Activist Sharon Salaam speaks out for WBAI. We should be moving forward, collecting the funds that we need to make sure that our station is whole and that it can do its job as it has done for me in the past. When all of this stuff happened to me many, many years ago in 1989, I didn't get very many opportunities to speak out in regards to the wrong that was done to my son and the other boys in the Central Park jogger case as it was called at that time. Very few people stepped up. Yes, Like It Is was there, WBAI was there, and a few others. Majority of those stations that let people like myself speak and tell them what was going on on the other side, those stations are gone. If we lose WBAI, where do we go to get our words out? Where do we go if you've been arrested unjustly? Where do you go if someone's taken your children unfairly? Where do you go to seek justice? We must keep this station alive, alive. WBAI. This is listener-sponsored, locally controlled WBAI New York. And the previous program was Economic Update with Professor Richard Wolff, heard Wednesdays at 6 30 p.m. here on WBAI. Stay tuned for Off The Hook coming up. And again, if you consider supporting this radio station and haven't done it yet, well, this is a great opportunity than any to do it now. 212-209-2950 or go to give to WBAI.org online and you'll be glad you did. As I've mentioned before, WBAI is now 63 years being part of the Pacifica Radio Network, part of the Pacifica Foundation, and it's because of people like yourself made it happen. Now stay tuned for Off The Hook coming up. Due to telephone company facility trouble in the area you are calling, your call cannot be completed at this time. Please try your call later. 078-T. We're sorry. The number you have reached, 99.5 WBAI, is now Off The Hook. 078-T. And a very good evening to provide the program is Off The Hook. Manuel Goldstein here with you on this Wednesday evening, joined tonight by Kyle. Yeah, I'm right here. And out there in Skype land, I see Rob P. Firefly. Good evening. And Arsene, you're joining us again. Yes. Hello. Arsene, you may remember from many years ago, used to be one of the co-hosts of this particular program. And in fact, you've just flown in from London, I believe. Yes, yes. You didn't have to do that. You could have been on the show from London. You didn't have to fly all the way back here just to be on the show. I'm here in person. Okay. And we also have a special guest. Lorex is joining us from Distributed Denial of Secrets, one of our favorite organizations. Greetings, Lorex. Hi. Thanks for having me on. We're going to get to a very big story involving you folks in just a moment. But first, we're going to just go through some of the things that have happened over the past week. It's kind of our usual hodgepodge of smart things and stupid things. So we'll try and race through this as quickly as possible. Okay. By the way, Rob, Gila's not here. So is she coming later? She is not. She is on her way. She is caught in the wonderful weather out there. And so she'll be here at some point. Okay. And I should also point out, Alex is currently on a plane from London to here. But his plane, unlike Arseny's plane, is getting here after the show. And if you remember the last time we tried to talk to Alex on a plane, it did not go well. We're not even going to try to do that again. I don't know what's going on in London or why everybody's in such a rush to get back here. But whatever. Well, in any case, I'll be very happy to provide very bad legal advice. Okay, that's fine. That's great. Yeah. So now speaking of degrees and accomplishments and things like that, MBA, Masters of Business Administration, that's quite an achievement, don't you think? It's something that a lot of people strive for and they work hard, they study. And a damn Chad GPT passed an MBA exam given by a Wharton professor. Yeah. Professor Christian Tiewitsch, who authored the research paper, Would Chad GPT-3 Get a Wharton MBA? A prediction based on its performance in the operations management course, said that the bot scored between a B- and a B on the exam. The bot's score shows its remarkable ability to automate some of the skills of highly compensated knowledge workers in general, and specifically the knowledge workers in the jobs held by MBA graduates, including analysts, managers, and consultants. The bot did an amazing job at basic operations management and process analysis questions, including those that are based on case studies. Now, as you recall, we were playing with this last week on the air. We were writing poems and songs and even film screenplays. And it wasn't doing badly, I have to say. It's a little frightening how on the mark this can be sometimes. But there's all kinds of concern over how this could be taking over our lives in one way or another. Certainly, Google is concerned because it might do a better job of searching online than Google does. And they haven't had competition in a very long time. Experts who work in both artificial intelligence and education have acknowledged that bots, like ChatGPT, could be... I keep saying it wrong. GPT. Yes, I said it right. Okay. They need a better name. It could be a detriment to education in the future. In recent interviews, some educators and experts say they are not yet concerned, but they expect to be concerned really, really soon. There's a student in Princeton who has written an app. And we believe he's human. We're not sure yet. Hasn't really been verified. But supposedly, this human student has built an app that helps detect whether a text was written by a human being or using artificial intelligence tool ChatGPT. Of course, that's exactly the kind of thing that ChatGPT would do to fool us. So I'm a bit wary here. And what's stopping ChatGPT from using that app on itself, on its own stuff to improve it? Yeah. Yeah, you're right. It could use the work that Edward Tian, which is the human name that's being used here, devoted all this time to. He said in a recent tweet that the algorithm behind his app called GPT0 can quickly and efficiently detect whether an essay is ChatGPT or human written. As you know, it's exploded in popularity recently for its ability to spit out coherent essays on virtually any topic in just seconds. You know, fun projects. I think this is what we need to be doing. Just, you know, create as much mischief as possible. I had it write an essay on George Santos. Now, keep in mind, this thing only goes up to 2019, is it? Is that where its knowledge base cuts off? I thought it was 2021. It might be 2021. OK, but that's still before we all found out the truth about George Santos. So this thing read back this essay that the current George Santos could have written. It was full of praise. And this guy will make a great congressman, etc., etc., all his accomplishments. So that was a bit of fun. And there's no limit to the other kinds of things that you can do with this to create mischief and mayhem. I was thinking of taking a controversial subject, let's say something like nuclear power, and writing a letter to a local newspaper in favor of it and then writing another letter opposed to it, both written by the bot and both getting published, I'll bet. That would be brilliant. Yeah. Just side by side alone. We don't need humans anymore, do we? Contrasting the arguments. Yes, go ahead, Rob. This business about ChatGPT earning an MBA, it's very entertaining. I'm wondering how long it is until we have to call it Dr. ChatGPT. But this also talks to a lot of teachers are talking about completely revamping how they teach subjects in high school, in college, to specifically avoid the pitfalls of being prone to ChatGPT being used to cheat. And so this is a funny story about the bot, but it's also kind of a funny story about the requirements to earn an MBA from Wharton. So they're going to have to reconsider how they hand these things out. I have a business degree, by the way, and it's not rocket science. Well, yeah, I guess not. And you're going to have some competition in the very future, I would say. Gila is actually listening to the show right now and texting me from Parts Unknown. She says she would love to watch ChatGPT have to defend its dissertation. Yeah, you know, you could write songs in the style of particular bands and artists and things like that. You can make arguments based on the logic of certain people. You could recreate debates, presidential debates between different candidates, all sorts of interesting things like that. I'm thinking of all the fun applications. We'll get to all the dire applications and how this can really be used to hurt us. But I think staying away from it, as many people have suggested, is not the right thing to do because you have to plunge into the danger and see just what exactly it's capable of before you can figure out a way to get past it. And that's what we're all about here in this show. OK, another technology that's been in the news lately is facial recognition. As you know, if you have upset the people at Madison Square Garden in any way, they will keep you out of various venues that they own. Local elected officials are now crying foul on Madison Square Garden's ban on certain lawyers and the use of facial recognition technology to impose it. Manhattan State Senator Brad Hoylman Seagal and a bunch of other politicians gathered outside Madison Square Garden on Sunday to demand its controversial CEO, James Dolan, end the practices. Over the last six months, we've seen extraordinary, courageous and alarming use of biometric technology, said Hoylman Seagal. Obviously, there's a pattern here. There's a pattern of James Dolan punishing who he views as his corporate adversaries. And the thing about this story is these are not people who are criminals. These are not people who are a danger or a threat to the operations of Madison Square Garden or any other venue. These are people that work for the same company that is involved in a lawsuit against Madison Square Garden Enterprises or one of his companies. And it just shows you how easy it is to misuse this technology in a way that can really hurt people, hurt innocent people who are just there to see a game or a concert or something like that. So it's interesting to see politicians getting involved. New York Daily News, look at this. They printed a big picture of James Dolan. So if you want to take his face and ban him from your events, I guess you can do that. We don't use facial technology at Hope, do we? Maybe it's worth it just so we can ban him. What do you think? Certainly possible. Creative ways people can retaliate with the same kind of attitude. Yeah. I've never had the chance to play with facial technology, facial recognition technology. It's something that I'd like to mess around with a little bit. Yeah. Wasn't it at the second Hope conference that everyone was wearing masks of Kevin Mitnick? That was the first Hope conference. That was 1994 we were doing that. Yeah, that confused a lot of people. But we didn't have facial recognition technology. Go ahead, Arseniy. Yeah, I mean, are there consents when you go to a sporting event or a concert or whatever that they can use your face as a way to verify you or something? Well, there might be a sign at the door that says by going through this door, you're agreeing that facial recognition technology will be looking at your face. And I don't know many people who would turn around and say, yeah, I'm just going to give up my ticket now because of that. But the point is, if you do go through that door and they, for whatever reason, decide they don't like you, they can kick you out. And it just seems like a real abuse. I had a big fright when I came into the country, not today, but last time where I was a Global Entry member, but I was then expired, but I went to the machine to check, was it working or not? And you go up to the machine. So Global Entry allows you to get through customs very quickly just by putting your passport in. And I'd given them my fingerprints before, but I'd never given my face. They have my picture, but it was just a picture. In any case, you come up to the machine, it scanned my face, immediately just knew everything about me and said, hey, your membership expired. So why did I still remember my face if it expired? Why wasn't your fingerprint enough? I mean, but usually you'd have to put your fingerprint in the machine. But now it just takes a picture. You know, it just the webcam is always on and it's reading you. And it's frightening because I've never given a biometric kind of face scan. It's just it's taken my picture enough times that it can recognize me. It could probably do that without you going right up to the machine, too. I'll bet it can get you in a crowd. That is frightening. OK, over to the inevitable department. T-Mobile got hacked. 37 million customers had their data stolen back in November. T-Mobile said a bad actor. You think a bad actor? This wasn't somebody who was just out to do good and spread the knowledge about 37 million people doing a favor? Yeah, OK. Well, 37 million current customers were victims of a November data breach. Regulatory filing last Thursday. That's when the company said the hacker stole customer data that included names, billing addresses, emails, phone numbers, dates of birth. Why does T-Mobile need all this information in the first place? You know, I've been asking this question ever since they started, since they were OmniPoint. Why do you need all this information? And many times you can give them fake information and still have an account. It's not impossible, but it's more and more difficult. Social security number, you know, dates of birth. No, they don't need all that. They really don't. But yet they insist on getting it all from you. Anyway, the information can easily be compiled with other stolen or publicly available information used by scammers to steal people's identities or steal money. And of course, T-Mobile says working with law enforcement. I don't know what they're going to do at this point. They've begun to notify customers whose information may have been breached. And I'll bet I'll just bet when they notify these customers, they're going to offer them a free period of enrollment in a program that monitors their credit report. And they can sign up and pay for it after that period of time has ended. It almost seems like a promotion, you know, when they when people get hacked or have their identity stolen, that that entitles you to a free year or 18 months of this service. Anyway, the wireless carrier did not indicate what it might do to remedy the situation. Of course not. It noted it could be on the hook for significant expenses because of the hack. Although the company said it doesn't expect the charges will have a material effect on T-Mobile's bottom line. They hired an external cybersecurity team to investigate after they found out about this. They were able to discover the source of the breach and stop it a day after it was discovered. The company says it continues to investigate the breach, but believes it is fully contained. Protecting our customers' data remains a top priority. And we see that's how priority gets us. Okay, over to some of the smarter news. Appliance makers, Whirlpool, LG, they're a bit baffled by this. They added Wi-Fi to all their dishwashers and ovens and refrigerators. They made apps. But only 50% or less of their owners have connected to Wi-Fi. And they don't understand why aren't people connecting the dishwashers and their ovens and refrigerators to the internet? And apparently most people don't think that's a good idea. Most people must be listening to us. So that's great. Don't connect your damn refrigerator to the internet. What do you need to do that for? You know, yeah, sure. There might be an instance where you're, you know, delayed on a train and you want to turn something down a little bit. Or you can just be a little bit inconvenienced and not have the refrigerator be the gateway to people hacking your entire home network. Because oftentimes these devices have default passwords that people don't change. And it's just all kinds of security holes as a result. Anyone here ever put their refrigerator on the internet? Or their oven? Or their dishwasher? I mean, I'm always thinking about this. I got into those automatic vacuum robots that vacuum. And right now I can go on my phone and turn on my vacuum cleaner in Russia. Why would you want to do that? I've always turned it on when I'm in the house. You know, which actually kind of defeats the purpose of having it do it by, you know, having all that. But, you know, thinking a lot about why the circuits for these kind of small Wi-Fi connections, they're really small. They don't take up a lot of energy. And it is easier to connect to the device if you need to, for some reason. You know, for whatever reason, you'd need to connect to your dishwasher. And a great reason would be for diagnostics. If it's broken, it would be easy to connect to it. But I don't think that's what they're doing. I'm just happy that so many people aren't doing this. You know, we talk about things like this week after week. And it just seems sometimes like people are just following blindly into the world of high tech without asking questions and, you know, buying the same thing over and over again because it's built in obsolescence. But in this particular case, I think people are doing the right thing by not adding these things to their network. There's no reason to do that. And hopefully that's a trend that continues. Okay, so we're going to dive right back down into the stupid again. Uh, every so often you see a headline where you just are so disgusted by it. You don't want to continue reading, but we have to. It's our job. The lights have been on at a Massachusetts school for over a year because no one can turn them off. How do you continue reading a story like this? Well, let's see what happens. Yeah, for nearly a year and a half, a Massachusetts high school has been lit up around the clock because the district can't turn off the roughly 7000 lights in the sprawling building. The lighting system was installed at Minichug Regional High School when it was built over a decade ago and was intended to save money and energy. But ever since the software that runs it failed on August 24th, 2021, the lights in the Springfield suburbs school have been on continuously, costing taxpayers a small fortune. We are very much aware this is costing taxpayers a significant amount of money, said the assistant superintendent of finance. How does that person still have a job at the Hampton-Wilbraham Regional School District? And we've been doing everything we can to get the problem solved. Have you? Really? Because I feel like the guy in war games who just says, can't you just unplug the damn thing? It's insane. How can you design a system that you can't bypass, that literally keeps lights on, and there is no way for you to figure out how to just turn the power off? Hey, talk to the electric company. Maybe they can just turn all the power off and then reset the thing somehow. There's got to be a way, but this is insane. Well, I think it has something to do along the lines of what Arseny was saying with that integration to the systems that are in inconvenient, sort of hard to get to places that by having this, it allows you to do things remotely without having to send someone into a machine room somewhere. They have lights, a light switch, the easiest thing in the world. It may have been like relying on something that was just unaccessible and broken, and they would have had nothing were it bypassed. I'm all in favor of convenience. I'm all in favor of gizmos and the modern things of the day, but you always need a way to get around it if and when it fails. It always fails. It always will fail one way or another, but these people, they installed a system that there's no way around. It failed, and they're screwed, and they're making the taxpayers of the area pay for their stupidity. I really don't think they should be held accountable for this. This is something that was a really, really bad decision, and those kinds of bad decisions should be held accountable. Rob, and welcome, Gila. I see you made it. Thank you. Yeah, I am heartened by the hacker spirit evident in the staff of this high school because this new story on NBC talking about this mentions that when the teachers have to do things like show a film or project something onto their whiteboard, they figured out that they can reach up into the sockets and unscrew the light bulbs manually in order to darken the room. That's being credited to hackers? Like literally knowing how to unscrew a light bulb? Okay, you know what? How many teachers does it take? You know, with all the bad press we get, I guess we can take that. Yeah, we do know how to unscrew a light bulb. We can manage that. We have to stay on task if we accomplish what you're there for completed, so by any means. Wow. Arseny, we didn't point out that you normally live in Russia. Well, not anymore. Not anymore. Disclaimer, disclaimer. Fortunately, yes, but when you were there, this kind of thing wouldn't happen, right? I mean, it's interesting. I think these problems are just, you know, universal stupidity is universal. True, but keeping the lights on, period, is a challenge in many parts of the world. I don't think they'd be so quick to jump into this, you know, super, quote unquote, modern, efficient way of doing it. The smart home thing is getting out of hand everywhere. But this is not a smart home. This is a stupid school. This is a stupid design. Yeah, it's just wrong. Okay, and now for the ultimate, we're going to go into something that we always knew was going to happen at some point. We always knew at one point in history or another, the no-fly list would be compromised. And that is exactly what has happened. And that is why Lorex from Distributed Denial of Secrets is joining us tonight. And Lorex, maybe you're the best person to simply tell us what happened. There's a story in the Daily Dot that really does a good job of describing it. But you guys are on top of all of these security breaches and leaks and embarrassments. But this one, I mean, we're talking, I think, over a million names of people. And we're talking, you know, some of them are legitimate terrorist types. And some of them are eight-year-olds. There's all kinds of variety here. But can you tell us how this happened? Can you hear me? Yes, we hear you fine. Great. Yeah, so the Daily Dot was the first outlet that reported it. And it was a small regional airline from Ohio that I think is part of United Commuter Service called CommuAir. And the security researcher was browsing Jenkins servers on Chinese Shodan, which I guess is called Zumai, and came across some keywords that made her think that this was an aviation-related entity. And eventually, they found the no-fly list. Maya Arsene Krymu was the hacker who reported this breach. And the Daily Dot also was checking the data set pretty early. I think that they were collaborating before that story came out. So, yeah, there are more than a million and a half lines on the Excel spreadsheet for the no-fly list. There are two parts of this data set. There's the nofly.csv, and then there's the selectees.csv, which is a smaller list of names of people who aren't necessarily banned from flying, but they are selected for the no-fly list. And then there's the selectees.csv, which is a smaller list of names of people who aren't banned from flying, but they are selected for increased screening. And it's sort of up to the discretion of the TSA agent on duty, whether they can fly or not that day. So the file is actually called nofly.csv. It's not like they were trying to make it at all hard to find. This server was something that they were using for testing purposes. The original people who found the leak, they didn't know when the list was dated from. But before the first Daily Dot piece came out, the airline issued a statement saying that it was from 2019, so it wasn't the most up-to-date list of names on the no-fly list, but it was a genuine snapshot from 2019, which is pretty recent. That is incredible. What has been the response so far from the airline industry, from governments around the world, at having this information just made public, I guess? Well, it hasn't been made public in that the researcher has restricted access to the data set. I think that Maya replied to maybe a few hundred requests for the data, and DDoS Secrets has a bigger archive of data sets, and we have this category called limited distribution, where we routinely put data sets in this category that are for requests from researchers. So it's not that the list is public, anybody can search for it or find it yet. It's restricted to people who have published research in the past and who can be generally considered that they won't leak the full data set, because we think that it would cause more discrimination of the people who are perhaps on this list than they've already been through just by being put on the list. There's no due process. There's often no way to get yourself off the list. There are names on the list of people who've been dead for years. As you mentioned, there's children on the list. So both Maya and DDoS Secrets think that for harm reduction, it's best if we don't publish the full list. Absolutely, yeah, and that's extremely responsible. I just worry if somebody had gotten to this first, before that researcher was able to find this, then that list would indeed be public, or even worse, just given to certain people who really shouldn't have it and used for nefarious purposes. But has there been any kind of pushback from other organizations or governments, the fact that you have access to it at all? Nothing official. I mean, I heard that there was a Republican Congress person who wants to launch an investigation. It might be an investigation of the airline for leaving this sort of data on the open web. It might be shooting the messenger, which often happens with hacking cases where they go after the security researcher who found the vulnerability. We don't know, but it could also just be looking into the fact that there is this ballooning no-fly list. The names, I think the number of names, the amount of names on it should be surprising because previous reports of the no-fly list have listed things like 81,000 was reported in 2018. In 2011, I think it was 16,000 people who were on the list. But if there's a million and a half rows, some of them are duplicates, but one can assume that there's more than 100,000 names on this list now. Yeah, it mentions that the recently freed Russian arms dealer, Viktor Bout, he had over 16 potential aliases as well. But that's probably an exception. Even if you divide this in half, that's still 500,000 names. That's a lot of names of people who can't fly. What does it mean if you show up on this list? You're just barred from getting on a plane, period? No questions asked? Well, I think it is the U.S. no-fly list, so I don't know how far outside the U.S. that sort of ban would travel. The FAA controls a lot of air brules around the world, but it is specifically a U.S. no-fly list. Yeah, I don't know the answer to that question. I think that it would depend. Like you said, the Viktor Bout was on the list more than a dozen times. That was unusual. A lot of the names only have like four or five variations. Some of the names are only on there once, so they're not all duplicated to that extent. But I do think that they have problems with Cyrillic alphabets in the U.S. no-fly list. I was going to ask, how do other alphabets and languages get translated? One thing that the researcher said, it's just crazy to me how big that terrorism screening database is, and yet there are still very clear trends towards almost exclusively Arabic and Russian-sounding names throughout the million entries. That's something that is definitely cause for concern. I just wonder how many innocent people are caught up in that. Yeah, I mean like some of the names on the list were children who are four, eight years old or seven years old, who one would assume have not committed any terrorism at that age, and they're just related to someone who was on the no-fly list. So there's names like that that are totally just attempts at predictive policing or something like that. And then there's a lot of dead people on the list as well. Osama bin Laden is on there a few times. He is, wow. Okay, so what kind of information do they give for Osama bin Laden? The home address? Oh, they didn't have the home address, right? That's the whole point. Well, the list is redacted and only includes name and date of birth. So there are other columns that have been redacted either by the airline or by someone else before. So the list just includes the name and then the date of birth. So why would it be redacted if it was being used to basically keep these people off planes? I don't know. I don't know how the list was used in the testing environment that Commutair had left it open on the internet. Yeah, you know, that's something I can't wrap my head around. They're using it for testing purposes. Why not use a testing file? Why use the real file with real information in it? It just seems like a really bad idea. I mean, that's the thing. It's like this was on Jenkins server. The list was old, right? It's from 2019. And then the format CSV, I think, would have a lot of trouble with those alphabets we mentioned. But then the question is, shouldn't there be – I mean, this information is pretty sensitive. Shouldn't there be enforced rules on how it's used by the airlines? One would think. But again, we see this time and time again where these rules, if they even exist, just are ignored or bypassed. Yeah, when it comes to use of PII like this, a lot of organizations who have a testing environment set up, like from a technical standpoint, it's the easy way out to just take a snapshot of the real data, move it into the testing environment, and do what playing with it you have to. To come up with new data would take work, and it would be too much like work. And even when it's like ultra-sensitive PII and new data, it's still too much like work. And newsmaking stuff like the no-fly list, I think the temptation had to be there to just use what they had rather than do things basically the safe way. Yeah. For the benefit of listeners, we've mentioned Jenkins and Shodan. Does anyone want to give an explanation as to what those are just so people have a better sense as to how this data exists and how it was compromised? Well, I don't know. Shodan is a search engine of sorts for things that are open and online. I don't know much more about it. Can someone else elaborate on how these tools were used? No. So I can talk about Jenkins. That means it's a way to process builds. So if you are working on software that's not, you know, released, it's a way to process it, it's still internal, you would use a software like Jenkins to deploy it or move it down the pipeline. Okay. And Shodan, as Kyle said, is used to find things like video cameras. That's what I thought it was. I don't know what form it is if it's a program. Is it compatible with washing machines? You would find washing machines. It probably can be because it basically exists to find the kind of servers that internet connected devices of various types would have on the internet. So just various things that are connected up and making their presence known, Shodan finds them and you can search them. So that's what this researcher was doing. And I imagine researchers are doing this constantly. Is that right, Lorex? Yeah, I think that step one, boredom. Like so many of my other hacks, this story starts with me being bored and browsing Shodan. Well, technically it was Zumai, which is the Chinese Shodan, looking for exposed Jenkins servers, which I think Maya has done before and successfully found source code, which was the theme and one of the main leaks that they used to put out on their Telegram channel was source code that was exposed in these sorts of testing environments. So this was very much within the theme of how Maya usually works. So when something is found, what is generally the next step after that? I think it depends on the person. We at DDoS Secrets hear from a lot of sources who have a higher than average curiosity for what is out there and what can be discovered. I know that Maya has been criticized for basically not reporting this directly to the company and leaving everyone else out. I think Maya did report it to the company and the company fixed it before the news report came out. But Maya also involves journalists and communicates to the public when these sorts of things happen, which a lot of security researchers criticize it for. But yeah, so it really depends on the person. We at DDoS Secrets frequently hear from sources who find data that they think needs to make it out to the public. Now, when someone contacts you, you generally are very responsible with the data that is shared. As you mentioned before, only researchers or certain journalists are even allowed to view something of this nature rather than just posting it online somewhere where anybody could just download it and use it for all sorts of nefarious purposes. Do you get any pushback to that policy? Yeah, all the time people who wish that they had access to our limited distribution data sets are challenging our decision to keep something on the redacted stream. But yeah, we basically don't have the staff to redact the PII from everything that we archive. And we do publish a lot publicly. There are a lot of data sets that don't consist of mainly PII for people who are unrelated to the public interest. If it's data of politicians and corporations, then that's different than if it's a database of all of the citizens from a given jurisdiction and their ID numbers and their addresses. So we get pushback on both sides, I think, from people who wish that we published more torrents and public access data sets and also from people who don't think that we should archive hacked data at all. Well, if you're annoying people on both sides, you're probably doing something right. So that's a good thing. But how do you compare yourself to other organizations such as Wikileaks in the past when they would simply publish all this information? I guess that's probably the difference right there is they would publish a lot of this and not restrict access in many occasions. At times they did, but they've been criticized for not doing that. And that's what DDoS Secret seems to do differently. Yeah, I don't think that Wikileaks had a category for reserved data sets. Different reasons. They've also published less stuff and added less stuff to their archive over the years, like volume. Then we have, I mean, there are a lot of differences. I think that DDoS Secret tries to be less centralized around one person. We try to have multiple people doing multiple things so that if one person gets locked up or disappears, then the work wouldn't necessarily stop. We have a non-profit in the United States, which I don't think that Wikileaks has officially a non-profit. I think that they're registered as a for-profit corporation in Iceland. And then they have some non-profits in Germany that process donations for them. But they're not necessarily reporting their own finances in the way that we are to the IRS. I don't know. There's a lot of differences between us. Yeah, I do think that because Wikileaks doesn't publish or doesn't archive stuff in a reserved way, they've had to make different decisions about stuff that they put out there. So it's working for us so far. Although this week, with the amount of requests for the no-fly list, it has the system sort of like slows down when you're just humans processing these requests. I can imagine. Now, have you been targeted by any kind of agency or threatened with all sorts of legal action? In the past, we have lost a server to a law enforcement seizure in Germany. This was in 2020, I believe. 2020, Blue Leaks. You covered it at the time. But we published more than 250 gigabytes of data from U.S. law enforcement, fusion centers, and training facilities. And they got one of our public distribution servers taken offline that was in Germany. We did lose some data, some indexed data, and like a search engine at the time. So that was pretty annoying. But recently, we haven't had any new letters or indications that the no-fly list in particular has pissed anybody off. Wow. Now, how can people reach you if they find themselves in that particular situation? If they find themselves in that particular situation where they've discovered something and they want someone responsible to be able to guide how or if it's released, how would they make that initial contact? We have an email address, submissions at datasecrets.com. We also have chat accounts that they can contact if they don't want to put it in an email and talk to us about the data set. We ask that sources contact us after they have a full copy of the data set and not when they're like in the middle of anything because we don't want to be involved in anything that happens until the data has been reviewed by them. So yeah, contact us. Contact us. Details for like what's the most up-to-date way to reach us is on datasecrets.com. And I imagine people can make contributions as well. Contributions. Yeah, there are a few ways that people can contribute to the project. The most helpful way is like seeding the torrents. When we put new data out, download it and leave your connection open so that other people can grab it quickly and efficiently. We are also like a registered non-profit so people can donate to us and get a tax write-off. Yeah, datasecrets.charity is where we have sort of like a donation page. Was that what you meant by contribute? Other things that I missed. Because this kind of thing, it takes such courage and it takes such fortitude in just continuing day by day to try and share this information in a responsible way. On that note, what kinds of requests have you been getting for the no-fly list? Some of them might be funny. Oh, yeah, I mean, because this sort of made a big splash on TikTok, we've been getting a lot of like high school students who are really interested in this like relic from the 2001 era of like a no-fly list. So there's like a lot of that, which I mean, I hate to say no to, but I also, yeah, I remember myself in high school and I wasn't necessarily the most responsible researcher. So there's been some of that. There's definitely been like intelligence community, like international intelligence community. I think that the Brazil Secret Service approached Maya and asked for it. And Maya was like, no. Wait, they don't have it already? Secret Service of Brazil doesn't have access to this? Yeah, I guess that the US has locked down access to this data to certain countries. And that sort of does show up in the list. It's like, which countries have intelligence sharing mechanisms with the US? Because those countries would have more names on the list. I know that like Ireland has quite a few like Irish names on the list. Like members of the IRA or something. Yeah, but there's like a lot of countries on names on there. There was a report from Italy. They found like mobsters and communists from, what's it called, the Red Brigade. Oh, the Red Brigade. I remember them from the 70s. Wow. Okay, that's probably a badge of honor for many people to be on the list. That is simply incredible. Hey, we're down to our last minute or so. Anybody out in Skype land have any questions for Lorax before we go for the on-air part of the show? No? Nothing? Robert, your lips are moving, but I'm not hearing anything. Just thanks for keeping it going. And yeah, the URL for DDoS Secrets, again, is D-D-O-S-S-E-C-R-E-T-S? No, just one S. Just one S. I would get the other domain too, just in case somebody types that wrong. Because I imagine a lot of people do. And Ken, your domain still can't be typed on Twitter, right? Correct. You can't put DDoSSecrets.com on Twitter. But you can put DDoSSecrets.charity on Twitter. Oh, okay. Yeah, folks, try it. If you type DDoSSecrets.com on Twitter, your message will not go through. It'll fail. Even private messages. It's the most insane thing. And I don't know of anyone else that that happens to. It's really silly. But indicative of the kinds of challenges that you face when you're involved in something like this. Lorax, any final words from you? Things you want people listening to the radio to know about? No, I mean, thanks for having me. It's great to chat. I'll stick around for the after show. Great, great. And that after show, by the way, is called Overtime. It takes place on YouTube on channel 2600. Or you can click on the link that appears at the top of the 2600.com web page. And we can take phone calls over there. Which we can't do over the radio right now. Because we're not at the radio station. But hopefully someday we will be again. All right, that's it for this week. We're off next week. And as I said, we'll be on YouTube in just a couple of minutes. 8 o'clock p.m. on channel 2600. Good night. 8 o'clock. 8 o'clock. 8 o'clock. Once again, a reminder, Off The Hook is not on next week. However, there will be 2600 meetings a week from this coming Friday. So please visit 2600.com slash meetings to see where your local hacker meeting will be taking place. Again, stay tuned for Overtime over on YouTube. And keep listening to WBAI. 8 o'clock. 8 o'clock. 8 o'clock. This is Ralph Poynter. Join me and others every Wednesday, 8 to 9 p.m. Eastern time on WBAI 99.5 on your radio. Now, it would appear the human movement is such that at any moment in history, there are too few that understand possibilities of existence that would benefit all who inhabit this planet and are willing to act on this understanding. This program will feature that few. What are your views on these issues that impact your life today? What are your views on America today? What are your views on America's future? Can we talk? Call in 212-209-2877 Wednesday, 8 to 9 p.m. on WBAI 99.5 on your radio. And welcome everybody to off-the-hook overtime Where we continue the discussion that just aired on WBAI for off the hook And we do it on the internet on YouTube and we can take your phone calls, but not right now Not yet, because we still have other things to discuss first. We want to make sure everybody made it Kyle Well, you're in the same room as me. So I'm pretty sure you made it. Yeah, I feel like I've Arrived I'm yeah, I'm coming in clearly maybe a little Dynamic. Yeah, I was gonna look at that thing that I do but continue I was I was listening to what you're saying Okay, good Yeah, look at our levels make sure they're okay and Robin Gila you made it. Okay We have yeah If I can just throw one thing out there pursuant to my tardiness in the previous hour Urban exploration is cool If you feel the need to put yourself on the train tracks during rush hour don't do that That is why I was late. Wait, what happened? Someone was on the subway tracks near our home So they shut down all the trains running into our part of Queens Okay, so if you feel the need to be on the train tracks Um, please don't call nine eight eight if you need to but a 40-minute Trip home took two hours and also it's raining and snowing. So I'm sorry. I was late Don't get on the train tracks for the love of God That's my public service announcement for the day and nine eight eight If those who don't know is the suicide prevention three-digit code now Which is an unusual one because there are still phone numbers that begin with nine eight eight So I'm not exactly sure how I'm not gonna call it to test it But I think you have to pause a little bit after nine eight eight or maybe you have to dial an area code now before any exchange I would have I would have used one of the other numbers that you know, like 7-1-1 does anybody know what that's for? probably not and It probably more useful to use that way. But what do I know? Oh Yeah for digging how many people are digging cables? I mean, come on they can they can have an 800 number or something That's a 8-1-1. You see we don't even know 8-1-1. What's 8-1-1? What's 2-1-1? Huh? Nobody knows Okay, and we're still checking to make sure people made it arsony. You're okay. You made it to Skype. Yes to YouTube land Oh and Laura, actually, you're joining us as well, right? Yeah, I'm here for a bit great, you know during the break. I Had a little talk with our friend over at chat GPT and I Asked I asked a favor. Actually, I lost the window. Yeah, I asked the the bot to write a poem about the no-fly list and This is rather beautiful. I think yeah, you guys ready for some some culture here Yeah, okay beneath the skies so blue and wide a list exists that's not so kind I Have to make it through this the no-fly list a name so dire for those whose name it holds a fire a Name on this list is a curse a mark of suspicion a blot That's worse a label of guilt without a trial a sentence without a chance to dial The reasons for being on this list may be secret known only by a select Okay, it's kind of clumsy there. No recourse. No way to clear one's name a Kafka esque nightmare a perpetual shame So if you find yourself on this list, you may feel like you've been missed By justice and by Liberty, but know that you're not alone. You'll see For there are others on this list who share your plight and your twist Let's hope one day we'll all be free from the no-fly list and it's tyranny Come on I think that's better than any of us could come up with in the 30 seconds it took to make that What are you applauding with your fingers there? Okay, he was I was just gonna ask could you stop asking it to write poems because the poems and we're making my head hurt You know that people have always had this antagonistic view towards poems and and and poets and I just think you know digital poetry is It may be our future. I don't know any any questions that folks had for for Lorax or about DDoS secrets before we open things up to I think I can we're For the listeners out there. We have a little chat. So so we don't we don't talk over each other. So like How do you guys draw the line on what is too much personal information because like some of this innocent people are getting stuck in these data leaks and it's like That's I could could potentially be kind of furthering, you know problems for people Yeah, I mean when there's like a large collection of ID scans or Or like a list of names linked to other personal identifying information then it's it Makes a data set a candidate for the limited distribution section Yeah, like like this one. I mean a lot of information is not is not being shared I mean it was redacted to start with Yeah, that's true even like this spreadsheet was redacted when it came to us But this this data set is like all personal information there isn't like a portion of the data set that we would have released that wouldn't have just like personal data in it, so Yeah, this one was pretty obvious that it was on the List for limited distribution the ones that are tougher are when it's like an email inbox of a public figure and You don't And like not all of the attachments are able to be text searched so Those are a bit harder to like parse through and find and make sure that there isn't Like a list of everybody in the country and their ID number Especially if it's like half a terabyte, yeah Yeah, so a lot of data sets get put in the limited distribution category while they're being reviewed for what's in there and then if They can be redacted or if there's a portion of the data set that can be released Then it's put in the public access portion Something that like I think that happened with was There was a ransomware crew that hacked a law firm in Chicago I think and It ended up being like a lot of PII, but then within their Yeah, the Jones Day law firm within the Jones Day like Emails there was a section that was Part of the law firm's review of the city of Chicago's use of violence And so those were like within a data set that might have a lot of PII there was a portion that we found that could be publicly released because these were like emails produced by politicians in the city of Chicago So, yeah, that was I forget like the timing of when it happened That was I forget like the time How long it took to find the portion of the data set that could be publicly released But yeah Go ahead, Rob so, um Lorex, uh, if uh, if you're comfortable talking about it, would you mind Saying a little bit about what led you to get involved with this kind of work and with data secrets Sure, um, well, I'm a journalist I went to journalism school and was reporting on protests and social movements and Stuff like from when I was in university and writing like school papers and stuff And I started covering the police I think my first job in journalism. I was working for like a website in toronto and The g20 came to town and so there was like a huge security like build up in the city and just like cameras going up everywhere and A lot of like money being poured into the police for this like three-day event um So I started covering them and I wrote about this like law that they got um secretly Enacted which like basically suspended civil liberties in the area around the summit and I was very interested in this process and so I started like filing freedom of information requests for Data about this decision to suspend civil liberties around the summit And it took like years before I got anything useful I made it one of my um graduation projects and I never got anything back from From canada because i'm based in canada um so it just Like journalists talk a lot about the freedom of information system being broken Um, and i've found that in my work and when I started working with leaks It's so different like you just get like Gigabytes or terabytes worth of stuff at one time Uh, and you have to sort through it and it's so different than working as a journalist and just like clawing and um Just like working so hard to get like one document back from the government, um So yeah, I guess that I came at it from that experience of Of needing documentation for my stories and not being able to get it any other way than from hacks or leaks Fascinating you know, I imagine um There are probably entities out there that try to clog your inbox with all kinds of garbage You know to slow down the processing of actual leaks that you might Be forwarded or information Um, is that a problem for you guys? Uh I mean, I think that there's people who try to submit stuff. That's not interesting a lot, but We have a pretty fine-tuned radar for it at this point. Um, and You can usually tell when someone's trying to waste your time versus when they actually have a lot of data People submit stuff that's like not actually hard to find or it's from like a public website or they Just scraped like some government database so Like there's some of that but like you can always figure that out pretty quickly um And yeah, there's a lot of like overselling to like saying I got all of this data from this really interesting entity But it might not necessarily have anything valuable in a large like container of stuff so right There's some of that Yeah, and and how are people's identities protected if they do send you something that they uh when you communicate with them do you have um any kind of sensitive information that you have to Make sure it doesn't get um exposed in any way Uh, we encourage our sources to stay anonymous and not to tell us who they are and To communicate with encryption with us so that other people also don't know who they are. Um some sources Want us to know who they are like if they're a whistleblower um, this can be relevant to the Ability that they have to speak to a data set so There's different kinds of sources but like in general our advice is To stay anonymous. Um, we will make no effort to identify our sources and Yeah Yeah, and you know i've noticed many times um, uh people have difficulty uh protecting themselves and you have to sort of coach them and say Don't don't tell me this or don't communicate in this way because You could be tracked or you could be identified. Uh, if um, if you don't take certain precautions Um, and that's that's always worrisome, especially if somebody is is dealing with uh, sensitive information. They might not even know the gravity of it Yeah for sure and I think that like that's one reason why we don't have a secure drop or run a secure drop because I don't think that we would be Confident that um, we have the infrastructure to maintain this sort of like physical safe um box that a secure drop requires like they you need a lot of investment and Staff in order to keep something like that going our methods of contact are more Temporary it's a chat account. Um, it's an email address Um, so we always will have an initial contact and then graduate to like more Specific methods to transfer data depending on the needs of the source And have you ever been pressured to give up information about a source? Um Like Like in a legal filing or something like that like no it hasn't happened that we have either been Held or questioned about a source That's good Hopefully it stays that way because uh, that's something that that journalists everywhere have to deal with Um being pressured to give up their sources and as most journalists, um are are quite firm in saying that we will not do that but The threats get thrown around quite a bit We're talking with lorax from distributed denial of secrets about the Recently revealed no fly list that was sitting around on a server Pretty much unprotected as is the case with so many things Uh, i'm going to take phone calls in just a minute. I just wanted to ask lorax one more thing Are there any particularly memorable? um Revelations that uh, you can speak to things that people have said look what I found Uh whether things you've used or not used In a no fly list specifically no other other examples Oh, uh, I mean it's it's hard to just like pick one I think that the From the recent stuff that we've put out Uh, there's been there's a big story in the financial times this week Actually, yes that you guys were mentioned in the financial times. I think it was today. Uh, but very recently. Yeah. Yes. Tell us about that Um, yeah that was based on one of the russian leaks, uh, which is publicly available from capital legal services A law firm that represents among other clients the wagner group, which is a mercenary Army, um bellingcat Revealed the owner and operator of the wagner group recently and and so Um, yeah, there's some information In the financial times as well as in open democracy About how Wagner and uses these lawyers Uses these lawyers to do their dirty work basically Um, but this is like a data set that we put out many months ago, but is primarily in russian and so Indexing it Translating it And putting it in front of researchers has taken months. Um, so but it's an interesting story for sure It's called wagner inc a russian warlord and his lawyers um in the financial times and Yeah In open democracy, I don't have the headline in front of me, but it's not paywalled there. So Definitely look it up. Yes, because financial times was paywalled. Um, yeah, okay Uh one more time before we take phone calls Uh, can you give out the website and and ways people can make contact or make contributions? Yeah, we are data secrets dot com d d o s e c e r e t s dot com Or dot charity is for our donation page and People can send us data people can send us requests for limited distribution data um if you need Some of our reserved data for your research get in touch with our email address press at d dot circuits dot com Great, and um, our phone number is 802-321-4225. That's 802-321-HACK Uh, if you have been war dialing us for the last half hour We're not going to pick you up because we know you don't want to talk about what we're talking about It's it's just a way that we figure that out, you know People call when we give the phone number out if they call before that they they Want to talk about something which is fine But right now we'd like to keep it to the subject that we've been discussing for the past Hour and 20 minutes. So 802-321-4225 Uh is our phone number if you have any questions for lorax or any thoughts about the the no fly list um, and uh being left lying around on on the server, uh, or any other thoughts about um, um, Security breaches in general. We'd certainly like to hear about that 802-321-4225. What's our what's our phone status? Kyle, are we still being war dialed by by one number or um, uh, yes, I think it's settling Let's uh, put it that way. There's a little bit of uh, um Dynamic situation because it's sorting itself out sometimes people who do that aren't even listening and so they don't even hear us say we're not going to pick up the phone if If you're calling us over and over again Before we even give the phone number out Just you know, it's it's it's better. Well, there's that that rush of people as soon as you give the number out obviously every uh handset is is uh picked up and people are Frantically dialing phone system overload sometimes and nobody can get through that happens. It's a real uh hassle at the radio station We have 10 lines. So that's easy. We could just go to the next line here. We have one so it's a little bit more tricky Uh, so if you have any questions, uh For lorax or for any of us on um on the issues we've talked about tonight, please 802-321-4225 Uh, give it a couple minutes to uh to settle in Um arson, it looks like you have something You wanted to say no you okay. Look you look farther there rob. You definitely look like something you have something to say Again you're muted Yes Go ahead. That's twice. I've done that now. Um I I just wanted to mention that if you're in the united states, uh, you can also call us toll free Um, if that matters to you, you can call us at eight three three seven five five twenty six hundred Or you could call us at our regular toll number eight. Oh two three two one four two two five Okay, and I understand that call is still coming in so nobody else can get through as long as that person is war dialing us Is that right? Um, yeah, it's it's uh, definitely Exercising the wires which i've heard is uh with older uh systems the the wires need to be warmed up Okay, you know what? I'm gonna try a new tack here. Uh, pick up the phone. We'll we'll we'll use reason here. Let's see if that uh, that Well, i'm not ready i'm not ready That's that's the noise that it makes when you pick up and you're not ready. Do we have somebody? Yeah, why don't you try this is somebody on the line? Yes, hi rebel. Okay, we figured we figured it was you. Um, can we ask you to call us back in 15 minutes? Unless you have a specific question concerning d-dos secrets um Uh d-dos secrets. I heard on the off the hook show, uh, maybe adolf hitler's on the north fly list Is that possible? That's the question you're going to ask The question you're going to ask um, okay lorax, I guess maybe If you want to address that, yeah, I can handle that. Go ahead. Um, no adolf hitler is not on the no fly list, um, jerry adams from the ira Is on the no fly list really wasab and laden. Wow. Um some fun names from Like Yeah other dead people but not no, there's no adolf hitler. I imagine u.s citizens. It would be the most interesting uh to to find out that they were on the no fly list particularly Uh members of of the government, you know that uh fell into disfavor or some former officials former officials So that you might not want leaving um There are some nazis on the no fly list um like It was from 2019 not Not after january 6th. So there's less nazis than might be on it now after charlottesville So like yeah, charlottesville names are on there um other white supremacists from charlottesville as reported by emily gorsenski So they found james alex fields the charlottesville terrorist um, greg conti And his neo-nazi alias greg ritter Uh is in the selectee list, which isn't the no fly but they are enhanced like enhanced screening lists also Elliot robert klein And his neo-nazi alias ally mosley is on the selectee list. So there are some nazis on the list How about tucker carlson you find that name? uh I don't know probably probably not at this stage, but at some point Um rebel any further questions Oh, he's gone. Okay. Wow Uh, eight zero two three two one four two two five. We have another phone call kyle You're making all kinds of hand gestures. I know. Yeah. Why don't you try now? Okay. Good evening. You're on off the cover time Yeah, no, I just wanted to ask uh, we're talking about the no fly list Yes, go ahead Yeah, I just had a quick question. Is this no fly list? Is it a secret? I mean, can you just go online and keep your names on this list? Uh, no, uh, oh lorax you want to speak to that? Uh, no, it's you can't it's not it's also not a top secret document or anything that's classified because Um, the government hands it out to so many airlines that they can't classify it So it's not like a top secret document or anything like that, but it's also not a very open data set that That has leaked before What what would be the point of not just making it public, you know, you know If you're on there now, you don't even bother trying to get on the plane. Like why would they just put it out there? Uh, because there's a lot of possible negative consequences for people whose names are on the list Through no fault of their own. Um people who are underage people who are dead um I imagine you wouldn't want to tell somebody who is uh, you know, a criminal mastermind That they're on the no-fly list, you know, is this ever used for for actually capturing somebody who's wanted Uh, yeah, I don't know I imagine a lot of people Know that they're on the no-fly list already And don't fly if you have an alias And that alias is on the list um Then you know that you can't use that one anymore. Yeah, right. Good point. Uh caller any other questions? no, I was just gonna say because i'm pretty sure like I was just wondering because i'm sure there's like regular people not like The adolf hitler type i'm talking just regular folks whose name is just on there by mistake Who i'm pretty sure was curious to see their name is on there And I was you know, it would be nice if they just published the list I'm sure there's like mistakes people whose names got on there by mistake or whatever I don't know. It would have been nice if it was public Yeah Yeah, that's that's a good point All right, thank you have a great show Thanks. Thanks for your call I I imagine, uh lorex that's something that you you're constantly weighing over at tda secrets uh the public benefit for this knowledge getting out and and uh The benefit for keeping certain things, you know, uh private as as they've been Um, yeah, there's a lot of people who've written in to be like Am I on the list is my relative on the list? I just want to look up one name um and We haven't come up with a way to like do that in a privacy preserving way if anybody has like an idea of how to Permit those sorts of like lookups and get in touch with us But I think that there's a lot of potential for abuse, uh for that sort of function of just like False positives looking up a name and then Being like oh this person's on the no fly list. So i'm gonna Add them to my own list of whatever like people in brazil who the brazilian secret service wanted to Um put on their lists they just wanted to like cheat cheat from the u.s list and and Hurry up their own Creation of something like this. So I don't think that that's the direction that we want to see things going either Is is this the kind of um information that any employee at an airline would be able to get access to? I think so. Um But I don't know i've not worked in aviation, I mean I think that um probably many employees at an airline who are doing bookings or those sorts of things would Be able to access An a version of this list would somebody taking a booking on the phone say? Oh, excuse me, sir. You're on the no fly list. So we can't continue with this Would they actually be that courteous to tell you that or would they just let you go to the air? I don't think that they'd tell you if you're on a list. I think they would just like refuse your booking or Yeah, I don't know how I don't know how that how it would work um But we're learning more we're learning more by the day. We have another phone call. Okay. Good evening. You're on off the hook overtime Yes, the way you could get around the no fly. This is I put my real name because I got a show id But I put a fake like they ask you to put your birth date. I just put a different birthday They don't check your birth date All you they do is check that your name is on the ticket your name is on your id and that's it Your birth date is not on your ticket I'm not sure about that. I mean, uh, well if you're flying internet, have you ever tried that internationally? Not internationally, okay I suggest if you try that internationally you might get a different response and if you try it domestically because uh, they they do 10 I mean, they're going to match it against your passport. Obviously International oh, I think because oh, they don't have a don't apply for domestic for international. No, I think the no, uh, Well, actually, uh laura actually could you could uh, clear this up as is the no fly list, uh for domestic flights as well as international Yeah, I mean I also don't I don't know the answer to that question I know that this list has A lot of non-us citizens on it. Um It's probably mostly non-us Yeah citizens But I don't know I mean commute air is also a domestic airline. I don't think that they fly internationally so the Like the jurisdiction of the airline that this leak comes from was a domestic us jurisdiction I mean if I was an airline, which is a sentence, I don't say very often but if I was um, I probably wouldn't want somebody flying. Uh locally who's on an international do not fly list I just think that it could be awkward Uh rebel and any any last question from you since so Why do you uh, why would you have a toll-free number? Why people don't really need toll-free numbers anymore? Because one of our listeners asked for it and we were we were being nice and uh, And and now you're saying we don't need it. So I don't know. Maybe there are people who don't have access to um, uh, you know to to to a regular phone line or I know there's no pay funds anymore. So it's it's hard to use just a pay phone to call without putting a coin in But there could be a situation i'm sure there's somebody out there who will call the toll-free number and tell us why? Yeah, but then you're paying for the call Actually, we're not whoever donated the um, uh, the line is isn't that right rob? Yeah, our uh, our friend of the show lucky 225 set that up for us and uh, We're very grateful to him and and whatever it costs, uh, we we do not uh, we're not responsible for it It was a nice donation But hopefully we don't get a big fat bill in a few months, you know, that would That wouldn't be nice. Um, but but yes, thanks for that back in 15 minutes with my um, with what I know Rebel this counts so you've made you've made two phone calls so far. So You get my list i'm back a list. What do you mean a list? Yeah My list of uh things to tell you a list of things to tell my god, this is what we have to deal with Well, i'm back in new york. Are you back in new york? Okay Okay, call area called 518 502 i'll just demonstrate i'm not going to do the calling because I know you have people on uh, 518 502 Wait, what are you giving us? What are you giving us a phone number and see the albany area? I can tell that but why are you giving us a phone number? Well, because it says it's like a it reminds me of ai it just says hello. What do you want? What shall I maybe call? Well, yeah, but you could be calling a person who happens to talk that way And I I don't want to I don't want to call somebody at 8 30 on a wednesday night And uh antagonize them, especially if they sound like a robot Remember where we talked about last week about 202-456-1111 456-1111 we talked about calling the white house And I said 1414 was the extension that I usually would call when I was calling the white house. Yes Is the white house because when it well, it's all the white house 456 exchanges all the white house, but i'm saying the president's office Which you shouldn't call the comment But 456-1111 is the white house because after it says please dial whatever it wants to dial the two digits It says thank you for calling. Yeah, I know but again the whole 456 exchange is the white house So yeah, what the white house has 10 000 phone numbers. No, they don't have 10 000 phone numbers, but they have the whole exchange When you call a 202-456 number that says we are not the white house, let me know That's a number i'm interested. What about Okay, well what else trouble we we we do have to move on Okay, so the 518 number is you know, it says what do you want? Well, uh something like that like I don't know I forget what it's how did you find this number? Well, because I get calls from these numbers these 516 numbers and these you know Numbers in like illinois and michigan and all and it's you know Would you like medicare and all things like that? Like we have a special offer for you from marriott or whatever and when you call it it's a different thing That's because they're not calling you from that number you're calling somebody who did not call you So you're actually the person making the call now to somebody and annoying them Because their number was just used as a forgery on your caller id Right, so you shouldn't call them because you're not calling the people who called you That's what else I don't think that landed. Oh, let's see 703 818 Again again, you know if these numbers have not been vetted. I prefer not giving out phone numbers Unless you know, well, it's a wrong number When it's a wrong number every number you call is a wrong number if they're not expecting your call No, they get numbers instead of going John, I'm sure you have each H when it's you know, like they give you a recording and it's no intercept recordings. It's now Oh, we're sorry. You dialed the number that is not available, but I can help you find a number in your area A business or whatever like when a business disconnects their phone number They now instead of having that recording saying this number's been disconnected or whatever It says oh, you know, there's this ad saying I can help you find another business in the area That's that's a little creepy Damn, you know that I could demonstrate that I could call because it's you know business you want to hold Okay, let's let's do this. But then we want to open the phone lines through through other people. Okay. Yeah. All right Oh, that's right, he puts us on hold we have to wait for him to oh Oh, wait, hold on Yeah, i'm i'm happy to hold rebel thank you for this How long we're gonna wait I say 30 seconds get the phone over here is Cannot be completed. We can help you wait. Yeah, just repeating what you said. Can we hear it? For some reason I want to try and get a call But anyway, you don't know how to make a three-way call. Do you? I don't know how to make a three-way Then make a three-way call right now. Go ahead. Do it. Hold on. Let's try it again I think what's happening. I think he can only connect Stop saying you're gonna put us on hold. We know you're gonna put us on hold So I think what happens is um, uh, he can't three-way until it actually picks up But when it picks up it's past the point that he's trying to demonstrate So this is never going to be accomplished it's never going to work. Yeah, that's that's what I think it's called It used to be called supervision Like somebody would have to pick up. It's fun and exciting Well, i'm glad someone thinks so Um only a few more seconds folks and then we'll move on 802-321-4225 is our phone number Rebel that is amazing. Wow, where'd you find that? Rebel are you there? Did you just turn into a busy signal? Okay, um cutting edge right here. It looks like you have something to contribute to this fascinating discourse Actually something to contribute to this fiasco. Oh, wow all kinds of noises now. Sorry about that. Go ahead because When rebel began giving out an albany area code My first instinct was I don't know about y'all but I looked at the website for commute air And they have a facility in albany. So I thought he was giving us that number and it wasn't that number No, it was some poor robot sounding person. No, i'm well aware of that But when he said 518 I was like, oh, maybe he's giving us the commute air number. No, but it's interesting to me that in addition to all of the Safety implications and Privacy implications and all those things. My other question is are there going to be repercussions for commute air coming out of this? well you know if you leave something like the no fly list lying around on the server and somebody finds it and it becomes a big Public scandal as a result of that. I would imagine there would be some some fallout And I would like to think so and given the fact that a couple weeks When was it? The end of december when southwest airlines completely melted down And people were saying that part of it was because they don't have the same kind of Hub and spoke smaller carrier network That a lot of the other large airlines do commute air is a local carrier for united And they have hubs in houston denver And one other place that i'm forgetting right now So if that subsidiary were not allowed to continue to operate as part of the united network What kind of repercussions would that have? Nationwide That was where my mind went Which I suppose proves i'm just not really a privacy researcher. Yeah All right, folks a situation probably get fine though. It wouldn't be like You're out of business True but could I mean would united and the relationship would they and actually so actually You know coming from russia where the relationships suddenly get cut very quickly That could actually so it could be that these guys get fined and united wants to cut any risk Associated with this kind of data leak, you know, if it's if it's that bad. I don't think it's you know I don't think the fa thinks it's that bad All right, folks situation right now the phone is uh, rebel is just calling us non-stop, uh, so listen, let's just Finish the conversation. Hopefully, uh, we can open up the phone lines to somebody else and somebody else can dial quicker 802-321-4225 Kyle, let's let's pick up and end this go ahead Kyle you there? Okay Nobody's there. Who's calling then? There's a dial tone. You just got in between calls. I think great. Okay So i've kind of invited him to call now Yeah, you really want to talk to him? Is he there? Yeah, I just want to clear the phone line Hey rebel, is that you? Oh, yes, okay It doesn't matter what happened. It didn't work Uh, we're going to give you one more minute to finish whatever it is You need to say but we need to open up the phone lines for other people. So please go ahead. Okay yeah, what happened was it didn't work because I The supervision doesn't take it it just You know Where we're aware of this, okay, so that's probably why so, um, let's see, um Let's see what else you down to the last 30 seconds there. Oh, yeah about the uh, the airline thing Yes, southwest airlines because they don't have an updated computer system. I'm I very i'm glad I went to where on my vacation in january and not december But I missed by one day One day remember when I was in arizona. I came to california the day before they shut down the whole Entire airspace nationwide for for like From like nine o'clock in the morning to like five. Yeah, they they they did have a massive computer problem We didn't mention that actually on the on on the show when that happened. But yeah, that was a that was a big deal and this uh Data leak had nothing to do with that by the way. No this day. We had absolutely nothing to do with that Although you know if you can't access anything you can't access a no-fly list either. I would imagine so it would be a big problem Yeah Okay rebel finish up All right. So yeah, so I missed that by one day. I was flying out. I'd like something like one o'clock in the Afternoon mountain time so I would not have been able to had I been there a day later I would have been stuck until like maybe seven o'clock or maybe the next day The thing lasted the whole day and then there was like delays afterwards or something. We we all really dodged the bullet there Right. So, let's see. What else? Um, I guess At this point, um, uh saying our our farewells until next time would be in order I guess till next week Yes next week more things to say yeah, but thank you for calling and updating us and um, And we'll figure out, you know what? I don't hear the phone when I uh, when somebody's calling in the last caller I called in I didn't hear him Uh, you know, you're not hearing me. I don't think let me just we hear you We we definitely are hearing you And and the world is hearing you Listen rebel. We got we have to open up the phone lines because we have a limited amount of time here. So, uh I'm, not sure i'm being heard Okay, okay rebel. So we'll talk to you again soon. 802-321-4225 is our phone number And now this is the opportunity for anybody else in the world to give us a call Please pick up the phone line And uh, you have to dial one first Obviously in most parts of the country 802-321-4225 or country code one if you're outside the country We certainly like to hear from people in other parts of the world as we've heard from many many times Asia europe, uh, south america Anywhere, please 802-321-4225 uh any other um, um thoughts about um about these data leaks or uh, no fly list or airlines or Anything in particular rob? Um, just uh, I I had checked that the caller volume is pretty low on youtube. Um, I don't know what else we can I don't know what else we can do about this It's if I we raise it anymore it feeds back, um, it's a youtube issue i'm not sure what causes it Uh, but we have another phone call. Good evening. You're on I'll talk over time. Go ahead Yes, hi, can you hear me? Yes Okay, a few years ago. I discovered this very cool website Uh, it allow it had linked to the live broadcast feeds for msnbc cnn and several other cable channels Uh, unfortunately a few days ago, I saw that it went offline And I wanted to know would you guys know of any good message board or discussion forum? That I could post a question to to see if there are any uh other similar websites like that out there that I could go to What what what was the um, the old website called? It was called it was https Uh forward slash forward slash watch news live dot tv And it had been around for several years And it was great because you didn't need to install any software on your computer You just clicked on the link that was marked with the channel like msnbc um cnn Or pbs and it would take you right to their feed on your computer And um, like I said, the site is gone and i'd love to find another site like that and If you guys know of any or like I said if you know of any Message boards or discussion forums where there'd be people that would know that kind of information It looks like rob might have some information. Go ahead rob Well, um, I don't have information about this particular site, but I can say Um, first of all for like legal and legit ways to watch such things Uh, you can usually go separately to like the cnn website or the msnbc website if you're a cable subscriber And there are ways to put your cable subscription info in there and watch and watch those channels legitimately I think what you found was probably and i'm not familiar with this site. So I may be wrong but what you had was probably um a not so Up and up way of watching these and if you're looking for something like that a red box kind of thing sort of yeah But I think uh, I think if you're if you're looking for like the community where people talk about those kind of things Just go to search engines and put in The name of the old site and you might find other areas in which people are talking about that old site And possibly talking about newer sites if what you're looking for is like message boards and things Yeah, but also that to um Latch on to what rob said, um it you put in the information if you happen to be a cable subscriber or If you happen to know somebody who is a cable subscriber who will give you their information Because it doesn't cost them anything to do that. And then that gives you access to uh, um, you know To uh to feeds without actually having to be a customer yourself Right. Yeah, unfortunately i'm not i'm not a cable customer right now. I um have some uh Some uh cash flow issues and uh, I only my subscription only covers my internet connection. It doesn't uh, Doesn't give me access to uh getting cable channels and tv used to be completely free In fact, it still is uh, there's uh, i'm not a big fan of the digital tv system But you can put an antenna, you know outside and um pick up some some channels and sub channels And sometimes the sub channels are actually different cable networks Uh, not often but it does happen and you might find some channels that nobody else can see as well This is pretty much also a very good time to start investigating things like Some more sources for news you can look at some non-profit, uh things like wbai or similar, uh community Resources that you might have where you live Okay, all right. All right. Well, I appreciate your input and um, i'll uh, i'll try and pursue those other Let us know how you do and good luck All right. Thank you. Have a good night. Take care okay, let's uh, just keep it open for maybe one more phone call and hopefully, um, um, somebody wants to talk about the uh, The data leaks or uh security in general or anything else and any other thoughts from uh, you folks out there in skype land Uh, I forgot to plug that we also published this week Um, just like a simplified data server. It's data Dot data secrets.com. Okay, and it's like a list of our public data sets. There's more than 17 terabytes of public data there for easy download torrents are still like the best way to get our stuff, but Um, yeah, this data dot data secrets.com is back. So that's nice. Oh, that's great That that really is is helpful and as you said if people can run torrents for you that is uh, extremely helpful as well All right Well, you know, I I can't thank you enough for what you do for what the organization does Uh, it you know without something like ddos secrets around um I I you know, we would never hear about many of these things or they would wind up In the wrong hands being treated irresponsibly Um And then that comes down on all of us because then the hacker community is seen as the problem and as a real threat uh in this particular case, you know, I see I I see people acting responsibly and also exposing the tremendous security vulnerabilities that exist out there and um To think of these researchers that are just out there looking for these things. It makes me feel secure you know knowing that there are people on the lookout for for blatant security violations and and holes that you could drive a bus through It's it's the kind of thing that they tell you doesn't exist. But it does it always does And you know, we've been dealing with uh, these kinds of things for decades Yeah, I think that without um ddos secrets things would sort of like come and go and disappear and become harder to find um I think that the benefit that we bring is that people can be like, oh remember that breach from a couple years ago I wonder what that data can teach me about the current um state of the world, so We are a good place for like continuity. Um so that hacks don't just come and go and not get archived anywhere Absolutely. Hey, we're going to give it one more minute if anybody wants to give us a call 802-321-4225 802-321-HACK is our phone number If you have any thoughts or questions or opinions, please feel free to give us a call And of course, you can also email us oth at 2600 dot com and in case you uh, Didn't catch it at the end of the show. Uh, we do have 2600 meetings a week from this friday because we are not on next week Uh, but the meetings take place the first friday of every month and um, they take place all around the world and there's one here in new york city Which i've imagined rob. You have something to say about sam. Yeah. Um, the the one in new york city will be happening Um on february, uh third and at the city group building on 53rd in lexington And also after this particular meeting a bunch of us are going out to uh, sort of informal memorial, uh gathering remembering our friend jim, um past contributor to this program and Uh regular in the new york city 2600 seen since time immemorial So if you come to our next 2600 meeting, uh, just keep an eye up and a bunch of us will be going on To do that afterward Yeah, uh memories of jim that will be quite an event absolutely Um, and again, you can uh, check out where meetings are taking place um around the world 2600.com slash meetings And um, we're calling it right kyle. We're calling it no more calls. Okay, we're done for the night. Um, lorax, I I can't thank you enough for uh spending time with us and and informing everyone about what uh, you folks are up to over there and Uh and throughout the internet throughout the planet it's um It's good to know people like you are there and um data is being Dealt with maturely and responsibly. Well, thanks for also the work that you do. Um And thanks for inviting us on Okay That's it for us folks tonight and um, we'll see you again in uh, another two weeks Good night, everyone