this 47 state coalition quote in an effort to maintain its market dominance.

Facebook has employed a strategy to impede competing services. Man, this goes back, right? Does it flashback here a hundred years ago? 150 years ago. What was going on? I would love to see this happen. I think the biggest problem, frankly, and this is my opinion, but the biggest problem is we bail out these big companies when they fail. Right too big to fail, we can't let GM go under, because just think of all of the people there, the union people, the employees. So instead of that, we keep these companies that should be failing alive and on life support. With somebody like Facebook, they have really just grown too far, too fast.

We've talked a lot about what should happen with their immunity from the prosecution about things that people post on their sites. Did you realize that in Europe, there are laws that require them to take down content that's offensive or that might be a little slanderous?

That's true here too. You can sue someone and have it taken down, but over there, it's government regulators. So this is an interesting story. I just wanted to pop that up cause that just broke mid-week this week. I think it was Wednesday. We do want to cover that in a lot more detail. It's going to be interesting.

Next, up here we are going to really delve into this whole Flash story. This was a technology that was badly needed in the day, and I'm afraid that the model that developed Flash. As I recall Adobe ended up buying Flash and then it took it over and ran with it. The business model that developed it, developed from something that is all too common, which is, Oh, wow, there is a market window we need to jump on this and we need to jump on this hard and fast. So people jump on it and they don't pay attention. In fact, when they first came out with this, they paid zero attention to Flash's security implications.

It's just absolutely. Terrible. It Flash is one of the worst pieces of software ever to plague our security. Our cybersecurity. Flash and Java both have had just horrific histories. Flash has become a software security killer. This is going to happen again and again, and it's what I've been bemoaning with Microsoft forever.

I remember working when it would have been in the nineties on the replacement, Microsoft operating system called Windows NT, their next technology. I worked on it in pre 1.0 days in some of the kernel stuff. It was patterned after an operating system called VMS, which was an operating system that DEC, digital equipment, had made.

It was designed to be secure. It had security holes, everything does, Some worse than others. Nowadays security is much better than it ever used to be, but it was designed after a real operating system versus just the quick get to market let's add every feature under the sun because of the way people buy things.

We should talk about that sometime too. It is a little infuriating. People look to eliminate things as opposed to looking for things they want. So if you're trying to buy a piece of software, if you want a word processor, are you going to buy one that has a hundred features, or are you going to buy one that has 20 features?

I don't probably want a hundred features. That's how most people do it. Even though Microsoft for decades, until you got to version four, it was said Microsoft software was pretty much useless because most of the features didn't work, but they were there.

Versus maybe you liked one of the alternatives I used to use WordStar way back in the day that just worked and worked well. It was innovative in so many ways that Microsoft just wasn't. Anyhow. We have been plagued by that Microsoft symptom for years and the same thing's true with Flash. Everybody knew Flash was bad. 10 years ago, Steve Jobs came out when he announced the iPhone had said, we will not run Flash.

There were a couple of reasons for it. It had to do with Postscript or PDF, if you will, files that Adobe had some patents on. Apple butting heads with it. You might remember that pre OS10 days, the Apple equipment all used postscript and in fact, it still does. Postscript still much better language in many ways than some of these others. Like what HP uses for printers. Anyhow. We're going down at another angle on another road here. They had some fights, but Steve Jobs was really adamant that because Flash was a major security problem, he says, I'm going to ban it from iOS devices. The letter was called thoughts on flash. It's still available online. If you'd be interested. And it came out in I think it was June of 2010, but it really pointed out how abysmal security track record Flash had even in 2010, and it's gotten worse.

Nowadays, if you are using Flash in your business, you need to move to HTML five, a much more modern, much more secure way of having little moving things or quizzes and things on your website. Take a look at it. There are ways to move.

I was talking with a friend of mine who was saying that all of their training is done using flash. It's been a real problem for them since they are a training company. We've gotta be careful. Developers need to be more careful. If you have software that you make or you distribute, you really got to look into it and make sure that they are paying attention to security.

We have a client that has third-party-developed software for their hardware and they weren't paying any attention to it and that lent some liability to them.

According to the FBI business, email compromise attacks were responsible for more than $26 billion in damages over the last three years. What is BEC? What has it evolved into nowadays?

You're listening to Craig Peterson here.

Getting down into business email compromises, two things I want to get to here. I'm going to talk about this BEC as well as email account compromise, which is also called the takeover. I also want to get into this great article that the Wall Street Journal had out this week on what you should do.

As a company and basically they're saying you should stop scaring employees, but I think you got to know the numbers. So we'll go through a little bit of that.

Email. We've been using it for years. I've had emails since 81, I think it was. So I've had email for a very long time on the internet since the early eighties, myself, and have just been around this stuff forever. I guess I grew up around it. talk about generation Z and millennials growing up around technology. I've been around it a very long time.

I remember way back in 1970 designing and making my own little computer from scratch that played chess? It was mostly switches, lights, and release. It has come a long way since then, but it's fascinating how it's evolved, and way back when, email was fun.

We used it to announce, Hey, we're doing to get together. We used it for some of the information sharing. So what do I do with this? I remember in some of the earlier days of the web saying, I'm having this problem with Sendmail, how do I get that working? Just so many things, it's been very useful. We had all kinds of fun threads over usenet and things. Man, the memories.

Nowadays email really can be awful. It is still the number one way we communicate, but there are so many varieties of spam now that are getting through to our email boxes. We have some filters, we have some special filters that have been designed by Cisco.

Even our clients who are using Microsoft exchange online version, where they're now calling it, what Microsoft Three 60 as opposed to Office Three 60, but Microsoft does not do a great job at eliminating spam and some pretty nasty stuff gets through. Even with those guys, we route it through our system Cisco email filter which just does a bang-up job and allows individuals to control it themselves.

Then it sends it off to Microsoft servers for that cloud email service Microsoft office offers as well as we filter it and we send it to other email servers.

We use Zimbra as one of them, and there are many others. We'll send them right to the customer. If the customer has their email on site, and there are legitimate reasons to still have it on-site and very legitimate ones.

This is important, everyone, because frankly if Email is coming through and it has spam in it, what are you going to do?

What are you going to do as a business, right? You want your workers to be vigilant. What do you do? The Wall Street Journal had some great examples. I've heard of these before, where there are people whose businesses have cyber awareness training.

And the employee knows. Okay. Well, this could be a phishing message, et cetera. Then, they will send out little tasks to see if someone opened this email. In some cases you open it three times, you open three of these spam emails, you're out of a job, they fire you. In some cases, some of these businesses are fining employees as much as half of their annual salaries. If you can imagine that it is just crazy.

There's a little study here that was done on the use of the fear factor when it comes to cybersecurity. Should you be just scaring your employees? Should you tell your employees, listen, you, we're going to trick you up, and if you fall for it three times, you're fired. What they're saying is no, don't do that. I do so agree with this.

I should come up with a little program on that. Hey here's what's going on. You really scare the heck out of an employee and it's going to leave them in a permanent state of uncertainty. It's almost like PTSD, frankly. Certainly, nothing like our men and women or the military can get from being in combat, but it is a type of post-traumatic stress disorder. The productivity's likely to plummet because the employees go to mistrust every email that arrives in the email box. And they're not sure if they click on a link, is it safe?

Am I being scammed here? really going on? Fear-based approaches do not encourage genuine watchfulness. Even when you look at these stats, $26 billion that was lost stolen in most cases over the last three years, that's still a very small percentage of how much income all of the businesses have when you put them all together.

Getting right down to it in the classic business email compromise, what they're trying to do is convince an email recipient that a message is coming from a legitimate trusted source, when in fact it's coming from a bad guy. They might have a misspelling in the domain name or something out that looks legitimate at first glance.

But most people, if you just spend an extra five seconds having a closer look at it, you'll see, Oh, wait a minute. Now, this is not legitimate. Okay. And I'm going to tell you what should happen as the next step here. But the other one and this is frankly, more of a problem because we're talking with this next one, about it, a legitimate email address where you've got an email account compromised where someone's email account has been taken over.

How do they take over the email account? they go in and look on the dark web and they find email addresses and password names, physical addresses, business names, Put it all together and then they try and log in as you. Using the passwords that they found online. So they might go to Gmail and login as your Gmail account using your passwords that you've used for the Gmail account on other services that have been compromised.

So now they've got access to your Gmail account. Now it could be your company x.com email account as well. They're doing it again and again. So they might be doing a password spray. They might be doing fishing malware to compromise email accounts. Okay. But ultimately they're gaining access to legitimate email boxes.

So once an attacker has access to the accounts, they can do all kinds of stuff. They can grab the emails that are in there with all of their attachments and. Download them. And technically that's called exfiltrating data. Sounds like a spy thing, but it read frankly, yes, they can change forwarding emails.

They might even put a silent forward in there that you never notice. And it's forwarding to them. You can see, they can now see emails between you and the other people in the office, knowing that you're going to be out on vacation and they use that against you. It goes. On and on. So a business, email compromise, and an email account compromise are related, but they're different threats.

And I want to tell you what the Wall Street Journal had to say here and add my two bets as to what you shouldn't be doing when it comes to. Emails and fishing and employee training and hanging them out to dry as some of these businesses that are obviously doing.

should we be scaring our employees to death over emails and phishing and account compromises? Or are there some better ways to do it, or maybe it really is a middle of the road solution that'll work? that's what we'll talk about right now.

Craig Peterson here. Thanks for joining me. If you're just tuning in.

We were just talking about the basics here of business email compromise, each account compromise, and how it has cost industry worldwide here over $26 billion. That's what the damage estimate is over the last three years, it is a very big deal.

You can also. Of course, just follow me on any of the major podcasting apps. Just look for Craig Peterson. You should find me on that good-looking guy. And, and then you can listen for about two hours every week.

If you subscribe to my podcasts. I mentioned our friends over at the Wall Street Journal. They had a very good article written by Karen Reno. And I assume she pronounces it the French way. Maybe it's reneod. I'm not sure how she pronounces it.

So we'll stick with the French way. Karen said that the problem is fear. Does not work. And she quotes a number of discoveries, including from Mark dupli, from the University of Washington. Yeah. Wow. French name again? about how it works. Yeah. In the short-term at the moment, but scare tactics, don't get people invested in security over the term.

And she was involved as well with Mark on this research that came out, I'm looking right now at it. You can actually grab it online. it's fascinating what they had to say here, but, a comprehensive look at what really motivates people, what motivates and behavioral changes, and how cybersecurity researchers are really starting to experiment with these fear appeals and what.

Will work for them, what can work from them? So let's get into that right now. I, of course, I fear makes sense to me as a business owner because frankly, I want to know what the stats are. I want to know what the hard numbers are. Is this something I need to be concerned about? I would say more than fearful of and what they found Karen and Mark is that fear can have the opposite effect on people than what's intended, because fear can leave employees in this continual state of anxiety. And that's in the last segment when I was mentioning post-traumatic stress disorder, that's along the same lines here. So when you are in that anxious state, You cannot think clearly about the threats.

So having the heavy-handed scare messaging can also take those employees to the point where they're very disgruntled and frankly, completely uninterested in security. People think the threats are exaggerated. Look at what's happened with all this over and over again. People seem to be. You just numb now to the security threats that are out there.

So let's dig first here into why they say fear does not work. And number one is it's a short-term emotion. And what we're really looking for is a long term solution, right? You work at home. You were working with, other people in the office, you as a business owner, what do you need to do? And it's long-term vigilance.

It's the real point of cybersecurity so that after this initial surge, the fear's going to wear off and convert to an understating of anxiety. we were constantly talking about using strong passwords. Using password managers like last pass and one password using multifactor authentication, like DUO or some of the others.

Okay. So they go into, I think, a great solution here, but. They say, consider Jane's told Jerry awareness training that any email could be an efficient message. That's true. Of course, it is. So if she clicks on an embedded link or opens an attached Tatcha and she learns that malware could be installed and she will lose all of the files on her machine and be the cause of a major cyber incident at her workplace.

Okay. So now she's in this permanent fear state too. She has uncertainty. She has anxiety. Her productivity is going to drop off the cliff because she mistrusts every email that arrives in your inbox. And she's not sure if she clicks a link in a message that she's not going to cause the whole business to fail.

So just looking at it from that aspect, the authors are saying that this fear-based approach does not encourage genuine watchfulness. And I can see that, frankly, I can see that's a really big point here. There's a book out there by Paul Brown and Joan Kingsley and Sue Patterson. And it's called the fear-free organization.

And they've got some great points in there about how the brains get fully occupied in dealing with this fear emotion, and it's like fight or flight. You lose your fine motor coordination when you're in fight or flight mode because you are now pumping adrenaline and you're ready to fight her or run okay.

Much the same things. True here. And then people also don't believe these fear appeals and Tony 20 in hindsight, there's gotta be a good phrase for that one, but, what a terrible year it's been, we all have fear in the government and the media. I've been continually putting more and more fear into us to the point where we just don't trust other people.

Because of the lockdown because of the fear they've engendered over this latest Coronavirus. one of the issues that emerged during their study was that while many people might believe in fear-based appeals too much, others think that the appeals exaggerate the risk in order to give the message more power.

So I, I mentioned this UK organization up to 50% of employees, salaries find for clicking on it. their organizations, you click on one of these little tests, messages that they send in three times and you're fired. It is terrible. David rock is suggesting in his research into the neuroscience of collaboration that any employee who's singled out already feels bad about being deceived and now gets what's the equivalent of the physical pain of being shamed.

One of these businesses even posted names of people who had fallen for these little tests and clicked on something, they shouldn't have clicked on that the business had sent out. They're even posting their names on the communal refrigerator. Okay. It's pretty sad what they're doing. And these businesses just don't seem to understand the harm they're doing to the employer, employee relationship.

So what works better? And I'm so glad the wall street journal put this in here and you know what I'm agreeing with this. And this article was forwarded to me by a friend who's in one of my masterminds, Walt. He was just phenomenal. And, my mom. Thoughts and prayers go out to Walt is his dad just passed away this week as well.

But, he must've been doing some reading and for this along, but what's the alternative. What is the other side of the coin to fear? And they're saying creativity and trust. So here's the trick giving you and employees more leeway and giving them the support that they need. Works a lot better than building up anxiety and creating frankly aversions to doing their jobs because whose job does not include opening emails.

They all don't they? So here's a more productive three-pronged approach. And this is from professor Sydney, Decker, the Griffith University in Australia. He's a former submarine captain, leadership expert, David Marquette as well here. They've all put it all together. And. They're saying create a buddy system.

Yeah. It's just like when we were kids and we were outside, And we were going on a trip to the museum or walking down the street to the park, that teachers, they assigned us all buddies and we stuck with our buddy. They're saying don't put people in a room and talk at them for hours about security.

Give them a buddy. Who's there to help them in the office every day to help them carry out the actions you want in the system. Instead of trying to train everybody. One employee in each department is appointed to serve as a cybersecurity expert. This employee is close by to support colleagues.

Day-to-day available to answer questions about things like potential phishing messages. And if the message does turn out to be a phishing message, the buddy can warn the rest of the department immediately, or they could help somebody with a question about how to send files outside the company. Securely many of our businesses, we have restrictions too on things like thumb drives and whether you can use them, if you can bring them in, I would, by the way, recommend if you are using thumb drives to get the drives that have encryption built-in that little thumbprint.

So I think this is phenomenal. The authors say that they have talked to some businesses that were doing this and he says, it's really worked well. They spoke to one of these cybersecurity experts. I don't remember. Experts right there, but they are the person that's been designated the expert within bat group within the business.

So he says first, he always thinks of the people that come to him for consulting with him. If the email's not a fish, he lets them know it's safe to click on the link, open the attachment. If it is a fish, he praises them. Their alertness. Now, all of this can also be mostly solved by really good email filters.

I'm talking about the cheap stuff, the stuff from Barracuda or some of these others that are out there. I'm talking about all levels of high-end email filters so that you rarely get. Any of these phishing emails. In fact, nowadays from our clients and we have hundreds of thousands of emails reprocess every week, we get maybe one fishing plain to every few weeks, maybe once a month, it can be done.

Take that pressure off your employees.

Coming up in this hour, we're going to talk about some old-school encryption, the Nazi enigma, cipher machine. Another one was found.

Kmart just suffered another major attack using a new way of doing this stuff.

We'll talk about Alaska's voter database stolen. You listening to Craig Peterson. Thanks for being with me today.

My thoughts about a massively open election system. I think part of the problem we have with the elections is the fact that it's really quite closed. We had complaints in some States of Republican poll Watchers, not being able to do their duty and see those ballots as they were counted and were put in with one candidate or another, or this scanning that happened when all of the observers had been sent home, along with the media. It is not a good thing at all.

Then there's, of course, were the machines tampered with? I heard all kinds of stuff. I saw stories about every vote for President Trump counted for 0.75 of a vote. Every vote for Biden counted for 1.25 and on. I think there is an extremely transparent way to do this.

That will actually save the states a ton of money. We're talking about tens of millions of dollars per state saved and will dramatically increase the confidence that people have in the vote. What really happened with the vote? Let me just explain this simply. Simple's best, I grew up in the mainframe world and then the Unix world, and in the Unix world, rather than having one program that does everything, the whole idea is you have small programs that are very good at what they do. They're optimized for performing a certain function like sorting for instance. They might show you the date or who knows what? There are thousands of these little programs that are available in the Unix world, and you can tie them together.

Now. Microsoft tried to adapt and adopt the same type of technology using pipes and it has it, but it's not the same as a Unix world. Classic Unix is how long tail? How narrow can we make the function of this one little program? For instance, let's just use GREP as an example. GREP is a global regular expression program. So the idea is if you want to look for a pattern in a file, you can just say grep space and the pattern you're looking for, like Biden, for instance, and poof out of the standard output right there on your screen will come to every record with the word Biden in it.

It was very good at doing what it was doing. It was programmed in C, some of it in fact, would have been programmed in machine language. Particularly some of the library routines to make them very efficient. People wanted the more fancy stuff, so we ended up with FGREP and EGREP all these different commands that did a different variation of searching for this pattern. But added things like Unix regular expressions, which have been adopted in many parts of the world.

What has not been adopted in Windows or now in the voting systems is that same concept. You get a machine like one of these ballot marking devices that are being sold and were used in the election this year that are far more complicated than certainly, these Unix commands we're just talking about.

So my proposal is let's go back to the basics and let's open it all up and make it so that the elections can be observed massively. Here's what my thinking is. This would absolutely work. If the State House wants me to go up and testify and put together some stuff, I'd be more than glad to.

Here are the basics. You've got your sheet to vote on. That sheet is the bubble sheet that many of us are used to. That bubble sheet you just fill it in with your little flair pen or whatever it might be. You fill in that little bubble for the person or people that you're looking to vote for or the cause you're supporting in a referendum or whatever it might be.

Then the State, County, or whoever's doing the counting uses a simple scanning machine. Now it could be a fancy one, right? It could be one of these machines that'll scan a thousand per second. I don't really care. I'll actually probably get that fast, hard to handle the paper that fast, but it could be a very fast scanner.

It could be something that's very simple as well, depending on how many of these votes you need to count. So you've got the card, you're feeding it into the scanner.

We're talking about commercial off-the-shelf, regular scanners that are creating images. So the scanner spits out a PNG image or whatever it might be. I don't really care. It's probably better not to have it compressed. Just have the raw image and use a very standard image format that anybody can read and understand. So that's part one.

We're not talking about these fancy ballot marking devices, where you've got an Android tablet that may not have been updated or Windows Seven or heaven forbid some are still kicking around Windows XP voting machines. And then you. You touch the screen and Oh, magical out comes a paper tape with the people you voted for with a little scanning UPC type code over on the side that you then take, and it's run through the other machine and now your votes been validated.

There are so many things that could go wrong with that. So many things it's, first of all, it's really expensive, cause we were talking about a specially built machine to tabulate votes.

It isn't just a scanner. It has been set up. It is looking for the votes in specific places and then it tabulates them. Do you know how many things can go wrong with that? Even with the ballot marking device that I mentioned you are now relying on that ballot marking device to have been correct. How many times have we heard voters say my vote was changed from Trump to Gore. Wow. You probably ever heard that one. It was interim Trump to Biden or whatever might be. This would eliminate that you've got the card.

So now the secretary state's office or the County, or the city, whoever might be doing this particular plebiscite, this particular election, whatever it might now have all of these images. So let's say it's got a million, just for lack of a better number of these images in there. So these are the votes.

What happens next is. All of those images are posted online and they're posted online so that anybody can grab a copy of those images and look at them.

So now we can look for identical votes. We can look for these votes that have been fed through the machine dozens of times, right? You've heard those allegations.

We can look for the votes that were pre-printed, the votes that were copied on a machine, and then run through. We can look for all of these. very easily. If we have the images of the vote is available of the ballots.

So obviously you keep the ballots. Obviously, you're going to want to do some hand counts just to verify everything.

We have images of all of these votes available to us. The Secretary of State or whomever now can run two or three different pieces of tabulation software that aren't going to cost them a hundred thousand dollars or millions as in the case of some of these, we're talking about 800 bucks to buy the software, buy a license, use the software.

So I'm saying use two or three different pieces of software because it's different. People are going to code it up differently. Make sure it really is different, not like dominion, where all of these different systems are using the exact same software under the hood with maybe a few modifications to make it work with their hardware.

Completely different systems. So there's going to be some value judgments that are made by the software saying, Oh, this looks like a smudge more than a vote. So software A says that and then it flags it as I don't know what the hell this is. Then software B looks at it, it says, Oh, this is clearly a vote for Craig and chalks up to Craig. Then what can happen is people can be sitting at a terminal and every one of these questionable votes can then be shown to them and they can figure it out. If the initial ballots were all serialized without some sort of a good check digit on them, you can actually dig them up and look at the original if you needed to.

Talking about just disclosing everything. Now people can download all of the images of all of the votes that were cast. They can easily write software that looks for all kinds of discrepancies and tabulate it themselves. Of course, there's going to be now a bunch of people that are going to say, Oh, no, that was wrong my software did it better, whatever it is, but at least there's something to discuss.

If votes are fed into the system, especially if they're all serialized with a really good checksum on them, we'll know. It'll be obvious to even the most casual of observers. We're no longer counting on software that may have been written in Venezuela. Maybe tabulated in Germany, whatever. It's run locally, and you and I can check and double-check the results of the election.

That's my proposal. Anyways. I haven't heard it anywhere else, but I think this makes a lot of sense.

We've got a lot more to talk about.

Hey, we really are going to get to it. Now, the old technology that almost helped the Nazis, the national socialists win the war in World War II, the German enigma cipher. Another machine was just found.

Craig Peterson here.

Let's get into this whole rusty story. This is very cool. There's a story that's out there right now about some guys that were out dragging the Baltic sea. Now, if you're not familiar with dragging and what that's all about.

A lot of fishermen drag the bottom with their nets in order to catch fish, right? Certain types of fish. And in this case, there were divers that were going around the bottom of the Baltic sea, looking for discarded fishing nets. Those draggers often they'll get caught on something. Subterranean might be a mountain, might be a ship.

It might be who knows what? It might even be a World war two national socialist encryption machine, which is exactly what happened. This is one of the rarest of finds down there an Enigma encryption machine.

These things were absolutely amazing. I remember reading about them, studying them. Trying to understand how this all worked way back when I was very young and I, in fact, was just so enthralled with it. I wrote some software that basically did the same sort of thing.

This was basically like a typewriter, think of it, like a typewriter. If you haven't seen one it's electromechanical. The idea with encryption is that you have to obscure or the meaning of something, So how do you do that? And there are many different types of encryption and you can bury messages, even in the clear, inside of other things. pictures have been used a lot. Video has been used a lot. There are a lot of ways to hide messages.

Of course, if you're a fan of some of the different spy books out there, you're familiar with the idea of a cold drop.

There are many ways to, get a message across. Let's just leave it at that now.

There have been ciphers like the railroad cipher. You guys might've heard of that. The idea behind the railroad cipher is that, just a simplified version. If the tech says A really means G. we, for years on Unix, if we had something that might be considered offensive, we would post it on there in what's called rot 13. Rot 13 is just shifting the alphabet, remember 26 letters in our alphabet. So A through N I think it was L M N a would become, M through Z or whatever the right split is. I don't even remember anymore. It's so you would type something up. You'd send it out. It was encrypted by rot 13. Now anybody could break this encryption.

It's very easy to do. In fact, the readers who we were using at the time, just you just hit one button and it would rot 13, eight again, because of course, if you split the alphabet in the middle, And you use the last half of the alphabet, meaning the first half and the first half translating to the last half. You just have to do that again to see what's going on.

So there've been a lot of simple ciphers used over the years. Some of the best ciphers of course are book ciphers or one-time pads, but those are not particularly useful in wartime, back in the day.

Nowadays we're using them a lot more. So what the Germans did is they invented this machine and it had three or more of these rotors in the machine. And as I said, it looked like a typewriter. So you would hit the letter a, if it was a railroad cipher that we talked about, it might come out as a G every time. So if I said, how are you today? If someone typed enough in the message was long enough when we had enough examples in order to break that encryption, all we'd have to do is look at the repeats here. How many times does the letter G show up? it shows up at the same frequency as a letter A, therefore we can assume that letter G and the encryption is really an A and solve it. The national socialists knew this, right? They didn't want other countries to know what the socialist government was doing and where they were directing the Wolfpack submarines to sink the British and American ships.

So what the socialists did is they had these three rotors and every time you typed a letter, the rotors would turn. So basically what you were doing is like the railroad cipher, where a is G, but the next time you, for instance, you typed two A's in the row. The next time you typed a letter, those rotors would've moved.

So a would no longer necessarily be G a might be Q. Now. And so what would happen is that little typewriter and Enigma device would have a little light that would show up under the letter Q so you'd know. Okay. Q. So they'd write it down and then they'd usually be sending it off by a Morris code. A is much easier to send than Q is, by the way. But they would send that out in Morse code, which is really neat.

The idea was they would start the rotors. Those three rotors would be started in a certain position. And that way, if you typed in that message, now that queue would become an E, et cetera. So there'd be a nice direct translation. They also were supposed to change those initial settings every so often in the codebooks, So the initial settings would be one way for a week. And then the next week they'd be a different way, but they got lazy and they stopped changing the codes. You might know that the whole story of what happened and how we broke the socialist code and how we were able to then defeat the socialists in World war II, which is just a phenomenal thing. Where they were trying to just gain power, gain power, gain power, and eventually try and take over the war world. So very cool.

And if you aren't familiar with this, if this is something that intrigues you, you do look it up. There are videos, it was a machine you can actually buy. I saw one on eBay, a German enigma machine that was not a real one. It was a reproduction, but they worked then and they still work. Now. They're actually pretty good.

We're doing much better now with our encryption, believe me. But it's funny, looking at this lead diverse statement, Florian Huber who told the DPA news agencies as a colleague swam up and said, there's a net with an old typewriter in it. They pulled it up and, had a look and the diver said that I've made many exciting and strange discoveries in the past 20 years, but I never dreamt, we would one day find one of the legendary enigma machines. The divers suspecting, and I think correctly here, that the enigma was lost shortly before the German socialists surrendered in May 1945.

At that time, the Nazi leaders issued an order for the submarines to be scuttled up in this Bay to prevent their capture by allied forces. They also tossed all of these enigma machines overboard.

So credit to Alan Turing, a phenomenal man, brilliant man, very troubled man, as well, but he was able to break the encryption. It's a fascinating story. Watch the movie about it. If you haven't. I absolutely enjoyed that movie. It was all kinds of breakthroughs that were made by scientists from the Polish Cipher Bureau that made it possible for the allies to decipher the messages about the German military movements. Absolutely fascinating.

Then of course you get into the second part of the problem. How do we use this information? Because we don't want the socialists to know. But we know what they're going to do next. It's fascinating.

We've got more coming right up. We're going to talk about a newer type of ransomware attack and how Kmart fell victim.

Hopefully, you got my email last week, my newsletter, where I went through the steps that the latest types of ransomware are taking in order to get even more money out of you. They got Kmart too. So here we go. I guess I don't have an I told you, so isn't it.

Craig Peterson here. Thanks for sharing your time with me this afternoon. I appreciate it. And if you have any questions, by all means, drop me a line. One of the questions I do have for you though, is what is it you enjoy most about the show? Let me know. Cause that's going to help me, help you with the show. Just email me ME@craigpeterson.com. What is it that you enjoy the most about the show? I've had lots of feedback from you guys over the years, and I'd love more. Make sure I keep up to date and get you guys the information you're interested in.

By the way, I also have some training courses coming up, so I'll make sure you keep an eye out for that. You'll find them in my newsletter when I have them. So make sure you're on that list. Craig peterson.com. If you want a copy of last week's newsletter about ransomware, just drop me a note. I'd be glad to forward you a copy. Just email me ME@craigpetersohn.com, and you'll get it. Me. Yeah. Just as the name implies.

Man, the poor guys at Kmart. Who remembers it, K-Mart used to be the place to go. The blue light specials. You'd keep an eye out for that. While you're in the store. It was really fun.

Reminds me of Sears in the day, going there. Do you remember, are you old enough to remember getting dressed up to go to Sears. Now, Oh my gosh, these poor companies. Sears owned, what was effectively the online shopping business, 120 years ago. The Sears catalog. Every year for Christmas or for birthdays or other special events. We would get a copy of the Sears catalog and we'd go through, we'd dog-ear pages, where there was stuff that we wanted.

Do kids even know what dog-ear pages are anymore? But dog-ear those pages and just enjoy dreaming of it. You could order a house on Sears catalog back in the day. Sears completely missed the online shopping revolution. They could have owned it. They had the distribution in place. They had the catalog technology in place. I knew how to do all of this stuff, but they decided they would stick with the old ways and, that didn't work out so well for them, but they still were doing better than Kmart. Kmart was going under and Sears bought them. Well, Sears holding company originally owned both Kmart and Sears.

Sears Holding Corp filed for bankruptcy in 2018. It was bought by this transform co in 2019 K-Mart, which was a household name that was multinational. I remember them in Canada. Is now down to 34 stores remaining. Isn't that amazing? I'm thinking about our local, K-Mart just, Oh my gosh. But it is still open. They still have the stores. They had originally over 2100 stores in all 50 States. It's a very sad time for Kmart. It really is. I'm looking at some pictures of some of the stores that are open right now. It's a problem. It's a real problem.

Now they've had another problem.

Bleeping computers reporting, and they also have some great articles. You can check them out@bleepingcomputer.com that Kmart suffered a cyber attack by the Egregor ransomware operation this week. Now they found at bleeping computer because they went to Transform Co human resources site, which is 88sears.com.

Now I went there this morning and it is online. It is their human resources page, but then when they brought it up, they found that indeed they were suffering an outage and they have posted bleeping computer on their website, a screenshot of that outage now, Egregor is known for stealing un-encrypted files before deploying the ransomware.

The bottom line is they're going to nail your twice. A lot of these bad guys. Nowadays, what they'll do is they'll grab your files. They'll download them and then they will encrypt them. And that isn't what Egregor does. And then they will put up then all too familiar, ransomware notice. You've seen it before, That red screen, demanding payment, and almost always in Bitcoin. And you can then hopefully find some Bitcoin, send them some money and you're off and running. And remember, I reported this a couple of weeks ago. If you pay a ransom, you could be in big trouble with the feds. And the reason for that is you are supporting terrorist organizations.

So you could indeed end up not only being sued by the Feds but going to jail over, paying a ransom. So think about that one. But they've escalated it now. So even if you pay the ransom or you don't pay the ransom, some other guy's going to come along. it's really the same people.

Okay. Some other guy's going to come along and say, Oh, guess what? I have your files. And they'll send you a list of the files and they'll probably send you some samples of some of the word docs or spreadsheets. And then they'll say, Pay up now, they're extorting you saying if you don't pay up. We are going to post your data online onto one of these data leaks sites.

And there are many of them. I'm looking at a list of them right now that bleeping computer is published, a through Z, and believe me, there are a lot of them out there. And so many of these look absolutely legitimate. Man alive. Do they ever, but with the Gregor, they will now say, I want to say, thanks for paying us the ransom on the encryption.

but they'll say, okay, now you owe us money or we'll post it on one of these sites and they do, and it's legitimate. Okay. What happened here apparently is that the bad guys targeted Kmart human resources website. And if it, if all of this is correct, Egregor would have stolen all of the data that was on that web server, about all of the employees within this.

Company. Okay. This transform co full name is Transformhold Co, LLC. So they are in some trouble. I'm sure if this really happened. And I've got to also add into all of this, that most of the time, these businesses don't actually know what was stolen because they don't have logs sufficient enough for logs at all.

To tell them exactly what happened. So a very big deal. It's a scary thing. And I went into it as well as what you can do about to help stop it in my newsletter last weekend. So if you miss that, have a look in your email box. If you need me to send another copy to you, just drop me a note me M E at Craig Peterson.

And I'd be glad to do that. But this is the next evolution and it works really well for businesses because think of the other angle, these bad guys have, they can get money from you. To give you the decryption key. They can get money from you in order to not release your data, which they may release anyway.

But they know who you are because they have your files. So they know you are a doctor's office and they'll charge you more. Or they know that you're a manufacturer in the DOD department of the defense supply chain. And so they'll extort even more out of view. Okay. very bad. yeah, it's a shame.

Good old Kmart. Oh, she's still around, I guess it'll be around for a little bit longer, but this sort of stuff is really happening. This can be the death nail and it is the death knell to the majority of companies. It happens too. Hey, stick around when we get back. Oh my goodness. I can't believe this.

We're going to talk about the Alaska voter database hack and more including police live streaming your Amazon Ring camera.

I guess our election system isn't as safe from hackers as we might've thought. We're going to talk about hackers breaking into an Alaska voter database.

We'll be talking about police piloting a program to live stream Amazon ring cameras and more.

Craig Peterson here. I talked about what I think the answer is to technology and the elections. In fact, what I described at the top of the hour would completely eliminate some of these major technology problems without a doubt.

This is a different type of problem from the gateway pundit.com, which you can find online.

Alaska state officials reported that hackers stole personal information for more than 100,000 individuals from the state voter database, that's a very big deal. Alaska is saying that information included birthdates driver's license numbers of more than a hundred thousand Alaskan voters.

If you think about these voting databases in most States, they are also going to contain your signature. They're going to have your home address. They're going to have a lot of information from you. Okay.

Now they stressed that there was no effect on the results of last month's election. Oh, okay. But your personal data was stolen and that's part of the reason I have such a problem with the driver's license databases as they are in most States. They also include things like your social security number now and think of these real ID licenses that are now being issued. I don't even want one of the silly things, but in most States, you're being forced into having one.

I've already got a passport, which is good enough for me to get in and out of the country. Why do I need one of these tamper-proof supposedly driver's licenses with all of the data that they're collecting? Think of what you have to do to get one of those things. You have to prove your residency. You have to prove all of this other stuff. I don't know. Maybe it's going to be a good thing for voting anyway, because if you have to present this type of ID, at least we know that you're legitimate.

Then there's California and that's a whole other issue.

It says the hackers gain unauthorized access to the data and the state's online voter registration system. It was built and maintained by a contractor and operated by the Alaska division of elections, goes on and on talks about the sad news.

So officials said the flaw that exposes the data has been fixed and Alaskan's information is now secure. Isn't that wonderful?

Now that the horse is out of the barn, they're going to close the doors, but it's still not known exactly which records were stolen. Again, that's a real problem. Most regulations that are out there for the private sector require us to know was stolen.

Oh, gay. let's keep all of that in mind. Just don't trust this stuff. I don't trust it to, the government. I don't trust it to, private companies. Look at what happened with Equifax. Basically, all of our personal information was stolen probably by the way, by the Chinese government. Anyhow, we talked about something similar to this next article fairly recently, and this is from eff.org electronic frontier foundation. They're very much a very pro-free speech place to a degree. As long as your speech agrees with them. But they want open software and, they do want to help keep more basic information safe, the civil libertarian side of things.

Let's see. So the police surveillance center in Jackson, Mississippi is going to be conducting a 45-day pilot program to live stream the security cameras in Jackson, Mississippi, including the Amazon ring cameras from residents who are participating. The idea behind this is it gives the police department real visibility, live visibility into neighborhoods.

So they can record it as well. They can play it back. If there are porch pirates, those people that are stealing our Amazon packages out there, they can hopefully find them. Of course, if there's a porch pirate that just stole your package. you've probably got them on tape, right?

So you can do a little bit of something about that. I have multiple cameras out there doing it, but the police want this live stream. Now there've been stories out there in the past about ring cameras being used by the police. in some cases, these stories have said that in the, in fact, the police departments, according to these guys have been doing it without a warrant.

in fact, that's going to be the case here again in Jackson, Mississippi, because people are going to be able to opt in to this program. So it sounds like they're trying to do some of the right things. There are concerns here from the EFF about rings 1000 plus partnerships with local police departments.

And that's kinda what I was talking about back in June this year, but there are a lot of people that are concerned about the police department, and you've probably heard of this socialist-communist in fact group called black lives matter. That has been out there protesting the police, defund the police, all of the things that have been promised to us about just drawing a lot of the local police departments. This is a real concern because people are buying ring cameras and these other cameras and putting them on the front door effectively to help keep the packages safe. The police are using them to build these comprehensive closed-circuit TV camera networks that are blanketing whole neighborhoods and it allows the police departments to get that type of video feed without having to buy surveillance equipment.

Think about what some of our local cities have done to put in surveillance cameras. It's really rather expensive. Then the second point here that E FF is making, is that evades the natural reaction of fear and distrust that many people would have if they saw cameras up on the street lights.

By the way, some of these new street lights do include cameras that are fed to the police department. Okay. So they are there, but they're hidden away. It's Oh, it's Joe's doorbell is basically what it is and it's supposedly. Going to be a little bit safer, but the police and these thousand different partnerships with different police departments now are allowing them to set up an array of cameras without anybody really noticing, by the way, Jackson.

Was the first city in the Southern United States to bland banned police use of face recognition technology. So they understand this invasive surveillance technology, but, in this case, maybe they've overstepped their bounds. They've got, also by the way, this national movement called community control over police surveillance.

See cops. These are different ordinances. The residents have put through legislatures in different States that have more say in whether or not please can build a program like this. I also have had concerns over the years about the ability to videotape or record, official police or otherwise in the performance of their duties.

Main is what is known as a single-party state, which means only one person who is part of that recording needs to be aware of the recording. And they, one person has to say, yeah, okay. I'm going to record, but the other person on the other end of the line or the other end of the camera doesn't have to say anything.

New Hampshire and many other states are two-party States. In other words, Both parties or all parties that are part of that recording have to consent to be recorded. So something like this ring system really could be a bit of a problem. And depending on the state you're in Maine, wouldn't be because you knew you had a camera up.

I think in most States, including New Hampshire, you would, which is a two-party state. I think you're are going to be safe enough because. You got a Ring doorbell with a camera. I think most people nowadays know that it could be recording what's going on and I have security cameras up as well. And you might want to do the same thing.

I use security cameras that meet the federal department of defense standards. Okay. they ain't feeding ring or anybody else out there, but it's something to seriously consider. the last article here before we disappear is about the cybersecurity pandemic that's going on right now. This is a scary thing.

It's a big thing. The next war is really worldwide going to be a hybrid war. We're already seeing that where businesses and governments are targeted by cyber attacks. There's espionage going on. I've told you about some of the clients I've picked up because something weird was happening and we looked into it and we found.

Direct evidence of espionage and got the FBI involved. That it's amazing what's going on. But the threat from hostile nations like China, Russia, Iran, and North Korea is really growing. And we've got our critical national infrastructure. Now such as your water, electricity plants that are relying on network connections and also.

for changing valves, opening, closing them as well as for monitoring, we've got these SCADA systems, which are also used for monitoring and control in our manufacturing plant. This is a bit of a problem. And particularly when we think now about all of these people that are at home, working from home, that may be connected to a business.

That is part of our critical national infrastructure and they don't have the right kinds of security. It's it is mind-blowing. Anyway, I'm thinking about doing something about this article we talked about earlier from the wall street journal, the buddy system. Where you can really increase the security of your business by using it.

I'm thinking, how can I help with that? I'm not sure yet we'll figure out how I can help you with that sort of thing. Maybe we should just have a little report line where you can send stuff and let me know, and I can respond. Let me know at me@craigpeterson.com and we'll be back next week.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started this morning talking about a radical new way to assure transparency and validity in our Elections. Then we got into the Cybersecurity Pandemic we are facing and how the COVID-19 pandemic brought it about. Here we go with Matt.

And more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Matt called it a radical idea this morning, and frankly, I think it is. I think I've come up with a way to fix one of our elections and technology's biggest problems.

Hey, Craig Peterson here. I was on with Mr. Matt Gagnon this morning over on WGAN and carried on other stations throughout Maine and down in New Hampshire. Anyhow, here we go with Matt.

I think this is an excellent idea. I'm going to have to do a little more about this thing.

Matt Gagnon: [00:00:36] Let's turn to Craig Peterson, our tech guru, and let's get some thoughts here on technology. Craig, how are you? This one?

Craig Peterson: [00:00:43] A good morning. And you know what? I've got some fonts on how to make this election go way more smoothly in the future.

Matt Gagnon: [00:00:49] Do you now?

Craig Peterson: [00:00:51] Yeah. We've got the internet today, and part of the problem, I'm not going to get into all of this, but we've got these machines in some States called ballot marking devices just on the technology side.

We have other machines that are just basic touchscreens, but a BMD, A ballot marking device, is one where you've got a tablet, and some of these are Android. Many of them are Android-based, which you already know. I'm not too fond of it from a security standpoint, and they will spit out a little ballot, a paper ballot that you can take. That ballot now says, Oh, you just voted for Joe Biden and Joan and Jane and whomever, and it has a bar code. That bar code is what's actually read by the machines for your vote.

There are so many questions. Yeah. It says, I voted for Biden but did my vote actually counts for him? I don't know what the barcode names. We've got the problems. Potentially the device, whether it's windows seven, which is used in a lot of these machines, Windows XP is still. Android et cetera.

Let's make this simple. These machines are costly. States are spending tens or even hundreds of millions of dollars. Buying them.

All we need to do is have a card just like we're used to voting on where you fill in the bubble. Then buy normal every day scanners, just off the shelf things, and make sure they're up to date. People do their voting. The machines then read the votes and now have an image. Obviously, there has to be a chain of custody, and everything else like you'd normally have. But most of the images now can just be run through some very inexpensive software. I found a company out there that has $800 software. That software does the grading.

Here's where the confidence in the vote I think would come in. You could then post all the ballots online for anyone, basically, to download that wants to download them.

Maybe even like to do a check on ballots where you have a couple of different people manually counting to make sure the machines are right. Why not use two or three?

Craig Peterson:[00:03:11] Three different pieces of software to grade those ballots. Then have people have a look at them. Have any voter that wants to examine the ballots examine them digitally, with, of course, all of the right chains of custody,

Matt Gagnon: [00:03:24] Radical transparency then is what's your,

Craig Peterson: [00:03:27] Absolutely, and it's cheap. It is way cheaper than what we're paying right now for these various machines.

Matt Gagnon: [00:03:34] Yeah, I remember I don't know how many years ago this was, but probably 2013, maybe even earlier than that. Yeah, no, it was earlier than that. It might've been like 2009. Now that I'm thinking of it.

When I was living in Virginia, I went to vote. The machine that I had there to vote on, I was blown away by it because I was used to the Maine system where you, you fill in bubbles on a piece of paper, and you feed it into the machine, and it does basically, what you just said outside of providing you images and stuff.

It had a scroll wheel. I felt like I was playing like Golden Tee or something. I had a scroll wheel and digital thing where I made my selections for whichever office it was, and I selected it. I pushed the button, and I had no physical interaction with a piece of paper or anything. It basically just said, thank you for voting.

Then I left. At the same time, I didn't really actually doubt that my vote was counted and all that other stuff. It did skeeze me out a little bit. It didn't feel real to me.

Craig Peterson: [00:04:20] I'd move beyond that. I think radical transparency is a way to do it. Even the machines that we use in Maine. They are special, dedicated, purpose-built voting machines. We don't need that. We really don't.

Anyhow. My opinion on it.

People could have a lot more confidence in the votes if we did something this simple and really observable by anybody.

Matt Gagnon: [00:04:45] That's a good suggestion. Oftentimes we try, in terms of simplicity here, we try to go more complicated and have more machines do more crazy things when something like this should be as easy and simple as possible with as much verifiable tracking as you could have.

To verify it is what it is, right? Yeah. But it's a, and it's a big topic. There's got to be some congressional action on voting in general soon. Whether you thought the election was stolen or you don't think it was stolen?

I would hope that most regular people, rational people, know that whatever we just lived through, it was probably not the best way to do it. So we'll see. We'll see.

So Craig, before I let you go, we got a couple of other topics to get to, that we've been talking about a pandemic, in our health, of course, for a while now. Is there also a cybersecurity pandemic that is running rampant around us now?

Craig Peterson: [00:05:30] Yeah, it's really become a huge problem because of the lockdowns, frankly. People working from home, the systems were never designed for this. Our cable carriers carrying most of our internet data from our homes are saying they've seen a four X increase in the amount of use. We've got machines at home that have who knows what, if any security or security stuff on them.

It's become a huge problem that the bad guys are really leveraging right now. They have, as you saw in my newsletter, this last weekend just changed their tactics. They are going, still for some of the ransom stuff, but now they're not just holding your data hostage by saying, Hey, listen, if you want your data back, pay up because it's all encrypted.

Now they're saying, Hey, if you don't pay up. We're going to release all of your data onto the internet. They may do it anyway.

During this whole lockdown crisis, we have really taken some major leaps forward in going online. I'd say probably 10 to 15 years in advance of what we would have done previously.

We not only have those bad guys, those criminals, but we've also now got Russia, China, and North Korea, and Iran that are all growing their capabilities, and they have been using it to attack us. As I've said before, we really have fired the first shots on world war three, and they are digital. They are probing for weaknesses, frankly.

In this day and age, we really do have a cybersecurity pandemic in our businesses. And a lot of it's caused by the lockdown and people working from home when the systems just were not set up for it.

Matt Gagnon: [00:07:20] Well, Craig Peterson, our tech guru, joins us at this time every week to go over technology in the world of technology.

He has a show on Saturdays. If you want to hear more, make sure you tune in for that on Saturday at one o'clock, where you can hear this and so many more topics gone into in greater depth.

Craig, I appreciate it as always, and we'll talk to you next week.

Craig Peterson: [00:07:38] Take care.

Matt Gagnon: [00:07:39] You bet.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the current Cybersecurity Pandemic and Phishing and what happened to Jim Polito, the host, this past week and then hit on travesty to the American worker through the H1B Visa program and how Facebook and other Big Tech is front and center with it. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Jim Polito: [00:00:00] I was afraid to answer the email. Cause I, I said, wow, has this been hacked. Have they been hacked? No, it was a valid email. Then I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here.

Craig Peterson: [00:00:21] Good morning, everybody.

Craig Peterson on with Mr. Jim Polito looks like we've picked up another station. That's kinda cool. W H J J, I think it is down in Rhode Island. Well, Jim picked it up, but I'm along for the ride. So that's kind of fun. We talked a little bit about that this morning. Jim's problem where he got hacked so we went into that.

We also got into H1B visas and how they are hurting badly the US job market, and between you and me, I'm very concerned about what Joe Biden's going to do if he takes office with this whole program. So we got into all of that this morning. And here we go with Mr. Jim Polito.

Jim Polito: [00:01:05] Here he is the man. Every Tuesday at this time he joins us. Boy, he got me out of a jam last week. I am talking about our tech talk guru and good friend, Craig Peterson, Craig say hello to Rhode Island. We are now the network has expanded to W H J J, a landmark and legacy station in Rhode Island.

Craig Peterson: [00:01:33] Hey, good morning, everybody. Man, Rhode Island, of course, Central, Western mass parts of Vermont today. New England tomorrow, The world.

Jim Polito: [00:01:44] Well, I don't know about that. The guy who, kind of, coined that expression, I don't know if I want to be affiliated with him, but, Craig, just so folks, I can introduce you to Craig Peterson, in Rhode Island and we don't make this up. Craig Peterson actually wrote code that is still being used on the internet. So unlike Al Gore, he truly did play a role. In inventing the internet.

Now he has his own company and he graces us out of the goodness of his heart, with a great, great visit once a week. And he's got a show on T A G and H Y N. That is fantastic on the weekends. But the best thing is that he's here with us and I'm his shall we say lab experiment because boy, Craig, did you help me out last week? Saved me.

Craig Peterson: [00:02:38] Oh, thanks. You know what Jim what happened to you, happens every day to people. So many people just don't understand some of the things. I look at it as the basics, right?

There's something that's known in expert circles. I'm going to put it this way. Knowing too much and not remembering too to not know this stuff.

I'm so glad to be able to be on every weekend. Talk about this stuff and really explain it in ways that I hope people can understand a little better.

Jim Polito: [00:03:10] Yeah. So let me just tell everybody what happened. I got an email from someone in corporate human resources. Now, remember iHeart is a very big company. We are very local in all of our stations and the iHeart radio app can go from the big, big stuff, like concerts right down to local with us. But here's the thing about getting an email from a company. I'm looking at it saying, is this real? I looked up the person in the directory Oh, okay, that person does work for the company. But it said someone has applied for unemployment. We have something here that you've applied for. I'm like, Oh my God.

Well, first of all, Craig. My first reaction was, wow, I'm already out. That's it. This is how the company is telling me. Then the other reaction was, I was afraid to answer. Because I said, wow, has this been hacked? Have they been hacked, but no, it was a valid email.

I got some other emails from Google saying somebody used one of your email accounts, so I sent it to Craig. I said Craig help me here. Lo and behold Craig, it was real. Somebody got my information and applied for unemployment.

Craig Peterson: [00:04:35] We looked up your email addresses and I found them in a whole boatload of breaches of other information out there. I think Jim didn't we find your name, your home address, obviously your email password? Weren't what, all of those in there, as I recall.

Jim Polito: [00:04:53] I think so. Yeah. I mean, somebody had really, somebody really got in there. Um, and you know, uh, I responded to human resources. They were great and right away, they sent me back an email, which was very helpful, Jim.

Here's what you need to do, get to your credit right now and freeze it, all of it, lock it down, you know?

And, uh, luckily so far, I don't think anything, you know, has been an issue. Um, but Craig, we talked about it, Massachusetts. It was an issue. In other states like Rhode Island, it's been an issue.

Um, you see it in the news, they're talking about people, uh, trying to take advantage of the, um, the benefits that came out earlier in relation to COVID and to scam, take someone else's identity and do something with it.

Craig Peterson: [00:05:47] Absolutely, we're calling it now a pandemic. This is a cybersecurity pandemic that's really been triggered by the lockdown, by the fear of COVID trying to understand that. Also of course the big deal with the lockdown is so many people are working from home, look at you, and pop they're at home. Right.

You've got the technology to connect to the radio station. But because of that, now employees are on insecure devices in their homes, utilizing their own networks. We now have seen this massive pandemic of identities being stolen of all kinds of fraud, not just what we've known for a while called business email compromise, where you get an email and it's trying to trick you.

Into doing something, but it's not necessarily from someone you know.

Now we're seeing email account compromise where the bad guys are taking over an email account, using the information that they have found on the dark web about each one of us. Now you will get a legitimate email that is from someone legitimately in HR.

And in fact, it's really not a legitimate email, but everything about was. They took over HR's email account.

Jim Polito: [00:07:08] Yeah. I mean, the other thing I did is, you know, folks who don't have, you know, access to a lot of other, uh, checks and, you know, um, I called, you know, the best thing to do is, okay, I got an email from this person I called and said, Hey, what's going on here?

So that's always a good backup, but you know, I get so much of that email in accounts, you know, I'll have an, uh, an email come to me, you know? Uh, and then, uh, and then, uh, I've got about one, two, three, well with work and then like three other emails. And it's just because I've had them for so long. I just keep them.

But. Um, they're not as active, but I'll get an email to one of those accounts saying, Hey you need to reset your Amazon password. I was like, this is not the account I set up Amazon with, like good try guys. This is not the account, but you do worry about some other things. You take a look at it and say, I don't know for sure.

I'm worried. And a phone call is always a good thing for people to do. And I know you've recommended that in the past too. Unless the person on the other end of the line has an Eastern European accent. Right. And it could just be a coincidence that the woman in HR is from, I don't know, one of the Eastern European nations.

She, she could be Moldovan. Right. you never know, so, that's a good thing. And that's something people have to look out for.

But you know what I want to, I want to really discuss with you, other than bringing the attention of what happened to me, to everybody to be mindful of it. Watch out, somebody may try to get unemployment in your name.

Hey, what's this thing about Facebook hiring foreign workers over US workers, and isn't ole "Zucky" breaking the law by doing this.

Craig Peterson: [00:09:08] This has been a soapbox subject of mine forever. You talked about these people trying to deceive you. My daughter got a voicemail from the IRS. They called her out of the blue and you're absolutely right. Don't respond to the email by all means. Don't click on the email. Pick up the phone. You did such the right thing.

The Zuck here, this has been one of the things I've been talking about, not specifically with Facebook, but for well over a decade.

We put a program into place to allow immigrants to come to the United States to do specific jobs. So here in New England, we have a lot of people that come to our Ski Hills, for instance, to work in the winters. Many of them are from in fact Eastern European countries and they come here, they get exposure to the US and there we're able to bring those workers in because we can't find enough. People to work here on some of the ski Hills with these seasonal jobs, people want permanent jobs and I can understand that sort of thing. So that made a lot of sense.

Congress decided, Hey, you know what? We need tech workers because it happened forbid we just don't have enough tech workers in the US. Even though right now, there are many of US that are out of work and have been for ages.

So here's what's happened just on Thursday less than a week ago, the Department of Justice sued Facebook because apparently what they have been doing is they've been bringing in foreign workers to work in the US.

You say, wait a minute, Craig is isn't it people looking for work and the answer to that is yes.

And they might even want one of these jobs. Jim, did you see the average salary of more than $156,000 a year?

Jim Polito: [00:11:02] That's what they say is a good job at a good wage.

Craig Peterson: [00:11:05] Yeah, exactly. So what Facebook apparently has been doing, and this is the allegation in the suit is they've been advertising these positions as being open, which they're required to do under the law. Let's Americans know about the jobs and what the qualifications are, and then they can apply.

Well, apparently what they've been doing is advertising the jobs in little local newspapers that no one reads and looking at the statistics, the job between July 2018 and April 2019. Okay. 81% of these 1100 jobs, 81% did not receive a single applicant while another 18% received just one applicant such add that up 81 plus 18%. Oh my gosh. 99% of the jobs didn't get applicants.

So my gosh, we've got to go overseas to find people to work here.

Jim Polito: [00:12:05] That is that's so sleazy.

Craig Peterson: [00:12:09] Isn't that something. Well, yeah, the deal Jay said also earlier in 2018, Facebook advertised 22 openings for art director jobs and they had more than 2,600 applications for those jobs.

Okay. So obviously if they advertise in the right place, maybe even on their own platform, they get applications.

Jim Polito: [00:12:34] You know, I love that. So what you're saying is today, I need to pick up a copy of the penny saver if it still exists or the want ad advertiser and all those other things, uh, You know, like the automobile, uh, and boat and recreational vehicle one, you know, at the, at the convenience store, I got to grab one of those and all of a sudden I'll say, Oh, you know, what's open the position for the chief financial officer at Facebook.

I'm going to apply.

Uh,

Craig Peterson: [00:13:04] Make sure you go to Bath, Maine to pick that one up. Right.

Jim Polito: [00:13:07] I know, right, right. Our good friend, Craig Peterson, tech talk guru. Now listen, you can get him on WTAG and W H Y N, I believe Sundays at 11:00 AM. Um, and you can listen to my Rhode Island friends with the iHeart radio app, and then Craig, if people want to get in touch with you, how do they do it?

Craig Peterson: [00:13:31] Well, if you go to Craig peterson.com, you'll find lots of great information there.

I'm going to start a course on hardening windows. After the first of the year, we're going to get back to the basics. So we'll be doing some free webinars and other things, and you want to know about it. So the best way to learn about this is just going to Craig peterson.com and you'll see at the bottom of the page that you can subscribe, they'll get my newsletter.

Hey, I'm not some marketer out there hammering you all of the time. I just don't do that. I want to get the information out so you can sign up right there. You'll get my show notes and you'll find out about all of these pieces of training.

Jim Polito: [00:14:09] All right. Thank you so much, sir. And we'll catch up with you next week.

Craig Peterson: [00:14:14] All right. Take care of Jim.

Yes, it's true. I really am going to be doing the hardening windows course after the first of the year, we've got it all laid out. Karen and I have been working hard on that and making sure it's all in place. So keep an eye out for that. I had a lot of responses I can have casually mentioned it in a PS in my email this weekend.

And I got a lot of responses. I was really, really surprised. I anyhow, that's that?

And we'll be back in tomorrow. With a W G A N up there in Maine. We're talking to Mainers. All right guys, take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Jeff Chidester on NH Today. We really got into a topic that has been a soapbox topic for me, and that is H1B Visas, and the outright fraud that has been going on with this program, especially in the Tech sector and I have to assume other sectors as well although I have not reviewed other sectors. H1B Visas are being used to take jobs from American Technology workers and replace them with wholly unqualified workers who are marketed by basically "third world slave traders." These large "third-world consulting firms" represent their candidates with outrageous resumes and charge an arm and a leg" for almost incompetent workers to tech companies and pay their worker's one-fifth to one-sixth of what an American worker would be paid and then pile them into an apartment 12-15 at a time. These people are afraid to rock the boat, or they will lose their job and be sent back. It is a modern-day tech equivalent to the slave trade. We must stop it. But the US Legislature led by a "good-hearted but quite misinformed" Senator named Mike Lee pushed for H1B Visa renewal this week. Then we talked about the demise of Adobe Flash -- to which I say Good Riddance. It was horribly insecure software that had outlived its usefulness and purpose. Here we go with Jeff.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] This was a bit of a tough one this morning. Craig Peterson here. I was on with Mr. Jeff Chidester, of course, on December 7th, Pearl Harbor day. How could I not? My father-in-law was there in the war. I talk a little bit about it. I had to stop talking because I couldn't just talk.

we talked a little bit this morning about this whole H1B thing. Man. It really is upsetting to me. What has happened to us? What has happened in the country, frankly? Flash. Adobe Flash, may it rest in peace. Jeff's company relies on Flash for some of the training they've put together. But that is all going down the tubes. Anyways, here we go.

Jeff Chidester: [00:00:45] Seven 38 in the morning. Of course, Jeff Chidester with you, December 7th, as always. We're pleased to be joined by this next gentleman. He joins us at this time, every Monday, you can also catch him on the weekends. We call him Craig Peterson. He calls himself Craig Peterson, as well.

Craig. How are you doing this morning?

Craig Peterson: [00:00:59] It's weird how that all fits together.

Jeff Chidester: [00:01:02] You see how to seamlessly. I just said it without even hiccuping, right? The silliness of Monday. Craig, we're all kind of euphoric that the Patriots not only won, but they won so big that, we're just, we're letting that euphoria carry us through the day as it just so happens.

Hey, Facebook hires foreign workers. This is an interesting thing. There Is this bill going through the Senate and the house right now from Mike Lee, and it's disappointing about H1B. Please talk a little bit about that. Facebook actually got caught on this, and there are some issues with that.

Craig Peterson: [00:01:35] Oh, there are all kinds of issues. I've been talking about this whole H1B thing for years and years, Here's what's been going on in many of the larger tech firms rather than pay Americans to do jobs. They have been using what has lately been a loophole in the law that allows them to bring in foreign workers. So they've been bringing in workers from all kinds of countries that they can pay a lot less to.

Now they're supposed to pay equal wages to Americans. They are supposed to be advertising in places where Americans will find out about the jobs and apply for those jobs. It's called the H1B visa program.

However, what's just happened now is the Department of Justice sued Facebook on Thursday. They're saying that Facebook has discriminated against US workers. They've been giving preferences to Facebook workers on H1B visas. That means a temporary worker. It's a worker that they couldn't find in the United States. No one in the whole United States has the skills that they needed. So they had to go to a foreign worker. It brought them into the country. In many of these places, these workers live in one apartment with as many as a dozen from some of the reports that I've read. They're already working there at Facebook. They're already underpaid. They've taken jobs that should have been given to an American by law.

Apparently, they're advertising their outreach to try and get Americans to apply for the jobs. Is to put them in a newspaper that nobody reads anymore. These are jobs with an average salary of more than $156,000. Out of some 1100 jobs that Facebook posted between July 2018 and April 2019, 81% did not receive a single applicant. Another 18% received, just one applicant.

You add those numbers up, and that's 99% of the jobs, not a single American applied for a $156,000 job.

Jeff Chidester: [00:03:55] Craig too, if not for you, if you didn't tell us those facts, Facebook and other companies that participate in these kinds of practices, just come back and say, we just can't find qualified American workers, which is just hogwash.

Craig Peterson: [00:04:08] It's totally hogwash because the DOJ noted that earlier in 2018, Facebook advertised 22 openings for this is an art director job. 22 openings, and they did it legitimately, right? They put it up online. They put it where people could find it. Facebook had more than 2,600 Americans apply for those jobs.

Jeff Chidester: [00:04:32] Unbelievable

Craig Peterson: [00:04:32] There's some really nasty stuff going on. I've come up against this before. You might've as well. Jeff, because you're in the tech business. Where I've had problems is with one big company. It is a massive consulting firm. They have all kinds of H1B visa holders. It's like the third most of any company in the country.

We're talking about thousands of these H1B holders within this one single company. We were up against them on a bid, and we lost the bid because they were able to undercut us. When we did more research and talked to some of these completely incompetent people, that they had brought in from overseas who had generated diplomas, showing that they had a Ph.D. yet I know high school kids that knew more about computers than these people did. They were being paid about a sixth, one-sixth of what a normal American would be paid.

The abuse is just going on and on.

Then last week, the US Senate just voted on an extension here, this whole H1B program. Instead of having Republican senators and Democrat senators saying, we need these jobs for Americans, look at the unemployment rate. They just sat on their hands and let it pass.

Jeff Chidester: [00:05:56] Oh yeah, there was no open debate on it. And of course, that's Mike Lee, the one I was talking about, and I was surprised that Mike Lee allowed this. And once again, the bi-partisan killing of American jobs is just insane. We will certainly have to see how that progresses through, but buyer beware too. If you're hiring these tech companies are hiring these companies that help in that area ask. How many employees are actually H1B employees? How many are Americans? It's just a thing we should be thinking about.

Hey, Flash is going away. I'm dealing with this. I've been dealing with this issue for a while because I do a lot of online training. A lot of our old courses were built into Flash. Flash, it's dead. Dead at the end of the month. Isn't it.

Craig Peterson: [00:06:34] Thank goodness. I was going to have Justin cue up some trumpets blaring. Flash has been one of the worst things that ever happened for security. Now it was great. Yeah. Because when it first came out or an Adobe product now has been for years, it gave us the ability to have moving graphics, to program stuff like your training courses.

You just mentioned where people could click on things, move through them. It was great, but it was designed by I swear it was 10,000 monkeys on typewriters. Okay. They managed to develop this little programming language. It has been terrible. It's Java, and it is now completely removed. It has never been on a single iOS device in history in the 10 years that my phones have been out. Because Steve jobs, it's a complicated story, but he saw the security problems. He said, you can't do this. You've gotta be kidding. Plus, he had a little fight going on with Adobe at the time.

So it's gone. It's over with, at the end of the year. Good riddance. Adobe has been pushing updates for your browser for Flash that actually removes it from your systems.

Jeff Chidester: [00:07:51] Yeah. It's interesting as I go through this process too, Craig, there was no easy fix to fix those courses. So some are actually going to be retired.

We'll have to rethink how we present them, but you're right. It was something that we were all warned about long ago.

Last thing I want to talk about, extortion. Where gains traction and Kmart gets hits, I'm always surprised, Craig.

Once again, you can catch Craig, Saturdays, and Sundays on the station, as well as other stations.

I'm always surprised these big companies just get hammered. We always think it's the little companies, and they should be careful, but these big companies keep getting nailed by this stuff.

Craig Peterson: [00:08:20] Yeah, absolutely.

And I want to, and also, before I get into that real quick, if I could just some honor here, my father-in-law was on a submarine in Pearl Harbor when it was attacked on to state many years ago. He was just an amazing man, a big-time boy scouter. He did everything with these boys and these kids. He never talked about his experience and could never have breakfast, with eggs and orange juice, because all he ever did, was taste diesel.

There are so many of our veterans, two of my kids, did military service as well. I know you did. Thanks for your service. We're talking today freely because of what these people sacrificed in memory of my father-in-law. I had to bring it up, Gerry.

Jeff Chidester: [00:09:12] Oh, that's very nice. We're going to be talking about, Pearl Harbor during the eight o'clock hour, too. and look it back in remembrance as well.

We actually have to break. Next time we'll catch up on some of those other topics that we want to catch up on as well

Craig Peterson: [00:09:22] Very Good and take care

Thanks, Jeff.

Jeff Chidester: [00:09:24] You as well. Thanks a lot, Craig Peterson. Once again, you can check him out, Saturdays and Sundays on these stations and the other stations. Also, all of his podcasts are up on his website to Craig peterson.com. Craigpeterson.com and catch up on all those as well. A great podcast.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This week I am spending a bit of time discussing Faces that are designed to deceive, Dangerous Printers, Multifactor Authentication, Shopping Securely on and offline. Why you must update ALL your devices and More so listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

Designed to Deceive: Do These People Look Real to You?

Printers' Cybersecurity Threats Too Often Ignored

What's in Store for Privacy in 2021

Alexa, Disarm the Victim's Home Security System

HOLIDAY ONLINE SHOPPING SECURITY - From the Cybersecurity & Infrastructure Security Agency

Latest Version of TrickBot Employs Clever New Malware Obfuscation Trick

Artificial Intelligence can run your work meetings now

Facebook’s libra currency to launch next year in limited format

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, what's up for privacy coming over the next year. We'll be talking about that design to deceive. How about your printer? When was the last time you actually checked that printer to make sure that well, everything was legit, as it were?

Hey everybody. Craig Peterson here. We've had a problem with fakes.

You've heard about fake news. Of course, President Trump's been talking about it. I think it was actually Hillary Clinton that had coined the phrase fake news, but there is all kinds of fake stuff going on right now, out there.

One of the big things that really concerns me is the fake identities that are right now being used in order to rip people off. That's a huge problem. When you get right down to it, we have a lot of people who are lonely.

Think about people who might be divorced, particularly elderly people, someone that's lost a lifetime mate. Nowadays, they don't see anybody anymore. they might have someone come in with a face mask on and a big shield and gloves and it's just not human touches, it's not human interaction. They're not interacting with their family face to face.

They of course, hopefully, have some way to do it virtually, maybe using Zoom, which, isn't safe. You should never use that as a business, but it is fine for family connection type of stuff. And I've used it before for different types of business conversations. I'll admit that. And in fact, when I was doing all of the webinars for the FBI's training program, as part of the whole InfoGard stuff. I was indeed using Zoom because that's what they told me to use. I approached them. I said, Hey guys, we should really be using WebEx because they have versions that are safe. That can be used by people like us that are trying to keep our information safe and keep people out we don't want to have in it. The response I got back was, no, the FBI has authorized the use of Zoom. We can't use anything else.

Of course, once again, Craig's proven, right? About a year, actually about two years later, what happens? We find out that Zoom was routing data through China, that they have developers in China, and that it was anything but safe. A real problem, frankly. okay. That was an, I told you.

But how about when you're going onto the dating site and you're not so concerned about people finding out about you. In fact, that's the reason you are on the dating site. Do you want people to find out about you and you go there and you're trying to figure out okay? Is this somebody that I can trust? Is this somebody that I should trust? I know many people who have found some of these dating entries, if you will, the posts we'll put up to be highly deceptive.

That is the problem that we're seeing all of the time. Now, when it comes to security. The bad guys are highly deceptive. And that's a huge problem because when you're on that dating site, they, might not even meet data insight. It might just be your Facebook page or something. And you find someone with some common interests and you start to talk to them and you build a relationship, all good stuff.

It's all stuff you and I need to do, we all need to do, isn't it? How do you verify whether or not that's a real person? Let me give you a hint. If you go to the Google homepage. I'm going to bring it up right now for me, myself. So we can talk along and you can see it has Google search on it.

I'm feeling lucky if you go to the upper right-hand corner, you'll see a little thing called images to a little line. You click on images and now up comes Google image search. So this is a bar you can type in just like you would any sort of a regular Google search. But it has a little camera. Did you notice that over on the right-hand side of the bar, you click on search by image.

This is where it gets interesting because if you're on Facebook or Instagram or one of these dating sites and you want to see, is this a stolen picture? Is this really a picture of John or a picture of Mary, whoever it might be. You just get the URL to that picture in the way to do that is either you can save it to your disk. If you can download it or you can right-click and copy the URL of the image, and then you paste it here into the paste image URL.

That you see right there on Google images and then you click on search by image. So I'm going to do it right now. I'm going to go to Craig, Craig Peterson.com. And I am going to grab my picture.

I'm sure I'm on here somewhere. Okay. We've got all my latest podcasts. Got questions? Subscribe for email updates. You know what? I don't have my picture on there, but I'm going to grab the U R L and you say open image and hub. And this is my logo. Okay. It's not like a phase. Yeah. Good and find a picture of my face right there on the website. I should probably fix that.

I'm going to copy, I've pasted it now into the paste image URL on Google. I click on search by image. Now, remember I was looking for my watch. It's looking for my logo and it's telling me, okay, here we go. Oh my gosh. Oh my gosh. So my logo does come back with my website a whole bunch of times, which is what you'd expect. But it also comes up with this. I'm not seeing here, come up with crude. The real price of oils. It says it's an epic story of one of the largest and most controversial legal cases on the planet. a $27 billion Amazon Chernobyl lawsuit pitting 30,000 rainforest dwellers. So it must have something to do with crude oil. That's interesting because their logo is similar to mine, but that's what we're looking for here.

Is the person whose pictures on that Facebook page or Instagram or dating site or whatever it might be? Is that person real? So when you look them up, you're going to see multiple times. results hopefully. and just kinda show them all. Yeah. This is a picture of them at home. This is, Oh, wow.

That's where they work. It's got a picture of them at the office. It's got pictures all over the place. Okay. That's obviously a legit person. what happens if it comes back with. Only maybe one match and that's their Facebook page or their dating page, et cetera. that's what I'm concerned about right now because so many people are being deceived and it's one of the things that the. FBI has sent us notices about. They are mostly seniors, all the way on, down through generation Z, the youngest adult generation we're falling for it. So if you go right now, there's a website called this person does not exist. Okay. So while you're listening, go there, this person does not exist.com and you will see an amazing picture. So I'm looking at one right now and it varies. Okay.

This was generated by an adversarial network is what it's called. You can find out how it works and you can do all kinds of stuff. And the picture I'm looking at right now is actually a young lady. I would say she's probably around 30 years old and that's based on some wrinkles around her eyes and under her eyes, mine puffy under my eyes and the cheeks. Just little tiny wrinkles. So she's in her thirties somewhere and a really pretty I would say it's been a little bit, bleached hair is Brown and they at the roots and then as you get further down, it's more bleached out as more like mine, a dirty blonde, very interesting stuff.

So you can go and you can go to right there grab a picture of a person that is not real. This person does not exist and you can even manipulate it there on the website. You can go to other places like generated.photos. That's the whole domain generated.photos. And once you're there, you can get what they call unique worry-free model photos.

What's a whole worry-free thing about? The bottom line is if you are a business and you buy a photo of a model and you can get them a lot of places online, I subscribe to some services that provide those for me. So you can get all kinds of different pictures, photos, but you can end up getting sued because maybe the release wasn't quite right. Or they signed the release, but they never got paid. The check bounced as it were. Or the transfer didn't happen over on Apple pay. Whatever they were using Samsung paid failed on them. So they have removed their permission and yet that picture is still being sold.

We've seen more and more, some of these places online that are selling our personal pictures that we've posted up on the websites. Obviously, not the best idea in the world is it frankly. So you can just go to generated photos.com, browse photos they're made by AI, these AI systems. What are you looking for?

You can search for anything I'm seeing right now. It says white woman, young adult, Asian toddler, infant, or so cute, elderly. This guy doesn't actually look that old. maybe it's because I'm older. I don't know, but, you can get them all there. You can buy a whole for three bucks or you can go and buy if you need a lot of them, a thousand for a thousand bucks.

So how do you use that? obviously, there's this legitimate purpose.

Unfortunately, there's also illegitimate slash illegal purposes out there. That is to use these pictures to con people to make them think that you have a legitimate presence or they have a legitimate presence online, and then they build a relationship and that turns out they need some money to save their Aunt who needs this surgery.

All of that stuff. So be very careful out there.

There are a lot of cybersecurity threats that we just don't deal with. It's gotten too difficult. It's overwhelming. How can I keep up on all of this stuff? you think it's bad enough with your windows machine, your main computer. Hey, I got some news for you.

You're listening to Craig Peterson. We have a lot of devices in our networks and I've talked about this quite a bit.

It's one of my soapbox subjects, right? What's called the whole internet of things. We have all kinds of devices hooked up to our networks. I'm sitting in front of well, within my view, probably two dozen different devices right here in my studio. That's frankly, that's a lot of devices and many of those devices could be hacked.

Now my network is completely set up so different things are isolated. I have multiple segments, multiple physical segments, as well as virtual segments. And one of the ways to do a virtual segment. Is to have some special stuff on that wire where you have what's called a VLAN or virtual local area network. That's getting a down into the mud here. Something I cover in some of my courses.

When we're talking about networks, segmentation is absolutely critical. You have to make sure that your home computers are on a different network or at least a different network segment than your work computer. Now what I'm talking about in-network segment, I'm not, I don't mean, Hey, I've got a switch, or right at the router that the Comcast or an internet provider gave me. I have maybe two, three, four, Ethernet ports. And so plugging in a switch to one of those ethernet ports and then putting your home computers on that switch and then putting another switch on and plugging it into the second port on that router that you got from your ISP, your internet service provider that is not segmenting your network at all because that's typically a flat network.

If you have a fancier router firewall at the edge, you may be able to segment it that way. For instance, we sell a lot of the Cisco Go equipment, which is the low end, very good stuff, but it's very basic. It's inexpensive. It does let you do real segmentation. So you can have a guest network on the wifi.

You could have a business network and the wifi, you can have multiple what are called SSIDs that's the name of the network you're connecting to. You've probably seen that if you've gone in and configured Joe or router and SSID so you can have multiple of those on some of this hardware, like the Go hardware, for instance.

There are some others out there. I think I might end up in my emails here. In fact, it is planned. To come out with something, talking about these SSIDs and what equipment you can buy. So it should be pretty simple. Keep your eyes out on that in my newsletter that you're hopefully getting every, Saturday ish.

It depends on where I am, what I'm doing that week as to when I get it out. I just try and get it out on the weekend before my weekend show airs. But, here's the bottom line. You don't want your home computers to be able to talk to your business computers. With so many of us working at home, this is a very big deal.

So how do you do that? If they're both plugged in two separate switches that are then plugged into your router? They can probably still see each other. But if you have a more advanced router that lets you have different network segments and make it, so the one network cannot talk to the other network. Then you're really cooking with gas because now they're not going to be able to spread infections.

I've talked before about VPNs and the proper way to use them. I really think I should have a whole course on working from home again for everybody out there to help. Understand some of these basics.

Make sure you're on my email list. Craig peterson.com and then subscribe on that little subscription form that comes up. Be glad to send you these things because I will let you know when I'm going to do that because there's a lot of confusion about all of this sort of thing. One of the devices everybody has in their home and certainly in their businesses, Is a printer, and we buy the printers and we buy ink and then we buy more ink and then we buy more ink. It's just a constant buy more ink it, sometimes it drives me crazy. You're buying ink for these printers, but are you connecting them to the network? Now some of the printers, especially the lower end ones are just connected via USB port to our computer. And when they're connected directly to our computer. It's really handy but it's difficult to share that printer. You can share it from Windows. You can share from Mac. So other. devices on your network can see it. That's probably the safest configuration of all of these devices bar none really. you can get safer, but it gets very expensive, very quickly.

If you have now taken that printer and instead of plugging in the via USB port, and this is typical of shared printers like we have three shared printers here. And they're all on the network and they are all self-updating. That is the next thing, to be concerned with. In fact, self-updating is probably a very good thing.

So we have some higher-end Xerox printers. These are what we sell to our clients. These are what we use internally and those printers. Call home order supplies. in fact, you can buy these printers if you're a business and you just pay by the page, you print or photocopy, and everything's taken care of all of your supplies, the machine itself, absolutely everything and that's a great way to go for many businesses out there. That way you don't have to manage it. You don't have to worry about the expensive repairs that are almost inevitable with some of these printers, but they are hooked up to the network and that means that they could potentially become infected.

I like the idea that these things are self-updating and as self-updating printers that means one, they are going to get the latest security patches, et cetera.

If you have connected a printer to your network and it does not update its firmware automatically, or frankly, even if it's supposed to be, you got to check it. You've got to check which level of firmware that's the software that's running on the printer because nowadays everything's a computer, right? Especially a printer. Find out what version of the software it has. Go to the manufacturer's site. Make sure you have the most recent release of the software. If you do life is good. If you don't, you're going to have to follow the instructions from the manufacturer on how to load in that new software, because that printer is a computer and because it's hooked up to your network, any malware that gets on your network, and it could just be the kid's friend who came over for the evening or the night or whatever, and plug their laptop into your network or connected to your wifi. and that laptop he brought over was infected.

So now it's going to try and infect everything on the network. It finds a vulnerable printer on your network and it infects it. So now due to almost no fault of your own, your network right now has a device cause he's going to leave. He's finally going to go home. Thank goodness. Now you have a printer that is acting as a launching pad for the bad guys to be able to get into the other computers on your network. So keep that in mind.

We know that we're supposed to do something, but we don't always do it. And in this case, we're talking about your printer it's firmware, but also I mentioned that router that's sitting at the edge of the network. Do the same thing with that router, make sure it has the latest versions of firmware.

That's part of what I like about those cisco Go stuff that you can buy through me. You can find it on Amazon. Go equipment, self-updates, which is very nice.

Believe it or not, 2020 will eventually come to an end. And then we've got next year, 2021, which shouldn't be an interesting year as well, but what's in store for privacy in 2021.

2021 is going to be a turbulent year, according to dark reading, you might want to check them out. They've got some great articles, but there are changes coming in the privacy landscape.

We've seen a few over the last few years, for instance, in Europe, they come up with the GDPR, which is this data protection law. They have something similar for consumers and their data over in California.

Massachusetts has something similar. New York too.

We're expecting certainly under a Biden administration to have many more standards put in place. They'll end up being federal standards as opposed to the state set standards and whether or not you like that idea. I've got to say, I think it's a very bad idea, but it's good that we're talking about it because our privacy has been under assault for a very long time.

I had this conversation with my wife earlier in the week. And she was just fed up with the lack of privacy in the online world. Not that I can blame her for that. that's not where the issues came up. The issues really were surrounding. What privacy should you have? What privacy do you want now?

Ultimately, we know that when it comes to the government, Privacy on our part needs to be absolute. There are no two ways about it, right? It's one of the Bills of Rights. We have the right to be secure in our papers. We have the right to be secure in our homes. The government cannot just willy-nilly start monitoring us, recording our conversations, tracking who we call. Actually, they did that. Under the Obama administration, they did it more than ever. They dramatically increased all of that spine on us citizens. huge increases. And under the Trump administration, they drop that back pretty dramatically. under a Biden administration, I'm afraid it will actually increase.

There are two types of people in the world. there's them and then there's us, right? There are many more of us than there are of them, the people in power, but the people in power want to force standards on us that say you cannot store certain types of information or track things on people.

However, for them. The double standard just doesn't really apply, because for them they can do even more monitoring and spying on us. Pulling together the intelligence and buying it from these commercial data brokers who pulled together, all of this information that's available publicly and all the information that they can buy about us in many States and includes driver's license information.

It certainly includes everything in the registry of deeds. The secretary of state's filings like UCC ones, et cetera. So they've got a real good picture of you. They can tell from all of this information, Hey, he's driving an 11-year-old car or, Oh wow.

He's got a brand new, $150,000 car. You expect different things from those people. It's one thing for businesses to be collecting that and it's entirely another thing for governments to be collecting that. So what my wife and I were discussing was, is it a good thing or a bad thing that businesses are collecting?

it really is a double-edged sword. It's not something that's obviously bad are obviously good. For instance, if I'm in the market to buy a new truck, I'm all for seeing ads from truck manufacturers. These are cool new electric trucks, Ford of course, GM, Chrysler, whomever, it might be. I want to see it.

If I'm not in the mood for buying a new truck, I don't want to see the ads. It's a total waste of my time. So broadcast TV, for instance, doesn't know much about us. You might've noticed if you're listening via one of these streaming services to me on a podcast or a live stream, the ads that are inserted are specific for you.

I think that's generally a good thing, frankly. But there is one company out there that has been very good in trying to keep, quite a bit of privacy for you and me, and that's Apple. And I want to talk about them in just a minute.

I also want to warn you that the Department of Justice has signed a letter along with other businesses out there calling for what we call back doors. So they want some technological solutions to give law enforcement access to specific communications.

I personally call that a threat. Now you might say, Oh, that's the Trump administration. That's Bill Barr. terrible man. Terrible man. this has been going on forever. I remember talking about this back in the days of bill Clinton and the clipper chip and how they had come up with this.

Chip, the Doug does encryption and it should be used by everyone and they were going to mandate it and it turned out I had a backdoor in it, just I think it was the Jupiter foams that, Saddam Hussein and his sons were using that were actually made in the UK. And we're encrypted phones. So that they could carry on their nefarious deeds, no one could track them.

No one knew what they were saying, et cetera. Except it had a back door and the Brit shared it with us and we could listen to all of their communications. We could track where they were with who. As they were going, et cetera. Okay. as of December 8th, this year 2020, Apple's requiring developers to disclose all of the data it's apps collect from users, including data that's collected by third-party advertising frameworks that are included or linked into their code.

Now, this is really a big deal, because remember I was talking about how the government is collecting data on us and it's restricted in collecting certain types of information.

It can't do it. However, we have found now that the IRS, the immigration people over at Homeland security, and others have been buying data from these app developers. So they've got these frameworks that are for advertising and I'm using air quotes here, and those frameworks are used in those free games you have.

Why is the game free? how can it be free? How could you afford to give away these games? All of the work you put into them? They're not they're including these little frameworks and these frameworks now track where you are? Where you're going? Where you're playing the game? Some of them like Google maps try to track you all of the time.

Google, of course, makes its money primarily off of selling your information. So Apple doing this I think is a huge win for Apple and for the consumers again, how many times have I said, don't use Android. Java. One of the biggest security problems that we have in information technology is these Java runtimes.

That's all Android does. Plus the fact that it can be six months or in most cases, never until you get security patches because your phone's no longer, the latest, greatest, they just don't care about you anymore. Use an iPhone, get an iPhone. Even if you get, you do like me right now, I'm using an iPhone eight who cares?

It works. It does the job. Get the older release. It's going to save you a lot of money.

We're going into Alexa. This is interesting. Disarm - the victim's home security system. If you want to see these articles are more, I don't know. I have a lot more listening to my podcasts.

As in any of these segments, I do just visit Craig peterson.com and make sure you sign up for my free newsletter.

Many of us have Alexa. Maybe Google home. Maybe some of these other assistants that have either Google Home or Alexa built right into them. I guess it would echo, but did you know that there is a very interesting way to hack them?

Hey, you're listening to Craig Peterson.

Anyway, if you have one of these wonderful little home assistants, you may not be aware of it, but a light can be used to hack these things. I don't know if you watch some of these really cool spy movies. I think they did this with one of the Tom Cruise movies, but they might take out a laser and point it at a piece of glass and then use that to listen

to the discussions or whatever's going on inside the room. Now that does happen. That's very easy to do. There are devices you can buy out there for very cheap that'll do that. So it takes the light from the laser it's modulating by the vibration of the glass and they can listen to what's being said. So there have been times where I was in meetings that we needed to keep very private and unfortunately, We were well aware that there were people who would do anything to listen in to the meeting, and because of that, we ended up putting some vibration, some speakers with some Brown noise right there at the windows, so that they couldn't be listened to by laser.

So maybe I'm paranoid. At least when we were, but there was a big lawsuit going on. And there's, when you're talking about millions or hundreds of millions, even billions of dollars, some of these people will do almost anything.

And for private investigators, it's really cheap and really easy to just use that laser too. Listened to the vibration on the window from across the street. And it doesn't have to be like one of those pointer types, where it's red and you can see it. You can use all kinds of wavelengths of light, even invisible wavelengths of life, light invisible to us, Our eyes, but not invisible to the equipment that they're using. So there can be very sneaky about it. there's a team being reported here in dark reading from researchers over the university of Michigan and the University of electoral communications over in Tokyo that they were able to use modulator.

Laser beams in order to inject command into the microphones on Amazon Alexa and Google homes and other digital voice assistant devices via laser pointers. Yes indeed modified laser pointers. Now, this is very intriguing to me because the physics involved actually are not understood very well. these digital assistants have built-in microphones and in the case of I have an Alexa or an Amazon echo dot.

It has multiple microphones and you can see the light on the top that moves around and tells you which one of the microphones is listening to. Right then it's really very cool. It's a very nice way to do things. And the same is true for some of these Google devices and other devices. So they have multiple microphones and usually, these are microphones that are mounted right on the printed circuit boards inside, but they are called memes.

Microphones. And these are often kind of surface mounted and are usable by anybody who wants to buy it. These aren't like made specifically for Amazon or anybody out, but they're microelectromechanical systems, MEMS microphones, and you put them right on the printed circuit board. And off you go, it's really that easy for these guys to put the microphones on.

What was fascinating here is that these researchers used the light beam, some the laser pointers to send invisible to the naked eye and inaudible commands to the digital voice assistance. As well as by the way, voice-controlled smartphones and tablets, even through glass windows as far away as a football field.

In fact, a little bit further. So think about that. Okay. Let's say that you've got your Google assistant or your Amazon Alexa or whatever it might be your Siri set up to control. The devices in your house. So turn on and off the light, maybe turn on and off your security system. Maybe open the garage doors all through these smart devices.

And all they would have to do is send a command disarm. The home security system, open the garage door, unlock the front door, turn off the alarm you getting where I'm going here now. Okay. So now they've taken the research to the next phase because there's still some real mystery. Around what's actually causing this physically, how is it working?

And that is just phenomenal. So there's a Ph.D. student by the name of Benjamin Cyr over at Michigan, who, along with another researcher, Sarah Rampazzi is presenting the latest illustration of the research that they are doing at Black Hat Europe coming up on the 10th. So the big question is why are the microphones responding to light as if it's sound?

They're trying to nail it down on a physical level so that future hardware designs can protect them from these light injection attacks. Now, apparently our friends over at Amazon. heard must have heard about this. I don't know if these guys reported it or not, but there are some other people who have found out, there's a researcher, an assistant professor at the university of Florida.

Another one at the University of Michigan who are planning to show how a security camera could be manipulated by a hijacked voice assistant. So they're going to show it and they're using it against the Amazon echo three, which is a newer model of the smart speaker. There was not available last year when they first detected, detected this problem.

Echo's series Facebook portal, Google home, basically anything that has one of these memes microphones in it. And they are saying that apparently they all care. We go, yeah, they did share their findings with Amazon and Google and other vendors and Amazon at least have put a little block in front of the microphone so that, lasers can get and get inside to the microphone.

But the researchers spent just $2,000 in equipment in order to conduct this attack. And that included the laser pointers, a laser driver sound amplifier, but they said it couldn't be done for as little as a hundred bucks. Including a low-end laser printer for cats. Pointer, I should say for cats that can be bought on Amazon.

So there you go. Cat toys, a longer range attack, apparently, they purchased a $200 telephoto lens and that let them shoot the light beam down a long hallway and they encode the signal to the microphone. It gets modulated by the light. It's pretty darn simple. To carry out this attack.

I don't know. We'll see what happens. Apparently, the new generation of devices from all of these manufacturers are going to have a cover.

Amazon made some slight updates to the Alexa software so that an attacker would be unable to brute force a device pin. If you have a pin set on your device, which is probably a really good idea, if you're using it to open doors or turn on or off alarms, I'm not as worried about turning on my lights right in the house.

But this is just absolutely fascinating and once we figured out the physics behind it, maybe there are some good things that could come of this. But, there were thinking about making the mic and susceptible to the light, adding authentication to the software, many other things, but it is absolutely fascinating.

So there you go. Something we never expected. Something no one could have predicted that is frankly an absolute problem.

We're going to get into some shopping tips here. We've got a special emergency, a bit of information here from the cybersecurity and infrastructure security agency.

CISA as it's known C I S A and we'll be talking about that as well.

I want to just take a minute here for businesses. If you have security requirements. And there is a lot that, listen, in on my show that has these new DOD requirements called CMMC. There are five levels. I'm going to be doing some special training on this stuff. So we're going to be going through everything from level one, through level five and explaining each one of the controls. There are over 170 controls now, and we're going to go through each one of them. So if you're struggling with this and I don't know a soul that isn't struggling with it. Even these huge military contractors whose whole life is doing military contracts. They're all struggling with it. So how do you deal with it? So we'll start with, how do you know if you have to comply? If you're selling something that is sold to a defense department, subcontractor, or contractor, You may have to follow these new guidelines. I know companies that make just passive filters, power supplies, wiring harnesses that do fall under these various categories. Now it could be as easy. If you are the guy mowing the lawn for the facility, it could be as simple as a few thousand dollars to get yourself up to snuff as to where he needed to be.

If you are, however, making something that goes into something that goes, boom, and it is truly not commercial off the shelf and buys that commercial off the shelf. They mean it really is just off the shelf. You have no idea that it's a military use. You have no idea what contract it might be under. You don't know that it's a military subcontractor. then you're okay.

But if you know that one of these subcontractors or contractors is buying something to go into something that is used by the department of defense, well, now you have to worry about compliance. So yeah. I'm going to be doing a whole series of training on this, and we're going to have some free stuff. There are going to be some paid ads, but I want to make sure that you subscribe to my newsletter so you can find out about it.

We'll be starting that up after the first of the year. So make sure you check it out. Go to Craig peterson.com. Slash subscribe. You can subscribe right there. I'm not going to harass you or anything else, or fill out the form on the bottom of my page.

Craig peterson.com.

Hello, everybody. you are probably fairly familiar with all of the normal tips about shopping online. We're going to get into a little more detail here and what you should do while you're shopping and after you have been shopping.

Hey, this is Craig Peterson. you can find almost all of this stuff up on my website@craigpeterson.com. And if you are not subscribed to my newsletter or my podcast, please take a minute to do that on your favorite podcasting application.

There are a lot of tricks that are going on right now when it comes to online shopping things that we have to be very aware of. You've probably heard about many of them before. There are, of course, all kinds of nasty people out there that are trying to trick us into maybe given a credit card where we shouldn't.

I want to play a little bit of audio as well from my daughter. This is really sad, but, she got this phone call and it came through on her phone. Regarding some fallbacks activities in the state of Washington. Do we need to talk to you as soon as possible? This call is from the social security administration. I'm literally trying to the department (509) 524-9631. I think it's (509) 524-9631. Thank you.

Now I usually don't play the phone number when someone leaves a message. But in this case, I don't know. I, if I was you, I probably would not call it. Cause now they know that you are a person who is potentially going to be open for fraud. So don't call those numbers.

I think that's an important thing for us all to remember. But in case you couldn't quite make it, how it was the social security administration calling and they were calling because they saw some fraudulent activity in Washington. And they wanted to follow up with you and you, they wanted you to call back. So obviously don't do that.

My daughter got this phone call just this Thursday. It was in her voicemail. Don't call these people back.

I have a friend who will see a phone number coming in, a call comes in. Oh, I don't recognize that call. He'll just let it go to voicemail and he doesn't listen to the voicemail. He just calls the number back. Hi, you called.

Don't do that. There's a couple of reasons. One is in the, in most of these cases, they are trying to get information about you so they know you'll call them. So they might be able to trick you. But in most cases, that caller ID is fake. So they're sending you a caller ID and it says some phone numbers. Sometimes they even use phone numbers of police departments, which is really funny.

There's a video online of a police captain getting one of these fraud calls and she keeps this fraudster on the phone and who's telling her that he's going to report her to the local police. They're going to come by and arrest her unless she pays him right now. She's just doing everything she can to not laugh because she's the chief of police. Are you kidding me? She knew it was a fraudster. We have to be very careful with these people. So many of us, particularly the older generations, are trusting, and that can be a bad thing, but it's not just them. It's the young people too.

I am shocked at what they will do, what they'll get away with, and how they just don't care about cybersecurity. Really don't care. I had a discussion with one of my sons and he didn't care. He was just pushing back as hard as he possibly could. So maybe it's a Dad thing. Cause I'm his dad and I'm into cybersecurity. It's what I've done for a living for decades and he is just rebelling. He's how old is he now? He's probably 24 or something like that. I know a lot of us rebel and push back against this stuff.

Just like I talked about earlier with the printers, we know we should be keeping our firmware up to date, but we just don't. So watch out for those scammers.

One time I was on the floor of a trade show. I was actually exhibiting there at the trade show and talking with people and everything back and forth. I thought it was going pretty well. Then I got a phone call and I answered it and it was a lady from the IRS or at least that's what she said she was and I knew it was just totally fake because the IRS doesn't just call you out of the blue. The social security administration doesn't just call you out of the blue. They will send you a letter. It's really that simple. So I hung up on her and she called back like six times and I told her, listen, this is a scam. I know it's a scam. She was asking for I think it was Apple gift cards. Really Apple gift cards. I can see Amazon gift cards, but Apple's a little more limited, I don't know. I don't know. Maybe they'd just buy apple phones with those gift cards and then sell them on the gray market or the black market once they got the hands-on. I just don't know.

So it is happening and it is going to happen even more this year. And many people ask why would someone do that? In many cases, they don't really know what they're doing. They're just calling from a call center and they've got a script to read and they are told that it's legitimate, right?

In another case, the people who are running this scam know it's not legitimate. And then other cases, they're an active participant, but they're making money. And it's the only way they know how to make money is to rip people off, which is just a shame.

Between you and I see this all the time in the IT world, where there are a lot of businesses out there that are scam artists. They put up a shingle saying I'm a managed services provider, or I'm an IT professional because there's money in it and they're not.

We have a client. This was absolutely fantastic on Thursday this week. One of our techs. One of our senior techs was out there. He said that we were the best, IT support people he has ever seen. He's been in business for about 40 years and he was just ever so grateful for everything that we're doing for him and his team, his company, helping him to grow and solving all of these it problems. He doesn't even have to think about them. He doesn't even hear about them because many times we solve them before they even know about it. But we're right on top of it. We're helping them, we get the right equipment. So he doesn't have to buy it again when it breaks and he doesn't have to do with the downtime that you always have to deal with when something breaks or something fails. So he is very grateful and so am I frankly, for what he's done for us, which is pay his bill it's right. They're very good people and made me feel very good about that. But anyhow, okay. So I am going on and on here.

Let's talk about online shopping and the safety of online shopping. There is a great article that I picked up from CISA. Which is a federal government agency called the cybersecurity and infrastructure security agency.

CISA.gov is where you'll find a lot of this online, but let's go through some of the tips. The first one is the best defense there is, frankly, which is be aware. Before you do anything, stop and look.

I do that all of the time. I get an email from someone. It might be a legitimate email. It might be legit from Amazon or from Walmart or whatever online store. I always stop and look at it.

The number one thing to look for is grammar. Good English grammar, at least good enough. English grammar that you think that they're probably a native English speaker.

Now you say, there are all kinds are wonderful people who aren't here, English speakers in. That's true. There are multiple things to look at. We're just talking about one of them here right now, which is are they native English speakers or is this very poor or grammar?

Because most businesses are not going to send out an email just full of grammatical mistakes or spelling mistakes. Does that make sense to you? They're not going to do that because frankly it just reflects very badly on them. That's not something that you want to have happened. So that's the first thing to do.

Next double-check all of the URLs. So that email from the address should be absolutely correct. Is it absolutely amazon.com or is it AMA dash Z O N.com or is it a M Z O N.com?

Any of these misspellings, common misspellings, things that you might just overlook normally, does that email contain any of those types of things? That's all a part of Awareness. What we're trying to prevent here is what is called phishing attacks, or even spear-phishing attacks, where they are sending us something that looks legitimate on its surface, but obviously is not when you get right into it.

So in most cases, when I get an email from somebody, what whoever they might be, I look at it and say, is this a legitimate communication? Am I expecting it? If it's from a bank of mine or some other vendor, I rarely ever click on the link in there. I usually go to their website directly.

You don't call back a phone number. If they say they're calling from the local police department, you look them up in the book, and yet, and you look them up online, right? Who has books anymore? You call that number, not the number that they gave him. All right.

We've got a lot more about shopping safely online this year.

Visit Craig Peterson.com.

Now that we know the basics, let's get into the details of what are some of the things you can do. In addition, we're going to get into multi-factor authentication and much more. So here we go.

So let's talk about these devices that we're going to be buying this year and next year.

2020 is going to come to an end. Some of this stuff's going to spill over into next year. There are a few things you really should be doing, especially with your Bank or Amazon, anywhere where you have financial data.

One of those things is called multifactor authentication.

A lot of these businesses have this called also two-factor authentication. You might see it abbreviated as. 2FA or MFA.

So what is this two-factor authentication? In many cases, businesses are using a text message that they'll send you when you log in. So you go into your account, normally it's where you would set your password, and you'll see something there about multi-factor authentication or two-factor authentication.

You'll go to that and in most cases, they'll ask for your phone number and they'll send you a text message to verify it. And you're off and running. So now the next time you go to log in to that site, it's going to want your username or email address, and it's going to want also your password. And hopefully, you're using a different password on every website out there.

And then it's going to send you a text message and that text message will have a number that you can then type in on the website. Okay, this is really you. Now you gotta be careful with this because there are a number of people who have been bamboozled by this. One of the ways they got bamboozled was where yes, indeed people stole their phone number.

So an attacker knows that you have something valuable, they want to get into your bank account, or maybe it's getting into your Bitcoin account, whatever it might be. They find out what your cell phone number is and then they call up your cell phone provider and they say, Hey, I've got a new phone and then they give all of the information for the new phone and they can bamboozle them to get them to switch.

Before you know it, 'cause you're not getting to notice, Hey, I just didn't get any phone calls. Not a big deal. It's wonderful that people haven't been bothering me on the phone. But what has actually ended up happening is they now have your email address. I assume that they have your password because most people use the same password on multiple sites, or it's an easy to guess a password, easy enough to find the breached passwords on the dark web. I do it all of the time when I'm looking for dark web stuff for my clients, but now they have your phone number.

So when they go to log into that bank account, They've got the email address. They got your password. Cause you have used that same password elsewhere. When the bank sends a text message to your phone, it doesn't go to your phone and you don't even know it went to your phone.

So here's an important tip. Contact your cell provider and have them use a pin or a password with you so that when you call up, they're going to ask you, what's the password for the account. Now, this is going to be a different password than you'd use on the website. But it's going to be a password, in some cases, it's a pin.

So come up with something that you don't use anywhere else and set it up with your cell phone provider. That way, if they are going to hijack your SMS or text messages, it doesn't matter because even then they can't get through, but there's a better way. Okay. There's a better way to do all of this. There are some paid and some free two-factor authentication apps. What I use personally, and what we use with our customers is called duo D U O.

We've been using them for years. Cisco of course bought them because they were the best in the business. That's what Cisco does.

So DUO allows you to have a different type of two-factor authentication. You can also use Google authenticator, which is free. You can use Lastpass. In fact, I got an email this week from one of the subscribers to my email list, thanking me for the recommendation for Lastpass. And by the way, if you want a copy. I have my special report. I'd be glad to send it to you. That talks about passwords talks about 1password and Lastpass and what you should do a little bit about two-factor authentication.

So I use DUO. I also have Google authenticator, although I don't really use that at all. I tend to use Google or I should say. what happens with that is they'll display a QR code when you're setting up the two-factor authentication. That's one of those square things that has all of the little squares inside of it that you can use to go to a website is typically what you'd use it for in this case, it then syncs up a special Countdown a few seconds, and it'll give you a six-digit code that you can use. That code is only good for 30 seconds. So now when you go to log in, you're going to give you a user-name or email. You're going to give your password. And then it's going to ask you for that. Code so you can use.

Again with DUO, I have adjusted automatically. It comes up, it's integrated with my one password as well. So I can now log in and I know it's extra safe because even if someone steals my phone number, It's not going to do them any good because I do not use my phone for verification, for two-factor authentication.

Now there's one more trick that you could play if you wanted to. And I have done this more than once. Some websites do not allow you to use an authenticator app. Yeah, I know behind the times, aren't they? So you have to use SMS. If you want to use two-factor authentication, in other words, you have to have a text message sent to you. So what I do with those sites is I have a phone number that isn't a real phone. So I have a phone number that I got years ago from a company that Google bought. Nowadays, Google calls it Google voice. So I have a Google voice number and I will give them that number. Now, why would I give him that number? first of all, I can filter calls that are coming in and text messages and everything out. Google will forward the text message to my phone. Remember it's Google, so it's not terribly private, but that's okay because those numbers are usually only good for a number of minutes. Okay. So it's not a very big deal, but the reason I use something like Google Voice is it's not a real phone number, so they can't call up T-Mobile or Verizon or whoever you have your phone through pretending to be you and get them to transfer that phone number because they can't and they won't. Okay. It's very important.

The SIM card that you have on your phone nowadays, some of these devices have virtual SIM cards. that SIM card that's in your phone can not be stolen or duplicated or anything else either if you're using one of these Google voice numbers. So some really important tips there.

I hope you took some notes. If you didn't, you can find this online. I post these as podcasts, you'll find right on my website@craigpeterson.com. You can listen to them, take notes. And my wife even provides a transcription of these things most of the time. bless her heart.

She spends a lot of time doing that, and she'd appreciate it. Check it out online. Craig peterson.com.

We're talking about how to keep your devices safe that you're buying this year things you're getting for family, for friends, maybe for yourself as well. And we're going to get into it more. Now we've got some really surprising things for you guys.

One of the things that we have to do, and this is again, over and over again but better than 60% of Windows computers are not up to date. Remember we're buying nine devices that are basically computers.

Do you remember that whole Barbie thing from not too long ago? I was on TV with this thing and it was sending audio up to the internet and we were able to intercept it. We did a whole thing on television about this. Obviously, it's a very big problem because it's your kid's information, voices being sent up, in the Barbie was interactive. Now Mattel cleaned some of that stuff up and that's always a good thing. But the point behind this whole computer in a toy or other device thing is that their computers. We're talking about mobile phones and Android phones, just not getting security updates. If you're going to insist on using an Android phone, make sure you get the latest model every two years, because even Samsung only supports their phones. They're top of the line phones for two years. Okay. Versus your iPhone, which is good for five or more years. So keep those phones up to date.

In fact, when you first get the phone, probably the first thing you should do is check for a software update. Computers are the same thing. Whether you're getting one of these Chromebooks, which are very good, generally speaking, I'll remember it's Google okay. But the Chromebooks tend to be kept up-to-date because it's pretty much automatic. And I know a lot of security researchers use Chromebooks and use them exclusively because they don't have the same security problems as Windows. What's one of the reasons Apples don't get attacked as much as windows computers because the Macs, frankly, are not as common. They're only about 8% of the market out there, depending on whose numbers you're listening to. So why would they go after it? Plus it's a little more hardened than windows is. In fact, it's a lot more hardened than Windows is. Microsoft is starting to fall-in behind Apple's lead, which I think is a good thing.

So those computers, update them immediately. If you're still running Windows seven, make sure you get 10. Cause seven isn't getting the updates anymore. If you're running Windows eight, 8.1, make sure again, you upgrade to windows 10.

But brand new computers shouldn't come with those. Another quick word of warning about computers that you're buying. The home edition of Windows does not have the same features as the business additions or enterprise additions of Windows. So you might want to when you're buying something, look for Windows professional, it has more options. One of the options that could save your bacon is the ability to put off updates.

Now, you're I hear you saying Craig, you're always telling us to update early and update often. yeah, that's very true because many times when you get that patch, it's because there is something going on in the wild. Bad guys are actively using it to exploit you. To exploit your faults. Okay. So there are some very good reasons to stay up to date.

But, here's a problem. I had a law office call me up because right in the middle of them putting together some documents for the court that were due in less than two hours. Windows and they were running home edition, decided it was going to force them to do an update. You can imagine the trouble that ensued because they weren't going to be able to get the paperwork filed with the court in time. Very big problem.

Even if you're not an attorney, you're not dealing with the court. Windows professional does give you the option to schedule the dates, you can push them off for a week and then you can get into the more advanced stuff too, with the device management, MDM type stuff where you can now manage that device and make that device, secure, most, if not all of the time.

Okay. So let's move on next to tablets. Again, look at something like the Amazon Kindle. Here's my watch talking, hit the Siri button accidentally. So the Amazon Kindle fire that is an Android tablet. Now, one of the advantages is it is updated by Amazon automatically. It gets all of these security updates and other things. That's a very good thing, and it gets them for a fair length of time and they are cheap. You can get them for 50 bucks, 70 bucks brand new from Amazon. I got one a year or two ago, probably a couple of years ago. And it wasn't well packaged and it's shipping and the front screen was just cracked all the way down. So I returned it, they shipped me another one, and that one wasn't cracked. So that's good, but I've kept an eye on it and it has been very good. I also got with the amazon fire tablet, one of these stands that you can put it in, it's a charging stand, but when you place it in the charging, stand it then becomes an Amazon Alexa.

Little kids come over, grandkids, and they want me to play baby shark, which is an annoying song that, the grandkids, every generation has this. I remember a slightly older grandchild. A granddaughter who used to love, ah, jeepers. What was a gummy bear? That's what it was. Gummy bear. Remember, that song was incredibly annoying too. I ended up getting the guy who wrote the song on the radio show with me to talk a little bit about it. It was fun actually.

Those of us who needed to be kept up to date all of those tablets, because they are real computers, but nowadays we're buying appliances. I remember five years ago, I think it was out of the consumer electronics show. I saw another one that you put into your home and it had an Android operating system in it, it connected to wifi and it allowed you remotely to say, Oh, you know that steak or roast. It told you to cook in the oven at 5:00 PM, I'm going to be late. So you just go online and I type it into my phone and ta-da, I am now all set. There we go. And it's not going to start cooking it until six 30. that's all well and good.

That appliance has a computer in it and it's sent into wifi. Have you updated it? And does it self update? How long are they going to be providing updates for that oven? I'm sure five years later, there are no more updates for it. Now have an appliance, a device, that is frankly dangerous on your network because if somebody comes over to your house, they've got a laptop, they connect to your wifi and it now infects your appliance.

Okay. Whether it's your washer or your dryer. Those are the two most common, I think right now that are internet-connected or your oven or your microwave or your garage doors or your security system or your lights, those can all get infected. They are used as launching points to infect everything else on your network.

Check the update, make sure everything's up to date. And in some cases, it's pretty hard to update, but it's worth it. You have to do it even with your children's toys. One of the things I do is I put them on a network segment that has no access to anything else. I have an IoT wifi network, the internet of things.

You're listening to Craig Peterson. Make sure you visit me online. Craig peterson.com and sign up for my newsletter.

We've talked about, multi-factor authentication, we've talked about, of course, protecting your devices by keeping your software up to date and that's everything nowadays, really, and how to do that. What's up for that. And now we're going to go into a couple more good points.

Of course, you're listening to Craig Peterson.

Now, once you've purchased an internet-connected device, no matter what it is, if it's a router or firewall, if it's a Barbie doll, change the default password. In most cases you can connect to the device, just using a web browser that makes it very simple.

So you use the web browser, you connect to the device. Most of them have web servers on them. If you can imagine that, A little doll with a web server on it, but yeah, that's what happens. Your refrigerator probably has one of his internet-connected and your washer, dryer, light bulbs have little web servers built into them and you want to connect to them and change the default password.

Look up the manual. It's probably not going to tell you how to do it with the information that's in the packing. If you go online and search for that device, you can find out how to change it. Use different passwords for every device.

Always use complex passwords. Now complex doesn't mean that it has to have special symbols in this upper case, that lowercase, et cetera, it can just be three or four words strung together. That's all it needs to be. You might want to throw a digit or two in there, maybe a special character too, but a phrase is the best.

In order to do that, you're probably best off using a password manager to help out. So that means using something like one password or LastPass. Once you've got that in place, it'll generate these passwords for you, automatically. It'll remember them. It keeps them encrypted. So you only have to remember one password and that's the password you have set for the password manager.

Now, in my case, I've got it set up with DUO again. So I'll go into one password and one password is going to ask me for my password and it's also going to authenticate me via DUO on my smartphone. So there's multifactor, three-factor authentication. Okay. So important for all of these devices that connect to the internet.

Also check the devices, privacy, and security settings. A lot of times the manufacturer will let you set up an account on their website. From there, you can tell it what information you want to share and don't want to share.

Now, remember what I was talking about in the last hour with Apple, they are being very good about this and they are now demanding that all of the app developers disclose to you that you have indeed given consent for this information or that information to be used by that app developer and sold.

You can go to the Mattel website, set up an account for your device, or the Samsung or whatever it might be. And right there, you can examine your privacy settings and what do I want to allow the vendor to gain access to?

Make sure you're not sharing more information you absolutely need to provide, they're not going to ask you for social security numbers or other things. There's no reason to write that stuff that the bank or the IRS is going to want. Not these guys, at least, hopefully. Make sure you're enabling automatic software updates, wherever you can.

The latest version of the software usually tells you that it has the latest security fixes. Hopefully, it does but it also helps to ensure the manufacturer still supports it. If you've got automatic updates and they're sending updates to you and a hundred thousand of your closest friends who also have the same device, they're going to continue to support it and that way, the latest patches are going to be out there. If you're not getting the updates and nobody else is, the manufacturer is not going to have a lot of incentive to give you security updates. Then there's the normal stuff about, don't use public wifi. That's generally a good idea.

But if you're using a secure server connection, That's that little lock up in the URL bar. Then you are effectively creating a VPN between your web browser and that remote server, and that's going to be quite safe. So personally, I don't worry so much about that. I do worry about my machine being attacked, but I also have a very good firewall turned on and I have all of the services that I don't need to have shared turned off.

I am going to do a class on this, a little course on hardening windows. In fact, we've got it all written. We've got slides together. We'll probably be doing that after the first of the year. So keep an eye on your email for that. Cause anybody who gets my newsletter, I'll tell you about that.

How to harden windows, so that even if you are on public wifi somewhere, you're going to be relatively safe and the same thing's true. If you're. Using your phone for instance, and you're sharing your phone's network connection with your computer. It could still be used by bad guys to try and get into your phone.

These ISP internet service providers are not completely on top of all the security. Okay. all of the basic stuff don't provide personal information, financial information. I tend to use. These one-time credit card numbers. So every time, if I go to a site and I want to buy something, let's say I'm on GoDaddy buying a domain or I'm on Walmart side or Amazon site each one of those, I use a different credit card number. Check out your credit card provider, all of the major ones, Visa and MasterCard have the ability to create virtual credit card numbers. That way that credit card number can only be used on that website. So you create this credit card number. It's very easy to do. It's usually a plugin in your browser. You create a credit card number and it's for amazon.com. If somebody were to get that credit card number from Amazon and try and use it somewhere else, it will not work. It will only work on amazon.com. Isn't that cool. The other advantage is if someone starts misusing it, then you can just turn off that virtual credit card number. It's really that simple. So have a look at that. One-time use credit card numbers or these virtual credit card numbers, which is what I like where you can use it multiple times on that site, you don't have to create a new one every time available from most banks and all major credit card companies.

Also, be careful with the websites. You're going to make sure you type that URL correctly. As I said before, I always spend a few extra seconds whenever I'm on a website, I'm going to a website. I'm reading the email, just making sure that it is correct. I spelled Amazon or the email address that sent it to me is legitimate.

I can't believe how many times I get an email. It's a phishing email and it's from somebody@gmaildotcom as though a major business is going to use gmail.com. That's a word of warning too, to the small businesses that are trying to do online stuff. Make sure you have your own domain. That you're not using Gmail or Hotmail or Yahoo.

I've seen so many people doing that got even proton mail. Proton mail is quite secure and, it's really nice the way they're doing it. It's hosted in Switzerland. Check them out by the way. I put something about that in my newsletter a month ago with what that's all about. If you want it, just let me know, just email me@craigpeterson.com and in the subject line mentioned proton mail or something, and I'll forward you that newsletter so that you have it. You can always search if you don't delete my newsletters, you can always search for that information.

You can have proton mail set you up with your own domain. So it's from Bob's country store.com instead of Bob's country store at gmail.com. Okay. It looks much more legitimate. let's see offers obviously, be careful with those who don't click links or download attachments unless you're really confident.

Again, I tend to go to the website as opposed to click on the email that I got. There always this warning or that other thing, just go to their website, make sure that it's all being encrypted again. That's that little padlock if it's closed or your information's encrypted, which is really good.

If you can use a credit card. Don't use a debit card. There are laws to limit your liability for fraudulent credit card charges, but you don't really have quite the same level of protection when you're using a debit card and the money will be taken out of your account with a debit card. If a bad guy. Is using your debit card and then you have to file a police report and then you have to file with the company that gave you the debit card and then you have to wait for the money to be credited back to your account.

In the meantime, your checks are bouncing or if you use the debit card for other things, it is being denied. Okay. So be very careful with that. insufficient funds are always going out there.

I would urge you to just be very careful, very cautious, just like Santa Claus, checks his list and checks it twice to the same thing all the time when you're online.

Hey, if you don't get my free newsletter right now, make sure you sign up. I have all kinds of tips. That's what it's about. You also get all of my podcasts segment that you can just click on right there in the emails makes your life easy and helps to keep you safe online.

Just visit me online. CraigPeterson.com. You can go look at anything you want. If you scroll down on the homepage, there's a little form you can fill out. If you have an explicit question for me, always glad to answer them. And then at the bottom of the page, a little subscribe box will show up as well.

Take care, have a great weekend. Join me again next week.


More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started off this morning talking about Fake Faces and the legitimate uses for them and then got into some of the seedier applications that they are being used for and what we can do to protect ourselves from being victims. Then we got into some things you can do to be sure you are shopping securely this holiday season. Here we go with Matt.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Any of these internet-connected devices. So add to your list once you buy these things. Or even before you buy them. Do they self-update for security issues? Can I even get new firmware? Hey, I was on with Mr. Matt Gagnon this morning and we talked a little bit about our printer security, the security of the toys online. The shopping where you bought those toys, right. And being safe online. We also talked about, again, our little face generation, what's it being used for? Is it legit? Is it not? For three bucks you can get a little diversity on your website with fake people, which is just amazing. It's amazing how good it is. And it's amazing how cheap it is as well.

So here we go with Mr. Matt.

Matt Gagnon: [00:00:54] It's WGAN morning news on Wednesday, which is a great time as always to talk to Craig Peterson, our tech guru, Craig, how are you this morning, sir?

Craig Peterson: [00:01:02] Good morning. Doing well. Thank you.

Matt Gagnon: [00:01:05] Indeed. Craig Peterson also of course heard on this very station on the weekends, Saturdays at one o'clock.

If I'm not mistaken, Craig.

Craig Peterson: [00:01:12] Yes, that is correct.

Matt Gagnon: [00:01:14] And you'll be talking about many of these same issues when you've got the microphone all to yourself.

So let's get into them right now. cybersecurity, something that's often ignored and, something that's incredibly important. and, and I think this is a great time to talk about cybersecurity in general and this is something that I know you're passionate about.

Why don't you tell me what I should know about, printer cybersecurity threats that are often ignored?

Craig Peterson: [00:01:36] Yeah, this is a bigger deal than most people might realize. When we go into a business and start looking at the security, that's there. The first thing we typically do is do a little scan and we check to see what are the versions of software that are on the computers and the devices.

Now, we all know that we should be updating our Windows, machines, Macs, or our Android devices, et cetera. But. Most of the time we go in and in fact, I can't think of an exception. So I'm going to, I, most of the time, when we go in, we find that their printers have never been updated. Now, this becomes a very real problem because the printers are running a real computer inside of them, now. Especially these laser printers that are attached to your network and that particular little computer can be used and often is used to launch attacks. We've been into businesses that are saying, Hey, listen, something weird is going on. Our network is slow. The printer seems slower. We're not sure what's up. We've got some threats here. How did we get ransomware? In one case, that printer could be the source. So make sure that particularly in the shopping season, when we're online and more concerned about our finances. We've got taxes coming up again early next year. Quarterly's due at the end of this month. Make sure that your printers are up to date.

I would put that on my list to make sure this week you have to go to the printer. Many of them have a little webserver built right into them. So you can just use your web browser to connect to that printer, check the firmware version, which is the version of software on that printer.

Go to the manufacturer's website, find out what the latest version is. Download it and then install it on the printer. I know that seems like a lot of work and frankly, it is. The more advanced printers that are available out there. Do have the ability to automatically update their software. But it is key nowadays and too often, as you said, ignored.

Matt Gagnon: [00:03:52] Craig Peterson, our tech guru joins us at this time every Wednesday to go over what's happening in the world of technology.

Craig, I am interested in buying a unique worry-free fake person and I have about a $5 bill in my pocket right now. Can I pull that off? Can I get one?

Craig Peterson: [00:04:07] Yeah, you can even get one for free.

You can get them in for as little as a dollar. Many businesses now have been using these pictures on our websites for years and years. Oftentimes you'll go and hopefully buy one, right? Adobe has a service for that. There are many of them out there.

We have had problems in the past where those pictures didn't have the right release behind them and many companies especially, the SoHo small office home office. They'll just grab a photo online all the way through the big guys. Facebook is one of those that when you sign up, they say, all of your pictures, you upload basically bond to us. Some of these pictures have shown up on billboards and people have complained.

So number one, it's easy to use these types of pictures for our businesses and websites and things because these people just don't exist.

In fact, you can go online to this person does not exist.com and you can get your own fake person for free, which is amazing. You can buy them for as little as three bucks, just for one.

So yeah, your $5 bills do well. But there are also problems with this when it comes to just these dating sites. We've talked before, Matt, about people who are lonely. They go online, just trying to find maybe not full companionship, but at least someone to talk to.

There are many bad guys out there, all over the world who are more than happy to try and con us into sending money to help their, mother or whoever, who's supposedly is in the hospital and needs this surgery. There are so many excuses out there. Con us out of money.

If you generate one of these fake people and use that as your picture for your profile. Now, all of the standard techniques that are used to figure out if you stole a picture or from a site online and use that as your profile picture if didn't have to do a reverse lookup, but those types of techniques to see if you're a fake won't work because there, the picture doesn't exist anywhere.

So you've got to be very careful, online. And this is just another example of what's coming our way.

Matt Gagnon: [00:06:36] Craig Peterson, our tech guru joins us at this time every Wednesday.

Craig, before I let you go, obviously we are now. Fully and the holiday shopping season, December it's after Thanksgiving. So we now give permission to everybody to actually do this. so I think particularly given COVID, a lot of people are going to be going online. That's obviously been a trend anyway for recent years, but I think it's probably going to be even more pronounced this year. So in terms of keeping yourself secure while doing your holiday shopping online, what's some important stuff to keep on the top of your mind.

Craig Peterson: [00:07:05] Everyone knows the basics, right? We just mentioned keeping your computers up to date. You obviously want to look and make sure that it is what's called a secure site, which basically establishes a VPN from your browser to their site.

Unfortunately, that little lock in the corner of the website URL up there on your screen, that little lock doesn't mean your data is actually safe once it arrives. So make sure you are shopping at a legitimate store online.

Make sure while you are shopping that you also just look around take care make sure that deal is really a good deal. Do a little comparative shopping, just like in the old days.

Tying it back into the printer that you were asking about earlier, we're buying more and more internet-connected items. You might remember that. Barbie from a few years back that allowed interaction with it. You can talk to this little doll and it could talk back to you. It turned out it was sending all the audio straight to the internet. That's a computer inside that toy. That's a computer inside that washing machine.

Any of these internet-connected devices. So add to your list once you buy these things or even before you buy them, do they self-update for security issues? Can I even get new firmware for those devices? I want to encourage people to check out right now. Have I been pwned.com? That's spelled it. Have I been P W N E D. Have I been pwned.com put in your email address and find out has my account been breached? More or less? It probably has been. It'll tell you where it's been breached. It'll tell you if your credit card number was stolen, your password, your email. Whatever was stolen in that particular breach. Keep in mind that we need to change our passwords. We need to find out where they have been breached. And maybe be a little more cautious with that particular company in the future.

And as we go out there again, Stop. Think. Look at that email, that website make sure it really is legit.

Matt Gagnon: [00:09:33] Indeed. Craig Peterson, our tech guru with some great advice here as you head into your holiday shopping habits.

Appreciate it, Craig, as always. And we'll talk to you again next week.

Craig Peterson: [00:09:41] Take care, Matt.

Matt Gagnon: [00:09:42] All right.

Craig Peterson: [00:09:43] I had a little bit of noise there underneath my audio. Anyways, we'll have to see where we can fix that. Everybody have a great rest of the week. Hope you did have a fantastic Thanksgiving.

We'll be back on Saturday. Of course.

Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed the Fake People Phenomenon and some of the positive and negative impacts it is having. Then we got into Online shopping and how to do it securely. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] One of the ways that people get scammed, and this isn't just our more senior citizens, but it's all the way down into their thirties and forties. By people who put up fake profiles on these dating sites.

Hey, good morning, Craig, Peterson here. I was talking this morning on the air with Mr. Jim Polito, and we spoke about some of the major changes this year because of the lockdown that we have seen in the online business.

What can small retailers do? What should you be doing when you're shopping online? Then we got into the whole "designed to deceive" thing with pictures. There's some, this crazy website out there that lets you create completely fake people. So all of that and more here, right now with Mr. Polito.

Jim Polito: [00:00:56] One of our favorite guys, I'm talking about our tech talk guru, Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:04] Hey, good morning.

Jim Polito: [00:01:06] How are you been?

Craig Peterson: [00:01:08] I've been doing pretty well. Not sleeping so well the last couple of nights, but it might be all of that Turkey, I think.

Jim Polito: [00:01:15] I thought that was supposed to make you sleep with that L-tryptophan, but maybe not.

Craig Peterson: [00:01:20] Yeah.

Jim Polito: [00:01:20] Maybe not. Listen you celebrate Canadian Thanksgiving and then this Thanksgiving, maybe it's just too much Thanksgiving.

Craig Peterson: [00:01:28] That's true. It is a Thankful time. I'm so glad to be here. It's this crazy. We've got a great family and even though some of them were remote, it was still, it was a really nice day.

Jim Polito: [00:01:41] I'm glad to hear that. All right, let's get a look at, well, first of all, let me just ask you off the cuff, cyber Monday. Black Friday, they were really the same thing. There was a great increase in retail shopping, but it all came online, I guess.

Craig Peterson: [00:02:00] Yeah. Yeah, no, it really did. This year. Their stores were down depending on the store, their traffic anywhere from about 60% to 75%. So it was online, but there wasn't the emphasis this year on those two days, you mentioned of course, black Friday, which has been historically where businesses make their money.

They finally go black. And then cyber Monday for the online businesses, but that emphasis now is over the entire season. We saw a week or two weeks beforehand of these stores offering great deals or at least what appeared to be great deals. As we've talked about before, You really gotta shop around.

Jim Polito: [00:02:45] To make sure that you're getting the right deal. I would imagine that you feel this trend will continue right through the holiday.

Craig Peterson: [00:02:53] Yeah. I've mentioned that a couple of times in my show as well, but yeah, the bottom line is this is just going to keep going.

These retailers have to make the money. There are a few like Amazon, for instance really profited. More than that it's like half a million new employees roughly over at Amazon right now. They've really profited from this whole lockdown thing. Many other businesses, particularly the small ones have really suffered.

It's hard for people to shop. For instance, when I talked about what are the things you should do or look for when you're shopping online? One of the things is to really look at the retailer. Can they be trusted with your data? I hate to say that because it's the small guys that have a hard time with it, at least so you'd think right. Equifax, TJX, and all these other big ones aside. It's difficult for them to come up in the search engine results. It's difficult for the small guys to be able to really compete on any sort of an even footing. Then you get these search engines like Google that really do weigh things towards some of their own properties.

You get Amazon who weighs things. There've been suits that I believe Amazon just lost a suit over in Europe because when you do a search for something on Amazon, they will steer you towards their own products. And I've seen this before and you may not be aware of it, but they have dozens and dozens and dozens of their own private-labeled products.

So when you're buying something, it could well be an Amazon thing and not from some small company.

Jim Polito: [00:04:42] Hey, I bought it, but this wasn't like a private label. It was actually the Amazon label. I bought Amazon batteries because I needed some and they had their D cell batteries, the real big ones. Amazon. I don't know why had a limit on the number you could buy. So I bought some Rayovac and some of theirs, I maxed out on both of them cause I needed a bunch of batteries. It was for, these window candles, you know? It was Amazon made.

It wasn't like them being sneaky or it wasn't made, I'm sure it was made under license, but it was the name Amazon on it and it was a battery.

Craig Peterson: [00:05:25] Some of those are really good. And I've done that before, too. I've got an Amazon power strip and I use these batteries that are rechargeable. It's a new generation. You can recharge them a thousand times. It's just incredible.

They perform as well as a regular battery. So I use those very, very frequently and they're Amazon branded. I used to buy, what is it, Sanyo? I think was the original company Panasonic.

Jim Polito: [00:05:55] Yup.

Craig Peterson: [00:05:56] Rechargeable batteries.

Jim Polito: [00:05:57] Interesting. All right. So the trend continues. Amazon will be sneaky. Speaking of sneaky, you sent me some stuff in the notes that was incredible. It's actually the first story in the notes. It's about designed to deceive making fake people. Now, why would I want to make a fake face? Not my face, but a fake face.

Craig Peterson: [00:06:25] Well, I can tell you, I, you know, I've been doing internet for Oh, since 83, I think was I first got started in it. Wow. But here's the problem I've seen. Cause I started making commercial websites back when it was legal to do it. And that was September of 91. And we built some of the biggest properties. You might remember Big Yellow or Superpages, you know?

Jim Polito: [00:06:54] Wow.

Craig Peterson: [00:06:55] I put together the team and we wrote all of the software and we built the data center. We ran it, absolutely everything. I've built websites for the last count it was over 5,000 businesses over the years. Not something I really do anymore. One of the problems we had with those websites is that people would say, okay, well either I need a group of people on my website here, or I want this face, or I want that face and you can go and you can buy these pictures of people and it's a model and they have to assign the release. Then once they've got that release signed, you can use it, but you still might get sued.

I had more than one occasion where they came back to me and said, we have to change the picture because we were contacted by that person and that did not cover this type of usage of the picture. So it's very legitimate reasons.

If you're going to put a face-up on a website, So now we can go to a website called generate photos, and you can buy a big person for as little as a buck, depending on how many you want. And you can go right now to a website for free called this person does not exist.com and get a completely computer-generated person. And you know what? It looks like a real person. So there are legitimate reasons for this, but as you can guess, Jim, there's illegitimate too.

Jim Polito: [00:08:29] Uh, yeah. And you know, this is like that whole thing I see on Tik Tok.

Like people actually themselves superimposing the face of say, Arnold Schwartzenegger. Over them. And it's like a combination of their face and Arnold, and it looks really reall.

Craig Peterson: [00:08:51] Let's talk about another side of this. That's bad. It's very similar to what you're talking about, and that is people are being scanned all of the time, and one of the ways that people get scammed and this isn't just our more senior citizens, but all the way down into their thirties and forties. By people who put out fake files on these dating sites. And they started a relationship back and forth. And then, you know what?

Jim had turns out that their mother needs surgery. It turns out that it's going to be like $5,000 and they just can't afford it. And this is part of a conversation they're really working with these people. These are crazy good Grifters, nowadays. And that's where we're concerned because now you can take one of these pictures.

You can put it up on one of these websites, you can now start a conversation and this is going to lead to even more people being scammed. And I'm very worried. You're in the holidays is there's so many of us out there that are lonely and looking for. I have a little bit of companionship, even if it's just online the way they've dealt with it before is, and I'm sorry, I'm going on and on here, but this is something that really irks me, but the way they've dealt with this type of thing before is.

You, you have someone who sets up a new profile. So there are people, usually volunteers at these dating sites who take that photo and use Google's reverse image search to see if that's a legitimate person, or if they took the picture from some other site out there. And then they'll say, okay, well, this is obviously not a real person because we found this picture on 50 other sites, and doesn't look legit.

Well, there's something like this. They're not going to find a picture anywhere because it only costs them three bucks to buy one picture.

Jim Polito: [00:10:48] Wow.

Craig Peterson: [00:10:49] That doesn't exist. It's not a real person. Right. So I'm getting worried.

Jim Polito: [00:10:54] Yeah. So I do that reverse image search. Right. Which I always do. And nothing comes up because it's unique.

Craig Peterson: [00:11:05] Yeah. This is AI now. The other people that should be worried about this, and you mentioned the videos is Actors, right. Who are out there because now they can really take anybody who physically can move around and do all of the actions that they want, and basically do it in a green suit and then paste any base they want to on it, including these types of faces.

So you'll see, in the future, these movie companies having fully computer-generated people from every angle, everything about them. There will be I don't know if they're going to copyright and trademark it patented. I don't know what they'll do, but now they don't have to worry about that. Actor or actress aging.

Because they can always use them and they can generate that say says at 80 years old and that same face at 20 years old. It's really going to change everything.

Jim Polito: [00:12:09] Yeah, I know. I mean, the set, the difficult thing is, um, For politicians too, cause somebody could ruin your you're running for a race and somebody could, uh, put you, um, as a politician, into a compromising situation, release that video.

And as Mark Twain said, you know, what is it? A lie makes it all the way around the world before the truth gets up out of bed. Um,

Craig, this is fascinating. So you've got the show on Sundays. From 11 o'clock great show, um, that everybody should watch on and listen to on TAG and HYN. And then, uh, if people want to reach you, what do they do?

Craig Peterson: [00:12:52] Well, the easiest way is go to my website@craigpeterson.com. I answered questions every day that people just email me. I'm more than glad to do that. Just email me ME@craigpeterson.com.

Jim Polito: [00:13:06] Craig, always a pleasure and thank you so much, sir. We'll talk to you next week. I hope you get some sleep.

Craig Peterson: [00:13:12] Thanks. Bye-bye

Jim Polito: [00:13:14] All right. A final word. When we return, you're listening to the Jim Polito show, your safe space.

Craig Peterson: [00:13:20] You guys might be interested to know that I was on WBZ. They started making some little news things with me, as well as WRKO too. The big powerhouses in the Boston market. So that was fun yesterday. Hopefully, we'll be able to just a little bit more of that, get this word out to people, but what they should be doing.

I got a great little note too, from one of our listener's Guy, and he was saying, okay, after yesterday, Monday, I'm going to have to check off of the pictures in the office, make sure their firmware is up-to-date.

So another note, really good thing here, hoping to raise awareness and telling people what they can do in order to get. A little bit safer in this online world.

Take care of everybody and we should be back tomorrow. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Jeff Chidester on NH Today. We hit a number of interesting tech topics this morning. We started off with Fake People and the legitimate uses for them and then we got into how the scammers are using them. Then we discussed how your office printer can be used as an attack launchpad into your business network and how you can prevent that from happening. Here we go with Jeff.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning, everybody had a good call with Mr. Jeff Chidester on New Hampshire today. And, they still don't have a permanent host thereafter Jack Heath left, but anyhow, we had a good little chat about everything. Printers and what the federal government's warning about from your shopping this year, all the way on, through the basics of some of the privacy that we have, or maybe we don't even have anymore. So here we go with Mr. Chidester.

Jeff Chidester: [00:00:32] 38 past the hour. Jeff Chidester with you. Of course, our next guest Craig Peterson, you can find out more by going to craigpeterson.com. Craig peterson.com. Also, you can hear him on tech talk right here every Saturday. Plus you see them all over the place. So he's just about everywhere, Craig, how are you?

Craig Peterson: [00:00:47] Hey, good morning, that's because I need to lose a few pounds, I think. I'm everywhere.

Jeff Chidester: [00:00:51] I have a great idea for you. you can have a fake person generated. That's actually one of the top news stories you were talking about. This is a really odd dynamic that I've seen over the last few weeks. That is as real, it doesn't seem like it would be nefarious, but there are some implications to this of being able to generate fake people to put up online.

Craig Peterson: [00:01:12] Yeah, there really is it, I have built a website since it was legal to new business on the internet using the web. When that whole protocol came out. One of the biggest problems we've always had is, what faces do we put up there? most of your customers don't want you to take.

It cheers with them. And we've had issues in the passage from people in different phases. And this is all part of this kind of this deep fake that's been going on for quite a while. I have a software impact on doing podcasts and any sort of audio recording. Yeah. That I trained for my voice, Jeff so if I'm there and I'm saying, man, I just love listening to Hampshire every day, but I, it should be on Saturday and Sunday as well.

She could have added that in after I recorded it. Just add in that it should have been on Saturday or Sunday. And it sounds like it was me saying that. We've got deep fakes now for videos. You've probably seen some of those things where people put in have their favorite celebrity, do whatever they want.

Now, what you're talking about is you can go for free, there is a website you can go to for free and have a, get a photo. If you will, of a person that just doesn't exist at all. You can get them for free. you can buy them for a buck apiece, depending on how many you're buying. These are attractive faces.

They look like they're normal. And this technology over the last three years has gone from you gotta be kidding me that wouldn't fool a soul back in 2017 to today where it is absolutely amazing. Check it out. Check, go to this person does not exist. And get your own free, fake face.

Jeff Chidester: [00:03:03] We're talking to Craig Peterson.

Once again, you can find out more by going to Craig peterson.com. I always, I kid with people that I have a face for radio, so maybe I should hop over there again, really. That's what Jeff looks like. we talked about, this could be a great tool for businesses. As you said, for those who go through testimonials and the picture, people don't want to be pictured and stuff like that.

But, people can actually, there's a, there's something about a face, seeing a face that could lead to a false trust factor. Talk a little bit about that as well.

Craig Peterson: [00:03:31] Yeah, that's that is a very big deal. It's been a problem for a long time. One of my sons is a volunteer on this dating site and what he does is when people submit their, their photos, as well as other stuff, he verifies it.

So you'll take the photo. Google has a reverse lookup. That allows you now to check and see, does this photo exists somewhere on the internet? So you'll take the photo of Jeff Chittister and you'll put it into Google reverse image search. And it'll say this person picture shows up all over the place.

With Jeff Chittister, he's going to be in some newspapers, he is going to be on the iHeart radio site, et cetera. okay. Those are all legitimate. But what if you wanted to cheat someone out of something. This is happening more and more where it's not just our seniors, it's the younger generation now generation Z that is far too trusting of information online.

So you could generate very easily. As I said, go to this free website. This person does not exist.com. They could use that. Photo from there posted somewhere. I have a make a new Instagram profile or Facebook, whatever it might be, and then con people.

Because even if you're smart enough to know that you should do a reverse photo lookup on that person, it's not going to show up anywhere. And that seems a little bit illegitimate. I don't know. Maybe in this day and age, if the person's photo doesn't show up anywhere, maybe it really is a fake, but this is incredible because they can also take that face and they can make them talk.

They can turn it into videos. They can become now your product. Person. And Hollywood's really worried about this because what it has the ability to do is take someone completely unknown person/Actor have basically put them in a green suit, have them do all of the physical stuff, and then they can paste in whoever they want, saying whatever they want.

And the actor in 10 years from now, are going to be second class citizens.

Jeff Chidester: [00:05:42] Oh, yeah. and just completely destroyed those wages as well. I want to go to talking to Craig Peterson, Craig peterson.com. You can find out more.

So more people are working remotely. One of the other interesting stories you were talking about more people are moving remotely, and we always think about the computer as the actual laptop or the desktop it's choosing from home for your office work as the issue of the greatest susceptibility to cybersecurity.

But now we have to look beyond that computer don't we when we're talking about remote employees?

Craig Peterson: [00:06:12] Yeah, you do. There's there are so many things that are on people's networks and so many devices that are there now. And so many of them have been compromised and, I'm always beating my drum out the Android devices, and don't use them, Because the biggest problem is that they don't get the updates. They don't get those software updates at the rate that Apple does.

Apple will release a security fix and it'll be installed on 70% of the phones in two weeks. Versus Android, where many phones won't get the updates. And right now I thought that I saw that 60% of Android phones are three major releases behind. So you know that you've gotta be very careful. If you're a business person, you have to extend the security that hopefully, you have in the office out to all of your homes are people's homes and their mobile devices, whatever they are.

When we're talking about updates, that's another thing that's come out in that great article by the people who are providing the cybersecurity and infrastructure protection. There's this security agency about that. They're warning us now with this gift-giving season coming that we have to keep everything up to date, including remember our appliances, all of our electronic devices, and nowadays, more and more our children's toys.

It turns out even some voting machines are connected to the internet and they're running Windows Seven. If you can believe that,

Jeff Chidester: [00:07:51] I will tell you the story I had about a few weeks ago about a guy who's still running Excel 97. I don't even know how you do that. but clearly, that's something to think about, and it's you're right, because a lot of these businesses too, Craig only have one or two, IT people, and they have been just inundated with moving people into a remote office and then trying to manage that most officers weren't ready for that.

So even like the printer, becomes an area of susceptibility, because they're not printing in the office anymore. They're going out and buying one or giving them a generic one to use at home.

Craig Peterson: [00:08:23] All of those, again, attached to the network. Have you ever updated the firmware in your printer? That's now on your network or your light bulb that comes in the roof above you?

And now we've got the children's toys that are coming our way. All of those, especially for using a VPN. Can now get through the VPN to the offices called piggybacking. And what happens is that the VPN is running on your machine. Whatever it might be, a mobile device and other devices that are on your network can potentially. Use that it's just like having a roadway. Almost anybody can get on unless things are configured properly.

Printers. When we go into facilities, businesses, even bigger ones, even DOD department of defense contractors, we're finding printers that have never, ever been updated. That has major security problems and is, in fact, the source of this security vulnerability and loss of all of their data and intellectual property. It all started with a printer.

Jeff Chidester: [00:09:27] There's so much to think about once again, that's why I need to follow Craig. Once again, Craig peterson.com Craig peterson.com.

Here we are worried about the Terminator when we should've been worried about Teddy Ruxpin. I'm looking down the hallway to see this thing marching down, cause he's been connected to the internet as well.

Hey Craig, we've actually run out of time. We've got to remind everybody who wants to Craig peterson.com Craigpeterson.com.

I'll see you heard on this radio station and other radio stations this weekend as well.

Craig Peterson: [00:09:50] All right. Take care, everybody. Thanks

Jeff Chidester: [00:09:52] You as well, Craig, once again, all that great stuff.

I would highly suggest that you go ahead and, make Craig part of your, one of your bookmarks or favorites. Cause he keeps you up to date on all the things you heard here, plus other interviews and other podcasts he duds does are all located up on Craig peterson.com.

What we'll do is go and take a break right back, catch you up, up to date on the markets on this first day after the Thanksgiving holiday.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

Happy Thanksgiving day to all!

I was on WGAN this morning with Aaron Chadborn and started off this morning talking about electoral issues that are taking front and center in the result counts going on. I discussed Dominion Voting systems and how they meet even the level of cybersecurity that is required at your local pizza shop. Then we discussed online shopping, Black Friday, and Cyber Monday Deals. Here we go with Aaron.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey good morning, everybody. I hope you are going to have a great Thanksgiving this year. We're just so busy, my wife and I getting everything ready, doing all of that.

This morning I was on with a new guy because he's sitting in for Matt. Gagnon. His name is. Aaron Chadborn. He's been involved in politics for a long time.

In fact, worked for the governor for a while. We talked about this dominion voting system. We got into it a little bit. I'm going to get into it a lot more on my show this weekend. we also spent a little bit of time talking about shopping this season here, where should you go? What should you do?

What can you expect? So here we go with Aaron on news radio five 60 am and 98, five FM W G A N. I had to put that in there. Well, I didn't have to wait anyway. Here we go.

Aaron Chadborn: [00:00:56] I'm Aaron Chadborn filling in for Matt Gagnon. We wish him a very happy Thanksgiving. He's on vacation all week.

We are not in Jeremy mixer in the sound, but with a freezing, I'm sensing a theme. I think it's cold outside. It's very cold outside.

Well, we are pleased to be joined once again for Tech Talk with our good friend, Craig Peterson, Craig, how are you?

Craig Peterson: [00:01:16] Hey, good morning, doing well. A little work in the bathroom, remodeling, and the normal COVID stuff.

Aaron Chadborn: [00:01:24] Well, I think that during COVID, everyone's been home much more than usual, and I've been talking to folks who are contractors or who are at Home Depot, Lowe's and they say that everyone's doing a new project. So I think you're in good company, Craig.

Craig Peterson: [00:01:40] Well, looking at the stock value of Lowe's and Home Depot. Yeah. Yeah. Oh, wow.

Aaron Chadborn: [00:01:48] The year 2000 for elections, it was Florida, Florida, Florida. This year. It seems like it's Dominion, Dominion, Dominion. Obviously, a lot of people are very concerned, whether they're hearing about technology and these dominions voting machines.

Craig, I know you've been watching the issue closely. What can you tell us about what's going on there?

Craig Peterson: [00:02:06] Well, this is huge. In fact, I'll be talking about that on my show on Saturday at one o'clock right here, but in doing a deep dive, but it is really very concerning. You know, I do security for a living. That's what I do.

I run the webinar training series for the FBI and their InfraGard program. Ideal with everything from a pizza shop, all the way up through Department of Defense contractors and providing cybersecurity for them. So I kind of know a little bit about cybersecurity when it comes right down to it here, Aaron.

What we're seeing now with Dominion is very, very concerning. And I wanted to just make a comparison between what's happening with our voting systems. the majority of states in the US are using the Dominion voting system and compare that to the very basic the bottom, the beginning, of where you should be in cybersecurity.

Now the basics when we're talking about cybersecurity are what is known as the payment card industry standard. PCI has been around for a long time, and it is what you have to do to accept credit cards. This isn't DOD stuff. This is very, very basic. In fact, what your local pizza shop has to deal with. They have to be PCI compliant. There's this massive 400-page document that they have to accept and then go on from there.

So I got a call from a pizza shop. They had been informed that they were going to be audited because there were some questions about some credit cards that have been processed. So the payment card industry was going to come out just to find if they had been breached and the data was out on the internet about people's credit cards. Was more than a hundred dollars per credit card that had been taken by them over the last year? We're talking huge, huge fines. So we went out, we had a look and sure enough, they weren't compliant and they needed to be compliant within two days. So we got busy and we upgraded their security, but it's very, very basic stuff.

So comparing Dominion, which is our voting. This is our right here as citizens of the United States. Comparing Dominion software and voting systems to what a pizza shop and has to comply with, Aaron, what do you think? Do you think pizza shops should have more security requirements than the voting systems?

Aaron Chadborn: [00:04:50] I think they certainly have higher thresholds and better resumes. then some of the people running our voting systems, Craig.

Craig Peterson: [00:04:58] Well, PCI, the payment current industry standards have 12 different requirements or controls that you have to meet in order to accept credit cards. Of those 12 requirements, the Dominion voting system meets only two. It fails on everything from built-in firewalls, through proper password protections, a cardholder data, or protecting voter data of maintaining antivirus software being even patched up to the latest versions of Android or Windows, restricting data access. Having logs on the voting machines that cannot be modified. You can go in and modify them with just a basic admin password using the same password on multiple machines. It goes on and on-air, just how bad this is.

When you compare an online voting system, for instance, or I'm looking right now at a company and you can find them online called elections online, and they have a basic set of online voting software. They are PCI validated. They meet the basic requirements. It's $800. Versus $800,000 for Dominion system

Aaron Chadborn: [00:06:25] You're listening to WGAN Morning news. This is Aaron Chadborn in for Matt Gagnon. And we're talking with Craig Peterson. You can hear him every week on Saturday afternoon from one to three.

Now, Craig with Thanksgiving coming up tomorrow, Friday is Black Friday. I know you always have tips and tricks for Black Friday. What are you pointing people toward this year?

Craig Peterson: [00:06:44] Well, Black Friday and Cyber Monday, frankly. Have been changing places over the last few years, and this year. It's completely different again, because of what we're seeing is that the deals, the great deals that we used to have online just don't really exist this year.

Yeah. There are some deals and you need to be an informed shopper, and that means you've got to go online. You've got to poke around. I can guarantee you that Amazon does not have the best prices on things. Guaranteed. Amazon has now taken its market leader position and been cranking up on the prices.

Walmart, when we're talking about online has some great values this year. So look at cyber Monday a little bit more. Don't just buy something on Friday this week, thinking that it's going to be a good deal. It's guaranteed to be a good deal, cause it's not true. Cyber Monday, we're expecting even better deals.

I think the bottom line this year, Aaron when we're looking at all of them, is to pay attention. Shop around. There are a lot of reasons not to shop this year on Black Friday. One of the biggest ones really is that the deals are hard to come by. These bargains aren't necessarily as good as they appear to be. There's plenty of other chances to save, even later in the season this year.

Aaron Chadborn: [00:08:16] Well, I think that, you know, we were talking earlier in the show, Craig, that it's going to affect a lot of brick and mortar retailers in a number of ways. This is going to be one of, I think the most difficult holiday seasons that a lot of our local mom and pops and local retail shops have ever seen.

So I know as much as I like getting deals online, I'm trying to do some of my shopping in person this year. I'm spacing it out. I'm not waiting in line on Friday morning. I'm trying to make sure that those people that are using those payment systems, that local pizza shop is still going to be here.

We lost bull moose music. We just learned yesterday in Portland. Um, but you know, I, I think a lot of us are looking for new ways to support our local retailer.

Craig Peterson: [00:08:53] And that's a great thing to do. I've been doing that as well in many of these retailers because of COVID because it can have as many people in the store at one time, they are now going the whole week, this week, and probably all the way up through Christmas this year, in providing deals for people that come in and you know what? I like that friendly face, a small local toy shop.

One of my daughter's first jobs, I think it was her first job. She was fifteen and she had the key to the toy store.

They went out of business years ago and now you'd have a look around. You're not going to see Toys R us anymore. Even the very big, you know, opposite ends of that scale. Aaron, all retailers have been hurt. I do try and go local. That's a good consideration this year.

Aaron Chadborn: [00:09:43] So for folks looking to tune into you on Saturday, Craig, what else do you have coming up?

What topics are you going to cover?

Craig Peterson: [00:09:48] Well, we're going to do a deep dive we're into the whole Dominion, the whole voting system thing where we're looking at what's happened with Texas. Why did they reject it? And they had a lot of good reasons for rejecting that system. How can we keep our elections safe?

In addition, we are going to talk a little bit about holiday gift shopping and how Apple is trying to stop some of the creepy user tracking that's been going on.

Of course, a little bit about how cyberattacks are working today. Are we expecting too much from our internet service provider?

There we go. I hope everybody had a great Thanksgiving. It is a wonderful time of year. I actually kinda like this time of year.

Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed Why I think it is safer to buy pizza than to Vote. Then we got into the lack of deals this Black Friday and Cyber Monday and why it pays to shop around. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. I was on with Mr. Jim Polito this morning, and we talked about the dominion voting systems. Did you know, your vote is not as safe as buying a pizza?

We went into that. the reason why I'm really upset with the way this whole software is set up is it's just craziness.

We talked a little bit about whether or not, you should actually be shopping on Black Friday. There are a lot of changes this year. So here we go with Mr. Polito.

Jim Polito: [00:00:33] Here he is. Always great to have him here and even though as a Canadian, he already had a Thanksgiving back in October. He joins us now leading into Thanksgiving, a lot of important stuff on the plate.

How about the Dominion voting system? But before that, How about his recommendation that you don't shop on Black Friday? Whoa, joining us now. Our good friend and tech talk guru. Craig Peterson. Good morning.

Craig Peterson: [00:01:03] Hey, good morning, Jim. It is one of those mornings. Isn't it?

Jim Polito: [00:01:08] It is. I want to get to the dominion thing, which is important.

It's relevant with the election, the president's complaints, but, you don't want me to shop on Black Friday? Is this a, just an ethical thing, a moral thing, or is this a Jim, I can save you more money thing?

Craig Peterson: [00:01:26] First of all, there's Cyber Monday, which of course people are now familiar with, which is the Monday after Black Friday.

And the deals are really interesting this year. I don't know what you want to blame it on, whether it's been some of the lockdown stuff or something else. The deals have been there all along. But this year, it looks like many of these retailers are looking to make up the difference of the money they lost because of us just not shopping anymore.

And they are not giving us these deals. They used to, in fact, these online deals now are. Pretty hard to come by.

Jim Polito: [00:02:03] Ah, so it's not so novel anymore, right? Oh

Craig Peterson: [00:02:09] Yeah. That's a really good way to put it. Yeah, I liked that.

Jim Polito: [00:02:12] So now they're just going to stick it to us through the whole thing.

Craig Peterson: [00:02:17] You also want to look at companies like Amazon. Amazon is expected to be a big winner this year, and so is our Walmart and some of the others.

But if you look at Amazon and look at their prices, people just assume that you're going to get the best price, the best value by shopping at Amazon. It certainly is probably the most convenient, especially if you pay that extra a hundred and change right every year to Amazon.

As it turns out, those deals that you're seeing on many of these sites, Amazon included aren't so hot. You really have to do comparison shopping.

Jim Polito: [00:02:58] Ah, I see that,

Hey, Our folks who do the financial exchange showed on TAG and HYN. Barry Armstrong told me a while ago, you know what, Jim, you should comparison shop when you're online shopping.

And I said, other than Amazon, he said, try Walmart. He said Walmart is really making an effort. For the things that Walmart stocks, there are times you can beat Amazon, and if you order enough, you get free shipping. He's right.

Craig Peterson: [00:03:26] Yeah, absolutely. And with Cyber Monday this year, again, we are expecting even better deals than we will be seen on Black Friday.

Compare, make sure you've got that budget line down, obviously the normal don't fall into the hole of running up some of your credit cards. Look online is a great place to go. You probably also want to visit some of these local retailers. It's a shame to see all of these stores closing, but frankly, the majority of us will be shopping online this year.

It's like over 80%.

Jim Polito: [00:04:00] Wow. I remember years ago having conversations following the holidays and it'd be like, Oh, 20% of people shopped online, like this, and now the whole thing has flipped. COVID pushed it over the edge, but the whole thing was flipping.

Craig Peterson: [00:04:16] Yeah, it is flipped in a very big way.

Many of us, me included. We just go to Amazon and buy something. it's just so easy. My family. And as we've got a couple of kids. we, every year we have a gift exchange and rather than everybody buying something for everybody cause there was 10 of us. plus now the grandkids and the spouses, we have one of these sites that you just put everybody's name in and it goes ahead and split them up and says, okay, you've got stocking, you've got the main gift or this particular person and that site is free.

But here's how that works. You do some research using this site and they list here's what I want for Christmas sort of a thing. And they now get a commission on anything that you're buying. Via their sites. So every link that you click on, every gift that's in there tends to be with Amazon and they make over there one to 3% on every gift.

There's just not a big amount of money, but it's enough for them to have a whole business just based on that.

Jim Polito: [00:05:28] Wow. Wow.

All right. Let's get to, now that we've done the shopping, we've got our shopping out of the way we got to get down and dirty.

We've heard a lot about Dominion. This is the system for voting, that the president and his allies have pointed out is easily hacked and is not good. And, you've actually uncovered some more stuff about it.

Craig Peterson: [00:05:55] This is frankly, to me, the biggest indication of how bad this stuff is, but, I professionally do computer security, network security all the way from a little pizza shop, right by the studio. In fact, there's one all the way through the department of defense contractors.

So I see all of this security stuff. I see it almost every day, right? Yeah. And w here's the very basic level right there. There's the DOD and then there's a pizza shop. On the other side, the pizza shop, anybody that accepts credit cards has to comply with what is called the PCI standard, which is the payment card industry.

So you have to have certain security in place, no matter what kind of business you are, if you are taking credit cards. And if you don't, there are massive fines that come from the payment card industry. that contract, I don't know if you checked it, but it's over 400 pages long that you sign\ just to take credit cards. Okay.

So just taking credit cards. So let's look at the requirements for PCI. There are 12 basic requirements on security to accept credit cards. Okay. and you look down this list of them and you compare it with our friends over dominion voting system. And they fail our voting systems that were used in so many States, including here in the Northeast, that system is not compliant with 10 of the 12 controls. In other words, it's failing 10 of them, basic ones.

This is a little slimy if you ask me because there's a comparison that I looked at here from the Gateway Pundit, and they looked at HOA voting software and HOA voting software is fully PCI compliant, right? These are just basic things you need to be compliant with us to run a pizza shop. Okay.

Yet the $800,000 that our States have paid dominion, that software 800,000 is far less secure than the $800 HOA voting software. So it's a shame, of course, Elizabeth Warren or Senator, she wrote a letter complaining about that.

Jim Polito: [00:08:27] So the liberals back then and the left and the anti-Trump crowd. They were all on board saying this system is bad and now all of a sudden. No problem, nothing to see here, folks.

And on top of all of that, we have the NSA and these other organizations saying, we have no evidence of any hacking. Everything was okay.

How deeply did you look? Did you look all the way down to every single local system? I'm not suggesting that there was some overreaching, conspiracy with, worldwide conspiracy, has been inferred. How about just a local little conspiracy? Do you know what I mean? In one or two precincts that's sometimes all it takes.

Craig Peterson: [00:09:15] Yeah. And just real quick here are the Fails for dominion software. No firewall that's required by PCI. They do not have password protection in place here. Many of these systems are sharing even the same password. Data dumps or private voter data are possible on this. Encrypted transmitted data. In most cases, these things were not hooked up to the internet, but in some precincts they were.

Jim Polito: [00:09:45] Yeah.

Craig Peterson: [00:09:46] No antivirus. They don't have proper controls in place for updating the software. And we heard about that right? The night before the election, all of a sudden their software getting pushed out. Restricted data access failed, the whole concept of the need to know. Many people external even to the secretary of state's office have access to some of this data. Unique IDs for access.

Restricted physical access. Create and maintain access logs. The logs on these systems can be altered by anybody with an administrative password.

Jim Polito: [00:10:21] Wow.

Unbelievable. that's heavy-duty. That's heavy-duty and these are the things that people need to, keep in mind. Do you know what I mean?

Like when you're talking about all these systems are okay and this and that. It isn't okay. I love your analogy of, yeah you want to do business and had to take your credit card, 400-page contract. Compared to the dominion system something more important than a simple financial transaction.

And it doesn't even come close to the protections that no, it just doesn't. It's crazy.

Every time you want to do something, it's voter intimidation. It's not. But it's the most important thing we all do.

Craig Peterson: [00:11:07] It's true. and it's apparently running windows seven, scan and touch it for vulnerabilities.

No, it's gone years with the same security issues nothing's been done. This is absolutely crazy. What the heck's going on. Yeah.

Jim Polito: [00:11:25] Craig, this has been fascinating. And our Craig Peterson folks has a show every Sunday at 11:00 AM on WTAG, WHYN Craig, in the meantime, we want to wish you a very happy Thanksgiving to everyone in your family. I hope everyone is safe, but, How can folks get in touch with you?

If you have a question, you can always email me Me@craigpeterson dot com or all of this stuff ends up on my website at craigpeterson.com. And you can subscribe right there. You'll get my weekly newsletter.

I've been sending out show notes and more recently every week, got a little training tidbit, two to three minutes to run through to help you understand your home computer and your business computers, what you should be doing.

So just. Craig peterson.com.

All right, Craig. Thank you very much. And I look forward to catching up with you after the holiday

alright

Craig Peterson: [00:12:20] and you have a great Thanksgiving too, Jim.

Jim Polito: [00:12:22] Thank you, Craig. All Craig Peterson, everybody.

Craig Peterson: [00:12:25] Oh, and by the way, as my little Roomba is cleaning up here in this studio. Hey, I want to thank everybody for listening and wish you a great Thanksgiving time with you and your family, I'll be on the radio again tomorrow morning, but I'm not sure we'll get this out in time. So if not, or even if we do. I appreciate you guys I really do. You help make this all worthwhile.

Take care. Talk to you probably tomorrow. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed alternatives to big tech social media platforms and why they should big tech should lose section 230 protections. Here we go with Jim.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Parler. They have committed to not blocking the things that you want to say. They're not going to hire people who hate you to somehow do something called fact-checking, which doesn't mean fact-checking, which just, again, it's so Orwellian to change the language.

Hello everybody. Craig Peterson. I had a great little chat this morning with Mr. Jim Palito about social media alternatives. Specifically, we spoke about Parler, AKA parlay, and I thought it went really well. It was very, very, very quick.

Jim couldn't believe how fast the time went. This is a time when we need an alternative. We've got right now, today as I'm putting this together, it's Tuesday, and we've got Jack Dorsey, the Twitter guy, and we've got the guy from Facebook are both in front of the Senate, virtually answering questions about why they messed around with conservative information online. Here we go with Jim, and we talk all about it.

Jim Polito: [00:01:15] He is the man with the plan, the man who knows it all. Our good friend, one of our most popular guests every Tuesday at this time. Tech talk guru, Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:29] Hey, good morning. I don't forget the best-looking guest on Tuesdays.

Jim Polito: [00:01:33] Best looking guest on Tuesday. I hope your ears weren't ringing.

We were talking with our national correspondent, who is based out of Philly, and he was talking about how cold it is up here. I said, well, our Tuesday guest Craig Peterson, he knows real cold. He came from the great white North. And uh, yay. Go, go, go, go, go, go, go. I mean, really, you know, cold, as a matter of fact, you can survive living in the temperature that the Pfizer COVID-19 vaccination needs to be stored.

Craig Peterson: [00:02:15] Well, I don't know about that. That there's somehow that liquid nitrogen-oxygen thing scares me.

Jim Polito: [00:02:24] Well, anyway. Hey, um, always a pleasure to be with you. I do want to leave it up to you to discuss what you'd like to discuss today. Cause we're at the point where there's so much stuff going on. But I do want to discuss parlay, which, uh, but it's spelled P a R L E R. Choose the upstart conservative should I say Twitter? And has been growing exponentially since late in the election, the presidential election. Am I correct?

Craig Peterson: [00:02:59] You are. And I'm on parler. I have been for a while, and you're right. Parlay is how they used to pronounce it anyway.

Jim Polito: [00:03:07] Yeah, how do they pronounce it parler now? I just want to make sure. Okay,

Craig Peterson: [00:03:13] Well then, now they pronounced it. Parler because people were confused. They didn't really understand, and they don't know what parlay means. I thought Parler was perfect. Right. Because it was, we learned from captain Jack Sparrow, when you want to talk under a flag of truth,

Jim Polito: [00:03:28] Yes, you Parler

Craig Peterson: [00:03:30] Yeah. Yeah, exactly.

Jim Polito: [00:03:32] And it's also, you know, French for speak, so you know. Parler Vous Francais. You know.

Craig Peterson: [00:03:33] Craig speaking French

Forget it. Now. I'm done. See, but that was it. That was about it. And I know some bad words, and I had French for about three years and, uh, I think four actually, I had French for about four years now. I never did that well in it. All right. So let's talk about it because, um, I'm on it. I got on it early because I said, Oh, this new platform, and I always want to get Jim Polito, you know so that I don't have to be like the real Jim Pollito.

Like Donald Trump has to be the real Donald Trump, I have Jim Polito on Facebook, Twitter, Instagram, Snapchat, and now, parler. So tell us about it.

Craig Peterson: [00:04:27] It really is a replacement for Twitter. You're right about that. It has grown 300% just in the last little while. It has been growing like crazy as conservatives have felt that they needed to get away from Twitter. Remember Twitter. It's not just that they are bold in saying, there are people who disagree with this statement, even though it might be an opinion and might even be presented as an opinion. Twitter part of the problem is everything you see, you see, not because you follow Jim Pollito on Twitter, you don't see. Trump's tweets because you followed president Trump. No, no. You see what they want you to see no matter what, which is a real big problem. So with parler, they have committed to not blocking the things that you want to say. They're not going to hire people who hate you to somehow do something called fact-checking. Which doesn't mean fact-checking, which just, again, it's so Orwellian to change the language, and many people are using it.

I am too. And there are other alternatives that are out there right now. There's an alternative to YouTube. I don't know if you've heard about MagaBook, M A G A - Make America Great Again. Yeah.

Jim Polito: [00:05:50] Yeah. So there are alternatives. The question is, I mean, I know in parler has benefited from the problems with complaints about Facebook and Twitter, especially over the article in the New York Post, which kind of started it all.

Jack Dorsey and Zuckerberg, I think, are in DC again today. To answer questions. I believe that I believe today they are before a congressional committee. But Parler really seized upon that. Now the question is, when you compete with any massive monopoly, can they survive?

Craig Peterson: [00:06:28] Yeah, that's a good question. But I got to point out the people behind them. You've got the number one conservative podcast in the country is behind Parler. In fact, he owns part of parler now. Senators Ted Cruz and Devin Nunez, of course, he's a rep. They have both been pushing Parler, and because of the censorship, I think they stand a pretty good chance.

It's pretty new 2018 is when Parler first came online. I became aware of it about six months ago, really, and signed up, and I do a little bit. Candace Owens was probably the first high profile conservative to bail on Twitter and join Parler.

Jim Polito: [00:07:12] Yeah, I mean, for me, well, I just got listeners customed to Facebook and Twitter and following me there and now to flip them over. Now, there are listeners who are writing to me and saying, Hey, how come you're not active on parler?

And I, you have to make sure. That I do get active and, and make sure that I use my, use my name there and, and spread the word there. I do notice, though, that the president, Craig, continues to use Twitter.

Craig Peterson: [00:07:44] Yeah. Yeah. Well, that's where most people are, and he likes to share the pot. And so that just, that's where he gets the most comments and everything.

And it's interesting when you're talking about like the president and, and Twitter, et cetera, et cetera. Now look at so many of these companies. How well will Twitter do? How well will CNN do, uh, to use the Nixon quote if they don't have Trump to kick around anymore?

Jim Polito: [00:08:12] Oh, I've said that. Yeah. What are you going to do now?

The big boogeyman is gone. The big orange man, the great pumpkin, is gone. What are you going to do? Who are you going to blame?

Craig Peterson: [00:08:21] So I think that's going to hurt some of these left-wing sides, like the Twitters of the world, but it's going to help Parler. It's going to help some of these other sites that are out there.

I think YouTube, that's going to be a hard one to beat down because there's just so much content. But Twitter is it's up to date, right? It's up to the minute. You're not looking for a video, those recorded three years ago. So I think Google is going to hold onto that. But Jim, I've had so many of our listeners contact me over the last two to three weeks, way, way more. It's up hundreds of percent asking. So, what do I do? I don't like Google. I don't trust Google anymore. Many of our listeners really aren't Twitter people, but they are on Facebook. What do I do about Facebook? And right now, I think the only real viable alternative to all of those is, frankly, the Parler site parler.com, P A R L E R.com.

I've been recommending to everybody stop using Google for most things. I cannot do research anymore, using Google. DuckduckGo. Like kids game where you play. Yeah. They will show you the types of results you would expect to get from Google. But Google now, with all of their censoring and waiting and everything else. Just isn't showing you, frankly, even what it used to show you,

Jim Polito: [00:09:54] You know what I find I do, I'm finding it and cause I have been using duckduckgo. And because I look at, I put something in, and I see the first 10 results, and I know Google's going to say, Jim, this is based upon people's previous clicks now.

No, it isn't, um, it's based on their previous clicks. Cause you've been pushing this agenda. I find that for commercial endeavors, like I want to review a product or I want to look at something like that. I go to Google when I want to do my stuff. I go to duckduckgo because I know I will be more at ease.

I won't have to scroll through three pages just to find what I'm looking for. I find it much easier. If I'm looking for someone with a conservative opinion on some event. I have an easier time with that go because I get it all. They don't push the conservative side. I just get it all.

Right. Yeah. This is what we had hoped for, with the internet when it all started all those years ago. Look at what's happening, even more divisiveness.

Yeah. It's just not good. Craig, this was. Actually, I can't believe the time just flew by how fascinating this was. I'm gonna follow your lead.

I'm doing duck, duck go, but I'm gonna follow your lead. I'm going to get on parler. I mean, I'm on it, but get on it and use it. Why not?

Craig Peterson: [00:11:22] There are apps for everything. You can use it from a web page on your desktop. It's available everywhere, and yeah. Why not the top conservative voices now, including Mr. Jim Polito?

Jim Polito: [00:11:36] Well, I was there. I just wasn't active. You'll see the name, you'll see the name Jim Polito, and you'll see a picture. That's about it.

All right, Craig, as usual, excellent segment. Craig's got a great show on WTA G and W H Y N every Sunday morning at 11:00 AM. It's also podcasting on the websites, but Craig, how else can folks reach you?

Craig Peterson: [00:12:01] I've been really working on some special reports for people just absolutely free. I'm not going to hammer you write this. I'm not like Mr. Marketing. I'm Mr. Technology. There are things people need to know. So make sure you are getting my weekly newsletter, and that'll also, you need to reply to those, and I will respond to you.

So just go to Craig peterson.com/. Subscribe, and I'll send you some of these things automatically. If you have a question, just replied to those emails again. That's Craig peterson.com/subscribe.

Jim Polito: [00:12:36] Craig always a pleasure, always great to talk with you. We will catch up with you next Tuesday.

Craig Peterson: [00:12:43] Hey, thanks, Jim. Take care.

Jim Polito: [00:12:45] You too. Bye. Bye.

Craig Peterson, everybody.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Jeff Chidester on NH Today. We hit a number of interesting tech topics this morning with Jeff Chidester. We started off with Bitcoin, Silk Road, and the IRS, then we discussed California Prop 22 and the Gig Economy, then The Hammer and Scorecard Software developed by the CIA and how it may have been used in the election last week here in the USA. Then we got into business use of Cell Phones and Employees using their personal phones for business and the problem with misconfigured VPNs. Here we go with Jeff.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Don't use anti-virus use better than anti-virus. Microsoft's Free version of Windows Defender that comes with Microsoft Windows 10, and you should be using windows 10, is very, very good. Make sure everything's patched up. When was the last time you patched your light bulb, that is all internet-connected nowadays? Probably never. You've got, as a business, to do an inventory of everything that's on your networks, segment those networks, and make sure it's all up to date.

Good morning, Craig Peterson here. Thanks for being with me. I was on this morning with Scott Spradling over at an NH today. It's fun chatting with him and of course, it's heard all over Northern New England. We talked about a few different things. I'm enjoying chatting with Mr. Spradling here. Parler. Have you heard about Parler? What that's all about? The sameness what's going on in manufacturing? We've got all kinds of attacks, and specifically, what must you do as a small business owner?

So here we go with Mr. Scott.

Scott Spradling: [00:01:10] There's a really interesting new sort of social media network if you will. A new channel that conservatives are beginning to embrace in big, big numbers. Have you ever heard of Parler? It's called Parler and that's like a Twitter-based kind of sort of a channel if you will. That's become very, very popular.

It's been around, since 2018, but the popularity of it has really, really skyrocketed. Joining us to talk a little bit about that and a few other topics is Craig Peterson.

Craig, good morning, sir. How are you? Happy Monday.

Craig Peterson: [00:01:41] Hey, good morning, Scott. Happy Monday back to you. These things are getting huge

Scott Spradling: [00:01:46] What is Parler, and why is it so popular all of a sudden? What's going on with it?

Craig Peterson: [00:01:50] Well, Parler, which originally they called themselves parlay from the French. Let's just have a discussion here, right? A parlay. We learned that from Captain Jack over on Pirates of the Caribbean. But anyway,

Here's what it is. It is a replacement basically for Twitter. Parler has been very, very big about trying to make sure that they're not, they are absolutely not editing anything they're not adding their own editorial comments about people complaining. They're not blocking people off of these. So it's one of a number really that are out there right now.

Another big one is Magabook. M A G A book, which is a Facebook replacement. There's a replacement for all of these types of things because so many conservatives feel like they've been disenfranchised.

Scott Spradling: [00:02:41] Sure, sure.

That makes sense. Now, let me ask you this Craig because obviously there are so many lines of communication that are available for people to be able to connect and talk to one another.

Is there any concern from your perspective, that people will essentially retreat into talking to folks that are only in all ways, like-minded, and they're not really connecting with larger groups or folks that might have a different opinion or anything like that?

Cause like it, or lump it at least with Twitter and Facebook, everybody's there. Any concern about that?

Craig Peterson: [00:03:10] Well, they are kind of there, Scott. What's happened, and there was a big uproar about a decade ago, all of those Twitter and Facebook, particularly Facebook is giving you stuff that they think you will like.

Their goal is to keep you on that website. Their goal is to have your eyeballs there so they can show you advertising. So they can figure out you're trying to buy a brand new Ford pickup truck. Right.

Scott Spradling: [00:03:35] Ok, sure.

Craig Peterson: [00:03:36] That is what the goal is. The problem that we're actually seeing is even though there are certainly people from every walk of life and every political persuasion on Facebook and Twitter, you will not see things, for the most part. That disagrees with you. That's where Parler really is different. You see people on all sides of the spectrum here, you are not having your information moderated by a third party.

Scott Spradling: [00:04:02] Fair enough. All right. Let's change topics here a little bit. We're talking to Craig Peterson. Most businesses are now vulnerable to emerging risks that are not covered by their cyber insurance.

So this seems like a kind of a dangerous loophole. Especially now when we're also disconnected. Not being able to be in the same room. We're needing to deal with pandemic rules and social distancing. What is this about? What's the concern here?

Craig Peterson: [00:04:25] What we've found now is that the insurance companies have a standard and the standard has to do with cybersecurity.

What are you doing? Are you training your employees? Is all of your software up to date? Are you using next-generation firewalls, et cetera? So now when you put in a claim on that $5 rider that you're paying for on your business insurance, as though that's going to cover you in the event of a hack, right? Ransomware.

You put in that claim, they're saying, well, have you met all of these standards? They were on page 7,263 subparagraph two of the document that you did not download from our website, but you said, I agree with it. That document has some very, very specific requirements. Everybody from these huge, huge corporations all over on down through mom and pop that have cyber insurance are finding that the insurance industry has decided that they are just plain not going to payout.

It got worse, Scott, about two weeks ago. We arrested, the United States Department of Justice, a handful, about six people, who were charged with terrorism through the use of ransomware and hacking. Terrorism now comes under another clause in the insurance policies and that is an act of war.

So if they can't fall back on, Hey, listen, you weren't doing what you're supposed to be doing for your cybersecurity. Now we're starting to see more insurance companies, when you put in a claim saying, Hey, my business just got destroyed by these hackers.

By the way, in most cases, businesses that are hacked will be out of business within six months and 10 to 20% closed the doors within a week.

Those companies are saying, the insurance company said, Hey, an act of war. We have no liability.

So

Scott Spradling: [00:06:22] Craig what is your advice to these businesses? If we're vulnerable, when you do get hit by them, it's it can be such a sort of career-ending, existential, kind of a moment. What's your advice to listeners who are saying, Oh, okay. I need to tighten down my defenses.

Craig Peterson: [00:06:36] There are a few things you should be doing. Bottom line tightening. You use the right word here. If you're on a windows system, make sure you are using windows defender and it's turned on. Make sure you have the latest versions of all of the firewalls. Great. Use the next-gen stuff. Use advanced malware protection.

We now have Symantec who for a long time had the anti-virus software, everyone was using, Who is completely changing their game. McAfee. Norton. We have cases of the heads in some of these C-levels of these companies coming out and saying our software is useless.

So don't use anti-virus use better than anti-virus.

Microsoft's free version of Windows Defender that comes with Microsoft Windows 10 and you should be wearing windows 10 is very, very good.

Make sure everything's patched up. When was the last time you patched your light bulbs that are all internet-connected nowadays? Probably never.

Do an inventory of everything that's on your networks.

Segment those networks and make sure it's all up to date

Scott Spradling: [00:07:45] Just to underscore the fact that the threat is out there. You also found an article that talked about how manufacturing companies we're seeing the threat of ransomware. They're out there. They're knocking on these doors. They're stealing. They're making a mess out of everything. The risk is real right.

Craig Peterson: [00:07:59] It is very, very real.

We're seeing this year, somewhere around 30% of companies attacked. Which is absolutely huge. Manufacturing is really, really big now. Because of the fact that the Chinese believe it or not, it's true, are trying to break into our computer systems. I have clients here in New Hampshire who has had Chinese backdoors on their systems. They love manufacturing because now. They can take our designs. Our intellectual property. Take it to China, manufacture it there with no research and development costs. All they had to do with steal it. Now you're out of business because you can't compete against your own designs being manufactured in China.

We've gotta be very, very careful. Pharmaceutical manufacturers are really under attack right now. FBI has been warning about that. We're just talking about regular old manufacturing. Yes. They really are out to get you

Scott Spradling: [00:08:55] Craig Peterson, some sobering words, but at least some ideas and ways in which you can protect yourselves, especially online from the threats that come through these hackers.

Thank you very much for your time today. Have a wonderful Monday.

Craig Peterson: [00:09:07] All right. Take care. And you'll find more at CraigPeterson.com.

Scott Spradling: [00:09:11] Craig peterson.com.

Thanks very much. You're listening to New Hampshire today.

Craig Peterson: [00:09:14] I just listened to that interview again, and it was really quite fast-paced. Interesting. What do you guys think about the one and what a 10 minute, one hour, 10-minute podcast here on the weekend?

Let me know, drop me a line, please. At me@craigpeterson.com. All right, take care. We'll be back tomorrow. Oh, and by the way, Scott was just telling me they will not be on the air next week, so I won't be on with them on all of their stations.

All right. Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

This week I am spending a bit of time discussing Bitcoin and other crypto-currency and their tie to Ransomware and a couple of things the Feds are doing from the IRS to DOJ. Then we go into the Gig Economy and thru the ramifications of CA Prop 22 and More so listen in.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Tech Articles Craig Thinks You Should Read:

The feds just seized Silk Road’s $1 billion Stash of bitcoin

Uber and Lyft in driving seat to remake US labor laws

The One Critical Element to Hardening Your Employees' Mobile Security

Ransom Payment No Guarantee Against Doxxing

Connected cars must be open to third parties, say Massachusetts voters

Tracking Down the Web Trackers

Apple develops an alternative to Google search

San Diego’s spying streetlights stuck switched “on,” despite a directive

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] The silk road is back in the news as a billion dollars was just taken from their account. We're going to talk about mobile security, ransom payments, and doxing. And of course, a whole lot more as you listen right now.

Hi, everybody, of course, Craig Peterson here. Thanks for spending a little time with me today.

We have a bunch to get to. I think one of the most interesting articles, what kind of start with this week because this is a very big deal. We're talking about something called cryptocurrency, and I'm going to go into that a little bit. So for those of you who already know, just maybe there's something you'll learn from this little part of the discussion and then we'll get into Bitcoin more specifically.

Then the secret service, what they have been doing to track down some of these illegal operators and also how this is really affecting ransomware. Those two, by the way, are just tied tightly together, Bitcoin and ransomware. So I'll explain why that is as well.

Cryptocurrency has been around for quite a while now. There's a concept behind cryptocurrency and it's the most important concept of all, frankly, when it comes to cryptocurrency and that is you have to use advanced to mathematics in order to prove that you have found a Bitcoin.

Time was you'd go out and go gold mining. Heck people are still doing it today. all over New England. It isn't just the Yukon or Alaska or Australia, et cetera. They're doing it right here. And they have proof that they found something that's very hard to find because they have a little piece of gold or maybe a nugget or maybe something that's like a huge nugget man. I saw a picture of one out of Australia that was absolutely incredible. Takes a few people to carry this thing. That is proof, isn't it? You can take that to the bank, ultimately. You sell it to a gold dealer who gives you cash. That you can then take to a bank. Then the bank account information is used to prove that you can buy something. You give someone a credit card, it runs a little check. Hey, are we going to let this guy buy it? Or a debit card? Hey, does he have enough money in the bank? So along with that pathway, you have something that is real. That's hard and that's the gold that was mined out of the ground. Then it very quickly becomes something that's frankly, unreal.

Time was our currency was backed by gold and then it was backed by silver. Now it's backed by the full faith and credit of the United States government. not quite the same thing, is it? So we're dealing with money that isn't all that real, the United States agreed to not manipulate its currency.

We became what's called the petrodollar. All petroleum products, particularly crude oil are sold on international exchanges using the US dollar. China is trying to change that. Russia's tried to change that. They're actually both going to change it by using a cryptocurrency. At least that's their plan.

The idea behind cryptocurrency is that your money, isn't real either, right? You sure you've got a piece of paper, but it's not backed by anything other than the acceptance of it by somebody else. If you walk into Starbucks and you drop down a quarter for your coffee. Yeah, I know it's not a quarter used to be a dime. I remember it was a dime for a cup of coffee, not at Starbucks, but you dropped down your money. Okay. Your $10 bill for a cup of coffee at Starbucks, they'll take it because they know they can take that $10 and they can use it to pay an employee and that employee will accept it and then they can use that to buy whatever it is that they need. It's how it works.

With Bitcoin, they're saying what's the difference? You have a Bitcoin. It's not real. Ultimately represents something that is real, but how is there a difference between accepting a Bitcoin and accepting a $5 bill? What is the difference between those two or that $10 bill that you put down at Starbucks? In both cases, we're talking about something that represents the ability to trade. That's really what it boils down to. Our currencies represent the ability to trade.

Remember way back when, before I was born that a standard wage was considered a dollar a day. So people would be making money at a rate of a dollar a day. I remember that song, old country song. I sold my soul to the company's store and they made enough money just basically yet buy in to pay the company for the room and board and everything else they had. Interesting times, not fun, that's for sure for many people caught up in it. When you dig down behind Bitcoin, once you ultimately find at the root, was a computer that spent a lot of time and money to solve this massive mathematical equation. That's the basics of how that works. That's what Bitcoin mining is. Right now, it costs more to mine a Bitcoin.

In most areas, then it costs for the electricity to run it and the hardware to buy it. There are computers that are purpose made. Just to create these Bitcoins, just to find them just to mine them. If you're sitting at home thinking, wow, I should get into a cryptocurrency and I'll just go ahead and mine it on my computer, that's really fun. It's a fun thing to think about. But in reality, you are not going to be able to justify it. You'd be better off to go and buy some gold or another precious metal.

So that's how cryptocurrency has, how Bitcoin, that's how all of these really begin is just with the computer, trying to solve an incredibly complex math problem that can take weeks or months for it to solve.

For those of you that want to dig a little bit more, basically, it's using prime numbers. You might remember messing with those in school. I remember, I wrote a program to determine prime numbers a long time ago. 45 plus years ago, I guess it was, and it was fun because I learned a lot about prime numbers back then. But we're dealing with multi-thousand digit numbers in some of these cases, just huge numbers, far too hard for you or I to deal with and that's why I take so incredibly long.

Now we know how the value was started and that was with somebody running a computer finding that Bitcoin and putting it on the market. Now, normally when you're looking at market and market volatility, markets are supply and demand based except for government interference.

We certainly have a lot of that in the United States. We do not have a completely free market system, not even close. The free market says I had to dig this hole and in order to dig that hole, I had to have a big backhoe. Before that, I had to have a bucket or maybe some other heavy equipment to move all of the earth out of the way, the bulldozers, et cetera.

Then I had to run that through some sort of a wash plant and all of these things cost me money. So basically it costs me whatever it might be, a hundred bucks, in order to find this piece of gold, and then that hundred bucks now that it costs him to do it is the basis for the value of that piece of gold.

Obviously, I'm not using real numbers, but just simple numbers to give you an idea of how cryptocurrency works. So it's a hundred bucks for me to get that piece of gold out of the ground. Then that piece of gold is taken and goes to some form of a distributor. So I'm going to sell that piece of gold to somebody that's going to melt it down.

They're going to assay it and say, yeah, this is a hundred percent pure gold, and then they'll sell it to someone and then they'll sell it to someone and then they'll sell it to a jeweler who then takes it and makes jewelry. Every time along there they're adding stuff onto it. But the basic value of gold is based on how hard it is to get and how many people want to get their hands on it.

The law of supply and demand. You've seen that over the years, it's been true forever. Really? That's how human trade works. Capitalism, in reality, is just the ability of strangers to trade with each other is just an incredible concept.

What we're talking about here with the cryptocurrency is much the same thing. The value of cryptocurrency goes up and down a lot. Right now, one Bitcoin is worth about 15,000, almost $16,000 per bitcoin.

We'll talk about that. What is Bitcoin? How can I even buy it? Pizza for the silly things were 16 grand, right? It's like taking a bar of gold to buy a pizza.

How do you do that? How do you deal with that? So we'll get into that, and then we'll get into how the tie between cryptocurrencies, particularly Bitcoin, and the criminal underground. That tie is extremely tight and what that means to you. It is tied directly into the value of Bitcoin.

Right now the basis is it costs me 16 grand to mine, a Bitcoin. Therefore that's where I'm going to sell it for, of course, there are profit and everything else that you put into that $16,000 number.

We've got a lot more to get to today. We're going to talk about this billion dollars, which is, that's a real piece of money here that the feds just seized.

Right now talking about Bitcoin. What's the value of it? How is it tied into criminal enterprises and what's going on with the FBI seizure this week?

Bitcoin's value has been going up and down. I just pulled up during the break, a chart showing me the value of Bitcoin over the last 12 months. It has been just crazy. going back years it was worth a dollar. I think the Bitcoin purchase was for a pizza, which is really interesting when you get right down to it.

The guy says, Oh yeah, what the heck, take some Bitcoin for it. Okay. here we go. May 22nd, 2010 Lasso Lowe made the first real-world transaction by buying two pizzas in Jacksonville, Florida for 10,000 Bitcoin.

10,000 Bitcoin. So let me do a little bit of math here. Let me pull it up here. Today's price is about $15,750,000. So he bought it. Two pizzas for the value today, Bitcoin of $157 million. That's actually pretty simple math, $157 million. Okay, that was 10 years ago. The first Bitcoin purchase. So it has gone up pretty dramatically in price.

I think the highest price for one Bitcoin was $17,900. It was almost $18,000 and then it's dropped down. It has gone up and it has gone down quite a bit over the years. It seems to have had a few really hard drop-offs when it hit about 14,000. Right now it is above that.

So I'm not giving investment advice here, right? That's not what I do. We're talking about the technology that's behind some of this stuff, but one Bitcoin then. Is too much for a pizza, right? So he paid 10,000 Bitcoin for his first pizza. That's really cool, but, ah, today where it's another word, the Bitcoin was worth just a fraction of a cent each back then.

Today you can't buy a pizza for one Bitcoin. So Bitcoin was designed to be chopped up so you can purchase and you can sell them at a fraction of a Bitcoin. That's how these transactions are happening. Now there's a lot of technology we won't get into that's behind all of this and how the transactions work and having a wallet, a Bitcoin wallet, and how the encryption works and how all of these logs work. The audits, basically the journals that are kept as accountants and how a majority of these have to vote and say that particular transaction was worthwhile.

The fact that every Bitcoin transaction is not only stored but is stored on thousands of computers worldwide. Okay. There's a whole lot to that, but let's get into the practical side.

If you are a bad guy. If you are a thief. If you're into extortion. If you're doing any of those things, how do you do it without the government noticing? In reality, it's impossible when you get right down to it. Nothing is completely anonymous and nothing ever will be most likely, completely anonymous.

But they still do it anyway, because, in reality, they, the FBI or the secret service or whoever's investigating has to be interested enough in you and what you're doing in order to track you down. If they are interested enough, they will track you down. It really is that simple.

Enter a convicted criminal by the name of Ross Ulbricht

Ross was running something online, a website called the silk road. It was what's known as the dark web. If you've listened to the show long enough, the history of the dark web and that it was founded by the US government. In fact, the dark web is still maintained by the government. I'm pretty sure it's still the Navy that actually keeps the dark web online.

The thinking was we have the dark web. It's difficult for people to track us here on the dark web and if we use something like Bitcoin, one of these cryptocurrencies for payment, then we are really going to be a lot safer. Then they added one more thing to the mix called a tumbler. And the idea with the tumbler is that if I'm buying something from you using Bitcoin, my wallet shows that I transferred the Bitcoin to you. All of these verification mechanisms that are in place around the world also know about our little transaction, everybody knows. The secrecy is based on the concept of a Swiss bank account. When with that Swiss bank account, you have a number and obviously you have a name, but it is kept rather anonymous. The same, thing's true with your wallet. You have a number, it's a big number to a hexadecimal number. It is a number that you can use and you can trade with. You've got a problem because, ultimately, someone looking at these logs who knows who you are or who I am or wants to figure out who either one of us is probably can. And once they know that they can now verify that you indeed are the person who made that purchase.

So these tumblers will take that transaction instead of me transferring Bitcoin directly to you, the Bitcoin gets transferred to another wallet. Then from that wallet to another wallet and from that wallet to another wallet and from that wallet to a number of another wallet. Now is much more difficult to trace it because I did not have a transaction directly with you.

Who is in the middle? That's where things start getting really difficult. But as Russ Ulbricht found out, it is not untraceable.

He is behind bars with two life sentences plus 40 years. What they were doing on the silk road is buying and selling pretty much anything you can think of. You could get any hard drug that you wanted there, you could get fake IDs, anything, really, anything, even services that you might want to buy. There are thousands of dealers on the silk road. Over a hundred thousand buyers, according to the civil complaint that was filed on Thursday this week.

Last week, actually, the document said that silk road generated a revenue of over 9.5 million Bitcoins and collected commissions from these sales of more than 600,000 Bitcoin. Absolutely amazing.

Now you might wonder, okay. Maybe I can buy a pizza with Bitcoin or something elicit with Bitcoin, but how can I use it in the normal world while there are places that will allow you to convert Bitcoin into real dollars and vice versa?

In fact, many businesses have bought Bitcoin for one reason and one reason in particular. That reason is insurance. They have bought Bitcoin in case they get ransomware. They just want it to sit in there, to use to pay ransoms. We'll talk more about that. We're turning into the Bitcoin hour, I guess today. we are talking a lot about it right now because it's one of the top questions I get asked.

The IRS is saying that they may put a question on your tax return next year, about cryptocurrency specifically Bitcoin. So what's that all about? And by the way, the IRS had a hand in this conviction too.

Your listening to Craig Peterson.

We just mentioned, gentlemen, I don't know if he's a gentleman, by the name of Ross Ulbricht and he is behind bars for life. He was buying and selling on the. A website called the silk road. In fact, he was the guy running it, according to his conviction and two life terms, plus 40 years seems like a long time.

In other words, he's not getting out. The internal revenue service had gotten involved with this as well because you are supposed to pay taxes on any money you earn. That is a very big deal when you're talking about potentially many millions of dollars. So let's figure this out. I'm going to say, some 9.5 million.

So 9 million, 500,000. There we go, Bitcoin. What do we want to say? Let's say the average value of that Bitcoins over time, there was about $5,000 apiece. Okay. So let's see times 5,000, Oh wow. That's a big number. It comes back to 47 billion. There you go. $500 million dollars. Almost $50 billion. That's just really rough back of the envelope math.

We have no idea. So that's a lot of money to be running through a website. Then the commission that he made on all of those sales is said to have been more than 600,000 Bitcoin. So again, 600,000 times let's say an average price of $5,000 per Bitcoin. So that's saying he probably made about $3 billion gross anyways, on these collected commissions. That is amazing.

The IRS criminal investigation arm worked with the FBI to investigate what was happening here as well as, by the way, the secret service. I got a briefing on this from the secret service and these numbers are just staggering, but here's the problem. The guy was sentenced a few years ago. 2015 he was prosecuted successfully. where did all of his money go? His money was sitting there in Bitcoin, in an unencrypted wallet, because part of the idea behind your Bitcoin wallet is there are passcodes and nobody can get at that your wallet information unless they have the passcode. So they might know what your wallet number is, which they did. The secret service and the IRS knew his wallet number, but how can they get at that Bitcoin and the money it represents? They did. This is like something really from one of these, TV shows that I don't watch right there. What is it? NCU? The crime investigator unit CIU or whatever it is on TV. I can't watch those because there's so much stuff they get wrong technically, and I just start screaming at the TV. It's one of those things. What they found is that the wallet hadn't been used in five years. They found that just last week, people who've been watching his Bitcoin wallet number, found that they were about 70,000 Bitcoins transferred from the wallet.

So people knew something was going on. Then we ended up having a confirmation. The feds had admitted that it was them. They had gone ahead and they had a hacker get into it. So here's a quote straight from the feds. That was an ARS Technica this week, according to the investigation, individual X was able to hack into silk road and gain unauthorized and illegal access and thereby steal the illicit cryptocurrency from silk road and move it into wallets and individual X controlled. According to the investigation, Ulbricht became aware of individual X's online identity and threatened individual X for the return of the cryptocurrency to Ulbricht. So Ulbricht had his cryptocurrency stolen, which by the way, is if you are dealing with Bitcoin, that is very common, not that it's stolen. It does get stolen and it's not uncommon. It's very common for the bad guys to try and hack into your Bitcoin wallet. That's part of the reason they install key loggers so they can see what the password is to your wallet.

So apparently that unknown hacker did not return or spend the Bitcoin, but on Tuesday they signed consent and agreement to forfeiture with the US attorney's office in San Francisco and agreed to turn over the funds to the government. Very complex here. There are a lot of links that the Silkroad founder took to really obfuscate the transfer of the funds. There's tons of forensic expertise that was involved and they eventually unraveled the true origins of Bitcoin. It is absolutely amazing.

Earlier this year they used a third-party Bitcoin attribution company to analyze the transactions that had gone through the silk road. They zeroed in on 54 trends and actions, the transferred 70,000 Bitcoins to two specific wallets. I said earlier, by the way, that it was hex, it isn't hex. It's mixed upper lower case. characters as well as numbers. And, so it's a base. What is it? 26, 40, 60 something. The Bitcoin is valued at about $354,000 at the time. I don't know about you. I find this stuff absolutely fascinating. There's a lot of details on how it was all done and they got the money back.

So with a cryptocurrency, you're not completely anonymous. As the founder of the silk road finds out. You end up with criminal organizations trying to use it all the time. Just having and using Bitcoin can raise a red flag that you might be part of a criminal organization. So you got to watch that okay.

In addition to that, The IRS is looking to find what it is you have made with your Bitcoin transactions because almost certainly those are taxable transactions. If you've made money off of Bitcoin. Now you'd have to talk to your accountant about writing off money that you lost when you sold Bitcoin after it had dropped.

I do not own any Bitcoin. I don't. I played with this years ago and I created a wallet. I started doing some mining, trying to just get to know this, so I'm familiar with this. I've done it. I haven't played with it for a long time.

If you have made money on Bitcoin and you sold those Bitcoin, or even if you transferred Bitcoin and the profits as Bitcoin, you all money to the IRS. Now the feds have their hands on almost a billion dollars worth of Bitcoin, just from this one guy. that's it for Bitcoin for today.

We're going to talk about Uber and Lyft and how they're in the driver's seat right now to maybe remake labor laws in about two or three dozen States almost right away.

Are you, or maybe somebody driving for Uber or Lyft, or maybe you've been thinking about it? There are a lot of problems nationwide when it comes to employee status. We're going to talk about the gig economy right now.

Hey, thanks for joining me, everybody. You are listening to Craig Peterson.

Hey, Uber and Lyft are two companies that I'm sure you've heard of. If you heard about the general category here, it's called the gig economy. The gig economy is where you have people doing small things for you or your business. That's a gig. So during this election season, for instance, I turned somebody on to a site called Fiverr, F I V E R R.com, which is a great site. I've used it many times. I turned them on saying that because they wanted a cartoon drawn there is no better place than to go to Fiverr. Find somebody who has a style you like, and then hire them. It used to be five bucks apiece, nowadays not so much, it could be 20, it could be a hundred, but it is inexpensive.

When you hire somebody to do that as a contractor, there are rules and regulations to determine. If you are an employee versus an independent contractor, there are a lot of rules on all of this, including filing 1099s. But can you decide whether or not they are a contractor? So let's look at the rules here.

I'm on the IRS website right now and they have some basic categories. So number one, behavioral control, workers, and employee, when the business has the right to direct and control the work performed by the worker. Even if that right is not exercised. Then they give some reasons for behavioral control, like the types of instructions given, when and where to work, the tools to use the degree of instruction. I think the big one is training to work on how to do the job, because frankly, even if you're hiring somebody to do something for you, that takes an hour. You have control over their behavior.

But how about an Uber driver or Lyft driver? Are you telling them where to go? Duh, of course, you are. are you telling them, Hey, don't take that road because the Westside highway so busy this time of day, of course, you are? It looks like they might be employees but under behavioral control.

Next step financial control. Does the business have a right to direct or control the financial and business aspects of the worker's job, such as significant investment in the equipment they're using unreimbursed expenses, independent contractors, and more likely to incur unreimbursed expenses than employees? there you go.

Okay. So no that Uber Lyft driver, that person making the cartoon, I don't have any financial control over their equipment.

Relationship. How do the worker and the business perceive their interaction with each other in written contracts? Or describe the relationship? Even if the worker has a contract that says they are a contractor does not mean that they aren't a contractor.

By the way, if you're not withholding the taxes and paying them as an employee, and then they don't pay their taxes and the IRS comes coming after somebody they're coming after you as well for all of those that you did not pay taxes on.

Then it goes into the consequences of misclassifying an employee goes on.

So there are people who could maybe they're an employee, maybe their contractor, but with Uber and Lyft, California decided to put it on the ballot because both Uber and Lyft were saying, we're pulling out of California. California has a state income tax and they want to collect that income tax. Plus California, we're saying, Oh, we care about the drivers.

Maybe they do. Maybe they don't. I'm a little jaded on that.I might say because I had a couple of companies out in California, way back in the day.

So the California voters had it on the ballot just here. What a week ago? A little more than a week ago, maybe two almost now isn't it. They decided to let Uber and other gig economy companies continue to treat the workers as independent contractors. That is a very big deal. Because now what's happened because of this overwhelming approval of proposition 22, these companies are now exempt from a new employment law that was passed last year in California.

So what goes out the window here the well minimum rate of pay, healthcare provisions, et cetera. And by the way, They still can get this minimum pay and healthcare provisions. Okay. They can still get it. It's still mandated out there, but it's absolutely just phenomenal.

Apparently, the law that was passed last year was started because these gig people can really cut the cost of something and other people just weren't liking it.

Frankly, gig companies also outspent the opposition by a ratio of $10 to $1, which is amazing. 10 to one on. Trying to get this proposition to pass. So it's a very big deal. And what it means is in California, these gig workers are independent contractors, but there's a couple of dozen states that are looking at this, including to our South, or maybe the state you're listening in. If you're listening down in mass right now, but South of where I am.

In Massachusetts, the state attorney general has sued Uber and Lyft over worker classification. And this, of course, is going to have nothing to do with what happened in California right now. There are other States who are looking into this right now and you'll be just totally surprised. They're all left-wing States. I'm sure. I hope you were sitting down, New York, Oregon, Washington state, New Jersey, and Illinois. Okay. so we'll see what happens here. The companies have tried to make a good with the unions. Unions, pretty upset about this, good articles. So you might want to look it up online.

Now I want to, before this hour is up, talk about ransom payments. I have mentioned before on the show that the department of justice now looks at people and businesses, paying ransomware as supporting terrorist operations. Did you realize that it's like sending money off to Osama Bin Laden, back in the day? Because if you do pay a ransom, the odds are very good that it is going to a terrorist organization. Oh, okay. It could be Iran. Are they terrorists? No, but they do support terrorism, according to the state department. Is Russia terrorist. no, but are they attacking us? Is this okay? Is there an attack of the United States, a terrorist attack? This is bringing up all kinds of really interesting points.

One of them is based on arrests that were made about three weeks ago where some hackers were arrested on charges of terrorism. It is affecting insurance as well. I've mentioned before that we can pass on to our clients a million dollars worth of insurance underwritten by Lloyd's of London. Very big deal.

But when you dig into all of these different types of insurance policies, we're finding that insurance companies are not paying out on cyber insurance claims, they'll go in and they'll say, you were supposed to do this, that, and the other thing. You didn't do it, so we're not paying.

We've seen some massive lawsuits that have been brought by very big, very powerful companies that did not go anywhere, because again they were not following best practices in the industry. So this is now another arrow in the quiver, the insurance companies to say. Wait a minute, you arrested hackers who were trying to put ransomware on machines and did in many cases and charged a ransom. You charge them with terrorism. Therefore, the federal government has acknowledged that hacking is a form of terrorism. Isn't that kind of a big deal now. So it's an act of terrorism. Therefore we don't have to payout.

It's just if your home gets bombed during a war, You don't get compensation from the insurance company, and ransomware victims now that pay these bad guys to keep the bad guys from releasing data that they stole from these ransomware victims are finding out that data that was stolen is being released anyways.

So here's, what's going on. You get ransomware on your machine. Time was everything's encrypted and you get this nice big red and warning label and you pay your ransom. They give you a key and you have a 50% chance that they are in fact, going to get your data back for you.

Nowadays, it has changed in a big way where they will gain control of your computer. They will poke around on your computer. Often an actual person poking around on your computer. They will see if it looks interesting. If it does, they will spread laterally within your company. We call that East-West spread and they'll find documents that are of interest and they will download them from your network, all without your knowledge and once they have them, they'll decide what they're going to charge you as a ransom.

So many of these companies, the bad guys. Yeah. They have companies, will ransom your machines by encrypting everything, and the same pay the ransom, get your documents back. Then what'll happen is they will come back to you, maybe under the guise of a different, bad guy, hacker group. They'll come back to you and say, if you don't pay this other ransom, we're going to release all your documents, and you're going to lose your business.

Yeah, how's that for change?

So paying a ransom is no guarantee against them releasing your files.

Hey, we've been talking about how computers are everywhere. What can we expect from our computerized cars? What can we expect from computers? Intel has had a monopoly with Microsoft called the Wintel monopoly.

So if you missed part of today's show. Make sure you double-check and also make sure you are on my newsletter list. I'm surprised here how every week I get questions from people and it's great. That's it. I love to help.

I was asked when I was about 19 to read this little book and to also to fill out a form that said what I wanted on my headstone. That's it heady question to ask somebody at 19 years of age, but I said that this was pretty short and sweet. I said, "he helped others." Just those three words, because that's what I always wanted to do. That's what I always enjoyed doing. You can probably tell that's why I'm doing what I'm doing right now is to help people stop the bad guys and to make their lives a little bit better in the process, right? That's the whole goal. That's the hope anyway.

If you need a little help, all you have to do is reach out. Be glad to help you out. Just email me M E at Craig Peterson dot com. Or if you're on my email list, you'll get all of my weekly articles, everything I talked about here on the show, as well as my during the week little emails that I send out with videos that I've been doing.

I've been putting more together. Didn't get any out this week I had planned to, but I probably will get them out next week. I was able to make a couple of this week and we'll queue them up for the coming week, but you'll get all of that. So just go to. Craig peterson.com/subscribe. You'll find everything there. As part of all of that of course, you will also be getting information about the training that I do. I do all kinds of free pieces of training and webinars, and I've got all kinds of reports. One of the most popular ones lately has been my self-audit kit. It's a little tool kit that you can use to audit, your business and see if you are compliant. It's just a PDF that you can take from the email that I send you. If you ask for it, all you have to do is ask for an audit kit, put that in the subject line, and email me@craigpeterson.com and we'll get you going.

So I've had a few people who have this week said, Hey, can you help me out? What do I do? I help them out and It turns out when I'm helping them out, they're not even on my email list. So I'll start there. If you're wondering where to start, how to get up to speed a little bit, right?

You don't have to know all of this stuff like the back of your hand, but you do have to have the basic understanding. Just go online. And a signup Craig peterson.com/subscribe would love to have you there. Even when we get into ice station zebra weather here coming up in not so long, unfortunately, in the Northeast.

When you're thinking about your computer and what to buy. There are a lot of choices. Of course, the big ones nowadays are a little different than they were just a few years ago. Or a couple of years ago, you used to say, am I going to get a Windows computer, or am I going to get a Mac now?

I think there's a third choice that's really useful for most people, depends on what you're doing. If what you do is some web browsing, some email, and also might do a couple of things with some video and pictures and organizing you really should look at the third option. Which is a tablet of some sort and that is your iPad.

Of course, the number one in the market, these things last a long time. They retain their value. So their higher introductory price isn't really a bad thing. And they're also not that much more expensive when you get right down to it and consider the resale value of them. So have a look at the tablet, but that's really one of the three major choices also today when you're deciding that you might not be aware of it, but you are also deciding what kind of processor you're going to be using.

There is a lot of work that's been done going on arm processors. What they are called A R M. I started working with this class of processor, also known as RISC, which is reduced instruction set processors, many years ago, back in the nineties. I think it was when I first started working with RISC machines.

But the big difference here is that these are not Intel chips that are in the iPads that are in or our iPhones, they aren't Intel or AMD processors that are in your Android phones or Android tablet. They're all using something that's called ARM architecture.

This used to be called advanced RISC machine acorn risk machine. They've been around a while, but ARM is a different type of processor entirely than Intel. the basic Intel design is to try and get as much done with one instruction as possible.

So for instance, if you and I decided to meet up for Dunkin donuts, I might say, okay, so we're going to go to the Duncan's on Elm Street, but the one that's South of the main street, and I'll meet you there at about 11 o'clock.

And then I gave you some of the directions on how to get to the town, et cetera. And so we meet at dunks and to have a good old time. That would be a RISC architecture, which has reduced instructions. So you can tell it, okay, you get to take a right turn here, take a left turn there. In the computing world, it would be, you have to add this and divide that and then add these and divide those and subtract this.

Now to compare my little dunk story. What you end up doing with an Intel processor or what's called a CISC processor, which is a complex instruction set, is we've already been to dunks before that dunks in fact, so all I have to say is I'll meet you at dunks. Usual time. There's nothing else I have to say. So behind all of that is the process of getting into your car, driving down to dunks the right town, the right street, the right dunks, and maybe even ordering.

So in a CISC processor, it would try and do all of those things with one instruction. The idea is, let's make it simple for the programmer. So all of the programmers have to do, if the programmer wants to multiply too, double-precision floating-point numbers, the programmer that if he's just dealing with machine-level only has to have one instruction.

Now those instructions take up multiple cycles. We can. Get into all the details, but I think I've already got some people glazing over. But these new ARM processors are designed to be blindingly fast is what matters. We can teach a processor how to add, and if we spend our time figuring out how to get that processor to add faster.

We end up with ultimately faster chip and that's the theory behind risk or reduced instruction set computers, and it has taken off like wildfire.

So you have things like the iPad pro now with an arm chip that's in there designed by Apple. Now they took the basic license with the basic ARM architecture and they've advanced it quite a bit. In fact, but that Ipad processor now is faster than most laptop processors made by Intel or AMD. That is an impressive feat.

So when we're looking a little bit forward, we're no longer looking at machines that are just running an Intel instruction set. We're not just going to see, in other words, the Intel and AMD inside stickers on the outside of the computer. Windows 10 machines running on ARM processors are out already.

Apple has announced arm based laptops that will be available very soon. In fact, there is a scheduled press conference. I think it's next week by Apple, the 15th. Give or take. Don't hold me to that one, but they're going to have a, probably an announcement of the iPhone 12 and maybe some delivery dates for these new ARM-based laptops.

So these laptops are expected to last all day. Really all day. 12 hours worth of working with them, using them. They're expected to be just as fast or faster in some cases as the Intel chips are. So ARM is where things are going.

We already have the Microsoft updated surface pro X. That was just announced about two weeks ago, which is ARM-based. We've gotten macs now coming out their ARM base. In fact, I think they're going to have two of them before the end of the year. Both Apple and Microsoft are providing support for x86 apps. So what that means is the programs that you have bought that are designed to run on an Intel architecture will run on these ARM chips.

Now, as a rule, it's only the 64-bit processes that are going to work. The 32-bit processes, if you haven't upgraded your software to 64 bits yet you're gonna have to upgrade it before you can do the ARM migration. We're going to see less expensive computers. Arm chips are much cheaper as a whole than Intel. Intel chips are insanely high priced.

They are also going to be way more battery efficient. So if you're looking for a new computer. Visual studio code has been updated optimized for windows 10 on ARM. We're going to see more and more of the applications coming out.

And it won't be long, a couple of years now, you will have a hard time finding some of the Intel-based software that's out there.

"it won't happen to me." That's our next topic.

We've got companies who are investing a lot of money to upgrade the technology, to develop security processes, boost it. Staff yet studies are showing that they're overlooking the biggest piece of the puzzle. What is the problem?

Employee apathy has been a problem for many businesses for a very long time. Nowadays, employee apathy is causing problems on the cybersecurity front. As we've talked about so many times, cybersecurity is absolutely critical. For any business or businesses are being attacked sometimes hundreds of times, a minute, a second, even believe it or not.

Some of these websites come under attack and if we're not paying close attention, we're in trouble. So a lot of companies have decided while they need to boost their it staff. They've got to get some spending in on some of the hardware that's going to make the life. Better. And I am cheering them on.

I think both of those are great ideas, but the bottom line problem is there are million-plus open cyber security IT jobs. So as a business, odds are excellent that you won't be able to find the type of person that you need. Isn't that a shame?

But I've got some good news for you here. You can upgrade the technology that's going to help. But if you upgrade the technology, make sure you're moving towards, what's called a single pane of glass. You don't want a whole bunch of point solutions. You want something that monitors everything. Pulls all of that knowledge together uses some machine learning and some artificial intelligence and from all of that automatically shuts down attacks, whether they're internal or external, that's what you're looking for.

There are some vendors that have various things out there. If you sell to the federal government within three years, you're going to have to meet these new requirements, the CMMC requirements, level three, four, level five, which are substantial.

You cannot do it yourself, you have to bring in a cybersecurity expert. Who's going to work with your team and help you develop a plan. I think that's really great, really important, but here's where the good news comes in.

You spent an astronomical amount of money to upgrade this technology and get all of these processes in place and you brought in this consultant, who's going to help you out. You boosted your IT staff. But studies are starting to indicate that a lot of these businesses are overlooking the biggest piece of the puzzle, which is their employees.

Most of these successful attacks nowadays are better than 60%, it depends on how you're scoring this, but most of the attacks these days come in through your employees.

That means that you clicked on a link. One of your employees clicked on a link. If you are a home user, it's exactly the same thing. The bad guys are getting you because you did something that you should not have done. Just go have a look online. If you haven't already make sure you go to have I been poned.com. Poned is spelled PWNED

Have a look at it there online and try and see if your email address and passwords that you've been using have already been compromised. Have already been stolen. I bet they have, almost everybody has.

Do you know what to do about that? This is part of the audit kit that I'll send to you. If you ask for that. Kind of goes through this and a whole lot of other stuff. But checking to see if your data has been stolen, because now is they use that to trick people.

So they know that you go to a particular website that you use a particular email address or password. They might've been able to get into one of these social networks and figure out who your friends are. They go and take that information. Now a computer can do this. They just mine it from a website like LinkedIn, find out who the managers in the company are.

And then they send off some emails that look very convincing, and those convincing emails get them to click. That could be the end of it. Because you are going somewhere, you shouldn't go and they're going to trick you into doing something. Knowledge really is the best weapon when it comes to cybersecurity.

A lot of companies have started raising awareness among employees. I have some training that we can provide as well. That is very good. It's all video training and it's all tracked. We buy these licenses in big bundles. If you are a small company contact me and I'll see if I can't just sneak you into one of these bundles.

Just email me @craigpeterson.com in the subject line, put something like training, bundle, or something. You need to find training for your employees and their training programs need to explain the risk of phishing scams. Those they're the big ones. That's how most of the ransomware it gets into businesses is phishing scams. That's how ransomware gets down to your computers.

You also need to have simulations that clarify the steps you need to take when faced with a suspicious email. Again, if you want, I can point you to a free site that Google has on some phishing training and it's really quite good.

It walks you through and shows you what the emails might look like and if you want to click or not. But there's a lot of different types of training programs. You've got to make sure that everybody inside your organization or in your, family is educated about cybersecurity.

What do you do when you get an email that you suspect might be a phishing email? They need to know that this needs to be forwarded to IT, or perhaps they just tell IT, Hey, it's in my mailbox, if IT has access to their mailbox, so IT can look at it and verify it.

You need to have really good email filters, not the type that comes by default with a Microsoft Windows 365 subscription, but something that flags all of this looks for phishing scams, and blocks them.

There's been a ton of studies now that are showing that there is a greater awareness of cybersecurity dangers, but the bottom-line problem is that employees are still showing a lax attitude when it comes to practicing even the most basic of cybersecurity prevention methods. TrendMicro, who is a cybersecurity company.

We tend to not use their stuff because it's just not as good. But TrendMicro is reporting that despite 72% of employees claim to have gained better cybersecurity awareness during the pandemic 56% still admitted to using a non-work application on a company device. Now that can be extremely dangerous. 66% admitted uploading corporate data to that application. This includes by the way, things like using just regular versions of Dropbox. Do you share files from the office and home? Dropbox does have versions that are all that have all kinds of compliance considerations that do give you security. But by default, the stuff a home user does not get the security you need. They're doing all of this even knowing that their behavior represents a security risk. And I think it boils right down to, it's not going to happen to me. Just apathy and denial. So same thing I've seen, being a security guy for the last 30 years, I've seen over and over, apathy and denial. Don't let it happen to them.

By the way, about 50% believe that they could be hacked no matter what protective measures are taken. 43% took the polar opposite. They didn't take the threat seriously at all. 43% didn't believe they could be hacked.

We're going to talk about Mac OS is driving cybersecurity rethink.

By the way to follow up on that last segment. So Millennials and Generation Z are terrible with security. They keep reusing passwords. They accept connections with strangers. Most of the time. If that's not believable, I don't know what it is. They've grown up in this world of share everything with everyone. What does it matter? Don't worry about it. Yeah. I guess that's the way it goes. Right? Kids these days. Which generation hasn't said that in the past?

We were just talking about millennials, generation Z, and the whole, it won't happen to me, employee apathy and we've got to stop that.

Even within ourselves, right? We're all employees in some way or another. What does that mean? It means we've got to pay attention. We've' got to pay a lot of attention and that isn't just true in the windows world.

Remember we've got to pay attention to our network. You should be upgrading the firmware on your switches, definitely upgrading the software and firmware in your firewalls and in your routers, et cetera. Keep that all up to date.

Even as a home user, you've got a switch or more than one. You've got a router. You've got a firewall in many cases that equipment is provided by your ISP internet service provider. If you've got a Comcast line or a FairPoint, whatever, it might be coming into your home, they're providing you with some of that equipment and you know what their top priority is not your security. I know. Shocker.

Their top priority is something else. I don't know, but it sure isn't security. What I advise most people to do is basically remove their equipment or have them turn off what's called network address translation. Turn off the firewall and put your own firewall in place. I was on the phone with a lady that had been listening to me for years, and I was helping her out. In fact, we were doing a little security audit because she ran a small business there in her home. I think she was an accountant if I remember right. She had her computer hooked up directly to the internet. She kind of misunderstood what I was saying. I want to make clear what I'm saying here. People should still have a firewall. You still need a router, but you're almost always better off getting a semi-professional piece of hardware. The prosumer side, if you will, something like the Cisco GO hardware and put that in place instead of having the equipment that your ISP is giving you.

We've got to keep all of this stuff up to date. Many of us think that Macs are invulnerable, Apple Macintoshes, or Apple iOS devices, like our iPhones and iPads. In many ways they are. They have not been hit as hard as the Windows devices out there.

One of the main reasons is they're not as popular. That's what so many people that use Windows say you don't get hit because you're just not as popular. There is some truth to that. However, the main reason is that they are designed from the beginning with security in mind, unlike Windows, that security was an absolute afterthought for the whole thing

Don't tell me that it's because of age. Okay. I can hear it right now. People say, well, Mac is much, much newer than Microsoft Windows. Microsoft didn't have to deal with all of this way back when. How I respond to that is, yeah. Microsoft didn't have to deal with it way back when because it wasn't connected to a network and your viruses were coming in via floppy desk. Right? They really were. In fact, the first one came in by researchers. The operating system that Apple uses is much, much, much older than windows and goes back to the late 1960s, early 1970s. So you can't give me that, it is just that they didn't care.

They didn't care to consider security at all. Which is something that's still one of my soapbox subjects, if you will. Security matters. When we are talking about your Macs, you still have to consider security on a Mac. It's a little different on a Mac. You're probably want to turn on some things.

Like the windows comes with the firewall turned on however it has all of its services wide open. They're all available for anybody to attach to. That's why we have our windows hardening course that goes through, what do you turn off? How do you turn it off? What should you have in the windows firewall?

Now the Mac side, all of these services turned off by default, which is way more secure. If they're not there to attack, they're not going to be compromised. Right. They can't even be attacked the first place. So I like that strategy, but you might want to turn on your firewall on your Mac anyways.

There are some really neat little features and functions in it. But the amount of malware that's attacking Apple Macintoshes, nowadays, is twice as much as it used to be.

We've got these work from home people. We've got IT professionals within the companies, just scrambling to make it so that these people who are working from home can keep working from home. It's likely a permanent thing. It's going to be happening for a long time. But these incidents of malware on the Mac is pretty limited in reality.

The malware on a Mac is unlikely to be any sort of ransomware or software that particularly steals things like your Excel files or your Word docs on a Mac, I should say it is much more likely to be outerwear. It's much more likely to be. Adware or some other unwanted programs and that's, what's rising pretty fast on Macs.

Mac-based companies are being concerned here about cyber security issues. They are paying more attention to them. They're windows based counterparts have had to deal with a lot of this stuff for a long time because they were targets. So we've got to divide the Mac really into two pieces, just like any other computer. You've got the operating system with its control over things like the network, et cetera. Then you have the programs or applications, right? That is running on that device. So you want to keep both of them secure. The applications that are running on your device, Apple's done a much, much better job of sandboxing them. Making them so that they're less dangerous. The latest release, in fact, Catalina had a lot of security stuff built into that. Microsoft and Windows 10 added a lot more security. So that's all really, really good.

Now, if you have to maintain a network of Macs, we like IBM software. They have some great software for managing Macs, but if you want something that's inexpensive and very usable to configure Macs and control the software on them. Have look at JAMF, J A M F. They just had their user's conference this last weekend. They were talking about how the landscape has changed over on the Mac side.

All right. We've got one more segment left today and I'm going to talk about these cybersecurity frameworks. What should you be using?

If you are a business or a home user, what are those checkboxes that you absolutely have to have to use?

You might've heard about cybersecurity frameworks? Well, the one that's most in use right now is the NIST cybersecurity framework that helps guide you through the process of securing your business or even securing your home. That's our topic.

It's a great time to be out on the road and kind of checking in. We've got security threats that have been growing quite literally. Exponentially. They are really making a lot of money by extorting it from us, stealing it from us. It's nothing but frustration to us.

It's never been more important to put together an effective cybersecurity risk management policy. That's true if you're a home user and you've got yourself and your spouse and a kid or two in the home. Have a policy and put it together.

That's where NIST comes in handy. NIST is the National Institute of standards and technology they've been around a long time. They've been involved in cryptography. These are the guys and gals that give us accurate clocks. In fact, we run two clocks here that we have for our clients, which are hyper-accurate. It's crazy it down to the millionth of a second. It's just amazing. That's who NIST is.

They've put all these standards together for a very, very long time, but just before March, this year, It was reported that about 46 percent of businesses had suffered cyber attacks in 2019. That was up 10% from the year before. Of course, we've all been worried about the Wuhan virus, people getting COVID-19, it is a problem.

The biggest part of the problem is everybody's worried about it. Nobody wants to go to work. They don't want to go out to a restaurant. They don't want to do any of these things. You as a business owner are worried about how do you keep your business doors open? How do you provide services to the customers you have when your employees won't come in or cooperate or were paid more to stay at home than they would be to come back to work. I get it right. I know I'm in the same boat.

Well, because of that we just have not been paying attention to some of the things we should be doing. One of the main ways that business people can measure their preparedness and their progress in managing cyber security-related risks, is to use the cybersecurity framework that is developed by NIST. It is a great framework.

It provides you with different levels. The higher-end, the framework that is used by military contractors. Nowadays, we've been helping businesses conform to what's called NIST 800-171 and 800-53 High, which are both important and cybersecurity standards.

So if you really, really, really need to be secure, are those are the ones you're going to be going with. Right now, no matter how much security you need I really would recommend you checking it out. I can send you information on the NIST framework. I have a little flow chart. I can send you to help to figure out what part of the framework should you be complying with.

It also helps you figure out if you by law need to be complying with parts of the framework. It will really help you. It's well thought out. It's going to make you way more efficient as you try and put together and execute your cyber risk management policy. Remember cyber risk, isn't just for the software that you're running, or the systems you're running. It's the people, it includes some physical security as well.

Now President Trump has been very concerned about it. I'm sure you've heard about it in the news. As he's talked about problems with TicTok and with Huawei and some of these other manufacturers out there. Huawei is a huge problem. Just absolutely huge.

One of these days I can give you the backstory on that, but how they completely destroyed one of the world leaders in telecommunications technology by stealing everything they had. Yeah. It's a very sad story company you may have heard of, founded over a hundred years ago.

They're non-regulatory but they do publish guides that are used in regulations. So have a look at them, keep an eye on them. They have to help federal agencies as well. Meet the requirements is something called the federal information security management act called FISMA and that relates to the protection of government information and assets.

So if you are a contractor to the federal government, pretty much any agency, you have physical requirements.

So think about that. Who do you sell things to? When you're also dealing with the federal government they look at everything that you're doing and say, are you making something special for us? If you are, there are more and higher standards that you have to meet as well. It just goes on and on, but this framework was created by NIST ratified by Congress in 2014. It's used by over 30% of businesses in the US and will probably be used by 50% of businesses in the US this year.

So if you're not using them you might want to have a look at them. It's big companies like JP Morgan, Chase, Microsoft, Boeing, and Intel who meet a much higher standard than most businesses need to meet.

For a lot of businesses all you need to meet is what's called the CMMC one standard. You'll find that at NIST as well. And there are much higher levels than that up to level five, which is just, wow. All of the stuff that you have to keep secured looks like military level or better, frankly security.

There are other overseas companies that are using it too, by the way in England, in Japan, Canada, many of them.

I'm looking at the framework right now. The basic framework is to identify, protect, detect, respond, and recover. Those are the main parts of it. That's you have to do as a business in order to stay in business in this day and age, they get into it in a lot more detail.

They also have different tiers for different tiers that you can get involved in. Then subcategories. I have all of this framework as part of our audit kit that I'll send out to anybody that asks for it that's a listener. All you have to do is send an email to me, M E @craigpeterson.com, and then the subject line, just say audit kit and I'll get back to you. I'll email that off to it's a big PDF.

You can also go to NIST in the online world and find what they have for you. Just go to NIST, N I S T.gov, The National Institute of Standards and Technology, and you'll see right there, cybersecurity framework, it's got all of the stuff there. You can learn more here if you want. If you're new to the framework they've got online learning. They are really working hard to try and secure businesses and other organizations here in the U S and as I said used worldwide. It's hyper, hyper important. It's the same framework that we rely on in order to protect our information and protect our customer's information. So NIST, N I S T.gov, check it out.

If you missed it today, you're going to want to check out the podcast. Now you can find the podcast on any of your favorite podcasting platforms.

It is such a different world. Isn't it? We started out today talking about our cars. Our cars now are basically big mechanical devices ever so complex with computers, controlling them. But the cars of tomorrow that are being built by Tesla and other companies, those cars are absolutely amazing as well, but they're frankly, more computer than they are mechanical car.

So what should we expect from these cars? I'm talking about longevity here. We expect a quarter-million miles from our cars today. Some of these electric vehicles may go half a million or even a million miles in the future. When they do that, can we expect that? Our computers get operating system updates and upgrades, for what five years give or take?

If you have an Android phone, you're lucky if you get two years' worth of updates. Don't use Android, people. It's just not secure. How about our cars? How long should we expect updates for the firmware in our cars? So that's what we talked about first, today.

Ring has a new security camera that is absolutely cool. It's called the always home cam. I talked about it earlier. It is a drone that flies around inside your house and ties into other Ring equipment. I think it's absolutely phenomenal and it's not quite out yet, but I'll let you know more about that.

If you get ransomware and you pay the ransom, the feds are saying now that you are supporting terrorist organizations. You might want to be careful because they are starting to knock on doors, and there's jail time behind some of these things. So watch it when it comes ransomware and a whole lot more as well.

So make sure you visit me online. Go to Craig peterson.com/subscribe. It's very important that you do that and do that now.

So you'll get my weekly newsletter. I've got some special gifts, including security, reboot stuff that I'll send to you right away. Craig peterson.com/subscribe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

Happy Veterans Day to all who have served and are serving!

I was on WGAN this morning with Matt Gagnon and started off this morning talking about electoral issues that are taking front and center in the result counts going on. I discussed some of the known weaknesses in our Electoral system and how it looks like they may actually have used that as a way in. Then we discussed how a Biden administration would deal with technology and a bit about Section 230 protections for Big Tech. Then we got into CA Prop 22 and the ramifications that it could have nationwide. Here we go with Matt.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here. Hey, I want to just thank you guys for listening to the podcast, subscribing to the podcast. If you can on whatever platform. Although iTunes is still the 800-pound gorilla when it comes to tracking the whole podcast industry. And I've been podcasting now for about 20 years, a long time.

And I have hundreds of you guys listening who have been. Really devoted. And I appreciate it, but if you could, if you're not subscribed via iTunes, please do subscribe. It really helps our numbers. It helps people who are looking for podcasts and believe it or not, it isn't just the number of downloads that matter in this scoring it all also considers how many people are subscribed to the podcast and Apple is the iTunes is the place to go to. So if you wouldn't mind, I would really appreciate it. If you'd go to Craig peterson.com/itunes, hopefully, that link is working. Craig peterson.com/itunes and that'll redirect you to my page over. On the iTunes store. And you can just subscribe there whether or not actually you have an iPhone.

So I know why you guys like to kind of mess with things. So many people have Android devices and just going ahead and subscribing on the iTunes page works even for an Android, you may not be able to get them that way, but please do subscribe. And if you're listening on some other platform tune in, or Iheart, or any of these other big ones out there, just subscribed to those. I would so appreciate it.

So this morning, Matt Gagnon et Moi, have talked a little bit about the election and the technology talked a little bit about what Sidney Powell had to say. This is President Trump's. Attorney and she was talking with Lou Dobbs on Friday, last week about something called scorecard and the hammer. So talk a little bit about that. What that is and what that means. We got into the gig economy and something that happened out in California in a referendum about Uber and Lyft. So here we go with Mr. Gagnon. I plan on being back again on Saturday. We're going to continue to do that one podcast format rather than giving you eight podcasts. Back in the day, I was giving you 12 podcasts. There was just too much work to run the business, the homeschool, eight kids, and everything else. So we cut it back to eight, but now it'll just be these three. I usually do three or four radio appearances a week.

I do television appearances too, but I just thought about that and I don't usually put them up as podcasts. I probably should. Then we'll have one, which is my big podcast of the week covering all of our topics. All right, take care. Here we go.

Matt Gagnon: [00:03:09] WGAN morning news. It is about that time of the week on Wednesday to talk to Craig Peterson. Our tech guru joins us now and also joins you on Saturdays at one o'clock for I think he's an expanded tech talk, is what we can call it, really, Craig.

Craig Peterson: [00:03:23] Yeah, it is. I get to go into more detail on a lot of the articles of the week. What's going on? Why is it going on and really what you need to know about it?

Matt Gagnon: [00:03:32] Make sure you tune in for that, but let's get a little quick preview of that right now, by talking about some of these, some of these things that are on our tech list here for the day. I will start with the election though. there's a lot of interesting stuff. tech-related as it relates to the election we just lived through here. Any sort of thoughts or observations from your perspective here, Craig, on what we just saw in this last week or so?

Craig Peterson: [00:03:51] Oh, there's some interesting stuff. I don't know if you saw Lou Dobbs on Friday, I was actually watching it and was shocked at what Sidney Powell was saying.

We've talked before about what are the potential problems with an election when it comes to people trying to steal it and certainly, President Trump has talked about some, at least his team has talked about some potential problems, with voting and voting machines. We've seen some ballots had to be rerun some software that might've been a problem, but we, you and I talked.-, Matt, about potential problems.

It was really being between the polling places, the Secretaries of States offices, and of course the federal bureaucracy that's trying to keep track of all of it. Sidney Powell, who is an attorney for the president, as well as Michael Flynn came out and started talking about something called hammer and scorecard programs that apparently were developed by the NSA used by the CIA and the state department to do some manipulation of foreign elections and monitor them as well, but really for manipulation. Apparently now I heard her say that hammer and scorecard were used in this election. Now there's not a lot of information out there about any of this stuff. We'll see what happens. And she apparently is putting together a lawsuit about all of this.

Hammer and Scorecard program is aimed directly at what I've been saying for about 20 years is the weakest part of our election infrastructure, those ultimate systems that give the final tallies. so we'll see what happens with that. Overall. I think the machines anyway, and the technology that was used really seemed to work pretty darn well.

Matt Gagnon: [00:05:48] Talking to Craig Peterson, our tech guru. He joins us to talk over technology once a week here on Wednesdays.

So we can have lawsuits, Craig, there's a lot of stuff of course, about Google. And there's also a lot of discussions about section 230 and the Biden administration in-waiting, if you will, has actually been talking about making changes to section 230 of the communications decency act as well.

What is this whole story all about here?

Craig Peterson: [00:06:11] Hold on, I've been asked by quite a few people. About what do I think is going to happen. If a Biden administration takes over. The bottom line, there are a few things that they've talked a lot about. You mentioned section 230, which treats these big social media sites like they are the town square. Somebody posts something on that town square billboard, and it's defamatory incites violence, et cetera. As a general rule, the person that owns a billboard is not held responsible. Some people might want to pull it down. They might put graffiti all over those things that they disagree with. But in general, they are protected.

Interestingly enough, to me, Joe Biden has been talking about getting rid of some of those protections for the big social media sites and basically agreeing, I think Matt with you, which is a shocker, but that. in fact, if they're going to act like a publisher and sensor things and control what which is exactly what a publisher does, you don't talk about every possible story that has ever been out there.

You can't, there isn't enough time here on WGAN and for the morning news. You have to do some censoring, basically, boil it down. If you defame someone there are consequences. And it looks like the Biden administration might actually jump on that. Although I think they have higher priorities, try and reign these guys in right.

They have also been talking about, these companies are just too big, too powerful. And they're talking about using the antitrust act to in fact break them apart. So it's interesting. The things they've been complaining about over at the FCC are things that they're looking to do.

Matt Gagnon: [00:08:10] Talking to Craig Peterson. He joins us to talk about technology Craig before I let you go. I also want to ask about what happened in California here, with Uber and Lyft and that referendum question, out there, but proposition 22 last Tuesday, what that means in the future? What does it mean for these companies? And perhaps even, labor laws in general. What do you think?

Craig Peterson: [00:08:30] We've been talking this morning, of course, about the new minimum wage here in Portland. And what does that mean? In California, the state has been trying to tackle is Uber and Lyft drivers as though they are employees and they want Uber and Lyft to take the gig economy to turn all of these people into employees.

Now the gig economy is where you can go online to a site like Fiverr. And if you have little things to be done for your business, your home, your association, check it out. Fiverr F I V E R R.com, where you can get a little logo design, you can have all kinds of stuff. Yep. It is or 20 bucks, whatever it might be, that's the gig economy.

So if you hire someone to make a little logo for you, is, are they an employee? I think obviously not.

But how far up does that go? Should Uber and Lyft drivers be treated as employees, which has all kinds of implications? California decided in that referendum hey, no, they should not be treated entirely as employees.

So this, I think will have a ripple effect throughout the United States because there are a couple of dozen States right now that are trying to figure out. How should the gig workers be treated ultimately, and more specifically Uber and Lyft? I think some might follow California's lead here.

Matt Gagnon: [00:09:59] And that my friends is Craig Peterson.

He's got all these topics and so much more to talk about here on his show, coming up here on Saturday. I appreciate it as always. Craig, thanks so much for giving us a preview into the world of technology. And we'll talk to you again next week.

Craig Peterson: [00:10:09] Hey, take care. Bye-bye.

Matt Gagnon: [00:10:10] You bet.

Craig Peterson: [00:10:11] Hey, how's that for a quick cutoff?

All right, everybody. Thanks for joining me. Don't forget if you would please go to Craig peterson.com/itunes, or just go to iTunes and subscribe to my podcast. It really helps. All right. Take care, everybody, and thanks for being with us today. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We discussed how technology would be affected under a Biden Presidency in Re: Fairness Doctrine. Then we got into 5G and finished up with Apple's new search engine. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, you had another fun time with Mr. Jim Polito this morning, and we went a little off-script, right? If you get my newsletter, you see all of the articles that I sent you now to Jim and the other radio shows I'm on. You might know, I notice that today he went off script and we got into what will happen if there is a Biden administration with technology. How are things going to change?

I think I surprised him on a couple of things. By the way, I think they're going to change for the worse. I prefer having the market take care of this. People who are professional investors, venture capitalists, angel investors, they are lucky if they get it right one time out of 10. Government protecting and controlling the direction of technology and putting money into it, they never are It's just amazing what they've done to mess everything up and ruin lives and waste trillions of dollars. Yes, of course, I don't want the government involved.

We got into that and the alternative to Google that Apple's developing, that you may already be using that you're just not aware of.

The way I put these together, by the way, is I record the stream online from the radio station. In this case, there was a problem so we're missing the first, 30 ish seconds. We're going to pick it up here mid-stream as I answer Jim's question about what will happen or what's likely to happen if Biden does assume the presidency when it comes to technology.

So here I am mid-sentence.

With the Biden presidency, this concept of the fairness doctrine. Yes. But on the internet, they were trying to put a thing in place where the federal government controlled the internet and what we're seeing as a problem right now with Facebook and YouTube and Twitter, et cetera. Would go internet-wide.

We've got to treat every bit fairly because every bit counts. The bit that guy, who's a gamer living in mom and dad's basement that bit where he's got trillions of them a day should be treated the same way as grandma that might have a million a day, tried to get cat pictures and pictures of the grandkids.

Now grandma would end up having to pay for that little kid living in the basement, playing streaming video games all day. Pay for his internet because it has to be quote-unquote fair. That's my biggest concern

Jim Polito: [00:02:50] Now the Democrats don't have control of the Senate. They could have a very weak, tie if the two races in Georgia the first week in January go the other way. I think it's January 5th. They would have a tie-breaker with Kamala Harris. But do you think that prevents a lot of this from happening or can Joe Biden through executive order? Do some of these things?

Craig Peterson: [00:03:18] that's a bigger question, right? That I get answered. I'd have to go to the Supreme court as to whether or not I had an executive order and could actually work here It's Ajit Pai as the head of the FCC. Really made things better for us as a country, frankly, here. All of the things they said would happen if we didn't put this fairness doctrine in place, didn't happen.

In fact, the opposite happened. We have had more investment in the internet.

The other thing is 5g. What does 5g mean? Because if they decide that everybody needs 5g coverage, then we've got a bit of a problem. 5g for most of the cellular carriers, this is less true for T-Mobile. It's very true for Verizon. Verizon would have to have cell sites. Everywhere all over the country, because you can't have, those wonderful looking fake trees, every few miles, when it comes to 5g, you've got to have them every kilometer or less half a mile or so.

Jim Polito: [00:04:28] You know that,

go ahead. Go ahead. Because I have a question about that.

Craig Peterson: [00:04:32] sure. so what would end up happening is they would be forced to spend billions and billions of dollars. In order to broaden the coverage of the five networks, which would raise all of ours, Dell bills, smartphone bills, everything else. So there are so many things they can do. Yeah.

Jim Polito: [00:04:51] Yeah. That's now 5g just while we're on this. And I just want a quick answer. 5g is incredible, but it doesn't work like 4g. It doesn't work like the typical cell tower. You need them to be close to you to have 5g.

Craig Peterson: [00:05:07] You got it a small town, you don't have them on almost every corner and then a big city, like New York, if it ever comes back to life, you'd have multiple 5g cell sites just walking down one little block.

Jim Polito: [00:05:20] Oh my God. See, now that's the thing. You know what that almost reminds me of going back to being hardwired again, because with a cell tower, you can have distance and you can be in a remote area and still have a little bit of a signal 5g you can't, no, let's hope they keep three and 4g there. Do you know what I mean?

Craig Peterson: [00:05:45] They will. In fact, there is right now a satellite constellation being launched that provides 4g LTE from space. Yeah. as well as these newer technologies, like Starlink, which we talked about a few months ago, by the way, it is rolling out right now. And you can get it pretty easily, which is promising that gigabyte worth or gigabit.

I shouldn't say worth of speed. It's not anywhere near that right now. Ultimately it will be so five, G's going to even see competition,

Jim Polito: [00:06:18] Which would be fine with me. Which would be fine with me if they did. Alright, now

let's move on to Apple coming up with a search engine. Now look it, every time you talk with a person, a business person, they're always wanting to talk about where they show up in a Google search.

It seems that's all they ever talk about in Google, owns this market. Owns it. Yahoo was the first member. Yeah. They used to do that. Now, Google just took over and, so Apple is going to give them some competition. Like Microsoft tried with Bing, but how do you compete with that monster? And again, I would, rather than it be a different company than Apple, but is there a chance Apple can compete with Google in the search market?

Craig Peterson: [00:07:09] Oh, there is a very big If you have an iPhone and you've updated to some of the more recent releases of iOS you're actually using Apple's new search engine.

Jim Polito: [00:07:23] I just got an update the other day, everything is changed on my phone.

Craig Peterson: [00:07:28] Yeah. Yeah. So now when you're doing this SIRI searches or other basic searches, right from your iPhone. You are actually using Apple's new with search engine. They're looking to take that technology, which aims to actively they're testing it out now on you, but they're looking at taking that technology and having just like you go to Google to do a search.

You can go to Apple to do a search. Now you mentioned a few that have failed. Amazon had a nine. I don't know if you even knew about that one, but that was a general search engine that Amazon had. Yeah. Most people never heard of it. You mentioned duck go, which isn't just a kid's game anymore. I have had to move a lot of my searches from Google to duck go because Google, it used to be dead on all of the time.

It's still really good for the more advanced searches when I'm dealing with technology. But if I'm doing anything political, for instance, this whole thing about Sidney Powell with scorecard and hammer that she has been talking about, which by the way, if you've been following that at all, That's the same thing I've been warning about for 20 years that happened.

And Jim, you and I, you even talked about that. How could an election be stolen? And I gave the basic formula and it looks like they might've used it. And we'll talk about that as that comes more to the surface right now, it's just basic, but, then I've used duck duck go. Another one you might want to use is quant Q W A N T, which is out of France.

And I, as a researcher, I use another search software in this case that I run on my Mac called D E V O N THINK, and what devon think lets me do is go back to the AltaVista days. Do you remember AltaVista search engine?

Jim Polito: [00:09:32] Yes. Oh my God. Yes. Alta Vista.

Craig Peterson: [00:09:35] Yeah. And with Alta Vista, you could use what are known as Boolean El operators in Boolean algebra. So with Devon think I can do as deep a study as I want to do with word relations, root words, everything.

Pull their initial results. Either diva I'm thinking crawl sites for me, or they can go into anything. They'll go into the library of Congress pull stuff. They'll do research papers, Ph.D. candidates stuff, all the way through extracting results from Google, Bing, and others and give me a much tighter and better search that I get ever had with anything else.

So I've been forced off Google now for most of what I do

Jim Polito: [00:10:17] We had an earthquake yesterday. I think it was w I think it was a tech talk guru moving off off Google completely.

It caused a tectonic shift in the plates. All right.

Wait, hold on a second. There we go. There we go. Now it's now mine. Now my stupid statement is complete. Craig. This was fascinating.

This was great. You always give us a lot to think about, especially from the perspective of, the politics of what's happening and how that will impact things for us as consumers.

So look, everybody wants you to listen to Craig's show it's on every Sunday at 11 o'clock on WTA G and W H Y N. And it's a great show.

The also the powers that be at the station, if there are spaces in the weekend, programming. They actually dropped the show in for an extra chance for you to listen to it. You can always go to the iHeart radio app to look for it, but Craig, how else do folks get in touch with you?

Craig Peterson: [00:11:20] They can certainly go to my website at Craig Peterson.com.

You'll find all kinds of stuff there. And let me make a promise right now to our listeners here, Jim. And that is probably not this weekend, but maybe next weekend on my weekend show, I will do a deep dive into these search engines and how you can get around using Google. And we'll talk about alternatives as well to YouTube and Twitter.

And, w we'll do that either. Probably not this weekend, but probably next week then.

Jim Polito: [00:11:52] Excellent. Craig, it's always great to have you every Tuesday at this time. And we look forward to talking with you next week. My friend.

Craig Peterson: [00:12:00] Take care.

Jim Polito: [00:12:01] Thank you, Craig Peterson, everybody. Really a nice guy.

Craig Peterson: [00:12:04] I think I went a little along in that segment.

Jim had to really bail fast. Anyways, everybody, take care. I shall return tomorrow. And of course this weekend, I'm hoping to have a live show, this week. we'll see how it goes, as opposed to a best of. We're doing all kinds of renovations at the house. Getting ready for Thanksgiving. It's just a mess.

Anyway. Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Craig Peterson here. I was on with Jeff Chidester on NH Today. We hit a number of interesting tech topics this morning with Jeff Chidester. We started off with Bitcoin, Silk Road, and the IRS, then we discussed California Prop 22 and the Gig Economy, then The Hammer and Scorecard Software developed by the CIA and how it may have been used in the election last week here in the USA. Then we got into business use of Cell Phones and Employees using their personal phones for business and the problem with misconfigured VPNs. Here we go with Jeff.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Two right now, if they're not paying a lot of attention to you, you're probably okay. But it's easy enough for them to track you down if they want to. They had fun this morning with Mr. Jeff Chidester, who was sitting in. We talked a little bit about elections, but we really got into this whole Uber and Lyft thing in California and what just happened.

What happened with the silk road and the fed seizing a billion dollars worth of Bitcoin? What is that going to mean to you? If you own Bitcoin. So we went into that and the implications and the IRS and can you really be tracked?

So, Hey, you're listening to Craig Peterson and we're going in here right now with Mr. Jeff. Chidester.

Jeff Chidester: [00:00:45] Hi, welcome back to New Hampshire today. Jeff Chidester 37 past the hour. Craig Peterson. Of course, you can catch, Craig on his show tech talk Saturdays, 1130. Also, catch him over at his website. Craig peterson.com. Craig peterson.com. Good morning. Hey, I just talked to you on Friday. It's great to have you back on Monday, How ya doing man?

Craig Peterson: [00:01:06] I'm doing really well,

Jeff Chidester: [00:01:08] A lot of interesting news, it got lost in all the political talk. One thing. Bitcoin, I think is foreign to a lot of people, the concept of it, but a big thing. The feds had an action last week against silk road. Talk a little bit about that and the impact of that.

Craig Peterson: [00:01:23] Bitcoin, for those that aren't aware of, it is one of these, what they call cryptocurrencies. It's designed to only have so many Bitcoin's ultimately available so that there's a limited market. The way you find these Bitcoins is by what's called mining, which requires some very intensive computing stuff.

What has really driven up the value of Bitcoin, according to many experts is the illegal world out there. Ransoms that are being paid online are often paid in Bitcoin. People think that the beauty of that is they cannot be tracked and that's been a big deal. There was a site out there called the silk road, which I thought was a cool, clever name. The silk road was sitting there on what we call the dark web, which is an internet on top of the internet. It's encrypted. It is obfuscated. So it's difficult to figure out who's what and where.

The silk road was a bazaar that sold everything. I mean everything. You could buy hard drugs on it. There were all kinds of nastiness is going on. So there were a whole bunch of investigations. I attended a presentation given by a secret service about what they did, how they tracked down the guy that was running the silk road. They were able to do it, even though it was all Bitcoin and they use these special tumblers to try and mix it all up to make it hard to find out who it is and they were still able to find them.

So right now he's serving two life sentences plus 40 years, but there was close to a billion dollars in Bitcoin, still sitting there. That the secret service was a hard time having a hard time, getting their hands on and just this week it is now in the hands of the federal government. A billion dollars in illegal proceeds that came from the silk road in Bitcoin cryptocurrency.

Jeff Chidester: [00:03:31] Craig Peterson so once again, you can catch him on tech talk Saturday at 1130. Craig peterson.com. Craigpeterson.com. Many people like Bitcoin. They use it legitimately. Does this have an adverse effect on those who are trying to use this kind of currency legitimately?

Craig Peterson: [00:03:48] That's such a great question.

The IRS is supposed to be putting a question on the tax forms next year. At least they're planning on it saying, do you trade in cryptocurrency? They might even just say, do you trade in Bitcoin? Because the IRS is saying, Hey, you bought that coin for, believe it or not, a dollar per Bitcoin back in the day.

Yeah. And now you just sold it for $7,000. Don't forget to pay the tax on that.

Jeff Chidester: [00:04:20] What,

Craig Peterson: [00:04:21] Yeah, because you're supposed to write it in. In fact, it's 20% or Joe Biden gets his way 30 or 40% tax. So this is going to be an interesting thing as we go forward here, but you're supposed to pay your taxes on Bitcoin.

Does this affect normal people? Well, it does if they are looking at you right now, if they're not paying a lot of attention to you, you're probably okay. It's easy enough for them to track you down if they want to.

Yeah. I think it's amusing that people think that you could ever truly hide anything from the government, especially money.

Jeff Chidester: [00:04:59] Cause they're going to get it. They're like bloodhounds when it comes to money. It's amazing.

Hey, another thing that happened last week, Craig, that I thought was interesting. Everybody knows Uber Lyft. There has been this big conversation out in California about how to treat these types of employees and the voters had their say in this and it really not just affects Uber and Lyft, but it has a larger consideration for the economy as a whole. Tell us about that a little bit.

Craig Peterson: [00:05:23] This is a very big deal now because we have had for a few years, something called the gig economy. So I can go to a website like Fiverr. And if you haven't checked it out, you should F I V E R R.com.

I can hire someone to make me a new logo. To write an article for me to do almost any little task that I want to have done. It used to be five bucks a pop. Sometimes it is even more.

should those people be considered employees? Of course, the IRS has had this test for a long time with these different States.

Do you have to have a regular schedule? Do you have all of these different things as part of their tasks? Proposition 22 passed in California, which means that all of these Uber and Lyft drivers in California were trying to collect taxes on Uber and Lyft. Are now considered basically independent contractors. If you are an employer and I've been in this before in this potential problem, if you're an employer and you bring someone on, even if they sign a contract and you consider them a contractor, the IRS, if they're not paying their taxes will come after you as the employer. They'll just switch it all up. In California, of course, that a state government too. So this is going to have a ripple effect. Many States are looking at how do we classify the whole gig economy, let alone Uber and Lyft. I think they're going to look to California for this.

I've been warning for the last probably 20 years on the air about what I see the weakness to be in our election system. I have said the weakness is likely the secretaries of state offices and their websites where the final results are posted. I don't know if you saw this, you probably did. Cause you follow it closely. But what Sidney Powell is saying now an attorney involved with the Trump administration here.

She's talking about two programs called the scorecard and hammer. I just wanted to put a little, I told you so in here because apparently, that's what she's looking into overall. So what we'll know more, we don't know all of the details yet, but it is precisely what I have been warning for decades could happen to our election.

So there's some scary stuff still going on up there.

Jeff Chidester: [00:07:51] Well, absolutely. I think this process is going to continue regarding our election and transparency is the key to really stopping any kind of one distrust that may come. certainly that.

One last thing, I use my cell phone and it's my cell phone, and I do not do any business on my cell phone. There are people who do use their cell phones for business, and also companies issue these types of mobile devices. There's a problem there isn't there?

Craig Peterson: [00:08:14] There's a number of problems with that. Basically, if you're a business and you want to keep your data safe and that includes your customer list, if, think of everything that's part of your business, you might say, I don't have anything that's secret.

Well, yes you do. You don't want your salespeople walking away. You need to own those phones. That's going to keep things a little clearer, do not allow your employees to use their personal devices and particularly personal computers. Because now you don't have control over the environment that the computer is used in.

If you're using a VPN misusing them, which is by the way about 95% of businesses right now, then that home computer infections are going to come right across that VPN and hurt your business and much the same with mobile devices.

Keep an eye on those.

Jeff Chidester: [00:09:09] That's certainly a policy.

Hey, so we've come to a hard break. Once again, we'd been talking to Craig Peterson, of course, tech talks, Saturdays, 1130, Craig peterson.com. Craig peterson.com.

Craig, thanks a lot, and have a great rest of the week.

Craig Peterson: [00:09:20] Hey, take care, Jeff. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome! This is a "best of Craig." I have included the current articles that you should read this week in the article section so check that out. In this podcast, we cover Fileless Malware is on the rise, How covid is affecting the financial traders, Why you must find out what is on your Enterprise network, and more.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

Ransomware Demands are Doubling Every Six Months, Study Finds

Teach Your Employees Well: How to Spot Smishing & Vishing Scams

Mimecast Research: Half of all Workers Admit to Opening Emails They Considered Suspicious ‘Check the Box’ Awareness Training has Little Impact on an Organization’s Security Posture

MITRE Shield Matrix Highlights Deception & Concealment Technology

Act of War - Clause Could Nix Cyber Insurance Payouts

Most Businesses Vulnerable to Emerging Risks Not Covered by Their Cyber Insurance

Oh Jeeeesus: Drivers react to Tesla’s full self-driving beta release

Rising Ransomware Breaches Underscore Cybersecurity Failures

SANS Launches New CyberStart Program for All High School Students

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying. Long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Massive changes ahead. We've even got traders who used to be on the floor of the stock exchange, and on the floor of these massive financial companies. We've even got them at home. Now you're going to be shocked at what they're doing to replace that interaction.

Hi everybody. Craig Peterson here. We're going to be talking about these traders and how virtual reality headsets have changed the way some of them are doing business. We're going to talk about what's on your enterprise network. I talked about this last week.

Hopefully, you got my email. It came out on Wednesday this week. I'm going to try and do two of these a week. It's three minute little a coaching lesson, if you will, on security. This week we talked about your enterprise network. We're going to delve into that more today.

Have look at an email make sure you got that. I know you're used to getting emails from me Saturday mornings. This last weekend we sent our weekly email on Sunday instead of Saturday. I'm not sure if that's better for you guys or not. We certainly didn't have quite as many people open it as usual.

Usually, it's almost half of everybody that's on the list, and that's thousands of people open it but not as good on Sunday. We may switch back to Saturday. We'll see.

It also has to do with our time, right? This is a labor of love, trying to get all this information out to everybody. So things can change.

We're going to talk about some big changes in malware attacks this year, even though the decline a little bit in Q2. They got more potent, and we'll tell you why what's going on years.

Most severe windows bugs is now under active exploit. We'll tell you about that. VPNs are dying. You know what my thinking is about these paid VPN and free VPN services. If you've been listening long enough, right? They do not increase your security. In fact, they decrease your security in some ways. Maybe you're going to stop your local ISP from tracking where you're going online, but you're you overall are much less secure.

Shopify. We've got a huge theft of the hair, and turns out it kind of employees involved. We've got Microsoft booting more Chinese sponsored hackers out.

Wanna Cry. That yeah yeah, that same one that brought the country and the world to its knees a couple of years ago. It's back. And love in the time of Zoom. So if I don't get to all of these today, make sure you check online, or if you're going to miss part of this, all of that available there, Craig peterson.com. We're trying to make sure all of the audio is up there so that you can listen to it in your time on any podcast app. Make sure you check it out, whatever your favorite app is.

Technology has really changed everything, and we have seen that this year, they expect to be just an incredible online shopping season. Now that's good, and that's bad. You've got the local stores who are hurting very badly. I have gone out of my way lately to try and go to a local store as opposed to ending up online and buying stuff because I want to support them. They are part of the economy, obviously. They are where my kids got some of the first jobs in local stores. They are also the place where I can go to see things and play with things. It's not like where Amazon charges me sometimes to return something. That wasn't what I thought it was. That kind of always bothered me. So I like the local merchants and not just the restaurants, but the guys that sell the little electronic gear that we have and other things, but it's going to be a huge year this year.

We're going to talk later on today. This is kind of low on the list, but virtual online Zoom dating. It is really changing at all. Now we have a story that came up from Ars Technica this week, Owen Walker of the Financial Times, talking about how we have moved our businesses into spare bedrooms in our homes, living rooms, and we've talked about this before.

If you're working from home, make sure you have a spot where all you ever do is work from home. The brain kind of ends up associating, and you can become much more productive that way. Different parts of the room, maybe a different chair. Maybe all you do is turn the chair around just to let your brain know that it is time to get to work.

I also use some apps. I've got vitamin R that I've used, and I don't really use it as much anymore. I've kind of grown disciplined over the years. You might check it out online. Vitamin R. It uses the Pomodoro Technique, which is an Italian name. Remember those little tomato clocks or countdown timers you have in the kitchen, or at least you used to have years ago where it just reminds you, Hey, uh, you're supposed to be working right now cause you hear it go tick tock, tick tock, tick tock, and then it goes off and okay, well, my 20 minutes is upon this particular task, and then you take a brief few minute breaks and then you get right back to it.

There are all kinds of hacks to help us to be more productive when we're at home and ultimately more productive than maybe in the office in some ways. In other ways, you're not as productive, and you're not as productive because you're not around these other people who can come over and ask questions, and much of what we learn, much of what we do is just incidental communications. Where we are in a hallway, we bump into someone, or we go to a meeting. We have a side discussion. That's hard to do when you're on a WebEx team call because you're there, and so are 10 other people, two other people. It doesn't really matter how many other people, because you can't just lean over and say, Hey, what do you think of this or that?

Now, obviously, on the WebEx teams, you can go ahead and type a message, right? You have that chat capability, and you can send it to a specific person. You can do that on Zoom as well, but I don't. I'm not going to talk about Zoom right now because you should not be using it for business. Just you really, really should not.

So focus on that ability to communicate. Some companies are now going to happy hours online, and I've been invited to a Zoom happy hour, and the company's sending me three little bottles of wine. We're going to do it. Taste-testing and we'll just kind of chat while we're there online. It should be fun. It'll be interesting too.

Many businesses are doing that, as well. They have a little happy hours and get-togethers because you're not going out after work for a drink to talk to people. You're not going out in the hallway and talking to people. It is such a different world.

The whole thing with whether or not you're there physically is a whole other problem when it comes to traders. Think about traders. If you've seen some of these movies or TV shows where they're on the floor, I know Fox business, and some of these other business channels have a shot with a camera on the floor, the trading floor, and there just aren't the people there that they used to be. But it's again, it's the interaction, and that's what's been important in the past.

Some banks UBS particularly has been issuing some of its traders over in London. These HoloLens from Microsoft. These are virtual reality headsets, and the idea behind this is to allow the staff to recreate the experience of working on a packed trading floor without ever leaving their homes. I don't know if you saw the video or pictures of this, but when Microsoft first introduced these virtual reality headsets, they had issued them to everybody who was in attendance at this conference room, and they started playing these videos. So you see all these people looking around, of course, they can't see beyond what's right in front of their eyes, which is this HoloLens. These virtual lenses and they're looking around and right up the aisle walks Bill Gates, of course, nobody notices him because he can't see him. They're all just caught up in this experience.

That's what they're trying to do. Banks have been really desperate to bring workers back into the office. When you're talking about these regulatory sensitive roles or roles involving money, where banks will typically force employees to take vacations, which you should be doing, if you're a business person and you have a bookkeeper accountant, make sure they take a vacation, make sure they get out, and have somebody else fill in for them. That's going to help catch people who might be cheating with money. They really want to get these people back in. Trading is one of these, but because people are afraid of the Wuhan virus, they don't want to go into the office. So what they've done, and this is really cool, I'm looking at a picture of her right now is they've set it up so that the traders can be sitting there in their homes, and it looks like they have a bunch of different screens. You've seen this before, right where they have four or five, six screens in front of them, different data on different screens. They can look over, and they can pull up a screen, they can see everything out of the corner of their eye, just like they're used to. So I can see our market rise or drop in something. I think it's really cool. And that's a good use of that technology.

Deutsche Bank, by the way, told its New York staff last week that they were not required to return to the office until mid 20, 21.

Deutsche bank's going to be opening a whole new office. Many of these others are doing it as well, so we'll see what happens.

This HoloLens by Microsoft was new surely seen as a gaming device, and these headsets cost three grand. Many companies using them as a communications tool. You might want to look at it as well, depending on your business and what you are doing.

So coming up, we're going to talk about what's on your enterprise network. What's on the network, your house. You really might be surprised.

We've talked about the security cameras on our networks before and, of course, the internet of things. A new study is out is really very, very concerning to business people and, frankly, to even homeowners. So we're going to get into that right now.

Let's get into this big problem. Now that we have uncovered.

There's a new survey that was done by a research firm called Vanson Bourne. And it was done on behalf of Palo Alto Networks. Now Palo Alto networks are one of the competitors for Cisco and others, who make network equipment. Palo Alto network stuff is pretty decent. They've certainly had their fair share of problems lately, but so has everybody else.

I'm much more into things over at Cisco that has pretty much everything you need, and it's nicely integrated. Palo Alto networks, good people. I know a few people that will work for them. I know some people that absolutely swear by their stuff. So don't think you've got Palo Alto networks here you're completely out of luck cause you're not. They've got some pretty decent stuff.

Let's get into the survey. I found it to be very interesting. When we go into a business, the first thing we typically have to do is scan the network. You must have to have an audit of the devices that are on your network? And then we scan the devices themselves. Typically that means their servers. Whether they're windows servers, Linux servers, we scan them. See what services they have running, which ports they have open on the local firewalls. We scan them all for any sort of malware that might be on them, spyware, et cetera.

Then we move on to really identify the versions of software they're running. In many cases, if you're running Windows, you probably have done some patches, but some 50 ish percent, depending on the number you want to use and whose numbers you trust. About half of all windows computers are not patched up, and something like 30%, 40% of windows computers have never, ever been patched. But let's assume that they have. Let's assume that you're on top of your game. You are the person assigned to it in the business. Maybe you are an IT professional. You've had some training, and you have some certifications, so you're off and running. Things are going great for you, right. You have kept it up to date.

We're moving to the next level, which is our, our macs or our macs up to date. Well, they just keep themselves up to date automatically for the most part.

But remember windows are just the operating system. Mac iOS is just the operating system. How about all the other apps that you have on those computers? All of the applications. There are all a lot of them there, and it's everything from maybe the Microsoft office apps that hopefully you've got set up to do an automatic update. But it's also all of those other little apps that you've put on your computer over the years, that by the way, is another good reason to re-install your operating system every once in a while, make sure you have a good backup, make sure you test it before you do the reinstall and don't just, re-install everything.

Don't just restore that backup blindly, but actually restore the software. That you need. Okay. The data files you need because there are so many pieces of software. We have not been keeping up to date.

So you are the world's best IT administrator and you've got all of the computers up to date, all of the apps, only applications that you really need are actually there on the computer. You're not getting tainted by any of this other stuff that's going on, right? Oh, you are so, so good. Congratulations.

But let's have a look at the other devices on your network. This is where the survey from the research from Vanson Bourne really raises some questions. They surveyed 1,350 IT, which is, of course, information technology decision-makers in the US and 13 other countries, so that's a pretty decent sized survey.

I don't know if these people were self-identified or how exactly they came up with those numbers. You can find it this whole survey if you wanted to download it over on Palo Alto Networks. There's a lot of good information that you can glean from the survey. It's good stuff all the way around.

It's the connected enterprise IoT security report for 2020 is what it's called. These decision-makers, these 1,350 decision-makers in IT, were asked questions to identify the strangest IoT devices they found connected to their organization's networks.

Now let's define the internet of things devices here for a minute. We've already, and we've concluded here that you are the IT guru, right? You know enough to keep windows up today to remove the apps, to keep your macs up to date. How about some of the other devices that are on your network?

I'm not going to mention security cameras because I talked about them all the time. Right.

How about your printers? Have you updated the firmware in your printers? That's part of the reason we use higher-end Xerox printers. They all auto-update themselves, which is really nice, and we can delay the updates, et cetera because again, those printers are computers that are attached to your network. Even the ones that are attached by a USB cable, although they're a little bit less dangerous than something that's internet-connected or ethernet connected.

How about some of the other devices? Do you have a scanner attached to your network? Do you have a fax machine attached to your network? I know a lot of doctor's offices you have to have a scanner, you have to have a fax machine.

If you buy one nowadays, the odds are extremely high that they are connected to your network and maybe write directly to your file server. Have you restricted the access that they have on the file server to make sure they're not doing nasty stuff?

44% of this 1,350 IT business, decision-makers almost half reported seeing wearable medical devices, 43% said they had encountered kettles coffee machines and other connected kitchen appliances. People are doing that all the time and remember that this isn't just in the business offices. This isn't our homes, right? 38. Percent said the same of IP enabled sports equipment. We see more and more of those. Have you seen the commercials for Peloton or this mirror thing? This mirror thing is really kind of cool. You hang it on the wall. It's kind of a mirror with a builtin display that lets you exercise with somebody remotely who is a coach, or maybe it's a prerecorded class.

Some have had IP enabled sports equipment includes skipping ropes and weights. 34 present percent reported smart toys. 27% said they found smart vehicles on their network.

I want to make sure you guys pay close attention to your networks or whether it's a home network or an office network. Make sure you segment the networks as I mentioned in my video this week. Hopefully, you got that training video on Wednesday. Keep an eye out for them. Make sure you click through. I also, if you don't want to watch the video, I also have the transcript there when you click through. So you can just read it pretty quickly. It's like a minute to two-minute read and a three-minute video. So enjoy it and be careful out there.

Scan your networks and scan them frequently.

What is going on with malware? There've been some major changes just over the last few months. That's what we're going to talk about right now. What do you need to watch out for? What should you be doing in your business as well as your home?

We know that they're here. I have been a lot of attacks over the years. That's what we're trying to stop. Isn't it with our businesses, with our home users? That's why we buy antivirus software or why we have a firewall at the edge. Maybe we even upgraded your firewall. You got rid of that piece of junk that was provided by the internet service providers. Most of them are, frankly, pieces of junk. Maybe you're lucky and have a great internet service provider that is giving you really what you need. I have yet, by the way, to see any of those internet service providers out there that are really giving you what you need.

So there is a lot to consider here when we're talking about preventing and preventing malware. What we have found is that malware attacks declined this year in the second quarter, but here's what's happening. Right? They are getting through more.

Historically, we had things that have hit us that have been various types of malware. I remember when I first got nailed back in 91. I had a Unix server that I was running. As you probably know, I've been using Unix since the early eighties, 81, 82.

I was using Unix, and I had my own Unix machines because I was helping to develop the protocols that later on became the internet about a decade or more later.

The Unix world was on a rather open world. Was everybody on the internet was pretty friendly. Most people were involved in research, either government research or businesses doing research online, a lot of smart people, and we actually had some fun back in the day's puns and everything.

We weren't that worried about security, unlike today, where security really is a top of mind thing for so many people. We weren't worried about who's going to do this to me or that to me.

I had a Unix server that I was using, actually at a few of them that I was using for my business. Now, one of those servers was running emails, a program called Sendmail. That's still around today. It was the email package that was ruling the internet back at the time. I got nailed with something called a worm. It was the Morris Worm. In fact, it got onto my computer through no act of my own.

I didn't click on anything. It got onto my computer because it came through the internet. That was back in the days when we really didn't have much in the line of firewalls, so it just talked to my mail server. One of these days, we'll have to tell some stories about how we really trusted everybody back then.

You could query to see if an email address was good. You could get onto the machine and say, Hey guy, I noticed that you had this problem, so I went in and fixed it for you, and here's what I did. Much, much different world back then.

But that's how malware used to spread. It was something, and it was just kind of automated. It went out, and they just checked everybody's machine to checked firewalls to see what they were to see if they were open.

We've been doing that for a very long time, haven't we? We have been nailed with it. That's what the viruses were and are still, where it gets onto your computer.

Maybe you installed some software that you shouldn't have, and that software now takes over part of your computer. It affects other files. It might be something that's part of a Word macro or an Excel macro. And it now spreads through your sharing of that file and other people opening it.

Worms are like what I got nailed with. Just start crawling around through the internet. So they run some software on your machine, and that looks for other machines, and today things have changed again.

They are changing pretty frequently out there. What we have seen so far here in 2020 is a decrease in malware detections. Now, just because there's been a decrease in malware detections, I don't want you to think that the threat has diminished because it hasn't. But the signature-based antivirus system are real problems.

Now, what's a signature-based antivirus system. That's any antivirus software, like your McAfee's like your Norton's, the Symantec stuff, any antivirus software, that is working like your body's immune system.

What happens with your body's immune system? You get a virus, and you're your body says, okay, what's going on here? It starts to multiply. Eventually, body figures it out. It develops antibodies for it. So the next time it sees that virus, you're likely to be pretty much immune from it. Your body's going to say, Whoa, that's a virus, and it goes in and kills it pretty darn quickly.

That's the whole idea behind trying to stop the WuHan virus that is spreading out there. How do we stop it while we stop it by just developing antibodies? Right? That's herd immunity. We could also develop antibodies by an antivirus shot that is designed to stop that virus from spreading and prevents you from coming down with COVID-19 symptoms.

In the computer world, it's much the same with most of the software signature-based antivirus software is exactly the same as the way your body's immune system has been working, in many, many ways.

Here's what happens. Someone gets infected with a virus, and they reported to Symantec or Norton, or maybe the software reported itself. Usually, it's a third party that reports that, and they look at it, and they say, okay, so what does this virus look like? There is, in this program, the developers' names embedded, or the name of the hacker group is embedded in it. So we are going to now say any piece of software that it has this hacker group's name in it, we're going to ban. Right? It recognizes it. So when the file comes onto your computer, your computer looks at it. It looks at the signatures. These are called signatures. To say, okay, how does it match? Or it doesn't match at all, and it might be through a string that's somewhere embedded in there. So it might be through a name. It might be through a number of other things. That's signature-based.

The malware that was not detectable by signature-based antivirus systems jumped 12% in the second quarter of 2020. That is amazing. Amazing, absolutely amazing. Seven in 10 attacks that organizations encountered in the second quarter this year. In fact, involved malware designed to circumvent anti-virus signatures.

Most cyber-attacks last year, and this is probably going to be true in 2020 as well as we get into the fourth quarter. But most cyberattacks in 2019 came about without malware. That means that there were hackers behind this.

We're going to talk about that. What's going on some of the data also from CrowdStrike and what they have found CrowdStrike is an anti-malware anti-hacker company. They've got a lot of great people working for them as well what they have found.

It's like the bad old days of hacking, and they're back on us right now.

We see more and more malware-free attacks. We also see attacks are completely evade a signature-based pieces of antivirus software. If you have antivirus, you think you're protected. You're you really aren't.

Well, we were just talking about malware attacks declining, but what's really happening is that they are becoming more and more evasive. That is a scary, scary world out there right now.

These hackers are no longer just using regular old viruses to try and get into your systems. Time was, the good old days, there might be a macro virus that comes in on one of your Microsoft Office document. You might've gotten a virus from some software. You downloaded some free software from a warez site, but in reality, what is happening right now is the attackers are getting smarter.

Malware is designed now to circumvent completely, antivirus signatures. So that signature software that you had that you bought a few years ago that came with your computer, that junkware that was installed, that came up and said, Hey, you need to, to pay for it now. You had your 30, 60, 90-day free trial. It just isn't gonna work anymore. The antivirus signature code that you bought and paid for and have been using just isn't going to work.

So what do you do? That's a really good question. What is the right thing to do? Well, first of all, we've got to make sure that we're no longer just using antivirus signatures. We've gotta be looking at the behavior of the software. There are companies out there that use white lists in particular. I can think of PC MATIC, and I've got to get them on the show and talk a little bit about this. The way they do it is interesting. There are drawbacks to white lists as well.

The way we do it is a little bit different because we're doing it the Cisco way. We have antivirus signatures. We also have behavioral and analytics. So if. It's an old piece of malware, and an antivirus signature is going to pick it up. Well, our advanced malware platforms are going to pick it up, right? That's what Cisco does, and some others do as well.

But if it doesn't have a signature that's recognized, it watches its behavior, and depending on what happens with the behavior, it might do a few different things.

So, for instance, this week, we got a call from a client because what had happened was there was they got an email that had something that was flagged as suspicious by our software. Immediately that software was uploaded so that Cisco Talos. Talos has been around a long time; they are true experts in cybersecurity. There's a couple of hundred people that sit there and examine it. So that our software automatically sent this thing to Talos to be examined.

We called up the customer and said, Hey, there's something suspicious in your email box. We are heavily filtering all of their emails as well before it even gets into the box. They said, okay, what email was it? The subject matter was an invoice, a specific invoice. We said, look for this and this invoice, and they couldn't find it in their inbox.

Our technician had a look and said, Oh, wait a minute here.

Now what had happened is our software had automatically sent it to Talos for an examination. Telos will look at it and said, wait a minute. This is something that looks very malicious.

So it automatically puts it into a kind of a lockbox and examines it there.

It looked malicious, and so they retroactively pulled that piece of email mail out of that email box all automatically. Joe, our client, had no idea. We didn't realize it had happened either until after it had happened. But the idea is if it's in question, they can remove it.

The way it works, as well with the anti-malware platform that we have is if your computer gets some of the software on it and it starts to do something malicious, we can roll your computer back. So the malicious activity might be that your computer is now starting to probe other computers or probe other server servers that are there in your network. So we noticed that attempted lateral spread and our software would automatically shut off the network port that the computer is attached to. It's just phenomenal what you're able to do nowadays.

Now, one of the security vendors that are out there called WatchGuard analyzed some of the malware attacks that were going on, and it looked at 42,000 firebox appliances that were at customer locations worldwide.

Now, part of the reason I like Cisco is it's using billions of data points every day to figure this out. Right.

So WatchGuard has 42,000. But they found that the devices were blocking 28 million malware samples representing 410 unique attack signatures, which is an increase. But there are all kinds of tools that are available now on the dark web for as little as $50 that can be used in attacks.

When we delve into this a little bit more and look at some of the incident report data that came out of CrowdStrike, we see some very interesting things for the first time in CrowdStrike's research. They found that so-called malware-free attacks edged ahead of the malware based tool. 51 percent, in 2019, of attacks that were analyzed here by CrowdStrike, 51%, did not have malware.

Now we've talked a little bit about this before I go into this in quite a bit of detail in my courses, in my more advanced cybersecurity stuff, but what's happening is the bad guys are using information that's being harvested from the dark web.

You know how I'm always getting on your case about making sure you're using one password or last pass, right. I think it's important. Well, part of the reason for that is you should use a different username. I don't like websites that make you use it an email address. Cause that's currently insecure. But you should use a different username at every website, and for sure, you should be using a different password and use one password is great at generating them so's Last Pass. Those are the only two that I recommend. If you're a business, you really should be using 1password.

The bad guys are now taking the information they find from the dark web, which is copies of your email addresses, copies of your passwords. They are using them to log in as a regular user in your network. If you have VPNs, for instance, that your business people, your employees are using to connect, they will find the VPN through a scan, the VPN access point, or the remote desktop access that you might be providing the old terminal services from Microsoft. Then they will do a credential stuffing. They will try and use a username and password from your organization.

We just had this last week happening, and this was a government subcontractor. They did some work for DOD prime contractors, and there were people who were trying to use credentials that were found on the dark web to get in. It's happening all of the time, but now they're getting on.

They have these hands-on keyboard methods. They're trying to use usernames and passwords that they have found on the dark web, and they are using PowerShell. Now, PowerShell is a rip off that Microsoft made from the Unix world, and Microsoft, of course, messed it up pretty badly, and there are all kinds of major security problems with it. Microsoft Windows were not designed with PowerShell in mind.

Nowadays, you have to use PowerShell to do certain things. Microsoft has finally figured out, Oh, wait a minute. Command-line interfaces are wonderful. Maybe we should use them more. So what happens is they use PowerShell.

They start it up, and now they use it to exploit your network, exploit your systems because it's not a virus, it's not a program, very hard to spot and they'll hide files and directories, and they will use these tools like PowerShell and act just like a regular system administrator acts nowadays on a windows machine. System administrators on Windows machines, they're using PowerShell, aren't they? Now, most organizations don't have the technology to be able to differentiate between a legitimate user and a legitimate employee or contractor or an attacker who has stolen credentials.

This is about a very, very big problem out there that's been seen by Cisco, by CrowdStrike, Rapid seven is another one they're using. They're seeing hackers using valid credentials or reusing credentials from other breaches, i.e., credentials that are found on the dark web. So what do you do? How do you do this? That's our really big question right now.

The bottom line, do not ever reuse passwords. If you're a home user, it's true. If you are a business, it's true. One of the things we do for our customers, and you can do for yourself is to go out to the dark web and search. Use tools, like Have I Been Pwned, very basic tools, and see if your users username slash email addresses are out on the dark web. Also, see if the password that's associated with that account out on the dark web is still in use by them.

Just this week, we found another one of our customers where one of their primary users, one of the C-level people, Paul, was using the same email address and password for the business applications as he was in for one of these hacked accounts out on the dark web. So be very, very careful.

Well, we've just been talking about some of the ways that the hackers are getting into us now, avoiding some of the software we've been using; these antivirus packages just don't work anymore. I'm going to talk about another problem. This is a massive windows bug.

We're going to be getting into a couple of other things here. We'll talk about VPNs a little bit and how it's dying and going away. We've got another employee theft that's happened here, this time to Shopify. Microsoft, and what they've done with Azure. We'll talk a little bit about these cloud systems because they are problematic.

Wanna cry is back and Love in the time of Zoom. Why we're in the midst of a dating revolution. So why don't we start with that one here - Zoom. You know how much I don't like Zoom for business. It is not considered secure or does not meet any of the standard security requirements. So that's a problem if you were to ask me.

We are in the midst of a dating revolution. Do you remember that episode from Seinfeld where George is out doing speed dating, and they had these? What were they? 30 second or 60-second dates. I guess that's been the thing over the years, maybe a little longer than that.

You spend two minutes, five minutes with someone and you're all there at the restaurant or whatever conference room. It's like musical chairs. Every time you move one. Usually, it's the woman sitting there, and the men move around, and it could be the other way around, I suppose. There was a good way to meet a lot of people. If that's what you're trying to do, see if there might be any chemistry. Usually, they charge for them, and yeah.

Today, well, things have gotten higher-tech. They come about here in Zoom rooms as well. I mentioned earlier today some of the things that we're doing from a business standpoint on Zoom. Many people are now having business meetings obviously, or hopefully not on Zoom, but in the online world.

But right now, what we're seeing is love and marriage. How people are connecting. It used to be, of course, accidental. Then some of us might go to the church we belong to and look for a companion or a mate. There are a lot of ways that things have changed, and they changed a lot, really in the 18th century with the industrial revolution.

Now we're kind of back to the isolation days. Well, so what do we do now? I don't know if we'll ever really get back to normal. People have found that they can do business from home. They can work from home. Now they found that they can date from home as well.

Already, we're seeing nearly 40% of heterosexual couples reporting that they have met online. Most of the time, that's being through a social media site like Facebook, or maybe some of the others that are out there. Same-sex couples are even a higher percentage here, more than 40% of heterosexuals that are meeting online.

Of course, there is also the casual encounters that have been going on. I can't even believe it, but Dr. Fauci even mentioned that, right? Oh man, we're not getting into that right now.

But this type of online interaction is absolutely surging during the time here of the Wuhan virus. Bars are closed. Restaurants are mostly closed churches can't meet you. Can't sing hymns, depending on where you are. They might only let a few people in. I know there's one state where you can go to a bar, but only one person can be in the congregation of a church. I, I just don't understand some of that stuff, obviously.

So what do you do right now? We see a massive drop in the number of Americans that are married by the time they turn 30. Only about half of them are married by the time they turn 30. Fertility rates have plummeted to 1.7, meaning the average woman will give birth to 1.7 children over her lifetime, which means if that woman can be considered to be part of a couple. That is negative growth in our population. Something that some people have been trying to achieve for a very, very long time, but it is well, well below the natural rate of replacement, which is as I recall, what about 2.1 or 2.2? So that's pretty dramatic, and it is just continuing to go down more.

Men aged 30 to 34 were living with their parents than with the romantic partner, and that's before the Wu Han virus pushed even more of a back into our homes as we've lost jobs and opportunities that are out there. It's just not very, very good, but the future isn't all of that bleak.

I wonder, frankly, when we're talking about general social social media. So things like Facebook and messages and stuff, how much of what we see and we feel we have a connection with other people. How much of what's real. We already know much of what we see. Isn't it real. Some of these social media influencers you've admitted to taking as many as a thousand pictures before they found one that's worthy of posting where all the makeup was. Right. The pose was right. The hair was right. The background was right. The lighting was right. It leads to a false sense of, Oh, keeping up with the Joneses. If you will. There's an older expression. Where people see this, and they think that's the way their life is supposed to be. It's absolutely not.

So how about where where we're trying to do one on one stuff. I think we all can remember going on dates and being a little braggadocious. Maybe inflating things just to ever so slightly. When we went out with somebody and then over time, we got to know them, and then we started to loosen up. I'm in a mastermind group, and I also have seen that in the mastermind group that as we got to know each other. We kind of relaxed, but we know each other's businesses now, and we can give each other good advice and a good kick in the pants when necessary.

So I don't know. The future's not bleak. I think. Yeah. It might take a while for people to get to know each other when we're talking about meeting online, doing little Zoom meetings, or meetups online. But the whole courtship thing has really changed the whole structure of what it is. It is just absolutely amazing, but I think we are still going to be looking for those relationships. We're so going to be trying to find them online, and I think it might work, and I don't know. Maybe a breakup is even easier in the online world or maybe the whole fallacy behind the online world where people are literally making stuff up if the fallacy is going to make it even worse when it comes to breakups. I really don't know.

I'm looking at an article here from Debora Spar. She's a professor of business administration at Harvard business school, and she's been very focused on issues of sex and technology and what's been happening with the technological change. She has a new book out called workmate. Marry Love, how machines shape our human destiny, which is kind of an interesting book. I think the romantic times are going to continue, but we're going to continue to look online for ways of meeting and doing stuff with people. So there you go. Zoom is not just for little family gatherings, but it's also for romance. I think that's kind of cool.

Hey, if you like to listen to the radio, when you're driving around in your truck or your car, one of the things that I do, and here's a little tip for, in case you didn't know you do it is I have Bluetooth in all of my cars.

Nowadays, there's Android play. For Android phones, not all of them, just some of the newer ones, and Apple also play for the newer Apple iPhones. What that allows you to do is run the app near a phone. And once that app is up and running, it will come out through your car stereo.

Now, many of you guys, of course, you're the best and brightest. So you probably know how to do that already. I love the way car play works on the Apple side, Android. It works pretty well too, but the main concept behind it is to keep the interface simple, to keep the number of distractions down.

We are right now under attack. This is the windows vulnerability that I mentioned live on the air here a couple of weeks ago, it's not patched up by most people, and it's really, really bad.

Well, this is a big problem right now. This particular vulnerability is called a zero log on vulnerability. What that means is your computer is vulnerable to attack without the bad guy actually having to log on to the computer. Very, very, very. Bad. Okay.

Now, this is an escalation of the privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while, from everything I was reading.

This is crazy because what's happening is they are using domain controllers and remote procedure call login servers to get in. So if you're just running a regular windows machine in your house, obviously you want to keep it up to date.

But this particular exploit is against these servers that are out there. The servers specifically have exposed domain controllers, and remote procedure calls, also called RPC login servers.

Why do you use those? Well, most businesses use those types of servers to allow people to log in remotely. Who logs in remotely? Well, its employees, right? We're there in our homes, and we're trying to get into the office. So we use a domain controller. We are sending RPC calls here for the login servers. You may not know what's actually going on behind the scenes, but that's what it actually is. Now there's a search that you can do on a line. There's a couple of different searches to find. These exposed servers, very, very big binary edge.io. There's a couple of others also let you know about it, but okay. They show more than 33,000 3 million networks that are exposing domain controllers. This is absolutely crazy here.

If a single network has both resources exposed, and the combination can leave the network-wide open with no other requirements. Okay. It's very, very, very, very bad. I don't want to go much more into this. It is absolutely catastrophic. If you are a person who's responsible for the, IT resources within a business. You have to take care of this. Right, right, right away.

The cybersecurity arm of the Department of Homeland security mandated all agencies will over the weekend. They put the mandate out on Friday, and then they had to be done by Monday. They had to apply the patch by Monday night or remove the controllers from the internet. Take that as a little bit of a hint that maybe it's something you should do too.

So if you are a business owner, make sure you check with your managed security services provider and or your employees who are responsible for it. Okay. Cause it's very, very big. It's the year most severe Windows bug that we've seen this year, and who knows, maybe more on the way. So I'm not going to say it is the best or the worst.

Now let's move on to another subject here that I think is worthy of the news here, and that is that VPNs are a risk.

Now, one of the legitimate reasons to use a VPN would be so you don't expose those services on your server. In other words, they're not exposed to the whole internet. If they're not exposed to the internet, some guy or gal somewhere else in the world can't get to them. So how do you let your employees get to those services and keep them locked down for everybody else?

You could do it by having your firewall only allow certain internet addresses to get through to those services. That's what I would advise as a quick stop-gap for you. Ensure that only the home computers that are supposed to be able to get at it can get at it.

But remember too, that it is just a quick stop-gap, because those home computers could be infected and could be used as a launching point to come after your services. So you're letting that home computer through your firewall to get to the RPC services, the login services they need. If that computer is infected, that home computer, it could be used now to attack you. So it's just a stop-gap.

Another way to do it is to use a VPN. Now, you know what I've been saying about VPNs for the longest time, where VPNs are, frankly, a little on the hazardous side, particularly for your security. There's a difference between privacy and security. At least if you ask me.

The biggest difference is privacy means that advertisers don't know where you go, which means your internet service provider doesn't know where you go. That's privacy.

Security is where you don't want that information sold, but even more so, you don't want to have your bank account information stolen or other things that really need to be secured. Okay.

So that's the big difference here. If you get a VPN for your business so that people can connect to these log-in services, or maybe connect to your file server, that's a bit of a problem as well, because remember the VPN can be used both ways.

It's like that saying, I love this old saying, but tracers work both ways. Right?

You use tracer rounds when you're shooting at the enemy so that you can see where the bullets are going. By the way, that means the enemy can see where the bullets are coming from. The same thing's true with VPNs. You put a VPN in place so that home users can connect to those login services or maybe your SMB CIFS here, your file servers, right, the file shares. You open it up the VPN so they can get through, but now potentially, the bad guys can use it to get through as well. So it is a big problem.

Because of that, VPNs need to be tracked very closely in your firewalls.

We run all the VPNs that we have for clients or that are requiring security. We run them all through not just a basic firewall but one that reassembles everything. Examined all files that are being downloaded, et cetera, et cetera. Okay. That's what we do now.

There is a new technique in place right now that is gaining a lot of momentum, and frankly, within the next few years, all businesses should be using this. We're doing this already, and it's something called Zerotrust. Zerotrust means in the case of a VPN. Okay, great. There's a VPN in place, but I don't trust that home computer to have full access to my network. In fact, not only mine, do I not trust it to have full access to the network, but I don't even want to have full access to this particular server.

I only want it to have web access, let's say. Even then, I want to go to the next level. I want to make sure that that home computer is not being used to grab my client list. That an employee is about to take with them as they walk out the door to my competitor.

That's where you start getting into Zero trust and what that's all about. We're going to talk a little bit about that. What Gartner's predicting is going to happen here by 2023 and how you can use it and how you shouldn't be using it right now, in fact, so stick around because we'll be right back.

So we know a little bit about VPNs and what they are. So what's Zero trust and how's a Zero trust network run. What are we looking for here shortly? More than half of businesses will be Zero trust.

I've started to do some three-minute training. So the first one went out on Wednesday, and I was really surprised just how much work it takes to make a three-minute training. But we did it, and we got it accomplished. We're going to try and have a couple of those a week, plus the weekend newsletter, which is, of course, a fair amount of work, but we're doing it for you. Hopefully, you got a lot out of it.

I got a crazy number of responses to the first video. So thank you. Thank you. Thank you for respondeing. Hopefully, I got back to you in a reasonable amount of time here, and we're able to help you out a little bit. Anyhow, if you missed it, go look back on Wednesday this week. That's when I put out the first one. So it should have been in your email box Wednesday. As usual, it's from me@craigpeterson.com. So if you're not getting them and you think you should be double-check, make sure I am on your contact list or whitelist me somehow so that you get those. They're important. I'm going to be doing more of those a week just to kind of a light touch. Let you guys know what's up.

So VPNs have been around now for more than a couple of decades. They've been fantastic. They've saved a lot of businesses a lot of money. Now course, they tend to be kind of dangerous, particularly these free VPNs and the commercial ones that you're using, to somehow try and make yourself more secure. I just shake my head every time I hear these misleading ads. They are lying to you. It's really not going to protect you that much, frankly, if at all. It gives a little bit of privacy in certain situations, but not in others. I had a great call with Doug, in fact, this week. And he was having some problems. He is a small business guy been in business for a long time, sold his business, and now he's almost 80. I think he said he was 78. He's kind of back in business, again, keeping himself busy and occupied. He was wondering and worried about trying to keep some of this stuff secure. So we went through it a little bit with him.

He uses macs, so it is definitely easier to keep secure. When he's on the road, he has one of these little devices he takes with him that allows him to connect to the internet from Verizon. One that directs you directly connects you to the internet, which is dangerous. Another one that provides you with what's called Nat or network address translation that's a little bit safer. So he's going to send me the model number in particulars of what he's using so that I can help him out a little bit.

By doing that, he's no longer tying into the wifi at the airport or on the airplane or at the coffee shop, wherever he's going. He's got his daughter doing that too, which I think is a very good idea. I know a lot of people, as well that does it. I do it as well. I have one of those little devices. I just replaced the battery in mine because it started swelling. It's a lithium-ion battery. Some of them, when they start to swell, you've got to replace because what can happen is when they swell, they will short out and can start a fire. So be very careful about that.

So he's smart enough to know that you don't want to use public wi-fi. He effectively brings his own little wifi device with him, which is, again, a great idea.

Some people use VPNs when they are out there on the road and connecting back into the main office or their homes. I have that as well, and that lets me get directly in.

Most of the time now, what we've been doing for our office and our customers is putting together zero trust networks. These are far more secure than anything else we have out there right now, as far as firewalls and everything else goes. The idea is, just like its name implies, that we're looking at everything. We're no longer just trying to do what's called a perimeter security approach where we have a firewall at the perimeter.

Now we are trying to protect ourselves and our businesses from any kind of attack, including insider attacks, including the lateral movement that I've talked about so many times before. Where a bad guy gets a foothold inside of a network, and that bad guy immediately tries to start spreading things. Very dangerous. Very, very dangerous. There's several other flaws too. Perimeter security just doesn't do a good job of counting for any third parties, any vendors you might be working with contractors; all of your supply chain partners. If attackers steal somebody's VPN credentials, now the attacker can get into the network and roam freely. Like I've talked about many times.

Many of us use the same username and password on pretty much every device out there. That's a problem because when it gets onto the dark web, now the bad guys have it. Plus, the VPNs over time have become a lot more complex and very difficult to manage.

It's rare. I say rare, but I've never seen an exception. In other words, it seems that these businesses have misconfigured VPNs. It seems to be a pandemic out there, frankly—a lot of pain around VPNs.

So this is going to change it all. You are. We're going to have different equipment internally. Your devices are not gonna be able to connect directly.

So the way we have it set up all of the devices on a network, instead of speaking directly with each other, have to go through at least a firewall. The firewall watches what they're trying to do even inside the network. So it's no longer just out there at the perimeter. Frankly, what we've been doing with VPNs, it's just clunky. It's outdated. Frankly, kind of dangerous. So keep all of that in mind.

All right, if you need a little help, if you have some questions, I am more than glad to get on the phone with you guys and chat a little bit and help steer you in the right direction. You can just email me M E @craigpeterson.com, and I'd be more than glad to get back to you. So keep all of that in mind. VPN is dying. Zero trust is what's coming down the road.

Now, I just mentioned the problems of potential internal threats, and that can include bad guys that are in your network, spreading laterally, as I just mentioned, but it can also mean that your employees are the problem.

I've seen that before. I had it happen to me, where I had an employee who took all of my customer records and took my customers with him. I could not believe it. I still can't believe it to this day. What he did, I don't understand it. What does he think he's doing? He may have built up a relationship with my customers. I don't think he brought a single customer in. In fact, he built up a relationship with my customers, and then he figured they're his customers now because he has a relationship with them.

So forget it, Craig. They're his customers. It is just absolutely amazing.

Shopify, which many of you have heard of before and many people are using. Has found that two of their support team employees were involved in a scheme to steal customer transaction records from specific merchants. It affected apparently fewer than 200 merchants, but there's an example of where Zero trust can really come into play. Do your sales guys have access to information they shouldn't have?

How about some of your support people? We have to make sure we're monitoring where they're going and what people are doing within our networks. Okay.

We're going to talk about Microsoft and the Azure store and president Trump and wanna cry. You remember that really bad piece of malware? It's back.

I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of them here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out a lot of people this week, including a bunch of very small businesses, and that's what I love to do. That's why I do this, right. Help you guys out a little bit here.

Now, obviously, I have customers, big paying customers, usually, companies that are regulated and actually need cybersecurity.

But for the rest of you, I still will help you just as much as I can. Obviously, there are some things you need to do, and that's what this is all about.

Well, you know already about the Apple app store. I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to buy or download little applications that you can use on your smart devices. They're both great little stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

That's managed by Microsoft, run by Microsoft in most cases. Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have stores that are over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been amazing to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon, and anybody that has one of these cloud services also have a store.

And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they actually are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want to also use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like, mysequel, or whatever database you might want it to act like. Or maybe it really is one. Maybe it's your own version of that. Those types of apps are available in these cloud services just to use those terms loosely.

Well, earlier this year, it turns out according to Dan Goodman, who wrote an article over at ARS Technica up on my site, but members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this huge command and control network that was being run out of China.

Now we can also talk here about commanding control because your computer might even be part of this. So if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

Now here's the idea behind command and control. They're not going to ransom your data. They're not going to try and do something nasty with it. In fact, these command and control guys don't really care that your computer can do anything other than connect to the internet.

So one of the things they'll do with command and control is they will do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Now that company's servers just get hammered and nowadays we see in the order of tens or even hundreds of thousands of requests. Per second coming into some of these data centers and that there are services out there to protect against. Those types of denial of service attacks. Okay.

But here's where things really start getting interesting. That is, they all also use command and control systems to send out emails, to do phishing, even to research them. So command and control just as it sounds is they have control of your computer, right? They send commands to execute.

So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just, we're not talking about an app, like an app that would be in the windows phone. If you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference.

These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore. We're talking about the smaller guys who really don't have the resources to check.

You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So they had the cloud hook, hosted applications.

This is a hacking group that Microsoft is calling gadolinium. They had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you just flick the switch and the light comes on.

Believe me, and it is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now there's so many free trial services and one-time payment accounts. Hackers have been able to quickly get these different things up and running.

They, as I mentioned before, can even buy their own materials, their software to do the hacking, to do the phishing, to do the ransomware, to sell the decryption stuff. They even have banks that'll handle the transactions for them to in converting Bitcoin into the US or whatever dollars they want to. Very very big deal.

Earlier in the show, I've talked about this some of these tools are in use right now in particularly in Windows PowerShell, that are not well secured and are legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's very hard to detect the reuse of these illegal tasks.

This group, this gadolinium group, has recently started using a modified version of PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's very scary. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups that are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists are going to be using—these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

So one more thing real quick before we go. That is Wanna Cry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. This is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it. There's hardly any risk for them. It's even outsourced. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting in place some of the prosumer Cisco stuff to help out a very small company and some of the commercial stuff that you need to have if you are a regulated industry. So we'll be doing some of that this week, too.

You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. me@craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

It's Friday, everybody. Craig Peterson here. I was on with Jeff Chidester on NH Today. We discussed the Fraudulent Ballots and Printing Technology and how they can tell not only that it was printed. Then we got into social media and social engineering. Here we go with Jeff.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] That it prints on everything. And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology.

Good morning, everybody.

This is a kind of an unusual appearance, but this is an unusual week, right? I was on this morning on the New Hampshire today with Mr. Jeff Chidester. He was sitting in this morning. He and I go way back. He's just a great guy. I love him, but we got into some, I think, great topics here on how we can detect certain types of fraud when it comes to voting and also a deep dive into social engineering.

These sites are showing us stuff they think that we want to see and, uh, even search engine. So how do you get around those problems? This was a great little hit this morning. I'll be back, of course, tomorrow. But it is going to be a repeat show, but I think you're going to enjoy it anyway. It's one that I picked personally,

Jeff Chidester: [00:01:11] Welcome back eight 38 in the morning. Of course, we've moved this gentleman around throughout the week because of the election, but we also want to make sure we get to hear from him. Of course, we're talking about Craig Peterson. You can find out more about Craig by going to Craig peterson.com.

Craigpeterson.com.

Craig, I haven't talked to you in a long time. How you been, bud.

It has been awhile. Hey, I'm doing really great. It's great to hear you on the radio again,

It's fun. We had a really fun show today. It's always a pleasure when I get to join you. I think keeping with the theme when we think about the tech aspect of voting, one of the other things that have come out to light, is something that you've been talking about is the ability to go ahead and now print out these ballots.

I mean, some States actually allowed it, but the continuation of being able to do that also leads to potentially more fraud.

Craig Peterson: [00:01:54] Absolutely true. We have rumors out there. I know, for instance, in one of the polling places here in New Hampshire, they actually ran in and made copies of some of the same-day voter registrations because they ran out of the cards. There were so many people voting the same day. There are rumors that there's been some ballot stuffing going on. Apparently, in some areas, they have taken the real ballot they got their hands on. They ran it through a copier, printed them out and filled them in, and showing up with briefcases full of these things.

And many people might not be aware of it. But, you probably are, though, Jeff. Our color printers for, well, more than a decade. Now, when you print a page, any page at all that printer embeds on it, the serial number of the printer that made that print, as well as the date and time of that print. Were you aware of

Jeff Chidester: [00:02:54] that?

No, it wasn't.

Is it how, where is it? Where do you see that? How would you see that?

Craig Peterson: [00:03:01] The secret service apparently has some kind of secret agreements with all of these printer manufacturers, but it's not just in the US, it's worldwide, but if you have a slightly older printer, what you can look for is a series of little yellow dots, and they are scattered all over the page. And you can take a page that you print out and go ahead and take a picture of a zoom into the upper left-hand corner and take a picture, then put it on your computer and zoom in even more because these things are just one pixel and it has a grid that it prints on everything.

And that grid has all that information. The idea is we don't want people using color copiers or printers to print money, which is why the secret service got involved with this. But it's gotten even more intense now with these new printers and new printer technology, and you'll probably familiar as well—Jeff, with the technology where you can embed a message in something else.

So, for instance, you might send a picture of something to supposedly your friend, and it's intercepted by the Russians, and the Russians look out and say, Oh, it's just a picture. But embedded inside of that is a secret message. That sort of thing could happen pretty commonly. That is exactly what our printers are doing right now. They're using dithering now to create moderate watermarks. And it isn't just color printers anymore. It's even black and white printers.

So if they really want to get into this, they can tell that a ballot has been faked and which printer printed it, and the date and time of the printing itself.

Jeff Chidester: [00:04:49] Once again, we're talking to Craig Peterson.

Of course, you can find out more by going toCraigpeterson.com. Craigpeterson.com. I'll throw it up on the Facebook page as well. And tech talk show as well. It can be heard on many stations, actually. And his podcast. You just over the place.

You know, Craig, I never knew that. That's actually fascinating.

It would be interesting to see how people looked into that as they went through that process, of being able to deduce that number and that code. That's just once again, I just did not know that.

One of the things I wanted to talk to you about, Craig too, is when we think about, I haven't had a chance to talk to you in so long, you look at all these tech issues, and you look at how the tech giants have really been so much focused.

We found out yesterday that the tech giants have once again basically shut down President Trump's accounts, and they're not letting those posts up. Where's that going to go? I mean, I understand that the balance they want to have, but once again, they are, they're not supposed to be technically, journalists.

it's up to the people to decide whether they believe the information or not. I know that's a little bit difficult. We have to trust people. Where's this going to go, as far as a tech understanding, as far as the federal government addressing this issue.

Craig Peterson: [00:05:53] I remember way back in 83 when I first got really involved in the internet, and I was so excited because we had democratization of information, unfiltered and of course now what you're referring to today is the fact that these major social media platforms are filtering what we see.

That started those five, maybe it was eight years ago, where on Facebook you could follow somebody, and you would see on your feed everything that person posted. Facebook decided, no, we're not going to do that. We are going to decide what Jeff Chidester might be most interested in seeing.

Some major celebrities dropped right off. Basically, what was happening is Facebook said, "Hey, you company X or Mr. Celebrity B" If you want people to see the posts, you know, the people that said they liked your page and they want to follow you. Do you want those people to see your posts? You have to pay us extra.

That's when this whole controversy started, right? And where you're going, is, are they a publisher or are they more like a public forum? They're acting a lot like a publisher where I see this going. People are very upset about this on multiple levels right now because the left and the right have had this type of censorship applied to them. I am a free and open. Internet. It's difficult from a technology standpoint to do the type of censoring that they're doing. So they've got more people involved now they've got 200% more people censoring than computers. Ultimately I think this has been a terrible thing for democracy mean I'm gonna boil it right down to that.

It's a feedback loop, right? So anything you're interested in, you'll see. And anything that disagrees with what the computer thinks you might be interested in. You'll never see it.

Jeff Chidester: [00:07:44] Well, absolutely. Once again, we're talking to Craig Peterson. Of course, you can find out more about Craig by going to craigpeterson.com craigpeterson.com.

I happen to think that their algorithms actually suck in a little way because I keep getting dancing cat videos. I hate cats. So maybe that's why they're going after me.

Craig Peterson: [00:07:59] There is good news here, though. And here's what it is. There are some suggestions that that algorithm, that program, that computer, that decides what it's going to show you, that they open up, what's called an API or an application programming interface to it.

So that third parties could put out, Hey, listen, you don't like the way Facebook monitors and controls your feed. We are the Republican party, and you can use ours, and we'll show you Republican stuff you're interested in or the Democrat party or whatever it might be. That might be even worse to a degree, but I'm sure there will be organizations that if that does happen and it looks like it might, where they open up that computer engine, there will be organizations that say, Hey, we're going to try and be fair and balanced, and we'll give you a little bit of both.

Jeff Chidester: [00:08:52] It's a good point too when people have to be very mindful that what they're getting back for data is not the complete picture. So you have to be pretty aggressive, especially if you're going to use these tools to inform yourself, be aggressive with your search patterns, and your mindset to make sure you're getting the stories from every particular angle.

That means that my searching has to be searched differently on several different machines because I found out eventually one gets polluted. Even though I'm trying to get pushed past and looking at both sides,

Craig, before I let you go once again, Craig Peterson, you can find out more by going to craigpeterson.com. You can catch him on tech talk as well. Any last thoughts?

Craig Peterson: [00:09:25] Well, of course, that is every Saturday, 1130.

Yes, use two other search engines. Don't use Google for almost anything anymore, unless it's a really tough, difficult search. I have found much better results lately with duckduckgo.com.

I love that. It's so much better, or maybe even quant Q W A N T, which is out of France. And that'll give you much better results when you're doing the searching.

if you're like me and you really have to dig down deep, because remember I do the cybersecurity, then I use something called Devonthink, and it's paid software, but it can crawl sites, and it uses multiple search engines and Boolean algebra, even to allow me to really dig into a topic.

So there you go. I think that's the way for most people to go.

Jeff Chidester: [00:10:16] Perfect. 1130 tech talk Saturday, of course, Craig Peterson online Craig peterson.com. Craig has a great weekend.

Justin McIssac: [00:10:21] I don't know if you're wearing shorts, but if you are keep it clean, man.

Jeff Chidester: [00:10:25] Alright,

Have a good weekend

Craig Peterson: [00:10:27] I had a really fun little appearance this week.

I did a presentation for Ingram micro. They are like the largest distributor, I think, in the world. They're just massive. We provide master managed security services for some of their managed services providers, break-fix shops, VARs, et cetera. If you're interested in how you can sell cybersecurity and make some bucks off of it but not have to spend quite literally up to $5 million just to get launched. Check out Sellcybersecurity dot com sellcybersecurity.com.

I have a little form there and a video of the session. All it is going to do is give me your email, address, and name, and then I'll email you. Not any sort of a funnel or anything else. So check it out, sellcybersecurity.com.

Have a great weekend, everybody.

We'll be back next week. Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. Since it was Voting day, of course, we had to talk about that but then we got into a discussion about Tesla, Alpha and Beta tests, how they are perfecting their software, and what we can really expect. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] There's been a lot of speculation about what that second computer is being used for and without getting into the nitty-gritty too much, the Teslas are connecting, calling home on a daily basis, typically.

Hi everybody. Yeah, I was on with Mr. Polito this morning. We had a great time talking about a couple of things, but, he was a little surprised about Tesla. In fact, he's a little afraid, but, I'll let him tell that too. All right. So here we go with Mr. Jim Polito.

Jim Polito: [00:00:33] Here he is the man, the myth, the legend. I am talking of course about our very good friend and tech talk guru, Craig Peterson. Good morning, sir.

Craig Peterson: [00:00:48] Good morning, Jim. Happy voting day.

Jim Polito: [00:00:51] Yeah. listen. I'm good. I vote. As they say vote early and often, Yeah. Hey, I wanted to ask you if there's anything in particular, in voting, that you wanted to talk about. Any kind of a tech talk angle, but then I have questions about Tesla.

So let's start with the vote. Yeah. Let's start with voting.

Craig Peterson: [00:01:13] Unfortunately, we've got reports, major warnings out, and I got a flash alert from the FBI about that this week. The bad guys are into our voting systems very deeply, in some cases.

That's really concerning to me and obviously the FBI and Homeland security. They're saying that it looks like it's probably Russian hackers. They are getting in. Yeah and are affiliated, at least in the past, they have been affiliated with the Kremlin. Just throw another monkey wrench into this whole mess.

There's not much we could do. It's too late. You got to show up and as bring in your ballot or vote right there. In the future. I don't know, Jim, if we're going to be able to have a really secure system. There are so many great types of technology using public keys and things. The thing that scares me about every one of those is that they're tracking your vote, which means it could easily get to the point where it's no longer secret ballot.

Jim Polito: [00:02:21] I do worry about that. Joel had mentioned earlier, like people saying, wait a minute, it's not public information who you vote for, but it is public information if you vote.

Sounds like a threat. Yeah. it's all out there. I just wonder, because in the future what's going to happen. Is it going to stay that type of activity where you walk into a building and you vote, or is this mail thing going to continue? And then eventually they're going to want to make the leap to, okay. You can do it online in a secure way. And I just worry about that.

Craig Peterson: [00:03:00] We're looking at places like Facebook, right? These online sites, Facebook, particularly where they really want to be the center of your life. you couldn't go on Facebook without seeing a hundred thousand different reminders to vote today.

I strongly suspect that Facebook's going to come out before the election and say, Hey, we've got a secure voting platform. What could possibly go wrong? There's really a lot of companies in that boat.

Jim Polito: [00:03:34] I don't think so, Facebook. By the way, Facebook and Twitter have said today, if anybody calls the election for themselves unless two major media organizations have done it, they're going to block it or suppress it. I don't know.

Who makes that decision? What are the two major news organizations?

Craig Peterson: [00:03:52] Huffington post and Fox, right? Those two.

Jim Polito: [00:03:57] Huffington Post and Fox. Right? Good thinking.

All right, let's get off this and get on the road. That one of my greatest fears is that one day people will be able to sit in their car and watch a video.

They'll be watching TV in their car and they won't feel the need to hear old Jim's take on the day's news. I feel like that's still a long way off because, for the most part, self-driving cars are not there yet, buddy. They may want to tell you that they are, but they're not there yet.

Can you tell me about Tesla's latest, self-driving beta release?

Craig Peterson: [00:04:41] Here's what's going on with Tesla. Of course, they've got these electric cars and it's all controlled via the computer. Tesla has two different computer systems onboard and we know that one of those computer systems is being used for staying in the lane and the automatic control of distance, so like cruise control. There's been a lot of speculation about what that second computer is being used for. Without getting into the nitty-gritty too much, the Teslas are connecting, calling home, on a daily basis, typically. Tesla's trying to make a self-driving car.

If I was trying to make a self-driving car, the best way to do this is with "I've got a hundred thousand cars on the street" is have the cars run the normal software and on that second computer run tests, software, and any time there's an exception, like the driver hits the brakes or grabs the steering wheel to turn or something. I analyze it.

Analyzes what happened and then sends out to Tesla's home office. Hey, we just had a condition 63 and let me know if you want more details and then the car could potentially upload it. There was no way you could upload all of the data these cars are collecting. We're talking about terabytes a day for these Teslas driving long distances.

The thinking is that Elon Musk and Tesla have tons of data and analyses done by the computer in your car. That way they don't have to build as big a data center or anything else. So Tesla has probably been running alpha self-driving code. In other words, code that's not ready for release at all on your Tesla for years, frankly.

Now we've got what you just pointed out is that beta release. Tesla has been raising the price all of the time, Hey, do you want self-driving, no problem. So I think it's an $8,000, maybe $10,000 add on. There is no self-driving Tesla right now. Remember it's an assist. Okay.

Jim Polito: [00:06:57] Yeah. It's called driver assist. Means, I passed it to, Craig Peterson and then he does the layup, you know what I mean? I'm not shooting the shot.

Craig Peterson: [00:07:08] Yeah. exactly right. So that's what it is today. So there's not this self-driving beta release that they released to just a few people.

There's a great article in Ars Technica, this week, where a YouTuber called Brandon M. Captured drone footage of his Tesla self-parking. Now there are four parking spots here. One of the spots had a red car parked in it and the other three are empty. And yet Brandon's Tesla is heading right for a rear-end collision with this red car. Exactly.

It's not ready yet. Some other people are saying, Brandon, again, saying it's crazy. It's scary. And it's unbelievably good. That means it's getting close to that time where the software performances may be there. We'll see. But you know what, Jim, I think Tesla is already won the self-driving car business, but it's not there yet.

You can't trust it yet. It's still making major mistakes.

Jim Polito: [00:08:11] We're talking with Craig Peterson, our tech guru. So, Craig, your assessment looks they're way out ahead of everyone else. But they haven't arrived at the, not to make a pun. They haven't arrived at the destination yet, but they're leaps and bounds.

Yeah. You know what, by the way, with the assist, I should have used a hockey metaphor, not a basketball one, with UI. I apologize, my Canadian friend. That I didn't use a hockey metaphor.

No, but you're saying Tesla. Has it'd be tough for somebody to catch up with them. Unless of course, all of a sudden the Chinese company has a self-driving system, and coincidentally, it's going to look just like a Teslas.

Craig Peterson: [00:08:51] This is a hat trick now. They've got it out there. It's working. It's working pretty darn well. It's known to be beta. We've got Elon Musk saying that by the end of this year, full self-driving with the exception of maybe the last hundred yards is going to be available to the average Tesla owner.

He says buy it now. This is the only car it is going to appreciate in value over time because the value and the cost of the self-driving add-ons are going to continue to increase. So that Tesla you bought the self-driving at $4,000 while selling at 10 means there's a $6,000 increase in the value of that car.

Now, of course, he's wrong because, in reality, there is wear particularly on the batteries, and the hundred thousand dish miles, it's you've got to put another $20,000 into your car. This is interesting and I think he's gonna win. I think Waymo is just too far behind as is everybody else

Jim Polito: [00:09:55] Interesting.

Alright, so there you have it. All from Craig Peterson. I have job security. They're not there yet. I feel good about that. Craig has a great show every Sunday at 11 o'clock on W T A G and W H Y N, where you can get more and more from him.

But, Craig, if folks want to reach out to you now,

Craig Peterson: [00:10:17] Well, the best way is just to go to Craig peterson.com/subscribe.

And if you subscribe right now, I'm going to be sending you a security reboot. because as you know that's what I pay a lot of attention to. This weekend on the show, we're going to talk about the new ransomware demands are doubling every six months, teaching your employees about spotting, smashing, and vishing.

If you're a home user, what does that even mean? And what should you do? And, that's really what we're focusing on Sunday at 11.

Jim Polito: [00:10:49] And John Bay back. My, Intrepid newsman reminded me that it was okay to use the basketball metaphor because Naismith the inventor of basketball was Canadian.

Craig Peterson: [00:10:58] That's right, I forgot about that.

Jim Polito: [00:11:02] There you go. I use the right one, John. Thank you for having my back. Craig, always thank you for being here with us. You're a great asset to the show and we'll catch up with you next week. Unless of course something big happens between now and then.

Craig Peterson: [00:11:16] Absolutely. From what I heard, Kamala was also not born, but raised in Montreal and was at least a Canadian. If she's not still.

Jim Polito: [00:11:26] She would claim everything, you know what I mean? If it meant a vote. She would claim just about everything. If it meant a vote. Craig Peterson, everyone. Thank you, sir.

Craig Peterson: [00:11:36] Take Care.

Jim Polito: [00:11:37] All right. Bye-bye

Craig Peterson: [00:11:38] So there's Mr. Jim Pollito.

I hope everybody took the chance to vote. At least those of you that are voting the right way. And man, I don't know what's going to happen here in another four years with technology and voting and where it's all going to go. It's going to be an interesting time and you can be sure I'll keep you up on all of it.

By the way, I have had a lot of feedback about the one-hour radio show, as opposed to the. No, what is it? Eight different segments. And, people love it. So expect that in the future, if you are subscribed, you're going to get my show as one big chunk. It is a podcast as opposed to just a copy of the radio show. So we've been changing that up. Karen has been busy doing all of that stuff for us.

So if you're not subscribed, go to your favorite podcast app and subscribe there. You can use the iHeart radio app, but one of the easiest ways to find out how to subscribe, just go to Craig peterson.com/iheart, for instance, and it will automatically redirect you right to that I heart page, or you can go Craig peterson.com/itunes if you're using an iPhone and subscribe.

I'd really appreciate it. It helps with the numbers and that helps to get the people out and listening.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome! Craig has an exciting podcast that covers quite a few interesting topics this week including USB safety, Properly disposing of your smartphone before getting a new one, Why the National Guard is being used to investigate Cybersecurity incidents in Louisiana, Iran, and threatening mail sent to democrat voters, Phishing is back in the news and why you must train your employees to watch for it. Then he talks about IT Wages and problems with the H1B Visa program.

For more tech tips, news, and updates, visit - CraigPeterson.com.

---

How safe is your USB drive? *How to protect your privacy when selling your phone Louisiana Calls Out National Guard to Fight Ransomware Surge U.S. government concludes Iran was behind threatening emails sent to Democrats How AI Will Supercharge Spear-Phishing IT Job Wages Are No Longer 'Exceptional' Need for 'Guardrails' in Cloud-Native Applications Intensifies GIRDUSKY: Corporations Use The ‘STEM Shortage’ Myth To Abuse Guest Worker Programs ---*

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We've even seen where USB thumb drives come pre-infected with viruses and other pieces of nastiness. So, just how safe is your USB drive in this day and age of us taking them home and to work?

Hi, everybody, Craig Peterson here. Welcome. We're going to be talking not only about USB drives, but how to protect your privacy when you're selling your phone. Okay. We've got a national guard call out in Louisiana over the election. We've got the government concluding that Iran was behind some email sent to Democrats and we've got artificial intelligence that's going to just supercharge, spear phishing. We'll be talking about that. Defining both of what they are.

IT wages are no longer considered exceptional. That's a study from Harvard business school. Guardrails in cloud-native applications are needed. That's a great call. I love that.

Corporations using this STEM shortage myth to abuse the H1B programs. H1B visa programs that President Trump has been trying to clamp down on.

What do you call these little devices that we have these a USB drives, thumb drives? what do you call them personally? Probably about 10 years ago, I grabbed the domain. I registered thumbdrive.com and I never did anything with it. I was thinking, Oh man. I could have a whole bunch of different thumb drives up there. I ended up letting it go when I was really low on cash one time. I just went to it today. Thumb drive.com and it's somebody selling Toshiba thumb drive type stuff. It's still the disappointments in life that you tend to remember much more than the successes. So it's a bit of a shame. But thumb drives have become way more useful in this day and age. We're going from work to home. Our kids are taking their work for school. They've got to bring it to the teacher. Many of the times, of course now it's electronic, right? We upload it. We don't even use FTP anymore, but we upload it. We download it and we might email it. We use Box or Dropbox or Google drive in order to share files. That's really the most common way to do it nowadays.

But thumb drives are still out there. They're still in wide use and I still have a supply of them and somehow they all seem to keep disappearing and that's where the problems start, really?

If you own at least one thumb drive, you've transferred a file. You might've used it as a method of backing up some of your documents or your photos or other things you might like to carry your work with you. So you can dive into it at a moment's notice and you keep it in your pocket. I have one that is waterproof. It's a light fireproof, and it sitting there on my key chain. So that I have it if I ever need it in order to do something and you know what, I've used it a few times, but not so much. I've even got thumb drives in my wallet. Just really thin ones in case ever need them. I have used them from time to time.

If you're like most people. You might be using thumb drives that aren't necessarily trustworthy. So let's talk about that for a minute. Students tend to use flash drives to print out study materials at a Kinko's store, or maybe they go to a library to grab something. Maybe you are using it to move documents back and forth to your work, to your family events, soccer church, or whatever it might be.

Now, when we're talking about kids, they also tend to lend their classmates these drives, and they might have their notes from their class on them. They might've made their notes on a Google Chromebook, and now somebody plugged it into a windows laptop or Mac. Think about spreading diseases, right? It's the same sort of thing as they're passing them around and sharing them.

It's not just kids in school, in college. It's also friends at the office. It's friends that you have at home and you really can't be sure of these things and how protected they're going to be. If any of those thumb drives have been infested with malware, it's really very possible that your computer, if you've used one of these infected thumb drives, that your computer is now infected as well.

Some devices like your Macs, for instance, you've got a Mac laptop are immune to all windows viruses that are windows based. So it can spread them. It's like a little super spreader. So that if there is a virus for windows, that's on your Mac in a file, your Mac, will be just fine. It doesn't care. But when you now transfer it to somebody else, or you put it onto a drive you're in big trouble. here are some options that you can take.

Microsoft has made a big change a couple of releases ago, major releases in the windows operating system. There used to be an autorun file that was there, on, for instance, a CD drive or a thumb drive. So when Windows opened it up and said, okay, I'm going to run this file. And that file would do something like cool, play a movie for you. Or it might run a video game or whatever it's supposed to be doing on there, but the bad guys started taking advantage of that pretty early on. They started using this crass cross-contamination route using these autorun files as a way to send all of their malware to other people. Okay, so you have to be careful.

We're going to get into some solutions here in just a minute. What really do you have on your thumb drives? I want everybody to think about it for a minute. What are you using them for? How can they be misused? What happens if they're lost? I mentioned that this week on the radio, what happens if you lose the thumb drive and it has some intellectual property on it? has personal information on it?

I know a couple of listeners who are using external drives, which are more common now than they used to be. They plug into the USB port. It's the same sort of problem. You can't put these into your pocket like you can a thumb drive, but you can certainly share them. You can move them around and they're using these USB drives now spinning media, or sometimes even SSD, they're using them to move stuff back and forth.

So how do you deal with it? One of the ways is what we tend to do for our customers that need high security. We remove the mechanisms for people to be able to use them in the first place. We'll disconnect it from the motherboard if that's possible and we'll fill the port with epoxy. So people can't just put it in there. Now most of the time, they're not being malicious. They just want to plug it in and grab this file.

But there are people who are malicious who are trying to steal data. Which is why, again, in high security, We remove those USB ports. So that the thumb drives just can't be put in there. Companies like IBM have opted to completely ban removable storage devices, period. It's a real big deal. They were talking about all of this at WeLiveSecurity.com Amer Owaida is his name who was talking about some of this stuff. But when he looked around, he found that IBM was banning it, many other major companies were.

Let's start with what can be done. First of all. When we're transferring sensitive information from one place to another. So for instance, we might be tightening up security in a doctor's office or helping a doctor's office upgrade their systems, and we need to send all of their patient data.

To the third party who now has this new system that they're going to be starting to use in the doctor's office and we want it to be secure. So we have a disk drive cabinet that is encrypted the whole thing is, it's just a little thing. It's not much bigger than a disc drive and it has a drive inside of it. You have to enter the key when it powers on, and then it uses that key for the encryption on the disk So even if somebody breaks into the case, it doesn't matter because the disk that's inside is encrypted using this key. So you could consider doing that. There are thumb drives that have built into them. Thumb print readers. Most of them that I've seen are pretty easily defeated, but let me tell you that's harder to do than, having to defeat one of these things than just plugging in a drive that's not encrypted okay.

So step number one. You need to have, if you can use them, drives that you can trust for confidential information. That means they need to look different. They need to be different than the drives that you are using for home for your personal data, for your personal backups. So first of all, they need to look different. So maybe just having that thumbprint reader on the drive is enough to remind you. Sensitive data should be on that drive with a thumb print reader.

The next thing you probably want to do is encrypt all of the sensitive data that you want to load onto the drive. Now there's a number of ways to do it. You've got built right into windows, full disk encryption. Same thing's true for your Mac. So you could encrypt it that way. You can also use something that's free. I think it's pretty easy called PGP, which uses public keys. You encrypt the files before you put them on the disks.

I do like the hardware security solutions for the thumb drive that uses a pin code. That's probably best, as I said, I don't really trust the biometric scanners, but there's some really great articles out there about these thumb drives, and what could possibly go wrong.

Now there are thumb drives that are designed to burn up your computer, literally melt it down. Don't pick them up. Oh yeah, we've used that trick against Iranians before.

Our smartphones have our lives on them. There are some very quick ways to make sure all of your data on them are destroyed, because we're upgrading these things left right and center. It isn't just about e-waste as they call it. It's about your personal information.

Let's start getting into our security here on your phones. People are getting rid of their phones on really record rates. In fact, in market for new customers, their smartphones has dropped dramatically. We've reached saturation in most markets, worldwide, where people who want a smartphone have a smart phone, people who want an iPhone or maybe an Android, heaven forbid, have got those devices and they're pretty happy with them.

Now, the Android is going to be cheaper initially. If you ask me, it's way cheaper in the longer run to have an iPhone. What do we do with these things? We're talking about 50 million metric tons of e-waste every year and a large part of that is our smartphone devices.

Most of it isn't recycled. However. Your smart phone can be. So instead of tossing it into the trash, I think you need to look at a few different options. You can recycle it. You can donate it. You can sell it. There are a number of different places that you can go in order to get rid of these things and really make back a few bucks in the long run here.

Best Buy, Whole Foods, Home Depot, Lowe's and Staples typically have free drop off spots to take dead batteries. So that's step one. If you have a removable battery. You can remove it and drop it off on one of those. You can also check out a website that's called earth nine one one, and it's simple or nine one one.com and it will tell you where you can recycle these things because they've got all kinds of nastiness in them. The button cells, the older ones had mercury. You've got lithium, you've got zinc in these things. So that's always a good place to go to start recycling them.

There's also cell phones for soldiers where you can donate. That's their website, cell phones for soldiers dot com they will take your cell phones and they'll provide them to soldiers overseas. This is really cool too. Cell phones for soldiers also provides about 2,500 calling cards every week as well for the soldiers to use. Man, I'm choking up a little bit here.

In case you didn't know it, by the way, we're planning on building a 4g cell phone network on the moon and a 5g cell phone network on Mars, like real soon now with the next couple of years. So maybe you can donate them to NASA for them to take while they go up there. Now, there are a few places that you can go to. Recycle specifically, and I've used Gazelle before.

Let me just check. Make sure they are online still. Yeah, there they are. Gazelle, G a Z E L e.com. They'll let you buy refurbed pre-owned phones. You can sell them as well. They'll trade them in for cash. So let me just see, I'm poking around on their website as I'm here.

I'll tell you how to clean up your phone securely here a little bit, but let's say like me, I've got an iPhone eight plus, right? That's my phone. It's probably about time to upgrade it. I'm going to say it's factory unlocked and it's saying, I think mine's a two 56. So I'm going to say two 56 because I want money. Does the device power on? Yes. If I slowly functional all parts work. Yes. Front and back. Free of cracks. Yes. Cosmetic looks like new, which is true. So for excellent condition worth 181 bucks, light signs of use it's worth 173, normal signs 160 bucks. Then you can send it in. I've even seen gazelle having kiosks, where you can go ahead and just put your phone in. They have cameras in them and somebody remotely will look at the phone that you just stuck into it and will give you an offer. So there's buy-back services, flip C and all kinds of others.

So before you get rid of it, make sure you have a good hard look. Declutter gadget gone. That's a cool name, right? Oh, Apple, by the way, they've got store credits. I got $300. Last time I turned in my iPhone at the store. right now my iPhone eight is worth 170 bucks at the Apple store. So it's worth about the same as it is worth over on gazelle. Best buy let's you trade it in. Some will take them to Craigslist, Facebook marketplace, E-bay and others. So there you go. There are some things to do with that phone. Eco ATM, by the way, that's the name of the ATM that's owned by Gazelle trade. Amazon has a trade- in store, but just look, if you do a search for gazelle, you're going to see ads for others as well.

Before you do that, let's talk about your privacy here. Before you just throw it away into one of these recycled bins. So this is some suggestions from Tech Republic and I'm of course, going to add my own little tips into this as well. Veronica Combs wrote this original article. she says that you should unpair all devices. I don't think that matters really. I don't think you have to unpair anything because of what gonna do next is sign out of all services.

Now that can be important. If you have an iPhone, what all you really need to do on your iPhone is go to the settings. Once you're there in settings, you're going to go to general and then reset and then select a erase all content. Before you do that, you're going to have to turn off, Find my iPhone because if find my iPhone is turned on not only does it let you find your iPhone, if it's lost or stolen. but What find model iPhone it is Also it makes the phone, so it cannot be erased and then used by a third party. You have to be able to log into the phone using your Apple ID if it has been reset. So turn that off first. Find my iPhone. Then go to settings general, reset, erase all contents. Now it's not really erasing the content on the iPhone and also un-encrypted Android devices. What it does is it destroys the decryption key. That only takes a second or two. Once that's destroyed that phone is now completely reset. It's like a factory reset. There is nothing left on the machine. So on Android phones turn off the factory reset protection.

This started a couple of releases to go with Android. You can go to settings, privacy, factory data, reset, and then choose reset phone. once you've done that with your phone, either one of them. You are safe to send it off to a recycler.

Now, if you're like the campaign staff for Hillary Clinton or her phones themselves, they just took ball-peen hammers to them. Once the investigation had started and it was illegal to destroy evidence. So remember that, if you use a ball-peen hammer, apparently it's legal to destroy it that way. By the way, it'll make it pretty much unrecoverable if you really bash the living daylights out of How could our elections be attacked? Well, they already are according to a report right now in Louisiana. It may not have been directed at our election infrastructure, but it sure is affecting it. Here we go.

We have some serious problems being reported down in Louisiana. According to threat post the Louisiana National Guard, has been called out. Now that's a very big deal. You might ask yourself, why would they call out the National Guard to battle a cyber security problem?

That would be a good question, if you were to ask, so let's ask it. The answer to that would be. That the national guard, as well as our military, have been trained. Not all of them, obviously. They have teams that have been trained to do cybersecurity work, and we've done some. I've done some training on that for the FBI InfraGard program, so I have some intimate awareness of how this stuff works. Here's the bottom line, according to the article that was in Reuters. They're saying that there's evidence suggesting a sophisticated hacking group was involved.

So what happened now? This is something that happens to businesses. It happens to government agencies. It happens to almost everybody out there. They were attacked. Most of the time these attacks are coming, the more successful ones, in the form of phishing and phishing campaigns.

I've got some training that if your company really wants to do some, phishing training, let me know. I have some excellent training materials and we buy licenses for these from our third party. It just isn't worth it for me to do custom training for all of my companies and we buy these things in blocks and I have extra licenses. We buy them a thousand at a time. So if you'd like to offer some security training for your employees, that's primarily focused in on the whole concept of fishing and what they should be doing, what they shouldn't be doing. Social engineering even goes so far as to inbound phone calls. Let me know, just drop me a line. me@craigpeterson.com and I'll be glad to get back to you. We can make some arrangements to help you out there.

Cause I know a lot of companies just don't know where to go and you can't afford these expensive trainings. We have some extra licenses, so we can definitely help you with some of that stuff. So just email me@craigpeterson.com. If you'd like to get a little bit of that training and I can probably do it too for a home users, if you're interested, let me know. I'll see if I can't just drop you into one of these classes with one of my business clients, that, again, it's a nice little series of training. I think they do a really good job. I should be able to squeeze some people in here and there. So let me know.

That's how most of the time bad guys are getting into our networks. They send an email, it looks like it's legitimate. It looks like not only is it legitimate, but it's something you need to open and you need to open it right now. These guys have gotten really good at that sort of a thing. Then you click on it and they have your information or they have you running a program for them.

Now, many times these programs are called RATS, which is a remote access Trojan. If they can get a RAT onto your network, it's over for you if you don't know it's there. That's why we always suggest and there's a few companies that have these, I like Cisco, but there are some other good ones out there that we work with, that have the ability to detect these Trojans. They're watching them calling home. Where are they going?

A remote access Trojan on your network means they can remotely get onto your network right through your firewall. Right through it and then start doing whatever they want to on their network, anytime they want. That's part of the reason I really strongly urge everyone to use umbrella and you can find it, just umbrella.com. We sell the professional version of this for enterprises, but they have free versions as well. That are simple as just changing your DNS server IP addresses. They've got them right there on the homepage. Two, two Oh (860) 722-2222. It explains it all. If you just go to umbrella.com.

The idea is you use the Cisco umbrella software for your DNS server and if there is a Remote Access Trojan, when it tries to call home to give the bad guys access to your network, it is foiled in its attempt.

It doesn't block it per se, but it's like hopping in an UBER and saying take me to one, two, three main street and the Uber driver says, I don't know where that is. That's kind of the equivalent here, you ain't getting to one, two, three main street if the car or the driver doesn't know where that is or how to get you there. That's what umbrella does for you. There's free versions of it.

If you're a business you should use one of the higher level ones. What we sell the enterprise version is tastic for businesses because it allows it all to be customized as well. Umbrella has family stuff too, that you can use and the family stuff is great too. You can keep the kids from stumbling on websites that they probably shouldn't be stumbling on bottom line.

This paper that was released, showed that they had done a forensic investigation. I'm looking at this Reuters story, that goes into it and they found something called the Kim Jong rat. Which is a back door. It is a remote access Trojan and it had a source code leaked.

I haven't checked lately on the dark web, but it used to be a little buy tools like this for 20 bucks. They're not expensive.

So problem number one, the bad guys got into Louisiana's government networks. Problem. Number two, they installed a remote access Trojan in the network. Very common. Usually within a week to two weeks after that been installed, they will have examined your network and they are going to be digging in even deeper.

What did they do here? Wow. They installed the Trojan. Now I've talked about this before. We've seen attacks involving EmoTet, it was found also in the networks of these government victims, according to Reuters. The EmoTet Trojan can also load other malware and it's like a worm. It propagates all by itself through the networks, onto the file servers and onto the desktops and laptops.

It also, by the way, is just as happy to spread through a VPN connection. Do you know what I think about VPNs? They have their place. I use them, but as a rule, VPN's not a good idea. For most very small businesses, not at all. Okay. So this is a problem.

We now have the national guard in Louisiana called in according to Reuters to protect the systems, when we're in the middle of election season. Isn't that fun?

Before we get to that, I want to talk about this email. That concludes that Iran was behind sending these very threatening emails out to Democrats. How could that have happened? What should you be looking for? We got answers.

There have been some emails that are very scary out there. There were supposedly from this pro-Trump group called the Proud Boys and they have a very scary message. The messages say that they are in possession of all your information. By the way, that if you really want it and you're willing to pay a few bucks on the dark web you can probably get anybody's information on almost anything, okay.

But in there in possession of all your information and they've instructed voters to change their party registration and cast their ballots for Trump and I quote here from the emails, and this is an article from the Washington post. Yes. It says you will vote for Trump on election day, or we will come after you. So pretty, scary stuff.

Some of these were in a hotly contested swing States in the upcoming presidential election. It's going to be one heck of a season here. Let me tell you. But the U S official said privately that through the post that the operation was not terribly sophisticated and they said it was disclosed before it could have any major impact.

The cybersecurity researchers that they spoke with said little about the operation. They're thinking there wasn't a large scale deception. We'll see what happens. It was first divulged Tuesday by local law enforcement and election officials in Florida and Alaska, and people rightly reported them. For FBI reporting, it is IC three.gov online. If you get an email like this, or you get another threatening email or something that you think the FBI might. Want to know about because they do investigate these things.

I am involved in a couple of their investigations, that revolve around China and Chinese espionage. Anything like this, you can report, just go to IC three.gov. I C three as in internet crime complaint center. I C three.gov. Okay.

This is a real problem. In 2016, it took months for the Obama administration to publicly point the finger Moscow for the hacks and leaks of democratic e-mails despite the intelligence community, having determined Russian culpability early on. So there you go. The Russia story continues at the Washington post, but this came up from a disclosure by the Director of National Intelligence, the DNI, John Ratcliffe.

I like the fact that president Trump has, I'm not going to say strong armed, but he certainly has convinced our intelligence agencies to be more open with the public. Be more open with business, this FBI InfraGard thing that I'm involved with and did a lot of training, meaning over the years for, it's been around for a very long time. Let me see. 1996 it's been around. So it's a partnership for protection. It's a nonprofit, they have a lot of volunteers like myself that are involved with it. So the cooperation between the fed and business is nothing new. 96 was a long time ago. That would have been what President Clinton, that did that, but it actually started in Ohio and one of the field offices, as I recall.

President Trump here has taken this to the next level and we have had disclosures from the NSA. Remember NSA, we used to joke is true for no such agency because it was just so secretive. The NSA has even released information about vulnerabilities in our systems. So it's a huge deal.

On Thursday, by the way, Iran, some in the Swiss Envoy in Tehran, and Switzerland is who handles affairs for the US there, because the U S doesn't have an embassy or anything really there in Iran. Other than probably the CIA. They were condemning the baseless accusations of meddling in the U S election. They said the Iran has no interest into freeing interfering in the US election. It's the old habit and there's a new name for it, but the old habit of keeping information from people. You might remember in World War Two, right? If you tell a big lie often enough and you tell it with absolute rigor, people will believe you nowadays, they call it gaslighting and it's been very effective. So that's the Iran is trying to do. So be careful with those emails.

So that kind of leads us into this whole thing on spear phishing.

If you miss it today, I'm going to have that up on my website, along with IT job wages and pretty much everything else. I try and get it all up on Craig Peterson.com. I send out my weekly newsletter and we've also sent out some that people are really interested in. If you didn't get it this last week, you might just drop me a note.

We don't automatically send it to people who sign up new. So if you are going to go to Craig peterson.com/subscribe right now, you'd only get future newsletters. You wouldn't get the past ones. This past weekend I put together a really great newsletter. And it talked about taking your computer in for repairs.

I used this fictitious character called Hunter. Who took his Mac book into a computer store to have it repaired for water damage. I came up with all of the main things you should do step-by-step before you take a computer in for water damage. I think if our fictitious character Hunter had done all of this, he wouldn't be in all of this big trouble with this daddy, but I can send that to you, if you're interested. We talked about it a little earlier this week as well, but just email me at Craig Peterson dot com. And let me know you want the Hunter email. I'll be glad to send that to you.

Also, if you sign up, I am going to be sending you some of my most popular special report. The stuff you need to know, because everybody needs to understand how to do a security reboot.

I've got some very in-depth courses, but let's just start you with a simple checklist. I don't want to confuse anybody. So it's easy enough for me to just reply to you when you sign up and send you this stuff I have at this point about 60 different six zero different special reports.

So when you ask a question, oftentimes I can just send you a special report on it. Oftentimes if I don't have a special report, I will write one. because if you're interested, other people are entrusted too.

So make sure you sign up and you can just do that by going to Craig Peterson.com/subscribe. I'd be glad to do that for you.

We also have a couple of things, that I really want to cover quickly here when it comes to the election and election technology. I think as a whole, our election is pretty safe from a technology standpoint, right? I'm not saying anything about people printing their own ballots and sending them the in. About gathering ballots about bribing people to vote a certain way. That's not what I'm talking about. Obviously, all of that's easy enough to manipulate. We've seen post carriers who are dropping ballots into gullies and ditches and trash cans. That's one thing.

On the other side, there's the technology. I am pretty confident that in most of our States here where we are using these paper ballots and they're more like a light cardboard, right? What a hundred pound stock give or take 80 pound where we fill in that oval. Then we take it up to the machine. We put it into the machine, which reads it, optically and tallies. It I'm pretty confident those machines are in good shape.

One of my sons, who works with me and he's a Cisco fire jumper certified guy. He is also one of these election overseers. He had a look at machines that were shipped off from the Secretary of State's office, and even though some of the seals were broken, The seals that really counted, which are the seals over that little memory card inside that optical reader. Those seals were all intact. So that does my heart. Good. I'm also pretty confident that the people who are working the local polls and tabulating are being supervised and there tend to be Republicans and Democrats and independently minded people who are overseeing the process. So those tallied numbers that are then sent off to the Secretary of State's office, I think are likely to be correct.

Then the Secretary of State's office, puts them up on their website and then the Feds are going to look at them. That's where I'm the most worried about it. Emails sent to the Feds with tallies. The feds visiting a hacked website.

We just went through the major ransomware and remote access Trojan problem that they're having down in Louisiana. That is a very big problem because that could be a weak point that would be exploited by people who wanted to change our votes.

If you are involved in oversight in this stuff, make sure everything is double checked with the human. Get on the phone, call somebody, call the Secretary of State's office to verify. If you're working at a local polling place, verify that the Secretary of State's office has the right numbers. Then make sure the right numbers are on the Secretary of State sites website.

The rest of this is going to be an absolute disaster. What can I say.

Craig Peterson (2): [00:38:49] You've probably heard about spear phishing. I did a little phishing myself online and looked at some of these companies, like Barracuda that are saying that they stopped spear phishing attacks using AI. Hey, I've never been a fan of Barracuda.

Now spear phishing is by definition and this is from CSO online.com, is the act of sending an email to specific and well-researched targets while purporting it to be a trusted sender.

Now you've seen phishing. If you've been on the internet for the last 10 or 20 years, you've probably seen what's called the Nigerian Prince scam. That's an idea that has really perpetrated into every bad guy's mind over the years. The idea is, Hey, if we can send an email out to people and find the gullible people, maybe we can make some money.

It's fishing just like you might be out in a boat and you're casting a net to catch a certain type of fish. You hope that the gill size is right on that net and you're always catch some other things, right? Dolphin, tuna, and some of these other things, but, you don't really care.

What we're talking about here with regular phishing, which is spelled P H I S H I N G. We are talking about bad guys casting a huge net. This net is out there to try and catch anybody, anything there will go ahead and get caught in that net.

So the Nigerian Prince scam is, Hey, I am a Prince in Nigeria and I need to move my family's $1 million worth of wealth and the only way I can do that and get it out of US banks is if I have a US bank account. So if I could go ahead and I'll transfer in this $10,000 that I need to move. I'll let you keep 2000. So I'm going to transfer 10,000 into your account, and then you're going to wire me $8,000 of that money and you can keep the $2,000.

Now, there are many forms of this scam. The Nigerian Prince scam is one of them. Of course what's happened here is they say they wired the money in, and that money may show as pending in your account coming from an overseas account. So you look at, and you say, Oh yeah the $10,000 is there. The Nigerian Prince contacts you and says, Hey, I sent you that $10,000. I really need that 8,000 now, or I'm not going to be able to get my mother out of jail or something along those lines, kidney for my best friend on and on. People look at the account, look at that, there's that $10,000. Now they go to the bank and they wire the $8,000 to this account overseas and off goes your $8,000. When you wire that money out, it is gone.

What happens is a few days later, it can take a anywhere up to basically two weeks for the bank to clear the money. I know about the check 22 laws, that's all down the tubes. It's eight days to two weeks usually, especially for international transactions and they can take three weeks or longer sometimes. That transaction where he wired the money in is canceled on his side because he's got an inside thing going on with the bank. So you thought you had 10,000 that he had put into your account. You wired out 8,000. Net 2000, that's not so bad.

But then a week or two, or maybe even three weeks later, your bank contacts you for insufficient funds because that $10,000 transfer that he was putting into your account, actually never finalized and never really happened. So you have now sent him $8,000 of your own money. So that was the Nigerian phishing scam.

There are a lot of scams that are based on that are still out there today.

One of the big ones that the FBI just a few months ago arrested a dozen or so people out in California for is a mule scam.

I don't know if you saw this latest Clint Eastwood movie. I thought it was pretty good. I've liked Clint Eastwood for very long time, but he has a movie out called The Mule, came out in 2018. This is a 90 year old, horticulturalist and Korean war veteran that turned into a drug mule for Mexican cartel. A very interesting movie, rather believable, a lot of movies that just totally rip apart. but I enjoyed this enough to allow it to be believable. He was hauling money for the Mexican cartel.

What these people in California were doing is they were money laundering and that's typically called a mule, they're moving money around.

They would get some money from somebody. It much like this scam. I was just talking about with the Nigerian Prince scam. So they say, Hey, we're going to wire some money into your PayPal account, for instance, or we're going to route wired into your bank account. And then we want you to use PayPal to send us the 90% of the money.

In this case, these mules, we're not getting ripped off. They would actually get the $10,000 in to the bank account and then they would send $9,000 via PayPal and the bad guys were happy cause that money is laundered, it came from a more legitimate looking source.

I had some really great trainings that I did on this for the FBI InfraGard program with some think it was a secret service guy, and they tracked a lot of this down. There were some arrests here a couple months back.

We have to be very careful about this and how we're transferring money around and whether or not we do it for one of these people. Because we're getting tricked.

What's happening is these people who are doing the spear phishing are doing research on us.

We had a great example of another spear phishing thing. There was a company in the UK that was purchased by a German company. They knew all of the basics about this German company and they got a phone call one day from the CEO of the German company. The CEO told them to wire some funds to this particular bank account, and they did. It sounded like the CEO. They used some technology to impersonate, the guy's voice. They went ahead and wired the money.

Then we got Barbara Cochran who is one of the sharks on shark tank. Her assistant went ahead and wired, I think it was like $400,000. Another assistant of hers, her executive assistant, caught it, noticed it, because she was CC'd on the response, freaked out. They managed to stop the transfer from happening. So good news on that one.

These scams are out there and they're out there big time.

I have another one where a lady was going on line and doing research about business owners. She found a couple of business owners, actually quite a few. She wanted to narrow it down. So she researched them. She found some of these business owners had Facebook pages. She went to the Facebook pages and while on those pages, she found those business owners that said that they were going on vacation. She followed them a little bit and found out about where they were going when they were going. Then she managed to trick the email providers. Into letting them into the actual email account, which she did in this one case, where she got more than $40 million out of the company.

She finds out who the CFO is and then when the owner is on an airplane or is in Bermuda in cannot be contacted. She then sent off an email to the CFO saying, Hey, we've got this new provider, a supplier we've had for three months and we've never paid any of their invoices. Here's the invoice on the bottom of the invoice or statement the bottom of the statement it says, or to wire the money to, I need you to wire right now, or we're going to be out of business next month because we've never paid this new supplier that, and it's critical. The CFO wired the money because she had done her research and that's what it takes.

They want to send you an email that is really coded up for you.

That fake email that you got represents a huge industry and that industry is undergoing some amazing changes. They are using artificial intelligence for evil. So we're going to tell you about it right now.

Now, these types of phishing, where they are going after a specific person, after doing a bunch of research are called spear phishing attacks.

It's not like those from the mid nineties where you had the Nigerian Prince out there sending emails and just waiting for anybody to respond to them. These are aimed at someone individual.

Here's an example that was in Dark Reading this week, where it says:

Hey, I'll see you at nine for our four hour call. You're going to kill it today. See the dial in details for the call attached. Cheers, Al.

Now most people would not question the legitimacy of this email. It's kinda laid back. They might've done some research on Al. They might have cracked Al's machine. Somehow gotten a list of all of his contacts and sent this to everybody in his contact list that worked at the same company.

This is happening all of the time, everybody. So be careful of this.

So you get it. Looks legit. Everything about it smells legit. You're going to open it up because heck I'm going to kill it today in our nice little conference call, right? Yeah. That's what you're going to do.

But what could well be happening here is that email attachment that they said, Hey, you need to click on this, could well have a malicious payload. So you have to be careful and it may not have a malicious payroll payload on it. Maybe it went through the email filters looked pretty good, but maybe the website it's pointing to, or even the file on the website it's pointing to is malicious is a malicious pay load.

So you've got to be very careful and you could lose your job in total embarrassment. You could really the harm the company by opening this. But it's getting worse.

It's going to get even worse right now. There is something called offensive artificial intelligence. This is ushering in a whole new era of phishing attacks that are going away from these more simple ones, the broad phishing attacks, even the spear phishing attacks, where they do some research about your company.

I've picked up a few clients, unfortunately, that have had these attacks worked successfully. And then we had to put in some really great software to make it even work better for them.

Artificial intelligence can go out and start looking around, can figure out what's going on. For instance, blue.ai, found a cluster of pneumonia cases around a market in Wuhan, China, it flagged it and found it nine days before the World Health Organization found it. It's now being used to look at all of this health literature from around the world about COVID 19, the Corona virus, that we have this novel one and figure out what's going on and it's even comparing it to DNA. AI can be absolutely wonderful.

We use it for monitoring and protecting various types of networks, but inevitably AI now has opened the door for sophisticated cyber attacks.

It is really crazy what's going on right now. Cause it's not just these phishing attacks, it's going to agument every type of cyber attack. It's using adaptive decision-making capabilities based on what it finds inside your network.

This is scary as heck because once it gets inside your network, think of Skynet, right? That's really what it's going to ultimately be like, maybe not with Androids out there trying to shoot us, but trying to steal everything we have.

Our email boxes are just going to be used as a stepping stone to get into the business network.

The only way to really compete with this is to fight AI with AI. That's what's happening with some bigger companies out there.

I did a little searching of my own online and I got a little upset because I came across an article.

At the top an ad for Barracuda. Now, I've known these guys for a long time. They have used open source, freely available firewall software and other software to build their business and, good for them. There's nothing wrong with it. That's our open source software is for.

But there seem to be some misrepresentation that are out there. That's where it gets scary.

Right there on their website, Barracuda Sentinel, get AI based protection from phishing and account takeover. You read down a little bit further block threats already in your email, in your inbox. Stay a step ahead of attackers with AI based threat detection. Stop wasting time managing static security rules. I agree with that one. I think the problem that we have is we're putting a lot of trust in these companies.

This is Barracuda. I have had clients who've used it before, and I've had nightmares trying to fix problems with it, but that's me. I could tell you about them if you wanted.

On the other side, there are other systems, like from Aruba, Cisco, which is what I use and sell, these are not a panacea. There are all kinds of things that you have to look at and you have to be tying them together.

We're no longer just dealing with the perimeter. It's no longer just having a good firewall or trying to have a good email filter. Now we really are talking about this Zero Trust model because AI is being used by the bad guys. It is getting into our systems. We have to make sure that none of the data, what we call in the biz, east-west or west-east traffic, east-west traffic, none of that internal data, internal communications is going somewhere it shouldn't, or is being used incorrectly.

Spear phishing is difficult to detect. It is very difficult for AI detect it. It is much easier for person to detect it. You need to do training on this. Have your people get some training. I think it's just that important.

This whole business email compromise thing that the FBI has been talking about. That's all tied into spear phishing. So we gotta be very careful.

Harvard business school has a really interesting article out right now about wages in IT of course, information technology. We used to call it MIS management information systems, way back when.

Hey, it's bringing back memories of when I was a professor out at Pepperdine university. MIS 422? That class anyways.

Harvard has been of course helping people in all kinds of aspects of business, which includes things like the law, IT and General business, as well. But they've come out with something that has really surprised a whole bunch of people and it has to do with IT job wages.

I have talked about getting jobs in cybersecurity and how many open jobs there are. I think the biggest problem people have is getting into cybersecurity and then getting the support they need, once they're in cyber security. Over just the last few weeks, I've had a couple of listeners who have sent me an email and I asked a little bit about it and I pointed them in a couple of different directions and even pulled another listener into one of the conversations who has moved into IT security. Exceptional wages were the norm in computers for a very long time. You got paid good money, if you were good in it whether it's in management or in coding.

I made good money for a lot of years as a kernel programmer. Writing the operating system itself and device drivers and implementing internet protocols and designing new protocols. I made one of the world's very first centralized security systems for computers and computer networks. Way back when. So it has been around a while and it has paid very well. Their jobs have always been stable, the fast rising within the organization and made a lot of money. Back in the nineties, you had the dotcom boom.

It really bothered me, all of these people that started hanging up shingles saying, I'm an IT person. I design websites. I do these and they've never really had any real experience with IT.

To this day still bemoan.Microsoft products. Because it seems like it's a chimpanzees throwing darts at boards, as far as trying to make sure their systems work and inter-operate and don't even conflict with each other. It's so frustrating. Since I've been in the Unix side for so long and the mainframe side as well, the systems that work well and work consistently.

It turns out the things have changed a bit now when it comes to the wages that are being paid in information technology. In all, but the largest cities, according to Harvard wage growth in IT jobs has become relatively moderate following the dotcom boom.

They're saying that these wages in IT are a lot more like wage patterns that have been seen in the broader STEM space. STEM being science, technology, engineering, and mathematics. So some of those like mathematics are well known for really having terrible wages, right? You got a PhD in math and wow, you can get a $60,000 a year job. So IT has changed. IT really has leveled out.

In some geographical regions where there's fierce competition for IT talent, superstar performers do not earn the same high premium they once did over average performing programmers and other IT professionals. So in short, IT wages are still relatively high compared to most other occupations, but they have lost what Harvard says is their exceptional luster.

The IT wage premiums today, have more to do with where you are working then with rewarding, specific skills that you have for the job. So keep that in mind.

This paper, if you want to look it up, it's called the digital labor market in equality and decline of IT exceptionalism. It was written in Harvard business school post-doctoral researcher was involved with this at the Martin Marshall professor of business administration. So there's a whole lot to chart the rise and fall of the salaries. They examined 142 of the largest urban areas in the us between 2000 and 2018, and of course we've had crazy change over those 18 years in IT. We've seen the major rise of the internet and apps, which didn't really exist until the last 10 years, these mobile phone smartphone apps. We've also had two pretty darn big recessions over that period of time. In smaller cities and rural areas, which is what we're talking about here for most of my listening area were excluded because of missing data for at least one year. They use the data from the Bureau of labor statistics. They parsed both the broad difference in wages against other lower paying jobs, STEM professionals. Salaries they found in five places, Silicon Valley, San Francisco, Seattle. Washington DC and New York climbed as there was more competition for talent. I will interject there that I think that places like New York city are going to see a continued Exodus of IT professionals since there's so many people working from home. That is going to have an absolutely major impact on all of us IT workers in the rest of the country just didn't get the same bump.

Let's see. So they're saying there's two distinct and competing forces on the one hand, the advantage of tech hubs and urban metropolises, especially the combination of dense population and vigorous innovation increasingly leads to higher it wages making some regions more attractive to skilled talent.

On the other hand, this is not Ronald Reagan's, ideally economist, right? On the other hand, wage spread narrowed within advantaged areas, moving the top, 10% of IT wages into convergence with other STEM occupation. So they're saying, yeah. The highest paying IT job category that they examined, which was a research scientist paid between 140 and 170,000 per year in the Bay area. So that's almost a minimum wage out there considering how much it costs for a house, et cetera. 45% more than a typical region such as Indianapolis in contrast, in those with biochemists, they earn about the same wage in the Bay area as they do in Indianapolis on average. Isn't that scary? So it goes on and on. Superstars are not super paid anymore.

There's major implications for organizations. If you're looking at IT wages. You need to use the same sort of reasoning you would have used for other skilled labor markets. There are HR people who are used to this. When you get into the rare parts of STEM, how rare are they really? How many openings are there?

This is an interesting time and it's changing more and more at because of people working from home and the lock downs and you saw France just locked down. I think it was Switzerland just locked down. Belgium apparently is about to lock down. We've even got Vermont locking down saying, don't go into these two counties in New Hampshire, which is right across the river because of higher COVID rates. Now I'm not going to get into all of it cOVID rates versus death, right? What morbidities and other things, but it's really tough.

People are moving out of the big cities, including IT professionals that are moving way out. We've had a lot of people moving into New Hampshire and other areas that are more rural. So I suspect IT jobs as well as other STEM jobs just are going to continue to go down.

We just talked about AI in the last segment and its effect. I think AI is going to have a huge effect on the whole IT industry, but it's going to take a few years before it really hits.

We were just talking about wages. We're going to talk right now about another reason those wages have gone down something I've seen personally that has caused harm to my business and that President Trump has been trying to crack down on. We're going to talk about cloud native apps too.

Hi everybody. Craig Peterson here.

Let's get into this guest worker program problem that we have. It's very upsetting to me because I have lost business. I have lost contracts because of this program. What's been going on, and I took advantage of this program back in the nineties. I had a company with about 40- 50 employees. They were all IT people and I needed somebody with a very specific skillset.

I needed a couple of people and so I hired an attorney and what they did is they worked to show the federal government that we had indeed tried to get people to work for us with these skillsets and we couldn't find anybody.

We needed to bring in a foreign worker and that was under what's called an H1B visa. We brought them into the country and gave them the jobs and the work and off they go. Eventually I ended up having to pay for the airline tickets to send them on back home because we didn't need them anymore after the whole dot com boom thing.

It was a really, quite a mess back then. This whole H1B visa thing has been a real problem. We have some extremely large consulting companies that have been bringing in thousands of foreign workers in the IT space, tens of thousands of them. They then bid against US American companies.

Some of these companies, even though they're supposed to pay prevailing wages, with H1Bs, we're not. What we've ended up with now is a clamp down on this.

We bid on, we had proposals, where there was absolutely no way in heck that we could have matched the price of this other consulting firm using people that were paid about a fifth of what we were paying.

We found this out, of course, after the fact. We'd dug into it, trying to figure out why, we were the obvious choice, why didn't they use us? President Trump has come to the realization that Americans need the jobs in America, first. He has put a bit of pressure onto this whole H1B program.

The Daily Caller has an article out this week called Corporations use the STEM shortage myth to abuse tech worker programs that President Trump's announcement really sent shockwaves through the whole tech sector. He suspended most of these guest worker visas through the end of the year.

The big guys in tech were all condemning this. You've got Google, Amazon, Facebook, Microsoft, all individually condemn the moratorium. It affects these H1B visas, that these big tech firms use to hire the foreign workers that they don't really need. Tim cook who's a head of Apple said he was deeply disappointed. Twitter called it short-sighted. Overall, they may reduce the cost of things that are produced here in the US because they work for much less money. However, The quality isn't there.

I looked into, when I was bringing some people into the country, I looked into their backgrounds and found these people claiming PhDs and they have their certificates. Yet their background was basically a high school education. It was shocking to me. Shocking. Then what I also found is that some of these companies found somebody they were going to hire from overseas that would work for cheap money. As I said, a fifth of what we had to pay US wages and they crafted the advertisement and they crafted the language in the application to the state department, et cetera, specifically for that person.

So they took the resume and they said, we need someone with these exact qualifications three and a half years in this technology two years in that technology, a degree in this and degree and that a five years experience in this so that they could then justify it because you post that ad somewhere and Americans are going to look at it and say, no, I don't have that exact qualification. Then they took those applications and they got the foreign workers that got them to come into the US. They were able to pay them a fraction of what they would normally have to pay a US worker. So that's where I'm coming from. Okay.

I think that's pretty obvious these companies, Google, Amazon, Facebook, Microsoft, as well as these big consulting companies. I mentioned earlier. I didn't give names, but you've probably heard of them. they were all actually worried about their bottom line. That's got to be the sole thing that they were worried about here.

Congress created this H1B program back in 1990 to help companies recruit skilled foreign workers, where there was a shortage of qualified workers in the US. But the companies have circumvented the H1B programs safeguards. They're weak. It's crazy.

They've been bringing in cheaper and less qualified foreign workers, even when there's plenty of qualified workers here now. When we've got an unemployment rate above 10 or so, it's ridiculous to be bringing these people in. We have people in the US that can take these jobs that they just don't want to pay because they want to pay foreign workers.

Now, we had problems before where they were shipping jobs overseas to again unqualified companies. People in the US were forced to train their replacements overseas. You've heard these stories before. I know people that were forced to do this in the tech industry. I's all fake. That's exactly what they're saying right now. Rutgers professor Hal Salzman testified in Congress that this whole idea of a science technology, engineering, mathematics, employee mathematics, employee shortage, this desperate lack of people trained in these fields is a myth.

Rutgers professor Salzman said that they graduate about twice as many STEM students as there are STEM jobs for them each year. He said, in fact, Minneapolis, Federal reserve bank president Neel Kashkari dismiss the whole concept of STEM shorter worker shortage. Noting that skills gap is just a euphemism for, we want skills at lower wages.

So if there's no shortage of graduates and Americans are willing to do the work, why are these big tech companies so obsessed with H1B visas? It really comes down to money. Let's see. There's a lot more detail in this article.

I think Harvard did a great job Harvard business school on this, but man, we've got to be hiring Americans. We've got to.

I'm great with people coming into the country. I'm an import, right? I've been here for many years. I got my US citizenship and I think it's a wonderful thing because we need new blood. We need talented blood. We need bright people. Bringing in these people for just cheap labor or outsourcing our jobs because it's a lot cheaper is going to hurt these companies in a long run. It's hurting the United States in the short run. There's no doubt about it.

We are all looking at cloud apps. We probably use them every day. If you've got an iPhone or an Android phone, you're definitely using the cloud. Many businesses have looked at the cloud as a way to save money. Sometimes save a whole lot of money.

A lot of organizations have decided that the cloud is this panacea that they can use. Because of the pandemic, why not shift the worker's functions to the cloud and get rid of our local computer room, data center closet, wherever it is, you might have your file server, et cetera.

We have a huge security fallout now because of this sprint to set up employees home offices, because it's not just about vulnerable end points in home networks anymore. We've now rushed into adopting cloud-based technologies that have not been secured. It's absolutely nuts. We've got this hybrid physical cloud-based IT infrastructure and it is altering the landscape. Obviously it's already altered in 2020, but 2021 and beyond it is going to be just changed forever. So how do you manage it? How do you put up guardrails?

Look at what's happened with Amazon web services, with their S3 data storage and how many security breaches there have been with S3. These buckets being wide open. Salesforce, Slack Service now, and others have all had hacks. We've got major potential for vulnerabilities because we're tying together systems that were never even designed to be working together in the first place. Certainly weren't designed for security in the first place. So this is just a hint of things that are to come. Okay. It's very easy to mess up cloud security. Now there's a number of startups right now that are out there trying to address this. Jupiter One came out of stealth mode here. They had $19 million in series a funding that tells you how much these investors are thinking they're going to make off of this. This service automatically finds and keeps updated online, physical and virtual devices and assets and organization, including cloud native services. That doesn't seem like it's that hard to do, but man, the misconfiguration of all of the Software as a Service, or Cloud Native is common and it's mainly due to human error.

So if you are using cloud services, I really would suggest that you, if you're a business, you assign someone to look into this or you look into it yourself. You're using Dropbox. You're using Microsoft O three 65. What are they doing to secure their data? A lot of these services don't even guarantee that they'll back it up and just had a huge data loss a because it wasn't being properly backed up,

Hey, if you have any questions, just email me@craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started off this morning talking about Iran and the letters sent to some of US Voters. They were purported to be from the Proud Boys but were from Iran. We also discussed a bit about Election Hacking and then got into, How safe are our USBs? Here we go with Matt.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Typically what's been happening is that the polling places go to the Secretary of State's website, enter in the information. Then the Secretary of State's office now goes through all of that posted on their website. The Feds have been going to the Secretary of State's website and pulling it from there. So there is a risk of hacking.

Good Morning, everybody. Craig Peterson here. Thanks for joining me. I really appreciate it. And if you could, if you haven't already, make sure you do hit that subscribe button, it really helps get the show numbers up and helps other people find this. This morning I was on with Mr. Matthew and we spoke this morning a little bit about the whole technology and election thing that's going on. Man, it's impossible to not know there's an election going on, isn't it? So here we go with Matt.

Matt Gagnon: [00:00:59] Seven 36 WGAN morning news on a Wednesday morning. What do we usually do at this time? Oh, I know we talk to Craig Peterson. He's with us right now. Craig. How are you, sir?

Craig Peterson: [00:01:09] Hey, good morning. I'm doing just fine. Hey, did you hear there's an election going on?

Matt Gagnon: [00:01:15] There's an election going on? That is brand new information.

Craig Peterson: [00:01:19] Bad guys are trying to do stuff.

Matt Gagnon: [00:01:21] I know.

Craig Peterson: [00:01:22] Somehow the two met its like chocolate and peanut butter.

Matt Gagnon: [00:01:26] Oh man. Now I'm hungry. Craig, speaking of. Iran and, threatening emails being sent to Democrats, I would say that would fit into the category you were just talking about here.

Tell me more about this story.

Craig Peterson: [00:01:37] This is a big deal, frankly, and things have gotten so bad, in fact. Louisiana has called out their national guard, but here's what's going on. there are emails that people have been receiving and they say something that's frankly, a little bit disturbing.

It says you will vote for Trump on election day or we will come afterward. Yeah, exactly. And supposedly they're from this group that has the, I don't know, people have been hearing a little bit about lately, but it's supposedly the proud boys that are sending this out. People have been pretty upset by this because there have been some legitimate threats to people.

Is this legitimate? Is it not legitimate? it came out just this last week from the Director of National Intelligence, John Ratcliffe. That in fact of this is election interference and it is coming from Iran. Which is a real big deal. He also said, as well as, some other us officials, that Russia is still the major threat to the election. We know that North Korea has been involved, China's been involved. What it shows is, frankly, you don't have to hack into a computer in order to mess with an election.

Matt Gagnon: [00:02:58] The other thing that bugs me about this, and I'm sorry I'm gonna have to get on my soapbox here a little bit, Craig. I think you know about this, as well, when you're talking about so many of the things that I've heard about election hacking this year. This is one of the things that I've heard an awful lot about which is that Iran has, or Russia has the voter list. They've got our registered voter list and they're going to use it to mess with us. They must've hacked into computers somewhere, some servers to get it. Maybe at the DNC or the RNC. They got the data and the information about voters from it. Dude, I have that information on my computer. Like seriously.

Like you can buy voter lists. The voter list is not something that's an ultra-secure thing that needs to be broken into. It's something that is basically public information. If you'd like to get it, you have to pay for it, but you can get it. So if Russia wanted it or if Iran wanted it and they wanted to have a list of people and where they live and what their voter registration status is, their party membership, all that stuff. What they've done in the last four elections, you can just get it.

It's not hard. The reason I'm bringing it up, Craig, is because I think that it manipulates the news coverage. From people covering politics that don't understand anything about politics, frankly. they're covering it as media outlets and it's disappointing to see that kind of thing.

Craig Peterson: [00:04:04] Well, ABC News had a report here, so we now know what's really going on. Miryousefi told them, quote, Iran has no interest in interfering in the US election and no preference for the outcome. So we now know what's going on. Obviously a different Iran. Obviously, these people were hallucinating.

But you're right. The information, if you combine the voter lists now with the information that's been stolen from companies, like Equifax out there, you can now tie all of that together. So you've got their email address. You've got their physical address, who they are. They could interfere in such big ways, right? This is just so minor.

Matt Gagnon: [00:04:46] You don't need to break into computers. Oh, let's just say, you see your Russia and you actually do want to mess with American elections and target people and stuff like that. There are zero requirements that you have to break into anything to get that information.

You can literally buy a magazine subscription information and you can basically do what the political parties do, which is layer voter registration data with a bunch of consumer information and data and come up with a model of who the voter is and what their life looks like.

They can do that themselves. I could do that if I had enough money. It's very simple and easy to do that. It doesn't require some sort of a security violation in order to occur. So if you're worried about them, trying to manipulate the elections by, cleverly marketing to us. The security of computers is not really going to be a part of the equation. In my opinion.

I think it, is at the endpoint because you've got all the local polling places, reporting it to the Secretaries of State in all of our 50 States and territories, and then the secretaries of state have now brought it to the Feds. But how does that mechanism actually work in the various States?

And what's your whole works here in Maine, but typically what's been happening is that the polling places go to the secretary of state's website, enter in the information and then the secretary of state's office that's now going through all of that. Posts on their website. So the Fed has been going to the Secretary of State's website and pulling it from there.

So there is a risk of hacking, but I really hope that people are actually also picking up the phone and checking the polling place and saying, Hey, is it legit?

But your involvement also. With politics over the years, you know that there are people at every polling place that are double-checking the numbers, double-checking them.

Craig Peterson: [00:06:37] The secretary of state is publishing. So I agree with you. I think overall we're pretty safe and this just goes right back to phishing. Be careful about the email you get. Cause it's not necessarily legit.

Matt Gagnon: [00:06:51] Said, Craig. Before we let you go, I do want to ask you how safe your USB drive is? That's the other story that we had here that we wanted to chat about here this morning?

Craig Peterson: [00:06:58] Yeah, there are quite a few things to be concerned about, particularly in this day where we're working from home. We're taking that USB drive and we're moving it between computers, home, computers, work computers. That is how we put the Iranian nuclear program about five years behind was one little USB thumb drive.

So be very careful if we're using that as a backup for sensitive documents. We might leave it somewhere, which could be bad. They are also used very commonly for passing viruses around. So if you find a drive at your favorite coffee shop in the morning, be very careful because it may have something nasty on it. Not necessarily because they're trying to, the US and Israel trying to bring down your nuclear program.

It might've been contaminated before you even got it and now it's there on your computer. So don't use them randomly. Be very careful. There's a lot of reasons why you should not be using regular drives. There are USB thumb drives that are encrypted. So if you accidentally leave it somewhere, it doesn't really matter.

If you're using a Mac or you're using a Windows PC in both cases, there are options for encrypting them. So they're very careful, only use fresh ones, right out of a package that is probably safe.

I'm not going to tell you probably, yeah, there have been USB drives that were shipped with malware. Pre-installed accidentally because of the machine they used to format them. Hadn't been infected. Dangerous.

Matt Gagnon: [00:08:42] These are the very things you're going to hear. Craig Peters on talking about on Saturday. Of course, he has to show there, you can hear it at one o'clock at this very station.

Appreciate it, Craig, as always. Thanks so much for joining us and we'll talk to you again very soon.

Craig Peterson: [00:08:52] Hey, take care of Matt. Bye-bye.

All right. So that's it from my radio hits most likely this week and I will be back this weekend. Thanks, everybody. And thanks to those people who sent me an email yesterday, letting me know what's going on. How they listen? How you consume? If you haven't had a chance or if you wanted a copy of that Hunter Biden email that I put together, talking about what to do with your computer when you take it in for repairs. Just drop me a note. Drop me a line. Me at Craig Peterson. dot com take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a lengthy discussion about some letters purported to be to democrats from the proud boys. Then we talked about Hunter Biden and recycling phones. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] In the US, it says you will vote for Trump on election day, or we will come after you. No, this is really scary. It's reached voters and multiple States. Now, obviously, as I said, the Feds are involved.

Hello everybody, Craig Peterson here. I usually say good morning, because a lot of the listeners here listen in the morning and that's when I do. Almost all of this recording for the podcast and radio appearances. So, I don't know. When do you listen to it? Let me know, drop me a line. Really? I'm serious me@craigpeterson.com trying to make this a little bit more relevant. Well, talking about relevant today.

We got into with Mr. Jim Polito. A couple I think are important to pretty much everybody out there is this email. That came out to Democrat voters from a group called the proud boys. We talked about your phone, about upgrading phones. What do you do? How should you recycle it safely? Unlike Hunter Biden. If you want a copy by the way of this newsletter from last weekend, where I go through the five steps you need to take when you recycle your phone, just email me@craigpeterson.com and ask for it and we'll get that out to you. So here we go with Jim

Jim Polito: [00:01:30] Joining us now, our tech talk guru and all-around great guy, Craig Peterson.

Good morning, Craig.

Craig Peterson: [00:01:38] I'm looking at it search terms right now in Massachusetts. And I looked back here for 90 days on the term change vote this, to see how many people are searching for that. And it is a number one is Springfield Holyoke, Mass.

Jim Polito: [00:01:55] Wow.

Craig Peterson: [00:01:56] Number one area. Then number two is Boston and number three is Providence for changing my vote.

I don't know. Maybe, WHYN listeners out in Springfield are having second thoughts.

Jim Polito: [00:02:08] Second thoughts about who they voted for? Well, there's a Rasmussen reports poll. That says now a large 54% of people feel that Joe Biden knew about his son's business dealings and profited from them. So I don't know, in other States there's, it's been somewhat reflected that people who voted for Biden early may be changing their minds.

Joel just brought something up very interesting to me, but it's not what I want to. Get an as a topic today. It's okay for the Ayatollah of Iran to tweet death to America, but don't tweet a story that may negatively impact Joe Biden's candidacy. Don't do that. You can say death to America, but that's it.

That's where we draw the line. Isn't that crazy? It's still going on. Isn't it? Craig.

Craig Peterson: [00:03:03] It is. I've got a little concern about these States that do allow you to change your vote because the only way they can tell if you voted or to protect it, so you don't vote twice as to track it.

Now we get into some of the problems here. If you can change your vote. How much do they know about your vote? The secret ballot is what you get when you go and vote in person. When you're sending it in the mail and I understand, you've got the multiple envelopes, et cetera. It really scares me to think that people are going to be voting, calling back their ballot.

Man, could we have a mess, and it's a security issue?

Jim Polito: [00:03:44] It is a security issue. I don't like it. And I, and actually I want to talk about security with you. I want to talk about people selling their phones because a lot of people do that. How you can protect yourself when you sell that phone. But first I want to get to this and you had discussed it with us already that Iran, speaking of the Ayatollah. Iran was behind the threatening emails that were sent to Democrats, correct?

Craig Peterson: [00:04:15] Yeah. It really looks that way, Jim. It's scary to think about. What we're talking about here is a disclosure that just came out from the Director of National Intelligence, John Ratcliffe.

He called a news conference, he went into some detail here about what is happening with a foreign adversary, because there's been restaurant Russia, Russia for four years. And again, it's Russia, Russia, Russia, when it comes to a Hunter Biden's laptop. I had a lot of responses last Saturday, cause of my newsletter, I went into detail.

What do you do when you take your computer in for repairs. How to keep that information safe? Well, it was from say somewhat fictitious listener named Hunter who apparently had a problem with his laptop.

So, we had a lot of great responses from that.

What's happening now, is we're looking at this and saying, there are these emails coming out, supposedly from a group that to laugh, found out about it is continually asking president Trump, which is called.

The proud boys, the FIT into this, and others too. But what does email says? And it's a spoofed email. It's not really from the proud boys or anybody else here in the US it says you will vote for Trump on election day, or we will come after you. No, this is really scary. It's reached voters and multiple States.

Now, obviously, as I said, the fed juror involved. And it really looks like it is coming from Iran, but look at how easy it is to mettle with our elections without going into a computer that you broke into and changing a single vote.

Jim Polito: [00:06:03] Exactly. Exactly and the whole idea was, Iran wants Joe Biden to be president.

And as far as I'm concerned, that's one endorsement that would make me vote for anybody else. If Iran wants you as president, that's not a good sign.

Craig Peterson: [00:06:19] Yeah. I think you're mistaken here. According to ABC news and that they had on mirrors, you know, Sephora. Iran has no interest in interfering in the US election and no preference for the outcome.

Jim Polito: [00:06:35] Okay. Thank you. Thank you very much. I appreciate the update there. You're very, very good Craig. You're right on top of things, as usual.

So we know they're doing that. The problem is, but I mean, the good part of it is Craig. We can detect that right. We know it. Oh yeah. But the problem is reading the word.

Yeah. But the problem is spreading the word so that other people understand that, Oh, that's what's going on and making sure that everybody gets the word that that is fake.

Craig Peterson: [00:07:13] Yeah. Yeah. Well, like, you know, real fake news was promoted for four years, as we just mentioned. And now we've got these social media companies.

I was really excited about Facebook because "the Zuck" came out and said, Hey, where we're not going to do any centering. We're not going to stop the messaging that goes out. And I think he was right to say that, but that's not what they ended up doing. They are deciding what you're going to see. Now this was a change Facebook actually made most people really haven't thought about this may not have been aware of it, but here's your surprise.

About five to eight years ago, Facebook decided that. It was going to decide what you saw. Now here's what was going on, right. You subscribed to Jim Pollitos page and you could scroll through your posts on your own home page and you'd see everything Jim Polito had to say. And many of these stars at the time when Facebook made this change were very upset because if you, Jim Polito want more people to see your posts, people who have said they wanted to see your posts. You have to pay Facebook. So they started this whole censorship thing quite a number of years ago.

Jim Polito: [00:08:36] Lovely. Thank you, Facebook. Thank you, Mark Zuckerberg. Thank you. You robber Baron you,

Craig Peterson: [00:08:47] And Twitter's doing the same thing here, and deciding what you're going to see, what you're not going to do. See, who you're following, whose tweets you're going to see. And this has made matters worse. I was so excited in the earliest, the eighties when I was on the internet and the free exchange of ideas, and the internet was about 99% conservative or libertarian.

It was a great place. And I thought this was going to be an opportunity for us to have a real dialogue. No, this book is showing you things that reinforce you. And even though the number one pages, the top 10 pages, Facebook every day, the top 10 posts about 80% of them tend to be conservative. Facebook is squashing it across the board, even for people who want to see conservative content.

Jim Polito: [00:09:33] I'm going to tell you, I've seen a little bit of a drop-off in the reach of my stuff and I'm not, you know, it's not an ego thing. But I've seen a little bit of a drop-off and I'm just wondering, wow. Is it really getting worse as we get closer to the election? And this is material that I'm basically with my eyes closed, can tell you what kind of a reach it's going to have.

But I think some of the, um, algorithms have changed. It's not getting the reach that it did. Let's get onto something series here and we don't have too much time for it, but it is something. Important people do want to sell their phones. You know, in the old days, when you had a flip phone, you didn't care, it was free.

Whatever. Now your iPhone or whatever you've got is worth money. And so you don't want to have that drawer. With the old phone in it, you want to be able to make, and I'm thinking about getting a new phone. I'd like to get money for this old one, but I'm afraid that somewhere in that phone, there may be personal information about me and I don't want the next person down the line to get it.

So what do I do? Yeah, it's, uh, our lives are on there, right?

Craig Peterson: [00:10:47] It's just as a real problem. Here's what you do, bottom line. If you're using an iPhone, always make sure that you have a passcode or some sort to get into it. You either have like me a 12 digit passcode, maybe you're. Yeah, it takes a while to unlock my phone.

Or you're using one of these fingerprint scanners or facial recognition what's your iPhone will do at that point is encrypt everything on your iPhone. The other thing you need to do is turn on, find my iPhone. So if you do that with your iPhone, That I found is now considered to be quite secure.

Although in most cases now the police departments can get into your iPhone. So remember that. So we're talking about Braden, so yeah. So when you're trading in your iPhone, remember everything on an iPhone is encrypted. So it's very, very simple. All you have to do is turn off, find my iPhone, and then you erase your iPhone.

It's called erase old content. And that's under your settings in general. It doesn't actually erase it. Okay. And that, but that's not a security problem. What it does, Jim is it removes it deletes the encryption key. So all of your data is now unreadable. It, it looks like random trash.

And so at that point, it's fine. It's all done. Okay. If you raised it, you can deactivate your counselor. If you want to, you can do other things, but really that's all you have to do. Erase all content.

Now on Android phones, turn off the factory reset protection. This is extra security protection that began with Android lollipop here a couple of releases ago.

So go to settings. Privacy factory data reset and then choose reset phones. And there's one more step.

For almost every phone out there. It has. What's called a SIM card. This is a very small card. And that SIM card has the information about your phone, all the phone numbers, you've called your messages, billing information, all kinds of stuff.

So pop out that little card. You can usually do it with a paperclip. Yeah, but there's a little hole in this that how it works. Yep. And keep that card. So if you restore your phone to factory default or erase all content and remove the SIM card, you can now trade it in.

There are a number of websites out there that you can go to that we'll buy your iPhone, but it's, you can recycle it, you can sell it, you can donate it.

I'll have more information about this on my show on Saturday. That's great. Okay. Uh, it's Sunday at 11 o'clock on WTA G, W H Y N. Okay.

Now, what's the other way folks can get in touch with you, Craig.

Well, the best way is to go to CraigPeterson.com. There's a lot of great info there. Everything we've talked about, I've put up there and, if you have a question, you can always email. Me@craigpetersondotcom and I always get around to answering them just me ME at Craigpeterson.com.

Jim Polito: [00:14:08] All right, there, you have it, folks. I told you it would be worthwhile to stick around.

Craig. Thank you. We will see you. On election day next week, I'm sure there's going to be plenty to talk about Craig. The election day a week from today. Alright, take care. Thanks, buddy. Bye

Craig Peterson, what a great resource.

Craig Peterson: [00:14:33] And if you do want a copy of the newsletter from last weekend, if you missed it. If you're not subscribed yet talking about what to do to avoid your very own personal Hunter situation. Of course, you probably don't have, hopefully, the same types of stuff that Hunter had on his computer. Just email me, me@craigpeterson.com.

And let me know. You want to know what you should do about your computer before you take it in for repairs.

Take care of everybody. Be back tomorrow. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. I was on with Scott Spradling on NH Today. We discussed the threatening Email and letters being received by voters and where they came from. We talked about Google search terms. Then we discussed why The National Guard has been called up in Lousiana to deal with Ransomware. We wrapped up today's discussion with election security in the light of revelations by the FBI and DHS about Nation-State Actors accessing our election systems through known vulnerabilities in the Secretary of State Websites. Here we go with Scott.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Same basic thing. It peaked in March. Like you'd expect it, a huge peak being the end of July. Now people just aren't searching about masks anymore. But this election, this COVID thing, it's looking online. It's driving people crazy.

Good morning, everybody. We had a fun time talking about what is going on with the election meddling. There's some serious stuff happening. I'm not sure how big this scale is, but we've got warnings out. Another one here. The national guard actually called out apparently in Louisiana over real election problems.

So here we go. Craig Peterson, of course, with Mr. Scott Spradling.

Scott Spradling: [00:00:43] Interesting developments over the course of the last few days.

I don't know if folks saw this in the news, but there were letters and emails that were sent to voters threatening that if they didn't vote a certain way, that there would be some form of retribution. It looked like most of those emails went to democrats, although I'm not a thousand percent clear on the details. A follow-up investigation by the authorities has determined that these threats were coming from Iran.

Joining us to talk more about this is Craig Peterson is welcoming back to New Hampshire today, Craig, thank you very much for joining us and tell us a little bit about this headline and how they figured out that this was coming from Iran.

Craig Peterson: [00:01:20] It's interesting stuff isn't it here, when you get right into it. Sometimes it's hard to figure out exactly what's going on. Apparently, there were emails that were being sent to Democrats and they were set up in such a way that it looks like it was this pro-Trump group called the proud boys. It's been all over the news lately. A lot of questions asked about it. A couple of them in the debate in fact where President Trump's said: "I don't really know these guys, but if their bad guys don't have anything to do with them."

According to the Director of National Intelligence, John Ratcliffe, apparently what happened is that the Iranians decided they would jump on this whole proud boys stuff that had been in the news and they started sending threatening emails. Talking about how, if you didn't vote for Trump, basically, we know who you are and we're going to come after you. In fact, they literally, what it said is you will vote for Trump on election day, or we will come after you. By Tuesday night, they are said to have reached voters in four different States. The FBI has been involved.

We've been having problems in Milford. You've probably followed some of that. I know Scott that you've talked a little bit about it. It's crazy. This morning I just heard from one of my daughters that her boyfriend's family had a thing stuck on their door. A little letter stuck on their door saying that if he votes for Trump they're coming after him. Wow. This is crazy.

I went online and Google has this trend feature that allows you to look at the terms that are being used, who is searching for them, and what's going on. I checked out a couple of terms. You have been talking about Covid fatigue, and it is showing some very high interest, but it's interesting where it peaked, it really peaked in July and it peaked again last week, which is interesting.

Scott Spradling: [00:03:24] Uh, Huh.

Craig Peterson: [00:03:24] COVID mask. The same basic thing it peaked in March like you'd expect it a huge peak beginning of July, and now people just start searching about masks anymore.

This election, this COVID thing. Looking online it's driving people crazy. I tried to verify another story that's been floating around. Basically, a rumor based on my exploration here, saying that, the number one search term is, "how do I change my vote?" So I checked a few States, including New Hampshire. Nowhere near true. In fact, so few people are asking on Google, how to change their vote, that doesn't even show up in most of the graphs.

Scott Spradling: [00:04:02] I have a lot of faith in the New Hampshire election system, which is nice to hear. Craig Peterson. Let me ask you a different question because we were talking about the Iranians being behind this kind of a threat via email. One thing that's really, really interesting, in the headlines is that some States are devoting some serious resources to pushing back to local threats like ransomware. And I directed to the state of Louisiana where the national guard is this actually being mobilized, if you will, to go against a tech threat. Talk to me about that.

Craig Peterson: [00:04:33] This is very interesting there's a study out, Reuters is carrying an article about it right now, from, Friday and Thursday last week. Apparently what's happened is they found inside some of the Louisiana governmental offices that are specifically involved in elections. In other words, Secretary of State's offices. They found some Trojan rats, remote access Trojans, it's called the Kim Jong rat back door.

This particular back door apparently has allowed them to get into the government networks down there right now. Many people may not be aware of it, but our military, including our national guard, has been very well trained. I did some of the training myself, for them on the techniques to help repel these types of ransomware and other types of attacks, direct attacks as well. Also, come in after the fact. Frankly, between us, we have a very strong offensive cyber capability where we can go after other countries, of course, that happened to Iran already.

So there are some warnings out there. The United States cybersecurity infrastructure security agency issued a warning. I have for years now been talking about. The weakness even here in New Hampshire has to do with the websites, particularly against Secretaries of State. Those websites are used for gathering information from the local polling places, as well as for the federal government to go out to the states and find out what the final tallies are. Those websites are very risky, frankly.

That's the part of the election that I really don't like, Scott, because it's so exposed.

Scott Spradling: [00:06:20] That's gotta be tightened up. No doubt.

Craig Peterson, let me ask you another question. So that's for the macro, the big picture perspective, and what governments need to do. What actions are being taken at home, whether it's, the privacy of your information on your phone, especially when you're selling and maybe trading yours in. Or the safety of your USB drive. How well protected are we right now at the sort of micro-level? What steps should we be taking?

Craig Peterson: [00:06:45] Our protection level for the average person right now is barely there at all, at best. You've got a little bit of a firewall. There's something called network address translation is protecting you. Almost every computer out there in your home is unlikely, unless it's a Mac, to be up to date on patches. That's the bottom line.

The best thing you can do, keep everything patched up. We've got thermostats now connected to the internet. We've got lights. We've got security cameras. When was the last time, Scott you patched your security camera, at your house?

Scott Spradling: [00:07:23] Never.

Craig Peterson: [00:07:23] Yeah, exactly. That's huge. The second thing you can do is get a prosumer firewall. Don't use these pieces of junk that are given to you by your Internet Service provider. You really got to upgrade, get into something a little bit more professional and that'll help a lot.

Scott Spradling: [00:07:40] Craig Peterson. Thank you so much for your advice and observations. We appreciate you helping keep us safe, especially when it comes to our electronic footprint. Hope you have a great day, a great Monday.

Craig Peterson: [00:07:49] Thanks, Scott. I'll be back Saturday at 1130.

Scott Spradling: [00:07:52] Great. We'll talk to you then.

Oh, my gosh, I so much better. That's all I'm going to say. All right, everybody. We are going to be back tomorrow and Wednesday and of course, I'll be back this weekend.

I will be posting this now. I had a guy, he had suggested one of our listeners here, who is becoming a friend of mine. it's been fun chatting back and forth, but, he had suggested that I put up one-hour shows. Now we tried that a couple of times and, we just fell out of the habit, for no particular reason.

There were only a couple of people that reached out when I asked about it before, I'm going to assume you're indifferent unless I hear otherwise from you and there are thousands of you out there. So we really, you should try and do this a little bit differently.

Let me know if you think I should post this as well. At least my weekend, podcasts, instead of breaking them up into topics. Do you think you guys should do them as one big podcast? It's going to be about an hour and a half worth of podcasts or continue to do it based on topics. Please do let me know?

This isn't some ruse, I want to know from you guys. Just email me, M E at Craig peterson.com. I'd love to hear from you. I'd love to hear how you consume the podcast. I know a few of you have already told me, you're listening while you're out driving the trucks. Some are listening in the gym, others are just really just going about their weekends. So let me know. I would really appreciate that.

We've been really releasing the podcast on Friday afternoon. and that's probably the earliest we could possibly release them. But does that work for you guys to do that? It might be better for the show may be to release on Monday. Or more people listening over the weekend than during the week? When do you guys listen to it? I can certainly look at the stats and I have, but I've never really tried to release it later. So let me know, just email me. M E at Craig peterson.com.

I want to make the most of my time and of yours have a great day.

We'll be back tomorrow. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig gets into some detail about why Hunter Biden's laptop that he took to a shop and never picked up is now in the hands of the FBI/DOJ and the things he did wrong when he took it in for service -- and no -- it has nothing to do with Russia.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Yeah, I'm sure you heard about Hunter Biden, and what happened with his computer when he took it in for repairs? How about your computer? We'll be getting into that right away, right off the top. And then the FBI says hackers are already in our election systems. Man really.

Hey everybody. Welcome. Welcome. You're listening to Craig Peterson.

Well, we had a lot of news this week. Some stations covered it. Certainly. But bottom line things just weren't covered here in the US. It was interesting listening to some foreign stations. They were covering the whole Hunter Biden thing, yet here in the US, it's like a ghost town on most of the major networks. This is really, really crazy. I'm sure you are interested in knowing a little bit about what's going on? What are your rights? What should you do?

Karen and I are putting together a special report that you can get for free. I don't squeeze you for these things. All you have to do is send me an email and I'll send it off. We're putting together a special report specifically on steps you have to take before taking your computer to one of these computer repair shops.

Now, you know, I already suggest you do not use break-fix shops. Don't use any of these big squads that are out there running around saying they can fix your computers. I really do recommend that you use a managed services provider.

I'm a managed security services provider, right. I want to put that on the table and we do tend to do take care of systems for our customers, of course, security customers a little thing there we'll usually do it for them.

A managed services provider should be someone that you're using that you trust and have a certain responsibility to your data and all of the information behind it. Particularly if you are a subcontractor for any DOD contract. There are certain responsibilities that flow down to you.

Obviously, if it's off the shelf stuff, the responsibility is a lot less than if it's the stuff that is not necessarily secret but is part of information about a base or information about how many items are being ordered. The military and the prime contractors don't like that information getting out for good reason. They don't want the bad guys, the Chinese, the Russians and North Koreans, et cetera, et cetera, in on that information. Look at what's happening right now. If you go right now to Duck Duck go, and look up the Chinese carriers or better yet, look at their newest jets, They are a clone from just looking at it. They are a clone of our US jets. The reason the Chinese have this data is that they stole it. Rolling back to the time of President Clinton, he just gave them the technology for launching Intercontinental ballistic missiles to hit the United States.

He gave it to them. Because he said, we want the Chinese to be able to launch our satellites? Because it's going to be way more cost-effective. The only way they can launch satellites is if they have this particular type of technology for their rocketry. And so basically, he just gave it to them.

I think that it's crazy reasoning if that was the actual reasoning behind it. Now they've turned to. Theft. This always happens in every socialist country. Any country that goes socialist, you just don't have the innovation that you had otherwise because you end up with all kinds of taxes, all kinds of restrictions.

You take away the motivation for people to make money. Look at what's happened with 50 Cent, he's a rapper. He went most of his life with no money at all. Worked really, really, really hard, and finally made some money. So the average person is going to make a few million dollars if you are a white-collar worker over the course of your lifetime. What if you worked for 10 years, 20 years, 30 years trying to get some software to work, trying to come up with something, and man it didn't work in the marketplace. So let me try something else.

Let me try something else.

Let me try something else.

So for 20 years, you're living off of almost nothing. Just scraping, just trying to get by. Then yes, I got it. Finally everything clicks. The market's there, your product is there. It's all working. You've got the right team working with you. Your partners are the right ones, not these two Hunter Biden partners that have ended up in prison or one's waiting for sentencing right now. You got good partners that are really working for you working together, pulling together.

And now all of a sudden you make a million, 2 million, 3 million, $4 million. Maybe you made $5 million over the course of 40 years. That isn't much different than your average white-collar worker. Yet you are going to be taxed to kingdom come if you live in a socialist country. So all of that work that you did for 40 years to finally make some money, maybe even leave a little bit of money behind for your kids. Generational wealth. It's gone. It's been taken. It's been confiscated at the point of a gun by the socialist government.

When you're someone like China, you have to steal intellectual property from other countries because the incentive is just not there. If you stick your head up, if you try something and you do it wrong, that head gets bashed in. You get sent out to re-education camps.

Look at the millions of people that we know of that have gone to these Chinese, every education camps. Look at the tens of millions of people that have starved to death because of socialism. Well over millions, in fact, documented in the 20th century, just because of socialism. It happens every freaking time.

But, let's get back to the laptop here. If you are China and you're trying to steal concepts, ideas so that you can then build your military, build your commercial infrastructure, compete with Tesla, compete with Apple, you need to steal it. You want to get your hands on computers.

You need to use other people's computers in order to hide where you're coming from. You've seen it in movies before. You might remember way back when you were watching war games. In War games it showed this modem and he was trying to go here and then it was hopping over to there and there was hopping over to here. How they kind of hop around. That is reality. It's still to this day.

That the bad guys need your computer in order to hack other computers. Now, sometimes what they're doing is they're attacking other computers using your computer. So that might be attacking it, looking for a way to break in. They might be attacking these other computers through a denial of service attack, where they have thousands or even millions of computers sending requests to websites or other places. Then they hold that site hostage at that point. That happens. It really, really happens. We've also found that the bad guys are using our computers in order to store and forward illegal information. So in some cases, it's illegal information like designs for jet aircraft engines that we use in our fighters. Or the latest one. This is just from this last week is they stole the vibration dampeners in our jets that are designed to be very stealthy. So the less vibration, the harder it is to pick up.

What did they do? Well, they steal it from us. At least ask what it looks like right now, allegations just everywhere on that.

I have firsthand personally seen this sort of thing happen where China is stealing. Intellectual property from US corporations. We've gone into these companies that thought they were secure. We have a managed services provider. Most of the time, it's all we have an IT person and we call these other guys up when something breaks.

We go in there and we find these back doors. A case that I've talked about before that I was involved in, expert witness out a New Jersey, where illegal information is put onto third parties, computers in order to share it with other people. It is happening all the time. It's everything from the ISIS beheadings and burnings all the way through kiddie porn.

This is real. We have to lock down our computers because of this. Now you might ask why I'm talking about this one. We're talking about Hunter Biden's computer that was taken to a repair shop, or maybe what we want to talk about is your computer that you're going to take to a repair shop. Well, I ask that because the big question here is what's on your computer.

You know what you have put on it. No, maybe you even forgot some of the stuff that you put on it. But what have the bad guys put on your computer? Is your network system secure enough that you can say, yeah, yeah, nobody is using my computer, my network maliciously? Do you even have a firewall that tracks your outbound connection?

We get into, and a lot of detail about how to do that, what you need to do in our cybersecurity mastery course. It's an important thing.

So stick around when we get back, I'm going to give you the tips that you need to know. If you're going to take your computer to a repair shop and we are going to turn this into a little book for you, a special report, something like that.

Stick around. We'll be right back. You're listening to Craig Peterson. Online Craig peterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig continues his explanation about computer repairs and what you can and must do to protect your data and privacy. Back up your data! Also, the proper way to destroy old disks.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Do you know, what's on your computer? Do you know what they do with it? At some of these repair shops that you take your computer when it gets slow and something breaks? When you're just trying to figure it out? What the heck is happening here, man? We've got an eye-opener for you right now.

Hi everybody. Craig Peterson here. Thanks for joining me.

We talked a little bit about what it's on your computer. You may not remember everything that's on it. It may just be some malicious stuff a third party has put on there. You might have bank account information. You might have password information. You might have intellectual property on it.

If you are trying to take in a computer, that's badly broken. You're in a little bit of a hard spot here because that computer can't be cleaned up. Can't be cleaned very well at all. You can be just totally stuck with it and you can remove stuff, right?

Let's, roll back a little bit before your computer broke. The first thing is what I teach in my cybersecurity mastery course, which is something we call a three, two, one backup.

Make sure you have a data backup. Three, two, one talks about the number of copies, the different types of media, the different locations to store it. Having a data backup is crucial. I've been using Backblaze for a while. I have a Backblaze little partner thing, so I get literally a dollar for referring people. Just so that you know. Note: If you go to backblaze.com they'll know I referred you because they won't. I use it. It's six bucks a month and it'll back up a computer and all of the directly attached hard disks for six bucks a month.

Now my main computer has many, many, many terabytes of data on it. I think it's. 40 something terabytes and it cost me $6 a month. It is amazing. So check them out online, make sure you got a backup. It needs to be a solid backup, needed to have multiple copies. And this is something that people always forget, test it. Make sure you can restore that backup. This is a really good practice to follow it's something that is a part of disaster recovery. There are other parts as well.

If you are a public company or you are owned by a public company, the bottom line you have four hours under the law to get back online. It's only for four hours. What we have done for companies and we could do it for yours too, we go ahead and make sure we have additional hardware on-site in case something goes extremely wrong. That way we can get them up and running in a matter of minutes. In most cases, if they have a major crash, if the building burns to the ground, we can get them up and running in four hours. If that's what's needed.

Of course, that costs a lot more than just doing it mean a Backblaze back up, but that's okay at the beginning. That's the start. Make sure you can restore and as always. I go over this a lot in my cybersecurity master course and on the module on backups, make sure you realize how long it will take to restore your backup. It may take weeks to back everything up. In my case, it took months, right? It may take a long time to back everything up.

How long is it going to take to restore? Does that data backup company have an offer where they will go ahead and either restore your data to a hard drive that you can then hook up to your new computer and copy everything over that's fast? Some may even overnight that drive to you or will they take them back up and put it onto a brand new machine. That's what we do for our customers so they have it. It's not a disaster.

They have a computer that isn't working anymore. It's just totaled time for a new one. We'll go ahead and restore it, new machine, and then install that machine for them or send it to them, depending on who they are.

That is ultimately highly important. So make sure that happens before it's time to take your computer to a repair shop. Because you never know that repair shop while they're trying to fix your computer may just toast it, or maybe already toast in this case. Meaning. It is no good anymore.

So that's number one before anything. Okay.

So if your hard disk just toasts out on you and you need to take that computer now to a repair shop to get a new hard disk in it, make sure that you remove the hard disk first. Then take it in say, yeah, my hard disk is toast. You're going to need to start from scratch.

Now you're going to need to have your windows license for them. If it's a Windows computer, if it's a Mac, it just is going to work, right? The Macintosh, I'll go ahead and do a network install, or if they know what they're doing, they can do a local install of all that Mac software, as well, to a new disk.

In this day and age, of course, the recommendation is don't use spinning media disk. Use an SSD. There are a number of different types of SSDs and the cheap ones fall apart quickly because you can only write to them so many times. The pricing has gotten a lot better for consumers.

You might have heard this week, Intel got out of the flash memory business because there just isn't the margin in it anymore. So shop around a little bit, make sure you got the best price on that.

So there you go. Number one. Good backup.

Number two, make sure that if your disk fails, you remove it. Because you cannot do the next step, which is okay.

Make sure you remove any personal data from the computer or make sure it's encrypted.

Now, what we do because customers are regulated. If a disk is bad, we remove the disk, we break it down and we have a special furnace that we can melt those disks. Most of the platters are aluminum nowadays. There are also glass platters, but we will melt them down at extremely high temperatures and then certify that yes, indeed it is now a slag of aluminum and has been completely destroyed. That's the only way that you can meet the federal regulations if you are one of those types of companies.

If you are someone that's just a small, basic company, you're worried, but you're not worried about China getting at it or somebody else. Right. A real bad actor. Then what you need to do is get a half-inch drill bit and make three holes. Holes in that hard disk right around the little circle. You'll see a circle in that hard disk. That's usually where the spinning media is. That's usually the central bearing. So go out an inch or two. Probably a couple of inches from that bearing and drill all the way through that will destroy the data on there. So that will help to protect your intellectual property. If you want to do it the best way, it is to melt that disk down and that's what we do for our clients as well.

Okay. So back to if the disk is still working no matter how trustworthy you think that this business is you took the computer too, is there's always a chance. There's a bad egg amongst all of the staff members there. So delete it, remove it. Again, hopefully, you have a backup. Hopefully, that backup is tested.

You can restore it afterward if your disk is encrypted and that can be true on Windows or on a Mac. There are a few different ways to do this, then.

Remember that they're going to have to boot that computer. And that may mean almost certainly mean that they're going to have to, if they, to do an end to end check boot from the disk that media that's in it.

What we tend to do is we booted off of a USB drive so that we don't have to have the decryption password for the hard disks. That way there's no temptation, right? None of my techs have that temptation because they can't get at the data anyways.

Make sure again, boot encryptions turned on.

Stick around. We'll be back. We've got a couple more things to cover here. This is all spawned by Hunter Biden and his computer that he dropped off at the repair shop.

If you sign that little contract, in 90 days, the computer and everything on it is theirs.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig continues his explanation of what you need to do if you have to take your computer to a shop to be repaired. This segment covers encryption.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to talk right now a little bit more about removing that personal data before you send it in for repair and a couple of other things that you need to know about your rights when it comes to repairs.

Hey, you're listening to Craig Peterson. Thanks for joining us today.

Next up is probably pretty obvious to everybody make sure you're very selective about who you trust. What's the reputation of your work with them before? If you're dealing with a managed services provider, They have a fair deal, in fact, of responsibility for your data. If they are a federal compliant managed security services provider, then there are federal laws to help protect some of your data.

But if you leave that data on that computer, it's like not paying for the guy that did all of the yard work outside who brought in the bulldozers and the trucks full of soil, et cetera. They have a mechanics lien on your home. They can take that right out of you and even force the sale of the home in order to get paid.

Kind of similar in the computer world. They did put in the time to fix a computer, they might've added parts, et cetera. So when you sign that contract, when you're dropping that thing off, remember that you kinda are signing your computer away. That is not a good thing for you if you don't come back in the 90 days, because that computer and all of the data on it becomes not yours. It becomes the repair shop's data and computer. They can do with it, whatever it is they want to do with it. That's, what's gotten Hunter Biden into some serious trouble here and Joe Biden as well. Remember this, isn't a Hunter Biden problem.

It's now showing some major corruption on the part of Joe Biden. So if it's true, Where did this all start? Well, he's kept his head down pretty well for 47 years in the US Senate, et cetera. But, this one thing just dropping the computer off for repairs could be a problem.

Encryption is important. Remember most of us are just using what's called encryption at rest. In other words, the data is encrypted while it's on the disk. That does not meet some of the higher standards of various regulations, but it's okay. It's a start. So you use encryption on the disk, you use the builtin windows encryption or the built-in Apple encryption as well. Now there are some very good tips here as well. That has to do with your keys. I keep all of my keys, my software keys, my log-in keys, license keys in a vault. An encrypted vault.

There is another level of that. It's something that we are trying to convince our clients that they need to do because some regulations are requiring it now. Although most companies are not doing it. That is, it has to not just be kept in an encrypted vault, but half has to be kept in an encrypted vault that will self-destruct if someone tries to get into it.

So keep your software keys, separate, keep them off of your main computer. Nowadays put them in your smartphone in an encrypted vault. I use one password there. You can use LastPass, which is another good one. There are many others, but keep them on a separate device. This again is the next step ultimate insecurity. We get into this in our cybersecurity mastery program. When we're talking about some of these different levels that you have to comply with, but you can have a unique key for each disk, that's stored on a separate machine so that when your computer boots up, it has to go to the separate machine in order to get the keys in order to decrypt and use your hard disks. Okay.

That's way above and beyond what home users are going to do. It's way above and beyond what a SOHO, a small office home office business is going to do. It is absolutely required for government contracts here in the next three years, it's already required today for some vendors.

There's one more step here we've got to remember. That the repair guys have to be able to repair your computer. You're going to want to make it easy for them to access your device.

A word of caution. We've had stories, and I have personal knowledge of people working at some of these big companies. Many of us look at it and say, I'm not going to take it to Joe's repair shop, because who knows if they're going to repair properly or what's going to happen to my data, et cetera, et cetera.

There was a great article we talked about when it came out a couple of years back from one of the bigger companies out there that have a squad of people that go around and install equipment, fix equipment, et cetera. Where some of their stores were being paid a bounty. What would happen is you'd bring your computer in and they would look at the data on the computer. They would check to see if they could find kiddie porn or anything else illegal, such as well pictures of you smoking crack cocaine, which is what's alleged here on Hunter Biden's computer. They would get paid a few hundred dollars, that technician, for finding it. How's that for scary? They would work with the police. The police had a bounty program. It was just absolutely nuts.

So how easy do you need to make it for these people? Don't go crazy with making it easy for them. In fact, in many cases, before I would possibly take a computer in for repair, of course, I don't, right? We repair them ourselves. Or we have a repair company come out and we watch them repair every step of the way.

What I would do is remove that drive, no matter what kind of computer it is, and then take it in for repairs. The company that's doing the repairs, they've got bootable USB drives that they can just plug right in, boot it up, it's up, it's running. Life is good and they give it back to you.

Hopefully, the problem isn't that, that hard drive was bad. But again, hard drives are easy enough to replace. But what you going to do to make it easy for them to repair, if you're going to ship it to them or give it to them with the hard disk intact, is to remove the password.

Now I've done that before with my Apple computers, taking them into Apple for repairs. I also make sure that there's nothing on the machines. We'll make sure the backups good, which you should be doing anyway. Then we wipe the computer by destroying the key, the encryption key for that computer. Then we reinstall the operating system and we test the machine again because sometimes it's just the operating system got messed up. Particularly if you're dealing with a windows computer. So that's always a good thing to do anyway. Then when we give the computer to the repair guy. She's going to be able to just run it and it's not going to require a password and life is good, right? She's often running.

That's what I would recommend as opposed to just removing the password on the computer. Remove the password, destroy the address by simply deleting the key and you can do that with these disk and full disk encryption programs, and then reinstall windows or Mac iOS, whatever it is. Check your machine again, make sure it's still not working the way you want it to, and then take it in for repairs.

Things do break. It doesn't matter what kind of computer it is. It doesn't matter if it's a smartphone or a laptop or a server, they are going to break. There's your basic tip. Make sure you got the backups. Make sure everything is as it should be. So that you're not going to get nailed and your data's not gonna get stolen if the bad guys did hack into your computer and use it as a store and forward for illegal materials, they will no longer be on that computer.

Stick around. We'll be right back and make sure you get my newsletter. Craig peterson.com/subscribe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig explains why DHS and the FBI are warning us about Election Hacking and why it individual State Website Security is the culprit.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We've talked about the potential here of hackers getting into our election systems and what are they going to be able to do? No, I've never been really big on this, but now FBI and DHS, well they're both disagreeing with me.

Hey everybody. Welcome back. You're listening to Craig Peterson.

I've talked about the likelihood of hackers being able to influence, I mean, in a very big way, our election here in the US and I've kind of poo-pooed it, because as a general rule with 50 state elections, it would be very difficult for a foreign adversary of some sort or somebody that just wants to mess with us to really cause havoc with our election.

Of course, it looks like we're going to cause enough havoc ourselves falls because of this lockdown that we did. All of the crazy things we're trying to change at the very last minute with our voting this time around. This is going to be one heck of an election season. Ah, I'm not looking forward to it.

I have been warning about some of the problems that have existed with Secretary of State office websites. Some of these Secretaries of State are putting up websites that allow the local County chairs, city, et cetera, to upload the vote tallies via the web. To the Secretary of State now, on the whole, that sounds pretty good. It seems pretty reasonable.

You might remember what happened in Iowa early 20 20. Yeah. Where the Democrats decided they were going to use this app for tallying all of the votes. It wasn't being used for voting, but it was being used for the tally who won. We actually don't know who won the Iowa Democrat caucuses. Isn't that right? Just amazing, because of the technology and the problems behind it.

Well, when we're talking now about state hackers, countries that have massive hacking campaigns, ongoing. Yeah. How much could they mess up our election by getting into the Secretaries of State websites? Because not only are the 50 States responsible for running the elections. Tallying the votes, but they're also responsible to give that data, hopefully, good data, the federal government. So how does the federal government get that data?

Well, they tend to get it by going to the 50 Secretaries of State websites nowadays. And that's where my big concern comes from. Obviously, I do not like these touch screen voting machines.

I know I am a good old fashioned writing on a piece of paper or the kind of the heavier paper, a hundred-plus pound stuff. You fill in an oval for who you want and then that card you put it in the machine. The machine counts it. I love those because the bottom line it's completely auditable.

I talk a lot about audits because so many of my customers are getting audited because of federal regulations, but this is different.

Let's say the machine tallied, a hundred votes for Trump, and 120 votes for Biden. A spot audit could be conducted. So you take all of the cards that were fed into that machine and you manually count them.

Okay. This is obviously a Trump vote. Okay. That's obviously a Biden vote. So you're going through, you're seeing what the votes were for each person and you can now say, okay, it came up the counts the same, and you know, that machines counter right for what you were looking for was correct. Those cards can then be taken later on and you can have a Republican and a Democrat and a libertarian or whatever the parties are in your state watch as those individual ballots are counted because a physical ballot exists. That's just incredibly important. They can't hack a pencil. I love that saying. Right? I think it was our Secretary of State that said that you can't hack a pencil. I'm not sure that's not all entirely true, but it's mostly true.

But you can hack some of the systems that are behind the reporting, according to the FBI and the Department of Homeland security right now. An article by Brooke Crothers is pointing out that hackers and they're saying possibly nation-state actors, which means who China, Russia, Cuba, North Korea, Venezuela, Brazil, not so much in Venezuela, not so much nowadays, either because their economy is in shatters because they are a blank country, a socialist country. Exactly. So their economies in shatters.

Brazil's in shatters looks like we might get a trade agreement by the way, with Brazil kind of interesting, but.

They are saying now that there is no evidence so far, this is a Homeland security, that the integrity of the elections data was compromised. And they're saying that it does not appear these targets are being selected because they are part of our election apparatus. In other words, wait a minute, guys. Our secretaries of state's website, other systems are being hacked just as a part of a random hack. What happens if they get ransomware? And what happens if a nation-state really does want to go after them this week.

We saw six spies arrested, Chinese spies who were stealing information critical to the United States of America. They lie on their visa applications. You know, that's why right now the State department's saying you might not want to go to China because China's threatening to kidnap Americans over there and hold them hostage in exchange for these spies. It's not like the old days where we would catch some Russian spies. They would catch some American spies and then we trade them. Right?

No, China is right now threatening to, and they already have with Canada and two other countries, they are threatening to kidnap regular old, innocent Americans off the street of China and hold them hostage until we give back there are six spies. Can you imagine that? Yeah, China is not an enemy. China is a friend, right? Well, it's a friend. If they give you one and a half-billion dollars. That's another story for a new section here.

What I have been concerned about it looks like it's happening, that these were not attacked because they're part of the election apparatus. These were attacked because they were vulnerable systems. So what vulnerabilities were used, I think everyone needs to pay attention to this cause this is a very, very big deal. This is Seesaw. This is the cybersecurity and infrastructure security agency Seesaw. They are saying that they got in through what's called vulnerability chaining.

That is a big deal and that is on my list of things as part of what we cover in my cybersecurity mastery course. This is a technique that's commonly used and it's used against businesses. It's used against federal state agencies, government critical infrastructure, elections organizations.

In this case, it targeted something that I've been talking about forever. VPN vulnerability. Don't use virtual private networks unless you really, really, really, really know what you're doing. Okay. This was a target against a VPN vulnerability and a flaw in that log on, which is a windows protocol that used to authenticate people who are connecting over the VPN.

Now what makes us even worse is that not only did the Secretary of State offices and other government offices not have adequate security to prevent this, not only did they not have properly configured VPNs, which is like 98% of them out there. So pull up your socks, people.

Patches were already available for all of the vulnerabilities. They were already out there. This is what came straight from the FBI and CISA the patches were already there and they had been disclosed and the systems were not updated. So. How safe then is, is our election infrastructure?

I go back to what I've been warning about for many, many years, our over reliance on the accuracy and security of the technology. These guys that did it are known as advanced persistent threat actors. Which usually means nation-states. They did not identify who it was most of the time lately. It's been China, no matter what these so-called news organizations have been saying, it hasn't been Russia. Russia really hasn't done much lately. It's mostly China and apparently, it looks like it's a financially motivated nation-state actor that can mean Russia. They are more financially motivated, but so is China. That's why they're stealing our business secrets as well. Okay. Very, very bad.

Microsoft. You might remember, we talked about it here in September, said it detected Russian, Chinese, and Iranian actors targeting the 2020 US elections. So this is stepped up activity. They are targeting the 2020 election, according to Microsoft and the national counterintelligence and security center director, William Evanina. It's a very big, very big deal. So something else to worry about for our elections in 2020.

It's also something you need to worry about if you are working from home. If you are a business owner or if you're an IT person, and that's why I'm here, I'm trying to help you guys understand this. That's why I have my cybersecurity mastery program. So you can ask me any questions you want to, and we can get things solved. Get them rolling.

Be sure you are on my email list so you get my newsletters. You get the training and you know, what's going on.

Hey, you're listening to Craig Peterson.

We're going to talk about the IRS being investigated this time. You've seen those CLEAR things in airports, let you pass through quickly. We're going to talk about what they're trying to do nationwide.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses how the IRS gets around collecting data on US Citizens. They buy the information from these private Data Aggregators like our friends at Equifax - who by the way collect tons of information on you without your permission (you have no say in what information they collect) and then sell it!

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson (2): [00:00:00] Coming up in this hour, we're going to talk about the IRS. Yes. Investigated for using location data without a warrant. We're going to talk about us airports and the company that clears you going through that little test that they have at the very beginning.

Hi everybody. Craig Peterson here. Yeah. If you've ever had a run-in with our friends at Homeland security with blue shirts, transportation security, many people have decided to do something that.

I haven't done and I don't know what I would do. I think it's kind of dangerous and we'll explain why here in just a couple of minutes. Of course, at my website at craigpeterson.com, make sure you're on my email list. So you get all of my newsletters and all of that great information that comes with them. And right now, if you sign up, we are including some bootstrap stuff, getting your cybersecurity for your home altogether, as well as for small businesses.

So all of that. Craig peterson.com/subscribe.

We were talking in the last hour a lot about taking your computer to a computer repair shop and what to do. Well, how about you shouldn't do and how Hunter Biden apparently got himself into a whole lot of trouble by this little eighty dollar repair that apparently needed to be done to his Mac computer. Yeah. Not so much fun.

We're going to start out this hour by talking about the I R S. Yes, the internal revenue service, right. We have a system here in the United States. It's different than most socialist countries, certainly different than the fascist and communist countries of old, where you got your check from the government and that was your paycheck.

There's no withholdings or anything because of course everything is free and you get money to spend as long as you've cut those little ration coupons in order to spend it. Even then, right, the stuff's not on the shelves. The joys of socialism.

Here in the United States, we don't have capitalism in its purest form. There are a lot of limits on what can be done and what should be done. The federal government bets a lot of your money on technologies that never pan out. We could give up hundreds of millions, actually, billions of dollars worth of wasted tax money that went to various friends of various government officials, frankly, when you start tracking down the money, it's very, very frustrating to me and I'm sure to many of you out there.

So we have something called the Internal Revenue Service here in the United States. Its job is to collect the revenue, the taxes from the people. We voluntarily disclose all of the money that we make. We are paying taxes with withholdings. If we have, I have a regular salary income, right?

That W2 income and the in the cases of some of the other ways we make money, we're supposed to disclose it, right? Like I do some farming. So I had this little form that gets filled out along with my taxes. Cause I got chickens and bees that I raise and. It's just a really complicated system and it frustrates me to no end how complicated it is.

That's because we've got our wonderful legislators and rule-makers just constantly changing everything, right? It's kind of crazy.

Well, one of the things the IRS has been concerned about is I think a very concerning thing, frankly, and it should be concerning for all of us. This is also part of our cybersecurity control number 16 here, which is account monitoring and control. What the IRS has done, they said, Hey, listen, we got to find these people who are out there who are using these electronic devices and are potentially not paying taxes that are due.

Again, this is something I warned about years ago, not just because it's part of control 16, but because. It's just inevitable, right? The government wants to get its hands on all of the data it possibly can.

It's like marketing firms, right? As a marketer, you want to know your customer and you want to give them the right message at the right time. What good is it to have an ad for a Ford truck when you're never, ever going to buy a truck? It doesn't do you any good? It doesn't do the advertiser any good.

So how does the government do this and what did the IRS do? We've got a couple of Senators right now, Ron Wyden and Elizabeth Warren, who is now demanding a formal investigation into, how the IRS used location data that they got from a third party.

We've known for a long time that the Federal Government is not allowed to collect data on US persons. What does that mean? Bottom line, they're not supposed to be out there and looking at what we're doing. I think that kind of makes sense because we're supposed to have privacy. We're supposed to be secure, right? In our papers, our documents, it is part of the Constitution, which is being ignored more and more, nowadays. But anyway, so they're not supposed to be coming after our data. So they go to data aggregators. Data aggregators and I had some on my show years ago when it was first in my mind becoming a real problem. It might've been even a decade ago now, but these are companies that buy data. Some of the data is a matter of public record and you would be surprised I'm sure to find out all of the public records that are out there on you. Some of the data is private that they buy from some of these agencies that track your credit. They give you a credit score. Some of it is a property that you own. It's the state secretary of state's office. That has all of the liens filed under that uniform commercial code. So UCC one filings, all of these things. They get pushed to put together and take driver's information - driver's license information, car registration, and now they have a picture of you.

One of the things that they've added to this recently, and this wasn't true way back when I was first interviewing these guys, is the information from your cell phone. Now you might say, well, I have my location tracking turned off on my cell phone. So what are they doing? Have you played a free game lately?

To do know what a free game actually costs too, because some of these games that you download, some of the software that you put onto your mobile devices are tracking you in some places sometimes you know about it. These Fitbit watches, for instance, remember a few years ago, there was a big controversy because military members were wearing Fitbit and we're going out and running in the morning and tracking their runs and having competitions with each other, which is a wonderful thing. Then we found that it was being tracked and put onto a public website. So you could see all the Fitbit users all over the world. And you could zoom in on military bases, including apparently secret military bases where people were running around in this big oval, that was about the size you might expect from a landing strip.

So this information can be used and can be misused. Frankly, there was a real big thing too. A few years ago, they found some monitors down in Central Park in New York, and then some of the other parks, and they listened for the broadcast that comes from smartphones.

Smartphones, for instance, are they're out there trying to find wifi networks. What you can do is you can send out a wifi network ID and then talk to a phone and apparently what was going on is some bad guys were using them to track women who are jogging through central park and potentially attack those women. Again, information that you're not really thinking about, that's being leaked.

So what's happened now is the IRS and other federal agencies and state and local agencies have done this as well. The IRS apparently went to one of these data aggregators and they wanted to find where certain people were, where their homes were. So how do you do that? How the IRS wants to find phones, they want to know where you live. All you have to do is figure out where does this phone spends the night, because the phone is at your home at night, typically, right? It's turned on in case the kids need to reach you.

This week we got a phone call at like four 30 in the morning. One of our daughters was in pain on the floor in the bathroom and it was a phenomenal thing. So we don't turn off the phone. It's great having that and it was great that you could call us from her bathroom, right?

That could never have happened before, but it happened now. Her phone was at her house at night. Ours is our house at night. it is common, certainly not just talking to these cell towers. Right.

But apps that are on them could potentially be targeting us, keeping our data, keeping our information.

So when we come back, I want to talk a little bit more about this.

Because two things I want to talk about that haven't been done to help protect our information, but I also want to tie this back to the IRS again.

How far should the federal government be able to go to track people who have no criminal convictions, no history? They're just regular ordinary citizens that are out there.

Hey, you're listening to Craig Peterson. Stick around. Cause we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams. Business Email Compromises are also commonly known as Spear Phishing scams and target executives. In the past, many came from outside the US but this has changed. Next, he discusses what happened with Excel and the loss of some Covid data. Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson (2): [00:00:00] We're talking about the misuse of our data by these data aggregators. What's it being used for? What can you do in order to maybe not stop it, at least slow some of it down? What government's doing to us, frankly.

Hey, welcome back everybody. Craig Peterson here.

So we were talking about these data aggregators and what they're collecting on us. Well, the most recent stuff that they started collecting is information from the apps we're using. Typically we're talking about apps that are free apps as opposed to paid apps. While we're using them we're giving away information about our location. This became such a problem that really came to the attention of Apple and Google both now.

Google has had very kind of fine-tuned stuff for many years in Android that tells you the app wants this, wants that, wants the other thing, and frankly, that's pretty darn handy. Isn't it?

What Apple has done is, Apple has tried to make it very, very simple for you. Far fewer options. When it comes to the granularity of what an app is asking for. Apple forces these app developers to only get or ask for the absolute minimum that they need. The more recent versions of Apple's iOS and Android have built into them now, a request so that when an app is asking for access to, for instance, your location, this GPS data, it will pop up a little warning.

Apple in the latest release of its operating system it did a really nice thing. In fact, I think it was late in iOS 13, they added this, but it started reminding you every once in a while that this app is using your GPS. For instance, in the background, you want it to still be able to use it. They added it a while ago. Hey, by the way, You can just restrict it to having access while you're using the app.

So when you're looking at those little popups, come up on your Android device or your iOS device, keep in mind. Okay. What is this app for? Why do I have this app? Oh, because I want to Tetris. Why would an app that is playing Tetris need access to your contacts? Why would it need access to your location? Why would it need access to any of these things? I like the way that Microsoft has gone with Windows and Apple with its operating systems and Android, where it is giving you definitive have warnings now about what apps want.

Many of these apps still sell the information. Remember Google is in the business of selling information about you and selling your information as well. So if you have Google maps on your phone, even if it's an iOS phone, you may well be leaking your personal information to Google, and then it goes to the data aggregators.

Apparently what the Senators are worried about here is that the IRS had gone out and got data that we didn't receive under a warrant. A letter here from the Inspector General says we are going to conduct a review of this matter, and we are in the process of contacting the criminal investigation division about this review signed by Jay Russell George, who is the Inspector General. That was his response back to the Senators Warren and Wyden. So I like this, right. I like what she's trying to do here. I don't think that they should be able to get this data without a warrant of some sort. But it's happening every day and it isn't just the IRS.

It is many other agencies out there that are getting this data and that's what kind of concerns me.

So let's move on to another real problem here and this is our personal identities. Remember I mentioned at the top of the hour. This whole airport thing, right. Where we've got TSA out there and they are chartered with, let me put it that way, trying to keep us safe. I think that's a wonderful thing. We used to have airlines and airports that are paying for security. They can still do that. And in some cases they do, but most airports have TSA agents there now.

Have you noticed that there are two programs that are being actively used? You've got one, which is the prescreening. So you go, they take your fingerprints, they take all of your identity and they look you up. Okay. And they are checking public records by the way. They're checking to make sure that you buy oil for your home to heat it. If you're in the Northeast or you have an electric bill in your name and that all of the address rest all add up to gather. They check, of course, criminal records as well, but again goes back to the data aggregators and then they say this person no criminal record. And they are pretty much who they say they are. It looks like they're a decent, upstanding citizen. So we are going to l, have them this little pass.

Now that lets them be pre-screened. It's a little easier at the airport it's a little faster get through. Although now so many people are pre-screened that line is slowed down a lot.

So now there's another program that you might've noticed?

Well, there's a couple of others as NexUS and things, but another one you might have noticed, which is called CLEAR. I have a friend who swears by CLEAR because he just goes into the airport Bam he's through TSA. What clear does is it is taking your biometric information and is doing the background check that we talked about before. A real problem for getting through TSA. Right? Is it a real problem? Has it been a real problem for you? Because what CLEAR is doing is making it so that it just takes seconds to pass through TSA.

But here's what you're doing. They've got all of your personal information. They've got your driver's license. They now have your biometrics. They have your Iris information from your eye. So they know who you are. They can recognize that eye.

Think about biometric information here for a minute. If you are on locking a door, using your fingerprint, that fingerprint scanner has to have that biometric information. Many businesses, many buildings now will unlock doors based on your face. Again, biometric information. There are more advanced systems that listen to your voice. There are systems that watch your cadence as you're walking because those are all unique to individuals. That's what they're doing in China right now, too. You're wearing a face mask, but they can still identify you.

There is a problem with having this type of biometric information. I think it's a very big problem. Hey, if you go to "Have I Been pwned.com" and you find that your password and your username were leaked in a hack of a website, let's say. What do you do? Well, of course, first thing, first, you change your password and you make sure you're not using it anywhere else.

What do you do if your biometric information is stolen?

We'll be talking more about that when we get back, you are listening to Craig Peterson right here.

Stick around. Cause we'll be right back.

Of course, we're always online, Craig peterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses CLEAR and why what they are doing now is NOT a good idea. These biometric databases can be hacked just like any other database. The Danger is - there is no way to guarantee 100% security of your data and if it gets hacked -- You can't change your biometrics!

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson (2): [00:00:00] Hey, who has your biometric information? Is it really a problem? You've got your phone, you unlock with your face or your, maybe your fingerprint, your thumbprint. Where's that information all going? What is CLEAR doing now? In case you're not aware of it CLEAR is a company that has been taking biometric information and using it at airports has got about 5 million members.

You're listening to Craig Peterson. Thanks for joining us today.

Clear who are they? If you've seen the signs, you've seen the people that walk through CLEAR, either use an eye scan called an Iris scan or a fingerprint scan they're used in airports, also used in stadiums.

Well, April this year came as quite a wake-up call for our CLEAR, because the air travel industry just completely fell off a cliff, didn't it. You had the Coronavirus scare spreading worldwide airline passengers just stopped flying. It's just crazy.

Some airplanes were turned around and mid to air and sent back to where they came from. Because borders were closed at the very last minute. Then there was the grave reality that hit in April of this year because basically, nobody was flying. Revenue was plummeting, empty airports and airlines are reporting a 95% drop in travelers. Absolutely. Huge. It's crazy. Crazy to think about just how devastating it was. Not just for the airline industry, but for related industries.

Well, people hadn't been using CLEAR to travel. My friend, Dean he's sworn by CLEAR because he could just walk right in and walk onto the plane. It was that simple for him.

He also uses one of these luggage transportation services, you pay like a hundred bucks a pop and they pick up his luggage from his house they ship it to the hotel he's going to be at and he never has to touch it. He literally just walks on board with the book or whatever it is he wants. Man, am I envious. Okay.

So there are about 5 million people who paid past tense for CLEAR's service. It costs them about 180 bucks a year and they would go to these kiosks, that TSA, about 60 airports and sports arenas had these things and it verified their identity. They were able to then skip these long lines at the airport security and off they went. Absolutely phenomenal.

Well, it looks like based on a report that came out here from a company called one zero, who looked at some public records that CLEAR's income was about halved. This surprises me that it wasn't 90, 95% drop in revenue knew, but some people just kept going at $190.

One zero says that they've had a look at more than 3,500 documents and emails and they have found the CLEAR is now using the pandemic scare to pivot. What it's doing now is instead of just being at the airlines in the stadiums, they want to be the clearinghouse for biometric information everywhere. Absolutely everywhere. It wants to be the identity verification platform. Covering every moment of our lives, every day in our lives. They've already got tons of information from these public sources, from these companies that sell our information. They've also got information on people, customers who used CLEAR to buy at concessions, enter the sports stadiums, and they are now starting to explore if not already selling that data for marketing purposes. Isn't that something?

By the way, you can get a free CLEAR identity for stadiums. So you don't have to pay if you're just using it to go into some stadium. So this is very, very concerning.

I got a great article on this from one zero.medium.com. Up on my website @craigpetersohn.com. If you want to get into a little bit more.

CLEAR considers itself a platform company. They've got something, they call a health pass they introduced in May this year. It's using CLEAR's identity verification service and attaches your personal health information to the profile. This gets really scary.

Remember I said here before the break that you should be going to "Have I been pwned", I've said that many times, and if you need a link to that, just email me@craigpeterson.com. I'll be glad to send it to you. Just the subject line, just say radio show. If you go there to "Have I been pwned" and you find that your password has been breached, so you just change your password.

What do we do now, if we're registered with CLEAR? If we're a registered traveler? If CLEAR has our facial recognition biometrics? If CLEAR has our fingerprint biometrics? And on and on, and it gets hacked. You cannot change your biometrics. At least that's the whole idea, right?

I am extremely concerned about it, which is why I don't use CLEAR.

Now let's take that same question and let's apply it to our devices because we are using our biometrics to unlock the devices. Right now the Apple iPhones are the best when it comes to facial recognition, there are a number of Samsung models that have been quite easily fooled.

The fingerprint recognition on the older I-phones is quite good. Frankly, some of the Samsung models have been easily defeated for fingerprint recognition.

First off do go search on your phone model, find out how good it is? How good is the facial recognition? Because you're giving your facial biometrics to the phone. You're giving your fingerprints to the phone. What Apple has done is they put it into something they call the secure enclave. Now, last week I spent a lot of time talking about the T2 chip about TPM, these different types of encryption, and security controls that are on our laptops and on our smartphones.

If you want more about that go to last week's show, you'll find it on Craig peterson.com because I discussed that in-depth. But I'm very concerned about this.

My wife and I both have more than 10 digit passcodes on all of our devices. We use 20 plus character codes, login passwords on our Mac books, and on our desktops as well, just to try and keep it safe. Neither one of us actually trust the type of security you get from fingerprints or elsewhere.

Now, one of my sons, what he does, is he doesn't use this thumbprint. He uses a knuckle. A print on a knuckle. I know some other people that use various private parts, women, and men to identify themselves. Maybe that's a good idea. Maybe it's not. But I would be very cautious here. Be careful with CLEAR. It might be nice to be able to just zoom through the airport. It's one thing if the government has the information, but governments are losing the stuff all the time, they're getting hacked all the time.

That's bad enough but giving it purposely to these companies like CLEAR that really bothers me again, search for your phone online, and in the Apple world, the secure enclave on the phone, that's where your biometric information is kept. It is never ever sent to Apple. Can't say the same about all of these Android devices.

Stick around. You're listening to Craig Peterson and we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

In this very busy segment, Craig addresses a number of tech issues that are in the news right now. First off BEC scams. Business Email Compromises are also commonly known as Spear Phishing scams and target executives. In the past, many came from outside the US but this has changed. Next, he discusses what happened with Excel and the loss of some Covid data. Then he explains why the IRS is looking at Cryptocurrency on people's tax returns. So let's get into it!

For more tech tips, news, and updates, visit - CraigPeterson.com

---

FBI, DHS says hackers have gained access to election systems

The IRS Is Being Investigated for Using Location Data Without a Warrant

Clear Conquered U.S. Airports. Now It Wants to Own Your Entire Digital Identity.

5G in the US averages 51Mbps while other countries hit hundreds of megabits

IRS may put cryptocurrency question at the top of 1040 to catch cheaters

Publishers worry as ebooks fly off libraries’ virtual shelves

25% of BEC Cybercriminals Based in the US

What's Really Happening in Infosec Hiring Now?

---

Automated Machine-Generated Transcript:

Craig Peterson (2): [00:00:00] Well, we've got a story here about how Excel may have lost some 16,000 potential COVID cases. A little story about the IRS and really happening in info security right now. Great career.

Hi, everybody listening to Craig Peterson.

Oh, cybersecurity. IT cybersecurity, I think is a great profession. It is a difficult profession. Don't get me wrong. I talk with people in IT all the time about how it is just kind of overwhelming. How they just got this major inferiority complex in Infosecurity understandably so. There's so much going on, it's a very high-stress job.

There is a great article that was out in Dark Reading earlier this year, talking about what was predicted for security roles going forward. Due to the pandemic scare, what matters.

Six months later, Dark Reading went back and had a look at it. What they've found is it's just as tough to fill open cybersecurity positions as it was pre-pandemic. In fact, there are new problems now that I, I hadn't really even thought about, frankly. 30% of businesses that responded to the survey said that their security teams are hiring now. 45% said that they need additional staff, but are restricted by hiring freezes or spending limits. So add those two together where it's 75% of companies are looking to get more cybersecurity people. 12% said that they were recently forced to cut security staff. Which is obviously in my view, more than a little short-sighted, right?

So they went in and started looking at it a little more deeply. It's a years-old story now, and it typically takes about eight months to replace a security analyst and about four months to train a replacement. There is right now a huge shortage of appropriately skilled workers. Others are claiming it's an unreasonable set of expectations amongst employers, and that job listings that are put out there are difficult to decipher.

I think that's funny considering its cybersecurity, right? Get it - decipher. I have thought long and hard about maybe offering some sort of cybersecurity training course. That's what the cybersecurity mastery thing is all about. Getting you the basics of cybersecurity and then have a couple of phone calls a month to answer questions that people have that are in the program.

That's the whole thing behind understanding cybersecurity or mastering cybersecurity program because employers want the right skill set. There just aren't enough people out there.

The pay is very good depends on what you consider good, I suppose. Right now for a not particularly well-skilled person, the salaries are in the hundred thousand dollars a year range, Which is why statistically looking at this whole thing a business that has fewer than 500 employees with standard revenue based on how much revenue per employee cannot afford a cybersecurity team. You just can't afford it because it's so darn expensive.

You're much better to find an outsource team. That'll do it for you. It'll save you a whole lot of money. So keep that in mind.

A business email compromise is a very, very big problem. We've talked about it before. FBI is talking about all of the hacks that have occurred via BEC. I've had firsthand experience with it that is how we picked up a couple of clients. We do a cyber health assessment for one company and this company had a few different servers and some desktop machines. We did a whole, what we call an NSAAP, which is a network security assessment and action plan.

So we gave them this action plan. These machines need to be upgraded. These machines this software needed to be upgraded. These machines were not properly protected. These ports were open. They shouldn't have been right. So it was a really good network plan for them. I think it was like 300 pages long of stuff they needed to do.

Again, this was a very small company. I think they've only got maybe three or four dozen employees and gave it to them. Thanks. Appreciate it. Bye-bye. Then we got a call from them. I don't know what was it? Eight months later because they had become, I'm a victim of a business, email compromise attack.

This happens all the time now. This is where someone sends an email pretending to be someone they're not usually within the organization, but sometimes they pretend to be a vendor. One of the attacks that I know of here, that's pretty common, comes out of Eastern Europe.

Hey, Mr. CFO. They send this while the owner, CEO, the president is out of town and unreachable, and they know that because the owner posted it on Facebook and the bad guys have been tracking the company for a little while and said, Oh, he's going to be down in Bermuda. This period of time in February.

So they send an email to the CFO and supposedly from the business owner, and there are methods they use so that they can use a legitimate email address, or it looks really like it is from the business owner. The email says something like, Hey, we started using this new vendor. We haven't paid their invoices. We're three months behind unless you wire this $120,000 that is going to go away and can really hurt the company. Can't deal with this right now. Please just go ahead and wire the money and then the CFO does it.

We saw this happen to Shark Tank's Barbara Cochran. You know her from Shark Tank. She's one of the sharks, big real estate investors. Her assistant got tricked into wiring out - Was it 300,000? I can't remember. It was a fair amount of money. She got tricked into wiring it overseas.

Now the FBI tells us that once that happens, 90 seconds later that money can no longer be recovered. It just disappeared. We have clients that have had the money disappear. Of course, we picked them up after it's disappeared, right? Just like this customer that did not do what we told him he should do. Right.

Even if they did it themselves, they would have been ahead of the game. They didn't have to hire us to do it. We gave them an action plan as part of our NSAAP evaluation. Right? They lost, last I heard, actually, it has gone up, a $180,000. So they lost money right out of their operating account. It got emptied and they also ended up incurring all kinds of fees and then they couldn't deliver some things. So they had problems with customers, right.? It just goes on and on and on.

This stat is something that was a bit of a surprise for me. There's a study that was just done looking at business email compromises and found that the attacks are coming one-quarter of them from the United States. One-quarter of all of the business emails is coming from the US. Of course, many times these people are caught by the FBI and end up in prison. But of these attackers located in the US, nearly half of them are in these five States, California, Georgia, Florida, Texas, and New York. So be very, very careful.

Interesting reports got information from more than 9,000 defense engagements from this year between May and July, right? 2200 of them, by the way, they could identify the likely location of the attackers. So interesting stuff. That's a problem.

IRS is saying that they may have a question and on the top of the new form, 1040 asking filers if they dealt in virtual currency in 2020, we talked about the IRS earlier in the show today. The IRS is concerned that people are making money off of these blockchain things, like Bitcoin, and are not reporting the capital gains that they had from these cryptocurrencies. So be careful with that. IRS is starting to take that very seriously.

Then COVID, we put all kinds of systems in place because of the panics around the Wuhan virus and worry about people having the COVID-19 symptoms. Apparently in the UK, more than 50,000 potentially infectious people may have been missed by the contract tracers. How?

Well, Microsoft has a million row limit on the Excel spreadsheet. Now, if you have a spreadsheet with a million rows in it, you are misusing spreadsheet software that really needs to be in a database somewhere. Okay. That's not something to do in a spreadsheet. Apparently what they were doing in the UK is hospitals, et cetera, or we're sending in spreadsheets. We're probably doing the same thing here in the US and then those spreadsheets are being pulled into one master spreadsheet and almost 16,000 positive tests were left off the official daily figures which translate to more than 50,000 potentially infectious people running around. A great little story from the guardian.

Again, all of this stuff is up on my website. I have a great newsletter people love, and I'd love to have you on it. Where I talk about these things. We do a little bit of training. I answer people's questions. You'll find it all @craigpetersohn.com slash subscribe. Make sure you're on that list so you can stay on top of these things.

Take care, everybody we'll be back next Saturday at one.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a lengthy discussion about Hunter Biden and the legitimacy of the emails and how to tell, also about computer repair shops and then a little about Steve Scully's tweet and his lies about it. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] That is a dead give away and these news agencies such as Fox who have seen both emails, I'm sure dug into it because they said these emails were legitimate because we now have a second source.

Hello everybody. Craig Peterson here. Thanks for joining me this morning with Mr. Polito. We did a deep dive into one topic and that is because of what's happened with Hunter Biden's computer.

What are your legal rights? What can you expect? What are these guys going to do?

I even reveal a company that I know that was doing something I consider very nefarious. So here we go with Jim.

Jim Polito: [00:00:42] You know, we're going to call a little bit of an audible here with our good friend, Craig Peterson, the Tech Talk guru cause we got a lot of stuff we could talk about.

How about cryptocurrency? The IRS tracking your location with all those things. But, we want to talk about Hunter's laptop. What it would mean for you? What's this all mean? Your data? So let's bring him on board. Our good friend, the tech talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:12] Hey, good morning, Jim.

Jim Polito: [00:01:13] Craig, you're the guy, you're the go-to guy for something like this. So let me just lay it out for you. So let's say it's not Hunter Biden. Let's say it's me. I bring my laptop to a repair shop. They give me a receipt that says, look, Jim, if you don't pick it up within 90 days, it's ours. Do they, can they really do that?

Then do they own all of my data? It's one day you own that piece of it equipment, right? Because it's a piece of equipment, but inside that piece of equipment, there's a lot of data. Do they own that? So I guess that's where I'd like to start with.

Craig Peterson: [00:01:50] Yeah. It's a very good question and many people just don't pay attention to.

Apparently, Hunter signed that receipt when he dropped it off saying, yeah, you don't makeup at 90 days, it's yours. This is similar to a mechanics lien where someone comes to your home does some repairs, maybe the oil company delivers oil. They now I have the ability to, without even your knowledge, go ahead and get a lien on your property. That's valid until it's paid for.

This is the case when it comes to computers as well. You leave that computer, particularly when they bring it up to you saying, Hey, listen, you have 90 days to pay after it's repaired and at that point it becomes ours. That's pretty darn common now.

As far as the data goes, Jim, there are some steps you should take in advance.

Also, one other thing that I have heard from someone who knew this first hand that I think people need to be aware of. That is some of these shops that you take your computers into. The one I'm thinking of is one that pretty much everybody knows it's a national chain. They have little deals going on where they'll get paid, this was the case as of a couple of years ago, if you bring the computer in and one of the technicians find something, like child pornography on that computer. It may not even know it's a child right there. It's crazy what they're doing with porn nowadays, but they get a $300 bonus for every computer where they look at the contents that are on that computer and then report it to law enforcement. There's bounties on our computers out there.

Jim Polito: [00:03:44] Wow. So I do remember that so-called organization. When you bring your computer in, we won't give them any at free advertising. Not that I would support anyone that would have child pornography on their thing, but that's interesting.

So I guess, uh, you, you bring your computer over there. It's you might as well as open it up. To the stranger and say, you can, you can look at whatever you want.

Craig Peterson: [00:04:15] Yeah. You know, I had a case, I was a witness, an expert witness in the case out of New Jersey, and in this case, it was also a computer that was found to have kiddie porn on it, apparently.

Here's the problem with this, Jim. You and I, we have our computers at home and our computers at the office as well. If you're a business like mine is we have servers. Very frequently what happens is our devices are taken over. They are controlled, remotely. There are remote controls. There's a whole name for that. That called rats, which is remote access or various types of remote access.

But anyway, they have been using our computers to share child pornography, to share pictures, videos of beheadings of Americans, of burning Americans to death inside this state. I'm not even gonna get into that horrific. On our computers using our business computers, our home computers that just were not properly secured.

So things are tough and there are some things you really should do before you take your computer to a repair shop for repairs. But in reality, you never really know what's on that computer unless you look at it thoroughly.

Jim Polito: [00:05:41] So what do you think the chances are that this is really his? Have you been following the story?

Craig Peterson: [00:05:49] Yeah, I've been following it pretty closely. Cause, of course, it does intersect with my business. Where we're trying to secure things and I think from everything I've seen, particularly now that there are corroborating emails from other people that we're in those email chains. I think it's legitimate.

The way you corroborate these emails isn't just, you look at the text of the emails. But you look at the headers of the emails. Every time an email goes through a server or goes through a mail filter it is assigned a unique serial number.

Jim Polito: [00:06:23] Ok.

Craig Peterson: [00:06:24] So. Any emails, probably gone through three, four, five different servers have these serial numbers. They're all timestamped. And putting those together makes that a very unique identifier for that email.

So if two people have emails that did go through the same servers and they will have at least gone through one server, that's the same. It will have a unique email. Oh, you don't see that. Normally if you're using outlook, you click on an email, you right-click on it and say view source, and then you can see it. But that is a dead giveaway.

These news agencies such as Fox who have seen both emails. I'm sure dug into it, because they said that these emails are legitimate because we now have a second source. There may be a third source very soon now.

Once you've got those types of sources and the serial numbers and the timestamps all match up. Now you've got corroboration that these are the legitimate emails

Jim Polito: [00:07:29] We're talking with Craig Peterson or a tech talk guru. You know what Craig, why not? Why not just switch to something else? Not Jeffrey Toobin. I promise you, I won't bring up Jeffrey Toobin and his Zoom call. But let's bring up somebody else.

Steve Scully, the reporter or the anchor for C-SPAN. He wrote a direct message to Anthony Scaramucci, the MOOCH, and he thought he was writing a direct message and he actually tweeted it and it exposed him as probably having a bias against the President. He was supposed to be the moderator for the second presidential debate. But he did the old, I don't understand why they do this. It's so stupid. I was hacked.

I mean I was waiting for Tobin to say that, but he was smart enough not to. I got hacked. That's ridiculous because you could tell me in no time at all if I had been hacked and determine whether or not I was telling the truth,

Craig Peterson: [00:08:31] This is an interesting problem, right? Here he is a public figure saying that his account was hacked. It looked like a legitimate message that he might send, right? It wasn't anything outlandish. It wasn't, Hey, send me $10,000 in Bitcoin and I'll send you 20,000 back.

Jim Polito: [00:08:48] Right.

Craig Peterson: [00:08:49] Which is very suspicious? Yeah. And when somebody likes Scully goes ahead and says, I was hacked and a police investigation gets started. That's when the ball really starts to roll. Apparently, the FBI has gotten involved in this. I'm not sure if charges will be coming. It is quite easy to figure out whether or not it's been hacked. If you have access to the account and the information. So C-SPAN suspended him after he admitted to lying.

But in this case, the only place that would really know would be Twitter who has logs of the TCPIP address, the home address, if you will of Scully. Where it was posted from? Where he usually posts from? They also have information about the GPS coordinates from once it was posted. You can tell a lot of this stuff now.

I mean it's such a stupid excuse to try and fall back on.

Yeah

Jim Polito: [00:09:55] You're going to get caught in a second. You really are. There are so many different ways to catch you for saying that. It's such stupid. As usual, Craig, I know this is outside of the realm of tech, but when you caught doing something wrong, don't cover it up because the coverup is often worse than a crime.

If Scully, just comes out and said, yeah, you know, I was asking for some advice. And it was no big deal. You know, it was no big deal. It story would have ended.

Craig Peterson: [00:10:26] What happened after that. Mr. Nixon.

Jim Polito: [00:10:33] Very good Craig. All right, Craig Peterson, folks, you can catch him on WTAG, WHYN Sunday mornings at 11 o'clock with a great show. Then Danny, Steve, and Kevin, they all drop the show in when there are other openings on the weekend. But, Craig, how do folks get in touch with you?

Craig Peterson: [00:10:53] Well, if you have any questions or you want to get on my newsletter where I cover all of these topics every week. Yeah, we are going to cover this whole Hunter Biden and what the steps are you should take when you take your computer to a repair shop, just go to Craigpeterson.com. If you sign up for my newsletter, I'm not going to beat you up on anything, right. This isn't a marketer thing. I. I really want to get the information out.

So just go to Craig Peterson slash subscribe. I get questions every week that I answer. In fact, I've been putting them in my newsletter the last few weeks with the answers, obviously not exposing who you are. I'm not including those message IDs. okay.

Really a lot of great information. Yeah. You can send the question to just me. M E @craigpeterson.com.

Jim Polito: [00:11:41] All right, Craig, it's always great to have you onboard, especially days like today. Always a pleasure. And we look forward to talking with you again.

Craig Peterson: [00:11:50] All right. Take care, Jim. Thanks. Bye. Bye.

I probably won't be back to WGAN is doing a post-election thing. They've got a little election going on, so I will be back this weekend. And although this is a crazy week, so what I'm going to do is have part of the show will be fresh and new, because I got to cover these going back to the repair shop things. I also might have a couple of segments that are best of as well. This weekend.

Take care, everybody. We'll talk again soon. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. You will find here a different host this morning on NH Today. Jack Heath has moved on to another radio group. I was on with Scott Spradlin. We discussed election security in the light of revelations by the FBI and DHS about Nation-State Actors accessing our election systems through known vulnerabilities. Here we go with Scott.

These and more tech tips, news, and updates visit.

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: How vulnerable are the web pages where these final tallies are as well. So we've got now known nation-state hackers into our systems. We've got them into web sites as well, where the tallies are displayed. We've got to be very, very careful. Jack Heath has left, and now we have Scott Spradling and at least for the time being.

[00:00:23] I like Scott. He's a professional news guy reporter for many, many years, and that's who I was on with this morning. Jack has apparently moved to another radio network. So we'll see what happens with him there. Best of luck goes out to him. So here we are this morning with Scott Spradling.

[00:00:41] Scott Spradling: You've heard me on with him before, but I think it's been a little while. Let's talk a little bit about what the FBI is doing and how technology might be used to protect our elections' integrity. Craig Peterson from Tech Talk joins us now on the air.

[00:00:54] Good morning, Craig. How are you?

[00:00:56] Craig Peterson: Hey, good morning, Scott. And as you may know, I've been involved with the FBI for some years now. In fact, I ran there and their entire webinar program for what they call Infragard. And InfraGard is trying to get regular businesses all the way through government agencies, whereof what's going on out there.

[00:01:18]We've got a new one that just came out on Friday. It turns out that the FBI and the Department of Homeland Security have now confirmed that hackers and, in this case, nation-state hackers, which means countries like China and Russia and Iran, and maybe others, including North Korea, have gained actual access to our election systems.

[00:01:42]They went in, and they would use multiple vulnerabilities to get in over something I've been warning about on my show forever, and that is misconfigured VPN. So this isn't going to help matters.

[00:01:56] Scott Spradling: So how many States, and this is not a fair pop quiz.

[00:01:59]Approximately how many States have a lot of their voter type information or access to the totals electronically that are vulnerable. The reason I ask is that if nothing else, Bill Gardner has a system that is in my mind, largely offline. Cause if the electronics go sideways, we've got paper ballots as a backup.

[00:02:18] So we can hand count if we have to in New Hampshire and assure a good election result. Are a lot of States moving more towards paperless and then being vulnerable.

[00:02:29] Craig Peterson: Well, Justin brought up, of course, the year 2000 in the wonderful times we had passed then. That really woke up a lot of States. Many of the States are using that same system that Bill Gardener's using here. It's phenomenal. It's the only way to go, which are you fill out a paper ballot? It goes into a machine. It can be spot-checked to make sure the machine looks like it's accurate.

[00:02:53] Where the problem has been coming in that we're most worried about here is Scott, because so many have moved to that, is how the votes are finally tallied.

[00:03:02]In many States, what they do is the federal government go to the state's webpage to collect the totals. The question might be asked how vulnerable are the web pages, where these final tallies are, as well.

[00:03:19]We've got now known nation-state hackers into our systems. We've got them into websites, as well where the tallies are displayed. We've gotta be very, very careful. I, too, have heard Bill talk about what they're doing, and I think we're in pretty good shape. But we've got to pay a lot of attention here because the hackers really are after it. They're just trying to upset our election.

[00:03:44] I think they might be successful. Not to mention all of these other potential problems that are out there.

[00:03:50]Justin McIssac: One of the freelance jobs I used to have was going around and collecting election results from different towns in Rochester and then calling them into the AP.

[00:03:56]The way in New Hampshire works is. You get the fill in the circle thing, and you feed it into that machine, at the end of the voting cycle, that spits out a receipt, like an actual receipt telling you who got what.

[00:04:08] So almost like here's a real deep cut for sci-fi dorks. It's almost like an Admiral Adama situation where he had the Battlestar Galactica offline so the Cylons couldn't hack in. We don't have to go that far. Do we, Craig, take everything completely offline? If we have those types of backups with a physical paper printout, or what do you think?

[00:04:27] Craig Peterson: I think that's a pretty good way to do it and keep those ballots around and allow people to inspect them. I don't know if we have to go totally Admiral ADAMA on this. I am concerned that we have 50 individual state elections, and every state's doing it differently. Every state has different competencies, and that boils all the way down to what you were talking about, Justin. It's really the towns that are doing some of these tallies. I get a little bit worried about those things. Final tapes in some States they're using these touch screen devices, and then it spits out a little audit trail that looks exactly like what you might get at the grocery store. Those things fade over time. If someone leaves them on a dashboard, they will go black.

[00:05:11]I have a little less worry here in New Hampshire than I do for other States. Scott started by talking about what's going to happen nationwide. Will we know by that deadline on December 14th who the President is?

[00:05:24] I am very, very concerned because of an over-reliance on technology. These systems are hacked by the FBI and Homeland security. All of the hacks that happened. We're using software that had patches out. These were sometimes known four months and a couple of them for more than a year, but the local States and towns did not bother applying. So it's a real problem.

[00:05:52]Here in New Hampshire, we're great. We have these devices, and they are loaded with ROMs. One of my sons is a ballot inspector. He went and physically looked at the machine, although there were a couple of problems with the machines used in his precinct, the final device, a little memory stick, if you will, that's inside, that machine did have the right seals on it. It had not been tampered with when he checked it. So I like what we're doing.

[00:06:19] I think we got to pay a lot of attention.

[00:06:21] Scott Spradling: Good final thought. Hopefully, technology and paper ballots will combine nicely for a clear result with no debate by the time we're done at the end of election night, or at least within a couple of days. So we'll see.

[00:06:33] Craig Peterson: Yeah, that'll happen, Scott.

[00:06:34] Scott Spradling: I like it. I like your optimism. Craig Peterson from tech talk. Thank you so much. My friend, I appreciate you being on the air with us.

[00:06:42] Craig Peterson: Take Care. Saturday 1130. I'll be right back here.

[00:06:44] Scott Spradling: Excellent. We'll see you then. You're listening to New Hampshire Today.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses a new Phishing Scam that is targeting Republicans with a legitimate email but that adds an attachment with a nasty trojan payload.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hi, everybody. We're going to be talking about some new Trojan malware that targets Trump supporters. Some new tools that are out there. Ransomware being paid by one of the country's biggest online providers right here.

Hey everybody. I'm Craig Peterson. Today we are going to with no exception, get into some of the things that you need to know. Some of the things that you might not really be aware of, you've always wanted to know, but I'm here to explain it to you. This is the sort of stuff I like to do, and I've done pretty well for many years.

So let's get right into this malware. We've talked about phishing before and for a quick introduction for the rest of you guys, phishing is where someone is trying to get you to do something and they are just trying to trick you into it.

So you might be familiar with some of the old phishing staff, the Nigerian Prince scam nowadays, they've gotten much more sophisticated, try and get you to click on a link to do that something. So they might be phishing so they can put a Bitcoin miner on your computer.

They might be phishing to do something malicious, maybe. very malicious right now. There are some bad guys out there who are phishing Trump supporters. Here's what they're doing.

They're taking legitimate emails that have been sent out by other Trump supporters. Some of these political action committees. That is really single focused on one thing or another, and they'll be supporting a candidate that supports their, so there's these PACs on both sides of the aisle and all the way in between. All right.

The biggest problem, if you ask me about DC is, that's where the money goes and so that's where all the attention goes.

So you're online. You're looking at your email and you see an email that has a subject line that starts with forward. I got to point out in case you weren't aware of it, subject lines that start with forward, like FWD colon, or re R E colon, as in regards to. Those subject lines tend to attract a lot of attention. The only subject line that tracks more attention is if someone has your name in that subject line.

So these emails that are being sent out by, we're not sure who yet have. Forward or re: up in the subject line and, we'll talk a little bit more about what is in that subject line. So there are things like breaking President, Trump, suspends funding to the WHO that is one of the most common ones they're using right now.

Of course, we're looking at President Trump and he's been calling the world health organization corrupt and seen an email like this would get you to open it. Wouldn't it? You know what, frankly, between you and me, so would people on the other side of the aisle, right? Cause they want to hear what's Trump doing this time.

So the idea, yeah, it is it's political. Another one is an email with a subject line that says stand with Trump again, that's definitely targeted at Republicans who want to open it because they want to stand with President Trump. And they're also using something called display name spoofing.

If you look at emails, you receive, you'll see, it says it's from so and so. Well, that's not necessarily who it's actually from there's some spoofing you can do there and a lot of these guys are doing it. There are ways to block phishing. Phishing, by the way, it's used a lot by ransomware. That's not what this is. We'll get into what this is exactly a minute.

But you've got to have some really great stuff in place. Hey, if you're interested in it. our friend of mine, Guy, he had sent me a thing on LinkedIn this week about that's a really great little ransomware checklist. It goes through the basics of what you should be doing to protect yourself against ransomware.

And if you want me to. I'll dig it up for you and send it off. Just email me@craigpeterson.com and in the subject line put ransomware. I'll notice that. I will, I'll send it to you. Just send it to me@craigpeterson.com. And it's a great little checklist on ransomware, and it's telling you should be doing things if you are a system administrator like looking for specially signed DNS records and other things that are going to help identify the reality of who they're talking to. Very important. DMark is one of those types of tools.

Now they are also using hijacked legitimate, the email addresses, and they'll use those to send out these emails. So they'll take an email from a PAX, a legitimate email. They will forward it, quote-unquote to you. It looks like a foreword for all intents and purposes. It is, and it has all of the links in it that the original email had and all of those links, some, the original email will work and they'll take you to the places that you expect to go to. The problem with this one is that they have a word document attached. Not that having a word document attached isn't necessarily a huge problem. We've had problems in the past where it was effectively a drive-by download. Sometimes you did not even have to open the email in order to get the infection nowadays unless you have very out of date software nowadays, you do have to open it.

So if you get that email, you click on the attachment. You open the attachment. That's when the real pain starts, because inside that attachment is a Microsoft word document that has something inside of it called the downloader. So you open up that document down comes EmoTet and once Emotet is on your system, that's when it all hits the fan.

What happens with EmoTet is really nasty. It starts to try and spread within your network. It scans for open services. I'm looking at a whole chart here on EmoTet which is known as S zero three six seven. It'll start to scan ports on all of the systems on your network, on your own system. It uses the most common ports that you might think of port 80, 80, 84, 43.

In one instance, it has used. port four, four, five, which is an SMB exploitation. SMB is windows file sharing. So it uses a number of different types of attacks here to go after services that are available on your network, on your computer, and on your network. And then it spreads laterally and it starts to scan other machines.

This is where EmoTet is different than some of the others. It acts like a worm. And that's the very first piece of malware I had. That's what got me going on cybersecurity. Cause back then, I'm pretty much, nobody had even heard of a worm before.

What a worm is for those that don't know. Is it some piece of software that gets onto one computer and tries to crawl through other computers all the way out?

Now you can see where the problem comes in because it now will try using all of these different protocols, try and get onto another computer. Now we can get on another computer as simple as getting onto your file server.

Are you using the VPN in your business operation? A lot of our people are at home. This is one of the real dangers of VPNs. VPNs do not make you safer. Don't think that they make you safer because in almost no cases, do they help with the safety. What's gonna happen with the VPN, if you're connected, is something like EmoTet or some of these others that spread like worms are going to try and crawl through your VPN to the other side.

You say, Oh, we've got a firewall quote, unquote, in the other side, We've got a SonicWall, we've got whatever it might be.

Is that configured to stop a worm from crawling through and getting into other machines? And you might say, Yes. Yes, of course, it is. We block out all other servers that user at home only has access to the file server and their own computer acting as a file server isn't that just hunky Dory. The problem is it has access to the file server. Your typical ransomware even is going to start pulling files off of the file server, sending them over to Eastern Europe for examination to see if they can use it for extortion or to see if they want to use it for ransom, just hold the encrypted and hold your data ransom. All of that stuff can happen over your VPN. Just as if you're sitting there locally at the office.

Remember that you've got to have all of your security, not just in the office, not just maybe at the edge of the firewall, but everywhere.

We're setting up systems now, that one packet will be examined five times as it flows through different firewalls within the organization. So that someone who's sitting there working on something is going to have to go in and out of firewalls just to get to that server.

It's not just the packets that are examined nowadays. We're talking about having the data examined, completely reassembling the streams, and looking at it and looking at it all very closely.

Hey, you're listening to Craig Peterson stick around because we will be right back. We're going to be talking about a new scanning tool release and what that's all about. So stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses one of the security tools he uses and why you should use it too.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Remember everybody, don't open those email attachments. I'm going to talk about a new tool released out there that if you're involved with security, you probably need it. So here we go.

Hi everybody. Craig Peterson here.

I want to talk right now about this great tool that I've been using for decades now, I think. It's called Nmap. Now it's something that I cover. In my cybersecurity mastery course, but it's something you can do to learn a lot about yourself online. There are YouTube videos about it and many others. But the idea behind Nmap is to be able to check and see what's on your network and not just what's on your network, it'll also tell you about what that particular device is, and it just does a whole bunch of things for threat management. It'll check ports. Some of this stuff can go so far as to actually try and break into the systems. Now, Nmap isn't designed to do that. It really is using fingerprints to figure out the operating system that's in use, which is really handy.

Particularly for the internet of things devices that might be attached to your network.

This is great for home use, as well.

If you're a little bit of a techie, they have new protocol libraries. They've got payloads. Now that they've added for host discovery, port scanning version detection, which is really important to make sure that you have the latest version of different software on your systems. So you're not running something outdated.

They've fixed a whole bunch of bugs. They've got some different improvements and code quality improvements. But one of the biggest things is that they're using a new driver for raw packet capturing and sending out on the windows side and the Unix side it's been stable forever, but on the windows side, there's never been a really great way to do this.

There's something called WinPCap, but that driver has not been updated in the last seven or eight years. It doesn't always work on windows 10. It's using deprecated Windows APIs.

I know this is a lot of. TLAs write three-letter acronyms for everybody out there.

But bottom line, there is a new driver that lets software like Nmap send and receive its own packets it creates.

Normally if you are writing just regular old software where you would open a network connection to a server and then speak whatever protocol you wanted to. You would ask the operating system, Hey, open up a TCP session on port 82, this web server, and so on that remote server. Obviously, I had to get them an IP address, ultimately on that far server.

There's a web server and it's listening for requests on port 80. That TCP session requires five packets going back and forth, and then it's established, and then you send your get requests. So it would be like getting space HTTPS slash one dot one or whatever it might be. Whatever version of the HTTP protocol you're trying to use space. then the file you want and the server name. Then the remote server responds. It goes back and forth. There are a lot of packets that are exchanged between your computer and the remote computer, whether it's a web server remotely, or might be a file server remotely could be almost anything remotely.

There's a lot going on if you're trying to do diagnosis on the network, if you're trying to figure stuff out, you want to get down to that level. Really.

Remember I said, though, that the initial TCP session took five packets in order to set it up. That takes quite a bit of time in internet time because those packets have to go back and forth.

Google, in fact, came up with a new version of the protocol that requires less handshaking going on.

Software like Nmap that is going to connect to that web server itself wants to see all of the packets. It does not want the operating system to be sitting there, setting up the connections, and sending the data back and forth. It wants to do it.

That's the whole idea behind the raw packet capturing and creating is all about. On, the Unix world, which includes Linux, Mac OOS, solarise BSD they've had great packet capture. Code running forever, but this is brand new for Windows. So if you've tried it before and it didn't always work, try it again. Nmap N M A P online, just do a search for it, or you can download it from the Nmap.org, N M A P.org.

As I said, this is one of the tools we teach and answer questions about in my cybersecurity mastery course, because it's just so important. So Nmap is basically a command-line type program, but there's something called Zenmap that you can get as well as right there on the Nmap.org site that gives you a graphical front end.

If you would like to tinker you probably we should grab it and download it. It's already compiled. Although you can get the source code for you can also check signatures, GPG, signatures, and SHA one hash is for the different releases they've got install, guides, everything. They try and make it very easy for you.

The idea is once you have it there on your computer, You can then go ahead and run the latest release, which is right there on the homepage again. Nmap that's November Mike Alpha, Papa N M A P.org. You can just download it from right there and you're off and running. It is very handy.

So you run it against your network. It's gonna come back now and show you a whole bunch of information that you need on your network. So there are penetration testing uses, Nmap defense, of course, uses Nmap. There's a bunch of stuff. Password audits, vulnerability, scanners, just all kinds of stuff that you can use right there. On the Nmap.org site. This is going to take you off-site.

Now, if you're on a Unix distribution, like a Linux distribution, You can just grab RPMs for your distribution, whatever it might need be. If you're on a Mac, I think brew has it use brew. That's what I use all of the time for managing third-party software. Like this open-source stuff. It'll just download and install it for you, which is really cool.

Use the least concept of least privilege. Which is what you really want to do.

They've got a, they've got a reference guide that's showing you absolutely everything.

There's an SSH service that it discovered on this machine. It's going to tell you which version of SSH it is. It's going to tell you what the operating system is. It's going to give you a key that you can use now to distinctly or uniquely, I should say, I say, identify what it is.

I'm looking right now at a scan and it's showing me there's an SSH service. That's what I use in order to connect remotely to a computer and do command line stuff. It's showing me that there is an open Apache server, which is a web server. And it even tells me the version it's HTTPD protocol, a 2.2 0.14 running Ubuntu. Very handy stuff, because you can then feed this into other tools to know.

Is it up to date? Do I need to do updates? In fact, this Nmap stuff is used as the basis for the code that uses. Cause we'll use Nmap, it'll do scans, it'll find stuff and create a database. Then we take that database back.

If you have us do an audit for you, for instance, you give us the database. We don't even have to run the software. You just run it. It does all of his scans, puts it in a database. You send the database back to us in a zip file. We run it into a whole bunch of process software that lets us know exactly what's going on and also compares the versions.

Check it out. Nmap. November Mike alpha, Papa dot org. Absolutely valuable tool for everybody.

Hey, we're going to talk about paying ransoms when we get back in and what Tyler technologies did and why. So stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses why State and Local governments are getting ransomware and who is actually at fault.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, Tyler technologies, you might not have heard of them, but you've almost certainly use them. And we'll tell you why they got nailed by these human-operated ransomware pieces that are floating around there as part of phishing expeditions. Here we go.

Hey, thanks for joining me. This is Craig Peterson of course.

Tyler technologies, you might not have heard of these people. They are the largest provider of software to the United States public sector. At the end of September, Tyler technologies disclosed that they had been nailed by a ransomware attack.

Its customers, which are public sector companies, Or not obviously not companies, but organizations like towns, counties, States, it's customers reported finding suspicious log-ins and. What is called the RATS on their networks? A rat is a remote access tool. Remember I've told you how we found Chinese back doors on networks, time and time again and we continue to find them. Those are rats. Those are remote access tools.

What happens is your network gets infected bad guys, gets onto your computers and they install software that gives them remote access. Isn't that just phenomenal? Oh, we have the majority of states here in the country that are using Tyler technology services and software. Some of those, at least I have found remote access tools on their networks. That is a very bad thing apparently.

According to security affairs.co, apparently Tyler notified law enforcement about it. It took place on September 23rd and they brought in a forensics firm to investigate the incident and trying to figure out what did the bad guys get.

That is a very big question. Did you know that if you are a business, you are required to be able to figure this out? Under certain federal contracts or DOD particularly you are required to keep long-term logs. Those you have to have logs of everything that's been happening on your network for the term of the contract. I think it's plus three years, depending on the contract, that is a long time.

That's a lot of logs gets pretty expensive, pretty fast. When you're a company like Tyler technologies you'd think they would have some absolutely amazing logging software. But do they? No. No, of course not.

I see this all the time. We've got to be careful people. We've got to keep the logs that come in from our firewalls, the logs on our computers. They need to be basically vacuumed up and put into a database for at least a few weeks so that an investigation can occur. If something were to happen.

One of the things that we've got to keep in mind too, is that from the time the machine is infected until the time they are moving around in the network right now is about a week. You have five to seven days to notice that you've been infected and to shut it down before they start expanding.

So having a few weeks worth of detailed logs of everything going in and out of your firewall and everything going on your computers can quickly Put an end to the types of hacks that Tyler experienced.

As I said, depending on the regulations you're under, you could be in trouble. I had probably about a dozen people this week asked me for my audit kit. So if you'd like a copy of my audit kit, if you are in a state or a local government, or you are in business, I have an audit kit that covers everything, all of the major stuff anyway.

FINRA requirements. If you are a financial organization dealing with personal information, identifiable information, et cetera, just send me an email in the subject line. Just say audit. Kit. I'll email one out to you so that you have that I'm not charging for any of this stuff.

It is a checkmark thing. This thing's over 300 pages just long. Okay. It has all of these different standards in it, but it's something you can use. You can sit down and go through it with your IT provider or your internal IT people.

Or you can sit around at the conference room table with your senior managers and go through it because there are different sections in it.

So the very first section is just general high-level stuff to make sure that you're going, to have general compliance. And then it gets right into the national Institute of standards, technology stuff, the NIST 800-171, and some of the other sections that are needed. So it even goes to absolute detail here bit by bit if you want that.

So I can send that to you if you want. I'd be glad to. It's a PDF. I found a lot of people had it bounce, though. I think the majority of them, cause it was a huge and like 20 megabytes, which is crazy. So I compressed it. I use PDF Expert on my Mac to compress it down to about 12 megabytes, which is still too big to send by email.

As a general rule email shouldn't be used for anything that big and by the way, a lot of email filters we'll assume if it's a big piece of email, a big attachment like that it's malware.

I'll probably just send you a link to my Dropbox account so you can pull it right out of there when you want. Anyhow, that's just me, M E at craigpeterson.com audit kit. Be glad to send it to you.

It's useful for home users as well. You're not going to, of course, delve into all of the more detailed stuff for specialized businesses, but you are going to be able to have the nice high-level stuff that is going to help you out.

Immediately after this attack friends over at Tyler technologies said that the incident only impacted the internal network and phone systems. Yet, it looks like they got the ransom X ransomware. This is human-operated, ransomware. This is the type of stuff I've been talking about.

It's a RAT. It's remote access. It allows them to get in, like a Chinese back door. With human-operated ransomware, they get onto the computers and they start poking around.

Back in June this year. Ransom X again was used in an attack on the Texas department of transportation. In September effected systems over at IPG photonics, which is this high-performance laser developer. Bleeping Computer, which is a great site for keeping up on some of this stuff is also talking about now how Tyler technologies paid a ransom to receive the decryption key and recover encrypted files.

Now you might ask yourself, how do they figure out what ransom they should charge, right?

A home user's not going to be able to afford the same ransom that a city can afford and just ask Atlanta. How many times have they had ransomware and paid ransoms and been down for months, some of their systems, just crazy. They do it with this type of ransomware, where you've got a human-looking around figuring out what is this? Is this a business? This, a home user. Okay. So we'll charge them a couple of hundred bucks. Oh, this is a city. So let's spread laterally. Let's poke around. Let's see what the weaknesses are in their internal networks.

Remember I said earlier in the show, that we run sometimes through firewalls here at five or six times, that's called ZeroTrust and that's to stop these attacks. We gotta be able to stop them. We absolutely have to be able to stop them.

All right. Crazy times we live in, you're listening to Craig Peterson.

I'm feisty stick around. Cause coming up, we're going to talk about the five G in the U S of A.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses 5G and explains how it works why what you may have heard about 5G speeds might have a bit misleading.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Are you as excited about five G as I am? I got some good news and I got some bad news and we're going to explain 5g here because five G, isn't five G, isn't five G. Why is Europe so much faster?

Hey everybody. Thanks for tuning in. You're listening to Craig Peterson.

five G held open a couple of different promises. One of the big promises of five G was that it could handle way more devices than 4g can handle.

It isn't just because it's using IPV six. For those of you who are a little more technical, five G is designed to handle microdevices by the billions. So we're talking about having your coat, for instance, hooked up to the five G network. You might have the new Apple watch six and that Apple watch six has built into it a cell modem. Exactly. So it doesn't need your phone anymore. Your iPhone, it can talk directly to the cell towers. It can take a phone call, can send a phone call. Let's just like Dick Tracy. You can even have videos, so cool. You open up your camera and you can see what your camera sees right there on your watch and you can control your camera. I am just so impressed by it. It Is such a cool device as well as being just an amazing device for tracking all your health, but I digress.

So in the five G world, the idea is that you could have millions of devices, just the Apple watch, which is not 5g by the way the watch six is not 5g, but you could have millions of these devices in the 4g world.

It was never really intended to, for an individual to basically have a couple of dozen or a few dozen or more devices. To start thinking about it, you've got a smart car. It could have one or more five G modems in it so that it can call into the dealer in advance and say, Hey, I'm having this problem that you could have a technician diagnose it remotely, which is already happening, Then you have your, Levi trucker jacket on, which is also getting the weather report. To know if it should be heating itself up charging itself, you're just everything. You name it? I'm just, I'm thinking about all the devices. You won't in the future be able to buy a laptop that does not have internet built into it that doesn't need wifi anymore. The other side of five G when we're talking about not needing wifi anymore is the speed. Five G is promising up to gigahertz bandwidth, which is wow. Gigabit bandwidth is absolutely amazing. How fast is your internet on your phone right now? So what you can do is on your phone, or even on your regular laptop, desktop tablet, whatever. See if you can find an app called speed, test.net speed test.net and not just the app, but see if there is just the website. So if you're on a regular computer, I can just go to the web, and then at speed test.net, I'm going to pull it up right now. Speed test. I have that right. They're actually on my phone.

So it's by. and they'll go and try and find the optimal server, and then you can hit the go button. So now it'll connect to that server. It's going to download some big files and it's going to upload some big files and it's looking at a couple of different things. It's looking at ping time, which is how fast it can get from you to the remote server and then back and that's in milliseconds. Typically it's also measuring jitter and jitters important if you are using it for video conferencing. So if you've had problems with the phone that kind of breaking up a little bit sounding were dropping. That's probably a jitter problem. Speed tests will tell you about your jitter and w how much loss you've had, how much data loss, how many packets just did not make it to the other end.

So I'm running it right now. No. I don't want you guys to get upset with me, but I've got fiber lines coming in here, dedicated fiber business fiber lines. So my phone right now is showing a download speed of 229 million bits per second. So 229 megabits upload of 236 megabits. So that's called symmetrical.

It's basically the same speed. Up as it is down. A lot of us, if we're using cable modems, we'll have something called asymmetrical and our work upload speed will be about a 10th of our download speed. That's absolutely normal and sometimes it'll be faster than that, but these cable modems and some of the other services are designed for basically for web browsing. When you look at the TCP protocol overhead, it's about the same as that, about 10% up versus your downloads. So three milliseconds, Andy is my pink time, which is really quite fast. I remember for my first ethernet networks, we had 10 megabits thick wired ethernet. And I'm trying to remember, I think a hundred milliseconds was wow on a local network.

So this is three milliseconds and my jitter is 0.23 milliseconds. So excellent lines. And these types of speeds that we're talking about here on fiber for me are the types of speed that they want to get to with five G. Think about that, think about being able to get these quarter gigabit or all the way up to gigabits speeds just on your smartphone or your laptop or your I pad or your car or whatever it might be.

That's the other big promise of five G right? There's a company out there called open signal and I'm looking into some of the five G's statistics. They checked average speeds in a dozen countries. These are based on people going to like speed test.net type stuff. It's just, it's not a great sampling.

It's people who self-identified right. Put up their hands. Yeah. I want to be involved, but these were conducted between May 16 and August 14. So over the course of a few months, And the United States came in deadline last of the 12 countries in five G speeds with 10 of the 11 other countries posting five G speeds that at least doubled those of the US. So the question is why is the average five-speed in the United States about 50 megabits per second. Okay. Why are these other countries out more than a hundred megabits? A second? it has to do with the providers who are the providers that actually have five G here in the US and which of those providers are able to have a big enough footprint that people can relate.

Tested. the only provider that pretty much has coast to coast, five G right now is T-Mobile and T-Mobile's a company that I use and it's not the best for general coverage, is up in Lincoln, New Hampshire here last weekend and there are a lot of areas where I had no coverage. Verizon has a lot of coverage all over, even in some of these weaker areas and they tend to be more expensive.

M,y T-Mobile plan is a business plan. And then I don't get paid by any of these guys on getting kickbacks nothing. Okay. Okay. So what you're getting from me is my absolute truth here. What I have seen well, Teen mobile is using a lower frequency that is being used in these other countries like Taiwan, South Korea, Saudi Arabia, who had some of the best speeds out there, and Australia as well.

And remember, these are self-selected people, right? These are people that know they have 5g. They tend to be a little more techie, which means they are probably in larger urban areas. That's where the problem starts coming in. T-Mobile's 5g at a lower frequency, more easily penetrates glass and walls, right? Wood walls, drywall, et cetera. That's typically what I want.

Versus Verizon, that's running at much higher frequencies. And last I checked, I think they were suing because they were upset that the FCC sold and gave these frequencies to T-Mobile, but they are running on much higher frequencies, which means they can deliver higher bandwidth because that frequency gives them the ability to have a lot more variants in their signal, which ultimately translates into more bandwidth for you.

Now, I have an advanced class amateur radio license if you've listened for a while. And so I studied this stuff and I know a fair amount about it, frankly. I was one of the first people involved in packet radio here in the United States, way back when I still have some old equipment. So I, this is stuff that I know about. So the Verizon just signals cannot pay trade as well, which means they're going to have even. More cell sites in the five G world.

We're not talking about cell sites that are on these huge towers. As much as we're talking about cell sites that are mounted on buildings and even homes all over creation. Verizon's other problem right now is they don't have a whole lot of coverage. They've got five G coverage in some major cities and even then it's only in some areas of those major cities.

So once Verizon's totally rolled out, if you're living in a fairly populated area, you're probably going to get a faster data path through Verizon, then you'd get through T-Mobile. However, with T-Mobile, you're going to be more likely to have a signal pretty much anywhere because the T-Mobile signals also go further because they're lower frequencies.

So think about that. People my age. Do you remember am and listening to am at night and you got the bounce off the ionosphere and is really cool? You could listen to somebody on the other side of the country and sometimes even on the other side of the world. It was so cool. I still have short wave radios I listen to.

It still blows my mind. It's something I've loved since I was a little kid. I and made my first little cat's whisker radio, crystal radio way back when.

So that's, what's going to happen here. We'll see how things actually end up flushing out. But the other side of this is based on the type of phone you have, you may be restricted to a specific carrier. So we're going back to the old days. Because the frequencies are so far apart and the less expensive phones they're going to be dedicated to certain carriers. So keep that in mind as well. When you're looking to buy your new phone.

All right, stick around. We are going to be back here. We're going to talk about an unfixable flaw that Apple has this hardware security where it's going. Verizon sent out a new wake up call, Android malware, some new tricks on that front, and you can find it all online@craigpeterson.com.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig helps to unravel the mystery behind disk encryption and tells you what you need to know.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, welcome back in this hour, we are going to be talking about security, hardware, security. You might not be aware of it. we're going to be talking about trusted platforms and hardware, encryption, and keys because this is the only thing that's really going to protect you.

Thanks for listening. I'm Craig Peterson.

Let's talk about that security. That's what we're going to kick off this hour with. And we're going to get into our new Verizon security report on payment, and then we'll get into some Android stuff, but. We had this week and announcement here. And this is about Apple. Apple has built hardware security inside most of its devices that includes the iPhones and include your Macs and Mac pros. You name it, really the iMacs, the Mac minis. They all have the hardware. Inside of them to help provide security. Now in the Apple world, it is a chip that Apple makes it's called a T2 security chip, and that makes sure that people cannot get onto your computer.

The whole idea is if they have physical access to the computer, they cannot get inside. They can't make it boot off an external drive. They can't do just a whole ton of things get real deep system access. Back in the day, you used to boot off of read-only memory. Or proms, programmable read-only memory, those BIOSes that was in so many of the consumer pieces of equipment out there, and even some of the prosumer stuff that many businesses use. Those BIOSes were really cool, but they weren't secure at all. The hard disks that machine could easily be removed and put onto another machine, they didn't even have to be booted up. You could just have another machine of a, for instance, my Mac, I can take a disk from a Windows computer. I have a device sitting there that's hooked up full time. That allows me to just plug a hard disc. just, you just slide it, And while the machine is up and running and it will Mount that disk. And let me do whatever I need to do investigative work or whatever, it might be very cool devices.

I can have two of those disks that I just plugin. I also use them for my video, where I am recording directly to SSDs. I move SSDs around, which is much faster than trying to push them over gigabit ethernet. So Apple has decided that this T2 chip is a good thing and it uses the T2 chip for a few different things.

Once we're talking about your hard disc itself, the newer hard disks at the higher end and have the ability. To encrypt the data on the disc, which is, it's good. It's great. But that data that's encrypted on that disk can be read by the operating system. And that's the whole idea, right? If you can't read the disk, what good is it for you?

So any data that's stored on that encrypted data is still available for your programs and is still available for hackers. So the disc encryption I'm talking about right now at the kind of the low end of all of this security stuff. It's designed so that when your computer is life it's over, or maybe the hard disc crashes, there's a little jumper that you can pull, or maybe there are the jumpers you short out on the disk.

Just look it up online, do it. In fact, go search for your disc model number and you pull that jumper or you short out those terms and what happens at that point is your disk is now complete. Erased, but it's not really erased. It's like your iPhone. Have you been to the Apple store? You're trading in your iPhone.

You want to get a brand new iPhone? Isn't this great. They have you turn off. Find my iPhone. That's the first thing they have you do. And then they say to erase the iPhone. And have you noticed it takes what? Five, 10 seconds. To erase the iPhone. How can you possibly erase hundreds of megabytes or gigabytes of data in five to 10 seconds?

You cannot. So what's happening inside the iPhone is similar to what's happening with these basic encrypted disks. Okay. Everything that's written to these disks and everything written to your iPhone is encrypted. So if you want to make all of the data that's on that disk inaccessible or basically useless.

All you have to do is destroy the key that was used to encrypt it. So think of a door that cannot possibly be breached and a key. There's only one key. You can't pick the lock. Okay. Oh, maybe this isn't the best of analogies, but if that key is destroyed, it's impossible at that point on to open that door.

It's not like a real door where maybe you could take blow torches to a metal door or something right there. You can always get in, but it is completely effectively destroyed. The data that's on that device. If the encryption is good, looks like just random data. There's no difference between completely random and.

It has everybody's social security number, income, and addresses in the whole United States encrypted on it. Okay. So that's the low end. On your iPhone. When you go ahead and you erase your iPhone when you're trading it in or. If you have one of these encrypted hard disks where you just pull that jumper, it now destroys the key.

That key now in both cases makes that disk, the data on the disc useless. Now that's cool. And the next time that disk is powered up, it's going to generate a brand new key and it's going to be hopefully pretty darn random. And now you can use it again, assuming the disc isn't bad. if you took it out, cause it was just totaled.

So that's a very basic layer, but just like your iPhone, that encrypted disc has data, that's readable on it up until the time that you destroyed the data by destroying the key. You're with me so far. That's the very basics of how this all works. Now there's something called TPM, which stands for trusted platform module.

This is an international standard that's been out now. It is a standard that describes a secure cryptoprocessor. That's what Apple's T2 security chip is all about. Now, the problem that came up this last week, this week, in fact, is that there is a flaw in Apple's trusted T2 security chip. And it's the flaw that apparently researchers have been using for more than a year to jailbreak older models of iPhones.

We've heard I heard about this. We've heard that the FBI was able to get into iPhone and get at the data that's in them. There are well, there's one primary company it's over in Israel that sells a device that lets the police break into iPhones. I'm just talking about iPhones right now. Many of the Android devices are very easy to break into as well, but Apple is really trying to make these things secure.

That's why they came up with this chip of their own, which is really a kind of a trusted platform module. So they have been using this flaw in order to jailbreak into the iPhones. And the way that this T2 chip is vulnerable is a problem. And the slightly bigger problem is that this particular problem is ultimately unfixable.

In every Mac that has a T2 inside, that is a lot that T2 chip launched in 2017 and it created some limitations. Many people have used macs to run Linux for many years. It's a great little Linux computer. We know that PC magazine had on its front cover or was a PC world. The cover said the best PC for windows is a Mac because they were just that solid. But because of the T2 chip, when it was introduced in 2017, all of a sudden problems started to arise for people. they effectively hacking their Macs.

Apple added the chip so that it had a trusted mechanism to secure the device. The biggest reason for adding this chip or a TPM, this trusted platform module, which is available on many windows, computers is encrypted data storage. Now, in some cases, the TPM or the T2 chip.

Apple is also used for touch ID and activation log that all works with Apples find my iPhone type services. So this vulnerability is known as checkM8 and the jailbreakers as we mentioned, they've been exploiting problems with Apples, A5 through A 11 chipsets that's from 2011 to 2017.

Now the same group that developed the tool for iOS has released support for a T2 bypass. This is not good people. It just plain old is not good. Now we're going to. Pick this up. When we come back, I'm going to talk about the trusted platform, modules of vendors that are using it over on the windows space, how Apple's using it, how this whole black box things work works, and we're going to move up.

We talked about the hardware-based disc encryption. That's right there on the hard disc. We're going to move up the stack and talk about other types of encryption, including encryption. On the fly and encryption at rest, both are important concepts to understand when we're talking about security and system integrity.

Hey, you're listening to Craig Peterson. Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses the vulnerabilities in Apple's T2 Chip.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, if encryption has been really messing you. I'm trying to figure out how do I make these things safe? What is data at rest? What is Data-in-flight? How come we have disc encryption at the hardware level? What does it mean to have a TPM, the T2 what's Apple doing that's what we're talking about right now.

Hi everybody. Craig Peterson here. Welcome back. So glad to have you. I appreciate you being with me today and by the way, you can get all of this background information by going online. If you are on my email list over the weekend.

I will send out an email that has all of the articles I'm talking about here today. So go to Craig peterson.com/subscribe. All right.

We were just talking about the whole T2 problem that Apple has on their hands right now on macs. This new jailbreak now is allowing researchers to probe this T2 chip and explore all of the security features. That is not a good thing. You can even use it to run Linux on the T2, because this chip, the security module is a computer. You can play doom on the Mac book pros, touch bar doing this. This jailbreak could really be weaponized by malicious hackers as well to disable macOS security features like the system integrity protection, which is used to stop people from modifying files that should not be modified.

It also could turn off secure boot and install Mount malware, which is a real problem. We've got, these machines are no longer using the bios. Now they're using more advanced stuff, the UEFI stuff. That is also an operating system in and of itself, much more advanced than we had ever seen before with bios.

Now there is another T2 vulnerability that was publicly disclosed in July by a Chinese researcher group. This particular jailbreak could also be used to obtain file vault encryption keys, and to decrypt user data. This is good. Okay. Because the vulnerability is unmatchable because this flaw is at a low level.

It is in the hardware inside this T2 chip. It is an unchangeable code. In the hardware, it's the firmware. Now the T2 chip, as you can probably tell, is designed and intended to be a lockbox inside the macs. Something where information can be restored, where information can be read from it's used to generate a cryptographically secure key.

It's used to hold those keys. Handling things like lost mode enforcement, where a computer is lost and you have to log in using your Apple account in order to get it back online. It's bad. Integrity checking all of these different privileges. So it is a very big deal that this chip has been compromised.

Now the good news is longer term. There's a couple of pieces, but one is now we know about it. We know how these groups were breaking into Apple equipment. They did not expose it. Under President Trump, the national security agency has been ordered to release information about vulnerabilities that it finds.

And the idea there is, okay, NSA, you have all of these cooked up vulnerabilities that allow you to get into windows machines and iMacs and phones, et cetera. if you can figure it out, odds are good that the Chinese, the Russians, the North Koreans, maybe some others like Iran, odds are good that they can figure it out as well.

So NSA, you need to tell the vendors of these different pieces of hardware and software, when you find a vulnerability. if you ask me, I suspect that the NSA and CIA keep a few of these hacks in their back hip pocket, but they actually have been following President Trump's directive, which is absolutely phenomenal in my mind. It's, it is silly slash stupid to have these government agencies know about problems, like what we're talking about right now, this T2 chip problem. How long have government agencies known about it? We don't know because this has been reported by two different security researchers at this point. So that's good news. Frankly, because in future versions, we'll have this fixed as time goes on, everything's going to get locked down better and better, but there are some important limitations of this jailbreak as well.

So this is not a full-blown security crisis. So the first is that an attacker would need physical access in order to target your Mac computer or your iPhone. So that's number one, they have to have their hands on it. So the tool can only run off of another device over the USB port to use the buses inside the mac to get to the T2 chip.

So that means that hackers can't remotely infect macs. They can't mass infect every Mac that has a T2 check chip in it. They could jailbreak a target device and then disappear. Here is the good news the compromise if they were to break in and put some malware into your Mac, it isn't persistent. In other words, when that T2 chip is rebooted, the jailbreak goes away.

Then the compromise that they did to that T2 chip goes away. I should point out too, that at least right now, I suspect Apple's probably going to be able to come up with a patch for this in the operating system. But right now it's important to note that, T2 chip itself does not necessarily reboot every time the device does. So to make certain that you, that your Mac has not been compromised.

So if you're going to China and I'm dead serious about this, China's known to sneak into hotel rooms and steal everything that they can that's on your computers. If they have to they'll steal it in an encrypted fashion. That's the whole idea behind the trusted platform stuff in the T2 chips.

To be certain that it has not been compromised by jailbreak the T2 chip has to be restored to Apple default. So the jailbreak does not give an attacker instant access to encrypted data. It could allow hackers to install key loggers or other malware. They could later grab decryption keys or it could make it easy brute force attack it.

But this particular hack we're talking about right now, this is the check RA1N or check rain. It's not a silver bullet there. When we look at this as a whole, the T2 chip compared with other vulnerabilities, there are other vulnerabilities, plenty of them.

Most of them are sitting at the keyboard. It's the wetware two and me a 60 plus percent of the time when there is a hack of some sort it's because of something you or I did. So remember that there's plenty of other vulnerabilities. This is a difficult one. I would turn off my computer, my Mac entirely, boot it from scratch every time that should get that T2 chip to reboot.

I think that's an important thing. So anytime someone else may have access to your Mac, just shut it down. That's important too because there are other hack techniques that include freezing the memory on the computer. They can just use canned air, hold it upside down so that liquid comes out, spray it on the memory.

Pull the memory, which you cannot do by the way in the latest Mac books, it is soldered on, but pull the memory and get direct access to it. It will keep some of the keys in memory. That's a very difficult way to do it. Apple has some things still built in that are still functional that can and will stop that type of a hack.

Okay. And when we get back, we're going to talk more about the hardware security, what you can do, the different levels of it, and everything else. Your listening to Craig, Peterson.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses the uses of TPM in securing Windows and Linux

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to delve now into the idea behind keeping your data safe on your disks and what are the different regulations about it? Cause there's a few right now that you need to know about.

Hi everybody. Welcome back, Craig Peterson

We're talking today, at least this hour about security because of a major security problem that was announced this week, about Apple's security chip, the T2 chip. not a very good thing, frankly and so going through all of this right now and we're going to move upscale just slightly here.

I love this quote here. It was in ARS Technica this week, and it is from a gentleman who worked for the NSA his name's Patrick Wardle. He's an Apple security researcher at the enterprise management firm JAMF JAMF. I've talked about them on the show before they have some great management software.

He's also a former NSA researcher. And he said I had already assumed that since T2 was vulnerable to CheckM8 Check M eight. It was toast.

He said, okay, there really isn't much that Apple can do to fix it. It's not the end of the world, but this Chip, which was supposed to provide all this extra security is now pretty much moot. So it's, an interesting time here.

Wardle points out that for companies that manage their devices using Apple's activation lock and find my features, the jailbreak could be particularly problematic, both in terms of possible device theft and other insider threats. He knows that the jailbreak tool could be a valuable jumping-off point for attackers looking to take a shortcut to develop potentially powerful attacks Quote you likely could weaponize this and create a lovely in-memory implant that by design disappears. On reboot. By the way, that is a very common method now for much of the smell where it's memory resident, there's no sign of it on disc. It never hits the disc. So your antivirus software, ain't gonna find it because when it scans the disc, it's just not there. It's just amazing. So the bottom line here is building in hardware security mechanism is always a double-edged sword. That is true, not just of the Apple side, but over on the windows side and the union Linux sides, there's something called a trusted platform module also called TPM. This is an ISO standard here. It's standard for a secure cryptoprocessor. Just like that T2, it is a processor. It is a computer and it's designed physically to be almost impenetrable. I call it elephant snot. It's that really hard epoxy that they put onto the chips so that you can't get into the chip without destroying it. There are other methods for it as well, to try and keep that data safe.

But it's been around now for quite a few years, the most recent edition of it came out in about 2016. There've been a few errata, but it is designed to have a hardware, random number generator. Now that's important because having a secure cryptographic key, it means you have to have a very good source to generate that key with, and that means a very good, random number generator. Most processors aren't that great, man. I could talk for hours about the problems we've had over the years of these types of things. That's the whole idea behind the trusted platform module. It can also store those keys. It can also identify itself and the computer uniquely, which is very handy when you are trying to log in, you can use the TPM to help to identify the machine. It has bind keys. It's public key cryptography. It's an RSA key and ceiling as well. So it allows the TPM to be used or not be used. I'm trying to keep this pretty simple. Department of Defense is now specifying that all new computer assets that are purchased by the DOD must include a TPM or a trusted again remember platform module that is version 1.2 or higher. There are details on that. You can look those up, but I've gotten to say no matter who you are, what business you're in, you really should make sure the computer you buy has a TPM in it. Now we have seen security problems with TPMS by certain vendors. They've fixed them, just like this T2 problem with Apple. I'm sure it'll be fixed. By the way, the T1 chip from Apple does not have this problem, it's just the T2 chip, but the whole TPM is really there to help ensure the integrity of the platform. In other words, the operating system, the hard desk, the encryption for the heart.

So if you're using BitLocker on Windows, it works best with a TPM. So BitLocker and windows will encrypt the desk using the key that is generated by and stored in the TPM on the machine.

So write that one down and in my cybersecurity mastery course. We talk about BitLocker and how to use it and TPMs and how to just select those.

Also nowadays, you're going to find the newer computers no longer have bios in them. You probably already figured that one out. Most of you guys, right? You are the best and brightest out there. But they have UAF, I mentioned earlier, that's the unified extensible firmware phase to boot.

So the UEFI works with the TPM to create this kind of circle of trust crust if you will. It's absolutely phenomenal. So Linux has its own little thing called the unified keys set up. I already mentioned BitLocker's private core and various other things. Full disk encryption. Very important.

There are utilities to do that again on Apple. It's very easy to set up full disk encryption in all these cases here where you should be using your TPM or T2 chip in order to do that. The authentic catered mechanism. It just me authentication mechanism in. The software can be hacked in hardware.

Usually can't be hacked. What have we just been talking about for the last half hour? yeah. Hacking the hardware. But that's what the TPMS is all about. That's what gene to do. There's discreet, TPMS, there's TPMS that are built right onto the motherboard. And, there are also some that run as software-only solutions inside the CPU itself.

That's part of their trusted execution environment. Not really fond of those. But now, you know what to look for. There are other things as well that we go through a lot of other things in the cybersecurity mastery course. But, one more thing before we go. And that is we talked about encryption on the hard disk level.

So the physical hard disk itself can have encryption, which is great, but that encryption is really only useful for when you are getting rid of that disk. So you destroyed the key by removing a jumper or shorting out a jumper and now that disks data is effectively destroyed. And the disk can actually be reused again.

Certain standards, federal government standards. we have a system that literally melts the aluminum platters right down. It's Kiln. I forgot what you call these things, but a very hot, yeah. Over a thousand degrees, but for a regular business computer, you're not going to have to worry about that.

You need to also have a TPM and make sure that on top of that you are using BitLocker or some other type of encryption. And when you get. Way up there into the CMMC as part of the department of defense standards or the 800-171 standards from NIST, then you have to have special key management remotely that has a different key for every desk.

And it gets pretty complicated pretty quickly, but the whole idea is to secure your data and remember. Just because it's all encrypted doesn't mean it's safe from hackers.

We should talk about that at some point, but when we get back, we're going to talk about, but our final two final do articles of the day, listening to Craig Peterson, and you'll find me online at craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses PCI DSS Compliance in businesses and the increasing problem with Android ransomware.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Trojan Malware Targets Trump Supporters

Nmap 7.90 released: New fingerprints, NSE scripts, and Npcap 1.0.0

Tyler Technologies finally paid the ransom to receive the decryption key

5G in the US averages 51Mbps while other countries hit hundreds of megabits

Apple’s T2 security chip has an unfixable flaw

Verizon Payment Security Report is a Wake-up Call: Time to Refocus on PCI DSS Compliance

Android Ransomware Has Picked Up Some Ominous New Trick

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] If you have a business that takes credit cards if you. Ever go into a business or use a business online that takes credit cards. There are some special rules that you need to follow called the PCI standards. We'll talk about it.

Hi, welcome back. This is Craig Peterson here.

Verizon. I'm not sure if you've seen these before, but Verizon has security reports. It has a number of different reports and they tend to all come out annually and here within the last couple of weeks, Verizon released their payment security report for this year,. It is an annual report and it's having a look at how organizations are maintaining compliance with something called the payment card industry data security standard, or PCI DSS.

Now we have a client I'm thinking of right now that's a small a doctor's office and they, of course, have to take credit cards and they had their credit card processing suspended by the credit card processor. I'm thinking of another one as well, which is a pizza joint. They too had credit card processing threatened for suspension. In their case, they had a couple of weeks to clean up their act and both cases. They pulled us in to help straighten things out.

But what was interesting about the doctor's office is they sent a physical copy of the PCI agreement, the payment card industry agreement, so that if they wanted to accept credit cards, they had to sign this agreement. Now, first of all, in this day and age, that's remarkable in and of itself, right?

We get PDFs, but how many of us just pencil whip, PDFs, or click whip, I guess PDFs, most of us. It's really rare that we read the contract and it's interesting to know too, that not only was it a physical copy, but this thing it was hundreds and hundreds of pages long. It was huge. It was absolutely huge.

So they had to sign a physical copy of this thing. What happens is if you are accepting the payment cards, in other words, credit cards, and someone reports that there is an unauthorized charge on that card. The guys and gals at the payment card industry, start to look at your business. Now we had a case right here by my house.

It was a Wendy's,I think it was and apparently, the manager of the Wendy's and the employees were skimming credit cards. So you'd go in, you'd give them the credit card. They'd run it and give you the card back. Wow. They didn't just run it for your lunch. They made a copy of the credit card.

Okay. Now that's part of the reason we've got these smart chips on credit cards. Europe is way ahead of us on using those smart cards. And frankly, it's a risk, right? It's risk tolerance.

How much risk tolerance does Visa or MasterCard or whoever have and how much risk tolerance do the businesses have that accept the cards and then how much risk tolerance do you have?

In this case with Wendy's, they got a lot of complaints about that Wendy's store, where the cards we're all used at some point over the course of the last number of weeks and were used elsewhere as well. The owners of the cards had reported some of these transactions at other places as not right being made by them. Now the credit card companies will go ahead and give you a credit on your bill, so you don't have to pay that contested portion.

But then, and they start looking into it a little bit more seriously. In the case of the doctor's office, they did get suspended at least for a short while. The pizza joint, we got them up to standards within the two week period that they had. So they didn't get suspended. Because what would happen to a business if that card is card processing suspended, it'd be really bad.

Now you and I, we have to deal with the fallout as consumers because we used our card and the card might've been duplicated by someone working in that store. Our card number may be stored on a computer. In the case of another doctor's office, that's exactly what was happening.

The card number was being stored. then that information was then being sent off for processing, and then they would repeatedly enter the card information. Now there are some sites that have these virtual terminals that you can use, which is really great, where you are typing in the card number. But remember if your computer has a keystroke tracker, a key logger on it, and you're typing in credit card numbers. That's easily recognizable and you're going to get in trouble with the payment card industry, It's a very bad thing all the way around. So be very careful.

There are a whole bunch of security instances where this has happened and the Verizon payment security report is showing businesses just are not compliant. According to the data that they gathered here in 2019, less than 30% of organizations achieved compliance during interim compliance validation. That's like the pizza shop I was talking about, all we had to do with them was move them up to prosumer hardware. We had to get them to upgrade some of their software on their computers and change the software they were using because OMG. It was just crazy, the software. I couldn't believe what it was doing, but we got them all in all setup, all taken care of her. But less than 30% of the businesses that had to comply during the interim compliance validation period did not meet the compliance.

My bottom line here is to start now because Man oh Man applying quick fixes instead of creating and executing an overall strategy is really going to affect your compliance with PCI or any of the other standards out there, any of them. Just like the pizza shop and the doctor's office, I just mentioned, in both cases, we had to upgrade their systems, move things around, split up their network, have better encryption on the Wi-Fi, split off a customer network. So there's no way for any of them to get back and forth, and firewall some of their internal systems. So keep that in mind as well.

We're not going to get into the whole electronic voting thing, which also showed up in this Verizon report.

We only have a couple more minutes, so let's get into the Android, part here. this is an important one as well because we're seeing some new tricks.

Wired has an article by Lily Hay Newman saying she's calling them foreboding. Isn't it? here's what's happening. First of all, it's far more common on PCs, but as some of the newer research is showing that mobile ransomware has undergone an, a real evolution here.

We've seen it to the point recently where you go to a website and that website now uses your Android phone to start Bitcoin mining. Remember that? So if your Android phone is getting like really hot. It might be making money for somebody else they're using your computing power, but there's a lot of other things that are harmful.

Now, of course, in Bitcoin mining, it could burn up your Android phone and that's happened more than once. This silly thing gets so hot, it just melts down. But along with all kinds of types of PC malware used in these types of attacks against hospitals, municipal government, and any institution that can't tolerate downtime.

There's another platform that's really getting hit hard recently with ransomware and that's android phones. New research from Microsoft is also showing the criminal hackers are really putting time and resources into refining mobile ransomware tools. So why do you invest money? Because you're making money?

So the fact that they're investing money into coming up with new ransomware tools means. It's making the money. People are paying the ransoms.

There is some new software you might not be familiar with it. Of course, Microsoft has a windows defender. It's been on windows for a bit. Now it's actually quite good.

Microsoft also has released Microsoft defender for Linux, which really shocked me. I haven't tried it yet. And Microsoft defender on mobile. They've looked at a lot of different Android ransomware families, and apparently, they've added some really clever tricks, including a new note delivery mechanism. They've got improved techniques to avoid detection and they've even got machine learning built into the ransomware, that's attacking Android phones. That can be used to really fine-tune the attacks for different peoples android devices. So be extra careful out there, everybody.

We talked about in the first hour an attack that's going on right now, that's primarily directed at Republicans, but I think a lot of Democrats and independents would also open these emails and opening these files it's a very dangerous place out there. Use filters, use some of the anti-malware software. On an iPhone, there really isn't any. You certainly don't need it as much, at least at this point. On Android, however, there is some great anti-ransomware software and you might just try Microsoft defender, which is a basic stopgap for you.

But, do be careful out there, everybody.

All right. So keep an eye out for my emails.

We've got more coming out here. I'm trying to go up to two a week, maybe even three a week, doing a little training. You might have noticed the last three weeks, my emails have looked different and I dropped some of the information in it because I think it was just visually confusing.

So make sure you are on my email list. Get my newsletter. Get all of this free training. All of this information that you need as a home user or a business user, or a business owner.

Go to Craig peterson.com/subscribe. Craig Peterson that's SON.com/subscribe and have a great week.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and started off this morning talking about emails that are targeting Republicans with a particularly nasty trojan. Then we got into 5G and why the US speeds are so much lower than the speeds in Europe, and then we wrapped it up discussing the Ransomware that has been infecting local and state governments. Here we go with Matt.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] So the whole goal here of five G is twofold. The first goal is we want to be able to have a billion devices connected to our networks and local networks. Plus we also want to have a speed of maybe a gigabit worth of bandwidth.

Woo Wednesday morning gremlins. Craig Peterson here. I was on with Mr.

Matt Gagnon, this morning and had the weirdest thing happened to me here. I'm on the phone, right? I'm talking to the radio station. I'm being interviewed and all of a sudden the podcast starts playing on my phone. It was very distracting. I'm used to hearing myself. When I'm doing an interview on a radio or TV station, sometimes I hear myself on delay and the delay can be sometimes a few seconds. So I'm used to that. That one I can live with, but having the podcast playing of me on another radio station, while I'm doing an interview with a radio station was just a little too much to handle. I managed to pull my act together, but wow. That was the weirdest thing.

Anyways. Happy Wednesday, everybody takes it for what it is. I suppose we talked about the same things, a little bit, slightly different angles, of course, but some of the same things we talked to Jim Polito about yesterday. So here we go with Mr. Matt Gagnon.

Matt Gagnon: [00:01:29] It is six 36, and it is time to talk to Craig Peterson, our tech guru.

He joins us now as he does every Wednesday at this time.

Craig, how are you?

Hey. C'est nous. Comment ça va ce matin?

Ah, ça va Bien. So Craig is malware targeting Trump supporters? That's a good place to start off. Do you think we're in election season? That's a, it's a nice topic, right?

Craig Peterson: [00:01:51] Yeah. Yeah. Or were you one of these people that pass conspiracy is that

Matt Gagnon: [00:01:56] I am not, of course, a conspiracy theorist, but, but still things like this do happen out there.

So it's worth chatting about.

Craig Peterson: [00:02:03] Well, this is a very big deal. Everybody should pay attention here. We'll get into this for just a minute here, but the bottom line is there is a very dangerous banking trojan is going around right now. It's called Emotet. Emotet has been around for a long time.

The difference right now, Matt is that this Emotet malware is being sent. In a piece of email that is forwarded from a political action committee supporting Trump. So in other words, they take an email, a legitimate email from a political organization that is supporting president Trump and they forward it. For the subject line.

will have a start of FWD or RE just like you would, when you were forwarding something. Forward to re: and it'll have the body of the message that was forwarded from the legitimate group. It'll have all of the links in it that will all work normally, but there is attached to that email, a word document. That word document, if you were to open it up and become infected is horrific.

What it does it goes through your computer. It scans your network. It actually scans looking for other vulnerabilities. If you're misusing the VPN, which is about 90% of businesses that are using the VPNs, they're not set up right now, your computer at home that gets infected because you're open this mailer, the look perfectly legitimate about President Trump.

Now that malware is going to get onto your business network and spread through the corporate network. This is really, really bad. There's speculation about why is this happening? But I think the bottom line is that this is the ultimate in social engineering and phishing, and it is absolutely targeted at Trump supporters.

Matt Gagnon: [00:03:56] Speaking with Craig Peterson. You hear him on this very network on Saturdays at 1:00 PM, where he goes into all of these details. Much more in-depth and to move on here a little bit, one of them, one of the more fascinating things he had on the list here today that I wanted to talk about is about the average speed of five G in the United States versus what it is elsewhere in the world. What is going on with this speed difference? And why is it different elsewhere?

Craig Peterson: [00:04:22] Yeah, it has to do with the frequencies that are assigned. The higher the frequency, the wider the bandwidth, the more bandwidth you're going to get for download. So the whole goal here of five G is twofold. The first goal is we want to be able to have a billion devices connected to our networks and local networks plus, we also want to have a speed of maybe a gigabit worth of bandwidth. Well, the US average speed is about twice now, the five G speed twice what our four G LTE speed is. But when we started.

Matt Gagnon: [00:05:00] That's nowhere near that gigabit that you're talking about,

Craig Peterson: [00:05:03] Nowhere near. Absolutely. Absolutely not. So we're talking about give-or-take 50 megabits right now. It will go a little bit faster. T-mobile has lower frequencies. I have an advanced class ham license, so I've been involved with TCP IP over the air. Multiple different places.

So what the problem is, the bottom line with some of the stuff is, we've gotta be very careful about what we're doing here. I'm having a bit of a problem on my end. Without speeds. T-Mobile is giving us the ability to listen to the signals inside businesses, some of the others like Verizon, they cannot do that.

That's become a bit of a problem. Well, I think for everybody. So sorry, a bit of wandering here on my side, looked a bit of a technical problem.

Matt Gagnon: [00:05:57] No worries, Craig, we're talking to Craig Peterson and technical problems are no problem for him because he's our tech guru. And a final question for you, Craig, before I let you go this evolving story about Tyler technologies and the ransom that they're paying to receive the decryption key is very interesting as well.

Tell me about this thing.

Craig Peterson: [00:06:12] It is interesting we found out that a couple of things, one, most people are paying for the ransoms when the ransoms come up. I can understand that because they want to get their data back. We're also seeing that bottom line, people who are paying for these ransoms out there are also breaking the law and the feds are saying they're going to come after them for paying money to these terrorist groups. That's where paying ransoms do. Tyler Technologies provides software to the majority of states here in the United States to do things like collect taxes and also to just run towns and they got nailed.

It took them about three days. They finally paid the ransom to the guys that had taken over all of their systems and shut down many of the towns and even state operations throughout the country. So, you know, bottom line again, what should we do here? We're now. Rock and hard place where the Feds are saying they may take us criminal charges if we pay a ransom yet we need our data back as well.

Matt Gagnon: [00:07:23] Craig Peterson, our tech talk guru joins us at this time every Wednesday to go over what's happening in the world of technology. Craig, appreciate it as always good luck on Saturday, discussing all these things in more depth of detail. As you can hear a one o'clock on WGAN and thanks a lot, Craig.

Craig Peterson: [00:07:36] All right. Thanks. Bye. Bye. Everybody, we will be back on Saturday. Also, remember if you are on my email list, you'll get all of my articles for this week. What I talked about here on the podcast and on the radio. So keep an eye out and make sure you're subscribed. craigpeterson.com/subscribe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. We got into a lengthy discussion about some new malware - a trojan that is targeting Trump supporters, specifically. Then we briefly hit on 5G. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] There is a word document attached to that malicious email. That malicious email has in it, in that word document, something called malware. One of the nastiest pieces of malware out there. They're forwarding political information relevant to Republicans. People are targeting Republicans.

Hi everybody. Craig Peterson here. Yeah, that was me on with Jim this morning. We went into quite a bit of detail about this Trojan malware. It's an interesting discussion here.

Why is it coming out? What are they saying? What are their subject lines? What's it going to do to you? Why is it targeting Republicans?

So here we go.

Jim Polito: [00:00:47] Here he is, Oh, everybody waits for Craig Peterson and this is going to be an important visit today. We're going to talk about malware. If you are a Trump supporter, kind of a Trojan horse out there. Well, we'll get to all of that, but first, let's welcome him aboard. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:09] Hey, good morning. I've got another little granddaughter who was born just this last week and her parents are both captains and they sent a picture of this little baby girl in a captain's outfit.

Jim Polito: [00:01:23] Now that is that's worthy of a wonderful congratulations there, grandpa again.

Craig Peterson: [00:01:34] Thanks. I've got 8 kids and I've only got six grandkids. These millennials what's with them.

Yeah, yeah,

Jim Polito: [00:01:39] yeah.

Craig, they're just not, I mean, I finally am going to be a grand or great uncle, whichever way you choose to say it. Yeah. These millennials, come on. Come on, guys. Listen.

Well, listen, before we get to this. I've got to tell you something, that'll make you feel old or it'll fascinate you.

Today. The first cell phones were made available for sale commercially in 1983. They were ridiculously expensive. There weren't a lot of towers, but they were for sale.

Craig Peterson: [00:02:16] Yeah, the big bricks. They were really. Oh, you remember those? I was so jealous when those came out. I've been a ham radio operator. I have an advanced class amateur radio license and land mobile was the thing back then. Right? So you'd have this huge antenna on your car. You drive around and almost could listen to you as you're driving. Now came cell phones, which had a modicum of privacy on them. They were so small compared to the land mobile things.

And now I've got a cell phone on my wrist. This is like big, crazy time.

Jim Polito: [00:02:49] It is. It's too cool. It just goes to show you, where will we be four decades from now? I'll probably be dirt napping, but anyway, Where were we? Where will we be? Alright, Craig, I've got to talk to you about this, cause it really caught my attention.

A piece you sent me about Trojan malware targeting Trump supporters. This is something that a good portion of the audience wants to hear about.

Craig Peterson: [00:03:18] Yeah, I thought you might be interested in this one and for everybody, this will come in my newsletter on Saturday. So make sure you're subscribed to that newsletter so you can get this.

There is a Trojan right now that's being circulated and it's targeting just Trump supporters. I might ask, how does that happen? Right. It's not like the virus only targets people in the white house and Republicans. Well, actually, maybe it does. But anyways. The way it works, is they are sending emails that are actually forwarded emails from these political action committees that are pro-Trump. These attackers are forwarding perfectly legitimate emails.

It has legitimate links in it that you can click on right to that political action committee. You can just look at and you think, Oh, it's great. The subject line says forward, and it's got the subject or maybe re the subject. Those are both things that people have is clues. Hey, this is an email you want to open.

The problem with this is it's entirely Republican PAC. That they are targeting that they're forwarding to people and there is a word document that's attached to that malicious email. That malicious email has in that word document, something called malware. One of the nastiest pieces of malware out there.

They're forwarding political information that's relevant to Republicans. There are people really targeting Republicans.

Jim Polito: [00:04:58] There you go. How do you argue with that? That's shall we say fact?

Craig Peterson: [00:05:07] Right. Its science. I believe in science. It's just, I believe in my science, this is very obvious, right? The researchers are calling it like a Wolf in sheep's clothing. Well, here's what Emotet does once you get it. Emotet is a Trojan. It's been around a long time. They use what's called a spear-phishing technique and they have for a long time.

So they try and coerce you into opening up by putting something in the email that's of particular interest to you. Then once you've opened that word document and that malware is on your computer and it starts to spread. It actually acts like what we call a worm and it brute force attacks all of the services on your computer and all of the services on every other computer on the network.

Now, you know how I've been warning about using VPNs when it comes to businesses, Jim. This is why. If you VPN in, into the office and that office is not protected from its VPN users, this Emotet will now start spreading to your business as well. We'll start taking over your file servers because it looks for SMB shares.

The window shares, is what it is, a valid local account. Very, very nasty and it is very sad and scary that it is attacking Republicans. Now Democrats would get this email as well, but the likelihood is they're just not going to be interested. So they're not going to open it.

They've gotten a little more advanced too, for those of you out there that are a little geekier, It does pass email authentication protocols, such as D Mark. So this is a bit of nastiness and it'll be interesting to see if we can figure out who's sending them.

Jim Polito: [00:06:53] It was what I was going to ask. And we're talking with Craig Peterson, our tech talk guru, and about this malware that is targeting Trump supporters.

Now, could this just be an opportunity? They're going after Trump supporters, just because it was easy. It's a segment they are going after and it's apolitical. their reasoning behind this is not political because maybe the door was left on the lock on this house.

It was a crime of opportunity. It's not particularly against the family who lives there or do you think there's more to this.

Craig Peterson: [00:07:29] Well, back up a little bit and I thought about this and here's kind of my thinking on it is that, um, Sleepy Joe's supporters are not particularly excited about his campaign or

people voting for Joe Biden are voting against Trump for the most part. It's just crazy. So the way I look at it Trump supporters tend to be, you know, man, I'm on top of it. I do want to hear what's going on, you know? That goes right into your target of opportunity theory. I think it's absolutely likely that's what's going on here.

They could be an attempt to kind of influence the election, but I think it's more likely a moneymaking opportunity for them.

Jim Polito: [00:08:11] So they look at it as, Hey, there's more Trump voters engaged. They're going to be more active. Why not go after that big fish? Just like if the Patriots were in the world series, you'd have a lot of people from New England or elsewhere fans looking for stuff online related to the Patriots.

So why not attack Patriots fans?

Craig Peterson: [00:08:36] Hey now I even, I know that the Patriots would never be in the world series because that's baseball. Okay. Come on, Jim, come on. Pay attention.

Jim Polito: [00:08:46] Did I, did I say words that I say world series?

Probably. Yeah. Yeah. Series. It just proves it pages in the world series of the super bowl. Look, if it's not hockey, I trust you only with hockey. Okay. Because you're a Canadian, maybe that and curling. Okay. That's it.

Craig Peterson: [00:09:08] Yeah. There you go. I love Curling actually. I really do. So here's what to look for. If you get a subject, this is the number one out there right now for this.

The subject line has forward breaking President Trump suspends funding to WHO. That is the number one subject these guys are using right now. Breaking President Trump has spending funny to W H O and they're asking you to click a button labeled stand with Trump. They're hiding the sending address and everything else in these things.

So, watch out. Be very, very careful in this political season about opening emails and more particularly about opening Microsoft documents. They've long been used as attack vectors against all of us,

Jim Polito: [00:09:51] You know? I think about my own email and of course, I've got campaigns, pundits, everybody emailing me every single day, and you know, I open most of it and look at it. Just because I want to say, well, what's this, what's that?

I have not received anything like that, but I'm going to be very careful now going forward because that, the last thing I need is is that,

Hey quickly, because we've only really got a minute. Five G it looks, it looks like from what you sent me, the download speeds of five G in the US are going to be a lot slower than they are elsewhere in the world. It's going to be an improvement over 4g, but it's still going to be slower than the rest of the world. Why?

Craig Peterson: [00:10:45] This is something that takes some serious time to explain. But getting it down to 60 seconds here's the bottom line. Five G is not the same thing across all carriers. Five G is using some different bands and different frequencies.

Jim Polito: [00:11:01] So here's the problem that we're seeing right now. T-Mobile has the biggest five G network in the country. In fact, you could say it's the only five G network in the country, quite reasonably. However, because the frequency is there. Using it is not as fast as Verizon's, which is only available in certain cities. In fact, in only available in certain blocks in certain cities.

Craig Peterson: [00:11:25] Here's why. The T-Mobile frequencies will go through glass. They'll go through walls. You can use them in a building. Verizon's will not. You have to be very close to the cell site. Okay. So because of the lower frequency, you also cannot send as much data. On those little frequencies. So look right now, the US average is about two times faster than four G, which is really good in Europe. We're seeing much, much higher. They have denser populations they're using the higher frequencies like Verizon is. Once Verizon's rolled out further, they will have faster download speeds.

But, with Apple's big announcement today where we're going to have to make some decisions about what carrier we want, based on whether or not we want 5g. My bottom line on that it's not that a big win unless you are hauling a lot of data up and down to your phone.

Jim Polito: [00:12:18] All right. That made sense to me, even in that short time.

So Craig has got a great show Sundays at 11 o'clock and it's repeated at other points during the weekend on TAG and HYN, but Craig, if folks want to get in touch with you, and I know you said you're putting it out in your newsletter, some of this information,

Craig Peterson: [00:12:37] well, just drop me an email. me@craigpeterson.com M E @craigpetersondotcom Subscribe by going to craigpeterson.com slash subscribe.

Jim Polito: [00:12:47] Alrighty. Very good. Craig, always a pleasure. We'll catch up with you next week.

Craig Peterson: [00:12:53] Thanks, Jim. Take care.

Jim Polito: [00:12:54] You too. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses cybersecurity audits and new vehicle lifespan.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

With our cars being more and more computerized should we be treating them like a computer? Do we have a right to repair? Should we be expecting upgrades? How long should our car last? We're going to get to that and a whole lot more.

Hi everybody. You are listening to Craig Peterson. We're going to get into a number of different security things this week. I've talked about them on the radio, some really cool stuff coming from Elon Musk. Some news about how paying ransomware demands could end up getting you a jail sentence. Yeah. Yeah. It makes sense, once I explain it, okay. So hold on a couple of minutes.

We have some very cool new technology. I talked about Intel before and how disappointed I've been with so much of what they've done over the years. And we are going to talk about Intel's maybe biggest competitor outside of maybe a company might've heard of AMD. We'll be getting to that and employee apathy. MacOS workers really driving a cybersecurity rethink. We'll talk a little bit about the NIST cybersecurity framework because that is getting to be a big deal. I just had this week, a client, actually last Friday that client informed me that their customer had stopped ordering a couple of weeks prior they're trying to figure out why now up until then. My customer had not told me how much this customer was worth to them but they don't buy much. That DOD contractor stopped buying from my client. Now, this is a client that we've had for 20 years, maybe longer and we'd been warning them about the changes that have been occurring. In the regulations regarding cybersecurity.

You might remember me mentioning here on the show a couple of weeks ago, there was an emergency change, right? An emergency order of 48-hour notice to change in what was being. Required of DOD contractors. Now, the department of defense is one thing, right? But how about the rest of us? All those same rules are going into effect for everyone that has any sort of federal contract coming up here within the next three years are affected by this change and their clients. So their client was getting worried and said, Oh, let's wait a minute. yeah. Yeah. They're not fully compliant. And there weren't, and we've been warning about pad, as I said for, at least 18 months and they lost 70% of their business overnight, 70% can you imagine that? Now they're freaking out and trying to figure out sorta we do now. Hopefully, we'll be able to help them with all of that and they'll survive it.

It turns out that a federal contractor that was a client of theirs was more important, 70% important to their business. That's a lot of business to lose and it took them about two weeks, apparently calling-in daily. Trying to find out from their client. Why did the order stop? What's going on here? Did something get messed up? Is this a billing mistake, an order mistake? Do we need to talk to somebody who is over in purchasing or what do we have to do here?

They finally got an answer from somebody that knew what they were talking about and it turned out that it was because they weren't compliant with these federal regulations. So keep an eye on that.

I just had another conversation on Thursday with a gentleman who indeed is really under the gun here. Now, he asked his IT provider, Hey, am I all set here? And the IT provider said oh yes yes sir you are all set. We're taking care of it for you.

But you already know my response to that, 99% of the time when we walk in, and I say 99, because. I've never seen an exception, but I want to leave a little room for error, right? The margin for error. So maybe it was just saying over 90% of the businesses we go into that think they're compliant are not compliant. If they were to get audited, they'd be in deep trouble.

The case with our client, they weren't even audited. This was it a self-audit form they had pencil whipped and the primary contractor realized, Hey, listen, this doesn't jive with what we've been seeing.

So keep that in mind, everybody. This is a very big deal.

Now I've put together it's about a 300-page long document, but it goes through all of the major cybersecurity standards and I'm calling it an audit preparation kit or an audit kit and I will be glad to send it to anybody that wants it, this is generic. This isn't to use me. This isn't to use Cisco. This isn't to use Mainstream. This is just a compilation of all of the rules that you have to follow based on the different levels within the new CMMC stuff. That's actually been out for a little while, but now they're really pounding the table about it saying you darn well better get this stuff done.

So I'll be glad to send it to you. Just send me an email within the subject line. Just say. Audit kit. I will be more than glad to get that off to you or we can do an audit for you.

We've offered audits for many years and found a lot of things and help put together a plan.

So whatever you want to do there, do it. But whether you're talking to your own internal IT people or external IT people remember most of them are not as familiar with this as they need to be. So getting a copy of this audit kit, looking at it at yourself, having the person who's responsible for IT, review it with the vendor or review it with the internal IT people, you can get your act together.

That's what I'm trying to do. Get you to the point where you can handle it all and really take care of it. That's the bottom line.

Let's get into our cars here. We're going to totally switch subjects. And then this is something that's happening right now in a lot of States in Massachusetts, there is a bill that went through back in 2013, or maybe it was something a ballot question, but it's back on the ballot this year.

Question one in mass and this is a referendum on how can traditional independent automotive repair shops survive in this world. I remember I said at the opening, is it a car or is it a computer? How should we treat it? I remember when odometers on cars, you rolled over at a hundred thousand miles because who expected a car to last a hundred thousand miles.

That's ridiculous. But bottom line now, today we expect most cars to last a quarter-million miles easily, maybe longer. Not to say that there weren't cars from back in the day, that would last that long, but it just wasn't an expected thing. So today we know, okay, I want this car to last me at least a couple hundred thousand miles, maybe a quarter million, however many you want. Before you go and sell the car, right? Doesn't that make sense?

It seems to make sense to me and vehicles have really gotten a lot better. So if you are going to buy one of these cars that is electric or are very high tech, what are you going to do with that? What are the odds that the car is going to last you? I don't know, quarter-million miles, half a million miles, the electric motors in some of these cars, frankly, should last a hundred thousand miles without even blinking twice and probably will last a million miles with no problem.

Now, the batteries, that's a different deal. We've talked to before about the efficiencies and how your F-150 is probably better for the environment than an electric car, because when you consider the global environment, the conditions that are created in China, all of the shipping that has to go on between Canada, where some of the stuff is mined and how NASA uses it for moonscapes those areas because there's death for hundreds of square miles and shipped from Canada and it goes over to China and it goes to Japan that goes back to China, that goes back to the United States. And you've seen some of those pictures of Beijing and China, I'm sure, and other places where they do a lot of manufacturing where it's deadly to drink the water. You just can't breathe. Everyone wears masks to try and protect their lungs from pollution. So don't sit there all high and mighty thinking you have an electric car or you've got a Prius or one of these other hybrid cars, and you're high and mighty thinking aren't I great because I'm saving the environment versus that guy driving the F150. When you consider how long the F150 lasts when you consider how long those batteries in your car last and how long those batteries' environmental footprint will last and what it took to make those batteries. The F-150 is still the better option worldwide when it comes to pollution, the environment, and being green.

It's so funny. You see these signs out there right now during political seasons that say, I believe in science. Yet in reality, no, that's not science. It's not science, climate change is happening. It's always happened. We've always had a changing climate. Man's impact on the client is so minuscule there's almost nothing we could do to affect any change in the environment unless we did something stupid. What scientists told us to do in the seventies and some of the so-called scientists are telling us to do now, the models are wrong. They've always been wrong.

These electric cars are our future. It is absolutely going to be our future. What do you expect from your electric car? I have nothing against electric cars. I think their great, just don't think that you're being green by driving an electric car, because you're not. They are cool as heck the technology in them is absolutely amazing and I'd love to own one. All right.

So I want to put that aside. I want you to remember that I love these things and when we get back we're going to talk more about this, the expectations, what's happening with insurance and should question one be on a referendum for this right to repair. What's that all going to mean as well?

Hey, you're listening to Craig Peterson.

Stick around because we'll be right back.

We're going to finish this discussion and of course, we got a whole lot more coming up.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses new car technology, electric cars, and how long we can expect them to last.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

From a 50,000-mile model T to a 100,000 mile Chevy in the seventies to nowadays we're expecting maybe as much as a half a million or a million miles out of these newest cars.

Hi everybody. Welcome back. You're listening to Craig Peterson.

Before the break, we were talking a little bit about our cars and we were expecting our cars to not last terribly long back in the day, we have gotten a lot better with our manufacturing.

In fact, some people say the cars are designed to start falling apart as soon as the warranty's over, which of course varies based on cars. Some have been longer warranties than others, but. What are we going to expect our newest cars? I'm talking about things like Tesla, Tesla may deliver this year over a half a million vehicles. That is a lot of cars that are out there.

California, just announced last month, this effort to phase out the sale of new gas-powered passenger vehicles by 2035. That's only 15 years from now. Not a whole long way away. What are we expecting from these things? Just like with your computer, you expect upgrades, right?

Do you expect a new release of software? You remember for many decades you bought a computer and there was a software update. Date, you needed a new version of PCdos or MSdos and you needed a bigger, faster computer. You needed 64 megabytes of Ram instead of what you had before he needed to move from static Ram, which was just too slow to dynamic ram as well.

If you're old as I am you remember that and much more from even older computers. That happened through Microsoft's entire life cycle until just a few years ago. Where, when it was an upgrade from windows 3.1, two 95 to 98 to XP. Millennial edition, et cetera. Every time you pretty much had to buy a new computer.

Why? because the old computer technology hardware that was in it just could not keep up with the new operating system. Frankly, software programmers are pigs - every last one of them. Yes, I said that and I say they're pigs because they're not paying attention to memory consumption. When you get right down to it, what is cheaper programmers' time or the hardware?

I know for many years I was told by my clients as I was designing and writing, operating systems and device drivers and networking code that it was always cheaper to do it software than it was to do it in hardware. So in order to save a quarter-cent on each machine, we would spend an extra few hundred hours working on some of the software that wouldn't get around that fraction of a cent piece on that motherboard.

Microsoft doesn't think that way and programmers, nowadays, don't think that way either, because. They're not programming the way we used to program. Nowadays, it's all about drag and drop. We're using languages in our cars that are so far away from the hardware. It doesn't even matter what hardware they run on.

We're using languages like Java, for instance, which is just an absolutely amazing language. It certainly has its security problems when you get right down to it. But. Java is designed so that you can run it on a fast mainframe all the way on down through your Android phone. They're all running Java and they could all run pretty much the same code without a whole lot of problems.

That's an interesting dilemma when we're talking about cars. Your Microsoft Windows computer, you were probably able to upgrade from windows 7, maybe to 8. Most of the time people bought new computers to go to 8 but upgrading to the next release of Windows 10. Was much easier, wasn't it? Did you have to replace your hardware? I know I did not. My hardware could still support windows 10 from windows seven to 8.1 while 8.0 than 8.1, right in there. 10. That is a very big change in the Microsoft world because these computers were fast enough. Now, of course, that hit and hurt companies like Intel and also AMD.

And we're going to talk more about where the hardware is going here in the near future a little bit later, and if you miss it here on the air, make sure you visit me online @craigpeterson.com. You can catch all of the podcasts there and on your favorite podcasting platforms where we talk about, should you buy a new computer now? Should you wait? And why, and where is the technology going?

But we've gotten to the point now where a new release of an operating system does not mean you have to have new hardware. That's true on your macs and has been for a long time. That's also true on your windows devices. Every few major operating system releases, you might have to get new hardware. So you're talking five to 10 years, frankly, of support out of that device.

Have you thought about your car? Because of these new cars, Tesla is a great example of it. They really own the market. I think they've won the battle, at least for now that might have even won the war for the time being when it comes to owning that whole space of self-driving cars, electric cars, et cetera, they are doing an absolutely amazing job.

But that car, that Tesla that's parked in the garage is maybe hooked up to the wifi in your house. It is maybe using the built-in data connection that it has, LTE. We know that Tesla has two processing units in it, completely separate ones. There's a lot of speculation about exactly what they're used for and when I'm not going to get into that right now. That Tesla that you buy today that has really a fancy cruise control that tries to help keep you in the lane. Might be better in a year from now. And how's it going to be better while it might be better in a year from now because that electric car you bought is going to get an upgrade. It's going to get an update and that update may even make it faster, make it use less battery, make it even smarter. Elon Musk says that he already has the software built-in and the hardware in the cars that can handle fully autonomous mode.

That'd be an interesting discussion I'd like to have with you guys sometime about what exactly is happening on that end. So the car you buy may be better next year, but how about five years now? How about that upgrade cycle?

You have a car that is full of what are basically laptop batteries, a whole bunch of these little batteries, they're all hooked up in parallel and series in order to get to the right voltage and supply the right amount of current. Those batteries just like your laptop, have a limited life. It can only be cycled so many times. Maybe it's a total of a thousand cycles. This is quite a bit, but at some point, those batteries aren't worth much or anything, and they're going to have to be replaced. By the way that is the most polluting part of these electric cars is the manufacturing and transportation of those battery components. But I digress. So you have to replace them at some point.

How about these new pieces of software that come out with, or even hardware? For instance, Tesla is completely devoted to using cameras to figure out its autonomous driving mode, versus some of these other cars that are using LIDAR, which is a laser radar combination that does absolutely phenomenal.

What happens if Tesla decides, Hey, listen, we just couldn't pull it off with what we had. So we're going to have to add some more hardware. Maybe they need a faster processor, more memory, more storage on another sensor, whatever it might be, then that car has limited use.

I bet you'd say so does a 1980 Mercedes diesel. Doesn't it.

We're gonna continue this when we get back. So make sure you stick around to listening to Craig Peterson and you can find me of course, online. Just visit me at Craig peterson.com/subscribe.

I'll send you my weekly newsletter. I won't pester you. I'm not one of those crazy marketers. Craig peterson.com.

That's where you'll find it all.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses Ballot Question 1 coming up in Massachusetts in the next two weeks and a take you may not have been expecting. Tune in.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

So with our fancy electronic cars driving around and our electric cars driving around, how do you repair them? Should you have the right to repair those vehicles? That's the question they're asking in Massachusetts next month.

Hi guys. You are listening to Craig Peterson.

These cars, the Tesla has been on the market now for quite a few years, back in 2013, Massachusetts voted here on this right to repair legislation.

The idea was that these car manufacturers should not keep you out of your vehicle while working on it. Having just a regular car guy, car shop, whoever it is, you got a gal that does it? You could not have them mess with your car and still retain the warranty, in many cases. So they changed that law.

Now we have these cars that thankfully are 90% software. What do we do now? The reason I said 90% software is, of course, you've got the chassis, right? You've got the suspension. You've got a steering wheel. You have a gas pedal. You have a brake pedal. You have a motor or motors depending on the vehicle that's all mechanical.

That's all parts and pieces. Some of them move. Some of them don't move. Don't forget about the brakes, but every last one of those things is controlled by computer, even in a standard car, nowadays. I've ranted and raved about how I'll never drive a Volvo because they make assumptions about when the car should take over. It's kind of true for every vehicle. That steering wheel probably does not have a mechanical linkage to those front wheels on your car. Did you know that? Turning that steering wheel, all that's really doing is setting off a sensor in the steering column. That brake pedal almost certainly is not connected to the brakes on your car. Right?

It used to be, you push it down. There's a diaphragm created pressure. They use that to amplify through hydraulic pressure to the brakes, and then the brakes would grab whatever type of brakes you had. Right? Sometimes it was strictly mechanical as well, without that hydraulic assist in there. Same thing with the steering wheel, that gas pedal is guaranteed to not be hooked up directly to the engine. Used to be you'd push down the gas pedal and what would it do? It would change some valves in the carburetor or a little bit later on in the fuel injector and feed the fuel into the car nowadays. All it is is a rheostat or potentiometer.

Just a little dial like you might have on your television that is being manipulated. Buy that gas pedal, go, and have a look. Next time. You're there down there, cleaning out the car, getting rid of all of that salt from the wintertime, looking down at that car. And when you're down on the floor, the driver's side. Look at where the gas pedal is, but you can see this more, obviously in most cars on the gas pedal and the brake pedal look up, you'll see the linkage just goes to a little dial. Well, most of the time now, That's all well and good, but what it means is our cars no longer have that mechanical linkage.

If you go to my Mercedes, my 1980 Mercedes diesel, you will see mechanical linkages to everything. When I push on that accelerator, there is a steel rod that goes up under the hood of the vehicle that tilts forward control on the fuel injectors that inject the diesel into the cylinders. It is absolutely something that you can look at.

If it's jammed, you can look and see why you can replace a bearing. You maybe add a little grease here or there, you can straighten out a bent rod. But when it's software, what can you do? How much can you tinker with it? And if you tinker with it, what's going to happen?

Now with motor vehicles, it's become pretty obvious over the years, whoever touched it, whoever broke it, whoever caused an accident to occur, is the person or company, liable for the accident. So for repairs, damages, whatever might be involved.

How about an electric car? That's self-driving who carries the insurance, who has the liability. I think you know. I personally would carry insurance just in general, right? Some broad-based insurance, but is Tesla responsible for this? When that Tesla car hits someone who's responsible?

We know what just happened in Phoenix within the last month where charges were brought against a driver that was sitting there in one of these autonomous vehicles. It was driving down the road and hit a lady on a bicycle. As I recall, as she was crossing the road. Now the car didn't properly detect what was happening, so it did not stop in time.

The driver apparently wasn't paying attention, right? Drivers in quotes, air quotes, because obviously, they weren't paying attention. So that driver got charged and it's not going to be fun for that driver.

When that vehicle truly is represented to be autonomous, what happens when there is no more steering wheel in the vehicle, or whose responsible? You probably can say the manufacturer's responsible for it.

If you have the right to repair your vehicle, what does that mean? How far does that go? If you tinker with your vehicle and the software in it? You might burn out the electric motor, just like changing the chip and your engine might damage the engine, my damage to the valves, or whatever might get damaged. At that point you take it in, they look at it, the dealer manufacturer says, hey, you broke it. It's yours. We're not fixing it or at least we're not going to pay to fix it. You can pay.

So what happens now with an electric vehicle? And what happens when you trace that liability down and say, okay, who's responsible here. What happens if that person who's responsible is you because you had the right to repair and you went a little further than might be prudent.

This is an example of the law outpacing technology. Usually, the law is behind the technology. It's usually years behind technology. And that makes sense.

That gives the technology a bit of a chance to get established and then once its established then the technology can be rolled out and we know what the laws should be because you never know what's going to happen until it happens.

Now, personally, I think we have far too many laws and some basic rules or laws about liability are probably all we need.

We don't need laws about every little bit of liability, but there are a lot of questions that would need to be answered. That's where the judiciary can come in, not to make laws certainly, but to interpret the law, and say that law means you cannot kill someone negligently and therefore it's your problem and can get that all resolved. So that has years to come.

So you can see I think, how this all relates to this 2020 Massachusetts question one ballot initiative. This is the sort of thing we're starting to see all over the country here. How can traditional independent automotive repair shops, aftermarket parts, suppliers, home, tinkerers, and mechanics? How are they going to function as part of the automotive ecosystem? This ballot initiative aims to enact a law that makes vehicle-specific data for opening connectivity available to anyone. For the purposes in this case of quotes, maintaining, diagnosing, and repairing the motor vehicle. So interesting problems in trust and repurposing it. Personally, I think it's a safety threat.

I think it's a little too ahead of the game.

Hey, when we get back, we've got a lot more to talk about.

We are going to talk about Ring a little bit here and there. Latest security cameras. I don't know if you've been following this market much lately, but this is pretty cool.

You'll find out more about this by going online.

Craig Peterson dot com

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses a new home security device from Ring. The always-on home cam -- get this... it is a drone. Then he talks about Elon Musk and his 25,000 Completely Autonomous Tesla he will have in 3 years. Plus, you better think twice, or three times before paying that ransom to get your data back.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

You've been looking for a home security system. We've talked about a few of them on the show before. Right now we're going to be talking about a completely different approach to home security and what Ring's latest camera is all about.

Hi everybody. Craig Peterson here. Thanks for joining me.

Okay. Ring has been around for a while. As I recall Ring was purchased, two, three years ago by our friends over at Amazon. They have some interesting security stuff and they've certainly had their fair share or share of computer problems, security problems here over the years who hasn't, right?

This is what's being called a true ambitious new home security device. This thing is really cool. It sits there. It just, it says Ring on the front. it's just a little square almost. The device has got rounded corners, so looks very nice. And it's got a little light button on it.

One of those little Rings, which is always cool, but it's called the always home cam. And this thing reminds me a little bit of a movie that I've enjoyed many times called Tron from way back when. You might even remember these flying T things, although they had two legs on them and they flew around, that's what this Ring looks like.

It is an autonomous and manual little Quadrocopter, and it is designed where all of the blades are completely hidden if you will. So they're not going to run into anything. They're not going to hurt anything or anyone and hanging beneath these four enclosed blades is a thing like a pack of gum. You remember the old packs of gum, the long thin ones. That's it looks like underneath these four blades. So the idea is you pay them 250 bucks and you plug this thing in, you're going to have to configure it obviously, but it is this little, I guess a Quadrocopters, how I describe it that sits in its charging base.

Now, when it's in the charging base, it's the tail, the long downward part of the T that sits completely immersed in the charging base.

So this charging Base goes all the way up around the base of the Quadrocopter. And it's just the blades that are exposed on top. What it has on that is a camera. I imagine it probably also has a microphone. It doesn't say, but it has a little camera. So when it's in the dark it's charging and that camera is not active.

Even if it was it wouldn't be able to see anything. But what's really cool about this thing is that it can provide you with viewpoints throughout your house. You don't need multiple cameras anymore. The Rings founder's name is Jamie Siminoff. And he's also the chief inventor said that Ring has spent the last two years called focused on the development of the device.

And that it is an obvious product that is very hard to build. And thanks to advancements in drone technology. Ring pulled it off. They're not available yet. It's called the "always home cam." So I'm keeping an eye out for this thing. It is quite cool. It, you can program it what path to take, where it can go.

When you first get it, you build a little map of your home for it to follow. And it asks you for specific viewpoints, such as the kitchen or the bedroom, and the drone can be commanded to fly on-demand or programmed to fly when a disturbance is detected. So you might have a Ring alarm system you in that might include a window opening sensor door, opening sensor. So this little drone can fly up in the air. When it detects someone trying to break in and off it goes, isn't that cool? The drum makes an audible noise when it's flying. Of course, it's small and it's got all these little blades for little blades. So it's obvious when footage is being recorded.

I'm looking at a picture of her right now. It's very cool. Indoor only it's got high Def Ten-Eighty P video. It only records when it's in flight, the propellors are enclosed and integrates with the Ring alarm. So if you are a Ring fan, Check it out. If you're looking for home security, it is not a bad thing.

If you are a business, do not buy Ring. Okay. Because there are real security problems with some of these devices. They are not certified for use in any business that has any federal contacts. In the near future, it's all being disallowed. So just keep that in mind as well. If you're looking to buy security stuff. Also the cheap security stuff we have found backdoors in. Chinese spies that they're just getting in and they are messing around. So be careful of the Panda out there that is the bottom line.

Now we were talking about Teslas earlier, autonomous cars, electric cars. I got to add this. I was thinking about it as we were talking, but Elon Musk announced just about two weeks ago some amazingly aggressive plans. He has built a big battery plant. You probably know about that. I think that was in New Mexico or Nevada. I can't remember. Might be in Nevada. His whole goal behind all of this is to just slash the costs of producing batteries. And he says, Elon Musk, that is that within three years, he's going to have a fully autonomous electric vehicle for $25,000. Isn't that absolutely amazing?

Now they were expecting that he would be announcing a million-mile battery, which would be, wow! If he had a million-mile battery and a $25,000 Tesla, I would buy it. I would sell some of the other cars and buy them. They also announced a car that has over a 500-mile range. You're going to have to use one of their supercharge to get that thing charged back up again. But it's absolutely amazing.

Could you imagine that a $25,000 electric vehicle battery operated to the market within three years now, the other giveaway from this, because he said it would be autonomous that means, by the way, he has a goal of an autonomous vehicle within three years? So that's another thing to consider.

So the model asks the three, my daughter just bought a Tesla Model three, and she's barely used it yet, but she's absolutely loved with it. It is cool. There's no doubt. It is very cool, technology here.

I got to hit this before the hour runs out and that is that paying ransomware could land you in jail. This is a fascinating article, came out in about a week ago in ARS Technica, and Dan Golden wrote this thing, but I agree with him.

I have many times had to advise people not to pay ransoms for their data and most of the time I have to admit they went and they paid the ransom.

Even these companies that say that they can get your data back by scripting it, breaking the encryption, et cetera. Even those companies, well, a large percent of them, not all of them, the percentage of them are actually paying the ransom behind the scenes.

So you pay them 50 grand and they pay the 20 grand 40 grand ransom and they make a cool 10 grand right off the bat.

Right now. I've got to also mention that there are a couple of websites out there that are dedicated to helping you break the encryption on ransomware. If you do have your data ransomed, now I'm talking about its encrypted and they say, if you want to ever see it again, you pay us. That's different than having ransomware to actually extortion saying, we stole all of your data. Then we encrypted it. And unless you pay this extortion money, not only are you not going to get your data recovered on your computers, but we are going to release everything that we stole, which is your client lists, on and on. We're going to release that to the worldwide internet.

Most companies say, Oh no, don't do that. we'll pay, we'll pay. I can understand that. Statistics I've seen right now, I think it's a little less than 50% of companies are paying the ransoms.

Now, part of the reason when I say not to pay the ransoms is you, don't want to encourage these guys. They are stealing your data. You have your intellectual property that you have spent a lifetime building, right? Or a career building it's not something that really they should be having access to and you don't want to encourage them. One of the things that these bad guys have found. Is, if they can get you to pay a ransom today, they can get you to pay a ransom in a couple of weeks. So they'll try and hit you again because it takes most companies a while. And to bring in security managed security company like mine takes a while to get everything locked down.

Usually what we'll do in that case, is we'll come in, just lock the heck down then try and restore them from backup. Hopefully, their backups are good. I got to say 80% of the time, the companies that think they have backups do not have good backups and it can't all be restored. Plus the time it takes to restore them, you got to factor all of this in. Treasury Department officials said in an official advisory published last Thursday that these bad guys are part of as designated sanctioned nexus, which means you are paying a ransom to an organized criminal or to a blocked person list. There prohibited lists, Cuba, Iran, North Korea, other countries that it is forbidden for you to do business with. So guess what ends up happening then if you pay ransoms law enforcement officials can now charge you. The treasury department, says they're going to. So keep an eye out for that.

Make sure you stick around because we'll be back here after the top of the hour.

Check out my website, Craig peterson.com. There's a whole lot of information there as well for you.

And we're going to talk about the future of computers and it has nothing to do with Intel, nothing to do with AMD, at least the way it looks right now.

So stick around and we'll tell you about upgrading your Windows machine or your Mac because it's all changing.

You're listening to Craig Peterson.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses the new firmware architecture being used in the newer computers and laptops and why this architecture is preferred.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

Hey, we've been talking about how computers are everywhere. What can we expect from our computerized cars? What can we expect from computers? Intel has had a monopoly with Microsoft called the Wintel monopoly.

Hi everybody. You're listening to Craig Peterson.

So if you missed part of today's show. Make sure you double-check and also make sure you are on my newsletter list. I'm surprised here how every week I get questions from people and it's great. That's it. I love to help.

I was asked when I was about 19 to read this little book and to also to fill out a form that said what I wanted on my headstone. That's it heady question to ask somebody at 19 years of age, but I said that this was pretty short and sweet. I said, "he helped others." Just those three words, because that's what I always wanted to do. That's what I always enjoyed doing. You can probably tell that's why I'm doing what I'm doing right now is to help people stop the bad guys and to make their lives a little bit better in the process, right? That's the whole goal. That's the hope anyway.

If you need a little help, all you have to do is reach out. Be glad to help you out. Just email me M E at Craig Peterson dot com. Or if you're on my email list, you'll get all of my weekly articles, everything I talked about here on the show, as well as my during the week little emails that I send out with videos that I've been doing.

I've been putting more together. Didn't get any out this week I had planned to, but I probably will get them out next week. I was able to make a couple of this week and we'll queue them up for the coming week, but you'll get all of that. So just go to. Craig peterson.com/subscribe. You'll find everything there. As part of all of that of course, you will also be getting information about the training that I do. I do all kinds of free training and webinars, and I've got all kinds of reports. One of the most popular ones lately has been my self-audit kit. It's a little tool kit that you can use to audit it, your business and see if you are compliant. It's just a PDF that you can take from the email that I send you. If you ask for it, all you have to do is ask for an audit kit, put that in the subject line, and email me@craigpeterson.com and we'll get you going.

So I've had a few people who have this week said, Hey, can you help me out? What do I do? I help them out. It turns out when I'm helping them out, they're not even on my email list. So I'll start there. If you're wondering where to start, how to get up to speed a little bit, right?

You don't have to know all of this stuff like the back of your hand, but you do have to have the basic understanding. Just go online. And a sign-up Craig peterson.com/subscribe would love to have you there. Even when we get into the ice station zebra weather here coming up in not so long, unfortunately, in the Northeast.

When you're thinking about your computer and what to buy. There are a lot of choices. Of course, the big ones nowadays are a little different than they were just a few years ago. Or a couple of years ago, you used to say, am I going to get a Windows computer, or am I going to get a Mac now?

I think there's a third choice that's really useful for most people, depends on what you're doing. If what you do is some web browsing, some email, and also might do a couple of things with some video and pictures and organizing you really should look at the third option. Which is a tablet of some sort and that is your iPad.

Of course, the number one in the market, these things last a long time. They retain their value. So their higher introductory price isn't really a bad thing. And they're also not that much more expensive when you get right down to it and consider the resale value of them. So have a look at the tablet, but that's really one of the three major choices also today when you're deciding that you might not be aware of it, but you are also deciding what kind of processor you're going to be using.

There is a lot of work that's been done going on arm processors. What they are called A R M. I started working with this class of processor, also known as RISC, which is reduced instruction set processors, many years ago, back in the nineties. I think it was when I first started working with RISC machines.

But the big difference here is that these are not Intel chips that are in the iPads that are in or our iPhones, they aren't Intel or AMD processors that are in your Android phones or Android tablet. They're all using something that's called ARM architecture.

This used to be called advanced risc machine acorn risk machine. They've been around a while, but ARM is a different type of processor entirely then Intel. the basic Intel design is to try and get as much done with one instruction as possible.

So for instance, if you and I decided to meet up at a Dunkin donuts, I might say, okay, so we're going to go to the Duncan's on Elm Street, but the one that's South of Main Street, and I'll meet you there at about 11 o'clock.

And then I gave you some of the directions on how to get to the town, et cetera. And so we meet at dunks and to have a good old time. That would be a RISC architecture, which has reduced instructions. So you can tell it, okay, you get to take a right turn here, take a left turn there. In the computing world, it would be, you have to add this and divide that and then add these and divide those and subtract this.

Now to compare my little dunk story. What you end up doing with an Intel processor or what's called a CISC processor, which is a complex instruction set, is we've already been to dunks before that dunks in fact, so all I have to say is I'll meet you at dunks. Usual time. There's nothing else I have to say. So behind all of that is the process of getting into your car, driving down to dunks the right town, the right street, the right dunks, and maybe even ordering.

So in a CISC processor, it would try and do all of those things with one instruction. The idea is, let's make it simple for the programmer. So all of the programmers have to do if the programmer wants to multiply two double-precision floating-point numbers, the programmer that if he's just dealing with machine-level only has to have one instruction.

Now those instructions take up multiple cycles. We can. Get into all the details, but I think I've already got some people glazing over. But these new ARM processors are designed to be blindingly fast is what matters. We can teach a processor how to add, and if we spend our time figuring out how to get that processor to add faster.

We end up with ultimately faster chip and that's the theory behind risk or reduced instruction set computers, and it has taken off like wildfire.

So you have things like the iPad pro now with an arm chip that's in there designed by Apple. Now they took the basic license with the basic ARM architecture and they've advanced it quite a bit. In fact, but that Ipad processor now is faster than most laptop processors made by Intel or AMD. That is an impressive feat.

So when we're looking a little bit forward, we're no longer looking at machines that are just running an Intel instruction set. We're not just going to see, in other words, the Intel and AMD inside stickers on the outside of the computer. Windows 10 machines running on ARM processors are out already.

Apple has announced arm based laptops that will be available very soon. In fact, there is a scheduled press conference. I think it's next week by Apple, the 15th. Give or take. Don't hold me to that one, but they're going to have a, probably an announcement of the iPhone 12 and maybe some delivery dates for these new ARM-based laptops.

So these laptops are expected to last all day. Really all day. 12 hours worth of working with them, using them. They're expected to be just as fast or faster in some cases as the Intel chips are. So ARM is where things are going.

We already have the Microsoft updated surface pro X. That was just announced about two weeks ago, which is ARM-based. We've gotten macs now coming out with their ARM-based versions. In fact, I think they're going to have two of them before the end of the year. Both Apple and Microsoft are providing support for x86 apps. So what that means is the programs that you have bought that are designed to run on an Intel architecture will run on these ARM chips.

Now, as a rule, it's only the 64-bit processes that are going to work. The 32-bit processes, if you haven't upgraded your software to 64 bits yet you're gonna have to upgrade it before you can do the ARM migration. We're going to see less expensive computers. Arm chips are much cheaper as a whole than Intel. Intel chips are insanely high priced.

They are also going to be way more battery efficient. So if you're looking for a new computer. Visual studio code has been updated optimized for windows 10 on ARM. We're going to see more and more of the applications coming out.

And it won't be long, a couple of years now, you will have a hard time finding some of the Intel-based software that's out there.

Hey, you're listening to Craig Peterson.

Stick around. Cause we'll be right back and "it won't happen to me." That's our next topic.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses the problem that many businesses face -- employee apathy and lack of security awareness.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

We've got companies who are investing a lot of money to upgrade the technology, to develop security processes, boost it. Staff yet studies are showing that they're overlooking the biggest piece of the puzzle. What is the problem?

Hey everybody. You're listening to Craig Peterson.

Employee apathy has been a problem for many businesses for a very long time. Nowadays, employee apathy is causing problems on the cybersecurity front. As we've talked about so many times, cybersecurity is absolutely critical. For any business or businesses are being attacked sometimes hundreds of times, a minute, a second, even believe it or not.

Some of these websites come under attack and if we're not paying close attention, we're in trouble. So a lot of companies have decided while they need to boost their IT staff. They've got to get some spending on some of the hardware that's going to make life. Better. And I am cheering them on.

I think both of those are great ideas, but the bottom line problem is there is million-plus open cybersecurity it jobs. So as a business, odds are excellent that you won't be able to find the type of person that you need. Isn't that a shame?

But I've got some good news for you here. You can upgrade the technology that's going to help. But if you upgrade the technology, make sure you're moving towards, what's called a single pane of glass. You don't want a whole bunch of point solutions. You want something that monitors everything. Pulls all of that knowledge together uses some machine learning and some artificial intelligence and from all of that automatically shuts down attacks, whether they're internal or external, that's what you're looking for.

There are some vendors that have various things out there. If you sell to the federal government within three years, you're going to have to meet these new requirements, the CMMC requirements, level three, four, level five, which are substantial.

You cannot do it yourself, you have to bring in a cybersecurity expert. Who's going to work with your team and help you develop a plan. I think that's really great, really important, but here's where the good news comes in.

You spent an astronomical amount of money to upgrade this technology and get all of these processes in place and you brought in this consultant, who's going to help you out. You boosted your IT staff. But studies are starting to indicate that a lot of these businesses are overlooking the biggest piece of the puzzle, which is their employees.

Most of these successful attacks nowadays are better than 60%, it depends on how you're scoring this, but most of the attacks these days come in through your employees.

That means that you clicked on a link. One of your employees clicked on a link. If you are a home user, it's exactly the same thing. The bad guys are getting you because you did something that you should not have done. Just go have a look online. If you haven't already make sure you go to have I been poned.com. Poned is spelled PWNED

Have a look at it there online and try and see if your email address and passwords that you've been using have already been compromised. Have already been stolen. I bet they have, almost everybody has.

Do you know what to do from that? This is part of the audit kit that I'll send to you. If you ask for that. Kind of goes through this and a whole lot of other stuff. But checking to see if your data has been stolen, because now is they use that to trick people.

So they know that you go to a particular website that you use a particular email address or password. They might've been able to get into one of these social networks and figure out who your friends are. They go and take that information. Now a computer can do this. They just mine it from a website like LinkedIn, find out who the managers in the company are.

And then they send off some emails that look very convincing, and those convincing emails get them to click. That could be the end of it. Because you are going somewhere, you shouldn't go and they're going to trick you into doing something. Knowledge really is the best weapon when it comes to cybersecurity.

A lot of companies have started raising awareness among employees. I have some training that we can provide as well. That is very good. It's all video training and it's all tracked. We buy these licenses in big bundles. If you are a small company contact me and I'll see if I can't just sneak you into one of these bundles.

Just email me @craigpeterson.com in the subject line, put something like training, bundle, or something. You need to find training for your employees and their training programs need to explain the risk of phishing scams. Those they're the big ones. That's how most the ransomware it gets into businesses is phishing scams. That's how ransomware gets down to your computers.

You also need to have simulations that clarify the steps you need to take when faced with a suspicious email. Again, if you want, I can point you to a free site that Google has on some phishing training and it's really quite good.

It walks you through and shows you what the emails might look like and if you want to click or not. But there's a lot of different types of training programs. You've got to make sure that everybody inside your organization or in your, the family is educated about cybersecurity.

What do you do when you get an email that you suspect might be a phishing email? They need to know that this needs to be forwarded to IT, or perhaps they just tell IT, Hey, it's in my mailbox, if IT has access to their mailbox, so IT can look at it and verify it.

You need to have really good email filters, not the type that comes by default with a Microsoft Windows 365 subscription, but something that flags all of this looks for phishing scams and blocks them.

There's been a ton of studies now that are showing that there is a greater awareness of cybersecurity dangers, but the bottom-line problem is that employees are still showing a lax attitude when it comes to practicing even the most basic of the cybersecurity prevention methods. TrendMicro, who is a cybersecurity company.

We tend to not use their stuff because it's just not as good. But TrendMicro is reporting that despite 72% of employees claim to have gained better cybersecurity awareness during the pandemic 56% still admitted to using a non-work application on a company device. Now that can be extremely dangerous. 66% admitted uploading corporate data to that application. This includes, by the way, things like using just regular versions of Dropbox. Do you share files from the office and home? Dropbox does have versions that are all that have all kinds of compliance considerations that do give you security. But by default, the stuff a home user does not get the security you need. They're doing all of this even knowing that their behavior represents a security risk. And I think it boils right down to, it's not going to happen to me. Just apathy and denial. So same thing I've seen, being a security guy for the last 30 years, I've seen over and over, apathy and denial. Don't let it happen to them.

By the way, about 50% believe that they could be hacked no matter what protective measures are taken. 43% took the polar opposite. They didn't take the threat seriously at all. 43% didn't believe they could be hacked.

Some interesting numbers stick around. When we get back, we're going to talk about Mac OS is driving cybersecurity rethink.

We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses the oversharing attitudes of Millennials and Generation Z, and the importance of paying attention to our networks, how it can lead to malware in businesses, and what can be done to stop it.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

By the way, to follow up on that last segment. So Millennials and Generation Z are terrible with security. They keep reusing passwords. They accept connections with strangers. Most of the time. If that's not believable, I don't know what it is. They've grown up in this world of share everything with everyone. What does it matter? Don't worry about it. Yeah. I guess that's the way it goes. Right? Kids these days. Which generation hasn't said that in the past?

You're listening to Craig Peterson. Thanks for joining me today.

We were just talking about millennials, generation Z, and the whole, it won't happen to me, employee apathy, and we've got to stop that.

Even within ourselves, right? We're all employees in some way or another. What does that mean? It means we've got to pay attention. We've' got to pay a lot of attention, and that isn't just true in the windows world.

Remember, we've got to pay attention to our network. It would be best if you were upgrading the firmware on your switches, definitely upgrading the software and firmware in your firewalls and your routers, et cetera. Keep that all up to date.

Even as a home user, you've got a switch or more than one. You've got a router. You've got a firewall in many cases, that your ISP internet service provider provides equipment. If you've got a Comcast line or a FairPoint, whatever, it might be coming into your home, they're providing you with some of that equipment, and you know what their top priority is not your security. I know. Shocker.

Their top priority is something else. I don't know, but it sure isn't security. What I advise most people to do is basically remove their equipment or have them turn off what's called network address translation. Turn off the firewall and put your own firewall in place. I was on the phone with a lady that had been listening to me for years, and I was helping her out. In fact, we were doing a little security audit because she ran a small business there in her home. I think she was an accountant if I remember right. She had her computer hooked up directly to the internet. She misunderstood what I was saying. I want to make this clear what I'm saying here. People should still have a firewall. It would be best if you still had a router, but you're almost always better off getting a semi-professional piece of hardware. If you will, the prosumer side, something like the Cisco GO hardware, put that in place instead of having the equipment that your ISP is giving you.

We've got to keep all of this stuff up to date. Many of us think that Macs are invulnerable, Apple Macintoshes, or Apple iOS devices, like our iPhones and iPads. In many ways, they are. They have not been hit as hard as the Windows devices out there.

One of the main reasons is they're not as popular. That's what so many people that use Windows say you don't get hit because you're just not as popular. There is some truth to that. However, the main reason is that they are designed from the beginning with security in mind; unlike Windows, security was an absolute afterthought for the whole thing.

Don't tell me that it's because of age. Okay. I can hear it right now. People say, well, Mac is much, much newer than Microsoft Windows. Microsoft didn't have to deal with all of this way back when. How I respond to that is, yeah. Microsoft didn't have to deal with it way back when it wasn't connected to a network and your viruses coming in via floppy desk. Right? They really were. In fact, the first one came in by researchers. Apple's operating system is much, much older than windows and goes back to the late 1960s, early 1970s. So you can't give me that it is just that they didn't care.

They didn't care to consider security at all, which is still one of my soapbox subjects if you will. Security matters. When we are talking about your Macs, you still have to consider security on a Mac. It's a little different on a Mac. You're probably want to turn on some things.

The windows come with the firewall turned on; however, it has all of its services wide open. They're all available for anybody to attach to. That's why we have our windows hardening course that goes through, what do you turn off? How do you turn it off? What should you have in the windows firewall?

Now the Mac side, all of these services turned off by default, which is way more secure. If they're not there to attack, they're not going to be compromised. Right. They can't even be attacked in the first place. So I like that strategy, but you might want to turn on your firewall on your Mac anyways.

There are some elegant little features and functions in it. But the amount of malware that's attacking Apple Macintoshes, nowadays, is twice as much as it used to be.

We've got these work from home people. We've got IT professionals within the companies, just scrambling to make it so that these people working from home can keep working from home. It's likely a permanent thing. It's going to be happening for a long time. But these incidents of malware on the Mac is pretty limited in reality.

The malware on a Mac is unlikely to be any ransomware or software that particularly steals things like your Excel files or your Word docs on a Mac, and I should say it is much more likely to be outerwear. It's much more likely to be. Adware or some other unwanted programs, and that's what's rising pretty fast on Macs.

Mac-based companies are being concerned here about cybersecurity issues. They are paying more attention to them. They're windows based counterparts have had to deal with a lot of this stuff for a long time because they were targets. So we've got to divide the Mac really into two pieces, just like any other computer. You've got the operating system with its control over things like the network, et cetera. Then you have the programs or applications. That is running on that device. So you want to keep both of them secure. The applications running on your device, Apple's done a much, much better job of sandboxing them. Making them so that they're less dangerous. The latest release, in fact, Catalina had a lot of security stuff built into that. Microsoft and Windows 10 added a lot more security. So that's all really, really good.

Now, if you have to maintain a network of Macs, we like IBM software. They have some great software for managing Macs, but if you want something inexpensive and very usable to configure Macs and control the software on them. Have a look at JAMF, J A M F. They just had their user's conference this last weekend. They were talking about how the landscape has changed over on the Mac side.

All right. We've got one more segment left today, and I'm going to talk about these cybersecurity frameworks. What should you be using?

If you are a business or a home user, what are those checkboxes that you absolutely have to have to use?

You're listening to Craig Peterson.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses Cybersecurity Audits, Compliance, NIST Standards, CMMC, and what is expected of the Department of Defense Contractors and Sub-contractors in this segment.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Right To Repair Or A Fight For Survival?

Ring’s latest security camera is a drone that flies around inside your house

Malware Attacks Declined But Became More Evasive in Q2

Elon Musk reveals plans to slash electric battery costs, build $25,000 Tesla

Paying ransomware demands could land you in hot water with the feds

Windows 10 machines running on ARM will be able to emulate x64 apps soon

'It Won't Happen to Me': Employee Apathy Prevails Despite Greater Cybersecurity Awareness

Rise in Remote MacOS Workers Driving Cybersecurity 'Rethink'

A Guide to the NIST Cybersecurity Framework

---

Automated Machine-Generated Transcript:

You might've heard about cybersecurity frameworks? Well, the one that's most in use right now is the NIST cybersecurity framework that helps guide you through the process of securing your business or even securing your home. That's our topic.

Hi everybody. Craig Peterson here.

It's a great time to be out on the road and kind of checking in. Of course, you can find me online at craigpeterson.com. We've got security threats that have been growing quite literally. Exponentially. They are really making a lot of money by extorting it from us, stealing it from us. It's nothing but frustration to us.

It's never been more important to put together an effective cybersecurity risk management policy. That's true if you're a home user and you've got your yourself and your spouse and a kid or two in the home. Have a policy and put it together.

That's where NIST comes in handy. NIST is the National Institute of standards and technology they've been around for a long time. They've been involved in cryptography. These are the guys and gals that give us accurate clocks. In fact, we run two clocks here that we have for our clients, which are hyper-accurate. It's crazy it down to the millionth of a second. It's just amazing. That's who NIST is.

They've put all these standards together for a very, very long time, but just before March, this year, It was reported that about 46 percent of businesses had suffered cyber attacks in 2019. That was up 10% from the year before. Of course, we've all been worried about the Wuhan virus, people getting COVID-19, it is a problem.

The biggest part of the problem is everybody's worried about it. Nobody wants to go to work. They don't want to go out to a restaurant. They don't want to do any of these things. You as a business owner are worried about how do you keep your business doors open? How do you provide services to the customers you have when your employees won't come in or cooperate or were paid more to stay at home than they would be to come back to work. I get it right. I know I'm in the same boat.

Well, because of that we just have not been paying attention to some of the things we should be doing. One of the main ways that business people can measure their preparedness and their progress in managing cyber security-related risks, is to use the cybersecurity framework that is developed by NIST. It is a great framework.

It provides you with different levels. The higher-end, the framework that is used by military contractors. Nowadays, we've been helping businesses conform to what's called NIST 800-171 and 800-53 High, which are both important and cybersecurity standards.

So if you really, really, really need to be secure, are those are the ones you're going to be going with. Right now, no matter how much security you need I really would recommend you checking it out. I can send you information on the NIST framework. I have a little flow chart. I can send you to help to figure out what part of the framework should you be complying with.

It also helps you figure out if you by law need to be complying with parts of the framework. It will really help you. It's well thought out. It's going to make you way more efficient as you try and put together and execute your cyber risk management policy. Remember cyber risk, isn't just for the software that you're running, or the systems you're running. It's the people, it includes some physical security as well.

Now President Trump has been very concerned about it. I'm sure you've heard about it in the news. As he's talked about problems with TicTok and with Huawei and some of these other manufacturers out there. Huawei is a huge problem. Just absolutely huge.

One of these days I can give you the backstory on that, but how they completely destroyed one of the world leaders in telecommunications technology by stealing everything they had. Yeah. It's a very sad story company you may have heard of, founded over a hundred years ago.

They're non-regulatory but they do publish guides that are used in regulations. So have a look at them, keep an eye on them. They have to help federal agencies as well. Meet the requirements is something called the federal information security management act called FISMA and that relates to the protection of government information and assets.

So if you are a contractor to the federal government, pretty much any agency, you have physical requirements.

So think about that. Who do you sell things to? When you're also dealing with the federal government they look at everything that you're doing and say, are you making something special for us? If you are, there are more and higher standards that you have to meet as well. It just goes on and on, but this framework was created by NIST ratified by Congress in 2014. It's used by over 30% of businesses in the US and will probably be used by 50% of businesses in the US this year.

So if you're not using them you might want to have a look at them. It's big companies like JP Morgan, Chase, Microsoft, Boeing, and Intel who meet a much higher standard than most businesses need to meet.

A lot of businesses all you need to meet is what's called the CMMC one standard. You'll find that at NIST as well. And there are much higher levels than that up to level five, which is just, wow. All of the stuff that you have to keep secured looks like military level or better, frankly security.

There are other overseas companies that are using it too, by the way in England, in Japan, Canada, many of them.

I'm looking at the framework right now. The basic framework is to identify, protect, detect, respond, and recover. Those are the main parts of it. That's you have to do as a business in order to stay in business in this day and age, they get into it in a lot more detail.

They also have different tiers for different tiers that you can get involved in. Then subcategories. I have all of this framework as part of our audit kit that I'll send out to anybody that asks for it that's a listener. All you have to do is send an email to me, M E @craigpeterson.com, and then the subject line, just say audit kit and I'll get back to you. I'll email that off to it's a big PDF.

You can also go to NIST in the online world and find what they have for you. Just go to NIST, N I S T.gov, The National Institute of Standards and Technology, and you'll see right there, cybersecurity framework, it's got all of the stuff there. You can learn more here if you want. If you're new to the framework they've got online learning. They are really working hard to try and secure businesses and other organizations here in the US and as I said used worldwide. It's hyper, hyper important. It's the same framework that we rely on in order to protect our information and protect our customer's information. So NIST, N I S T.gov, check it out.

If you missed it today, you're going to want to check out the podcast. Now you can find the podcast on any of your favorite podcasting platforms.

It is such a different world. Isn't it? We started out today talking about our cars. Our cars now are basically big mechanical devices ever so complex with computers, controlling them. But the cars of tomorrow that are being built by Tesla and other companies, those cars are absolutely amazing as well, but they're frankly, more computer than they are mechanical car.

So what should we expect from these cars? I'm talking about longevity here. We expect a quarter-million miles from our cars today. Some of these electric vehicles may go a half a million or even a million miles in the future. When they do that, can we expect that? Our computers get operating system updates and upgrades, for what five years give or take?

If you have an Android phone, you're lucky if you get two years' worth of updates. Don't use Android, people. It's just not secure. How about our cars? How long should we expect updates for the firmware in our cars? So that's what we talked about first, today.

Ring has a new security camera that is absolutely cool. It's called the always home cam. I talked about it earlier. It is a drone that flies around inside your house and ties into other Ring equipment. I think it's absolutely phenomenal and it's not quite out yet, but I'll let you know more about that.

If you get ransomware and you pay the ransom, the feds are saying now that you are supporting terrorist organizations. You might want to be careful because they are starting to knock on doors, and there's jail time behind some of these things. So watch it when it comes to ransomware and a whole lot more as well.

So make sure you visit me online. Go to Craig peterson.com/subscribe. It's very important that you do that and do that now.

So you'll get my weekly newsletter. I've got some special gifts, including security, reboot stuff that I'll send to you right away. Craig peterson.com/subscribe.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon, and we began talking about Cybersecurity and Businesses. We discussed some of the new Federal Regulations and how they are cracking down on businesses. We discussed some of the problems with work at home and then we discussed Cybersecurity training and Ransomware and why the Federal Government is now charging companies who pay ransoms Let's get into my conversation with Matt on WGAN.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. Thanks for joining me. And I'd love to know what do you like about the podcast? Maybe something I should do more or something I should do less of just email, me @craigpeterson.com. I'd love to hear from you. This morning, I was on with Mr. Matt Gagnon over there on WGAN, which is a fun time.

I love talking to Matt, but now in the political season, of course, most of these radio stations are pretty busy with. Politics. So I don't get quite as much time as I used to get on some of them, at any rate, we talked this morning, we covered three different topics as something we haven't talked about with any of these other radio stations this week.

So here we go with Mr. Gagnon.

It's all things. Technology tech talk with Craig Peterson right now on news radio 98, five FM and am five 60 WGAN

Matt Gagnon: [00:01:03] It's seven 36 on a Wednesday. Great time to talk to Craig Peterson, our tech guru Craig, how are you this morning, sir?

Craig Peterson: [00:01:11] Good morning. Doing well.

Matt Gagnon: [00:01:13] Craig, are you heard on this very network on Saturdays? I'm under the impression you might be.

Craig Peterson: [00:01:17] Yeah. Yeah. Saturdays from one til three. It gives me a chance to delve into some of these topics a little bit more because we only have a few minutes here every Wednesday morning,

Matt Gagnon: [00:01:28] Indeed. Let's get into that so that you have as much time as possible, Mr. Peterson. and I think that you have a lot of topics to deal with here today, but a couple of themes I'm seeing running throughout here is about security. One that caught my eye and it was pretty interesting to me was about employee apathy and how it is sort of combating against increased cybersecurity awareness. I. E. We all know more about cybersecurity, but we don't really think any of this stuff is going to happen to us and that is the open door that's necessary for a lot of it to actually happen? Interesting.

Craig Peterson: [00:02:01] Yeah, isn't that kind of the norm though, for people just kind of in general so that it's not going to happen to me, nothing. I need to worry about it, but it is causing some serious problems with the business.

When we're talking about employees here, I don't want just people to think of that man or that woman who might be manning the cash register. We're talking about all the way up the chain. Businesses are having a serious problem right now because we've got some cybersecurity.

We know that we've got something that kind of work in the past. Like they had antivirus software and we're not really aware of what's going on in general. Now we got some serious problems right now with the federal government, finding China, Russia, and others in our systems. In fact, there was an emergency order that came out just about a week ago now for anybody that is a department of defense contractor or subcontractor, even if all you do is mow the lawn for someone, that's a contractor to the department of defense.

Now you have to have serious cybersecurity. The reason that they ended up doing this is that even though the rules were passed four years ago, everybody was saying, it's not going to, it happened to me. I don't need to worry about it.

Matt, they were pencil whipping forms. So now they are coming down hard. I know a contractor who called me up last Friday saying, Hey, I've got a bit of a problem here. I'll tell this story a little bit more, but they lost 70%, seven zero percent of their business faded away. They couldn't find out why a general contractor for the federal government was no longer ordering from them.

It had to do with their apathy from soup to nuts. They were not trying to be secure. So we've got to pay attention. They really are coming after us, Matt.

Matt Gagnon: [00:03:58] Craig Peterson, tech guru joins us to this time, every Wednesday to go over the world of technology.

Speaking of security, remote workers are causing, perhaps a little bit of a rethink in cybersecurity as well. What's that all about?

Craig Peterson: [00:04:12] Yeah. You'd think that again, we've got so many people working remotely that we'd have it down by now. We've been doing this since March-ish timeframe here for most of our companies. But the biggest problem we're still seeing is a misconfiguration. Right? Machines, not patched up, businesses using VPNs incorrectly, that are giving direct lines into our businesses.

Then our employee is going back to the apathy thing where we're not taking some of the training, seriously. Every business nowadays should be doing some training. That training means that they are looking at phishing attacks. What are the bad guys doing? What do we have to be careful of now?

So be very careful if you're working from home, remember that VPN is like a tracer, right? I've tracer round works both ways. You can see where it's going and you get to see where it comes from. A VPNs the same way you can use it to get securely into your business network, but the opposite can happen. Someone else on your network, some malware, any network, and also use it to get into your business.

It gets very dangerous.

Matt Gagnon: [00:05:24] The other thing that was, is security related that I found fascinating Craig in, uh, in the list of stuff that we're going to talk about today is about what actually happens. If some sort of an attack happens like a ransomware demand is made. Then you actually pay it, that could get you in a different world of trouble.

Could it not.

Craig Peterson: [00:05:41] Yeah, this didn't use to really be the case. If you were ransomed and your data was ransomed, typically because of encryption, as opposed to extortion, where they've stolen your data and they are telling you, if you don't pay up, we are going to release all of your data that we stole from you online publicly, which is really bad too.

In this case, where your data has been encrypted, a lot of businesses

have paid the ransom in fact, businesses that are supposedly out there to decrypt your data and get it back for you. Many of those have been paying the ransom. So the treasury department has gotten finally a little bit of a crackdown here and they published just this last week.

Some new guidelines. Basically, if you are paying a ransom, you are paying a ransom to criminal organizations, terrorist organizations, and enemies of the United States. Therefore it is clearly illegal under federal law.

Now the other side of this is if you pay a ransom, the odds are only about 50%. Only about half of the time will you get all of your data back? So that's something to think about.

Then the other thing is you are not just encouraging them to ransom some more people. You're also saying, Hey, We are a company that pays ransoms. So yeah, go ahead and break in again and hold our data ransom and we'll pay.

The FBI has long advised against it, and now they're cracking down on the legal process on those people, but businesses do pay the ransom.

Matt Gagnon: [00:07:20] All right, well that is Craig Peterson. Once again, you can hear him on this very network to get into these stories and so many more in more depth on Saturday WGAN.

Craig, we appreciate you. So much as we always do on Wednesdays and we'll talk again next week.

Craig Peterson: [00:07:33] All right. And I'll be back at one on Saturday

Matt Gagnon: [00:07:36] Indeed. Thanks a lot, Craig.

Craig Peterson: [00:07:38] Keep an eye out also in your email, I've been working on a new little, three-minute coaching session and these things are just taking some time. Right. But we are getting there. We'll be getting those out, the little videos and. And I'm putting transcripts burned right into the video.

Plus if you click on the link in the email, it'll take you to my website where I have a transcript right there. So if you'd rather just read about the topic I'm talking about, and we're talking about all of the stuff you might expect. VPNs and two different types of security things you need to look at.

You can just read it right there on my website. So keep an eye out for the email. You can just click through, watch the video. You can listen to it. You can see the transcript going by, or you can just plain old read the transcript. How's that for making it easy for everybody?

All right. Take care and we'll be back hopefully before the weekend, I'll be able to get another one of these out.

Take care. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. He had a few questions about VPNs, seems like it is a little confusing for people to understand that they were designed for something completely different than what people are using them for today and that is where the problems are coming from. Then I broke some big news about the Federal Register changes and DOD contractors and sub-contractors that went into effect last night at 5 pm. Then we got a little light-hearted with a brief discussion about Love and Zoom. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] So that it can be hooked up by any technician to read what's going on. And to at least clear it, if not adjust it. Now, the opponents of this are saying, Hey, wait a minute. Now, do we really want backyard mechanics getting their hands on the software on the internal runnings of our car?

Jim Polito: [00:00:22] Yeah.

Craig Peterson: [00:00:23] Hey everybody.

We got to talk about a couple of cool things this morning. Craig Peterson here. I was on with Mr. Jim Polito. We talk about a new law, actually, it is on the ballot.

It is initiative one in Massachusetts, where it is an augmentation to another law that passed, The Right to Repair. We may do another segment on it. Jim talks a little bit about this, cause just can you cover in 10 minutes. Then also a little bit about Ring's latest security device. So here we go with Mr. Jim Polito

Jim Polito: [00:01:00] One of my favorite days of the week, just because of who visits. Our good friend and tech talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:13] Hey, good morning. That is so kind. I appreciate that.

Jim Polito: [00:01:17] Come on, come on. You offer a great segment and you help an awful lot of listeners here.

That's why I want to do two things today. Cause I know we're going to eat up all the time, just doing these two. One of them is the right to repair. Question one. If I were to look at what do I get the most questions about emails and messages, it would question one. Second, I want to talk about Rings' latest security camera, the drone.

Oh my God. That's crazy. So let me just say, folks. I will do this as the deep tease, the drone flying around your house to keep your house secure. I mean, now that's something I would buy.

But let's start off with the right to repair. Okay. Many people it's the 2020 Massachusetts question one. It's a ballot initiative. It's looking to augment the right to repair. Now I gotta tell you I'm voting. Yes on this. Okay.

But when I see the commercials against this, they are highly deceptive. That's my opinion. Let me see now if the brilliant man agrees with me and that is Craig Peterson. All right, sir. Go ahead. The floor is yours,

Craig Peterson: [00:02:48] Go for it. Right?

Yeah. This is a very, very interesting problem. We've got an article this week. In fact that I put into my newsletter, that everybody got about Elon Musk in Elon's coming out with another car. He says here within the next three years, that's going to be a $25,000 electric car from Tesla that's fully autonomous.

Now I brought that up because that's kind of the extreme. These electric cars run entirely on software. Well, of course, there are mechanics, right? There are electric motors in them, but Jim, these things are software. How do you repair software? That's really what it comes down to, nowadays.

You've got a computer. For decades, Jim, you bought a computer, Microsoft came out with a new version of the operating system. It required a faster machine, more disc space, more memory. Every time there was a new release of Windows you had to buy a new computer.

Jim Polito: [00:03:51] Right?

Craig Peterson: [00:03:51] We know on the Samsung-side and the Android-side, your phone only gets updates for two years. That's at best. Some phones have only had updates for three months.

So, what do you do when the car company decides it's not going to support it anymore? It's not going to give you updates, right? Or what happens now? When the car company says, yeah, we can fix that. It's only a $4,000 and all they do is hook it up to their computer. It uploads some software. The problem is gone. In reality, it took them less than five minutes, right. That I think is what it boils down to.

Jim Polito: [00:04:31] Okay. So I understand that I have a neighbor, one of the guys who lives across the street has a Tesla. The mechanic comes to his house in a vehicle and works on his vehicle.

You're right,. Mechanically, there aren't as many things in that vehicle. You got a suspension. You've got internal things, power windows, all that stuff, those types of things. There are mechanical things that could break, the wipers, all of that, but right. The thing that usually breaks the most, mechanically, the engine is just software.

There is an engine and it runs off a battery. But it's not as complex as an internal combustion engine.

Craig Peterson: [00:05:16] No, it needs electric motors that are in the Teslas and these other cars are designed to last a million miles. Now the batteries won't. That Tesla won't. You're only good for your Toyota Prius or your Tesla for maybe a hundred thousand miles. Although Elon Musk is working on that. We'll see he's coming out with a million-mile battery, supposedly, which would just be incredible.

But what do you do now? You've got people in the Midwest. You've got farmers who have tractors. You buy anything, nowadays, your Harley that you buy.

Jim Polito: [00:05:52] Yeah.

Craig Peterson: [00:05:54] You're out riding has computers on board. That's been true for quite a while. And so the Federal Government mandated a port in your car that is standardized so that it can be hooked up by any tech nation to read what's going on and to at least clear it, if not adjust it.

Now the opponents of this are saying, Hey, wait a minute now, do we really want backyard mechanics getting their hands on the software on the internal runnings of our car.

Jim Polito: [00:06:27] Yeah.

Craig Peterson: [00:06:28] Because it is their car. We haven't even answered the question of who's liable for an accident when a car is in the autonomous mode. Right? It's the manufacturer is the one that's liable. Should we really allow even a trained service tech to make adjustments that might be outside the specifications that the manufacturer set for the car.

There still are so many questions here, Jim, it just kind of blows my mind you to get down to it. Then there's one more point, which is that Tesla you buy this year may actually be a better car next year because Tesla is continually coming out with updates and releases and downloading into the vehicle.

So your car can actually get better and even more valuable as time goes on, as new features are added. If you're messing with that software and you install it, you got problems.

We've got a saying, I do manage security services, that's what I do. the thing is whoever touched the computer last owns the next problem.

Jim Polito: [00:07:43] My mother had a philosophy like that with things in the house too.

Craig Peterson: [00:07:47] Yeah.

So whose fault is it, when something goes wrong? If people have been tinkering with it. It's one thing to maybe replace an electric motor. We've had issues even with these inkjet printers, they'll give you a printer for free because the ink costs an arm and a leg. They put into the ink cartridges, little computers to track whether or not this is an unofficial cartridge. Your printer won't work with an official cartridge that we overcharged for.

Jim Polito: [00:08:15] All right. I want to make sure we get the Ring in. So the bottom line is. What am I doing with question one? I mean, if Tesla is going to continue to update the software in their vehicles, are we saying they're going to charge for it if they do. We're saying that my local mechanic can't do that.

Craig Peterson: [00:08:35] Yeah. Well, again, does your local mechanic have the actual capability, the ability to manipulate the software in such a way that it retains it's security. It's integrity. If by opening it up to the local mechanic, or we now opening it up to maybe state-run bad actors that are out there that want every Tesla in the country to crash on September 11th. Potentially, a big deal. I think that there's another idea. Example of the law, trying to get ahead of technology, and these lawmakers really just trying to make a bit of a name for themselves, right? It's not a big problem yet and there's too many unresolved.

All right. We, you know what, I think we need to do a segment on this alone because we need more time to go through this.

I think I need to bring you back on a day when we're not doing the regular segment and do that.

Jim Polito: [00:09:28] But meanwhile, as the clock winds down, I need to hear about this, the Ring - drone, the new always-on home cam. An autonomous drone that can fly around your house. That's going to drive pops crazy when we're not home, you know. I don't know if he's going to like that. He just may be able to jump up and get it.

Craig Peterson: [00:09:51] You might want to take the lasers off of it. It doesn't like zap pops.

Jim Polito: [00:09:57] So wait a minute. Tell us quickly what this is. We've only got about two minutes.

Craig Peterson: [00:10:02] Here's what it is. This thing's expected to cost about 250 bucks and the calling of the always home cam. What this is, it looks like a T the letter T capital T in fact, and it has motors in it. Obviously, it has little fans and the camera itself is down at the bottom of the T and it's in a charging station.

So if it's not flying that camera's not going to work it, can't sit there and monitor you.

The idea behind this is if anything happens if any of the other Ring sensors detect something or even on a regular interval, it's going to fly around the house is fully autonomous mode as well. You can tell it where you want it to go, and it's going to give you viewpoint and it's going to record stuff.

If it hears a window smash, it's going to go have a look and it's going to be streaming the video. that video will be stored online and you can see exactly what's been happening.

Jim Polito: [00:10:59] That is cool. Now that's something I can go for. I'll tell you what my mother-in-law has. One of the autonomous vacuums, I helped her to set it up, which I thought was very cool.

You know, for our house, that thing would get a hernia with all the hair that the dog is shedding. For my inlaws, it's perfect. It just takes off at a certain point, cleans up vacuums. This picks up this thing. Yeah.

This thing sounds great and we're going to have to talk more about it in the future.

Alright, Craig, I did have a question. A gentleman from Boston, Joe from Boston wanted to ask you about five G, and I don't have time to get to him.

Craig Peterson: [00:11:39] Yeah

Jim Polito: [00:11:40] How can he reach out to you or send a message and try to get some kind of an answer in between segments.

Craig Peterson: [00:11:48] Well, I'm always available at me. M E @craigpeterson.com. You can just drop me an email, anytime me@craigpeterson.com. Remember I have a busy schedule, so it might take me a couple of days to get back to you, but I always do.

Jim Polito: [00:12:04] You heard that Joe, me at Craig Peterson, which is spelled P E T E R S O N, but that is the Canadian pronunciation, even though Craig Peterson is all red, white, and blue. He's still got a maple leaf in there somewhere. Correct? Listen, this was a great segment. Very interesting. And again, I'm going to, I'm going to reach you offline and we should talk more about this, cause that's fascinating about Tesla software, it's basically turning a car into a laptop and who's going to give you the updates. I find that very, I find that very, very interesting. So, Mr. Peterson, always a pleasure and I hope folks listened to your show Sundays at 11 o'clock. And then it is dropped into the schedule on at other points on the weekend at times.

So a great, great show. And then we look forward to talking with you next time.

Craig Peterson: [00:13:00] All right. Thanks, Jim. Take care.

Jim Polito: [00:13:02] Thank you. All right. When we return a final word, you're listening to the Jim Polito show, your safe space.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed the political perceptions of the electorate in the age of Social Media and how it is affecting our decisions. Here we go with Jack.

These and more tech tips, news, and updates visit

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] You remember it was your Tesla. You're getting updates over the air. Over the internet, new software, new features impact your Tesla might be better next year than it is this year, just because of a software update, cheap electric cars, repair bills that add up farmers having to maybe throw away $800,000 tractors.

And we kinda got into it this morning with Mr. Heath. Usually, my hits with a Jack are short and sweet. Here we go, Craig Peterson and Jack Heath.

Jack Heath: [00:00:34] All right. Joining us now with a tech talk update, Craig Peterson. Craig, what a new Tesla's coming out?

Craig Peterson: [00:00:41] Yeah. Hey, maybe it's car talk today because yeah, we've got a couple of things about cars and talk about, first of all, Elon Musk has been busy.

We know this guy with his Tesla cars. He's been trying to drive the price down, at least the cost of manufacturing down, and the main way he's been working on that is through announcing what we're calling a million-mile battery, a battery that will last a lifetime of one of these electric cars. They potentially could get a million miles because it's electric motor versus all the mechanical systems.

What he is doing right now is, he has announced at least within three years, he plans on having an electric car that will cost $25,000 and he says this vehicle is going to be fully autonomous. Just phenomenal things here. We'll be talking more about this on my show Saturday at 1130. With the battery cost down substantially, it's getting more affordable for anyone who might want an electric car.

Jack Heath: [00:01:45] Interesting. Of course, Tesla, what a ride that is no pun intended. All right. Anything else for us, Craig?

Craig Peterson: [00:01:51] Another point here is you buy a car, when does that car outlive its usefulness to you and to everyone else? If you buy a computer, it gets to the point where it's time to upgrade. You have to not just upgrade the software, but the hardware.

How about these cars? These computerized cars nowadays. There's a big fight and down in Mass right now on a bill, actually this ballot question one on right to repair, again.

They passed a law in 2013. We tried to pass one in New Hampshire last year, which didn't make it out of committee very far. The problem is if you have one of these cars and the manufacturer decides not to support your model anymore, after some number of years. Or the dealer wants to charge you a crazy amount of money to do something simple, shouldn't you have the right to repair that vehicle.

They're trying to open up the cars to the point where a regular auto mechanic shop could buy some equipment that would allow them to fine-tune the vehicle.

Remember with your Tesla, you're getting updates over the air over the internet, new software, new features. In fact, your Tesla might be better next year than it is this year, just because of a software update.

So question one is going to be interesting in Mass this year, they're trying to open cars up even further. The car dealers and manufacturers are saying, Oh, no, we can't do that because of security problems. If we allow the mechanics to get into the guts of the car, What's going to happen?

Those are some big questions coming up ahead here, but that $25,000 Tesla sounds pretty interesting.

All Right.

Justin McIssac: [00:03:37] I was going to say, Jack, that Rights to Repair thing has been a huge deal, right?

Well, not only Mass but in the Midwest with John Deere has been in a fight for years with farmers because those tractors have the same sort of software in them.

The farmers have gone to having their tractors hacked so that they can get them fixed rather than buying a new $800,000 tractor. It's been a whole big thing.

Craig Peterson: [00:03:58] It's expensive. Isn't it?

Jack Heath: [00:03:59] I heard a spot in one of the areas wherein terms you decided to go to a local shop versus.

All right. Craig, Thank you very much.

Craig Peterson: [00:04:05] Take care.

Wow, did I get a ton of responses to my newsletter? Went out this weekend a little bit later on Saturday. I didn't get it out, quite, first thing in the morning on Saturday, a little slow this week. You guys have been extremely responsive. So I'm very happy about that.

Probably the biggest response I've had to a newsletter. So if you haven't read it, check it. I'll check it out right now. I tell a story, about something that happened Friday to one of my customers. It happened about two weeks ago and it's a type of thing that puts somebody out of business.

In this case, all of a sudden his orders stopped coming in. Anyways, we'll look at that. I will have another little quick video this week. At least one I'm trying for two. But you know how it goes.

Of course, I'll be back tomorrow and Wednesday.

I'll be back this weekend with a new show, but it might be a repeat, depends on how the week goes.

Cause it's a holiday weekend coming up and there's always stuff to do.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Virtual Reality is no longer just for gamers. It is now a business tool that is coming to your home office.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Massive changes ahead. We've even got traders who used to be on the floor of the stock exchange and on the floor of these massive financial companies, we've even got them at home. Now you're going to be shocked at what they're doing to replace that interaction.

Hi everybody. Craig Peterson here. We're going to be talking about these traders and how virtual reality headsets have changed the way some of them are doing business. We're going to talk about what's on your enterprise network. I talked about this last week.

Hopefully, you got my email, it came out on Wednesday this week. I'm going to try and do two of these a week. It's three minute little a coaching lesson if you will, on security. This week we talked about your enterprise network. We're going to delve into that more today.

Have a look in your email make sure you got that. I know you're used to getting emails from me Saturday mornings. This last weekend we sent our weekly email on Sunday instead of Saturday, I'm not sure if that's better for you guys or not. We certainly didn't have quite as many people open it as usual.

Usually, it's almost half of everybody that's on the list and that's thousands of people open it but not as good on Sunday. We may switch back to Saturday. We'll see.

It also has to do with our time, right? This is a labor of love, trying to get all this information out to everybody. So things can change.

We're going to talk about some big changes. Changes in malware attacks this year, even though the decline a little bit in Q2. They got more potent, and we'll tell you why what's going on years.

Most severe of Windows bugs is now under active exploit. We'll tell you about that. VPNs are dying. You know what my thinking is about these paid VPN and free VPN services. If you've been listening long enough, right? They do not increase your security. In fact, they decrease your security in some ways. Maybe you're going to stop your local ISP from tracking where you're going online, but you're you overall are much less secure.

Shopify. We've got a huge theft of the hair and turns out it kind of employees involved. We've got Microsoft booting more Chinese sponsored hackers out.

Wanna Cry. That yeah yeah, that same one that brought the country and the world to its knees a couple of years ago. It's back. And love in the time of Zoom. So if I don't get to all of these today, make sure you check online, or if you're going to miss part of this, all of that available there, Craig peterson.com. We're trying to make sure all of the audio is up there so that you can listen to it in your time on any podcast app. Make sure you check it out, whatever your favorite app is.

Technology has really changed everything and we have seen that this year, they expect to be just an incredible online shopping season. Now that's good and that's bad. You've got the local stores who are hurting very badly. I have gone out of my way lately to try and go to a local store as opposed to ending up online and buying stuff because I want to support them. They are part of the economy, obviously. They are where my kids got some of the first jobs, in local stores. They are also the place where I can go to see things and play with things. It's not like where Amazon charges me sometimes to return something. That wasn't what I thought it was. That kind of always bothered me. So I like the local merchants and not just the restaurants, but the guys that sell the little electronic gear that we have and other things, but it's going to be a huge year this year.

We're going to talk later on today, this is kind of low on the list, but virtual online Zoom dating. It is really changing at all. Now we have a story that came up from Ars Technica this week, Owen Walker of the Financial Times, talking about how we have moved our businesses into spare bedrooms in our homes, living rooms and we've talked about this before.

If you're working from home, make sure you have a spot where all you ever do is work from home. The brain kind of ends up associating and you can become much more productive that way. Different parts of the room, maybe a different chair. Maybe all you do is turn the chair around just to let your brain know that it is time to get to work.

I also use some apps. I've got vitamin R that I've used and I don't really use it as much anymore. I've kind of grown disciplined over the years. You might check it out online. Vitamin R. It uses the Pomodoro Technique, which is an Italian name. Remember those little tomato clocks or countdown timers you have in the kitchen, or at least you used to have years ago where it just reminds you, Hey, uh, you're supposed to be working right now cause you're hearing it go tick tock, tick tock, tick tock, and then it goes off and okay, well, my 20 minutes is up for this particular task and then you take a brief few minute breaks and then you get right back to it.

There are all kinds of hacks to help us to be more productive when we're at home and ultimately more productive than maybe in the office in some ways. In other ways, you're not as productive and you're not as productive because you're not around these other people who can come over and ask questions and much of what we learn, much of what we do is just incidental communications. Where we are in a hallway, we bump into someone or we go to a meeting, we have a side discussion. That's hard to do when you're on a WebEx team call because you're there and so are 10 other people, two other people. It doesn't really matter how many other people, because you can't just lean over and say, Hey, what do you think of this or that?

Now, obviously, on the WebEx teams, you can go ahead and type a message, right? You have that chat capability and you can send it to a specific person. You can do that on Zoom as well, but I don't. I'm not going to talk about Zoom right now because you should not be using it for business. Just you really, really should not.

So focus on that ability to communicate. Some companies are now going to happy hours online, and I've been invited to a Zoom happy hour, and the company's sending me three little bottles of wine. We're going to do it. Taste-testing and we'll just kind of chat while we're there online. It should be fun. It'll be interesting too.

Many businesses are doing that as well. They have the little happy hours and get-togethers because you're not going out after work for a drink to talk to people. You're not going out in the hallway and talking to people. It is such a different world.

The whole thing with whether or not you're there physically is a whole other problem when it comes to traders. Think about traders. If you've seen some of these movies or TV shows where they're on the floor, I know Fox business and some of these other business channels have a shot with a camera on the floor, the trading floor and there just aren't the people there that they used to be. But it's again, it's the interaction and that's what's been important in the past.

Some banks UBS particularly has been issuing some of its traders over in London. These halolenses from Microsoft. These are virtual reality headsets and the idea behind this is to allow the staff to recreate the experience of working in a packed trading floor without ever leaving their homes. I don't know if you saw the video or pictures of this, but when Microsoft first introduced these virtual reality headsets, they had issued them to everybody who was in attendance at this conference room and they started playing these videos. So you see all these people looking around, of course, they can't see beyond what's right in front of their eyes, which is this halolens. These virtual lenses and they're looking around and right up the aisle walks Bill Gates, of course, nobody notices him because he can't see him. They're all just caught up in this experience.

That's what they're trying to do. Banks have been really desperate to bring workers back into the office. When you're talking about these regulatory sensitive roles or roles involving money, where banks will typically force employees to take vacations, which you should be doing. If you're a business person and you have a bookkeeper accountant, make sure they take a vacation, make sure they get out, and have somebody else fill in for them. That's going to help catch people who might be cheating with money. They really want to get these people back in. Trading is one of these, but because people are afraid of the Wuhan virus, they don't want to go into the office. So what they've done, and this is really cool, I'm looking at a picture of her right now is they've set it up so that the traders can be sitting there in their homes and it looks like they have a bunch of different screens. You've seen this before, right where they have four or five, six screens in front of them, different data on different screens. They can look over, they can pull up a screen, they can see everything out of the corner of their eye, just like they're used to. So I can see our market rise or drop in something. I think it's really cool. And that's a good use of that technology.

Deutsche Bank, by the way, told its New York staff last week that they were not required to return to the office until mid 20, 21.

Deutsche bank's going to be opening a whole new office. Many of these others are doing it as well so we'll see what happens.

This Halolens by Microsoft was new surely seen as a gaming device and these headsets cost three grand. Many companies using them as a communications tool. you might want to look at it as well, depending on your business and what you are doing.

So coming up, we're going to talk about what's on your enterprise network. What's on the network, your house. You really might be surprised.

You're listening to Craig Peterson.

Stick around because we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Are their things connected to your network that you don't know about? Most likely! How and why to find out.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We've talked about the security cameras on our networks before and of course the internet of things. A new study is out is really very, very concerning to business people and frankly, to even homeowners. So we're going to get into that right now.

Hi everybody. You're listening to Craig Peterson, and so glad to have you here. Let's get into this big problem. Now that we have uncovered.

There's a new survey that was done by a research firm called Vanson Bourne. And it was done on behalf of Palo Alto Networks. Now Palo Alto networks are one of the competitors for Cisco and others, who make network equipment. Palo Alto network stuff is pretty decent. They've certainly had their fair share of problems lately, but so has everybody else.

I'm much more into things over at Cisco that has pretty much everything you need and it's nicely integrated. Palo Alto networks, good people. I know a few people that will work for them. I know some people that absolutely swear by their stuff. So don't think you've got Palo Alto networks here you're a completely out of luck, cause you're not. They've got some pretty decent stuff

Let's get into the survey I found it to be very interesting. When we go into a business, the first thing we typically have to do is scan the network. You must have to have an audit of the devices that are on your network? And then we scan the devices themselves. Typically that means their servers. Whether they're windows servers, Linux servers, we scan them. See what services they have running, which ports they have open on the local firewalls. We scan them all for any sort of malware that might be on them, spyware, et cetera.

Then we move on to really identify the versions of software they're running. In many cases, if you're running Windows, you probably have done some patches, but some 50 ish percent, depending on the number you want to use and whose numbers you trust. About half of all windows, computers are not patched up and something like 30%, 40% of windows computers have never, ever been patched. But let's assume that they have, let's assume that you're on top of your game. You are the person assigned to it in the business. Maybe you are an IT professional. You've had some training, you have some certifications, so you're off and running things are going great for you, right. You have kept it up to date.

We're moving to the next level, which is our, our macs or our macs up to date. Well, they just keep themselves up to date automatically for the most part.

But remember Windows is just the operating system. Mac iOS is just the operating system. How about all the other apps that you have on those computers? All of the applications. There are all a lot of them there and it's everything from maybe the Microsoft office apps that hopefully you've got set up to do an automatic update. But it's also all of those other little apps that you've put on your computer over the years, that by the way is another good reason to re-install your operating system every once in a while, make sure you have a good backup, make sure you test it before you do the reinstall and don't just, re-install everything.

Don't just restore that backup blindly, but actually restore the software. That you need. Okay. The data files you need because there are so many pieces of software. We have not been keeping up to date.

So you are the world's best IT administrator and you've got all of the computers up to date, all of the apps, only applications that you really need are actually there on the computer. You're not getting tainted by any of this other stuff that's going on, right? Oh, you are so, so good. Congratulations.

But let's have a look at the other devices on your network. This is where the survey from the research from Vanson Bourne really raises some questions. They surveyed 1,350 IT, which is of course information technology decision-makers in the US and 13 other countries so that's a pretty decent sized survey.

I don't know if these people were self-identified or how exactly they came up with those numbers. You can find it this whole survey if you wanted to download it over on Palo Alto Networks. There's a lot of good information that you can glean from the survey it's good stuff all the way around.

It's the connected enterprise IoT security report for 2020 is what it's called. These decision-makers, these 1,350 decision-makers in IT were asked questions to identify the strangest IoT devices they found connected to their organization's networks.

Now let's define the internet of things devices here for a minute. We've already, we've concluded here that you are the IT guru, right? You know enough to keep windows up today to remove the apps, to keep your macs up to date. how about some of the other devices that are on your network?

I'm not going to mention security cameras because I talked about them all the time. Right.

How about your printers? Have you updated the firmware in your printers? That's part of the reason we use higher-end Xerox printers. They all auto-update themselves, which is really nice and we can delay the updates, et cetera because again, those printers are computers that are attached to your network. Even the ones that are attached by a USB cable, although they're a little bit less dangerous than something that's internet-connected or ethernet connected.

How about some of the other devices? Do you have a scanner attached to your network? Do you have a fax machine attached to your network? I know a lot of doctor's offices you have to have a scanner, you have to have a fax machine.

If you buy one nowadays the odds are extremely high that they are connected to your network and maybe write directly to your file server. Have you restricted the access that they have on the file server to make sure they're not doing nasty stuff?

44% of these 1,350 IT businesses, decision-makers almost half reported seeing wearable medical devices, 43% said they had encountered kettles coffee machines, and other connected kitchen appliances. People are doing that all the time and remember that this isn't just in the business offices, this isn't our homes, right? 38. Percent said the same of IP enabled sports equipment. We are seeing more and more of those. Have you seen like the commercials for Peloton or this mirror thing? This mirror thing is really kind of cool. You hang it on the wall. It's kind of a mirror with a builtin display that lets you exercise with somebody remotely who is a coach, or maybe it's a prerecorded class.

Some have had IP enabled sports equipment includes skipping ropes and weights. 34 present percent reported smart toys. 27% said they found smart vehicles on their network.

I want to make sure you guys pay close attention to your networks or whether it's a home network or an office network. Make sure you segment the networks. As I mentioned in my video this week. Hopefully, you got that training video on Wednesday. Keep an eye out for them. Make sure you click through. I also, if you don't want to watch the video, I also have the transcript there when you click through. So you can just read it pretty quickly. It's like a minute to two-minute read and a three-minute video. So enjoy it and be careful out there.

Scan your networks and scan them frequently.

You're listening to Craig Peterson.

Stick around. Cause we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses problems that businesses can face when using VPNs and why you should be looking to a Zero-trust network if you are running a business today.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] What is going on with malware? There've been some major changes just over the last few months. That's what we're going to talk about right now. What do you need to watch out for? What should you be doing in your business as well as your home?

Hey, you're listening to Craig Peterson.

We know that they're here. I have been a lot of attacks over the years. That's what we're trying to stop. Isn't it with our businesses, with our home users? That's why we buy antivirus software or why we have a firewall at the edge. Maybe we even upgraded your firewall. You got rid of that piece of junk that was provided by your internet service providers. Most of them are frankly, pieces of junk, maybe you're lucky and have a great internet service provider that is giving you really what you need. I have yet, by the way, to see any of those internet service providers out there, that are really giving you what you need.

So there is a lot to consider here when we're talking about preventing and preventing malware. What we have found is that malware attacks declined this year in the second quarter, but here's what's happening. Right? They are getting through more.

Historically, we had things that have hit us that have been various types of malware. I remember when I first got nailed back in 91. I had a Unix server that I was running, as you probably know, I've been using Unix since the early eighties, 81, 82.

I was using Unix, and I had my own Unix machines because I was helping to develop the protocols that later on became the internet about a decade or more later.

The Unix world was on rather an open world. Was everybody on the internet was pretty friendly. Most people were involved in research, either government research or businesses doing research online, a lot of smart people and we actually had some fun back in the days', puns, and everything.

We weren't that worried about security, unlike today, where security really is a top of mind thing for so many people. We weren't worried about who's going to do this to me or that to me.

I had a Unix server that I was using, actually at a few of them that I was using for my business. Now, one of those servers was running emails, a program called Sendmail. That's still around today. It was the email package that was ruling the internet back at the time. I got nailed with something called a worm. It was the Morris Worm. In fact, it got onto my computer through no act of my own.

I didn't click on anything. It got onto my computer because it came through the internet. That was back in the days when we really didn't have much in the line of firewalls so it just talked to my mail server. One of these days we'll have to tell some stories about how we really trusted everybody back then.

You could query to see if an email address was good. You could get onto the machine and say, Hey guy, I noticed that you had this problem so I went in and fixed it for you, and here's what I did. Much, much different world back then.

But that's how malware used to spread. It was something, it was just kind of automated. It went out and they just checked everybody's machine to checked firewalls, to see what they were to see if they were open.

We've been doing that for a very long time, haven't, we? We have been nailed with it. That's what the viruses were and are still. Where it gets onto your computer.

Maybe you installed some software that you shouldn't have, and that software now takes over part of your computer. It affects other files. It might be something that's part of a Word macro or an Excel macro. And it now spreads through your sharing of that file and other people opening it.

Worms are like what I got nailed with, just start crawling around through the internet. So they run some software on your machine and that looks for other machines and today things have changed again.

They are changing pretty frequently out there. What we have seen so far here in 2020 is a decrease in malware detections. Now, just because there's been a decrease in malware detections, I don't want you to think that the threat has diminished because it hasn't. But the signature-based antivirus system is real problems.

Now, what's a signature-based antivirus system. That's any antivirus software, like your McAfee's like your Norton's, the Symantec stuff, any antivirus software, that is working like your body's immune system.

What happens with your body's immune system? You get a virus and you're your body says, okay, what's going on here? It starts to multiply. Eventually, the body figures it out. It develops antibodies for it. So the next time it sees that particular virus, you're likely to be pretty much immune from it. Your body's going to say, Whoa, that's a virus and it goes in and kills it pretty darn quickly.

That's the whole idea behind trying to stop the WuHan virus that is spreading out there. How do we stop it while we stop it, by just developing antibodies? Right? That's herd immunity. We could also develop antibodies by an antivirus shot that is designed to stop that virus from spreading and prevents you from coming down with COVID-19 symptoms.

In the computer world, it's much the same as most of the software signature-based antivirus software is exactly the same as the way your body's immune system has been working. In many, many ways.

Here's what happens. Someone gets infected with a virus and they reported to Symantec or Norton, or maybe the software reported itself. Usually, it's a third party that reports that and they look at it and they say, okay, so what does this virus look like? There is in this program the developers' names embedded or the name of the hacker group is embedded in it. So we are going to now say any piece of software that it has this hacker group's name in it, we're going to ban. Right? It recognizes it. So when the file comes onto your computer your computer looks at it. It looks at the signatures. These are called signatures. To say, okay, how does it match? Or it doesn't match at all and it might be through a string that's somewhere embedded in there. So it might be through a name. It might be through a number of other things. That's signature-based.

The malware, that was not detectable by signature-based antivirus systems jumped 12%. In the second quarter of 2020. That is amazing. Amazing, absolutely amazing. Seven in 10 attacks that organizations encountered in the second quarter this year. In fact, involved malware designed to circumvent anti-virus signatures.

Most cyber-attacks last year and this is probably going to be true in 2020 as well as we get into the fourth quarter. But most cyberattacks in 2019 came about without malware. That means that there were hackers behind this.

We're going to talk about that. What's going on some of the data also from CrowdStrike and what they have found CrowdStrike is an anti-malware anti-hacker company. They've got a lot of great people working for them as well. What they have found.

It's like the bad old days of hacking and they're back on us right now.

So make sure you stick around. Cause we're going to get into that when we get back. And of course, we got a whole lot more, including a major windows bug that's now under exploit and how does this all fit together?

You are listening to Craig Peterson.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses problems that businesses can face when using VPNs and why you should be looking to a Zero-trust network if you are running a business today.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're seeing more and more malware-free attacks. We're also seeing attacks that are completely evade are signature-based pieces of antivirus software. If you have antivirus, you think you're protected. You're you really aren't.

Hey, you're listening to Craig Peterson. Thanks for joining me here today.

Well, we were just talking about malware attacks declining, but what's really happening is that they are becoming more and more evasive. That is a scary, scary world out there right now.

These hackers are no longer just using regular old viruses to try and get into your systems. Time was, the good old days, there might be a macro virus that comes in on one of your Microsoft Office document. You might've gotten a virus from some software. You downloaded some free software from a warez site, but in reality, what is happening right now is the attackers are getting smarter.

Malware is designed now to circumvent completely, antivirus signatures. So that signature software that you had that you bought a few years ago that came with your computer, that junkware that was installed, that came up and said, Hey, you need to, to pay for it now. You had your 30, 60, 90-day free trial. It just isn't gonna work anymore. The antivirus signature code that you bought and paid for and have been using just isn't going to work.

So what do you do? That's a really good question. What is the right thing to do? Well, first of all, we've got to make sure that we're no longer just using antivirus signatures. We've gotta be looking at the behavior of the software. There are companies out there that use white lists. In particular. I can think of PC MATIC, and I've got to get them on the show and talk a little bit about this. The way they do it is interesting. There are drawbacks to white lists as well.

The way we do it is a little bit different because we're doing it the Cisco way. We have antivirus signatures. We also have behavioral and analytics. So if. It's an old piece of malware and an antivirus signature is going to pick it up. Well, our advanced malware platforms are going to pick it up, right? That's what Cisco does, and some others do as well.

But if it doesn't have a signature that's recognized it watches it's behavior and depending on what happens with the behavior, it might do a few different things.

So for instance, this week, we got a call from a client because what had happened was there was they got an email that had something that was flagged as suspicious by our software. Immediately that software was uploaded so that Cisco Talos. Talos has been around a long time they are true experts in cybersecurity. There's a couple of hundred people that sit there and examine it. So that our software automatically sent this thing to Talos to be examined.

We called up the customer and said, Hey, there's something suspicious in your email box. We are heavily filtering all of their emails as well before it even gets into the box. They said, okay, what email was it? The subject matter was an invoice, a specific invoice. We said, look for this and this invoice and they couldn't find it in their inbox.

Our technician had a look and said, Oh, wait a minute here.

Now what had happened is our software had automatically sent it to Talos for an examination. Telos will look at it and said, wait a minute this is something that looks very malicious.

So it automatically puts it into a kind of a lockbox and examines it there.

It looked malicious and so they retroactively pulled that piece of email mail out of that email box all automatically. Joe, our client had no idea. We didn't realize it had happened either until after it had happened. But the idea is if it's in question they can remove it.

The way it works, as well as the anti-malware platform that we have is if your computer gets some of the software on it and it starts to do something malicious, we can roll your computer back. So the malicious activity might be that your computer is now starting to probe other computers or probe other server servers that are there in your network. So we noticed that attempted lateral spread and our software will automatically shut off the network port that the computer is attached to. It's just phenomenal what you're able to do nowadays.

Now, one of the security vendors that are out there called WatchGuard. Analyzed some of the malware attacks that were going on and it looked at 42,000 firebox appliances that were at customer locations worldwide.

Now, part of the reason I like Cisco is it's using billions of data points every day to figure this out. Right.

So WatchGuard has 42,000. But they found that the devices were blocking 28 million malware samples representing 410 unique attack signatures, which is an increase. But there are all kinds of tools that are available now on the dark web for as little as $50 that can be used in attacks.

When we delve into this a little bit more and look at some of the incident report data that came out of CrowdStrike, we see some very interesting things for the first time in CrowdStrike's research. They found that so-called malware-free attacks edged ahead of the malware based tool. 51 percent, in 2019, of attacks that were analyzed here by CrowdStrike, 51%, did not have malware.

Now we've talked a little bit about this before I go into this in quite a bit of detail in my courses, in my more advanced cybersecurity stuff, but what's happening is the bad guys are using information that's being harvested from the dark web.

You know, how I'm always getting on your case about making sure you're using one password or last pass, right. I think it's important. Well, part of the reason for that is you should use a different username. I don't like websites that make you use it an email address. Cause that's currently insecure. But you should use a different username at every website and for sure you should be using a different password and use one password is great at generating them so's LastPass. Those are the only two that I recommend. If you're a business, you really should be using 1Password.

The bad guys are now taking the information they find from the dark web, which is copies of your email addresses, copies of your passwords. They are using them to log in as a regular user in your network. If you have VPNs, for instance, that your business people, your employees are using to connect, they will find the VPN through a scan, the VPN access point, or the remote desktop access that you might be providing the old terminal services from Microsoft. Then they will do a credential stuffing. They will try and use a username and password from your organization.

We just had this last week happening and this was a government subcontractor. They did some work for DOD prime contractors and there were people who were trying to use credentials that were found on the dark web to get in. It's happening all of the time but now they're getting on.

They have these hands-on keyboard methods. They're trying to use usernames and passwords that they have found on the dark web and they are using PowerShell. Now, PowerShell is a rip off that Microsoft made from the Unix world, and Microsoft of course, messed it up pretty badly and there are all kinds of major security problems with it. Microsoft Windows was not designed with PowerShell in mind.

Nowadays you have to use PowerShell to do certain things. Microsoft has finally figured out, Oh, wait a minute. Command-line interfaces are wonderful. Maybe we should use them more. So what happens is they use PowerShell.

They start it up and now they use it to exploit your network, exploit your systems because it's not a virus, it's not a program, very hard to spot and they'll hide files and directories, and they will use these tools like PowerShell and act just like a regular system administrator acts nowadays on a windows machine. System administrators on Windows machines, they're using PowerShell, aren't they? Now, most organizations don't have the technology to be able to differentiate between a legitimate user and a legitimate employee or contractor or an attacker who has stolen credentials.

This is about a very, very big problem out there that's been seen by Cisco, by CrowdStrike, Rapid seven is another one they're using. They're seeing hackers using valid credentials or reusing credentials from other breaches ie., credentials that are found on the dark web. So what do you do? How do you do this? That's our really big question right now.

The bottom line, do not ever reuse passwords. If you're a home user, it's true. If you are a business, it's true. One of the things we do for our customers and you can do for yourself is to go out to the dark web and search. Use tools, like Have I Been Pwned, very basic tools, and see if your users username slash email addresses are out on the dark web. Also, see if the password that's associated with that account out on the dark web is still in use by them.

Just this week we found another one of our customers where one of their primary users, one of the C-level people, Paul was using the same email address and password for the business applications as he was in for one of these hacked accounts out on the dark web. So be very, very careful.

All right. I appreciate you listening to me today.

You're listening to Craig Peterson.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses Zoom and finding love? Can it really happen and what are the drawbacks.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Well, we've just been talking about some of the ways that the hackers are getting into us now avoiding some of the software we've been using these antivirus packages just don't work anymore. I'm going to talk about another problem. This is a massive windows bug.

We're going to be getting into a couple of other things here. We'll talk about VPNs a little bit and how it's dying and going away. We've got another employee theft, that's happened here, this time to Shopify. Microsoft, and what they've done with Azure. We'll talk a little bit about these cloud systems because they are problematic.

Wanna cry is back and Love in the time of Zoom. Why we're in the midst of a dating revolution. So why don't we start with that one here? You're listening to Craig Peterson. Glad to have you with me today.

So let's get into Zoom, you know how much I don't like Zoom for business. It is not considered secure or does not meet any of the standard security requirements. So that's a problem. If you were to ask me.

We are in the midst of a dating revolution. Do you remember that episode from Seinfeld where George is out doing speed dating and they had these, what were they? 30 second or 60-second dates. I guess that's been the thing over the years, maybe a little longer than that.

You spend two minutes, five minutes with someone and you're all there at the restaurant or whatever conference room. It's like musical chairs. Every time you move one. Usually, it's the woman sitting there and the men move around and it could be the other way around, I suppose. There was a good way to meet a lot of people. If that's what you're trying to do, see if there might be any chemistry, usually, they charge for them.

Today, well, things have gotten higher-tech. They come about here in Zoom rooms as well. I mentioned earlier today about some of the things that we're doing from a business standpoint on Zoom. Many people are now having business meetings obviously, or hopefully not on Zoom, but in the online world.

But right now, what we're seeing is love and marriage. How people are connecting. It used to be of course, accidental. Then some of us, might go to the church we belong to and look for a companion or a mate. There are a lot of ways is that things have changed and they changed a lot, really in the 18th century with the industrial revolution.

Now we're kind of back to the isolation days. Well, so what do we do now? I don't know if we'll ever really get back to normal. People have found that they can do business from home. They can work from home. Now they found that they can date from home as well.

Already, we're seeing nearly 40% of heterosexual couples reporting that they have met online. Most of the time that's being through a social media site like Facebook, or maybe some of the others that are out there. Same-sex couples are even a higher percentage here, more than 40% of heterosexuals that are meeting online.

Of course, there is also the casual encounters that have been going on. I can't even believe it, but Dr. Fauci even mentioned that, right? Oh man, we're not getting into that right now.

But this type of online interaction is absolutely surging during the time here of the Wuhan virus. Bars are closed. Restaurants are mostly closed churches can't meet you. Can't sing hymns depending on where you are. They might only let a few people in. I know there's one state where you can go to a bar, but only one person can be in the congregation of a church. I, I just don't understand some of that stuff, obviously.

So what do you do right now? We're seeing a massive drop in the number of Americans that are married by the time they turn 30. Only about half of them are married by the time they turn 30 fertility rates have plummeted to 1.7, meaning the average woman will give birth to 1.7 children over her lifetime, which means if that woman can be considered to be part of a couple. That is negative growth in our population. Something that some people have been trying to achieve for a very, very long time, but it is well, well below the natural rate of replacement, which is as I recall, what about 2.1 or 2.2? So that's pretty dramatic and it is just continuing to go down more.

Men aged 30 to 34 were living with their parents than with the romantic partner and that's before the Wu Han virus pushed even more of a back into our homes as we've lost jobs and opportunities that are out there. It's just not very, very good, but the future isn't all of that bleak.

I wonder, frankly, when we're talking about general social, social media. So things like Facebook and messages and stuff, how much of what we see and we feel we have a connection with other people. How much of that is real. We already know much of what we see. Isn't real. Some of these social media influencers you've admitted to taking as many as a thousand pictures before they found one that's worthy of posting where all the makeup was. Right. The pose was right. The hair was right. The background was right. The lighting was right. It leads to a false sense of, Oh, keeping up with the Joneses. If you will. There's an older expression. Where people see this and they think that's the way their life is supposed to be. It's absolutely not.

So how about where we're trying to do one on one stuff. I think we all can remember going on dates and being a little braggadocious. Maybe inflating things just to ever so slightly. When we went out with somebody and then over time, we got to know them and then we started to loosen up. I'm in a mastermind group and I also have seen that in the mastermind group that as we got to know each other. We kind of relaxed, but we know each other's businesses now and we can give each other good advice and a good kick in the pants when necessary.

So I don't know. The future's not bleak. I think. Yeah. It might take a while for people to get to know each other. When we're talking about meeting online, doing little Zoom meetings, or meetups online. But the whole courtship thing has really changed the whole structure of what it is. It is just absolutely amazing, but I think we are still going to be looking for those relationships. We're so going to be trying to find them online and I think it might work and I don't know, maybe a breakup is even easier in the online world or maybe the whole fallacy behind the online world where people are literally making stuff up. If the fallacy is going to make it even worse when it comes to breakups. I really don't know.

I'm looking at an article here from, Debora Spar. She's a professor of business administration at Harvard business school, and she's been very focused on issues of sex and technology and what's been happening with the technological change. She has a new book out called workmate. Marry Love, how machines shape our human destiny, which is kind of an interesting book. I think the romantic times are going to continue, but we're going to continue to look online for ways of meeting and doing stuff with people. So there you go. Zoom is not just for little family gatherings, but it's also for romance. I think that's kind of cool.

Hey, if you like to listen to the radio, when you're driving around in your truck or your car, one of the things that I do, and here's a little tip for, in case you didn't know you do it is I have Bluetooth in all of my cars.

Nowadays, there's Android play. For Android phones, not all of them, just some of the newer ones and there's also Apple play for the newer Apple iPhones. And what they that allows you to do is run the app near a phone. And once that app is up and running, it will come out through your car stereo.

Now, many of you guys, of course, you're the best and brightest. So you probably know how to do that already. I love the way car play works on the Apple side, Android. It works pretty well too, but the main concept behind it is to keep the interface simple, to keep the number of distractions down.

Hey, you listening to Craig Peterson.

Make sure you stick around. Cause we will be right back. We got more to go today.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses a big problem right now. This particular vulnerability is called a zero log-on vulnerability. What that means is your computer is vulnerable to attack without the bad guy, actually having to log on to the computer. Very, very, very. Bad. Okay. Known as an escalation-of-privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while. Thanks, Microsoft (said firmly with my tongue in my cheek!)

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We are right now under attack. This is the windows vulnerability that I mentioned live on the air here a couple of weeks ago, it's not patched up by most people and it's really, really bad.

Hey everybody, you're listening to Craig Peterson.

Well, this is a big problem right now. This particular vulnerability is called a zero log on vulnerability. What that means is your computer is vulnerable to attack without the bad guy, actually having to log on to the computer. Very, very, very. Bad. Okay.

Now, this is an escalation-of-privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while, from everything that I was reading.

This is crazy because what's happening is they are using domain controllers and remote procedure call login servers in order to get in. So if you're just running a regular windows machine in your house, obviously you want to keep it up to date.

But this particular exploit is against these servers that are out there. The servers specifically are those that have exposed domain controllers and remote procedure calls also called RPC login servers.

Why do you use those? Well, most businesses use those types of servers to allow people to log in remotely. Who logs in remotely? Well, its employees, right? We're there in our homes, we're trying to get into the office. So we use a domain controller. We are sending RPC calls here for the login servers. You may not know what's actually going on behind the scenes, but that's what it actually is. Now there's a search that you can do on a line. There's a couple of different searches to find. These exposed servers, very, very big binary edge.io. There's a couple of others also let you know about it, but okay. They show more than 33,000,000 million networks that are exposing domain controllers. This is absolutely crazy here.

In the event, a single network has both resources exposed, the combination can leave the network-wide open with no other requirements. Okay. It's very, very, very, very bad. I don't want to go much more into this. It is absolutely catastrophic. If you are a person who's responsible for the IT resources within a business. You have to take care of this. Right, right, right away.

The cybersecurity arm of the Department of Homeland security mandated all agencies will over the weekend. They put the mandate out on Friday and then they had to be done by Monday. They had to apply the patch by Monday night or remove the controllers from the internet. Take that as a little bit of a hint that maybe it's something you should do too.

So if you are a business owner, make sure you check with your managed security services provider and or your employees who are responsible for it. Okay. Cause it's very, very big. It's the year's most severe Windows bug that we've seen this year and who knows maybe more on the way. So I'm not going to say is the best or the worst.

Now let's move on to another subject here that I think is worthy of the news here and that is that VPNs are a risk.

Now, one of the legitimate reasons to use a VPN would be, so you don't expose those services on your server. In other words, they're not exposed to the whole internet. If they're not exposed to the internet, some guy or gal somewhere else in the world, can't get to them. So how do you let your employees get to those services and keep them locked down for everybody else?

You could do it by having your firewall only allow certain internet addresses to get through to those services. That's what I would advise as a quick stop-gap for you. Make sure that only the home computers that are supposed to be able to get at it can get at it.

But remember too, that it is just a quick stop-gap because those home computers could be infected and could be used as a launching point to come after your services. So you're letting that home computer through your firewall to get to the RPC services, the login services they need. If that computer is infected, that home computer, it could be used now to attack you. So it's just a stop-gap.

Another way to do it is to use a VPN. Now, you know what I've been saying about VPNs for the longest time, where VPNs are, frankly, a little on the hazardous side, particularly for your security. There's a difference between privacy and security. At least if you ask me.

The biggest difference is privacy means that advertisers don't know where you go and that means your internet service provider doesn't know where you go. That's privacy.

Security is where you don't want that information sold, but even more so you don't want to have your bank account information stolen or other things that really need to be secured. Okay.

So that's a big difference here. If you get a VPN for your business so that people can connect to these log-in services, or maybe connect to your file server, that's a bit of a problem as well, because remember the VPN can be used both ways.

It's like that saying, I love this old saying, but tracers work both ways. Right?

You use tracer rounds when you're shooting at the enemy so that you can see where the bullets are going. By the way, that means the enemy can see where the bullets are coming from. The same thing's true with VPNs you put a VPN in place so that home users can connect to those login services or maybe your SMB CIFS here, your file servers, right, the file shares. You open it up the VPN so they can get through, but now potentially the bad guys can use it to get through as well. So it is a big problem.

Because of that, VPNs need to be tracked very closely in your firewalls.

We run all the VPNs that we have for clients or that are requiring security. We run them all through not just a basic firewall, but one that reassembles everything. Examined all files that are being downloaded, et cetera, et cetera. Okay. That's what we do now.

There is a new technique in place right now that is gaining a lot of momentum and frankly, within the next few years, all businesses should be using this. We're doing this already and it's something called zero-trust and zero trust means in the case of a VPN. Okay, great. There's a VPN in place, but I don't trust that home computer to have full access to my network. In fact, not only mine, do I not trust it to have full access to the network, but I don't even want to have full access to this particular server.

I only want it to have web access, let's say. Even then I want to go to the next level. I want to make sure that that home computer is not being used to grab my client list. That an employee is about to take with them as they walk out the door to my competitor.

That's where you start getting into zero-trust and what that's all about. We're going to talk a little bit about that. What Gartner's predicting is going to happen here by 2023 and how you can use it and how you shouldn't be using it right now, in fact, so stick around because we'll be right back. We got a couple more segments left and of course, a bunch more to talk about, and don't forget, visit me online.

Hopefully, you got my email on Wednesday with that three-minute training. Go to Craig peterson.com/subscribe right now and make sure you get all of my newsletters.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses problems that businesses can face when using VPNs and why you should be looking to a Zero-trust network if you are running a business today.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] So we know a little bit about VPNs and what they are. So what's zero-trust and how's a zero-trust network run. What are we looking for here in the near future? More than half of businesses will be zero-trust.

Hi everybody. Craig Peterson here. Thanks for being with us today. Of course, you'll find me online as well. You can just go to Craig peterson.com. I've started to do some three-minute training.

So the first one went out on Wednesday and I was really surprised just how much work it takes to make a three-minute training. But we did it, we got it accomplished. We're going to try and have a couple of those a week, plus the weekend newsletter, which is, of course, a fair amount of work, but we're doing it for you. Hopefully, you got a lot out of it.

I got a crazy number of responses to the first video. So thank you. Thank you. Thank you for your responses. Hopefully, I got back to you in a reasonable amount of time here, and we're able to help you out a little bit. Anyhow, if you missed it, go look back on Wednesday this week that's when I put out the first one. So it should have been in your email box Wednesday. As usual, it's from me@craigpeterson.com. So if you're not getting them and you think you should be double-checking to make sure I am in your contact list or whitelist me somehow so that you get those. They're important. I'm going to be doing more of those a week just to kind of a light touch. Let you guys know what's up.

So VPNs have been around now for more than a couple of decades, they've been fantastic. They've saved a lot of businesses a lot of money. Now course, they tend to be kind of dangerous, particularly these free VPNs and the commercial ones that you're using, to somehow try and make yourself more secure. I just shake my head every time I hear these ads that are misleading. They are lying to you it's really not going to protect you that much, frankly, if at all. It gives a little bit of privacy in certain situations, but not in others. I had a great call with Doug in fact, this week. And he was having some problems. He is a small business guy been in business for a long time, sold his business and now he's almost 80. I think he said he was 78. He's kind of back in business, again, keeping himself busy and occupied. He was wondering and worried about trying to keep some of this stuff secure. So we went through it a little bit with him.

He uses macs, so it is definitely easier to keep secure. When he's on the road, he has one of these little devices he takes with him that allows him to connect to the internet from Verizon. One that directs you directly connects you to the internet, which is dangerous. Another one that provides you with what's called Nat or network address translation that's a little bit safer. So he's going to send me a model number in particulars of what he's using so that I can help him out a little bit.

By doing that, he's no longer tying into the wifi at the airport or on the airplane or at the coffee shop, wherever he's going. He's got his daughter doing that too, which I think is a very good idea. I know a lot of people, as well that do that. I do it as well. I have one of those little devices. I just replaced the battery in mine because it started swelling. The lithium-ion battery starts to swell, you've got to replace them. What can happen is when they swell they will short out and can start a fire. So be very careful about that.

So he's smart enough to know that you don't want to use public wi-fi. He effectively brings his own little wifi device with him, which is again, a great idea.

Some people try and use VPNs when they are out there on the road and connecting back into the main office or into their homes. I have that as well, and that lets me get directly in.

Most of the time now, what we've been doing for our office and for our customers is putting together zero trust networks. These are far more secure than anything else we have out there right now, as far as firewalls and everything else goes. The idea is, just like its name implies, that we're looking at everything. We're no longer just trying to do what's called a perimeter security approach where we have a firewall at the perimeter.

Now we are trying to protect ourselves and our businesses from any kind of attack, including insider attacks, including the lateral movement that I've talked about so many times before. Where a bad guy gets a foothold inside of a network and that bad guy immediately tries to start spreading things. Very dangerous. Very, very dangerous. There's a number of other flaws too. Perimeter security just doesn't do a good job of counting for any third parties any vendors you might be working with contractors, all of your supply chain partners. If attackers steal somebody's VPN credentials, now the attacker can get into the network and roam freely. Like I've talked about many times.

Many of us use the same username and password on pretty much every device out there. That's a problem because when it gets onto the dark web, now the bad guys have it. Plus the VPNs over time have become a lot more complex and very difficult to manage.

It's rare. I say rare but I've never seen an exception. In other words, it seems that these businesses have misconfigured VPNs. It seems to be a pandemic out there, frankly. A lot of pain around VPNs.

So this is going to change it all. You are. We're going to have different equipment internally. Your devices are not gonna be able to connect to each other directly.

So the way we have it set up all of the devices on a network, instead of speaking directly with each other, have to go through at least a firewall. The firewall watches what they're trying to do even inside the network. So it's no longer just out there at the perimeter. Frankly, what we've been doing with VPNs, it's just clunky. It's outdated. Frankly, kind of dangerous. So keep all of that in mind.

All right if you need a little help, if you have some questions, I am more than glad to get on the phone with you guys and chat a little bit and help steer you in the right direction. You can just email me M E @craigpeterson.com and I'd be more than glad to get back with you. So keep all of that in mind. VPN is dying. Zero-Trust is what's coming down the road.

Now, I just mentioned the problems of potential internal threats, and that can include bad guys that are in your network, spreading laterally, as I just mentioned, but it can also mean that your employees are the problem.

I've seen that before I had it happen to me, where I had an employee who took all of my customer records and took my customers with him. I could not believe it. I still can't believe it to this day. What he did I don't understand it. What does he think he's doing? He may have built up a relationship with my customers. I don't think he brought a single customer in. In fact, he built up a relationship with my customers, and then he figured, they're his customers now because he has a relationship with them.

So forget it, Craig. They're his customers. It is just absolutely amazing.

Shopify, which many of you have heard of before and many people are using. Has found that two of their support team employees were involved in a scheme to steal customer transaction records from specific merchants. It affected apparently fewer than 200 merchants, but there's an example of where zero-trust can really come into play. Do your sales guys have access to information they shouldn't have?

How about some of your support people? We have to make sure we're monitoring where they're going and what people are doing within our networks. Okay.

When we come back, we've got a couple more things to talk about Microsoft, Wanna Cry is coming back up again.

We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses big problems found with the Microsoft Azure Store and provisioned servers that were part of this massive command and control network run out of China.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Read More:

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to talk about Microsoft and the Azure store and President Trump and WannaCry. Do you remember that terrible piece of malware? It's back.

Hey, you're listening to Craig Peterson, make sure you follow me online as well. Craig peterson.com. It is a pleasure to be with here with you here today. I had just so many great discussions with people this week.

I sent out a three-minute training, the first three-minute training. I'm going to be doing more and more of these here as time goes on. This training got just a plethora of responses from people. I'm so happy I could help out many people this week, including a bunch of tiny businesses, and that's what I love to do.

That's why I do this, right. Help you guys out a little bit here. Now. I have customers, big paying customers, usually companies that are regulated and need cybersecurity. But for the rest of you, I still will help you just as much as I can. There are some things you need to do, and that's what this is all about.

Well, you know already about the Apple app store. I've talked about it many times. Do you know about the Google play store? Both of those are stores that you go to to buy or download little applications that you can use on your smart devices. They're both tremendous small stores. Apple tends to do a better job when it comes to watching for security problems than Google does.

Both of them tend to take about a 30% chunk of any money that you pay. Then of 75% or 70%, I should say to the developer. Well, Microsoft has a store, as well. You might have heard of Azure. That's a service that Microsoft has, and it is an online service. It's a cloud service. It lets you run Microsoft Windows in the cloud, in a data center.

That's managed by Microsoft, run by Microsoft in most cases. Also, by the way, it'll let you run various types of Linux, and that was a bit of a surprise, but anyhow. That's the Microsoft Azure story. Then we also have over on Amazon, and that's called AWS Amazon web services. There is a lot of others too.

We tend to use some of the IBM stores, including the IBM mainframe stuff, which has just been unique to us, just how good those things are. The IBM mainframes, how fast they are, and how inexpensive they are for computing stuff. It's just amazing. Anyhow. Microsoft and IBM and Amazon and anybody that has one of these cloud services also have a store.

And it's much like the stores that you would expect to find for your smartphone. But in the stores where we're talking about here, Azure, or these cloud services, they are selling and leasing or renting fully configured machines. So you can go on, you can say, Hey, I want a new Ubuntu version, blah, blah, blah, or red hat enterprise Linux, which is what we tend to use, version this and such, and maybe you want also to use containerized stuff. And so they have all of these things pre-configured you can say, Hey, I want a database engine and Tada, poof, there is a database engine for you. It can be either poorly maintained by them. And you have no idea what it is. It acts like MySQL or whatever other databases you might want it to appear to be. Perhaps it's your version of that. Those types of apps are available in these cloud services to use those terms loosely.

Well, earlier this year, it turns out, according to Dan Goodman, who wrote an article over at ARS Technica up on my site. Still, members of the Microsoft threat intelligence center suspended 18 Azure active directory applications because they determined they're part of this massive command and control network run out of China.

Now we can also talk here about commanding control because your computer might even be part of this. So, if you have a computer and that computer gets hacked, one of the reasons they hack it is to use it as part of a command and control network.

Now here's the idea behind the command and control hackers. They're not going to ransom your data. They're not going to try and do something nasty with it. These command and control guys don't care that your computer can do anything other than connect to the internet.

So one of the things they'll do with command and control is to do what's called a denial of service attack against somebody. So there's some company they don't like, or maybe they're ransoming. This company says, Hey, listen, we'll shut down your website unless you pay us a million dollars.

What they'll do is he'll use a thousand, 10,000, however many computers they have in their command and control network. They'll use them now to send off fake website requests to that company. Then that company's servers just get hammered, and nowadays, we see in the order of tens or even hundreds of thousands of requests per second coming into some of these data centers and that there are services out there to protect against it. Those types of denial of service attacks. Okay.
But here's where things start getting interesting. They all also use command and control systems to send out emails, do phishing, and even research them. So command and control just as it sounds is they have control of your computer. They send commands to execute.

So, in this case, what we're finding is that Microsoft had these apps that were in there as your active directory, their cloud service, that were part of this commanding control network. 18 different applications. Again, we're not just we're not talking about an app, like an app that would be in the windows phone. Suppose you are sad enough to have bought one and no longer getting support. So it is a difference. It's a pretty big difference.
These are the types of applications that are used by businesses, database applications, web server applications. All right. It's not just the fortune 500 companies that are doing this anymore.

We're talking about the smaller guys who don't have the resources to be able to check.

You know, between the two of us, most of these fortune 500 companies aren't doing what they should be doing either. Hence all of the hacks that we've been seeing. So this hacking group that Microsoft is calling gadolinium had the cloud hook, hosted applications, and had also been storing stolen data in a Microsoft one drive account and used that account to execute various parts of their campaign. Now, Microsoft, Amazon, all these other cloud providers have been touting how secure it is, how fast these cloud services are. They're just so much cheaper. Oh, this scale that comes from renting computer resources. I remember describing what they were hoping for a way back when with cloud services, that it would be like the power company who cares where the electricity comes from as long as you flick the switch and the light comes on.

It is no longer like that. The hackers have realized now the benefits of hacking the cloud surfaces and, in this case, using them to share their stolen data to store it, et cetera, et cetera. And now, there's so many free trial services and one-time payment accounts. Hackers have been able to get these different things up and running quickly.

As I mentioned before, they can even buy their materials, their software to do the hacking, do the phishing, do the ransomware, and sell the decryption stuff. They even have banks that'll handle the transactions to convert Bitcoin into the US or whatever dollars they want to. Very very big deal.

Earlier in the show, I've talked about this before some of these tools are in use right now, particularly in Windows PowerShell, that are not well secured and legitimately used by the system. Administrators have become a huge, huge tool for the bad guys to use. They're so widely used for legitimate tasks. It's tough to detect the reuse of these illegal tasks.

This group, this gadolinium group, has recently started using a modified version of the PowerShell empire post-exploitation framework. It's open-source. Can you believe this stuff that's going on? So it's terrifying. Agility and scale, frankly, are working both ways here against us, and for us, I am very concerned about some of the stuff that's going to be happening.

If we've got some of these bad guys that are out there, right? Some of these terrorist groups, domestic terrorist groups, are burning our cities right now and shooting people, shooting cops, et cetera, that these terrorists will be using these same techniques shortly here in the US. You probably already are. We already know it is using them to finance and fund their operations. Very, very scary stuff.

So, one more thing real quick before we go. That is WannaCry. Very, very big deal. SonicWall is reporting a 109% increase in ransomware in the US during the first half of 2020. Keep your eyes out. It is very, very inexpensive for the bad guys to do. Get ransomware on your systems. They have high rates of return on it with hardly any risk for them and even outsourced it. We've talked about that before. It is a preferred method of attack for cybercriminals. So be very, very careful out there.

Get the right kind of security. I was talking with a couple of companies this week. We're going to be putting some of the prosumer Cisco stuff in place to help out a small company and some of the commercial hardware you need to have if you are a regulated industry. So we'll be doing some of that this week, too.
So I'm going to be kind of busy, but I plan to release two videos this week, two training videos, and knock on wood. One will be on Tuesday, and one will be on Thursday, but we'll see how it goes. I only got one out this week.

You've been listening to Craig Peterson. Have a great week, and make sure you visit me online. me@craigpeterson.com.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. He had a few questions about VPNs, seems like it is a little confusing for people to understand that they were designed for something completely different than what people are using them for today and that is where the problems are coming from. Then I broke some big news about the Federal Register changes and DOD contractors and sub-contractors that went into effect last night at 5 pm. Then we got a little light-hearted with a brief discussion about Love and Zoom. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] We're giving you an emergency regulation, right now you have 48 hours notice and you have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better and they're going to start that audit December 1st.

Hey, good morning everybody. Craig Peterson here. Mr. Jim Polito was in his studio for the first time in many months. He sounds much better there in the studio. We got into VPNs. What is the problem? What is this whole thing called zero-trust, and how's that going to be affecting us here in days, weeks, months ahead. Also huge, huge, huge, huge announcement. Federal register. If you do anything for anybody that does anything for the Department of Defense, including mowing their lawns. A big change in the federal register. You are now in serious trouble. If you don't meet these guidelines, that has been published for a couple of years. This NIST 800-171, but anyhow, I mentioned that is Whoa!

So here we go with Mr. Polito

Jim Polito: [00:01:16] A great Tuesday segment, it would be a great segment any day of the week. He is our good friend and tech talk guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:28] Hey, good morning, Jim. How are you?

Jim Polito: [00:01:31] I'm good. I'm good. I'm actually, I never thought the day would come and this will be the second topic, but I never thought the day would come that Craig Peterson and I would be talking about dating. We're going to talk about dating. We're going to talk about dating in the age of COVID, but before we get to that, you have some really big news you provided me with. Okay. So I understand the concept of a VPN. A VPN so that you can work securely from home or another remote location, and yet still have access to everything.

Every computer, every little bit of hardware you have in software and drives that you have to say your business now. Thank God Danny has this, uh, my former producer now. Program director, because Danny can, uh, if I need something VPN in from home and do it or fix it or whatever, uh, now you're saying that VPN, what? Isn't the. Gold standard anymore. What's going on?

Craig Peterson: [00:02:46] We have to remember where VPN came from in the first place. You know, it's been over 20 years ago, but I had three megabits worth of internet here at the house and it was costing me, 20 years ago, about $6,000 a month to have three megabits worth of internet. Yeah, exactly. So I had internet here at the house so I could work at home and that network was then routed through, of course, the phone company had all of those lines and that they went to the office and then the whole VPN concept came along. What we could do now is run a virtual network link.

So rather than paying the six grand a month, for me to be able to connect to the office or my house. I could now connect the two networks together, just over the internet. So my cost went from about 6,000 a month to about 150 to $200 a month back then. It was a huge win. Yeah. That's what they're designed for is for the networks to connect together. And that is the problem. If you connect your home network to the office network, you now have a huge problem because all of the attack surfaces, all of the computers in your home, that really cool internet coffee pot that you bought that is really a computer that happens to make coffee is now gained access to your network at the office. That's where the problem is.

This is the internet of things that you often talk to me about, right?

Yeah. It's the internet of things, plus if you've got teenage boys, where are they going online? Right. What are some of the worst, the worst places you can think of? And so now all of these computers that are infected can now spread laterally out there and, and that's just a huge problem.

So, yeah, VPN, as you said is no longer the gold standard. In fact, I've got to make a quick announcement here in just a second about their defense the national register just had an emergency update as of 5:00 PM yesterday, but this all ties in.

Because what we're moving towards now is what is called a zero-trust network.

It's a way different concept than most people are used to than businesses are using, But the idea is why should you connect your home network to the office network? Because that's dangerous as heck. Okay. A zero-trust network as any device that wants to speak to another specific device has to be approved to not only does that device have to be approved to talk to the other device, but the protocol it is using has to be approved.

So it has gotten very very different in this world today because of all the hacks going on and the zero-trust is what you're going to start seeing a right, left and center here over the next year or two. Moving away from just the concept of an open VPN.

Jim Polito: [00:06:05] Wow. We're talking with our good friend, Craig Peterson, tech talk guru, and all about all things technical.

Now. The VPN in terms of security as you were talking, I mean, it was the gold standard. Isn't this just a race every time we turn around. So this new system that you're talking about, won't it have a shelf life, won't it at some point be useless against the bad guys.

Craig Peterson: [00:06:38] You can have a great point.

It's always been a game of oneupmanship between the defenders and the attackers. That's why zero-trust comes into play. Yeah. There are going to be problems with the implementation. The biggest problem we see is stuff being misconfigured. Businesses are completely misconfiguring the VPNs. Heaven forbid they have to try and figure out zero-trust. That's where we're going to see the biggest problems is with misconfiguration. But the whole concept behind zero trust says basically, no, there is no one that's going to shift because everything has to be approved and what we're trying to do with this is stop the lateral movement.

So if your business gets infected with something, Nowadays, it ultimately ends up being ransomware much of the time, but it gets infected. The bad guys if they've got ransomware in your machine, don't do what they used to do a few years ago. What they do right now, Jim and these guys are smart. Right? What does that make money doing? The good stuff.

Jim Polito: [00:07:44] Yeah,

Craig Peterson: [00:07:44] But what they're doing is, they've got ahold of Jim Pollito's son's computer. Yeah. And so they don't immediately encrypt it. They don't immediately pop up a notice saying, Hey, you've got ransomware. Like they used to do.

What they're doing now is they spread laterally inside your network. So their software looks for files that have interesting names, it uploads them to the bad guys. So they can have a look at that. The bad guys might hop onto your computer now and poke around saying, Hey, wait a minute.

Your Jim Polito's son works for this health management company and it looks like they might have some assets. So now the bad guys are looking at your computer. I mean the bad guy's actual intelligence, not programming. So these people are looking at it saying, Oh, wait a minute. Here, we've got medical records, we've got all of this stuff and now they evaluate, okay.

So what do we think this is worth. We're into the town of Worcester's computer network. What should we do now? Well, let's infect some more machines because we're in now. So they start spreading to other desktops here. You know, Jim Polito's his son's girlfriend's computer, who also works there in the town.

Now they have visibility into everything, but they've also copied many of these files out of your network. So this might go on for weeks and businesses aren't even noticing this because they don't track any exfiltration of data. Most businesses. So they're pulling all of this data out and now what they do is they encrypt everything on your computers and they pop up a notice saying you have one of two choices.

You can either pay us X dollars. And if it's a town it's probably more along the lines of $10 million dollars

Jim Polito: [00:09:38] Yeah.

Craig Peterson: [00:09:38] You can either pay us that and we'll give you the decryption keys. By the way, they have a help desk now where you can contact the help desk and they'll help you out. Or what will happen is we'll just release all of the tax records of everybody in the town, or all of the medical records of everybody in your medical office or all of the records of all of your customers? Yeah, it's crazy.

Jim Polito: [00:10:01] Yeah.

Craig Peterson: [00:10:01] You know, I've been saying businesses aren't doing this, and this is where the federal register thing comes in. There was an emergency order. If you will, last night here.

On the defense acquisition regulation system from the department of defense. Finally, finally. They basically said all of you contractors out there, the DOD subcontractors, we know you've been lying to us about your compliance with these rules that have been out for two years and so we're giving you an emergency regulation right now.

You have 48 hours' notice. You have to actually secure your systems by December 1st. We now have people who can audit you, who have secret clearances or better. They're going to start that audit on December 1st.

Jim Polito: [00:10:54] Wow.

Craig Peterson: [00:10:54] So just we're talking about, um, you know, company X that make power supplies for DOD contractors, right? This is the power supply. There are no smarts in there. They now have to comply with these new, which are called CMMC rules that are out there. These are just the set of compliance stuff. And they said you have to do it now. Quit. pencil whipping the forms because we're going to be taking a close look.

Oh, and by the way, It's only federal prison time as much as 10 years and millions of dollars worth of fines. Okay. So finally, the feds are getting upset about all of this and, and you've asked me before, what are we going to do about it? How can we make happen? Well, let me tell ya when we get some CEOs going to prison, Jim.

Ears are going to get a little bigger. I think as people listen with these auditors coming in with their sharp pencils, having a good look at the security. So again, here I am on a soapbox. Sorry.

Jim Polito: [00:12:01] No, it's okay. It's okay. It was, it was a complete story. Yeah, it's gotta be done now quickly before we leave, on the lighter side, Zoom. Is the new singles bar. Is that what you're trying to tell me? Because, by the way, I know you have concerns is about Zoom and the security associated with Zoom for businesses to lose proprietary information over Zoom. But Zoom is new, Hey, what's your sign, you know, is the new singles bar.

Craig Peterson: [00:12:36] Yeah, I love this. If this is absolutely amazing here. People are getting married later in life, or not getting married at all. Our fertility rates have plummeted to 1.7. Now, this is going to make it even worse. But businesses and now roof dating groups, you know, we used to have the fast dating. You remember George doing that on Seinfeld? Like 30 seconds eight? Yup. It's. So now. Yeah, speed dating. So now all of this is happening on Zoom businesses or having happy hour. Some of them are sending out little bottles of wine and all of the employees do Zoom. You have to see each other getting drunk and it's spreading into dating more and more and more. It's a fascinating thing. Really changed South here, Jim.

Jim Polito: [00:13:33] Wow. Well, you know, I mean, come on. It's the age of COVID and, maybe that's more effective. You get a look at the person, you can hear them talk, you know, you don't have to give them your personal number. It's just a Zoom thing. If the man or woman is a loser, while you're all set, it's like, yo, I gotta go. I gotta go. I'm all set. I gotta, I ain't gotta go, you know, uh, That's a good thing that you and I aren't out there anymore.

That's a good thing. Yeah. Craig Peterson folks now, uh, Craig, I think I got a correction from Danny. It's 11 o'clock on Sundays. On WHYN, WTAG. That's what he's telling me now. Craig Peterson show. That's what he's telling me.

So we'll have to, we'll have to make sure about that, but in the meantime, how can folks more information from the tech talk guru?

Well, you can always go to my website@craigpeterson.com. But if you have specific questions, especially now, I can send you guys, if you drop me in a line the information here on the changes to the federal register.

If you make anything that is bought by any DOD, contractors, your business just changed at 5:00 PM last night. Just email me M E @craigpeterson.com. I'll send you some of these articles that are out there. The changes by the DOD. Just email me and with any question, I answered dozens a week, just

me@craigpeterson.com.

All right, Craig, we'll talk to you next week. Always a pleasure, always some great surprises.

Craig Peterson: [00:15:18] Thanks, Jim. Take care.

Jim Polito: [00:15:20] Bye-bye.

Craig Peterson: [00:15:21] Hey, I got to get busy right now because there are a lot of companies that need some help and I gotta make sure everybody knows, and I am finishing up right now our first little three- minute videos.

It's taking me a long time, first time around, right. It always does, but things will go a lot swifter here in the future.

We're planning on doing this every Tuesday and Thursday. So keep an eye on your emails for that.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed the political perceptions of the electorate in the age of Social Media and how it is affecting our decisions. Here we go with Jack.

These and more tech tips, news, and updates visit

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, good morning, everybody. Craig Peterson here. I think election season is in full force and I was on with Mr. Jack Heath this morning, chatting a little bit about this and social media and the high hopes I had for the internet back in the early eighties, 81 82, and how things have just gone? Well, downhill.

Politicization did I say that right? Politicalization of the internet and how really things have gotten a whole lot worse. There's something I'm going to have to think about. Maybe find a guest or two to talk about it. Anyhow, here we go with Mr. Heath.

Jack Heath: [00:00:42] All right. They may not seem like a tech talk point, but Craig Peterson joining us a little bit later on in the show, we were packed in the seven o'clock hour. The host of tech talk and Craig, good morning. I wonder what the debate tomorrow night and social media, perhaps you could comment on. It seems every year or two, we have more social media platforms. People are different ages using different mediums. You have all the different social media apps.

Yet this will be tomorrow night on the radio. We'll be having the debate live television, but people are getting information. Look at the number of people that may watch 90 minutes of that debate. He may be surprised and may not be as many people as you think. How important is social media with something like a presidential debate after the debate?

You know, who won? Who said what? What's in store, What part of its sticks?

Craig Peterson: [00:01:24] Hey, good morning, Jack. We were hoping that really social media, the online world would mean a revolution for us. That we would be able to see both sides of all the debate. Get closer together. I had high hopes. I remember back in the back to 81, 82 when I first got on the internet and it was a wonderful place way back.

Jack Heath: [00:01:45] Right. That was when Al Gore invented it right.

Craig Peterson: [00:01:48] Yeah. Yeah, my maybe a couple of years before. In fact, the whole thing that's interesting to me about it is that in fact, what we've ended up with is ways to segment ourselves even further than we had before all of these social media sites. Right?

Feeding us stuff they think we want to see, and they're highly addictive. Now leads to another problem rather than watching them a whole hour and a half of this debate or some of the debates that you have hosted in the past, Jack or on the radio. What people are tending to do now is just wait for the highlights. We've gotten where our attention span on average is less than that of a goldfish.

Jack Heath: [00:02:33] Yeah.

Craig Peterson: [00:02:33] So we just want to know what are the highlights? Give me a quick point. Then you're only going to get the point that their social media site thinks that you want to see.

Jack Heath: [00:02:46] Then you see how divided people are in social media. There's no middle road on anything.

Craig Peterson: [00:02:50] It makes it worse. It's like so many new stations and others now online that just feed one side, and be as inflammatory as possible.

Jack Heath: [00:03:00] Right.

Craig Peterson: [00:03:01] In order to get people to pay attention to and to listen. So, Jack, I think that's just what's going to end up happening here. Most people won't see the whole debate, not even close to it.

They'll just be sitting there scrolling through their social media feeds. Then when something comes across about the terrible thing that Trump said or the horrible thing the Biden did, that's what they'll see in their feeds.

Yeah, I think you're right. All right, Craig Peterson, thank you very much for the tech talk update.

Jack Heath: [00:03:27] Thank you, Craig.

Take care. Okay. My fingers are crossed and if everything goes well, you'll be getting an email here, midweek with a little training in it. I am calling it three-minute training. It might be three to five minutes if I can keep it short. I'm really going to try and help everybody out here.

There's no squeezing. There's no beating you over the head and shoulders to buy stuff from me. These are real training and I'm going to try and do most of them by video. Some of them will be just audio as well as we introduce these concepts that business owners need to understand along with the rest of us and what they can do about it in their business.

One of the big articles I had this last week and I was disappointed that I didn't get more feedback on it, but it was about how CEOs really, really need to pull up their socks. But anyhow, be that as it may.

Have a great week and we will be back tomorrow I expect to be on with Jim. I think Jim Polito is back from his little vacay and I am going to be working today and tomorrow on getting together that very first training.

Take care, Everybody.

Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Craig discusses problems that businesses can face when remote workers have IoT devices on the network they use to connect to work.

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, we got a new red flag for home workers when it comes to those smart digital assistants that we have in our homes. Yeah, indeed. Not only can it cause problems for us in our homes, but that problem can go right through to the business.

Craig Peterson here. Thanks for joining me today, and thanks for all of your messages. I've gotten some great comments. This week had one that I'm going to do another followup on, but it had to do with what kind of router to use at home. I did a whole webinar on this back in March. I'm going to add that back to my list again because obviously, there's still a lot of questions.

Many people can't attend these webinars, but I really would suggest when I do come out with them. That you consider attending if you possibly can. I get it. You can't always attend these things that you'd like to attend, but I responded directly anyways, and I've gotten to the point now where I look at it and say, these crappy, sorry for that term, pieces of hardware that you buy from the big box retailers that are given to you by your friends, at the phone company, the cable company, they are not worth it. It is not worth it. You've got to at least go to the prosumer stuff. And that's what I said to him. The prosumers stuff means that you really got to get something like a Cisco Go hardware.

Really? You do. Yeah. There's a lot of alternatives out there. Juniper has some stuff. HP has some stuff, but there's only one that has a beautifully integrated ecosystem. The low end of the consumer world nowadays really has to be prosumer and me. I'll let you know if there's something that comes out that I think is as good or better.

But, also that Cisco is what I do. My company mainstream has been the number one, installing reseller of Cisco gear in the Northeast US, quarters into quarters. So it's something I like. So just to let you know. Okay. But bottom line, my advice to him was trying to get the Cisco GO stuff.

Now you can buy it on Amazon, but there are things that you need that you cannot buy from Amazon. You've got to go to a licensed reseller in order to get the more advanced protection that you get from some of this Cisco software that is available for the go. Of course, as you move up the line, there's better and better software, but at least start there.

Let's start the show off here with our first article. You'll see this, of course, in your newsletter that came out this week, and this is something I've talked about a long time in general. And in general, what we're talking about is. The whole internet of things concept, and how many years have we talked about that? It's been at least a decade. In fact, I was going through some of the articles on our website.

We're just shutting some of them down because they are so old. But back in 2007, I was already talking about this. So we are 13 years later. And we still have these same problems. People still aren't taking care of them, and they're still doing things the same way, and they are getting nailed. And nowadays, particularly when we're thinking about workers working from home, and I am going to be in a couple of weeks doing a little sip series about working from home and what are the top things you can do to protect your business. If you have people connecting from home now, I don't mean like they're just connecting from home an hour a week, nor do we're only gonna talk about the people who are working from home pretty much full time, Doesn't matter. There are some things you have to do, things you can't do.

And so we'll be going into those with some of the training coming up in a couple of weeks and make sure. You are on my newsletter list. If you want to find out about that stuff, that's just Craig peterson.com/subscribe.

So we're working from home. I think we've established that we're starting to see office space deserts now. I went to see my chiropractor this week and massage therapist. I'm standing outside her office, and she's in this cluster of offices with other people having a little business, and of course, it's a type of business where she can't really do it from home now, can she. She has to actually have her hands on you in order to do some of this stuff. And boy, was it. Oh, a wonderful thing. Cause my neck and my back just it's been really bad after that whole kind of COVID, in bed for a couple of weeks, thing. And. I looked around the parking lot. It was shocking to me. I was there, and this was after lunch. Usually, there are a lot of people who are there in the parking lot, not just for her business. There's gotta be a hundred different office spaces that are in there. There has to be that in this case, when I was, there were three cars in the parking lot, and that was it.

So you are talking about these office space deserts. Where the people just aren't going in there anymore. It's just astounding. Some of these big cities like New York City, the whole city is shut down. They're losing all of these restaurants and all of these places where people used to go shopping because people aren't going there.

Where are they? They're at home. In some cases, you have to be at home. Think about all of the families or the young kids, where the kids are no longer going into school. They're sitting at home, they're on their computers, hopefully, following the teacher and doing their schoolwork. Now I got to put a side note here.

This is the perfect opportunity for you as a parent. To see what your kids are being taught, to look over the shoulder. Now it's amazing to me. I have read quotes from teachers who said they don't want parents looking in because they don't want parents to know what's being taught. Then there are some unions in some of the local school districts that are saying, and it has to do with the privacy of the other children in the class.

You use to be able to, as a parent, go and basically audit your school's classroom that your kid was in. So you could go there and sit in the back and just see what's being taught and how it's being taught. And then the teachers didn't like that because heaven forbid a parent question the professional.

Now we found out, some of these teachers, in fact, a very large number of them are blatant Marxists, just teaching the Marxists dogma. You can see that now, when you look at all of these fascists marching in the street, it's just incredible. So take that opportunity and watch what your kids are doing.

Watch what the teachers are saying and help your kids out. But in many cases, obviously, we can't and get people to watch kids. We can't get babysitters because there's such a high demand for that. So we are forced to work from home. For that very reason, just to make sure that the place doesn't burn down and maybe you can get a few minutes to watch what the teacher's saying. What's really going on there in that classroom.

So if you're working from home, what are you doing? We are sitting there on very frequently, our own computers connected again, quite frequently to the network at the office. Now, if you've attended any of my VPN training, that VPN we're designed for businesses to connect to. Networks at different locations, and that's what they're good at. They're not really designed to protect anything other than the data while it's being transported. That actually becomes a problem, and if you use one of these VPN services, it makes you less secure. I go into the reasons why in my VPN course, and we'll be teaching that one again. So keep an eye out.

But we're now looking at having people at home using their home computers, which don't have all of the protections in place that hopefully, your business computers had, the medium and large businesses have some pretty decent protections in place, but the small businesses, those businesses under 500 employees, very rarely have the right kind of protection in place.

So now you have a personal home computer to the network at the business. What's on that home computer? We've talked about that before. That's a real problem, but now we're asking them the question of what else is on your home network that's connecting to that business network. One of the things is probably your Amazon, Alexa, or your Google home or who knows what other things. We got light bulbs hooked up. We've got all kinds of things hooked up to our home networks. They found a trio of vulnerabilities recently in Amazon Alexa devices, just as they found them in all of these others, a Google home, everything else.

Apparently, these vulnerabilities could have led to broader attacks on the home networks because of the way most of us are misconfiguring VPNs. Those attacks can now easily spread over the network to our business computers. So these are vulnerabilities that were made public last week by researchers at Checkpoint.

Checkpoint has been in the security business for a long time. They made firewalls. I think they're based out of Israel. They've had some very cool stuff, but we're looking at more than 200 million Alexa smart home devices. I have them in my home, but what I've done is, I actually have five different networks in my home.

One of them is for the internet of things devices, so if they are compromised, they cannot get out, and they cannot get to any of the other devices inside my network.

Then, of course, I'm using professional gear for my network, not just prosumer gear. I would advise people to look at that very seriously.

So next we have a study coming out about the presidential election and how both parties, both sides, are very concerned about some security concerns.

So we'll get into that when we get back.

Stick around, you're listening to Craig Peterson, and I'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses problems related to Mail-in Voting and Voting technology.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Red team-blue team. This is a very interesting problem that is now being confirmed. Through a study. A bipartisan study. We are in trouble with our election this year.

Hey everybody. Craig Peterson here. Thanks for joining us.

Man alive! can anything be more political than a presidential election cycle? It is as. Downloading what has been happening when what's being said right now. There are a number of studies that have looked into the efficacy, the ability to have a fair election where we really know the results. There've been all kinds of suggestions.

We've talked on the show before. About well, we could have, an app that we use to vote. We saw what happened with the Democrat primary in Iowa, right? Total mess. We saw what happened with this app called Vote. I don't know if you heard about this, but this is another voting company. There were some security assessments done and votes criticize the researchers and their methods.

The security issues that were uncovered with the votes application, we've actually confirmed a security company called Trail of Bits in March this year. Some serious problems. At the USENIX security conference that just occurred here, about a week ago. Okay. They had a panel of voting experts and they got together and they talked about election security.

They in fact had a couple of sessions at the Usenix security conference that was covering the voting systems and technology. We've talked before about the black hat. Conference and how they set up these voting machines and just see if they could be he hacked. There was like a 12-year old hacked a voting machine that just so simple for so many of these machines out there.

The biggest problem with the voting machines is you don't have a physical audit trail in many cases. What did they do? They added some audit trails to some of them. They have a thermal printer. have you ever taken the receipt from the grocery store, stuck it in your pocket, and left it there for a couple of weeks and it becomes illegible or heaven forbid, it gets too warm? Maybe it is stuck in a hot room or a storage room or a car. It turns completely black.

What good is that sort of thing going to do? All you have is a whole bunch of lines, one at a time about what the votes were. Very hard to tabulate. It's not like the cards that you can use to vote on which many States in new England Jews and frankly, our country right wide right now.

But those cards. You can sit there and analyze them. You might've seen a video of what happened in the Florida election and holding these punch cards up to try and figure out. Is this a hanging Chad and pregnant? Chad was a punched. Was it not Punched? Was this intentional? Did they mean to do that instead?

All of this craziness with the cards. Let's say the question is about the president and who was voted for, was it Joe Biden or was it, Donald Trump, and all they have to do is look at the card. Okay. there's partisan left, a partisan right, maybe a neutral observer standing there. They say this is clearly Joe Biden. So they put it in the Joe Biden pile next. Who is this? that's clearly President Trump, so we'll put it in the Donald Trump pile. Then when you're done, you just count them in the pile versus these audit trails. Yeah. They're audit trails. But how do you do that when it's a paper tape?

How do you do that? If it's been written into a database? How do you know that database wasn't altered? Yeah. Yeah. Okay. there's, there are ways to track things in databases and databases having different types of integrity protection, but overall, you can't really trust it.

And these researchers reverse-engineered this votes Android application, and they did a static analysis on this back end server software that was actually tallying the vote and without having access to the source code without having them a massive number of people who are trying to analyze the system as Russia does.

Russia has its hands on some of our voting equipment. It's easy enough to buy online and pretends you're someone you aren't. So they were doing this blind, the security researchers, and they found five high severity vulnerabilities and a serious privacy issue.

That's using one of these apps from a company that does voting. And we've talked about some of the different voting systems out there from Diebold and many others that have various types of problems. Really. The only way to know if a vote is valid. Is to have a, I like the card ID where you fill in the little circle and then that gets run through a voting machine and it's all overseen by, hopefully, independent people, but I don't care if they're partisan one way or the other and that machine tallies it and keeps the card.

So you can now go back and do a spot analysis on it, or you can do deep analysis on it. I think all of that sort of thing makes sense.

But that's not what we're talking about this year. We're talking about having a presidential election where people are mailing in ballots. It just blows my mind. People comparing it somehow to absentee ballots and absentee voting.

It is not the same thing. And here's why. If you want an absentee ballot, you go to the town clerk or the election official. And you swear out in front of them that you need an absentee ballot. Now in most places that have now been removed that requirement to say, yeah, I'm going to be out of town out of the country. Eh, whatever the reason is, I'm not going to be able to vote on that day to this year. I think it's November 3rd and therefore needed an absentee ballot. Okay. So that's step one. And that's been removed in almost all cases.

I don't have a particular problem with that. Although I would much rather see someone showing up to vote on voting day, which by the way is required by the constitution. I have no idea how this early voting stuff has happened, how it could possibly be constitutional. The vote is November 3rd. It doesn't start on September 1st. It's November 3rd, and that allows the campaigns to get their messaging straight.

It allows the little guys to actually compete with these people who are already serving in office. Anyhow, that's a separate issue.

You have now been standing in front of that clerk's office. And that clerk now brings out the paperwork. what ballot do you want? You might have a partisan ballot, but for the general election, you don't, you have all of the final candidates and now they verify you are who you say you are.

In most cases, that means you present a valid ID. They check the voter rolls and make sure you are eligible to vote and once that's all taken care of, they will hand you the paperwork. Then you can go home. You can vote on that. You sealed it in an envelope, you sign the outside of the envelope across the seal. You follow the instructions. They are not that complicated. And you either drop that back at the clerk's office, which is the safest way to do it, or you mail it and it goes to the clerk's office and it has to be there before the election. And there's some argument that it just has to be stamped by the post office before the end of November 3rd. That's the absentee voting process.

What's happening in many States is they're saying, Oh, all you have to do now is look in your mailbox because we're sending ballots to everybody that we have a name and address for and then you just fill it out. You send it in. TaDa all done. No verification of who you are.

In some cases like the way Florida has been doing that, there is a verification that they did receive your ballot, but that's kind of it.

And there are more problems. And these are what I'm going to talk about when we get back, what are the real problems? The deep problems when we're talking about these ballots.

We'll get into that. Here are the problems that hackers could use. Very inexpensively, very easy for us to have zero confidence that the vote tally is right.

So stick around. I'll be right back. You listening to Craig Peterson right here on the radio, on podcasts, and online@craigpeterson.com.

Stick around.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses the mounting security issues revolving around the upcoming elections.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Before the break, we were talking about some of the problems with different types of voting, the electronic voting machines, the apps that have been used and developed, and serious problems with those. But now we're going to talk about the problem with the mail.

Hey, you're listening to Craig Peterson. Thanks for joining us today.

A great little study was just performed and I kinda liked it. The way they did some of this stuff. They were looking at the problems we are going to have with the presidential election this year. A lot of States, first of all, don't bother checking your voter ID. They don't bother checking to make sure you are a legal voter. Of course, that's a problem and you might know, I live in New Hampshire, our state sport is voting up here. It is. Politics we're first in the nation when it comes to the primaries and we pay a lot of attention to this. One of the things that are illegal and yet happen every time, every two years there's a vote. This is absolutely illegal, is that these kids are in our schools. Because we have some Ivy League colleges, universities. We have even high schools that have kids in them that are of age to vote. It is illegal for them to vote because they are not New Hampshire residents are just here for school and yet they vote every year.

It really bothers me, right? Because us taxpayers in New Hampshire, are being or election severely influenced by people that have legally no right to vote in New Hampshire. I could tell you all kinds of stories, talking with people that come up from mass to vote in New Hampshire elections that have no residency in New Hampshire. There is so much fraud. It just makes my mind boggle.

So this year, the only, or the problems that people have already been talking about, President Trump has talked about, the Democrats used to talk about with people voting illegally. We are looking at problems of, what happens when a state mails out ballots to pretty much every person in the state.

There have already been complaints in States where there have been ballots showing up for people who haven't lived in a house 15 years. Are you kidding me? Don't you guys purge your voter rolls? If people aren't voting it is absolutely insane. So what happens if a ballot shows up at a house and the person hasn't lived there in 15 years? Is someone going to take that ballot and fudge it for their favorite candidate?

How about these homes that people are living in, right where we've had all these COVID deaths. Many of these people are invalid, unfortunately. So are their caretakers going to take their ballots and vote for them? How do we know that a legitimate voter voted and only voted once? We don't. Okay.

That's a problem that many people have I've been talking about, but I talk about tech here and security behind the tech. One of the big problems that we could have right now. Has been proven by this red team-blue team approach. If you've been in the military, you are probably very familiar with the red team-blue team.

This is where you will have a team of people that are attacking. We have another team that is defending. So that whole concept has been moved into the security realm in cybersecurity. We use it. I got a book on it about what to do, how to do that sort of thing. If you're the attacker, here's how you attack.

If you're the defender, here are some good ways to defend it again. That's why it's so important. If you're trying to defend a network to have a unified integrated defense system so you can see when things are happening. You don't have software from these guys, hardware from those guys, hardware from another party, hardware from yet a fourth party. It's impossible to defend when you have too many disparate data points. It might actually be pointing in different directions, every one of them. So you've gotta be very careful about that.

So they had a red team group of attackers that had security professionals, election experts, and law enforcement from both sides of the political spectrum.

They tried a whole bunch of things. Their goal was to undermine confidence in the election results themselves, as well as reducing election turnout. So we've heard accusations that four years ago, the Russians were meddling in our election. Of course, they were, and it happens every year.

Russians meddle. They really are trying to undermine confidence in it. But the Marxists big time, that's what they want to do. They wanted to divide and conquer. They don't want to have any sort of trust, in any sort of government entity or anybody that has any authority so that they can collapse the system and then take over.

So when we're talking about this red team, trying to do something to the election. It's very difficult for them to get into all of the secretaries of state office computers because all of these secretaries of state have different systems. It's very difficult to break into them. Remember, we do not have a national election at all, ever in the United States.

We have 50 individual state elections. It's designed in such a way the small States have a voice against the big States. That's very important. Unfortunately, they changed some of this here with an amendment to the constitution. Senators were supposed to protect the state and they changed all of that by turning it into a popular election, but that's a separate issue.

You've got this red team and if they can't get into the 50 secretaries of States, individual election systems to modify the results or get into the voting machines to modify the results. What's the next best thing, obviously, you're trying to undermine the faith in elections. In voting. Undermine the faith in the results.

We're already hearing from both sides, that we're not going to trust the results. In fact, just this week, I think it was Wednesday, maybe Tuesday, secretary of state Clinton, Hillary Clinton came out and said, no matter what, if Joe Biden doesn't win, he should never concede. Because there is fraud coming. We know President Trump's been warning about fraud as well.

So we've got to come from both sides. Well, they found, through this study, that they can easily and inexpensively spread misinformation about new outbreaks in the COVID virus and that'll hamper people going out to vote. It's going to hamper the processes of mail-in ballots. And if the aim is undermining faith in the election and not necessarily swinging the vote towards one candidate or the other. It's very easy to do.

So we've got a great quote on my website here. You'll find it on dark reading from Maggie McAlpine. She is a co-founder of Nordic innovation labs and it was one of the red team participants and a cyber reason, by the way, was the company that ran this whole thing. She's saying, Hey, it's quite achievable.

And it's a very inexpensive direct quote here. There is this creeping sense of uneasiness because none of what we did was very expensive. Most of the attacks we proposed don't cost anything. Putting out a tweet that shows a crowded hallway and claiming it's a certain polling place. It's just that easy.

Then on the tech side. Did you know how easy it is to reset the post office sorting machines? Yeah. there's been all of this complaint about machines being removed from post offices, which they have been. That was a process that was started under President Obama. It's been going on for years now.

Did you realize that putting a specific barcode on a piece of mail, dropping it in a mailbox and that mail now goes to the post office that will reset the sorting machines? Yeah, it really is that simple. Then guess what happens? Those ballots do not make it to be counted by the secretaries of state in time.

Hey, you're listening to Craig Peterson, stick around. Cause when we come back, we're going to talk about the corporate office reincarnated.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses problems with some of the smart lock technology and an even larger issue surrounding IoT devices in general.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, welcome back everybody. If you have smart locks or you think maybe smart locks are the way to go, we've got a little bit of news for you. Some research had just come out about these smart locks in our homes and offices turns out they just smart for their own britches.

Craig Peterson here. Thanks for joining me online. And of course, WGAN where we air every Saturday from one till three, you can always join us there. I'd love for you to tune in. And of course, we're also on, yeah, you guessed it. Tune in as well as any pretty much any other podcast app out there.

Now, let's get a little bit into this whole smart lock thing. We've been talking a fair amount about the whole problem with IoT on the show. If you miss some of the earlier stuff, I think it's important to go back to particularly if you are a business person or you're working from home and VPNing into a business.

I covered quite a bit of that stuff just today, in fact, but you can always find it out on my website@craigpeterson.com for a review. What we're going to talk about right now? Isn't like the Alexa or the Google home. Although in both cases they do have smart locks and tie into them. Oh, it's just so convenient to tell Alexa to turn on the chicken coop lights or turn them off or open the front door, et cetera.

There are also other types of locks that I think are really cool where it's a proximity lock. It uses your Bluetooth phone ID. That ID is typically something that is merely a, are basically like a Mac address there on your Bluetooth device.

There are other ones that are being built into cars, including Teslas and now BMWs that use an app on your phone in order to unlock the door, cool all the way around.

But behind all of these is some technology that is not only unproven but according to grand view research, this is still a bit of a problem. We're looking at a global, smart lock market valued at $1.2 billion. Last year over 7 million devices sold last year and they are expecting this market to grow pretty dramatically over the next five to 10 years. But there are two recently published reports about smart lock vulnerabilities that are very concerning.

This is another article out of dark reading our friends over there. First of all the UTEC ultra lock. Now they have hit the news before this is a smart lock project. It began as an Indiegogo campaign. If you're not familiar with them, it's where people get to you, invest in a project. If the project comes to fruition they go ahead and they get one of the products. That's usually how those types of things work. It's a way for people to invest a couple of bucks on something that they really believe in.

So this guy came up with this ultra lock and the idea and the group put it together and they put it up on IndieGoGo to try and raise some money to build these new types of smart locks that they had.

Tripwire, which is a security research company among other things said that they came across this flaw late last year, the researcher's name is Craig Young. And he was looking into this, the protocol that's being used by a lot of these smart devices, It's called MQTT, which is message queuing, telemetry transport.

You can think of it as an SNMP if you are a little bit more techie. Which is the simple network management protocol, but lighter weight because the internet of things, devices just don't have enough memory and CPU and everything else to run big operating systems. Now I have a problem with that.

The manufacturers saying, we've got to go with this lightweight protocol, man. We're just a door lock. how can you expect us to do anything more? It turns out that a lot of these companies are not using authentication that's verifiable. They are not using encryption and they're not using any sort of real authorization scheme.

So what's happened here is he has proven that pretty much any unauthorized user, that can see one of these messages in transit port and get access that broker can easily guess the names of that are used the topic names. Now in SNMP, you have the MIPS. There are security parameters that you can use, but in this case, all you have to do if you can get access to that, the broker is use the pound sign and the topic name, and now all of a sudden you're obtaining all of the data that's going through that data broker.

This is a very. Big problem. So he looked at several pages of these protocols, topic names, and he kept finding references to LOC and free email providers. Like g-mail dot com that some of these companies are using, if you can believe that.

So he said, I query the server myself with Linux command, align tools, and I was instantly inundated with personally identifiable information, apparently from all over the world. He said that it included email addresses, IP addresses associated with the logs, timestamp records of when and where they opened and closed all of it.

Now there is thinking out there that really this protocol can be perfectly safe. But the problem again is these companies that are making them are not hiring professional programmers that understand the risks because it could have been secured. They should be using access controls. They should be using authentication. They should be using encryption. In this case with UTEC, it used none of those things. None of them. so again, don't just blame it on China, although they certainly take shortcuts. Most of these companies here in the US are taking shortcuts too.

We don't have any real programmers coming out of schools now it's all drag and drop. Yeah. Yeah. You just drag this visual basic, visual C-sharp thing, whatever it might be. There's this Java module and magic happens. Without them knowing what's really going on behind the scene. There's another one too, about the August smart lock. This is out of Bitdefender now a bit defender has software that I recommend a lot of people use.

It is not a panacea. It is not the ultimate. But bit defender, particularly their paid version usually does help with your security. So a little tip there for those of us on either a Mac or a windows computer. Check out Bitdefender, you might want to use it, not as good again as the commercial stuff, the real stuff for real businesses.

But they said, yes, they documented in detail, a vulnerability. The bit defender had found with the August smart lock also late last year and the Bitdefender guys were working with PC mag and they were evaluating smart device security. So Bitdefender is saying that their team does discover that while this August smart lock.

It could communicate with the smartphone in over an encrypted channel. The encryption key itself is hardcoded into the app. So it allows an attacker within range to use, drop an intercept, the wifi password it's really that simple. So there you go. There's an example. Of a smartphone using wifi to talk to the lock and yeah. Yeah. We're encrypted.

So again, it goes back to pencil whipping forms is your smart lock encrypted? Oh yeah, we are encrypted. And then that's where the conversation ends in the audit check purchasing manager just checks it there on the form. it's almost completely useless when it's programmed this way. Almost completely useless. So again, this is. Obviously specific to this device and when the device is being set up a real vulnerability, but you know what you could, if you want them to install another one of those devices, all you have to do is install a little monitor, hide it there in the bushes or something, and burn out the lock that's there or smasher or whatever you want to do so that it has to be replaced and when the guy replaces it. TaDa you have access to it. It's obviously not that difficult.

Now, someone overseas isn't going to be able to get at it. But someone that is really determined to get into your house could get into it pretty easily. It reminds me of a lot of these door lock systems that are still used in cars today that can be replicated.

You just sit there in the parking lot at a shopping mall and you have a receiver that's listening for that little. Click on the remote control right in the car goes, beep yeah, I'm locked.

Many of those, in fact, almost all of the older ones, can then be duplicated so that all the guy has to do is okay, great, he just locked up that old or BMW. It's only worth $30,000 today, but you know what the heck? And he can replicate it and get that car to unlock itself.

So we have to be a lot more careful with this stuff. Absolutely, a lot more careful. I am very upset with the vendors that do this sort of thing. They are fooling people. They are scamming people by again, pencil whipping forms that poor guy/ gal who's working in purchasing who bought it, who had no idea that, the checkbox was checked, is now in trouble because that device was hacked.

That's just an example of two obvious problems with smart locks. It's a really sad fact of life. That many companies don't have real security people who can look into this and look into a little bit more.

All right. When we come back, we got more, we're going to talk about facial recognition and what the cops are doing right now with not just protesters, obviously, but rioters and how they're using it to arrest people.

You're listening to Craig Peterson here on WGAN and of course, I am on every Wednesday morning at seven 30 with Matt, Gagnon.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses how Police are using Facial Recognition to identify and trace movements of rioters.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Facial recognition software is getting better all the time. You've seen these rioters and they're wearing all of the masks and hoods and helmets and everything to try and hide their identity. It isn't working anymore.

Craig Peterson: [00:00:20] Hey everybody, Craig Peterson here. Thanks for joining me here on WGAN and online. Of course, Craig peterson.com. If you would take a minute. let me know what you like about the show. Some things you don't like. I've had some great comments for people telling me about when they listen, where they listen, all of that stuff really helps me out. Also what it is, you like the best or you like the worst. Okay.

Make sure also you take a minute. This is for your advantage in a very big way that is making sure you get my newsletter. I have every week articles in there for you. I am starting up here in a couple of weeks. I'm going to have a couple of midweek articles to delving into a security topic, trying to help you out with some of that stuff. So you'll probably hear from me about three times a week. Those ones during the week should only take you a few minutes to go through and it's going to be what's happening now right now.

Trying to keep you up to date on that in the past, that's been something that has been reserved for my navigating cybersecurity masterclass. But, we're going to be releasing some of that for everybody out there. Cause I think it's just that important. All available for free and all of it. When you sign up at Craig peterson.com/subscribe, and I'll also be sending you. Three. Very cool, special reports. Things. I think you'll really like it, and one of them is about your security reboot. So all of that, you'll get to sign up. Craig Peterson.com/subscribe.

We've had some really interesting technology we've talked about on the show and then I've had some CEOs on talking about this tech, where it is being used to spy and track criminals. This particular track I'm thinking of right now was probably still is out there. I, in fact, I know it is. An airplane. It's just a small plane, like a Cessna and that plane flies over big cities and things like New York and Chicago and Los Angeles. Although in LA, they have helicopters all over the place being run by the police departments. This plane is up there with a super high-resolution video camera that is recording everything going on.

The idea behind this is if a crime is committed. They can play that video backward and track the people who committed the crime, hopefully back to where they started from. So they can track them all the way back to their home. Maybe their business, maybe some park that they met at, and then from that park, they can track them back.

It has days and days worth of data. So if you're out on the streets, you're walking around. The camera's picking you up from that airplane. If you are driving around the camera's picking you up on that airplane, I think that's really cool technology. The supposition here, and the Supreme court has held this up, is that if you are out in public, you have no reasonable expectations of privacy. So that was a number of years back.

Now, of course, they've been adding more and more video cameras. There's a lot of questions here in Maine. There've been a lot of discussions about it. Matt has talked about it before on his show. Should we be putting up these video cameras? Is it the right thing to do.

Some police departments have video cameras on all four corners of their squad cars. As they're driving down the street, just normally doing whatever it is they're doing, observing what's going on. Those squad cars are streaming that video Live to a computer system. That's looking up every license plate that has seen now, the police car also has GPS information. So now your cars tracked. If it sees it, if it picks it up and sees the license plate number, it is now logged, and it's fairly permanent. Although police departments seem to be having problems lately keeping the data, that's a separate issue. And if there is a warrant on the owner of the car, so guess what they have to do, they have a license plate number.

They have to look it up. They have to see who the owner is, then they run that through their local database or maybe the NTIC or something else to try and see. If there is a want or warrant out for the owner of the vehicle and they may impound the vehicle, then they may wait there for you to return.

There's a lot of things they can do. In fact, the tow truck operators, many of them have that same system on their trucks. They drive around parking lots over at malls. Looking for cars that maybe they're behind on the payments and they can't find the car, they have to go pick it up. Maybe that car is something that there's a lot of parking tickets on.

And so they get paid for doing that fine, that storage fee that you pay, that's going into the pockets of. It was some of these tow truck operators. It reminds me of a thing that happened to a friend of mine with his car getting towed and the tow truck operators had going kind of crazy jumping on his car and everything else. It was just a bit of a mess.

Anyhow, all of this type of surveillance. I personally think is bad. I think it's wrong. It is too easy to be misused. It is too easy for it to be stolen and then it's in the hands of it, who, which bad guys, right?

Wouldn't it be cool if you're a bad guy in, okay, I'm going to break into this home and it's going to be a burglary, not a robbery cause no one's home and isn't that a wonderful thing and by the way, we're tracking his car here cause we've tapped into? The police system. Or maybe we've into the system of those, tow truck operators.

And we know where his car is, and we'll know when it's on its way home. Because in addition to that, yeah. A lot of these cities have been installed on these cams on traffic lights. Now they know you are going through an intersection and where you went through, what time you went through. Did you wait for that red light? Did you squash it down as the yellow, turned red? It wasn't quite red, yet. This is something else.

Now we're looking at law enforcement dealing with. Violent protesters, right? these fascists who call themselves anti-fascist right. They, these Marxists, they call themselves a the BLM right now. There are legitimate people. There are great people who really care and are really trying to do the right thing. That's not what we're worried about. We're worried about the people that are burning down our businesses, that are causing havoc, that is shooting people that are hitting people over the head with a skateboard or baseball bat.

So the law enforcement in a number of cities now, including New York and Miami. Have been using some facial recognition software to track down and arrest individuals who were participating in criminal activities during these riots. They're doing it after the fact, it's interesting how some of them are doing it.

In some cases like with the fed, they have been tracking them. Watching them while they're in the protests, which is the wrong word is really riots, right? The protest is one thing, burning down buildings, police cars, civilian vehicles, batting people over the head. That's not exactly a protest. What they do is I wait for them to leave the area because you don't want to try and arrest them right in the middle of all of these rioters and they leave the area.

Then they get arrested. Which I think makes a whole lot of sense. Miami pleas are using something called Clearview AI. Now, remember we talked about them a few months ago, maybe six months ago now because this woman allegedly threw a rock at a police officer. Then what they do is they use facial recognition.

Technology not just to surveil them and track them and then arrest them later. They are running it. That's what Clearview does running it through social. Yes, media posts to try and find people. A very interesting problem. Frankly, a New York man air bill DeBlasio promised that the NYPD would be very careful and very limited, and they're not going to arrest it most of these people that are causing bodily harm and destruction of private property. Yeah. Good going mayor DeBlasio. Good. Going a lot of things here. You already know. I don't like Clearview AI, and I don't like the way this technology could be misused by any stretch.

Stick around. We'll be right back listening to Craig Peterson on WGAN and joined me Wednesdays at seven 30 with Matt Gagnon

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses the Hawthorne Effect and the changing business office.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, is this the great reset or maybe it's the inevitable reincarnation of the corporate office. That's what we're going to talk about right now. What is happening? What's happening at the corporate real estate? How are we using technology to cope?

Craig Peterson: [00:00:18] You're listening to Craig Peterson thanks for joining us.

This is a very interesting problem. We are looking at the corporate offices and we're seeing some major changes. I remember back when I was a professor out at Pepperdine university teaching management information systems 422, MIS 422, right now it's called more of IT, It's more information technology than management information. I remember being a professor there and teaching all of these young minds full of mush. Actually, it was mostly people who already had jobs about the Hawthorne effect. This was absolutely fascinating to me. I think it was Western electric, had a plant out in Illinois and there were just all kinds of workers. They're thinking about it. And I'm looking at a picture of it right now that I pulled up over on Wikipedia and the Hawthorne Works. It's an aerial view drawn by hand, a beautiful pencil work circa 1925. Huge buildings, six stories tall, if you can believe that.

It covered acres and acres, just looking at this picture. Absolutely astounding. There was a study of the Hawthorne studies conducted between 1924 and 1932. In this factory, just outside of Chicago and it was deemed the Hawthorne effect, and here's what they wanted to figure out.

You might've seen something like this in, in some movies in the past here, Schindler's list is one of them, right? How many hinges can you make in a certain amount of time? The Hawthorne Works commissioned a study, do to try and figure out if its workers would become more productive in higher or lower levels of light.

That obviously was just trying to make things a little less expensive for manufacturing. But also because Western electric to justify, you need more light, right? You got to buy lights from us. They found that the worker's productivity seemed to improve where changes were made, but here's what happened. Productivity dropped when the study ended.

What they actually ended up figuring out is that just being observed, changed the way these workers worked. That's the bottom line on this whole thing. There are other basises, if you will, of the Hawthorne, right fact, besides the workplace lighting. It had to do with maintaining these clean workstations, clearing the floors, relocating workstations. They all resulted in increased productivity, but only for short periods. So the Hawthorne effect, that term is used nowadays to identify any type of short-lived increase in productivity.

The big question I have right now is we are working from home more and more of us. We've got major companies out there, including Microsoft, Facebook, and Google. All of those guys, of course, are tech companies, who have closed their physical offices until well into next year. Twitter is told many of its employees. I have don't have an exact number, but Twitter is saying you can work from home permanently to those employees.

Now we have nearly six months. If you can believe it's been six months of forced work from home behind us now. Other organizations are reconsidering the value of office space. Of course, it comes right to mind too, that weSpace guy. If you know who he is, who started this company, where it was shared office space, and the guy turned out to be a real crook, maybe is a good way to put it, but, not a nice guy, not a good guy and he got forced out of that company. But there are others. There's like Regis and others.

But in April of this year, Gallup did a poll and Gallup says that in April 62% of the workforce force was working from home. Now, I think we've got to, as a business, people have to pull back and look at this. Why do we even have these offices in the first place? Is there a real justification for it? I brought up that Hawthorne effect because of the industrial revolution. Instead of having a blacksmith down on the corner and another blacksmith across town and another blacksmith, two towns over. What the industrial revolution did was pull all of the blacksmithing into one factory where we could do it more efficiently. We could do it faster, and we could even come up with a better product because we had better quality control by having it all in one place. I'm postulating and there are some studies that really agree that looked at this, but. We took that model from the industrial revolution that worked great for the physical side of working and we just pushed all of our intellectual workers into that same mold. It's gotta be more efficient, having everyone in one, one workspace where we can monitor and control better. I suspect that this Hawthorne effect we were talking about had something to do with that all, ultimately. That's a very big deal.

Very big deal. So in June this year, Stanford showed that only 42% of the workforce was working from home full time, down about 20%. But that's still almost half of the people. And I really want us all to consider this very seriously. There are some advantages to having people chatting over the water cooler.

So what some businesses have done is they have their employees get together, WebEx teams, and eat lunch together. And they chat about things, right? You don't always have to chat about business. Yeah. It's entrepreneurs, that's all we ever do. That's all we ever think of, right is business, but they're talking about their dog and their kid and just had the had fixed.

And, my bees are doing this week and you have that watercooler chat you still have it, but we have it remotely. Fascinating questions. Management seems to be coming to some conclusions here because, in April, the Gartner Group surveyed and found that 74% of chief financial officers are planning to remove office space, get rid of it.

We know some businesses are selling off buildings. If you're in commercial real estate, of course, I don't give investment advice, but I would be very concerned. The commercial real estate market has been in a bubble for many years, according to a number of people that I follow, who are financial advisors.

So the question really is to what degree should you transform your definition of the office? To what degree should you be transforming your meetings? Your communications channels. Many of us have moved to a team's app or Slack, which is a dangerous thing to use, Slack, but they have found that all of a sudden now people aren't working eight hours a day. They're working 10, 12, 13, 14 hours a day because there's no separation between work and home because people are putting things into these team channels that just don't need to be there.

So there's no question here that there's going to be some sort of a reincarnation of the office. It's bound to change. We're seeing numbers that are proving that right now. It's a very big deal. So I have seen a number of businesses, a lot of them, including big businesses that had projects underway. To redo their offices to build more offices that are now cutting way back. Even one of my kids has just such a job.

She's been working from home ever since March, and will probably permanently work from home. Now as a business person, you also have to consider. Can you compensate these people because it's way cheaper to have them work from home? Maybe you should be chipping in to help with their electric bill. Maybe you should be chipping in to help them get that second screen. Maybe you should not be requiring them to use their own cell phone smartphone to take phone calls on. Okay. So think about all of that stuff.

There will be a multi-year management consulting engagement available for thousands of managers, consultants out there. I've been working at home now for over 20 years. And I owned an office building. I owned a while. I rented office space from other local places that had a business office space. it worked out pretty well for us. But looking back at it, I think almost all of it could have been done and probably would have been done better if they'd been working from home.

If your managers can resist that urge to micromanage where we're installing spyware on people's computers, which I think is going a little too far, then you could get some incredible productivity out of employees. We've seen that happen, as well. Some organizations like consulting, firms, like my business, where we do security, we have people monitoring systems.

We have people designing networks and integrating with existing networks. those types of businesses can function pretty well without any sort of an office, but that means other businesses are going to have to change.

Banks. Want to see that you have a physical office in order to be a business? That's not true anymore. A physical office can be almost anything anywhere. We've got to rethink everything. We have to, as workers are conscientious about this, and as business people, business owners, we've gotta be very careful and very conscientious about this. Of course, earlier in today's show if you missed it, I did talk about working from home and some of the problems we're having right now with security because of the home computers, the home networks, the internet of things, All of that sort of stuff.

If we want to make this post COVID office work best. You've got to make it focus on a place that people want to be, at least occasionally. And that might mean I can tell the place that it's easy to drop in on, and just as easy as it is to work from home. So keep that in mind.

Hey, thanks for joining me today. I am dropping off here on some of the stations, other stations.

We will be back after the break here for another hour, and we're going to be talking about smart lock hacks, Cops in Miami and New York City, and of course, a whole lot more.

So stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses how a kid on a zoom virtual learning meeting caused his parents to be questioned by Police.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] When you think of a violation of somebody violating your privacy, what are you thinking about? Is it people Tom's? Is it somebody sharing a little story about you? That isn't true. with back to school, virtual, um.

Craig Peterson: [00:00:19] Yeah, we've got a story coming out of Joe Biden's country in Maryland. That is very disconcerting. This is from a TV station down in Maryland. Fox Baltimore is the station, and this is very concerning to me. We have many kids that are going to school virtually right now.

If you know me, I homeschooled along with my wife. In fact, primarily my wife, kids, we had eight kids together. They're all grown. This was back before homeschooling was popular. In fact, back when homeschooling was pretty much illegal and I got hauled into court over it, fought and won by the way.

It gets to be a difficult situation now where. You have a kid that's at home, which means your job is now threatened because can you work at home? Even if you can work at home. Okay. You take the time to monitor the kid to maybe help them out a little bit. There are some out there right now, school districts who are saying, you can't monitor, you can't be in the same room as your child. It might violate other children's privacy.

As though children particularly have a right to privacy. in loco parentis thing, the schools are the parents. You are giving up your child to the school and the school can do amazing bad things with your child without your permission. We're not going into that right now.

But I have seen that again and again, in fact, in our court case, it was eyeopening to me what came up, it was just absolutely shocking. Of course, none of my kids were in school and that was part of the problem. But at that point they said, we went to all of the local schools and, we were going over there cause we wanted to speak to your children.

Cause what they do is they just remove the child from the class. If they want to investigate you. The child has no right to have defense there. They don't have to notify you. They don't even have to record it in most cases. Then they sit there with the child and they do who knows what with that child. I've heard stories about, some of these dolls they use, and it's just scary how perverted some of these people are in government and in our school.

In my case, it was well we could not find your kids in school, therefore, they are not being educated, which if you know my kids if you know any of them, the opposite is true. Most of my kids have gone on to get advanced college degrees, university degrees. Yeah. and the rest of them have far more than a university Ph.D. program equivalent.

It's just shocking. Yeah. What they will do in the whole school system and it has to do with the teachers union. There are some fantastic teachers that really care. I remember two, particularly when I was growing up, cause I went to public schools and I remember their names still.

Mrs. Petri, Mr. Cotes, and the impact they had on me. The very positive impact. I had another one too that I have a few memories of. It is a different world today because the teachers don't want you watching over their shoulders. I have read quotes and I've seen a video where some of these teachers are concerned because the parents are going to find out what's going on in the schools.

What they're being taught. We know, for instance, one of the founders and people that are still running black live matter has come out and she's on video proudly proclaiming that she is a trained Marxist. We see that all of the time, they're trying to convince our kids to do that. Now, there are some amazing teachers that not only help the kids to understand it.

I still remember one of my economics professors and how he really was trying to help us understand what was going on. What was the value of different things and why? And I remember his explanation of how the Dow Jones average worked. Oh man, was he wrong? Be that as it may, we have teachers out there and I know them because you guys have reached out to me who are trying to teach the right things in the schools. Who is pushing back on the agenda that some of these teacher's unions are trying to push in this school?

I would suggest that you be very careful when it comes to your kids being online for school. Hopefully, they're not using something like zoom, which is horrific. It is not controllable by the school and the means it needs to be controlled. It is not secure. It is not safe. Don't use Zoom. But, what are you going to say? You're just a parent, right? What are you going to be able to do about it?

Use by all means WebEx teams or a straight-up WebEx. WebEx teams work great for classrooms and it has the types of controls on it so that you can stay private. You can do the things you need to do to really stay private.

So I see the school districts that are using zoom and saying, Whoa, it all for privacy. We've got to make sure that you are not sitting there watching what's going on. In the meantime, they're using Zoom. It's just Whoa, wait a minute. That's obviously not the reason.

Here's a case again, coming out of Joe Biden's home territory here in Baltimore. Where a child was on one of these virtual classrooms and someone reported her because if you can believe this child had a BB gun mounted on the wall, in his bedroom and that was offensive to other children.

And obviously, the parents who were watching over their kid's shoulders. Yeah. It's fine for those nare-do-wells to be watching and complaining. But it's not fine for you to watch your children make sure things are going, okay.

So apparently this parent reported it to the school administrators. The superintendent and the school board demanded answers. She said the principal initially compared bringing a weapon to a virtual class to bringing a gun to school, she was also told that she could not see the screenshot of her son's bedroom because it's not part of a student record.

Yeah. But it certainly got passed around. Didn't it. Okay, so who's on these calls? Who's viewing this stuff? Of course, the police end up coming to her home and the police have a report that they have to investigate a very big deal, Okay. Is this is very scary!

No one called her first. They just called the police and they had the police go by nothing. So the police knock on her door and say, we need to come in by the way. That's what they do. They say, yeah, we have to come in. We need to come in. Even though they may not have a legal basis, two force entry. That's not just true of the police. That's true of most people working for the government, but, she let them in. she let them look around. I have seen this before in my home state. A butcher block on a kitchen counter makes your home an unsafe environment. They tried to remove the children from that home. So that if the kid's in the kitchen and there's a butcher block behind them on a counter, does that mean there's a weapon?

Did that child bring a weapon to the classroom? Cause there's a butcher block in the kitchen behind him. Or there's a BB gun secured on the wall behind him. This is technology in misuse, frankly, if you ask me, okay. This is very bad. This is very sad. This is Joe Biden's. Baltimore, Maryland. Yes, indeed.

So the police searched it. They were in the home for about 20 minutes. They found no violations of the law. Again, that reminds me, of socialism, show me the man, I'll show you the crime. 20 minutes in the home. What might they have found heaven forbid? Maybe an unclean environment with some kitty litter spilled out of the kitty litter box.

I've seen worse. I've seen more done for less. Anyways. Keep that in mind with your kids while they're in these virtual classrooms.

When we come back, we're going to talk a little bit about Uber. You have security charges over there.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses a hack at Uber that ended up with its Chief of Security facing Obstruction of Justice charges.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Patch Tuesday (September 2020): Microsoft Addresses 129 Vulnerabilities

Ransomware accounted for 41% of all cyber insurance claims in H1 2020

A bevy of new features make iOS 14 the most secure mobile OS ever

Don't Fall for It! Defending Against Deepfakes

Patient dies after a ransomware attack reroutes her to a remote hospital

Lock your doors, people: Verizon breach on unsecured AWS server exposes 14M customer records

Time for CEOs to Stop Enabling China's Blatant IP Theft

Newly Patched Amazon Alexa Flaws -- A Red Flag for Home Workers

74 Days From the Presidential Election, Security Worries Mount Respawn point: The inevitable reincarnation of the corporate office Smart-Lock Hacks Point to Larger IoT Problems Cops in Miami, NYC arrest protesters from facial recognition matches 7 Ways to Keep Your Remote Workforce Safe Using Zoom Can Get You Arrested! Former Chief Security Officer For Uber Charged With Obstruction of Justice ---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, I've got a story right now that should be a word of warning to businesses that have personal information. If you are working for a company and they've got your personal information, you're going to want to hear this too.

Hi everybody Craig Peterson here on WGAN. Thanks for joining me today. I'm on every Saturday from one until 3:00 PM. And if you miss any part of the show, make sure you go online. Craig peterson.com. You can also find me on tune in and any other streaming podcast app that you might care to look for me. I'm pretty much everywhere.

We are going to talk right now about Uber. There are many people who are really not knowledgeable about security that are in security jobs and positions. I would say that the majority of people that are in jobs responsible for security are not fully qualified. They know more than everybody else in the organization, but that doesn't mean they're qualified. So that's one class.

Of course, you have the people who really do know what they're doing. They are few and far between. Then you have Uber's former chief security officer. He just got nailed over a coverup of a hack that had occurred at Uber. This is really fascinating because he played some games.

He played very fast and loose with the truth and a criminal complaint ended up getting filed against him. In federal court this week, the guy's name is Joseph Sullivan. If you look at a picture of him, he's got the kind of beard that almost makes him look like he's one of these gangsters.

I have a thing about facial hair and maybe it's just my generation, my age. I'm not sure what, but he looks creepy to me, that a beard thing that he has Joseph Sullivan, but he was charged with obstruction of justice and misprision of a felony connected with the attempted coverup of a 2016 hack of Uber.

Now isn't that interesting here? And this is a, I'm getting this from justice.gov and it's United States attorney David Anderson, and the FBI were involved in this, Craig de Faire. And this is really an interesting story when you get right down into it. And we'll cover a little bit of that right now.

But according to this complaint that was filed between April of 2015 and November of 2017. This guy, Joseph Sullivan, he's 52 years old lives in Palo Alto, California. Where else he was Uber's chief security officer. Now, he was contacted by two hackers via email that said that they had been able to hack Uber's system and they were able to download a database that had personally identifiable information-on 57 million Uber users and drivers. Now, remember Uber is the company that had this God-mode is what they called it. Uber is a company that had employees, including apparently their CEO. Watching people getting driven and where they started, where they ended up. Now, we'll go, okay. you got to do a little quality control. Hey, I get that.

It turns out they were monitoring celebrities, finding out where the celebrities lived, watching them go, where they were going, that the type of stuff you need. Yeah, in order to twist arms, right? Hold their data a little bit in ransom, little pirate operation going on there. So they got in trouble for that one too.

They have been hacked before. So apparently this Joseph Sullivan guy, when he got the email look to see, did this actually happen? And they found, yeah, indeed. At least this is what the criminal complaint is alleging. They did indeed get them the driver's license numbers for approximately 600,000 people who drove for Uber.

Think about that for a minute. And what are licenses good for? Oh yeah. This year voting, right? Yeah. Yeah, because there's no ID is necessary. It's just mailed in. 57 million users and drivers over half a million driver's license numbers. What he apparently did was he went and used Uber's bug bounty program.

Most companies have that nowadays. It's Hey, you found a bug in our software in our system. We will pay you because we appreciate that. We'd rather you did it and we pay you a bounty than for bad guys to find it. All right. apparently, he was being extorted here because these hackers demanded a six-figure payment in exchange for their silence.

Now that's become very popular nowadays, by the way, this was a few years back. Now, nowadays ransomware works in two ways. One, they say, Hey, if you want your data back, if you want to decrypt it, you got to pay up. The other way it works is that this ransomware downloads your files, first. So the bad guys have it, so they will ransom it one way or the other.

It'll say, Hey, you pay up or I'm going to release all of this data. Or in this case, I'm going to give Uber or black eye. Cause I'm going to tell the media about it and release it. Or Hey, if you want your data decrypted, you gotta pay me. They can get, they're getting clever. These criminals. That's very common nowadays.

So it alleges this criminal complaint. That Sullivan took deliberate steps to conceal deflect and mislead the federal trade commission about the breach. Why? it turns out that a month or so later, their FTC filing was due and part of that needed to be about the security that they were taking because prior settlements with the government and the court required them to report on their security operation.

Yeah. Yeah. interesting Justine and the charges and the statement I've got there. In fact, when I'm reading it from here is the justice.gov, but it actually has the information about the indictment. So this is very one-sided.

There's nothing here from Sullivan's attorneys. It's just what the government is saying. So the complaint also describes how Sullivan. Played a pivotal role in responding to the FCC inquiry about Uber cybersecurity. It's just absolutely amazing. Okay.

So what do we learn from this? I think we learn a few things.

First of all, if you are a business owner and you have any data at all, really nowadays, it's pretty much every business. Even if you don't have driver's licenses, do you know what you got, you might have bank account information, your own bank, account information, not even just customers or businesses that you trade with, where you're just transferring funds back and forth.

You might have all of that stuff on your computers. And we do scans for businesses and we look specifically for bank account numbers, social security, numbers, phone numbers, all kinds of stuff that is illegal to disclose. it's absolutely amazing. Apparently Uber paid the hackers a hundred thousand dollars in Bitcoin in December 2016, and hackers obviously never provided their true names.

Sullivan tried to get the hackers to sign nondisclosure agreements and these agreements that Uber's lawyers put together contained false representations saying that the hackers did not take or store any data, which apparently is not true. So this complaint goes on. It's absolutely amazing.

Again, if you're a business, all 50 States now have laws that require you to disclose when data is stolen. You have to disclose it and you cannot hide it. Particularly if you are a publicly-traded company or if you're a division of a publicly-traded company earlier in the show, I mentioned this whole pencil whipping forms thing where people have a form, it might be for the insurance company and might be for federal or state regulators and they just check the box.

Yup. yup. Yup. Yup. Even though they don't really know. And they don't know enough to know that they don't really know. Okay. So we have to be very careful about that. And so that's why we do these scans. In fact, we do them daily for our customers just to see if the data is out there. So make sure you're not storing any of that data.

I am a bit of a packrat myself, a digital packrat. I have stuff going way back when, but I make sure I don't have any PII. At least I try and make sure of that. You need to do that too. If you're a consumer, remember again, all 50 states have in place laws to help protect you. Now about the only thing that you might be able to do is get a couple of bucks from a settlement.

Look at this. I filed for my settlement offer from Equifax, which is how many years old now, where they lost all of your personal data was all stolen. Maybe four years, five years ago, by hackers it's known to have been stolen. They admitted it was stolen because they didn't keep things patched up and their security people were underfunded work too hard. Which happens every day in this country, unfortunately. And, who knows? the attorneys did, they got their tens of millions of dollars in attorney's fees that happens every year here in this country. I'm still waiting for my supposed check for $25.

They're now saying, it was probably gonna be a lot less than $25. Cause you know, attorney's fees, right? I added that last part, but this is absolutely ridiculous. It's ridiculous.

So if something does happen, if your data shows up on the dark web, you should take action. Cause that's the only way these businesses are going to get their act together.

Craig Peterson: [00:11:08] So I want to encourage you right now to go to a website it's called, have I been pwned dot com. Have I been pwned is like pawned, but with a P w n e d dot com. Okay. Look there, put in your email address and they will search their databases of known hacks. The data existing on the dark web and have been pwned will tell you where your data was stolen.

Craig Peterson: [00:11:35] What was stolen. Might've been just your email address might include your name, your social security number, bank, account numbers. They pretty much have it, but all, and then you can contact these various companies where your data was stored your people, and maybe you should get involved with the criminal complaint.

Against some of these companies be part of a class-action lawsuit, make some bucks, we've got to stop this. We've got to get people smartened up.

All right, everybody makes sure right now you go online Craig peterson.com/subscribe so that you can get in this training. You can get your reboot guide. You can get all of this stuff.

Listen Wednesday mornings at seven 30 while I'm on with Matt Gagnon right here on WGAN.

Take care, everybody.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon, and we began talking about Deep Fakes and then went right into China's theft of US Intellectual Property. Let's get into my conversation with Matt on WGAN.

These and more tech tips, news, and updates just visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Be extra careful, because the best way to defend against these deep fakes is to hold the people accountable that host them.

Good morning, everybody. It was on with Mr. Matt Gangon this morning, and he and I had a couple of conversations about this. It turns out hot topics in which both of us are very interested. Not just curious, frankly, I get on my soapbox.

Matt Gagnon: [00:00:29] It is seven 36 on the WGAN and morning news on Wednesday. It's time to talk to Craig Peterson, and it is a pleasure. Welcome on the program, as usual, Craig, how are you?

Craig Peterson: [00:00:39] Hey, good morning. I am doing well.

Matt Gagnon: [00:00:42] Thank you so much for joining us, sir. Of course, you could hear this voice you hear right now on Saturdays.

Is that correct? Mr. Peterson?

Craig Peterson: [00:00:52] Yes, you can every Saturday from one to three,

Matt Gagnon: [00:00:56] Indeed. All right, let's get right into things here. So I was watching some well done, deep fakes on YouTube the other day. They were taking a, I don't know if you've ever seen these Craig, but they were, they were taking, like impressions, like celebrity impressions of other celebrities.

Then actually. Like deep faking the real face of the real celebrity on to the person. Who's the impressionist and it's creepy. And it's all like Tom cruise. I think a couple of others, like Arnold Schwarzenegger, was one of them. It was creepy. And what I have to say here is.

Very well done. You can almost not tell this technology is getting so good. So anyway, my point in this is to ask you the question of what you can do to defend against this because, as fun, as it might be to see that kind of thing, it does have some, shall we say, nefarious applications?

Craig Peterson: [00:01:42] Yeah, big time. And we're already seen a few of these in this election cycle. I don't know if this is going to be an October surprise for one of the candidates. Defending against them gets very difficult. I do have to say, by the way, But it is more accessible to fake video or not, then it is to phony voice and the way they're doing it, some, someone has to say the words in the phrase and not have it all chopped up, but it does pose a considerable risk to all of us.

There's something called the deep fake detection challenge that's going on right now. They've got AI's artificial intelligence machines if you will. One of which is trying to create a deep fake. The other is trying to detect the deep fake made by the other device, and they go back and forth challenging them.

Then they also have people involved, more than 2200 teams, in trying to detect them. Today, they are pretty easy to detect, but if you know the technology, so I think the bottom line here, Matt, most people is if it is something that you just don't believe to be quite right. That you think this can't be right.

Do a little bit more research into it. Facebook and Twitter, and all of these other guys are working on how do they get rid of deep fakes and detect them. From a machine standpoint right now, it's easy to do, but be extra careful, because the best way to defend against these deep fakes is to hold people accountable that host to them.

So if you find something that you think is a deep phase, there is a report button there on Facebook, and on some of these other social media sites, report it. Then someone will start looking at it. Facebook this week just started having people reviewing some of these. YouTube, I shouldn't say, just had some people start examining videos again.

This year it's been almost entirely artificial intelligence, but we that see them and suspect it needs to report it so that these professionals can get involved.

Matt Gagnon: [00:04:05] I saw another one, I think that was done by maybe Smithsonian or the Nixon library or something too, where somebody had made, when the moon landing happened, Nixon had prepared both a great, it just went well, and I'm so proud of the Americans for landing on the moon. A speech and he also prepared a, and everything just was a disaster, which didn't work speech. And he never delivered the second one cause it worked okay, but they had deep faked that speech, the one he never gave, like onto, onto his, the face onto somebody who was doing it. And I got to tell you, it was, in a couple of spots, it was apparent, but for the most part, it was a creepily accurate. It is a technology that is only going to get more advanced. I would bet you money that voice angled things is probably going to get better as well.

And that's a scary prospect, as cool as this technology is, it's a frightening prospect in the future. It is,

Craig Peterson: [00:04:52] The bottom line is you have to get down to the individual pixels to have a chance of figuring it out.

Matt Gagnon: [00:04:57] Yeah, we're talking to Craig Peterson for our tech guru. He joins us on Wednesdays at this time.

Craig, the Chinese do a lot of really bad things on the internet, IP theft being one of them. and you believe that it's time for CEO's to stop enabling China to do this.

Craig Peterson: [00:05:12] Yeah. this is one of my political season rants.

Matt Gagnon: [00:05:15] That's fine. Hey, listen. It is the season, right?

Oh yeah, exactly. I'll be talking a lot more about this on Saturday at one of course, but it really is.

Craig Peterson: [00:05:27] It's time for CEO's to stop enabling China's theft. I don't know how many times I've said it, but I go into businesses every week and find that they have been hacked by China. Their intellectual property has been stolen in 2018 alone. The US trade representative found that Chinese theft of American intellectual property cost somewhere around four, 500, maybe as much as $600 billion dollars.

The FBI is right now investigating a thousand cases of Chinese intellectual property theft. Two of those are cases I'm involved in. People, we have to protect our IP. That means, an example, and I'll talk more about it this weekend. I've got two or three i'll talk about, but one is a guy I know and this was just two weeks ago.

I found out that he had designed a new system, he's an engineer, for controlling the air conditioning systems within a building and lighting systems and made it way more efficient and effective cut costs, and yet kept it comfortable for everybody. And he had worked on it for two years.

It was hardware and some software integration, and it would integrate with almost any HVAC system out there. the Chinese stole it. What he has now is nothing. They are manufacturing it in China. He is competing against his own while he wouldn't be competing against his own design, being sold for pennies on the dollar.

Because as we know, some of this stuff is made by slave labor. Either of it is made by people who just don't get it stayed much. So he spent two years of his life designing this map and it was stolen from him. Then I'll talk about a few more that I am personally involved with. I'll talk about two of these cases that I'm involved with.

The FBI is investigating, but the bottom line, we cannot sit back and allow them to our IP to be stolen. I'll try not to get a leg up on us and let us entrepreneurs whose businesses are our retirement package. To have our retirement stolen. I have our employees' jobs stolen and have us be in a terrible spot. We have got to wake up.

Matt Gagnon: [00:07:57] The Craig Peterson, our tech guru, joins us on Wednesdays at this time to go over the world of technology. Thank you, Craig. As always. We appreciate it. And we'll talk to you again next week.

Craig Peterson: [00:08:05] Hey, Take Care. Bye-Bye

Hard to believe. It's Wednesday already. Where does the time go here? Every week? Hey, we will be back on Saturday. Of course,

Thursday, we're going to start with one of these little lesson emails it's taken. It's a lot of time to get stuff together, and We're also taking Care of businesses with trouble that needs security help. And frankly, there's a lot of us out there. A lot of our companies that need help.

Anyhow, take care, guys. We'll be back on Saturday. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Steve Fourni who was sitting in for the vacationing Jim Polito. He had a few questions about computer security especially in light of the 129 Microsoft Vulnerabilities that were addressed on Patch Tuesday, I did get up on my soapbox for a bit, but Here we go with Steve.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, it's political season. I had to get on my soapbox. Okay. Little stump, speech, going on here, Craig Peterson. Of course this morning. I was on in Mass and south-central and Western mass as well as Southern Vermont and also from parts of Connecticut. So yeah, I guess we're expanding.

We're talking about serious computer issues. Steve Fourni was sitting in for Jim Pollito this morning and I like the way he was going with this and what he was thinking about. His train of thought is something that frankly, every business person needs to have. So here we go with Steve, his audio is a little bit low and I reported that over to iHeart because apparently it's going out okay on the terrestrial AM and FM stations, but it definitely not working so great on the iHeart stuff. So somebody turned a pot down. I think it's what happened. But anyway, here we go.

Steve Fourni: [00:01:00] All right. You know that music it's Craig Peterson our tech talk guru always giving us the information that we need. That is important. Now more than ever. We are all on that stinking computer now, and it is more important now than more than ever. Craig. Good morning. How are you, sir?

Hi, I'm doing well. You know If your computer is stinking you can wash it, but be careful.

Not with water while it's on I assume.

So let's start with Microsoft, who I handed in their term paper and he handed it back with 129 vulnerability mistakes and now it appears that they have corrected their work and turned it back in.

Craig Peterson: [00:01:34] Wow. Everybody, Pay attention to this one because this is a very big deal. Yes. We had patch Tuesday, 129 vulnerabilities in 15 Microsoft products is absolutely crazy. But here's the big news, very rarely here does Homeland security issue emergency warnings.

On Friday, the Department of Homeland security gave administrators, system administrators within the federal government until Monday to patch Windows. There is amongst all of these patches, the first patch for this came out last month, and another one's coming out.

Homeland security saying this is so absolutely critical you've got to get it done over the weekend. So that applies to all of us as well. It's called a zero log-on. This presents what they called an unacceptable risk because you don't even have to log on to the windows server in order to take control of the silly thing. Absolutely terrible. This is a flaw in Microsoft Windows net-log- on-remote protocol.

Many of our businesses, and Steve you've heard me talk about this before, we just don't understand how to do this stuff. We've gotten VPNs we are using windows net log on, it is not configured properly. Now it turns out that if you have not applied these most recent patches, you're in serious trouble.

Steve Fourni: [00:03:07] Yikes. So we're talking with Craig Peterson, our tech talk guru. Do you think Craig? It's a generic question, but do you think that most companies, are prepared for where we are in terms of the remote working, because you have, you have like your bosses who have other more important things to. Do you have your IT department who again, probably has more important things to do? Do you think they're in, on the whole, staffed enough to keep tabs on all this stuff?

Craig Peterson: [00:03:35] No, I don't. I really don't. This whole security thing is a very big deal, very hard for business businesses to do. When you get down to the raw number, businesses are concerned obviously about these business expenses. I think it can be looked at also as a plus to be able to tell your client, Hey, a big hug time here. We're keeping your data safe.

But until you have about 500 employees in your business, you are very unlikely to be able to afford the type of security that you need. So you get these businesses out there, small businesses, which is under 500 employees, considered by the SBA to be a small business. These small businesses who are there - I've got myself, somebody who used to be that and such, and now do you know, they really like computers and they are our computer expert and darn it, we've got SonicWall and we've got Norton, antivirus installed. We're all set.

It is not true. They have to, Steve, let go of those reins a little bit, outsource it to a managed security services provider.

I've got another article out there right now. The title is it's time for CEOs to stop enabling China's blatant intellectual property theft. They are absolutely right. We are not doing anywhere near enough. If you're on my email list, I'm starting these three-minute training, If you will, three-minute emails that are going to be going out, ultimately, here a couple of times a week to help CEOs, business owners, senior managers understand a little bit about what these problems are and if you're a home user, you're going to get stuff out of this as well. But this is a huge deal.

Then you get Jeff Bezos. You get the chairman of Microsoft, Sundar Pichai, and Tim Cook, who is the head of Apple. All in front of Congress denying firsthand knowledge of China stealing intellectual property. Mark Zuckerberg admitted that it was well-documented he's right. And I have seen it in the majority. Probably the vast majority. I'm thinking better than 90%. Me personally, 90% of the businesses that have called me and my team in, Steve, to have a look at their systems. Emails weird, something's slow. Can you have a look? They do a scan, do an analysis for us. And we did this for free about two years ago for a bunch of different businesses here, listeners to the radio show subscribers to the email list.

Almost every business out there has likely been penetrated by Chinese or Russian hackers. I have a guy, a friend, I know he's an engineer, hardware engineer, and he designed a business. for businesses, a system that took care of all of the HVAC, all of the heating and air conditioning ventilation in the building, pulled it all together into one piece of glass. One user interfaces and saved them a lot of money.

And turns out, guess what? It was stolen by China. And now he has all of that. It took them a couple of years to put it all together, tested, and make sure it was working all of that now. Is being stolen by China being made in China. And he has no way to make any money off of this because he just can't compete.

It's happening. We've got to pull up our socks, Steve, and it's political time. So I'm up on my soapbox here about this. It's a very big deal. Yeah,

Steve Fourni: [00:07:28] No doubt. We're talking with Craig Peterson, our tech talk guru. I know, Craig, we have other stuff to talk about, but on what you're talking about and those numbers are staggering. We're doing the whole TikTok thing back and forth. And I heard a clip yesterday from a guy who said, every time I mentioned the word fried chicken, I get ads for KFC. So they already have my information. I don't really care about TikTok. We talk about all these businesses that, basically, you're already vulnerable.

Are there actually businesses out there that are sitting there and saying to themselves, you know what, China's already got all our information they have no interest in Jimmy's pizza shop, whatever we'll just roll with it. Are there companies that think of the same way the kid with the fried chicken thinks?

Craig Peterson: [00:08:06] We have a customer right in Worcester, which is a pizza shop and yeah, they do need to be worried about it. Think about your employees. When you're talking about TikTok thinking about your employees coming into your business, using their phones. Yeah. They're on break they're on TikTok on their phones, they're using your Wi-Fi together. Now, all of a sudden, the bad guys have potential access to data that's on your network. Then you were talking earlier, Steve, about ransomware accounting for 41% of all cyber insurance claims. Yeah. That's a lot. How does ransomware work? Most of the time it gets in through phishing attacks.

P H I S H I N G. What does to get you to click on the link? Yeah, one more. There's an old reference. What do they need to get into you and get you to click on that link? It needs information about you. how about do they send an email that looks like it from a friend because they now know who your friends are because they have access to your TikTok friends and an email looks like it's from your friend?

It says, Hey, you got to this great new video that and so cause they know that you like you clicked on the link, that link. Now you've compromised all of the computers in the business by clicking on that link. That's why it matters.

That is absolutely why it matters. You're not wrong in saying that, the bad guys probably have pretty much everything about us. But what they want is really fresh stuff, really new stuff. To get to and trick you into doing something you shouldn't do.

When you're talking about ransomware accounting for 41% of all cyber insurance claims less than half of the claims, I've seen number saying as little as 10% are actually paid out because the insurance company comes in and says, are you following industry-standard practices? Let's have a look. And they do have a look.

That's what happened with the pizza shop right there in Worcester. They had a look and they found out that they weren't, that's why they called us in.

But even if you have insurance, cyber insurance, do you really you think that $10 a month rider is going to cover you for the loss of your business cause it got hacked? No, it will not. This is a big deal that people just aren't paying attention to.

Steve Fourni: [00:10:26] Wolf. When it's not one thing, it's something else. It's unbelievable. We're talking with Craig Peterson, our tech talk guru. Craig if people want to get to more information and again, the helpful tips and advice. I just think it's, important enough and especially again, to give it to us at a level we can actually absorb. Given it to us at a fourth-grade reading level, which we need sometimes. How can they get more information from you, Craig?

Craig Peterson: [00:10:46] Just go to Craig peterson.com/subscribe.

That'll get you on my newsletter list. Comes out once a week. That'll start getting you these little three minute emails. That'll help keep you up to date and help you understand this a little bit better. Just Craig peterson.com/subscribe.

Steve Fourni: [00:11:05] Good stuff. Craig. Thanks so much for the time. Good to catch up again and we'll talk soon.

Craig Peterson: [00:11:11] Bye-bye.

Steve Fourni: [00:11:12] Take care. Appreciate it. There goes Craig Peterson and, yeah, even I was yesterday, my wife and I finally decided where we signed up for one of those, delivery meal things. I mean I do most of the cooking. I just go to the grocery store every day and I get what I needed for dinner that night and I can't do that now.

So we decided to sign up for one of those things. Which I'd love but, as soon as I signed up, the minute I signed up, all my ads were for other meal delivery places, every single one. Even like I said, this happens all the time.

I'll buy concert tickets and then I'll get ad ads, get your tickets. Now, I already did. So there's that kind of stuff that just drives you nuts too. Well, that's enough complaining for today.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed a critical patch that was announced on Friday and is so dangerous that the Fed's gave their system administrators until today to get their servers patched up. Also, Microsoft announced 129 Critical patches on Tuesday -- Patch, Patch, Patch! Then we talked about some good economic news. Here we go with Jack.

These and more tech tips, news, and updates visit

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Hey, had a quick hit with Jack this morning up on New Hampshire today. We did talk a little bit about well, politics, really. What is going on with e-commerce and why did the federal government only give its own administrators 24 hours, basically to get this done? Zero log-on. Man, what a problem?

Jack Heath: [00:00:23] We appreciate it earlier. He yielded because of all the talk of the Supreme court, Craig Peterson, our tech talk guy with a quick moment or two on a tech talk point, or maybe tell us what his thoughts are when it comes to tech. Good morning.

Craig Peterson: [00:00:36] Hey, good morning, Jack. There is a huge warning that just came out.

It's unprecedented. This is from Homeland security. I've got to make sure that our listeners understand this. This came out Friday and they gave the federal government system administrators until today to patch windows, there is what's called a zero log-in vulnerability in windows servers. You can ask your tech people what that means, but bottom line check with them today. Make sure they know about this.

Microsoft released a hundred patches for 129 vulnerabilities, last Tuesday. This particular patch has been out now for about a month. Jack, we've got to make sure that people are patching and patching quickly. Get it done.

Some good news on the eCommerce retail front. They are expecting a thirty percent year over year increase in shopping online this year.

Black Friday might end up being truly a great day to go into the black for retailers again this year. Even with all of the people sitting at home, but maybe that's what spurred it in the first place.

Jack Heath: [00:01:48] Yeah. Who knows what that's going to look like? Right? From a retail online, you'd have to think the scales are online.

Craig Peterson: [00:01:55] Yes, they absolutely are. And they are seeing right now I'm looking at numbers showing some really big deals out there, but this is going to continue. The trend is expected to hit six and a half-trillion dollars here in about two more years, online sales. It's just growing dramatically and I think this whole COVID thing, shopping from home, really gave it a big kick in the pants.

We've got Walmart out there now just really going head to head with Amazon.

Jack Heath: [00:02:24] Oh, it's huge. I mean, you know, it used to be, you only heard about this during the holiday season, multiple packages on the porch. Take a walk in your neighborhood, the driving, the delivery people have been some of the busiest people of all time. Between Amazon, the post office, private deliverers. I mean, people will deliver packages to one resident sometimes it's like six times a day. That porch has packages. All right, Craig. Thank you.

Craig Peterson: [00:02:46] Take care.

This is an exciting week, but we are trying something new. We're going to be providing you with some training here, just real quick. I'm calling these our three-minute read and these there'll be emails. That'll be coming in your email box. If you already get my newsletter, you'll get my three-minute reads. It is going to help you out. So let me know what you think of these.

I had a lot of responses to over the weekend to our newsletter because we've got this new, Ask Craig column and people are asking. So that's really helping out with businesses and in a few people with some home issues. In fact, there was a big question. I am going to try and answer this week about home routers and some of the problems he's having.

So anyway, I'll keep an eye out, a big week this week, and Craig peterson.com/subscribe.

Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains why Hackers have found a new target that they love and why it might put you in jeopardy.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Welcome everybody. Hey, if you think that your IT being outsourced is going to somehow protect you from the bad guys. Unless they are a security service provider, I've got some news for you.

Hello everybody. Craig Peterson here. A welcome and glad you joined us here on news radio 98.5 And AM 560. I also want to remind everybody that you can find me online. You can listen to this as you are a hold of radio range, even just go ahead and. Ask your favorite platform, whether it's Google or Alexa to play, WGAN we'll give you some more or details a little bit later on in the show today, but let's start with our top story of the day today.

That has to do with managed IT providers. Now, a lot of businesses are trying to do the whole information technology thing themselves. You've probably heard different ads. In fact, there's one group that advertises frequently here on WGAN, and this is kind of a big deal when you get right down to it. Are you better off taking care of your IT yourself? Or are you better off having someone else do it?

Then when you really dig into it, the bigger question I think is, does it make sense to just use a regular IT company to outsource everything? Or should you again have specialties? No, it's like you've got a department inside your business that might do the finance stuff. You've got another department that obviously handles IT. You got sales, you got marketing. They're all fine-tuned. It is very difficult to find a third party that's fine-tuned, if you will, to cover everything that you might need from an IT side.

Well, we have been finding out some very interesting numbers lately. There's a great article I have up on my website from DarkReading. That's talking about this.

Basically, most of these MSPs or managed IT providers managed services providers. Have become a major gateway for the bad guys to break into small and medium businesses. I mean major gateway.

We've seen this ourselves just as recently as last week. We've been working with some managed service providers now to provide them with managed service security services because it's impossible for them to do the best job.

I just saw a mailing I got today from a company called SonicWall. They make firewalls, which are just fine for businesses that aren't heavily regulated, but they do not meet the requirements for more heavily regulated businesses. SonicWall's out there sending out these mailings saying, We've got it all. All you need is us.

That also reminds me of a mailing I got from Microsoft and I saved it. I just could not believe this. This must have been 20 years ago now maybe a little longer, actually, when I think of it, we're saying, Hey, listen, security is a real problem, but if you have Windows XP and Microsoft office, rest assured that your security is virtually guaranteed. I shook my head at that, decades ago in this sort of stuff still happening today. So many companies are out there lying and misrepresenting.

Now. I get it, you guys, this is not your forte. It's not the forte, cybersecurity of most managed services providers. Frankly, I think the vast majority of these companies that are trying to help you out with the IT, just don't realize what they should be doing and what's required of you, right?

You go to them because they are the experts. They tell you what you need, right. Isn't that the reason to write the checks. I've found the same thing being true inside a lot of companies where you have your own IT people and those IT people are trying to keep things straight.

And man, I've been working on this cybersecurity quiz thing. What are the main activators behind cybersecurity and where are you at? It's a self-evaluation thing that you can do as a business. Right now I've got the technical ones all done, and I'm working on one for the business owner C-level to understand where they're at and where they might need to go with it.

For years, cybersecurity has really been the area that big businesses, enterprises, what we used to call them here. And the enterprise was like a big business, a publicly-traded company. Nowadays we're adopting more of the European definition of enterprise, which is any business out there, but cybersecurity is been really the area that large businesses don't have to worry about.

What the bad guys have found that small and midsize businesses have also been the target of attacks, but historically those attacks have been the broad-based phishing attacks, or they're trying to run a worm around the internet. It's just a target of opportunity. From small business and medium business standpoint, the number of times they might be hacked or the damages caused were probably reasonable, you could get insurance for it.

But that has all changed now. The insurance companies and we've talked about a couple of these on the show before, are not paying out the policies. If you have a cyber insurance rider, for instance, as a regular end user, just a home user, many home policies now come with a cyber insurance rider. So if your identity is stolen, they will help you to recover the damage that was done, right. You can never really recover identity. You're not going to get it. Back. It's not gonna all of a sudden become safe, but they all help you with the damage. So anything that was bought in your name it'll, they'll back it out, any bad credit report backs them out. The same thing was available for the small, medium, and, even the large business markets where you pay a rider, and then if you do get attacked then okay, the insurance will pay for it.

When you look at the numbers, I think you might come to a different realization. Where right now about a year, a quarter of all businesses are hacked per year. There is some security event that occurs in about a quarter of all, all businesses. That's a lot. What was the fee for your premium as a small business? Was that fee just an add on, an extra 25 bucks a year, a quarter a month, whatever is, I, I know biggie. Well, what's happened is the insurance companies have realized that they can put requirements on you. That's one of the things we do. We have special scanning software that allows us to scan a network and look for standard insurance requirements. You know, the stuff the insurance companies usually want. No, we're not the only ones, I'm not the lone ranger out here.

There are other companies that have these tools. There are some free checklists you can find online. I would encourage you to use them. Nowadays, if your information is stolen, if you are hacked, they're going to go through that list and say, did you comply with this? Did you comply with that? Did you comply with the other thing? If not, they're going to fight you.

That's true for the mega-breaches like Equifax has been fighting their insurance company in the courts. We've seen everything all the way down to little companies that are fighting it in the courts. Then on top of it, not only is a cyber insurance stuff, a threat, and a problem. It goes to the next level. And the next level, when it comes to all of this is. Is your business going to survive?

You got hacked and you have to fight with the insurance company. If the regulators find out, if your business is regulated, which nowadays is pretty much every business out there, what is it 300 million? Oh, it, you won't get into that right now. All of the people here in the US plus the businesses and all of the hundreds of thousands of regulations anyways.

What's going to happen when the regulators find out you were hacked? That's when the real problems come up. The regulators are going to come in and there is a checklist, whether it's a NIST checklist, the CMMC, the HIPAA/HITECH, whatever it is, you are going to be held responsible.

So. What are the bad guys found? It's kind of like going back to the Willie Sutton misquote, right? Which is why did he Rob banks all that's where the money was. Turns out that isn't a legitimate quote, but you know, that's okay. He, he robbed the banks or bank robbers, Rob banks, because they keep cash there. They keep gold. They keep silver, back in the day. So they'd go in and Rob them.

Well, where are all of the keys to the kingdom when it comes to your computers? Well, they live in the IT department. Don't they, IT can get on, can give you access to stuff. They can take away access from staff, right? That's what it does. And they can be pissed off and leave your employ. If they leave your employment, what happens? Do you have automated systems that remove access for the IT people?

Cybercriminals have now figured out that these low-end small businesses that are out there calling themselves managed services providers, managed IT providers are a great way. If they break into one of those, we've seen major security holes for the tools almost all of these companies are using. If they break into one, those, they now have the keys to the kingdom for 50-100 companies out there. So be very, very, very careful.

Cybercriminals understand the average managed services provider cannot keep your data safe internally inside their own networks or in yours. So just like that Pandora's box is open.

Hey, you're listening to Craig Peterson. If you're going to hop in the car, the truck, and drive, hopefully, you've got Siri with you, maybe Google, maybe Alexa can listen to us there.

Just say, Hey, Alexa, play WGAN stick around. Cause we'll be right back.

You're listening to Craig Peterson.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig puts into perspective cybersecurity spending and how much you should be looking to spend based on certain criteria.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] This talk of MSP outsourced IT providers. Brings up a really great question. How much should you be spending on security in a business or at home?

Hey, you're listening to Craig Peterson here on WGAN 98.5 FM and AM 560. You can also hear me every Wednesday morning with Mr. Matt Gagnon and, he and I always talk about the latest in the news. Sometimes he surprises me as well with questions out of left-field. it's fun chatting with him, bright guy, and he knows enough about technology, but he hasn't stumped me yet.

If you wanna follow me, by all means, make sure you get my emails. We've got some new training. That's started this week that's coming out. I have these three-minute emails. That I'm sending out and we'll be doing more of those. So if you miss the first one, make sure you sign up Craig peterson.com/subscribe.

Now IT is a problem for most businesses, but I've got to point out something that many people haven't really thought through that is in fact, every business nowadays, is it computer business bar none. Because every business nowadays has computers at its core. I look at it and say, I doubt very many businesses, frankly, almost if any, are spending enough money on IT.

If they're paying enough attention to it. We still walk into businesses that don't have the proper licenses for the software they're using. They don't have the proper licenses for some of the cloud services they're using. They're not complying with regulations. They get a letter from one of their customers saying, we need to make sure you complying with this, that, and the other thing and they pull out the pencil and pencil whip the form. They just check yes, yes, yes, yes, and they may or may not even know what that form is talking about. Let alone, if they really are compliant. So it's a big deal. It's very concerning.

Now in this world where more and more people are working from home, some of these figures have changed. So I think it's important to talk about it.

Now on the very low end, if you are a home user, I strongly advise you to use prosumer technology, make sure your firewall and your router automatically updates, make sure that it automatically uses something like Umbrella for DNS that blocks DNS requests that might be going to bad sites that are out there, so that it's all taken care of for you automatically.

Make sure you're using Wi-Fi that has multiple networks. So that network has split up so that the devices aren't talking into each other. We've got, clients that are really all over the Northeast United States, that are using prosumer gear in very small businesses, and in many cases, that's okay.

It really depends and when we'd have to talk to really get into it, but basically, if you have a credit card machine on your network, it needs to be separated from the computers, the rest of the machines on your network. You need to segment. Even in my home network, I have my network segmented because again, Many of us are working from home. I work from home, so I have separate networks.

One is for guests that come over, it's completely separate. It has no access to anything else in my home network. I have a network for my business at the house. In fact, I have three, I think it is networks for the business at the house. I've got that all segmented. Again, if you are just a regular consumer, you're a retiree or you are working and doing some work from home. These pieces of prosumer hardware are what are going to get your network split up in such a way that the bad guys cannot move laterally and get into computers that they shouldn't be getting into.

So think about it for instance. If you have one of these Google or Amazon devices. If you have one of these Nest thermostats or Ring doorbells. None of those should be on the same network as your computers in your house. None of them. They're all considered what we call the internet of things. And as such, they probably are not getting updates. They are probably not being monitored from a security standpoint. The way they really should be monitored and that's going to cause nothing but problems for you. Frankly.

We've seen that before in small businesses where they've got everything on one network. They've got security cameras and there are these cheap ones that came in from China. As an example of some of those are like Hikvision, which cannot be used now in DOD contracted facilities. Those types of devices that never get updates. Some of them have built-in back doors and now they're on your network. They break into your cash registers, your point of sale equipment, et cetera, or in your home, they get onto your computer.

Now, how many of you guys have your account information on your computer? I know my dad. Keeps it still to this day on a spreadsheet, all of his bank accounts, all of his passwords, his usernames. If he has something on his network that gets compromised, he can lose all of that and they can break-in. In fact, that's already happened to him and we had to come in after the fact and do a little bit of cleanup and investigative work. So dad got it for free, but he also got nailed, which is really bad.

How much should you be spending? If again, the very low end, super small business with no regulation or a home user, you should be expecting to spend five to $600 on prosumer hardware. And then companies like mine. We have a thousand dollar package where we make sure it's the right stuff. We pre-configure it, we test it, we ship it out and we support you. Okay. So let's say a grand on the high side.

Now, if you start moving up and you have some regulations, so let's say you're a small doctor's office. So you have some HIPAA requirements or you're a business that has employees. So you have HIPAA requirements, but you don't have the real tough ones that come with the department of defense contractors. Then you should be spending. Oh, I'm just going to give the, basically a cash price here. You should be spending about $3,000 on your hardware.

This is just your network stuff. Your firewall that can examine stuff tear apart packets and reassemble them, look at everything in context and just do it all. One of these next-gen firewalls has intrusion detection, intrusion prevention built right in there. Really nice.

Then if you are a larger business that has real requirements, such as DOD requirement you're in the 50 to $150,000 range. On top of that, you're gonna have to spend monthly money as well. To have someone watch it and monitor it.

Now, the Gartner Group has reported that the average spending on cybersecurity was it's about five to 8% of the overall technology budgets in most businesses. But in reality that it should be closer to 20% to 25% of the IT budget.

Now, this is for bigger businesses that were the IT budget includes programmers and everything else. So how much is enough? there's no real magic dollar amount, but the number is definitely not zero. I think I gave you a few little ideas here of what you can look at.

You've got to be careful. You've got to pay attention. The big number is until you reach 500 employees, most businesses cannot afford to have internally the type of cybersecurity teams that they need. Yes, teams. So under 500 employees, it's cheaper to find a managed security services provider.

Depending, again, if you're on the DOD side, all in you should be spending about $320 per month per employee, and that'll get you all the cybersecurity you should need. You're not going to need employees worried about cybersecurity and trying to keep up on it. There are some real rough numbers out there. $50 a month, all the way up through 350 at the high end. There are your numbers.

All right. You listening to Craig Peterson here on WGAN stick around because we'll be right back talking about EMPs.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses Electromagnetic Pulse as it relates to the DHS warning that China might be planning something around our election. What would it mean? How would we deal with it?

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] If you're not familiar with the Carrington event, stick around because the odds are great we're going to have to live through another one of these. Even though it's been more than a hundred years, we're going to talk about EMP attacks and a real warning about it.

Hi everybody. Craig Peterson here. Thanks for listening.

Hey, if you have your Google smart speaker, Google Home, just say, Hey, Google play. WGAN and you can listen to us any time. I probably just turned on your Google speakers. Sorry about that. But it is really handy. That's what I use when I'm up in the shower, et cetera, these smart devices.

Now let's get into this. Very interesting article that just came out this week from Zero Hedge. Tyler Durden is the one that brought this up. We have in fact been given some really great information about this as part of the FBI's InfraGard program.

Now, if you are responsible for IT and more particularly responsible for security, you really should join the FBI's Infragard program. I N F R A G A R D.org is where you'll find them online. This is a channel that the FBI uses to let civilians, as well as military contractors and frankly, even various government employees of the federal and state level. It lets them disseminate all of this type of information.

It's absolutely fascinating. Some of them, the stuff I can share with you, some of the stuff is on a need to know basis. Obviously I can't share all of it with you, but I do try and bring some of these things up like this one.

The US Department of Homeland security has released a new report that's warning about a potential electromagnetic pulse. Now, specifically, this is talking about an electromagnetic pulse as part of an attack against the United States. I mentioned at the very beginning, something called the Carrington event. It's fascinating and this is something that we've talked about on the training for the FBI's InfraGard program that I conducted and you probably know I did that for a couple of years. It's a volunteer position and I did a whole bunch of different pieces of training.

This particular event occurred in September 1859. Now think back to 1859, there was not much going on from the electrical side, 1859. They didn't have too many computers, right? Obviously they didn't have any of them, but back then they did have a couple of things they did have Telegraph for one. What they found happened was that these Telegraph machines were getting burned out by this event. They weren't quite sure what it was, what was going on. They even had Telegraph operators that were injured from it.

There is something called a solar coronal mass ejection. This is a sunspot back in 1859, for those of us, like I ham, you know that right? I have an advanced class ham license. Yeah, totally. Am I funny? But I have a license from the federal communications commission. This is called solar cycle number 10, which one from 1855 to 1867 and us hams keep close tabs on the solar cycles because they affected the weather. They affect the temperature on earth and solar cycles also affect the propagation of radio waves. Why do they affect it? It's because these ejections from the sun come, they hit the Earth's atmosphere and they charge it.

If you've ever seen the Northern lights, that's an example of solar radiation hitting our Earth's atmosphere for lack of a better term. It's really hitting our Magnetosphere, but I don't want to get too detailed here.

This is very fascinating because back then they called it a white light flare. That is a British astronomer Richard Carrington, as well as co-astronomer here, Richard Hodson. It was named after Carrington though. It basically burned out telegraph systems.

Now you think about a mass ejection from the sun. Think about it being very kind of limited in scope, right? How big is it? You probably have seen pictures, videos of these injections coming up from the sun's surface. Well, what ends up happening is our entire earth's upper atmosphere and the Magnetosphere ends up getting charged by these. So it doesn't just affect one area. Like it's aimed like a, like a laser beam down in Missouri and hits the center of the country and that's the only problem.

Now what happens here is that will affect us worldwide. It will affect some areas more than others, certainly. But it'll affect us worldwide. It will knock out our satellites that are up there right now. It will cause blackouts. We saw that already some extended outages of the electrical grid here in the Northeast. This particular storm I'm thinking of was when was that? I think it might've been 84, the storm up in Quebec that knocked out the power to the province of Quebec from a solar storm.

So we could be in a whole lot of trouble. It could also damage all of our, or some of our major transformers. We do not keep those in inventory. These kinds of super transformers, if you will, there's a number of them located across the country. And knock out grids across the country. It could take from many months to years to get back all of our electrical infrastructures depending on what happens.

Here's what Homeland security is also worried about. It. Isn't just a solar flare and they are worried about that and I can tell you, I have had people on the webinars. I ran for the FBI that are telling us that indeed they have been working with the power companies, et cetera, to put in some controls, it would stop the problems from one of these coronal mass ejections these solar flares. So we're pretty much already set for those or we will be within the next couple of years.

What we're worried about is what the Chinese I've been up to. Apparently the Chinese government has been working for the last 25 years on plans to defeat the United States and kind of their lead plan appears to be an EMP.

Basically what they're looking at is a cyber Pearl Harbor attack and they've been looking at that because it's easy to do. All they have to do is set off a nuclear bomb up in the atmosphere above the United State s and it could cover the US coast to coast 1500 miles. If it was set off at 300 miles above the surface of the earth and conditions were right. Could be very, very bad.

We ve gotta be careful. China has been exploiting some of our weaknesses. I remember 2004, you might remember the power grid outage, we had up here in the Northeast and it started up in upstate New York and various rumors about it actually, surely having been an attack attempt. Just kind of testing things out and it went awry.

There are other reports so that things happen and hard to say, but we do know. That China, Russia, North Korea, Iran, as well as international terrorists have hacked some of our key infrastructures out there. Something like this could be very, very bad there. DHS Homeland security is field testing, a more resilient, critical infrastructure, which is really good. They've got a number of demonstration and pilot projects planned and others underway. So, we'll see what happens here with the EMP vulnerabilities that we have. President Trump back in 2019, signed in an executive order that is really trying to speed things up here. They delegated power to the White House for EMP preparedness.

Hey, stick around. We'll be right back. And we're going to be talking about the 2020 election interference and what is the US doing here when it comes to Russia?

You're listening to Craig Peterson online, as well as on news radio 98.5 FM and AM 560.

Stick around, because we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains Nation-state Election interference and what is more likely just spreading Chaos and distrust.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Of course, we talk a lot about Russian hackers, Chinese. Iranian, and it goes on and on North Korean, we're going to talk right now about our elections. 2020 a very big year. What's Russia up to, and what's the US doing about it.

You're listening to Craig Peterson here on News Radio 98.5FM and AM 560.

You can also listen to me online. If you have a smart speaker, let's say you have an Amazon. You can just say, Hey Alexa, play WGAN. And Tada it'll happen automatically. You can even program your smart speaker to turn it on automatically. So you can listen to Matt Gagnon every morning, Monday through Friday, that is as a, he gives you the latest news and keeps everybody up to date.

So let's get into these US sanctions here, man, against the Russian hackers. We now know what happened in the 2016 election. In the 2016 election. You might remember. We had emails stolen from the DNC, the Democrat national committee. In fact, it's known as the DNC email leak. These are emails that were stolen by some hackers running under the pseudonym of Guccifer 2.0, and it's been alleged that the Russian. Intelligence agency hackers, according to indictments carried out by the Mueller investigation. Some of the very few minutes, they cost us tens of millions of dollars with all Mueller investigation.

Nowadays, the thinking is actually more along the lines of China. It was China that might have done those DNC hacks. China also hacked our national HR department for federal employees, where we lost all of these federal employee records, including background checks for people who had Secret, top-secret clearance, et cetera. Just terrible stuff. Our government has not been keeping good tabs on our information in many cases.

So now we're looking at 2020, I don't know, in my lifetime, if there has been a more contentious election cycle, in the sixties, you certainly had some bad ones. 1968 was a rough year. For our country, rough year. In fact, for many countries back in 68 out on the West coast. it really was a bad time.

A lot of people had a lot of the same sentiments that they have today. Well, many of those same people are now in government offices, elected offices, et cetera. They still seem to have some of the same thoughts and they are causing as much disruption as they possibly can. But at least those people are Americans, right?

You can criticize the news, media, or Facebook for not properly censoring things or not reporting on the story, the whole story, and nothing but the story. Many of these news outlets now tend to be editorial outlets.

Whereas right here, when you listening to me or anyone else on the stations you are getting, I think the truth. Obviously, when it's editorial, it's obviously editorial, but they're not running headlines.

Like this last week. I was just shocked and amazed. President Trump has these countries over these Arab countries over in the middle East signing peace agreements with Israel. What is the headline that CNN runs? That the white house has a mass of people out front that are not social distancing and not wearing masks. These were people who came to the White House who were invited for some of these signing ceremonies. There were representatives there from Israel, from these Arab countries. Did they bother mentioning that? Was that their headline? No, it wasn't their headline. There was a lack of social media, just unseen was their headline.

How's that news. I just don't get it. So very contentious and now we're hearing people like Hillary Clinton, secretary of state, former secretary of state saying, it doesn't matter whether Joe Biden wins or not, he cannot, should not, will not concede the race even if trump wins clearly.

Really? I thought you said Trump, wasn't going to leave Office. Here you are calling for people not to leave Office. It couldn't be more contentious. It's absolutely insane. What's going on right now. Some people. Really dislike our president. it's absolutely nuts.

So what are the foreign countries going to do? Because I, frankly, I don't know. I don't think most foreign countries hate President Trump as much as some people in our country hate President Trump. I'm not just saying, Democrats. I know there are many Republicans that really hate President Trump. And I don't like using that word because hate is such a strong word. But these foreign countries are going to do whatever they can to really mess things up.

Now in 2016, Russia kind of mess themselves up. They were promoting Hillary Clinton in some ads or. Promoting president Trump in some ads. In fact, the numbers I saw showed that they spent more money promoting Hillary Clinton and her becoming President on Facebook than they spent money promoting Donald Trump. So I don't know how the Russians helped President Trump. They were actually helping Hillary more. And then to top it off, the Russians were spending money on ads and running ads after the election, it occurred. So they really messed it up. Don't expect them to mess it up as badly this time.

The US Department of the treasury's office of foreign assets control has sanctioned for Russia linked individuals for their efforts to interfere with the 2020 presidential election. So this came out of, or at least it was aligned with Microsoft. Microsoft had published some details on groups that were targeting both campaigns coming out of Russia. The campaigns are out of Russia. Both the Democrat and the Republican campaigns were both being attacked and Microsoft noticed it.

Now don't expect Microsoft to notice that your company is being attacked. I want to emphasize that. Microsoft, if you have office 365, doesn't have any guarantees of security. In fact, their anti-spam measures are actually pretty poor and to get into much higher levels.

We tend to run our customer's emails through as special anti-spam anti-malware filters that we have from Cisco and then we send that email off to Microsoft. Even though they have the enterprise, higher-level enterprise accounts.

So one of these people that was sanctioned is a member of the Ukrainian parliament has been an active Russian agent for over a decade and apparently is close to Russian intelligence. He is a coordinator coordinated. This indictment here directly or indirectly engaged in sponsoring concealed or otherwise been complicit in foreign meddling in the 2020 election.

The Treasury's alleging that between May and July, this year, he ran an influence campaign focused on creating narratives around us officials in the upcoming election. He released edited audio tapes as well as other unsupported information with the goal of discrediting US officials and spreading false allegations against the US and international political figures.

This is from an article over at dark reading, you'll find up on my website @craigpeterson.com and apparently these narratives were designed to get some corruption investigations going. Like the fake Russian dossier that got investigations going against the Trump campaign under the Obama administration, which has now been proven, fake, including all of the testimonies that the chairman Schiffs committee reviewed. But now that they've been released, we can see what was true and of course, chairman Schiff out just saying the exact opposite of the testimony that was given to him in committee closed-door committees. They were in a skiff, but anyways. So they were using press conference coverage, other news events, interviews, and statements as well.

Now I have some software that if you listen to my podcast, for instance, and you can find it on most major podcasting platforms. But if you listened to my podcast, you might've noticed that last week I used an artificial intelligence program to first of all have a female narrator say about four or five words in one spot.

And then also I used one to change some of the words I was saying, I did not get a single email from anybody. I don't know that of the hundreds or thousands of people that listened to the podcast. How many people picked up on that? Because no one said anything. So your host, me, Craig Peterson, has been inserting some of this fake technology that allows me to pretend I said something that didn't actually say.

So think of what the Russians or any of these other countries have available to them. Going forward this is going to be very concerning to me cause you're not going to know what's real, what's fake. I think it was Hillary Clinton's campaign that coined the term fake news and then President Trump's campaign picked it up. Of course, he's been screaming, fake news forever. Secretary Clinton lost control of the fake news narrative.

There's one thing when it's fake news because they're not giving you the whole story or they're not giving you the story in context. It's a completely different thing when the fake news is quite literally fake.

And if you want to go online, go to youtube.com and search for fake and then Mark Zuckerberg. There's one for him out there. Bill Gates, fake bill Gates. And you'll see, not just video with the audio behind it. Where he's saying something he never said, but you'll see. It looks like a video of him saying something he never said. It's absolutely amazing.

I can bet the Russians are going to be involved in that. And in fact, that is part of the sanctions against these Russian attackers. They are meddling. And their, meddling with our news media, who seems very hungry for anything that might be salacious.

Hey, if you missed anything today, make sure you check it out online@craigpeterson.com.

We talked about how managed IT providers are a major security threat, what you shouldn't be spending on cybersecurity, a home or a business and DHS, Homeland security warning about an electromagnetic attack potential here as well as natural causes. That sun thing that's up in the sky.

You're listening. Craig Peterson on news radio 98.5 FM and AM 560 stick around because we'll be right back after the top of the hour.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains Why you should be concerned about your private health information when using a Telehealth application.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Coming up in this hour, we're going to be talking about some of these cyber risks that are really exploded because of the telehealth services. We'll tell you about that. And online voting. Price gouging and defective products rampant on Amazon.

Hey, listening to Craig Peterson on news radio 98.5 FM and AM 560. Want to remind everybody, if you have one of those smart speakers, All you have to do is ask it to play WGAN, and you'll catch me right there on your smart device, as well as everybody else. All the other great programming that we have here.

Let's get right into it. And I talked, at least I wanted to talk a little bit about this with Matt Gagnon on Wednesday morning, where I am every Wednesday at about seven 34. And this has to do with, of course, the whole COVID thing.

So many of us now are afraid to go out. We're afraid to go to the doctors. There's been some interesting statistics looking at some of the hospitals who are saying, Whoa, wait a minute. Heart attack patients. We're just not seeing the number of heart attack patients what's going on, is COVID making people his heart's function better. Having fewer heart attacks. What is it? When they delved into it, what they were finding is that there were people still having heart attacks, probably at about the same rate as always. And of course, we know that certain people have a response to the COVID-19 part of the Wuhan virus that includes death damage to cardiac tissue.

So how could it be? What's going on? They were just afraid to go to the hospital. So many of us are free to go out. So many of us are afraid to go to the hospitals, even when we're sick.

So first off everybody, I know I say all of the time, the hospital, is the worst place to be when you're sick? Because it is. There are diseases you can catch there that you just can't catch anywhere else. But the hospital also has the ability to save your life. They can go in, they can look at problems. They can fix problems. Maybe you need an adjustment as simple as your diet, but maybe what you need is some surgeries, stint who knows what you might need. So don't put off going to the hospital.

Now, when it comes to the doctor's office, you women out there know that men don't like to go to the doctor. We never go, I don't need to go. And once our arms and twisted enough, sometimes we will go. But now you're no one, you're just not going to the doctor.

Most of the time. I do know some people that do go to the doctor all of the time, maybe more than they probably should. And I probably fall into the category of, I don't go as often as maybe I should, but we're now doing these doctor visits online. I'm not sure that's the best idea. It's also not the worst idea, but we've seen this massive adoption of people using apps on their phones and on their computers to talk to a doctor most of the time, not even their doctor.

Depending on what kind of consultation you need. You can get a doctor for 40 bucks all the way on up through I, when I looked last, it was like $150 for a bit more of a specialist and they can only prescribe certain things. They can't prescribe other things and goes back and forth.

But what we have seen that's definitive. When it comes to these remote docs is that there has been an increase in the risks and compromises within the healthcare industry. There's a new piece of research out. I have it up on my website and it was posted here on Dark Reading as well, this last week by security scorecard, Dark Owl. And they found that the rapid onboarding of these technologies that we've been talking about on the show forever, right? Zoom. Don't use Zoom. Zoom's, not safe, right? It's not credible. It hasn't been analyzed. It's not HIPAA compliant, et cetera.

So the rapid onboarding of all of this stuff has not only hurt businesses who have lost information. Zoom is trying to pull up its socks here, as far as security goes. Also true in the medical field where they've started using them now to really let them talk to you. Deliver services to a minor degree. They can call in a prescription for instance, to a pharmacy for you.

It is significantly broadened this attack surface of many of the healthcare organizations out there. When we're talking about our broad attack surface. What we mean is instead of just having to break into one computer at one location, they actually going to have to break in, or at least have the opportunity to break-in at a whole bunch of locations.

That means your home. They could come in through your home computer. Potentially, in fact, a remote computer that you're connected to, depending on how you're connected.

We're also now as a doctor exposing your home computer, maybe your office, this network to hackers because now you're on your home network. You are using a VPN into the office so you can look at your patient record, so you can add things onto your patient tracking system and your electronic medical records.

Those EMR systems might be in your office and might be online but now you're using them from computers that aren't very well protected. That's part of the reason I keep reminding everybody that your home networks need to be just as protected as those networks that are at the office. So if you are a doctor and you have HIPAA regulations while. Any of the computers you're using as part of your doctor's office need to so comply with the HIPAA regulations.

If you are a government contractor subcontractor, you're going to have to make sure that the computers are CMMC or maybe they meet the NIST standards, et cetera.

So security card and dark owl analyzed the data related to the use of telehealth, these remote doc programs here from 148 vendors. They looked at healthcare providers around the country, as they're looking at it. Now we have seen a massive change in the way we do business. There's no question that we've really seen a business reboot here.

We've seen some serious problems. I was on a call earlier this week, part of, one of my masterminds. One of the members of the mastermind has a business that provides some marketing services for gyms, gymnasiums. When was the last time you went to a gym? They are struggling. He's wondering why his marketing, isn't working anymore? I thought the answer to that was pretty darn obvious. People just aren't using gyms anymore.

But the same thing's true with office space. Saw an article this week that I did not include because I didn't think it reached that level, but it was talking about a business that paid $60 million to buy it's way out of a contract for leasing space. We're going to be seeing more and more of that as time goes on.

Now a lot of it, frankly, and the same, thing are going to be true for, I think doctors and doctor's offices, because when you're looking at it, if the doctor is using Tele-docs. Why do they need to have as much physical office spaces as they used to have?

So prior to the pandemic, these Teladoc services were in news by about 1% of the overall. Health care provider visits, if you will. Is it a visit really when you're on one of these Teladoc apps, but it was used less than 1% of the time. Now we've got this big blown up public health emergency due to them and it has resulted in primary care visits, dropping like a rock after mid-March that's a surprise. At the same time, the Teladoc apps soared 350%. That is absolutely huge. That's from a report that I'm looking at here from the US department of health and human services.

Now what really concerns me about all that, isn't, that we're going online. I'm concerned about these docs using insecure apps, like Zoom. I'm concerned about docs using VPNs incorrectly, like every other business out there that are not using them correctly. The speed that they transitioned, businesses and doctors, and in this case, here to these online health services, has really not let healthcare providers properly vet any of these teledoc products for security issues or to ensure they're safe to use. I absolutely agree with that. That's the conclusion that Security Scorecard came to as well.

So here's a quote from. The chief R and D officer over at Security Scorecard, we examined the 148 most popular telehealth apps from a number of angles. There are concerns across the board from the development deployment and configuration of the app, patients themselves, as well as a digital supply chain that supports them.

So think about that for a minute, right? These apps themselves are not written properly. They're not implemented properly. The docs have not installed them properly and are not using them properly. What could possibly go wrong?

Now? I know some of you are out there saying right now, Hey, Craig, it's my medical record. So I really don't care that people know I have type one diabetes or whatever your condition might be.

In reality. A lot of people want to know that information, right? So for instance, let's say a scammer knows that you're a type one diabetic. They can now use that to fine-tune yes, the messages to you these phishing messages they've been sending out.

So be very careful, a lot of different alerts, a lot of, by the way, increase chatter out on the dark web. So keep an eye out for that two mentions of telehealth vendors, products like Teladoc, Careclicks, MeMD jumped dramatically on the dark web after the pandemic began. No big surprise there,.

All right. Stick around. When we come back, we're going to talk about online voting and we're going to compare a little bit to banking. You can do banking online. Why can't I vote online? What's going on here?

Hey, stick around. You're listening to the Craig Peterson show here on WGAN.

We'll be right back with a whole lot more and make sure you tune in as well on Wednesday mornings. You can, of course, hear me at about seven 30 with Mr. Matt Gagnon as he goes through some of the news of the week.

So we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains Voting secrecy and privacy and why online-voting is not ready for prime time and how Mail-in voting is ripe for fraud.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're about to talk about online voting. I know you've heard a lot about the Mail-in voting, right? Both sides of that, as well as the regular voting booths and stuff. But we're going to talk about on-line.

Hey, of course, you're listening to Craig Peterson here on news radio 98.5 AM and AM 560 thanks for joining us today. Make sure you join me on Wednesday mornings as well. With Mr. Matt Gagnon in fact, you can listen to him every morning, Monday to Friday, as he covers all the latest in news here throughout the country, as well as right here in Maine. It's about the only place you can get. The good UpToDate news for Maine is right here. So I'm so glad you have decided to spend a little time with me here on Saturday afternoon.

We're worried about our elections this year and I think for very good reason. Frankly, I'm not that worried about the Russians or the Chinese, because they could certainly sway votes, but how many they're going to sway?

I am worried about some of these big tech companies. I'm very worried about Google. I saw a study that was done on Google, comparing elections here over the last two presidential cycles and how Google seems to have been manipulating the results. We know right now, Google. Is blocking certain conservative speech.

There was a great article that came up this week, that I don't think I shared it with most people. I did send it out to a few people. It might be of interest to most of you on the list, but the article was talking about how conservative media if you can believe this right, conservative media is dominating the social media sites right now.

And we're seeing out of the top 10 pages over on Facebook are on the conservative slash liberal, but classic, liberal side libertarian side of things. So you've got people that are right up on the top, and I'm glad to see that Facebook's top 10 is devoted to calculating who's on which Facebook page.

How many people are talking, what kind of engagement is there? But I'm looking right now of Franklin Graham, Donald Trump, 2020 voters, Ben Shapiro twice. He must have two pages. David Harris, Fox News, Sarah Pailin, Ben Shapiro.

I know Dan Bongino pops in there and some of the others as well. So there is a lot going on in the online space that is conservative. People are talking about finally, some of the real issues that are out there. Not just, quoting the socialist mantras that we've been hearing for. so long. Not that I have an opinion on the matter, frankly.

Let's talk about what's happening with the elections here from the computer side because I was asked by Matt this past Wednesday morning about online banking. Saying, how can we do online banking? Matt asked why can't we do online voting. That is actually a very good question and what it all boils down to frankly, is secrecy and privacy.

We count on our ballots being secret, no one can coerce us into voting a certain way. Now, maybe somebody can see, Oh, you took a blue card or a red card. That means you are a Democrat or Republican or whatever it might be. So they might go that far, but they don't know who you voted for.

Then in the general election, everybody gets the same card to vote with. They all get the same slate of candidates and then historically, anyways, you go into the voting booth. You close the curtain behind you, and now you spend a few minutes voting.

That is the reason why it's illegal in most jurisdictions for you to take a picture of your ballot. And people have complained about that. There've been court cases saying, Hey, this is my right to free speech look, guy. I voted for the XYZ candidate. The problem with that and the reason it's illegal is that you could be coerced. You might be taking that picture and someone can coerce you and say, you didn't vote for the right people. So I'm going to beat you. Shoot you. Bat you over the head. Burndown your business. The kind of things that demonstrators do. Not rioters, they're not rioters, the demonstrators do. Then you could also have somebody who's saying, okay, great. You voted the right way. Here's your pack of cigarettes, which has happened. A lot in major cities as they have people into the voting booth, or maybe there's some other method of payment, but that's all about secrecy. That's all about privacy.

The banks count on you and me reviewing our bank statements every once in a while, making sure that what we are saying that we are paying is right or it's wrong. The banks even realize that there is a lot of fraud and wast. Even in the system that they have with the checks and balances banks have, they're saying right now, according to the Nielsen report, that credit card fraud costs the world almost $28 billion in 2018. That's real money, that is fraud.

Now, remember that there are credit cards nowadays are coming with those chips in them, finally. I first actually saw them in use when I was over in Europe. It was really strange because everybody just stuck their card in. In Europe, not only have the smart card with the little chip on it, but they have a pin that you have to enter in. So you buy a beer for instance. You put your card in the reader, which they bring to you, they don't take your card away. Then you put it into the reader and you punch in your pin and now it's paid for, and the bank knows that shoe. They saved themselves some money because they, it wasn't just taken into the back and that magstripe duplicated, and now the bad guys can sell your credit card.

That happened in Merrimack, New Hampshire. I saw some charges that were filed. So I'm not sure if they were convicted or these were certainly the allegations involved, but apparently one of these chain restaurants had the manager and some of the employees doing the naughty. They were duplicating the credit cards.

So banking isn't the same. With banking, it's the opposite. In many ways of confidentiality, the bank knows the transactions you have made. The merchants, know the transactions you have made. You've probably gotten emails from your bank saying, Hey, did you buy this here? There? Did you mean to buy this twice? You got charged twice for the exact same amount, like five minutes apart from each other, is that correct? Or tips, Hey, you left this amount in the tip, was that right or not? So that's the big deal.

The secret ballot once you've dropped that paper ballot into a ballot box. It's mixed together with all the other ballots. It cannot be identified as you, it's very hard for anyone to link a ballot to a specific voter and I think that is a wonderful thing.

There are some secure digital voting systems and they are designed to track a ballot from beginning to end but I think that actually defeats part of the purpose of voting.

I know, I can think of one occasion where I said that I voted one way, but in reality, I've voted in another way and I just didn't want people to know, which way I voted, because I thought I would be pummeled and quite literally. But yeah, if you don't have a secret ballot, that's just not going to happen.

Be very careful with this. Because even the bank systems with all of the encryption they're doing, all of the security they have in place, all of this crypto-technology they're using to track it all. Even all of that isn't safe. So you already know. I don't like mail-in ballots being sent out to a whole of the voters. It's ripe for fraud and we are a long way away before we can count on online voting, being safe.

Hey, you're listening to Craig Peterson here on WGAN stick around when we get back, we're going to talk about price gouging and defective products from an online store whose name I think might surprise you.

Stick around. We'll be right back on WGAN.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains third-party sellers on Amazon and why it is not all it is being made up to be and why?

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] You've probably been shopping online and some of these retailers include some of the biggest ones out there have been price, gouging, us, and shipping defective products. We'll talk about who and why and what you can do.

Hey, welcome back everybody. Craig Peterson here, he listening to news radio 98.5 FM and AM 560 thanks for joining us today. You might also be listening online@craigpeterson.com and you can find me on most major podcasting platforms out there.

So welcome. Welcome. So glad to have y'all here.

Online shopping, right? It's a pretty big deal. It has been growing a lot. I'm looking at some stats here, statistics and in 2014 online shopping accounted for about 1.3. trillion dollars in sales. That's a lot of money, isn't it, online? So that was six years ago. Last year, it more about tripled to $3.5 trillion. And 2020 is expected to be $4.2 trillion. So, up about what, 20% from last year, it might even be higher than that. I think just because so many of us are shopping online, and it's probably going to hit about 7 trillion within the next three or four years. It's absolutely amazing.

We're talking about 2 billion online shoppers. There are roughly almost 8 billion people in the world and just over a quarter of them are online shoppers, almost 5% of people shop online at least once per month. Some great stats here, put together on sleek note.com, I am running through. 63.3% of shopping journeys start online. We've known that for a long time. So no matter whether or not you have a hard goods store or not, most people, 63% are starting online, and then they're going into the stores.

About half of eCommerce sales are made through mobile devices this year, about half 49.2%. 54% of eCommerce sales are going to be made through mobile devices as of next year. Mobile devices are at, by the way. It's why, if you have a business website, you need to make sure you are mobile-first in this day and age, not desktop first. But look at who's going to your site, like my site at Craig Peterson.com. My statistics show me that most people, 60 to 70% are going to Craig peterson.com from their desktops, not from mobile devices. I'm still a desktop-first kind of website, but you have to account for those mobile users.

Amazon accounts for almost half of all US eCommerce sales this year, 47% and it's going by next year. It's going to account for about half of all of us sales. 80% of online shoppers and 63% of mobile shoppers think that new technologies and innovations will improve their experience. Online shopping, I don't think anyone can deny is a very big thing. If you're a business and you don't have a great online presence, you got to pull up your socks.

I've got to say, I do not have a great online presence and I am in the process of pulling up my socks. Okay. I have been working pretty hard on redoing it and I had hoped I have the new site up by last weekend, but it wasn't.

I'm not going to promise it'll be up this weekend either. Everything takes longer. We just had some of the other things going on. We've got a new customer out there right now, and we're busy with them. Multiple installations and multiple sites here. Try and tighten up their security. So cobbler's kids.

What we're going to talk about right now are price gouging and defective products.

Did you know that about half of the products that are being shipped out right now through Amazon are from what's called Amazon Marketplace? The Amazon marketplace is third party companies that are selling using Amazon's technology. So Amazon will charge them a percentage. Amazon will stock their product and charge them for the inventory, the space in the racks, et cetera. Then Amazon will try and sell it to you and then ship it to you. You may not be aware of that, but the problem that we're seeing right now is that many of these third-party marketplace companies are bad actors, is what Amazon calls them. And that's true.

They are bad actors, according to Amazon. In a corporate blog post, they said we have suspended more than 3,900 selling accounts in our US store alone for violating our fair pricing policies. We've been partnering directly with law enforcement agencies to combat price gougers and hold them accountable.

Between May and August, Public Citizen found that ordinary antibacterial hand soap, which usually sells for around a buck and a half was going for $7. That's how almost a 500% pricing increase for antibacterial hand soap. They also found instances of markups of a thousand percent or more on things like disposable face masks, they were selling for $40 instead of $4.

Cornstarch selling for $9 instead of 90 cents. So it's a big deal here, but the report is also saying something interesting. It's troubling that so much effort was put into blaming third-party sellers, but so little effort was made to stop the price increases including on the product sold by Amazon directly.

Amazon is not merely a victim in the price gouging on its marketplace, it is a perpetrator. Interesting report.

There are other reports. There's one that was released this week by US PIR G found that erratic pricing for staples, things like paper towels, Kleenex, flour, bleach is still persisting over there on Amazon. So you'll find that@uspirg.org. I'm not actually sure what that stands for, but they are watching consumer pricing and trying to protect consumers according to their website. So it's really interesting what's going on.

Now, personally, I don't have as much of a problem with what they're calling price gouging as other people do. If the demand goes up, the price goes up. If the price goes up, the profit goes up over the profit goes up. More people are going to get into that business, which is going to drive the price down. That's just the way it has always worked. Now they call it capitalism, but it's been the way that people have interacted with other people since the Dawn of time, when someone traded a rock for another rock, or a leg off of a lamb for a few chickens. It's just the way it has worked and always worked.

So I would rather, for instance, these guys and gals and have generators. If I've been storing generators for two or three years, and I have them and they're not being sold very quickly because nobody needs them. But now there is a massive power outage. I have these generators, but it's cost me money to store them. Or let's say I have to ship them up from Florida. So now I have to pay the trucking costs. Plus the higher cost of the generators in Florida. Why should I not be able to pass that along to the consumer? If I can't pass along to consumers, guess what? I'm not shipping generators up from Florida or water down to Florida after a hurricane, from New England, because I can't recoup my costs. This is a difficult thing. So keep an eye out when you're shopping online. Even at Amazon, compare it with Walmart.com.

They're trying to make a huge hit against our friends over at Amazon and they're doing a good job.

All right, we're going to talk about ransomware.

You're listening to Craig Peterson right here on WGAN.

We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains the new Corporate face of Ransomware called Ransomware-as-a-Service or RaaS. How it works and what it means for you the small business owner.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Managed IT Providers: The Cyber-Threat Actors' Gateway to SMBs

Think You're Spending Enough on Security?

DHS Braces For 'Potential EMP Attack' As Presidential Election Nears

US Sanctions Russian Attackers for 2020 Election Interference

Cyber-Risks Explode With Move to Telehealth Services

Why online voting is harder than online banking

Price gouging and defective products rampant on Amazon, reports find

Ransomware Has Gone Corporate—and Gotten More Cruel

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Odds are pretty good, actually that you've already been hit with ransomware. Raise your arm if it's happened to you, put your hand up. Yep. Yep. I see you. it has gotten a lot worse lately.

You're listening to Craig Peterson right here on news radio 98.5 FM, AM 560, and of course, online@craigpeterson.com. Thanks for joining me today. And of course, during the week, every morning, Matt Gagnon is on Monday through Friday. You can listen to him during your morning drives and I'm on with him on Wednesdays as well at seven 34.

We've talked about a lot today and if you missed any of it, you can find it online at my website. You can also subscribe to my podcasts if you would like. Can just go to Craig peterson.com/itunes. Hopefully, I have earned a five-star rating from you. And if that's the case by all means go, if not, then don't. Hopefully, I have, we put a lot of work into this every week. I do certainly. My wife helps out with it. She does a lot of editing of the podcasts and putting everything together. Of course, we put it up on the radio stations. Appreciate all of the work Danny does there and just getting it all together. It is a lot of work and I'd love to hear from you if you have any comments or questions, by all means, let me know. Or, if you're interested in attending some of these training that I'm scheduling over the next few weeks. Drop me a note. Just email me M E @craigpetersawn.com. I'd love to hear from you. And if you'd like to get my weekly newsletter and find out a little bit more about what's going on through the three-minute emails. So then I'm going to be sending out and I call them three minutes because you're going to get a tip, in just about three minutes, as well as some action items that you can do. So you can get that by going to Craig peterson.com/subscribe, pretty easy. And I am not, I'm going to nail you. I'm not one of those people that just chugs away trying to sell you something. Just to ask anybody who has subscribed to that email list. I send those things out and I do respond to emails. Might take me a few days. Sometimes depends on where I am and what's going on. But just me, ME @craigpeterson.com.

Ransomware has taken a turn for the worse. And there's a great article by Brian Barrett up on Wired, this week. And I've got it up on my website as well @craigpeterson.com. But ransomware has gone corporate now. It's gotten a lot crueler. These operators, just the latest groups here to adopt what really looks like a professional attitude. This group is called Dark Side. Now, in case you don't know how this works you probably have misconceptions about how the whole ransomware business runs.

It's a business now, and you can make money, millions of dollars running a ransomware business. Now you might think that you have to go out and you have to hire a programmer and, maybe a few programmers and write some software that goes out and first of all, of course, you got to find a hack that works. What have people not yet patched on their windows boxes or maybe what have they not changed on their firewalls they haven't patched them up, so right. That would be step one, right? A logical step one. So you've got to find this.

Then of course, if people start patching that, then you've got to find the next one and you got to have, so you've got the hackers upfront, right? So you've gotta have a team of hackers.

Then what do you have to have? Let me see you need some programmers who can now program to use those hacks to your best benefit. It's going to crawl the internet. It's going to find these systems that are vulnerable. Then what you're going to have to do is have another team of programmers that are going to have to write code, to infect those machines, using the hack that was found by your hacker team.

Once that hacker team has found that, and you now have a hack that works. You now have to get it out in people's hands. So you have to have somebody that writes some emails that are phishing style. That's how most of it's spread, nowadays and that fishing style has to get people to click on it. It's not like the Nigerian Prince scams. Those are, those were so 1990s. No, we're talking about some professional email. So let me see how many people do we have. We've got the hackers and that's a few people, right? And so they're probably going to be mostly full time because hacks don't work forever and then you gotta have the programmers that can program to find machines that are vulnerable. Then you have to have the programmers that take that hack into those vulnerable machines and can now encrypt all of their data. Then you've got to send the information back from the machines that have been encrypted to let you know, Hey, this machine has been encrypted here, so how much money do we want out of these people, We need Bitcoin? So we have to have somebody that manages the Bitcoin account, make sure the money's coming in and then we have to have other people that send it back. Doesn't that make sense to you? As that's the way it would have to work.

You would be wrong. Yes. All you need nowadays to become a ransomware corporation is anywhere from 20 to a hundred dollars. You go onto the dark web, which is very easy to get on to. I've given you guys instructions on that before here on the radio show because there are legitimate reasons to go out onto the dark web, but you go on the dark web and you pay.

In fact, did you realize that you don't even have to buy the ransomware software anymore? Yeah. You could pay 20 bucks for some ransomware software, but now there are companies that provide ransomware as a service, and these ransomware-as-a-service companies like DarkSide, which is what I'm talking about right now, they'll do it all for you. They'll just take a percentage of the profits if you will, the money that you're swindling out of all of these companies that are out there. Yeah.

So these people, this is amazing, they've got a venture capitalist friendly pitch deck that they use. They're obviously not as strict and they say in this pitch deck that we created DarkSide because we didn't find the perfect product for us. This is the latest in a strain of ransomware. That's built to shake down big game targets for millions of years dollars with attacks that have this air of professionalism.

They've got tech support people. They've got real-time live chat software so that the victims of your ransomware can call. They don't know what's going on. They didn't patch their systems. They weren't patched up to date. Usually, you have a few weeks between the time that a patch is released and the bad guys really start going after it. Right now, you might even have a month or two.

Heck, it took the huge hugest attack, right where over 200 million people stolen from Equifax, all of your personal information, it took them about six months. So no, after a new hack comes out, you might have a few.

But these guys, they just take care of it for you.

If you haven't patched because you don't know how to patch or you don't want to patch, it's not your core business. I haven't hired a good Managed Services Provider (MSP). No one's going to come after me. These guys come after you.

Now they'd love to get their ransomware paws on to a city government computer, or they'd love to get them on to Equifax, again, but they just as soon get them on you and your personal computer.

How do the bad guys know that you have millions of dollars to pay in ransom? Because if it's on your computer, you're a 70, 80, 90-year-old retiree. You don't have a whole lot of cash sitting around, at least a pretty unlikely. If you're a very small business, you're not going to have a lot of cash sitting around. If you're a big business if you're a hospital, a school, a nonprofit, government target you do. So how do they find out?

Ransomware today isn't the ransomware of yesteryear. The ransomware of today gets onto your computer. It starts spreading laterally inside your network, unbeknownst to you because you didn't bother investing in the right kind of hardware or software to track any of this stuff.

So now it's on a bunch of your business machines and it gives the bad guys a back door now. Where they go onto your machines and poke around. Their software is even automated. It looks for word documents, Excel spreadsheets, all kinds of documents, even PDFs that might be of interest to them. Then they'd start poking around and say, Whoa, wait a minute.

Here we're into a police department. I wonder what they would pay to keep all of their records, to get them all back or to keep them secure. Or I wonder what this business would pay to us to not release all of their documents. So they download all these documents from you. And the now they've got it figured out. So they actually do have a team that sits there and analyzes it and says, okay, I think we can get. $2 million out of this business or this government agency. They have all of your documents in hand and so they will now present you with a ransom. They will encrypt your machines, just like yesteryear, just like the good old days, they'll encrypt your machines. Then they will say, Hey, listen here. Now you pay up.

It's only $2 million who can afford it. You can afford it. If you pay up, we'll give you a key. We even have tech support people. In fact, you probably are on a real-time chat right now and those tech support people are going to give you a hug and they are going to take care of you. They're going to decrypt your files.

Odds are, by the way, only about 50% that even if you pay the ransom, you get all your files back. Then they'll say here's the other edge of that sword. Hey, by the way, if you don't pay. By the way, the price is going up in three days, but if you don't pay, we're going to release all of your files to the dark web. We're going to post them up there and they're going to be in the hands of your competitors, or whoever wants to get their hands on it.

By the way, depending on the industry you're in, that's only a 10-year federal prison sentence and how many hundreds of thousands of dollars in fines, nothing to worry about.

They have turned ransomware into a corporate entity. It is very scary.

Make sure you are on my email list. So you can get those three-minute pieces of training. You can attend my free training everything. Especially if you are a C-level within a corporation, if you're just an individual you're going to get some great stuff. You're going to learn stuff.

Really I am trying to train business people on what they should be doing with their systems and with their personnel.

All right. Have a great weekend, everybody.

I'll be back Wednesday morning with Mr. Matt. Gagnon at about seven 34. We'll talk to you then.

You've been listening to Craig Peterson on news radio 98.5, and AM 560.

Have a great week, everybody.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on WGAN this morning with Matt Gagnon and we began with talking about Online and Mail-in Voting and some of the technical problems with those forms of voting, then we got into what the big Nation-States are hoping to do during this election cycle up to and including the possibility of launching an EMP and what that could mean for us in the US. Let's get into my conversation with Matt on WGAN.

These and more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Could put us back to those 18 hundred timeframes where we don't have electricity. And it is a scary thing because if they're able to knock out some of our major transmission transformers, we don't have any.

Hey, good morning, everybody. We got to a few different subjects and I ended in a bit of a depressing tone here talking about China in this electromagnetic pulse, apparently, that is being planned. I'll be talking about this a little bit more this weekend as well with Mr. Matt gang all over on a WGAN. So here we go with Matt.

Matt Gagnon: [00:00:43] Craig Peterson joins us now at seven 36 on the WGAN and morning news on this fine Wednesday, Craig, how are you this morning?

Craig Peterson: [00:00:49] Hey, good morning. This is the kind of weather I like. Fall's my favorite season

Matt Gagnon: [00:00:54] Fall also is my favorite season. Although a little bit warmer than it was yesterday. Certainly, it would be good. I think it was like 38 degrees when I woke up in the morning. That might be a little much,

Craig Peterson: [00:01:03] but surprise.

Matt Gagnon: [00:01:04] Yeah, as well as Maine for you. So it was great. Let's get right into things here. there's a lot of stuff I'd like to tackle with you, but, I think I'd like to lead off if you don't mind here with the Russians being back once again, election interference in 2020. What is this all about and what are the United States do about it?

Craig Peterson: [00:01:20] Yeah, who would have known a, the Russians? They've been after us for quite a few years. That's our whole goal really is to upset the elections. They don't appear to have ever had a goal to elect someone specifically, but there is a lot going on right now. The FBI is reporting that they have seen multiple attacks and almost consistent, apparently from Russia, it's hard to know a hundred percent for sure, but it looks like it's from Russia. Against both major campaigns here for the president. So they are targeting the US populace. But in reality, they're going after President Trump's campaign and vice President Biden's campaign, as well as other prominent US persons and members of the US government. We'll see what ends up happening here. It looks like it was actually China that managed to get all of those emails back in the last election cycle. Between the two of them, they're definitely going to cause a few problems this year. But they don't appear to be going after changing the vote, just confusing the heck out of us.

Matt Gagnon: [00:02:32] That was going to be my next question to you was while that is concerning and something we should care about, obviously, what do you think the real threat to the system is? Is there any sort of real concern that there's going to be wholesale problems with voting or votes changed or anything like that? Or is this really just what we saw in 2016, which was like manipulative interference ie they were trying to shape and shift public opinion and doing things like that.

Craig Peterson: [00:02:58] Yeah. That's what we're looking at this year as well. There's a group of Russian trolls, that's what they're called, where they're posting things on social media.

We'll see what ends up happening. But as far as the security of the technology, the election goes. We have 50 state elections all run by our secretaries of state and in every state. That makes it a lot harder for someone to hack our election results. Now, I would expect that some of the websites so that the secretaries of state are publishing the results on some of those websites will probably be hacked and that does give them the opportunity to change votes because frankly, that's all that's been done lately. Is people the news media, even Washington, DC when they're trying to tell you this all up, they go to all 50 websites and they try and pull the final results from there. This year we're expecting they will do more followup than that and actually contact a live person and verify the result totals. Because those could be hacked, but it would be just very difficult, Matt.

Matt Gagnon: [00:04:11] We're speaking with Craig Peterson, our tech guru, who joins us at this time every Wednesday. And of course, you can also hear him on this very station on Saturdays at one o'clock. For his own show where he goes through a lot of these topics in more detail in depth.

Speaking of voting though, online voting is another animal altogether, and it is a great deal harder than other things you do online, for instance, online banking. Why is that, sir?

Craig Peterson: [00:04:34] It has to do with the idea, the concept we've had for many years of having a secret ballot. The whole idea is if it's secret, someone cannot be holding a gun to your head. They can't be trying to influence your vote. They can't take your vote and just do what they want with it as happened in orange County last year. The election cycle out in California, where they were passing out ballots that had the Democrats already selected for you, which just makes voting so much easier. You can't verify. Now the bank counts on you going ahead and checking your bank account every once in a while.

Hopefully. We're all looking at our bank statements to make sure that nothing bad has happened. And even with banking where we have some of these checks and balances in place, we have encryption in place. There is an estimated $28 billion in credit card fraud that occurred in 2018. Teen. So even that isn't perfect.

And now of course we have those chips on our cards that are using more and more. They're still losing money. So the banks expect a fair amount of fraud and in fact, there is some fraud during the elections. There always has been. But we cannot double-check our ballot. We can't check the balance at the end to make sure that the state had tallied our votes properly and still have some sort of privacy or secrecy over our votes.

Matt Gagnon: [00:06:07] We're speaking with Craig Peterson, our tech guru, he joins us this time, every Wednesday. Craig, the other thing that I wanted to check in with you about is this story. You had a, that you sent me this morning about an EMP attack and, and the potential for that as the election nears, as if 2020 wasn't bad enough, is that something that's a realistic possibility?

Craig Peterson: [00:06:26] It is, of course, we're talking about an electromagnetic pulse. The United States had one of these called the Carrington events that occurred naturally and they do occur naturally, right here in Maine. We might remember what happened just North of Quebec, back in the mid-1980s. Where in both cases, we're talking about a solar flare and that's solar flare loss, not the grid electrical grid in Quebec, just from that one solar flare.

Think of all of these power lines as basically antennas so that when you get that mass and pulse of electromagnetic energy coming from that sun out there, it can and does disrupt our grid. In fact, burns out all kinds of things. So I can tell you most assuredly from some of the training I've done for the FBI InfraGard program, that we are addressing that problem.

However, China we know for the last 25 years has been considering an EMP attack as a first strike or even a retaliatory strike against us in the US. So if it were to happen in, it's very easy to do all we're talking about for a manmade electromagnetic pause is a fairly small nuclear bomb that isn't designed really to destroy buildings, but it set off high in the air and that will give a huge blast radius electromagnetically, and could put us back to those 18-hundreds timeframes where we don't have electricity.

This is a scary thing, because if they're able to knock out some of our major transmission transformers, we don't have any, and I'll give you three guesses where these things are made.

Matt Gagnon: [00:08:18] Oh, I don't know. China, and yeah.

Craig Peterson: [00:08:22] We would be completely out of luck there's estimates that if they did this right against us, we could be without power in many areas of the country for at least 18 months, if not for years. So it's a very big concern. They are addressing it, or the power companies are addressing it, but it's very real here. They could shut off a blast. That would cover 1500 miles worth of the United States and knock off all of our computers and even our air conditioners and in some cases our heating systems.

Matt Gagnon: [00:08:58] On that happy note, Craig Peterson has joined us on this fine Wednesday to go over the world of technology.

We'll talk to him again next Wednesday, and again, make sure you tune in on Saturday morning to hear Craig talk about this in more depth. Thanks a lot, Craig. We'll talk to you next week.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. I was on WTAG this morning with Jim Polito. He had a few questions about Voting and the Technology surrounding Mail-in and Online Voting and then we got into the sales of the Chinese company ByteDance to Oracle. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] They've been using some of our drone footage, which is why these Chinese drones are illegal to use for government contractors and many others. Good morning, everybody. Craig Peterson, here. I am enjoying this weather. This is my time of year. I was on with Jim this morning, we talked about TikTok, this whole Oracle thing. Why did the president do what he did and is the sale actually going to fix the problem? President Trump identified. So we talked about that and of course, we also talked about voting. It can't get political sometimes with Mr. Polito. So here we go.

Jim Polito: [00:00:41] Okay, this is the guy you need to have at your side through all of this. I want to talk to him about Oracle and TikTok, cause I want to get his take on it. I've got something more important to talk about first, and that is online voting - God help us. Here are our good friend and tech guru. Craig Peterson. Good morning, sir.

Craig Peterson: [00:01:05] Hey, good morning, Jim. Love this weather. Love it.

Jim Polito: [00:01:09] This is Canada weather. Speaking of the great white North, Gary, a listener from Gardner sent a picture of him. You know, some scrape marks on his windshield had a little bit of frost on the windshield little bit there. Yeah. I would figure that you would like this you're coming into your season here.

Craig Peterson: [00:01:30] I am. I, I remember summers, it would get to like 70 or 72 and it was just wonderful. That was summer weather. I just don't like 90 degrees.

Jim Polito: [00:01:41] Well, I'm kinda, with you there. I'm with you there. I don't like it.

Alright. Here's what I don't like. I don't like online voting. First of all. I don't like mail-in voting. I don't like online voting, but you sent me some interesting information. We can do online banking, which you would think needs all of this security. What's the difference between that and attempting to do online voting? Why can't online voting be done?

Craig Peterson: [00:02:10] Yeah, this is a really interesting problem. The bottom line for everybody is it's not a problem that will be solved any time soon, or my soon. I mean, it will take many years before this problem is solved. The big problem you have has to do with a secret ballot. So when you go to the voting booth, although this year they took the little flap off the back of the booth. So people could potentially look over your shoulder, but people were there to monitor to make sure there wasn't somebody holding a gun to your head to make sure you voted the right way. In fact, it's illegal pretty much everywhere to take a picture of your ballot. And that's gone to court many times because again, Someone could be extorting you to make sure you're voting the way they want you to.

Or if you live in Orange County, California, the ballots came pre-filled with the Democrats, checked off. How do you know if it's a legitimate ballot, that's the problem really comes in Jim? When you're talking about ATMs, banking is different. We do have encryption from the ATM machine, all the way to the data center for the bank.

And then the banks also share their data over secure links and, and they count on you checking your bank statement at least every once in a while.

But once you've voted, all right. How do you know that your vote was counted? That your vote made it? How can you do it secretly? Yeah. And so that's the big problem here.

You cannot have it secret. Now. There are some technologies out there right now that allow this auditable voting system, kind of using the technology that's behind Bitcoin, but it's not there yet. We can't be sure someone is literally or figuratively holding a gun to your head while you vote. Mail-in voting doesn't work because of that one reason and we can't do online voting because again, the same reason, but it just can't be audited.

Jim Polito: [00:04:24] Yeah, I get it. Now that makes complete sense to me because you do lose the ability of the secret ballot. I want everybody to vote, but if somebody chooses not to vote, that's their right. I guess it's public information that someone could look at.

Well, what ballot did Jim Polito take in the primary? You know, if I take a Democrat, I'm an unenrolled. So if I take a Democrat ballot or I take a Republican ballot or whatever, somebody can look at that and say, Oh, he took a Republican ballot. Oh, he voted in that election. And then you get on a certain list, but I see where you're going.

The next step from this is, yeah, it's actually easier to do the banking because everybody's upfront about it. There are built-in checks and balances. You would give away the secret ballot if we were to say you vote online.

Craig Peterson: [00:05:17] Well, even with banking, we look at it and look at your credit card.

Now they have the chips on them that do help to authenticate your card. But right now, the latest numbers that we have are from 2018, and credit card fraud alone costs the world's banks almost $28 billion. In 2018. That's a system that is sure. So what kind of fraud could we expect from heaven forbid, we have mail-in voting.

I think that might be inevitable, but that was a fraud. There's going to be crazy and it's not like an ATM, we just can't secure it. We can't be sure that people are voting secretly and that's been fundamental. You look at some of these other countries, China has 98% of the population voting every time there's an election. They know exactly who you voted for. Yeah.

Jim Polito: [00:06:14] Well, and you don't have much of a choice, frankly, when you voted China, you're voting for the communist party that's it. We're talking with tech talk guru, Craig Peterson, our good friend who loves the little cold snap in the air right now.

Alright. Let's get to Oracle and TikTok. Now, you know, I, I don't post things on TikTok but I did register my name so that I would have Jim Polito on TikTok as I do on everything else because someday, maybe, you know, people, my age will take over TikTok. I don't know. I found it. They talk to me decently. I was explaining to my stepsons. They said you're on TikTok. And they said, well, wait a minute. I'm not posting anything. I do view stuff on TikTok and I said, my TikTok experience is much different than yours and they said, what do you mean? I said, my TikTok experiences, politics and home improvement, and maybe motorcycles and the rolling stones. You know, like that's the kind of stuff that gets sent to me. Cause that's the kind of stuff that I like. Oracle now beats out Microsoft to buy this platform owned by the Chinese communists. I've been looking forward to hearing your take on this

Craig Peterson: [00:07:34] This real interesting thing, because it's the first time ever I'm aware of where some deal like this has happened. Certainly during the war, we had businesses that were broken up. For instance, Bayer here in the US that makes the aspirin was a German company in world war two. Congress divested the German company, Bayer of all interest in the United States. And, given the company to some buddies, right.

But you know, maybe not that I couldn't happen here in the United States. What we're looking at right now is this company called Bytedance, which is this Chinese company. Don't think of companies under socialism the way we think of them under a typical free market. The company is controlled by the socialists in China, by the Chinese communist party.

They were sending data to China. And anything that goes to China is monitored by the Chinese military. They've been using some of our drone footage, which is why these Chinese drones are illegal to use for government contractors, and many others because they have GPS in them. They're showing video it's giving them the exact GPS coordinates and they'd probably have a better map of the United States than we do now.

When it comes to TikTok much the same problem. We're taking videos. We're giving locations where we are, who our friends are. So if they want to trick you into something with phishing, et cetera, they now have enough information to do it. So that's why President Trump said that. This is it. I am invoking these powers that have been with the president in Congress for many, many decades now. I am going to force the divestiture of TikTok. Or it's going to be illegal to have on the stores here in the US. So where we're at right now is the Chinese government said we will not allow Microsoft to buy TikTok. So that came in over the weekend and that's when Oracle's rose to the top.

Cause Microsoft and Walmart were, kind of, going into together. Walmart really wanted to control it and Microsoft would do the technology. But what they're going to do is bring it here, under US control. But unlike the Bayer Aspirin factory, where you can have someone go when you can see there is no socialist influence here. The national socialists of Germany are not here running it anymore, it's the Americans. You can't audit all of this code, that is TikTok in a matter of days, weeks, months, or maybe even years. There's still going to be problems here, but it is moving in the right direction. Oracle is an odd company and their pricing strategy historically has been to grab people by the ankles and shake them upside down and see how much money comes out and that's how much it costs to buy their database.

Jim Polito: [00:10:39] Isn't the CEO of Oracle kind of an odd duck.

Craig Peterson: [00:10:44] Oh yeah. He has the biggest Yacht in the world. And he is very, very, very, very strange, Larry Elison. This is going to be interesting on that front alone is TikTok going to become a charge for service? What's going to happen? But we're not going to get the security we want out of TikTok for some time. But I would imagine initially the servers are going to move directly in the US, under US control, and Oracles going to be mandated to not allow any of that data to go to China. They will probably be able to stop most of that from happening.

Jim Polito: [00:11:19] Unless, of course, there's some little sleeper bit of code somewhere in there that the Chinese have developed, but we'll see. Interesting. I feel better. Look, I never really cared about the Chinese knowing what I'm looking at on TikTok and where I am. I'm not important. But maybe we just don't want the Chinese to know what do Americans do and where do they go to be able to mine, that kind of information about us. Maybe in that respect, I don't care as an individual, but I care as a country. We'll see. The good thing is, Craig we have you here with us to watch this whole thing. Very helpful information, especially about voting and everything else.

So Craig, if people want to know more about Craig Peterson, I guess they can tune in on Saturdays, but there are other ways to reach you.

Craig Peterson: [00:12:11] Yeah. In fact, starting today, I have a couple of times a week. You got to have emails going out there about a three-minute read. I'm trying to keep these short to help you understand what's going on here in the tech business, particularly securities, I'm giving you some tips, some tricks, other things.

I'll be doing live pieces of training, all of this free. I'm not trying to sell something right. This isn't the way you might expect it to be, but I am going to be putting that out and you can get it by going to Craig peterson.com/subscribe, correct. peterson.com slash subscribe. You'll get my weekly newsletter, which covers everything Jim and I talk about.

And even some things we don't get to as well as some of this real quick minute training that I'm going to be doing.

Jim Polito: [00:12:58] That's fantastic. The Craig Peterson show, if you want to listen Saturday mornings at 11 o'clock on WTAG obviously in Western mass, you can use the iHeart radio app. And, there you have Mr. Peterson. We've got you covered front to back. Thank you. Craig so much enjoys the Canadian weather and we'll talk with you next week.

Craig Peterson: [00:13:19] Indian summer. Alright? Bye-bye.

Keep an eye out for this first email today, these three-minute emails. And let me know what you think if it's worth my doing, I think it is. And I'm sure it'll get better, but what do you think might make it a little bit better as well?

All right. Take care, everybody, and we'll be back tomorrow. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome,

Good Monday morning, everybody. Craig Peterson here. I was on with Jack Heath and we discussed some less tech news that he was interested in getting my take on. For more tech news of the week listen in on Saturday at 11:30 am on this station. Here we go with Jack.

These and more tech tips, news, and updates visit

  • CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] Good morning, everybody. Craig Peterson here. We've got a busy week I had where you keep it on your email box. Would you? I've got some new emails coming out here mid-week. We're starting training and it's basically going to start with email. We're trying to keep these down to about a three-minute read. I'll get you up to date, keep you up to date as we go forward.

Then we're going to be having some more live stuff on YouTube live and Facebook lives and elsewhere. It's going to be a busy time for me, but you know what? I think it's worth it. I've been doing this for so long and I want to help those of you who are in business and are worried about what's really happening.

It's gotten crazy out there in the cyber world. So many businesses destroyed, not just by the whole COVID response, but because of the bad guys they've just gone crazy. All right.

This morning I was on with Mr. Jack Heath and I was out with my phone. It didn't sound quite as good as it does when I'm in my studio, but, you know, Ce la vie.

We talked a little bit about a kind of a nontech issue, but kind of a tech issue. So here we go with Jack.

Jack Heath: [00:01:14] Joining us within a different time slot, because we got to get, we had to move, somethings around for, we're going to give you an update on those state's latest opioid numbers with Chris Stawasz.

Right now, Craig Peterson, our tech talk guy, Craig, you know, one of the realities. Good morning. Hope you had a good weekend. One of the realities of, indirect realities of the pandemic or COVID-19 whatever you want to say about this that no one really saw was. A real estate, the booming market here where people are moving.

I heard stories over the weekend, getting into bidding wars to buy New Hampshire property and homes. What of it has to do with the reality of technology and people can work virtually from anywhere in their leaving larger urban areas. Good morning, Craig.

Craig Peterson: [00:01:52] Yeah, it sure does. Jack. Good morning. We're seeing an amazing change now in businesses, some businesses such as the New York stock exchange, where there are people who interact with each other are planning on reopening. But we've seen businesses paying as much as, the highest I've seen right now is $60 million to break a lease because they are just not going to bring the people back.

Some of these people are afraid of living in some of the bigger cities plus are just tired of all of the mess they've had. They are moving out or moving to places like New Hampshire and there have been massive booms cross country once you're outside of the cities. I'm afraid we're going to see a lot of empty business real estate, and that might be the next thing to fall.

Jack Heath: [00:02:39] Yeah, I think that we'd already seen malls, sort of falling by the wayside, with online shopping. I don't think we've really calculated the commercial real estate hit in a lot of major, major cities. I mean, you take cities like Chicago or New York City where some companies, corporations may not be renewing the lease. Where they would they didn't just lease a little bit they might have leased a whole building or several floors at a building. Then think about this, Craig, it is not just the commercial building and the services around the building, it's all the ancillary businesses that support commuters, coffee shops, Bistros, restaurants in and around a building. Where you might've had 800 workers, a thousand workers, that's a small economy and you go across the country with larger cities and no one's really calculated the hit on commercial real estate. Then the Washington, DC even we're seeing fewer visitors. What about all those little lunch places or restaurants or bars? So it's a lot of collateral damage as well.

Craig Peterson: [00:03:35] Yeah, who knows maybe this is going to be another New Hampshire advantage going forward here.

Great place to live. As it turns out a great place to work. New Hampshire for the longest time had some of the highest numbers of per capita high tech jobs in the nation. We were number two. And I think this is going to help to really solidify that as people move out of the box, often the area and some of the bigger cities I'm worried yeah.

To about obviously our restaurant and other small businesses that have been hit so hard. I was just reading about what had happened post world war two because almost all of these restaurants had shut down. We saw hundreds opening after the troops came home. So this might actually end up being a pretty good sign for us right here in New Hampshire.

Jack Heath: [00:04:20] Well, the other thing, Craig, I know it's not a tech talk discussion, but it's a human discussion. As we will also have the challenge of trying to get younger families and people to move here. We were kind of had an age-drain where we were one of the faster aging States. I know you're not getting older Craig, but you know what I mean?

Now, all of a sudden now we're seeing a. You know, younger families, people, you know, in their thirties and forties and not retirement age, moving to New Hampshire. These are not just all baby boomers that are moving here.

Craig Peterson: [00:04:47] No, and these younger people and then I know a few myself who used to have to leave in order to get those jobs.

Even those internships are finding that they can stay. Now, there are even online training available for how to get an internship over zoom or Microsoft teams or, or any of these online sites, something we hadn't seen before. These kids have the opportunity to live wherever they want.

Jack Heath: [00:05:14] Not only that Craig, but there are also unintended consequences communities didn't count on maybe as many students virtually or physically because you've seen towns like Bow, New Hampshire, all of a sudden they've seen an influx of families and that means more students.

The other thing. Is, we don't know yet, I'm sort of half being facetious before we go to break. A lot of these people moving here, bring their politics with them.

The demographic changes that we see from this little influx that no one's really calculated yet, but over the last several weeks and months. I'm literally hearing about bidding wars, almost a weekly now, of property, go on the market and several people from out of state are bidding on the property.

Craig Peterson: [00:05:53] Yeah. And these younger families tend to have kids, and those kids have to go to school, and typically the tax burden on that count increases higher than the tax revenue from the younger families.

So, yeah, it's going to be quite the little mix-up. We get a lot of technology to talk about so I'll be back on Saturday at 1130 to go into it in more detail right here.

Jack Heath: [00:06:11] Thank you, Craig Peterson, Craig Peterson dot com. Make it a good Monday.

Craig Peterson: [00:06:14] Hey, I got a question for y'all too. Karen had said, you know, why don't you just ask the people who listen on the podcast, you know, there are hundreds of them. So maybe they've got an idea, but I am going to be offering kind of a "done it for you" thing, right. It's what I've been doing for the last 30 years now, cybersecurity for businesses. So it's my team and I, it's a family operation and we help businesses by just taking over the cybersecurity side of their business. You know, they still have the people working within the business. They're the guys and gals that fix computers, help answer questions, and evaluate new products and all that sort of stuff.

But what would you do you call that? Right. We internally we call it, do it for them. That's what most people seem to want nowadays anyways because they who has time to learn this stuff. It's impossible to not only learn but keep up with it's just changing soul racks. What would you call a done for you type thing when we're talking about cybersecurity. Let me know what you guys think.

Just email me@craigpeterson.com. So I can see that I'm going to try and pay a little closer attention to my email this week, even though I have a lot to do as you try and get some of these new things online, but what would you think we should call a service offering as a managed security services provider? The oldest in new England? What should we call that?

Anyways, let me know. Take care. everybody. Talk to you later. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains contact tracing and how Apple 13.7 and Google Android are using it to help respond in this Pandemic.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] A lot of Great comments about last week show, appreciate you guys joining us today. Of course, this is Craig Peterson and as usual, we've got a lot of technology to talk about and some security stuff as well. So here we go.

Emily: [00:00:19] And now, here's Craig

Craig Peterson: [00:00:21] Hopefully you were able to join me earlier this week as I was on during drive time talking about many of these issues. We usually only get to talk about two or three, and you've probably seen in your newsletter email this morning, that most weeks we have, I don't know eight. To 12 different topics that I think are really important.

So we get to a bunch of those today on the radio show. And of course, in my email, in that newsletter, I've been adding an Ask Craig's section. You probably noticed that and these are some questions that people have asked me directly in response to the newsletter, or just like you guys can email me@craigpeterson.com anytime.

And I figured those are the things everybody really wants me to spend a little time on. So that's exactly what I do. You'll get those of course during the week.

Right now we're going to be talking about this new iOS version. In fact, it might even talk about the one after that because that's been hitting the news due to some critical flaws.

If you have a website and it is that time for elections and businesses to try and grow. If you're a candidate or a business, or you are running a website for the local soccer club a year are gonna want to hear this about WordPress. And, we've got a really sad little story here about a mistake Apple made, but they cleaned up after themselves.

So that's a little bit about what's going on today. We've got more of that as well as we go forward. So let's start with the whole iOS 13.7.

Those of us who've been using iOS for a while. We all know that we do get updates, right? That's one of the real advantages to the Apple ecosystem over some of these others out there, particularly the Android.

I know I can hear you guys now. Phew. Phew. In particular, Android, I use Android. In fact, I was chatting with a friend of mine. Who became a friend because he was a customer first. He was the chief technology officer for the state of New Hampshire. And I had done a whole bunch of stuff for the state over the years and had set up the nh.gov domain and all of the communications and everything.

It was interesting cause I hadn't talked to him and. The better part of a decade, maybe even more. and he said, so what kind of phone do you have? He says you gotta have an Android. And I said, no, I don't. Because he knows, I like to tinker with technology. And if you're a tinkerer, Oh, that's where the Android comes in handy. But the biggest problem with Android, and the main reason I don't have one, are you just don't get the updates. You don't have the stability that you have in Apple Ecosystem for your Apple, your iOS devices, your iPhone.

Apple launched a new version of iOS here a little over a week ago. It was called 13.7. It adds a few different features, but one of the ones that really surprised everybody was something called notifications express. Now, remember we talked a few months ago about Apple and Google getting together and they came up with a methodology that could be used in order to track people that come in contact with each other. The idea behind it was, Hey, listen, we want to be able to let people know if they've come in contact with somebody that had COVID-19 symptoms.

You know the contact tracing stuff that you talking about now. Whether or not COVID-19 is, the killer that they want everybody to believe, or maybe something else is going on. That's not the topic I'm going to get into right now. But what this does allow you to do is tie in for some of the contact tracing apps.

You may be familiar with Sturgis and the big motorcycle rally. They hold out there every year, even this year. The complaints now that they're a quarter-million new cases, actually it was a little higher than that of COVID-19 have been spread. It's going to be a super spreader. There's no hard evidence of that I've seen and I've read quite a few articles on it. No definitive studies, certainly at least not yet.

What does this all mean? It means if someone gets sick, they're going to have to track it down. We've seen that happen in Europe, a lot. Look at New Zealand, for instance, they had a major outbreak. One person had COVID-19 symptoms and then apparently spread it to 13 others.

There's another one just here in Maine that happened a few weeks back. Apparently these people had attended a wedding and then spread the COVID-19. There's a number of deaths associated with that. The deaths were people that weren't even at the event, but who got it from people who had been at the event and passed it all along.

Well, this is a new rollout from Apple second phase, we had software updates in may that included this application, programming interfaces, API to help public health authorities to develop their apps for their own use, for this purpose. We've had some countries that have already used that some in Eastern Europe, down in again, New Zealand they've been trying to track people that are part of this group that started this spread again. In fact, they locked down the whole country. Again, I'm not going to get into today. Oh, that's for another show.

With the second phase, now, the authorities can get high tech exposure tracking without developing their own apps. So phase one, Apple added the API. So people well could write apps. Some third parties did write some apps.

Now they can do that the tracking without the API, Google has, this is not released in an Android software update yet. It does have its own version of exposure notifications express and later this month, Android six or later, devices are supposed to be able to get that update.

Again, the problem with Android, most devices will never have that update available to them. In this case, just like with Apple's solution, they're going to be able to get these notifications letting them know, they may have been exposed. This is built right into the operating system in the Apple iOS version, but in the Google world, Android users are to have to download an app.

We'll see what happens, ultimately here, users who are in participating states are prompted there. They are said, Hey, listen, do you want to receive notifications? If the contact tracing app, if this app indicates that they may have been exposed and then the users advise on the next steps to take. That has to do with the user's local public health authority. So far, we've got Maryland, Nevada, Virginia, and the district of Columbia participating in what's called the exposure notifications express system. Yeah. More expected to come later. There are states such as, again, Virginia, North Dakota. I am my Hill mean Alabama, Arizona, Nevada, who all came up with their own apps or bought apps from third parties using this API.

We've got 20 countries that already have exposure tracking apps that they're using. And we'll see what happens. We'll see what happens here. At least you're given the option. It's not like in China where you don't have the option. You have to carry your smartphone and that smartphone does track you and does track your contacts. We'll see.

Ipads by the way, are not included in that. Now I mentioned at the beginning of this. Something about the next major version of iOS 14 and there is a whole lot of controversy about it. Apple has said that they're going to push it out a little bit. We'll see how far out that'll be. They're supposed to have a conference that has come in week one of their big Apple meetings, or they're going to announce all the new stuff. We'll see what iOS 14 has in it. Remember Apple does not make money off of selling information about you, does not sell your data the exact opposite of what Google does, right? Google, the people who gave us Android. So Apple doesn't sell our data. Google is in the business of selling our data as quickly and as much of it as they possibly can. Another reason not to use Android.

In this case now, with iOS 14, Apple is locking down your privacy even further and companies that are like Facebook, that also are in the business of selling your data are rather upset because what is going to happen with iOS 14, as it exists right now is they are going to totally squash the ability for these guys to track you.

That to me seems like a pretty big deal. We'll see you ultimately, what ends up happening? 13.7, by the way, this really, yeah, just came out is probably the last update before 14 comes out. But who knows? There've been so many complaints from companies that are in the business of collecting and selling your data. It might still be a little while before that happens.

I want to give you guys a little tip, here again, I give this out and I should make this it's an every week sort of thing. I'll probably mention it again during the show today, but make sure you go to have I been poned.com. How have I been PWNED dot com there are features for businesses as well, but. You go there, you put in your email address, and just like I explained last week, it will tell you where on the dark web it finds your email address. It'll tell you about the breaches that your email address might've been found in and also what data was stolen as part of that breach so that you know, and then really, I want everyone to remember. It's a dangerous world out there. And it's way more dangerous now that we have so many people working from home.

I've got another one. We'll talk about a little bit later here called jigsaw.

But when we get back, we're going to talk about a different kind of patch. I bet one, you may not have heard before, and if you're a business, you've got to make sure that you stick around because we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig Explains Why companies believe that they are Completely Patched up and Why it means more than your Operating System.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, do you have a 99% patch rate? Gonna talk right now about why that is a load of UMHUM in every case that I've ever seen?

Craig Peterson here and here we go.

Hey everybody. Thanks for joining me today. this is something that I don't know if I can ever repeat enough, but I want to take a little bit of a different angle on this than I have before. Most of us know that we're supposed to patch. What do we patch? What are we using? You might turn on automatic updates on windows. You might have those turned on MacOS, of course, on your iOS devices. Maybe you've got an Android device it's less than two years old and still gets updates so you have that turned on. Here's the problem. I have yet to walk into a business that doesn't say that they have just a phenomenal patch rate.

You know, so for instance, you'll walk in there and you say, how good are you guys at keeping up on patches? Almost every last one of them says, yeah, almost a hundred. We're probably 99, 98% of the patches are up to date and we're just phenomenal. We're safe. Yeah, we're safe. don't worry about us. Yeah, we're safe. Don't worry about it.

I've been in a couple of businesses and said that and then, they got nailed something awful and they were too embarrassed to call me back. When I talked to them later on, I found out what had really happened with them.

Many people and many businesses are focused on that patch rate and that kind of makes sense. We have to make sure the patches are done, particularly the critical patches. But why is it that I go into a business and every business says, yeah, we're patched up. it might not be a hundred percent, but we're patched up. Every business says that.

Yet I always find critical vulnerabilities when I poke around. When I do a scan. When we do these paid assessments to come up with an action plan for businesses. We scan their systems, which means their workstations, it also of course means there are servers and maybe other devices that are out there. I have never scanned a device that did not contain a critical vulnerability.

Where's the disconnect? Why are businesses and people saying, yeah, we have this 99% patch rate? Yet I am continually finding major problems. It has to do with what's being patched. People are not patching the right thing. So let's look at a couple of different things here.

First of all. When we're talking about workstations, desktops, laptops. Here are the four types of software that are attacked the most. Number one internet browser add-ins. How many of us have extensions on our browsers? Some of those extensions are in fact, malicious themselves. Internet browsers.

Another big attack vector is operating systems. Of course, all of our office applications, all of our productivity stuff, software like I'm using right now for the radio show. All of this stuff gets attacked. But when we're talking about a 99% patch rate yeah. We're pretty much all patched up. What they're almost all always thinking about and talking about is patching the operating system and that's where things end.

Now on the server-side, when we go into businesses, we're finding the webserver software, the database server, the operating systems on those servers, the remote server management stuff, like RDP, the active directory. Those are what is always being attacked. So why the disconnect? It's because it's difficult to patch everything.

Microsoft, I already mentioned has the ability to automatically install updates. In fact, if you don't have the business versions, the enterprise versions of Windows, professional, you're forced to do updates. You don't even get to say when you want those updates to happen. If you're running iOS, on your iPhone, on your iPad, again, updates just happen automatically.

But how about all of those apps? If you're getting those apps on your mobile devices, from the stores, like the Google play store or the Apple store, you were probably getting updates for your applications. If you're not getting them from there, you're probably not getting updates.

So not patching the right thing is a very big deal. I wanted to talk right now about one specific thing that people are not patching. Frankly, that is our web server. You've got a website, right? If you're a business, any size business, you've got a website. You have to have a website. You have to get the message out.

Now, of course, you can have some emails from other things too, but we're going to focus on one thing right now, the website. Hackers are actively exploiting right now, a vulnerability in a WordPress plugin. Now, I mentioned our browser plugins are the extensions for our browsers and how those can be hacked in many cases.

It's another vector, obviously for the bad guys to get on to our computers and really start messing around. in this case, we're talking about WordPress web server, which is the number one most popular web server out there, WordPress and there are more than 700,000 active installations of this. We are using it for our own little websites for our families, We're using it for our businesses. We're using it for our associations or organizations. This particular file manager plugin, which extends features for WordPress allows bad guys to run command and malicious software things, like scripts whenever they want to. Now, how many people are keeping their WordPress installation up to date.

Are you keeping your flash UpToDate? Are you keeping your other Adobe software up to date? How about all of the other software you're running on your computers? I look at this computer and it's just astounding how much software I have installed here on my Mac that I use all the time.

So the attackers are using this exploit to upload files that have these shell scripts in them that are hidden in an image. Makes it even harder for you to find.

So we have to be very careful. We don't know the impact of all of this yet. It's probably pretty bad. There are some companies that are blocking it. We block it as well, but we're talking about millions of exploit attempts.

Over the course of the last couple of weeks, that is pretty bad. And we're only seen about half of the sites out there. The WordPress sites actually patched up. So make sure you do the update. You have to inventory everything you have. Everything your enterprise uses. What software do you have? What is it installed on? Is it up to date?

Don't just Willy nilly, allow people to install software on their computers, and don't do it yourself either. Every time you install software, you open up another potential way for bad guys to get in. Its something else you have to track. It's something else you have to inventory. It's something else you have to update. You have to upgrade.

People are just downloading stuff, Willy nilly. And remember what was the very first thing I said, that's attacked frequently internet browser, add-ins. That means internet browser add-ins means that those wonderful little bars that people install on their browsers are, yeah, those are malicious much of the time. At the very least, they are providing something called adware that's tracking, where you're going. Sometimes it replaces the ads on the website shows you stuff. It clicks through to these not clickbait sites, but click through to make them money on ads that they're running.

It's bad. We can't do it now. I wish we had more time. All right.

Your listening to Craig Peterson.

Stick around because when we get back, we're going to talk about an Apple problem with security this time.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains how app design libraries are causing problems with the security of apps for some of the big tech firms.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to get into the guts right now of something called notarization. When it comes to our apps. What's Apple doing what's Google doing and how did Apple mess this is up so badly, frankly.

Hey, you're listening to Craig Peterson. Thanks for joining me today. We've had a problem for a very long time when it comes to any sort of apps. I saw a funny meme about yeah about Bill Gates this week. It said Bill Gates couldn't even stop viruses and Windows. It's a really good point that Windows was never designed to be secure at all.

When they came out with NT, that was their first attempt to design it like a real operating system. They took the design of VMS, basically of Dave Cutler and company that had been designed over a DEC - digital equipment. And they said, Hey, we'll use this as a framework. This really works. It's not a hack. Let's just make this work.

Then, of course, Microsoft had his fingers on it. So they really messed it up. They wanted to be compatible with everything that they could possibly be compatible with in the past. In the past, Microsoft did not have the barriers walls. If you will between the apps between the operating system, between the hardware and the apps. They didn't have the appropriate protections in place. Programmers used some lazy mechanisms to get around the operating system, going directly to things like graphics cards, because the operating system just slowed it down and they couldn't do the graphics they wanted to do that way. So it's been a real problem, frankly.

It's been a real problem for a long time in the windows world, and NT was supposed to fix some of that. It did initially, and then it didn't. Now they're trying to tighten up this whole thing. how do you, if you're Microsoft or Google or Apple, how do you protect the people who are using your products from some of this malicious software?

What's the way to do it? What Apple has come up with is a mechanism and Google as well that signs the software. You might have noticed that if you are trying to install software on your computer or your Google device from a third party website, it will come up and say, can't be opened, It can't be installed. There are a few different messages that come up.

In the case of Apple now, with MacOS Catalina, which is the latest Operating system. Although, there's another one that is about to hit and it looks like they're going to change the whole nomenclature to, with the next release, but in Catalina, Apple now requires what they call notarization for all apps.

Any apps that you are installing on that computer need to be signed digitally by Apple. So the developer, when they write the software, they compile it, they sign it themselves. It's a whole public key cryptography thing. Apple takes that software and checks it and then signs it.

Both Google and Apple are using automated systems that try to verify whether or not the software is malicious. So it'll go through this automated system and will try and figure out well, is there any malicious content? Are they doing things they shouldn't be doing? Are they making suspicious calls to the operating system? Is it trying to get into files that it shouldn't be getting into?

Now, there are ways to hide things from these automated systems. In fact, obfuscation seems to be the norm when it comes to any program or programming anything. It's just absolutely amazing. It does look for code signing issues and then it's designed to return the results to the developer very quickly and say, okay, it's all set. It is signed. You are ready to go. Then they can put it up for sale on the app store or available for free, et cetera. The same trick over on the Google side.

In this case, in the Google side, they've got this alphabet owned malware scanning service called virus total that looks at data from over 60 different antivirus providers to figure out, is this software malicious? Is it using any sort of malicious libraries or routines?

Now we have seen that happen, unfortunately, and it's scary because we have now found that even in the Apple app store, there have been many apps that included this library that was designed to basically steal personal information from you.

Developers would use this library and it wasn't flagged by this notarization process. Now you install it and it's not the main feature of the app, but the app is spying on you. Now, there is a new piece of software out there that they're actually not all that new. It's been around for quite a while.

It's called S H L E Y E R Schleyer and it is a Trojan that has been one of the most prolific pieces of Mac malware now for the last couple of years and it was notarized by Apple. Now, this is interesting, right? This whole notarization thing it's been in the last couple of major releases, but it snuck by.

There is if you're an Apple user, there is a piece of software there's you can put on your Mac called brew and it uses open-source software to install all kinds of features. I use many of these pieces of open-source software all of the time. And they provide functionality that does not come with the base Mac operating system. And so in the case of brew, It is verified and validated by the brew people, right?

Apple has nothing to do with this. There is another site out there called a homebrew.sh, which is a knockoff of the brew site, which is brew.sh. And the number of people were tricked into using that site, this homebrew.sh, and it apparently had fake flash updates. So it pops up and it says, Hey, you need to update.

And we've all seen that before if we have flash on our computer. you click on it and open it and install it. In fact, this Schleyer was slash is so smart. It gives you instructions on how to get around Apple's notarization checks. So in case you didn't know if you install an app on your Mac and you, first of all, you probably can't get it to install, but if you do get it to install or if you download it and you try and run it out of your downloads. If you right-click on it, you then have the option to just open it and get around the signatures from Apple.

Not good, not a good thing. So this, bottom line means that you cannot 100% trust these signed apps from Apple or from Google. Just, this is just to remember. Okay. This isn't something that any of these companies messed up recently. It's just normal. So be very careful. About what you install and it goes right back to something. I said a little earlier today, which is, do not install any software you do not absolutely need and make sure that you keep it all up to date. Some of this stuff does clickJacking. It tricks users into installing these cryptographic certificates. It decrypts and reads all of your HTTPS traffic.

So if you're going to a secure server that is using SSL, it's decrypting it. It's harvesting your user IDs, everything. Okay.

Apples goof, in this case, and they fixed it very quickly. It was reported to Apple. Apple did not figure this particular one out by themselves. So that goes right back to how important it is to have third parties out there that are looking at security, not just for Apple, but for many other pieces of software.

All right, stick around. When we come back, we're going to talk about a new little study that was done about the internet of things hardware.

Make sure you get all of this and more. My newsletter, Craig peterson.com/subscribe and stick around. Cause we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses IoT hardware and how these gaget-y devices can put your business at risk. Listen in to find out why?

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Sometimes it seems like the easier things are the tougher they are. And man is that true according to this new study we're going to talk about right now when it comes to these wonderful little appliances we have.

Hello everybody. Craig Peterson here. Thanks for joining me. I enjoy being here on the radio answering questions. I got a lot this week. I got dozens of them, so that's wonderful. Keep them coming in. I pick the best ones for what we call our newsletter. That typically goes out Saturday mornings. Again, it depends on what our weeks are like. Getting those out and I try and answer them there.

That's part of what we're going to be doing. Midweek starting next week. We're going to be sending out these little emails, a long tail thing, explaining a specific topic. Something you can read and just a few minutes and get something out of.

We want it really to be transformational. If you can do that in three minutes. We have been transforming our lives in a lot of ways. Many ways of us, of course, have been using computers for decades now. We've been using these smart devices for at least a decade. Before I had my first Android smartphone and my first iPhone, I had the Palm pilot phones and just what I could do with my Palm. It was just absolutely amazing.

Do you remember handspring and some of these other guys there are just so many wonderful things we could do with them that the Apple Newton, which never really hit it off, it was very expensive? All of these devices were designed to make our lives a little bit easier and they all required a lot of intelligence.

Now we have devices pretty much everywhere. I was going to say, come out of our ears, but that's true too. When it comes to hearing AIDS, these extremely small devices that have embedded computers, a whole computer system. Now when you're trying to manufacturer something like a light bulb that has smarts in it, it might be smart to be able to change colors. It might be smart to get on a network and accept a remote control code. It might be some smarts that are just designed to make the whole house easier. you turn on. A movie and automatically the lights in the room. Dim, the surround sound turns on. Just everything happens for you automatically.

These are all being done with these various small, hopefully, easy to use and install devices. But the problem that we've been noticing is that, wow, wait a minute. Now, none of these devices were really designed with security in mind, and in order to keep the costs down, they have to really strip those operating systems bare.

So there are versions of Linux, many of them now that are just very stripped down. The same thing's true with BSD Unixes or units are used in a lot of this internet of things, devices, and the idea is to get it small, get it simple. So that we don't have to provide them with a big computer or a bunch of computing power.

We can just do it simply. Get that information together, put it out there for the people to use. So what's that information as I said, it can be almost anything. It's about the internet of things. Now, because they have cost reduced all of these devices all the way to just out saving a fraction of a penny on each board. Remember they're making these things by the tens of thousands and ultimately by the millions and billions at least that's the plan, that's what five G is been designed to help handle. They have a whole problem when it comes to what we in the industry might call root-level access.

We've got a security researcher out there who presented over at the Octas virtual disclosure security conference last week that most of this internet of things hardware is dangerously easy to crack and completely take control of. Then they use it for malicious purposes.

The federal government has really cracked down now on anybody that's not just a direct contractor with them, but a subcontractor. We're seeing this all of the time. We're helping businesses. These enterprises that are making things, everything from a cable harness through power supplies, through control systems and control circuits. That now as of mid-August, this year, have to get rid of everything that's in their buildings that do not meet these new CMMC and other standards.

So things like the security cameras that you might have right there. Weren't they real cheap, like the Hikvision stuff, right? Heck, you could just go to any big-box retailer and buyHikvision. Hikvision is illegal to have in the building. You used to be able to separate the network. So you could say, yeah, my Hikvision security cameras on a different network than my Chinese made telephone voice over IP system, which is on a different network than my computer systems. You can't do that anymore. It has to all be gone. Why? It's because none of those systems meet the minimum security requirements.

If we go into a place that is just, for instance, we just picked up another client that's a pizza shop. They're doing really well because of the COVID thing, because people are ordering pizzas, they are being delivered to people's homes and they're just raking in the dough and they were having some problems. So they had us come in.

What was the problem? In their case, they found out that they were about to be audited by our PCI friends. PCI, that's the payment card industry folks. So if you accept credit cards, you now have PCI obligations. What are those obligations or what do you do? How do you deal with those in their case? It turned out okay. That for whatever reason, their credit cards had been stolen, the credit card information. It could have been a skimmer. We walked into and did a security audit on this chain of restaurants. Pretty big chain here in my home state. We had to poke around. I could not believe it, they had for all of the waitstaff, Android tablets. The Android tablets were all in developer mode, full access to everything on the tablet, including the card reader, that PCI non-compliant card reader. It's great for the servers because they come up, they take the order on this Android tablet, and then at the end of the meal, they just swipe the card in the side of the tablet. Wow. Isn't this just wonderful? Because of the way the software was being run and being used, anything malicious could be installed on that unit that was being carried around by the wait staff. All the wait staff had to do was put something on there that just the read the credit card numbers as they were being scanned or copied all the information from the transactions and TaDa they now have money in their pocket that happened here in my home state again and it's happening in yours.

Believe me, Wendy's is where this one was and they ended up having people go to jail over that one. This pizza shop. We went in there, they had credit cards, apparently stolen, and that's why they were getting a PCI audit. They brought us in a week before the audit was supposed to happen. We had a look and yes, indeed their equipment had been compromised. It's like I say, all of the time. We never have gone into a business and found that their security is up to date. Every machine we've looked at has had severe security problems and in every case where we've gone in and it's a government subcontractor of some sort. Every case we have found Chinese back doors and other, very malicious software on it. What does that mean to you a regular, a home person, right? Home user. What does it mean to you as an enterprise business, an organization, tax-free whatever you might be?

It means that this internet of things, hardware, whether it's things like the Hikvision cameras that can't be used anymore, legally anyways, for DOD subcontractors on any network on any piece of equipment or our voiceover IP phones that are being hacked or the pizza shop whose POS system had been hacked. What are you doing?

It's across the board for everybody? So Mark Rogers is this white-hat hacker who presented at the Okta virtual disclosure security conference. He was saying that these devices were hooking up to our networks have weak to no protections at all against attacks. Against the firmware on the devices against the software that's running on the devices, et cetera.

He claimed he's able to gain complete route access, route level access means that he can do anything he wants on the machines, including the ability to reflash firmware. In other words, put his own software on the device on 1,012 devices that he's tested.

And going back to this chain restaurant that we tried to help out and they decided no we're all set. Na-Na right fingers in the ears. We could have easily and so could their waitstaff have completely hacked any of these devices. None of them, none of it was probably protected. It's just shocking to me. It is shocking to me just continually.

The issue with all of these systems, and this is true of almost every internet of thing device out there is that most of the proprietary information about the devices, including their certificates or keys, the communication program or protocols it's stored in poorly secured flash memory.

You think of your flash memory like a hard disc drive, but there are no moving parts in it. Anyone with access to these devices, anybody with some basic knowledge of hardware hacking, even basic software hacking can access the firmware, look for data, including vulnerabilities. We've seen that happen before where security cameras are being used to launch attacks against the rest of the business and it includes DOD contractors, and it includes restaurants. We're seeing that every week.

Be very careful. I'm not getting into the details of how they're using Uart and J tag routes to get into them. But. This is a real problem, everybody.

So again, be careful the best stuff out there right now when it comes to the internet of things to smart devices, to these speakers that you can talk to is now, I'm going to sound like a broken record, but it's Apple. The Apple devices, the Apple speakers, all of that stuff tends to be more expensive, but it is well engineered and they do seriously consider security as part of all of this.

Well, there's going to be a lot more, go online, and stick around.

You're listening to Craig Peterson here and WTAG we'll be back.

After the top of the hour, we'll be talking about the Cybersquatting offense. Asking Google for phone information and more stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses Why hackers have resorted to Cybersquatting to ply their trades. Listen in to find out.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, how good are you at spelling and or typing? If you're like the rest of America, in fact, around the world, you may not be the best at either one of them. You know what the bad guys are taking advantage of that.

Hey everybody. Craig Peterson here. Thanks for joining us today. I have had a busy week as we've been answering emails, getting the new website ready to go up and it's just been absolutely crazy.

We've got more training coming out too. More training on the website and emails. We're going to be sending you these little two to three minutes to read emails. That'll keep you up to date on things. The number one thing that I hear comments on listeners is they really appreciate the little bit of learning that they get from the radio show and my appearances on the radio and everything else on with Matt in the morning on, of course, Wednesday mornings about seven 30, but that seems to be the number one thing and including the email.

I'm going to do more of it. You asked for it, you're going to get it. We're going to do more of all of that. The training, keeping it simple, helping you out. We'll be doing some, some webinars stuff. Just all the way across the board. Yeah. Because we have some serious problems out there and it's getting worse and worse. And I don't see it getting any better.

We just got news of another hack that happened. and it happened over on the Biden campaign. Man alive. It wasn't a hack-hack. What's a hack, I don't know. It's hard to say what a hack is nowadays because frankly, I count ransomware as a hack. It's something that somebody did that they weren't supposed to do, that they shouldn't have done, et cetera. That's a hack and that's what just happened to the Biden campaign.

Apparently the Kremlin hit about 200 political targets, including a key Biden campaign Alie. Apparently this hacking attempt was caught by Microsoft. Most of them are not, and they were able to gather some information about hackers. Microsoft was able to link them to the Kremlin as the most likely suspect.

And they were able to take all of that evidence and give it over to the FBI. So good for them. We had that happened last time too, remember Hillary Clinton's campaign. It happened exactly the same way for years later, Democrats again, the same way. Remember that whole thing, the DNC emails now turns out it was probably the Russian hackers that managed to get them and leaked all of those emails online ahead of the 2016 presidential election.

They really want to shake things up. Obviously they don't want Trump. Trump's been very hard on them, harder than president Biden. Would be certainly harder than President Obama ever was. Trump's been very hard in Russia and very hard on China. They just want to really stir things up in a very big way.

They apparently the Russians attempted to breach the systems at this Washington based strategy and communications firm called S K D K or S K D Knickerbocker whose been working for very hand in glove with Joe Biden's campaign, according to the daily beast. These attacks took place over the past two months. Ultimately they were unsuccessful. So that's really good news here. So maybe they did learn something from the last hack. This is the same method that was used back in 2016 to gain access to a very high, official, if you will, within the Hillary Clinton campaign.

So here we go. Apparently this firm is "well defended." So there's been no breach. We'll see how that happens.

We just had an instance this week. In fact, a company that we helped out a little bit, we moved them from just regular consumer network gear. We moved them up to some semi-professional network gear for their small business and it looks like they might actually have some contacts with the department of defense.

And DOD is very particular about your security. I hope the Biden campaign is too. Cause this wasn't directly against the Biden campaign. This was against a consulting firm that they were working with.

I want to remind everybody. These types of hacks for lack of a better term are typically phishing events. They'll send an email that looks legitimate and is a very simple plea asking for some information. In the April or March timeframes, actually, we usually see that email is going around talking about, Oh, and the W2 information, 10 99 information and pretending to be the CFO or the accountant, et cetera.

Now, this isn't the first time Microsoft has sorted the suspected Russian government hacking, and we've thrown to them many times for our clients as well, including in emails. Apparently, that's what this was. This was an email. This was a phishing email designed to try and get somebody to click on a link or answer a question.

Microsoft's saying they've identified over 120 new targets of the Kremlin's cyber spying. They have found them out apparently by suing the notorious hacker group known as Fancy bear. That's the group over there in Russia that is run out of the Kremlin. Microsoft's saying their legal actions led to the seizure of 70 command and control servers.

Now, this is where I talked again on my show here a few weeks ago. This is where your home computer comes in. This is where your small business computer or even your large business computer comes in. And that is they will compromise it. They will install some software on it that allows them to remotely control it and then use your computer to send out these phishing emails, to send out emails that have attached to them either directly or indirectly, ransomware, et cetera.

We just had a big ransomware thing just this week as well. I don't know if you heard about this one. But my gosh it's just happened, but again and again, this particular one. Hit this massive a company called Equinix, I should say. Equinix runs all kinds of data centers for businesses.

Now it's saying that this ransomware hit their internal systems and what it did is exactly what I've been warning you guys about. It doesn't just take a hold of your computer and encrypt all of the data. no. What this did is it grabbed the data. It could get its hands on Equinix's internal computers and sent it up to the bad guy's computer. So they now had copies of some or all of their data. And then it does the encryption trick. Now Equinix is saying that their data is centers and service offerings, including their managed services, are fully operational.

Now knock on wood. My company has never had this happen to us. but again, we're smaller. We use much better software than most companies out there.

We don't have all of the details on this, but this is a very big deal. Equinix is publicly-traded. The company traded on the NASDAQ stock exchange. It has around 8,000 employees. It just bought 13 more data centers. This is really something. And by the way, bought them for $750 million, three-quarters of a billion. So this is a big company and it happens to them. It can happen to you.

I started all of this out by asking if you were a good speller and how good a typer you are? There's another way the bad guys get to you. We've been talking right now about phishing and phishing sites.

We were talking about how phishing is being used to get you to go to a website. oftentimes that URL that you're going to will look almost legitimate. It might be instead of microsoft.com, it might be Microsoft dot something else, or it might be a misspelling or a common typo for the URL for that website that you're trying to go to.

Apple, PayPal, banks are being targeted by cyber squatters. Now they're taking advantage of the pandemic according to a study that just came out. In a single month, cybersquatters have registered almost 14,000 domain names. More than half of them went on to host malicious software. That is a very big deal.

That's according to Palo Alto networks, and that is being quoted in Dark Reading. But what these cybersquatters are up to is that they put up a website that has a URL that's very similar to a legitimate URL out there. When you go there, they are going to try and trick you into doing something. Now, the study says that basically 55% of these Cybersquatter domains are malicious or potentially fraudulent.

So it's not like somebody buying a domain saying, I'm going to, I'm going to buy it, Apple tart, because people type that in by accident when they're trying to go to Apple and maybe I can get Apple to buy it from me, or maybe I can use it as a parody site, et cetera. No. they are leading to malicious content more than 70% of the time.

So be very careful about the brand. A good example that they've done that has been shut down recently is secure dash Wells Fargo. This is a domain using the Wells Fargo brand, targeting the bank's customers and getting them to click through and use phishing to steal sensitive information. Be very careful when you're out there typing things in or clicking on links, because many of them, it turns out 50-55% of them are malicious and 70% of them are trying to fake you into giving up your own personal information.

Hey coming back. We've got a very interesting little article by Timothy Lee here in ARS Technica about a court order against the feds and local police departments. So we'll tell you about that. When we get back.

Stick around, you're listening to Craig Peterson right here on WGAN and Wednesday mornings at seven 30 with Matt.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses geofence warrants and why they are so popular with law enforcement investigators. Has the court seen enough? Listen in to find out.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Welcome back everybody. The fed had been out there using stingrays and other devices to watch where you're at. We're going to talk about that right now, and a new core ruling against the feds for some of the stuff they've been doing to spy.

We're not just talking about spying on the bad guys. This isn't a FISA court thing. This is in fact, the feds taking the lazy way out. So think about you. If you were a police officer trying to investigate a crime, what's the easiest way for you to figure out who was in the area when a bank was robbed?

Okay. I'm going to give you one second. What's the easiest way. it turns out that apparently the easiest way is to just send a letter to Google asking them for information about every phone within a 100-meter radius of where a suspected crime occurred.

Now, isn't that an interesting thing, right? Isn't that an interesting way to do it?

You might say, I've got an iPhone I don't have Google. So they're not going to be able to give that information to the fed. Do you have any Google apps on your phone that might be keeping track of your location? Things like, oh, I don't know. Google maps for instance.

That could be a bit of a problem because federal courts in the Chicago area have now rejected government warrant applications three times. The government has applied for a warrant to force Google to produce a list of smartphones that were near a couple of places where the feds thought that crimes might have occurred, during the specified 45-minute intervals.

Now, this recent ruling was handed down just last week and was recently made public and ARS Technica is talking about this. Now the numbers are frankly, striking here because these decisions really haven't significant impact. Google has reported. The growth in the law enforcement use of what are being called geo-fence searches.

Are you familiar with geofencing? On your Android or your iPhone you can say, Hey, I'm on my to-do list here. I got a pickup toilet paper when I get near the grocery store because we all know there's no toilet paper in grocery stores. So when you drive by the grocery store, you can have a little, geofence set up on your phone that says, Hey, remember you got to get toilet paper. Then you can run to the grocery store, pick up your toilet paper, and be on your way.

Geo-fencing when we're talking about these types of searches means a little bit different, but almost the same. That is Google gets or Apple gets a demand from the police, a warrant, that says, tell me about every phone that was within again, a hundred meters, 300 feet of this business of this area during this 45 minute period.

Now, what we're seeing here is a 1500% increase in these types of warrants between 2017 and 2018. And then it jumped up again. Another 600%. percentages don't mean much unless you have the raw numbers. Let me give you the raw numbers. Google says that they received 180 geofence search requests a week.

During 2019, that kinda adds up. At least I think it adds up. So let me see 180 a week. And let's just say there are 52 weeks in a year. Oh my gosh. That's almost 10,000 of these warrants that Google has to respond to every day. And if we say 180 a week and we divided by, Oh, I don't know. let's say the police work seven days a week.

That means 25 warrants per day, almost 26 warrants per day. So that's a couple of full-time people just to respond to these. Of course, it also has to go over to the legal side and everything else. It gets to be a real problem. Google is a very popular target for these warns because almost everyone uses Google products in one way or another.

Think of our cars, how many of our cars have Android in them? How many of them are using Google maps? How many of our cars have GPS on them? All of that is being tracked by Google. Yes, indeed. Android controls a majority of the smartphone market right now. As I mentioned earlier, even those of us who have I-phones might be using Gmail or Google maps.

So this is going to be an ongoing problem. I think it needs to be solved at a bit of a higher level than just district courts in various States out there. now for years, the. Police have gone after the cell phone companies to ask where a phone was that the whole idea of a tower location. What will happen is, am I trying to triangulate you more frequently? However, all of the phone companies will have is just data that you were connected to this cell tower, which means you, it was probably the closest cell tower to you because that's the idea, right? You'll hop between the South towers, depending on which one is the strongest. This is a kind of a Dragnet approach. Something I do not approve of and many courts don't approve of just because it makes it easier for the police doesn't mean it's constitutional. In one case last year, Google was required to hand over information on almost 1500 users to federal investigators, working on a Wisconsin arson case.

We've also seen. Cases where a guy was running his bicycle back and forth on this back street. Not like he was right in front of one house, but he got nailed because he was on that street at the wrong time. Although ultimately they figured out he had nothing to do with the crime, so they just turned his life upside down.

So we'll see what happens. This Chicago case apparently is being, appealed, and if the appeal goes through, it could place new limits on these broad government data requests, which I think is ultimately a pretty good deal. By the way, what were they investigating? it turns out they're investigating a case where there were stolen pharmaceuticals, apparently sold on the black market and investigators believe that the bad guys stole the pharmaceuticals from this drug store or a clinic, and then traveled to another one to ship them to customers like a FedEx or ups stores. So to help them investigate, the suspect, the investigators asked Google for data about every smartphone that was near either this drug store or the medical clinic or FedEx or ups during a particular 45-minute window, one window, the first location, two windows on different days of the second. So the application was rejected. It was said to be too broad. The government narrowed its request too much narrower areas right around the buildings, but the courts rejected them all.

The court said none of them complied with the Fourth Amendment's requirement that warrant particularly described the persons or things to be seized. Interesting. Very interesting. I know. What do you think about this? these all persons warrants are generally considered to be unconstitutional that's part of the reason we have the fourth amendment because the King was issuing these very vague big in the general warrant, the gave his military officers, governors and others, the ability to just go in and harass anybody they basically wanted to. So I tend to agree with the courts on this one. Sometimes, I disagree sometimes I agree, but then, in order to really justify this kind of a geo-fence search the government, according to this judge needs to show that everyone in the geofenced areas likely to be involved in the crime.

So how does this work when we're talking about these domestic terrorists that are burning down, buildings, cars dragging people from cars, beating them. Are we going to see these types of cases, as well as the geofence? Ultimately we will see. But again, it's another reason.

Not only do the bad guys have apps that are attracting you. And I talk about those a lot, but the good guys are too. And. They might just upturn your life for what turns out to be not particularly good reason and something that's probably against the fourth amendment.

Alright. When we come back, we're going to talk about a business problem right now, and that has to do with it. Security person, now there's a huge shortage, but what's the cost. When you lose the security person, you're listening to Craig Peterson, WGAN.

Stick around. Cause we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses Why you need to try to keep your Cybersecurity Talent and what it can cost you if you lose them.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Let's see there's Sue. There is Guy. There are Mary and a couple of other people. I can't remember everyone's names right now, but they are all listeners to the show and they have all changed careers. Here's what's going on.

Hey, if you enjoy my show here on WGAN and online@craigpeterson.com, you might want to think about a career in cybersecurity. Now, there are a lot of people who have already started that whole career path, who can start pretty simply. And it's really one of these careers as Guy had told me that you feel like an imposter, right? Imposter syndrome. Runs rampant, particularly when you're first starting.

I've been doing cybersecurity for many decades now. And I can tell you, I still feel like an imposter at times, so it's pretty normal, but there are a lot of jobs out there in the cybersecurity career path that is open right now. Everything from just starting out, just barely, Hey, I am a brand new guy, gal, and I want to do cybersecurity all the way on, up through CISOs, and all of that sort of stuff.

So you might know already, my company is a managed security services provider. That's what we specialize in. We're not a company that goes out and tweaks your computer so that, a hard drive that's failing, just doesn't fail anymore. Although we do that for some of our customers.

We emphasize and focus on cybersecurity. We're looking at some of these stats we're seeing anywhere from a half-familiar and open jobs in 2020 in cybersecurity, all the way on, up through one and a half million open jobs. And I've seen estimates as high as two and a half to 3 million people needed brand new people never been in cybersecurity before. Two and a half to 3 million new people here in the US that will be needed in cybersecurity by 2025. So a half a million right now, that ain't bad is it.

Now I want to warn everybody that is in business and is looking for a cybersecurity person that you do need to have at least one person who is extremely well versed in cybersecurity and that means they've got to have a minimum of five years on the job, cybersecurity experience. The future of your enterprise is entirely dependent on them believe it or not. There are so many businesses that are being hacked one way or the other, and you cannot skimp on this. Can't skimp on it at all.

I'm looking at it web page that just bothers me. This is a story here from the Freelance Star in Fredericksburg, Maryland, and this is September 7th, 2020. Stafford based cyber bytes foundation to offer a one-week cybersecurity certification course. Yeah. So if you live there in Maryland, back there by Joe Biden, wherever he lives now, and you want to be a cybersecurity professional, all you have to do is take this one-week certificate course and you too can be a cybersecurity expert, right?

They're saying in this article that if considering a career in cybersecurity, you will be one week away from certification will prepare you for an entry-level position in the field. I've thought for a long time, I should be teaching some courses to people who want to really understand cybersecurity.

Cause I can bet you anything that the poor people that are teaching this course are not true experts. I can also guarantee you that after having a whole week of experience in the classroom, you're not fit to do much in the cybersecurity business. You can probably turn on a computer and follow some basic instructions. That's it?

I'm thinking about these people that are listeners to the show that have gone into cybersecurity. Most of them have done about six months didn't give or take in cybersecurity courses and they come out and really in six months of just intensive, all you're doing a cybersecurity training.

You realize that you don't know enough. Okay. But at least they realize that after one week. I'm not sure people realize that they really don't know what they're doing. This is starting out here in two initial courses is gonna prepare you for the CompTIA security plus exam that tells you just how extensive that exam isn't.

Of course, there's a cost just under a thousand dollars. They're approved and certified by the state council of higher education.

It's just, wow. Wow, incredible.

So I brought all of that up because. This article that I have up on my website and was in this week's newsletter is talking about the hidden costs of losing security talent.

We've got to be careful as business people because we are losing talent. We're not respecting them. We're not paying them enough or we're giving them too much to do. Too many businesses look at cybersecurity as a cost center. They don't realize that it's not just a cost center. It's critical. It's essential for their business.

And if they market correctly, frankly, It is a big plus on the marketing and sales side. How many of your competitors we're actually doing what they should be doing? So the cybersecurity talent is going to cost you money. You've got to provide them with the training you, my guys, my cybersecurity people spend about a third of their time, a third one-third of their time, not being productive, but actually attending courses, doing red team blue team exercises.

Okay, this is not something you can really skimp on. In fact, you cannot do it yourself. I have seen the hard numbers. You cannot do cybersecurity as a business with less than about 500 employees. Can't do it adequately. You just can't. You can't get the right people. They don't have the right training. They can't afford to do what they need to do. Okay.

So keep that in mind. Now you can have a managed security services company come in. Be careful, make sure they don't just have the one week certificate or the CompTIA security plus make sure they know what they're doing.

But replacing an experienced security analyst where they're looking for an annual salary of a hundred thousand dollars, that's just salary plus load on top of that. And remember, 30% of the time, a third of the time they are going to be in class if they're doing things right. When they leave that company, it typically takes eight months to replace them and almost four months to train a replacement. So that's about a year. A full year of lost productivity. It's always possible that your company could lose a second person during that time as well. So be very careful, a bad hire. According to the US department of labor is going to cost at least 30% of the employees.

First-year earnings for a security analyst, frankly, we're talking about costing you 50 to a hundred thousand. If you don't get hacked, in the interim. At which point you could lose the whole business. It's very big. It's a very big problem. So keep in mind everybody, when you're looking at this, first of all, I think it's a great career path.

If you like a challenge. If you like things that are different. If you are not really big into just messing around but you really want to learn things and do things. Cybersecurity, I think is a great way to go, but it's continual learning.

You've got to keep on top of this. It is more than a full-time job.

All right. When we get back, we are going to hit a couple more articles from my newsletter week and, that's kinda it. I think this week's show.

So you'll find me online, of course, Craig peterson.com. You're listening to me on WGAN. We'll be back on Wednesday morning. I am every Wednesday during drive time with Matt Gagnon.

We have little fun with this, and we're going to be talking about cybersecurity on your back to school lists and tips for triaging risks. If your credentials are exposed, I'm going to give you a website that you have to go to see if your data has been stolen and leaked on the dark web. I'll give you that URL and a whole lot more when we get back.

So stick around, we'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses Why Cybersecurity is important and a must-not-forget item for your Back to School preparations. Listen in to find out.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

Don’t forget Cybersecurity on Your Back-to-School List

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, it's back to school time. We're going to talk about cybersecurity on the back to school list for parents, for children, and for school administrators. And then what do you do if your credentials have been exposed online?

Hey everybody, Craig Peterson here. WGAN and online, of course, Craig peterson.com. You will find all kinds of great information there. We've got a new website, we've got a whole bunch of stuff coming up here. So keep an eye out for that. I think you're going to really like it. So let's get into cybersecurity.

Now we're going back to school. Our kids are back at school. We're probably working from home, right now that's a majority of people in the United States that aren't in, manufacturing jobs or hands-on jobs. That is a very big deal and it means some potentially bad things as well. So what are those bad things potentially that I'm talking about?

If we have computers in our homes and we have kids on those computers and those kids are going. Who knows where online, including to the school and a parent is at home. And that computer's on the same day network is a kid's computer. You're in trouble. I've talked many times before about how these hacks and hackers bread, when it comes to a company, how they spread in your home, and what they do is.

Kind of think of it like the military, they get a beachhead. So they attack and they have now a footing inside the network and then they start spreading laterally. So if your kid's computer does not have the advanced malware protection on it, that it needs, if it's not configured properly, if that kid's installing software on it and that software gets out or is hacked or is a hack, to begin with.

That computer can now be used to spread malware onto your computer. So whether you using a computer from the office at home, or maybe you are using your home computer. At home, the bad guys are now in your network and now start to spread within your network. Now think of that, multiplied out. Even further, kids are bringing computers into school.

If you go into school one or two days a week. You probably never brought a computer into school before because the kids who were there five days a week. But now they're there one or two days a week and they bring the computer in so they can show the homework so they can get some assignments. Now things are spreading.

Do you think that the Wuhan virus spreads like crazy? what do you think happens when a child or a teacher brings an infected computer into a school while it's going to spread like wildfire? And what do you think happens when you have an infected computer on your network at home? it's going to try and spread like wildfire and it probably can, if you're not doing all of the right things now, as I said in the last segment, I should probably do some more courses on this, but that's part of what we're aiming at here to really help you guys out.

Yeah, that gets to be a problem. Doesn't it? It's spreading. So if it spreads onto the computer you're using from work, and let's say that you've made the mistake of using a VPN into the office and that's not properly firewalled at the office or on your computer. That mistake that VPN mistake could cost you dearly because now you are spreading that malware or you're allowing the hacker access by piggybacking on your computer, into the business.

Now, I know that might sound complicated, but it is very easy to do. And the bad you guys have tools that they can buy for as little as 10 to $20 on the black market, it allowed them to do everything I just described very easily. So if you are a school administrator, You need cybersecurity. It drives me crazy.

I was on a zoom call earlier in the week and the only thing they use is zoom. I had to explain to them, Hey, I have clients that are. DOD subcontractors. They sell stuff to military installations. They sell stuff that used by DOD contractors. Therefore, I can not use zoom because Zoom is not secure. The same thing's true when we're talking about using zoom in schools and in regular businesses. We cannot use it. Schools have seen an increase in these debilitating ransomware attacks, even with the FBI alert this summer about it going on. I remember the first time I was speaking at an insurance conference and I was up there.

I was their keynote speaker and talking about the problems that we were seeing in business and in schools. With these ransomware attacks. And afterward, one of the attendees came up and told me about his entire school district had been hit with ransomware. What do you think's going to happen when somebody brings a laptop into school, or somebody brings that laptop from home into work or they're using VPNs. VPNs are providing a network, a path for that ransomware to spread and it spread to wherever it can. It'll spread onto your file servers, spreads high and low across everything.

So be very careful. Okay. major problems with the remote desktop protocol. RDP from Microsoft, that I know a lot of you guys are using to connect to work, make sure it's patched up.

Slap yourself on the back of the hand for using RDP, especially if it's exposed to the internet, the same thing with a VPN. So we're going to do training on this. I'm going to help you guys understand it. I don't want you to feel bad about this. Okay. Cause you just didn't know.

The vendors are lying to you. Okay. you're using this stuff that you shouldn't be using because they're telling you should be using it. I was flabbergasted this week. I got an email from a security vendor that sells security hardware and software, and they said, the only thing you need is our one product. Which is not even close to being true.

What do you do right? I can tell you what I do. I let you guys know about it. Okay. So we're going to be doing a lot of training on that starting next week. So I'll make sure you are on my newsletter list. Newsletter members are the ones that are going to be getting this information, and it's going to be short.

You can read it and just a few minutes and it's going to be educational. Okay. Important stuff now. I'm going to talk about exposed credentials. What do you do if your username, your email, address your password, maybe some personally identifiable information? Is found out there on the internet. What do you do?

We've got over 15 billion exposed credentials available online, for free? In most cases, the bank has don't have to pay for them. Did you little shadows conduct a study this year? And they found that nearly two-thirds of the credentials available on the dark and by the way, the open-source or the clear web markets duplicates and 80%, of them are in clear text format.

Many of these are employee credentials that pose a significant risk to organizations because they are in the hands of cybercriminals. So the security team needs to assess all of the things, exposed employee credentials to help make sure that everything's taken care of.

So what should you do? first of all, I want you to go to a website. I should just put this Craig Peterson so you can find it easily, but go to a website called have I been pwned? You've probably heard me say this before, but it's worth checking again. Check it frequently. Now have I been pwned dispelled, P W N E D. Have I been PW, D d.com. And you enter your email address and it'll tell you what it finds.

So I used my Craig and mainstream.net email that I've had for 30 years now. And I, I know it's been exposed and you already know, I use different passwords on every website. In fact, I tend to use. Different email addresses and there are some tricks to that. And I'll do some training on that for you guys too.

What can you do? How can you do it? But, there are some tricks so that you can really, I have one mailbox, but to have what looked to be millions, if you wanted them of different email addresses, which is very good. Have I been pwned has seen my mainstream.net email. It has been found on 12 breached webs sites and one paste.

A paste by the way is a site where they just put all of this stuff together and upload it as one big file. Basically think of it a big zip file place. And so it lists through all of these. And I went through this a couple of weeks ago here on the air, but have I been poned.com? That's where I want you guys to go.

Okay. So not all exposed usernames and passwords, present a threat. You have to look at them and figure out, okay, am I using that username? But it says on, have I been pwned as having in stolen? Am I using that anywhere else? Am I using that password anywhere else? Make sure that you have a password manager.

I like one password. That's what we use. We also use something called Thycotic, but I also am really pretty happy now with the latest versions of LastPass. So look up LastPass as well. So use a password manager, always generate new passwords. let's see the same stolen leaked employee credentials. Keep on surfacing online.

Have I been pwned is going to help you with some of that stuff. You got to get rid of all of that weed out. All of those duplicates, make sure the credentials are genuine and then go to those websites. Go ahead and change them. And use one password use last pass. It's very important to do all of that stuff.

And then on an ongoing basis, make sure you monitor for stolen or elite credentials. So that means if you can go ahead and on, have I been pwned again, PWNED dot com on, notify me, put in your email address, it's going to send you a confirmation email. Once you've confirmed. It'll email you, anytime it find your email on any new hacks out on the dark web.

All right, everybody, have a great weekend. Make sure that you are on my list. Cause we're starting this up this week, little kind of micro training, and we're going to do other pieces of training as well, but there's only one way to find out about it and that's to be on my newsletter list. Craig peterson.com/subscribe.

Believe me. This is not going to harass you. This is going to help you learn even more. All right. Learn. And I always give you things that you can do just like to have I been pwned.

So have a great week. I will be back Wednesday, with Matt, at seven 30 in the morning.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Good morning, everybody. WTAG experienced some issues which prevented me from joining Jim on Tuesday. But this morning he reached out and had me on. Jim and I discussed The Internet of Things and why Businesses must be careful when they are attaching all these cool gadgets to their networks. Then we got into the WordPress Vulnerability that is hitting business websites hard. Then Jim asked about Apps and China. Here we go with Jim.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson (2): [00:00:00] So you ask yourself, how can this app be free? Really? Whoever developed it had to put hundreds or thousands of hours into developing that app, how could they possibly afford for it to be free?

I had a bit of a surprise this morning. This is Craig Peterson.

Craig Peterson (2): [00:00:15] I got a text from Mr. Jim Polito asking if I could come on today because their board was so messed up on Tuesday, they couldn't get me on. But he really wanted me on this week. So that was fun.

We freewheeled today. Although normally we stick with the topics that I have sent him that I also include in the newsletter. We go into deep dive on my radio show on the weekend. And of course, those are podcasts as well, but it was fun. I was a little bit of a different thing today. So here we go with Mr. Jim Polito.

No week would be complete without a visit from our good friend and tech talk guru. Craig Peterson. Missed him on Tuesday.

Jim Polito: [00:00:53] Can't wrap up the week without a visit from the man. Good morning, Craig.

Craig Peterson (2): [00:00:58] Hey, Good morning. I want to correct the thing that Fake Bernie said this morning and that is Connecticut river is entirely a New Hampshire. Vermont doesn't even have a border on the river, let alone the ocean.

Jim Polito: [00:01:14] I thought they had.

Craig Peterson (2): [00:01:15] Did you realize that?

Jim Polito: [00:01:15] No. No. So the state line is on the other side of the river.

Craig Peterson (2): [00:01:21] It is. It came from years ago. It was an order in council signed by King George, the third back in 1764 because remember Vermont was part of New Hampshire. And then yeah, New York, in fact, we've even got ski Hills that tried to re-annex themselves a few years ago to New Hampshire, tired of all of the taxes and everything.

But, yeah, so what had happened is that New York said, No No Vermont is ours. Then so King George says, okay, I'm going to settle this. So he established the border between New Hampshire and Vermont. It could be the Western bank of the Connecticut River and then the US Supreme court in 1933, upheld that.

So normally when you go across a bridge, I don't know if you've noticed, but usually in the middle it says, you're now doomed during the state of, whatever it might be, where Joe Biden might be from this week. But, when you're going from, Vermont, New Hampshire to Vermont, you don't see the sign until you hit the ground on the Vermont side.

Jim Polito: [00:02:22] Hey, you're right. I was Chesterfield New Hampshire over the weekend and I went and did the bridge there. There's the old bridge right next to the new one. And cause they never knocked down the old one. You're right, you get over the bridge, you come to the rotary, but there's the sign before you get into the rotary. Welcome to Vermont.

Craig Peterson (2): [00:02:42] Yeah. Yeah, exactly. I don't know if that's like the only one, but it's really weird. A little bit of history actually knew. How's that for strange?

Jim Polito: [00:02:50] No, that's why you're the man. And, and King George, the third, how do you like that coming up with the idea? No, it's on the banks of Connecticut.

Back in those days, The Connecticut River used to flood and break its banks. Oh, the Vermont border was a moving target. all right. I want to talk about some of the stuff that you, gave us today, but what is top of mind for Craig Peterson right now? By this top of the most brilliant man in tech wake up on Thursday morning, which is not typical for him.

What does he wake up and say, but that other people won't understand by the way?

Craig Peterson (2): [00:03:29] Oh, okay. details. so yeah, the big thing, and I'm going to talk about this on my show on Saturday here, but the big thing that has to do with the internet of things, hardware, again. Now we're talking about all of these lights that we have that may be voice-activated, and now it's everything.

If you're a business, I can't tell you how many businesses I've walked into that have. These hick vision cameras on the wall, security cameras. They've got automatically lights that come on when entering rooms, et cetera. So there is a little bit of a study that was just conducted and they found that about 85% of the devices that were tested could and be completely 100% hacked.

It's called complete root access on these devices. This is a real problem because we're making these IoT devices, the internet of things. They've got to be small. They have to be cheap. At least we want them to be cheap. So what they do is just cost reduce cost reduce, cost reduce, and what you end up with is a little computer.

It has to be a computer inside that can talk to, of course, your wi-fi in order to send its messages. And they just leave out all concepts of security, frankly. They come pre-configured with default usernames and passwords. These things come also with the ability to be completely hacked because they cannot get updates, so many of them. They never get re flashed. In fact, this particular investigation showed that they could be completely re-flashed by hackers. So we're surrounding ourselves with all of this wonderful equipment, all of this really cool stuff. At the same time, we're exposing ourselves and we're exposing our businesses to some of the worst hacks that have ever been going on, and frankly, that's a huge problem. I'm going to talk about that one this weekend. And similar to that, I gotta bring up one more thing while I'm on my soapbox. And that is, we know we're supposed to update our computers, right? And so you go ahead and you update windows, you're reluctant to do it. Cause is it going to break. What's going to happen.

If you're on a Mac, it just happens for you automatically and it's extremely rare that anything breaks or an iPhone. Android, of course, you got the problems and trying to do updates.

The biggest problem we're finding right now is that people think that they have turned on automatic updates and they're safe. Without thinking about the dozens of other apps or programs that they have on their computer that need to be updated. To a business 99% of the time they say, yeah, we're 99% patched up. we're fine. But then you dig into it at all, then you find out, they haven't updated flash. Oh, they haven't updated their web browsers. Oh, they've got all of these plugins, these extensions on the web browser that are known to be major security hazards.

So my whole message this weekend and this morning are, Yes, you've got to patch up and right now. Over 350,000 websites out there that are hosted, that are run on WordPress, which is most business websites have a critical flaw, critical, and we've seen before where ISIS goes ahead and they hack one of our websites, Jim, and then they have uploaded videos of the beheading of Americans and American soldiers onto and attacks against the soldiers to onto our business website. Then they share that with all of their friends and it's unbeknownst to you sometimes. They just hide it and they're using it for touch and go places. The bad guys are using it for child pornography.

They're using them for attacking other websites. They are putting in skimmers, just like ATM skimmers that we've seen before, right into the website checkout pages.

So that's my big thing today and I'm going to be talking about it more on Saturday. It's terrible.

Jim Polito: [00:07:47] We're talking with Craig Peterson, our good friend, our tech talk guru, and some of the concerns, Craig, I'm going to call an audible.

I have the list of stuff that you brought to us, but something came up personally for me yesterday. I wanted to do a reverse image lookup. I wanted to find the origin of a picture. And, there's a lot of different ways you can do that. But one of the ways that your smartphone will steer you toward is getting an app to do that, and of course, I'm on Apple.

Here's my question. I started looking at all the PR of course, I don't want to pay for it. I want a free app. And I started looking at all the free apps available to do a reverse image lookup. Now, for those of you who don't know, here's a reverse image. Look up. you take a picture that you have, you put it into an app and the app tells you the other places on the internet that they can find it.

So I, I did that, but I'm looking at all these apps. Then for some reason popped up on my phone who created the app and there were, and this isn't certainly a racist thing, but there was a lot of what appears here to me to be Chinese names. I said, okay, this could be someone in the United States, who's from China. Or could these all be Chinese apps from China?

So my question was how good of a cop is Apple when it comes to allowing its apps in the Apple app store. Cause I thought to myself, wait a minute. If Apple is offering it's gotta be safe. Am I being naive?

Craig Peterson (2): [00:09:32] No, you are not a few things that come out over the last few weeks. One is there is a library that a lot of application developers are using that tracks you and your data and the application developers are paid for it.

So you ask yourself, how can this app be free? Really? Whoever developed it had to put hundreds or thousands of hours into developing that app. How could they possibly afford for it to be free? So the big problem over the last few weeks was, Oh my gosh, there's this the library that app developers are using for Apple and for Android that they're getting paid to include in their app and Apple wasn't noticing it.

Then there's another problem app and requires apps to be signed on your Mac as well as your iPhone and there are ways around that. It was also found out that Apple had, this is just the last week, approved some malware to run on Mac. Now this is unbeknownst to Apple and we have to step back a little bit, and look this isn't just Apple this is Google as well. Although Apple historically has done a better job. But in both cases on the app store from Apple and the Google play store, they use software to scan the apps, to look for potential malicious stuff. They've done an okay job over the years.

That's part of the reason Apple gets 30% of any proceeds from apps that are on there.

Jim Polito: [00:11:07] Yeah

Craig Peterson (2): [00:11:07] You brought up China. China has been flooding both app stores. Then, of course, socialist government over there wanting to get our information because once your socialist, you've squashed most, if not all innovation. So the only way you can grow is to steal it from other people that aren't socialist.

Jim Polito: [00:11:27] It's true. it's true.

Craig Peterson (2): [00:11:28] Yeah, absolutely true. And so they've been very, It's strong or, front line thinking here on getting apps into the app stores that can leak data. Because again, they just need a little bit of data from this app. Maybe a little bit of data from that app. Get your contacts from this app, pull them all together. And now they've got a very good picture of you. Who do you work for? Where do you live? What kind of data might you have access to? Then they're using that to go spearfishing. So to answer your question, Apple does a, quite good job of vetting the apps.

Google does a good job on betting the apps. But there are many ways to obscure the code and frankly, Yeah. Having written all articles over the years and worked on a lot of different people's code, I can tell you that obfuscation seems to be the middle of the name of every programmer are known to demand, where are it's impossible to try and figure out what they're doing sometimes takes a while.

So I can't blame Apple and Google for letting some of that, this stuff into the store, but they're pretty careful about it, but this thing twice, Why is the app free? Why is the app cheap? What else are they getting out of me?

Jim Polito: [00:12:43] Let me just ask you a quick question and then, Oh, go ahead. Go ahead.

Craig Peterson (2): [00:12:47] No, I was going to say when it comes to reverse image this is a great tip for everybody that's listening. If you are in the dating realm or your kids or grandkids or whatever it might be, or out there dating. Google regular Google search has an image search on it. One of the best things you can do is take that photo that you found on the dating site and run it through the Google reverse image search and see if it's a stock photo or if it's just someone else.

Because so many of our seniors as well, they're not dating, but they're, the reaching out, some of them are lonely and you've got to make sure that this person is legit. And what Jim did with the reverse image search, just use Google. It is a wonderful idea

Jim Polito: [00:13:32] See, learn from my mistakes. Excellent.

Phil, I have since deleted the app, but who knows, there's probably code somewhere in my phone right now, from the Chinese and, and they know I'm friendly with you. So I'm I'm the enemy.

How can folks get in touch with you?

Craig Peterson (2): [00:13:50] Why don't you check out my website? I've got a new one going up here either this weekend or next week at Craig peterson.com.

You can get my newsletter. You can get all of the articles and background that I talked about here on Saturdays at 11. You can also of course digging a little bit more. Ask me questions, all of that. Just Craigpeterson.com.

Jim Polito: [00:14:13] Craig. Thank you. 11 o'clock Saturday. Be listening. Thank you, sir, for doing the extra duty this week and we'll catch up with you next week.

Craig Peterson (2): [00:14:22] All right. Take care. It was fun.

Jim Polito: [00:14:24] It was fun. Hey, when we return a very important thing you want to back the blue, I'll tell you how it's my final word. You're listening to the Jim Polito show your safe space.

Craig Peterson (2): [00:14:35] And safe it was. Take care, everybody.

We'll be back this weekend. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Good morning everybody!

I was on with Matt this morning and we began with talking about how to protect your kids when they are on the internet doing their school work and I gave a tip that will really help you. Then we discussed a Wordpress vulnerability and Apple's newest iOS update. Let's get into my conversation with Matt on WGAN.

These and more tech tips, news, and updates visit - CraigPeterson.com

---

Automated Machine Generated Transcript:

Craig Peterson: [00:00:00] That will stop your kids from going to no malicious sites and some of the darker corners of the internet. Absolutely free. Check it out.

Good morning, everybody. Craig Peterson here, and that was me with Mr. Matt this morning. It's been one of those interesting weeks. Monday of course, was a holiday.

So I wasn't on the air. Tuesday, there was a problem with the board over at the next radio station that I'm normally on Tuesday mornings. WTAG would Jim Polito and this morning it all seemed to go all right. So here we go with Matt.

Matt Gagnon: [00:00:38] It's seven 36 on the WGAN and morning news on Wednesday morning, which means Craig Peterson joins us as he always does at this time.

Craig, how are you?

Craig Peterson: [00:00:46] Hey, good morning.

Matt Gagnon: [00:00:48] Doing all right. Thanks for asking

Craig Peterson: [00:00:49] Confusing stuff, elections, and everything. My gosh,

Matt Gagnon: [00:00:53] Indeed. So Craig let's get right into things here. Lots of topics to go into, but, cybersecurity and going back to school would be, I think, topical for us here to begin with, because of course, as I'm sure, most people in Maine were going back to school as of yesterday, whether they were physically going back to school or if it was remote, they were going back to school.

So why should cybersecurity be on your back school list?

Craig Peterson: [00:01:16] it's important because frankly, our kids are now being exposed to who knows what, when they're online. So the basics are your child is going online. Hopefully, they're just going to the school site. But how many of us are monitoring our kids very closely. The bottom line is they're not.

And then, on the second side of this, we've got the schools themselves who are terribly overloaded and those poor school workers who are trying to do the, IT now has to protect all of the school systems from ultimately all of this malware that's coming in. From the students' computers that are hooked up to the school, depending on how this is working.

So think about it for just a sec, your kids might be writing a paper and sending in maybe a word doc. We already know about problems with word docs and cybersecurity, where the macros that can be in some of those word docs. Can be misused. Then that gets sent into the teacher whose computers now infected.

It may be stored on a server at the school that's now infecting more and more kids. So we've gotta be careful on both sides here, both the school and the parents.

I have a quick piece of advice. There's some software out there you can get it free, or you can pay for it. I advise you to pay for it. A very inexpensive it's called Umbrella.

Again, it's by Cisco, a very good in stopping some of the ransomware spread and you can get a version of Umbrella, right there, free from their website that will stop your kids from going to no malicious sites and some of the darker corners of the internet. Absolutely free. Check it out. It's called Cisco Umbrella.

Matt Gagnon: [00:03:04] There are many dark corners of the internet, Craig Peterson, our tech guru joins us at this time as he does every Wednesday.

Craig, I am a, on the side, an amateur WordPress developer. I noticed in the number of things that you had to talk about here today, that one of those things was that there was a gigantic security flaw in WordPress sites. About 350,000 of them have been affected in some fashion. What's up with this?

Craig Peterson: [00:03:28] Yeah, this is a very, again, very big call for people to pay attention. We know we've got to update our laptops, our phones, even. Although sometimes you can't get updates on some of the older pieces of equipment, which I respond to that. Hey, get the newer pieces of equipment, if you can't get updates.

When you're talking about WordPress, this is software that used to manage the content on your website. Most smaller companies use WordPress as the basis for their website. So the big question is when was the last time. You did an update on your WordPress site because again, it's software, it needs to be updated.

There's a package that you're referring to here called file manager, which is a plugin. It advances, it augments the features. WordPress has. It has a huge vulnerability in it and people just have not been updating.

Now in the WordPress side, there are some plugins that you can get that will automatically update your website for you and update your plugins for you. I use those all the time. worth looking into. Depending on where your WordPress site is hosted, some hosting facilities will do some updates to your WordPress site, most of them are afraid of breaking your site.

Personally, I use WP-engine. Is the name of the site for hosting some of my WordPress sites, just the basic ones. They do keep it up to date. They've got great tech support. They cost a little bit more. In fact, it's a lot more.

Matt Gagnon: [00:05:09] Yea they do.

Craig Peterson: [00:05:10] Have a look at those. At the very least use one of these free plugins that will do updates for you automatically.

Matt Gagnon: [00:05:17] Finally Craig, before I let you go, I do also want to bring up the new iOS update because we're living in a pandemic world and the new update has a system apparently inside of it that helps to fight against the pandemic a little bit in some fashion. What does that actually entail?

Craig Peterson: [00:05:32] Yea, this was not expected, frankly, here?

This is the new release of iOS. In fact, there is a little battle going on over the new. Releases that are coming out as well. We've got Facebook fighting back on it. There was this plan that we talked about Matt, where Apple and Google had a pandemic tracker who you've come in contact with. Well, Apple included it in the latest version of iOS as 13.7.

People are a little bit concerned about it, but Apple does have it set up in such a way that it's not squealing or reporting on you. It does allow you to participate if you want to. It will prompt you to opt-in, to receive notifications. If this contract tracing data shows that you may have been exposed.

So it's up to you. You can use it, or not use it, but it wasn't a surprise. We knew they were working on it, but we didn't know. That they were about to release it.

Matt Gagnon: [00:06:32] Craig Peterson our tech guru. He joins us at this time every Wednesday to go over the world of technology. Of course, you can hear more details about this on his show, which has heard on this very station on Saturdays

Craig, we appreciate you joining us as always. And we'll talk to you again next week

Craig Peterson: [00:06:45] Hey take care of Matt. Thanks.

Matt Gagnon: [00:06:47] You bet. Thanks a lot.

Craig Peterson: [00:06:48] Hey everybody starting next week, we are planning to have some major changes up on the website, a new type of email. We're going to be sending out a couple of midweek emails with long-tail stuff. n other words, some information you need to know. Just reminding you, letting you know what's new that you can read in two or three minutes, just trying to keep this simple for everybody and keep everybody up to date.

So keep an eye out for that. Everybody who has subscribed to my email list over at craigpeterson.com will be getting those.

So have a great rest of the week and we'll be back on Saturday. Take care, everybody. Bye-bye.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig discusses Elon Musks companies but specifically, the promising news about his Neuralink program has for those who are "locked-on" or confined to a wheelchair as a quadriplegic. Listen in to find out.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Musk says that Neuralink implants are close to ready for human testing

Is China the World’s Greatest Cyber Power?

**Russian tourist offered employees $1 million to cripple Tesla with malware**

Ransomware Red Flags: 7 Signs You’re About to Get Hit

**IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo**

Apple won’t let Facebook tell users about 30% Apple tax on events

**Tesla with Autopilot hits cop car - driver admits he was watching a movie**

iOS 14 Privacy settings will tank ad targeting business, Facebook warns

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We're going to be getting into Apple and their 30% tax or so they're calling it. We're also going to talk about the seven signs that you are about to get hit with ransomware. What can we do about it? Interesting article

chorus. This is Craig Peterson. So glad to have you here. You listening to me on WGAN. Of course, you can hear me also. Every Wednesday morning when I'm on with Mr. Matt Gagnon and we talked about the latest yeah. Things going on in the news that you need to know about and explained it in a way that nobody else does.

It's funny. You get all of these people now. Who were on the radio, a couple of really big names. They talk about things that they are paid by the advertisers to talk about. I just get shocked and maize at the promotions L except where they've got a no they're telling him they have to, Like we've explained VPNs before. How most of the time, these cheap and free VPNs actually make you. Less safe online. So I just don't get it. But anyway, I'm a tech expert. That's what I do. I've been helping businesses with cybersecurity ever since I got it. It way back in 91 was my first big internet hack.

It was actually called a worm that I got way back then and been doing it ever. I love doing it. Love helping people and I love doing training and stuff too. so glad to have you guys all here. Now I spoke this week a little bit about this on the air during the drive time., I think, yeah, this is just absolutely phenomenal.

about Elon Musk. You've got to he's out there everywhere now. You've got a boring company that you mean. I've heard of it out in LA and now in Vegas, it looks like they might be able to get something together, but this is a company. That makes holes in the ground and allows you to potentially drive at a hundred miles an hour, or ultimately what they want to do is have you going at two, three, four, or 500 miles an hour in a vacuum?

It's very cool. I saw a very neat little episode on it on Jay Leno's garage, where he drove a Tesla. Through one of these tunnels at the boring company had made out there now lay, this is a test tunnel and it was absolutely astounding how fast they were able to go and how well it all worked.

And so neat stuff there, of course, about the Tesla cars, which Jelena was driving at the time, you've heard about the rocket it's in the amazing things they have done. I saw a Falcon heavy videotape of the tape, Of them launching a craft, recovering the boots to rockets. like they all land in the back of the Cape and I also saw a hop, skip, and a jump that was done with this massive rocket.

They're going to use just sending people to Mars on it's just, yeah. He, this guy is just amazing. The things he's done. He's also got a satellite network up in space. That's going to give us access to the internet inexpensively worldwide. Very cool. Very cool. Now what I was talking about this week is something called Neurolink.

Now there have been a number of things that have been done. Recently trying to help people that are, have a disability, a physical disability. So let's say someone's leg was badly injured or our hand was removed arm. All of these types of appendages. You might've seen this for years. I remember when I was younger, the first time I saw one of these kinds of cloth things and it had a rubber band on it, and that was used to.

Close that, that kind of the hook, the claw. They could use it to pick up things, which is just a great step forward. But what they were doing is using no muscles. Sometimes I'd have a muscle attachment and then they got a little fancier and they put since sensors, for instance, in the arm and the sensors would pick up electrical signals.

So when someone was. Moving a muscle, although it muscle no longer moved a finger. For instance, like you're trying to move the index finger. That muscle would Twitch. When you tried to move the index finger, that was no longer there. The sensor picks that up and now moves that index finger that's on that mechanical hand, electromechanical hand also.

Very cool. So things to really help people out. There are a lot of people now who are completely locked in. They can't do anything. Think of Stephen Hawking as he approached the end of his life and how he was able to do some communication. He's lucky enough to be able to control his breath and his lip to some degree and use that to interface with a computer, to be able to speak.

You've heard him speak before. what ni Elon Musk is doing right now? What he demoed last week was something called a neural link implant. He had three little pigs while I can get more and more of that up on stage with him, this pretty low profile company. You might think, what's with the pigs, right?

they don't certainly get the publicity, the Tesla or Space X get, but he is coming up with a mass-market blood-brain implant. Ultimately that could be installed by a robot in same-day surgery. Now you might be thinking about Skynet and the Terminator and what happens when they get all of our brains hooked up to this big computer.

Some people have that as a goal. They say the reasons for this would be we would have access to all knowledge instantaneously. Think of what Google is doing. They're grabbing everything they possibly can. They are making it searchable a lot of stuff, but you really don't want them to you crabbing, They're out there and making it searchable, making it usable, but you still have to type it in. You still have to do the searching. Ultimately, what would happen if you could go and just have a thought and say, man, I wonder how long it would take me to get down to Miami right now. You'd have that answer.

You wouldn't even have to think the question, ultimately, that is decades ahead. What's happening right now with these pigs, for instance, is he has a second-generation neuro link that he is using. It's been about 12 months since he had the last version that's out, but he's changed the plan because it was far too complicated.

Of course. One of the toughest things to do is to make things simpler. That's exactly what he's done. It's very impressive. Of course, it's not him, he's not the one that's doing the hardware design and figuring out all the neuro stuff going on in the brain. There's a lot of people working on this, some amazing people.

But they did make a mess major change. That is that these pigs that were carrying his implants, they weren't able to read the brain, but they were able to determine with this one pig that was the main, the keynote pig. They were able to determine the pig's movement of a leg. Now you might wonder why that's a long way from reading someone's mind.

yeah, obviously it is, but what it is closer to is giving them the ability to know that pig intended to move its leg. So that ultimately what could happen is you put this neural link into the brain, the old version that had a thousand electrodes had to be inserted into different collections of neurons in the brain.

You had wires underneath the cranium, going to different parts of the brain no longer here. Okay. There are no only to run the wires across the surface of the brain, the whole behind that. Your hardware is gone. It's a single implant about the size of a quarter. there's whole original thing, right?

Ultimately they want to replace part of the skull. They're going to have to do that in order to detect everything. Cause they've got this pig's leg, they know where the leg is moving. They know a little bit about the movement that's going on, but different parts of your brain are there to handle different functions, different things.

So this is very cool. It is a major rethinking about how this whole thing's going to work. This particular one is like a very thick coin. It has all of the hardware. You need to keep it functional. There's a battery in it. That's good enough for full day operation and it uses inductive charging. So you don't have to plug it in.

You just put it right next to a charger can like you might with your latest smartphone, You just put it on a charging pad and there are some support chips and they've got some pretty cool stuff with Bluetooth, but. The central feature in this chips design is to determine what the neurons firing mean.

Okay. So yeah, you have all these neurons, billions of them in your brain. This device is listening in on it and is communicating by firing a series of little spikes a short burst of electrical activity, and they can detect what's going on in that area of the brain. Eh, this is fantastic. You're getting, going back to.

some of them, these brilliant people that are literally locked in their bodies, this could eventually, and in the fairly near future, frankly, allow them to interface with the world outside. Imagine Stephen Hawking being able to move around much more readily, be able to communicate much more readily, do his research to type up reports, to communicate with other teams.

This could be absolutely amazing. He is right now trying to recruit some people to work at Neurolink they've got about a hundred employees and he thinks that they are getting close to potential human trials. So they've got a breakthrough device designation from the food and drug agency, which is pretty darn cool.

And they are working on having. Some of this stuff goes further than the previous work could control a robot arm with a brain implant. this is neat. He didn't indicate when those experiments are really gonna start. But man, this is absolutely amazing. It's the type of thing that just brings tears to my eyes to think of all of these people, that technology is going to be able to help.

So stick around, we're going to be talking more about, of course, the tech this week, we're going to get into also another story about Tesla in this case of a Russian tourist, and then why he was arrested, trying to cripple Tesla, interesting stuff. Of course, Coming up here, these seven red flags that you're about to get hit with ransomware.

What are some of the things you can do about it? You're listening to Craig Peterson here on WGAN and Wednesdays with Matt at seven 30. Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553

View Details

Welcome!

Craig explains, why Apple and Google charge Apps 30%? Listen in to find out.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

Musk says that Neuralink implants are close to ready for human testing

Is China the World’s Greatest Cyber Power?

**Russian tourist offered employees $1 million to cripple Tesla with malware**

Ransomware Red Flags: 7 Signs You’re About to Get Hit

**IT blunder permanently erases 145,000 users' personal chats in KPMG's Microsoft Teams deployment – memo**

Apple won’t let Facebook tell users about 30% Apple tax on events

**Tesla with Autopilot hits cop car - driver admits he was watching a movie**

iOS 14 Privacy settings will tank ad targeting business, Facebook warns

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] You're buying apps from those app stores. Did you know that the app stores take your commission, shocker, and some people are very upset about this, and particularly Facebook, as it turns out, we'll tell you why?

Hello everybody. Craig Peterson here. Thanks for being with us today. This is a great weekend. I love the weekends. I love it when they come around, take a little bit of time and enjoy it. Hey, Apple, these guys, right? Apple's built a pretty darn big business nurse. In fact, right now, I think Apple's still the most highly valued business ever.

It's like the first business in history to hit a 2 billion or trillion, I should say. A dollar, a valuation. That's just an absolutely amazing kid right down to this. Apple is doing some just frankly, astounding things. Now Apple has never been one to really create a market. There were some amazing MP3 players before Apple came out with their iPod.

There were other smart devices before Apple came up Newton or, the iPhone as we have today. Of course, there were other operating systems around before Macko S which was is based on a Unix operating system. We'll leave it at that don't want to get too geeky on everybody. Apple, of course, came up with the iPad, which is just a bigger smart device, right?

They weren't the first ones to have a tablet, but what they've been able to do is really capture people's imagination and help them to make a big change in their lives with technology. One of the things Apple has stressed and has been very good at is trying to keep our information safe. I mentioned Google in the last segment and Google.

Is a company that's just trying to suck up everything and sell everything about you. Apple is not trying to do that at all. Apple wants to make money. Yeah. But it wants to make money because you like them. So you buy an app. When you buy an app off of that app store, Guess what happens? Apple we'll charge the developer a fee.

Now I don't consider that to be very surprising, I guess I don't know about you, but Apple, they made this ecosystem. They own this ecosystem. Apple has done just amazing things with it. It has people who review the software. That's submitted for inclusion in the apps to make sure that there's no bad code in there.

That's going to try and steal your data. Now, nothing to a hundred percent. But they do. Police did pretty darn well. They also advertise it. The apps they promote the apps. They give the developers, this, all the software. They need to develop apps for a hundred bucks. You can join the whole Apple developers program, do all kinds of stuff, even camp with a new programming language called Swift.

So there is an article this week in ARS Technica. That's talking about-face now. Again. Oh, let's talk about what happens here. You buy an app off of the app store. Apple gets 30%. Of that revenue. So if you pay a dollar, Apple gets 30 cents just to keep this simple. The same thing is true for the Google play store.

Now, the reason I'm bringing this all up is that we just had some big news out there about some of these app stores and apps being banned. From the Apple store. So it started first with the Apple store and then Google jumped right on it very quickly. Fortnite is out there saying, you can't ban us from the store.

why was it banned? it has to do again with this payment system. If you buy an app for 10 bucks, Apple gets 30% of that. So they'll get three bucks, but you notice a lot of apps have in-app purchases. That's particularly true when you start talking about these games and Fortnite is Epic games.

It's just a perfect example of that. You want to move further along in the game, you want to buy some additional virtual property inside the game. Remember how your assets trying to tax that, you want to do any of that stuff. They might charge you 50 cents or a buck. How about candy crush, right?

How many people have I seen playing candy crush and they pay to play it and they pay to get cheats in candy crush? I remember getting cheats for doom way back when I found out what they were, I didn't pay for them little sneeze there. People are using these in-app purchases and that's where the problem's coming in.

Now, of course, they'd rather you didn't. They have to pay 30% that developers right to Apple, but Apple's rules, state quite clearly that an app developer, she really has to use them. The purchase features that Apple provides them with. Which also, by the way, provide you with protection so that you don't have to worry about how good is the developer's store that's might be storing my credit card information, et cetera, but they say you have to use our technology.

If you are going to be selling something inside your app. That's where the big problem came in the big divide because Epic games decided they were going to just set it up. So yeah, you can get the app. why not have the app for free? Yeah. It's for free on the app store. Then if you want to upgrade, just you just go to go, yeah.

Go to our website there. They're over at Epic games and, we'll give you a 20% discount. So there's still making more money than they would have. If they had gone through the Apple app store. So Apple got very upset with them and not only did Apple but Google when they can figure it out, what was going on and this kind of Daisy chained into the WordPress app and everything else that it really got amazing here.

So Apple found out about something Facebook was going to do inside the Facebook app. Facebook put something in there to warn users of the Facebook app that Apple would take 30% of the in-event payments. So if you registered for any event, a cooking class, whatever it might be on Facebook, Apple would take 30%.

Facebook is trying to be actually for over a year now, make it so their platform can be used for training where you can sell it information products, where they can be sold. You can just go there. So they were going to put a message in there saying Apple is going to take 30% of the event payments, Apple wasn't too happy about that.

And they nixed that message, frankly. Then Facebook announced a new feature. For paid events earlier this month, so that you could host these workout sessions, happy hours, whatever you wanted to charge people to participate in. In its announcement, Facebook said that on its site, that it was not taking a cut of customer's payments.

So businesses could keep up a hundred percent of the revenue they generate over on the Android platform because Google was not going to charge that commission on events. So back and forth and back and forth. The big question that it comes down to is whose platform is it? And I want all of you guys that are business people out there to remember that and remember that well, whose platform is it?

Is it Facebook's platform? If you're on the facebook.com site, is it Apple's platform if you were writing or using an iOS app? So whose customer is it? Is it Facebook's customer. Is it Apple's customer? Is it Google's customer or is it your customer? So remember that because, in reality, any of these companies can change any of their rules at almost any time.

So always make sure if you are communicating with your customers or prospects that you. Drive them off of that platform onto something you own like a website so that you can continue to communicate with them, even if Apple and Google and Facebook decide to up to an eight percent tax if you will. All right, Steve, go round.

When we get back, we're going to be talking about it. The seven signs that you're about to get hit by ransomware. A great article out on dark reading. Make sure you sign up for my newsletter. Craig peterson.com/subscribe. Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553