Thank you both so much. You've been listening to the Electronic Intifada with Ali Abunima and Nora Barrows Friedman speaking with Haider Ayit and Ahmed Abufoul. This is listener sponsored non-commercial Pacifica Radio WBAI New York broadcasting at 99.5 FM streaming at WBAI.org. The time now is 7 p.m. Stay tuned for Off the Hook here on WBAI New York at 99.5 FM and WBAI.org online. Stay tuned. The number you have dialed is invalid. Please check which international operator. O nome marcado é invalid. Por favor, consulte seus operadores internacionais. We're sorry. The number you have reached, 99.5 WBAI, is now Off the Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a cough. We couldn't get much worse, but if it could, they would. Fondigley Bomb, but the flesh just picked for worse. I hope that's understood. Fondigley Bomb! We'll be right back. We'll be right back. We'll be right back. We're joined tonight by Kyle. Over here. How are you doing? Over in Skypland, we have Rob T. Firefly. Good evening. We have Gila. Good evening. And we have Alex. Good evening as well. Okay. It's been an interesting week. Update on all the whole business we were talking about last week. We are still working on getting more people involved. But we've had some amazing meetings since last week with core organizers and staff people from all over the world. I realized, you know, I was worried last week that we weren't getting a stronger response as we're used to. But after having conferred with all the different people that we are so lucky to have working with us, it's going to be an awesome event regardless. No matter how many people are there or aren't there, we are going to have some incredible things going on. So looking forward to the conference coming up July 12th through the 14th at St. John's University, Hope XV, our 15th Hope Conference, Hope Being Hackers on Planet Earth. There's going to be more information tomorrow on the 2600.com webpage. And also, if you go to that webpage, you'll see a link on the top of it right now that will take you to our overtime show that follows this show on YouTube. So all you need to do is click on that and you'll be transported over there where you can join in, call us, or just listen to more of us. Yeah, spread the word and absolutely stay tuned for more updates and information in the weeks and months ahead. Yes, Alex. I wanted to ask, did the CFP for Hope come out yet, the call for participation? Yes. In fact, we talked about that last week. You were there. This is the problem. We can't communicate. Yes. The call for participation has been out for about a week now. I'll tell you why. Because I was looking for it in my inbox to forward it to somebody who wanted to participate, and I couldn't. Well, okay, that's a good point. We sent out an announcement saying that the CFP was out. We didn't send the CFP to people. Maybe we should do that. Maybe that's a better idea. That was my question. Yeah. Did the official CFP come out? Well, it came out. It came out, but it came out on the Hope.net website. So what you're saying is that it's better if we take the CFP, make copies of it, and send it to thousands of people instead. Yeah. Okay. All right. I wouldn't say hard copies, but, yeah, email is fine. Well, yeah, we'll fire up the digital Xerox machine and take care of that. All right. Very good. I look forward to it. No, that's a very good suggestion. And these are the things we're bad at, Alex. You know we are not good at marketing ourselves. We are terrible at that. You know? And I'm not really, you know, that upset that we're terrible at that, but it does hurt us because so many people come to me and say, when's Hope? And, you know, Hope was last week, they don't know about it, or they think it's in odd years when it's in even years and things like that. So for now, Hope.net is where you get all the information, 2700.com. You'll also get information there, and we will be updating people quite a bit in the weeks ahead. Hey, some news. By the way, we have a special guest coming on in just a couple of minutes, so it's going to be pretty awesome and interesting. We have, Kyle, is everything okay? You're looking at computers and checking things. Everything is great. You have a crisis look on your face. It's okay? How would anyone know that? I don't know, but I know there was something going on with connections, and it's all sorted, though, right? I don't have to panic about this. It's smooth sailing. This is radio, E. I know that. In fact, there's a big sign that says, don't panic. It's only radio. When we get online, that's when we panic. All right. So, you know, you remember the trial, the DECSS trial back in the year 2000 that I got hauled into court for? That was a lot of fun. We've been looking to do something like that again. The closest thing so far, though, is that my judge, Judge Lewis Kaplan, has been in the news lately, so he's getting to have all kinds of fun in the courtroom still. Today, he threatened to throw Donald Trump out of the court. My judge, my judge did this. I like to think that I was a good influence. You know, I like to think that there was something about the way I conducted myself that gave this guy the courage to stand up to one of the biggest bullies that we've ever known. Now, he said, and there's news accounts of this everywhere. Lewis Kaplan is the judge. He said, Mr. Trump has a right to be present here. That right can be forfeited, and it can be forfeited if he is disruptive, which is what has been reported to me, and if he disregards court orders. So during this particular trial, you know, I'm not even sure which one this is. There are so many of them, but I think it's the sexual harassment and abuse trial, one of those. There's several of those, too. I don't know. Yes. You need a chart to keep track of all this. But basically, after an initial warning, Trump could still be heard making remarks to his lawyers, including, it's a witch hunt, and it really is a con job. This is while his victim is testifying that basically accusing him of sexual abuse. He's already been found liable for this. The judge, Judge Kaplan, then said, Mr. Trump, I hope I don't have to consider excluding you from the trial. I understand you're probably eager for me to do that. And Trump said, I would love it. He shot back. I would love it. And Judge Kaplan said, I know you would like it. You just can't control yourself in this circumstance, apparently. And apparently, that's where it stopped. You know, he didn't throw him out, but he got right up to the edge of the cliff. Just didn't do that final push. And I'm hoping, I'm hoping, Judge Kaplan, look, I know we've had our disagreements in the past, all right? You basically ruled against me. I was upset at the time, but I've gotten over it. It's been 25 years, 24 years. But now, I'm hoping that you can find it within yourself to kick that guy out of your courtroom tomorrow, if he's there, or whenever he misbehaves next. Go ahead, Alex. Well, I will tell you this, E, and if I recall from the DCSS trial, because I was there for quite a bit of it, and it was, in fact, it was before I was a lawyer. It was a couple of years before I became a lawyer, but it was one of the things that was actually quite inspiring to me, and one of the things that I think was really like an exhortation for me to become a lawyer. So it was part of my – those were some of my very formative years. But I remember you playing some silly games with Judge Kaplan yourself, as a matter of fact, when he had ruled that an injunction was to be put in place. If I recall correctly, you were enjoined from posting a link on the 2600 webpage that would link to the source code for DCSS. And for listeners that don't recall from 24 years ago, DCSS stands for D, Content Scrambling System. The Content Scrambling System was the encryption system that was used on DVDs, which were essentially a monument to stupidity. And it was a teenager, I believe, from Norway who came up with this code from DCSS. Yes. So Judge Kaplan said, if I recall correctly, and I might be recalling incorrectly or slightly incorrectly, that you weren't allowed to post a link on 2600.com. It wasn't just a link. It was many links. It was links to where DCSS was hosted all over the world. And, yes, we had sort of a directory there. Right. That's right. Yeah. So you weren't allowed to do that. So he enjoined you from posting this so people couldn't access the source code. So what you did was you just removed the hiker license. Excuse me. If I may, I complied. I complied. That's the first thing you need to say, Alex. I complied with the judges or Judge Kaplan's orders. Unlike Trump, I complied. All right. Yeah. As minimally as you possibly could. I mean, that was definitely coming close to the line there. I got to say. What did I do? I mean, I didn't have links up. I was told not to have links on the website. So everybody could see the link, see what the link was, control C and then control V it into their browser bar and then access the same materials. Alex, I can't control what people do on their computers. All right. Now, the judge told me not to put links up. All right. And I took the links down. Then we put up a list of website addresses. And nobody told me to take that down. Yeah. I mean, this was a lot of fun. It was so much fun. Being sued, you know, it's you got to try it. You got to try it a few times. It's it's something else. And that was the year we were getting sued by everybody. You know, all the the motion picture companies, the NFL, for some reason, got involved. And then Ford decided to sue us on top of everything else. So it's just it was crazy. We won that one, though. We won that one. But again, Judge Kaplan. Good to hear he's he's still he's still practice. I can't believe he was he was old back then in 2000. Yet he's still on the bench. And I mean, this would all do respect. He's he he seems to be as as capable as ever. And hopefully this time he'll get it right. I think so. Look, I think he's a great judge. He's tough. He's no nonsense. And also he's he's kind of fun to be in front of as a lawyer. And also with respect to the DMCA, that's still very, very much in the news and and in the courts. And in fact, I'm involved in a DMCA case right now that involves Altice and Sony and BMG. And, yeah, it's just, you know, nonstop fun. Twenty four years later, here we are still litigating in federal court over the DMCA. OK, that is something that is incredible. Well, any any other news from the world of technology? Anything interesting happening? Changes, developments? Things falling apart now? Just a lot of blank stares. You know, there was a go ahead, Rob. Sorry, there was a fun story about OpenAI kind of quietly deleting some wording in its terms of use. The wording that it that it deleted referred to referred to referred to a ban on activity that has a high risk of physical harm, including specifically weapons development and military and warfare. That language is no longer in their TOS. And people have noticed that and wondered just what military applications are in the works for things like OpenAI. I heard that story. And that was pretty, pretty disturbing that suddenly that was just left out. I just keep thinking of how bad OpenAI, ChatGPT, things like that are at like stating simple facts, giving good advice. And now they're going to be instructed to, I don't know, bomb certain people and not bomb others. Well, you know, I got to say, we should be worried about artificial intelligence and these quote unquote advances. It just it just seems like every time they try to do something, whether it be robotic checkouts at supermarkets or, you know, Tesla's driving around in subzero temperatures, something really bad happens and it doesn't work out. And they have to go back to the old way of doing things because they just didn't think it through. Yeah, I'm not saying there isn't a danger here. There is. But we're going to have a lot of fun with the mistakes that they make. Now, this in this particular case, artificial intelligence being involved in military, that that could be a really bad mistake. So we have to be vigilant. We have to keep keep our eyes open on that one. Yeah, Alex, go ahead. Another thing I think is worth mentioning is the because there's irony, I think, abounds in this particular story was the story about the Twitter account or X account, whatever the hell you want to call it, of the SEC being compromised last week. And then used to announce the approval of a Bitcoin ETF or exchange traded fund, which is would be essentially wait for you to invest in cryptocurrencies with actually having to buy investing in a fund and not investing directly in the currency itself, like through Bymance or some other exchange or something like that. So it was particularly funny because the SEC account was actually compromised. It was an unauthorized post that came from the SEC announcing the approval of the of an ETF. Yet at the same time, you know, this is the SEC that has taken such a very active role in policing companies is cybersecurity disclosures. And in fact, this is the SEC that has recently sued SolarWinds, the company that was breached by the Russians, was I guess it was about two years ago. Their software Orion, which is used to manage massive amounts of IT system, was compromised and used as the basis of a supply chain attack that affected thousands of companies worldwide. And the SEC recently brought suit against them and their CISO for misrepresentations about cybersecurity. And there they are a couple of weeks later, getting compromised on Twitter, making false announcements to the world that are actually market moving. And I think this is, you know, such a great example of why. And I know I keep banging on about this both here on the radio and within the magazine. But why social media is just an inappropriate forum for official governmental announcements? We shouldn't be looking to X or Twitter for official SEC. Alex, I have to step in, please. Don't say X. Don't say X. Yeah, I know. Use the right name. Yeah, Twitter. It's Twitter. It's Twitter. It's Twitter. It is still Twitter. Well, it's not still Twitter, but that's what we're going to call it until it's dying day. Sure. Yeah. Well, why Twitter or Facebook or any of these are just so inappropriate for official communications. When you cannot guarantee the security of your accounts, and especially when many of these accounts are managed through third-party service providers who have some kind of API access or persistent session access to these accounts, there are so many different ways that they can be compromised. And I just think this shows they are inherently untrustworthy. Okay. Well, let's leave that there because I want to bring in our special guest, who is Micah Lee. He is Director of Information Security over at The Intercept, a security engineer, open-source software developer who writes about technical topics and leaked data sets and the far right. He is a frequent Hope contributor as well, and he has just put out a book, which is going to be fascinating to many of our listeners, I believe, called Hacks, Leaks, and Revelations. Micah, welcome to the show. Hello. I'm excited to be here. Well, I want to read a little bit from the intro here before we dive in. Unlike any other point in history, hackers, whistleblowers, and archivists now routinely make off with terabytes of data from governments, corporations, and extremist groups. These data sets often contain gold mines of revelations in the public interest and, in many cases, are freely available for anyone to download. Yet, these digital tomes can prove extremely difficult to analyze or interpret, and few people today have the skills to do so. Now, this book, entitled Hacks, Leaks, and Revelations, just came out on NoStarch. It's available throughout wherever you get books. And Micah says he wrote it for journalists, researchers, hacktivists, and anyone else who wants to learn the technologies and coding skills required to investigate these troves of hacked or leaked data. So this is not only a book. This is an incredible tool, from what I'm hearing. First of all, Micah, congratulations on getting this done. Thank you. Yeah, it's my first time writing a book. It turns out it's a lot of work. Now, can you give us a specific or even a theoretical example of leaked data being made available to people who don't have the necessary skills to process it? What kind of vital details might they miss? I'll use a big example that I use throughout the book, which is the Blue Leaks data set, which was basically, it was dumped on the Internet in 2020 in the middle of the Black Lives Matter uprising. Anonymous took credit for hacking hundreds of different police websites. Most of them were fusion centers. And they all basically had the same kind of shoddy web application, and they were all hosted in the same place and stuff. So they hacked them all, and it was 270 gigabytes of data. And, yeah, this data basically includes a whole lot of stuff, but a lot of it that I was interested in was a lot of, like, police misconduct around spying on the Black Lives Matter activists. And also around, like, fusion centers and how they work and how they, you know, sometimes even spread disinformation to local cops and things like that. Wow, yes. Now, we heard about Blue Leaks, and that's prominently featured in your book. And most of Blue Leaks, your claim, has not even been reported on yet. There's all this 270 gigs of data, and it hasn't even been processed. Yeah. Yeah, so when that was happening, I spent a whole lot of time looking in one little corner of Blue Leaks, the NICRIC folder, which is the Northern California Regional Intelligence Center, which is my local fusion center. So I spent a lot of time looking at that. A few people in, like, Austin, Texas looked at the Austin Fusion Center. A few people in Maine looked at the fusion center. But there's just so much more than that. It's all across the United States. And for the most part, most of it hasn't even been reported on, which is interesting. And actually, like, I noticed that in the last few weeks, there's actually been a few new stories coming out of Blue Leaks, even though this is from 2020, including, like, The Guardian in December posted a story that was, like, U.S. police agencies took intelligence directly from IDF Leaks Files show. And it was, yeah, so I guess training materials about Muslim extremists were taken from, you know, IDF and pro-azil groups. And so that's, so yeah, there's still stuff in there. And I'm hoping that more people will look into their local police. Now, you, if I'm not mistaken, got your start working with this kind of thing with the Snowden Archive. Is that correct? Yes, it is. The Snowden Archive was the first data set that I started working with and also kind of how I accidentally fell into journalism. Like, while Snowden was leaking documents, I actually was working at EFF. I was a staff technologist. And I got an anonymous email from just, you know, someone I had no idea who it was. And it was encrypted to my PGP key. And it was like, like, hey, can you please help me teach some journalists how to use encryption? And I was like, okay. And so I ended up teaching some journalists how to use encryption. And it turned out that I was talking to Edward Snowden. And I ended up kind of doing a lot of the, like, communication and security work for the Snowden League. And so after The Intercept was founded, like, Laura Poitras was, like, contacting me and being like, would you like to come work with us and do, you know, this security for journalists? Full time. And then I started, you know, after I started working at The Intercept, I also kind of did a bunch of journalism myself. I didn't really, I was never trained in it. I didn't really expect it to happen. But, but it's very interesting. And I like it. So you weren't a journalism major or anything like that? No, no, no. I was actually a college dropout. Okay. Good for you, then. Thank you. I mean, it probably inspires a lot of listeners that, yes, you can, you can become a renowned journalist. And investigator just by having, having the passion to, to follow this. But let me just ask you, since working on the Snowden Archive, how would you say your skills have improved in being able to process that kind of material? So, like, starting working on the Snowden Archive, I was really into hacking. I was really into, like, going to Hope and going to DEF CON and things like that. And I worked as a web developer. I did a lot of, like, PHP, MySQL stuff. And I was really interested in this stuff. But I had never actually, I didn't really have a background in, like, data science. I never actually, like, worked with big sets of data. And so, I sort of kind of taught myself a lot with the Snowden Archive, which is, which is a very difficult way to teach yourself. Because, you know, you have to do it on air-gapped computers. And you have all sorts of restrictions and all sorts of stuff. It was an intense time. But since then, I've spent, like, the last 10 years doing this. And there's just so many data sets that keep coming out that are, like, you know, in lots of different formats. Sometimes you have big jumps of emails. Sometimes you have, like, a SQL database. Sometimes you have, I don't know, like, a scrape of thousands or millions of JSON files or whatever. Or collections of Office documents. And so, basically, like, I've learned how to look through all of these. And, you know, in this book, I'm trying to go through all these different types of data sets and show you how to deal with them. Alex, I believe you had a question. Yeah. Mike, I just want to say, I think it's fantastic that you're self-taught in so many respects. And I want to go back to one of the things that you mentioned, which was that Snowden had contacted you asking if you could teach others to use PGP and encryption, which I think is hilarious. I mean, knowing what we know now, I think people forget that Glenn Greenwald had no idea how to use encryption back then. And then I think it was very ironic that he became such a pro-privacy advocate and was so internationally known for being pro-privacy. But at the time, Snowden actually had to pass him over. And it seems like go to you so he could – and you and Laura, presumably, could go and help him understand how to use encryption. I think that's really funny. That's exactly what happened. And I spent, like, a few weeks trying to – I mean, Glenn was living in Brazil, and I was living in Berkeley. So just, like, trying to, as much as I could, you know, over not-encrypted channels because he wasn't really using encryption yet, teach him how to use encryption and teach him how to use PGP. It was very – it was difficult. But PGP is, like, notoriously, like, pulling teeth. It's a very hard technology to use. And ultimately, we ended up actually getting Pidgin and OTR encryption working, like, with OverJabber. And that turned out to be much simpler. But, like, I don't know. Today, those problems have been solved. It's great. You could just use Signal, and you have end-to-end encryption, and it's easy. Security is much, much, much better today than it was in 2013. And I think a big part of that is thanks to the Snowden link. Yeah, no doubt. And one of the other things I wanted to ask you about, in terms of working with these data sets, you mentioned the Blue Leaks data set. I think, if I recall correctly, that came from distributed denial of secrets, right? Is that where that was originally distributed? Yeah. Yeah, it was. The group that claimed responsibility was anonymous, and they leaked it to distributed denial of secrets. And so I work closely with The Adolf Secrets. And so a big part about this book is that it teaches you how to look through data sets, but it uses the real data sets as examples. And so all of the data sets that you download, like, as you're following along, all come from VDOS Secrets, and they're all public and available for everyone to download. But, yeah, Blue Leaks is the big one that's from VDOS Secrets. That's fantastic to know. We've had distributed denial of secrets, DDoS Secrets on here a couple of times over the last few years, and they've always been fantastic. They do such great, fearless work. One of the issues that came up, and I guess, God, this had to be about a year and a half, two years ago, was that in the immediate wake of the Russian aggression in Ukraine, the Russia v. Ukraine war starting, I don't know if you recall, there were these massive data leaks from Russian enterprises, from companies, from government institutions all around the world. And DDoS Secrets was putting them out there, but the problem that they had was that there just weren't enough Russian speakers. And with all these documents being in a foreign language, all of them being in Cyrillic, it became really difficult to separate the signal from the noise. Is this still a big problem, do you think, Micah? Yeah, this is definitely still a big problem. And I remember that a lot. I actually, I wrote all about the, like, dozens and dozens of huge data sets that DDoS Secrets was publishing at the time. And I worked on this big international collaboration, like, looking into these data sets. I actually talk about it a little bit in the book. In fact, actually, one of them is the GTRK, which is a massive, like, state-owned TV station or a company full of TV stations across Russia. And in the example of email, of, like, reading email dumps, reading other people's email in my book, there's a, I had searched for the Cyrillic transliteration of Tucker Carlson. And I showed, like, a screenshot of, like, a Tucker Carlson segment that's being played on Russian TV, where he's, I forget exactly, but basically saying Hunter Biden, Ukraine conspiracies. But, yeah, like, that's definitely still a problem, especially with the Russian stuff, because there's, like, a lot of, you know, Russian-speaking journalists who are in Russia, but it's really not safe for them to be looking through this data. And there's, like, a handful of, you know, Russian journalists that are kind of in exile working on it. And there's a few really good newsrooms that are doing a lot of critical reporting on Putin and on Russia. But, you know, like, the scale of the data is intense. But also, this isn't just a problem with the, you know, massive amounts of Russian data sets. It's kind of a problem with all the data sets, because basically, like, every single day, pretty much, there's new big data sets that, you know, probably a lot of them have really interesting, newsworthy stuff that the public should know about. And there's so few people that really know how to even download them, much less, once you get them, how to actually, like, dig into them and figure out what all the revelations are. And so I feel like I'm kind of drowning in data sets, and there's just, I have to skip most of them when I hear about a data set. Like, you know, a tiny percentage of them I, like, go and grab and look at, because I'm normally busy working on other projects and stuff. So what I'm hoping to do is make a lot more people that have these skills and that can start doing this work. You're building an army, it sounds like. Exactly. Wow, that's awesome. Go ahead, Alex. And, Mike, what about, speaking of just, you know, the volume of data sets, right? I mean, the volume and velocity of data that's being leaked or exfiltrated in some way is so extraordinary lately. And I think a lot of that is born out of things like supply chain attacks. Have you looked at any of the data or played around with any of the data from the recent breach of the MoveIt file transfer system? I don't know if you recall or if our listeners recall, but the MoveIt file transfer system was hacked ostensibly by a Russian group by the name of CLOP, which translates roughly to bedbugs in Russian. And MoveIt is essentially like an FTP program or file transfer protocol program. And a lot of companies just left data in this FTP system, which had this universal vulnerability that was automated, that was the exploitation of which was automated by CLOP. And they were able to steal massive amounts of data from hundreds of companies. And then, Mike, as you probably saw, they posted a lot of this data out on the dark web if companies did not pay them an extortion to take it down. So there's massive amounts of data from CLOP that's out there right now that relates to a huge chunk of the Fortune 1000 in the U.S. and around the world. Have you played around with any of that yet? So I followed this whole huge breach somewhat, but I haven't actually looked at any of the data from it. And that's, like, an example. Like, I'm sure that it's full of stuff, especially, like, for massive, you know, international conglomerates and big companies. I'm sure that there's a lot of really interesting stuff in there. But, no, I haven't looked at any of those specific ones. Like, basically, what I kind of tend to focus on is I follow DDoS secrets really closely, like, what they kind of curate, which is, you know, they put out so many data sets so frequently. But it's still just, like, a tiny slice of what's out there. So I follow what they curate. And then also if people, like, reach out to me directly to, you know, tell me about something or to just privately send me data or something like that. But, yeah, so I had heard about that. I followed it in the news. But I didn't actually download any of that data. Yeah. I'll tell you, and speaking of downloading, it's actually kind of funny what happened with it, too, is because they had all the data available on the dark web. This is CLOP. So everything was through a .onion site. And some of these data sets would be, like, 300 gigabytes, huge amount of data. It's not going to work over a tour. I mean, it's going to work. It's just going to take you weeks. Well, exactly, and companies themselves whose data were released, I've represented a number of them, and it became impossible to get the data and then to validate that it was, in fact, their data or even try to figure out what the hell was in it until CLOP got wise to the fact that their download system was horribly broken, and they created torrents for these companies' data. So that was how they solved it. All right. Go ahead, Kyle. You have a question? Yeah. Hi, Micah. I was wondering, were there any – this has a lot of different software tools and things that I had never heard of, and so I really encourage a lot of people that are interested in the steps involved in doing this kind of investigative work. But my question was, are there any tools that you, like, wish you had or are there things that you don't have or that haven't been created yet and shared that would be useful in this that you haven't yet stumbled upon good solutions for? I mean, I'm sure there's a lot. There's, like, what I often end up doing and what, like, a big part of the book actually is devoted to is writing custom stuff. So if you have a specific data set that doesn't really fit the existing tools, that's why a big chunk of the book is to teach you Python programming so that you can just start writing your own, like, very simple scripts but that are able to just, like, go through stuff. And I feel like there could be tools that could improve a lot of that work and make it easier for people to do without having to do any programming. But also, you know, for everyone who's intimidated by programming, it's, like – there is definitely programming in the book, but it, like, holds your hand for the entire thing. It doesn't expect any prior experience. So if you're interested in this but you are, you know, not sure about the programming stuff, you could totally do it, and you could totally follow along, and it, like, teaches you the – not just, like, how it works, but the whole process. It's, like, okay, try running your code now. You see this output. Now try and add this thing and run it again. And another thing about that is that if you use – I mean, you were talking about, like, ChatGPT earlier, you know, ChatGPT for evil, but ChatGPT can actually be very useful for helping you write code. And so I think that if you pair this with ChatGPT, where you don't actually share any data with ChatGPT or OpenAI, you just say, I'm writing a program. I want to look through all the rows in a spreadsheet and do this. And it can give you a little bit of example code that then you could edit. And I think that that could actually save a lot of time. And actually, speaking of – you were asking about tools that will be great to exist that don't really exist. I think that there are potentially some AI things that could be helpful, but for most of this stuff, I really don't want to trust third parties with the data. So I don't want to, like, give a copy of my whole data sets to OpenAI or to Microsoft or to Google or whatever. I think that there's a lot of open-source machine learning and AI things that could happen locally on your computer. And so the more of that, if there's tools where it's, like, you know, to translation tools and transcription tools to convert, like, audio into text and, you know, summarization and all sorts of stuff where you can just do this all, like, on your own computer or even on an AirGraph computer. You don't need the Internet. You don't need to share the data. That type of stuff will be really helpful, especially if it's easy to use. You're listening to Off the Hook on WBAI. We're talking with Micah Lee, author of the just-released book, Hacks, Leaks, and Revelations, available at NoStarchPress and all kinds of other places where you get books. Gila, you had a question. I did. Well, Micah, it's not even necessarily a question, but I really wanted to thank you. As a person who is fascinated by data, but definitely intimidated by programming, I was sitting there reading the introduction. I had the biggest smile on my face. I'm really excited to read this book. I had a twitch. I was reading the intro on my phone, and I'm sorry I didn't have a computer next to me because I wanted to start using the stuff you're talking about in the book. This is really exciting stuff to be talking about, and the way that you have kind of removed some of the barriers to entry. I'm really, really excited to sit down and do this, not least because of the real-world examples you're using. These data sets that we've been talking about here on this particular program over the course of the last couple of years are the real-world examples that are being used in the book. This is, you know, I'm a programming neophyte, I will admit it, but I don't feel like this is something that is impossible or intimidating. So thank you so much for opening this all up to someone like me. I'm really excited to dive in more, Micah, and thank you. Yeah, absolutely. I'm really happy to hear that. One of the chapters that I had a lot of fun writing that is a data set that I believe you've probably talked about in this show is the Parler data set, which included a lot of videos from January 6th. But basically, this one, so on January 6th, 2021, when Trump supporters were trying to, you know, subvert democracy and everything, they, you know, stormed the Capitol building, and they all had their phones, and they all took videos of themselves doing it, and they posted those videos to this right-wing social network called Parler. And a lot of those videos had metadata with their GPS coordinates in it. So there was, like, a whole lot of stuff. After January 6th, the AWS, which is the Parler's hosting provider, announced that it was going to de-platform them and kick them off the service because they wouldn't moderate content that incited violence. And then also Google and Apple did the same for the Parler app. And an activist was, like, oh, these videos probably contain a lot of important evidence about the January 6th insurrection. And she basically, like, wrote a script to go through and download over a million videos, which was something like 54 carabytes of data from Parler over, like, the two-day period before they got taken offline. And so one of the data sets is the metadata from over a million videos from Parler. And so you end up, like, it walks you through writing the code to, like, the very, very simple code. These are, like, you know, 20-line Python scripts to do stuff like loop through each of the million files and figure out which of these videos were filmed in Washington, D.C. on January 6th. And then, like, how to actually, like, plot them on Google Earth so you can go around and be like, oh, here's what happened outside of the Capitol. Here's inside the Capitol. Let's watch this video. So, yeah, you can totally go ahead and do that using the book by following one of the chapters. And I'm really excited that you are so into the book. You know, it's amazing. You give readers the opportunity to actually download genuine leaked data sets and show them how to extract information from them. You give them the opportunity to work with the Oath Keepers data set, which sounds really scary, but it's also super intriguing. And I can see this being a really popular project among the readers. Is there enough to go around? I mean, yeah, so I use a bunch of specific data sets that I had, like, you know, like, looked at and worked with in my own journalism over the last few years as examples for this. And, you know, like, when you read the book and follow along, you'll be using these same data sets. But the real purpose was just, like, at teaching tools. The idea is that you should be able to take any data set that you end up getting your hands on. Like, you go to DDoS Secrets and see what has been, you know, released through them recently. And then you can go ahead and just download that one that you're interested in and then just use the skills to look through that. So, yeah, there's definitely enough data sets to go around. There's hundreds and hundreds and hundreds of terabytes of data that are just, you know, out there with a lot of really interesting stuff in them. We've had the folks from Distributed Denial Service on many times, or secrets, rather, on many times, or a few times, anyway. Would you consider them a model in how to process and share leaked data sets? Yeah, I mean, I really like how they work. And I actually think that it would be great if it wasn't just them, if there was, like, more organizations that did similar things. And it wasn't, like, just this one group is all we have. Because things have been kind of, like, tenuous in terms – it's, like, a tiny, scrappy collective that, you know, have very few – they have, like, two paid staff, and they live on a stipend. And, I don't know, I'm always nervous about the future of it. And I think that, yeah, go ahead and donate to ZDOT Secrets if you can. But it would be great if more organizations started doing this type of work. But, you know, obviously, there's a lot of risks. People tend to really not like it when you publish their leaked data. But I really like that they make a lot of data sets public. But then they also make a lot of data sets what they call limited distribution, which means instead of making them just available for anyone to go online and download, they give them to journalists and to researchers that request access. And so this is a way that they can protect a lot of privacy. Because one of the things about data sets is oftentimes you end up with, like, huge databases of people's phone numbers and email addresses and other private information. And maybe there's some really interesting stuff in there, but also there's a lot of private data in there. And so what they're able to do is – like, actually, a good example is the Oath Keepers. The Oath Keepers data set, there was actually two parts of it. There's a public part that anyone can download, and that's just a dump of all of their email from the Oath Keepers email server, from Oath Keepers.org email addresses. And then the private part is, like, membership lists and donation lists and things like that. And so what ended up happening is, like, a lot of newsrooms requested access to the private parts and then spent a lot of time doing, like, real investigative journalism, tracking down all these people who, you know, had at one point, you know, maybe been an Oath Keepers member or a donor or signed a petition for them or something like that and figuring out how many of these are, you know, currently active law enforcement, how many of them are politicians in elected office right now and things like that. But, you know, just because your name is on one of these lists doesn't necessarily mean that it should be public for the whole world, especially if somebody else – you know, like, you never know. You have to do real work to verify data. And so I think the whole limited distribution model does a whole lot to solve that. Interesting. Yeah. But, you know, DDoS Secrets is also targeted just for doing this. You can't even link to them on Twitter. That's been the case since before Elon Musk. So they've really had to deal with some degree of hardship. And I'm sure, as you say, there are people who aren't that thrilled that their data is out there. But, you know, related to that, how is it so much of this information is getting leaked? What are these people doing wrong? It seems almost everybody is having their data sets leaked at one point or another. I mean, I think the crux of the matter is that computer security is hard. It's really hard. It's like it's really hard to be a defender. It's much easier in some ways to be an attacker, especially if you, you know, don't really care about leaving tracks. And so I think that's the big crux of it is, yeah, like data breaches happen constantly because computer security is really, really hard to get done. But also there's a lot of a lot of the data sets are not necessarily even like a data breach. It's much exactly like the parlor one I was talking about. This was actually just public data on the Internet that was scraped. It's like somebody decided to sit down and write some code to download a million videos and extract the metadata from them. And anyone could have done this because they were just on the Internet. And it turned out that like a lot of those videos were used in Trump's second impeachment inquiry. And so that's that's one way. There's also like some other ways that aren't aren't, you know, hacking is sometimes groups have open S3 buckets or open like Google Drive folders or whatever, where they just have the permissions that wrong to just like allow anyone with the link. And this actually happened. What was the what was the name of the group? It was this it's this anti-trans group, the American College of Pediatricians. This is one of the data sets that's on D.C. They're like the Southern Property Law Center called them an anti-trans hate group. And they like did legal briefings to help overturn Roe v. Wade. They had a open Google Drive folder with 20 gigabytes of like internal documents. Oh, and somebody found the link, downloaded the 20 gigabytes. And now that's the data set. And that's not exactly a hack. I mean, sort of. It was just like a mistake that someone made. Someone just like wanted to share it with, you know, someone and didn't feel like, you know, sharing it directly with their Google account and just made it public and sent them the link and thought that would be good. But now the data is out there. And I feel like that's actually a lot of a lot of the case how these data sets get out there, too. We only have a couple of minutes left, but I'd like to give you a chance to talk about your work investigating America's frontline doctors, what you're able to uncover about them using a collection of hacked files. Yeah. So this is one of the case studies of the book. So basically, in the middle of the pandemic or early in the pandemic, in like 2021, a hacker messaged me anonymously on Signal and said that they had hacked the horse-paced peddlers and that they were hilariously easy to hack. And basically, it was this group called America's Frontline Doctors. And really, it was these telehealth companies that they were working with. This is an anti-vaccine group that was founded by Simone Gold, who is, like, a very prominent, like, kind of anti-science doctor. She was also a January 6th insurrectionist. She served a few months in prison for that. But basically, what they were doing was teaching everyone that, you know, wearing masks is bad, vaccines are bad. The only way to protect yourself from COVID is hydroxychloroquine and ivermectin. And then they were selling it to people. And so they had this whole network of, like, things where basically, if you believe this propaganda, you can go and pay $90 for a telehealth consultation. And then you get on the phone and you talk to somebody. And then they write you a prescription for ivermectin or hydroxychloroquine. And I found that basically, like, over 72,000 people were tricked into paying at least $15 million. But probably it was actually a lot more for fake health care during the pandemic. And, yeah, there's a whole case study on how all this worked. In this case, it was this isn't a public data set. This is a private data set that a hacker just sent me privately. And so it's not public data. And, in fact, it really shouldn't be public data because it's, you know, patient records. And it was actually, like, 250,000 patient records. And only 72,000 of them had ended up paying. But, yeah, people's private health information and that shouldn't be public. But I basically ended up finding, uncovering this huge scam that ended up, you know, triggering a congressional investigation into them. Amazing. Well, Micah, this has been so fascinating. And, again, congratulations on the book. It's called Hacks, Leaks, and Revelations, available through NoStarch Press and wherever you get books. Anything that you want to tell our listeners? Any links or contact info or anything like that? Yes. Go to hacksandleaks.com. That's the book's website. And, you know, so this is a book that's for sale. But one of the things that I really wanted to do is make sure that this information is available to everybody, even if they can't afford it. And so I've released the entire book under a Creative Commons license. And so the whole book is actually available to start reading now on the website, hacksandleaks.com, if you want. And if you like it and if you can afford it, then you can totally buy a copy, too. And it's probably, at least for me personally, way nicer to read a physical book that has all this information than just in a web browser. But, yeah, so please go and check it out. And I have some contact information on that website. And if you like it, let me know. All right, Michael Lee, thank you so much for joining us tonight. You're welcome to stay on for overtime. Listeners, you can write to us, OTH at 2600.com. Please support WBAI. Give to WBAI.org. We will see you again on WBAI next week at 7 p.m. And again on overtime, starting in about eight minutes on YouTube. Good night. Bernie Rose knows don't argue. I must do record my phone calls Are you planning as a leg out thing? He says you've been threatened by gangsters Now we know You're threatening me We can't fight corruption We can't fight corruption We can't fight corruption We can't fix They use the law soon To call that crime And I dread, dread To think What the future will bring When we're in Says the law No coffee principal No coffee No coffee 12 It's a rock while I'm talking Oh, they'll come first, they'll tie your guitars Catch twenty-two, they're suffocating the truth They won't make me an over the star Don't offer a thing of protection The use I love to come and run I try to think what the future will bring When we're there, it really takes the time When you're both close, don't argue Don't call me Starface My name is Bernie Rose Gangster Killer Mafia Killer B-E-R-F-I-E Killer This is Ralph Pointer Join me and others Every Wednesday, 8 to 9 p.m. Eastern Time On WBAI 99.5 On your radio town It would appear the human movement is such that at any moment in history, there are too few that understand possibilities of existence that would benefit all who inhabit this planet and are willing to act on this understanding. This program will feature that few. What are your views on these issues that impact your life today? What are your views on America today? What are your views on America's future? Can we talk? Call in 212-209-2877 Wednesday, 8 to 9 p.m. on WBAI 99.5 On your radio town Yes Thanks All right You For more information visit www.fema.org weiter