at the Museum of the City of New York, 20% off sessions with life and career coach Nina You will also receive a WBAI tote bag, which you can use to carry around some on-air giveaways. go to Give 2, that's the number 2, WBAI.org And you're listening to radio station WBAI New York, where the time is, oh, 8.01. Hey, we're late. It's time for Off the Hook. The telephone keeps ringing, so I ripped it off the wall I cut myself while shaving, now I can't make a call We couldn't get much worse, but if they could, they would Bum-diddly-bum for the best, expect the worst I hope that's understood, bum-diddly-bum Bum-diddly-bum Bum-diddly-bum And a very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you. Joined tonight by Rob T. Firefly. Wait a minute. Hold on. Try that again. Good evening. Yes. Alex. Good evening. Kyle. Hi, everyone. We have a special guest. Greg Newby is here. It's great to be here. All the way from Canada. All the way. Wow. Good thing we were on this week. We weren't on last week. And hopefully we'll be on again next week. We'll see. So this is the show about hacking. About technology. About all kinds of Whoops. Hitting the microphone. Because we're so crowded in here. And we have a lot to talk about. A lot to update people about. Thank you everybody who called in during the fundraiser. Which is over now. Happy to say. And we are progressing with all sorts of technology type issues. Still working on Hope Conference planning. Hopefully we'll see how that progresses. We'll have updates for people in the weeks ahead. And all sorts of other stories are happening. Actually, let's talk about a couple of these. And I'd like to talk to Greg about some of the things that he is working on. There is a I saw this story on the way in. I didn't really have time to go over it. I kind of misread it. I saw there was a White House proposal to have the FCC and FTC Police, what I thought was alleged social media. But actually it's alleged social media censorship. So it's not like the FCC and the FTC will be watching over Facebook. They're going to be watching over whenever Facebook does something that Trump doesn't like. In other words, when they decide that some right wing hate speech is unacceptable and they erase it. Trump will have the FCC and FTC step in and do something about it. Is that an accurate description? Yeah, to defend it on his behalf, which I expect no less. Wow. Rob, I believe you posted this story. So is there something about this that's particularly significant? I just think it's really significant when government agencies are directed to enforce the partisan will of the president rather than the people. Well, that's what they're for. That's what I'm being told anyway. That's what's going on. So as far as I can see, the FCC is not going to be controlling Twitter or controlling social media. But rather, for some reason, they're going to be used to see if these groups are acting unfairly against a particular political party. Instead of policing, I think the right to speak versus hate speech, they're policing the actions of these companies to wield oversight over that kind of activity. And it just seems like a misplaced focus, right? I mean, it's about their responses to something. So it's not about the building burning down, but it's about how the firefighters are running in and perhaps what positions they take in that process. Wow, Alex, you must have some thoughts on this legally. Yeah, I mean, this could dramatically alter the Section 230 immunity under the Communications Decency Act that our friend Ron Wyden was instrumental in putting into place, which allowed the Internet to really proliferate. And it's what allowed platforms to grow. That Section 230 immunity gives Internet communications platforms and interactive computer services immunity from suit for the content that they host on their particular platforms because they're not necessarily in control of all this content. When you have massive amounts of content coming in and out, you're not necessarily responsible for it. What's deeply troubling to me is that it puts the FCC and the FTC in charge in a manner that could be based on viewpoint. And that any kind of determination made by the government that is on the basis of viewpoint should be inherently suspect, strictly scrutinized, and very narrowly tailored. And this seems to be none of those three. So I think that if this were to go into effect, number one, it would be by executive order, which is exactly the kind of thing that Trump was rallying against when Obama passed executive orders to alter fundamental policies in the United States government. And secondarily, I believe that it would be immediately challenged in federal courts as unconstitutional on the basis of viewpoint discrimination. Well, we'll see. We'll see how that turns out. It's concerning. And certainly a lot of things going on in social media these days is concerning one way or another. But the control of it and the basically monitoring by federal authorities, that's always been something that's been of concern to us and something that we'll be definitely watching over. Greg? Well, it's interesting to me that if you are censored on Facebook or any other social media platform, you don't really have a lot of redress. There's not much you can do about it. The company has some rules which are often opaque in the first place. And what this is saying that if you are censored and have a problem with it, and maybe have some powerful friends on the other side of the opinion fence, that the government will come to your aid against this. Will they, though? Will they come to your aid if you're not somebody who is aligned with that government? Well, that's what I'm saying. For those that are aligned, suddenly you have someone on your side to suddenly question where most people cannot question the types of censorship acts. I think the term is eligible victims. If you're an eligible victim, they'll come and they'll fight the big mean tech companies that are infringing. There was one instance last week which really got my interest. And I'd like to know what you guys think about this. Mitch McConnell's election team got suspended from Twitter for posting a violent threat. But the violent threat was a recording they made of somebody outside Mitch McConnell's office or home, a violent threat made against him. And, you know, I'm certainly no fan of Mitch McConnell, but I'm also not a fan of violent threats. It seems to me if somebody makes a violent threat against you and you put that on social media to show what people are saying in your direction, that shouldn't be used to penalize you. You're showing evidence that somebody is doing something that's wrong. But the response of Twitter was to kick Mitch McConnell's team off Twitter. I just think that's a dumb move. And I think it makes them look good. You guys have a different opinion or the same opinion? I mean, those would be in the eligible victim camp probably in the first place. But it sounds like in this case, the companies, what we've been reading about how the censorship occurs, whether it's YouTube or Facebook or Twitter, is there are thousands and thousands of people that are looking at, you know, millions of messages, a lot of automated flagging going on. Sometimes censorship is automated. So it's easy to think that this is probably just a some automation or some sensor gone awry, not realizing that it was the type of situation you're talking about, which is, you know, sharing a threat that was against you, which, you know, I think a lot of people think is reasonable as opposed to a threat that you yourself are making. Well, if it's something that's automated as opposed to an actual decision. And yeah, you know, it's another argument against the automation of these things. Even if it's moderated, they're not doing a very good job of reading context. Maybe they're not an English native speaker, or maybe they're just overworked. And, you know, anything that that's mean gets the flag reinforced. But we agree that that's not the right thing to do. If somebody posts a threat made against them, they shouldn't be the ones penalized, right? No, I mean, this is a long pause there. The whole thing is silly to me. It just shows you that nobody really knows what the hell they're doing here. I mean, the whole thing is a complete morass and a complete mess. And it's chaotic and unpredictable. And that's the way I love it. It does point out how it shows how ill equipped I think these companies are to actually meet the challenge that is before them. They can say they're proactive and that they have mechanisms and that they're working on these. You know what they need to say? They need to say we are ill equipped. We are overwhelmed. I think if they said that more, because we all know it's true. If they said that more, I think we'd be more accepting of them for realizing that they're in over their heads. They didn't know this was going to get so big. We're trying to deal with it. Please be patient. I'd be a lot more happy with that kind of a statement than saying, oh, yeah, we're doing the right thing. We know what we're doing because you don't. This is reminding me of when last year, near the end of the year, I think, when the site Tumblr decided to shut down all adult content on their service. And so they put in some filters in place. And we spoke about that on this program. And their announcement about what they were going to start filtering out itself was caught by their own filter and filtered. And then posts about that happening were filtered. And it was a great example of why we shouldn't trust AI and algorithms to make all these decisions for us. But at the end of the day, I mean, another thing I find interesting about this whole thing is that social media is such a nebulous definition. I mean, you've got your obvious social media. You've got your Twitters and YouTubes and whatever. But then you've got things like someone's blog who has people writing in the comment section and generating content that they don't control. And, you know, at what point are people going to start being held responsible for stuff that they had no hand in creating? Greg, I notice you're amazed by our soundproof studio here. We're hearing fire engines, people walking down the hallway. There's a dog down the street. We heard that. It's very real. Welcome to Brooklyn. You're welcome to Brooklyn. We're really in Brooklyn. The new studio will be more soundproof, I'm told, even though it's right next to our window. We're looking forward to that. Yeah, it's being soundproofed every single day. It's more and more soundproofed. All right. Speaking of artificial intelligence and all that kind of thing, what's this about Amazon being able to sense fear now? I didn't really get the whole story on this. There's just so much going on. But there's some kind of AI that they're able to tell when you're afraid of them or something? It's their facial recognition system, which is something they make available to clients to use. And apparently the thing can sense fear now, which I don't know. I've seen too many dark sci-fi movies to be comfortable with where this is going. I don't think you need to see any. I think you need to just watch this. This doesn't sound good at all. But also, I don't know if one of the biggest retailers in the world needs to know when I'm afraid. Who needs to know? Is this for government agencies to see who's about to be afraid of them? I don't know. It's scary. I don't know exactly very much about the mechanics of how this would work. If you could explain that, if you have any idea, Rob. I mean, are they looking at facial expressions? It's a very strange thing to me. As somebody who was subject to polygraph examinations a few years ago. It just had one now downstairs. I don't know what that was all about. Well, that was just for fun. This coffee shop, they want to make sure you want what you're ordering. That is true. If you ask for oat milk, you better be serious about it. I know. A series of yes and no questions. Who told you? Yeah. How'd you find out about the oat milk? That's right. And anyhow, I mean, those things are pretty well designed in order to determine whether or not somebody is under stress or anxious or nervous by using a galvanograph on your finger and measuring the output of the sweat on your fingers and your heart rate. So, I mean, I find it strange that Amazon thinks it can do this quite clearly when there are so many news stories out there right now about deficiencies in its facial recognition system and, in particular, deficiencies where lawmakers, black lawmakers in particular, were misclassified as convicted felons or people that were previously subject to arrest, criminals, et cetera. So, the measurement of fear on the basis strictly of video, I think, would be inherently suspect to me. I don't really love, but I love the revelation that artificial intelligence is racist. But it's not surprising. It shouldn't be surprising because who programs it? White people. So, obviously, it's going to be racist. Right. Or the data sets that are used to teach that software are used from our penal system, which itself is racist. So, I mean, there's plenty of steps along the way that that can be. It's ingrained into our society in so many ways. This is a great way to demonstrate that. Yeah. And this software of Amazon's, which is called Recognition, but instead of a C, it's spelled with a K. I was going to say, they have to spell it wrong. That's like page one out of the Evil Overlord handbook, I think, to start spelling things like that. But they have this thing, and they're saying that they've improved it in so many ways, in addition to being able to tell people's gender and other things about them, but also their emotional state from their facial expressions. And facial expressions aren't always an indicator of people's emotions when you're just looking at someone face to face. I mean, there are people with all sorts of different faces, all sorts of different facial types. There are people who express themselves differently. There are neurodiverse people on various spectra. I mean, there are so many things that could cause false positives or negatives in this thing. And I really have to wonder what people who are buying a facial recognition system that can tell emotions is doing with it. And I assume this is being marketed towards law enforcement and other agencies. What isn't? Yeah, but it's not being marketed towards us, right? We can't just buy recognition and play with it and see who's afraid. Well, we probably don't have the budget that they're asking, you know, for those types of clients. Well, if it's downloadable. Well, okay, fine. But I'm sure somebody will find a copy of it somewhere, and we can... It's definitely something that's being pitched to law enforcement agencies, including, apparently, ICE. So... Oh, joy! Wow! How nice! So see which inmates are the most afraid of you. Joke's on them. I assume everyone's going to be afraid in this society and everybody at the border and everywhere else. So, I mean, yeah, if everybody's afraid, what are you really proving with this? Is there a feature on there to tell when people are angry and about ready to say they've had enough and they're not going to take anymore and they're going to fight back? Do they have something for that? I think they're going to need it. I think so. Actually, that's a bad thing for them to have, because then they can tell. Well, look, I mean, in as much as facial recognition, and whether it's with a C or a K or whoever, you want to spell it, or a C-H, you know, it doesn't really matter. As long as you spell it wrong. Yeah, as long as you spell it wrong. It may seem like it's having a comeback, but I really think that there... I mean, if you look at what's going on in local government around the country, you look at Oakland, you look at San Francisco, you look at, I think, 13 cities around the country, and you see that there's real pushback here. And in particular, pushback against facial recognition, especially being used in body cameras of actual police. I mean, here you're taking something, a technology. I mean, we talk about function creep all the time, but we're taking a technology like body cameras that are supposed to increase transparency, increase the accountability of the police force to the civilians that they serve. But instead, when you implant facial recognition technology into those body cameras, you're taking something that was about transparency and accountability and turning it into a mechanism for invasions of privacy. So we're seeing a lot of pushback at the state and local level, and we're now even seeing pushback at the federal level with a bipartisan bill that was sponsored by, I believe it was Jim Jeffords... I'm sorry, no, Jim Jordan, who's Republican. Jim Jordan and Elijah Cummings. And Elijah Cummings, that's right, yeah. And this thing might actually have some legs. A bipartisan bill on facial recognition. That would be very interesting. I mean, it's coming down the pipeline, and Congress will debate this when it's in session. And I think, you know, this is a reason to tune into C-SPAN. We know that Kyle loves to do that. Yeah, many reasons to tune into C-SPAN. Believe me, I'm already tuned. There's only three C-SPANs, too. We need more of them, because there's so much to cover. Well, there's CPAC. You mentioned, that's Canadian, but you mentioned the laws to ban government use of facial recognition. San Francisco, Oakland, did you name the third one? Seattle. No? No, Somerville, Massachusetts. That's right, Somerville. Many people don't get Somerville. And also Cambridge is working on something. Yeah, they're moving forward with something. Yeah, moving forward. But it's good, I mean, and it's great to see local politicians, local mayors, and civilian review boards really taking account of this. I mean, and when you combine that with the fact that there has been a revelation, I think it was in the last month or a few weeks, that Immigration and Customs Enforcement had access to the photo databases of 21 states when it comes to driver's licenses. And then those driver's license photos could be used in some kind of facial recognition system out in the wild. It's a terrifying prospect. And the people who were against undocumented aliens having driver's licenses found themselves in a real pickle, because now you can find them all by going through those photos, and ICE has a field day doing that. But if you're against them getting them in the first place, well, you take away that tool. So what do you do? Do you support it, or are you opposed to it? It's an unintentional but foreseeable consequence of giving civil rights to illegal aliens, I guess, is that you can track them better. But the issue here, too, is that there will be some deficiencies when it comes to governmental bans on facial recognition technology. And those relate to how far-reaching that ban can be, because they are going to ban their police forces. They're going to ban their municipalities, their cities. There may be some kind of federal ban on law enforcement if this bipartisan bill has legs to it. But what won't be banned is the private use of these things. And when the private use of facial recognition technology proliferates in any manner whatsoever, all of that information is going to be stored somewhere. All of that information, therefore, can be accessed at some point by law enforcement through legal process and even private parties through legal process. So the fact that we're banning it publicly via public institutions is one thing. But I think we also need to put some pressure on private institutions. I mean, it was bad enough to see CCTV cameras all over London first, now all over New York. My six-year-old son is constantly spotting them out. We play games about, all right, where's the camera's blind spot? It's good that he's looking for them. He looks for them all the time. And it's like part of his life is looking at these security cameras now. He's very aware of them. But I think we all need to have that kind of innate recognition about this. Alan, let me ask you, do you think it's bad to have CCTV cameras everywhere only if they're tied into a network? Or is it different if there are cameras run by individual people or businesses just to look out for their own property and they're not tied into a system and they have control over who gets to see it? It's definitely easier to exploit when it's tied into a network and it's in one centralized place for sure. But if they are disjointed, you can still access – law enforcement can still access that CCTV footage very easily through legal process. And in most instances, people will just give it to them when they ask without even demanding that legal process be presented to them. Sorry, I just want to jump in. To say nothing of the fact that a lot of the surveillance kits themselves are run by specific companies that themselves – and they are ostensibly so that your app or whatever you're using with your doorbell, they're all online anyway. So, I mean, let's not kid ourselves that as much as it may be standalone, it very well could be tied into something whether you know it, like it or not. With the doorbells, tying those into a network where an entire community is being pressured to basically share who's at their front door with the police and everybody else. So that's very different than somebody just running something on their own and they have to be asked before they give it up. I think that there's a difference there. People like to see who's outside, who's prowling around. Or if there's an incident, they are forthcoming. They want to contribute what their cameras saw. They have a vantage that could help in an investigation that hurt their community. We saw a lot of this last week with the Ohio massacre and so on. Right. But, you know, it is an unhealthy situation though when you just assume you're always on camera. You can't do anything that you won't be able to account for. And just, you know, look back on our childhoods. How different would they have been if we had been watched every moment? Greg? A pop quiz for people that were listening a couple weeks ago. What was the name of the company that was making these surveillance doorbells? Ring? Amazon. Oh, okay. Wait. It's the same company that we're talking about. Yeah, you're right, isn't it? With the facial recognition systems. Is Amazon owns Ring? Yes. Yeah, they bought it. And I think Google owns Ring. No, Google owns. No, that's the smoke detector. Google owns Nest. Yeah, they're in the same business. And the blender. But the one you talked about was Amazon. And the toaster. And the. Did you hear CBS and Viacom got back together? Mm-hmm. And everybody's acting like it's the first time. Wow. Okay. So lots of surveillance out there. Lots of facial recognition. And it's scary. You know, we have to stay on top of this technology and see how it works. And abuse it whenever possible to see where the weak points are. To see where the abuses coming from the technology emanate from. And if you must use this particular type of technology. And of course there are legitimate usages for CCTV in security settings. If you need to have a secure facility. If you need to monitor who's coming in and out. Industrial control systems, et cetera. If you have to do this. And you have to monitor public spaces to keep your facility safe. There are ways that you can limit the amount of data that you're collecting as well. I mean, you have to take a look at your data retention policy. And make sure that it's a short enough period of time. That you're not going to unintentionally infringe on the privacy of innocent passersby. People just coming and going. So that if you do get a request for information. Whether it's from a private party or law enforcement personnel. You don't necessarily have that data. If you don't have the data, you don't have to hand it over. But this is where these corporate policies really become quite important to everyday life. Right. So I think we have to live with the fact that it will be part of our lives. But we should expect that people implement this type of technology at the very least responsibly. Hey, did anybody catch the test of the emergency broadcast system last week? It was on all TV sets. But this was interesting. It was run by FEMA. It was a national test. Happened at about 2.20 p.m. I think on Thursday. Last Thursday. This is a test of the national emergency alert system. The message read, if this had been an actual emergency, an official message would have followed a tone alert. You heard blah, blah, blah. This was different though. This was different than the ones that we usually see on TV. Because this seemed to come from the cable company itself. You couldn't change channels. You just had a message on your system. And it stayed on there for a couple of minutes. And I happened to be recording something on DVR at that point. Didn't get recorded. It's not there. So it was only something that got sent to those systems for people who were watching them live. And it's, I guess, just another method of getting that alert out there. So we've seen a radio EAS test. We've seen television emergency tests. We've seen tests sent to our cell phones. And now this. I just wonder how many more tests they're going to be going through in the next few years. So your DVR didn't record the test? Did not. Did not record it at all. Because it didn't seem to be coming over a channel. It seemed like the whole cable box just was disabled. And this message was put on. It was Altice, Cablevision, Optimum, whatever they call it this week. It basically just said this is some kind of emergency alert. But it wasn't, you know, if you changed your channel, nothing happened. That was just there. And then eventually it went away and your regular channels went back. And I could see why people recording something wouldn't want that on their DVR. Of course, I did want that on my DVR. But there's no record of it. That's interesting. Because that means it's interacting somehow with the actual OS of your cable box. Yes. Apart from the DVR, which is all stuff happening on the back end that your personal box really has nothing to do with. And that's interesting. I'm wondering how accountable this is. I mean, I doubt they're using an open source OS on those things. Most definitely not. And what was on the DVR itself? Just the program progressed normally? So when you went back to watch Friends, it wasn't interrupted? Okay, it wasn't Friends. It was something Trump was doing that I couldn't believe. And he did the whole thing. So, yeah, it was not interrupted at all. I'm trying to find out what the actual message on that channel is. I don't have it in front of me. But I'm sure people with Altice have seen this. Other cable companies around the country have seen this as well. Some kind of a test or alert message that just shows up on your screen. It's got a blue background, I believe. Well, the only small point I can add to this is I was in Canada at the time listening to Sirius XM on the radio, and I heard this test. Oh, you did? So it was in Canada, but it was a radio. So I don't know if it's exactly the same thing if you're talking about one that was just on video. But it was the three tones, you know, followed by the other three tones and the announcement. So it was sort of the standard test. One other thing about the one Cablevision had is the message itself was unintelligible. Yeah, they basically did one of these things where they played the same message over and over again, and then you heard this human voice. But it had been recorded something like 10 times by that point, and it was just muffled. You couldn't make out anything it was saying. And I imagine they were just handing it off one relay to another. Maybe that was the test to see if anybody could understand it. Well, that's the nature of a real test is you're doing some – I mean, the real system, I mean, is you're doing some rebroadcast of the message. That's the sort of thing that I heard, I think, actually, too. Uh-huh. Now, this is – actually, I found some information. You see a message that says Altice Information Channel, and then a name of a city or the name of your local cable company or the region that you're in. And that screen stays on for a while. So that's another version of that test. So, yeah, that was interesting. Well, I'll tell you this. We will have some more information about this next week. I know some people over at Altice. Okay. We'll figure this out. All right. Sounds good. Maybe you can get into Kary Al-Jazeera, too. That would be nice. Perhaps. Instead of Newsmax TV. What the hell? Yeah, that's not real. Well, just in terms of what Rob mentioned about sort of backdooring the operating system on the cable box, we know this is what's in our phones already, right? We've been talking about how the phone just gets taken over and you have little that you can do about it. So there certainly has to be some sort of, you know, whether it's a standard or a software package or something that's enabling all these manufacturers of all the cable boxes and all the companies to be hijacked, right? To be willingly hijacked for the duration of the event. And all that seems to be opaque to the end user. Yeah, it seems to be part of the protocol. I don't know if what it is these days, if it's like DOCSIS related with coax and these kinds of systems or if it's like something completely different, like another layer of what you would provide all of that content over like a broadband setup. I'm sure Verizon's offerings are different with their fiber and so on and so forth. But it seems to be built into the protocol. It seems like it's a low level part of it adjacent, but not at all like a part of the OS itself, like the user interface just seems to disappear. And it is another avenue might be just that every single signal that was being broadcast, whether you're in a menu on the box or you're just watching a channel, every single signal just got that channel switched out across every single channel. I mean, would that be even feasible? It didn't pick it up, right? So I don't know if that's something a little different. Yeah. Was it blank in the DVR or just a jump in time? It didn't happen. There was no record of it at all. It just did not. And that's the thing that really bothers me. I have this thing about how old technology many times is better than new technology, but without being a Ludite about it and saying that we should abandon new technology. But I mean, think of it. You have landline to landline phone calls. They sound much better. You can actually talk at the same time as somebody else, and they hear you. It's like a real conversation. Turning a TV channel didn't take 10 seconds just to switch to a new channel. And recording something, you recorded what was on the TV. And now they can change the commercials on the DVR to update them. They can erase things so that they never happen. They can delete programs they don't want you to see anymore. And this, where there's an emergency test. And I saw it. I was there. But there's no way to prove that. And there's no way to look at it again. Yeah, so I take my theory back. I would say it's sending out a signal that's bypassing all of that. And their DVR recording functionality completely gets bypassed in the process for the duration of the test. It's just completely not a part of the service at that point. But it doesn't seem to be the EAS alert itself doesn't seem to be a part of what they're broadcasting on the traditional multiplexed coax network. Unless it's being broadcast by the local channel, in which case it would get recorded. Because they're basically sending that out on their signal, and you're recording that signal. Is that like the red crawl that you get? No, it's not. Okay, we see the red crawl saying there's been a monthly test issued. Every night you see this at about 3 a.m. And that doesn't get recorded either as far as I know. So that's a different kind. There's so many different kinds of tests. We should write them all down because it's very different from back in the 80s and 90s when you had emergency broadcast system, EBS. But now it's emergency alert system, EAS. And I'm sure our listeners probably have something to say about this. We'll take phone calls in a little bit. 212-209-2877. We'd like to hear from you. Yeah, tell us about the system. What resolution? What kind of graphics? What are the capabilities of this platform? We want to know. But right now, we should tell you that there's been a fourth Florida city that was hit by hackers in less than two months. The city of Naples, Florida, has fallen victim to a cyber attack, a targeted spear phishing scheme. Basically, a fake bank account that was provided by the attacker while posing as a representative from the Wright Construction Group, which apparently was owed money by the city of Naples, paid them $7,000. And this type of—I'm sorry, I missed a zero there—$70,000. This type of business email—I missed another zero—$700,000. You want me to keep going? I'll keep going. But no, that's it for now. $700,000. That's what this slip-up cost them. This type of business email compromise targets businesses and individuals performing wire transfer payments. That's according to the FBI. And last year, victims in Florida alone lost $82,979,000 to this type of scam. But the city of Naples really contributed their share. The money taken was owed to the original Wright Construction Group for a renovation project the company was doing over the summer to improve water utilities. So hopefully their water is working all right. Their funds aren't as rich as they used to be, and certainly their cybersecurity needs some work. And yeah, the fourth city that this happened to in Florida. Let's do the other cities where I know. Lake City was one recently within the last two months. Yeah, Lake City. How did you know that? Alex, how did you know that? I just know these things. Wow. That seems like a variation on whaling. They're basically billing out something that's already known, which takes a little bit more social engineering prowess, right? The other two cities, Key Biscayne and Riviera Beach. Add that to your records. Okay. And interesting, because we track a lot of this. But I'll tell you, the business email compromise scams are becoming a hell of a lot more sophisticated. They often piggyback on domain names as well, look-alike domain names, cyber squatting, typo squatting, et cetera. I guarantee you that Wright Construction had some kind of permutation of their primary domain name used as part of this business email compromise. I got it. The H and the G are reversed, right? Something like that. HG, not GH. It could be something like that. Or very often relates to vowels. Switching up vowels, that seems to be very difficult for eyes to pick up on for some reason. Visual similarity when vowels are swapped out or a vowel is missing, something like that. But they often piggyback on the DNS, which is why I believe that DNS monitoring is so critical. It's one of the things that we do through our law firm. And then spear phishing attacks. Frankly, I think that Naples, Florida got off easy paying only $70,000. $700,000, Alex. Oh, with $700,000. I added another zero. You added another zero. I'm sorry. I was taking notes as you were adding zeros, apparently. Multiplying by 10. This is how it happens. Even still, $700,000 isn't- It's $7 million now. I'm not surprised at the rate that you're going. You want to keep going because we can do this all night. Because a spear phishing attack like this, once an attacker establishes persistence in a system, and especially a municipality, they know that ransomware attacks are going to be incredibly lucrative. And that's what we saw with the Lake City attack recently. And shutting down a municipality equals big bucks. The more people that pay out, the more likely this is going to proliferate. So, yeah, I think even $700,000 is not a bad price tag for them. But like all the best what you would call a cyber scam, it's based on a much, much older scam. I mean, in a past professional life, I did a lot of temping. And I worked in accounts payable in a couple of big corporate offices. And a big deal then was that people would mail in bills for either things that were completely fictional, or that looked like something that you would assume you had to pay for if you were a big office somewhere. Like some other telephone company would send you a bill that you had no relationship with them. But like bills come in and automatically office drones would tend to just stamp it and send it through. And you could charge anything you wanted for anything. That's whaling, right? Yes. Well, speaking of water-related hacks involving cities in the south, the city of Murfreesboro, one of my favorite city names, Murfreesboro, Tennessee. You know about this, Greg? No, I've been to Murfreesboro, though. Have you? I can't say it, but I've been there. I think we passed through it when we saw the eclipse. Murfreesboro. Yeah, we drove through there. Weird name. Anyway, their online access portal for their water department bill payment was hacked. Visitors there were greeted with an image of the Iranian flag with a Guy Fawkes mask next to it. You don't often see those two things together. Beneath the image, it reads, hacked by Iranian hackers. You know, guys, you could have phrased it better than that. Hacked by Iranian hackers. Use the word hack twice in four words. Below that, it reads, yet another time, hacked by Mahmud warning. I don't know what that even means. Further below is the message, we are always closer to you. Your identity is known to us. Your information is for us. Take care. I like these guys. I don't know why, but I just do. At the moment, it's unclear who the hacker or hackers actually are. It's isolated to the online access for the city's water department bill pay, which has two different access points, not affecting the entire website, not affecting the water supply. Doesn't look like it's even affected anything financially, just a bit of fun, and they're shutting the website down. I don't know if they've gotten to it yet, but they're doing that. And that's kind of what hacking is really all about, is putting funny messages in places and making people think twice about their security. Well, you know, back in the 90s, some of you may remember hacked by Chinese, which you would, you know, people would wake up in the morning and find their website just replaced by that, hacked by Chinese. So I guess it's the Iranians now. Maybe, maybe. I mean, I take a very specific issue with the language there, because, you know, why is everybody using the passive voice? Hacked by? Why can't people use the active voice? Subject, verb, object. How would you say it? Iranian hackers did this. Iranian hackers, you know, something like that. It's just easier to follow. It sounds detached, though. It sounds like you're reporting it. Iranian hackers hacked. You think so? I mean, if you had Guy Fawkes. It's worse than them. You're saying hacked twice in two words. You are an editor-in-chief. You should be just as offended by the passive voice as I am. If people would consult me before they put out messages on hacked webpages, they would read a lot better, I'll tell you that. I totally agree. Alex, how does their English compare to your Arabic? Probably about the same, I would say. Interesting. We have Greg Newby here, and we've been wasting him because he has a lot to tell us about projects that he is involved in and lawsuits that he's involved in as well. Where would you like to begin? Well, of course, I'm optimistic that this will be a topic for a talk at Hope. Yes, which means you're optimistic about there being a Hope. Fully optimistic, and I've been seeing some of the recommendations that came in. Hopefully, you'll put in another plug. Oh, my God. We got so much mail. We got hundreds of pieces of mail from people literally mailing us saying, don't give up. Literally, don't give up, Hope, because if you didn't hear about it, our hotel raised the price by triple, and it makes it virtually impossible for us to have a conference there. But people are giving us all kinds of suggestions and just filling us with optimism and realizing that, okay, this really matters to people. So, thank you. You've invigorated us. If you have more ideas, write to us, hope at hope.net. We're working on this, and we're very optimistic that we'll find a solution. Yeah, it's really a meaningful conference for people, me included, of course. And so, this is a story that I hope will be closer to the conclusion. Right now, it's getting towards the conclusion. But some people might know I'm involved with something called Project Gutenberg. And actually, at Hope in 2006, Michael Hart was the keynote, and I was up on stage with him. He's an inventor of e-books, founder of Project Gutenberg. So, we got sued by a company called Fischer Verlag in Germany. And they had complained once or twice by e-mail saying, you must remove these – I'm not going to try to do a German accent, sorry. Thank you. But you must remove these 18 books or else. And we wrote back with our highly qualified legal advice saying, pound sand. We're in the United States. You're in Germany. These are public domain books in the United States. The copyright is long expired, like decades long expired. And they sued us. So, we have been fighting the lawsuit, and we lost. And we have been pursuing an appeal, and we lost the appeal. And now we're investigating the next stage of the appeal, which is essentially the German Supreme Court. The whole deal here is a pretty simple one, which is that there are people in Germany who can access, who could have accessed these books, 18 electronic books that are free at gutenberg.org. But they're not out of copyright in Germany. They might still have copyright protection in Germany. So, they're out of copyright here. They're out of copyright in the public domain in the United States. So, you're legally allowed to do what you did in the United States. But in Germany, there are people who think that you shouldn't be allowed to do that in Germany. Because it's copyrighted there still. So, it's a little bit like anything else where the copyright term – most people don't even know this. The copyright duration, the protection of copyright is different in different countries. And it's not short in the United States by any stretch of the imagination. It's 95 or 120 years of copyright protection. But stuff expires. And the oldest of these items is 100 and – what is it? 123 years old. So, 123-year-old item, book, is still copyrighted in Germany based on the death date of the author. But it's in the public domain in the U.S. based on when it was published, which is in 1896. Okay. A couple of questions. First of all, does a German court have any power over here? We think not. However, we got advice because we're a little nonprofit organization with not a lot of money and not a lot of people, mostly volunteers. But we got advice from our lawyers that if you're a legitimate organization and someone sues you, then you show up. You respond. You don't just ignore it. We consider just ignoring it. But that sounded like the bad way to go because eventually they would do a – what's called a default judgment in the U.S. And then suddenly they have a basis to come to the U.S. and say, you lost this lawsuit on whatever grounds and pay up. And the U.S. court might be sympathetic to that even though they didn't hear the case or anything. So anyway, we fought it in Germany. But we have always said, look, really two main things. One is we're in the United States. You're in Germany. You want to sue us, you got to do it in the United States, whether it's in the business office address or the incorporation address, whatever. Do it in a court in the United States. But, of course, in the United States, there's no copyright. So they wouldn't have a basis for doing that. So we always said you have to do it in the U.S. But then the other thing which is even more important is we said, look, our actions in the U.S. are perfectly legal and even the other side agrees that it's perfectly legal to offer this stuff. But in the German court system, they say that the mere act of offering it to Germans is illegal. So this is actually very, very interesting. So essentially what they're saying is that the fact that we make something available on our website in the U.S. and a German person can get it puts us under the jurisdiction of the German court. And this has gone through now two levels of appeal. And they're saying, yes, the German court has authority in the German court system over whatever people are doing if it's accessible over the Internet from Germany. So you can imagine this has a broader impact than just our little nonprofit. Can it easily be made inaccessible to people in Germany through technological means? Well, we did. So, yeah, I mean, of course, if you're like YouTube or Google or any other international company, then you do localization. You have a storefront that's in German and you have terms of service that are in German and you'll have actual people on the ground possibly in that country. We don't have any of that. We're just a website. We're a library. So we're a little like the Murfreesboro Public Library having some books on their website and the German law establishment saying you are under our thumb because people from Germany can access that. But when we lost the case in the first instance, the court said you must make the items unavailable in Germany. And you can either do that through removing them, of course, taking them down, or you can put up blocking based on IP address. And rather than blocking just those 18 items, which would have been a little bit more of a hassle, we decided that the existential threat caused by this extraterritorial court coming after us was pretty significant. So we blocked all of Germany. You blocked all of Germany from all of your content. Yeah. It's actually it's easier to block all of Germany to the website than it was to block them just for the 18 items. But yeah, but we did this because it really is it's overreach that we couldn't even imagine. We were very surprised that we were sued because we've never been sued. We've been threatened by some of the best, been threatened by Ayn Rand's estate, been threatened by Oxford University Press. And in all cases, we said we are not under your jurisdiction. If you think there's a crime going on, let's say there's someone in Germany that's violating your copyright by accessing our item. You're in Germany. Go after this person. And if you need to block Germany from accessing this item, go ahead. And in fact, as Alex is ready to point out, their new copyright rule 13, right, basically says that they will do that. In other words, they will apply countrywide blocks if there is copyright violation elsewhere. So we were we were blown away by this. But the answer was we blocked Germany. That's been the case for over a year now. And and it will probably remain the case indefinitely. So if you're trying to access the Gutenberg Project from Germany and you can't figure out why, do they get a message? They get a message. They get redirected to a site called block.pglaf.org. And that links to a website called CAND.pglaf.org, which is the cease and desist page of Project Gutenberg Literary Archive Foundation that explains the reasoning behind. So was this enough to get them off your case? Well, the because we lost the case, we we went ahead and blocked. And what the law, what the court said was we need to pay damages and we also need to pay licensing fees. So a little like, you know, with all the file sharing types of lawsuits, like you have to pay on a per occurrence basis. How many people were looking at these books? Well, this is where it gets slightly interesting. We have no idea. So everyone remembers probably in this room the U.S. Patriot Act, which happened shortly after 9-11, which basically said that the government can show up, seize records at libraries and other places. And the library can't even disclose, you know, under a national security letter type of environment that that occurred. Since then, most places, including Project Gutenberg, stopped keeping records of, you know, of IP addresses. And, of course, we don't know everyone's anonymous anyway, but we don't even keep the download records, you know, the Apache server logs. So we don't know. They don't know. They did some weird math that says based on this and then the other thing, we think there are so and so many visitors from Germany. And but there's no evidence at all that anyone from Germany ever downloaded anything of these. I mean, it's when you get a warning letter from, say, you know, a provider saying that there's been piracy, you're downloading movies and things like that. They show you the evidence. They say on this date, this person downloaded from here. They need to show you something like that. And this is this is the most fascinating thing in the German court, because they want us to pay restitution based on downloads. But due to weirdness in the German court system, no one ever had to say there was a download in the first place. So in the U.S., I don't know all the details here, but in the U.S., exactly what you said, if you are accused of copyright violation. Step one is, does the plaintiff, the person complaining, actually own the copyright? Otherwise, go away. Yeah. And the Germans hadn't demonstrated that. In fact, they got a letter from a state, you know, the family estate that was dated two weeks before they filed the lawsuit, you know, giving some of these rights. So they didn't even demonstrate adequately. They own the rights. Eventually they did, but they didn't have that. And then in the U.S. court, the other thing is, well, show me what happened. You know, who downloaded this? When? You know, give me an IP address. Give me a, you know, Internet service provider. Certainly give me the nature of the content. What is the damage? Yeah. And so, yeah, it's been a little bit surreal. And so I'll go to the next step. This is something that we haven't put up on our website yet. So the very latest news concerning the Penitential Appeal to the Supreme Court of Germany. The question there is, did the appeal court or the first court make errors of fact or law? And so we submitted a big, long list of errors that we observed, you know, with a lot of detail and stuff like that. You know, dealing with jurisdiction, dealing with the fact that there were never any damages. In fact, they didn't even demonstrate that they're publishing. They're saying that we lost revenue and they never showed that they had any revenue in the first place from these. So there's just so many gaps. But we pointed out the most important ones. And upon review by the – you have to work through sort of a qualified lawyer there. They said none of this matters to the German court. None of this matters. We don't care that there were no downloads. We don't care about extraterritoriality. We're going to rely on these one or two precedent cases. So I'm really – as of today, I'm really feeling very railroaded by the German court system. I didn't go to camp, by the way. That's probably wise. Greetings to camp people. The CCC camp is happening right now. But I'm not there. I'm personally on the line for hundreds of thousands of euros in fines. That's what they want. For a book that was published over 100 years ago. By the way, including the director – I'm the director of the nonprofit, which in the U.S. would have a pretty reasonable level of immunity. But in Germany, under, you know, the way they see things, I am liable. So if you read up on the Volkswagen case, it had a little bit similar. The people in the U.S. kind of walked scot-free. But in Germany, the executives are actually getting charged. You're making our court system look sane, which is really a high reach. I just want to give out our phone number because we did promise we'd take phone calls. 212-209-2877. But we only have a couple minutes left, so call quickly. Alex, I'm sure you have something to say about this. Oh, absolutely. And Greg and I have been in touch on this. What I think is really fascinating is we're in a clear conflict of laws situation here between nations with respect to the copyright terms. You're on the hook for these particular damages. One corollary of this is that, you know, because of the downloading issue and the numbers and the frequencies is so up in the air, the implication of this ruling is that it will encourage service providers to increase the kind of logging and monitoring of their users that they do in order to mitigate damages in the future because they may be in situations like this. Separately, I think my thought on this is to go on the offense when they go on the offense. If they try to enforce that judgment in the United States, one way that you can contest enforcement of a judgment, a foreign judgment in particular, is if it conflicts with the public policies of the United States. Right. And our public policy right now is that this copyright doesn't exist and it should be made free. So when they go on the offense, I think that's when you should go on the offense. That's my two cents. Maybe we have some phone calls. We have a phone call. Good evening. You're on off the hook. Go ahead. Hi. Is it me? That's you. Yeah. Hi. Great topic. Wish I had more time to talk about it. Yes. Greg, can you spell your last name? Sure. It's Newby. N-E-W-B-Y. And I mentioned before it's Gutenberg, which is G-U-T-E-N-B-E-R-G dot org. But I'm Greg Newby, the director and CEO. Can you tell us the name of the organization that's been going after Gutenberg? Yeah. Oh, yeah. I mean, we have a website I mentioned where I've even published a lawsuit and stuff like that. It's called S, the letter S, Fischer Verlag. And this is one of the very big publishing houses in Germany. There's a family called Von Holtzbrink, which has been over 100 years one of the dominant publishers in Germany. They actually – They live in a castle? It sounds so gothic. I think they do. The organization actually owns Macmillan in the United States. Really? But the company that sued us, I guess, was divested or something. So they're not affiliated with Macmillan. It's just the personification of evil here, what they're trying to do. Do you have a website that has your contact information if I wanted to get some information to you? Oh, please do. Yeah. So I'll speak them. But the easiest thing to do if you can find Gutenberg dot org is look in the contact information. And I'm right there. My email address is right there. But there's a website, the Project Gutenberg Literary Archive Foundation, P-G-L-A-F dot org. And that's where I am. That's where we operate. And maybe for people who don't know what Gutenberg is all about, what's the mission? Well, it's a free library of electronic books. And we have a collection which nowadays is not as big as it sounded. We have about 60,000 electronic books. They're all free. They're almost all public domain in the U.S. We have some that people have donated. We have some stuff like sound and movies. But it's mostly electronic text books. And sort of the signature of Project Gutenberg versus, like, Google Books or Internet Archive or some of the other places, you know, of course they're all free. But the thing we do is we do a lot of proofreading. So we get them in pretty good shape before we distribute them. We have one more call. Good evening. You're on off the hook. Good evening. Just wanted to mention that Gary Nall on his show tomorrow from 12 to 1 is going to have a whole hour about the Internet, how it was created. It was on the Progressive Radio Network last night. But he's going to repeat it. So I wanted people to know about that. Okay. Just promise us you call his show and promote our show. That would be nice. Thank you for that. Okay. We're out of time. OTH at 2600. Whoops. I hit the microphone again. I am too close in this room. It's too tiny. We have 18 people in this room. It's no space. It's heating up also. It really is. It's like 95 degrees. OTH at 2600.com is our telephone number. No, that's not our telephone number. That's my mind. It's our email address. Our telephone number has been given out, and we don't have time for any more calls. But I hope people learned something this hour, and I hope we get to do it again next week. And, Greg, thank you so much for coming by. It's been a pleasure. Thanks for having me. And I hope this lawsuit thing works out. My God, the things that we hear about. It's coming to the U.S. next, and we are fighting. All right. One more time. That's my microphone. Have a good night. Yes. All right. Bye.