388 Atlantic Avenue in New York City. Get your tickets at GiveToWBAI.org. at 516-620-3602. That's GiveToWBAI.org. 516-620-3602. I look forward to seeing you there, and tag, you're it! And you're listening to radio station WBAI New York. It's seven o'clock time once again for Off The Hook. We couldn't get much worse. But if they could, they would. One big leap forward for the best, expect the worst. I hope that's understood. One big leap forward! And a very good evening to everybody. The program is Off The Hook. We're joined tonight by Rob T. Firefly. Good evening. And Kyle. What's up? Well, what's up? It's the last week of our fundraiser. That's one thing. So we want to thank the people who called in last week and pledged. We did quite well. And we hope to do even better this week because it's the last week. And overall, not bad. Not bad at the station. We're talking about getting that new studio up and running. I believe there's a separate fundraiser going for that. I think we're getting very, very close to the $10,000 needed for that to actually go live. So please, if you just want to pledge for that, call 516-620-3602 and say you want to pledge for the new studio. But we also have various other premiums that we're going to be offering as well. We'll get into details in just a little bit. Before we do that though, I'd like to discuss the various Orwellian things that have been going on in the last couple of weeks. A long time. Basically, this has been set up for quite some time. I know, Kyle, we went to a talk once. I think it was at Chaos Communication Congress. Talking about systems in China where you basically have a social rating. Do you remember this? Yeah, I think it's called social credit. Yeah. And it seemed so alien to us then. And now it's getting really, really familiar. Uber. Uber. Remember them? They say they will soon be banning passengers with low ratings. If you don't have a high rating, you can't get an Uber. Imagine that. I've never actually been put in Ubers, but I've never taken one myself. I don't like the idea. I don't know how they got away with it in New York when there are so many people who have put their life savings into driving cabs and how cabs can simply be expected to coexist when anybody can be a cab driver. It just seems horribly unfair. But now they're doing things like this. They won't pick you up if you're not popular. I mean, that's insane to me. I've always thought of it as something that disruptors in Silicon Valley really like and think everyone else should really like it as well. But I don't think it's as cool a thing. And then there was always the specter of them automating and removing the drivers altogether. So their jobs aren't necessarily secure. But as you pointed out, people who've spent a lot of money on the medallions and what it's done to people who are licensed, insured, and have been really sanctioned and professional. They're trained. They're professionals. They know what they're doing. All the more reason to get the Curb app, which allows you to hail taxis. Okay, so they have an app too. Well, it's one app that contacts actual taxi drivers instead of these ride-sharing things. So there are alternatives, so check that out. The app is great. The app is amazing, what it can do. But why wasn't that integrated into the taxi system? The people who already are there, the people who do the job. Instead of just opening it up to anybody and totally screwing over the cab drivers. Well, I think a lot of it is because taxis are, in a sense, like franchisees. But I'm not sure. Actually, I think I thought you were going in a different direction with that. But yeah, in a lot of ways, it's difficult for them to have had a technology arm that would develop something that would work for everyone who is driving a cab. Yeah, but think of the alternative. They develop something that will just work for anybody instead of anybody who is actually qualified. I don't know. In some places, yeah, it works where there's no army of taxi drivers. But here in New York, you can't shake a stick without seeing a cab driver. That doesn't make any sense. There's a lot of taxis on the street is what I'm trying to say. So this app should have worked for that instead of causing the chaos. Anyway, so now you have a situation where if you're not popular, you won't be able to even use their system. Now, drivers have long been expected to meet minimum ratings to continue working on the platform. I guess you want a driver that people don't hate. But riders may now lose access if they develop a significantly below average rating. For now, it's significantly below average. It could just be average in the future. Riders will receive tips on how to improve their ratings. Man, we are being talked down to so much in this era. But now we will be told by Uber how to be better people. Encouraging polite behavior, avoiding leaving trash in the vehicle, avoiding requests for drivers to exceed the speed limit. Riders will have several opportunities to improve their rating prior to losing access to the Uber apps. And, you know, it doesn't end there. Any app, anything that involves social networking of any sort, this kind of thing can happen. This is only the beginning. And I think, you know, that talk that we saw in China, that was... We didn't see it in China. We saw it in Germany. That was something that is coming home to roost, I guess. Rob? In the city in particular, it's not just anybody who can be a driver on these things. You actually need TLC plates on your car. There's a certain amount of lobbying that the entrenched cab industry, which is not a saintly thing. You know, they have so much to answer for, the whole medallion bubble thing, which there have been exposés about recently and that sort of thing. But the one thing the traditional cabs did have going for them is they were basically... They held this position as sort of a public utility to the point where they were not allowed to just skip over anyone they liked for whatever reason. There were outcries in the past when it was perceived that cab drivers were skipping over people due to things like skin color. Yeah, and literally what you can see through your window, that is how they are judging people, skin color. You can't get more black and white than that. But now you know the history, the history of the person, their credit report or whatever they're going to add to this profile. And now they can be ignorant and judge people based on that instead of just what they see through their window. And it is something we're giving up, among the many things we're giving up as things shift over to this gig economy. Where instead of established entities that have standards they have to uphold and stuff, people are expected to just pass the work along to anybody who installs an app. And lose the protections that they might have had, had they just taken a damn taxi, for example. Wow. Okay, we're moving on. More Orwellian things. How about this? You know in England you can be fined if you don't show your face to surveillance cameras. This guy pulled up his jumper. What's the American word for jumper? It's sort of a long sleeve t-shirt or sweater type thing. He pulled it up over his chin as he walked past the Metropolitan Police officers who were basically running a trial of live facial recognition software in East London. Now BBC cameras were on. Everyone's filming everyone over there. BBC cameras were filming as the officer swooped in on the man telling him to wind his neck in. You know if someone told me to do that I wouldn't know what they were saying. So it's a good thing it was a British citizen they told that to. Wind his neck in and then handed him a hefty penalty charge. Now a campaigner from Big Brother Watch, who were also there protesting the use of cameras, was also filmed telling an officer, I would have done the same. Can you get fined for saying you would have done the same? Probably. In England I think you could get fined for that. Now police said they made three arrests thanks to the cameras on the day in question. And a total of eight people including two 14 year old boys were arrested during the course of the trial. Okay but were they arrested for crimes or for not showing their faces? That's the scary thing. In the video the man who has not been named explains how he was pulled over by an officer who got his back up. I don't know what that means either. I think maybe that means he got offended or something? Yeah he got annoyed. His heckles or whatever you want to call them? Hackles. Hackles. Don't even have that right. He told the BBC, I spoke to a man who said there's a facial recognition down there so it's a cold day. I've pulled my jumper over my mouth and gone. Okay police officers asked me to come over so I've got my back up. Wow this is just a fun... This is really poorly written. Yeah it's from a paper called Metro in the UK so it might be just poorly spoken. So my take on this is I think it's baseless. I think you in most all circumstances should be able to cover your face and protect your own identity. Given how much surveillance and tracking there is between phones and gate recognition and all the other ways they could track you. And I think where this is going to end up is something along the lines of body armor. Where if you do it in the commission of a crime it could be considered as a part of that prosecution or an additional offense. But if you are not committing a crime you absolutely should have the right to do this. And that includes going to a rally, going to a protest or any kind of action like that. And I really think people should challenge this or flout it more often than they are being scared into complying with this kind of stuff. And I really am excited and I know we personally have thought about different ways to evolve the kinds of masks and protection and countermeasures for this kind of technology. Because it's only getting more sophisticated and more economical for these agencies and individuals and private entities to make use of recognition a la Amazon or other such platforms that are being proliferated. What I wonder is have we already lost this battle? Because if you think of all the technology that's been introduced when has it ever been turned in the other direction? You have fingerprint identification to open up your computer. You have all kinds of voice recognition software. And here you have something really neat that the authorities can use and that we can have fun with as well. Do you really think they might turn back? Indeed. And it won't be put back in the bottle as we say. The other point that you're I think right on the outer edge of is that the police, the authorities, military operatives who wear balaclavas and police who wear body armor that obscure their faces. No badges, no badge numbers, just coded numbers for different teams and groups they're on in rallies or protests. That is a double standard. Of course. They are never identified. They're never identified in incidences of excessive force. They protect their identities. It is abhorrent. It's disgusting. Disgraceful. And it is a double standard we ought not accept as taxpayers, as the people who fund their very livelihood. If they're going to protect us, they need to protect us from them. Well said. Well said. On the subject of facial recognition, I don't know if you guys have been following Amazon. They were trying, well actually there was pressure on Amazon to ban facial recognition and only 2% of their shareholders voted in favor of this. You know something about this, right Rob? Yeah. The issue on the table was should Amazon supply things like entities like governments with access to their facial recognition technology. And there was sort of this grassroots effort being attempted to get the Amazon shareholders to vote for that motion at their shareholder meeting. Of course, Amazon has untold zillions of shareholders. I think Jeff Bezos is something like half of them. I don't know exactly off the top of my head, but he has many, many shares and many, many votes. Ultimately, only about 2% of the shareholders voted in favor of not supplying their facial recognition tech to governments. So, yep, they're going to do it. Both failed. Both failed. Both failed. Pretty dramatically. The thing is, the shareholders is one thing. Customers are another thing. It's unrealistic for me to say, yeah, it's time for the customers to vote. Because they're not. They're not going to stop using Amazon. We know that. There has to be other ways of applying pressure. Indeed. And the fact that it failed is one thing. But the two initiatives, as I read or as I recall, I think they were fairly toothless. I mean, they were a nice gesture. But none of them had any kind of enforcement clause or anything that was binding. And ultimately, I think it might have been a pipe dream to expect the shareholders to vote for something that would mean Amazon gets less money. I'd like to know more about their service though. Because it's designed by Amazon. It's called Recognition. With recognition, of course, spelled wrong. R-E-K-O-G-N-I-T-I-O-N. I'd like to know all about it. I'd like to know how it can be used, abused, etc. And I think we all should. Yeah. And there's also the question of accountability with tech like this. Because as is known with facial recognition tech in general, a lot of it does not recognize, does not correctly recognize, say, people with darker skin. Or, you know, totally identify people with 100% confidence. And so when somebody, like, say, a police officer on their little computer in the car, pulls up a picture of somebody that's walking around and it says that, oh, this matches with such and such wanted criminal, they're just going to go ahead and respond as though that's the case when the computer might be guessing with reduced dependability. And there are a lot of issues that still need to be worked out with how well facial recognition tech actually works. It's still not very good in the grand scheme of things. But once this is instituted in things like, you know, checkpoint, police checkpoints, airports, things like that, the powers that be are basically going to be treating it as though it's gospel. And that raises a lot of questions and a lot of problems, I think, down the line. Indeed. Yeah. And I'll say, just for our listeners and people in general, we're a bit disappointed. We'd like a copy of this software or information about how it works. Would you want our listeners to send us the software somehow? If it's possible, if you've done some research, if you wrote an academic piece or something and you want to share it with the radio program or the magazine, we're always happy to take that. We never got any standalone automatic license plate reader software, which we talked about years and years ago. And that was disappointing. So to that end, we haven't got the latest machine learning powered Facebook algorithm. I know it's carefully protected, but we're always open to having backups and taking care of that for Facebook and other companies. We did get one really nifty app that I've been playing with called Cop GPS. It's a GPS app that only tracks cops, tells you where the cops are in your area, what cop number they are, what the neighborhood is. That's great. Isn't that great? It's just like learning, and we really appreciate other people who have done the deep dive and done the digging and stuff. So Cop GPS is the app that I dreamed of this week. Every week I dream of an app that doesn't exist and hope somebody designs it. So please, whoever is capable of writing Cop GPS, do so. I know you've got to get the GPS onto the car somehow, the GPS device, but there's got to be a way. There's got to be a way to do this. Maybe there's another way we can track the car by the license plate number or something. It has some kind of property that can be monitored. I don't know. We'd like your ideas for apps as well. OTH at 2600.com. Just because it doesn't exist doesn't mean it's not a good idea. Quite so. Talking of a software we'd like to get hold of, I could quickly mention that 2600 still has a secure drop. How does that whole thing work? Yeah, we do. You can basically submit things through an anonymizing portal. Basically, we don't know who you are unless you say, so don't say who you are. And then we don't know where it comes from. And it basically allows documents and links, pointers, discussions. Stuff that maybe you want to tip us off with, but protect yourself. Of course, nothing is perfect, but it is one of the best ways to submit to journalists. And a lot of journalists and publications have taken on this technology in the wake of other leaks. And a lot of the centralized leaking platforms that were popular 10 years ago, we've learned that having one entity curate all leaks ever is just not as good as each publication taking this on themselves. Of course, we've always accepted PGP encrypted submissions to the magazine. So there's just this other way of doing it that allows a bit more anonymity. You can also send us stuff in plain text, send us mail, all of those ways. So this was a recent addition and it uses the Tor network and some special software. And it basically gives you an account and you can log in and communicate, talk about your submission, upload files and the like. If you want more information, you just go to 2600.com slash SecureDrop. Yeah, and as Kyle said, you need the Tor browser. I just opened up the Tor browser on this laptop here. And if you have the Tor browser going, all you have to do is go to our website, 2600.com slash SecureDrop. And what you'll find there, you'll find all kinds of information on our particular SecureDrop instance where you can make your submissions. You'll see a page explaining it all. And what that page will give you is a .onion address. .onion address is unique to the Tor network. And you must enter that address. Does not work on Firefox, does not work on Chrome, does not work on any browser other than the Tor browser. Is that right? That's correct. To be completely clear, the Tor browser is technically Firefox. It's a very specialized version of Firefox. Yeah, it uses the .onion domain structure, which is basically on the outskirts of what normal browsers and internet protocol use. So it's sort of a separate protocol that is only used by that network. That's the sort of short version. It's really interesting. It's been around for a while. This is redundant. But for those of you who don't know, you can find out more at torproject.org. And that's where you get the Tor browser. Of course. And Freedom of the Press Foundation and SecureDrop are great sources for more information as well. And I see our address is LXA4RH3XY2S7CVFY.onion. I'm sorry, I read that too fast. I'll read it again. LXA4RH3XY2S7CVFY.onion. That is our SecureDrop address. And when you enter that into the Tor browser, you get routed over to our SecureDrop submission site. And then that loads up. And you have all kinds of basic options here. Submit documents is the one that you really should click on. And then you submit a document. You simply drag it over. Drag it over and upload it. And you get a bunch of words. You get a bunch of words that you should keep track of. Because that is how you communicate with us in the future. Those words will tell you how to reconnect. And you can exchange messages. But we don't know who you are. That's right. And you can rest assured this is only seen by our editorial staff. And it is not going to be disclosed how your submission got to us. As I said, we have a variety of ways. We even pick up envelopes behind dumpsters. But there's a lot of ways to get content to us. And stories. And academic work. Whatever it is. Demos of things. Scripts. All that. And we're not going to sell it. No. You know, we're not selling exploits here. We're not doing anything with private anybody. But curating it from an editorial sense. So, that is our assurance to you. Although we would have paid a large sum of money for Donald Trump's tax returns. We would have done that. That was an exception. But by all means, not the norm for us. But in any event, it is important to us that you're confident. And lastly, we will never, ever give up a source. It's very important to us. It's been important to us for almost 30, I don't know, 40 years. However long. As long as we've been around. However long it's been important to us. We value our own privacy. And we treat yours quite like we would want ours. But just looking at the text over here. LXA4RH3XY2S7CVFY.onion. You'll see that it says, Welcome. Please either write this code name down and keep it in a safe place or memorize it. This code name is what you will use in future visits to receive messages from our journalists. In response to what you submit on the next screen. Is there any possible security issue with me reading the code name that's displaying on the screen now? Because it's only to me, right? It's not to anybody else. Just to give people an idea of the kinds of words that they'll see. Yeah, read a couple of the words. Maybe not in order or anything like that. But ostensibly these are randomly generated. So you've taken that particular organization of words. And it would be an example of it. I don't know if you would want to read the whole thing. But it's, no. It's not really going to affect anything. Every time there's a submission made. Which you've began the process through the site. A new random arrangement of those are created for that particular session of submitting. Let's assume I'm a hostile actor. I would of course read these words out loud. And display them everywhere. But I wouldn't be able to penetrate the security and uncover anything about anyone other than me. So the words. Droplet. Luncheon. Crayon. Ellipse. Pout. Carried. And underfoot. So I would type those words in that order. If I wanted to check on my submission. See if anybody had any questions about it. Because we do not track users of our SecureDrop service. And future visits using this code name will be the only way we have to communicate with you. Should we have questions or are interested in additional information. Unlike passwords. There is no way to retrieve a lost code name. Of course this one will never be lost. Because everybody knows it. And so if I submitted something right now. And I've told everybody the code name. I guess anybody can check it. Anybody would be able to go and check it. Why don't I do that? I could. Or maybe somebody. Why don't you do that? If I submit something now. We can start this big huge chat. With all these different people that. No? That's not a good idea? Okay. Well. Somebody. Look. If I thought of it. Somebody else is going to think of it. And maybe abuse the system. Yeah. I mean it's. It would be interesting. Interesting. I think. But I think. Yeah. Not as desirable as people. Independently. Contributing. Well yeah. Of course. But we're not. We're not putting the kibosh on that. Anyway. So that's a general idea of how SecureDrop works. Again. If you just want specific information. And you don't have the Tor Browser. Go to 2600.com. Slash. SecureDrop. It's a great way to submit information. To all kinds of journalists. All around the world. And it's. It's inspirational. The kinds of things that. The hacker community. Is coming up with. Because. That's amazing. That's. A major part of all this. Okay. Let's give out the phone number. So that people call in. And. Start pledging. Because we do need your support. In order to. Keep this radio station. This radio show. On the air. The phone number is. 516-620-3602. Now. Tonight. We are offering something. Very special. It's called. The Hacker Portrait. For a pledge. Of $100. Now. A hacker and artist. Rob Vincent. Hey. That's you. Rob T. Firefly. Isn't it? What a ridiculous name. Wow. Okay. I didn't know this was you. All right. So. Hacker and artist. Rob Vincent. Of WBAI's. Hacker Radio Show. Off the hook. That should have. That should have. Clued me in right there. Has painted many. Different people. And things. For station supporters. In the past. You have. You have. And now. It's your turn. To tell him. Who to paint. I'm intrigued. Pledge for this premium. And Rob will contact you. To ask for a digital image. That's basically. Just a. A picture. These days. Sure. You'll send Rob. A photo. Of yourself. Or maybe a photo. Of someone else. That you have. Permission to use. He will interpret. Your photo. In a painting. On stretched. Five by seven inch canvas. In an artistic style. Of his own choosing. Now. Of course. You'll need email. To do this. You'll need the ability. To send the file attachment. A picture. From your camera. Phone. Whatever. But. You can go to. Robvincent.net. And see examples. Of what he's talking about. Is that right? Absolutely. Yeah. I've done. I've done sets of portraits. In the past. Of like for example. Notable people from hacker history. And I put those on the front page. Of robvincent.net. Which is my own site. R-O-B-V-I-N-C-E-N-T.net. And you can. You can look at. The various styles. Because I. I painted them in. Sort of a range of styles. Ranging. Ranging from like. Realistic. To. You know. Like. Realistic. Cartoony. A bit surreal. You know. Just things that struck my fancy. While I was painting these people. And. You could get a feel for. What. What a portrait. Of say yourself. Or a loved one. Or someone like that. Might look like. If. If I were to paint it. And then you could commission me. To do that. Now this is something. That I don't do a lot. I don't open up. My commissions. All that often. Because. Work like this. Takes a lot of time. And. And supplies. So. I'm doing it. In a limited amount. To support. This station. That has been my radio home. For such a long time. And. Has been. A source of things. That I've loved to listen to. For far longer than that. And so. If you call. 516-620-3602. And ask for the Hacker Portrait. Or if you go to. Give2WBAI.org. That's give. The numeral two. WBAI.org. And search for the Hacker Portrait. You can pledge. A hundred dollars. Or more. To request. A Hacker Portrait. Of yourself. And. Yes. Then I will get in touch with you. We'll arrange. Which photo you're using. And I will paint it. Well. I have a question here. It says. A photo of someone. You have permission to use. Is that a legal thing? Can you not. Paint somebody. That you don't have permission to paint. Even if it's a photo of say. Nixon or something. I don't know why I picked that. But. Well. Nixon's a public figure. I'm probably. You know. There's probably nothing wrong with. Using a picture of him. Frankly. I am not. I am not a legal professional. My colleague. Is not here tonight. But. I am just. Basically. Trusting that whatever photo. You send me. Is something that. It will not cause problems. For either of us. If I were to paint. And send back to you. So. Yeah. That's. That's about the size of that. Okay. Again. The phone number. 516-620-3602. The Hacker Portrait. Is available for a pledge. Of one hundred dollars. Only available during this fundraiser. It's not going to be. Available after that. So. If this is something that. Strikes your fancy. By all means. Call in. You'll be helping. The radio station out. And you'll be getting. Something really cool. And unique. In exchange. And. We try to. We try to. Come up with creative ideas. And this. This certainly qualifies. As one of them. Absolutely. In my. In my work. As a. As a. Freelance artist. Painter. Visual artist. Whatever you want to call it. It's something that. I really enjoy doing. It's something that. Kind of feeds my soul. And now. Thousands of computers have been frozen, email shut down, real estate sales, water bills, health alerts, all kinds of things like that have been disrupted. But you know who wrote the malware that did this to them? Our friends over at NSA. It's true. It's true. They wrote this. And they lost control of the tool. The tool they wrote is called Eternal Blue. It was allegedly picked up by state hackers in North Korea, Russia, more recently China to cut a path of destruction around the world, leaving billions of dollars in damage. And imagine anybody else who's just interested in causing mayhem was able to pick this up. Now over the past year, the cyber weapon has boomeranged back and it's now showing up in the NSA's own backyard because they're in Maryland as well. And it's basically happening all over America. All kinds of little towns and cities from Pennsylvania to Texas are being affected. Now the NSA's connection to the attacks on these American cities has not been previously reported. We learned this in the New York Times actually. Now the agency has refused to discuss or even acknowledge the loss of its cyber weapon dumped online back in April 2017 by a still unidentified group calling itself the Shadow Brokers. Years later, the agency and the FBI still don't know whether the Shadow Brokers are foreign spies or disgruntled insiders. Thomas Ridd is a cybersecurity expert at Johns Hopkins. He called the Shadow Brokers episode the most destructive and costly NSA breach in history, more damaging than the Edward Snowden 2013 leaks, if you consider that to be a bad thing. The government has refused to take responsibility or even to answer the most basic questions, says Mr. Ridd. Congressional oversight appears to be failing and the American people deserve an answer. Well, NSA and FBI declined to comment. But yeah, you know, do you remember a bunch of years ago there was something called the Melissa virus? This guy in New Jersey wrote it and he didn't release it. He printed it on Usenet and he was arrested for that. Not for running it, for releasing it, for basically writing it and having it available. How is this any different? Except it's much, much worse. They wrote this horrible thing and basically released it through not having secure systems and they don't want to take any responsibility for this. It really seems unconscionable to me that this is the source of such a horrible thing. Absolutely. This was the NSA putting together a tool made out of malware for their own ends, for their own use. And they lost control of it because when software is set up to do things on its own, sometimes it's just going to get unleashed. And there was that case years ago with the bit of malware that was meant to affect just nuclear power plants and it got out on someone's USB drive and Stuxnet. And you know, some poor dope brings it out on a thumb drive and suddenly this highly laser focused weapon ends up just messing things up on a grander scale. And it's a basic fact of information security that if you have a vulnerability, say it's a vulnerability you're exploiting, you're say a three letter agency, you've written the software to exploit it, it's a basic fact of infosec that you're never going to be the only one who knows about that vulnerability. If you found it, someone else can find it. And if you have this tool, someone else can have that tool. Whether it's your version that leaks out or whether somebody else just happens upon the same thing and writes one of their own. So this is why, you know, responsible disclosure is important. The NSA is not doing that because they don't want people to be able to defend against their own bit of malware. So you end up crashing the city of Baltimore. Indeed, yeah. The Stuxnet was famously used for the nuclear centrifuges in Iran and it was theorized that it was developed as a tool by state entities such as Israel or the U.S. or both or neither, deniably. That exploited Siemens process control equipment that used the SCADA protocol and it was very well devised and was used to great effect. It stopped centrifuges in Iran that were processing uranium and enriching it for, I think, non-medical purposes, let's put it that way. And anyway, there's a couple critiques here. Stop me if I start levitating and jumping out of my chair, but one thing I'm hearing in this is, as Rob said, it's responsible disclosure has been, I think, superseded by creating marketplaces to buy, sell and trade exploits like this. A long time ago we reported on sites like Metasploit and other places where vulnerabilities and things you could exploit in particular systems and software were being traded and not traded necessarily, but sold rather. And that proliferation along with a lot of the private computer security renaissance, everybody has got their red teams and they're all consultants and stuff nowadays. They're everywhere. I think the unintended consequence is that the entities that are interested and have the budgets to buy this stuff are the government, are the NSA. So if they're not developing it internally, they will buy it from these marketplaces. So yeah, you're a hacker and long ago you didn't want to get busted because you found something and you think it's cool and it does something cool, but you don't want to take advantage of people or hurt people. But there are entities that do. What we did by creating these markets and proliferating these consultancies who have their own little toolboxes of proprietary stuff is that we made it desirable for hackers who may not have means, who find stuff, instead of submitting it and getting published and having the company respond by fixing the thing, in this case Microsoft, they end up trying to make a buck and they have really no ability to control how it's used once they sell that information. And so what this did, this became an information arms race. And in this case the NSA did it internally and the code name Eternal Blue stands for Eternal Blue Screen because it was prone to crashing and doing the blue screen of death on Windows machines and it exploits the SMB protocol or some aspect of SMB in Windows. But essentially they really, really worked to find this vulnerability and then they sat on it for five years and it was so fruitful and they used it to such great effect that they just continued to use it and sit on it for five years. They never told Microsoft. And as in the Stuxnet case, Microsoft security researchers were the ones to report on that I think at one of the chaos communication congresses, but at an event, a security event they discussed Stuxnet. The same sort of response came from Microsoft and I have to say in light of this article, Microsoft is actually, of course they're motivated because their customer base is suffering, but they're coming out as really sober and their attitude about this is like, no, this is wrong. And it, of course, affects their bottom line and people's trust in their operating systems. But again, we hear from Microsoft, yeah, this thing that we patched a while ago, it's really bad and it came about and was being used. And of course, here we are listening with bated breath on how Microsoft is dealing with this. And the fact is, a lot of computers were not patched and Microsoft's security arm is dealing with this daily because state actors and people that are copycats with this malware that was released and out in the wild after the NSA lost control of it, this is particularly useful for small state and local entities and businesses that really, they just want to sell gravel or fix roads or supply water to 1,500 people in God knows where. But those machines, they aren't in an organization that is teaming with money and IT departments that can be tasked with fixing all of this stuff. So invariably, they are a great attack vector. These small companies, these small towns that have machines, yeah, they have a Windows machine and they don't consider themselves a target, a traditional target. They're not a big infrastructure. But the exploitation of them en masse becomes this large, soft target that can create revenue. And that is what this Shadow Brokers team is after. And they're really keen to raise money. And the last thing I want to say is that I think Baltimore is not paying as a point of pride, but I also think that they're really trying to find out who they are. And by leading them on or not paying, refusing to pay, they can maybe continue to communicate and try to find out who they are. Does it really matter who they are at this point? The tool is out there. The tool is what's causing the problems. It was written by NSA, used God knows how many times on foreign adversaries. And this is just, it's a wake up call to us because this is how the game is played. We act all self-righteous when we discover that Russian hackers were trying to dominate or influence our election. That is how the game is played. Nothing should be surprising about that. This is what we do. This is what they do. Happens all the time. And if you want to make any changes, you look to your own organizations, you look to your own intelligence agencies, your own governmental policies, and you see if those are things that you support. And if so, this is the payback. This is what happens. Somebody finds it, somebody uses it against you. And that's what Eternal Blue is. That's what it's all about. And I think NSA needs to take ownership of that and deal with the consequences and figure out a way to, I guess, make it not so harmful. I don't know what possible way there is at this point. Like Kyle said, they didn't tell Microsoft about it for five years. And then when the breach happened, they kind of had to talk about it at that point. The Baltimore attack took place on May 7th. It was one of those classic ransomware assaults. Screens of city workers suddenly locked. A message in flawed English demanded about $100,000 in Bitcoin to free their files. We're watching you for days, said the message. We won't talk more. All we know is money. Hurry up. And one of those messages. So they have not paid. Their systems remain locked up for the most part. They've restored some. The thing that really kind of bugs me about this, had they been keeping diligent backups, they could have just restored from that. And that is something that I see so many times. Whether it's individuals or whether it's companies or whether it's governments, they don't have a good backup plan. And sometimes a backup involves putting things in the cloud. Okay, if you're good with that, then do that. But do something. Don't assume that things are just going to be peachy every single day. Because things like this happen. Sometimes they're from down the block, sometimes they're from across the ocean, but they will happen at some point. And if they don't happen, you know what, a hard drive will fail. And then you won't have your data because of that. So these backups are hugely important. And don't just replace one backup with another. Keep an old backup in case something happens that corrupts everything within the past year. Have a backup from a year ago. Have a backup from a month ago. Have a backup from a week ago. And keep updating the weekly one and then replace the monthly one with that. It's simple to do, but you have to start doing it. Once you start, it becomes second nature. In this particular situation, I don't know how it's going to wind up, but it's a wake-up call I think for all of us. Yeah, I would just add OS diversity. And also, in other words, having more than one operating system in your shop or in your business. It's not easy for everyone, but if you just run Windows or you just want to run Apple, that can become a difficulty. But if you have a lot of different systems and also how you set up your IT infrastructure. Do you have subnetting going on and stuff like that? Also not particularly easy, but it's really helpful by adding just some additional layers to things and segmenting parts of your network and so on. And just practical things that can protect you from the sort of viruses or malware that people are experiencing. Yeah. One should hope that other cities are looking at Baltimore right now and taking an extra hard look at their own operational security practices and maybe working toward preventing something like this happening to them. All right. I also wanted to mention in the few minutes we have left, by the way, phone number again, 516-620-3602. Pledge what you can afford. Get that hacker portrait of yourself or a loved one or a hated one or whatever by calling 516-620-3602, pledging $100 and asking for that. We also have the Hacker Digest lifetime subscription available at that same number. But the Huawei band, am I saying it right? Huawei. Huawei. That's it. Huawei. The Chinese phone company that is being banned in the United States thanks to Trump and others. That is actually, according to the New York Times, threatening wireless service in some of our remote areas because many small carriers depend on inexpensive equipment from the Chinese company. I just think it's kind of ironic that we're concerned about this Chinese phone company doing the bidding of the Chinese government, hence spying on us. So Google goes about and at the behest of the U.S. government, bans them from using Android. I mean, doesn't that seem like the same thing? They're basically at the behest of the government doing its bidding and cutting off access. We're afraid that they will do something similar to that to us in the future. I know there's a difference. I know one is much more of a totalitarian regime, but the mentality is very similar. It also seems just a bit bananas to me because, I mean, I don't know if you could find a piece of electronic equipment in any of our pockets or maybe even in this room that didn't at least have part of it come from a factory in China. What's making an example out of this one company going to really do if the big bad now is supposed to be Chinese equipment? O'Reilly Yeah, I hear what you're saying. And indeed, there is some nationalism. It's rife with nationalism in here. You can kind of take different sides very quickly, but there is nuance as well. In my opinion, it's good to remember that, yes, the NSA is deeply entrenched in the telecommunications network for both private telcos, ISPs, and these service providers, search engines, whatever you want to call Alphabet or Google, etc. They, however, are independent private entities. They're operating within a market that requires them to provide products and make money independently of the government. The distinction with Huawei is they are not doing things at the behest of the Chinese government. They, for all intents and purposes, are the Chinese government. And that means they're being bankrolled by them, too. That means they don't have to wait until they can maybe afford to possibly research new telephone switching systems. They are absolutely funded by the government to accelerate the development of those technologies because it would position them in the international telecommunications market to take advantage of having their wholly backdoored equipment within different systems. I'm not saying that Nokia or Lucent or whatever switching provider AT&T or other operators are considering right now for 5G and other generations of whatever's going to replace switching system 7, but they are at least in a position where they're being coerced, not by design. Is that any different, though, than U.S. government bankrolling the airline industry, which would not survive without that funding? I absolutely agree. And again, there's many double standards and so on. But I do think that, and I feel the same way about the petroleum industry, but that is a different market. And again, I know the airlines are subsidized heavily, and thus we have less train and other sorts of mass transit that this fast ability to fly would come in and don't get me started. Oh my God, China would build the trains. That's why they're so against trains in our government, because China would probably be the ones building it. Look what they did in their own country. Right. Well, and also, let's not forget that quantity matters when it comes to jet fuel and airplanes. And if you can prop up with people using planes and jet fuel, you can make the cost of large planes that are maybe military versions much cheaper. So it's cheaper for Boeing to build tankers, or it's cheaper for Lockheed to build fighters, if more of the technology transfer to consumer goods is helping on the sort of civilian side of that. And that goes to jet fuel, too. I just think that it's basically a choice that we have. Do you want NSA spying on you, or do you want China spying on you? Which would you choose? I would want to use encryption, knowing that the NSA is probably spying in China as much as possible. One of them is going to get through. And I don't see the difference. I don't care if China knows what I'm doing. I kind of care a little bit more because NSA is just down the road. I disagree. Well, okay, fine. You can have the NSA. I'll go with China. See where that gets me. I don't see why they would care. I know it's a lot more complicated than that, but I just don't like these people in charge now making these kinds of decisions, because invariably, they are the wrong decisions. And we're going to have to leave it at that. Please give us a call, pledge whatever you can support, whatever you can afford and support us in these last few minutes, 516-620-3602. Pledge for the Hacker Portrait. Pledge for the Hacker Digest, the lifetime subscription of that. And write to us, oth at 2600.com. And we'll see you next week. Have a good night.