We're sorry. Your call cannot be completed as dialed. Please check the area code and number, then dial again. Or dial zero, and a BCTEL operator will be happy to help you. 6-0-4-1-3-6. If you'd like to make a call, please hang up and try again. If you need help, stay on the line, and a hacker will assist you shortly. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. We couldn't get much worse, but if they could, they would. One diddle-le-bomb for the best, expect the worst. I hope that's understood. One diddle-le-bomb! The What? Okay. Thank you. Thank you. Thank you. Yes, you do. Good evening. Well, it's been an eventful day. It's been an eventful week. Boy, so much is going on. Let's see if we can try and get through it. It's a lot to talk about. Dollar sign hacked on Solana. On each account we hack, we publish the token address, so we pump it and make profits together. I'm not going to give the token address. It's too long and it doesn't make any sense. Similar messages have been reported on other accounts across the platform from notable accounts like People and ABS-CBN News. Who is that? I have no idea who that is. There has been so far nobody who has reported who may have been behind this seemingly national hacking or for what purpose the accounts were all hacked. Santa Cruz County changed their password and are in contact with their internal security department. Well, Santa Cruz, I can tell you, you probably don't have to change your password because this was something, it happened to us as well. It happened to 2600. Actually happened to our Twitter account. People started reporting, hey, you guys have been hacked. It turns out we weren't really hacked. What was hacked was a third-party app that apparently, I don't know if they're even still around. It's called TwitTimer, Twitimer. It's one of those apps where you can say something and send it later. And I know Twitter got really upset by those because they want to be able to do that themselves. I don't know if they put them out of business. I haven't seen any updates from this company in over a year. But that is where the, if there was a compromise, that's where the compromise was. Simply removing that app solves the problem. We were never locked out of our account and we did not change our password because we wanted to see what was going on. We wanted to learn from it. If there was somebody who had access, we wanted to have a little chat with them and see just what they learned. No panic, you know, no freaking out, just another fun day at the office. Alex, do you have some insight on this? A bit. I also realized earlier today, I was contacted by some colleagues at Human Rights First who were also subject to this particular vulnerability. Somebody had reached out to me and mentioned that it was actually the same exact message, Emmanuel, I think that was posted on the 2600 account about some kind of Solana pump and dump scheme. And it was exactly what I said. I said, this sounds like some kind of third party that perhaps has access to scheduled tweets or something like that. That's usually some kind of third party provider that has some kind of legacy API access to Twitter. And in fact, I don't know if our listeners will recall, but something very similar happened just ahead of the Super Bowl in 2020. So just before the world started to shut down, when I was the acting CISO over at the NFL, we had a very similar problem, whereby a massive amount of sports teams and sports related Twitter accounts were compromised. And it was some kind of third party back end service provider that provided tweet scheduling services through Twitter. It was still called Twitter at the time, so we don't even have to refer to it as X back then. But so it was kind of old wine in a new bottle, so to speak, today. Yeah, I guess that's one way of looking at it. But it confused some people. It was a bit of fun trying to figure out what it was. It took us 10 minutes and we moved on. People are panicking, I know, and talking to their security people and changing passwords and all that. But it's important to understand why something happened, not just keep it from happening again, but also understand what the actual weak point was. Go ahead, Rob. Yeah, absolutely. And in this case, the weak point is a very common weak point for this sort of social media, which is all the little apps and tools you might use and grant access to your account. Some of them, some of which you may not use anymore, may not work anymore. You may have forgotten about those little back doors you opened up into your own account until something like this happens. And to big accounts like People Magazine and ABS-CBN News, which you mentioned, I'll just point out, that's the biggest media outlet in the Philippines. Oh, OK. I feel stupid now. Well, now we're all a little smarter. And, yeah, so it does behoove, folks, if you're using a social media site or anything to which you grant access to, you know, every single different app and tool that you use, go through that list every so often. This is what could happen. Get rid of the access for the ones. This is what could happen when you allow third parties access. You know, I remember asking at the time, is there a security threat? Everyone is, nah, don't worry about it. It's going to be fine. Yeah, you know, there always is some kind of possibility. Now, they didn't get access to the account. They weren't able to read anything, all the juicy bits of Twitter, private messages that we have going on. But it was a little embarrassing to be sending a message like that. But I think people knew that that wasn't us. OK, moving on to something a bit more serious. You know, I don't know if you guys remember. It was I think it was called the Weekly World News. You guys remember a publication called the Weekly World News? You do. You're smiling broadly, Rob. OK, so I guess you read it quite a bit. They had a famous headline. I don't know how long ago this is because they didn't believe in putting dates on their articles. I'm going to assume it was sometime in the 90s, maybe even the 80s. But it basically, in big letters, said hackers can turn your home computer into a bomb and blow your family to smithereens. Yeah, right now, computer hackers have the ability to turn your home computer into a bomb and blow you to kingdom come. And they can do it anonymously from thousands of miles away. Experts say the recent break-ins that paralyzed Amazon.com, buy.com. OK, this will date it, if you can figure out when that was, buy.com. And eBay, websites are lame, or I'm sorry, tame. It's hard to read this, tiny print. Tamed compared to what will happen in the near future. Well, it wasn't really the near future, but it was the future, and it did happen. It took a little while, and it wasn't a computer either. The last couple of days, it's been pagers, and it's been walkie-talkies. And it's happening in Lebanon, courtesy of Israel. And it opens up a whole new ugly chapter of what desktop warfare can be like. Imagine a device that you have in your pocket suddenly exploding, because at some point in the supply chain, somebody was able to get access to it and put an amount of explosives in there. And it's just, you know, it's kind of unfathomable to even think of this. To think of, well, if we have potential enemies in the future, this could easily happen to us. And I guess, you know, the Weekly World News, maybe they weren't so far off in their fears. It was the execution, I think, that they were kind of inaccurate about. Go ahead, Rob. Yeah, the Weekly World News was great. I actually subscribed for a while. And this particular article, which scans of it have been going around for ages, but I had the issue that this article was in, and I had clipped it out and framed it and put it on the wall above my computer in, I think, like the Windows 98 era. And it was a lot of fun to look at. But what's important to note about the current situation in Lebanon is this was not somebody exploding the device as it was off the shelf. This was a supply chain attack in which devices were modified after the fact with actual explosives added into them before they got in the hands of the people who would own them. And it's a terrible thing that happened. It's, you know, it's an atrocity. It's hard to see what has happened to people as a result of this attack. But it is also not a danger of your sort of standard device that you might get off the shelf. Well, it depends what shelf you get it off of. I mean, seriously, if this kind of thing is, I can't even imagine. I mean, some of the media coverage of this has really astounded me. And people pretty much mocking those in Lebanon for not knowing that there were explosives in their phone. Do you guys know if there were explosives in your phone or pager or whatever it is? Who inspects these? I mean, I guess you should. I guess that's something that we need to always do. I would dispute that we need to emphasize that pagers are safe more than what actually occurred here. But that is a great point. Yeah, well, the thing is, this could happen at any point in that supply chain. Depends, you know, do we know where our electronic devices come from? We can theorize. But how many steps are there along the way? And what is it that can actually trigger them? It's it just it makes the world a lot more scary. It really does. Go ahead, Alex. Yeah, I think regardless of how one feels about the the casualties that at issue here in Lebanon, I do think you have to tip your hat to the to the Israelis here and to Mossad for implementing what was an absolutely brilliant and elegant scheme. Let me let me just stop you right there, Alex. Brilliant is not a word I would use for the kind of terror that's been inflicted on civilians here. It blew up in supermarkets, in streets with families. If your phone, Alex, if your phone blew up right now, how many other people would be hurt? You know, it doesn't it doesn't just go for the guilty people. It goes for the people that are around whoever it is you're targeting. It was it was abominable. There's nothing to tip the hat for. I'm sorry. I disagree. I disagree entirely. I think that's disgusting to to to basically compliment the terrorist act like that. I don't think it was a terrorist attack. Well, what do you call when when when the populace is is is frightened to even go near a radio? All right. Everybody is is freaking out now over there. I want to I want to I want to give you something that I just I just pulled up here about mourners who are gathered in the village of Sarain today for the funeral of a nine year old girl who was killed by one of these damn things that you think are brilliant. Give me a break. I think that was a brilliant scheme. I absolutely do. I think it was very well orchestrated. Extraordinary. Well, you know what? There are smart people who who are cold blooded killers. So I guess we can find a middle ground. I would disagree with that as well. I would. I would absolutely disagree. You know, I didn't want to talk about the issue. I didn't want to talk about civilians. I want to talk about the technical aspects of this, how it was done. But I'm not going to sit back and just allow them to be complimented for killing innocent people. I'm sorry. That's just that's my line. You can keep talking over me if you want. I will. I will talk over anybody who espouses nonsense like that. That's insane. I don't think it's nonsense. I don't think it's nonsense. And I think you have to weigh this operation based on the evidence that these were pagers that were put into the hands of Hezbollah operatives. Yeah. You know what? If you understand the intelligence that was at issue here, then it's more likely than not that this was a highly targeted attack. This wasn't an attack on a discriminant civilian population. Yeah, but it was because because guess what? People who work for Hezbollah are in the streets. They have families. You are not targeting somebody. I don't care at all about Hezbollah. OK, I do not like them at all. I wish they were not around. So let's get that clear. OK, but they are human beings that exist with other human beings. And you can't just blow one up and think there's not going to be some kind of ramification for innocent people. And yeah, they are innocent people. They are innocent people. You might want to categorize everybody as an enemy, everybody as evil. And I'm sorry, that makes it very easy to wipe them out. Emmanuel, I would totally disagree with this, because I think if we're talking about innocent people here, we need to have a very hard look in the mirror because civilian casualties as a result of drone attacks from the United States have been a massive problem for the last several decades that we've been fighting the quote unquote war on terror. This, I think, with two casualties that happen to be children, which are absolutely terrible. I think two out of out of 10. I mean, that is a really terrible return there. If you kill eight so-called terrorists and two, two more are children. Come on, that is not— Apparently there will be 2,500 Hezbollah activists, though. But the other aspect of this that you have to consider in terms of the targeting and whether or not it was a proportional attack or a terrorist attack is how—what's the amount of explosives that were put into these individual pagers? Was it a small amount to make this targeted? And I think that was absolutely the case, because if it was a large amount of explosives, you would have seen a huge number of Hezbollah casualties, not just 10 or 2. And I think two children dying as a result of this is terrible. But relative to what— No, but— No, but— No, but— No, but— Look, is it worth killing eight so-called terrorists to kill two innocent children? I don't think so. I don't think so at all. But that's not the calculus. Well, it is for me, all right? And seeing the kind of terror that people— First of all, this isn't World War II, okay? So people keep comparing it to, well, what would the Nazis have done? You know, it's not the same thing. These are countries that aren't even—you know, they're firing missiles at each other, and it's really—it's stupid. It needs to stop. And a lot of innocent people are still dying. But in this particular case, I don't understand the logic, because what have you done? You've eliminated a small number of people. You've wounded a whole lot of other people that supposedly were standing nearby. You've created so many new enemies. I mean, you're trying to win something here? What you're basically doing is writing a very dark future that's not going to stop anytime soon. You know, I do not understand the mentality, and I think lunatics like Netanyahu are the true threat here. I really do. If you want to label anybody as a terrorist. Well, I think that this also sends a very clear message to the enemies of Israel that they're dealing with an adversary that has extraordinary operational capabilities here. And you have to think about how this happened. And I think we can talk about the technical aspects. Well, that's what I wanted to talk about. Well, let's talk about that. I can't just listen to somebody praising something like this. I'm sorry. That's one of my buttons. So maybe let's step around that, and we can have a conversation about the technical aspects. I think this was an attack that was proportional to the targeting. I think it was very, very, very well executed. Okay, would you say that if the shoe were on the other foot? If the shoe were on the other foot and all these Israeli soldiers were blown up, along with their families, too, or children that they were holding in their arms at the time, you would call that brilliant? Because I would not. I would call that disgusting. You would have to commend the technical capabilities of any adversary that's able to pull this off. Well, maybe in a few decades when we're all reminiscing over lemonade. But right now, when people are still suffering, you know, let's try and calm the situation down. Gila, I'm sorry. Go ahead. Ultimately, I think you're both right. Alex, I agree with you 100%. I think the technical pieces of this were, it was a brilliant operation. With that said, I think it was an incredibly stupidly timed decision. I think that now there are going to be forever wars running in a lot of different places, and a lot of people who are really angry because their penises got blown off. But, Emmanuel, I do take exception, and it's one of my buttons to refer to the inner circle of Hezbollah as alleged terrorists. I say alleged terrorists because you don't know who you blew up, you know? But, Hezbollah bought a ton of pagers to give to their people. These are their Hezbollah pagers, not their personal pagers. And maybe they didn't have a Hezbollah pager if they're not in Hezbollah. Okay, I don't know how Hezbollah pagers work. I honestly don't. But I do know that when I had a pager, it wasn't always on me. Sometimes I left it at home. You know, someone's kid could be playing with it. You don't know what's actually happening. There's no guarantee you're getting the right person. And that's why I have to agree that it's an incredibly stupid operation. I don't understand the logic behind this, except to spread terror and fear. Hence, my labeling of this as a terror act. Go ahead, Kyle. I just think that, like, if it's going to be this kind of party, you then have a lot of this going on in the supply chains. And then you do actually run the risk of thousands of something being ordered going to people who are completely unaffiliated through some shipping receiving error. I mean, that's the playing field. If we're going to do off-the-shelf lookalike, like, looking like one thing, you know, but actually just planting bombs, like, this is a different party. A different kind of party. Yeah, the rules have changed. Now this is our reality. And, you know, I don't know if I'll feel safe buying a new phone anymore, you know, unless I know everything about it, you know, or any kind of electronic device. And, you know, what happens? Cars can be blowing up. I mean, that's nothing new, obviously. But, you know, if you inject yourself into the supply chain, it really changes the landscape quite a bit. And I just don't, I don't think it was a good idea. I don't think it was a good idea to take that step. Yes, Alex. But let's talk about how it went down, though. I mean, there's some telecommunications aspects of this that are a bit of a mystery to me that I think would be really interesting to explore and also to explore with our listeners on overtime, too. Because my understanding of how this all came to happen simultaneously yesterday was at 3.30 p.m. local time in Lebanon, a page was sent to all of these pagers. And it appeared to come from Hezbollah leadership. So there's an issue right there that I think a lot of the media has not really been exploring, which is, number one, how did the Mossad or IDF know what all of these telephone numbers were to which they needed to send some kind of individual message? That's number one. Number two is how did they spoof a message coming from Hezbollah leadership? You know, were they embedded somehow? A couple of things. First of all, Israel seems to know an awful lot about people that they're about to bomb because they call them first. Many times they call people and say, hey, your apartment building is about to be blown up. You might want to leave. So they have phone. I don't know how this works. I don't know how they get the phone numbers. I don't know if they if they know people's names they're talking to. There's some kind of level of communication there that I don't quite get. So maybe it's something similar here where they have a roster of people. I don't know. And the other point was was was forging a source, the source of the message. My recollection of pages, and I don't know if pages have changed much over the years. I haven't used one in decades. You didn't know who was calling. They would be inputting their number to tell you who who to call back. I know alphanumeric pagers added the ability to send text messages, but I'm not sure if a number was was. I think you might have keyed in the number yourself because a lot of that was pre caller ID days. Yeah, that's a really good point. I hadn't thought about that because you're you have to self-identify the number. Right. And so or maybe there was some kind of code that made it seem like the message was coming from Hezbollah leadership. And that code was compromised and they use that. But it still raises the issue of how were they able to simultaneously ring so many pages at the same time? Well, going back to my days of phone freaking and pranking and things like that, it wasn't hard inside a particular system. You make one phone call, you enter a number, hit star, enter another number, hit star, each one of those numbers. And they usually abbreviate it three or four digits. That's another person. So you can page 100 people pretty quickly to the same number if you really want to annoy the person that you're pranking. But that's that might be one way. I don't know what their system is. I imagine that's trivial. You can write a script to do something like that. The real. Go ahead, Kyle. Well, it's like it's sort of inconsequential exactly how because it's, again, in the design and building phase of the device or otherwise rebuilt into something in transit. So like, yeah, how those mechanisms, there's when you have physical access, a whole lot more level, a greater level of control in that. Right. So, I mean, you can design anything if it's right in front of you. Yeah. I mean, I don't know. I don't know. I mean, it just speaks to how high a level it takes to like when you're designing something that's a bomb as well as like looks like a pager. You can do it. You can make it work whatever way is convenient for you. It's not some like trick. That's true. I mean, they had physical access to these devices, so they could program them to do all sorts of other additional features, I suppose. Go ahead, Alex. Yeah, I think that that's a good point. This physical access to the device itself would enable them to potentially just copy down a number that might have been associated with them or some kind of ID and then look for that ID within the telecommunications network and then essentially and then paying it that way. But, Al, it's also broadcast frequency, right? Like the frequencies, the channels, like all that is like under their control. So they may not even have used a telephone network in the same way as you would paging someone who's just using a regular page. I'm pretty sure these are passive because today it was walkie-talkies. Who knows what it's going to be tomorrow? And, you know, something sent to that, whether it's a radio signal or a particular string of text, I think that's what triggered it. So it doesn't really matter what the number it was coming from was. What matters is that this particular series of letters or numbers was received and somehow the pager was programmed to blow up when that was received, which is an incredibly scary thing to think about because anybody could send anything to, you know, a phone number or a pager or a walkie-talkie. And just, you know, thinking of someone accidentally sending the wrong word and blowing somebody up, it's just, it's a nightmare. Go ahead, Rob. Yeah, talking of walkie-talkies, there's breaking news coming down the pike now that another wave of attacks has happened. And this time they are walkie-talkies that they were carrying around, including at a funeral for victims of the pagers. Yeah, I was reading that in the Times actually early today. It was a panic at a funeral, you know, stampedes and things blowing up. It's hell. It's hell. I feel for those people. So from a technical standpoint, this is not just sending things to pagers now. This is, I guess, a similar sort of setup, but, you know, across different devices, different networks, different media. Well, and the worst part, actually, is not what blows up next. It's what you think might blow up next. It's the fear of not being able to do anything. And these aren't, you know, I don't want to get into it again, but these aren't fighters. These are people. These are, you know, everyday civilians. They're feeling this fear, and I just can't imagine what it is. What I want to talk about, though, is the supply chain. How? How do you get injected into that supply chain and not be detected or not have one of the manufacturers or shippers in collusion with you? And that's something I haven't seen very much coverage of. Alex, do you have a theory? Well, I do. I have a couple of theories about this. What we know from the media reporting on this was that there was a Taiwanese company located in Taipei called Gold Apollo that was supposedly designed and manufactured most of the pagers that had exploded in the hands of Hezbollah or pockets of Hezbollah yesterday. And that apparently Gold Apollo had then said, well, for all of those orders that went over to Lebanon, we didn't actually manufacture them. In fact, we sub-licensed to a separate company called BAC Consulting that was located in Budapest. And it was BAC Consulting that supposedly had shipped these pagers directly over to the Hezbollah operatives in Lebanon. So it seems like if Gold Apollo had nothing to do – pardon me there – if Gold Apollo had nothing to do with the – I'm so sorry. Careful. It might be Israel. That's one way of putting it, yes. So if Gold Apollo had nothing to do with the manufacture of these particular devices and was all up to BAC, then you know that the compromise of the devices happened at that point. So then there's two alternatives there. Did – was BAC Consulting in Hungary an ordinary, you know, innocent actor here, or were they in collusion with Israel in the Mossad? And if they were an innocent, ordinary actor, then perhaps somebody had then gained illegal entry to wherever their factories were or wherever they stored or warehoused these particular items. But that would be really hard. I think that it would take a lot of either signals or human intelligence to know that in order for pagers that were going to Hezbollah operatives were to be manufactured and made over in Hungary, and then to figure out where they were and then to get some kind of covert or illegal access that gave you – that allowed you to put these devices into your own hands, modify them, play with them for a little while, test them, and make sure that you could remotely detonate these devices in the hands of Hezbollah. I think that would take a lot. So I think a more reasonable theory about what happened is that BAC Consulting may have been some kind of proprietary or fictitious corporation that had sub-licensed for the manufacturing of these particular pagers directly from Gold Apollo and were operating basically through or at the direction of the Mossad. I think BAC Consulting may have been itself a proprietary corporation owned and operated by Israeli intelligence. That seems to be more likely the case. Now, I did a little bit of digging on this, too, if you want to hear about it. I looked at some of the domains associated with BAC Consulting today, and there aren't very many domains throughout the domain name system. There's really only about eight or so domains that have anything to do with BAC and then consulting associated with them. Some of them are kind of old, but some of them are really quite new, registered within the last year or so. So there's one, BACconsult.com, that was registered on 20th of January, 2024. There is BACconsultants.com, registered on the 28th of January, 2023. So pretty new stuff. But the domain that belonged to what I believe is the Hungarian corporation, BACconsulting, is BACconsulting.org. And if you look at how the DNS configuration of that domain is currently set up, the host country does appear to be Hungary, and there are mail servers that point to domdom.hu, which H-U is, of course, the country code top-level domain for Hungary. So this seems to be like this is the actual domain associated with the company that had created the pagers that ended up in Lebanon. Now, this domain doesn't resolve anymore. Apparently, yesterday, it resolved to some kind of login screen, and then that had been removed. But what's kind of fascinating about this is that BACconsulting.org itself as a domain seems like it was – if you look at the certificate transparency records for that domain name, meaning the issuance of things like SSL certificates or secure socket layer certificates that allow for an encrypted connection between the browser and the server, it looks like this domain actually had existed in around 2016 or so and then expired. And it was re-registered by somebody on October 4th of 2020. So that, to me, I think is quite consistent with the theory that this may be a proprietary corporation that somebody picked up the domain name for what used to be a real corporation in Hungary and it was operating it as if it was a continuation of that same corporation. I think that's a theory. That's a theory, but it means that there are people who used to be associated with that company that are certainly going to say something about how their name was used without their permission. But the other question I have is, how do you assure that a particular company that you might have taken over is going to be part of the transaction? I mean, if you're part of Hezbollah and you need to order 1,000 pagers, is there only one place that you can go to? And how does Israel inject itself into that particular supply chain so that it's guaranteed it's going to somehow go to their operatives? It remains to be seen. I don't know. I mean, maybe this is just something that intelligence agencies are really good at doing now, is kind of injecting themselves into supply chains like this and becoming what are essentially licensees of other people's technologies so that when the opportunity arises, you can do something like this, or you may be able to modify tech, not necessarily to explode, but perhaps to have some kind of inherent vulnerability that would allow you to have some sort of signals intelligence collection capability. I think that's much more likely here. I'm missing what is so astonishing about any of this. I mean, these are state-level security agencies. They're really well-heeled. They have plenty of resources for all of this. They do this for a lot of other industries and securing materials for armaments. What are we astounded by here? What I'm curious about is how you have a warring faction, all right? You have enemies. They need to order something from another country. How do you inject yourself into these places where you don't necessarily have good relations in the first place and succeed in... Well, through proxies or shells, as Alex laid out and was pontificating about. But, I mean, the way you build and procure things in a highly developed economy is you place orders as a company. You manufacture the items. You know, money. You know, that's how it works. You create your legal entity. You do it like any other business, although, you know, at an arm's length, as Alex pointed out. Right. So what we're trying to... So what's astonishing about this? They do this all the time. Nothing's astonishing. We're trying to figure out how it actually happened. Where is the fake company? Is there a fake company? Is, you know, who's in whose pocket, et cetera? Because it's, you know, it's interesting. And like you said, it's something that state actors are able to do easily. And you've got to realize that it's not just explosives. It's all kinds of spyware and all sorts of other things that are used to victimize people all over the world every day. So knowing how it works, knowing how it operates, knowing how these so-called trusted sources can be compromised, it's something I think we all need to know. Alex, did you have something else? Yeah, this is actually really fascinating. It's something I literally just learned a couple of seconds ago. So I was right about BACconsulting.org having been previously registered, and then it seems to have expired around in 2020 is what I think it was. Yeah, it looks like it might have changed registrars then. And here's something fascinating, though, is that prior to that, I won't list this person's name. Is it expired or has changed registrars? Those are two different things. No, I believe it expired because the current domain says that it was created on October 4th of 2020. Now, the domain had existed since 20—you know, the earliest historical Whois record that I can find relates to May 11th of 2010. So it expired right around 2020, and it seems like almost at the exact time that the domain expired, somebody else picked it up. But prior to it expiring, it was associated with a BAC consulting company that was actually located in the United States. It was located in Chicago. Well, that's interesting. Okay, because now you have a country that is very friendly with Israel that could have maybe helped out a bit. I think you need to take a trip to the Wayback Machine and check out the site in years past. Yeah, I haven't done that yet. I'm just doing a little digging in the DNS right now. But this is pretty fascinating. I mean, there's even phone numbers associated with the older Whois records because it was pre-GDPR when all of this stuff was just out there and not masked because of European privacy regulations. All right. Well, you know what? We have a lot to think about, a lot to talk about, a lot to argue about. Yeah, I love the implication that the U.S. is at fault. So let me get this straight, Alex. We're to blame ourselves and rally our representatives to maybe stop some of this? Yeah, I'm sure that'll play. Well, I don't know. I don't know. All I'm looking at is Whois record here. I'm not making any kind of implications or anything here, but it is weird. It is weird. Yeah. I'd like to move on to a different story if that's possible. I'm sure we'll have much more to talk about on this. And again, over time following on YouTube, go to our channel 2600 at 8 o'clock and you can call us and yell at us and do whatever else. Well, write to us, OTH at 2600.com. But I just saw this today, actually. The Tor Network, we're all familiar with the Tor Network, it's considered the most important tool for moving anonymously on the Internet. Authorities have begun to infiltrate it in order to unmask criminals in at least one case. They have been successful. This is according to a website called Tagesschau.de. It's German. And this was translated from German, so it might be a little rough here. But law enforcement agencies in Germany have servers in the Tor Network monitored for months at a time in order to de-anonymize Tor users. Sites in the so-called darknet are particularly affected. This is shown by research by the ARD political magazine Panorama. And a word I can't pronounce at all. The data obtained during surveillance is processed using statistical methods in such a way that for anonymity—I'm sorry, this is how it—oh, Tor anonymity—is completely eliminated. Reporters from these two publications were able to view documents that show four successful measures in just one investigation. These are the first documented cases of these so-called timing analyses worldwide. Until now, this was considered virtually impossible. Has anyone else heard about this, by the way? But they can't hear you nodding or shaking your heads, folks. Yes or no? I had not, no. Nor have I. All right. Well, again, this is just something I stumbled upon today. But the story concludes by saying this is a heavy blow for the Tor Project. The revelations are a serious blow for the Tor Project. The nonprofit organization based in the USA, which aims to ensure the maintenance of the anonymization network, stated in response to a request that it had not been aware of any documented case of timing analysis. However, so far, there is nothing to indicate that the Tor browser has been attacked. Tor users can continue to use the Tor browser to surf the Internet safely and anonymously. Matthias Marx from the Chaos Communications Club warns—or Chaos Computer Club, is it?—warns of the consequences of the measure. This technical possibility exists not only for German law enforcement authorities to prosecute serious crimes, but equally for unjust regimes in the persecution of opposition members and whistleblowers. The Tor Project is therefore now under pressure to improve anonymity protection. And now I have to say, yeah, this could be considered a serious blow for the Tor Project, but I know they love a challenge, and this is a challenge, to make it better, to make it more impenetrable and more safe for people to mask their identities. Of course, you know, the article goes into how this draws some unsavory types, and that's always going to be the case. But you cannot give up anonymity or privacy just because there are some bad actors out there. I think that's very foolish, very naive to believe that. No thoughts? Yeah, we've got some thoughts there. I mean, I think you have to be really careful about, you know, assuming any type of activity like that is going to be private, because it's always possible for some kind of rogue actor to insert a nefarious node. And I think a colleague of mine was sharing some information with me yesterday about a similar attack vector on the cryptocurrency known as Monero that is known for, you know, not having its own form of public ledger and actually being a truly anonymized form of cryptocurrency, and that very similar attacks using rogue nodes to identify transaction-related data and sources was utilized. So, you know, if you don't control the entirety of the network, you know, you have to really be careful about the security of your data. And this is why cryptography and encryption is so important. Yeah, and use the network more. More traffic has always been good for them. And I'm sure there will be guidelines and advisory about, you know, if you want to use it and what you can reasonably expect. But, yeah, if you're going to do your real crime in, you know, beware. It's probably a bad idea to put all of your faith in one particular network. Yeah, but, I mean, again, it's not about crime. It's about being able to communicate. You know, whistleblowers are certainly number one on our concern list. But I think the answer here is to collaborate more, to make organizations like Tor Project stronger. And, yeah, I encourage people to visit torproject.org. Contribute if you can. Help out if you can. And fight for privacy. Go ahead, Alex. Can we take one detour back to the BAC consulting issue again? Because I just want to clear something up. You have 30 seconds. Yeah, 30 seconds. So I did that U.S. company that was associated with the domain in the past doesn't seem to have anything to do whatsoever with electronics. It seems like it was a social worker that owned this. The domain expired in May of 2020, and then somebody had re-registered the domain in October of 2020. And that's the current registrant, whoever did that. A quote-unquote social worker. I got it. Yeah, I see what you're saying. Yeah, it was a consulting group that had to do with parenting and adolescence and human issues and taking a rosarian and humanistic approach to social, you know. No, no, no. You don't have to speak in code. I know exactly what you're saying. So, okay. They're good. They're really good. They are something else. Definitely nothing to do with this. All right. So, you know, other news to update something we were talking about a couple of weeks ago. The Brazil Supreme Court has unfrozen the assets of Elon Musk's Starlink and Twitter in a victory for him. No, not really, because first they took a whole lot of money out of it because that's what he owed for all the fines for refusing to follow the law. So, now it's unfrozen, but Twitter still doesn't work in Brazil, and it won't until he starts following the law. Isn't that unfair? All right. We have a couple of letters, and you can write to us, OTH at 2600.com if you have something to say. I wish I had realized the show was on 9-11 last week, so I could have sent this in advance. The lasting changes in security and politics were not that severe outside the U.S., but the day itself was a major event. I was in my early 20s working at an advertising agency in Finland when the attack happened. The first crash was about 3 p.m. our time, and the whole company stopped. I, being a turbo nerd, was always on IRC back then. In fact, I was on IRC that very day. I used a terminal-based IRC client that was the only real-time source for info before Twitter, and similar to Twitter, it was full of misinformation. There were reports of many things that didn't happen, but also lots of actual news before it made the real news. People gathered behind my desk, and one colleague said in jest, Everything is more reputable when it's green text on black background. I think that's true. For a while, it seemed like the attacks would keep coming around the U.S. Fortunately, it was only the handful that were realized, but still a horrible day. It is a day I always remember, even though I was halfway around the globe. I can only imagine how it felt for people in the U.S., and especially New York City. Thank you, Lobb, for that letter, and if you want to hear what it was like for people in New York City, you can listen to last week's show on the archive, or you can even go back to 2001, listen to the shows back then. Dear Emanuel and friends, I discovered off the hook on WBAI with a small FM shortwave radio while living in a tiny log cabin, no water or electricity, up in the Catskills in the mid to late 80s. You know, that's how you do it. That's what makes radio magical, that you can go into a log cabin in the middle of the Catskills with no power and hear something. I don't know how you heard us, but, you know, maybe we bounced off something. I appreciate all those decades of programming. I'm at a very rudimentary level of technical proficiency personally, and that doesn't matter at all. The reason I'm writing is for some pretty basic telephone advice. I have a Samsung Galaxy A54 5G phone bought in February 2023. I don't know why we need to know that. With service through Consumer Cellular, I'm traveling to France in three weeks. I'll need to access the Internet and make and receive lots of calls while there for 16 days. If it's not too big of an imposition, can you please explain to me what I would need? What SIM card will work for France? What's possible? What would you recommend? Mary James. Thank you for writing to us, Mary James. Gosh, you know what? It's been a long time since I've gotten a phone specifically for travel. It used to be you would swap out your SIM card and put it in a different phone that maybe you bought over there or maybe you just would use in Europe because they use different frequencies. But now it's pretty much every phone works pretty much most places. And depending on the plan you have, you might be able to get away with not doing anything. Kyle? There's also a move, I think, on some of the more modern devices towards electronic SIMs that do not require any kind of small chip. And you can store multiple versions of that in certain devices. I don't know all of this. I know that it has appeared in some publications. People have talked about it. And so word of that technology and its use is sort of spreading maybe a little slower than USB-C. But it's out there, you know. So there's different ways you can manage multiple types of prepaid and international SIMs on the new device. Alex, we travel a lot. Any suggestions? Yeah. I was thinking about this when the letter came in, and I'm one of these people that never really changes the SIM card when I'm overseas. I know I should for multiple reasons. Are your phone bills astronomical when you get back? No, not necessarily because most of the time there's some kind of agreement with the country in which I'm traveling whereby the calls aren't extraordinarily expensive. There's a certain amount of data that you get at the local high-speed rate. And then it drops you down to like a 3G type of situation where you might get something like 256K. You know, use Wi-Fi. Wherever you can use Wi-Fi. It's free. It's in most places, cafes, hotels. So definitely do that. Don't use your data. And I don't know Consumer Cellular, but check with your company. See if there are plans that could work for you overseas. Receiving calls, I think, you don't have to worry about that. But I could be wrong again because I haven't thought about this in a while. Just wait for the implant that connects to satellites. You'll be fine. Yeah, there you go. Out of time, OTH at 2600.com. Join us over on YouTube, channel 2600 for overtime. We'll see you next week. Good night.