A high at a at And a very good evening to everybody, the program is off the hook, a bit of a rough landing there. This is a manual joined tonight by Kyle. And over in Skype land, we've got Alex, and we've got Rob T. Firefly. And we have Gila. Well, what a week this has been. It's March 10th, 2021. I guess if you called it anything, it's the week of security lapses and violations and things like that. We've got a lot to get into, a lot of follow-up for things that we've been discussing. And of course, we have overtime coming up at 8 o'clock on our YouTube channel. That's channel 2600. And you can get the exact link by clicking on the icon at the top of 2600.com and just wait over there because you can make phone calls. The phone number, by the way, for later, for 8 o'clock is 802-321-4225. It's 802-321-HACK. And you can call us and tell us what you're up to, how you've been experiencing the pandemic, if you've been able to get a vaccine. We've been helping a lot of people get vaccinations with different systems, New York, New Jersey, places like that. And people are getting them. I got mine last week. I know, Rob and Gila, you got yours last week as well. Quite an experience. I had it out in Long Island and got to see the National Guard directing traffic. And it was, for the most part, pretty calm and collected and organized and really felt kind of proud seeing everybody coming together like that. And I continue to feel proud seeing people following the guidelines, wearing masks, keeping distance, taking care of each other while this thing plays out. And it is playing out. We're getting to the end of this, but we'll get there if we all continue to think logically and follow the science. Because everything that we have been told as far as what to expect has come true. When the peaks will be, when things will go down, when things will get better, when things will get worse, what kind of behavior will cause problems, how the holidays affect things, it all has played out exactly as predicted. So when people tell us that there's going to be a lot more availability of the vaccine in the weeks ahead, I believe them. And I think by summer, we will be well on the way to normalcy, unless stupidity reigns. And of course, if stupidity reigns, then anything is possible. It's all about adhering to just the basic stuff and still living your life and having a little bit of fun. But in the basic steps, not really backing away from as much as it's taken to get to the point where we're at, where there is tremendous excitement for the possibility of doing what were really simple things, I guess, a year ago to the day or this week. Yeah. I should point out that I'm kind of on call as far as something might beep or buzz or ring, and it might involve a vaccine that becomes available that I need to help somebody with. So if that happens, I might have to duck out for a few minutes. Yeah, the schedules don't wait, do they? Don't. And it's possible that will happen during the show, because that is just how Murphy's Law works. But you guys, any Rob, any feedback you want to give? How have you felt after after your vaccine, by the way? I feel like feeling fine. I was tired the day after, but that was it. And you know, it's been a week and feeling great. Yeah. Same. I felt like I had a mild cold the next day and cleared up by the afternoon. So really, I couldn't feel better about this whole thing. I felt a little tired and I had this mysterious ache right where they inserted the needle for about a day. Still haven't figured out what caused that. That's gone now and I feel fine. Which vaccine did you get, by the way? Pfizer. Pfizer. Same here. Pfizer represent. Wow. That's great. Well, let's calm down. You can take pride in your vaccine, Kyle. Maybe you'll be a Johnson and Johnson. I don't know. I just think it gives the wrong idea, but that's good. There's some affinity in the group. They gave me a flag. OK, so I intend to use it. Flying the Pfizer colors. Yes. Alex, go ahead. Well, I feel like you guys have all disclosed that you got your vaccines. I can disclose I got mine, too. Good. OK. I'm glad we can finally reveal that that happened. Tell us your experience. Yeah. My experience was a little bit different from yours. I got the Moderna vaccine. I was happy to get it. I got it in Pennsylvania fairly recently and it really did kick my butt for a while. The injection itself didn't hurt really whatsoever, but I was very fatigued later on that night. I had a pain in my arm for about three or four days and not just a regular pain, you know, like something was injected in you and, oh, that's pain, but deep soreness in my shoulder to the point where it was very difficult for me to lift my arm over my shoulder to go higher than my head with my arm. That hurt. And then the second day of the vaccine, I was not only really tired, but I also had the chills that night and then the sweats and then the chills and then the sweats. So I was running a fever. After that, I was perfectly fine and I was happy to endure all of that for the privilege of obtaining the vaccine and having that measure of security and normalcy, hopefully returning back to life soon. And we are in no way implying that just because you got the Moderna vaccine, we're not looking down on you. We're Pfizer's. We're not looking down on you in any way. So don't feel like we are because, Alex, we're not, I promise we're not doing that and we're not saying that you had all those side effects as a result of you getting that vaccine instead of the one that the rest of us got. So don't feel that way. That's right. They're all as good. They all will combat the disease. Well, you know, as an Oxonian, I think that the Oxford vaccine is probably going to be better than all of them. So, you know, the main idea, though, is that when when they offer you a vaccine, if you get the chance to have a vaccine, get the vaccine. Don't worry about picking flavors like you're at the Soda Fountain and Burger King. Any one of the vaccines available will help you. It will help the people around you. It will help this whole herd immunity thing we need to get going. And it's all of our responsibilities to just get on that as soon as we can. Yeah. And while you're at the Soda Fountain at Burger King, don't dawdle there either, because wait, why? Why are we at a Soda Fountain and Burger King of all? Is that where they are now? What happened to the independent ones? My God. All right, well, let's continue vaccinating the airwaves here at the WBAI. That's good. I like that. Where you can always become a WBAI buddy. So this is an interesting story. This is, I think, the one story that doesn't have to do with a security breach. It has to do with a release of information, however, though. Last Thursday, New York City's civilian police watchdog released a searchable database of complaints made against current and former NYPD officers. Much of the information contained in the Civilian Complaint Review Board's database was made last summer by the NYCLU, New York Civil Liberties Union. This release of records marks the first time a city or state agency has made such a database available in compliance with last summer's repeal of 50A. That's the state law that had long shielded police misconduct records from public scrutiny. The repeal was vehemently opposed by law enforcement unions, our favorite people, which have spent the intervening months challenging the decision in court and throwing all kinds of temper tantrums. The database's launch comes right after the Court of Appeals for the Second Circuit said the release of disciplinary records for police officers, corrections officers, and firefighters could begin immediately. Now, this database includes information on 34,811 active NYPD officers and 48,218 inactive officers with complaints dating back to 2000. That's a lot of complaints. I would have guessed that's how many officers there were, but boy, a lot of complaints against these people. Details about each complaint are limited to the incident date, the type of complaint, which is force, abuse of authority, discourtesy, offensive language, a one- or two-word description of the allegation, and whether the complaint was substantiated. Unlike the NYCLU's database and a smaller one published by ProPublica, information on the CCRB's site will be updated on a daily basis. This seems like a golden light onto democracy, onto revealing actual information. It's just basic public interest oversight and probably long overdue in a lot of cases, and there's really interesting stuff in here. You want to know, are there officers or groups of officers that tend toward many of these violations? Is it always a violation, or it's not different officers, but how many groups, how many times and how many different officers were involved in different incidents, and what kinds of patterns of behavior, and how can you associate that with other information? It's important. Yeah, whereas in the past, this information was kept completely secret. You couldn't find out somebody's name who was involved in some kind of crime or abuse or something like that. Yes, go ahead, Alex. To bounce off Kyle's point, too, I think this is a real victory for the civilian oversight of the police, and that's just a fundamental principle that we have in this country. The military has civilian oversight by the commander-in-chief. The commander-in-chief is somebody who is a civilian. The president is a civilian. Overseeing the military, we should have a high degree of transparency and civilian oversight of our local police forces, and so anything that contributes to that sort of transparency, I think we can all get behind and be a proponent of. My understanding, too, is that with the release of this data, it will be in a format that it's not easy to completely digest all of it, like we were talking last week about the gab leaks with Zan and Emma from Distributed Denial of Secrets, which was such an awesome show, by the way. If they're listening, thank you guys so much for being on, but that's a different type of data. That's a huge amount of data that can be analyzed really quickly. I think this type of data, hopefully, will be put up in such a way that the data can be easily digested and downloaded and then analyzed for corresponding data points like Kyle was suggesting. I think that's going to be really, really interesting, and the other thing I'm personally curious about is I complained about treatment from an officer about two years ago, and I'd like to see if it's in that database. In particular, and this was an interesting anecdote, are you interested in hearing what happened to me? Absolutely. Okay. Well, this was the situation. I'm walking across 14th Street in Manhattan, so the West Village was on the south side, so West Village, north side's Chelsea, and I'm there with my wife and I'm there with my child. This was actually maybe about three years ago. So this was before a bunch of cars got stricken from 14th Street? That's correct. They've changed 14th Street, basically. Yeah, this is before that, and my son was in a stroller, and we're pushing the stroller across the street, and we have the white man telling us that it's okay to walk. Okay, well, I've got to stop you right there. When you say you have the white man telling you to walk, you're talking about the crossing signal, which is a white light with a man on it, and then it turns into a red hand with a number counting down at some places, not all of them. That's a racist overlord telling me it's okay to cross the street. Please continue. Try to avoid those kinds of references. So yes, I'm crossing the street going from west to east, and coming from the eastbound lane on 14th Street, making a left to head south onto 7th Avenue. The avenue that I was crossing was a police officer in a canine unit truck, and the white lit up man is telling us it's totally okay to cross. We're going. We got a stroller. We're trying to get a move on, and all of a sudden, out of nowhere, a cop, this cop who's making a left-hand turn, rolls down his window and starts screaming at us and screaming expletives. Get the F out of the way. What are you doing? Come on. Move it. I couldn't believe it. I could not believe that we were being treated this way by some random cop who wanted to make a left. Two questions. Obviously, he was in a car. You had the light. You had the white man or whatever you want to call it, or maybe it was turning red by then, but you still had the light. Was his siren or his flashing lights on or anything like that? His lights were not flashing. He just was in a hurry to make a left. He didn't want to miss the light, because the more pedestrians they cross, the less likely you are to make that light. Wait, wait, wait, wait, wait, wait. A cop was worried about missing a light? I've never heard of that. Well, I'm speculating as to why he was in such a hurry, because like you said, his lights were not on. He didn't seem to have any other sense of urgency. There wasn't any kind of emergency situation, and yet here he is screaming and yelling. Hang on. Gila has a question. So you said it was a canine unit, right? Wait, a canine unit? Maybe the dog pooped in the car and he needed to deal with the poop. Don't help the cops, Gila. Don't help the cop with alibis. I'm just speculating. That's their job. Let them do it. Yeah, leave the dog out of this. Yeah, and don't blame the dog. It's always the dog's fault, right? I'm sorry. Continue, Alex. So in any event, I don't really know what to do at this point, because I hear somebody yelling and screaming at us. I look up and I see it's a cop. I think to myself, what in the world is going on here? This is crazy. And it was also sort of emasculating, too, because here's a guy that you know not only has a vicious dog in the back, he has the authority to arrest you, and he's armed. So ordinarily, I would yell back at this person, tell him where to get off, whatever. I have Sicilian blood in me, so I've got a bit of a hot temper. But when it comes to a police officer yelling at you like this, it was a little bit emasculating for me, because there's really not much you can do. You just take it, right? You just hurry up across the street, because he thinks he can completely act with impunity. So I was so mad about the situation that I called up 311, and I went through the whole process of filing an official complaint. And then somebody followed up with me about this, but I didn't have the exact unit number of the vehicle. So they're trying to figure out who was going south on 7th Avenue, crossing 14th Street at that particular time. And I requested follow-up several times from the 311 system or the NYPD, and I never heard anything. So I'm very curious as to whether or not that complaint is in there. But how are you going to find, if you don't know the guy's name, and I assume you don't know the dog's name, I don't know if dogs are even included in this database, and how would they ever find? I guess the K-9 unit, they might be able to eliminate the number of cops in that region at that particular time of day, but I would bet against it for that kind of a thing. You would think with all of the geolocation tracking that's involved in traversing Manhattan these days, they would be able to locate one of their own K-9 units at a specific place in time in the city that they are charged with policing. You would think that. So that's why I found it particularly incredulous that I didn't hear any follow-up about this whatsoever. Go ahead, Rob. One thing you can do with this database, and like I said, it is a real win for the Civilian Complaints Review Board, which is baked into the city charter as civilian oversight of the NYPD. And so it's good to see them actually get the ability to accomplish things like this. You can look things up by the officer's name. You can look things up by the officer's SHIELD number, the badge number, which is especially interesting if, like me, you tend to keep tabs on when protests are going on, political actions, things like that, and there come up photographs or video footage of police officers behaving badly, let's say. And you can now look that up and not only look up the badge number and get the complaints, but look up the badge number and see which officer this is without going to further trouble. And this is hosted on nyc.gov. It is a part of the city, basically, that's doing this. We're going to give you the URL in just a second, but first these caveats. The database reflects CCRB complaints only. That's Civilian Complaint Review Board. Only their complaints. Allegations of misconduct that fall outside of their jurisdiction are not included in that database. The New York City Charter specifies that the CCRB's jurisdiction includes four categories of police misconduct, force, abuse of authority, discourtesy, that's you, Alex, and offensive language. That's also you. You got two of them. That's right. I got two. CCRB allegation history does not include open allegations, successfully mediated allegations, or mediation attempted allegations. CCRB allegation history does not include allegations from complaints filed prior to the year 2000. It also does not include referrals to the NYPD or other investigative entities. In the modules included in this database, FADO type refers to where the allegation fits within the CCRB's FADO jurisdiction. Anybody want to guess what FADO stands for? No? Okay. Force, abuse of authority, discourtesy, and offensive language. I just said it, so they have an acronym for it. There is a significant difference between the CCRB dispositions exonerated, unfounded, and unsubstantiated. When exploring the database, please refer to the definitions of the CCRB's case outcomes. The URL is the following, www1.nyc.gov slash site slash CCRB slash policy slash capital M, capital O, capital S dash records dot page. You know what? That's too much. You expect people to remember that? Because if you don't have the capitals in there, it doesn't work. All right, so what we did right before the show is we made a tiny URL for you, tinyurl.com slash NYPD dash database. That's much easier, right? Lowercase. Lowercase. Just do that instead. NYPD dash database. Have fun. Enjoy yourself and look up whatever it is you want to look up. That's what we're about, spreading information. Yeah, the important thing is you have this as a resource now, and it's important to recognize and find out how we can help and benefit from this information now. What ways will it be used, and how do we get it out there to the right people? Exactly. So that's really cool. That's what Off the Hook is about. That's what it's been about. Yeah, absolutely. That's what we've always been about. What hackers have been about. Yes, Alex, go ahead. My understanding as well is that there will be some kind of NYPD database that will eventually come online, but at the time that this database went live, the NYPD said it wasn't yet available to be made live, so I think there will be more data coming. Of course. Yeah, because they delay as much as possible. I heard that their database, when it does become available, it'll look like baseball cards. In fact, that's how they're going to present their officers as if they're on baseball cards, which is fine. Spread the information however you want to do it, but as far as getting to the actual truth, I would trust the CCRB. I think you mean Little League cards. I'm not going to say, but yeah, they're not out yet, though. Okay, so to the breaches, because we have a lot of security issues to deal with tonight that we really should get into. First and foremost, a threat actor has hacked into the social media account of South Korea's biggest boy band, BTS, also known as the Bangtan Boys. The seven-member band joined TikTok in 2019 and has since ... Wait a minute. Why did this make it to the top of the list? This is hardly the most important thing that happened. I'm sorry about this. Yeah, I'm looking at the ... Okay, the TikTok messages or whatever. It's pretty shocking, but deal with it, guys. Okay, your TikTok got hacked. I'm sorry. That's not the story I wanted to read. Microsoft Exchange. Yeah, that should have been at the top. This is something that's pretty huge. Since January, since early January, the signs have been here for this particular exploit. Now, Microsoft announced last week that its widely used email server program had been hacked, and since then, experts are not encouraged by what they have found. According to Katie Nichols, the Director of Intelligence at the cybersecurity firm Red Canary, in short, it's gotten really messy. We are seeing no signs of this slowing down. The cybersecurity community sprang into action after Microsoft first announced a series of vulnerabilities that let hackers, or perhaps we should say intruders, break into the company's Exchange email and calendar programs that are used by hundreds of thousands of companies around the world. China has used it to spy on a wide range of industries in the United States, ranging from medical research to law firms to defense contractors. China has denied responsibility. Maybe we don't say China, maybe we don't say hackers, maybe we just simply say intruders because it could be anybody, and that's what this is increasingly pointing to. Now, Microsoft's announcement has complicated the situation with efforts to fix the flaws appearing to have drawn more intruders to exploit organizations that haven't yet updated the software. Nichols said she'd seen indications of five different hacker groups whose identities are unknown. We're now exploiting it. If their identities are unknown, I'm not sure how we know they're hacker groups, but whatever. The list of victims is growing. According to Ben Reed, Director of Threat Analysis at the cybersecurity company Mandiant, it's big. We're above 40 incidents we're responding to, just current customers we have. We have right over 500 likely victims based on confirmation of likely sources. Now while there was no official public list of victims, the full tally is definitely in the tens of thousands. There's definitely a lot of small, medium-sized entities. That's the customer base of Exchange. Now there have been no reports so far that any government agencies have been affected. The U.S. Cybersecurity and Infrastructure Security Agency, the country's primary cybersecurity agency, today exercised its emergency powers to force government agencies to update to the latest version of Exchange. I'd like to see that memo. In an unusually candid message, the agency then tweeted Monday evening that CISA, Cybersecurity and Infrastructure Security Agency, urges all caps, organizations across all caps again, to follow guidance to address the widespread domestic and international exploitation of Microsoft Exchange server product vulnerabilities. Now the hack started quietly as a more surgical operation. Initially the only intruders exploiting Exchange were the ones Microsoft identified as Chinese spies, sometime around the beginning of the year, the beginning of January. Near the end of January, the cybersecurity company, Valexity, noticed that hackers were spying on two of its customers and alerted Microsoft so it could begin working on a fix in its next Exchange software update. Keep in mind the amount of time that has passed here. Now Valexity president, Steven Adair, said that they were using that explicitly to steal emails. It was under the radar. And he said, after he told Microsoft, he noticed a change in the hacker's activity. They seemed to realize a patch was coming, so they moved from stealthily reading emails to trying to create footholds to stay in their victims' networks, which made them far more visible as cybersecurity defenders. You don't care if they're noisy because you're trying to beat a patch. That's what he said of their strategy. You found your high priority targets. You've been stealing emails. Now you want to move on. Maybe you want to build infrastructure to launch future attacks. Hackers began frantically exploiting the Exchange vulnerabilities around the end of February, and it's escalated since. We continue to see exploitation of these vulnerabilities over the weekend. Any organization with an Exchange server needs to take it very seriously. And yeah, I would definitely say so if we know anybody who uses Microsoft Exchange. According to a David Kennedy, CEO of cybersecurity firm TrustedSec, he said hundreds of thousands of organizations could have been vulnerable to this hack. Anybody that had Exchange installed was potentially vulnerable. It's not every single one, but it's a large percentage of them. On the scale of one to 10, this is a 20, he said. Yeah, he's good with the soundbites. It was essentially a skeleton key to open up any company that had this Microsoft product installed. Fixing the problem isn't as simple as clicking an update button on a computer screen. It requires upgrading an organization's entire so-called active directory, which catalogs email users and their respective privileges. Taking down your email server is not something you do lightly. But something else you shouldn't do lightly is sign on to these companies that might not get security as much as they should. This is going to cost so many companies so much. People laugh at us when we say we run our own mail servers, and they're not laughing now. This is why. This is why people like to do things themselves and not just sign it over to a company that when they mess up, what happens to you? Yes, Alex, go ahead. Look, there's no way, I think, to overestimate this type of breach. This is totally massive. This is something that the effects of which are going to be felt for a very, very long time. Because, as you mentioned, I think rather quickly in the article, there is this race to develop persistence in high-value targets as networks. So it means they had access through exchange to certain portals, and they knew a patch was going to be coming. So what they were trying to do at that particular point was figure out how they can stay in, and that may take any kind of form. There's no indicators of compromise for whatever those other forms of malicious activity are that these threat actors then use to maintain some kind of persistence in the network or otherwise make some kind of lateral move around the network. So it's not enough to just figure out, okay, our exchange server does look like it seems to have been compromised or it was abused by some of our cyber adversaries or threat actors, whatever you want to call them, because then if that is the case, if you find any kind of indicators of compromise that your exchange server was in fact affected, then you have to begin the hunt anew to determine whether those same threat actors have any kind of additional foothold within your network. So this is extraordinarily big business for forensics firms that are going to have to response to this. I mean, there are a lot of entities right now that are in incident response mode. To go back to what you were saying, Emmanuel, with regard to this is why others do it, I mean, Microsoft has, I think, has been a lot better lately and has really been at the forefront and leading the charge when it comes to sharing threat intelligence and taking security seriously. But I think that this shows that there are any number of ways to compromise a system and a belief that something is secure is particularly naive because you have a widespread event like this happening. And on the flip side of this, too, is there once the indicators of compromise were out there and there was a race to patch, I think not only Chinese cyber adversaries, but there were threat actors and organized crime groups from around the world that were trying to exploit this as quickly as possible. So in so doing, and no doubt they got there before the patches were properly installed. In so doing, there is now, we have to assume, a great deal of private information from these various exchange servers that is floating around in the hands of adversaries. And that's information that will be exploited over time, over long periods of time, perhaps for identity theft or business email compromise or the theft of trade secrets. So I think a lot of perhaps even intelligence services were trying to exploit this as quickly as they possibly could so that they could hoover up data and use it for their own advantage. So I think there's criminal groups, there are intelligence agencies, there's a lot of other adversaries out there that probably took full advantage of this. And this is going to be a problem that's felt for a very, very long time. Go ahead, Kyle. I think it's valid, the critiques of services like Exchange or Outlook, if it's hosted and maybe there are other solutions you could take an interest in. But if an organization is choosing this, I think there are arguments to be made that, as Alex indicated, Microsoft is to a degree proactive in developing that product because it is a product that they're expecting people to pay for, to get updates, or to have control over how they host their email. And I think the vulnerabilities, there were four zero-day vulnerabilities. And to a large degree, when you look at this, if you step back a little bit and you want to give Microsoft the benefit of the doubt, you would maybe point to the ways we're incentivizing the knowledge around zero days and how that's marketed and even repackaged in intelligence circles and becomes valuable instead of fixed. And I think that's where hackers who talk about these things are open with firms and have a sense of humor about it and really have the same feeling that they want products that they've essentially paid for or that we have an expectation to work. They want them to work as well and not leak our own data in the process of just simply using the stuff and so forth. Well, when you consider the first inklings of this were in early January, and here we are almost in mid-March, and it's still playing out, the response could have been better, for sure. But when you sign up for a company to trust with your private information, there's no guarantee that it's going to remain private. There's just no guarantee of that. And if you understand that when you sign up, well, then you can keep your own local backups. And if something like this ever happens, at least you still have your data. It might be in other people's possessions as well. But that's kind of, when you sign over to Microsoft to handle your email, you're kind of giving that away right then because if they mess up, your private information is no longer private, period. We have to move on because we have so many other stories to get to in a very limited amount of time. A group of hackers say they breached a massive trove of security camera data collected by Silicon Valley startup Verkata Inc., gaining access to live feeds of 150,000 surveillance cameras including hospitals, companies, police departments, prisons, schools, my God. Companies whose footage was exposed include car maker Tesla, software provider CloudFlare. In addition, hackers were able to view video from inside women's health clinics, psychiatric hospitals, and the offices of Verkata itself. Some of the cameras, including in hospitals, use facial recognition technology to identify and categorize people captured on the footage. The hackers say they also have access to the full video archive of all Verkata customers. And I apologize if I'm pronouncing Verkata wrong, but I've never encountered that word before. In a video seen by Bloomberg where this story comes from, a Verkata camera inside Florida Hospital Halifax Health showed what appeared to be eight hospital staffers tackling a man and pinning him to a bed. Halifax Health is featured on Verkata's public-facing website in a case study entitled How a Florida health care provider easily updated and deployed a scalable HIPAA-compliant security system. Another video shot inside a Tesla warehouse in Shanghai shows workers on an assembly line. The hackers say they obtained access to 222 cameras in Tesla factories and warehouses. The data breach was carried out by an international hacker collective and intended to show the pervasiveness of video surveillance and the ease with which systems could be broken into. That's according to Tilly Cotman, one of the hackers who claimed credit for breaching San Mateo, California-based Verkata. Cotman, who uses they-them pronouns, previously claimed credit for hacking chipmaker Intel Corp. and carmaker Nissan Motor Company. Cotman said their reasons for hacking are lots of curiosity, fighting for freedom of information and against intellectual property, a huge dose of anti-capitalism, a hint of anarchism, and it's also just too much fun not to do it. OK, these are my people. So that's probably the best. These are hackers. That's what hackers do. They find a security hall. They reveal it. They show how vulnerable everybody is. And we learn from it. There's no profit motive here. There is simply the desire to educate. And this is huge. This is huge, being able to spy on all these cameras. And just because you're able to do it doesn't mean that there aren't thousands of other people who can do it and won't tell you. Go ahead, Rob. And this goes back to what you were saying before about when you just hand control over something to some external company for really no good reason. I mean, security cameras are a known technology. It is basically a simple matter to get a set of security cameras, get a system to run the thing, and have that all hosted locally in your building or even hosted somewhere else but still somewhere under your control. You don't have to sign it over to some cloud-based company that's just going to leave you vulnerable to something like this. And especially when you're running security cameras in a place like a clinic, a hospital, all these places where privacy of the footage is paramount. It is just an act of, I consider it an act of carelessness to even go for external providers and things like this when you can get it done yourself for probably more money but it's worth it in the end. But, you know, that's not to say that you can't also make yourself vulnerable by doing it yourself and not obeying security rules. For instance, if you have a security system on Wi-Fi and you use default passwords, well anybody just driving by will be able to log into your system and spy on you in a more personal level. This one in particular, yeah, it's very dramatic because it's one company. One company was accessed and they have hundreds of thousands of customers and by extension all of them are vulnerable as well. That is the choice we make when we sign up for these massive companies who don't respect security. Alex? One question I have about how this was done is that was all the data from Verkada going to one centralized repository that was breached by these particular hackers or were these individual breaches of security cameras? Do you know the answer to that? I think one led to the other. I think it was a massive breach of Verkada and then through that you could pretty much pick and choose because it seems that's what they're doing. They're able to access almost anything they want. Well, two points come to mind from that. One is that if this was not a centralized breach of the Verkada system and it led to breaches of internal security cameras themselves, meaning that if you breached Verkada you could then use Verkada as a roadmap to figure out where the other vulnerable cameras were. Most of these cameras, the way in which they work, are they're essentially web servers. They're just web servers. They're running some kind of stripped down version of Linux and Apache. Apache is a web server software that runs on Linux open source software. If you're able to compromise some of these security cameras, what you have in effect is a compromised Linux system on somebody's network, which means that once you have a compromised Linux system on somebody's network and you have super user privileges, you're able to go in as root. You're able to install some really interesting nasty packages. It's pretty much game over. You can do a hell of a lot of damage from a security camera. I think the hackers here did the right thing in releasing this information to the public so that we can begin to recover from it. The second point here that I wanted to make, which is quite interesting, is if you think about the backlash over the last year or so against facial recognition, all of those cities and local municipalities that have banned facial recognition and dragnet surveillance were probably spared from this particular breach. Just something to think about. Go ahead, Rob. And something else to think about talking about this is Donk Enby on Twitter. Well known hacker has noted earlier today that the command, if you happen to be in a root shell on a Verkada security camera, the command kill dash nine dollar sign dollar sign will exit your root shell without saving the batch history. And that will fool even Cloudflare's security response team. So there is fun stuff going on with those things, but yeah, it was a massive hole left open that didn't have to be. Okay, moving on, because we still have more stories to get to. A security breach of a different sort, a fire at a French cloud services firm has disrupted millions of websites, knocking out government agencies' portals, banks, shops, news websites, and taking out a chunk of the .fr web space. Yeah, the fire broke out earlier today at OVH Cloud, destroyed one of four data centers in Strasbourg in eastern France and damaged another. There was no immediate explanation provided for the blaze, which erupted just two days after the French cloud computing firm kicked off plans for an initial public offering. Europe's largest cloud services provider told clients, including the French government, the Centre Pompidou, that's a cool building by the way, and cryptocurrency exchange Deribit to activate their disaster recovery plans following the blaze. Here's the thing, a lot of people didn't have disaster recovery plans. A lot of people had everything just stored in that data center and now it's gone. So if you don't have a security plan for when your cloud provider disappears, you're going to be facing some hard times if something like this happens. Because yeah, this is a fairly low-tech attack, fire, but it does happen and it can happen to any building, any service. With regard to plans, we were talking earlier about this email thing. Have another way to communicate, okay? Because if you have that type of server right now, you're taking a little vacation from that. You're taking it out. It's going to go sit on the back porch and cool down. You'll put it back in and turn it back on later and they're making forensic copies of everything now. Not the French. They're not cooling down. Those are not coming back up. And then you're going to start up with some patched email servers and everybody's going to slowly come back to that. That's what's going on because it's ongoing. Same thing with a fire. You have a disaster recovery plan. You have to come back online slowly, but you have to have back channels and other ways to communicate with your team, with your staff, with your clients and customers, all of that, or family, whatever your vital systems, whatever kinds of things you're storing in this way. When realities of technology, maybe the Bitcoin mining farm next door caught on fire or whatever, yeah, you then have a problem in your digital neighborhood and have to have other ways, other forms of technology, other types of communication that you have those lists, that stuff in advance so that you can fall back on them as an alternative. I certainly hope OVHcloud had their own disaster recovery system in place where everything is stored in a different site someplace else that they can basically retrieve after all the paperwork is filled out. In addition to that, it's on all of us as users to keep our own backups because you never know when you'll lose all connectivity or something will just disappear, a company goes bankrupt, or there's court orders against them. Who knows? There's all sorts of things, but this is something that I guess a lot of people didn't see coming. It is unusual. Alex? As someone who's drafted many disaster recovery plans myself, I would say it's one thing to have what looks like a great plan on paper for your particular department, but it's another thing to test it, and it's only when you test your disaster recovery plans, when you make sure that your systems can fail over, do you see whether or not you actually have that redundancy that you intended to design into the system in place because you may have redundant backups in place, but they may be with OVH, or they may be with a single provider. You really need to try to take out of the equation certain components of whatever the disaster is affecting and make sure your disaster recovery plan can still operate. Testing I think is as important as drafting, and then another problem that I see with disaster recovery plans is that they're done a bit in a vacuum. You look at your department, but you may not look at other departments. Other departments may have data on which your department relies and have completely inadequate or woefully insufficient disaster recovery plans. You have to look at this holistically. You have to test it. You have to make sure that certain things can fail over. Really important. Yeah. What you say about testing I think is very important. Pretend that there is a disaster. Pretend that you lose access to a key machine or your connection goes out. How do you recover from that? Do you have a backup? Where is that backup? Since the 90s, I think we've been trying to hammer this point home. If you keep a backup, say for a local machine, something in your house, you don't keep the backup on top of that machine. You don't keep it even in the same house because your house burns down. You lose everything. That's what happens. So many people make that mistake, and so many companies make similar mistakes. I think we keep seeing this reinforced over and over again, how to maintain good security, how to plan for that day when something is no longer there. Because that day will come. Every hard drive will fail. That is just a fact of life. I guess no one wants to debate that point. Okay. No one wants to defend hard drives? Okay. Well, our last story for tonight. Do you remember we did a show last week, and we were talking about this service called Gab and how they got hacked? They got hacked again! Yes. A beleaguered social networking site Gab was breached on Monday, marking the second time in as many weeks that hackers have gained unauthorized access to a platform that caters to users pushing hate speech and pro-Trump conspiracy theories. The compromise came to light after someone hijacked the account of Gab founder and CEO Andrew Torba and left a post criticizing him for not paying an eight bitcoin ransom for the safe return of documents used to verify the identity of some users. First of all, I think that's the right thing, is not to pay people who are basically threatening you. That's like 400 grand. It's a lot of money. Two eight bitcoin is a lot of money. But that's the extent of which I'm going to defend their actions. The letter itself was kind of interesting. Let's see. Where does it begin? Wait a minute. Who is the ransom for again? Well, it came from someone named Captain Jack Sparrow. We mentioned this last week, which is a reference to the Pirates of the Caribbean character, Captain Jack Sparrow. Verified accounts on Gab were apparently compromised with a message from the hacker posted on their feeds. Dear Andrew, meaning Andrew Torba, one message apparently read referencing the CEO of Gab. If you value transparency so much, why do you keep lying to your despicable users? This website has been fully compromised last week. Thirty five million public posts and three million private posts. Fifty thousand emails, seven thousand passwords, eight hundred and thirty one verification documents. That's a reference to the Gab leaks hack, which saw more than 70 gigabytes of data taken from the social media site. Gab users, your leaked verification documents are not even worth eight bitcoins to them. They do not care about you or their 18000 pro users. Don't worry about it. Well, you know, at this point, I would just say that if you are a Gab user, your information really isn't worth anything anymore, because it's not going to it's not going to remain private. It already is out there. And you have a better chance of getting it on the dark web than you do on Gab, because I don't think they have a handle on their on their on their service at all. Anybody anybody surprised by this? Kyle, are you surprised? Just keep watching what they say, I guess, as a user. I'm not sure if your customer service, you know, your responses are going to come back. I don't know what you would be saying as a customer now. I don't know, Alex, you know, what one benefit of this to Gab users could potentially be if they lose their ID or, you know, if they're in a pinch somewhere, they need a copy of their driver's license, something like that, you know, they can they can just hop onto the dark web and and buy it. It's all there. It's all there. It gives you a backup. The dark web. How about that? So, yeah, the attacker who stole data from Gab harvested. How do you say this? Zero off to our off to bearer tokens. It's not usually part of our day to day speak during their initial attack toward the road through their ability to harvest the ability to harvest new tokens was patched. We did not clear all tokens related to the original attack. By reusing these old tokens, the attacker was able to post one hundred and seventy seven statuses in an eight minute eight minute period today. Gab's failure to purge bearer tokens may have stemmed from unfamiliarity with the open source mastodon code the site runs or an unwillingness to require users to go through the hassle of resetting their bearer tokens. The theft of the tokens came as a surprise to many because they weren't included in a trove of hacked Gab data posted by the Wikileaks style site Distributed Denial Secrets following the breach. I think it's what's noteworthy here is that they never knew this data was obtained, at least not based on their reporting, said Troy Hunt, owner of the breach notification service Have I Been Boned, referring to this notification that Gab posted on Saturday. Hunt said he was also surprised that Gab has yet to enforce a mandatory password reset for all users. Breach resets are standard practice after sites experience breaches that compromise user data. You know, just looking at stories like this and seeing how they just keep getting into trouble doesn't seem like they're in the right line of work. You know, you have to take security seriously. They're in over their heads. I feel sorry for them. And for me to feel sorry for something like Gab, I know you're shaking your head, Kyle. It's wrong to feel sorry. But I do. It feels like no matter what they do, they're going to do it wrong. Well, their mishandling of it affects a lot of people, and they're not actually looking out for them. And that goes for exchange, you know, email or whatever the case. There's businesses or institutions, patients. They're all affected when their information is swept up in an institution or corporate leak. And that's something we cannot forget in the midst of however one or the other entity flounders in their handling of it. Absolutely. Hey, we're out of time. We're going to continue this conversation on Overtime at 8 o'clock, Channel 2600 on YouTube. Follow the link on 2600.com at the top of the page, and you can participate. You can call us, 802-321-HACK, 802-321-4225. We're off next week, back in two weeks for Off the Hook on WBAI. Thank you for listening. All kinds of amazing material on this radio station. And we will see you soon. Goodnight. Bye. Bye. Bye. Bye. Bye. Bye. You're tuned to Pacifica Radio, WBAI New York, and what follows is a message from Pacifica Radio's National Election Supervisor. A proposed new set of bylaws is available for member review at Pacifica.org. And here we are on Overtime. Welcome to everybody. Emanuel here, Kyle, and Rob Gila, I see you over there. There's Alex. We are here. Yo! All right. I think everything went smoothly. Okay. Now, just this slight admonition. We want people to call us. That's the reason we do Off the Hook Overtime. And we have to struggle to get phone calls. So, please, give us a call at 802-321-4225. I mean, you don't want to just hear us talking more. We want to go back and forth. Tell us about your vaccination experience, or your experience trying to get an appointment, or your backup strategies that you believe in. Whatever it is, to participate like we used to when there wasn't a pandemic, and we went to the radio station, and we took phone calls live on the air constantly. We want to do that again. We will do that again. But this is the best we have right now. So, for us to continue doing Overtime, we would like to get people participating. 802-321-4225. And, Alex, you're not even in the room. It's not exactly a ringing endorsement of what I'm saying here when you walk away. There he is. He's back. I'm here. I'm just dealing with a wood-burning stove simultaneously, but I'm listening. Why would you be doing that during a radio show? We just did a story about a whole data center burning down. That's a good point, yeah. Trust me, that thought didn't cross my mind. Were you burning Ethernet cables? That's right. They let off a really pleasant smell. By the way, Rob, can you verify that we are, in fact, on YouTube? Because sometimes we forget to hit a button, and things don't work. We are, indeed. We are on YouTube. We are hearable, and we are waiting for those phone calls. All right. We are waiting for the phone calls. 802-321-4225. 802-321-HACK is our telephone number. So, folks, we had to cut the gab conversation short a little bit. So, did anybody have any further points they wanted to make? I mean, just the fact that I have a few friends who run federated social media services on their own steam with their own admin skills. These are smaller sites, of course, but they just seem so much better at it than the seditionists and traitors in charge of gab. So, I've got to take my hat off to those people who are running their own mastodons or other federated services, or even just hosting their own little sites and forums and things, and doing a better job of it than the humane home of terrible people. Well, not to make excuses for white supremacists, which I try not to do, but they're busy. They're busy trying to take down democracy. They don't really have time to learn security and to run a social networking site effectively. So, my advice, hire someone else to do that for you, and if nobody will work for you, maybe look at what you're doing. Maybe that's the lesson here. Hey, we have a phone call? Okay, great. Let's take this phone call. Good evening. You're on Off the Hook Overtime. Hi. How are you doing? How are you doing? I wanted to tell you, since you asked, about getting my shot. Oh, I remember you called a few weeks ago, and we were walking you through the system, and now you got your shot. That's awesome. Well, it was quite a challenge. I was giving out my personal information to total strangers in the hopes that they could get me something. And then, finally, I got up one morning, and I was heading towards the bathroom, but I checked TurboVax, which we remember you did that program on TurboVax. Absolutely. And there was a huge number of Javits Center appointments, and that had been put on seven minutes before I checked. And I went to the first page, and I looked at the column that said how many slots were open, and I chose the time slot that had the largest number, like 45, because I had had problems before, which you remember my telling you about. Right. And I went through it as quickly as I could, and I said I didn't have insurance so that I wouldn't be asked my birth date again and be rejected because they didn't like my birth date, no matter how I formatted it. And once I had the appointment, I went back, and I did it again and said, yes, I do have insurance, and this is my insurance. And I got it the same day, same time slot, and, of course, I canceled the first one. I was about to ask. Make sure you cancel the one that you didn't go for. And I also canceled the one in late March and early April that other people tried to get for me, because the one I got, the dump came on Thursday, and the appointment was for Friday. Wow. The very next day. Amazing. That is awesome. But I also have to report that Thursday evening, it was Thursday morning that the dump came and I got my appointment. Thursday evening, a man was randomly attacked in Chinatown. A mentally ill person stabbed him in the back, and people were thinking that it was a hate crime. However, particularly because the guy who did it said, I did it because I didn't like the way he looked at me, and he said anti-Asian things. But the camera footage of the actual crime showed that he stabbed him in the back, and he never even saw his victim's face. So he didn't even know whether the person was Asian or not, let alone, you know, there was no looking at him and, you know, didn't like the way the person looked at him. The person never looked at him. How does this relate to your vaccination? A huge ma, the man who created TurboVax, was extremely upset at this happening to an Asian man in Chinatown, along with all the other anti-Asian hate, and felt that his family and friends were threatened, and he shut down TurboVax for 48 hours from Friday noon, no, Saturday noon to Monday noon, trying to publicize this and ask for action from allies. And I had gotten my appointment and my shot, but had the timing been just a tiny bit different, I would have been one of the people who was hurt by missing out. Absolutely. And it goes to what we were saying earlier about how stupidity can reign, and it's exactly that kind of a thing that can derail everyone's good efforts. Because what TurboVax is doing is an incredible service that has helped so many people, and for them to feel like they're being threatened, that's just unacceptable on so many levels. Well, I wanted to encourage you to give some airtime on Off the Hook, next chance you get. You're going to be off the next two weeks, did I hear? We're not going to be on, because we can't do radio on St. Patrick's Day, so we're not going to be on next week, but we will be on in two weeks. Well, in two weeks, I would like to encourage you to do a follow-up of your coverage of Yuma and TurboVax, to mention this. He has information at the top encouraging people to learn more about anti-Asian hate, and talking about this incident and his reaction to it. And I would like to encourage you to help fight against anti-Asian hate. Yeah, sounds like a great idea. And I think we should focus more time on what they are doing, their efforts. Now, TurboVax, correct me if I'm wrong, they basically, it's the New York metropolitan area, right? It doesn't go beyond that? Yeah, pretty much. I've got TurboVax, I still have the tab open on my computer, because it makes me feel good to be able to see that there are more appointments being put out there, even though I personally don't need them anymore, and I'd be willing to help other people. It's got Bronx, Long Island, Manhattan, Queens, here's one upstate, Westchester County Center upstate has got some, so it goes a little bit beyond. Well, it's amazing to see what has been accomplished in that period of time, and this is only one region, I'm sure there are other TurboVax type systems that exist in other parts of the country, we'd like to know more about that as well. What's going to happen though over the next few weeks, what we're told is that the vaccine is going to become more and more available. In fact, there might even be more of it than people will be registering for, and that will cause another problem, having to convince people to get the vaccine. People will say, oh, it's here, I don't have to worry about it right now. No, you do have to worry about it. The smart thing to do is to get vaccinated so that this thing goes away, and we can resume our normal lives. It's as simple as that. The problem, well, not the problem, a problem, is as more people become vaccinated and more vaccine becomes available, they're opening it up to more people, which means that people who have been having difficulty getting an appointment are now struggling further against more competition. Right. Well, the solution to that, obviously, is to have more sites available where people can get it, and also to expand the hours. I understand Javits now is 24 hours. You can get a vaccination at 3.30 in the morning, if that works for you. So, I know that doesn't work for everybody, but that definitely helps. There are people who are either their second or third shift, or they are just plain desperate. If you can get vaccinated and get your life saved at 3.30 in the morning, and you can get there, why wouldn't you? It's life or death. Absolutely. Hey, congratulations. What was the actual vaccine like when you got it? Did that go smoothly? Yeah, I barely felt the needle. I always ask people giving me vaccines to do the plungers slowly, so that my bodily fluids have plenty of time to get out of the way of the new stuff coming in. But it was a pain-free vaccination. I barely felt the needle coming in. The feeling of it was by no means, not even a tiny bit painful. And may I ask which vaccine did you get, if I can ask? I got Pfizer. Pfizer, yes! We're all getting Pfizer, Alex. You're the only Moderna around. At the Javits Center, you get Pfizer during the day, and you get Johnson & Johnson during the night. Okay. It's just a little friendly competition, that's all. I don't mean anything by it. We're not mocking you, Alex. But you are the only one that's different. Well, you know, I like to stand out. You certainly do. Caller, thank you so much. Congratulations on getting it. Make sure you go back in three weeks. Of course. I have a terrible problem to face. I'm supposed to... I'm playmastering. I'm probably the first and probably the last person ever who's going to try to do a Zoom play reading of Peer Gynt on Ibsen's birthday. And that's a massive undertaking. It's got like 87 rolls, and it's like five hours long. And it's scheduled for the day after my shot, my second shot. So if I get knocked out by the shot... It'll just be a different interpretation. Well, you know, it has been suggested to me I should maybe delay getting my shot. No, don't do that. Don't do that. Get the shot when you're supposed to get it, and everything else will fall into place. I hope so. As a theater guy myself, I just want to point out... I hope that I get some reaction. Go ahead. Go ahead, Rob. Sorry, as a theater guy myself, I just want to point out that you would not be the first person to get out there on the boards while suffering some sort of medical anomaly that affects your performance. But I'm sure you'll do wonderfully regardless. I'm playmastering, so I have to make sure everything goes smoothly. So if I'm entirely incapacitated, that would be a problem. Yeah, and then people realize how much you're needed. So it works either way. I have to do or die. Well, set yourself up as best you can so that you maximize the possibility of not having as... or having as little a response as possible. But also, you know, do what you're passionate about. Well, I want to have that response so I know it's working. Yeah, right. There you go. I'm liable to be one of the five percent that it doesn't actually... No, that's not... the amount of people that get the vaccine, that number goes down even more. It's a lot of math involved, but believe me, the disease will disappear and people will not get infected anymore if we reach herd immunity. That's the goal. Anyway, listen, thanks for updating us. Congratulations on getting the vaccination, and please keep us informed in future weeks. Thank you. Take care. And don't forget huge math. No. And the Asian hate stamping out. Absolutely not. Yes. Thanks for your call. And our phone number again is 802-321-4225. I'm glad she got the shot. I remember we were walking her through it a few weeks ago, and it just seemed like she was having a lot of difficulty registering on the site, but she did it. She did it. And boy, the help that people are giving to others, I think, is simply amazing. Specifically, can we give more information as to how the service she used and how people can access that? Yeah, TurboVax, as we've spoken about before, you can go to TurboVax.info, which has all the info on there, and you can also go to TurboVax on Twitter, which is T-U-R-B-O-V-A-X. And that is an example of people helping people, because this was an effort put together by an independent programmer who happened to be someone who was capable of setting something like this up. And the fact that the person who set this up then had to interrupt the service with news of what was going on in their community, it's heartbreaking. But it's also, I would say it's understandable, because when you've got that kind of platform and you need to get your feelings out there about it, that's something to do. But yeah, TurboVax.info. And it's what Gila and I used to get our appointments. I think it was actually the same info dump that we also registered for our vaccines. And it is just a running feed of appointments that open up throughout the New York metropolitan area, upstate, Long Island, all of that. And you can see minute by minute the appointments that are opening up near you. Clarify upstate, though. I don't think, like, upstate. Oh, upstate is an open question. But no, it actually, TurboVax made me tear up earlier today, because 33,000 appointments at the Javits Center opened up earlier today, and I burst into tears. Because this is actually happening. It is actually happening. It was an amazing moment. To me, the amazing moment was actually going there and just seeing hundreds of people all there for the same reason, and hundreds of other people helping them. It just felt like community. It felt like, you know, we're battling this thing, we're going to win, and we're going to be strong, and we're going to be supportive. And that's what people need to feel. The other thing that it really reminded me of, and, you know, had conversations about this with several people, is that with all the lines and all the regimentation and all the documentation, it seemed like the airport. But when we got married, Rob said that the Marriage Bureau was like the happy DMV, because it was, you know, bureaucracy and forms to fill out, but everybody was really happy to be there. So, in the same way, the Javits Center kind of felt like the happy airport, because everybody was standing in line and waiting to get this done, but everybody was really excited to be there. The happy airport. Can I just speak about the DMV, though, for a moment? The DMV and the pandemic, I don't know if this is just me, but they seem to get so much better. I mean, there's a local office that you can drop off forms, there are people who come outside, they answer all your questions, they're very pleasant, and then if there are any issues, you call a number, and you speak to a person, an actual human being. And I think I'm speaking to somebody in their home, who basically was bending over backwards to help to make sure that everything was okay. I've never had an experience like that at the real DMV. So, in a way, I think the pandemic might have humanized the Department of Motor Vehicles a little bit. Yeah, that's really interesting, because it's one of the many ways in which this pandemic has forced us all to rethink things that we just took as sort of necessary evils or necessary hassles in life. Like going to the DMV in the normal schleppy fashion, or going into the office five days a week for 40 hours when a lot of your job can be done effectively from home, sometimes all of your job for some people. And we're going to come out of this pandemic with a whole new understanding of how we could better be doing the routine things that we all have to do. Absolutely. Kyle? Yeah, it's not all the same, but there are probably attributes of working from home that people who work in places like the DMV maybe enjoy a little bit more. And to that end, perhaps, when they're on the clock, when they're helping customers really think about their job a little bit, take a little bit more pride in it because of the accommodation or at least a relative comfort. But I don't want to make that as a blanket statement, because I know that's not true. And nothing about virtual customer service or answering calls and managing home life can realistically, I think, be that much of a virtue. I don't want to sing its praises all over the place. It's more, though. It's more because I think people are seeing others as human beings. And when you talk to that person on the phone who's working for DMV, you see them as a person going through the same thing you're going through. And that's why you say stay safe to everybody these days on the phone in person, because we're looking out for each other. So you see the person who works at DMV as a human being facing the same challenges. And I'm hoping that when it's over, we keep that, we keep that basic human common ground that some of us might have found again. Go ahead, Alex. On that exact subject, I had an experience this morning. And I think it really speaks to this, because I think what we all have now is a sense of connectedness that we did not have a year ago at this point today. I mean, literally, on March 10th, a year ago, I think that as a species, we were way farther away from each other, metaphorically, of course, than we are today. I think there is this sense of being all part of the same ecosystem. And this morning, I'm out here in the Poconos and got out and take the dog out for a walk in the backyard and whatnot. And I heard for the first time this year, the geese flying overhead. I heard those honks, and I thought to myself, what the hell is that sound? And I haven't heard that in a while. And also for the first time, I saw a little bit of grass, a little bit of green peeking out from the massive amount of snow that we've had over the last two months. And I thought to myself, wow, it's here again. Spring is here. The earth is coming back to life. The geese are here. Things are coming back to the way they were, and it felt like this, wow, I can't believe how fast everything has gone. I can't believe that we're going to see the baby geese roaming around. I can't believe that it's all going to happen yet again. And now I think that there was this sense of me being so much more connected to the place where I am, the people that I'm around. And I did not have this last year or the year before, the year before that or the year before that. And so I think you're right. I think there is going to be a change of philosophy and a change of mentality across the board, not just in any country, but across the world. And I do hope that you're right, Emmanuel, that we can maintain and persist this as a shared burden that we all went through together through 2020 and 2021. Absolutely. And the thing that I think we also have to remember is that it's not over. It's still going on. Two thousand people a day are still dying. And while things are getting better, it doesn't necessarily mean that things are close to over. And it speaks to what we were saying before about stupidity. Texas today just reopened as if there is no such thing as a pandemic. You don't have to wear a mask. They put shopkeepers, bar owners, every merchant out there in a really bad place because the state no longer supports their saying, you have to wear a mask to come into my establishment. No, you're on your own if you say that. You're the one that's got to get into a fight with some idiot that doesn't believe in science. The state will not back you up. That is a horrible thing. You know, the governor of Texas, Abbott, needs to be called out on this by all of us. And I'm not seeing enough of a reaction. That is the kind of thing that is going to prolong this agony for so many. It's literally going to cost lives. Whereas if there's a reason why airplanes, people travel by airplane. How come you're not seeing outbreaks from people traveling in an airplane? It seems like the worst possible place to be during a pandemic. It's because mask mandates are in force. People wear the mask. And that makes a huge difference. It's been proven over and over again. Yeah, you don't like to wear a mask. Nobody does. But if it's that or death, I'll go with the mask. The mask is a better choice. And if we had all been wearing masks from the beginning, it would have ended a lot sooner. So, you know, let's stop being patient with these people. Stop saying, yeah, you've got your right to your opinion. No, no, you don't have the right to put all of us in danger because you're an idiot. I'm sorry, you just don't. First of all, Alex, we'll get to you in a second. Do we have another call? No, we don't. Why don't we have another call? That's on you, Kyle. You're handling the phone. Well, I don't have the number. That was your part. You received the phone call. Next time, you can give me the number and I'll be in charge of the number and the call. That's a lot. If you want Kyle to take the blame for this, folks, don't call. But if, you know, 802-321-4225 is the phone number. Just dial those numbers and talk to us. That's all we're asking. Go ahead, Alex. On the subject of Texas reopening, which I don't agree with practically, philosophically, ethically. I think it's a terrible thing. And I thought about this for a bit the other day. And one of the things that's reasonably foreseeable that could happen from Texas reopening is, number one, it compromises the entire world vaccine effort. Because it's a gigantic state without anybody wearing masks or any regard for normal precautions that we've all been taking for so very long. And if you don't keep your foot on the throat of this virus for an extended period of time, that's how it escapes. And number two, it could escape because it could conceivably create a variant of COVID itself. But my understanding is that the more COVID spreads from person to person, the more likely it is to mutate and create a dangerous variant. And how ridiculous would it be if a year or maybe even two years from now, there's the Texas variant or the San Antonio variant. We wanted to call it the China virus. Now, the next iteration of this could very well be the Fort Worth virus. Well, we didn't want to call it that. Certain people wanted to call it that. But what you say makes a lot of sense. I mean, so far, thankfully, all the variants are pretty much affected by the vaccine that we get. No variant has shown up yet that is not affected by that. But that could change. There could be a variant down the road that is immune from the vaccine. Imagine the horror of that. Now, that doesn't happen if the virus itself is wiped out. If there is no virus so that there is no variant of that virus, it doesn't happen. But if the virus is out there still because people aren't getting the vaccine or they're just ignoring science in various ways, then the chances of such a variant coming along are high, very high. And we could, regardless of having the vaccine, we could be going through this all over again. So we should be angry at these people. We should be really, really angry at these people for doing this. And because this is happening on the exact, you know, on the precipice of herd immunity. It's the worst possible time for something like this to be going on in an entire state, especially a state the size of Texas. Are you in Texas? Listeners, are you in Texas? If you are in Texas, please call us. We want to know what's going on out there. 802-321-4225, 802-321-HAC. Or if you're in a state that is, you know, is run by dumbasses that don't believe in science, we want to know how that's affecting your life. And we'll give you a few minutes and then we're going to sign off if we don't get any more calls. Or if you have an exchange server and you're having a very long, deep conversation with your server. That too. Yeah, we're going to talk about that some more. And debating removing it, or maybe it's already removed. And, you know, you're contemplating the future of email in your organization. Tell us about that. Yeah, yeah, we'd like to know. Do we know anybody who's running Exchange? Do we run Exchange? Wow. Okay, I think we got a call. I'm sorry, Rob, did you have something? I can wait if we've got a call. We do have a call. Caller, go ahead, you're on, off the hook. Hi there, I just wanted to make mention on the mask mandate thing. That in the Texas region, the Texas Attorney General threatened to sue Austin officials if they don't lift the local mask mandate. Meaning businesses could be sued if they require their customers to use masks. I believe that's fairly insane. That is insane. It's passing the buck. You know, this is how you keep a virus around, in my opinion. And, you know, you have to wonder, do they want the virus to stay around? Is there some reason? It just, it goes counter to all your instincts. I think it's just simply that there's too many people that, you know, this whole mask thing, it gets whipped up into, oh, you're stepping on my rights versus, you know, your right not to be infected. And once it got to that point, some people treat it as, oh, it's my choice. I don't agree with that. I tend to believe the science. And it's not just their choice. They're choosing for other people as well. Everybody that comes into contact with them, they are in danger. What gets me is you see all these outraged people in New York saying, how dare you tell me that I have to, you know, have my shop under restrictions. You know, the same mentality. But you see more of a reaction against authorities who are trying to do the right thing. And out there in Texas, I'm not seeing mass demonstrations. Of course, it probably wouldn't be safe to have a mass demonstration. But, you know what I mean? It's almost like a different world. It is almost like a different world. I think people need to be a lot louder, a lot more offensive as far as standing up to this nonsense. You know, but quite honestly, don't you think it's just common sense? Yep. I think humor goes a long way. Yeah. There will be some great ridicule. I mean, businesses that have opened and had to deal with customers and being confrontational, they tend to reiterate their policy as many times as it takes to keep their business open and safe. So, hopefully, there's that kind of statement. How can we in New York help those companies, businesses in Texas that are fighting to stay safe and being thwarted by their own government? If there's any way we can help here in New York. It's spiking the ball on the 10-yard line and saying, oh, touchdown. It's like, no, we've got to keep going. That's an analogy they might actually get. Rob, did you have something? Yeah. I mean, of course, the other story around this was that there was a Mexican owned restaurant in Texas that decided to keep a mask requirement in place after Texas had dropped the requirement. And in return, people started threatening to call ICE and things like that on them. Because as we're seeing now, this pandemic, it has so much ability to bring out the best in people. It also, unfortunately, is bringing out the worst in some people. Wow. Any other? Go ahead, Alex. And the idea of penalizing small businesses in Texas who would require masks when ostensibly this is a Republican pro-government, pro-economy, we want to support business. And that's the whole reason we're ending a mask mandate and ending lockdown is for the sake of the economy. So to destroy small businesses in the name of the economy is just completely insane. It makes zero sense whatsoever from a policy standpoint, from an enforcement standpoint. And moreover, the very idea that our response or attitude to a pandemic should be dictated by our politics, whether we're right or left, is just so insane and such a horrible sign of the times. And the echo chamber in which we live in 2021. I'm done. I'm going to drop off, let somebody else call in. Okay, thanks. Go ahead, Kyle. It just occurred to me, it's an old play, right? It's the old narrative, the old playbook, and not actually what is being promoted and talked about as far as unity now and getting past this so that we can have normal economic activity. But it's that old narrative that they want to cling to, to show this allegiance and kind of wield the specter of the return and doom and what we're supposed to be afraid of. It's so misdirected. I mean, Fauci is a Republican, isn't he? If people respect the science, I don't care about their politics. When I see people walking down the street, they're wearing a mask. I support them and I feel proud of them, regardless of who they vote for. It's got nothing to do with that. I don't see how people ever go down this road in the first place. Go ahead, Rob. While we're waiting for another call at 802-321-4225, that's 802-321-HAC. I just want to give a little shout this past Saturday. Lou Ottens, the Dutch engineer who we audio engineers know was the inventor of the audio cassette, passed away. But he was at the ripe old age of 94. And you can't say that wasn't a good run. You know, when I was a kid, I think 10 years old was when I got my first tape recorder. And that sort of started me off on archiving things. I'd walk around, I'd record relatives at family gatherings. And there would always be these little compact cassettes that came out. They all looked different, but they all had that logo on them. And it was magic to me. It was magic. On my 10th birthday, I demanded a tape recorder. That's what I wanted. And I just became a madman with it. Everybody would say, turn that thing off. Don't record me. And always, years down the road, they were the ones that wanted to hear what they said. Anybody out there that wants to archive something, it's the best thing you can do. No matter what it is you're archiving, save it. Hold on to it. Because guaranteed, nobody else is going to do it, and you'll be the one with the history. And you can share that. You sound like an advertisement for the National Security Agency right now. How? How in the world is that NSA material? You may want to hear what you said. A 10-year-old walking around with a cassette recorder. That's NSA material in your world. Sounds like a budding director of the NSA. I'm not talking about recording other people's conversations. I'm not talking about climbing telephone poles. I'm talking about walking around, recording your interactions. And there are many ways you can do that. Email, YouTube, video, audio, all kinds of radio. What we do. By saving it all, you can go back to it. You can learn from it. You can hear the differences. NSA. Good God. Yes, Gayla, go ahead. You also get the family history, right? My grandfather was an inveterate cassette recorder. And there are pictures of him recording baby me and baby my little brother while we were infants, just lying on a blanket. And grandpa is holding out the microphone to us. And there are just tapes of us babbling as babies. There's a tape of me and my grandparents. I was two, having breakfast. And it's just this incredible recording of just a very mundane morning. But we have this, excuse me, we have this history because of this little cassette recorder that my grandfather always carried around. Your grandfather knew. He knew the importance of this. And while so few people get that, and many are annoyed by it, it does matter. Saving things. And you can say everything is digital, everything is saved. It's not true. It's not true. Things get erased. Things are unable to be accessed. Remember how long it took us to get our own voicemail recordings to play back? Thankfully, our listeners were able to help us with that. But it can be very difficult. And you can lose things digitally. Books, photo albums, they tend to stick around a lot longer than your digital collections. And it's not because the technology is faulty. It's because we don't follow through and we don't protect them nearly enough. It's very easy to get overwhelmed. Go ahead, Kyle. I can relate with people not wanting to have you photograph them. I hear that in your story a lot. And I think that's part of what makes capturing that stuff and creating something, composing an audio recording or something like that, it makes it work. It's worthwhile, but it still takes setting up a little bit or thinking about what you're going to capture and how to get it and not mangle the thing in the process and have something worth looking back at. But the benefit is that you get this amazing time capsule of what was going on around you. The biggest argument against me recording people at family gatherings is that I was wasting tape. Because tape was a tangible thing. And I guess it was expensive. But it's a good thing I did waste that tape because I captured some real gems, some amazing moments. And I still have the tapes. I still have those cassettes. These are from the 1970s and they still work. Of course, I digitized everything since. And yeah, we should always combine the technologies. Take the analog, digitize it, but hold on to the analog. They still work. And I'm amazed by that. And the same thing for my video collection. I didn't subject my relatives to video cameras, but I did record a lot of things off television starting in the 80s. And unlike most people, I kept recording. I recorded the commercials as well. A lot of people turn the thing off when the commercials are on. They're the most interesting parts. Hearing or seeing car commercials from the mid-80s, there's so much there and so many other things, news breaks, you name it. So digitizing that is also important. Yeah, I'm a strong advocate of mixing, going back and forth from one format to the other so that you have the physical as well as a digital. And the real advantage, I think, and it is not often realized, is the ability to search through. It's great that your albums are a print negative or a print of some scene or video or an old reel of film, 8mm, 16mm, all that stuff stays, but it's very hard to look at quickly. But we have tablets, we have all these new modern ways to view things, and I think that's been really exciting that you can take stuff that's on the shelf somewhere, you know it's sort of in cold storage, but you can quickly flip through, reference the stuff, and then maybe in proxies and smaller resolution stuff, but then go get maybe a higher resolution copy and integrate, like Gila said, the sounds of cooing and kid talk, that could be integrated into new media that tells your family story. And there's all kinds of cool stuff going on with like changing, colorizing is an example, but wasn't there something recently where you can add motion to stills? Oh my god, I've seen that, I've seen that. Basically you take a still image, you take a still image, and all of a sudden you see that image moving, blinking, turning the head. I got to tell you, someone sent me a picture, and I knew right away what it was. It was the spookiest thing, that you've met with people that have passed away, and that you only have still images of them. Like Abraham Lincoln, for instance. Imagine seeing him start moving around and blinking and smiling. I don't know if I can handle that, but that's artificial, but it still is pretty fascinating. My point is, these different forms of media can all be components of a larger story that you're telling, and something that I think is important for memory too, like your own memory of things, how your family remembers things and memorializes things, and how you think of your story, even identity. These are all parts that we can pull out of a lot of this media that we've accrued in different formats. I just want to also point out that archiving, it is work, it's a part of the work of producing the media itself, but it can be very therapeutic. Absolutely. Looking at your history, looking at those commercials, maybe you've since earned a sociology degree, and you want to look at how ads shaped the way groups of people behaved over the years. Whatever, it's fascinating stuff. Going back, it can be edifying, but it can also be cathartic. That creative thing of sitting with your own history, it's kind of daunting and a lot, as they say, but it could also be this enormous source of inspiration and creativity, and as I said, building new art and memory. I want to make my video collection available for people to scan through. I have a couple of thousand tapes, and each one is between six and eight hours long, because I always use the slowest speed. The problem is, when you try to upload that to YouTube, it immediately gets flagged, because, my God, Google doesn't want you having this musical note that somebody is going to pirate, apparently, from a tape that's 40 years old. Probably through Internet Archive, a way that this can be shared, and people can go through it and say, hey, this commercial is this, this is that actor when he was nobody, et cetera, et cetera. There's no way one person can do all that. A group effort, crowdsourcing would definitely come up with some historic relics that I think would be quite fascinating. We can't get caught up in copyright issues, though, and all these restrictions that we're really good at imposing on ourselves. Just having this, I guess, evidence of something in history that occurred that we were witness to, being able to share that and add our own to what it is that is actually there. That's a valuable thing. I want to be able to do that. Hang on, Alex. Let me just grab the phone number one more time, and we're going to stay on for a couple of minutes until we don't get a call. Then we're going to sign off. 802-321-4225. 802-321-HACK is our phone number. We're on for a couple more minutes here on Overtime, and hopefully we'll get a call from any of mine. Anything? Alex, I think you're muted. Oh, I'm sorry. Yeah, there we are. I was about to say that I would love to see a way for that to be shared. On the one hand, sometimes not all copyright claims are illegitimate, but when it gets in the way of this kind of archiving, and I think that there should be a reasonable way for you to get a huge amount of liability. Perhaps there's some kind of time carved out or something that should be made to the Digital Millennium Copyright Act. Going back to what you were mentioning before, and Kyle was mentioning, which is this notion of the digitalization of these memories. Emmanuel, I think you said that you had inadvertently filmed a whole bunch of gems during all of this filming that you were doing. A tape recorder. Or audio tapes, whatever you were filming, without people's consent. Hold on a second. Let's be clear. The audio recordings were of relatives at family gatherings, and no, I didn't go around and get written consent from my grandfather. It's pretty innocent. The video recording was on television, commercial TV, and non-commercial TV. Over the air. Over the air, and a lot of it is over the air, and you see static and things like that, which I find interesting, too. You see car ignition static. Who sees that anymore? I have station breaks of WNEW TV. That's Channel 5, before they became WNYW, before they became Fox. Things like that, and I feel like it should be a really large, either really small or really large coordinated effort. It has to be. Another thing that comes to mind is some of the institutions like communications museums and media museums, there's one I know in Chicago and all over, at different institutions, I'm sure universities as well, as well as non-profits that just are interested in communications, and I think there's certainly, I don't know, just the over the air aspect alone, that's probably a whole area of research for all we know. Absolutely. It's really critical that it's curated in a way that's accessible, that people can really dig into it. But again, the quality is not perfect, and a lot of institutions demand perfect quality, and you're not going to get that. It's taped at the slowest speed, but it's worth waiting. I would say, much like yourself, Emanuel, with your filming without consent, the NSA also captured a whole bunch of jobs. I am going to drive out there to Pennsylvania and tell you in person that I am not the NSA. They're digitized too. You can get them with a FOIA request. We have a phone call. This is a good time to go to the phones. Hi. I had a totally different question to ask. Are you the first caller calling back again? That's the third caller? Yes. Okay. Well, boy, it makes us sound like we don't have any listeners, but okay, go ahead. Make your point, but make it quick. Okay. Well, you've got 29 people watching now, so it says. Is that all? I thought we had thousands of people watching, but there was this article. They released someone from Rikers by mistake. He's accused of having committed murder, but, of course, he's not been tried yet, so we don't know whether or not he'll be convicted. He has not been convicted. Something else, he had gotten 30 days, and it was wiped off as time served. They released him by mistake, and he has prudently made himself scarce. Is there anything wrong with a person who hasn't been convicted of anything, who has been released, even if mistakenly, been released? They let him go with their just trying to go where they won't be found. Well, it sounds like a lot of the Capitol Riot people might agree with that sentiment. I'm not going to comment on this. I mean, someone released by accident probably shouldn't be released. I'm sorry? Yeah, Alex is a lawyer. I'm not sure if you want to take up this case, but go ahead, Alex. Look, on the one hand, I can see on the equities, hey, he was released. He can go, but he made a mistake, right? And I think as Matt pointed out, releasing somebody by mistake, well, that might be something you should be able to reel back in. But also, OK, let's say he's released. They made a mistake. Maybe he should get the benefit of that mistake. But only until he is supposed to be tried, he would still have to return to trial, right? I mean, otherwise, if you're released pending trial, you're released on your own and you still have to show up to be tried. So I don't think he could or should rather be able to benefit from that mistake to the degree of never having to face trial again. He's going to show up just like anybody else. Yeah. What was the crime that he's accused of? Murder. Oh, well, yeah, you know, that's kind of a biggie. I think maybe they should take a good look at whether or not they really want him walking around outside. Make sure they're showing of him for people to say if they've spotted him, show him with what looks like a really nasty injury on the side of his face. And so I'm wondering how did it get there? He's been in prison for he was in prison for I think you're answering your own question by saying he's been in prison for bad things happen in prison. Absolutely. There's no question about that. That's a whole other issue. Anyway, listen, thanks for bringing that to our attention. Let's make room for another caller if they're out there or if our listenership is plummeting even further. Our phone number 802-321-4225. That's area code 802 exchange 321 extension 4225. 802-321-HACK. Go ahead, Rob. Yeah, I mean, this reminds me of there was a recent case and I don't remember who it was, unfortunately, but there were people who should have been released from jail being kept in jail because of a similar glitch. It just worked in the other direction. And one has to wonder, like, in which direction should these things fail? Do we want to risk having people who shouldn't be in jail locked up? Or do we want to risk having people who should not be in jail? Rather, I'm botching what I'm trying to say here. But like, what's worse, having an innocent person behind bars or having a guilty person out in society? And this is a complicated question. Well, for me, it's a very easy question. I think having innocent people locked up is far worse than having a guilty person out. Because a guilty person is, you know, you can always catch the guilty person, but what do you do for an innocent person who's lost years of their lives or even months of their lives? You know, there's no way to give that back. And yeah, you could be more at risk with guilty people walking around if you assume that every guilty person is guilty. It's very simplistic. And I think, you know, it's far more dangerous for us to just accept innocent people being locked away than being, you know, missing a couple of people who should be penalized. Alex, I think you had something to say on that? Oh, I was going to say I entirely agree with that. I think, you know, maybe only Kim Jong-un would disagree with those kinds of people. I don't know why Kim Jong-un is the only one that people bring up. Almost any leader, I think, you know, is guilty of the same things. Maybe not to that extent, but, yeah. Yeah, look, yeah, perhaps. All right, we're going to give it another minute or so. It's getting kind of late anyway. We've been on almost a full hour, which is pretty long. And if no one else wants to call in, that's fine. There's no guilt or anything like that. I would like to see more people call. I'd like to see more people online as well. Maybe we should spread the word more somehow. It's our phone number, and that's the last time I'm going to say that. The final rule... That is why we do this. Oh, I had a non sequitur. I'm sorry. Go ahead with your non sequitur. Oh, no, I was just going to say the final rule for domestic hemp production goes into effect. This is the USDA's Agriculture Domestic Production of Hemp program, and it goes into effect March 22nd. So, yeah. This country makes hemp now. Well, that's good news. It's also, as you said, a non sequitur, and we could talk for hours about that. I will talk about Outlook some more. I know you will. I will. But, I think we're almost at the end of our energy level here. Or we didn't talk about the media using the word hacker. No, we didn't. We could talk about that, but we've been talking about that for, what, 30 years now. Yeah, it seemed a little weird for us to be covering that since we cover it all the time, and nobody really asked our thoughts on it. I guess we've made them clear. Yes, we have made them clear. There's no need to ask our thoughts. Okay, you know what? The time has come. We will not be taking phone calls at this point. We're going to sign off, and we're not going to be on next week. We're preempted, and we'll be back in two weeks, both for Overtime and for Off the Hook. Any last words from anybody out there? Meaning you people. Just keep applying and get your vaccines. Yes, get your damn vaccines. Seriously. If you need advice or help, you can write to us, othat2600.com. We can give you some tips on ways to get through the system, but it should start getting a lot easier. These vaccines are showing up. I think we're really turning a corner. Just be sure to urge everyone in your life to take this seriously, to get a vaccine, to not go against what science has proven, and to protect those people who might be in parts of the country or the world that are vulnerable because their leadership doesn't believe in science. If you look back in history, that has been how civilizations have fallen over the years, people doing stupid things. Let's hope we get through this. All right. That's going to do it for us tonight. For Rob and Gila and Alex and Kyle, this is Emmanuel signing off. We will see you in two weeks. Good night. Good night.