I видел your camera Gal actually sent a video to the posh lady And It's now seven o'clock. You're listening to WBA I New York and That means it's time for another edition of off the hook But if they could I Don't know And It's another exciting edition of off the hook and then you're hosting here with you on this Wednesday evening joined tonight by Kyle Yes, I'm here and over in Skype land where my voice always changes Skype land we have Alex Who apparently is oh, there you are, okay, you're in a long delay tonight Yeah, I was on Myself Is someone playing a video game in your house because boy you're you're you're not sounding that great I Would I would check your connectivity? Okay, yeah No right now Let me shut up barely make on anything you're saying you are on earth though, right? Yeah, I don't even know does If he wasn't on earth, we'd hear him a lot clearer. You think it would be better So Alex do some troubleshooting Rob T firefly welcome good evening and Gila Hello, we were not on last week, but we are on now and we're gonna make up for it. We have Over time coming up at 8 o'clock You can go to our YouTube channel channel 2600 or just click on the link on the main page of 2600 comm Meet us there at 8 o'clock you can make phone calls or listen to this hour where you can't because we're broadcasting all sorts of remote places and Trying to catch up with various news. Here's some good news. I always like to start with good news whenever possible Cryptocurrency platform Polly Network said on Monday that almost all of the six hundred and ten million dollars stolen this month In one of the biggest crypto heists has now been returned by the unknown person or persons behind the attack Yeah, who says? Hacking doesn't have honor In a Twitter post Polly Network said it had regained control of all the assets except for thirty three million dollars in stable coin Okay, I'm trying to understand what I'm saying here a stable coin tether is that a thing it's anybody know Nobody knows. Okay. We're all again here You know something Alex yeah Barely Heather is the coin that is pegged to the the value of the US dollar and is backed by certain other types of assets Okay, well the network said it was in talks with tether about unfreezing the funds The hackers had previously said they did the attack for fun Like doing something for fun that carries over 600 million dollars with it They did that to expose a vulnerability in the platform's digital contracts, I'd say they found one It was always their plan to return the tokens Some blockchain analysts have speculated. They just found it too difficult to launder so much stolen cryptocurrency You know it's always somebody there You know to cast aspersions and to say that their intentions were not good look they returned a Lot of it most of it the vast majority of it if they kept 33 million I don't know if that's such a big that is a big deal a Lesser known name in the world of crypto Polly Network is a decentralized finance platform that facilitates peer-to-peer transactions With a focus on allowing users to transfer or swap tokens across different blockchains But I'm sure they never intended for the tokens to be swapped like this I guess it's a happy ending right I mean They're still out 33 million dollars, but I guess that's nothing compared to to what we were facing or they were facing Yeah, and and look I think the part of the lesson here, too Isn't this something that we've been saying for a while, and I hope you guys can hear me a bit better much better This is any better. Okay good It is that it is actually very difficult to launder significant amounts of cryptocurrency and turn it into fiat currency turn it into real Money that you can use in the real world. It's hard to push these things through what would be known as coin swappers or tumblers that Push these coins through and make it very very difficult to trace because you're turning them into do other different types of coins other currencies And essentially putting it through a clearinghouse type of effect, but there's lots of new Heuristics that you can use to identify Residual bits of coins, there's lots of different tracing mechanisms that are out there and I'm actually working on a couple of different matters right now where we're tracing Cryptocurrency that was stolen and having a great deal of success with it It's just sometimes very difficult to claw it back in a reasonable period of time But finding cryptocurrency edged out into fiat currency can be really really difficult. I would venture to say that these Ransomware attackers people are doing ransomware as a service or the rivals or the are evils and They probably I would guess maybe take ten or maybe fifteen percent of whatever their haul is and cryptocurrency out into the real world Alex let me ask you as one involved in this. Do you find it harder to be able to retrieve funds that have been stolen or Funds that somebody has managed to lock themselves out of either by Forgetting a password or losing a hard drive or having a corrupted hard drive or various things like that Well if in certain instances, I think it's it's nearly impossible to get funds back if they've lost the keys to a wallet There are certain things though that depending upon how the cryptocurrency works in the smart contracts that underlie the cryptocurrency work you may be able to do certain things like Make a notation on the currency itself that was lost that indicates that it's Essentially blacklisted or it's banned from any future use or or being transferred at which point once that cryptocurrency is banned or sunk You may be able to have an exchange or a coin reissued for that particular currency, but the exchanges and You know and the platforms that run these coins They don't like to do that that often and it's a very long and burdensome process to prove that you are in fact The owner of those particular coins It's it's pretty rare but it does get done and I think that it's harder to get that done in a situation where you may have just lost the coins as opposed to Tracing out coins because it there are certain ways where you can trace with damn near certainty The route that certain stolen funds have taken from the victim through various coin swapping services or tumblr services, you know and and find where they Actually freeze them where they end up Before they are further transferred or edged out into fiat currency or pushed out through an over-the-counter service So in the situation of theft, I feel like it's easier to make that case Is there anything you could? advise people who are maybe just dipping their toe into the world of cryptocurrency mistakes not to make ways to ensure that their their Funds don't go missing or get lost or get corrupted or anything like that Types of backing up that makes sense things that you they they shouldn't do. I Think a lot of I think there's a lot of common sense that goes into this and you know how you treat your your wallets and a Very hard passwords use some kind of passphrase as opposed to a password. Don't use passwords that you've used elsewhere To to secure your cryptocurrency walls, but I think a really great piece of advice these days especially is to be very very wary of Scams that involve cryptocurrency phishing scams voicemail scams smishing scams SMS scams There is a massive amount of energy and activity directed towards stealing others as cryptocurrencies especially from some of the larger exchanges and this is the kind of activity that I Watch in the DNS and the domain name system every day and the volume and velocity of phishing attacks targeting Cryptocurrency holders, I think because there are more and more cryptocurrency holders every day and a lot of people aren't necessarily That familiar with the types of scams or how they work Or the mechanics of various KYC or know your customer requirements from all of these exchanges that that can be exploited Very very easily for a new user or a new holder of cryptocurrency. So be very very careful of these scams Be very careful as acronyms Alex because KYC pronounced says kick and I don't think that's what you want to do to your customers I know you love that Right, you know Okay. Hey, well, we've got a really interesting story here that we're gonna be devoting some time to Involving the Taliban. Yeah, they've seized u.s. Military biometrics devices that could aid in the identification of Afghans who have Assisted coalition forces current former military officials have told the intercept The devices are known as hide HII DE handheld interagency identity detection equipment They were seized last week during the Taliban's offensive that's according to a joint special operations command official and Three former US military personnel all of whom worried that sensitive data They contained could be used by the Taliban by the way. That was actually two weeks ago The story I'm reading is about a week old hide devices contain identifying biometric data such as iris scans and fingerprints as well As biographical information and are used to access large centralized databases It's unclear how much of the US military's biometric database on the Afghan population has been compromised It was billed by the US military as a means of tracking terrorists and other insurgents But now biometric data on Afghans who assisted the US has also been widely collected and used in identification cards According to a US military contractor. We process thousands of locals a day had to ID sweep for suicide vest weapons Intel gathering Etc. Hide was used as a biometric ID tool to help ID locals working for the coalition and It's basically this is this is really shocking we know the US military has long used these devices in the so-called war on terror and Use biometrics to help identify Osama bin Laden during the 2011 raid on his Pakistani hideout according to investigative reporter Annie Jacobson The Pentagon had a goal to gather biometric data on 80% of the Afghan public To locate terrorists and criminals and now those devices have fallen into the hands of the Taliban so you can imagine What that could mean for people's safety? We have on the online with us Will burn the director of human rights first innovation lab Who knows a thing or two about what is going on here? Well, welcome to the program Thank you for having me so this is a big deal is it not It is we are very concerned about multiple different ways that the Taliban are using technology, but the advent of Biometric Data that could be in their hands at a relatively large scale across Afghans in the country is It's unprecedented certainly in a humanitarian situation Like what we're facing in Kabul Do you know how how big these devices actually are physically? Yeah, so the the handheld devices So there's a number of issues and sort of bits of the technology as we understand it that are in in Play so the handheld devices Were used by coalition forces and they're essentially like a you know, almost like a large Gun, right Almost like the size of a like a super soaker or something very strange looking devices They do have capability of storing some data in the machine that can be pulled from we are to understand and so those devices were being used as you mentioned to actually Create databases of Afghans that were working with coalition forces So that database from the standpoint of the Taliban, right? It's like a laundry list of the type of folks that they would want to go after those particularly Concerning there's actually quite a bit more data biometric data that's out there in Afghanistan on Afghan citizens the 2019 election used biometrics to register Afghan citizens that were voting so The there's there are questions on the intelligence right now whether the Taliban actually have access to these databases So whether they can actually ID people that they're screening through existing cameras And potentially these hide devices we are operating as if they have that potential or they will have that potential So as a human rights organization One of the things that makes our organization unique is that we are Being with we post fellowships with technologists working in emerging technology big data products, etc. And we've issued a guideline that really became quite No viral is the word quite circulated on social media around how Activists on the ground and citizens can evade tools like facial recognition and Fingerprint as well as iris scan Efforts that could be used by the Taliban now when you say it could be used by a Taliban a number of sources in this intercept article actually Says that it's quite possible that they they would need additional tools to be able to process the data But if say an entity like Pakistan were to help Well, then they could probably do it quite easily. They they have these tools. So having these devices having this data We might as well assume that they will at some point have access to all the information Correct and that's what we're doing. We're we're we're we're we're we're we're we're we're we're we're we're Raising whether it's whether it's via Pakistan Special special see I guess secret security We know they have the capability or it's or it's others it's it's essentially a Wild West scenario right now in terms of Data that is available to the Taliban for use of identification We have a Saigon level Humanitarian crisis unfolding currently in Kabul people Putting their lives in danger In the hundreds or thousands trying to get into the airport with evacuations imminently shutting down most likely for Afghan and but Saigon did not have this element at play in terms of This level of ability of a hostile Potentially Revenge oriented Power that now has access to could have access to this database and the tools to Use it. So it's one of the things that we keep coming back to on on this program is basically imagining Technology both it's good aspects and it's bad aspects, but we always ask ourselves Well, what if the Nazis had this particular technology? What would they have done with it and you think of things like databases and just basically technological ways of tracking and finding people and That might make something that seems like a great advantage Into something that could be a terrible nightmare and I think that's what we're beginning to see right here But one of the things I wanted to ask you will is these devices are handheld. How were they left behind? How how did they manage to fall into the hands of the Taliban? We Wish we had a good answer for that as the is the most direct way I can respond I can see you were filtering quite a few possible responses there Yeah, it's the pace with which the withdrawal happened What was incredibly disorganized and And it's it's it's caused all kinds of problems Is there a way perhaps that these devices can be bricked remotely or accessed in any way like, you know Something that Apple might do That's something that we and partners are looking into there are it appears to be Some companies that could have the power to shut down access to Remotely shut down access to some of the data that's in play So that is something we're working on. It's not it's not an Apple or You know, it's more data security firms that have contracted with the US government So that is possible. I mean the other element of this that we're sort of dancing our way toward is you know with this issue of Retention of biometric data in unstable societies and unstable you know political economies is I mean this this we hope will not result in Really even more tragic outcomes, but Hopefully this sends a very clear message that we need we need policies and protocols in place If we're ever going to be collecting biometric data at this scale for Securing remote deletion of that data in instances like this, you know I would think that would be something that we would have concluded decades ago But we always see the stragglers and don't seem to get it until something like this happens Rob. You had a question Yeah related to all that. Well, thanks for joining us tonight But I've been thinking about this a lot and they had to realize that they had, you know cutting-edge military equipment bought with you know, the the 20-year long budgets of everything that was being poured into the occupation there and It seems crazy that no one would have planned some kind of failsafe for like what if we leave? Where's the switch that we should pull to make sure that this stuff isn't useful to those who? Who would pick it up after we leave it behind or should we bring things with us like in? In in more perfect worlds like what would they what should they have done? when shutting this all down when when leaving to to ensure the safety of the people who cooperated with the coalition or Just just people in general Who might have ended up in these databases? Yeah, and it's it's relatively intuitive for once it come once you stop and think about it, right it's If you are going to put these systems in place in this level of collection and database You know, you're populating databases like this in an unstable situation where that data could be repurposed for grave harm and humanitarian Transgressions should we say then as part of a contract if you're a technology company and the US military is is Reviewing that contract that the it's not just about contracting the military itself needs to have a clear game plan on a Simple and efficient way by we by which this data can be Can be shut down and deleted from from from external access so This is a conversation that needs to be built right and and grown when it comes to biometric by use of biometric technologies Yeah, the other element is to say it quickly. Is that in in creating a guide on how? You know people can try to evade these technologies for example If you're walking in the public square and you've got you've got cameras on you with with this type of technology operating in the back end It's very hard. It's very hard for to evade these technologies There's you know, not to go into too much detail, but even you know, people think putting a wig or glasses up Will work if these are detecting the bone structure of your face And are highly highly Effective go ahead. Did you have something else Rob? No, okay Yeah, well, thanks for coming on with us and in full disclosure I also work with human rights first on the technology advisory board and I would like to invite everybody To take a look at the biometric evasion techniques that human rights first has published they're available on human rights first org and perhaps we can tweet this out and or maybe put it in the show notes because Those tactics and techniques for evading biometrics. They're really interesting Because what the the document gets into you dig into it is How effective some of these technologies really are and how difficult they are to evade as well as I had mentioned but there are also some very simple recommendations for Decreasing the probability that you would be detected by a biometric identification like facial recognition systems Sometimes it's as simple as taking an evasive measure like putting your head down, you know things like just that easy we're we're kind of Surprising to me to see in the document. So there are things I think that we can all take away about evading biometrics if we need to and and quite frankly Afghans who need to be evacuated who worked with US forces are not the only ones facing biometric surveillance on on massive scales these days Unfortunately, but will I want to ask you it and and I think what human rights first is doing on this front is is absolutely Great critical cutting-edge And I'm not saying that because I'm no partial to to their efforts But could you talk to us a little bit more about what human rights first in general is doing with respect to? Afghanistan on the tech side and and elsewhere because I think there's a lot of efforts underway And I think you're involved in quite a bit of it Sure, so at a high level part of what makes the effort of human rights first as a human rights organization unique is that we essentially have a incubator of technologists that we're supporting to Apply, I mean build with code Applications and tools that are Useful now in the fight to protect people's human rights so those tools range in our first cohort and I should mention we'll be taking on a second cohort of Applicants and we'll be putting out an open call To technologists to be a part of our next cohort this fall. So would love to work through your all's channels to get the word out to Right now we have for example a computer vision AI tool that is really at the cutting edge of computer vision Capability focused on detecting violence and use of force in video to flag that for human rights by violation and researchers and journalists and and others we have a number of tools that are Being used to counter violent at register and track and Surface violent white extremists And their networks by scraping across many different data sources online and applying natural language processing and machine learning To identify so we have that tool working with pretty In tandem with some pretty high profile Prosecutions That are underway in that area and then I should mention We have a tool that is also using machine learning to track incidents of basically through language on social media incidents that are likely related to Human rights violations and that's something that we have in prototype that we're getting ready to apply for monitoring in Afghanistan and so we're actually scrambling to get translation Language capability in place for Pashto and Dari, which is the local languages In place there, but that's Unfortunately, we are transitioning now from this sort of evacuation moment to what will most likely be a rolling human rights crisis In Kabul, and so we are looking to apply the best technology we can to Speed up our ability to detect where issues are happening so it's a really I Just started in the role here as someone that's worked in at the sort of intersection of technology and social justice My whole career. It's completely unique what the organization has been able to do and actually attract real technologists and people like you Alex to advise us, so Really appreciate the opportunity to join you all and Happy to hopefully build the build the conversation even outside of this recorded one Of course, it's it's it's so important the work that you do and I think that it'll It'll impact a lot of people who are listening I want to read something from someone else from human rights first Welton Chang who said I don't think anyone ever thought about data privacy Or what to do in the event that this hide system fell into the wrong hands, well, I'm changed chief technology officer moving forward the US military and diplomatic apparatus should think carefully about whether to deploy these systems again in Situations as tenuous as Afghanistan. I would say, you know, they they should have thought of it before they did it this time Because the risk just seems so obvious maybe it's because we do a show about this type of type of thing every single week but I don't know how they could miss the potential threat of Having all this biometric data. I see that 80% of the of the Afghan population that was the goal of the Pentagon and I wonder you know, is this something that is Is being rolled out as a test so that they can do it here at some point I find that usually things are tested first either on the battlefield or in prisons Before they're rolled out to the general public and by the time it gets to that stage they've they've perfected all of the Imperfections and they've made it palatable So people are willing to give up a little bit of privacy and freedom for the convenience. Do you think that's? That that's a realistic scenario what what I'm envisioning here well Forgive the humor, but if that's the case They're doing a very poor job of branding Branding this technology. I don't think this is something that's made it more popular in the eyes of American citizens. I would hope I Would hope so too. They they've gotten criticism, but you know, the only real criticism that That I can see here is back in 2011 The Government Accountability Office criticized the Pentagon for not doing enough to ensure that other Agencies had easy access to the information that they were gathering So it wasn't that they were upset that they were doing this and collecting all this biometric information on regular everyday people But that they didn't make it easier to share that information Through every agency that was interested in looking at it, and I think that you know, that is the kind of cluelessness I think that is the theme here where they just don't see that this is bad Collecting all this information and storing all this information is a horrible thing and I think we're going to see that play out in unimaginable horrific ways yeah, it's a Last thought I'll share on this and then I'm actually involved in some final pushes on evacuation happening in Kabul, so I need to jump to that but You know the There are reasons that there are not just the United States government and governments that are using biometric technology To to create this data NGOs are doing this as well And in some instances there's been justification I mean the World Food Program had a biometric Program that they started for for refugee camps And the logic behind why you why it's useful makes sense in the instance that that you're using it, right? It was logical that the United States would be trying to screen Folks they were contracting with in the Afghan population in an unstable wartime environment. It's logical in the case of you know sometimes some of these programs are creating identification for people that have lost their Financial and legal identity and they have no record of it because they are refugees for example, and so there's this notion that It can help with that that makes sense but but not having a plan in place for What happens with this data? How how is it actually secured? If the if the program's completely overrun is untenable Can't can't can't happen again, and I would agree with Welton that you know, it may be best practice to Avoid collecting it all together Kyle very quickly because Will's got to help with the well, I think it just speaks a little bit to the the way we Characterize terror a terrorist. I mean the number you were reading was 80% was that 80% of the population I believe that that was that was correct. Yeah amazing that it's billed as something to just really organize control And and reference a database of terrorists and those are the that's the only implementation for it and it creeps into Well, most everyone needs to be a part of this just in case or so We can go back and make sure we don't miss anyone But I believe the information also Indicated if this person was someone that could be worked with or someone who was cooperating and that's that's the real danger if I'm not Mistaken that that information is also Stored as part of the notes on the people's is that correct? Well I believe so Okay, so it's becoming this sort of like universal tools. Yeah database of everybody Alex I'm gonna give you the last word because Will's got to go Yeah, sure. And and thanks again well for hopping on I I think this data if you think about just the ordinary course of business records that the US government is going to be generating in the course of a 20-year occupation There's going to be paperwork there's going to be other data and files that are associated with these Afghans that have assisted US contractors and if Those are tied to an identity and then that biometric data becomes available Let's help. Let's say with it with the assistance of the ISI or or some Technically adept members of the Taliban then it becomes very very problematic for these Afghans I mean if you think about the fact that you know, this is really a failure of data governance and and data Retention policies frankly if you think about it from a private sector perspective, what if Afghanistan had its own GDP are you know? How would we deal with this? This would be a major breach this happening in the United States? there'd be plenty of state laws that regulate the use of biometric identification technologies and The release of which would would start a flurry of class-action lawsuits Against whatever contractor this was or whatever private entity this was but what are you going to do against the government of the United States? Especially when it was occupying or at least you know residing in Afghanistan for so long I think the doctrine of sovereign immunity would prevent anybody from seeking redress or legal remedy in the courts of at least the United States, but I mean, I think Afghanistan this is a case in point It's crazy to think though that when we talk now about Afghanistan passing laws That we're talking about the Taliban passing those types of laws So fat chance that I think data governance and regulation of biometric technologies is going to hit on the legislative agenda anytime soon Anyhow, well, I know you've got a jump It's wonderful to have you here and unless anybody has any parting comments or questions I think you know, we'll let you get back to it and And thank you for your time just on behalf of Afghans Americans and people all over the world Thank you for what you're doing. It makes a difference and we need more of it Well, thank you, thanks for having me to see you all soon, all right, good luck and And that was that will burn the director of the human rights first innovation lab now since you're involved that organization Can you give website information and ways people can get more information and and get in contact and help out perhaps? Yes, sure. Absolutely. And I do want to mention that that quote from that you quoted from Welton Chang Welton was on our show if you recall maybe about six or seven months ago He was also from from human rights first and and so pretty pretty funny you picked that quote human rights first you can find them at human rights first org I Think it's a you know a fantastic website. There's a lot of information there You can find I think pretty easily the biometric evasion Technique document that will and and I were and and the rest of you were discussing this evening on the show As well as a slew of other information about their campaigns topics resources media initiatives fact sheets and a lot of the other efforts underway with respect to the Evacuation of Afghans right now. So I definitely check it out. They're a great organization to support and And I'm proud to be part of their technology advisory board What a mess what a mess this has turned into of course, you know, it's been a mess for 20 years I remember, you know just after 9-eleven the the throngs of people that were trying to stop this trying to stop an invasion or occupation of Afghanistan why because it wouldn't work because that the region the country has a history of repelling invaders and This just took longer, I mean they they just got over ten years of Soviet occupation where they kicked the Soviets out and now the same thing has happened, but it's it's far more tragic because of of all the waste of all the The militarization has taken place in response. That's made things so much worse. I You know, I I hope but hardly expect that there is a lesson that will be learned here How do you hold out any hope for that when this comes on the heels of Vietnam and and all sorts of other misadventures that we really should have should have learned something from Such a such tragedy and of course the responsibility falls on everybody falls on Joe Biden But boy, it also falls on George W Bush. It falls on Barack Obama. It certainly falls on Trump who made this deal That excluded the Afghan government and just made things a whole lot more difficult made the the Taliban into an equal partner and That's being forgotten. That's being forgotten. Yes, Rob. Go ahead yeah, this whole situation is fascinating in you know, terrible and heartbreaking ways and also needs to be like we need to keep the receipts from this and learn the lessons that it has to teach us about What is going to happen if we if we get into another situation like this and maybe it you know Goodness willing it'll it'll prevent us from getting into something like that. But yeah, Afghanistan repelled the Russians Afghanistan You know has a history of this but this time we left all our Really really dangerous toys behind and that's that's gonna have you know, that's that's going to keep having effects throughout Throughout the coming years on on the people that are that are caught in this database I mean I am I am just fascinated You know I've when when I when I had a day job that ended they managed to shut off my email and shut off my access to the internal systems as as one expects during these things and you know I don't know if the organizational abilities of the company in question should be directly compared to that of the US military and everyone else that was involved but you know, it's not looking great Alex go ahead Yeah, and the other thing to mention about this particular type of data as well as that It's data about you as an individual person based on your biology. That's why we call it biometrics That means it's not going to change that the data in that database may be passed around to various other governments as well that are friendly to the Taliban and For these people who are part of that database It's going to make it easy to track them at the border if they try to let's say, you know Visit Iran or go into Pakistan They may be branded as as traitors or as collaborators with the the great enemy the United States of America and perhaps abducted tortured mistreated on because they were in that database and so the power of data and the power of data to Facilitate human rights abuses is what we're seeing playing out right now It's absolutely terrifying and I think it goes back really to what will was talking about and why human rights first is is so unique among human rights organizations because I understand the power of Technology the power that it can be used for good and the power that it can really be used for Absolutely malicious and nefarious purposes the very types of principles that we address on the show every week are embodied in that organization and And they do a lot of amazing work For refugees asylum seekers, not just these humanitarian crises, but all throughout the year There's cohorts of lawyers and private law firms that work with human rights first Technologists the Technology Advisory Board, I think is absolutely fantastic and a lot of these These innovative projects that are happening right now really show that Technology can be re-harnessed and used as a force for good But we have to continually watch to make sure that it's not a force for bad But I have a challenge for everybody here Can can you name a single government that exists now or has existed in the past? that would not want this database on their citizens a single one Because I can't I can't every government wants to know who its citizens are what they are doing what they're up to what they are thinking and Once that verifiable through fingerprints Irish scans you name it so It's not going to go away if we rely on their goodwill. It's only going to go away if we rely on our resistance to it I Entirely agree and another interesting bit of technology being used for purposes for which it wasn't ordinarily designed right now is And our listeners can do this if they have snapchat on their phones If you go into the snap map and go to Kabul Airport the Hamid Kazi Airport Swipe over over to Afghanistan Zoom in to Kabul Airport and you can begin to see these sort of heat map looking things and Those generally are where people are congregated around the airports and as you see those heat maps changing Those are indicative of where checkpoints are around the airport if you're trying to get to the airport I've seen a couple of people and a couple of colleagues post about this and using Social media platforms like snapchat to gather open-source intelligence information and data About these checkpoints in Kabul is also incredibly fascinating and and really I think an innovative use of open-source intelligence Wow interesting stuff All right. Let's let's move on to a couple of other things if we have have time for it. There's been some Some data intrusions t-mobile says a hack has exposed personal data of 40 million people Used to be that was a headline remember even a million people having their 40 million people Wow basically names birthdays Social Security numbers This is why whenever possible you lie, you don't give your real information to these companies They don't protect it and before you know it it's out there and and and how are you gonna change that information? How are you gonna hide that information in the future when when they're sharing it with the world t-mobile said in the statement? It had been investigating the data breach since last week, which unfortunately was after it happened And they were informed of claims made in an online forum that a bad actor had compromised t-mobile systems That's how they find out about these things on online forums Some of the exposed data includes customers first and last names SSN's driver's license and other information It also included the pins of about eight hundred and fifty thousand active prepaid customers, so they got everything pretty much The company said it would reset pins For those prepaid customers and urged other customers to change their pins as well It and this is this is the part that really annoys me It added that it would create a website to help customers take steps to further protect themselves Like it was the customers fault and I've seen I've seen notices that go out to the customers were affected saying Here's our things that you shouldn't do if you want to protect your data They're not the ones that lost the data t-mobile is the is the entity that didn't have proper security We should all be sending them a note saying this is what you need to do better You know or maybe be in a different business It's absurd Now there's also a report that 70 million customer records from AT&T were breached almost like a response to this Basically AT&T is is claiming this didn't happen so it's kind of up in the air I Don't really have much more than that because this is coming off of a blog but the reports are the 70 million customer records were breached in some kind of massive hack and I guess we still have to find out if that's true and They're not just rumor-mongering But it's likely it's possible it's the kind of thing that happens all the time and It's it's it's why we have to take steps against these companies before We trust them with anything so Use a PL box don't use your address Don't give them your social security number give them some other Form of ID that you don't mind if it gets out if you have to even give them that at all There's nothing wrong with being anonymous. There's nothing wrong with having alternate identities there's nothing wrong with trying to confuse the system and I feel that We try to follow the rules a little too much and it always hurts us Because these vast companies They don't care They don't take precautions Your data is is simply their means to make a profit and they don't protect that Yes, Rob and What what fascinates me about these cases and you know, especially t-mobile AT&T, you know the telecommunications industry You'd think if anyone would lock their networks down, but we know better, you know, especially those of us who are phone freaks but you know if I personally as an individual were responsible for the information the personal identifying information about 100 million people and I lost it. I screwed something up. I Leaked it out there. I would probably suffer some repercussions for that. I would probably get sued I might have you know charges brought against me whatever but you know, what's what's gonna happen to t-mobile? What's gonna happen to AT&T? Probably nothing because it really doesn't matter when a company that's made of money and has many legislators that they've bought and paid for in position You know, they don't get punished for things that they do wrong Well, there's not their stock might go down There might be some profits that won't be as big as as they could have been but you know what we're talking about t-mobile People are hearing about t-mobile and they're saying hey, it's a name of a phone company. I need a phone company Maybe I'll pick t-mobile. I mean, what are the odds of having another data breach after you already had one? It's like lightning doesn't strike twice does it? You're right they don't let's go ahead Alex Yeah, I look on the other side of this really you're gonna pick another side to this As black and white as it can possibly be this is the Death Star literally that we're talking about. All right, fine Go ahead. Well the the Death Star I mean, yeah, the AT&T logo the resemblance to the Death Star has always been pretty uncanny. I have to say intentional But the that's my theory Yeah, sorry about that Thunderbird. But the the issue I see here though is that We're faulting them for collecting this data But they need this data in order to bill us and to run their systems to send out mail to be that I think a lot of it could probably be minimized. Why do they need a social security number Alex? Why in God's name does a phone company need your social security number? Well, they probably shouldn't be retaining it for purposes other than for which it was originally They need an address to send the bill to that's all they don't even need your name. They need an address They need to just get paid. That's all they need But to a certain extent here, I think we do have to be careful about you know, blaming the victim here I mean these companies in as much as they are Very much for profit and and supposed to be stewards of our data These are the companies that have been breached in one way or another. Well, you said the victim. I thought you meant us You mean they're the victim. We're the victim. We're the ones having our data passed all over the world That's true, so there are multiple victims here But I think we have to realize that the company is also a victim here that there is an inherent value to the data That was exfiltrated from them for a reason Because if people want it out there, they want to use it. There's too much of it out there. I completely agree and Sorry, I'm gonna go on mute for a second here Okay, that's an unusual way to make an argument but Look they basically It's heard that I had a call coming in through the same computer and using this new microphone thing It's been been weird. But but yeah, I I think you know, look the these companies were were breached it is a I Think it's a it's a big looming issue that it happens over and over and over again, and it's not enough I agree to just say oh well cyber security is hard But it is very difficult when you're warehousing this data to do it properly I think everybody needs to redouble and recheck what their security controls are it's not a simple fix by by any means but any exposure personal identifying information will probably lead to some kind of governmental inquiry and certainly as Rob suggested I think a slew of Lost suits as well. I just don't think we are wrapping our heads around 40 million people what that means how many people that is I Mean if you if you added up every Mets game since they came into existence and and and added the attendance I don't think you'd reach 40 million. It's that many I'm not sure about that. But it's a lot of people. It's like a six of the country, right? Yeah, something like that. It's huge and it's not even the biggest and look we don't seem to be getting anywhere because we've been reporting these stories for many years now and it just keeps happening so I Just I'm tired of buying the argument that yeah, they're gonna get better I don't think it's in their interest to get better. I really don't because if it were This wouldn't be happening over decades. They they would have taken this more seriously and not collected so much information about us and Allowed it to fall into into unauthorized hands so many times I mean if as Rob said if you know, if any one of us did that we'd be looking for another job We'd be facing charges all kinds of serious things would happen to us that do not happen to major corporations I'm sorry That's gonna have to be the last word except on overtime which you can join us on in Just a few minutes at 8 o'clock go to youtube.com slash channel 2600 or go to the link That's on the 2600.com webpage and you can call us and talk to us and We'll be on there in just a few minutes. We lost a major Octogenarian drummer in a rock and roll band is going to be a lot of octogenarian drummers in the years ahead Charlie Watts from the Rolling Stones. I want to go out with a tribute where he basically Played on the only song that has our name in it So here's our tribute and we'll see you next week. Good night and welcome back everybody it's time for overtime on off the hook manual here Kyle there and everyone's just getting back we all take little breaks in the five minutes that we're given I'm told that we are actually on the air however that's incorrect because we're not on the air we're on the net but whatever maybe somebody's broadcasting us someone could do this I could broadcast the YouTube stream you mean from the stream yeah why not yeah you have our permission yeah except we don't have to abide by FCC rules now although we still do but we might not and then it would be up to you and yeah we can take phone calls now too that's one of the reasons we can take phone calls our phone number eight zero two three two one four two two five that's eight zero two three two one hack and I don't know what you're pointing to Kyle just pointed to something well I hadn't heard it I just wanted to know if you could test it test what we don't have a call yet okay would you maybe turn it up so we can see if it's there yeah turn this oh yeah we have a dial tone which means nobody can call because we have a dial tone well now they can all right well good good thanks for that eight zero two three two one four two two five there is another story that broke this week that I like to spend a little bit of time on and I wish we could spend more time on it or any time on it on the air but there is a a content subscription platform called only fans you might have heard about this in the news we had about 120,000 creators registered with the site and after the pandemic left millions of people out of work and sex workers unable to safely meet with clients in person people flocked to the platform which was already well known for its adult content by the end of 2020 only fans boasted 1 million creators and 80 million users call that success creators like the control the platform gave them over the kind of work they wanted to do but the more the site grew the more nervous they got only fans is not going to last but it is a hell of a ride only fans creator Kimberly Kane told the New York Times in May it's that's rather dire to for the for the basically well she says okay you know it's kind of confusing here when you say only fans creator I assume that meant she created only fans but she didn't did she she just a creator on only it's how they describe I don't like that I don't like defining people in that way because it just makes them seem like gods you know creators I would never call myself a creator I creative I'm creative but I create I don't know it's just in this context okay so she didn't start the site itself it made it sound like she was saying that they were gonna take it away from the people that made the site that started the site they'll take it away from us just like they do everything else it's only a matter of time and she was right last Thursday the site announced it would ban sexually explicit content beginning in October in order to comply with the requests of the platform's banking partners and payout providers as it seeks to attract outside investors isn't that always the way and as it turns out bankers and credit card companies are extremely conservative in their policies and they don't tolerate certain things that you might find is no problem for for most of us basically this was something that had bothered a lot of people and was turning into a real issue but I understand has it been resolved has been changed Rob you know something about this yeah basically they they they announced that they were going to ban assess what's known as sexually explicit content I think in October and there was a huge outcry there were people who depend on the platform for a living that was only exacerbated by the pandemic and lockdown and everything else it's it's a form of work that people find that some people find they can do from home and that worked for a lot of folks and so you know it was a good thing but the the platform has been advertised for people like performers of all types people with you know cooking lessons and yoga lessons and things like that that's that's what it looks like in the ads in the ad campaigns but practice on practical terms it was driven by sex workers it was driven by people producing pornographic content just like every technological innovation in our history you know home video the internet itself commerce on the internet site security so much of this was spearheaded by people in the adult entertainment industries and OnlyFans was was ready to drop all of that but there was an outcry and apparently OnlyFans was able to resolve the issues with their bank that was that was the the root of their their policy change and so they reversed the decision maybe not going with the first Christian Bank of Alabama was a mistake you know maybe they should go with somebody a little bit more liberal yeah because you know there are porn sites everywhere I understand there's porn sites all over the place and they take credit cards so what is the issue there are virtual banks everywhere and they take well uh-huh there's money cryptocurrency that certainly doesn't care yeah but but it turns out there was so much discourse that's coming of this and a lot of it is really fascinating even if you're not interested in the product itself because this the the the real the real issue behind all of this is that the banks find themselves under pressure from organized evangelical activists conservatives people like that who basically are using this as a way to legislate what people can do with their bodies and you know it's a roundabout way to come to it but it it is something that's happening in the world and I think based on what I'm seeing it really seems like OnlyFans maybe even if they thought they could get around this and keep paying their sex worker creators we're maybe interested in testing the waters to see if they could move away from the the pornographic end of what they do and realize that it failed and they weren't going to continue their business based on you know the cooking classes and and yoga mat stuff and whatever consider those waters tested and I think maybe they they've had second thoughts it just goes to show that public outcry matters that's how you make change and a lot of people never even heard of OnlyFans before now they've gotten a lot of publicity and they they are going to hold on hopefully to their their their client base and not let this nonsense happen to them again yeah and there are so many ways that creative people have been have been able to make their living online by you know selling artwork by you know selling items but so much of that has found itself under censorship restrictions because you can't do adult level stuff like if I want to sell stuff as a creative artist if I want to sell work as a performer the instant it becomes what people would generally define as pornographic it's almost impossible to get paid for it in any easy-to-use way and that that is that is by design from people behind these organizations who find themselves you know acceding to these policy decisions. Alex looks like you have something to say. I've always got something on my mind here and I think it's this time that we shouldn't never underestimate the the power of the dollar either and in effecting this kind of change at OnlyFans in the first place and if you take this extrapolated it to other context other situations or scenarios think about something other than a payment processor for instance let's think about advertisers or advertising networks which support a great deal of the web these days advertising especially journalistic endeavors and and media outlets themselves that don't put all of their content behind a paywall generally rely on ads to be popped up and let's say that there became a coalition of advertisers some advertising network that had a lot of purchasing power and really held sacred Christian values Christian and family values and then determined that something like the New York Times or Wired wasn't really syncing with those values and that they began to pull all their ads and get all of their coalitions and all the coalition of their companies to to pull all of their ads I mean they could effectively change content and change the voice of a lot of these outlets by the power of the dollar which gets us full circle back to the reason why places like WBAI exists yeah we're not on the air right now but the Pacifica radio network is independent from all of that and has been for what is it manual I think it's over 60 years now because Pacifica started in 1949 WBAI started in 1960 Wow amazing so yeah even even longer than that but I mean so these networks that are by design outside of that process are I think becoming fewer and far between and extraordinarily valuable and you know I wish we were fundraising at the time because you know I'd say now's the time to become a WBAI buddy but hey you still can no one has ever said that before I wish we were fundraising that's true absolutely yeah I don't miss that I feel like I'm gonna eat my words we'll probably be fundraising before you know it all right yeah speaking of eating your words um we have a phone call okay let's go to the phone call good evening you're on off the hook overtime hey I wanted to add some context to the only fan situation I'm like a 3d creator and I'm friends with a lot of people who make pornographic content specifically it was mostly on Pornhub and earlier this year if you weren't a verified creator you basically lost everything Wow and those people I know ended up going to patreon they ended up going to only fans and they still have only like recovered a fraction of what they were earning but it wasn't because of Christian evangelicals I mean we can you know you can blame them for everything it's actually like reverberations of the Patriot Act really because back whenever yeah whenever they re whenever they enacted the Patriot Act way back in the day they deputized the bank to act it's like you know financial arms the government in a way so that's like why you can't like get weed stuff done but they would take like cartel money it's totally in backwards right but it's it's just really insane but like specifically the driving force behind all of this is MasterCard like MasterCard is this insane rabbit hole if you ever look into it like um whenever only fans released like what was considered sexually explicit it was MasterCard like known list of things that porn sites can't have on them but porn porn hub and only fans they both got into trouble for basically the same thing there were like child sex workers people being forced into prostitution and forced onto the platform and that was kind of like the the entryway for them to start having you know this is happening when your platform you're gonna have to start you know banning sexually explicit content or we're not going to process your stuff yeah we're seeing like that happening and it's just it's real messy and messed up yeah that's interesting that you bring that up as a fallout from financial reporting laws that were instituted really as under the auspices of terror like anti-terror law I think and specifically Freedom Act and Patriot Act refer to that and child sex trafficking of course being a part of that kind of criteria where they want to exhibit this exert this kind of control but as you characterize it sort of became something that was unsupervised and then just left to the banks right yeah it's it's it's really it's really insane and it's only gonna get worse I mean they're gonna come for the porn people first and you know a lot of people are like yay you know porn's yucky whatever you know there's actually a big movement especially among like Generation Z that's very like anti-porn it's it's very interesting I don't know maybe their parents watch too much of it and that's them being edgy. Rebelling against porn as part of growing up. Yeah it's actually there's like a whole movement called nofap where people refuse to masturbate because they think it'll make them more powerful as people. Oh yeah the future is bright. The future is really bright. I wasn't feeling pessimistic before I am now. Yeah some of that came out of like porn addiction becoming something that was really talked about widely more widely right yeah for that generation. It's just it's we're in a very shady valley and if if we can start banning porn we can start banning speech and it's I know slippery spoke fallacy and all that but it really is something to think about you know it's it's not good. Absolutely absolutely well thank you so much for the insight and giving us a lot to think about. Yeah no problem bye. All right take care. What an amazing call. Wow so much Pornhub Pornhub being told not to have porn it's it's more than half their name and oh boy. You have something Rob? It's it's fascinating and I'm so glad we got a call from somebody who's actually closer to this and and can speak from can speak from experience on it because it's really it's really something and if I if if you're out there and you have something to add on this we would really love your phone call at 802-321-4225 or toll-free at 833-755-2600 because yeah we need to we need to get everyone's voices in on this and hear about what's going on from all these different perspectives and yeah as a creative you know it sucks when there's there's limits placed on what you're allowed to do. There were so many other venues before OnlyFans that people who were creating sex work or you know adult entertainment could could go to. There was Patreon for a while and then Patreon banned the porn and there were other things similar things but that you know one by one have fallen like dominoes because banning adult content on their platforms and OnlyFans was meant to be the one. It was meant to be the one where you were allowed to do that sort of thing and they kind of embraced it but let that industry build them up into a major player and then seemed really willing to just throw throw the adult producers under the bus. But there's a .xxx top-level domain you know what what do people think that's for and and you can't shut this down this is this is what what I don't want to say it's what the net was built upon but it's a major part of the net and you can't just wish it away. But you know if nothing else this kind of emphasizes the importance of having these alternative ways of paying people and cryptocurrency has never looked so good because they don't have to play by these rules. Absolutely because you can build it in in some ways if you're having some trouble. I'm sure there's been some talk or people trying different workarounds in the in the interim as these policies are fluctuating and there has it's interesting point I was brought up it's been there's been a lot of investigative work around some aspects of that platform and how it's been abused and much in the way we've talked about like social media platforms cracking down you know how to control stuff that is against definitely against your policy and and how to show of course that it is concretely being managed in some way and and you know enforced as as build and we're really happy to share anybody who does know a bit more about this field how payment management systems are used and how much power they've been given and if if if the scope of some of that legislation has changed please share with us we've we've covered some of those acts and and so forth over the years so oth at 2600 dot-com to to get your emails go ahead Alex it bounced off your your comment about dot XXX in addition to that there is also a dot sex dot generic top-level domain and a dot porn generic top-level domain these were part of the expansion of the global domain name system so explain to me the difference between dot porn and dot XXX I'd like to know the spelling I mean they're owned and operated by different individuals different registry operators but we have 2600 dot XXX but don't go there you'll be disappointed I'm sure yeah I bet you would but yeah but there's two other top-level domains that are devoted entirely to this type of activity and you know I can saw fit to allow additional delegations into the root zone of the domain name system for dot sex and up or and that was back in probably 2014 I think was when those were delegated 2014 2015 I would guess it's like they've been around for a long time and they're pretty popular go ahead Rob and and just as someone who has been putting creative work on the net you know since time immemorial it's been such a joy of the internet to see people being able to make their own careers to connect directly with people who appreciate purchase enjoy their work you know so many traditional publishing industries have found themselves disrupted by people who don't need them anymore you don't need to a record deal with a major label to put your album out there you can just put it on the internet you don't need a TV studio or a TV network deal to put a video out there you can just upload it yourself and to find a segment of the population a segment of the creative population excluded from that just because of the type they work the type of work they put out despite the fact that it's a type of work there is demonstrable demand for it sucks it sucks seeing people seeing people legislated unfairly like that you know this kind of thing this kind of thinking doesn't just affect porn whenever there's a corporation that feels it's going to inject it's all moral values into something you find situations like this this story came out recently well-intentioned hackers trying to teach online hygiene and safety are running into a problem on tick-tock the newer social media platforms algorithms can't distinguish between videos about criminal and ethical hacking Marcus Hutchins who rose to fame after temporarily stopping the WannaCry ransomware attack back in 2017 knows this problem well whenever he posts an educational video demonstrating hacking techniques bad actors use tick-tocks content moderation algorithm immediately removes it for seemingly violating policies against promoting criminal activity and it also bans him from posting for a couple of days the weird part is each time he's appealed the removals tick-tock has reinstated the video and hushin says he's not the only one everyone in cybersecurity is having this issue tick-tock spokesperson Jamie Fazza Fazza basically pointed to a section in the platform's guidelines that says educational content like Hussain's should be allowed we recognize that some content that would normally be removed per our community guidelines could be in the public interest therefore we may allow exceptions under certain circumstances well interesting in this particular case they're pointing to the algorithm as the cause of the problem but it's basically an extension of their policy saying talking about criminal hacking is something we're going to forbid even if it's in an educational setting and this kind of thing always backfires it always backfires and and winds up making people unable to post creative content or educational content yeah I mean look it's a problem with any kind of algorithmic decision-making at such a large scale but if they're going to have any kind of community guidelines they certainly can't be individually policed by a massive force of content regulators at tick-tock to do it they're going to have to have a large portion of this done via automation but what boggles my mind in the situation is if the same situation is arising time and time again and in the same result it is achieved mainly that the content is placed back up because it is founded not violate the community standards then why is there not some kind of whitelist for creators who continually have this problem if your content doesn't is found to have been flagged and then after let's say five reviews or ten reviews and every single time it's found to not actually have violated community standards but it's it's always within that gray area then why create this problem over and over and over again you should have a whitelist for certain creators so you can avoid this it's it seems to me that they're operating on the assumption that users are going to do something bad and violate their community standards despite empirical evidence to the contrary and and that's a problem that these platforms are going to continually have until they wake up and and whitelist certain creators and let's say there's some kind of anomalous event where certain content then is flagged by numerous individuals people who reviewed it you know if all of a sudden Marcus Hutchins starts posting snuff films or something like that let's say hypothetically he's going to get a lot of complaints that's something that certainly would violate community standards that would jump out and and then you can remove the whitelist but I think if creators are their business model they need to I think be a little bit more respectful for those that are on the edges of their community guidelines well the other issue with that is this list of this whitelist at that you suggest that has to be something that's open and easy to get on not like Twitter with their their little blue check which takes decades it shouldn't be an elitist group that has certain rights that other people don't have because they're new or because they're unknown these platforms if they're going to be anything like what they purport to be they have to be open to everybody and allow other people to become oh I don't want to say influencers but recognized more recognized for what they do maybe there'd be less influencers because there'd be other people saying things and we wouldn't be devoting all our thinking power to what did this particular famous person say it shouldn't be like that in fact what I like to do on Twitter is sometimes just hear what people are saying without knowing who said and it would be great app to have you know if if you can read tweets and not know who said it and say yeah that's good you know but if Neil deGrasse Tyson says something everybody likes it and there's a billion retweets but if you say the same thing two people say something and one of them is arguing with you so yeah we need some kind of of a system where it's it's just more open to more people I think some of his followers are actually stars and galaxies yeah that's why there's so many and influencers influencers stars yeah that's right there's only like certain stars that we we look at you know there's regulars you know there's there's serious but we don't look at the little dim stars well I just call people dim stars well we're all stars how about that we have a phone call in the dope show good evening you're on off the hook over time good evening of the hook over time it's Bobson from Bulgaria I assume you're in Bulgaria yeah there's an issue that I didn't hear you mention about payments being denied the processing of payments being denied to that site that was in trouble recently probably Phyllis I don't remember its name you mean the site we've been talking about for the last 20 minutes probably yeah only fans each violation pops in is it only fans is that what you're talking about can you hear me okay I think we lost pops and he was beating call back but why was he beeping he'll call back okay but I think I think he's talking about the thing we were talking about could be something funny with the system or service that he was employing or a service he was in being employed upon him without his knowledge I don't know but we're available in here it sounded like he was wanting to speak about the argument of this being a limiting of sort of a speech a sort of and and I think really the association is that it's a form of expression sexual expression in this case but I'm curious what he thought about that perhaps that was what I was hearing in his characterization of if that's what he was talking about in the first place yeah we don't know that I don't know because he didn't know that finished the first paragraph really was saying 802 excuse me I can't eat on the radio I can't eat on YouTube I found out yeah it doesn't get flagged by the algorithm no it doesn't eight zero two three two one four two two five there is a WPA algorithm that will flag you this might be Bobson who knows good evening you're on off the hook overtime is this Bobson good evening no it's not it's Chris okay Chris well you have to be our Bobson for now you're talking on a turn down my radio here you're talking about tick-tock it doesn't that site originate in red China and doesn't that provide security concerns by itself I'm a little upset at the red Chinese for giving me the Wuhan virus at a tourist event that they shook my hands and well a bunch of Chinese tourists back in October of 2019 and if you want to make them upset keep calling them red Chinese I don't like that communist China okay fine they were orientals and I said where you from they said China I said Taiwan they said the people know the People's Republic of China very proudly and then they shook our hands and five days later I and they stood very close and talked very close to us and put their arms around us for pictures and sat at the tables were later going to eat and then then they five days later I collapsed on the floor of my kitchen and was taken away by ambulance but they didn't they didn't know about the Wuhan virus at that time and when was this the Wuhan virus I know what but when did this happen oh this happened in October I was taken the hospital October 25th of 2019 after that I had a number of symptoms so you had you had coronavirus before virtually anybody else you had coronavirus before virtually anybody else is what you're saying well not before it was filling up the hospital's parking lots in Wuhan and where were you where were you at the time this happened at the time I belong to the group called the hunting Huntington militia we reenact events from 1775 the American Revolution and Jim I'm trying to get away from my speakers where you're speaking here I've got a turn that volume down further so and I've lost my train of thought so yeah 2019 October is when October 20th was the last event there were seemed to be a lot of Orientals all summer very well-dressed and that's where they were sending they were sending tourists to the United States as Trump said to spread this virus around okay I gotta stop this does so much here no no this is this is wrong using a term that is offensive and accusing an entire race of people of deliberately infecting us I can overlook quoting Trump all right that's you know upsets me but no this is I I tried to listen as long as I could I really did this is it's it's utter nonsense utter nonsense that that was a historical reenactor and maybe he was just reenacting the Cold War okay that could be that's from the 50s or something where that sort of thing was encouraged and acceptable yeah I don't know okay this is Bobson so we turn the caller ID on hey Bobson are you there oh boy I don't know what kind of connection you have now you hear this Bobson smack your phone or something you're super distorted oh no this isn't working is there there's something on our end no Bobson can you hear me and and just answer loudly it's like talking to another form of life Kyle say something to the phone okay you sound fine Kyle but Bobson sounds like he's in another dimension Bobson please call us back again and call fast so we don't get the militia calling us 8 0 2 3 2 1 4 2 2 5 why am I giving out the phone number I want Bobson to call and he knows the phone number so hopefully he calls back and I will be able to talk about intelligent things oh my god well I just too much too much hit me at once here basically trying to communicate with aliens matter space and aliens from right here on earth this seems to be a call from Washington DC you want to try this let's see what happens oh wait that's Bobson again though well we I don't know he's either on call waiting or he's here good evening go ahead yes hi you're the Washington DC call right no not in Washington DC but your phone number is are you not calling from a tool to number okay we don't know where you actually are we don't have that means of what's on your mind yeah we don't go ahead what's I thought I'd call you guys because I heard you talking about only fan and I had a girlfriend who recently had a problem with not only fans but what is it called chatterbait chatterbait you guys know what chatterbait is that's when I haven't heard about not heard it okay I think it was the original it's like a website that you use to masturbate or have sex shows whatever maybe play for these content creators to share their performances I guess and receive payment tokens whatnot but she recently had trouble because she I guess a broadcast did something was under the impression that there were only 30 or 40 viewers however I think either a bot or a person recorded the content and then started distributing it on other websites so now she's finding it popping up on hundreds of different websites and she I guess she wanted it to be live and not exist afterwards and it still is and so I was wondering if you guys knew any similar situations or if you think it's a lost cause if you think it was a plot or an individual but I know that that's an issue that a lot of these creators yeah I I hear this in in a lot of ways in resembling revenge porn and situations where people have been filmed maybe with permission and then someone distributes it without permission even and most importantly in in vengeful ways and and so this this seems like a little bit of an automated way right like a way to scrape or capture live all of this data that people are monetizing maybe maybe exploiting vulnerability or some open network in some way and then trying to capitalize it maybe not even in a directly personal way but just to kind of automate content creation and then repackage it sounds like what points to the automation here why couldn't just be a person because I think it's a bot who's doing it what what tells you that because there was something we did a lot of research into it and I think they're almost start to record all of these live streams on like the chatterbait or the only thing but I'm not sure okay all right Rob go ahead yeah there is there's a lot of this sort of thing that happens and it's a matter of like what we would call forms of DRM and the the end the long and the short of it is that on a technological level if somebody is watching something on their computer screen they could just as easily record that screen no matter what it is it's like you know people watch a movie on Netflix and it's very commonplace for those movies on Netflix to be recorded on the viewers end and then re-uploaded to like a BitTorrent site or things like that digital content is not lockable in any meaningful way it's just difficult it can be difficult to get past the the the security measures there but it's never impossible and I while I'm not familiar with this particular sort of case happening on like a site like a site like chatterbait I think it's very common for any sort of streaming site to find themselves being recorded either by the people watching or you know by an account that is just using that to gather content which it can then upload elsewhere and in the field of like adult content I think there is a huge sort of scene out there of people like recording something from here so they could re-upload it everywhere else and so you know if if you fell victim to that there are like entire businesses now that a lot of sex workers are using which you know exist to basically trawl the sites and look for your clients material and then send the the DMCA notices and everything else and much much like Hollywood sends takedown notices for people sharing movies or TV shows whatever they don't have permission to so it's very it's very sensible that it's sensible it's very commonplace that this sort of thing would happen and it sucks if it's something that you're putting out there just as a stream and you're hoping it doesn't get out there as a recorded thing I call it did you have something to say to that I said the problem with those DCMA or whatever reports is that sometimes if you do that and you use your real information they'll blackmail you and ask for lots of money and the whole headache yeah yeah yeah absolutely and the the the ability for people to capture I think Rob's point about it could be a paying customer someone that's paying for it but they want it even for their private viewing at a later time even though it's something that happens as sort of a real-time service in this mutual video virtual session or or instance if they capture it it's about the content creator maintaining control once it's sort of out of their control and that's sort of a I think a problem with the platform itself billing it as kind of like snapshot where we'll we'll control this you'll be maintain this and it'll go away or you you can it will follow this one path but as we know with with data streams and and digital files they can be copied very easily and and and so there may be like precautions and things that people can take with the people that they're engaging this in this with if something pops up somewhere and they know it was a certain user they interacted with they can make and it happens again or something you see a pattern and like Rob was suggesting a way to take stuff down maybe something that people consider or organize themselves I think your your your best move at this point you might not be able to keep the material from being posted but it sounds like you have the ability to figure out how it's being done and if you can expose that or if you can expose who is doing it who is behind it that's a powerful weapon and that might help a lot of other people and and maybe help design a system where it's not so easy really okay Alex did you have something yeah and I think you know to to Rob's point with the DMCA notices and things it this is a very tough situation because if it goes from the excuse me that what was it caller that chatter chatter box site chatter bait chatter bait sorry yes chatter bait site if it goes I just got the name I get the fun yeah all right yeah me too yeah it's like a grenade there but if it goes from chatter bait to various other websites I would venture to guess many of them are going to be outside the United States they might not respond to DMCA notices that might not respond to lawyers they might not respond to legal process and you know and she's probably right that this this can result in greater extortion fees especially if there's any PII or facial recognition let's say pylometric databases again coming up today but if you can identify that particular person then you know it's problematic obviously and becomes a very ineffective method of whack-a-mole and I also think you're right to Rob maybe the issue should be approached as one of like a copyright enforcement or like a brand protection system copyright protection system and you know if only there were a way whereby let's say one file or image could be matched against an image remotely somewhere you know maybe like a hash matching technology you're defending that whole Apple thing all over again well we'll get into that if you want to get into that again I'm just thinking of another use case scenario here for victims of things like revenge porn I don't think that would help in this case at all I don't think I think it quite possibly would help and if it didn't help I think would undermine your own arguments from the last time anyhow because if it well look if it was an exact match of a file elsewhere I think the hash matching technology here obviously would work but if you're recreating a file if you're recording a recording and you're not taking the actual file that's gonna be a different digital signature it's gonna have a different hash so in all likelihood hash matching probably wouldn't work but I think that's I imagine there's got to be something akin to this what does brand protection systems do that that troll various media outlets and things but they might not have coverage on these these weird new sites that pop up to disperse this sexually content and even if you go after one they're probable they're very likely to be throwaway organization something that can just pop up somewhere else in another jurisdiction perhaps with another corporate entity so it's a it's a very I think it's a very tough position to be in I wonder if technology can be developed that would use facial recognition and then basically hunt for that face showing up and shut it down on whatever public sites might be displaying that particular face and but the only person that could that could do that that could say revoke all instances of this face showing up is somebody that has that face it's just something I I'm thinking of right now yeah I mean to an extent I think that's what a lot of these these brand protection systems will do that that go out and look for counterfeit marketplaces and and things like that usually as of products right and and those will to a certain extent I think match hashes of the individual files but there's also a visual similarity component to the way they work to go ahead Robin then we'll let the caller go yeah I'm like as we've as we've spoken about on this program the facial recognition algorithms out there and in common use are still not very good they're they're mostly they're mostly work on I think white men and that's about it but but beyond that like and this is this is a sad part of the of the reality for people trying to make a living with online content once you put something on the internet you are never going to retain control of that file theoretically anybody else could copy it could you know make derivative files of it and whatever and it could circulate around out there outside of your control and that that's something that I think needs to be better better said and like educated out there among people who are thinking of going into this type of work because it is a real danger I hope we were somewhat helpful any any other questions or thoughts no you guys were wonderful I don't think there's really any hope for her to get that content off the internet but she is desperate so if you have any listeners who are hackers for hire please write him off the hook and maybe you guys can find my number and let me know or I'll call it and check in because she really would do anything to get it off the internet well be sure to know that we support her she has lots of support out there and that basically many people are going through similar things she's not alone well thank you thanks for your call take care Bobson from Bulgaria has been trying throughout that whole call to reach us I've been watching the screen have you connected Kyle not yet okay well let me know when you connect all right I'll let you know okay there's nobody in the phone now it is currently okay not active okay all right because I just started ringing but I guess it went to voicemails right Bob's in the phone line is open out there in Bulgaria if you want to give us another try I won't give out the phone number so nobody else will will hear it for the first time and hopefully we'll be hearing from why do we have something to say that we were waiting for he you know he wanted to talk about some site that we thought we had already talked about well this is him this is him now so go ahead Bobson is this you hear me yes if this is Bobson I can hear you if it's not Bobson then I can't yes it's me okay good good okay don't lose this connection this is the best connection you've had all night well so what I was trying to bring up earlier about the only fences it issue yes we were talking about it where their payment processing was denied them for unclear reasons and all that I think it may be a freedom of speech issue in this case and the reason I think that is because there was a movie a quarter of a century ago which was produced by Oliver Stone and another person I don't remember their name but it was directed by Milos Forman and it did dealt with a case that was in front of the Supreme Court in 1988 I'm talking about the movie the people were sorry yes and in that movie one of the things that became clear to me as much as I may have felt uncomfortable about his magazine is that it was a freedom of speech issue that they were trying to defend and I'm not very I haven't I'm not familiar with the paperwork to the case or what-have-you but I think maybe Alex who's far more competent than me in legal matters may look into how this thing may relate to that thing from the 1988 Supreme Court which was Flint versus Falwell and they are both passed by now so yeah that's what I wanted to bring to the discussion well Alex you've been called upon any any comments I'd say I think it's the long and sort of you know drawn-out history of First Amendment jurisprudence you know from the 1980s onward but I think it raises interesting issues and I'll tell you that you know these First Amendment issues and matters arise in a lot of places where you wouldn't ordinarily expect them to arise as well and a lot of things are forms of expression that that wouldn't otherwise be thought of as as protected by the First Amendment so it's something I'll take a look into and I would say you know give me some let me let me have a think about that when I don't know how to answer it off the top of my head but I will say though when it comes to the First Amendment there's one thing that is definitely and has been found to recently fall outside the First Amendment and and that is child pornography by the way in case you were wondering it's far less protected by the First Amendment so if for instance there was a system devised on an individual device that would permit you to let's say match hashes of local files with other known files of you know sexual sexually explicit material on faulting children oh you are asking for it Alex you are really asking for it that was the April at the Apple communicator issue yes that's exactly right yeah I'm just gonna bring every single question back to that in some way I wasn't expected that from you Alex but if you feel like it why not right change it up judges love him so much if you're gonna do it just don't lie Alex I mean it's not recently that child pornography has been considered illegal it's it's not it's not like that recently changed like it was just a couple months ago there was this big free-for-all of kid but yeah well look yeah it wasn't a few months ago I mean it's it's been around some precedent obviously it's been around for a long time and and pornography you know its constitutionality has been you know the subject as a certain amount of scrutiny and and and certainly a lot of case law over the last several decades too I mean there was a famous cases where this literally the Supreme Court had to decide whether or not something was pornographic so they used to watch pornography in the in the you know the basement I think of the court is a very very strange thing you know I don't think that's an old wives tale but I'm pretty sure that court was actually doing well but there is I'm not sure that was the issue in some of those cases I mean I've only seen the as I said from a quarter century ago maybe not for decades now but the Flint versus Fowler issue they no one was saying it wasn't pornography and it was about how it was a freedom of speech issue from what I remember of the legal side of it which wasn't which may not have been very accurately portrayed you know major Hollywood Hollywood blockbuster as it turned out to be but yeah well that that's it I mean and I think that gets right to the heart of the issue here and one of the one of the famous quotes from the Supreme Court justice is that you know the pornography is incredibly you know it's very difficult to define but you know it when you see it that's literally how they dealt with you know was it you know I don't think I ever saw that I think it was people versus Larry Flint right is that what the name of the movie was yeah directed by my watch for months starring Woody Harrelson and some other rights all right yeah yeah interesting one so let me think on the the other issues that you brought up though yeah okay well he's puffing on his pipe now so while he's doing that I think some other other topics anything else pops in from you well no I just thought I'd bring up that freedom of speech thing and speech thing and I wish you a great evening thank you for the radio show and follow up well thank you for being there and for calling sorry it took so many it was worth it it was worth all the efforts and I'm glad you got through all right you too take care have a wonderful 3 in the morning or whatever whatever time it is over there pops and from Bulgaria okay so Alex you seem to want to talk about this this whole Apple thing you know I'd like to just read a couple of remarks from from someone who was involved in this basically Jonathan Meyer an assistant professor of computer science and public affairs at Princeton University this is what he wrote in the Washington Post we wrote the only peer-reviewed publication on how to build a system like Apple's and we concluded the technology was dangerous we're not concerned because we misunderstand how Apple's system works the problem is we understand exactly how it works our research project began two years ago as an experimental system to identify CSAM child sexual abuse material in end-to-end encrypted online services as security researchers we know the value of end-to-end encryption which protects data from third-party access but we're also horrified that CSAM is proliferating on encrypted platforms and we worry online services are reluctant to use encryption without additional tools to combat CSAM we sought to explore a possible middle ground where online services could identify harmful content while otherwise preserving end-to-end encryption the concept was straightforward if someone shared material that matched a database of known harmful content the service would be alerted if a person shared innocent content the service would learn nothing people couldn't read the database or learn where the content matched since that information could reveal law enforcement methods and help criminals evade detection knowledgeable observers argued a system like ours was far from feasible after many false starts we built a working prototype but we encountered a glaring problem our system could be easily repurposed for surveillance and censorship the design wasn't restricted to a specific category of content a service could simply swap in any content matching database and the person using that service would be none the wiser you know these are words coming from someone who has designed a system like apple's that people are up in arms about and i think you know that that carries a lot of weight that is something that we need to take seriously when people who are behind this type of thing are saying whoa this is dangerous and it can be misused we have to ask ourselves is is that kind of thing worth it uh look i respect the author of that article i think he's well bona fide but the the fact of the matter is here i read that article i don't think it advanced the debate about this at all because it just parroted over and over again the same arguments that are all premised on an identically erroneous assumption that what you're reviewing here is content what every single one of these articles and all of these privacy advocates never mention in any of their articles is a definition of what a hash is and i would go out of my i would go out on a limb and say they may not know how to define a hash if you ask a lot of these privacy advocates without any preparation time to explain to them what is a cryptographic hash and how does it work on a file i bet you most of them are not going to know how to answer that question accurately because if they did they wouldn't be making the same mistake over and over and over again about this particular system the problem that everyone assumes uh i'm sorry the assumption that is the error amongst everybody is that this can be used to track some kind of concepts it cannot it can only be used to track files individual files have a a fingerprint essentially called a hash it's just a long string of numbers and letters uh something like an md5 sum it's very unique we don't need to get into all that but uh you know if if you truly believe that the person who designed the system like this doesn't understand how how a hash works you're free to believe that i think he does i think he knows what he's talking about but let me just ask you this okay let's say that i have a meme okay a meme of uh of say a president of a country that's not very flattering and i pass that meme around to my friends okay it's a file it's something we all share and then the government says to apple whatever government it might be you need to tell us if this hash exists on these phones how is this any different the hash is going to be the same because the file has been shared with all these people sure it's the same damn thing how is this not a threat manual but any change to that file anybody who crops it anybody who changes why would anybody change that file why would anybody change it what's the point of changing it we're passing it around it's like a baseball card to make it bigger to make it larger to evade some kind of hash matching technology that's how it would be very very easy okay so your advice to avoid the gulag is if you get something that could be used against you make sure you modify it a little bit so that the authorities will be fooled that's that's our form of protection from now on it would be that would be an effective way to defeat the system this mastermind system you know that's going to be out there tracking dissonance look everybody's making this slippery slope argument about this technology and that it's going to be eventually misused it's going to be used to track cons it cannot be used to track concepts sure an individual file but you got to remember the manufacturers of these devices have complete control over the operating system if they are going to be forced to put in some kind of backdoor to monitor concepts that can happen anyway it has nothing to do with the technology when it happens we will be there to reveal it but this is something that can be used in a very dangerous way and you know the aclu sees this eff sees this and and and people who design such systems see this i think they're wrong and i think they're wrong because of the very fact and again this is something that has been ignored in large part by the media that this type of technology has been in place for many years already it's been used by google it's been used by facebook i i even mentioned last week a criminal prosecution that arose i think an erroneous criminal prosecution that's what i'm more afraid of but these types of situations because i've seen it happen but criminal prosecutions that arose from detection of c-sem in google photos and so we have about 10 years probably okay but but what you're what you're not saying here is that that's a completely different system where you're uploading photos to a service this is this is on your phone the apple is going into your phone and checking the hashes of files on your phone and reporting the ones that are objectionable that is very different they're only looking they're only looking at files when they're about to be uploaded to the cloud to their cloud so these files that are imminently going to reside on apple's own servers are being reviewed over there but okay so can i just ask you this can i just ask you one question they're looking at files that are about to be uploaded to their cloud service what keeps them from looking at them even if they're not going to be uploaded is there some kind of technology in place that prevents them from doing that no they're just they're just they're good word that they won't but that has nothing to do with matching hashes they have the ability to do that no matter what they can put anything they want on these phones matching a hash on one side whether it's on the device or whether it's in the cloud i really think is a distinction without a difference because what we're talking about is the ability of the technology to do something bad and which is the slippery slope argument but my major premise here is that because we have over 10 years of data of this happening already and we don't have some totalitarian regime misusing hash matching to track down dissidents this we know that it's not a slippery slope it's a sticky slope it hasn't moved at all because it's an idiotic way to try to track dissidents and people i maintain that if you have a meme that says lucaschenko sucks on your iphone and you're in belarus and apple has revealed how they're able to to uh match hashes i think there'll be a very strong interest in finding out who's got that on their phones and then they'll be visited and if you can tell me that's not possible in light of what apple says they are doing now then i will say i'm wrong but it seems to me you're saying that that is indeed possible and that the best defense is to crop the picture and change it some way so that you'll fool the authorities possible regardless of whether or not there's just hash matching technology on your phone because apple basically owns these devices they create the operating system they can create any functionality they want into this i would be much more concerned about the technology that is about to be implemented that detects nudity in text messages sent to children that's some kind of algorithm that is looking at the content of the actual images that's technology that could be used to find a photograph of lukashenko much more effectively than matching the hash of the file and because there's no content of the fact that they were both announced at the same time tells me that that's that's exactly what the thing is here it was a it was a i just think it was a very bad pr move for them they didn't expect this backlash uh because people conflated the two technologies that issue at first if they just announced the fact that they were going to be hash matching that wouldn't have caused any fanfare would have actually probably been bad for them because apple has not done this for so long and you've got to remember this is a company that really resisted the fbi and the united states government when they wanted them to build in a backdoor it's a company that has built its brand reputation on being privacy conscious so i think that they have probably gained a little bit of credibility and that they're not trying to build in some nefarious backdoor to enable autocratic regimes to track down dissidents here i mean we're talking about something that is non-content whatsoever a hash is just a long string of numbers that exists in one way or another without respect to what that picture is of or what the file is i mean it's listed in a database and it's very much about what is contained in in that file or that picture kyle you have something to say i just want to extend this i i think the the two things being released i agree they're both pr moves i'll agree with that and i think they were both concerning at the time i don't think there was anything about that one or the other this got a little bit more attention because of the confusion i think and about where some of this activity was being taken place and things like the fourth amendment and you know having some control over how your data is judged or when it is judged specifically let's extend out so this is being used what about hash planting or if this is what we are using as the rubric to confirm that something has taken place e.g. evidence right this is the the the rule of thumb we're going to use what's stopping the authority just saying yeah we found several hash matches and that's it i saw mike lindell with a whole lot of cascading text and characters and that looked like a lot of hash and you know hex and so if he says that's what it is you know you know what i'm saying like that that so we we decide that this is how we know evidence exists what is stopping it from you know people plant it you know planting evidence is the thing what if what if it is simple if it's so simple to get access to a device if it was used by an authoritarian regime which we know apple operates in many of these countries uh and and parts of the world and arguably our own could be in that category in some ways so like extending it out what do you foresee i mean how do you how do you plan in a world where this is just totally cool with everybody go ahead alex yeah and look unlike the rest of you guys i actually agree in part with kyle so you know he's got that going for him i think but the um uh i think i think you're exactly right though about the it's the principles that underlie what have the consequences of this technology that i think are are frankly more problematic to me than the technology itself because there's other erroneous assumptions that are built into the hash matching uh idea itself and that's namely that whatever is on your phone the owner of the phone is responsible for that content it's just assuming that these are all single user devices that they might not be out somewhere where you know 50 60 people have access to them you know like in a public library or let's say a poor community how are you then going to figure out who's who downloaded that that material who's going to be charged criminally what kind of privacy violations is this going to arise to because whenever these hashes are matched and they meet a certain threshold i think it was 30 of them it was fairly generous number it will then go to nick mick the national center for missing exploited children who then reports it to local law enforcement possibly fbi as well and that becomes probable cause sufficient to obtain a search warrant then the next thing you know the police are in your house another thing go go ahead sorry i was just thinking of like airdrop too like where you have unsolicited stuff that could match a hash where you're basically you're hash bombed on on a train or something with with stuff that we've been bombed wow i'm just making up stuff no we're going with this you're writing the future is where i'm truly trying to take you know work through this with you know the conversation alex we could talk about this all night and it is fun uh i i think i think you you should have a debated hope i i think it would be a good uh good conversation make people think about this get some civil libertarians on one side a bunch of them and then you on the other side and it'll be uh me on the other side yeah we'll make sure people don't throw things i'm a huge privacy advocate i think people know that about me but i just i think this is the wrong battle to fight here when it's non-content and and look you know an important principle to remember is you know you can only die on a hill once i just don't think this is the hill that these privacy advocates should die on i don't know they seem to die on a lot of hills but um no i i i hear you and uh yes you you are a privacy advocate but i have to disagree with you here but i respect your views and um and like i look forward to continuing the the dialogue we have no more calls we have no more calls we have no more time we're out of time we're out of calls um but please write to us oth at 2600.com tune in next week we'll be back both off the hook and off the hook over time please support wbai however possible 516 uh no wait that number doesn't work anymore 212-209-2950 or give to wbai.org and if you like what we did today please support the station and tell them we're your favorite show unless you can find a better one it's possible until uh next week it's emmanuel for kyle and uh and and rob and alex and gila good night