It's from 7 to 8.30 p.m. The Open Center is located at 22 East 30th Street and for more information go to opencenter.org. This has been your WBAI Community Bulletin Board. If you have an event you would like us to announce send it two weeks in advance to CBB at WBAI.org. And this is radio station WBAI New York. It's 8 o'clock. Time once again for Off The Hook. And a very very good evening to everybody. The program is Off The Hook. Emmanuel Goldstein here with you joined tonight by Alex. Good to be back. Welcome back. Thank you sir. Kyle. Howdy. And Voltaire joins us again. Well it's it's another interesting week of all kinds of events that are happening technology-wise and that's what we discuss. We discuss technology. We discuss freedom of speech. We discuss just the evolving society that we find ourselves in and it always is evolving. You might not see it because you might not be feeling the changes but the changes are always happening and that's what we try to focus upon week after week. We've been doing it since 1988 so there's been a lot of changes but just just today we're just going to go through a few interesting stories here and you can see what people think of those. Today two JFK air trains stalled and the whole system shut down. What do you think about that? Yeah two Kennedy Airport air trains stalled before dawn this morning temporarily trapping about 70 people. That's according to a spokesperson for the Port Authority of New York and New Jersey. The system runs from the New York City subway and bus stops and Howard Beach and Jamaica and Queens to the airport's terminals. It shut down for reasons not yet understood so I guess hackers are suspected because we always are no matter what. Basically you know I wonder if people missed planes as a result of this. It's very very possible if you're stuck on an air train but what's interesting about this is you've all ridden the air train right? Oh yes of course. There's there's nobody driving it. It's driverless. It's driverless and you know it's funny when you shout that in the air train. There's nobody driving. People people react in weird ways but it's true. You're just you're just shouting the truth so I don't know what people get so upset about. And so you're on this system that nobody's driving. It's automated so you're there and nobody knew what was going on because there's nobody to tell them and that is the automation system of the future where things just stop but you don't find out why. I mean you could say the same thing about the subway and the LIRR. Oftentimes they stop and they never tell you why but at least as humans you can yell at. What do you do on the on the on the air train? There's nobody to yell at except your fellow passengers and you can't get out. There might be a call button. There might be a call button. Good luck with that. Emergency. You might get someone some way far away who has other things to do. Well so anyway what's what's weird about this is that they say that the two air trains that stalled were not related. They stalled independently which I find hard to believe because they stalled at the same time. So to me you know that tells me you're not really understanding your own system if you're telling me that two air trains stalled at around the same time pretty much yeah the two trains stalled at 5 a.m. How do you say that's not related? Of course it's related. It doesn't happen all the time does it? I mean I've seen the thing stop and not stall out for however many minutes this this took place. The entire system shut down about 645 a.m. We don't have information as to why the system was shut down at that time. They say they don't know a lot about their system. You need help? We'll come over. We'll take a look at it. But clearly we're not getting the full story here. For how long were these people stalled? Yeah I'm trying to I'm trying to let's see the one of the stalled trains had about 25 passengers who got on at Howard Beach. The second had around 45 people when it stopped working near Terminal 8. That's the last terminal. Which by the way if you ever want to get to Terminal 8 quickly don't ride the whole loop get off at the first stop the first terminal and walk across the platform to the air train that goes and just the loop inside and you your next stop is Terminal 8. That's a handy tip from off the hook. That is a handy tip actually. I mean what is there anything happening at Terminal 8? Well no it just takes a long time to get there if you stay on the train that goes around the entire loop and stops at every single terminal. But while I was I was saying all that I was looking for information on how long it actually stalled for but they don't say they don't say exactly how long it was. Well it was it was enough to be annoying though. Yeah well what's the what type of engines are driving these things? This is all electrical based? It's electric yeah of course everything's electric. So the two trains stalled exactly the same time. This has got to be an electrical issue. I don't know if it's exactly the same time but it's pretty damn close and it's obviously something related so to say it's not related is just insane to me. They're not indicating that it was like an emergency break or anything like that either as though it was like two independent emergencies on each one or people dare I say coordinating some kind of emergency stop at the same time. Like Al-Qaeda you're saying like this is a coordinated stop of air trains? I didn't want to bring that in. On 9-11 really wow okay. That is that is something to consider. I also want to know are there any more running? I mean were those the only two on the automated track or do more than two or one in each direction? Do more than one in each direction? I can answer that yes there's more than two running at any one time. It is a long track. When you're riding the thing you pass like three or four of them before you even get to the terminal so yeah there's there's a few running. Okay. But okay that's that's a good point if only two stopped. The others need to stop if only if two are stopped on the rail because the others will run right into them if they don't. That would be another part of the system to be sure of yes. Mm-hmm. Okay moving on moving on to McDonald's. Fast food is about to get even faster. McDonald's has announced it is buying the voice tech startup Apprente so it can automate its drive-thru menu. Yeah the Mountain View based company specializes in building voice based agents that can take orders in multiple languages and accents. The fast-food giant has been testing Apprente's technology in several locations and expects it will allow for faster simpler and more accurate order taking at its drive-thrus. In other words we don't need humans anymore we're gonna have these machines and and robots and computers listening that can be more efficient. So good luck to everybody that has a job taking orders at McDonald's. This is just gonna be an absolute disaster. I mean going through a drive-thru at any time is a disaster when you have human beings with real cognitive abilities on the other end and you know this just takes the most annoying part of having to call any company on the telephone you know these these idiotic voice prompts that you know get get muffled or you know there's all kinds of errors caused by background noise etc and puts it into the context of you driving a you know a motor vehicle in an outside environment and then well you're trying to order a Big Mac and a six-piece chicken. I could just imagine this is gonna be a complete and utter disaster and I can't wait for it. Well it might be a disaster or it might not be a disaster either way though we're moving more into this automated world. They say that Apprenti will form a pivotal part of McD Tech Labs. Yeah that's what it's called McD Tech Labs a new restaurant technology group that's based in Silicon Valley. Now the Apprenti team will become the group's founding members and co-founder Itamar Arel will serve as vice president. McDonald's commitment to innovation has long inspired our team. He says it was quite clear from our various engagements that McDonald's is leading the industry with technology. Apprenti was born out of an opportunity to use technology to solve challenging new world problems and we're thrilled to now apply this to creating personalized experiences for customers and crew. Okay you know take it down a notch there. New challenging new world problems you're ordering a Big Mac through a speaker that's what you're doing it's not that challenging and I don't know how much of a personalized experience for customers and crew you're creating here people aren't going to remember this kind of thing after after two minutes. I mean it seems like a very much simpler way to solve this new world problem of difficulty ordering through a drive-thru would be to put some kind of touchscreen in place where you just touch you don't have to say anything you just you know touch Big Mac touch fries touch this that would be really really simple I mean there's drive-thru ATMs where you put in your card you touch on the screen you do all this good I mean that seems like we're over complicating the solution to a very simple and and I think perennial problem here you know and and more to the point I mean are people still really going to McDonald's all that frequently? Oh yeah yeah they're doing that. I guess where you live. No it's true everywhere. I just wanted to say I'm interested in the argument for accuracy because I think having people fill out forms like that through an app or some kind of technology I think that's there's actually I think a case there to a degree in terms of planning your meals or I mean in this case planning your your snack or whatever it is you're getting at the drive-thru but you've also seen some of this with grocery stores I think I passed by a grocery store that's owned by an online retailer and a woman had all of these bags filled to the top of a cart and they were all individually labeled and she was loading them up to what I assume is go deliver them to all of the online orderers and what struck me in this conversation is that she is still able to she's still employed probably not by the grocer but by the online retailer that has an association but my point is there are still people involved in this and I will buy the argument for accuracy not that talking to a speaker is confusing or difficult but for the sake of speed and the sort of visual aspect of an app I think there is an argument you could get more sales more volume in those drive-thrus which is maybe in this company's interest but and but it's not completely eliminating the people what I'm what I'm saying here is it's separating them right there being pushed further from the users in both this grocery store example that I was that I saw in a parking lot the other day and and also with this story with McD Tech I'm also thinking of the college students who spent 200 grand or whatever and you know they're they're having to make the case that mom dad I'm gonna go work for McD Tech it's serious and I have a degree now and I'm an adult don't get me wrong I think the technology is cool I love playing with automated things and and seeing how we can replicate what humans do but when you get less and less connected to actual humans in the process you do lose something and you do take on some risks of having a completely automated environment where all kinds of things can be introduced without somebody detecting it and I can't be specific as to what the threat is but we'll see it we'll see you know it could be a stop train that nobody knows about because nobody's driving it it could be all kinds of things that we have not even conceived of yet this is something that can be considered growing pains for for the technology. Voltaire? What McDonald's menu item do you think you'll get if you blow a 2600 Hertz whistle into the... You'll probably get reported to McDonald's police or whatever happens but yeah you know this is this is what I encourage people to do and you know I do encourage people to do things like this experiment play with the system try to break it because yeah try to break it I mean it because that is how you get better by breaking things by by testing them by seeing what it is and if you know blowing a 2600 whistle into a McDonald's automated order taker makes the whole system come down then the whole system needs to come down so that they can fix that and make it not happen but we need to experiment and learn that. Well speaking of which I mean McDonald's could have a lot of fun with this too if they implement it properly if you go to this drive-thru and you try to order a you know what's the equivalent of a Big Mac at Burger King? Whopper. I don't even know I'm saying the right words. Whopper. If you try to order a Whopper at McDonald's I mean they could have some kind of automated funny thing you know like when you ask Siri where can you bury a body you know they could have lots of different Easter eggs. What happens if you ask Siri that? She tells you where the nearest like garbage dumps and things are. Really? Yeah yeah absolutely. You've never done this? No I've never done that. Of all people I thought you would have definitely asked that question. Well I just figured that the government's listening so I wouldn't ask there. Yeah. I would call. Well Apple. I'm not gonna tell you what I would do. You know what struck me too in this conversation is also how do you anonymously buy food from this chain? Yes. Because what will happen with the account and the data that you're generating? I just in the midst of this realized we're kind of we're missing something we talked about so so frequently which is now they're gonna push it to a platform. I'm assuming you have a login and some kind of thing that's associated with your payment method. What profile and who buys that profile information I'm sure I'm thinking insurers you know and then so on and so forth. What is the logical extent now of how how the accuracy then of their customer profiles is is going to be augmented by this? Well absolutely and you have to consider things like data retention. How long are they going to be retaining these recordings? Are going to be tied to any personally identifying information? As long as those fries make you retain water. Yeah which is a for a while and you know are they going to be doing additional data collection like license plate reader identification so that when you come in with your license plate and it knows your voice it's going to automatically reorder those six Big Macs that you get every morning. Wow. And you know and and and so on and so on and then that information can be shared with other parties and there's compliance issues when it comes to you know things like CCPA and New York State privacy bills and how they're doing this data sharing. I mean so by implementing this simple solution to quote-unquote new world problem they are also creating a gigantic host of compliance problems of their own that they're going to have to solve internally. You know there's a coffee shop Kyle and I go to where when we walk in the guy tells us what we're going to get because we always get the same thing even though we don't but when we were there with this guy he he seems no we and it's it's kind of annoying because you feel like you have to get that now you don't want to start an argument but you know he's human so at least we can have that conversation and what happens when you walk in there and the robot tells you what you're gonna get and I just feel like that would be a little bit more annoying and scary. That's time to rewatch 2001 I guess you know open the pod bay doors Hal you know I don't want this latte frappuccino nonsense Hal and but you're gonna get it anyway it's just you're stuck with it now. Wow. You got to listen to the robots. I have a feeling that those are words that we're gonna say came back to haunt us in decades to come. Yes I I think that is a good example of how things can become less personal something that is quite personal just being recognized in that way and I think it's mostly a testament to that location having a good crew and and they you know are personable in that way but with a automation of it it turns into something totally different yeah because you realize that's not someone remembering your face well it's a machine remember or an algorithm. And not only remembering what you got remembering when you got it and how many times you got it and who you were with when you got it etc etc it can all be stored remember data is cheap. It's less unexpected and and thus not as much of a gift from on a social level it's more of a mechanization. Mm-hmm all right here's a late-breaking story Stewie's Steam account hacked during CSGO Berlin major playoff I don't understand a single word I just said. Does anybody understand what this story is about? Apparently it's got something to do with games and somebody's Steam account got hacked and for some reason that made it all the way to a major news source. I think we should just stop right there because that's yes what the hell am I talking about? Steve is Steam Steve Wow. Stewie's Steam account get it right Kyle. The hacker took control of Stewie2k's account and locked him out of it completely his account was hacked on the eve of his StarLadder major Berlin playoffs. Okay so Steam is a platform by the company Valve and it is a gaming platform that can run primarily their gaming engine but I think other games are ported to it I'm not really totally abreast of how it works I think anything can run on it it's as it's as independent yeah it's as independent as any gaming console but it itself is primarily online and something you would play through your computer or an account such as the one that's hacked. So get the account back and play the damn game later. Right it sounds like he was in the middle of something important too namely a competition. Yeah so are we we're in the middle of a radio show and we're talking about this. And fortnight's a game. Who said fortnight is fortnight even? I thought you said ew. What's the game? I don't keep in mind I don't understand. Can you read it again? Read what? I don't know. It's such a jumble of words Stewie's Steam account hacked during CSGO Berlin major playoffs I understand Berlin I know where that is. Basically nothing else in that sentence. CSGO is Counter-Strike. Counter-Strike okay okay. I know CS is Counter-Strike what's the goal then? Global offense. You don't know do you? Counter-Strike's a first-person shooter. I hope you get your account back but stop wasting our time you know play your game and and and I'm sure I'm gonna get mail about this because I'm insulting somebody who's playing a damn game on Steam. Okay well. Okay I know what Steam is I was aware of it. He did not win. I don't know I don't care. All right. And and if anybody out there cares shame on you. Yeah choose a better game. To care about. You're a winner. We're all winners we know that. We're all winners in this game of life here. What else is prescient? Okay so Long Island schools and and governments because there's multiple governments on Long Island we'll be discussing hacking in a summit in October. Did you know they had summits on Long Island? Yes they do. Suffolk County and Long Island University's Homeland Security and Terrorism Institute will host a cybersecurity summit next month in the aftermath of two local school districts being hacked this summer with a ransomware virus. The summit will be held October 16th. It was organized partly in response to the Rockville Center School District paying nearly $90,000 in July to hackers who okay first of all stop calling them hackers they're not hackers they're criminals. They're people who stole money from you. They're people who I mean anybody. Extorted. Yeah anybody who who can encrypt files and and and say pay me to unencrypt that that there's not much hacking involved in that. That's extortion. And they probably didn't even do that. They probably had a program that did that for them. Anyway they paid $90,000 to these people who encrypted files on the system server until payment was made to unlock the information. The other district was Mineola that was corrupted by the same ransomware known as RYUK. R-Y-U-K. So if you get an installation file for RYUK don't run it. The district did not have to pay a ransom to unlock data. Why? Because it had everything backed up out offline. Bravo Mineola. You did the right thing. You backed it up offline. It's all you have to do. It's not that hard. The invitation only summit which will include state and federal experts from industry, law enforcement, academia, and government will be held at the LIU Tillis Center in Brookville. If it's invitation only why are you telling us exactly where and when it is? Seems like we're causing some possible problems here. The summit is expected to cover the cybersecurity threats local governments face along with opportunities and resources that are available to school districts, towns, villages, and counties to protect themselves. Now as we all know ransomware has threatened several large governments and schools throughout the country. It is believed to be coming out of Eastern Europe although where it comes from really is kind of immaterial. It's malware that targets data and systems for extortion and is delivered through targeted phishing emails that's according to the FBI. After the user has been locked out of the data or system there is a demand for payment and the victim gets to learn how to use Bitcoin and transfer large sums of money. The State Education Department sent a notice to all districts July 31st about a cybersecurity threat reported in four districts Syracuse, Watertown, Lansing, and Rockville Center. Officials advised educational agencies that believe they may be compromised slash infected with ransomware to contact several agencies including the State's Division of Homeland Security and Emergency Services. So basically the viruses for both Rockville Center and Mineola came in through emails with links or attachments. It's the same thing as as what we were seeing in the last century where people are clicking on attachments and and and links that go to suspicious places. And these ones these these viruses that they managed to get by clicking on these things they lay dormant for months before attacking the servers. State Education Department officials said another Long Island school district also had been hacked but declined to name the district because officials had not yet notified residents. So if you're on Long Island your district could have been hacked and maybe you'll find out about it. Rockville Center Superintendent William Johnson said his district's technology systems including telephones, emails, and many files were held for ransom. Telephones? Wow. The district paid $88,000 in Bitcoin via insurance. Well that's interesting. Via insurance to release the data. That's according to a statement from Boses. He urged the other districts to review their insurance policies to ensure they have a high enough limit and that the policies cover ransom. Well this makes the story very very different. So insurance is covering ransomware now. Yeah that that's absolutely right. I mean most new cyber liability policies that you're going to take out are going to have some kind of coverage for ransomware events. What's the incentive to not click on those mysterious links if it's going to be covered by insurance? Well you there's always a deductible that you have to pay and then when you renew your insurance you know that's going to become you know a bit of an issue as well. But it's you know it becomes up to the insurer to make this determination as well because you are the insurer from their perspective. They need to balance what the costs are. If the costs of recovery are going to outweigh the costs of paying the ransom then you're going to pay the ransom. So a lot of these cyber liability insurance policies leave that distinction and that that that decision-making process over to the insurance company and sometimes that might not be the best way to deal with this because if you're just paying the ransomware and locking the stuff you have no guarantee that you're actually going to get your files back number one and number two you're not remediating the vulnerability in the first place. And part of the reason why I've always been a big fan of cyber liability for for many years cyber liability insurance policies is because they have the potential to change certain practices in and across various industries. So the more people that take out certain cyber liability insurance policies the more likely they are to do things like asset classification of digital assets penetration tests you know vulnerability assessments all these types of things can be prerequisites to obtaining cyber liability but there are so many players in that arena right now that underwriting for cyber liability has become I think woefully insufficient. So they're writing all these policies they're not necessarily changing a lot of practices with them as they stand right now and then when they're just paying out these ransomware attacks it actually well it could have the opposite effect which is if you continue to pay out these particular attacks and people can make $90,000 a pop at them you know sometimes hundreds of thousands of dollars in ransomware is paid by by state and local governments when they are subject to these attacks all you're doing is serving to reinforce the economic value of these particular attacks and increasing the likelihood that they're going to recur. And let me say something here too on the air and I know some of our listeners may have actually been in touch with me about this but we have been tracking now for almost a year and I won't go into all the details of it but a pretty pernicious we've been doing this tracking on our DNS monitoring platform within our law firm we've been tracking a really pernicious advanced persistent threat that's been targeting a lot of critical infrastructure in the United States we we have been in touch with a lot of companies that have been targeted by this but one of the things that we noticed over the last year and a half or so was a massive amount of school districts being targeted by this APT which we believe is either extraordinarily organized crime or perhaps even a state sponsor and we're not entirely sure why all of these school districts are being targeted and I'm when I say I'm a massive number I'm talking about over 200 school district might I venture a guess there are a lot of them you just said over 200 and they're covered by insurance exactly well that's part of it too now the other thing and I had to adjust my tinfoil hat slightly to the left with respect to this is school districts we realized and we saw a lot of them being targeted before the 2018 midterm elections by this particular APT school districts are also the situs of polling places and if you want to disrupt an election as we all know you don't actually have to change any votes all you have to do is cast some kind of doubt as to the credibility of the polling places of as to the the voting machines etc if it's possible for a state actor to demonstrate that hundreds if not thousands of our polling places were compromised after the 2020 election that would cause a serious lack of credibility I think and our electoral process so this issue of school districts being targeted on the one hand could be for economic gain on the other hand it could be part of a larger ideological attack or it could also have to do with the fact that the social security numbers of children these days are actually often more valuable economically than those of adults because nobody has credit monitoring services watching the social security numbers and the PII of their children not until they go off to college so there may be any number of years that a malicious actor can exploit the PII of a child as opposed to that of an adult so there's all these reasons why I think school districts are being targeted and I think it's going to become a really interesting cottage industry with respect to information security and securing school districts in particular because they're guarding some of our most vulnerable assets it's also worth pointing out that that these schools are because they're massively underfunded they have even less of an IT budget than the private sector does and we hear we hear all the time about actually I feel like we hear less they're probably even more prevalent than we heard about in the private sector but because they're private they don't have to say reveal every time they have a security incident whereas public sector schools and stuff they have to reveal this I think also with regards to IT in schools very often they overlook the best sources and that's the students ask them you know maybe they'll be able to figure out ways to keep things more secure than the IT department or at least work with them and and teach each other things because you have some really really amazing assets right there in the same building and oftentimes they're demonized thought of as the threat when in actuality they're there the the promise and and filled with all kinds of new information and eagerness to to make the changes well I can attest that when I was in high school they got it absolutely right I was the threat yeah they should never have let me near anything yeah so yeah they had it right in the 90s you got in trouble for the most ridiculous things and I'm sure there are many people out there to this day that are getting in trouble for the most ridiculous things that's right yeah I can kicked out of libraries for modifying auto exact up at all kinds of fun stuff yeah well okay product of my misspent youth here's a school where students were puzzled yesterday afternoon when a new message appeared in their inboxes it's a school called Marquette and as usual the new story doesn't tell us where Marquette is they assume they're by reading a new story knows where they are but basically the sender was another Marquette students under of this email claiming their aunt recently moved to the area the aunt was offering $350 weekly for students interested in pet sitting her dogs the message was sent to dozens of students and the emails came from different student senders it was an instance of online hacking okay the hack started with a librarians email account the hacker used the account to email students a message claiming the librarian was a human resources employee with important information sent in the form of a link you see the the the similar things going on here every single time hackers get blamed and usually there's a link involved when students click the link they became the hackers next victims suddenly their Marquette email accounts began sending messages to other students asking for pet sitters well if you need a pet sitter and you go to Marquette I think you covered the information technology desk started receiving service tickets related to the hack and they were I'm sure quite overwhelmed the librarians link took students to a Microsoft account login page when students entered their information why would you do that enter their information the pet sitter hacking message was sent from their accounts right when we found out about that all the accounts were disabled so no one had access to them anymore all the passwords were reset hacked accounts were locked immediately victims of the hack were required to call IT services or go to the IT services desk to reset their passwords this highlights the importance of cyber security said an IT services employee and a junior in the College of Health Sciences so lesson learned we suggest take a course to look at ways to notice fishy emails so I don't need to take a course to know not to click on mysterious links but okay lesson learned there and doesn't seem like any real harm was done but if you're looking for a pet sitter in that area you might have some additional questions to answer I think you're right here I mean not much has changed in terms of the the attack vectors I mean it seems like so they were they were taking the credentials here and automatically using them over and over and over again I mean they this could have been done much more covertly rather than overtly and I think it could have been far worse but you know you bring up the this issue with the students and learning and teaching and you know I deal with cyber security training all the time with our firm and it's very difficult I think to teach people to look out for all of these different hallmarks of particular fish because then after you have security training the the malicious actors can then capitalize on that particular training so they teach you to look for certain things like domains that don't end in calm or domains that are look alike etc etc right so now the malicious actors are migrating over into the subdomain space in the DNS and replicating what looks like an actual fully qualified domain name of a particular target by using DNS a records and replicating you know but let's say registering a domain name that begins with calm dash something and then creating a DNS a record on top of that so it looks like gmail.com I mean this is exactly how John Podesta was popped during the 2016 election and so you can teach all these types of things and all these hallmarks of attacks but then those particular lessons can be capitalized on by the attackers what I think and this has been my theory now for a while the real way to teach people how to stop an attack is to teach them how to create an attack because if they understand how the technology works if you teach them how to create a phishing site using subdomains or how easy it is to register a domain in a country code top-level domain set up an email account I mean literally this lesson takes 20 minutes to do if you teach people how easy it is you teach them how to you teach them how the technology works once they understand how the technology works then they're going to be able to use their brain and I say over and over and over again I think our brains and our cognitive abilities are the best firewalls we have against these types of attacks that don't necessarily change over several decades of time I think if we lose up to the individual and their kind of ability given how innovative people are with email they play that's somewhat unrealistic it like the solution has to be a more technical thing with the the browser manufacturers they've been experimenting a lot with the way that URLs are displayed and I think the solution will be in innovations through those mechanisms as opposed to having to rely on either training well but then those will be exploited as well but you know I think for every change there's going to be some kind of exploitation and I mean my point is that if people understand the way the technology works they're going to be less susceptible to manipulations of it and so I think as part of the training we should teach them how these attacks actually work show them how easy and how simple it is they're going to be looking out for the right things at that point ultimately down down the line I think you're right and you know Google has a lot of these initiatives going on with Chrome and and especially marking sites that don't have things like SSL certificates installed as insecure things like that are also you know extraordinarily helpful but then we see the massive manipulation of SSL certificates and that's partly due to the increased availability of SSL certificates from places like Let's Encrypt so you have you know the law of unintentional consequences coming into play here too where you know this encrypt the web initiative from the Electronic Frontier Foundation you know is now being used by malicious actors to create that padlock on various sites that allow it to have you know the the the indicia of being some kind of secure site you know it's because we've taught people to look for the padlock and now people manipulate the ability to have that particular padlock so I think my point is that we really just have to teach people to understand more basic tenets of how the technology works and I think only then are we going to have a real increase in excuse me information security practices and cyber hygiene as it's called these days yeah and I think the technology is is should be evolving the stuff that serves users should evolve as much as the attacks do and and I do hear the point that a firm foundation in in just the like fundamental aspects of an attack like this you know what is what is the tactics or syntax of how you might be vulnerable and also other things like urgency you know sense of urgency if it feels like a hustle and how to kind of train your gut as a user to to see those kind of red flags when you're you know in a moment of that feels like it's more urgent than it should be or you're kind of being shaped or controlled and manipulated with the wording of an email like this but absolutely we we have a lot of tools and I think as the attacks evolve like with what Alex has said we need as many tools to to help people avoid this stuff and also not have to be on alert at every single turn but you know have some confidence that there's a quality systems and processes in in anticipation of this stuff as well but it is certainly like a constantly evolving thing but but has very similar roots like with the link you're listening to off the hook here on WBA I where the show about hacking technology and freedom of speech and all kinds of other nice things like that you can write to us OTH at 2600 calm this person wrote to us and here's what he had to say or she actually because they didn't sign the letter your archive of shows are an invaluable source of history I've been listening to your backlog from the beginning for a long time slowly working through the years today I just listened to the live episode from beyond hope in 1997 I remember that I've gotten to know many interesting people you fiber rebel and other regular callers it has been extremely farsighted of you to archive all the shows it's good to be called farsighted for a change instead of that other thing they provide such a great view on progress and topics of discussion it's been fun to see the discussion moving from landlines and BBS is to internet and mobile phones I wish I had found out about your show when I was a teen in the 90s I had a 486 slash 33 until 1999 and it couldn't play mp3s in real time but I might have been able to play the lower quality real audio recordings I would love to hear all episodes of the computer show the personal computer show that was your neighbor but sadly their archives only seem to go to the early 2000s anyway enough rambling keep up the great work and we will try to do that and thank you so much for that letter and yes you know most most programs and this goes for television programs radio programs they don't save their material and we save everything you know it's important to save what you do it's important to save your work whether it's written work whether it's broadcasting whether it's film just look back on it someday you might hate it but it is it's a time capsule of things that happened in the past that you will you will find valuable and other people will find valuable as well I mean I find it absolutely amazing that this guy was using a 486 33 megahertz machine in 1999 I mean I'm very curious if it was an SX or a DX processor if he could write us back it wasn't too slow or too fast for that period way too slow way too slow so you're putting him down for a machine he had almost 20 years ago no I'm not putting him 20 years ago I'm propping him up I'm saying I'm saying you know that's pretty amazing that you were still using a 46 probably a DX 33 I think it would have probably used the z100 okay so come on yeah I had a centrist back then that was 25 megahertz oh my god it wasn't in a 5e SS but it was you know it chugged along those are the days I mean my first computer was an XT that ran at 4 megahertz was you know CGA monitor those were the days I think it's I think it's fantastic even to just hear these old specs on the radio yes absolutely all right well some other interesting things that I think we should talk about has to do with the nature of fascism which we also delve into occasionally and how insidious it can be and what I mean by that is that you you see things going on around you in society on the big scale you see it on TV you see laws being passed and actions being taken that basically turn your stomach and and you think surely something will happen but then then you see elements of it taking place very close to you on a local scale now I'm gonna read something I'm gonna read you a passage from one of my favorite organizations the IRS the Internal Revenue Service organizations that are exempt from income tax under section 501 a of the Internal Revenue Code as organizations described in section 501 c3 it's a section yeah you hear 501 c3 all the time it's actually a section and worth reading may not participate in or intervene in including the publishing or distributing of statements any political campaign on behalf of or in opposition to any candidate for public office what that means is nonprofit organizations cannot participate in campaigns they cannot participate in elections they cannot endorse candidates they cannot issue political statements that's understood and that includes churches that includes the ACLU that includes us and we have been quite good I think in observing that I think we have a full understanding of what that means over the years since we went on the air back in 1960 and the Pacifica Foundation well before then well not everybody sees it that way and we are being challenged in many many ways always we're always being challenged in many ways but in particular we are being threatened with all kinds of actions if we don't do things a certain way and that comes from a misreading a misreading of what I just read to you to extend to all of us in other words not just the organization but anybody broadcasting on the organization using using WBA eyes airwaves may not partake in these discussions in these opinions so in other words if I were to say that I think Donald Trump is a menace to society and I think that the best thing anyone can do is make sure he does not get reelected in 2020 that would be against the IRS regulations something I have never heard before something that I've never heard any other station that I've been affiliated with now people express their opinions all the time and that's something that we take great pride in at this radio station people expressing their opinions and we have had people who are pro Trump on these airwaves we've had people who are anti Trump on these airwaves and we have expressed our own opinions and I'll be damned if someone's gonna tell me that I'm not allowed to express my opinion on something yes we know we know what the radio station can and cannot do as an organization we know the regulation we know it well the management here knows it well and they've done a good job making sure that does not happen but but that does not mean that people who don't get it or people who do get it and simply want to twist it won't have an undue influence and won't make things very very unpleasant for those that don't toe their particular line listen to this this is this is a statement from from somebody I'm not gonna say who you can't legally use the assets financial or otherwise of a tax-exempt 501 c3 charity or those who in New York State registered charity or an FCC non commercial educational broadcast station to lobby or advocate for or against political candidates so far so good the Donald J Trump Foundation was dissolved by the New York State Office of the Attorney General for doing that kind of weird to compare us to the Donald J Trump Foundation but whatever and then obviously unpaid producers are assets to WBA I dash Pacifica yeah we're assets to WBA I granted thank you for that but we are not being used we are not being used by WBA I to convey a message we are conveying our own damn message by ourselves as individuals I speak for myself when I say something I don't speak for WBA I I don't even speak for off the hook half the time you guys disagree with me passionately happily just last week somebody on this station was suspended for violating this made-up rule because people are afraid people are afraid that well should we be more careful I've seen this before I've seen this before many times on the left where we kind of yeah I said we we kind of overdo it as far as being careful and we overcompensate there was another radio station I worked with when we had the safe harbor safe harbor runs from 10 p.m. to 6 a.m. that's when you can use those bad words not obscenity you can't be obscene but you can be indecent and it's called the safe harbor period runs from 10 p.m. to 6 a.m. well at this other station they thought they'd be a little bit more careful so they made it 11 p.m. to 5 a.m. and then they made it midnight then it was 1215 for some reason and then you know what let's just let's just not do it at all no indecency you see the the steps that you wind up going through to placate some imaginative or imaginary rather enemy that could have something on you but you're following the rules so they have nothing on you so somebody at the stage again I'm not naming names ran a promo in which the phrase dump Trump was uttered dump Trump I think it was shut down shut down I'm sorry I'm sorry I've said two different things I just say it was allegedly they had said something and you're now quoting it and also I think when in this moment when you're sort of being attacked especially at a station like WBA I and you feel under attack I think there's some confirmation bias at play where people are kind of looking for things that are evidence of an attack and that we must double down our efforts and that kind of thing well clearly this is this is completely wrong people can express their opinions they can say shut down Trump if they want to say that the station is not saying that the station does not take a position you might think the station takes a position because of the number of people who are on our airwaves who have similar views but the station simply provides a forum that is what the station does we provide a forum for discussion and people on the air behind microphones are people just like the people who call in and nobody yet disagrees that people who call in can say whatever they feel like saying and that's good great wonderful but the thing that has to be remembered is that the people who are on the air also have that right and that right should not be taken away anyway new rules were handed down saying no on-air endorsement of candidates well you know we don't endorse we don't say that because who would care if if I endorse somebody but we do express opinions and if you look up the definition of endorsement it's an opinion it's basically saying I like this guy I don't like this person you know that's an endorsement and a non endorsement no on-air issues of advocacy that functions as one of the above okay whatever no public statements for or against a candidate okay you know and that got that got twisted even further and now we can't make public statements at all like outside in the street we can't have calls for action no calls to action that is literally what it says which means we can't say advocate for net neutrality let's let's save net neutrality we can't say that weak and it's you know I'm saying what these phrases are telling us they are incorrect because obviously their organizations such as the ACLU that advocate for all kinds of things the ACLU does not endorse candidates either however you might go to an ACLU rally and speak to an ACLU representative who tells you their opinion and that is perfectly legal that is perfectly allowed listen to this statement this is again from somebody who doesn't get it this has nothing to do with the First Amendment nobody forced Pacifica Foundation to apply for IRS 501c3 status and register for state charity status for five radio stations to get major tax advantages in exchange for complying with certain rules compliance with these laws and regulations is baked into Pacifica's bylaws utter nonsense that is not at all what the interpretation is again going back to the IRS what the IRS also says and pay attention to this the political campaign intervention prohibition is not intended to restrict free expression on political matters by leaders of organizations speaking for themselves as individuals and again we're not even leaders okay they're talking about the president and vice president and whatever nor are leaders prohibited from speaking about important issues of public policies however for their organizations to remain tax exempt under section 501c3 leaders cannot make partisan comments in official organization publications or at official functions of the organization again easy to understand and we've been complying with that for many decades you know we can't set up tables we can't put out newsletters that say this is the official position of WBAI we can't we can't tell you to not reelect Trump as a result of that but as individuals we have the right of free speech but you will see you will see this around you and you might see it in your home you might see it in your school you might see it in your workplace you will see attempts made to curtail your freedom of speech on a local level to avoid trouble to avoid you know pissing off the wrong people and you may wind up paying the price we might wind up paying the price for simply bringing that up for challenging that I just heard today that one of our most popular programs Trump watch no longer on the air because I don't know in all honesty I don't know why it's not on the air it might have nothing to do with this I hope not because if it was taken off the air because it's seen as criticizing Trump Wow okay we are in a very bad place then but to tell us and and again because Trump is a candidate to be told that you're not allowed to say nasty things about him or to encourage people to to make sure that he does not win in the future that somehow goes against these regulations not true so you might hear things in future weeks future days that that imply certain changes or certain regulations that don't exist now Alex you're you're lawyers I understand it you've looked into this a little bit yes have I said anything completely off base because tell me if I have no more than usual thank you but no less either unfortunately but the you know I think that the crux of the matter here is is really something that you touched on when you read the interpretive the statement of the IRS with respect to the 501 c3 rules because to read them very broadly what is would be tantamount would be the equivalent of taking the regulations that apply to 501 c3 organizations themselves and having them operate to curtail First Amendment rights guaranteed by the Constitution of the United States that the 501 c3 tax regulations would be operating essentially as a prior restraint on our freedom of speech that would be unconstitutional number one number two there is a big difference between analyzing politics political analysis of the sort that we do on the station every week every minute every hour for the last I don't even know how many decades that's been going on on this particular station there's a big difference between political analysis and political endorsement and if we were to let's say you know begin to in you know totally change our tune you know come 2020 election cycle and start endorsing let's say somebody like Beto O'Rourke because he used to be a member of the hacker community with the cult of the dead cow that would be a radical sea change in how we have operated that could cross the line if we're asking people to change their votes to vote for a particular candidate to endorse them that would be a big difference now what we've been doing here for many many years is criticizing every administration that's in power whether it's Trump whether it's Clinton whether it's Obama anybody is fair game and that has always been the case if we were to change that now that Delta that new precedent that we establish that's what can operate to curtail our freedom of speech in the future because if we stop the political analysis that we've been engaging in for so many decades and then we begin to try to pick it up again that's when it's going to look like political electioneering or trying to change other people's votes using the voice of WBAI to do so that's what would be wrong what we have to do now is continue in the present course that we have always persisted in for so many goddamn decades if WBAI is really concerned about this regulation and its interpretation its potential effect on the station which has existed for decades which has existed for decades exactly they should be seeking the legal opinion of qualified personnel who can opine on this and if they come back with a an analysis based on cogent research case law interpreting the rules and regulations that there is some kind of threat here you can go to the IRS you can seek an advisory opinion nobody's going to yank anybody's 501 c3 status by the way without a lengthy due process it's not something that can just be pulled overnight at worst you're probably going to get some kind of letter that said hey at this time and date you might have crossed the line be careful it's not reason enough for us to totally change exactly what we've been doing and doing effectively for so many years that's all I got to say and yet the the mere prospect and rumors and allegations I mean had us just coming in tonight there were some producers that really are confused and I think rightfully they are they're at a loss as to how this organization would change directions and I think that's that's mostly as a result of the sort of lack of an argument here in a lot of regards look if you hear somebody say shut down Trump it's their opinion they are saying if you hear somebody say Beto O'Rourke is a big dummy for being in a hacker group and that he couldn't get root on a plastic bag that's their opinion that's not my opinion but that's that could be somebody's opinion it is not the opinion of the radio station is not the opinion of Pacific I can't believe you have to say this but it's clearly it's clearly an agenda to to basically put fear into people and I don't really know I can't really speak to what is at play here but you can't listen to this you will get this all the time from all different levels the important thing is to know where you stand to believe in and what you believe in and I can say that about this place yeah I think especially this talk about social engineering when it comes to phishing if you hear the phishing email includes like some very technical topic people's eyes will glaze over and they'll just click it they'll lose their critical thinking skills same thing is happening here they see that it's mildly related to something legal and they say oh it's legalistic so I'm gonna stop thinking critically and just assume that this house is that's exactly what exactly what I was kind of getting at the confirmation bias thing that we're on such on edge and so on alert given in the moment we're in politically and socially that it is a sort of confirmation bias that yes of course we have to change our policies to protect and but my argument is our opinions and everyone's opinions here at the station are as important to the survival and and are the very thing that we are protecting so I mean we're out of time Kyle we're out of time so thank you everybody write to us OTH at 2600 calm we do have a qualified lawyer right here I'm not volunteering your services Alex but thank you for your analysis and let's leave it with a PSA Oh Oh Oh I freeze you're not gonna actually try Know your rights, these are your rights Oh, know your rights, these are your rights Of the other And it has been suggested in some quarters That this is not enough Oh, get off the streets Oh, get off the streets