Thank you again. Thank you. Thank you for having me. And to all of you in my audience, I look forward to speaking with you again next week when we will continue this kind of programming. The previous program was Economic Update with Richard Wolff heard Wednesdays at 6 30 p.m. right after the WBAI Evening News. It is now 7 p.m. Stay tuned for Off The Hook coming up. We're sorry. The number you have reached 99.5 WBAI is now off the hook. And a very good evening to everybody. The program is Off The Hook. Emanuel Goldstein here with you. Joined tonight by Kyle. Yes, I made it. I'm here. You're here. Great. Awesome. And joining us through telephony, the magic of telephony is a Rapti Firefly. Good evening. Gila. Hello. And Alex. Good evening. How are you all doing this week? We're doing well. Gila and I just have had a full day. We certainly have. Through the good graces of our hero, TurboVax, we went to the Javits Center today and got our first shots. Get out. No, seriously, get get out, because I am jealous. Wow. So the thing that we talked about two weeks ago on these very airwaves you used to your advantage to get a vaccine this early. Wow. I am impressed. Very much. Yes. Tell us what what you did as far as using the TurboVax system. How did it how did you get the appointment? Absolutely. So I was I had Twitter open and I saw that TurboVax mentioned that like 7000 appointments had just opened at the Javits Center. And I said, well, this is worth checking out. And yeah, I think within 10 minutes of figuring it out, I had secured an appointment both for myself and for Rob. And we went today and it was honestly a very smooth process from start to finish. We were inside the Javits Center for 45 minutes, maybe. It was fantastic. I cannot say enough good about the whole process. Wow. That is that is incredible. That's that's amazing. I'm so happy that that you guys managed to do that. One by one, we're all getting the vaccine. And I hope that we're able to help the listeners as much as possible. Two weeks ago, the show is in the archives, 22.com slash off the hook. You can see all of our shows. And we talked about various tips, ways that you can beat the system and get an appointment focusing primarily on New York. But we are willing to look into any other state that has a system. There are always tricks and people in the hacker community are sharing these tricks, are helping people get appointments. This is when our skills really, really come in handy. I must have gotten a couple of dozen appointments for people over the past couple of weeks. And it always works. It always works at some point. You don't get what you want necessarily. You might not get it tomorrow, might not be until mid-April, but at least it's something. And even if you don't get it immediately, you will get it fairly soon. Things are looking good. So the important thing is to keep trying and to take it seriously. If you have any stories about it, always, you can write us OTH at 2600.com. Yes. Alex, looks like you have something to say. No, I think it's wonderful that Rob and Gila were able to do this and that you've been helping so many people as well. I mean, this is, you know, I think a great thing. We're hopefully well on our way towards mass vaccination and something like herd immunity. Yeah, it's especially good. People who are good at video games, which I'm not, by the way, I think they have special skills here that would definitely help out because the way the New York State system works, if you have an auto refresh going, well, the first thing you have to do, you have to stop the auto refresh so you don't lose what just came up on the screen. And then you have to quickly go into the window within a window, scroll down because the select button doesn't appear right away. You have to scroll down. You can use a combination of a tab and return keys to do this quickly, but you have to get it in the right order or you lose. It literally takes place within three seconds, and that's how the system is right now. And I can't imagine people who are not at all computer literate attempting this. Think of, you know, your elderly parents or grandparents or aunts or uncles. Help them out. Contact them. See if they've gotten their appointments yet. Other people are able to get appointments through doctors or I know NYU, if you're a patient there, they have a whole lot of openings. There are all kinds of, and of course pharmacies are offering vaccines as well. One trick somebody mentioned to me is to call a pharmacy and ask if they have a cancellation list. And if they do, that means if they have leftover doses in a particular day and people haven't shown up, they'll call you, assuming that you qualify. And for pharmacies right now, it's only 65 and over. The comorbidities aren't part of the pharmacies, but they will be soon at some point. And when they get to, I think 1C is the next category here in New York state, a lot more people will be eligible as well. Any other vaccine stories? Go ahead, Alex. Yeah, sure. I was just going to mention that, you know, in light of Rob Aguila getting the vaccine today in the New York Post, there was, at least this morning in the New York Post, there was an article about all of the various desperate systems. I mean, it was very similar to what we had described two weeks ago. It probably was. I mean, the New York Post, really, you read that rag, it probably is word for word what we said. It wouldn't be the first time. It does have some good local news, I think. Look, it's not the pinnacle of truth in any sense, but even look, I do like it for the stories, especially early in the morning. But in reading through this article, it was very long for a New York Post article and about all of these different systems and the different manners in which you can try to obtain a vaccine, whether it's going through a pharmacy, whether it's going through the TurboVax site, whether it's going through medical systems. And it was just obvious to anybody who was reading this that it is so disconnected and so discombobulated in a sense that people are starting to really just throw up their hands and say, well, I guess now, even though I'm eligible, now is not my time. But I don't think that that's right. I think we need to continue to encourage people to try to use these systems, to try to figure out how to navigate effectively around them, to listen to the show that we did two weeks ago, especially with the trick manual that you had identified that allows the page to refresh with additional vaccine appointments simply by changing the zip code. And I would really encourage people to use that tip and trick. That's the New York City system. It's changing the last digit of the zip code, makes the page refresh. You just have to keep doing that over and over again. Which is great. And that's on the New York City system, is that correct? Yes. Or it was last time I checked. Yeah. And look, and to continue to look outside of New York as well, but always to keep an eye on the changing regulations about out-of-state vaccines. Even if you are able to get a vaccine, let's say in a place like New Jersey or Pennsylvania, and you may live in New York or in surrounding areas, if you're an out-of- state, that day of the vaccine, you always want to make sure that you are up to date with respect to whatever documentation they may require to get that vaccine, because it could change overnight. Yeah. You don't want to take an interstate trip for nothing. In fact, you'd have to take two because you have to get the next, the second shot. Rob, Gila, what did they tell you about the second shot? When do you have to come back for that? They said that our second shot appointments have already been made, that we just have to show up three weeks from today. If we can come around the same time of day, that's great. And all we need to bring with us for the second shot is our card. Yeah. The card that they gave us today when we got our first shot. You get a card? Yeah. That's a new CDC immunization card. Really? I can show that at various places for discounts. It's a part of the whole- Well, not that card. Yeah. It was actually very funny. In the observation section, because the site at the Javits Center is staffed by the National Guard, so there are military personnel walking around in uniform. And one of them said, okay, now if you're going to take a picture of your card, don't put it on social media. And he walked over to a young person who was sitting there with his phone and said, I said, don't put it on social media. It was very funny because this thing has your full name and your date of birth on it. And so a National Guard person is going around giving cyber tips to kids? Basically, that is what happened today. Yes. Wow. It was a fascinating day from start to finish. Hey, I'd like to play a piece from one of our favorite commentators who we played a couple of weeks ago, actually, involving certain events that are taking place in the country right now. This is from Cory Forrester, who has a lot to say about a lot and is a great comedian as well as others. But listen to some of these comments on some developments taking place regarding the vaccine in other states. Hey, Governor Greg Abbott, have you done it? Have you got it out of your system? Do you feel like all the conservatives and Republicans think of you as the rootin' tootin' shootin' Texas f**kin' cowboy that you want to be looking all tough? We can't have no mask mandates. This ain't really freedom. People are gonna f**kin' die. There's a huge difference in this f**kin' Orwellian bulls**t that you all conjure up in your brain where nobody has any freedom and Big Brother's watching you all the time. There's a huge difference in that and just being f**kin' safe to be f**kin' safe because you care about people and you care. Also, when did you and Marjorie Taylor Greene become the scientists all of a sudden? Now you're, well, because of all the vaccines and we can just open back up to 100 bullets. Or is it that you thought, like, hey, you know what? We can just open Texas back up since there's not as many people. Since we let a lot of them f**kin' freeze to death, naturally there will be more social distancing going on. Is that the logic going through your brain? This is so goddamn dumb. The f**kin' checks aren't even here, all right? Yes, people are getting vaccinated. Things are looking better, but we're still f**kin' not there. Jesus God, how much more do you old white men gotta sling your dicks around while everybody f**kin' dies and suffers? F**k you, man. Come on. Well, I could not say it better. Corey Forrester with more commentary. Look him up. He's on Twitter. I'm sure YouTube, all over the place. What do you guys think? That was a bit subtle. I'm not quite sure I understand completely what they're trying to say. He should be more direct, I think. Yes. He's, of course, referencing the recent disaster with power outages and the overall sort of free system. It's a kind of a nice parallel to his redress over the use of the term freedom, because that's exactly what created that isolated power system, and so many people were affected in Texas. Right. But also, I mean, just in the last day or two, having all the restrictions pretty much lifted, just wishing it away, saying that because things are getting better, you know what, no more masks, no more crowd control, and this is how we lose. This is how all the gains that we have made, by all the sacrifices we have made, that is how it's lost, through idiocy, through the governors of Texas, of Mississippi, of Florida. There's not enough attention being paid to the idiocy going on in these places and the people that will die as a result of it. It's really disgusting, and I think we need to focus a lot more attention on that. Okay, so we have other stories to, Alex, you have something to say as well? Well, I wanted to provide a short anecdote about this very situation, which is, you know, I went to a veterinarian this past week here in Pennsylvania. My dog, Beagle, she wound up hurting her back, slipping on some ice or something, and she wasn't herself, so I had to bring her to the vet. It was not the ordinary vet that I would usually go to, the vet I usually go to is very cautious about coming into the office. They come to your car, they take the dog, you never step foot into the office. This other vet, though, that I went to, I won't name it, but it was the polar opposite, where you took your dog or cat, whatever it is, whatever your animal was, into the waiting room, and you're in there in this enclosed space, and they weren't following any kind of mask mandate. The employees had masks on, but people could be in the waiting room without any mask on. In fact, there was one individual, one man there, who was probably in his 30s, a big dog, you know, drove a pickup truck, and he's just sitting there in this enclosed space with no mask on whatsoever, and I'm thinking to myself, how goddamn inconsiderate can you be to all these people around you? And I'm thinking about it from his perspective, and that he probably never got sick and doesn't believe in COVID or thinks the virus is some kind of hoax. Who knows? I'm putting all these thoughts into his head, you know, trying to empathize. You're also assuming he drives a pickup truck. No, he did drive. Oh, he did drive. Okay, sorry. And you have to think about this. If this person has been able to get through this past year without having contracted the virus, it's in large part due to other people wearing masks, right? Because masks are about protecting those around you. It's common courtesy. It's like what the, you know, this comedian that you just played had mentioned. It's not about protecting yourself, and as much as it is about protecting other people around you. And I saw something in that waiting room that I never saw before. There was a woman who was trying to comply, in some respects, with the mask mandate by using her hair around her face. She wrapped her hair around her face. She had her hair wrapped around her face. I couldn't figure out. That's not going to help. That doesn't help, Alex. That's wishful thinking. Her long locks of brown hair she's using as a mask. I'd never seen that before. I thought to myself, I have to get the hell out of here. This is dangerous. And I felt weird, but, you know, I made up some excuse saying, you know, I need to take some work calls. I'm just going to be hanging out in the parking lot. They seem to get it. But anyway, that's my mask anecdote from last week. Now, where did this happen? This is in Pennsylvania. Oh, in Pennsylvania. I was about to say, give me the address of the place in New York. I'll go down there myself, you know, because I mean, I do see a lot of idiocy. I do see stupidity, but I also see it challenged, and I see it overwhelmed by smart people who are following guidelines. And, you know, that is so important, and you have to reinforce that wherever possible. But, you know, it all goes to leadership. If you have a president or a governor or a mayor who is telling you that it doesn't apply to you and that science is subjective, you're going to make the wrong decisions. And that's where you lay the blame. And that's where we should be focusing the attention, not seeing that enough. And that's really tragic because we could be so much further along, and we are making great strides because of the vaccine, because of the effort so many people are making, but we could be so much better. So just extremely frustrating. Okay, so we have some interesting stories. Actually, a very interesting story, which is kind of the elephant in the room. We talked about Parler over the past few weeks, months, but there was another. There's another conservative social media platform that we haven't really talked about very much called Gab. Have you heard about Gab? Have we talked about Gab? I don't think we've really mentioned it. Well, it's a right-wing social media website, I guess is one way to describe it, but it's really more than that. They have been hacked. Yeah, this always seems to happen. The CEO, Andrew Torba said on Twitter, and I'm not making this up, said that demon hackers were to blame. Demon hackers were to blame. Well, I mean, okay, let's look at the good in that, okay? By saying demon hackers, he's implying that hackers by default aren't demons. So you have to call them demon hackers. Maybe hackers are good in his eyes, but these are demon hackers. But then he went and used a transphobic slur to describe them, which really is revealing, quite revealing. Now, Wired actually reported that a hacker who goes by the name Jack Sparrow, and I can't even tell you what letters are capitalized and what letters are not capitalized in that name, Jack Sparrow, and my little anonymous revival project, that's a great handle, I think. MLARP. What? MLARP. What does that mean? Oh, you mean you're spelling it out. Okay. I was trying to make sense. Does that mean something? I don't know. I tried to make sense of it. That's all I could come up with. Ever since all the real names were taken, I can't keep up. People are spelling things with numbers and symbols now. Got to keep up. Anyway, so Jack Sparrow, or Jack Sparrow, I don't even know. Someone tell me how to pronounce it. And my little anonymous revival project carried out the hack to expose Gab's users. Private messages from some 15,000 Gab users were used to create a data set of more than 40 million posts from the site. 40 million posts, including private posts, user profiles, some users hashed passwords, passwords for groups. They were all affected by the hack, which used an SQL injection vulnerability. Might have some more details on that in a bit. To siphon some 70 gigs of data. 70 gigs. Now, activist data transparency group distributed denial of secrets known as DDoS secrets, I guess is how you pronounce it, plans to share the data with researchers and journalists, but says it's not releasing it publicly due to privacy concerns. In a simpler, more ordinary time, it would be an important sociological resource, according to a blog post on that wiki site. In 2021, though, it's also a record of the culture and the exact statements surrounding not only an increase in extremist views and actions, but an attempted coup. And speaking of which, this is all very relevant because tomorrow is supposedly the day that Trump comes back and takes the helm at the White House. March 4th, the day that lives in conspiracy theorists' minds as the day of infamy. And they are basically, I think they canceled the House of Representatives tomorrow because they really think something is going to happen. Honestly, I don't see how it's possible with all the National Guard basically taking over the city there. But you know what? If they want to try that, I think they should. I think they should show their true colors and show up and, you know, now we'll have more information on these people. That's how you find out. And the information just continues with, I think, the initial change from one platform to another. The real area of interest, and I'm excited to know more about it, is that transfer of people, at least in sort of the real sort of academic sense. But I think we're all ready to go and we're going to be able to learn a little bit more about that tonight. Yeah. Okay. Well, basically concerning Gab, they've had an 800% spike in traffic since January 6th, since the attack on the Capitol. And its registered user numbers have doubled. That's according to National Public Radio. The Anti-Defamation League has called for investigation into Gab to determine whether the social media platform intentionally aided or abetted people who were involved in the riot. Now, this guy Torba found Gab in 2016. It was styled as a free speech alternative to other social media sites that didn't have enough free speech, apparently. It gained notoriety in 2018, you might remember this, when a man posted an anti-Semitic message on the site before driving to Pittsburgh and killing 11 people in a synagogue. Gab removed the account and cooperated with investigators, but they were dropped by their hosting platform and by PayPal. And its app was kicked out of both Google and Apple's app stores for violating hate speech policies. So, same old thing all over again. Wow. So, Alex, I believe we have some people joining us now. We do indeed. We are very lucky to have Zan, who is one of the major players with Distributed Denial of Secrets, here with us tonight to talk about the Gab hack, the Gab leaks, and what Distributed Denial of Secrets is doing with this data, how they are distributing it to researchers, to threat analysts, to people who are doing analysis and research with respect to extremist groups and insurrections. And with that, let me hand it over to Zan and say, welcome to Off The Hook. We're so delighted to have you here. Yes, welcome. I'm very happy to be here. Thank you for having me. Let me just ask right away, Zan, so Distributed Denial of Secrets, people are going to right away say, is this another version of WikiLeaks? What is the difference between these two organizations? Well, we are a transparency organization. We do believe that information should have the right to be free. We do accept leaks. But we are a little different from WikiLeaks in that we are a little bit more cooperative in our approach. We make decisions together as a group. We are not run solely on the whims of one person. We like to make our decisions based on everybody's wishes, not just on the wishes of one. We are run primarily by queer and trans people. And we try to also take the wishes of the source more into account. For example, with the recent Gab leaks, the way that we decided to distribute it was not only based on privacy concerns for the users contained in the leaks, but also based on what the source wanted. The source agreed with how we released it. The source didn't want it as a public release. Oh, I'm sorry. You might see a cat or two. There's always a cat. They're quite welcome. Yeah. But the source didn't want it released as a full public release. The source did want it released as a limited distribution or what we at DDoS describe as a limb, as a limb, as a limb disk. So we very much do also take the wishes of the source into the account how they want it released, when they want it released, in what format they want it released as well. Well, I was struck by that. You mentioned the differences between Wikipedia and your organization. I can't imagine who the one you're referring to might be, but we'll just skip over that. I can't really imagine. But as far as the release itself, what you folks have been doing seems really socially responsible as far as not wanting to invade anyone's privacy, reveal information of a personal nature, and only revealing this to journalists, researchers, people who treat it responsibly, when it certainly could have been. Well, especially in Gab, a lot was pulled. And in it, we feel the data is a very valuable data set for people who want to research things like extremism and things like that. But also, in there, there was a lot of stuff that isn't applicable. You know, Gab is a very big platform. And while it is mostly a right-wing platform, there are just people that are there to talk about things like their day, or their pets, or what their kids did on any particular day. And they don't deserve to be boxed. They don't deserve to have their life splayed out to the world for everybody to see. They don't deserve to have their email address put out there, their password cracked. They don't deserve that. And while there is an undeniable interest for researchers and journalists that do things like track extremist groups, track hate groups, and things like that, you know, there absolutely is an undeniable value to that part of the data set. We also did want to preserve the privacy of people that were just there to talk about their day, or their pets, or their kids, or, you know, complain about work, or things like that. They do not deserve to have their lives laid bare like that. No, that makes sense. I can't help but think that if the tables were turned, the right-wing extremists would say that this is evidence of a Pizzagate-type conspiracy, and that these private messages are actually coded messages, and we have to reveal them all so that we can see if they're talking about cats, they're actually talking about insurrection, or, you know, whatnot. And I'm glad to see cooler heads are prevailing here. And I mean, one of the things, excuse me, that the GAB, that Andrew Torba, the CEO of GABSat, said was that, oh, you know, this is something that they're just doing for us, which is absolutely untrue. Distributed Denial of Secrets has multiple data sets that are considered limited distribution for a number of reasons that, you know, researchers or journalists or whoever want to get access to, they actually have to get in contact with Distributed Denial of Secrets. They have to explain why they want the data set and things like that. We have a whole section on our website for data sets like that, where, you know, it's just not of interest to the general public. That information does not need to be out there to the general public, but may, for one reason or another, be of interest to researchers or journalists or whoever. How about law enforcement? I mean, are you looking at a potential crime scene here as far as planning for things like coups and insurrections? I mean, maybe, but I think one of the things that we really want to focus on is getting it out to researchers who do track things like hate groups, because I think that a data set like this is really important to track the evolution of hate online. The internet has become such a vector and such an echo chamber for hate groups, so it's so important to track how these things evolve online, not only so we can keep communities safe, but also so that, you know, maybe we can break that echo chamber, find out what they're saying, what they're doing, how they evolve, and maybe from that we can learn how to break that echo chamber and maybe de-radicalize. We can find new ways to maybe de-radicalize. Yeah, you know, and along those lines, Jan, you know, especially with regard to the issue of law enforcement having access to this, there may be evidence of criminal activity in this, but there is 70 gigabytes of data. Today, we often lose track of what 70 gigabytes is. If you think about that amount of data in comparison to the Panama Papers, which was 2.6 terabytes of data, which was a massive amount of data, 70 gigabytes sounds like it's not a lot of data, but it really, really is. 70 gigs is a huge amount of data. It's a huge amount of data, especially when you're considering it's text messages and DMs and password hashes, and these are things that normally don't take up a lot of space, and yet you have 70 gigs of it. Yeah, I believe there are no pictures or videos or anything like that included in this, right? No, there's no pictures or videos or any sort of media. The data does have the information that a university lab could use to download the media. It notes, like, GAB posts that had pictures attached or videos, and gives you URLs, and so if, you know, a particular research outfit wanted to use that to then retrieve that additional media, they could, but that didn't seem like the priority for us here. So 70 gigs really is a lot if it's just text. It is a lot. I mean, you know, 64K is a lot if it says something significant. Well, text then links to more data, presumably. Go ahead, Alex. And along those lines, too, we're talking about this is a massive amount of data. You mentioned, and rightly so, there's a lot of contact information. There's a lot of ways that this data can be misused, and I think one of the things that we often forget about, too, is when these things happen, when the parlor leaks happened, and internet archivists were able to scarf down massive amounts of parlor-related data, and while it was in its death throes, and it's still being resurrected in weird places and platforms these days, the communities on these platforms tend to break apart. They tend to segment or balkanize in certain ways. And if you release this data publicly, if you just released it all out, these extremist groups could then use that data, use that contact information to reform, to regroup, to put together a new platform. So I think there are ways in which this data can be weaponized by the extremists themselves, not just by researchers or law enforcement or archivists, that we need to take into account as well. And that's why I love that Distributed Denial of Secrets is doing the responsible thing here in limiting the distribution to researchers, and I'm wondering if there's going to ever be a limited or subset of the data that will be pushed out to the public itself. Yes, sorry. My wife is sitting next to me, Emma Best, one of the co-founders of Distributed Denial of Secrets, and my wife is sitting next to me throughout this interview, so you may hear some interjections. So I will pass this over to them. So on the issue of a public release, it's something that we're definitely interested in. That brings with it some challenges, though, in terms of time, because there's some things that just would absolutely have to be removed, like the hashed passwords and the passwords for the groups, which are all plain text. And then there's a lot of discussions that we need to have beyond that, stuff like the email addresses for verified accounts, what do we do with posts that are marked private, you know, do we make it just public posts, blah, blah, blah. And even after we have all those discussions, that still takes time to execute, because, you know, you're talking about a fairly large database. And one of the reasons we went ahead and just decided to offer it up limbus straight to journalists and researchers was so that we didn't have to introduce this long waiting period. Because there's so much that's going on where this is, you know, very recent events, contemporaneous events, this is stuff that, like, it's an historical archive, but there's a lot of journalists, and we've seen this in the response so far, there's a lot of journalists that could really use this data set now. And so by putting it out this way, we leave all of our, we leave all of our options open and kind of get the best of both worlds. And that way, we also don't have to sacrifice any of the other things we're working on, because we do have, you know, several other projects that we're dealing with. How selective are you with the researchers and the journalists, because I'm thinking, you know, all it takes is one irresponsible person that doesn't care as much as you do, about the privacy, that that could just reveal all kinds of information that really shouldn't be revealed. We're trying to right now, just keep it at, we'll give more or less automatic replies and yeses to people that are very well established, or, you know, work for a very firmly established outlet or institution. You know, like we get an email from someone using a Washington Post email address, and we know it's legitimate, or like New York Times, just going to go ahead and say, yeah, here you go. Same with think tanks and established researchers. There's more room for discussion when it comes down to the freelancers, because there's a lot of very, very intelligent, very valuable freelancers out there. I see a lot of them still out there, and I've worked with them in the past, but anyone can also call themselves a freelancer. So there's some requests that we're letting sit for a little bit longer while we think about it, or figure out exactly how to proceed. You know, most of the people that we've had to turn down are just people that are going, oh, well, I'm just curious. I just kind of want to see what's in there. I want to see if I'm mentioned anywhere. Yeah, yeah, and we have kind of an interesting dilemma with anti-fascist groups that are requesting the data, because pretty much everyone who's part of DDoS or connected to it in any way is anti-fascist. You know, who likes fascism? Apparently a lot of people, but... Apparently, if the number is more than zero, that's too many. Yeah, but tell us about that dilemma. That's interesting. Yeah, because when we get requests from anti-fascist groups, I mean, our immediate personal instinct and reaction is always to say yes, because, you know, I mean, these are our comrades. These are our allies. We're, you know, all about anti-fascist work and direct action. But because of the situation, because of the role we're acting in when we're doing DDoS stuff, DDoS secret stuff, we have to look a little bit more closely at them and focus on anti-fascist groups that do research and they publish their findings, because anti-fascists are flat out, undeniably, some of the best researchers on fascists and fascism. The only people that, you know, study fascism more than anti-fascists are fascists. That's very true. Mm-hmm. But at the same time, there's also a lot of anti-fascist groups that are much more focused on direct action. And again, this is where we get into a little bit of a personal dilemma, because personally, myself, big fan of direct action, but that's not what we're doing with DDoS. You know, and we have to make sure that, like, okay, you're not, if we give this to you, are you using it to research and identify things or are you using it to, like, mess up some Nazis' days? Because as much as we want to see the latter, DDoS isn't and can't be in the Nazi harassing business, no matter how funny we think that would be or how much of a public good it would be. That's not the role of DDoS secrets, and it can't be. No, you're serving a very valuable role, and there are plenty of other organizations that are willing to take on the role of harassing Nazis, so you don't have to worry about that. That will be covered. And to be clear, we're a big fan of those groups for the most part. I mean, if you punch a Nazi or you just follow one down playing a tuba so no one can hear them, whatever, you know, we're watching the clips on TikTok, we're watching the YouTube videos, and, you know, we're big fans of that, too. Awesome. Rob, go ahead. So, Zan and Emma, thank you very much for joining us. I wondered, you were talking about the sorts of individuals and organizations you do want to share this data with, and the way you're releasing it is very fascinating. Have you had, like, a response, in general, if any, to the way in which you're releasing this from, say, the journalists and the researchers? Mostly just a few people that have questions about how Tor works and how to extract and browse these particular files. Unsurprisingly, a lot of journalists are not very familiar with SQL databases or forms of compression that isn't just dot zip. And yes, it was an SQLI. Yeah, and apparently their chief technical officer also isn't very familiar with SQL issues as well. I'd like to go into a little bit about how this happened in the first place. Apparently, from the account of Fosco Morato, a former Facebook software engineer, who in November became Gab's CTO, and on Monday, I'm not sure if it's this week or a previous week, actually, Gab removed the Git commit from its website because the change that Fosco Morato made was a Git commit. And that is what basically opened up the security hole. The commit shows a software developer using the name Fosco Morato introducing precisely the type of rookie mistake that could lead to the kind of breach that was reported over the weekend. Specifically, a line strips the code of reject and filter, which are API functions that implement a programming idiom that protects against SQL injection attacks. And I guess we don't have to get into the specifics here too much, but this is a rookie mistake is how it's being described in Ars Technica. And anybody can make mistakes, I suppose. But boy, this is something that really shouldn't happen in a platform like this, correct? Yeah, I mean, when the source first told me that it was an SQLI vulnerability, because I never try to get too many details, because I don't want to know things that I could be compelled to testify about. But, you know, we do have to ask some basic questions. And they said it was SQLI. And, you know, for a while I thought, like, okay, I wonder if that's just them trying to, you know, come up with something to help cover their tracks. It's a diversion. Because some sources will try and, you know, get clever like that. And after it became public, I started getting several people sending me messages and little excerpts from the public gab code saying, I'm not positive, but it looks like you could execute arbitrary code here. People found multiple things. I've heard that. I've had friends look at the code multiple times and say, here, here, here, here, here, here, here. Yeah. And I mean, to kind of give everyone listening an idea of just how bad it is. When we were talking about it internally, whenever I first explained it to anyone, like when I talked to Zan or, you know, the other DDoS members, the way I explained it was, I want you to imagine the worst possible way gab could have been breached. And I went, no. It goes beyond that, too. In this Ars Technica piece, there's a section called revisionist history. Besides the commit raising questions about gab's process for developing secure code, the social media site is also facing criticism for removing the commits from its website. Critics say the move violates terms of the Affaro general public license, which governs gab's reuse of Mastodon, an open source software package for hosting social networking platforms. Critics say the removal violates terms that require forked source code be directly linked from the site. The requirements are intended to provide transparency and to allow other open source developers to benefit from the work of their peers at gab. Now gab had long provided comments at code.gab.com. Then on Monday, the site suddenly removed all commits, including the ones that created and then fixed the critical SQL injection vulnerability. Now get this, in their place, gab provided source code in the form of a zip archive file that was protected by the password. Jesus Christ is king. Trump won the election. I am not making that up. That is. Yeah, didn't they leave the password in plain text somewhere? Well, they had to because it was otherwise it was a violation. Yeah, they just left the password there. Real quick, just jumping back half a second, because you mentioned that the gab code is based off of Mastodon. You know, they did the fork. I just want to be very clear for everyone listening. gab introduced the vulnerability. I know we kind of said that earlier. But this was 100% gab, they they forked Mastodon, they got something that was, you know, pretty dang secure. And then they tweaked it and made it vulnerable on multiple fronts in the most embarrassing way possible. Okay, that that thing is not Mastodon. Please don't blame Mastodon. Yes, I'm very glad you made that point. This is all the white supremacist's fault. No, I'm very glad you made that point. But also, I think they deserve some credit, because what you just described takes a bit of skill to take something secure and turn it into something so insecure. Alex, go ahead. Yeah, as a lawyer and someone who's also been a CISO, I mean, it's hard to get it right all the time, right? But it's also hard to get it that wrong. It does take some work, I think, to do it that poorly. But what I'm wondering about here, from a legal standpoint, you know, whenever there's a breach, that affects a large amount of people, and especially on something like a social media platform, like gab, right, there may be some kind of regulatory scrutiny of those information security practices after the fact, right? So here, I'm wondering, if, if Xan or Emma, you know, what gab had said about its cybersecurity posture before this particular breach? Did they hold themselves out as being as respecting privacy and having a mature or enhanced cybersecurity posture? What did they say about cybersecurity before this breach happened? Because that could determine whether or not there is any kind of governmental or regulatory scrutiny into this breach after the fact. I can't, I can't quite answer that. But I can do you one better. I don't, I don't know what they were saying about their security before the breach. But I can tell you that after the breach, I think within a couple hours of Andy Greenberg at Wired reaching out to them for comment, they posted a blog post. And they said that they knew about the vulnerability and had patched it the week before. And it was very much still live. And because of the way gab's PR handled it, demon hackers, a lot of people were watching as they edited the code in real time, and removed the still active vulnerabilities. And one one thing we haven't really gotten to yet, because just so much has been going on. Because the vulnerabilities were still active, the source Jack Sparrow was able to get a little bit more. And the other day, we got an update of just the little bit from the window of when they first scraped and sent us the database, and when they finally turned off all the vulnerabilities. So we're going to be adding that, I imagine, to what we're offering journalists pretty soon. Zan, I'm away in our last minute. So I just want to give the opportunity, if there's a way people can help DDoS secrets, or any any inspiration you can give to others that might be following this story with rapt attention. If you want to help out with anything, ddossecrets.com slash donate. It also has information on how you can contribute. And honestly, just spreading the word about everything we're doing is one of the most helpful things anyone can do. Well, I want to say, what you're doing is really inspirational and responsible too. I can only imagine if leaks of the past had been handled this responsibly, I think we would have learned so much more from them in a timely fashion. Yeah, it's important when you have a ship to steer, you have to steer it and stick to that, not a waiver while you're handling stuff like this. In the 30 seconds or so we have left, can you tell us something about the history of the organization, how it started, how you guys were inspired? Some colleagues approached me, basically saying, there's no leak projects or outlets that we feel we can support anymore. We kind of want to help you put together a new one. And they did, they kind of handed over a little bit of technical stuff for me, people I'd known for a few years, and slowly people have been joining up, helping out, and we've just been doing more and more ever since. Awesome. All right, thank you very much for joining us, Zan and Emma from DDoS Secrets. And what a story, and I'm sure it's going to get better as the weeks go by, and who knows what other platforms are out there as well. Well, we are going to be back in at eight o'clock for overtime at YouTube, youtube.com slash channel 2600. You can find us there at eight o'clock, we'll take your phone calls at 802-321-4225. You can write to us at offthehook oth at 2600.com. We'd love to hear your feedback, but we're going to take a short break now. This is from an album that just got released today by Leonard Summer, who is from the Indigenous community of Canada. This is pretty awesome. Take a listen. I thought that I was paying the cost twice. Industry's not nice, it'll burn like a hot knife, hammer you down like a stone in the Klondike. They're looking for gold, any way they could get it. Put a price on your spirit, if you're willing to sell it. And I told them, no, I have never regretted it. I am rooted in culture and it's deeply embedded. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was, sitting in the lodge with the drum songs feeding us. Hey, hey, hey. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was, sitting in the lodge with the drum songs healing us. Hey, hey, hey. If I could have told me when I was a young man, not being yourself, well, that's just a dumb plan you got to invest in. Your health can be rested. Aggression is useful if not misdirected. Lust is for lost ones, so proceed with caution. There's a lot of hurt people, just make sure you're not one. True love is awesome, though the heart can play possum. If the energy's right, it'll make your life blossom. Make room for correction, tell all your blessings. Reputation is nothing if you ain't respected. If you have learned something, every loss is a lesson. Being boss is a notch and everything is connected. Tell your mama that you love her every day of the week. Give thanks to the creator when you wake and you sleep. Life ain't a game, ain't no playing for keeps. We don't take what we own when we finally make peace. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was. Sitting in the lodge with the drum songs feeding us, hey, hey, hey. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was. Sitting in the lodge with the drum songs healing us, hey, hey, hey. Patience is discipline. Love is a medicine. Let me go at you Wayne Dime. I am thankful for everything. I am thankful for everything. Patience is discipline. Love is a medicine. Let me go at you Wayne Dime. I am thankful for everything. I am thankful for everything. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was. Sitting in the lodge with the drum songs feeding us, hey, hey, hey. College never taught me the knowledge I was dreaming of. I was 27 when I learned who I really was. Sitting in the lodge with the drum songs healing us, hey, hey, hey.