2 RAW 4 RADIO, Comedy at the Commons, Brooklyn, located at 388 Atlantic Avenue in Brooklyn. Just three stops from Manhattan. On the A-Train, 2 RAW 4 RADIO, June 4th at 7 p.m. Find us on Facebook at 2 RAW 4 RADIO, WBAI's only comedy show, June 4th at 7 p.m. at the Brooklyn Commons. And you're listening to Radio Station WBAI New York. The time is just about 8 o'clock. Time once again for another exciting edition of Off the Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. We couldn't get much worse, but if they could they would. Bundledly bombed for the best, expect the worst. I hope that's understood. Bundledly bombed. And a very, very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you, joined tonight by Kyle. Yeah, what? Alex. Good evening. And the return of Voltaire. Hey. How you been? Pretty good, just doing some finals at school. You went through a whole school year, it seems. Wow. Okay, well, it's over. It's now almost June. Another couple days, it will be June. And we are still in our spring fundraiser. I want to thank all the people who have called in and shown their support. People who have pledged online, via text message, Morse code, however it is you decided to support this particular radio program, this particular radio station. We appreciate it, and we ask that you continue to do so. The phone number, 516-620-3602. We have a couple things. We'll get into that in just a moment, but any updates from anyone, Alex? You're looking at me funny there. Yeah, well, I know this is something you wanted to bring up last week. I know, we got sidetracked last week. We had Jason Scott in. When you have Jason Scott on the radio, that hour is going to be... There's no stopping it. It's going to be one conversation about all kinds of interesting things. That's true. I mean, we mentioned, I think, after the show, we were probably the only show on terrestrial radio talking about the ASCII art scene back in the 90s, and how it interacts with hackers. So, I mean, I thought it was a very interesting show. And what a reaction we got. Especially for a fundraiser. We got a good reaction to that. But as it happens, that same day, I was in a very interesting meeting, sitting about five feet away from Rod Rosenstein. Wow, that's funny, because he has the same name as the FBI... What's that guy's position? Oh, you mean the Deputy Attorney General? Deputy Attorney General. Yeah, yeah. I'll bet you mentioned that to him. I did, in fact. And you know what's weird? What? It was actually him. Really? Yeah. Well, that explains it then, doesn't it? I know. I know, yeah. So, tell us about this meeting. It actually... Well, it wasn't just me. It was a bunch of people at this law leadership forum, sort of in midtown Manhattan. And it was great to get an invite to this particular thing. And Rod Rosenstein showed up, and I think everybody was expecting him to say something interesting. But he, you know... He disappointed you. He really did, to an extent. What was sort of funny about this was, first of all, when I got to the building, you know, I had to check in. You have to be on a list, and you have to show ID. So, I'm checking into the building, and I said to the receptionist, I'd just like to know if Rod showed up yet. And she said, Rod who? I said, Rod Rosenstein. She said, how do you spell his last name? So, I spelled his last name. And then she looked at him. She said, oh, yeah, sure. He's right upstairs. I mean, it was kind of funny. I mean, she just... And did you say, what's that room number again, so I can deliver this to him? Yeah. So, I mean... Come on, social engineering. Well, I mean, I knew what room he was in. I was going to that room. No, I mean the room he was... Was he staying in a room, or was he just... Oh, this was an office building. Oh, okay. So, I guess he wasn't staying there. Who knows? Maybe he does. Maybe he likes that kind of thing. Uh-huh, uh-huh. I'm sure he works long hours. But in any event, so we get up there. There's a lot of fanfare, long introduction about how you say his name and whatnot. And he got up, and he took zero questions from the audience. He really stuck to the script. It was about a 15, 20-minute rant about how DOJ is doing, that they like fighting crime, and kind of generalities about amendments to the US Attorney's Manual. But he did mention, I think, a couple of things. He really, really stuck to the script, and I think he was trying to not make any headlines after making his remarks about the fact that DOJ would not be extorted a few days before by the President of the United States. So, one of the things that he mentioned was they took out of the US Attorney's Manual this notion that he used to call piling on. And he used to describe it as piling on because it was a football term. Somebody fumbles a ball, and one person jumps on it, and everybody piles on top of that person in the hope that they'll drop it or something like that. But then he said he realized that when he looked up the term piling on in the Merriam-Webster Dictionary, it actually had a different meaning than what he thought it was, and it was to sort of unfairly pile on, to use the same definition, the same word in the definition, to unfairly criticize somebody over and over and over again, repeatedly, for something in an unfair manner. And then he started joking, he said, well, so I stopped using that term because I'm really familiar with piling on, meaning, of course, that he's used to being piled on himself by the President of the United States. So that was interesting. But then he started to speak sort of in parables towards the end of this, and this didn't really get much press coverage, but I think he meant to send a message out, and he talked about stonecutters and cathedrals. I know this is starting to sound somewhat Masonic, and maybe that's the point. No doubt he's a member. Well, let's hope so. But in any event, he started talking about this anecdote where he said, three stonecutters were asked what they do for a living, and the first one said, well, you know, I cut stones, and the other one says, well, you know, I sort of fashion these stones, and they're cut, and then I put them in some sort of arrangements for people, and then the third person said, well, you know, I build cathedrals. And he said, you know, that's the way that the Department of Justice looks at the practice of law is that they're doing something that is going to last forever. They're creating an institution that is going to be permanent, and that the cathedral that they have created already through the practice of the Department of Justice for, you know, God knows how many years at this point. I don't know when it was the inception of it, but he said now the point of the Department of Justice is not only to build this cathedral, but also to protect it, and it needs to be protected. And I thought that that was particularly interesting in light of all the flack that he was getting, and then that was pretty much it. Then he took no questions from the audience, and he rushed off the stage. He didn't take names of people that were going to join him in this epic fight against injustice? I think they're already on the Mueller probe. That's it, though, that and Jeff Sessions. Because it sounded like he was about to lead a charge to, like, dive into something. I know, I know, and it was, you know, somewhat compliance-based, somewhat, you know, legally technical in a lot of ways. But then that last bit, I thought, really ended on a high note there about protecting this cathedral. So let's hope that he stays true to that particular word in light of everything that's going on, in light of the criticism of the attorney general coming down from the president today. You know, let's hope things stay on the right path. Although, you know, it's hard to feel sorry for Jeff Sessions. Absolutely. I hear he's inconsolable, though. Well, you know what's interesting about Jeff Sessions is, I mean, you remember the 80s pretty well, right? Bits of it, bits of it. Yeah, you know, occasionally I get something. Yeah, I can imagine. I mean, this is a guy who was up for a federal judgeship in the 1980s when, you know, racism was just par for the course. It was just like an everyday occurrence. It was in vogue, yeah. Racism, homophobia, everything was, you know, it was just what you did back then, right? I mean, everybody, racism was just in your face. He was found to be too racist in the 80s for a federal judgeship. That's insane. Yeah. Crazy things happened in the 80s, and if he was disqualified for his racist tendencies back then, I mean, either this guy is just a highly morally evolved human being, or he really shouldn't be the top law enforcement official in the United States. I don't know. Yet, on the other hand, you know, he seems inconsolable from this particular criticism, but I think this decision to recuse himself was right, and he's standing by it. And at least for that, I think we've got to give him a little bit of credit. You know, even a broken clock makes a decision correctly every now and then. Yes, that's right. We're kind of veering away from our normal topic here, which pretty much is almost everything, but I want to talk about some of the things that are going on in the world of technology. Also, I'd like to be able to take phone calls later on. We haven't done that in a while, but again, the phone number to call to pledge is 516-620-3602. We have one thing that we only have one of these left, actually, because we've been offering it throughout the phone drive. And it's especially exciting because tomorrow, the 31st of May, we're releasing the next in a series of Hacker Digest. This one will be volume 19, I believe, 2002. And I'd just like to read to you a little bit of the summation of what was happening back in 2002. Basically, the Hacker Digest is a collection of 2600 magazine on an annual format. In other words, volume 1 is 1984, volume 2, 1985. We're up to volume, I think, 35 now. Is that what we're up to? And every year, we put this together in electronic form and give people a huge PDF or a link to a file where they can see every single issue. And not only see every single issue in digital form, hear some insight into what was going on at the time, have all the covers explained. Imagine that, having all the early covers of 2600 magazine explained to you. That's all part of being a lifetime member, a Hacker Digest lifetime subscription. That's yours for a pledge of $100 if you're the first and only caller to 516-620-3602. $100. You will get all the ones that have come out so far, and you will get all the ones that come out in the future. And this will be an ongoing thing because every year, we put out a digest for the previous year. Next month, we're putting out 2017, and it will continue onwards from there. But we already have volumes 1 through 18 out and volumes 25 up until whatever 2016 was. So it's really interesting reading material, very enlightening. You'll find technology changes over the years, over the decades, but the attitude doesn't. And the fights that we were engaged in are the same fights. Listen to this. 2002 was the year we saw our fights expand on a global scale. The concerns that once seemed to only affect the hacker world were now of concern to everyone. Our rights as individuals are either being wiped away to benefit some corporate interest or being severely compromised in the name of September 11. That is a quote from one of the issues. It was no longer just our worst nightmare. It was now everyone's. Another quote. Unquote. Hackers found themselves being thought of as both targets and advisors. And with that, we saw an opportunity. Unlike legislators and unlike those who have become swallowed up by the industry, we have an understanding of the technology and the ability and desire to communicate with others outside our world. What better way to translate the evils of these new laws into terms that even one's grandmother could understand? Well, that is basically where we stood in 2002, the year after 9-11. And as you can see, a lot of what we're talking about there is subject matter we're talking about today. Back then, though, we were facing a very different world. We were facing a world where most people were gung ho for war and for whatever the Patriot Act was standing for. And over the 15, 16 years since then, I think we've learned quite a bit. So, anyway, I'm just getting swallowed up in that world again. That is what will happen to you when you get 2002 Volume 19. You'll get that tomorrow when that comes out. If you're the one person to call in and pledge $100 for the Hacker Digest lifetime subscription, you can either go to give2wbai.org or call 516-620-3602. And you'll get all the other volumes as well. I think that letter is a really good reminder of how awful things are during the Trump administration. It's so much better than it was. The administration isn't necessarily better, but the people that are against it are so much stronger. Back then, if you go on CNN, people were literally getting fired for being against the war. Now, people speak out freely against the administration. It's true. You're right about that. No, the administration certainly has not gotten better, but what has gotten better is our outlook. And let's look at the things that have changed over the past however many years, two decades. Gay marriage, marijuana legalization, more awareness of injustice and more of a voice against that kind of a thing. Kind of like what WBAI has been doing since we first went on the air in 1960. But I think it's more in the mainstream now. I think people are becoming a lot more aware of this and the power that they have. I mean, the digest is kind of interesting and relevant in so many different ways. But what spoke to me when I was listening to you read about the changing of our culture and the changing of our viewpoints and not letting the bad guys win by eroding our civil liberties and eroding the principles upon which our entire country was founded, struck me as interesting because of the CIA director's nomination proceedings recently. When what was at issue with respect to Director Haspel was the torture of detainees shortly after September 11th. And that there's a real fallout from this now, from the destruction of these videotapes that purported to contain the faces of actual operatives that were performing the torture. And the destruction of those particular videotapes because we did have this attitude back then that we should just do whatever it took to make us safe from this. And that included, you know, not only the passage of legislation, but the changing of the faces of our federal institutions. And now, 16 years later, we start to see the fallout from that, that we're realizing that these were not the wisest decisions to compromise the morality of our democracy in the name of some kind of farcical security. And, you know, it's really quite interesting because it was the lawyers at CIA who were really advising against the destruction of that tape. And in particular, John Rizzo, who was, when I worked there, my boss. And then he became a colleague again when he left CIA and joined the same Washington law firm at which I worked. But, you know, I think the fallout of this sort of erosion of our foundational morality is really coming home to roost now. And the digest makes that really clear and you can kind of feel it. It's palpable in the words that you wrote there. Well, it's amazing, too, because, you know, we get the chance when we're preparing this. It comes out four times a year as we're catching up. We get to re-experience what was happening then. Sometimes experience it for the first time. And it all seems so relevant now. Back then, we were just doing what we were doing and we didn't realize how it tied into the rest of the world. And now it's clear as day that, wow, this was a part of what has turned into a resistance movement against all kinds of injustice and craziness that we take for granted. So, yeah, you know, a hacker magazine is something that is a pretty interesting time capsule to look back on, see how individuals have changed, how technology has changed, how attitudes have changed, and how we can apply that to the future. So, if it is still available, call 516-620-3602, pledge $100 for the Hacker Digest lifetime subscription. Or if it's gone or if you want something else, we have, we just replenished this actually because this is a very popular premium, the flash drives of the HOPE Conference Keynote Series. That's basically a flash drive that will contain video of every single keynote address at every single HOPE Conference, from the first one in 1994 to the 11th HOPE in 2016. And you'll see people like Jello Biafra, Corey Doctorow, Edward Snowden, William Binney, you name it. We have all kinds of variety, all kinds of people giving some of the most interesting talks you'll ever see. That's for a pledge of $75. Just ask for the HOPE Conference Keynote Series. It's available in either flash drive or DVD, but most people seem to go for the flash drive. Same phone number, 516-620-3602. Good stuff. I mean, there are wonderful, wonderful speakers. Jello Biafra, I think you mentioned, Siva Vaidyanathan, Aaron Magruder, some of the names that don't come up every day but had really, really wonderful things to say. And again, sort of a time capsule and a glimpse into what the world was like back then. Aaron Magruder, yes, from Boondocks, Black Jesus. An amazing speaker. And a lot of people wondered, why are you getting somebody who draws cartoons in the daily newspaper as a keynote? Well, you know, he was the one guy in the daily newspaper that understood the case that was being waged against us by the Motion Picture Association of America back then, the DECSS case. He got it right in the comic strip, whereas news stories couldn't do it. And I believe we described that as a real hack. That is something that, you know, we got the word into newspapers through that. So, it definitely mattered. Jello Biafra, you know, another question there because he didn't even have a computer at the time, but he certainly had an outlook, something that questioned authority, and that's what we do in the hacker world constantly. And if you think about what he was really talking about there and then, you know, subsequent hopes when he would just show up, a lot of it had to do with the media and the fact that, you know, you can't trust what you're given. You know, all these facts that are spouted out, you know, all this spin, you know, a lot of his points when I saw him speak subsequently were about becoming the media and the need to have independent media and how that's crucial to democracy, which sort of lends itself really well to our fundraiser today. And also gives, you know, a lot of perspective on how we ended up with this nonsensical fake news culture, you know, and the criticism of the media and the spin that we're dealing with and the ammunition that the president has now to discredit truth and discredit facts and the role of independent media. And so, 516-620-3602. Please call, support WBAI and check out the Hope Keynote Series. It's pretty awesome. Yes, and feel free to ask the people, answer the phone for other things that they might have that you might be interested in. Now to the news, to some things that have been going on and maybe you folks have heard something about this. The FBI apparently wants everybody, including you, to reboot their routers in case they've been hacked by Russian cyber warriors. Yeah. An infection known as VPN filter has been detected in hundreds of thousands of routers in dozens of countries, and it's believed to be in many more. It's being used to launch attacks on infrastructure. It has the ability to brick your device, which of course renders it useless. It was made public a week ago. And routers known to be affected are Linksys E-1200, E-2500, WRV S-4400N, a bunch of Netgear routers and QNAP and Mikrotik. It seems like quite a lot. And I wonder, has everybody rebooted their routers? Absolutely. Have you? Okay. Yeah, several times. All right. We actually have not been rebooting any of our routers because we want to get in on the fun. Yeah. I mean, I want to make contact with the people that are doing this. What better way than to have our routers stay up? So, yeah, we've got it going there. The interesting thing about this is apparently, so this was some kind of massive GRU, Russian intelligence operation, whereby routers were compromised. Traffic could be diverted and therefore inspected, or it was possible to inject certain things in traffic. And so it was this massive Russian supposedly operation. The end goal of which I guess is not really clear to the public. It hasn't been made clear in the news stories, but yet this has been all over the news. You know, this could have been really useful for some kind of distributed denial of service attack. Or perhaps the intention was to cause a massive outage by bricking millions of devices all at once. You know, perhaps. I mean, think of what a disaster that would be if we all get our news and our phone service and everything, and we have some kind of natural disaster and then all of our routers are bricked. It's not a disaster for the router companies. Has anyone looked into them as being behind this? Because you have to buy a new router then. Perhaps. But, you know, here's the interesting thing. So rebooting the router supposedly removes the ability of the router to communicate with some sort of Russian domain or something like that. But I think it removes the domain. But I think what's unclear to me is that the FBI may be able to then access the router. They seized the domain already. They seized the domain. So that means that if the domain with which the router is communicating is now in the possession of the FBI, by rebooting your router, you are then giving the FBI access to your particular router. And they might know the details of the exploit because they're investigating it. Of course. Right? I mean, they most certainly would. So that's really interesting. So you have to sort of think of this, well, who would you rather have access to your router, the Russians or the FBI? Can you explain it again? How does the FBI get access to your router if you reboot it? Because it communicates with one particular domain. That domain was seized by the FBI. Right? And so, therefore, if the FBI then activates this domain or figures out the way in which the VPN filters. You're saying the router is still communicating with that domain even after it's been rebooted. I think it could. I think it could. I mean, it's all hypothetical. Right? But let's say that this hypothetical is correct. What I think would be extremely interesting is let's say that we're writing this. And a year down the road, there is a national security investigation that relates to an individual residing in the United States or elsewhere. It doesn't matter. But they know that he is behind a router that is exploitable. Can the FBI through the DOJ then go to a judge and ask for an Article III warrant to surveil that person by exploiting this particular vulnerability in a router? Perhaps. I think the more pertinent question is would they bother to go to a judge before they did that? Well, let's assume that they're going to follow the law and that they could. Right? They probably would have to if it was subject to the laws of the United States Constitution. Right? If it was happening within the borders or if it had to affect a United States citizen. If it was a intelligence operation and directed towards a foreign national, if it occurred within U.S. soil, then that would be subject to FISA. So assuming then they would have to go to the Foreign Intelligence Surveillance Court and get some kind of warrant there. But if it had to do with an overseas person, then that would be an intelligence collection operation, which is not subject to the United States Constitution or any kind of Fourth Amendment strictures. So perhaps that wouldn't necessarily be FBI doing that, though. That would then be an intelligence operation, which would be the domain of CIA or NSA. But FBI obviously does have a lot of overseas presence, so you never know. I mean, the hypothetical, though, is really, really interesting, I think, just from a technical perspective in terms of what they can do. On the other hand, though, you do have to hand it to them for identifying this, seizing the domain, figuring it out, and getting the word out, I think, pretty effectively. Wow. Yeah, they did suggest a couple things in the alerts about not having remote services active on the wide area side, like the Internet exposed side of the router. They also suggested checking and updating firmware as well as changing or otherwise revisiting your credentials, e.g. like logins and passwords, making them more complex and so on and so forth to mitigate the sort of exposure that anybody has. So if you are worried about it, there are steps you can take, and definitely those are some good tips. Yeah, to the router companies' credit, they do. Most of them, the higher-end ones, do ship firmware updates and security updates, which can't be said about even high-end Android manufacturers. They want you to have to buy a new phone to get security updates. Wow. Yeah. Okay. That's something to consider. Sticking with Russia for a moment, there was another story that came out. A 23-year-old Canadian resident has been jailed for five years for hacking into Yahoo email accounts, allegedly on the orders of Russia's FSB security service. He was extradited to the U.S., where he pleaded guilty to conspiracy to commit computer fraud and identity theft. He was born in Kazakhstan, one of four people charged in the U.S. in connection with the 2014 Yahoo hacking that affected at least 500 million accounts. That was the small hack, because the bigger one affected more than a billion accounts. The others charged were two Russian intelligence officers and a Russian hacker, but they've opted to stay in Russia, from what I understand. The Yahoo email hacking victims included White House staff and employees of the U.S. military and diplomatic corps, as well as executives at global companies. But U.S. officials say there are no links with the U.S. probe into Russian interference in the U.S. 2016 presidential elections. Now, prosecutors had asked for a 94-month prison sentence, 94 months. U.S. District Judge Vince Shabiria said Baritov, the person in question, Karim Baritov, was not one of the ringleaders, and although the need for deterrence called for a stiff sentence, the defendant's personal history and circumstances point toward leniency, and leniency is now defined as five years in prison. I mean, that doesn't shock me either. I mean, the person who did this was either psychologically tricked or coerced, obviously, into doing this for the Russians, possibly under some form of extreme duress. So, you know, I could see how leniency would come into play here. Again, it doesn't really seem all that lenient to be sentenced to five years for doing something like this, though. The other interesting thing about that story is they mentioned, you know, no links to Russian interference or collusion with respect to the presidential election. But, I mean, do we really know? I mean, nobody would really know unless they did a real analysis. I mean, I think what they should have said is, you know, I don't think an analysis had been done yet as to whether any links exist with respect to, you know, Russian collusion and whatnot. I think they're looking at the fact that this took place before 2016, and therefore it's not related to what happened afterwards, which, you know, some of the same people might be involved, but probably not this person. Right. You know, the aggregate of all of these particular breaches, though, I think is, you know, a sort of harm that's really, really difficult to quantify. When you begin to think about the fact that a lot of high-ranking government officials were part of this breach, it becomes more and more serious when you combine that with the fact that the OPM breach breached the SF-86 information of, you know, everyone that had a security clearance with the U.S. government. And that SF-86 national security questionnaire is extremely detailed, requires you to divulge, you know, illegal activities, your criminal convictions in the past, you know, any illegal drugs that you have used within the past five years, things like that, really highly personal information. You know, that information may also be coupled with things like psychological exams or answers to polygraph exams that are required for higher security clearances above top secret with a lifestyle poly. When that happened, I actually got two data breach notification letters because I had intelligence community clearance and DOD clearance. So I got two separate ones and then, you know, overlapping identity theft protection from this idiotic company with which they contracted. But so I think that the real sum totality of all of this harm, we don't necessarily know. It's definitely, if it's being perpetrated by the Russians, going to be used to compromise high-ranking U.S. officials or... But why high-ranking U.S. officials using Yahoo? I mean, I guess it's better than Gmail or Hotmail. Well, they shouldn't be using any kind of commercial web-based email server. And then we're going back to 2014 here. It's just it's bad practice. And, you know, I think that's something it's a bit of an eye-opener. I'm not saying this guy is innocent. I'm just questioning whether sending somebody to prison for five years in a foreign country is the appropriate response. Yeah, he's no angel. Basically, they claim he was paid to hack into 80 email accounts, including 50 Google accounts. They said he used spear phishing emails to trick targets into providing passwords. He claimed he did not know who was behind the hacking request. Said he began hacking as a teen seven years ago and charged customers $100 a hack to access web-based emails. That number doesn't add up with the 80 if he got through to that because he supposedly said to have collected $1.1 million in fees, which he used to buy a house and expensive cars. So, again, you know, no angel here. And, you know, when you start charging people for accessing somebody else's email, it's a trip down to Sleaze City there. But this all can be prevented by implementing some decent security. Sure. I mean, two-factor authentication, which can be compromised in certain ways, but probably beyond the reach of this guy several years ago. But then again, on the other hand, 2FA wasn't really all that popular several years ago. Encryption has been around for a really, really long time. And it's not all that difficult. It is a pain in the butt to figure out initially. But once you get the hang of it, it's really not all that bad. And we go back to these commercial email services. I mean, it's just hard to get away from them, I think, for personal email accounts for the masses. I mean, you have things like ProtonMail and HushMail now. But they're not necessarily more secure. I know. They're not necessarily more secure. But, you know, none of them are. And then if you run your own server or, you know, a mail server on a domain, then you're sort of at the mercy of whoever your provider is. And they're often much worse than, you know, Google or Yahoo in terms of keeping security. But on the other hand, the breaches that occur when you're on some kind of virtual server running a mail server for your own domain are much less pervasive in terms of the quantity of emails and accounts compromised. Because it's segregated, it's going to be much less. So perhaps the likelihood that you would be compromised is some sort of massive breach would be far less as well. But I don't think there's really any easy fix. But, you know, all this data is going to be circulating for a really, really long time. Well, it's just there's something about this that just doesn't add up for me. Because, you know, I have a Hotmail account somewhere. And if somebody wound up using that account, what, I can have somebody sent to prison for that? Am I high enough up on the totem pole to have that happen? Or is this just for people that, you know, are powerful people who are dumb enough to use systems like that for important things? I mean, basically they're saying, they're trying to justify this. They're saying that this hack threatened to derail the sale of Yahoo's core business to Verizon and ultimately resulted in a $350 million reduction in the price. Well, is it this guy's fault that Yahoo was incompetent and had these massive security holes? Maybe Verizon should be thanking him for saving them all that money. You know, if we're going to say that this guy is responsible for all this, you know, it goes two ways. Yeah. I mean, I always heard it was $200 million that was shaved off. I guess, you know, it all depends on how you do the math. He only got $1 million. He was only buying expensive cars and houses. Yeah. Well, you know, there you go. But, you know, this is the way of the world now. I mean, prices of companies drop when these kinds of things happen. So, you know, you have to always ask yourself the question, cui bono, right? Who benefits here? You know, really, Verizon was, as you mentioned, you know, the real beneficiary of this particular type of hack. I'm not claiming that they were responsible for it, but this does go back to the issue of leniency, I think, with this particular guy. Because if he didn't know who gave him the orders to do this or for whom he was working, he had to be, I think, extremely cooperative with the authorities for them to figure out that this was some kind of active measure that was being perpetrated by the Russians or the GRU. They had to be able to access his data, get all the communications. He had to be really cooperative. So, again, I think you're right. Five years does seem a bit harsh here. And, you know, considering we get mail frequently, we always have gotten mail like this, encouraging us to take down our enemies, break into North Korean computers, break into Chinese email and Russian accounts and things like that. Now, imagine if we took them up on that because, you know, that is how hackers are viewed in the eyes of the military and the government as additional soldiers they can just call upon. So, you know, we're doing our patriotic duty and we're breaking into a bunch of Russian servers now. Well, what happens when Russia says, you know what, we're going to extradite you and stick you in a Russian prison for five years because of what you did to us? You see, you know, if you just apply a couple of different factors to all of this, it suddenly looks very different, doesn't it? Yeah. I mean, it becomes an issue of fundamental fairness, right? I mean, it's the same reason why we don't want to have torturers running federal agencies, right? Because when we authorize the use of torture against our enemies, then they're going to authorize it against us. And it just doesn't work out. It all ends in tears. Here's another case. Two teenagers have been charged with computer crimes in connection with hacking the YouTube account of a major music video hosting platform last month, replacing its content with pro-Palestinian messages. How is this even a crime? I mean, basically, you're hacking – I don't know how you even hack a YouTube video, but they must have figured out their password and replaced a music video with something else. Well, do you really think people were fooled? Do you really think people said, wait a minute, this is supposed to be a hit. Now I'm going to free Palestine instead of following Justin Bieber. No, it's basically a hole. You patch it. You move on. But no, they're going to go after these teenagers. They're French, French teenagers. Maybe you can explain this to me. The Manhattan District Attorney's Office is behind this. Palestine, France. How is Manhattan involved? Identified as French citizens, the accused hackers, 18 years old, were arrested in Paris, charged by prosecutors there with crimes related to tampering with music videos uploaded to YouTube by Vivo, a Times Square-based video hosting company that boosts content created by artists signed to the nation's largest record labels. That's according to District Attorney Cyrus Vance Jr. That's enough? Just because they used a company in Times Square? That's enough to have people charged in a foreign country? They used the handles ProSox and Kirillish, respectively. The hackers allegedly gained unauthorized access to Vivo's account, subsequently altered the music videos for artists including Selena Gomez, Taylor Swift, Katy Perry, Chris Brown, Shakira. The list goes on. Several of the affected videos were replaced with footage of masked figures wielding guns accompanied by the words free Palestine. Well, you know what? If it was me, I wouldn't have used those particular figures. That's not exactly winning people over. But the message was there, and you can understand why the message was there. The video for Despacito was briefly deleted from YouTube only days after reaching a record-setting 5 billion views. Manhattan prosecutors provided critical investigative support that culminated in the arrests. Crediting an arrangement with Paris that allows investigators from either city to embed in the other's office. Wow. So, I wonder, are they going to try and extradite them to the United States? Well, it sounds to me like they're being charged in France, if I understood that correctly. With evidence provided by Manhattan. With evidence provided by Manhattan, right. So, it's probably on the basis of one of these mutual or multilateral assistance treaties between the United States and France. That are going to be modified and actually become a lot easier to implement without a lot of the procedure that ordinarily goes along with this. But yeah, there's quite a long history of this type of cooperation between nations. Especially Western Europe like this. I mean, it doesn't surprise me at all. Especially since a lot of the evidence was going to be possibly stored within the United States. Or maybe they had access to the particular network that was being operated in Times Square by this company. But, you know, these kinds of recording industry association type companies have got a lot of pull when it comes to the Manhattan DA's office. And so, it doesn't surprise me at all that they would be offering up assistance and prosecutorial and offering warrants. It's the equivalent of a website hack. What I don't understand is what exactly is the crime? What was lost? Yeah, you had a message showing up on videos that shouldn't have been there. Like, you know, a pirate TV broadcast. It's the equivalent of that. Okay, you know, you figure out how they got in. You fix it. You move on. Why are they going after these people and trying to ruin their lives? Well, they're taking this stuff extraordinarily seriously. I mean, sometimes, you know... If they're taking it seriously, they should fix their security so that people can't do this. Well, that's the first step, I guess, right? I mean, on the other hand, right, to play the devil's advocate here, this could have been extremely harmful to... How? You know, sales, marketing, reputational damage. We're talking about it now. We never would talk about this otherwise. We never would mention the names we just mentioned. That's probably right. Everyone would have forgotten about it and it would have been a non-issue. And nobody would have been talking about this at all. But from the perspective of these companies who spend extraordinary amounts of money, I mean, the marketing budgets of these particular types of companies are so extraordinary that when somebody steps in and compromises their PR and their marketing efforts in this way and associates them, you know, with a political message that they may find abhorrent or a lot of their users may find abhorrent for whatever particular reason or whatever your politics are, they're going to make a lot of noise and it's the squeaky wheel that gets the oil. And so it doesn't surprise me at all whether it's right and whether it's moral for the Manhattan DA's office to offer up this particular type of assistance. Again, I think it goes back to this issue that you mentioned before when it came to fairness. It's reciprocity. They'll offer this assistance because they may need it from the French in the future. You know, one hand washes the other. And, you know, this kind of assistance, well, we may need it. And hopefully, you know, that favor will be required. Well, you know, to me, I just see all these things being made into far bigger deals than they need to be. Oh, they definitely are. And it doesn't – if you know the security hole, you're not going to tell anybody about it because you're going to be worried about this kind of treatment. And it just makes people more afraid to, you know, to even explore a little bit. Yeah. Well, I mean, you couple that with this idiotic legislation that we saw in Georgia. Thankfully, that was overruled or I think it was vetoed. For now. For now. Yeah, for now. But think back to – you know, this goes back to the digest we were talking about. You know, these types of draconian penalties have been meted out to all different types of offenders to make an example of individuals, people like Kevin Mitnick, people like Bernie S. Right? I mean, all these people – and Mark Abene, right, fiber optic. You know, all these people went away for a long period of time. This is all documented in the digest, I would presume, you know, for what would be considered relatively minor offenses, things where the damages were very, very difficult to quantify. But people high – people with a lot of power in high-ranking offices were made to look foolish or silly or companies were made to look as if they had lacked security procedures. In particular, I'm thinking about Novell and Kevin Mitnick. But if we look back at how some of these crimes were treated in the 90s too, if you weren't a high-profile offender, you would have gotten off relatively easily. This kind of stunt pulled back in the 90s, you know, would really have probably just resulted in a slap on the wrist. Now it's such a serious issue that the deterrent component of the criminal justice system is beginning to overshadow and eclipse the – I think the real fundamental issue, which is justice here. You know, meeting out a fair and just punishment that is proportional to the crime. When all we're thinking about is deterrence, these criminal punishments are going to be way out of proportion, way out of whack, and perhaps that's what's going to happen to these poor French kids. And do you realize, though, that more attention is being focused on these French kids saying the phrase free Palestine than is being focused on what's going on in Palestine that's causing the deaths of countless people? You know, that's the thing that really bothers me is our priorities get shifted to nonsense. And so what if someone's YouTube account is temporarily unavailable? You fix it, you move on. It doesn't seem like that big a deal to me. Here's another case. A jury trial of a San Francisco man accused of executing a damaging hacking attack of paloaltoonline.com. And four – I'm sorry, four. This seems very specific there. And I'm actually reading this from paloaltoonline.com, so I think it might be a little bit biased. Four other Embarcadero Media websites. That trial will begin – actually, it began yesterday, Tuesday, May 29th, in San Jose Federal Court. Ross Colby is alleged to have hacked the online news sites paloaltoonline.com, Mountain View Online, Almanac Online, PleasantownWeekly.com, and DanvilleSanRamon.com. I know we all read these websites a lot, so it certainly would have affected us. This happened back in September of 2015. Wow, it's been going on a while. He gained access to the corporate Google email accounts of at least three Embarcadero Media employees. Gained access. So they probably were using a stupid password, and he got access that way. Monkey. Could be, or he just asked for a password. I don't know. He allegedly used the information to cancel four domain names on the company's godaddy.com account and changed the company's email exchange, MX Records, that is, to redirect email. Wow, okay. The website content was replaced with an image of Guy Fawkes, the icon of the activist group Anonymous. Let me just stop you right there, Palo Alto Online. It's not a group. It's more of a barometer of feeling, but you know what? There's no way I can explain it in terms you'll understand, and we've already spent enough time talking about you anyway. The hacker posted a message indicating unhappiness with the Almanac, which covers Menlo Park, Atherton, you know what, places we've never heard of, and it doesn't really matter. The message said, greetings, this site has been hacked. Embarcadero Media Group has failed to remove content that has been harmful to the well-being and safety of others. Failure to honor all requests to remove content will lead to the permanent shutdown of all Embarcadero Media websites. And as part of the hack, each website's URL was replaced with the text, unbalanced journalism for profit at the cost of human right, brought to you by the Almanac. We do not forgive. We do not forget. We are Legion. Okay. Now, Colby has no ties, no known ties to the company nor to any of its papers, but he basically is being put on trial now for this. The FBI launched, got this 18-month investigation immediately after the hacking attack, which resulted in a grand jury, federal grand jury indictment of Colby. He's charged with felony intentional damage to a protected computer and felony attempted damage to, wait a minute, felony intentional damage to a protected computer and felony attempted damage to a protected computer. Okay. He's also charged with three misdemeanor counts of intentionally accessing a protected computer without authorization and obtaining information for acts allegedly committed July 23rd through 25th of 2015. He's on $50,000 bond. I don't know what he's facing exactly, but it seems pretty serious. What do you think, Alex? Is this something worth pursuing? Well, I mean, worth pursuing is tricky. Again, it does seem like the deterrent component here is really over-clipsing the justice component. It's obviously serious, and the guy may have been up to more than just defacing websites if he's changing around mail servers. I'm curious what his beef was. Obviously, he had a very specific gripe with this particular newspaper, which they don't get into and don't expect them to. Right. They all seem to be sort of in the San Francisco area over there, so maybe this was some sort of disgruntled ex-tech startup or tech company employee who thought he was treated unfairly or something like that. It's like the IRC mentality. People would get into these massive fights on IRC. They probably still do, and then it spills over into the real world, and you have to tell people it's only IRC, and I think you have to tell people the same thing when it's a comment board. This guy got all bent out of shape because somebody might have said something disrespectful to him, or maybe his post was deleted by the moderator. Who knows? You see this kind of thing all the time, and it just escalates and turns into, okay, now I'm going to delete your site, and now I'm going to burn down your building. At some point, we have to separate these things and say, okay, this is not as important as we're making it out to be. Voltaire? Yeah. I think that we shouldn't be trying to say that because it's on the Internet. It's less important because it's like IRC or nothing matters there. But the FBI and U.S. government goes to the other extreme where they say if you do such and such crime but it involves a computer, then we're going to add 10 years onto the sentence. What I'm trying to say is if I get kicked out of a channel on IRC, somebody shouldn't go to jail for that. I think that's, you know. But I think the analogous case here is like if he had snuck into the newspaper, like printing physical newspapers at night and then changed the article that they published into a paper newspaper, then he'd be facing a lot less time than he's facing now when he did it with the computer. Oh, that's interesting. Yeah. You're saying that if he did this kind of thing in physical life, he'd actually be facing less than because he used a computer. For sure. That is definitely interesting. It wouldn't necessarily be a federal crime at that point either because it's the interstate component of this that sort of makes it more serious. That's why the FBI can get involved. That's why DOJ can prosecute this is when this crosses state lines. But I think this does actually have indicia of seriousness that, you know, we may be missing as well. Again, I think changing the MX records, canceling out domain names, all this seems to be like an attempt to really destroy the infrastructure. No, there was definitely a crime committed here. We can do something like that. But is it as much of a crime as it's being portrayed? I mean, should there be an 18-month investigation? Should the person be spending multiple years in prison? Yeah. I mean, we have to ask, you know, what kind of deterrent do we need to deter this? Does it have to be as extreme as it's going to be with these particular cases? Or can we accomplish this in a more reasonable fashion? Absolutely. Hey, we're going to open up the phone lines. The phone number is 347-335-0818 if you want to call in and say hi to us. If you just want to give us money, though, and we do appreciate people who do that, call 516-620-3602. Remember, we still have the Hope Conference Keynote Series available for a pledge of $75, but all kinds of other things as well. You can also go to the website give2wbai.org, or you can text 41444 with the letters WBAI and figure out how that works. Walter? Yeah, and if you have comments or questions, you can also tweet at us, Hacker Radio Show on Twitter, and we'll be monitoring that and responding live. Okay. Let's take a phone call. Good evening. You're on off the hook. Go ahead. Hey. Thanks for another great show. I have so many things to say. I'm going to try not to take too much of your time. First, the last thing with the guy who was sent away for five years. I seem to recall, and your lawyer friend there may confirm or rebut this, that there is no legislation on the books whereby anybody assisting the boycott of Israel is committing a crime. I'm just making a hypothesis here that that's what they were trying to do with this prosecution. Then, still tying into that, I remember in 2001, when this paranoia about security came about, that Franklin was being quoted. That seems to have proposed still today. Benjamin Franklin said in his diaries that those who renounce freedom in favor of security in the end will get neither. The FBI router story has got a very interesting undertone, which is apparently there are three types of infections. What they are trying to do is basically get an eco bounce from the primary one. What they're not telling people, and I just simply found out doing a Wikipedia research, that the secondary and the tertiary are cured by simply doing a factory reset, which unfortunately means you'll have to put in your new passwords, but that also cures the vulnerabilities that a lot of people leave on their network because nobody ever changes the factory settings. That's why they were so impregnable. That's about it. I could go on, but I want to let someone else talk, and I want to hear what you have to say. Thank you so much. Thank you so much for calling. I think you raised some very good points. Regarding the boycott, yeah, that is something that really bugs me to say that it's illegal to boycott anybody. You can boycott anyone you want. Boycott a country. Boycott us if you feel like it. Boycott other people, whatever, to actually try and make it so it's illegal. That's how you know it works, and that's why you should redouble your efforts when someone tells you something like that. They went about it the wrong way. Clearly, they have to get the five billion views. Okay, the pro-Palestinian video needs to be that popular. Then Viva will host it. Okay. Well, there you go. There's a little tip there for people out there. Let's take another phone call. Good evening. You're on off the hook. Go ahead. Yeah, I just want to mention one more thing about the MLAT, that treaty that many countries have signed with each other. If the country doesn't belong to the MLAT with the United States, and you can find that online, all the countries, who's with whom, the U.S. will go there if they want somebody and tell them, listen, we're going to shut down your banking with the U.S. if you don't give us that person or maybe to extradite or maybe make some other threat and then get the person anyway. So if somebody doesn't belong to the MLAT, that doesn't give you protection just in case you think it does. Wow. And the other thing is, where's the new phone lines? Well, the new phone lines are coming supposedly after the fundraiser is over. So the real question to ask is, when does the fundraiser end? And I think hopefully that'll be in the next week or so. Voltaire. For another joke, Gonzo wants to know, is there any word on when Hope tickets will be going out? Hope tickets should be going out in the next week or so. I know people have not gotten them. It's just we want to make sure that all our graphics look nice and things like that. But we have all the ticket information, and it should be going out, I'd say, probably in the next week, two at the max. But everybody will be getting them. So don't panic. Nothing is wrong. If your e-mail address has changed, e-mail tickets at 2600.com and let us know that you changed your e-mail address, which, you know, probably bad timing to do that. See if we can get one more phone call in. 347-335-0818 is our phone number. I might also take this opportunity to point out that this Friday are 2600 meetings all around the world. So if you have a meeting in your area, go to it. I mean, it's a great way to meet people and exchange information about technology and hacking and things like that. And it's always fun. Let's take one more phone call, and then we'll be out of here. Good evening. You're on off the hook. Go ahead. Yes, hi. I wanted to comment kind of on what you talked about in the beginning of this program with your digest of 2002 2600 issues and just kind of make a larger point. Of the age that I was involved in the hacking scene back in the 90s, and I wanted to ask your opinion, the panel's opinion, as to whether or not they feel the way that I do, which is that a lot of the arguments that we were trying to make against privacy, against intrusive technology, like, we didn't win. We didn't articulate. I remember specifically turning down a job in the, like, mid-90s on biometric research because of the fact that I thought that that was morally repugnant, and I didn't want everybody to get fingerprinted for stupid things or iris scanned for stupid things, and I didn't want to work on that. But you know what? Obviously somebody else that didn't have that moral problem with it took the job and look where it is now, and I feel like privacy has been enervated so completely it really disgusts and saddens me that this thing came out with Facebook this year, and what's the ultimate blowback? How many people actually left their accounts? I never had one because I always knew by going to Hope and my own research that they, you know. Generations of people that actually work and are in those positions. Actually, there's been enough churn. Okay, so the implementation of that kind of surveillance and stuff as a result of 9-11 is something that we were throwing all kinds of technology. People were walking through airport scanners that wasn't really proven until we got millimeter wave. There was all kinds of technology. We're opening the boundaries and letting loose everything. Well, enough young people have come in that don't have a memory of any of that that they can fill those positions and not ask questions about what they do. They just take their paycheck and pay their Spotify bill, whatever they do with their lives, and a lot of the old guard, a lot of the people that fought for that aren't in those positions anymore. It's churn. It's what we do. So we've got to continue to share the history, and that's part of what this premium was about. So we hope that people can get something out of that. That's one of the reasons we talk about this stuff and publish what we do. Yeah, and it's a very good point that the caller brought up. I wish we had more time to explore it. Maybe next week we can get into that a little bit more. Is the battle lost or is the battle continuing? I'd like to think the latter. That's going to do it for us tonight. What do you have, Walter? Radio Statler, which is the real-life radio station at Hope. They put out calls for people to submit to be able to do your own radio show, so you can do your own off-hook during Hope. And how do they do that? You go to apply.radiostatler.com, slash, application. Or you can go to the off-hook Twitter feed, which is Hacker Radio Show on Twitter, and we treated that. And we are in the process of organizing the conference. Go to hope.net for updates on that. We just got a deluge of speaker submissions at the deadline this week, so a lot of fun coming up. We'll have details in the weeks ahead. Until then, have a good night. We'll see you. OTH at 2600.com is our email address. Good night. Good night. Good night. Good night. OTH at 2600.com is our email address.