on WBAI. Thanks to you. Thank you for thinking of me. And I thank you. I thank you. Let's say thank you to all you people out there. I want to thank each and every one of you for coming by. And while he's thanking those folks, let me take this opportunity to thank all of you, our listeners and support staff, our contributors, our interns, the volunteers, producers, and entire crew that works countless hours to bring WBAI into your lives. Yes, thank you. And thank you for listening. It's currently 8 o'clock and this is WBAI New York. Time for Off The Hook. I make a call. We couldn't get much worse. But if they could, they would. On Diddley Bonk for the best, expect the worst. I hope that's understood. On Diddley Bonk! On Diddley Bonk! And a very good evening to everybody. The program is Off The Hook. Emanuel Goldstein here with you, joined tonight by Kyle. Hello. What is that in? Hi. No, no, I see you there. No, I'm sorry. I'm looking for other people. Howdy? No, Kyle, I'm not dissing you or anything like that. Usually there's a whole crowd of people in here and I just see one person. This is not enough? No, no. All right. Kyle's here. I'm here too, Emanuel. Hi. Apparently nobody else is here. Wow. Okay. I guess that happens occasionally. Oh, you're right. It is. It's very spacious today. It's kind of like it this way. Huh. Well, the World Cup's tomorrow. I guess that must be it. Yeah. It's got to be something like that. Welcome. Welcome to you, Kyle. Welcome to our listeners. And we're doing a special program tonight because, can you believe the conference, the Hope Conference, only one week away? My goodness. It just sneaks up on you. Yeah. It's the much anticipated, long awaited, now imminent Hackers. Wait a minute. No, no, no, no, no. On planet. Sorry. No, it's not. It's a month away, not a week away. Oh. Oh, yeah. It's June. Yeah. I had the wrong calendar thing again. Oh, that's true. This wouldn't happen if I had the Hacker calendar in front of me, but I don't. Oh, okay. Well, we don't have to panic nearly as much as we've been panicking, but it's a month away. All right. A month and a week. How about that? Five weeks away. Still much anticipated. Yeah. And, boy, are we looking forward to it. Well, gosh, there's so much to say. There is, well, we'll talk about it, but it's really coming together. There is great enthusiasm, and we're getting all kinds of participation. It's pretty incredible. Some really amazing ideas from people. Why don't you do this? Just the things that Hackers do. We have all this bandwidth, a ridiculous amount of bandwidth. More bandwidth than any Hacker conference in America. Ten gigabit, right? That's accurate? Yeah. That's one thing. Yeah. Just one attribute of an event, and, of course, a Hacker event. You're going to want to be able to communicate, of course, and get out to the Internet. Yes, Hackers. And stream. Stream the talks to people who can't make it, which is another thing that we take great pride in, and something that the Germans inspired us to do at CCC when, you know, the years we couldn't go. We were able to watch it as if we were there. But just to put it in perspective, we have a ten gigabit connection. About what percentage of that was used in the last conference? I think I'm not sure about the last event, but the saturation of that connection, I think, peaked the first year we had it, at around, like, 1.4 or, you know, just under two gigabit or just over one. That's the most traffic there was, and that was during a talk where we had a lot of interest and ended up that quite a few people were streaming it because they just couldn't get a good vantage point. They were streaming it from the conference itself. They were. They were on site, and they were using the local connection and streaming from a host. You know, like many of the streaming companies out there, we used one of them at the time, and it really, really helped in that situation. Of course, this time we're growing a bit. There's going to be a little bit more seating, a little bit different layout than people had maybe noticed in the past. So that's going to be changed. That's going to be a little bit different maybe to avoid a situation like that, but we'll still have the bandwidth. The biggest complaint we get is that there are too many people, and it's too popular. And I hear that, and we're taking steps by growing, by having more space and keeping an eye on how many people come in so that we don't have too many people and people are able to see as many talks as possible. We're kind of a medium. We like to be kind of a local, kind of a small event, even though we're international. I mean, there are people that come from all over for our event, for Hope, and we really love for them to be here. But that smallness is kind of important. It's funny you say smallness. We're talking 3,000 people. I am, and it's kind of an exaggeration. But when you grow a little bit, you always end up kind of growing. You grow the resource a little bit, but there's a lot that doesn't get used because you kind of have to make that bit of a leap. That's why I end up when we pushed for a bit faster Internet connection, we weren't able to completely use it. And now we're sort of used to it. Two out of ten, you said, is what we peaked at. Ten gigabit, two gigabit is what we used. And we're trying to do more, and we're trying to get more. Actually, ten gigabit isn't fast enough. We want more. Yeah, and it's funny. It's really funny. So we've now had this for two or three events, and we have a switch on site. And I think some of that hardware is itself becoming faster in that it can accommodate many ten gigabit connections. And what that means, this is kind of exciting. What that means is we have the possibility of accommodating additional Internet connections. Now, at the time when we leapt from our 50 megabit microwave link up to this incredible ten gigabit speed, we were changing our method of transport. We're using fiber optics. By the way, we were told this was impossible. It was, at the time, incredibly impossible. There's no way, no reason. That's the other common thing when you're doing something. When you're on the right path and people are telling you it'll never work or you don't need that, that's the time when you make that leap. Well, in 1994, at our first conference, they said the conference itself would never work. Exactly. In fact, it was the biggest conference in the States at that time. And we had been to a few in Europe, and everybody just had opinions as to why that could never happen here. And not only did we make it happen here, we made it happen right in the middle of midtown Manhattan. I always knew. I mean, I think I had a strong feeling that New York City itself is very well connected. It's really just navigating that. And being hackers, we figured it out. Yeah. And we had seen it used overseas, optics. And the thing with that technology is it's incredibly flexible, especially when you get into some of the technical, some of the specifics. You can invest at sort of a reasonable cost for especially an organization like ours or smaller events and ended up reusing and multiplying the amount of data you can send over this medium. So, in particular, another thing that we had seen overseas done quite frequently was the use of wave division multiplexing. And if you know anything about telephones, telegraph, and the old sort of analog systems, multiplexing was incredibly important. So, it's not an unfamiliar concept. But with fiber optics, you can do some pretty cool stuff with light and physics. And basically, by possibly moving towards that, we are able to have many different connections for our uplink to the internet over the same fiber optic. They just use different wavelengths or channels of light. It's somewhat similar to what ISDN was and so on and so forth. But this is fiber optics and some cool physics stuff. And, of course, in that, there are multiple types and so on and so forth. And it gets a bit more technical. I'm not an expert by any stretch at all myself. But suffice to say, we've seen this employed elsewhere. And we're sort of at the precipice of maybe incorporating this. As I said, our infrastructure can handle multiple 10 gigabit and faster connections. So, it's really about additional providers. And some of the equipment required to combine wavelengths of light and so on and so forth. So, we're really excited about the possibility of that. We've been approached by different providers. If you yourself are a provider and you're interested in supporting hackers and you would like to see us reach 40 or 80 or 100 gigabit as far as uplink, even just as a demonstration. We're very interested in talking to you. Please, we would like to include you in the pool of people who have suggested maybe we move towards this. This is a capability we want to have. We know that once you establish the experience and you understand how to do it, you can set it up in the future. And that just allows us as video and virtual reality and whatever else people are running on the internet. As that stuff advances, we'll be ready for it and we'll have excess capacity on into the future. So, that's just one element of our infrastructure and something we're pretty excited about for Hope. But there are a myriad of other things. That's just kind of a necessary resource when you have 3,000 hackers all getting together and talking and sharing information. And of course, many people around the world will be watching online. The conference takes place next month, July 20th through 22nd, Hotel Pennsylvania in Midtown Manhattan. You can get more info at hope.net. In fact, I'm looking at the website right now. We're doing something else that's kind of fun this year. It's our 12th conference. We're having a little display known as the hacker's dozen where a dozen different types of hackers are profiled. And so far, we're rolling them out about once a week. We have the coder. We have the social engineer. We have the lock picker. We have the freaker, the phone freaker, the whistleblower, and the latest one, the journalist. And I think that's a particularly good one because every good journalist is a hacker at heart. There are so many ways you can apply the hacker mentality. So, it's very important to realize that it's not just hunched over a keyboard tapping out code. Yeah, the first hacker in our list was a coder. Maybe that's the most obvious description of what a hacker is all about. But there are so many ways you can apply these talents. Kyle just said he's not an expert. Yeah, you know what? A lot of us don't consider ourselves to be experts. But in the eyes of mainstream society, we are experts because we're talking about this. And we're taking on these challenges and getting things done and meeting up with all kinds of other people. So, that's the magic of it. That's the magic of a conference like this. And we're going to take phone calls in just a little bit with hopefully your stories about Hope, questions about the Hope conferences. If you've been to a Hackers on Planet Earth conference in the past, we'd like to hear what your experience was like and maybe memories and things like that. Our phone number when we start taking phone calls in a little while is 347-335-0818. But first, let's take a look at some news items that have been taking place over the past week or so. As we mentioned, the World Cup starts tomorrow, the match of the century, Saudi Arabia versus Russia. That's going to be something. Yeah, it's quite interesting. Now, it's UAE. Who is hosting the next World Cup? The next World Cup is Qatar. Qatar, I'm sorry. Yes. And it's going to be in the winter. So, that's going to be our winter. Yeah, yeah. And then U.S. and North America recently. The United States qualified today for the 2026 World Cup. That is such a stretch. Well, we're hosting it, so we have to play. And apparently also Mexico and Canada, three countries hosting at the same time. That's never happened before. But most of the games will be played in the United States. But, of course, Russia is the host. So, in that match, they're there because of that. Right. And not necessarily qualifying. Although they have qualified in the last few. They have good players, right? We did not qualify for the World Cup this year. I'm very excited about Iceland. Iceland did. Yes. Serbia did. Yeah. Yeah. Morocco. Did Morocco qualify? I'm pretty sure Morocco is in there. Wow. Okay. Well, that's pretty cool. I'm blanking on all of the other ones. But it is going to be exciting. The coverage is certainly going to be interesting. They're employing a fair amount of technology, too. The refereeing, as I understand, is now they're using sort of digital- Robots or- Something. I have no idea. The balls have gizmos in them and wireless and all that. Yeah. The balls have cameras in them. Yeah. That's what they do. Yeah. It just tracks you and rates how hard you kick the- It's really complex. I don't want to get into it and bore our listeners. Imagine what it will be like in 2026 when it's in this country. Yeah. By the way, the final, the final final, the championship game is taking place at the Meadowlands in New Jersey. In fact, I'm going to have to cut out a little early because the line is starting now to get tickets to that. Right. Actually, I'm going to miss the conference because I'm still going to be online then. You better not. Well, unless I can work out a deal where somebody takes my place for a few days. We could get people to stand in lines. Isn't there an app for that? Is there an app for that? I don't know. Of course there's an app for that. There's an app for everything. Well, here's an app. I think people will really find crazy and offensive. Now, people are watching the World Cup, right? Now, in Spain, the soccer league is known as La Liga. They broadcast some of the most viewed matches in the world, Barcelona, Real Madrid. Real Madrid. Yeah. Atletico. Atletico Madrid, the real team there. The real team. And so many others, so many others. But anyway, their concern, their main concern is what they define as piracy. Yeah. Now, basically, in an attempt to curb their definition of piracy, La Liga has recently started to use modern technology and its users to its advantage. In what is being referred to as an unprecedented move, the soccer league has turned its official Android app into a piracy spying machine. Now, the app in question, it's already been installed by millions of users. It's going to use the microphone and GPS readings of the devices it's installed on to report possible instances of streaming piracy. Now, with consent from the user, maybe the user doesn't know what they're doing, but they're giving consent to this, the app will analyze the audio in its surroundings to check if one of La Liga's matches is being played. And it then pairs that with GPS data to see if that location is an authorized broadcaster. And they're saying, protect your team when they're prompted to enable this type of data collection. It is really kind of insane. They justify it this way. The purposes for which this functionality will be used are, one, to develop statistical patterns on soccer consumption, and two, to detect fraudulent operations of the retransmissions of La Liga football matches, in parentheses, piracy. The microphone will only be activated when La Liga is broadcasting its football matches to policy further clarify. So let me say I get this straight. The microphone is automatically going to activate whenever there's a game being played. You don't have to actually activate it yourself. It's going to be out there spying, saying, hey, who's broadcasting our game, and did they pay for the rights to do this? OK, isn't this broadcast over television? So who is it exactly that you have to pay to have it being played on a TV set? Having it being played on a TV set in a public establishment is only a good thing for the soccer league, because people are paying attention to what they're doing. And there are so many reasons why this is a bad thing to be doing. I think what you mean by reasons is there's so many ways for them to accrue revenue as a result of this game. Of course. I mean, think about it. There are logos and brands and advertising all over the field, like in every shot of the thing. Every jersey has some major sponsor on it. You want people to be watching this. You should be paying the people that are broadcasting your game. You've got ads running on commercial breaks. You've got people who are, most of them, paying already for the cable to then be served all these ads and images of brands and logos. I mean, how much money do these people need? They want more. And now they want to take punitive action using this. I would be very curious also how much of that audio, what frequencies, if it's just listening for a tone or something that's broadcasted out. It's listening for the audio and somehow matching it in some crazy way. Now, there's ways you can get around this. Turn the damn sound down on the TV set, broadcast it 10 seconds later, or maybe turn on a different language or something like that. There's all kinds of ways, but that's not the point. Yeah, the ways, that's exactly what I was saying, that perhaps there is a frequency or a tone that it is using to verify. I mean, it's not fancy. It's something inaudible or something that the app can recognize, similar to the stuff we've talked about with all these home assistants and stuff. But it really, it would be an invasion if it's just taking all the audio and perhaps a discussion with granny or whatever while you're watching the game gets recorded. And what are the implications there? And how about this? I walk around with a portable TV set just to cause trouble and start playing the game in places where the game isn't supposed to be playing on a TV set. And all these piracy cops suddenly show up on an innocent bar or whatnot to bust them for alleged piracy when they couldn't care less about this game in the first place. We should develop the same app for people watching Hope Talks. Well, I'd like to know how they work. I really do want to know how they work. Just like I want to know how the YouTube algorithms work, because those things drive me crazy. Yeah, we've seen how they're kind of inaccurate. They're very inaccurate. We've been playing around with that. And of course, we're getting excited for videoing all these talks and interesting information coming up. But it's not always the precise thing. And you can't, of course, appeal to a robot or an algorithm. And then you're sort of at the mercy of whatever this thing determines. It seems like the same sort of functions are going on here. Yeah. And this is something that really is an invasion of privacy. Imagine how many applications could be applied to this kind of formula where you're listening for a particular type of sound to verify if somebody is where they're supposed to be. If somebody else is doing something they're not supposed to be doing. It's really scary. It's extremely scary to think that that is what an Android app is being used for. Yeah. And that people are opting in to surveil themselves. But they don't know. I don't think they know. For whatever perceived benefit. Yeah. Even if it's a background thing in an app that's telling you what game is next, it seems like something you wouldn't necessarily, given some thought, opt into right away. But people may not be thinking because they're enticed by add-ons and other features. Well, if you're in Spain and you have this app, please write to us, oth at 2600.com. We'd like to experiment with this app. Actually, I guess we could get the app to ourselves. In fact, they'd have to come all the way over here to investigate piracy when we start playing a game in the United States for La Liga. And I wonder how short a clip you could get to flag or activate this. And could just a short clip have multiple violations accrue just by, as you said, somebody walking around with a TV or something? Well, just to put everybody's mind at ease, the Spanish Soccer League informed the publication investigating this that nobody accesses the audio fragments captured by the microphone as the audio automatically becomes a signal, a binary code. This happens only in Spain and without storing any recording or content. Says you. That's what you say now, but we all know that it's possible that such a thing could be abused much greater than this already is being abused. Wow. It was all Ronaldo's idea, too, I heard. He's so smarmy. Yeah. That's the reality of the situation there. Speaking of listening in on people, last Thursday night, former Senate Intelligence Committee aide James Wolfe was arrested for allegedly lying to the FBI during a leak investigation. Now, according to the indictment, Wolfe repeatedly denied providing classified information to four journalists regarding sensitive topics like the Russia investigation. The FBI alleges it found proof that Wolfe, in fact, used encrypted messaging apps to communicate with the reporters. Journalists were dismayed to discover that prosecutors were actually able to quote the signal messages in the indictment. Wolfe allegedly wrote to one reporter, good job, and I'm glad you got the scoop. And the reporter messaged back, thank you. Mail one, which is how the person is identified here, I guess it's just a person, is not pleased but would deny that the subpoena was served. You can only guess who that is. Signal is generally regarded as one of the most secure encrypted messaging apps available. And many reporters rely on its services to communicate with confidential sources. So does this indictment prove that Signal is not as protected as we all thought? Well, Signal offers robust end-to-end encryption. We know that. That ensures only the people involved in a chat can see the messages. But it doesn't automatically delete messages from your devices. It's unclear how exactly investigators were able to retrieve the messages in this case, but they could have theoretically seized a phone belonging to Wolfe or one of the reporters and simply read the messages on the app. That simple. Now, the best way to safeguard against snoopers is to turn on Signal's disappearing messages feature. Every time you start a new chat, which lets users determine how long messages will be retained in the app after they've been sent or received. You can also manually delete all of your chat history. It's also important to make sure the person you're communicating with has this setting enabled and is not taking pictures of your chats. That all came from Slate.com. You know, the thing is, whenever you have humans involved, somebody is going to make a mistake. How are you ever going to know that someone's not taking a picture of the window that you're chatting with? How are you going to know that a record of it is not being kept someplace or that somebody's password will be compromised or that their phone will be seized? Who knows? There's so many possible ways that this could happen. It's always going to be possible. Yeah. What if the phone was compromised and something was exfiltrating a screenshot of that very window? Or the person's reading their messages aloud outside the window. Who knows? and a determined attacker could very much retrieve and reveal this kind of information. It is somewhat reassuring that it is probably using seized or otherwise compromised hardware instead of something being captured over the air, which would probably be a lot more concerning for other signal users. Well, yeah, they would have to have broken the encryption in order to do that. And there's no indication that that has actually happened. But again, it has to be made easy. It has to be made simple for people to take the desired action. So if you want to see a message just once and have it disappear forever from all devices, that has to be made an option that is easy to implement and very clear. And if there are backup copies kept someplace, you have to let people know that. You have to let people know what the risks are and not make it so difficult that it discourages people from installing the app in the first place, because these things are important and increasingly so. Okay, what else is going on? It's only a matter of time, according to—I'm reading a story from Russia Today, but I believe this came from Vice Motherboard as well. It's only a matter of time until a commercial aircraft is hacked. According to the Department of Homeland Security, and other U.S. government agencies have also warned of the same thing, most planes lack cybersecurity protections to prevent such a hack. Now, Motherboard obtained internal DHS documents through a Freedom of Information Act request which detail vulnerabilities with commercial aircraft and risk assessments. A number of the documents are still being withheld pursuant to exemption of the FOIA. Now, the hacking test that they performed from the Pacific Northwest National Laboratory, part of the Department of Energy, this hacking test was to be carried out without any insider help from a position of public access, for example, a passenger seat or the airport terminal, and without using hardware that would trigger airport security. Now, according to the presentation, the hack allowed the researchers to establish actionable and unauthorized presence on one or more onboard systems, and I assume we're talking about more than the entertainment systems. We're talking about actual systems that people would care about. Now, another document from 2017 says, testing indicates viable attack vectors exist that could impact flight operations. A DHS presentation included in the documents say, most commercial aircraft currently in use have little to no cyber protections in place. It points to the fact that even a perceived successful cyber attack could have an enormous impact on the global aviation industry, which that's really what they care about the most is the industry, I think even more than the safety. Now, in November, DHS official Robert Hickey said, the agency successfully hacked the avionics of a commercial Boeing 757 in 2016. He also claimed representatives from American Airlines and Delta Airlines were shocked to learn the government had been aware of the risk of such hacks for so long and hadn't bothered to let them know. However, a Boeing spokesperson told the Daily Beast that they witnessed the test and can say unequivocally that there is no hack of the airplane's flight control systems. Well, you know, speaking from experience with computers and systems and installing complex applications, somebody is going to get something at some point, something will be left open. And this is a situation that we have to be extremely careful and vigilant about. And one way of doing that is not to be secretive, not to cover things up because somebody is going to figure it out at some point. And when somebody does, you need to be able to listen to them. Hopefully, they will feel comfortable enough to actually put forth their findings and not feel like they will be seen as the problem. Yeah, and just one thought. You mentioned the entertainment systems. Those things become more complex and feature an entire operating system in and of themselves combined with things like USB ports and other things that you would get right from your passenger seat. In the past, those were not available. And, of course, the planes themselves were running with actual cables and hydraulics instead of fly-by-wire technologies where it's electromechanical based on sort of firewire or other sorts of signaling protocols within the plane. And I think it's worth noting that a lot of the instances that we've seen of people allegedly manipulating airplanes while in flight is using those systems and perhaps traversing them so that ideally or by design, the thought is that they're compartmentalized to a degree, but then someone using a computer or software. I think the one individual that we reported on a couple years ago or a year ago was using a real-time operating system to interact with the entertainment system and otherwise traverse and get into other parts of the plane that ought not to be communicating. But again, having real tangible evidence of this, it's interesting that they're pursuing this now. And, of course, details on exactly how people are doing it either once upon a time or currently with the types of aircraft that are in service and the kinds of things you can actually get onto a plane, it's yet to be seen. And this is kind of the first report of kind of where that is. Yeah. I mean, it's going to be a royal pain for the industry. I realize this. And they're going to have to do a lot of work to fix things. But if there are problems, we need to know exactly what the problems are because if we have those details, for instance, if the entertainment network is able to talk to the aviation network, that's an extremely bad thing. You can have two networks side by side that don't connect at all. I see that all the time, and that should certainly be the case here. If it's not the case, we need to know about it. We need to fix it. Yeah, but the truth is there are not less computers being added to these flight systems and to these entertainment systems. And we all know that things are getting smaller and cheaper and more powerful. So the ability to bring a capable machine onto a plane that has custom software or interconnects or otherwise can be attached and mimic an expected device that the plane systems would grant permission to do these kinds of – to access other parts of the system. It's not something we're reducing. We're having cheaper and more electronics on us. They're adding more things to the seats that you can actually plug in and interface. So that compartmentalization and security is crucial as we continue to have more and varied devices and with different capabilities. The one fail-safe that I think we should never let go of is manual override. When everything goes haywire like it does in the movies, you need a way to get control back. And if you can't override the computer, that's a big problem. There's no reason why human beings can't take over themselves. Now, I know that sounds evil because we're used to evil human beings, but let's assume that the humans are doing the good thing in this scenario and getting around a maladjusted piece of software that is doing something it's not supposed to be doing. You need a way to get around that. You need the skills, obviously, to be able to fly a plane yourself if that happens. You know, you never hear about other vehicles, though. I mean, it's always sort of the plane, but like a bus? I'm hearing about it with cars. How about a train? You never hear about people controlling a train from their seat because they got the right IP when they logged into the Wi-Fi. I think there was a movie they did that once. But yeah, no, you're right. You're right. You know, though, I mean, a train is as connected. Maybe not as many Amtrak trains as we're exposed to overseas, but certainly there is wireless and computers and high technology on that mode of transport, but it always seems that the plane is the scary, vulnerable one. So perhaps they could talk to some other transport industry types and get some notes on how to secure something that is 35,000 feet in the air. I think train drivers are just so into driving a train that they don't want to give that control up to a computer. That's a good theory. They won't relinquish it. They want to stay in that room and be part of the action, and I understand that completely. Interesting. We'll keep following this. You know, in regards to the World Cup, you know, the United States, Mexico, Canada, they were up against, of all countries, Morocco for 2026, and Morocco lost. But one of the things that they were saying, Morocco would have to install all this high-speed rail for the World Cup. So does that mean we get the high-speed rail now? Are they going to install high-speed rail so that, you know, we can connect cities together for soccer games? Because I would be all for that, but somehow I don't think that's going to happen. It would be nice. Another thought, just in the context of transport and devices taking over, I mean, what happens when you have autonomous systems and then software that is independently taking over? In other words, not someone sitting controlling a vehicle while they're on it, but remotely or otherwise just sort of letting it go into a system, and it then exploiting whatever autonomous system is supposed to be in control. These are all problems we've got to consider as we embrace these future technologies. Yeah, and one thing that I think is the common thread here is that secrecy doesn't help the discussion. So let's have an open, honest dialogue. In fact, conferences like HOPE is where that dialogue can happen amongst many people that really know what they're talking about. Here's an interesting story out of China. According to Chinese Internet security firm Qiho 360 NetLab, hackers have stolen $20 million in Ether from poorly configured Ethereum mining rigs and third-party applications. Well, I just know stealing $20 million in Ether used to mean something completely different, but, well, it's a different time. Experts at the firm say the cyberattacks target unsecured Ethereum nodes on the Internet. On March 15th, Qiho 360 NetLab alerted the cryptocurrency community to the activities of hackers scanning the Internet for unsecured Ethereum nodes, and at the time, the alleged cybercriminals had stolen 3.96 ETH, which, that's a couple of thousand bucks right there. And now, according to a tweet, they say that a particular wallet address has over $20 million in it. So they basically hijacked unsecured Ethereum wallet apps, and the hacker has managed to siphon off 38,642 Ethereum, what do you call them? Ethereum coins? Ethers? What's the proper way to say it? ETH. Is that really it? No. I have no idea. And the story is just ETH, and I don't know how to say that, but, yeah, Ethereum coins. Let's just say that for now. Yeah, we're really up on this. I'm still trying to figure out how much a barrel of Ether costs these days. Well, okay, but the point is, and this is not a hacker that did this. This is somebody who steals money. They may have used some skills to figure out that somebody wasn't using a password or was using a default password or something like that, but I'll prove it to you. I'll prove it to you. If that is a hacker, hackers, you know, we support each other. This hacker has $20 million. And, of course, all hackers listen to this radio program. So hacker that has $20 million, give us one. Give us $1 million to this radio station, because that would solve a lot of problems around here. And in so doing, you will prove that you are, in fact, a hacker, and that the hacker community is all involved in this. I suspect that you're not going to do this because you're not really a hacker. But if you are going to do this, OTH at 2600.com, that's our email address. We'll happily accept the $1 million equivalent of Ethereum. We will hold your Ether in escrow and make sure it gets to the station so that we can service our loan. Yeah. Well, really? That's what we're going to spend it on? I was going to... Okay. Well, we can talk about what the money goes for. That's, I think, the most immediate need. Maybe we'll buy some furniture, too, but... All right. Well, I have needs, too, but... There's a lot going on here at WBAI. There sure is. No, it's going to be exciting, and all these kinds of fundraising efforts go to this incredible place. Mm-hmm. Mm-hmm. A working water cooler. That would be nice. Yeah, I noticed that wasn't working recently. How hard is it to get a water cooler to work? Well, you know, it's... Well, if you throw a million bucks at it, I'll bet it'll work for a while. It'll be the least of our problems. Okay. So how about this? How about drones being targeted by the Trump administration? Yeah, the Trump administration has urged Congress to give it new powers to disable or destroy what it considers to be threatening drones. And I know the 2600 drone will be number one on their list because it's got that skull and crossbones drawn on it for one thing. David Glawe, Undersecretary for Intelligence and Analysis at the U.S. Department of Homeland Security, and Haley Chang, DHS's Deputy General Counsel, told the Senate committee that oversees the department that it needs new authority. At any time people like that say something like that, we should all be paying attention. Terrorist groups overseas use drones to conduct attacks on the battlefield. And you know who else does that? We do that. We do that more than anybody. But okay, fine. Terrorist groups are using drones as well. I continue to plot to use them in terrorist attacks elsewhere, even though I don't think it has ever been done anywhere. This is a very serious looming threat that we are currently unprepared to confront. Fair enough. Now, a bipartisan group of senators, including Senate Homeland Security Committee Chairman Ron Johnson and the committee's top Democrat, Claire McCaskill, last month introduced legislation to give DHS and the Justice Department authority, here's a quote, to protect buildings and assets when there is an unacceptable security risk to public safety posed by an unmanned aircraft. The federal government does not have the legal authorities it needs to protect the American public from these kinds of threats, and the threats posed by malicious drones are too great to ignore, they say. I think they're watching Colony. I think they see what these drones can actually do when they turn super evil. Is this like one of those, the only thing you can do about a bad drone is have a good drone or something? No, because I don't think they're talking about destroying it with a drone. I think they're talking about shooting it down from the ground, but probably they will have other drones involved. I will say we have a license for this, 2600 does, and it has not become less complex. This is something that is requiring more training. The FAA wants you to use their app now. You have to identify where you're going to be. There's all kinds of regulation. This has been something that has been growing. Of course, the prevalence of drones, I guess the last two Christmases have substantially increased as far as that kind of air traffic, and it's changing rapidly. This kind of control, I think people ought to pay attention to because something that was once, I guess, a little bit more lax and so on is becoming quickly regulated, highly regulated, and disallowed. This is your ability to fly things as much as anyone else. Just the specter of this boogeyman of bad drones or nefarious uses is similar to the limitations after 9-11 that you couldn't photograph large structures or bridges, infrastructure and so on and so forth. It is an encroachment with this guise of we're going to prevent this possibility, this hypothetical. I think that can become very quickly not a good look, not at all good for people just using drones like normal. Young people, students, people interested in photography and so on and so forth. Let me just also add that the background of only good drones or only police drones or only federal drones or only Amazon drones. Wait a minute. This is again like, okay, only our authorities or only these regulated players, these moneyed individuals can drive on these roads or use this technology. High-speed internet is only for high-frequency traders. That's the new rule. We come to the same reporting on net neutrality issues. These technologies, these advances should not be immediately locked down and only available to the elite or the bureaucrats that impose the rulemaking. Now, you may ask who will come to the defense of a generic working class drone? The answer is the ACLU. The ACLU is opposed to this. I'm not too surprised. A proletariat drone. Well, they say it amounts to an enormous unchecked grant of authority to the government to forcefully remove drones from the sky in nebulous security circumstances. And yeah, they go on to talk about these nebulous security circumstances. I'm talking about the proponents go on to talk about this. They basically say things like the threats could include surveillance, apparently surveillance from somebody other than them as a threat, chemical, biological, radiological attacks or attacks on large open air venues like concerts and sporting events and attacks against government facilities. You know, I think they're drawing from their own wish list here of the things they want to be able to do to our perceived enemies. But how do you shoot down a drone that has chemical weapons on it or biological weapons? That's something I'd like a little bit more detail on. What are they actually thinking about here? And what evidence are they, besides science fiction television, what are they looking at? Yeah. And how do you safely do that? I have absolutely no idea. Yeah. And that's really interesting because, again, you run out this specter of a dangerous virus or something being released, then all of a sudden we have to be on alert and fearful. There it is, fear, just the consummate partner of control. Absolutely. Hey, our phone number is 347-335-0818. If you'd like to share a story about HOPE, Hackers on Planet Earth Conference, of which there have been 11 so far and there will be a 12th next month, give us a call. 347-335-0818. Tell us your stories, tell us your experiences, ask us your questions about HOPEs in the future or HOPEs in the past or the hacker scene in general. Phone number 347-335-0818. We still have the phone that only takes one call at a time, so it's harder to take phone calls, but as soon as the first one comes in, we'll go to it. If you want to be more abstract, what are you hopeful for there? Okay. If you don't want to talk about the conference, I'm telling you though, you're missing out. Hackers on Planet Earth, it's coming up next month. I like to limit it to talking about the conference because a lot of people go, a lot of people have questions, we're getting so much email, so this is a chance to actually express yourself and express concerns or wishes or experiences. Or maybe you're going to share something at HOPE. You're bringing a project or you're really fired up and your friends and fellow hackers are going to be there, let us know what you're going to do. And maybe if you're going to show off some things or what you're interested in hearing about, I'm sure there's a talk regarding whatever that interest is. Yeah, we have well over 100 speakers. We have all kinds of people participating in workshops as well. Chelsea Manning is going to be there. There are unscheduled tracks for individuals that would like to present. It's all being put together right now. The schedule will be announced probably in a couple of weeks. All sorts of displays, vendors. It's just going to be an amazing event as it always is. But again, our phone number is 347-335-0818 if you have any questions, thoughts, opinions, et cetera. And while we wait for that call to actually make it through the system to us, let me describe another nightmare scenario. This is from an American mom. Okay, I should point out now, I'm talking about an American mom because I'm reading from a British story. That's where this story came from and so the terminology is going to be in British English. So an American mom has shared a terrifying experience after her baby monitor was hacked by a stranger and some of her most private moments breastfeeding her son were intruded upon. In a post on Facebook that has been liked 1,000 times, which somehow seems inappropriate. That's weird. And shared more than 2,000 times. Jamie Summit encouraged parents to be vigilant about their baby monitors. If you have this baby monitor, do yourself a favor, unplug it and throw it away right now. Here's a little background on the monitor and app that it is used in conjunction with. She went on to write that she ordered the monitor off of Amazon after realizing she could access the video feed from her phone when connected to Wi-Fi. That's what she wanted. She also noted that she was attracted by the fact that you could also have multiple people download the app so they could watch. Again, this is what you wanted. The camera itself is able to be turned 360 degrees and can be moved remotely from the app simply by dragging your finger across your phone screen. Sounds kind of cool actually. Not at all uncommon these days. Yeah. Well, this afternoon I had the app pulled up and was watching Noah sleep in the bassinet in our room. Noah's the kid. Or maybe it's her husband. I'm not sure. No, no. He wouldn't be in the bassinet. He would not be in the bassinet. All right. I don't know Noah, so I don't know. I was in the living room with the only two people who had access, or so I thought, to the monitor. All of a sudden, I noticed out of the corner of my eye that the camera was moving and it was panning over to our bed, the exact spot that I breastfeed my son every day. Once the person watching realized I was not in bed, he panned back over to Noah asleep in his bassinet. I realized that this morning the camera was facing our bed when I had last left it facing away from our bed and over at Noah in his bassinet. Occasionally, Kevin would check... Who's Kevin? I think that's the father, maybe. Well, an introduction would have been nice. They don't mention who Kevin is until now. Okay. That's bad writing. Okay. Occasionally, Kevin would check... Well, it could be Kevin Mitnick checking in. Oh, you're right. You don't know? Kevin would check in on us while at work to see how the baby was sleeping. I assumed this was the case, but Kevin informed me he had not accessed the app all day. I feel so violated. This person has watched me day in and day out in the most personal and intimate moments between my son and I. I am supposed to be my son's protector and have failed miserably. You know what? Your son's not going to know. He's not going to care. Wait a minute. Yeah. I honestly don't ever want to go back into my own bedroom. Really taking it hard here. No, no, no. We got to back up. We got to back up. Because, look, you put a camera in a room that you have an expectation of privacy, even if it's well configured, even if it's set up the way it's supposed to be set up, if it is somehow exploited and you end up being on camera, you cannot be surprised because you did put the... Yes, of course, a reasonable expectation that it would work and protect, you know, from others to see it. But she put the camera up. I mean, you have to, at some point, say, you know, consider the possibility that the camera could be accessible by others. Well, she wanted to be accessible by... That's the thing that gets me here. She wanted a camera that more than one person could have access to through an app. So, you know what? If the password isn't good or if it's a default password or there's some other security issue, the people that will be vulnerable are the people who have cameras in their rooms that can be accessed remotely. Those are the people. The people who don't have that aren't going to have that problem. Yeah. And just as you're saying, I was thinking, if you communicate the configuration information in an unsecure way, insecure way, it then opens up that method. If someone is monitoring that form of communication, they could then easily be doing exactly whatever you're suggesting to help your friend or trusted persons configure it. You may not realize that that mode of communication is not a safe way to communicate that configuration stuff, and thus, you get compromised. Our phone is open. I don't know if it's still open or if we missed a call when I was reading the story. 347-335-0818. I know there are people out there, so please let us know if you're having difficulty getting through. 347-335-0818. That is our telephone number. I know it's not the one that rolls off your tongue, but it's how to reach us right now. And we're only on for another couple of minutes, so we'd like to hear from you. But the family in this particular story said nothing could be done when they contacted police and were locked out of the system when they believed the hacker overheard their conversation. All right. Well, now you have a battle going on with somebody in your room watching your baby through the monitor that you installed. Unplug the damn thing, like they do in war games. That's how you fix problems like this. Some have said they have changed all their passwords up their Wi-Fi security, but have encouraged all parents to be vigilant to avoid the complete nightmare they've embroiled in. You know, it would be nice if the story told us the brand, the model, something. What? Baby monitor? Yeah. So now all baby monitors should be feared, which I guess probably is wise. It's true. If anybody has seen these, I mean, they're rapidly changing. They have a lot of features. But as with, you know, all the kinds of connected devices and things with, you know, wireless and other forms of radio connectivity, you open up these sort of these cans of worms. And yeah, you've got to be prepared and you can always, you know, move to a different room when you're having that moment. You hear that? Not one phone call. Not one. What's going on, folks? I think everyone is at WBAI.org signing up to be WBAI buddies. That little guilt trip always works. Good evening. You're on off the hook. Yeah. That's a Wi-Fi hack. And that means that and not through the wired connection. And that means the person who hacked it was within 200 feet. Right? Well, no, not necessarily because Wi-Fi is how the thing is streaming inside the house. But, you know, if you know the address and it's supposed to work on an app on a phone, you could be anywhere in the world. Yeah. It depends on... I mean, you're right to a degree. It depends on the particulars of it. But say, for instance, there's a small web server that is serving that up locally on your network and other devices on your network have been compromised. If someone is remotely on your network and able to see that server as a local device, then they would be able to receive that just as well as an app would be locally over Wi-Fi. But then again, if the wireless itself is compromised, you're right. Someone could be some distance away. Yeah. If it's just a... If they just had... Let's say it was WEP, Wireless Encryption Protocol, that's 200 feet or even WPA2, which is hackable but much harder than WEP. That's very true. And it is really why I was sort of alluding to that. Really, in a general sense, you're just adding all of these vectors, all of these ways and methods that people can get access. Yeah. So, a few years ago, I think that would have been the only way to get through. And now everything has to be available everywhere so anyone can actually access this. Hey, we still have some time to talk about Hope stuff. 347-335-0818. It's only five weeks away. When was your first Hope, Kyle? Oh, my first Hope was Hope number six. That would be in 2006. That was 2006. Yes. Wow. That's something... It changed my life. Well, you will have been to more than half of them. So, that's kind of cool. I am more than halfway through and I'm helping a lot now and I wouldn't change a thing. Good evening. You're on the air. Hi. Good evening. How are you guys doing tonight? Good. All right. How are you? We're great. Dynamite. I just wanted to add a side point. One of the things that I think people, consumers, would be a wise thing is to demand that some of these apps become spread spectrum or somehow have a digital scrambling. Because remember we had the cordless phones and you could listen to people on the cordless phone? Of course. Yeah. But when you agreed with the phone, you're accepting that. So, a lot of these people, when they're turning on the apps, it's also acknowledging that you're allowing anyone who may be able to receive it too. So, if they kind of just research the, you know, I accept and maybe even call the company because I'm sure some products will have a spread spectrum ability, which means unless you subscribe, you're not going to get it. Okay. So, just food for thought, you know. And as being a licensed ham operator, I want to say anytime anyone is transmitting even a cell phone, any signal we transmit, we accept. So, you know, if you accept it, you should also voice, we want it to be safe. Yeah. Good point. Good point. Thanks for that info. Thanks for that call. Yeah. This is, it reiterates, I think, the hacker spirit of just how do things work? If you're going to be using something, you're a consumer, figure out what's going on. How does it work? Is it sending this stuff to a cloud service or something as an intermediate? Is it only local? Is it using X, Y, or Z wireless standard? All of these factors can contribute to your exposure. Absolutely. Yes. You know, we didn't get a single call for the conference. I don't know. Well, of course, you know, it's hard to get through. I know. We only have the one phone line, so there's a lot of competition. If people would like to learn more about it, go to hope.net. Yeah. All the info is there. We will be posting all kinds of announcements. A schedule, of course, will be posted there as well. We have all sorts of amazing plans and things. Bring computers. Bring servers. Bring gizmos. Bring projects. Just bring yourself. Bring your inquisitiveness and zest for sharing knowledge and learning because that is what this event is going to be about. You can write to us, oth at 2600.com. And again, for more info on the HOPE Conference, hope.net. We'll see you there hopefully in about five weeks or so. And we'll see you back here in another week. Stay tuned for the Personal Computer Show coming up next. Good night. Hello, listeners. I'm WBI's General Manager, Bertolt Reimers.