At the customer's request, the line you are using has been told restricted. Only local calls will be completed. I cut myself while shaving, now I can't make a cough. It couldn't get much worse, but if they could, they would. One day they bombed for the flesh to stay for worse. I hope that's understood. One day they bombed! One day they bombed! One day they bombed! One day they bombed! And a very good evening to everybody. The program is off the hook, back again after a few weeks. Emmanuel Goldstein here with you, joined tonight by Kyle. Technically. Yeah, technically joined by Kyle. We have over in Skypeland, Rob T. Firefly. Good evening. We have Gila. Good evening. And we have Alex. Who? Who, as usual, is far away on the microphone now, so you've got to turn your levels up. I don't know what to tell you. I'm trying here. Well, you've got to be a little louder than that. Or start shouting. Either one of those two works. We do this every week. Unless you're buying new equipment every week, I don't know why it keeps changing. But we have a lot to go over tonight. Now, we had a lot of activity a couple of weekends ago. We're going to discuss that in depth on Overtime Following on YouTube, 8 o'clock. Go to the link at the 20sandcrum.com webpage, and you can call in over there and talk about all kinds of things related to this show and other things. But, boy, there's been a lot going on in the world as far as technical issues. I don't know where to begin. I guess we should begin or try to begin in order. We had a bit of a breach over at AT&T, which I know has upset a number of people, and for good reason, for good reason, too, because what they're saying is that virtually every AT&T wireless customer has had their information compromised because of poor security, because it was just out there for the picking. Yeah, and the recently disclosed AT&T data breach has been linked to an American hacker living in Turkey, and the telecom giant reportedly paid a significant ransom to ensure that the stolen information would be deleted. Now, I wouldn't pay AT&T anything to get their promise that they would delete sensitive information. I wouldn't trust them. I don't understand how a company can trust anybody to say, yeah, I've got your data, I'm going to delete it. I mean, it just doesn't seem very smart. But then again, you have to realize these companies that have massive data breaches probably aren't operating with peak intelligence. Now, AT&T revealed a couple of Fridays ago that it had suffered a data breach affecting nearly all of its wireless customers. The company said that in April, hackers exfiltrated records of customer call and text interactions from May 1st, 2022 to October 31st, 2022, as well, for some reason, on January 2nd, 2023. So, if you're looking to get a backup of any text that you have sent between May 1st, 2022 to October 31st, 2022, that's Halloween, and also the day after New Year's, January 2nd, 2023, perhaps that data is floating around someplace. Okay, all right, all right, funny guy. Yeah, you know, perhaps you're not familiar with AT&T's service or lack thereof, but you're not saying very much to anybody who's actually a customer. Well, whenever I hear people talking about AT&T's service, they're usually shouting, and their faces are usually turning bright red at the time. But AT&T basically explained that the compromised records identify other phone numbers that impacted customers interacted with, including call or text counts and call durations. The content of calls or text timestamps and other sensitive personal information was not impacted. So, okay, it's a little confusing here. Text interactions, but not the actual text, if I'm understanding this correctly. The data doesn't include customer names, AT&T said. There are often ways to find a name associated with a phone number using publicly available online tools. It sounds like AT&T is trying to help people compromise the identity here. Yeah, the data that was compromised did not include customer names. However, you can get those customer names if you have the compromised data simply by using publicly available online tools. Thank you, AT&T, for that helpful information there. The telecom giant also noted that it does not believe the stolen data is publicly available and said it had received information that at least one person has been apprehended. AT&T is notifying roughly 110 million customers about the incident. More information relating to the AT&T hack became available a couple of weekends ago through a Wired report that AT&T paid a hacker roughly $370,000 in Bitcoin back in May in order to prevent the data from getting leaked. The hacker in question, who is a member of the notorious shiny hunters group, they provided proof of the transaction, which was also confirmed to Wired by others based on cryptocurrency transfer records. The hacker reportedly demanded a $1 million ransom from AT&T, but they bartered it down to $370,000. The hacker provided AT&T with a video showing that he had deleted the stolen data. Okay, you know what? I don't care how good the video is, but okay, you're deleting the data, but that doesn't mean you didn't copy the data 10 minutes earlier to a different computer. What does that prove? How do people believe this? I mean, fine, you know, maybe if the data is deleted and no further harm comes of all this, but honestly, I think the harm was done when the compromise happened in the first place, or it was done when data was left around in a place where it was likely to be compromised. Now, the AT&T customer data appears to come from the Snowflake Data Storage Platform, aptly named. Hundreds of Snowflake instances, including ones belonging to major companies such as Ticketmaster, Centender Bank, Advance Auto Parts, I don't know why they're in there, and Neiman Marcus, were recently compromised through the use of stolen customer credentials. The Shiny Hunters Group is said to be involved in the Snowflake attack. Let me repeat that. The Shiny Hunters Group is said to be involved in the Snowflake attack. I can just imagine Walter Cronkite reading that headline in the past. Yeah. Now, according to information obtained by Wired, John Binns, an American hacker who has been living in Turkey for several years, is also involved in the AT&T hack. In 2021, his name appeared in the press after he took credit for hacking T-Mobile. Okay, different company, but I guess they're all pretty much out there, ready to be compromised. He was indicted the following year and reportedly arrested in Turkey in May of this year over the T-Mobile breach, which may be why AT&T mentioned an individual being apprehended in its public statement. Now, 404 Media also learned from multiple sources that Binns is linked to the AT&T hack. A researcher who uses the online moniker Reddington told Wired that he was contacted in April by Binns, who had claimed to have obtained the call logs of millions of AT&T customers from Snowflake. Reddington was asked to facilitate a buyback of the data with AT&T, and he claimed to have also handled negotiations between the hackers and other victims of the Snowflake hack. AT&T was reportedly supposed to send the $370,000 ransom to Binns, but ended up sending it to a Shiny Hunters member due to Binns' arrest in Turkey. So the guy they were negotiating with got arrested, and AT&T was very diligent in making sure the money got to somebody who was involved in the compromise. Okay, you know, I guess that's honor. According to Reddington, Binns and the Shiny Hunters hacker stored the full AT&T database on a cloud server from where it was deleted after the company paid a ransom. Oh, you know, those cloud servers sometimes keep backups, and sometimes they get compromised, too. Yeah. However, they may have sent samples of the data to multiple individuals before it was deleted. You think? You think that's possible? Yeah, they could have sent samples all over the place. Absolutely. Security Week, which is where this article came from, has reached out to AT&T for confirmation, but the company has declined to comment. Yeah, I don't see why they would. I don't see what's in it for them at this point. Guys, any thoughts on this? This is unbelievable. Almost every customer of AT&T, their wireless network, is affected by this. I can't say I'm surprised. Rob? The funny thing about you were talking about the ransom being paid and then trusting the thieves to have deleted your data. The ransomware scene out there, the ransomware industry, because it is an industry, is an incredible thing because it has such infrastructure and it has such power, and it has basically an honor system on which it operates. And the advantage of being in a ransomware group that is honoring the agreement and deleting the data when they get paid means that if you find yourself getting ransomware by that group, you know that, okay, their previous victims haven't had their data leaked after the fact after paying. So if it got out that you weren't deleting the data and it leaked out somewhere else, that would, I think, spoil your chances of getting paid on future jobs, the way the organized crime of it all works. So it's funny to think about, but it's also this actual thing that exists, and they have, like, tech support people that will help, you know, little old grandmas who don't know how to use the Internet or Bitcoin through the steps of paying a ransom to get data back and things like that. It's an incredible thing. So think about what you're saying for a second. Again, this isn't a heist. This is a heist company. These are people that didn't just get away with something, but they're planning a career and getting away with the same thing down the road. So they need to build up their reputation as people who compromise data and then do what they say they're going to do with it and don't disappoint the customer. Is that what they are? Who pay them to delete the data after the data was compromised. Pretty much it's an organized crime like any other organized crime. Well, that's more organized than I'm used to as far as organized crime. That's something. I think a lot about this. I think these are companies. Some of us, we just can't avoid working with like having a phone is is sort of not even something we consciously think about. Right. It's something we all take for granted or just assume others have a phone. And I don't know. The more I learn about these communities and companies and everyone involved, the more I detest them. All of them. Every one of them. The companies, the actors that these other companies doing whatever fraud they're doing. I mean, tell me what the bottom line is for the consumers affected by this. Like, do they get anything, any kind of restitution out of this? Is there any kind of technical fix for this? Or, you know, are we going to be scolded and like have fingers wagged at us? Oh, yeah. Oh, you should have done this and you should have done that. And why did you do this and why did you do that? And all this sort of blaming of people who are just living their lives ostensibly and paying their damn bill for whatever subpar service, this whatever we call this bill that will go up because of the expense of this particular compromise. And, like, I hate the security, like, the security research and, you know, hobbyists out there, our own, you know, people that think this is hacking. Like, I don't think this is pushing technology anywhere. This is just, like, side hustle for people or their, like, full-time hustle. And I just don't respect it at all anymore. Alex, you must have some thoughts on this. Alex, are you there? Well, I've been trying to fix my audio for a while here. Is this sounding any better? Much better. Okay. Yeah. I generally think AT&T is a nightmare. I mean, to go back to one of your initial points, you know, about when people are mostly talking about AT&T, it's mostly them yelling about the service. I mean, I can attest to that. I was an AT&T subscriber for the mobile service for, I don't know, like, at least 10 or 11 years. And I always felt like they were trying to screw me in some way. It was terrible. I think switching from AT&T to my current carrier many years ago now was, I think, one of the best things that I ever did. I never trusted them. I don't think we as hackers and phone freaks have ever really trusted AT&T fully. I mean, can you trust any company where their corporate logo looks like the Star Wars Death Star? Right? I mean, that was always the joke, right, back in the 90s. I think this is really bad, though, that all of this data was accessible in some way. There's going to be ways to concatenate that data with other data breaches, and it's going to give people a very accurate picture of who was communicating with whom at what particular place. And we talk about this every time there's a massive data breach, which is that when you begin to combine these different types of data sets together, let's say you combine it with an airline's travel data that was compromised, you know, together with other geolocation data that may have been gone. And you can begin to really piece together a very intimate mosaic of an individual target's life, and that becomes really problematic, let's say, if you are working undercover, or you're some kind of confidential informant, or let's say, God forbid, you're a journalist, and the government or some hostile foreign power wants to figure out with whom you've been communicating. Or you're some kind of activist, right, let's say you're an activist, and you may be a foreign national of a separate nation, you know, maybe you are very critical of a foreign nation. I mean, think about Jamal Khashoggi, right, and how he was tracked by foreign operators, like, this is all making it easier and easier and easier for foreign powers to begin tracking U.S. citizens. And none of this is good. None of this is good. So I see this as just more of the same badness that we've been experiencing for the last half decade and change. Yeah, it does seem that way. On the note of accessing phones, accessing data, a lot has happened since we were on the air last. One of the presidential candidates has been shot in the head, fortunately survived, but it definitely was a rather traumatic moment for everybody. Another of the presidential candidates has dropped out. We can talk about that forever. But concerning the assassination attempt, the FBI had announced that it had accessed the locked phone of the shooter. A new report from Bloomberg revealed more details about the process and the phone that was used by the would-be assassin. After Saturdays, two Saturdays ago, Trump rally shooting, the FBI said the following day it had been unsuccessful in unlocking the phone. It was then sent to the FBI lab in Quantico, Virginia. And on Tuesday of last week, the Bureau confirmed that it had successfully unlocked the phone in question. Until mid-last week, though, we had no indication whether the shooter had used an iPhone or an Android phone, nor did we know specific details about the process. Bloomberg reports that the shooter used a newer Samsung model that runs Android's operating system. The FBI's initial attempt to unlock the phone on Sunday involved using Celebrite software to bypass or identify the phone's passcode. When that initial effort failed, the FBI turned directly to Celebrite for help unlocking the Samsung device. In other words, the software didn't do it, so they just called the company. And Celebrite then gave the FBI access to, quote, additional technical support and new software that was still being developed. With the new software from Celebrite, the FBI was subsequently able to unlock the phone in 40 minutes. Shortly after, the Associated Press reported that the shooter had photos on his phone of the former Republican president, President Joe Biden, and other officials. The FBI also reportedly found searches for information about major depressive disorder on the phone. Meanwhile, a leak on Thursday revealed that Celebrite can't unlock iPhones running iOS 17.4 and later. As of right now, Celebrite also cannot break into most iPhones running iOS 17.1 to 17.3.1, though hardware vulnerabilities to the iPhone XR and iPhone 11 mean those are exceptions. So, yeah, this is rather interesting. I think it speaks to what you were saying, Alex. Oh, where did Alex go? He's gone. Did he just walk away? What's... Okay. He appears to have stepped away. Great. Okay, he's back. So, Alex, any thoughts on this? Yeah, I mean, I think it goes to show you what I've been saying for a long time, right? That, you know, I think that for the security conscious, the iPhone is the way to go, right? You know, it's harder and it's obviously much more difficult for some kind of threat actor to break into an iPhone. There's, I think, better inherent security. You have less control over the device itself in many, many ways, but I think it is overall a device that has better security. And it's interesting to learn, you know, that Celebrite, which is the bog-standard forensic tool that you use to analyze most mobile devices, devices, and has been for, I don't know, at least a decade or so now, that they still are having difficulty with iOS and the newer iOSs. But it also seems like, given enough time, those security controls can be overcome. So, you know, nothing is sacred here or nothing is permanent. There's always going to be this cat-and-mouse game, I think, between Celebrite and iOS. But I'm pretty happy to learn that my current iOS version cannot be popped. That's nice. And you really believe that. You believe that because they say it can't be compromised. I mean, look at it this way. This guy who did the shooting had an Android phone, and that's what they cracked. Do you think they're going to tell you, yeah, he had an Android phone, we cracked that. Had he had an iPhone, we would have cracked that, too. No, if you say we couldn't crack the iPhone, then every would-be assassin is going to get an iPhone next time, right? Because they assume, as you do, that it cannot be cracked. And I don't think it's that simple. I certainly think Apple has a head start on how to crack them. Well, quite possibly, maybe. I mean, they designed it. But still, I mean, if it's a matter of math, that might be problematic for Apple as well. But I think the real moral of the story here, though, is that if you are an assassin, you probably shouldn't have a lot of data on your phone to begin with, right? I mean, you should start wiping things. You should perhaps be using burner phones. I think the iOS versus Android controversy for assassins is one of the least of their worries, especially if you're doing it in such a way to very likely get yourself killed in the process. Well, it kind of also speaks to attitudes I think we all should have about what privacy you could expect from your device. Like, however, whatever measures, however secure, like, assume that it's basically open to scrutiny. I don't know. I wouldn't act as though any of these companies have an edge on it because clearly we've showed there's no legal will to prevent law enforcement or government access when you deny it or if you deny it. They do have recourse. And, you know, depending on however it's papered over, I mean, what do they care? Whether they tell you or not or honor it or not. I mean, it is possible. We know it is possible. These companies are soliciting and developing software continually that tells us it's possible. We know Apple will say up and down that they do not want to allow access to any of this. But ultimately, I mean, or that they can't possibly technically because it's designed for them not to be able to do anything. But when push comes to shove, when there is pressure, there seem to be a lot of engineering resources at the fingertips of those that want to compel these companies to make them easier to work with after especially a crime like this. But I think it just should be instructive to anyone with a phone that under the right circumstances, it will become not your private information anymore. I think that's the wise approach is to assume that your data is accessible. You know, no matter how many protections you might install and how many guarantees you might hear, when it comes down to it, you know, whether it's through a leak or whether it's through a government, your data will be accessible at some point, depending on how much effort is put into it. And in this particular case, who would argue, who would say, yeah, the potential assassin's phone should be protected? Of course, everyone is going to want to know what he was planning, what was being said on that, what he was looking for. And then once you say that's OK, you're pretty much opening the door to any phone that the government or authorities of one sort or another deem important enough to be able to crack. Yes, go ahead, Rob. I have a couple of thoughts about this. I mean, one of them is that, OK, we can argue stock Android versus stock iOS and, you know, what can or can't be cracked. I'm curious about the the fringier OS is the alternative ROMs that you could put on a phone. You know, the countless open source and free operations out there and how crackable they might be with the standard set of tools. Them being I'm I'm, you know, such a small fraction of the market. Is it worth it for the companies that make such tools to to even address them at all? But apart from that, of course, this is the sort of news story that people who want to limit, diminish, eliminate security protections for the average person love, because you can point to somebody who, you know, tried to kill somebody and say, well, we need to get at their phone. So, you know, why should the rest of you worry if your phones are not secure? Why should the rest of you worry if we want to, you know, the ability to get into all phones because we might get this bad guy? And so it behooves us, I think, to maintain awareness over the overall value of privacy and security for the individual without letting cases like this cloud that and, you know, end up in a situation where we have government mandated backdoors in software. Alex, it looks like you have something to say, but I'm not sure. Yeah, I think for those who are extraordinarily privacy conscious, there are there's always a lot of options that, as Rob indicated, go beyond the standard iOS, Android divide or debate, however you want to call it. But, you know, one thing to look to would would always be that organizations like cartels and massive drug dealers and things, right, would would use certain phones that were designed to be privacy enhancing in many ways. I think some of them were called sky phones and they were they were known to be like this kind of monopoly for drug dealers and others who really want to lock down their phones and they would lock down the OS and in many ways and make sure that certain data wasn't being stored locally on the phone. And so they were extraordinarily privacy conscious. But if I recall correctly, I think it was Joe Cox, who used to be a reporter for Wired. Now, I think he's with 404 Media. He he was hanging out with us last weekend, as a matter of fact, and he wrote a book about this massive sting operation that busted. It was an FBI sting operation. I think I think I think the book was called Dark Wire, as a matter of fact, and it was a massive FBI sting operation that busted what was essentially a telecom network providing telecommunications and phone service to drug dealers. And it was like this years and years and years and years long sting operation that ultimately ensnared a massive amount of drug dealers and and members of cartels. So there are definitely other options out there, but I think that they're just as vulnerable and just as dangerous as this novel that Joe Cox had written illustrates. That's something to to consider. Now, we're moving in in date order of all the momentous things that have happened since we were last on the air. And one of these events that took place strikes kind of close to home. It involves our good friend Virgil and Alex. Again, you have the update on this. Yeah, this is a pretty massive update, too. And I'm I'm very pleased to provide the community with this information. And it it it came on Wednesday of last week. So it was, you know, just a few days out of date. I think, you know, just a few days late for us to announce it that, you know, last last weekend. But the the long and the short of it is so we had filed a motion to have Virgil resentenced. And for people who don't remember who Virgil is, Virgil is a good friend of the hacker community, has been part of our community for for several decades now, probably going on 25, 30 years, I would guess, Emmanuel, right? I mean, since he was a teenager. Yeah, I'd say probably 25 in that realm. Yeah, so Virgil is extraordinarily talented guy. He was a senior person with the Ethereum Foundation, an American citizen, extraordinarily well credentialed Ph.D. from Caltech University. And I believe it was neuroscience and computation. And just Emmanuel, you I heard you describe him several times as a one man think tank. And I think that's absolutely right. So Virgil was a living in Singapore, went over to Pyongyang in North Korea and gave a talk at a blockchain conference over there about information that was eminently Googleable in many ways. And he self-reported most people that self-report, especially when you're an academic or you have some kind of Ph.D. Let's say you go over to Iran, you accidentally talk about geothermal energy origins or something like that, that you shouldn't have been talking about. You go and self-report. Generally, you would get a letter from OFAC or the Office of Foreign Asset Controls of the federal government. And they would say, thank you for telling us about this. Don't do that again or you're going to get in trouble. In Virgil's case, when he self-reported, he was ultimately charged with a sanctions violation, a violation of the International Emergency Economic Powers Act, which is coincidentally the same federal law that Trump tried to use to ban TikTok four years ago during the outset of the pandemic. So Virgil pleaded to the charge. This is making a very long story so much. Can I just make it a little bit longer? Because just a couple of details. When he went to North Korea, first of all, I've been to North Korea. Many hackers have been to North Korea because it's fascinating. And it had been easy to go there, fairly easy to go there, before Trump. Trump decided to ban travel to North Korea for Americans. Now, you mentioned he lived in Singapore and, you know, basically hadn't even come to the United States and didn't think that he should have to get permission just to go to a country that's nearby. And as you said, talk about things that are readily available on the Internet. So that alone was something that was kind of not reported enough. People seem to think, oh, you're going to North Korea, you must be up to something. And in his particular case, it was just curiosity like anybody else. Now, when he got back, he self-reported, as you said. He was interviewed by the FBI, and it was very convivial. It was very polite, and they were interested in what he did. He was giving them North Korean newspapers that he brought back, and he thought he was doing a good thing. He thought he was helping them. And we talked to him that very night afterwards when he went there without a lawyer. Big mistake. Folks, if you're ever called in by the FBI to be interviewed about anything, bring a lawyer, for God's sake. You cannot trust them. They made him feel that everything was fine. They said what you said, Alex. Don't do it again, or you'll get in trouble. And he had absolutely no reason to think that anything else was happening. Months later, on Thanksgiving Day, when he was arriving in the United States to visit his family on Thanksgiving, they arrested him at an airport, and his life has been utter hell ever since. That was, that was, what year was that? That was 2019. 2019. That was Thanksgiving Day 2019, because it was April when he was in New York, and the FBI wanted to interview him. I remember this. And then he had, yeah, yeah, he had spoken to the FBI several times. And like you said, Emmanuel, he thought he was doing his country a service here. And Virgil was always somebody that believed in American exceptionalism. He was very patriotic to the point of being like bizarrely patriotic. He really believed in American hegemony. And I think to a certain extent, he still does. But after what's been done to him by the federal government, it's got to make you see that in a much, much different light. So, yes, he was in the LAX airport. He was about to head back to Alabama, where he, the state from which he came and grew up, to go visit his family on Thanksgiving. He was arrested at the airport, and then I think that they had to bus him all the way across the country to New York, which is an incredibly unpleasant experience. And, yes, his life had been utter living hell since then. And he had, I guess it was the summer of 2021. I had known Virgil before that, but I wasn't really helping out with the defense because I was at a much smaller firm at the time. And we started helping out a bit in the background with the defense. I wasn't part of the decision whereby Virgil decided to plead guilty. I was actually still believing that there was going to be a trial the next day until I got a call from the Maine Defense Council telling me that there wasn't going to be. And to everybody's chagrin, Virgil had pleaded to the charge because it seemed like he was going to. It seemed very much like. Based on the evidence that the government had lined up and was going to adduce a trial and the fact that his hands were tied in terms of what he could adduce in his own defense, that would probably would have been better to to plead to the charge. So being found guilty by a jury would have been far, far worse for him. And just the way the case was being presented, as I mentioned before, just, you know, going to North Korea makes you seem guilty just by default. It probably was the right decision. I certainly can't second guess, you know, what was what was going through his head at that time. But as we're running out of time, let's get to the announcement that happened a week ago. So so, well, let's let's step back a little bit. And he was sentenced pretty harshly in 2022. I think it was April of 2022. He had been in confinement up until that point as well. But he was sentenced to 63 months in prison, five years and three months. And this past November, Congress had revised the federal sentencing guidelines and they had made it eligible to have retroactive sentences to retroactively redo sentences on the basis of these new guidelines. And you would have to make an application to the judge that sentenced you to be resentenced. You had to qualify for for this resentencing. You had to be essentially a zero point offender. You had to make sure that, you know, the offense didn't involve some kind of violence, didn't involve a firearm, didn't involve, you know, sexual violence of any nature. You had to have a very essentially low probability of recidivism of committing a crime again in the future. And the probation and we had made an application for Virgil to be resentenced back in April. And the probation department at that point had come out and issued a new pre-sentencing report. And they said, yes, we think Virgil is eligible for this resentencing. At that point, the government opposed Virgil being resentenced to a sentence lower than 63 months. They said, given the severity of the crime, I'm going to paraphrase their their filings to Judge Castile in the Southern District of New York. But they they very much opposed Virgil being resentenced. And they claim that given that defense involved North Korea, which was a hostile foreign power that was known to torture its own citizens. And they really worked it up quite a bit. They asked the judge to not resentence Virgil to anything lower than 63 months. The 63 months was still the right number, even though they had sought, quote unquote, a guideline sentence at the time of sentencing. And if the if the sentencing guidelines were and now our argument in response to that was the sentencing guidelines were what they are right now. You wouldn't have suggested 63 months. You would have said you would have asked for 51 months. So we had to explain a couple of infractions and things that the government was making a lot of hay about that Virgil had been involved in. Well, since he's been in confinement, you know, some things that were totally minor that the government was trying to, I think, to overinflate. And mind you, we're really working. This was an uphill battle because the judge that Virgil had really was not a fan of him. As you know, Emmanuel, he said some pretty nasty things at the sentencing. Hearing about Virgil. And unfortunately, other than what the government had put forward in its filings, there weren't a lot of counter facts about Virgil that were out there. And nobody really took the time to get to know him as an individual like we knew him. And had Judge Castell done that, I think it would have been a totally different situation. But in any event, it was a bit of a back and forth. We put in, I think, a very strong argument for Virgil being resentenced. Now, I always thought it was still an uphill battle. Last week, Wednesday morning, I get into the office and I get a notification from ECF and PACER, the electronic court filing system, that there was a decision on our motion. And I quickly scrolled down to the to the bottom of the motion to the judge's order where the actual decision was made. And I couldn't believe it. I really couldn't believe it. We won. We won the motion. We had Virgil resentenced. We took more than 10 percent off of his sentence. So we got seven months removed. That drops him down to 56 months. And this could this has a pretty massive effect here now. And and the reason being is because Virgil's original release date was January of 2026. So shaving this off, shaving seven months off of that takes a big chunk of time off the this release date, which was coming up. Now, BOP or the Bureau of Prisons was already making some kind of plans to have Virgil either go to a halfway house or perhaps even to home confinement as soon as January 2025. So now if you turn the clock back seven months from January 2025, you get to April 2024. Now, that's a date that's already passed. That's a date that's in the past. Uh huh. Right. So if we are operating under the assumption that BOP was looking to release Virgil to home confinement, possibly in January of 2025, that may explain why Judge Castile did not make the order effective immediately. This order that changes Virgil's sentence goes into effect on August 2nd. Now, the reason for that may be because now Judge Castile is extraordinarily smart judge. He's very, very tough and you don't want to be in his bad side, but he's very, very deliberative and very judicious in a lot of ways. Now, I would like to think that he recognized that this could have the immediate effect of possibly releasing Virgil on the day that the order goes into effect. And so by spreading this out, by spreading the effect of the order out and waiting until August 2nd, maybe he was giving the Bureau of Prisons enough time to get their ducks in a row and make their own calculations to determine whether or not that would in fact be the case or to determine where he goes on August 2nd. Can he go to some kind of halfway house on that day? Can he go somewhere else? We don't know. Now, the manner by which BOP determines exactly how to release somebody and what the release date should be is somewhat opaque. There isn't a lot of room for advocacy during that process either. But I would like to think that August 2nd or shortly thereafter may be the day that Virgil Griffith finally comes home. Well, Alex, you deserve a lot of credit for making that happen, making that possible, and we certainly will be keeping an eye on this and hoping that within the next couple of weeks that he will finally be released from the hell he's been going through because it's just – it's been going on way too long. Well, it really has. It really has. And I will tell you, one of the great things about being able to be counsel to Virgil for the last couple of years was to get to know him. What started as a professional relationship, as I mentioned before, has very much blossomed into a personal friendship. And I believe in my heart of hearts that Virgil and I will be friends forever. Yep. All right. We have only a few minutes to get into a big, huge story that happened. A lot happened. I told you, a lot happened since we were away. Since we were last on the air, that is. And that was, of course, the clown strike. Clown strike? Is that what they're called? No. Crowd strike. I don't know what their name is. They probably want to change their name. Airlines grounded flights. Operators of 911 lines couldn't respond to emergencies. Hospitals canceled surgeries. Retailers closed for the day. The Wu-Tang name site was down. No, actually, that's back up. Is that back up now? Yeah, Wu-Tang name generator is fine. Okay, because you want your rap name. Yeah, they know what they're doing. Okay, well, I was worried. These actions all trace back to a batch of bad computer code. A flawed software update sent out by a little-known, well, they're not little-known anymore, a cybersecurity company, caused chaos and disruption around the world on Friday. That company, known as CrowdStrike, based in Austin, Texas, makes software used by multinational corporations, government agencies, and scores of other organizations to protect against hackers and online intruders. Nice job, guys. You protected us into a shutdown. All these computers went down everywhere. And they all were running Microsoft Windows software and getting those dreaded updates that just got installed without any yes or no options. Now, the fallout was immediate and inescapable, highlighted the brittleness of global technology infrastructure. The world has become reliant on Microsoft and a handful of cybersecurity firms like CloudStrike. So when a single flawed piece of software is released over the Internet, it can almost instantly damage countless companies and organizations that depend on the technology as part of everyday business. So it wasn't a cyber attack. They were very quick to point that out at the beginning. But the effects on Friday showed how devastating the damage is when a main artery of the global technology system is disrupted. You know, an attack might have even been less damaging. This is unbelievable. Did you guys follow this? Go ahead, Kyle. Yeah, I know this is part of a package of software that helps larger institutions maintain big deployments of machines across the big network, however diffuse or global. And I think this is speaks to something about software orchestration and how we administer things in production. And also, I think, might be sort of the last we allow this kind of thing without using more modern tools or sort of ways to check it. I'm thinking like simulations or other sorts of mechanisms to prevent it from having these or sort of staggered or maybe other techniques just to not do it on mass like this. They're definitely not going to have the same procedure, I think, after something this massive because it really makes that whole business model look flawed. Oh, it absolutely does. Absolutely. Gila, go ahead. I think part of the significant issue here has been this idea of centralization of everything. One update gets rolled out to more than 8 million computers in one minute. The fallout is still ongoing. And I did actually want to share my favorite piece of the follow-up now, which is I don't know if you guys heard about this. This happened yesterday and today. CrowdStrike decided they were going to offer an apology gift to the vendors who were affected by the outage. Oh, boy. So, they sent everybody an Uber Eats code. Really? Wait, it gets better. Uh-huh. Everybody tried to cash in the codes at the same time. Oh, no. It crashed the Uber system, which decided they were all fraudulent. You know, a Hollywood script would be sent back as make it more believable because, wow, I wouldn't have even thought of that. It's fascinating. I'm watching the repercussions of all of this. Something that I'm hearing about a lot in my world is that Delta Airlines, due to their comeback from the shutdown, they've stopped letting unaccompanied minors fly. What does that have to do with anything? So, their systems were completely bollocksed up. They still are. They were excited that today they're back to, I think there are only 48 canceled flights. But, they weren't letting unaccompanied minors fly in case, I don't even know why. So, people are telling stories about having to, like, buy a ticket to take a trip with their child. Kids are stuck on summer programs. They can't get home from events by themselves. And I'm still confused as to why this was the thing they needed to do. So, in Delta's view, it's safer to leave a kid in an airport terminal after the security problem that they had, or technology problem they had, and instead of having them go on the flight like they're supposed to. Yeah, why risk it? Right, instead of having them go home to their parent, we're going to strand them at the airport for heaven knows how long. Allegedly, I heard a rumor that the only airline that made it through this unscathed was Southwest. Southwest. I have a story about that right now. And you'd be surprised why Southwest survived this. They are running Windows 3.1. And, you know what, I've got to take my hat off just for them doing that in the first place, let alone getting through this crisis. But just for them, all these years, we're running Windows 3.1. You know, even I don't have that anywhere. Yes, we do. We do? Oh, that's right. The voicemail messages. Yeah, the old... The voice BBS. Which we're supposed to release. You know what? Southwest, you just reminded me to do that. So, okay. More good comes out of this. Honestly, I hope they probably have, like, redundant systems and all kinds of... And it's all that old. But, yeah, I agree with you. That's laudable. Sometimes, you know, if it works. Major portions of Southwest systems are reportedly built on Windows 95 and Windows 3.1, which is something the company has come under fire for in the past several years. It should go without saying that Southwest needs to update its system. But in this case, the ancient operating system seems to be doing the airline some favors to avoid a complete Y2K-level apocalypse. So, yeah, you know, even if you have a system that's just a backup running something that wouldn't be susceptible to this, it might be worth looking into. Alex, go ahead. We have only about a minute left. Yeah. I mean, the thing about this is it's extraordinary, the Windows 3.1 thing. I mean, really amazing. And I always thought that these older OSs, since they're not targeted anymore, might end up being more secure. But in terms of security, the CrowdStrike is obviously so prolifically dispersed amongst the Fortune 500 that it itself becomes its own vulnerability, right? I mean, we saw this already with the SolarWinds attack that we had had. You know, and that was an actual cyber attack. This was an accidental attack. But I think the effect is the same, is that you're pushing out an update. This one happened to be accidentally malicious and just crashed everything. But also CrowdStrike, in terms of EDR, endpoint detection and response, the Falcon system is probably one of the most expensive systems out there. The other systems obviously don't have that market share. But, you know, I think it's time to reconsider. Yeah, I think the landscape might be changing just a little bit in the weeks and months ahead. So, yeah, that's a big deal. And we'll be talking about it more in the weeks to come. Also on Overtime, following this show on YouTube. Go to Channel 2600 on YouTube and you can call in, share your experiences, talk about what you've been up to over the past few weeks. And we'll be happy to chat with you there. That's coming up at 8 o'clock. Again, we'll be back next week at 7 here on WBAI. You can write to us, OTH at 2600.com. Good night.