and to advocate for the release of Julian Assange. non-commercial, locally controlled WBAI New York. with Richard Wolff heard Wednesdays after the WBAI Stay tuned for Off The Hook. It is now one minute past 7 p.m. And you're listening to radio station WBAI New York. It is time for Off The Hook. The telephone keeps ringing, so I ripped it off the wall I cut myself while shaving, now I can't make a cut I couldn't get my dress, but if they could they would A lily bulb for the best, it's fake for worst I hope that's understood, my lily bulb Off The Hook Off The Hook Yeah, what? I'm in a car, that's right. I'm in route to Pennsylvania. My garage company in New York really screwed me today by delaying getting my car out a half an hour in a rush hour for about every one minute you delay getting on the road that equals another five or ten minutes on the road so yeah, coming to you from the car. Why do you need a company to get your car out of a garage? I can do that myself. Well, it would be very difficult because this is a garage that I use where it's actually a big building in the West Village that's converted You know what? We don't have time for this. I'm sorry. Maybe on overtime we can talk about your garage but we have a limited amount of time. As people know, we were not on last week. It was a mistake and we're not going to talk about it because we're going to spend all this time talking about the fact that we weren't on the air. It's a waste of time. Sometimes people make mistakes and we're just going to live with that and move on. What WBAI is doing for us in exchange for that mistake is unpreempting us for next week. We weren't going to be on next week but guess what? We are going to be on next week so yeah, all is well that ends well. Well, not really quite like that but it's okay. I wasn't really in the best of moods anyway last week because I had just come out of a medical procedure and I was recovering from that. I'm still recovering from that but we still have a lot of things to talk about. Something happened to us two weeks ago that I think we should not forget about because that was a true injustice. Somebody reported our show, our overtime show. That's the one that follows this one on YouTube. Apparently somebody reported it. We were talking about the importance of getting a vaccine and not listening to people who are spouting nonsense and spreading fear. Someone reported it as us spreading medical misinformation and YouTube took the show down. They sent us this notice saying that, yes, YouTube has removed your video. Here is what you can do. The thing that you really can't do is talk to a person because they don't really have any of those. But basically they said, Hi, Channel 2600. Our team has reviewed your content and unfortunately we think it violates our medical misinformation policy. We've removed the following content from YouTube. Folks, this is why you do things yourself. This is why you don't rely on a big company like Google to decide things for you because when you do that and when you have artificial intelligence making the decisions, the decisions are wrong lots and lots of times. This was simply unbelievable to all of us. We, of course, talked about it on social media and people were outraged. It didn't last very long because we forwarded a very strongly worded appeal to whatever bot handles that. A couple of hours later we got an email, Channel 2600, we've reached a decision on your appeal. After taking another look, we can confirm that your content does not violate our community guidelines. Thanks for your patience while we reviewed this appeal. Our goal is to make sure content doesn't violate our community guidelines so that YouTube can be a safe place for all. And sometimes we make mistakes trying to get it right. We're sorry for any frustration our mistake caused you and we appreciate you letting us know. Okay, you know, I like apologies, even when they come from computers. But I think there's a bigger problem here. The problem is that this can be done so easily. In fact, I'm going to ask whoever did this last time to do it again this week. Let's see how easy it is. Do it every damn week. Report us for spreading medical misinformation by telling people that it's important to get a vaccine against COVID-19. You know, Rob, what do you think about this? Is this how it works? Is this how all these massively complex systems are set up that all somebody has to do is simply say something is true and they will act as if it is until somebody says otherwise? Well, that's always the way it goes with systems like YouTube where it's not humans handling the complaints, at least not on the first, you know, line of defense. It's computers. And it's been shown time and again that if you report something enough, whether or not that report is legitimate, it will get taken down. People have used this as a harassment tool to all sorts of people. All sorts of innocent people have found their videos taken down, demonetized. If they're making a living off of things, that can make things especially rough. And it's actually unusual, I think, for sense to prevail and these things to get appealed properly and reviewed properly by a person. So we're kind of lucky in that respect. Well, if you know how to phrase an angry sentence, that helps. If you have the weight of a radio station in back of you, that helps. If you have the hacker community speaking up for you, that certainly helps. But yes, you're right. There are many instances, we've talked about it on this very show, where common sense does not prevail. And there are certain topics that if you run afoul of, you can find yourself having your video turned off. And we don't care about the monetization. We don't do that. But a lot of people do, as you mentioned. It still runs ads, though. Yeah, it does. Wait, what? Unless they're premium customers. So wait, you mean even though we don't get anything out of it, people have to see ads when they watch our videos? I believe so. And then if you're using a web browser, I think it would depend on if you have a blocker of some kind. See, we do this just because it's convenient, not because we endorse it. Anyway, the other topics that you could run afoul of, harmful or dangerous content policies, violent or graphic content policies. I'm sorry, I'm reading their policies, but these are the topics that they have policies about. Violent criminal organizations, hate speech, harassment and cyberbullying, and the one that we were accused of, COVID-19 medical misinformation. So, yeah, that's really incredible that we spend time. And this was on the other show. This wasn't on WBAI. We talked about it a little bit, but because WBAI is a free speech radio station, nobody can turn us off. Sometimes people try to turn us off. As you might recall, that happened a while back. But people power. People power works in the end, and that's why it's so important. Let me just say for a second, too, that's why it's important that you keep this place alive, because if it's not here, then we're stuck on YouTube. Then we're stuck with Google. They're the ones making the decision, and we don't have any power. You, the listener, you have power. You can vote. You have the important bylaws elections that are happening right now to determine the future of the station. Yeah, and all sorts of other things as well. But that only happens if you continue to support the place. 212-209-2950 is a phone number. Call up. Pledge whatever you can, but keep WBAI on the air. And for us to get preempted with no notice last week by accident and come back on the air this week and say support this place, you know it's got to mean something. You know it has to mean something to us. So anyway, yeah, we did battle with Google, and I guess we prevailed on that. But again, I want to see if it's that easy. I want to see if every single week somebody can simply say, hey, they're spreading medical misinformation when all we're doing is telling the facts about the importance of a vaccine and the dangers of a virus. And if that is the case, well, then we have an interesting story, I think. Rob? And I think it's also important to point out that we're not depending on Google. We're not depending on YouTube. You can always get a hold of our show over the air, 99.5 FM. You can listen to this program. You can always find Off the Hook Overtime on our page, on our own chunk of the internet which we control, which is at 2600.com slash offthehook. There is archives of this program, and there is archives of the audio from Off the Hook Overtime there as well. It's also important to point out that, as you said, when they took that video, and when we say video, it's really just one picture that has audio. This is our way of getting audio out on YouTube. When they took that video down, they didn't take it down from our site because they can't control our site. We control our site. So it was always there. It was always around. It's just that particular outlet had been shut off. And really we only use that outlet for the live aspect of it so that we can take phone calls and that we can broadcast to a lot of people. And it wasn't turned off then. And that's kind of weird, too. I guess they can't turn it off if it's live. If we're spouting medical malpractice or misinformation, they can't turn it off. Here's another challenge for you idiots out there who want to shut down free speech and spread misinformation. See if you can turn us off live. Alex, I can see you're moving in your car. You're driving, but you seem to have stopped. What's going on? I did, actually. I have arrived at my destination. Oh, how exciting. Yeah, it is very exciting. It's wonderful. Thank God, you know. But I think, was this the first time I was driving during this past year? There may have been one other instance. It looked cool. Yeah, it looked really cool. Unfortunately, nobody else could appreciate it, but it looked cool to see you just moving on the screen. I bet. It would have been pretty neat, right? If only these things were video, I bet. And, of course, because of radio, we could be lying. None of this could be happening. We could all be in the studio, but we're not. That's absolutely correct. That's absolutely correct. So did you have anything to add to this conversation? Alex? Okay. To be clear, to balance it out a little bit. Maybe get a little closer to your hotspot in your house there. There was a very short period. Can you run to your hotspot, please? Yeah, you know what? Because right now all I see is your eye. Let me get in the house. All I see is your eye, and I can barely hear what you're saying. Okay. Are you inside? I'll be back. You'll be back. Okay. Well, then let's give this update right now on a couple other things that happened over the past couple of weeks. We announced that our HOPE Conference, which was scheduled for this August at St. John's University in Queens, will not be happening after all this year. We'll be doing it next year, but we just figured, despite the fact that everything is really progressing nicely, New York has just opened up again, and we're getting back to normal, we didn't want to make it any more stressful for people. We didn't want to add another task on top of everything else that we've got to put back together. And having a conference is great, but let's get our lives back. Let's have a little fun. Let's enjoy ourselves, and we'll make the best damn conference ever next year. This conference was only going to happen if everything was back to normal, and we were going to make up for the one that we didn't have in person last year. Since that's not entirely the case, it would have to be somewhat reduced and subdued. We figured, why? Why bother with that? Also, the planning and preparation to host that kind of event really does depend on a lot of interactions, a lot of people coming into proximity, checking things out, and anyway, to say the least, it would have been a logistical real hassle. And we're talking about people throughout the world, and in places where things aren't necessarily as good as they are here right now. We don't know where people are in their lives. We don't know where people are in their countries or in their households. We don't want to add more to that at this stage, because the conference would be in a couple of months, and a lot of preparation has to go into these things. It's usually done months further in advance, but that was impossible because everybody was going through hell. So next year seems like the best course of action. And why put people at risk at all if there's even a chance of that? We don't want to be a part of that. We want people to stay healthy. Yeah, exactly. A lot of what's going to be happening in the next few weeks is kind of an experiment, kind of an experiment to see how it goes, to see if we are really past it. And if the amount of people who are not helping out is enough to really turn things in the other direction. We don't know yet. We don't know. New York State's doing very well. Yeah, we are. We are. 70%, 70% vaccinated, 75% out here in Long Island. I'm very impressed, and I'm not usually impressed. But anyway, the date, July 22nd through 24th, 2022, next year, July 22nd through 24th. That is the date for the next HOPE Conference. As yet unnamed, maybe you have an ingenious name that you'd like to share with us. Our email address, oth at 2600.com. Write to us. Tell us what your ideas are. We'd like to know. Also, 2600 meetings, still suspended. But starting next month, starting in July, we are going to start resuming at least some of them. We're going to start phasing them in, and we're going to base that on the overall statistics for each area, wherever they happen to be. Obviously, some places are doing better than other places. I would say, Rob, I think we can count on New York coming back next month in whatever you call that damn mall uptown, not Citigroup, the one near Citigroup. There is the atrium, but there are interesting developments regarding that. Oh, yeah? Because a lot of us who are regulars at the New York City 2600 meeting have been looking around at the venues. The atrium where we'd been meeting before lockdown is currently remodeling. Wait, wait, wait. The one that we moved to because the other one was remodeling is now remodeling itself? Yes, indeed. It's been remodeling for a while. Why does everyone have to remodel all the time? It was fine the way it was. What's even funnier, a bunch of us went around on a field trip recently looking at that place, looking at Citigroup where we used to meet, and a lot of places, all the privately owned public spaces, rather, in the area, we were seeing closed signs on all of them. But just this week, the city government decided that the publicly owned or the privately owned public spaces, I'll get that right soon enough, that had been closed due to COVID have to reopen on July 1st. Oh, wow. So it's like they know about our meetings, so they know it's got to happen by then. Okay. But, of course, if their remodeling isn't finished, then they still can't open. So what we're doing is we are doing our best to get in touch with management of buildings and things like that, and we're kind of planning on a knife edge because it's the next meetings in a few weeks, but we will keep you updated. Stay tuned to nyc2600.net or nyc2600 on Twitter to keep updated with what's going on for next month. And we also, whatever happens, if and when we reintroduce a physical meeting, we're still going to do what we can to involve people who want to attend virtually. And I suggest for people running meetings in other places, try and do such a thing as well. You know, have a laptop running video conference software or something to that effect to continue to include people who are not yet comfortable attending physically. Go ahead, Kyle. Rob, will there be a call for supplies to help with the remodeling for hackers that may have some suggestions or maybe they can lend a hand, maybe they have a skill with some drywall or whatnot? Yeah, they love that. I think if you have Elmer's glue and Popsicle sticks, let us know. Look, if the atrium is not finished with their remodeling by the meeting, surely Citigroup, which had been remodeling for years beforehand, is done with their remodeling and they can't use that as an excuse. They can say, we don't like you, stay away, they can do that. But as you mentioned, it is a privately owned public space, whatever the hell that means. The last I checked with Citigroup, they were still several years behind on their remodeling project and had not yet. Are you kidding me? They still haven't done it? Yeah, this is moving at the speed of amazement. You know, a good place to have a meeting, Moynihan Train Hall. Okay, it's big, it's spacious, and right now there's not a lot of people in it, but that's a great place. Your voice echoes, it's amazing. I've certainly got great access by public transit. Yeah, a lot of trains go there. That should be a backup location and then maybe it will become a permanent fixture in the meetings. Okay, that's one meeting, that's New York City. As you can see, there's a lot of coordination and organization involved. If you are involved in any meeting anywhere, or if you want to be involved in any meeting anywhere, what we're doing is we're starting from scratch. We're not just going to relist all the meetings. So what's going to happen in the next couple of months is you'll see 2600 meetings start to reemerge and it will seem like there are a lot fewer of them because there will be because we're starting from scratch and only working with the meetings that contact us. So if you go to the meeting section of 2600.com on the webpage, you'll get more information there. You can follow 2600 meetings. That's the number 2600, the word meetings on Twitter, and you can DM, send a direct message to that particular entity if you have a meeting that you want to organize or that you want to resume. But we have to hear from everybody. Email address meetings at 2600.com. Many, many ways to get in touch with us. And if you have a website or a Twitter ID of your own, we will be contacting you. But, again, we'll only be listing the meetings that are in safe locations where things are at an acceptable status. And we're only going to be communicating with those meetings who talk to us, who respond. So it will be interesting. And if you want to start a new meeting, this is a great time to do it because you'll stand out all the more. There won't be – how many meetings? We have like 60 meetings, 70 meetings. And for those who don't know, 2600 meetings, it's a unique concept that we've been doing since 1987. It started right there in New York City at what was called the City Corps Center back then. We basically have a bunch of people who are interested in technology, hacking, and things like that who meet in a public space like a food court or even a bookstore, cafe, places like that. Some groups go to hacker spaces, but it's better to get away from the computers and the technology and just hang out and talk. And the best thing is meet new people who just wander by and say, hey, who are you people? We've gotten so many good people to join up as a result of that. So we have the meetings. Generally, we have the meetings on the first Friday of every month. And it started with just one meeting in New York City, but then it grew. And we figured why not keep meeting on the same day at basically the same time because back then in the 1980s, we were being followed a lot by federal agents, and we thought this would spread their reason to be the thin if they had to follow everybody at the same time. Kidding aside, though, it makes it easy to remember when the meeting is. But there are exceptions. There are exceptions. So again, meetings at 2600.com is our email address or go to the meetings section of the 2600.com website. We'll have more information here as well. I've missed that part of our columns and having to update people on the special hiatus. Yeah. You missed the actual page in the magazine. Yeah, that's what I'm talking about. It's been blank. I missed the actual meetings that they talk about. Those are fun too. But, yeah, our meetings page has been a disaster the last year. Yeah, it's been rough. It's been rough. Now, Alex, you've made it inside. It looks like everything is normal. Congratulations. Is there anything you'd like to share now that you have good connectivity? Sure. I mean, while we're on the subject of 2600 meetings, that's something that's near and dear to my heart because it's where you and I met many, many years ago back in the 90s. I think it was probably 1994 or something like that when we had the meetings. It was a city court building back then, and it was near that large bank of pay phones. And I think a few weeks ago on Overtime, I read the beginning of my law review article from law school that was published in the Vermont Law Review in 2005, and I described that large bank of pay phones as being really fascinating because it's where phone freaks from all over the world would call into at around 5 o'clock in New York. And it was just such a great place to meet interesting individuals, people that I met at 2600 meetings 25, almost 30 years ago now, my God, still friends with to this day. They're pretty extraordinary places. And I know in Vermont, when I lived in Vermont, they meet or used to meet on Church Street in Burlington in the top floor of a McDonald's. So these meetings really run the gamut in terms of locations. Yeah, and they exist everywhere. I've been to many British meetings. There are meetings in Japan, all over the place. You name it, Brazil, Argentina. It's an incredible way to bring people together, and the similarities, no matter where you happen to go, are striking. And it's an incredible catalyst and way to build strong hacker communities all over the world, and it has. When you visit and travel, you can count on maybe finding a local space or a group that's interested in the kinds of things you are. Yeah, and to call it a meeting is kind of a misnomer because there's no agenda. There's no leader. It's basically a gathering. It's basically hanging out in a food court or something equivalent and just talking to the people you want to talk to. You don't have to talk to anybody you don't want to talk to, and nobody is in charge. We just ask that people obey the rules of whatever place they're in. Sometimes there's discussion. Sometimes people lead. Yeah, sure. Some meetings do it a little bit differently. Yes, Rob? I also kind of appreciate that we're taking this opportunity to reboot the whole list that had been building up over the years and years because we would often hear from people via email or whatever that they would say, oh, I went to where the magazine said such and such a meeting would be in such and such a place, and there was nobody there. It is a natural thing that events would sort of fade out or move or evolve in some way, but the list wasn't keeping up with what was going on in reality. So now we have this opportunity to restart everything, make sure that all the meetings we list are people we're in communication with that are active and are going to meet there. And we'll be able to have our listing in the magazine in a font size bigger than six point, I think, right? Is that what we have now, Kyle? It's really tiny. You need a magnifying glass to read it. I don't know. Any of our readers would know it's getting smaller and smaller. It's going to be big for a little while. People start them. So, yeah, we're going to go back to a bit more legible. Well, there's just going to be less there, but it will grow, and that's the exciting part of this. Yeah, absolutely. Things have changed, though. Like Alex was saying, pay phones. You can't call into pay phones anymore if they're even there. They don't take incoming calls, and many places don't even have pay phones. But the spirit, that is the same. That has not changed. I noticed, too, at some of the locations I visited for meetings, they're competing with other meetings, and there's other things that start up in whatever coffee shop or locale is chosen. So these things are dynamic. Sometimes, as we're talking about remodeling and stuff, there's other competing factors. So this is a great time to restart and rekindle that. Were there Starbucks or Barnes & Noble when our first meeting started in 1987? I honestly don't know, but they certainly weren't everywhere like they are now. So that's something to think about. Okay, we have more news. All sorts of other things have been happening. Late-breaking reality, Winner has been released from prison. Former intelligence contractor jailed for leaking classified information. She was released from prison to serve her remaining sentence in the halfway house program. Winner's attorney, Allison Grinter, tweeted the news a couple days ago, and the Federal Bureau of Prisons website lists her in custody of San Antonio's Residential Reentry Management Field Office, which oversees community-based programs for incarcerated people. I am thrilled to announce that Reality Winner has been released from prison. She is still in custody in the residential reentry process, but we are relieved and hopeful, her lawyer tweeted in a statement. Reality and her family have asked for privacy during the transition process as they work to hear the trauma of incarceration and build back the years lost. Her release is not a product of the pardon or compassionate release process, but rather the time earned from exemplary behavior while incarcerated. She is still barred from public statements or appearances, and the Bureau of Prisons website still lists her release date as November 23, 2021. Still good news that one more person is no longer incarcerated. Well, was she the one who was incarcerated because her data was somehow leaked? Was it the Intercept? Yes, this was the case involving micro dots, a more recent case involving micro dots, and I think the Intercept was involved with publishing the document without transcribing it in a way that couldn't share those, and they ended up being quite revealing about the location of where the printouts were made. Yes, Gila, go ahead. Oh, no, I'm sorry. I had an itch. Oh, okay. Alex, go ahead. Sorry. Alex, do you have an itch or do you have something to say? Yeah, Kyle's exactly right about this. This was the case that had to deal with the micro dots, and more importantly, I think the documents that Reality Winner had taken from the government in violation of, I believe it was the Espionage Act, or transmitting classified information, rather, were incredibly important to our public understanding of the 2016 Russian campaign for election interference, and so Reality Winner, by taking these documents, these classified documents, and transmitting them to a journalistic outfit like the Intercept, and for full disclosure, I've written for the Intercept in the past, in quite a few years, but I have written for them. She was a whistleblower. She was engaging in whistleblowing activities here, because the Russian activities that were the subject of the documents she had exfiltrated, or taken, stolen, released, whatever verb you want to use for it, indicated that Russian intelligence, or the GRU, I believe, was targeting a Florida-based voting entity, and also seeking to spearfish certain high-ranking election officials in the state of Florida. So we did not know this, and would not know this, but for, I think, in my opinion, the really selfless acts of Reality Winner, and she paid a very, very hefty price for this. I don't think that she thought that she was going to get caught, but this underscores, I think, the real importance of how any kind of press agency or media outlet handles source information, and publishes source information. It can literally be a matter of life and death. I mean, just like any intelligence agency, you have to protect your sources and your methods, and this is a case that really underscores that, and had a very tragic outcome for, I think, information that was squarely within the public interest. Also, I think of note that Reality Winner sought a pardon from Donald Trump on the basis of her whistleblowing activities, but was denied. Yeah, and it was especially, it seems a little out of context now, but at the time, I think if you look at some of what was going on, I can't even really, I don't have one specific detail I can point to, but it was a time where a lot of the information about that was being suppressed. Well, okay, so good news on that front, and yeah, hopefully she'll adjust to life in the free world as soon as possible. There's a documentary, I haven't seen this documentary, I've heard good things about it, the United States vs. Reality Winner premiered at the South by Southwest Film Festival earlier this year, so that might be something for people to catch up on what this story is all about, and what she was all about. One thing we were going to mention last week, it was a particularly good week for the feds, my goodness. The FBI was able to recover millions of dollars in cryptocurrency that was paid to the ransomware hackers that targeted Colonial Pipeline, not the kind of thing you think is possible. Listen to this interview with the Wall Street Journal that FBI Director Christopher Wray participated in. He said coordination between ransomware victims and law enforcement can, in some cases, yield positive results for both parties. It's kind of funny that he says that cooperating with the FBI sometimes can result in positive results. Many times not, though. I don't want to suggest that this is the norm, but there have been instances where we've even been able to work with our partners to identify the encryption keys, which then would enable a company to actually unlock their data even without paying the ransom. Does anybody know what he's talking about? Yeah, sure. If a threat actor, some kind of criminal or ransomware gang, had used the same key somewhere else to encrypt someone else's data, and the FBI or law enforcement had assisted in decrypting that data, they might have copies of those particular keys and be able to reuse them in decrypting this data, or they might have some kind of covert capability or covert access to the threat actors' systems themselves, acquire those keys and hand them over to the affected organization. Yeah, that's pretty much it. According to the report I'm looking at here, in some cases, U.S. officials can find the ransomware operators and own their network within hours of an attack. That basically allows relevant agencies to monitor their communications and potentially identify additional key players in the group responsible. When ransomware actors are more careful with their operational security, including in how they move money, disrupting their networks, or tracing the currency, it becomes more complicated. If you're a ransomware operator, you need to take a course in how to safely run your network to avoid this kind of thing from happening to you. And it shows you there are absolutely levels to the kinds of games people are playing out there. It also shows you that for all the complaining that we hear about how technology is leaving law enforcement behind, no, it's not leaving them behind at all. This proves it. This shows that if you're good at what you do, if you're clever, if you're smart, you can figure it out. You can outsmart them. And I applaud the FBI for doing this. They actually were able to win one for the good guys. I think also what they're saying, if you read between it a little, is that the more cases people report that have affected institutions, they're increasingly having a broader view, a map, basically mapping out how keys and parts of the blockchain are being used and then what networks they're associated with or what service providers are being used wherever and in whatever case. So the more people are open about it, the more tools they can apply from history and other investigations they've done, which makes sense. Can you imagine, though, being a ransomware operator who's just siphoned off millions of dollars from some company, losing it all because your network was compromised by the federal authorities? I mean, the symmetry is perfect. And yeah, I'm blown away by it. Go ahead, Alex. Look, I think it happens in more cases than we hear about. I have worked on and am working on a couple of matters that have to do with the theft of cryptocurrency and the return of the currency. And I will say, everybody operates on this erroneous assumption. Not everybody. As I would say, a lot of people operate on the erroneous assumption that Bitcoin is some untraceable magic. It certainly is not. I mean, Bitcoin is the coin du jour because it's easily accessible and widely available for this type of payment. They then put this through different coin swappers or mixers. But all of this ultimately is traceable. And I think even if you're stealing Bitcoin or if you are requesting a ransom, I would say in a good percentage of cases, the majority of the cases, the threat actors, the criminal groups responsible for these ransomware attacks, likely do not get away with exfiltrating or edging out into fiat currency the 100% of the money that was paid into the ransom. And that's because the money is traceable and very often frozen when it's in other currencies or other exchanges. And I wound up actually writing an article last week for CNN, an opinion article for CNN, where I talk about the role of ransomware and cryptocurrency and how cryptocurrency essentially fuels the ransomware industry. And that because we are now seeing a change in attitudes towards paying these ransoms and more KYC or know your customer requirements that are ubiquitous through cryptocurrency exchanges and more popular exchanges like Coinbase being a force for good in this group, in this land of cryptocurrency, we're going to start seeing cryptocurrency and ransomware, I think, decreasing over time. But in the immediate future, the access that these criminal enterprises have, these threat actors have, they want to try to monetize it as quickly as possible. If you think about how the Colonial Pipeline ransomware attack worked, it was ransomware as a service, which means that the creators of the ransomware, DarkSide, they did not necessarily have access to Colonial Pipeline. Some different group of criminal bandits of threat actors had access to Colonial Pipeline and they deployed the DarkSide group's ransomware on it. At the end of the day, they would split a certain percentage of the ransomware that was paid to them. So now those that have access are in a race to monetize it and those that have developed in the ransomware are in a race to monetize it because of all of these regulatory changes, including changes from the insurance industry itself, where insurance companies are now beginning to look askance at paying out ransoms because it may be against public policy. It also may even violate sanctions, U.S. sanctions. Some of these criminal groups have been placed on sanctions lists or on the OFAC list by the U.S. government, and so paying them may even be illegal. So all of this, I think, is coming to a head right now where we're going to see a higher velocity of ransomware events. But over time, I'm really hopeful that they'll decrease without destroying cryptocurrencies themselves. A couple of things you said strike me. Now, if it's illegal to pay a criminal, doesn't that make every single kidnapping something that can't be resolved? You can't pay a ransom. You can't legally pay a ransom because the person who is demanding a ransom is a criminal and is being sanctioned. Well, it wouldn't be every criminal. It would be certain groups. Well, why wouldn't you sanction every criminal? Well, you could, but it would be difficult to keep up with the gangs and the naming conventions. I think known threat actors that do this regularly or that may be state-sponsored or operate within a state that has turned a blind eye to their particular activities or they have some kind of immunity from prosecution, those are the types of groups that we can likely see being placed on sanctions lists that would prevent U.S. companies affected by their ransomware deployments from paying the actual ransom. You mentioned that cryptocurrency is in many cases traceable. Does that mean, though, that it's accessible? My understanding is that you might be able to see what's going on in a ledger. It doesn't mean that you have access to the people that are actually doing it or can find out any actual information. Yeah, if there were ways of doing it, would you want to talk about it? That's true, too. Yeah, well, it is to a certain extent, right? And it all depends on where the currencies end up and on what exchange and whether that exchange has some kind of reasonable KYC type of requirement, some reasonable know-your-customer requirement. I stop at that, Alex, right away. This KYC thing is not working. First of all, it's a silent K, so that doesn't work right there, and I hate those acronyms. In corporate boardrooms, I know people talk like that, but not on 99.5 FM. I'm sorry. All right, well, we'll call them some kind of disclosure requirements for opening up a particular account. Also, that doesn't get you out of the ambit of, let's say, an account is hijacked by a threat group and used as some kind of mule to launder the money. I mean, these types of disclosure requirements for opening up an account, I think they're going to be more and more forthcoming, especially if they're a condition of doing business with larger exchanges like Coinbase and Celsius. Yeah, I had a real problem. Like, the news cycle really ran with this, and it made me a little bit annoyed just at just how sensational and the reaction and the confusing of various things, this sort of allegation that Bitcoin didn't work anymore because the investigative entities in these cases were actually doing their jobs and putting things together and coming up with ways to work to the victim's favor, but it was being cast as this, like, end of cryptocurrency or what is even the point anymore? Fareed Zakaria did a really, like, a bit of a preamble on this that was pretty nauseating, and it was just like, well, why not we just go to these, you know, all of the functions of it except for the dangerous parts? And I just looked at that, and I'm like, well, why is it this particular cryptocurrency that's broke? I mean, you would just start up another one. There are so many of them anyway, but for some reason, Bitcoin was the bad one, and it's just it became this huge attention-getting thing when it really didn't serve the ends of the people that were using it and the public as far as awareness of what was going on. Gail, either the sun is in your eyes or you have something to say. No, I actually do have something to say this time. I know. It's exciting. No, because Kyle, when you said it got huge, and this is, of course it did. It did because it had to because of the severity of the hack, if you will, of the negative. Like, people were putting gas into plastic bags. Someone had the answer for it. This is why people cared. This is why people zoomed in on it. Nobody knows any, not nobody knows anything about Bitcoin, but a lot of people don't, and people just needed to see, okay, the bad guys are doing X, X is bad, and it's a really, I think, oversimplification, which I'm actively oversimplifying now, but I think it's sort of leading to a demonization of cryptocurrency because if the only people who are interested in it are Elon Musk and people who are making me put gas in plastic bags, it's not something I'm interested in. Okay, can I just say something about the gas in plastic bags thing that people in Carolina were doing? You can't blame that on the ransomware people. There's something else going on there, and we need to focus on it. When people go around doing that kind of thing, there are issues, and I was blown away by that myself. I think it's benzene poisoning. I don't know what it is, but it needs attention. But, hey, this story continues because this wasn't the only victory that the FBI had. Now, there was this case in Australia I'm sure many of us have heard about. For years, organized crime figures around the globe were reacting on these cell phones that basically had a calculator app on them, and the calculator app was basically hiding what the phone really did, which was sending encrypted messages and photos. So, all these organized crime figures were using these devices to orchestrate international drug shipments, coordinate the trafficking of arms and explosives, discuss contract killings. It's basically a festival of organized crime. They trusted the device's security so much that they often laid out their plans, not in code, but in plain language, mentioning specific smuggling vessels and drop-off points. Unbeknownst to them, however, their entire network was actually a sophisticated sting, FBI in coordination with the Australian police. Unbelievable. A week ago Tuesday, global law enforcement officials revealed the unprecedented scope of the three-year operation, saying they had intercepted over 20 million messages in 45 languages and arrested at least 800 people, most of them in the past couple of days, in more than a dozen countries. And using the messages, U.S. court papers say the authorities have opened a barrage of international transactions into drug trafficking, money laundering, and high-level public corruption. The FBI's operation, according to court documents that the Justice Department unsealed a week ago Monday, had its origins in early 2018 after the Bureau dismantled a Canadian-based encryption service called Phantom Secure. That company, officials said, supplied encrypted cell phones to drug gangs like Mexico's Sinaloa cartel and other criminal groups. Seeing a void in the underground market, the FBI recruited a former Phantom Secure distributor who had been developing a new encrypted communication system called ANOM. The informant agreed to work for the FBI and let the Bureau control the network for the possibility of a reduced prison sentence. He let them control the whole damn network just for the possibility of a reduced prison sentence. They also paid him $120,000. ANOM devices were cell phones that had been stripped of all normal functions. Their only working app was disguised as the calculator function. After entering a code, users could send messages and photos with end-to-end encryption. Over three years, more than 12,000 ANOM devices were sold to over 300 criminal syndicates, operating in more than 100 countries. The devices' costs varied by location, but were generally sold on six-month subscriptions, available for about $1,700 in the United States. Working with the Australian authorities, the FBI and the informant developed a master key that allowed them to reroute the messages to a third country and decrypt them, ultimately intercepting more than 27 million messages. The authorities also relied on the informant to get the devices into the highly insular criminal networks. The informant started in October 2018 by offering the devices to three other distributors with connections to organized crime in Australia. And that informant, I would imagine, he has got to be under double secure secret witness relocation onto another planet because he is no friend of many, many people right now. But boy, what a coup, what a coup from the FBI and law enforcement everywhere. And again, another indication of how, yeah, you can outsmart encryption. You can do it if you have a plan, if you work together and you're smart. Rob? And it's not the encryption here that was weak. It was the fact that the criminal underworld let themselves get talked into buying a fake secure app that was under the control of the people trying to catch them. And, you know, if they'd gone to open source, this would never have happened. Yeah, I guess that's another argument for open source. Yes, go ahead, Alex. I mean, speaking of protection of sources and methods, really you have to hand it to the FBI and law enforcement agencies the world over that were working in coordination with FBI that, you know, they really pulled this off. I mean, keeping this secret, monitoring this, making sure that nobody was going to make an arrest or have a prosecution where this type of methodology was going to be disclosed in a court proceeding, I mean, they kept us under wraps for three years. I have to say, that's a great job on the part of law enforcement to keep this thing operating. And also, as Rob mentioned, too, this just underscores the very fact that many of us don't necessarily understand how this technology works. We power up our iPhones. It's sort of magic. We all assume that that signal or wire or telegram or whatever it is is perfectly secure. We don't look under the hood. We need the right to look under the hood to make sure that our privacy is not subject to the same type of insecurities based on the assumptions that these criminals make. Oh, wow. My phone has a calculator. I just found it. I didn't know my phone had a calculator. I bet, yeah. But it really is incredible how they pulled this off. I was wondering when I read the story, God, what were they privy to and what did they let pass by and happen with their knowledge just to keep this type of operation secret? It's incredible. And again, congrats to FBI for pulling this off. But by pulling off these two things, you're also demonstrating that you can operate in today's technology just fine. You don't need to have back doors into everybody's phone or a spy in everybody's Internet account. No. You can use the prevailing landscape and use your criminal detection skills to win in the end. It's not that difficult. Oh, we are almost out of time. I want to remind people to pledge to WBAI 212-209-2950 or go to give to WBAI.org. We have a letter from somebody. Hang on. Let me try and track this down. One of many people, hopefully, who have contributed. This is from Thomas. Not looking for any recognition. Well, too bad, Thomas. You're getting it. However, I'm donating monthly since I faithfully listened to Off the Hook. And I would like to credit my monthly donation to that program. Thank you so much, Tom, for that generous donation. You can be like Tom. Give a call to 212-209-2950. Go to give to WBAI.org. You can become a BAI buddy. Pledge every month. And by doing that, when you pledge every month, it adds up to a bigger number over an entire year. And everybody wins. Write to us. OTH at 2600.com with your emails if you have something to say to us. And, Rob, I think you have something to say right now. Yes. And if you're already a member of BAI, do cast your vote in the Pacifica Bylaws Vote. Go to WBAI.org slash bylawsvote.html for more info on that. Yeah. Remember, the station is imperfect. It's a work in progress. But it's been around since 1960. And it's ours. And Google can't kick us off it. So it's a treasure worth preserving. So do whatever you can to make that happen. We'll be back on these airwaves next week at this time. Well, we'll be leaving this time. But at 7 o'clock, we'll be coming back on. In a few minutes, at 8 p.m., we'll be going to Off the Hook Overtime on YouTube. You get there by going to Channel 2600 on YouTube or by clicking on the link that appears at the top of the 2600.com web page. We'll have more updates on various things going on as we transition back to normalcy. Remember, folks, get that vaccine if you haven't already. And join us on Overtime as we no doubt get shut off for medical misinformation. We'll see. Good night. They came after Julian not for his vices, but for his virtues. Journalist Chris Hedges on why the persecution of Julian Assange. They came after Julian because he exposed the more than 15,000 unreported deaths of Iraqi civilians, because he exposed the torture and abuse of some 800 men and boys aged between 14 and 89 at Guantanamo, because he exposed that Hillary Clinton in 2009 ordered U.S. diplomats to spy on U.N. Secretary General Ban Ki-moon and other U.N. representatives from China, France, Russia, and the U.K., spying that included obtaining DNA, iris scans, fingerprints, and personal passwords, part of the long pattern of illegal surveillance that included the eavesdropping on U.N. Secretary General Kofi Annan in the weeks before the U.S.-led invasion of Iraq in 2003, because he exposed that Barack Obama, Hillary Clinton, and the CIA orchestrated the June 2009 military coup in Honduras that overthrew the democratically elected President Manuel Zelaya, replacing it with a murderous and corrupt military regime, because he exposed that George W. Bush, Barack Obama, and David Petraeus prosecuted a war in Iraq that under post-Nuremberg laws is defined as a criminal war of aggression, a war crime, that they authorized hundreds of targeted assassinations, including those of U.S. citizens in Yemen, and that they secretly launched missile, bomb, and drone attacks on Yemen, killing scores of civilians, because he exposed that Goldman Sachs paid Hillary Clinton $657,000 to give talks, a sum so large it can only be considered a bribe, and that she privately assured corporate leaders she would do their bidding while promising the public financial regulation reform, because he exposed the internal campaign to discredit and destroy British Labor Party leader Jeremy Corbyn by members of his own party, because he exposed how the hacking tools used by the CIA and the National Security Agency permits the wholesale government surveillance of our televisions, computers, smartphones, and antivirus software, allowing the government to record and store our conversations, images, and private text messages, even from encrypted apps. Tune in to Radio Unnameable Thursday at midnight to hear hedges and more on the power of moral resistance and the importance of protecting whistleblowers and journalists and to advocate for the release of Julian Assange. That's midnight on Thursday, Radio Unnameable, here on listener-sponsored, non-commercial, locally controlled WBAI New York. Okay, here we are. Off-the-hook overtime is on the air until somebody decides that we're too objectionable and reports us. Well, it's good to be back. And I've got some interesting headlines. We're talking about sensationalism. Here's one. Hackers threaten poisonings, blackouts of utilities. Are we prepared? Hackers are threatening poisonings now. It's really getting serious. This is from some TV station someplace. This is how they get viewers, by scaring the crap out of them. Or how about this? Hackers expose 8.4 billion passwords online. Your security is at risk. Alex, your security is at risk. I'm talking to you. Well, it always is. That's the issue, right? Even though we are security professionals, even our security is at risk. We have to, I think, constantly stay vigil, stay alert, and keep learning. That's part of the hacker spirit. That's, I think, why many of us as hackers are drawn to these types of professions. So yeah, it's great. Yeah, it's the challenge. It's the thrill. Hey, you know, we didn't have time for this story, which I thought was very important and very good news. New York State Senate overwhelmingly voted to pass electronics right-to-repair legislation, becoming the first legislative body in the country to do so. It's a major step forward for a movement that is overwhelming public support and has been working towards getting a law done for the last several years. It protects consumers from the monopolistic practices of manufacturers, said Senator Phil Boyle. We all have computers, laptops, and smartphones that we repair once in a while. Many times we have to send them back to the manufacturer for simple repairs that cost a lot more. Now people can repair their own computers, laptops, and smartphones, and farm equipment. I like how that's thrown in there. Their own computers. I'm sorry, every time I say computer, the Alexa app freaks out, because that's her name here. Every time people repair their own C-words, laptops, and smartphones, and farm equipment, we don't have to send them back to the manufacturer. So good news, right? Prepare their own C-words? No, this is very good news. Right-to-repair really is a no-brainer, because it's one of those things where everyone wants to be able to fix the stuff they've got if they can. There is no argument against it except for monopolistic manufacturers and hardware and software people to make sure that they make more money than they're entitled to. But it's been fought off by companies with massive amounts of money. It's nice to see that the opposite happen for once. Now, does anybody know what's missing? I mean, just when you think about it, what is missing from this? What's missing? I asked a question. All right. Tell us what's missing. We don't know. I just think it's really great. It's positive, and I agree with it's a no-brainer. But why aren't cars included? Now, before you say, that's a mechanical thing, didn't we just have a whole bunch of news stories and craziness about chip shortages, leaving car manufacturing, and all this stuff in disarray, and how everything is dependent on chips, and doesn't a chip imply that it is an electronic? Yeah. No, you raise a good point. I would also say farm equipment, that's a vehicle, but it's not really a car. It's a cutout, a carve-out, and I just think that's very suspicious. But I love that it's happening. I think Canada did something even more, or is planning to as well. So this is really spreading, and this is a good thing. We need more of it, and more documentation, and less really hostile manufacturing, and convoluted designs, and just stuff that is unreparable, or is a whole assembly, you can't get individual parts, or even designs for maybe really old stuff. You could release some, and help people make replicas properly, instead of bad replicas, and so forth. We have a caller on the line, but we haven't given out the phone number yet. It's 802-321-4225. We'll get to that caller in a second. 802-321-HACK. Go ahead, Rob. I just want to say it's important that they note farm equipment in this, because farm equipment is a major driver of the issue. Farmers and I'd love to hear from any listeners who work on a farm, or have a farm, or experience with this directly, because farmers have been put in the position by monopolistic manufacturers where you have to do stupid things like subscribe to your own tractor in order to keep it running year after year, and it's really ridiculous. Subscribe to your own tractor does sound ridiculous. It's farm equipment as a service, and it's this model that, oh, we'll control everything and make it ... Render it unusable unless they pay. That is predatory. Exactly. Let's take this call. Good evening. You're on. Go ahead. Hi. I had two things I wanted to mention. Okay. One, you were talking about how wonderful it was that 70% of New Yorkers were vaccinated, but that is not true. 51.0% of New Yorkers are fully vaccinated. Fully vaccinated. Yes. Okay. There's an asterisk next to that. Have gotten a shot. I should have said it that way. And you should have mentioned that that's only adults. It doesn't include younger people. Look, I don't know how they get the numbers. All I'm saying is everyone's saying 70%. All I did was repeat 70%. So while everyone is outside celebrating, I'll be inside looking at the numbers and getting them right, but it's basically ... It's a good thing that we're up to. Yeah, it can be higher. It should be higher. And don't take our advocating or informing as we're throwing caution to the wind or not watching carefully ourselves. It's just a milestone we wanted to make sure people were looking forward to. And we don't want to encourage other listeners to throw caution to the wind. But the thing is that they are manipulating the figures, and you accidentally passed along a manipulation- Well, who's manipulating it? Who is manipulating the figures? Who is doing that? Because I'm just hearing it the other way. I'm hearing that this whole thing is blown out of proportion. You're saying that they're not saying the truth as far as how bad it really is? 70% of adults have had at least one shot, but only 51.1% of the entire population is fully vaccinated. Okay. So what Joe Biden has asked for, for the entire country, is 70% by July 4th, and that 70%, if I understand correctly, is one shot, not fully vaccinated. Is that correct? Yes. One shot, adults. So what we are celebrating is the fact that we've reached that particular milestone that Joe Biden would like us to reach by July 4th. And if the rest of the country does the same thing, we'll at least make him happy. Except that's not going to happen. But anyway- Not with that attitude. It's not. Well, New York is ahead of the curve. Yes. Toronto's ahead of us. They're 80%. Anyway, did you have something else? Yes, I did. What's that? I wanted to encourage the savvy people who listen to this overtime to please sign my petition that disabled people need vaccinated aids. And I'd like to encourage you, Emmanuel, with your checkmark, to please tweet about it because I seem to be stalled at 21 people. Ever since I got that damn checkmark on Twitter, everyone's coming to me for favors and obligations and things like that. Well, I asked you about this before that even came up, you know. I know. I know. Give out your info. Give out the address so people can sign. Sign people, please. Sign. Okay. Do you have the info? I wanted to give you a piece of good news. But you have to give the info out. How do people get to your petition? You've got to give the address. It's change.org slash- Where are we working in a tiny URL? Wow. I'm blanking. Isn't there a tiny URL? And you wonder why people don't go there. This is the tiny URL part. No, no, no. Where's the tiny URL? Or whatever. I don't know. It doesn't have to be that. Disabled need vaccinated aids. That's change.org slash disabled need vaccinated aids? Yes. Spelled A-I-D-E-S. Correct. Perfect. I think that's the info. So, thank you. And we'll spread the word. I have a piece of good news. Oh, go ahead. I have a piece of good news. I have a piece of good news. I have a piece of good news. Oh, go ahead. Good news is good. A couple of pieces of good news on that front. You probably already heard about that hospital that was being sued by 117 people who didn't want to get vaccinated, and the judge ruled in favor of the hospital's sanity, saying if you're- Yeah, I heard that. If you're in contact with the public, you need to be vaccinated. I cannot understand how anybody who works in a hospital would be arguing against getting a vaccine against a pandemic. It doesn't make sense to me. You're in the wrong line of work. And thank God there was a judge that saw that. There are too many that don't see that. But this time, yeah, this time the right judge ruled on it. And the other piece of good news I had is I'm trying to get physical therapy. And I was shocked to find that the person evaluating me had not been vaccinated. And so I wanted to make sure that I made appointments with therapists who had been vaccinated, because you can't keep physical distancing if you're doing physical therapy with a therapist. So they gave me a whole runaround. They're not allowed to do it. But they tell the person, finally, after weeks and weeks of this, a manager said they would instruct the people who make the appointments to only offer me appointments from vaccinated aides, except they offered me an appointment with someone who had already told me they weren't vaccinated. But they're going to be getting little stickers to put on their IDs that will say that they're vaccinated if they're vaccinated. I just bought a whole bunch of those stickers. I just bought 500 of those stickers on eBay. And basically, whenever I see somebody and I ask, have you been vaccinated? And they say yes, I slap a sticker on them right then on the spot. And you know, it's considered a good thing. And that way, they don't have the awkwardness of having to prove it anymore, because a sticker can't be faked. You know, that's legit. Well, these are stickers that are put on their official IDs. So I think there would be a problem if they tried to fake them. Well, it's not. Yeah, the official ID isn't fake. The sticker, though, it doesn't matter what you put the sticker on. I mean, you can put it on their forehead. It doesn't matter. It's still the same sticker. But yeah, then, you know, I take your point. You might be dealing with a liar, but look, at least you tried. And the thing to remember is you're vaccinated. So that is 90% of it right there. So don't short sell yourself as far as that goes. I don't want to be victim of a breakout, because I can't afford any more medical issues. Right. It could kill me. Absolutely. And it could kill a lot more people than we believe. I think we've seen that. Having hit 600,000 deaths in this country alone in one year. That's a low estimate. That's a low estimate. Exactly. And I don't know if we'll ever find out the real numbers. Anyway, listen, thanks. Thanks for the good news. Best of luck. We'll stay in touch. Bye-bye. Bye. Again, phone number, 802-321-4225. Let us know your thoughts and feelings on various things going on or experiences. Rob, yes, go ahead. I just think the sticker angle is interesting, and I'm thinking I can design a sticker for the non-vaccinated that it's a large sticker, goes completely over the mouth and nose, and I think saves the rest of us a lot of trouble. You're getting our show banned again, just by saying that. You're going to get those people angry. This is medical misinformation. My goodness. Are we on call? Go ahead. You're on the air. Yes. Yeah. Hi. Are you going to be making an attempt to get Reality Winner to speak at the next HOPE conference? Well, I can't make that attempt now, because she's not allowed to talk to anybody. But as soon as she is allowed to talk to somebody, she certainly would be on my list. We'd have to check if that's what other people want as well. But it sounds like she has a lot to say. I don't know if she wants to say it to us, but right now, I'm just thrilled she's out, one step closer to total freedom, and I hope it's an inspiration to other people to always do what's right. It really sounds like she worked very, very hard immediately when that became her situation to go through that process and took it on, being released early because of her behavior and so forth. So I'm sure the halfway house is something that will be a necessary part of reentering society and so forth, but something short. Well, I'd love to hear her. I'm sure she has a lot of good stories. I hope you were able to hook up with her when she has the ability to communicate with you guys. Yeah. Well, we have a year, and hopefully sometime this year, we can see what's possible. Yeah. I just wanted to point out one other thing. Joe Biden has a vacancy on the FCC, and he still hasn't appointed another member to fill the five-member panel. I'd encourage listeners to contact the White House and tell them to get moving on that. The Republicans are going to try and block any appointments he makes. So while he's got a thin majority, he should go ahead and just appoint somebody. Who was the vacancy, do you know? I don't know. I guess... Oh, Ajit Pai. Oh, he's gone? Yeah, a guy that Trump appointed. He stepped down, and there hasn't been, as I said, Biden hasn't named a replacement, so it's still only four members right now. Alex, do you have something to say? I thought that the replacement happened yesterday, if I recall correctly. I thought that he was replaced with a woman, and that there might have been a vote on this yesterday. Seems like the kind of thing we could look up. I think that was the FTC, not the FCC. Oh, I'm mistaken. It's very similar, Alex. Many people would make that mistake. Yeah, there's so many letters in common there. That's true. There's an FEC, too. Stay away from them. Right. But yeah, I would encourage people to, like I said, Republicans are going to try and block anything he does, so he really does need to get moving on that. Okay, so we would need somebody in the FCC who values net neutrality, among other things. What other things do we want to see in a candidate? Well, there must be something. One that is not affiliated with a large corporation, perhaps. Maybe someone that's worked at a public utility commission, or someone that has experience building rural infrastructure, or helping people in some way, or regulating in some way, other smaller sectors of the communications industry. Alex? Somebody that wanted to bridge the digital divide, I think. I hadn't realized it was open to the entire floor, but we could just generate a giant list of things that we would want from an FCC commissioner, and one of them would be to expand the FCC's role when it comes to privacy enforcement, to go after social media companies that do bad things with our data, or share data with bad people, and do a lot of things with our data without our consent, to go after more companies when it comes to bad data practices for deceptive trade practices, to actually enforce their consent decrees against platforms like Facebook in a meaningful manner, and not just slap them on the wrist with monetary fines that are absorbed within, let's say, a day or a half a day's worth of profits. Yeah, I mean, we could probably go on and on and on. There you go. That's what I was looking for. Yeah, sure. Also, I mean, all of this, really, to bounce off Kyle, is contingent upon Kyle's original request, right? That this person be independent, be able to look at things objectively, and not be in the pocket of large corporations, whether it's big tech or anybody else. All right. Anything else, caller? No. No, thanks. That was it. Thanks for bringing that to our attention. Thank you very much. Take care. Again, phone number, 802-321-4225, 802-321-HACK. Someone in the FCC? We could definitely use that. I was not aware there was an opening, but yeah, the caller is right. This is a great opportunity to do something positive. It won't last for long. It won't last forever, anyway. It really is. Just to go back to Reality Winner for a moment, of course, she is blocked from saying anything, but to people who want to keep up with anything that does develop, I recommend following Reality's lawyer on Twitter. Her name is Alison Grinter, screen name A-L-I-S-O-N-G-R-I-N-T-E-R. There is the official statements as they exist now, and I'm sure it'll be updated with developments. Okay. We have another letter from a listener here, and you could be one of these listeners that writes to us, othat2600.com is our email address, open to all. Dear Off The Hook, first, congrats to Emmanuel for finally unlocking the blue checkmark achievement. I've enjoyed the show during the pandemic and hope you can all be back in the studio soon. I wanted to write in about the whole COVID passport drama. Too many people conflate being anti-passport as being anti-vaccine or being anti-passport as being anti-proof of vaccination. I am pro-vaccine and pro-proof of vaccination, but I am anti any sort of digital passport. There is a common retort about how having to prove your vaccination status is nothing new. Clearly this has been a requirement for schools and international travel for a long time, but the systems being built today are incomparable to a piece of paper sitting in a file cabinet since 1995 showing I got the MMR vaccine to attend middle school. The primary difference, which seems to be missing in nearly every conversation, is the implementation of such a system and the data that it may generate. People can see how letting a human bouncer visually inspect a CDC card is different than forcing people to install an app on their smartphone and scan it whenever asked. The latter generates a permanent record of your movements and as adoption increases would allow governments to query such a system to answer questions like, show me all the people who visited this mosque this week or give me a list of all the teens who have visited the Planned Parenthood, this Planned Parenthood office. It's not hard to imagine a future in our data brokered surveillance capitalism economy where businesses sell, trade, and inevitably lose this data. I'm surprised at the lack of nuance around this discussion on the show, especially for a group so creative in the ways in which systems and data can be abused in unintended ways. I was happy to see at least EFF released a cautionary report on this, signed Arthur, you're absolutely right. These are certainly things to be concerned with and maybe I haven't been looking at it as closely as I should. I'm simply looking at something on my phone that I show to people and they see it, they look at it, kind of like showing a train ticket to LIRR conductor. I'm not aware of that being on my phone being part of any kind of permanent record keeping, although it certainly could be. It could be misused in that manner. I simply see it as a way that I can easily carry the same information that's on that little piece of paper that I might lose. And it's also just makes me feel good knowing that somehow it's official, you know, that I have the vaccination and it's there. But you're absolutely correct that in this society of ours where we love to keep track of people and see what they do and where they go, this could be abused quite easily and either the whole thing is a bad idea or it needs to be very, very carefully watched and protected. Not really 100% sure which is the best way to go. Right now, getting people vaccinated is the priority as far as I'm concerned. Kyle, did you have something? Yeah. Sorry. Yes, I just wanted to make the distinction between the machine readable barcode that like an app like the Excelsior Pass generates, if you could exfiltrate that from the app, it could be on a laminated card or wherever else you could laser cut it or tattoo yourself with it if that makes you feel, I don't know, comfortable or more uncomfortable depending on what you like. But the point is disconnecting the app, the app itself operating on your phone, if you can't audit that software or have a reasonable control over location and its access to things like location, and that includes from telemetry just passing by access points, all the different ways you could be located with the sensors, the myriad sensors on a phone, that's distinct from having like a machine readable copy of something that can verify. I could still place you somewhere, but it's not going to necessarily track you in the same way. I think there is a distinction there, but this is more levels of it. It's, I mean, there is still a point that it certainly organizes all the information of the vaccinated or like these groups of people and then assessing their behaviors definitely could be facilitated in an app like this. One thing he said though, which I don't really agree with, we're not being forced to do this. If we were being forced to do this, I'd have much more of a problem with it. It's a completely voluntary thing. And there are also, what you're talking about, Kyle, with barcodes, how many times do we use barcodes on our smartphones for something else? And that could be tracking us as well by some other entity. Go ahead, Rob. Yeah. And there's also the fact that like this also is basically on the level with other things that we've been doing. If you've been to bars and nightclubs in the past couple of decades, you very likely, if you got carded at the door by the bouncer, there is a thing where they scan your state ID card, your license or what have you to make sure it's genuine and that you're of age. And that's been something that everybody's fine with. There is also the fact that yes, this is not mandatory. You could carry around your vaccine card as proof. And I'm given to understand, correct me if I'm wrong, but I'm given to understand that in all the contexts in New York in which you could be scanning your Excelsior pass to prove your vaccination, you could also just show your actual vaccine card. And this is this is also in the context of like events, concerts, sports events and things like that where you have a ticket that you bought with your credit card. The information is not anything extraordinary. I don't think that that even would be gathered. But also like these venues have also been responsible for personally identifying information as part of their business for decades. And so I don't see how this is much different. Yeah, and like the machine readable part for a large venue allows a lot of people to move through quickly. It would be much different, though, if that app also was advertising its ability to track your interactions with all 60,000 people in that stadium. But that I don't think is what they're trying to glean from the information. And an example, you had a couple MTA is another one. They have an app or the the transit in general is moving in this direction. They've started to have it so you can hold your phone to get into the subway system. But it's their system, right? It's not different types of systems like the mosque is is read in the article and so forth. So I don't know. There's some disconnecting of it, the fact that it is sort of voluntary. But as it's become as the adoption increases, I guess that's that that the ability and the capability, as well as the questions you might want to ask become myriad. There are so many more questions, I think, as you increase the amount of people using this kinds of stuff, you want to make sure that stuff's handled well. And what if third parties get it, get access to stuff if you're mining it or using it in really exhaustive ways instead of just sort of showing something that's machine readable? Yeah, absolutely. Again, it's a it's a voluntary system. But if it ever reached the point where you had to use that as your way of proving you were vaccinated and the card wasn't acceptable, I'd have a real problem with that. Absolutely. But I've never heard that said or even imply that it's going to be that way. It's just something that is easier for some people to handle. People might like to have something electronic. And I haven't, of course, other other states, other countries might do it completely differently. But what I've seen here, the Excelsior pass, it doesn't seem to be that. But again, that's no reason not to not to be cautious. Alex, did you have something? Yeah, sure. At a very basic level here, I think, you know, we're dealing with this issue of requiring vaccinations to participate in some activity or another, right, or even to in some instances to go back to the workforce, as a caller earlier had mentioned. But philosophically, I think we have to to reconcile something here or maybe correct a misconception, because we live in a society where you have a come out of the state of nature where we can do whatever the hell that we want to do at any time and to any person. And because of the social contract that we have between our government and our fellow citizens, we are a country that is governed by laws. We're a civilization governed by rules and norms and procedures. And when we live under a government, a government has certain rights and sometimes we have rights. But we have to realize our rights are not absolute. We may have the Bill of Rights, but that does not mean that those rights are absolute. The state has a lot of power when it comes to public health and our individual rights at some point have to yield to an extent when it comes to the harm of others. We're not giving away the kit and caboodle. This whole slippery slope argument, I think, is a real red herring here because we're talking about harm. We're talking about other people. We're talking about a duty to our fellow citizens. That is the whole reason we live in a society and don't live out in the jungle. I'm done ranting for now. For now. Okay. But you realize this is the same society where you can't even get people to wear masks, let alone get a vaccine, where people think they're victims because somebody in a Costco asked them to put a mask on their damn face. You can say that our rights are not absolute, but good luck trying to convince people that. Well, you know, they just need to go back and read some Thomas Hobbes, Leviathan, I'm sure we all recall. But speaking of masks, for the last week I was in Florida, by the way, last week and a half. And that was an experience, let me tell you, because it's as if the virus never happened in most places down there. When I was over on the West Coast, I won't say exactly where, but everywhere I went nobody was wearing a mask. It was bizarre. And inside too. And certainly, pardon me? Inside too, you mean? Yes. Oh, inside. That's what I mean. Yeah. I mean, outside, it goes without saying that nobody's wearing a mask in Florida. But inside, where I was on the West Coast, I couldn't believe how few people were wearing a mask. There was an instance where I had to pull off the interstate, grab some coffee at a 7-Eleven. And I went in there and I was kind of scared because I walked in there, I didn't realize that this was like a major truck stop or something. A place was full of people. I mean, nobody was social distancing. The line was going down one of the aisles. It was really crazy. And when I looked around, nobody was wearing a mask. Nobody. It was scary. I was the odd person out there. And I certainly felt like an outsider. And I felt like people were looking at me differently because I was wearing a mask. And they certainly were. I don't think it was a feeling. It was a reality. And I'm sitting there in a line, and I felt terrible because there was only one other person in the store that probably had to have 50 people in it, and it was a small store as well. One other person that was wearing a mask was a kid who was probably 12 or 13 years old. And he went up to the counter and he was trying to order two slices of pizza. Remember, you get two slices of pizza for a dollar. That was the sale that they had going on. That's how they get people to go to Florida. I guess so. But I mean, the kid obviously didn't have a lot of money. He's wearing a mask. He's up there. And I'm probably about 25 feet away from him. And I can hear him ordering these two slices of pizza. The guy behind the counter, who was three feet away from him, pretended not to hear him. I can't understand you. I don't understand. Oh, because you have a mask on. Until he removed his mask and forced him to say it without the mask on, then he heard perfectly clear that he wanted two slices of pizza to go. What an idiot. I felt really bad for the kid. I felt really bad for him. You should have bought his pizza, Alex. You should have paid for his pizza, at least. You could have done that. If I was next to him, definitely, but it might have incited a riot. The only reason these idiots are able to walk around like that pretending there isn't a problem is because a significant portion of people have gotten the vaccine. If it weren't for that, they would all be in the hospital within a week or two. So many of them would not survive. It's so ridiculous. I hope everybody gets through this, but that's not how you get through it. You get through it by the way we've been doing it here, gradually taking steps and being careful, being courteous. I have to say, all my complaining about how people have been misbehaving, I've never seen that myself. Every instance I've had going into a store or a place of business or even on the street, people have been courteous. Nobody has said anything insulting because someone has a mask on or has intimidated anybody. I know that's not the norm everywhere, but I've been lucky. I think most people are decent. Most people are getting it and most people care what other people think and care about their safety as well. Yeah, you really have to look for it. I've found, because if you are respectful and considerate of others, they, I think, are showing that same respect and acknowledging. Yeah, by that same token, I'm not saying, hey, meathead, where's your mask? I'm not like that, but I will cross the street. Not anymore, but in the past when we had to wear them outside, yeah, I would. You can laugh at me and say, oh, well, it never did any good outside. Well, you know, whether it did or not, that was the advice at the time and it wasn't much of a sacrifice. And if it helped in any way, I'm glad to have done it. And if it was not the right thing to do, okay, then we learned that. We learned something. You might have inhaled less particulates in your lungs. Yeah, I got some exercise crossing the street all those times. We have a phone call. Good evening. You're on off the hook over time. Good evening. Go for the hook over time. I can hear the hiss in the long distance connection. Listen to this. Hear that? Wow. Well, it's like the old days. Maybe you're standing by the ocean. No, I'm not. No, you're in Bulgaria. You don't have an ocean, right? Yes. Well, we have the Black Sea, but it's a bit far off. It's very late at night, Bobson, to be at the Black Sea. No, it's not. It's only 3.34 and that's by summertime, so it's actually 2.30. So how are things over there? Well, not getting out much lately. Why is that? Well, I try to as much as I can, but it's too many people walking around without masks on. I hear you have been crossing the street when you see such folks, but that's the wrong way to go about it, I think. Well, staying inside isn't the right way. The right way to go about it is to get them to cross the street when they see them coming your way. That's true, but you have to frighten them somehow. I don't know quite how to do that. Well, if you carry a large stick and you wave it at a distance, they figure it out. I miss him. I really do. How are things vaccine-wise? Is it readily available? Well, as far as I know, it is, but there were at some different times, different shortages here and there. And yeah, there are technologies to certify. Well, people who have been vaccinated get certificated with a QR code on a piece of paper that is linked to a database that a government-operated outfit is running to say that, yes, the person who showed you this QR code is vaccinated, according to doctors so and so. And the thing is, the way it works, at least the national certificate is a piece of paper, and when you show it to someone, there's a URL to the outfit that runs the database that they need to get into their smartphone, which then leads them to a webpage that takes control of their smartphone's camera, and they point it to the QR code on the piece of paper you're carrying. And then the QR code reader that's being transferred to their camera gives them the result from the database that, well, whatever the result may be, I've only tried it on mine, so it says so-and-so has been vaccinated, and his ID number is so-and-so, if it matches his personal ID, he's vaccinated. But this is only something that a medical person would use, right? If you buy a sandwich, a person's not going to do that, right? No, no, no, no, no, no. Anyone who gets the piece of paper can put in the URL in their smartphone and point it to the QR code on the piece of paper to get that certified, to go from the certification. Right, right. But this isn't being used... Not a normal person of any sort. I'm addressing the listener's concern before, this isn't being used to track your every movement, right? Well, if someone asks me to show it to him, I have the choice not to. Exactly. Another thing, a few weeks later, they came up with a EU-wide version of the certificates, and they have a lot more on their QR code, and I haven't played with that to see what comes out of it, but it may be linked to a Europe-wide database somewhere, but I haven't played with it yet. Well, that's the important thing, is to play with these things and figure out if there are security issues. Oh, well. Well, there's a few more things I wanted to mention over the past few weeks. First, I wanted to apologize to you and all of your listeners worldwide for the Eurovision Song Contest thing. Okay, you know, now, hold on a second, for the first time I was actually able to watch Eurovision, because I never get to see it, and I thought the Swedish band was really good. They were the heavy rock ones, right? I wanted to thank Finland for their entry, because they rocked. Well, no, maybe it was Finland. I can't remember. Sweden. I think I'm thinking of Finland. Finland was the one you played on the Eurovision show. Okay, I'm sorry. I'm sorry for mixing the two up. Finland, yes. And, of course, the winners, Italy. I thought they were great, you know, and rock and roll. It won in the end. The thing is, Italy gets a free pass on the semifinals. Did you watch the semifinals? No. Or just the finals? No, just the finals. There's two two-hour semifinals, so yeah, if you're interested. But basically, there's five countries and the hosting country that get a free pass on the semifinals to the final. I love how everything in Europe has to do with semifinals and quarterfinals and knockout phases. It's just, it's so complex. I couldn't figure out the voting in the end. The voting was so complex. Anyhow, the first five large European countries that started the competition in the 1960s get a free pass on the semifinals, so no voting is done on their entries. So Germany, Italy, the United Kingdom, France, Spain, and the host country, Germany, Italy, United Kingdom, France, Spain, and the host country get a pass on the semifinal votes, so they get straight into the final. The Italian entry that won actually won a very large competition in Italy, which is called the Sanremo Festival or whatever. There's an annual competition of Italy that's been going since the 1950s on which the ESC is based partially, but the winning entry of Sanremo winning ESC is a bit, I don't know, I'm not happy that Finland didn't win. Well they came up with a great song, and the thing is, the weirdest part about all this, we keep talking about, we're saying Finland, Italy, we never say the names of the bands. That's what's weird about this whole competition. It's all countries. Oh well, I don't, I could look it up if I wanted to. Yeah, you can look it up, right, but it's just, it's interesting how it's nationalized. And I don't remember the name of the band, so I apologize to the Finland entry. What was the Bulgarian entry? Well, it's even less memorable than the other, however many. I like the Iceland entry, did you like that one? Iceland? Well, yeah, but it's kind of silly. It was, it was. It's the kind of silly that captures my attention for a while. They were playing, what, cellos at the beginning or something? It was kind of classical. The what? They were playing, I think, cellos or violins at the beginning, and it just, uh. And also, it's a family, a family of folks, it's like a, someone who's singing and his wife, his sister, their cousin and something like that. Oh, I didn't know that, wow. Interesting. The Iceland entry. Well, I just thought the entire, the entire event was interesting, and it was like, it went on without a single. You may enjoy watching the two semifinals. Yeah, well, if I know about them, you see, I learned about this the day it was happening. They're all on YouTube. That's true, but I learned about it, I learned all the songs in one day, they were all very easy to remember, and there were no commercials throughout the entire thing, which is unheard of in this country. Well, it's a four hour late at night type of thing, so who would be selling bubblegum at that time? Uh, turn on the TV in the United States at four in the morning, and you'll see everybody selling everything. Yeah, I've done that. I didn't enjoy it. Another thing I wanted to mention, I've had an idea because of a phone call I got at Overtime a bit more recently than that. One of your listeners was complaining that you don't talk to people on the side that's not very happy about vaccinations and such. One thing she mentioned is that very low doses of hydroxychloroquine have been shown by some people to be useful against the pandemic, and that gave me the idea that if we can arrange for a patent on homoeopathic hydroxychloroquine, if we set it up so that 85% at least of the proceeds on the patent go to WBAI, that might be of some use. That's a hack right there. That would definitely be... I like that. Yeah. That's the way to think. Good thinking. Well, if you want to do that, I don't mind, too. Might make YouTube mad, though. Yeah. We have to think about that. We have to live in fear. Alex, you have something to say. YouTube? Oh. Yeah. We're on YouTube. Sorry. Go ahead, Alex. You do make a great point when it comes to supporting the station. It should be noted that like any other charitable organization, if you are leaving this earth and you have to bequeath some kind of intellectual property that has a recurring royalty fee to the station, I'm sure we can figure out a way to accept it, and Bobcat's absolutely right. I mean, these things are often... This is Bobson, not Bobcat. That's a different listener. I'm sorry. I've got Bobson. Yeah. I just insulted both of them. Yeah. I got carried away. That's right. And in any event, yeah, it's possible. You could actually do something like that. You can bequeath some IP to the station that can give us some annuity-like income. But does the station... Think about it. The station has to monetize it, though, right? Or would there be some kind of arrangement? We'll figure out the details. Why are we talking about this? We'll figure out the details. We're not even on the station right now. We're assuming that it's already monetized in that sense, right? That there's already a system in place that is self-perpetuating. Self-perpetuating. Yeah. Well, I don't plan to patent the homopathic hydroxychloroquine myself, so... I just want you to keep saying it. I just want to hear you say it, because you say it so well. I've been trying it out. I've been practicing with it, I guess, because I thought you might enjoy the... I can see Dr. Bobson recommending it to his patients. I don't have patients. You have tremendous patients. Yes. To talk to us... Yeah, absolutely. Impatience. Anything else, Bobson? We're going to move on. Well, I... Oh, yeah. There was another thing I wanted to mention. Congratulations on the blue checkmark on that database for short passages that you were so happy about. But I was... When you started talking how happy you were about your blue checkmark, I remembered another person who had a blue checkmark, who was the holder of the highest office in the land over there, the 45th holder who had the blue checkmark. Yeah. We know who that is. Yes. A few months later, got banned from their database, so... Which opened up a blue check. It opened up another blue check. This is... It's not hard to figure out. They're recyclable. Yeah, absolutely. Not transferable, though. Oh, yeah. I understand you are happy, but maybe it's not too much to be happy about anyhow. You know, I have to take whatever I can get. It is a little bittersweet. It is. We hear you. Yeah. We hear you. All right, Bobson. Good to hear from you, as always. Thank you for your time. Have a wonderful evening. All right. Take care. All right. Call the Bulgarians over there and tell them to get a damn vaccine and put their masks on. Well, I... Most of the people I've talked to about it, too, about it, have reportedly... Call us again. Yes. All right. Well, someday. Thanks. Thanks for calling in. I'm not saying next week, but someday. All right. You're always welcome. Bobson from Bulgaria there. Definitely a highlight of our show here. Our phone number still is 802-321-4225, 802-321-HACK. And yeah, that's what's going on over there. What else we got? Here's a headline. Ransomware attack hit Teamsters in 2019, but they refused to pay. Is anybody surprised? Is anybody surprised by that? Expect Teamsters to pay ransomware? I could just hear the conversations. This nerd, I swear. If I find the guy... I'm going to get my hands on that guy. Not giving him my half of a sandwich. Hey, well, look, that's very heartening because it's good use of union dues, right? I mean, they don't come cheap, and I think the union's been protecting the workers and discouraging ransomware being deployed against other unions. So I see this as a great victory for the worker and a massive defeat for the ransomware as a service criminal enterprises. If you had your record stored on the Teamsters computer system, please send them your information again as they're recompiling it and rebuilding it from scratch, but they're not paying. All right. We have another phone call. Good evening. You're on off the hook. Go ahead. Hey, thanks. This is the Gibson from Hackers.Town. We spoke last March at the beginning of the pandemic, and we also presented the hook right here. So thank you for that opportunity. Hello? Yes. Go ahead. I'm sorry. I'm sorry. I was arguing with our... We have a robot. Yeah. The robot was going nuts. Sorry. I just wanted to thank you guys for the opportunity to speak at Hope last year, looking forward to next year, and on the matter of ransomware, my team, I lead a team of threat intelligence professionals that work on this problem day in, day out. One of the things that we have found and that we find is a flaw in all of this is that everybody talks about the ransomware bomb going off at the end of this, right? Usually that's covering tracks on the way out the door for the criminal. The part of this in the modern ransomware delivery method that people don't talk about is the botnet infection that leads to it. Right. Right. There's anywhere between 11 to 42 days of time that the botnet will be in place before the deliverable is there, giving the attacker plenty of time to really figure out how to evade defenses. Right? Mm-hmm. So... And how to infect backups, too. How to infect backups that are stored locally. Right. Right. And once... And you know how this works. I mean, once you've got it squared away, they're done. Right? I mean, there's no defense, and you're going to be in the position of having to either pay or rebuild like the Teamsters did. The Teamsters' situation is kind of amazing, and I applaud them, frankly, because it takes some testicular fortitude to do what they did. And I was joking. I was joking about them rebuilding. I don't know how they got out of it, but I don't know if they had to rebuild. According to my sources, they rebuilt from scratch. Did they? Oh, wow. My joke was right then. Yeah. I mean, that's what I've read about it. I don't know anybody who was involved in that particular one, so I can't say for sure, but... Okay. Well, good for them. Anyway. Yeah. So, you know, one of the things that can be done, you know, as we all understand as hackers going back a bit, you know, data in transit is data that's vulnerable. Right? Anyplace data is exchanged, it's vulnerable. And there are methods in play that you can use to detect those botnet infections from outside of the network. So, beyond the walls of the castle, so to speak, you're able to hunt this and then detect and notify whatever team is infected with that, or whatever organization's been infected. And you can take away the time that the attacker has. Right? This is a thing that isn't in play very much yet and really needs to happen, because there's two kill chains to this, and we only talk about one of those two. We need to push back through time to that first kill chain, which is the botnet infection. And when you do that, you give yourself a lot more capability of surviving one of these without incident. Yeah. Absolutely. Yeah. It makes for an entry point in the lifecycle of it far earlier, so you're responding to it with a lot more options, I guess, ultimately. Right. Well, the thing is, it's the thought process around it. Right? If you assume that you're already hit with ransomware somewhere out in the future, and you know this is going to happen, let's just, for the sake of the thought experiment, say that's going to happen, and you accept this as an endgame, then instead of playing a game of siege, right, where you're preparing for a siege, effectively, you're able to think in a different position and look for those indicators. Most InfoSec teams don't think like this. Right? Most of them are focused on endpoint detection and what's going to happen at the last second, and that should be your last circle of defense. Right. So, you know, getting in that position where you can assume that you're going to get hit, that puts you in the mindset of being able to look at it differently and say, okay, well, how can I avoid getting hit? What can I do differently? Well, one thing, you might not be able to avoid getting hit, but you can certainly construct something so that you can rebuild quicker, like have a tape backup that is off-site that you can restore from. Yes, it'll be a pain in the ass, but it won't be catastrophic, at least. People make the mistake of keeping their backups, you know, on the same system, and of course they get infected as well. Or network-attached storage, or a drive that stays connected, or it's in the machine, like a second drive, et cetera, et cetera. Restored someplace else entirely. Or, God forbid, a service that is also compromised maybe because they're already looking through the kinds of logins and stuff you're doing, et cetera. I mean, cloud backups could be a good thing if they don't get compromised in a different way, you know. There's that as an option as well. Alex, did you have something? Yeah, I want to say I entirely agree with our caller in that the way to get ahead of this is to be more proactive, be aggressive, and this concept of difference in depth, which is only with respect to the castle that you're protecting, is largely antiquated. You have to be out there. You have to be acquiring good intelligence. But with respect to those botnets, too, and I would like to get his thoughts on this, is that one of the problems is something like fast-flux hosting, where the addresses are constantly changing, and we may be able to identify where a good number of these bots are and identify good portions of the network. But again, it's always changing. It's always growing. It's an amorphous sort of animal. And in order to take these things down en masse, take down lots of different hosts that belong to a particular botnet, requires process. You can't just do it. You can't just go to one single service provider and flip a switch. Taking down a botnet requires generally legal process, filing an action, and getting a judicial order to take down a massive network. Or on the other hand, one alternative here would be then to have some sort of memoranda of understanding in place amongst service providers and perhaps governments that would allow certain types of takedowns to be effected without that type of process. But then when we're giving up that due process, we're giving more power to government. More power is in their hands, and then that can be abused. So I'd love to get the caller's thoughts on that. So I can't give away too much of my secret sauce here. What I can say is I am less concerned about shutting down the botnets themselves for what we're doing, what we're trying to accomplish, and more concerned with detecting when they have infiltrated a network that we're protecting. I do very much agree with your take on aggressive blue teams. This is something I talk about regularly, and it's very much what has to happen. The idea of just defending the assets that you support is an ancient way of thought at this point. It started to become that way when we reached into the cloud, and then we decided, OK, well that's just another part of our castle we have to defend, and that's fine. But with the pandemic and workforces going further afield, suddenly you're in a situation where you have so many attack surfaces. They could be anything from a local router at someone's house all the way up to your cloud environment, your on-premises environment, whatever it is. And as such, the idea, the concept of just defending the edge of your asset, even the concept from five years ago of the endpoint becoming the edge of your network, that doesn't work anymore. So becoming more intelligence-based and attacking the threats further back the timeline is the way I like to talk about it. I always hate people that use Sun Tzu as an example, but there is something there that applies here, that we get to choose the battleground, right? And if we get to choose the battleground, we should choose the battleground that benefits us, not the aggressor. As such, we think of these battlegrounds as the edge of our network or the edge of our whatever, whatever our assets are. The truth of the matter is that battleground is time. It's not the edge of the network. It's the time you have to respond to an infection or an attack. And in order to be able to do this, we have to get better at the intelligence we gather to warn us that this is coming. So we, on my team, and like I said, I can't get into too much detail, but we do the same thing that governments do, frankly, to spy on their own citizens. Yeah, I said that. But we're using it not to violate the privacy of individuals. We're collecting metadata, right? We've got listening arrays we're collecting metadata with, and it allows us to pinpoint where these infections are at when they're inside of an organization. And then we can reach out to that organization and work to remediate before they get hit. And that's kind of the model we work with. So, you know, my focus is a little less about that, although I do agree with you that we have a situation here where governments themselves are slow to respond to this sort of thing. Even at their quickest, I mean, it's bureaucracy. It's going to slow things down. I don't believe that's a negative, necessarily. So, you know, what can be done there are effectively the same as a nongovernmental organization to provide defenses against these sorts of botnets and networks, these threat actors. And that could be organized through, first of all, let me say I am not a free market capitalist kind of person, but what I am saying is that we could put together our own organizations effectively that offer these defenses to an area. If you look at Australia, for example, last week, their intelligence agency started warning Australian organizations of these botnet infections. It's kind of the same as what I'm describing, right? We've been working on the same concept in two different places, it turns out. So them providing that sort of intel ahead of time to warn those that are about to be impacted is exactly what I'm talking about. The idea of a regional defense shield, for lack of a better way to put it for this, might be very plausible, and it might give us the ability to respond to these things in a timely manner instead of waiting for a federal or even state government to move. You need to write an article for 2600, you know that, right? Yeah, I can do that. That's not a problem. This is the stuff that we do all day long. And like I said before, you guys are legends. I know who you are, and I respect that. So thank you for that. I'll take it as a compliment. And if you want me to write something, I'll put pen to paper. Absolutely. Definitely. And keep doing what you're doing and spreading the information. Yeah, that's why everybody's having more intelligent conversations about it, and we love hearing an in-depth kind of take, and it's valuable. So please, if you're at all interested, we'd love to share what you know and help other people get educated. Absolutely. And Alex, I know you do a lot of threat intel yourself with some of your tools that you've developed. If you want to hear more about what we're trying to do here, I'm happy to have that discussion in private sometime. Even over email, but I don't want to broadcast exactly what we're doing because I could offer comfort, so to speak. So we don't want to go there. Okay. Well, you can connect to us, othat2600.com, and we can get back to you individually or however you want. Sounds good. And to say to the caller, you were reading my mind entirely. It sounds like a lot of the work that you do, we do some sort of analog of in the DNS. So maybe there's an opportunity to collaborate there. That started on off-the-hook overtime. Oh, boy. On 16th of June. I'd wear it like a badge, Alex. So, yeah, we can talk about that. As would I. Let's carry that conversation offline for short. And thank you so much for the call. Yeah. Thank you. All right. Take care. Good night. Wow. Interesting call tonight. Absolutely. What a great call. Yeah, totally. When the calls come in rolling like that, one after the other, but please stop because we're tired and we want to go. We've just cleared our hour. Yeah, we sure did. Two minutes after nine. And some of us haven't eaten all day. And all sorts of other challenges. Well, we don't want to wear out the Internet either. No, exactly. And on that subject, by the way, I don't know if anybody else has noticed this. I'm looking at our broadcasting. It says excellent connection right now, but a few minutes ago during that call, it said no data. And, in fact, there was a little spinning wheel at one point. So if anyone out there is listening to this and there's a cutoff in the YouTube program, if the audio cuts off, let us know. Email us, othat2600.com, because we have a local copy we can replace. That does not have that happen. Someone's not listening. No, no more calls. No more calls. Please. We're done. But, yeah, if we're not posting entire copies here, we need to know about that. And, yeah, that's something I just noticed right now. Yeah. I was updating some things, so maybe... Did you take the Internet? Maybe I broke it. I don't think it's affected, though. I think that has been an issue, but I'll work on that. It just said no data and there was a spinning wheel, so I just was concerned. The machine you're using for that could use some better connectivity, I think. Oh, I'll criticize my machine now. No, it's not the machine. It's the connectivity. If the entire call is intact, then we're fine. But if it got cut off, it got cut off in that call. Anyway, enough housekeeping. Good to be back. We'll see everybody next week for both Off the Hook and Off the Hook Overtime. Again, write to us, othat2600.com. We'll see if somebody tries to take the show off YouTube again. See, it's doing it again. It's spinning. It's spinning. I don't know what it means. It's YouTube. We'll be back next week. Good night, everybody.