News on Wednesdays at 6 30 p.m. Stay tuned for off the hook coming up in this hour This is WBAI New York 99.5 FM and WBAI org on line. Stay tuned And you are tuned in to WBAI New York it's 7 o'clock time for off the hook So And A very good evening to advise it the the program is off the hook A Man who goes team here with you joined tonight by Kyle Hi coming in loud and clear over here. Yeah a bit flustered a lot going on let's see, let's open up the the Skype lines here and Joining us is Alex Hello from the snowy Pocono Mountains. You went out to Pennsylvania in this weather Well, I went out very early this morning. Wow. Okay, and Rob is joining us as well Good evening from snowy, Queens, New York and Gila who's sitting right next to him. I am It's still snowy Queens, New York And it's snowy out here on Long Island where we expect to lose power any moment and that's going to be a lot of fun It's um, it's a blizzard. It's snowing outside. It's snowing in December I'm happy and it's another reason to stay indoors if we need more reasons to stay inside. Here's another one and we have an hour of Technological talk From the world of hackers and and at 8 o'clock. We'll be doing overtime again on our YouTube channel channel 2600 And you can call us and speak to us as callers did last week, which is neat. We heard from people all over the place so Everybody everybody safe and dry Alex I'm especially worried about you being out there in the in the tundra Yeah, it's it's freezing here it's about 15 degrees it is It's been snowing since about 1 p.m And it's really incredible out there. I mean, it's whiteout conditions and You know not the kind of stuff that you want to go out and drive in I would think so Hopefully by tomorrow when I'm due to head back to New York in the afternoon You think you're going back to New York in the afternoon, I'm sorry, that's funny No, you're gonna be there for a while. I think it's going to be 18 inches. They're saying It's not gonna stop till tomorrow afternoon I've got a Volkswagen and I can just drive right through. Oh, you got a Volkswagen. Okay, never mind then you can get through anything All right Robbie Lee you're safe there in Queens, right? We we are safe We were out of the apartment earlier this afternoon and it was amazing Earlier this afternoon and it was amazing. We had a thing to go to when we went it was completely dry and while we were there the snow started and And we walked out into an absolute snow globe. It was amazing. Uh-huh this is what winter should be, you know, and Don't listen to people who complain about it diversity That's a spice of life and having four seasons in a year is a good thing and here in New York We savor that so I'm glad we're getting some cold weather, I'm glad we're getting some snow The climate change is still a thing. So don't listen to Trump if he shows you a snowball or something and says Yeah, everything is fixed. No, that's not that's not how it works but please be safe be safe on the the kovat front be safe on the blizzard front and And listen to the radio nothing better than listening to the radio Well, actually there is something better than listening to the radio and that's listening to old voice BBS recordings from 25 years ago We went through a couple more not very many this week because we've been extremely busy But I just wanted to play a couple that I think I think they come from 1996 if I'm gonna guess Let's listen to a couple of rescued voice files. Thanks to to a Couple of our listeners who really helped us figure out how to convert the the files and get the Get the playback just right let's listen to the voice of a hacker from many years ago who might actually Hear his voice today and be shocked And I wanted to leave something for our hacker friends and the United Kingdom which I had discovered When calling world premiere customer service world world link world premiere, however, you want to call them they've just Started up a new world premiere card for the United Kingdom. The name of it is British Airways card and From the United Kingdom to activate a British Airways Prepaid card you would call zero eight hundred two seven nine Twenty seven hundred once again, that's zero eight hundred two seven nine 2700 Works just like the world premieres in the United States, but it's primarily for use in the United Kingdom and I know that sometimes Our British friends do call here, so that's one for you guys It's not nice helping helping out the hackers from all around the the planet Alex. You remember that service at all I I think I do actually yeah, I I think I do and it was very kind of him to You know to share that knowledge Yeah, Robbie. You looked like you had a note of recognition in your eyes It just it just sounded very familiar and it's also kind of just generally emblematic of the messages I loved so much on that thing back in its day a lot of the messages being helpful. Yeah, that's true There are a lot of helpful messages, but there are a lot of messages Also, we can't play on the air because they don't have they don't have that same mood to them They are funny like those two, but yeah, they're they're they're pretty interesting well, you have to figure out how to share these the best way to do it and we're getting all kinds of Listener suggestions, so if you have suggestions on what we can do with what we have over 4,000 files That doesn't mean we're anything near that number of messages, but we definitely have hundreds if not thousands of messages Public messages what private ones will probably keep private since you know, people had had voice mailboxes. I don't think we should share those but Some of these public ones have information that but woefully outdated is still interesting and it speaks to the hacker mentality I think that's what's brilliant and especially making some of the more Aggressive ones a little bit funnier because because they're out of context because it's so much later And it's the same thing with technologies. You can still apply and find parallels and glean cool bits and History out and somebody listening today can say hey, that's my dad 13 year old hacker who is calling in to to share information on how to clone a cell phone. Okay, we have we have one more This is from somebody more local from some of them 718 so they could actually be listening right now Yes, this is the jackal for NPA 718 I'm just calling because I need some info concerning Juno the email free service anyway, I recently Set up my account and then I checked out the modem initiation files to determine the Username and the password to get into the system after doing that, I dial up, you know to my modem directly and Got into the system and to the username and Tried to enter the password, but the system won't allow me to do it So anybody could advise me on how I can get the system to accept me entering the password. I appreciate that What else I know it's something simple though, what else Does anybody I mean has anybody ever heard of a hundred cheap talk? That's an LDS long-distance service that allows you to dial directly through without a credit card To call long-distance I'm thinking that they probably Separately bill because my long-distance service is blocked and it still allows me to make a phone call, you know So anybody can give me info on that. I appreciate that. Um, lastly what I want to say it seems to me that there's only a few people in this system that really has useful info and one of them is Intercept that's what I say. Thanks for calling this line, you know Because there are a lot of people out there that can use your info, you know, even though even if they're lame at least, you know They're trying to learn something. Why everybody else just wants to preach about who's lame and who's not peace Okay Well a little lecture there Duly noted. I hope we've learned something in 25 years Any tips on on Juno or was the other one cheap talk? No Alex Just brings back so many memories and I'm and and I think really is is emblematic of The fact that this was really a scene I did what he was talking about at the end Where's was you know, essentially people? Gossiping about each other about who's elite and who's lame and who's got good info and who doesn't and he was interested in some sort of content and I think that's pretty cool and I think that is, you know, it really brought back a lot of memories because Yeah, there was even The the the voicemail hacking and the hacker community kind of subculture there's always going to be some form of of hierarchy where people think that there's And others aren't but you know for him and I think for about for most hackers It's always about the information about sharing that information and I think he he captured that spirit really well. I think there was a great recording Rob, do you have something to add? Yeah, Juno for those who don't remember it was basically a dial-up online service like your America online CompuServe things that existed back then but they would they would offer you free access in exchange for usually they would put a big ad banner somewhere on your screen and Make money through showing you the ads which you know seems crazy now that somebody would give you a free email in exchange for showing you ads except that's how the pretty much the entire internet ecosystem works now, but Those those were really fun to play with because they were a very it was very cyberpunk They were a scrappy way to get access if you were, you know a poor kid out there who couldn't keep making long-distance calls or whatever, right and And it was it was just a lot of fun to find ways around what they were trying to do In order to get direct access to their systems that they were offering without going through having to watch their their ads So that was the thing to get into Juno and not deal with ads And and then you have free email something that we take for granted now free phone calls something we also take for granted But why do you think Juno didn't succeed because isn't that exactly what Gmail does now? You would think I think they they just might have been a little ahead of the curve with how much people would Require free access to email and in fact expect that to be a thing You know The the the online world in general was people using things like America online You had to use their clients to dial in and this person was trying to just dial straight in without that client Just making a direct modem to modem connection With with their own software, but yeah, it was there were there were ways to make that happen Sometimes that was like like this person was saying finding the username and the password that the thing was secretly using to get into the system Behind-the-scenes as it as it as it where well the whole concept of dialing in that's something that I think is alien to so Many of our listeners now. Yes, go ahead Alex Building on what Rob said it and I think he's he's precisely right here that this this was a very early stage Revenue model based entirely on advertising and and I think the Junos of the world if we remember correctly probably started to go away entirely as Gmail started to rise exponentially and Gmail was very interesting to a lot of people back in the day because in addition to it being in a free email service ostensibly free again ad sponsored It was also or rather should be considered One of the first cloud storage service providers as well because they were giving you about a gig of storage for your emails for your Attachments so that made Gmail much more attractive than a service like Juno And then Google became very adept at looking at your email scanning your emails finding what the keywords were and then monetizing that for their advertising base And that's probably something that Juno did not do nearly as effectively and so their revenue model was Was probably flawed from the outset or at least I think inferior to Google's model. I would echo those points and and really just elaborate on the fact that The approach and the growth model for Google and a smaller entity like Juno there they emerge a different on different trajectories in the timeline and You imagine what Juno might have been working with what computers were they trying to? Get online. What were their costs? I mean, there's a lot of like Business decisions and then what is what is the marketplace like and I think a lot of this Unique ways to get on online was because they're really it was a huge push to attract users and and get subscribers to your service Whereas I think Google a lot more of their trajectory was attracting engineers attracting talent and breaking down these services and then Approaching one each one as they grew from purely search and ads That's a really long way of saying they're just totally different companies at totally different times. I think or emerged Different rates. Do you remember how they did things when they rolled out Gmail? They made it something that people couldn't get you had to have an invitation to have a Gmail account and everybody wanted an invitation and Only because they did that to me Gmail the whole concept was offensive from the start to today Where they scan your mail and and and show you ads based on what you say I just I can't wrap my head around that and even to this day I I use Gmail not as a primary communication just as a convenience But I'm getting warnings today that my Gmail account is getting full a Gmail account. I don't even use it's completely filled up with their Own spam most of it is from Gmail and it's it's it's just they expect me to go through and clear it out And no, I'm not gonna do that. The other thing that happened only last week when I was forwarding something to a Gmail box I was told that that Gmail account did not exist and it existed because I I cut and pasted and mailed again and it went through but They lose mail and that is something that I never actually saw Right in front of me happen like that where it said clearly this account does not exist Have the the evidence still and then I just cut and pasted and did it again and it worked so That kind of thing is is disturbing to me and plus just storing things in the cloud not having Physical access yourself in case something disappears like Yahoo Yahoo news groups. They're gone as of yesterday they disappeared you cannot post on a Yahoo group anymore and I know people that Pacifica and BAI tearing their hair out because there's probably a hundred different Yahoo groups I mean that reminds me I have to get in touch with the group. Thank you for oh, yeah I don't think you can anymore. Well, yeah, that's the thing whatever back channel they can change the rules and and you know Google Google introduces these I remember Google wave all kinds of They should write a book about all the failed Google projects. They just decide to discontinue them and You're out of luck. There's really enormous lists of failed dot-com startups. Uh-huh. It's hilarious It's bad enough when when operating systems change and you can't run your programs as Easily as you used to be able to run them. I've just been moaning this yesterday because I've I've a Database in dbase2 if you can believe that from the old MS-DOS days. It's my video collection okay, that's how I started and finding something today that can read those files and Allow you to actually interact with them. It's I mean it can be done, but It's it's like the voice BBS all over again And you're basically paying for somebody else changing their mind on how something should work Works fine on a particular machine in a particular environment. You should be able to keep that and unfortunately places like archive.org exist where You can go back to the past and see things as they were and even get things to work. So It's good that we communicate this and share this information. Go ahead The other thing about like Juno and they're like there was net zero there was a blue light which was owned by Kmart I think there was a whole bunch of them But all of those had one single problem in front of them They had to provide email service and make the ads profitable enough to cover the cost of that whereas Google their main advantage has always been like how big they are and the fact that the the email and Google Wave and Whatever else whatever other little services they give to you That's not how Google makes their money Google makes their money by Bring by bringing you in with these services and then getting your eyeballs on ads and also getting your biometric info your biometric You're you're you're you're at your ad watching and clicking info to develop a profile on you Which itself is very profitable thing to have but they don't have to make the email pay for itself They don't have to make anything they do for you pay for itself because with your eyeballs you're paying for all of it There's the old saying now that if you're not paying money for a service, you're not the you're not the customer You're the product being sold. Absolutely. Absolutely. And if I continue my Google rant, it's a little bit more They have completely destroyed YouTube. They really have They have injected What they call mid-roll ads, you know what? Those are you're watching a video in the middle of the damn video you get an ad not just at the beginning at the end but right in them sometimes in the most important part and That was turned on by default everybody who puts up YouTube videos has to physically press buttons and opt out of that Otherwise the default is that there's an ad smack in the middle of your video It's it's ridiculous. You know, there was one Incredible example of how horrible this is. They have these really really long videos some people put up That's designed to let you go to sleep it's rain on a roof or the sound of the forest or trains going by all kinds of things and They're eight hours long ten hours long twenty hours long and you're drifting off to sleep you know you have this nice sound of crickets and Maybe an owl or two and the wind in the trees Maybe some some rain and then all of a sudden in the middle of it you get this loud Advertisement because Google decided to put an ad in the middle of that video and the person who put the video up didn't ask for That they just inserted it So that's when you don't control it when you control it yourself things like that happen and you find yourself surprised Alex Yeah, I've had that exact same experience with with these these annoying advertisements or YouTube videos because Oftentimes I'll drift off to sleep while I'm listening to some video about cosmology or astronomy for some reason thinking about black holes and event horizons and things expands my mind and and puts me right out it basically makes me into a Narcoleptic something and then I'll wake up in the middle of a 30-minute advertisement And you know the headphone will still be in my ear or something and I'll be very confused about what the hell I'm listening to but then the other effect of that too is which is if you let's say you did fall asleep Like I often do within you know, two or three minutes of putting on one of these cosmological conundrum videos you you were Listening to some advertisement for 30 minutes while you're sleeping and who knows what the hell the effect of that is on you I mean you wake up in it may really make you have some some very strange dreams or otherwise Subliminally affect you or retarget your your tastes while you're sleeping. It's it's a strange thing to me Well, is it possible that your video just went to another video? Is it is an ad inside that video or did it go to a second video? No, it's an ad inside the video 30-minute ad inside a video. Yeah, that's right. Yeah Incredible that is incredible Okay. Well, I think we've we've gotten all our anger. I guess Gila. Okay. Now I have a question Which is I do wonder if the Google algorithms inside YouTube are Related to the ads that you get served. I can only imagine I did get one in Spanish yesterday I got a Google Maps ad in YouTube In Spanish, I don't know why but yeah, I was listening to some stuff in the background and all of a sudden Spanish and I was Thrown but I'm curious if everybody's getting served the same ads in the YouTube or if they're different for different users I'm assuming they are but I can't say one way or the other but I'm still a little confused about the Spanish app Google News not now that I'm sorry, but I just I keep thinking of more products and they anger me Google News All right, that used to be useful used to be a good aggregator where you could read stories from different places But now every time you click on a story, it's a paywall. Why list stories that are paywalled? Am I supposed to subscribe to every newspaper in existence on the Internet in order to use Google News? It's useless It should be free stories that are put on the Internet for you to read And nothing more. Otherwise, what's the point? All right. Yes, Rob. Go ahead The unintended side effect of Google News and how they do things is sometimes I don't say this I'm not saying this works in all cases But sometimes if you can manage to make the user agent string of your browser Look like the one from Google News is bought Then sometimes the sites will show you the article thinking you're Google's but you know Spidering their site so Google doesn't have to pay to read the article But they show it to you and tell you to pay it's it doesn't make any sense to me The Internet used to be so much cooler. I hope we can bring it back somehow I we have some some interesting stories that are going on this this really left out at me an American hacker is Claiming to have gained access to both the Canadian and the American Emergency alert systems that that always piques my interest According to a new report from input and I have no idea what input is. I'm sorry the hacker who goes by the alias Vertrux Says he's able to send a message nationwide Using a system he found open on the Internet By scanning for ports utilized by two systems commonly used in emergency alerts Vertrux says he found millions of IP addresses. He then scanned through them for a list of keywords likely to be used in such alert systems and narrowed that down to thousands I social engineered some Manufacturers of these to give me either the service password or the default password and after trying a few IPs I was in I was disgusted. This is federal infrastructure. This isn't a printer left open Vertrux claims that the system access points are available online for use by authorized users But are also easily accessible by those with the technological knowledge You can get whatever you need to gain full access not to all as most are updated but a scary majority This reminds me of the banking systems They run COBOL because they are too lazy and cheap to upgrade to something more secure and we get left with very old people who? Know how to program COBOL working on the banking and insurance infrastructure. Okay, I think a bit harsh bit harsh there I think the the federal government needs to set a proper training for setup and usage of these devices and Make it illegal to operate if you have not been trained. I'm not exactly sure what what he means by that The hack okay input refers to him as the hacktivist the hacktivist says he could send whatever he pleases to millions of people Theoretically I can send anything from a volcano warning to the entire u.s. To an amber alert if I really wanted I could send out custom messages to Believes it can do the same in Canada. I'm sure the same as possible custom messages to countrywide levels of emergency In the wrong hands this can and will only incite panic He says I wouldn't go as far as to say the wrong message sent out can theoretically start a war But I don't think it's all that impossible and I'll tell you a Vertex it's not impossible because we live in a world where where things are decreed by Twitter and a war can be started not only through the emergency alert system, but through a tweet and that is the problem Well, the problem is is obviously The fact that so many of these systems aren't kept secure in the first place But the fact that we take things We believe whatever we see flash across us on a device whether it's reading Facebook whether it's Reading an SMS or a tweet or even seeing something that comes across the EAS system We we need to do better as far as how we verify the information that we are given because many times we're being lied to or We're seeing something that purports to be something that it's not, you know, whether it's a forged email Some kind of phishing expedition. There are so many ways you can be fooled All you have to do is believe what is in front of you as far as text or even even audio or video so The healthy skepticism I think is it's a good thing. I don't know. I'm healthily skeptic about this particular story I'm not sure how true it is, but it's certainly I think Possible theoretically should there be fines maybe for default passwords? Fines for default passwords. Well, that means somebody has to check your password. How do they do that? I mean in the public interest, maybe not a personal router. That's something you really need in your life How about this fault all you want when I was caught back in the 80s? All right, I was on a system called Telenet Actually a subset of that system called telemail and the reason I was able to get hundreds of accounts was because they used the default password of the letter a And it was relatively easy for me to scroll down a list of accounts that were publicly available And simply try the letter a for each Each one and see how many I could get into now something like that When it's revealed that yeah that this person hacked your your system and Was able to aim nukes and do all kinds of turn off electrical grids and things like that because you use the password a yeah I think there should be a fine for that. That's stupid Well, especially stream, but but it has to be revealed that they did something incredibly boneheaded like that. Well also with a Huge push towards new EAS. I know just with some of the radio stations and broadcasters in general. There's been Changes and and updates to the to the systems So if you're putting in all this new equipment Imagine that every broadcaster everyone that is required and they get pretty serious about the requirement for EAS so why isn't there a requirement on this install instead of Requiring the install and basically providing this enormous opportunity if Defaults are widely kept. Yes. Go ahead Alex I think two points bouncing off both what you and Kyle and said Number one, I think I would go even further Emanuel with respect to the severity Of this information coming from something like an emergency alert system Remember, I guess it feels like a different world ago, but it was probably about two years ago Maybe when we did the tests and had the party for the presidential alert system. Yes, and And that was that was very cool, I still have our flyer from that. Yeah, that was fun We had we had something in the comments downstairs and yeah, that's right That's when we did radio in a studio and saw people in person. Wow Yeah, it was it was a different world But in any event, I the point I want to make here is that unlike Twitter where people are used to seeing garbage, right? It's garbage in garbage out is the old platitude people are used to being skeptical About stories on Twitter and you know Even seeing the the president's of the United States's tweets himself being flagged as potentially false or misleading So I think we're getting more used to that But when you see something flash across your phone, whether it's an amber alert or something that looks like an official communication You tend to believe it. So if this story is in fact true I see it as extraordinarily dangerous is something that could be used by a foreign actor to create Massive havoc. I mean think about the weather alerts that could be going on You know right now or or something that would have related to protests Can I just but in for a second Alex? There's always this mention of foreign actors. Why is it the foreign actors? We're most concerned about how about the domestic actors because there's a whole lot of them causing all kinds of mayhem right now with false information Misleading people. I you know, I don't think we have to get nationalistic about this I think this is just something where We need to be more educated as far as what is true and what is not true what is unlikely to be true how to question how to check how to verify how to how to access multiple sources of information and not just believe whatever you're told whether it's coming from us or your uncle on Facebook or Newsmax or whatever. I Agree with that. It doesn't have to be a foreign actor can be domestic Just you know general threat actor could utilize this for extraordinarily malicious purposes Especially when you were in the middle of a global health crisis for God's sake, right? I mean think about the misinformation that can come across your that's that's your opinion Alex that it's a global health Are these things real? We don't know but going back to what Kyle had said to he raises an interesting point which is essentially about fines for Having horrible security configurations and if you're a regulated entity let's say you're regulated by the FTC or Health and Human Services and you're not HIPAA compliant something like it it is certainly possible to be fined by a Regulatory body for having insufficient security practices in place and and certain regulated entities are required to undergo Enterprise risk assessments to look for things like these, you know, idiotic default passwords that are placed up there But Kyle to Kyle's point though What's very interesting about this is if the entity that is housing the insecure system is in fact the government Then how would you find them? It would be our tax dollars. They would pay a fine with our tax dollars. That doesn't seem fair At that point, you know We have we need to have I think better ways of regulating the regulators systems better ways of regulating governmental systems And ensuring that and then and also having a carrot-and-stick approach there to some kind of Penalty when it comes to government state local or federal not securing their systems properly. I I would just feel like there's like a personnel like accountability. This is be like an HR escalation I mean if I change the oil in your car and I don't toy torque your drain plug or whatever and You need a new motor like you're gonna come back at me over it and my competency as a technician so if a technicians installing something either as a contractor or working directly for the government and their choice is to not Go the next step, but I don't know if that's necessarily the the first culprit, right? I think there's a lot of people operating these systems that may not be a governmental entity But if that's our focus, yeah, I think I feel like that would come back on whomever the technician was Maybe that's not a huge fine levied at all. Maybe it's more Your certification or whatever whatever alleged qualification guide to that point probably would be in question, you know after so long I'm not but but the Contractor or whomever it would probably have there was to be some kind of repercussion Maybe not a fine per se but you raise a good point That's a good that's a good point because how circular do you want to get with with public, you know and be bureaucratic policing? yeah, I think it's pretty clear that we're gonna have trouble figuring out who is policing whom and Who has more authority and more knowledge and things like that? But but the one thing we can do to help the situation is always have that healthy skepticism now Healthy skepticism versus unhealthy skepticism, how do we differentiate because if you have a bunch of people Refusing to take a vaccine for instance, because they don't believe they're being told the truth. How do you counter that? I think the way is to have as many trusted news sources out there that people can go to to ask questions and to get information and Not just simply treat every blog out there as if it's equivalent to the New York Times Because it's not there are people that You can basically rely upon to give you accurate information and there are people who are complete phonies we need to be able to judge for ourselves Who who knows what they're talking about and who does not and unfortunately, we're in a society right now. We're basically a a lot of the a lot of the skilled people are being torn down by Very powerful people and that has a price that has a very high price because people stop trusting The very people they should be trusting and start listening to people who don't know what they're talking about then you have an uneducated suspicious populace and It becomes really really hard to get any bit of information out and to to not be completely Led around by the nose. I Think it's really hard to pick and choose which emergencies though. I mean with EAS It's a different sort of thing then then like I think what I'm hearing as a wider social Misunderstanding in other words people talking past one another or another concern I'm hearing that I would imagine in this is confirmation bias like if somebody's riding and you're looking for that group to be out riding and you get some alert about Such and such in your neighborhood causing all kinds of havoc, right? Maybe that's what you're looking for and you're gonna take up whatever defenses or Offensive measures you think are necessary. That's a chaotic moment and that is Kind of what makes it hard is like, okay, should you be questioning? You know a Launch of some kind of missile as we saw in Hawaii like a couple it wasn't a year Yeah, remember that that was a mistake by someone qualified to send these at EAS message That wasn't even something that was fake. It was just a mistake. I can happen to how do you categorize like which EAS? Okay, like amber alerts ignore all of those. Nobody cares, you know, I mean, do you really start having that kind of crash? That's not Kyle saying that he's he's quiet. I'm sorry. I'm quoting somebody that I was being facetious like Yeah, and sarcastic and all that. But yeah, exactly. How do you categorize and then? Wait one emergency alert over another to ignore pay attention to and and let me say everyone listening to the WBA I right now pay attention to EAS alerts. We keep our EAS mechanisms nice and shiny so You can trust alerts from this radio, but if you notice something doesn't make sense say so and and Have a conversation and don't dismiss out of hand Let's ask you guys a question If you had access if you could just send a message over EAS like this guy purports to be able to do What would you say? What would you do? Alex you you have an idea. I'll give you a go ahead Yeah, I mean right now if I were gonna send a message over EAS right now right now stay home Okay home. So you're gonna fight is closed. You're going to be responsible. I'm gonna do what the system is designed for Boring, okay Alex do you have something a bit more a bit more nefarious? That's what I'm looking for Something it says, you know, hello world, you know the classic first line of you know that you learn in every programming language or Support WB AI by calling 5 1 6 6 2 0 3 6 0 2 and and support community radio So anything could you imagine? Yeah, because hacking the emergency alert system is a surefire way to get support for WB AI Yeah, I'm sure I'm sure the feds would love us even more. Yeah Rob do you have an idea? yeah, I might go the responsible disclosure route and My message would be here's a hint to what you could fix so I'm not able to do this That's good. That's yeah, that's that's Both good and nefarious at the same time like the IP that was way that could cause hate havoc But yeah, the IP the password or just maybe the IP and like, you know change your password What I was thinking was just saying don't believe anything you see Because this is the fact that you're able to Because this is the fact that you're able to see what I'm writing instead of what is official should prove that you should always question But that's getting a little wordy I know but at the same time this is an invaluable service for those times when you do need to hear from somebody but Look at the security holes that you could drive a truck through That's sort of the message. Did you have one Kyle? I Can't think of anything. I'm I just would say it's a good question Maybe It's like if you have access to Trump's Twitter account Which I don't think it should be a crime if you have access to Trump's Twitter account and you tweeted something under his name It's it's mischief. It's not a crime the fact that you could start a nuclear war over Twitter. That's not your fault That's that's our fault for believing everything you see on Twitter I probably put a quotation out there like or just say like don't panic. I would say I quit I'm on Twitter account right now. That's what I would do Okay, we need to move on Trump's Twitter account Probably won't be around much after the inauguration. It'll be around. It just will be it'll be suspended. I'm pretty sure Yeah I'm not sure if he's gonna get permanently banned because he's broken every single Twitter rule and once he's not the president anymore I think they're gonna start enforcing maybe yeah, that's that's that's the hope I should not believe everything I see no No, you should not Yeah, it's something Okay, I'm sorry. This is my fault. I only Have the second page of this story, so maybe you guys can help me figure out what the story the rest of the story Is these are apparently tips? That we were sent look for can't okay I don't quite understand look for cameras before engaging in a fight if You're already in a battle shoot out any cameras you can see before your overheat bar fills up Cameras can help enemies locate and easily hack you Scanning the area for enemies is also a great preventative measure as this can tell you Which enemy can hack you as soon as you see an enemy you can quickly take them out Before they hack you or do any significant damage identify Enemy netrunners attempting to hack you once you find the hacker you can shoot them out Before you overheating bar fills. I what am I talking about here? That's crazy. Talk. Is that a letter really wish I had the first page of that article hang on that must be a letter It's a OTH. No, it's not. It's a new story. This is a new story. Oh, you're really news gave this to me that makes That's that's really confusing wait. It's what wait what in the bar? What what is the bar? Oh wait? This must be this this page here overheating in cyberpunk 2077 what is that? Oh? Wow, okay. This was the the Game title that had a bunch of errors. This is a game. I believe it is yeah I heard I think a little bit about this so don't shoot out any cameras unless you're in a game Is that okay? I'm sorry folks. I thought I was Giving out some valuable information for people that were in going through hard times But no, okay fine cyberpunk 2077. I have no interest whatsoever. Yeah, I don't know much about it I know they were having a lot of problems cyberpunk 2020 is hard enough offering refunds though if you're not happy with it Are they yes? They want you to stick with them through their first round of updates so so Alex I want to ask you there's all this talk about Some some major systems being hacked I'm seeing Talks of something called fire. I am seeing talks of something called solar winds. It's very confusing Has to do with all kinds of US agencies Russian hackers What what can you can you sum this up? Yeah, this is a very very interesting, and I think a fast-moving story, and it involves those Those pesky foreign actors again that we are just discussed a few moments ago. I so in short. Yeah, you're right This is about fire. I and solar winds are two different companies and so earlier this month fire I which is a cyber security company that focuses on things like incident response risk management cyber threat intelligence As well as penetration testing found out it had suffered a breach it had been hacked by somebody now This was really big news We talked about this a little bit last week with with Welton Chang from from you and rides first Because fire eyes is a company that gauges in penetration testing and had unique Toolkits used for probing and and possibly compromising its customers networks legally I thought that's part of penetration testing So if fire I was compromised and bad actors could use those toolkits for Malicious reasons and therefore if they made their way out into the wild you could be sure that other sophisticated threat actors other foreign State actors or organized crime would use them precisely because it would give them a certain amount of cover Meaning it would be difficult to attribute the attack to any particular group in or country But here's where solar winds comes in because the focus of the story has really changed over the last few days now Well fire. I was investigating its own breach the breach of its own systems and looking through Apparently 50,000 line and source codes and and other source codes It found that there was a backdoor within something called Orion solar winds now Orion is is the software is actually the platform solar winds is a Texas based company that makes the platform Orion and what Orion does in essence is allow monitoring and management of complex and often geographically dispersed Information technology assets things that are critical to a business's operations So you're going to have this Orion system on so that you can monitor it make sure that systems and processes are not going Out of whack and you can restart certain things reboot the machine and make sure that it's operating effectively So in order to do that, you're going to have to have certain types of administrator access on that machine Now the threat actors behind this particular attack are supposedly some elite unit of Russian intelligence and according to others though Making that attribution may be a little bit premature and I think that's probably correct. But what's critical to? Understanding how this whole thing happened is that the threat actors whoever they are and this is where it gets really interesting appeared to have compromised Solar winds is software build infrastructure So once inside that infrastructure once inside solar winds is place within their company where they build their software where they do their coding the bad guys then added malicious code Blending in their malware with legitimate code and really stealthy ways to prevent detection by things called Yara rules That are designed to find malware And with that code going undetected Solar winds signed their new updates meaning to all their customers. They appear to be legitimate Graphic, you know form of signing the software and when new updates were delivered to the solar winds as client base Which is huge the malicious code then allowed the threat actors Access to the customers networks through a backdoor and according to the hacker news network the malicious code Actually may have been present as far back as October 2009 so we're going over a year 2009 of 2019 Going over over a year. Yeah, 2009 would have been really precocious to do something like this But you know, it's not clear how the threat actors obtained access to the build infrastructure this goes back to Something Kyle had mentioned earlier But Reuters had actually Reported I think was today or yeah, I think was today actually that solar winds is update server was accessible with the password solar winds one two three and That a security researcher had a prize solar winds of that information We're not getting any more intelligence we keep making the same damn mistakes, it's just we keep trusting more and more things Solar winds one two three. That was that was their password. Yeah But that's not clear to be fair to solar winds, I'm sure they have a very complex IT environment, there's probably lots of people maybe change management could have been more effectively managed solar winds one two three hours I'm sorry, how much how much billing did they do and we're supposed to give them a break. This is Classic you had one job pretty much However, however, there's no indication yet that that solar winds one two Three password was used as part of the breach of solar windows is build Infrastructure and allow them to get into it would have allowed people access to The update server which you know What was part and parcel of how this all got? Distributed around around the world to all of solar winds customers Well think about that think of the harm that was caused by that solar winds basically infected their entire customer base They did the work of these evil actors I'm putting that in quotes because honestly, this is the kind of thing the US government would do and we'd call them the good guys You know for getting into some some foreign countries infrastructure You know, I I'm fascinated by this type of thing and I think it's something that we need to learn from And and we have to expect it. It's it's not you know, do you see this as an act of war or some kind of? Heavily punishable crime I see it as as a system being tested for what it's worth and finding out that it's not worth all that much Well, that's a good point. And I think it's an excellent question, too And you look at the targets the the entities that we know to have been compromised by this particular incident involving solar winds as Orion platform and there are a lot of Governmental entities that relate to the to the federal government of the United States like the Department of Commerce Department of Homeland Security Treasury there's likely to be a whole bunch of others. In fact, there was a federal directive that came out Instructing any agency or or component of the federal government that was utilizing solar winds as Orion platform to disconnect it and If this was Russian intelligence, or if it was any other intelligence Operation and they were targeting US entities and governmental entities Well, then that to me sure it would violate our criminal laws But that's just bog-standard practice when it comes to the collection of intelligence. That's what we do Every country does if they use this to steal trade secrets to steal intellectual property to compromise the private networks of America's critical infrastructure That that is involved in the private sector then I think you know then we're crossing into a line that that certainly involves criminality and and theft and And has gone beyond ordinary intelligence because of the action because of what they stalled I'm fascinated by doing it for the sake of just showing you can do it And oh certainly and quietly quietly. Yeah. Yeah, and this was an absolutely amazing way to compromise So many people that are geographically dispersed, you know as widely as their as their own IT assets are geographically dispersed Because you're piggybacking on something that already has what is essentially super user access to a whole bunch of these systems You're just riding in you know with with this, you know, this bus that's authorized to get into the compound and and that that's what they did and they got away with it for a long time and a lot of people are Hypothesizing that the reason why they got away with this for so long when our intelligence community has this defending forward Mentality where we're out there hunting for this type of activity is because we were so focused on the security Of the election infrastructure that we missed something like this and that's quite possible But you know look the elegance of this type of attack I think is something you know to be commented on and to be You know commended quite frankly. It is it is really I think a fantastically effective way of Getting into the networks of a massive client base Yeah, you have to realize it's a game and and whoever this is they won this game. They deserve respect for that Rather crimes are committed after that. That's a different subject. But this this to me is a work of art That's that's how you that's how you pull off a hack and they seem to have done it really well guys I don't want to cut this short, but I do want to mention that overtime is starting at 8 o'clock on channel 2600 on YouTube And you can call us and be on that stream and archive as well Phone number is 8 0 2 3 2 1 hack. That's 8 0 2 3 2 1 4 2 2 5 We will be opening up the stream 8 o'clock channel 2600 on YouTube and Love to hear from you and you can write to us to OTH at 2600.com but Like to see people on the YouTube thing. So it's an experiment. We're trying this way We can take phone calls, which we can't do right now since we're broadcasting from all over the place and don't have access to the board If you dial 802 3 2 1 4 2 2 5 at 8 o'clock and listen to channel 2600 on YouTube you can talk to us and Who knows who knows what else we might be able to do any closing comments Alex No, I just you know, wish everyone well who had their Christmases ruined by the solar wind Platform back and and good luck rebuilding your networks. Yeah, don't take it too. Seriously I mean, yeah, it sucks, but your job just changed a little bit and we learned something hopefully So the winds one two three, come on, let's not do that anymore Rod Vila any any last words for you? I Just got to remember to change my password on all my stuff from solar winds one, two, three. Yeah Someone broke solar winds. Wow. That's good one. Good one Kyle Okay Please join us channel 2600 on YouTube. See you next week. Good night You You And you're listening to WBA I in New York 99.5 FM and WB AI org Well, here we are, our second overtime stream for Off The Hook. I'm here, Kyle. Are you there? I think I'm here. Okay. Yeah, there you are. You're loud and clear over on this end. Am I? Okay. Yeah. We're sitting two feet away from each other, but that's fine. Well, I just want you to know that I can hear that. Okay, good, good. That's good news. I see Rob. I see Gila. Yeah, we can see each other. Hello. We can see you folks. That's by choice. I'm sorry. I know we're not using YouTube for the purpose in which it's intended. We're using it for audio. We don't do things the way you're supposed to do them. Alex, where the hell is Alex? This is why we need to be able to see each other. We can see that he's not there. Eight o'clock, that's when you're supposed to be back. I think he took a break or had to attend to something and was going to be back momentarily. That was last I heard. I was attending to some things as well. Yeah. You guys want to update us on the weather? And we'll get the phone number out again, 802-321-4225, 802-321-HACK. And one call at a time can get through. So if somebody else calls, again, Google. We can't get a busy signal from Google. We're forwarding the line to a single line. It doesn't have call waiting, but you're going to get voicemail if you don't get through. That's just the way it is. So if that happens, just call back when the other call is, assuming there is a call in the first place, when that call is finished. So Rob, Gila, how are things in Queens, weather-wise? I would actually like to repeat my favorite radio weather forecast I ever heard in my life, which someone gave on my summer camp radio station, looked out the window and said, it's dark. Good. Okay. All right. But as far as, as far as the raging blizzard, though, how is, how is that going? We're sending, we're sending her over to the window for a live weather update, but yes, to build on, to build on her earlier report, it is dark, but the, according to the forecast is going to be followed by a light in, in, after a certain length of time. I'm so happy we're doing this. This is really adding to my evening. Folks, you know, you have to call for us to continue doing this though, and if we don't get phone calls, we just won't do it anymore. I know people are shy. Getting the first phone call is always hard. We're only doing this for about 10 minutes or so. 802-321-4225. We tested it. We know it works. Welcome back, Alex. Glad you could join us. We're on, we're on the damn YouTube right now. Ah. Yeah. Yeah. Like we said, we were going to. Oh, I'm here. You know what? I guess when I watched it, I thought, I thought it was exactly eight o'clock. And I came back down. I had to go up and get a cup of tea. It's 803. Yeah. There we are. All right. Yep. How is the blizzard in Pennsylvania? It's pretty bad. I was, I looked out the window. In fact, I'll take another look right now, but we must have at least four or five inches. I don't care anymore, Alex, because we have a phone call and good evening caller. Can you hear us? Yes, I can. Where are you calling from? Can you hear me? Yes. We hear you fine. Hi. Can you tell us where you're calling from? Massachusetts. Okay. Is it snowing in Massachusetts? Let me check. Okay. Nobody seems to be looking out their windows, but I guess that's a good thing in a pandemic. Yeah. I actually don't have a window that I can look out right now. What are you, in a basement? No. Just all my, it's. Well, we don't need to, we don't need to get into the situation you're in. It's a personal choice. So, uh. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. Yeah. This is a hacker show. We respect if people don't want to use windows. Yeah, that's true. So what, what, what's on your, what's on your mind caller? My name is CJ, by the way. CJ, how are you doing? Good. I've been researching a website that has had some issues. Long live token that does not expire and can be used to access your account. Oh, nice. Yep. Yep. So on the bright side, you cannot access their purchasing information or make any purchases on their behalf with that information. Okay, but. You can watch all the shows you want with it. Really? Interesting. So you told us what kind of a system it is, I guess. Yeah. Wow. It's a streaming platform and I've reported it to them. And any response? Not yet. Okay. Okay. It could have been a worse thing because with it, you can't actually get there. So the problem is you can actually, that token lasts even if you change your password. That's true. That's yeah, that's how tokens can work. What would you suggest they do to fix this? They short, shorter with tokens and basically like a lot of revocation every so often. What part of the system? All the tokens. What part of the system is it? Is this is for like account creation? It's that kind of thing? It's for login. If you get a person's token, you can then use that to log in again under their name without their password. You just need the token. So when did you discover this? When did you notify them? I discovered this a few days ago, but it's also known information. Like there's a GitHub repo that actually mentions it. And they still haven't fixed it? Nope. This, this site has been so bad for a long time. Like a long time ago, you used to be able to tell their mobile API that you were paying customer and it would just accept it. Wow. Well, in your opinion, at what point do you go more public with something like this? If they don't fix it in like six months. That's a pretty healthy amount of time. So you're more generous than I would be. Yeah. Okay. I also broke the DRM on digital talking books from the National Library Service. Oh, you didn't? Oh, wow. That's pretty awesome. It involved a talking book player, a steady hand, and a serial cable. Nice. A UART cable. So an FTDI chip. CJ, would you write an article for us about that? That sounds awesome and very inspirational to a lot of people. Yeah. I actually still need to do that. Yeah. The moral of the story, don't dynamically link to OpenSSL. Duly noted. Write that down. This is an ARM embedded device. So I actually contacted the company, asked them to give me their open source bits. So basically they're OpenSSL and they gave me their build route. And then I compiled OpenSSL with a backdoor that spits out private keys. And this breaks the protected digital talking book standard, which is basically just key escrow. Wow. Rob, you had a question. Yeah. CJ, are you referring to the DAISY players? Yes, I am. Yeah. I used to work in the field. Those things are actually pretty cool. But yeah, I respect what you've done. Yeah. Also, I will not go public with this because if I did, the storm that would happen would be ridiculous. I will not release the keys. If someone else decides they want to try that, first off, they have to have access to the NLS. And second off, they have to spend like $300, $400 on a player. Right. Well, you don't have to go public with particulars. But the theories that get people to think in those methods and also to design systems that are better, I think that's an invaluable service you could perform. The reason why I won't go public with it is because it would be near impossible for them to revoke the keys and then redo everything. Because they would have to recall every single talking book player. And the logistics would just be insane. Yeah. No, that's very responsible of you. And the scary thing is that there are many people out there who are not nearly as responsible. That would cause harm. And people designing these systems should keep that in mind. Yeah. And also, this is like 10, 15 years old tech for the days of the protected digital talking book standard. So also, it doesn't help that the audio is encoded in a format that's in padded hell right now. Mm-hmm. AMR WB Plus is the codec. Wow. It's not really that much that can actually play it, especially in software. Uh-huh. Yeah, we're familiar with things like that. It's always good when you can figure it out, though. Alex, did you have any question for CJ? No, I think it's interesting that he's taking the responsible route and disclosing this to the company and giving them ample amount of time. And some types of companies don't take kindly to this type of thing. And others may offer him some form of bounty as well. So that's certainly something you would want to look into. And don't hesitate to be in touch with us if you need some additional guidance. CJ, thank you very much for your call. And thanks for being a good hacker. Yeah, no problem. All right. We'll talk to you again soon. Talk to you soon. Take care. Bye. And that was one of our listeners, CJ, from Massachusetts, from a room with no windows. I'm not really sure. But the important thing is that he's got a good sense of values. And that's what I like to see in the hacker community. Okay, we're going to be on in a couple more minutes. 802.321.HACK. I didn't have to give the phone number out, did I? It's ringing off the hook. You should give it out anyway, though. 802.321.HACK. 4-2-2-5. And right now, if you call it, it'll ring, even though it's busy, and you'll get a voicemail message. So just hang up and try again if we take another call. But after this, maybe you can get in. Yeah. Let's see who we have. Good evening. You're on overtime. Who is this? Hey, guys. Alan Cullen from Cranford, New Jersey. Great. I imagine the weather in New Jersey is pretty crazy right now. Yeah, it's looking pretty good. About 4 or 5 inches right now. It's supposed to really start coming down in the next few hours, though. See, I like that you said really good and not really bad, because I think it is really good to have snow in December. Changes up the routine. You know, it's the first storm of the year. It's like, I don't know. I was a teacher for a long time, so like a snow day is like a big deal happening. But now you don't get snow days anymore, because everybody can learn from home, you know? All this virtual environment. I'm hearing that it's become, it's kind of like a charitable thing. Some districts are giving the day off tomorrow. Those are good districts. Alex? It's a nice thing to do. Go ahead, Alex. On that point, you know, my son is in school, in public school in Manhattan. And they have issued, well, the Department of Education has issued a snow day for tomorrow. But there's a lot of disappointed kids, because, you know, it's all remote learning. Well, most of them have remote learning the following day anyhow. But the principal of our school has given us the option of having the kids do the remote learning or not. Because some parents, you know, see a snow day as something that's beneficial to a kid, part of growing up. And I thought that was pretty cool that she gave the option, that the principal actually gave the option of attending school or not tomorrow. Caller, did you have something you wanted to ask us? Yeah. Hey, it's like one nice thing, you know, that they could do. Yeah, actually, you know, I was listening to the show on the radio just now. You guys were talking about the SolarWinds story. And I just wanted to bring this into the conversation, because I feel like it didn't get in there. But you guys know more about this stuff than me. But I was listening to a talk about this about a year ago, six months ago. And it was a group called the Center for Strategic and International Studies. They're like a think tank that's like in D.C. I don't know much about them. Maybe you guys know more. But, you know, they have like these discussion panels. And one of them is about security and like, you know, technology and security. And the entire panel was about supply chain in like virus and injections. Where, you know, you get like some group that basically tries to do exactly what happened with this case. And it's hidden because it's in like a piece of code that somebody, some contractor used, you know, to put together a piece of whatever they're using. They might not even know it's in there. But I just wanted to mention that idea because they had a whole panel about it for a couple hours. And I feel like I didn't hear that come up when you guys were discussing it. But maybe I missed it because I'm not technical enough to follow the conversation here. Yeah, sure. You know, you mentioned CSIS. They're actually part of Johns Hopkins University in Baltimore. And they have some absolutely excellent panels and some really great researchers as well as, you know, just strategic thinkers when it comes to things like you had mentioned, the supply chain attacks. I have no doubt that their panel was very, very interesting. And this certainly was, you know, an example of a supply chain attack. And I think we tried to hint at that by describing it as somebody who's essentially on a bus, right? That's got access to the internal compound, right? So this is part of it. This is part of the infrastructure that a lot of major companies and minor companies all around the world, not just the United States, use to manage a dispersed network infrastructure. And, you know, almost everybody, you know, who's anybody will use SolarWinds in some form or another. And so now it's, you know, triage time, right? Because if these entities know that there was a potential route for being compromised through something like a supply chain attack, as you mentioned, which this certainly can be classified as, now they have to figure out, well, did the attackers break out anywhere? Have they established any sort of other persistent access to our networks? And if so, how are we going to root them out of our networks? Are we going to have to tear it down? Are we going to have to rebuild it entirely? So, yeah, it becomes a very, very big problem. And supply chain attacks are certainly not going to go away. I think in the election component, or rather in the election context, this has been something that's been talked about for quite a while, because a lot of the election, electronic components that go into digital voting, things like that, they're all made overseas. And so how do you monitor and regulate these third parties that are all part of that supply chain? It's a very, very big problem. It doesn't have any great solutions for it yet. But, yeah, you bring up, I think, an excellent point, Collar. It's some scary stuff, for sure. Yeah, when you have these popular services, it just becomes something that, like Alex insinuated, everybody who's anybody is using it, because these networks are so similar in a lot of their complexities that you would need a dashboard like what this provider offers. And, okay, so they're best in class, and our teams inside engineering and operations aren't going to build or engineer it. And even what we said, I guess, they won't even go so far as change the password in some cases. They just need to fix a gap in the internal knowledge as they're designing. What is, as we pointed out, rightly very complex, often very complex and disparate, both things requiring something to keep a handle on a huge system, global systems. But I'm not sure I have an answer in there either. Collar, anything else that you wanted to tell us? Yeah, no, that was good. I'm glad to hear you guys talk more about it, just to hear it that way. It sounds like a totally impossible problem to solve, and I'm sure we'll figure it out, though, so it'll be interesting to see. But, yeah, thanks for letting me keep that conversation going. Thanks for bringing it up. Great show. And thanks for listening. It's a great show, and I'm happy to keep watching you online now. So, thanks. All right, you take care. So, yeah, it's about thinking really carefully with people. He said he was watching us. He can't see us, can he? Are we hacked? Did he hack us? Maybe he can see us. Good question. Anybody watching the YouTube feed? I think it's just fine. I put a piece of tape over everything, so we're just fine. We're secure. Well, then what? I ripped the camera out. Oh, is that what you were doing with the drill? Yeah, all that noise was. Okay, that's an upgrade. I think it is. I think it is. A lot of this depends on how much resource you're willing to put into procurement. And when you're building a system with off-the-shelf products and services, you need to think these things through. And this would be, I think, a best-in-class, off-the-shelf service that fit the bill but had a high cost in failing, especially with lateral moves. Consider this hack is probably old news. Everything that you could have seen or gleaned as a consequence of it, though, those lateral and other effects, that's where people are probably looking right now. Right, Alex? By the way, we're going to try to take one more phone call. 802-321-4225, 802-321-HACK. And that's going to be the last phone call. And that's if we get another phone call. 802-321-HACK. Yes, go ahead, Alex. Oh, I was just going to say, I think you're absolutely right there, Kyle. This one's going to be tricky, but like the caller suggested, too, this is a very, very difficult problem to solve. But it's also an issue of third-party risk, right? And how much risk are you taking on board from third parties that have access to your networks or develop network management software like this, right? I mean, this is the type of risk that I think people have been undervaluing for a long time. So now CISOs and GRC teams or Governance Risk Compliance teams are going to have to re-evaluate all of the network monitoring software that's going to have administrative rights within their networks. And any company that's very similar to SolarWinds that develops this type of software that could be used and abused is going to have to really redouble their efforts to ensure that their source code is not compromised, signed and sent out to all of their customers. This is certainly also not the first time that we've seen compromises like this happen. This also happened, and I don't have the details in front of me, but I want to say it was in Ukraine or it might have been Czech Republic. It was someplace in Eastern Europe that I think had to do with accounting software where a specialized form of accounting software was compromised and dispersed to the client base through the updating process. And I think we might have even talked about this maybe three or four years ago, perhaps. But this sort of attack vector is not entirely new. It's very innovative, and to compromise a company like SolarWinds, this is a massive, massive coup. Very different from some lesser-used accounting software firm, but maybe that was the proving ground several years ago for the threat actors. And showing that as a proof of concept, the attack could be accomplished. Well, there's a major motion picture here, I think. It's a fascinating story and something that we'll be hearing about for years to come and seeing the effects of. I just want to say we're going to be on another two minutes. If somebody calls us in those two minutes, we'll take the call. If not, we will sign off with two good calls. I'm happy with that. Again, the phone number, 802-321-4225. Now, that's a Vermont area code. We're not actually in Vermont. We just thought that was a cool number to get. It's a Google Voice number. It forwards to a landline, and the landline has one phone line attached to it. It does not have call waiting. So, if you called it again, you would get a busy signal. However, Google Voice decided nobody wants to hear a busy signal, so they insist on going to a voicemail message that we don't want. So, if you call when someone else is on the phone, that's what you'll get. And you'll hear the anger in our voices. 802-321-4225. We could lose power at any moment, Kyle. I realize. I hear the wind howling outside. It's very Vermont-like out, I would imagine. It is. It is. I like this. I could live like this for the entire winter. Alex, you lived in Vermont at one point. I imagine this is bringing back some memories. Yeah, it certainly does. I mean, Vermont was like this pretty much almost every other day. You'd have a massive snowstorm. And I used to live – I lived in Vermont when I was in law school. I used to live in Montpelier. Which is smack in the middle of the state. The law school was about 35 miles south. So, we'd have these massive snowstorms. And I remember thinking, you know, the tragic irony of all this was that I was driving an old 1992 Geo Prism, which, you know, wasn't 1992 back when I was in law school. But I would often get on the interstate and drive this small car with sandbags in the back to lay it down before the interstate was plowed. And so, it was an incredibly dangerous 35-mile journey on un-plowed interstate to get to my Will's Trust in Estates class at 8.30 in the morning. And I always thought it would have been terribly tragic and ironic if I had died on the way to my Will's Trust in Estates class. So, it was sort of a reminder for me to slow down on the interstate. Only to be topped by you actually writing or signing your will while you're driving. I think we all have stories of the incredibly dangerous things that we used to do that we somehow lived through. I remember I had a 66 Impala that had bald tires all around. In fact, I got two flats at the same time, which was unheard of. I remember also, the same route, I would ride my bike in the middle of the night with no lights or anything. And somehow, I would make that. That was before people wore helmets. So, yeah, there's a lot of finger crossing. And we're fortunate that we get through this. But that doesn't mean that you listeners should be out there taking unnecessary risks. It's blizzarding outside. It's very cold. There's a pandemic. Although, I have to say, you know, tomorrow or the next day, sleigh riding. I mean, it seems like the perfect opportunity. You're socially distant. You're bundled up. You wear a mask. You're not near other people. You're outside. Seems like a healthy thing to do. And if I'm wrong, of course, Dr. Fauci will tell me. But enjoy the weather. Enjoy the winter. Enjoy the uniqueness of it all. Because these are times that we will remember for the rest of our lives. Okay, I don't think we're getting another phone call, so let's sign off for tonight. We'll see you guys next week, eh? So long, Adam. Good night. Stay dry. Stay healthy. Good night.