Welcome to the AT&T FDS 2000 Network A. Thank you for listening to Off The Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a cough. We couldn't get much worse, but if they could, they would. One minute, mom, for the best, expect the worst. I hope that's understood. One minute, mom! One minute, mom! One minute, mom! One minute, mom! One minute, mom! See you next time! Thank you. And a very good evening to the program is off the hook. Manuel Stein over here, Kyle over there. What's up? Out in Skyplan, I believe we have Rob T. Firefly. Good evening. And we have Gila. Good evening. And we have Alex. Yes, you do. You might lose me momentarily, and then I'll be back. Okay, I won't even ask. So we're not going to have overtime tonight because we're all busy with all kinds of other things. So we're just doing the one hour on WBAI tonight, which is great. We have a lot to talk about. We have a lot of things that have been happening. You hear about this hack into Trump's campaign. The headline reads, Iranian hackers tried but failed to interest Biden's campaign in stolen Trump info. I thought that was pretty fascinating right there. Iranian hackers sought to interest President Joe Biden's campaign. I don't know why they're saying Biden's campaign, because it's not Biden's campaign anymore. It's the Associated Press. You'd think they'd get that right, the candidate's name. Yeah, so they tried to interest that campaign with Donald Trump's unsolicited emails. Actually, they sent the unsolicited emails. Boy, this is a train wreck of an article here. There's no indication any of the recipients responded, and several media organizations have said they also were approached with stolen material. They did not publish it. Kamala Harris's presidential campaign called emails from Iran unwelcome and unacceptable malicious activity that were received by only a few people who regarded them as spam or phishing attempts. Of course, that was all Trump needed to hear. He's accusing Kamala Harris of hacking into his campaign somehow. And from what I'm seeing in various other news articles as well, that hack might still be ongoing. In other words, they still haven't secured whatever it is that's been compromised. And apparently, people are still able to access various things. It's really a fascinating story. You might wonder why all the news outlets are sitting on these documents. Interesting article in Vanity Fair that addresses that issue. This is why Biden's campaign was mentioned. This happened in mid-July. I just found that out. I thought it was a new story. It just came out this week. In mid-July, a source identifying himself only as Robert. I know of Robert. I know a couple of Roberts. Oh, boy. Began contacting news organizations with what sounded like a tantalizing offer. Internal documents from Donald Trump's presidential campaign. In email exchanges, Robert was cagey about how, and they have he in quotes here, I guess because you don't know, had gotten the goods. I suggest you don't be curious about where I got them from, Robert advised, when a Politico reporter pressed for more information. Any answer to this question will compromise me and also legally restricts you from publishing them. Yes, I guess that's probably true. Robert's spy moving statements aside, the material he was peddling was the result of a hack, one that Microsoft and federal authorities said began in June and emanated from Iran. The penetration of the Trump campaign's files was reminiscent of Russian hackers' breach of the Democratic National Committee's computers in 2016, which led to WikiLeaks' slow drip release of emails that embarrassed Hillary Clinton's campaign and helped Trump in the final months before the election. You might recall also Donald Trump welcomed that at the time. Now, this time is different. None of the information stolen from the Trump campaign has been published to date. Politico declined Robert's offer, as did the Washington Post and the New York Times, which Robert also approached. You know, Robert, you could approach us, too. Approach us at off the hook. I mean, I'm not saying we'll distribute the information, but at least, you know, we can talk more intelligently about why we're not, if we're not. But since everybody else is turning it down, you know, in the words of Trump, what have you got to lose? You know, the decision by editors to sit on the hack materials invited accusations of a double standard with Popular Information's Judd Legume calling out news organizations earlier this month for apparently changing their standards without any detailed explanation. Legume revealed Tuesday that Robert approached him on September 18th, and that's pretty recently, with hundreds of pages of vetting documents on Trump vice presidential contenders J.D. Vance, Marco Rubio and Doug Burgum, materials believed to have been sent to the aforementioned news organizations, as well as purported emails among Trump campaign officials spanning October 2023 to August 2024. And I'm turning you guys down until you figure out what button somebody just hit. Notably, a four-page letter that a Trump attorney sent Times reporters on September 15th. Yeah, they actually have that already. Semaphore's Ben Smith confirmed the authenticity of the letter, indicating that the Trump campaign breach went on longer than previously known and could be ongoing. Popular Information and Semaphore have also opted not to publish the hacked materials. Oh, come on, someone's got to publish this. Someone has to at least give some details about it. The new revelations are sure to bring fresh scrutiny on the editorial calls made in newsrooms surrounding this late-in-the-election breach. I mean, that's pretty much the story right there. Have you guys been following this? I have not, but I'm very interested in this, Robert. And not only because, you know, I'm thinking of all that time I spent wondering what hacker handle I should be known by, and it never occurred to me to just be Robert. If it's you and you didn't give it to us, we're going to have to have a conversation. I'm just saying that. You know you always get right at first refusal with my stuff. But, no, it's interesting to see this, you know, far-beleted story, but still this little look at what it must be like behind the scenes when stuff like this is flying around. Uh-huh. Alex, any legal perspective? Yeah, I mean, I think people are right to be somewhat cautious in terms of how they handle this particular type of information because there are various rules about handling stolen information these days. It can become quite difficult and quite, I think, fraught. But what it does is it makes people really reluctant. And I think that that's somewhat disconcerting, right? But what's really fascinating about this entire thing is that, and Emmanuel, I haven't been following the entirety of the story, and when you were mentioning it, I thought that you were just recanting really what everybody already knew, which was this attempt from some kind of hypothetical Iranian hacker to try to distribute information that was already known from the Trump campaign. But what seems to be really interesting is that this may be ongoing. There may be an ongoing compromise. And so I think that we have to be a little bit more avant-garde and a little bit more, I think, I don't know, adventurous when it comes to exploring this type of information. You know, and look, maybe if it was on the Democratic side, we'd be taking the other side of this. I don't think so, though. But I think no matter what, we have to be looking at this particular type of issue, I think, on a facts and circumstances basis here. And it seems like there may be some more persistent and prevalent compromise of the Trump campaign. That's certainly relevant. That in and of itself is news. Exactly. Yeah. The fact that they're still able to get in, they're still able to access this information, it doesn't say much for the minds at work over there. But just, you know, some more words on what the actual material is. The material consists of publicly available records, such as news articles, speech transcripts, tweets, media interviews. And the work itself is incomplete. The 271 page rundown on Vance is inexplicably missing Vance's now infamous childless cat lady's comment from a 2021 interview with Tucker Carlson on Fox. That's according to one reporter who has seen the material. So the file does include Vance's comments from 2016, in which he called Trump an idiot and privately compared him to Hitler. That's that's in there. But the files are basically an opposition dump and not a very good oppo dump at that. Oppo? Is that a word? I guess it is. That's a word, Alex? O-P-P-O? Yeah. Oppo. I think it's I think it's a word that politicos use. Yeah. Well, that's what I'm reading now is from politicos. Oppo research, because it's too much effort to say that last syllable. Oh, the same. Opposition. Yeah. Opposition. Who has time for that? There's not a single allegation that you couldn't find with one click on the Internet. It's not good work. Honestly, it's just not very interesting. I'm not really sure, you know, if there is anything here that really is anything. But, you know, if it really is nothing, then why not just show people what has been released? You know, that could be interesting in other ways. Rob? Yeah, honestly, in terms of things being interesting, I mean, we're in a position now where the actual public face of what's going on in this campaign is already, to use more political science terms, nuttier than squirrel poop. And what could possibly be in these hacked documents that would even add to the crazy swirl of things that are already available from open sources for every journalist to chew on and ruminate on? But at the same time, I am kind of fascinated by the fact that in 2016, right, the hacked emails from Hillary Clinton's email server, those got published. Everybody knew it was in those. And it was, you know, she emailed like a grandma. So it was forward, forward, forward, forward, forward, make sure your shampoo isn't trying to kill you type stuff. And I think we could all agree that that's not, there's not a lot of there there. So, you know, we don't have the childless cat ladies thing. But are you saying that in 271 pages of documents on J.D. Vance, there's nothing? Yeah, let us be the judge of that. You know, let's rifle through and see what we can find. Alex? I mean, Gila, there may actually have been nothing because I don't think he has much substance, to be honest with you there. I mean, it's like it's the kind of stuff that's not necessarily newsworthy, like gathering information about ridiculous tweets, stupid positions that he's taken, crazy positions that he's taken, things that are all publicly known to everybody all around the world. Just concatenated in one document. So maybe, maybe literally there is quite, you know, literally nothing newsworthy. So sad, but true. Well, in a New York Times podcast back in August, David Sanger, who's the paper's veteran national security reporter, said there was nothing there that couldn't have been assembled by a bright college intern using Google to put together a dossier of nasty public things. Vance had already said. Now, Robert's approach to the three news organizations suggests the hacker or hackers. Now, he apparently is not the one that actually hacked into the data. I guess he's their agent or something or their PR person. I don't know. Or maybe he is or she. We don't know anything. The hacker or hackers hope to piggyback on a mainstream news outlet's reach and credibility. It also suggests that the hackers believe that the reporting of the material would show the Trump campaign's wariness and reservations about Vance, undermining Trump in the campaign's final months. So if so, that's naive. Presidential campaigns routinely produce this kind of material to assess the would-be running mate's strengths and vulnerabilities. What's more, dangling the material in front of three publications looks like an amateurish move designed to stir up a race to publish, despite the weakness of the information. And even if the material wasn't revealing, Robert's actions may have been. His emails, oddly via an AOL account, were written in clear colloquial English, suggesting to one reporter that he was a useful idiot, an intermediary recruited by Iranian overseers. It's also telling that Robert approached Politico reporters, not those covering national security, whose suspicions about a foreign influence campaign would have likely been immediately aroused. You know, we're so certain that this ultimately comes from Iran. But how do we know that? It's what, an IP? That can't be masked? People can't route things all around the planet? How do we know for sure? I mean, just today, Trump threatened to blow Iran to smithereens. So much for not getting us into wars, but whatever. If somebody does something that is offensive or harmful to the president, yeah, blowing them to smithereens. That, you know, it's being taken very seriously, and the culprit is being identified very definitively. But I just wonder, could people have that completely wrong as well? It is the Internet, after all. Go ahead, Alex. I mean, did he literally say smithereens? I believe smithereens was used. Smithereens. Someone please check that, but I'm pretty sure that was a quote. That seems like, in and of itself, a deprecated word that should give us pause to, you know, about, you know, certain, I guess, vocabulary-related skills. But in any event... I'm not concerned about the word. I'm really not concerned about the use of the word. I'm concerned about... Well, never mind. I'm concerned about a lot of things. Go ahead. I believe words matter. I don't know about... I don't know how you feel about that, but I... Oh, they matter. They matter, but I'm just saying it's the thought behind... Well, I don't know if thought is a right word to use in this case, but it's, you know, the intent, it's the power, it's the hatred, it's all kinds of things. But to go back to the original question... Hang on, Gila, do you have something? He did, in fact, say smithereens. He also suggested that the shooters were both sent from Iran. He claimed that if he were the sitting president and another candidate were under threat from a foreign country, he would inform the threatening country, in this case, Iran, we're going to blow your largest cities in the country itself to smithereens. We are going to blow it to smithereens. And he's upset that the Iranian president is being protected during General Assembly Week. Right, and this is the guy that says he can negotiate peace anywhere. Good start, good start there. I'm sorry, go ahead, Alex, finish your thought. In terms of the attribution of all of this to Iran, all of that's really opaque. We don't necessarily know. Nobody's sharing the data about why we think that this originates from Iran. We just are told that it's originating from Iran because of various things happening in the background. So, look, I think we're all right to question the veracity of that attribution. We all know that attribution is a really difficult, tricky topic in cybersecurity. But I do think it's the type of data that should be subject to more public scrutiny. I think it would be very interesting to learn why we all think that this is originating from Iran. Fair enough, yeah. On a related note, this is a really fascinating story that you might have seen. But apparently, you know how on Twitter, we'll just name them because this is mostly what it's about. If you say something that is untrue and you're a public figure, or if you're a news organization, you say something that's untrue, a correction might be posted as part of your tweet, labeling tweets featuring false claims about election fraud as disputed. That's an example. But apparently, when you do that, when that happens, with regards to Trump, it makes his followers believe the falsity even more. Yes, study says that tagging posts with false claims may make Trump voters more likely to think they're true. This is a study put on by John Blanchard, who's an assistant professor from the University of Minnesota Duluth, and Catherine Norris, an associate professor from Swarthmore College. They looked at data from a sampling of 1,072 Americans surveyed in December of 2020. Okay, this is, it's rather old, but still, I imagine mentality hasn't changed that much. The researchers published a peer-reviewed paper on their findings this month in the Harvard Kennedy School's Misinformation Review. I want a subscription to that publication. Wow. The Harvard Kennedy School's Misinformation Review. Oh, that's good reading. That's good reading right there. I'm checking into this. These disputed tags are meant to alert a reader to false slash misinformation. So, it's shocking to find that they may have the opposite effect, said Norris. Participants were shown four tweets from Donald Trump that made false claims about election fraud and told to rank them from one to seven based on their truthfulness. A control group saw the tweets without disputed tags. The experimental group viewed them with the label. Before and after seeing the tweets, the subjects were also asked to rank their views on election fraud overall. The study found that Trump voters who were initially skeptical about claims of widespread fraud were more likely to rate lies as true when a disputed label appeared next to Trump's tweets. The findings, meanwhile, showed Biden voters' beliefs were largely unaffected by the disputed tags. Third-party voters or non-voters were slightly less likely to believe the false claims after reading the four tweets with the tags. I don't know. It seems to be a problem with people who follow Trump. But it is kind of sobering to realize that no matter what you say, you're not getting through to them. You're not going to convince them. It doesn't matter. God himself can come down from the heavens and say, no, no, he's right. Believe him. And they won't. You know, it's fascinating, but it's also scary. Oh, it's terrifying. It's absolutely terrifying because it means that there's no legitimate source of truth anymore. And having some kind of source of truth, I think, is imperative to almost any kind of knowledge-based system, whether it's a system of technology like domain names or it's a system of epistemology like human knowledge. You need to have some kind of source of truth. And that's totally broken. And I think that's by design. I mean, if we look back to how Trump has attacked sources of truth since 2016, and it's no doubt that – or I guess it's no surprise that these types of sources are broken. Go ahead. So it really speaks to the media environment that we're in now, you know, which I think owes a lot to when Trump started, you know, back in the day talking about fake news. And we're in this environment where if you don't like a piece of news, all you have to do is decide that it's fake. All you have to do is decide that, oh, I don't believe that bit. And, yes, we're really hurting for a general source of information on which everyone agrees. We're really hurting for, like, an objective yardstick to measure everything we see by and ways to confirm or, you know, things are true or false. And it's a really dangerous place to be. It's a really frightening place to be. And I really want to hear more ideas about what we can do about any of this. Go ahead, Kyle. Just establishing that has traditionally been through a process, through an editing, a reporting, and an editing, an investigative, checking facts, checking sources, double-checking things. And that has been hollowed out in large part and in many ways disintegrated. But information is no less more powerful. In fact, there's so much more of it now. And aggregating it with the tools we have is really intensifying the entirety of what was already a process of disseminating stories and our understanding of the world. So when a lot of that has been leveraged and hijacked and, well, hollowed out and auctioned off. And literally, I think InfoWars is for sale right now. Oh, that's right. Because he's bankrupt. Yeah, because he owes – he's worth nothing and he owes like a billion – I'm sorry. It was like 10 million or something. That's like the best estimate if this auction goes well. But yeah, so it's like – it's just a funny media landscape because people have undervalued the process that allows us collectively to establish an approximation of truth. Truth is an amalgamation of a lot of truths, a lot of facts, a lot of people's understandings of things. I mean, I'm speaking outside of scientific fact, which – but even that has been something that's in dispute and in itself goes through a process we typically refer to as peer review. So, like, all of these processes need to be reinvigorated, to say the least. So much of this is related to the death of traditional journalism or at least the severe wounding of it. I know, you know, we've always had trouble with mainstream media. We've complained about it since day one. We've always touted the Jell-O-B offer phrase, become the media, and we saw it actually happen. But you know what? That's not actually the solution either because when everybody's the media, nobody knows the truth because everybody's got their own version of it. It becomes too diffuse. It really does. And, you know, you need those, quote-unquote, trusted sources or at least informed sources, people who know how to pursue a story, people who know how to do research, and people who genuinely aren't so biased that it affects the facts that they report. Everybody is biased. You know, nobody's denying that. But, you know, I can't count a number of times I've heard people around me saying they're going to boycott the New York Times because of something they printed. But then a week later, they're reading it, and there's a story they like about that, about something else. You know, we're always going to have trouble and problems with the mainstream media, especially the tabloid mainstream media. But I like to think that, you know, for instance, what we just reported on with the hack into the Trump campaign, certain people in the media, certain journalists, decided this was not something that we want to publish. And I think for the most part, we respect that decision. We're questioning it. And, you know, I think maybe there's room to do something with it. But these are people, just like with Snowden's Leaks, people who are studying it, who know something about what is right to release, what is not right to release. And we're lucky to have people that do that much in the way of thinking it through. Because, you know, on the Internet, when you're just looking for likes and followers, you don't do that. You don't put a whole lot of work into making sure that everything you say is as correct as you believe it to be. Go ahead, Gila. But, I mean, Emmanuel, when you're telling us about the story, I was almost a little nostalgic because the misinformation tagging system on Twitter has been functionally decimated. You know, there used to be fact checking by like the AP and other reputable news organizations, and they've destroyed that infrastructure and replaced it with community notes. You know, as much as I want to have a decentralized media environment and learn more from more sources, I'd much rather hear what the AP has to say about topics of interest than like Edgelord69420. No, I agree, and I don't know why you're picking on them specifically, but, you know, what I see on Twitter today, when stories are being questioned, it says that. I imagine that's because of a whole lot of people stepping forward. It's not just because one person is saying this or has a different version. Of course, that can be misused. That can be used in any other direction where something factual is disputed because a lot of people don't like what it says. I don't know if that has happened yet. I expect it to happen, but that is, as you say, a danger. Go ahead, Alex. Yeah, I think it's an interesting situation we're in where the media sense that, you know, we're almost embodying this notion of we go high when they go low, but perhaps it's just that the information that was stolen or exfiltrated or whatever it was was frankly too boring to be considered newsworthy. I think that's the issue here. I think that, you know, maybe we're giving them a little bit too much credit in terms of discerning whether or not something is newsworthy or interesting, and I agree with you entirely that the media economy shouldn't be fueled by likes and the amplification of algorithms and things. It's just absolutely terrible. It's the wrong way to go about journalism, I think, from the get-go here. But I think that the stuff that was taken from the Trump campaign was just so incredibly boring that it actually just wasn't fit to be published or even distributed anywhere. Well, I mean, that's the thought. That's their claim. Yeah. We – I think for the most part respect that, but kind of want to know more. I mean, I agree with you. Yeah, we – you know, there are ways for us to make that – to make the decision for ourselves. You know, the documents can be released. They can be put out there in the open. There are ways, you know, and mechanisms and outlets that would distribute these types of documents whereby the people can make their own decisions and maybe, you know, going back to Jell and Biafra, right? You know, we've talked – which is, I think, really a very apt type of reference right now because one of the things that he always mentioned was, you know, becoming the media yourself, right? And perhaps the people are the best – are in the best position to connect the dots on a lot of these types of things. You know, I don't think that we can necessarily rely perhaps on one source of truth or one media organization in order to do all that dot connecting. I think there are a lot of dots to be connected, and maybe this type of information should be out there in the public. Maybe there's metadata associated with these files that hasn't been examined. Maybe there's other data sources or references or something, but, you know, I tend to agree. I think I would like to examine the information firsthand as a primary source by myself to make these types of assessments. Well, I think we'd all like that, not just for you to have it, for everybody, all of us to be able to look through it. And maybe Robert could post it somewhere since nobody's biting, you know. At least if it's a public service and people need to see this, then it's almost a duty to put it out there. But maybe it's boring. Who knows? Okay, another story that happened last Thursday. Russian cybersecurity company Kaspersky deleted its anti-malware software from customers' computers across the United States and automatically replaced it with Ultra-AV's antivirus solution. Yeah, this comes after Kaspersky decided to shut down its U.S. operations and lay off U.S.-based employees in response to the U.S. government adding Kaspersky to the entity list, a catalog of foreign individuals, companies, and organizations deemed a national security concern back in June. Now, on June 20th, the Biden administration also announced a ban on sales and software updates for Kaspersky antivirus software in the United States starting September 29th over potential national security risks. In July, Kaspersky reported that it would begin closing its business and lay off the staff on July 20th because of the sales and distribution ban. In early September, Kaspersky also emailed customers assuring them they would continue receiving reliable cybersecurity protection from Ultra-AV after Kaspersky stopped selling software and updates for U.S. customers. However, those emails failed to inform users that Kaspersky's products would be abruptly deleted from their computers and replaced with Ultra-AV without warning. According to many online customer reports, including the forums over on Bleeping Computer, which is where we're getting this article from, Ultra-AV's software was installed on their computers without any prior notification with many concern that their devices had been infected with malware. Yeah. One user said, I woke up and saw this new antivirus system on my desktop and I tried opening Kaspersky, but it was gone. So I had to look up what happened because I was literally having a mini heart attack that my desktop somehow had a virus which uninstalled Kaspersky somehow. To make things worse, while some users could uninstall Ultra-AV using the software's uninstaller, those who tried removing it using uninstall apps saw it reinstalled after a reboot, causing further concerns about a potential malware infection. Some also found Ultra-VPN installed, likely because they had a Kaspersky VPN subscription. Not much is known, by the way, about Ultra-AV, besides being part of Pengo Group, which controls multiple VPN brands. If you're a paying Kaspersky customer when the transition is complete, Ultra-AV protection will be active on your device. You'll be able to leverage all the additional premium features, says Ultra-AV, on their website. On September 30th, Kaspersky will no longer be able to support or provide product updates to your service. This puts you at substantial risk for cybercrime. So you'd better not delete that, apparently. What do you guys think about this? It seems like a really awkward and clumsy way to do a transition from one company to another based on foreign policy. Rob? Yeah, this is kind of a big deal, because for those unfamiliar, Kaspersky was a really big player in antivirus and InfoSec. And a lot of people used Kaspersky tools. And, you know, not everyone, I think, really considered much about the fact that it was a Russian company. But with things being as they are now, you know, it was going to be blocked from serving Americans. But oftentimes, when you're using a tool, a security tool, any kind of computer program, really, and the company disappears or goes out of business or stops making the thing or whatever, you just get stuck with the last version you had. No one was really expecting this to uninstall itself, reinstall some other thing that you haven't heard of before to try and replace it, and leave you with just a completely new thing that you're looking at and didn't choose and are completely dependent on, especially in, like, a business setting. So this has really screwed things up for a lot of people, or at the very least, kept some IT folks from sleeping through a night or two. Go ahead, Alex. Yeah, I think this is a very weird decision that comes from Kaspersky to do this, for exactly the reasons that Rob just stated. What I will say, though, is if you look back at what the Department of Commerce had actually said, so the BIS, which was the Bureau of Industry and Security, had said when they finally determined that, because Kaspersky was no longer going to be allowed to do business in the United States, they said this. They said, Today's final determination and entity listing are the result of a lengthy and thorough investigation, which found that the company's continued operations in the United States presented a national security risk due to the Russian government's offensive cyber capabilities and capacity to influence or direct Kaspersky's operations that could not be addressed through mitigation measures short of a total prohibition. That total prohibition seems to have been cut short by the idea or the crazy action of trying to reinstall some kind of alternate antivirus system. It's a kind of, I feel like it's a very desperate measure to try to continue to capture a bit of this market share in the United States. On the other hand, though, I will say this, that despite Kaspersky's, or rather despite misgivings about Kaspersky as an organization itself having been beholden to the Russian government or maybe be, or having been subject to the influence of the Russian government, there's no doubt in my mind that Kaspersky has extraordinarily capable cybersecurity researchers there. I've worked personally with quite a few different people over at Kaspersky and they were really, really capable. And so I see this as a really sad outcome here because I think that the political affiliation of one particularly private entity being, or rather originating from a foreign adversary and that foreign adversary being rather authoritarian, namely Russia, with respect to its underlings, its corporations, etc., that it's essentially tainted this otherwise really capable company full of really talented cybersecurity researchers. I'm not whitewashing anything that they've done in the past. I don't know what they've done or whether they have been adversarial to the United States, but I will say that they were really, really effective cybersecurity researchers. And so this may be a situation where we see politics tainting things and maybe to the, I guess, well, it's in a way that's not benefiting the consumers whatsoever, but I think Kaspersky has really made the wrong move here and has probably eroded a gigantic amount of consumer trust that it had or that it had left by reinstalling itself as ultra-AV. Hang on. Why would they need consumer trust if they're not going to have those consumers anymore? Why would they even care? Well, this seems to be like it's some kind of alternative way for them to continue to have those particular types of consumers. Unless there's an overtly nefarious reason for them doing this, I can see this as a way to continue to have... What do we know about this other company, Ultra-AV? Yeah, wouldn't it... Go ahead. Wouldn't it possibly just be a sale? Maybe, maybe not. But I think even a sale of those particular types of interests would probably still be covered by the U.S. government's BIS order. But if they're in a jurisdiction that is not policed in the same way by FTC or if they're operating in a place that is otherwise friendly, then I don't think that would be an issue if that's part of the settlement. How was this supposed to go? When the order was issued, what was the correct procedure? I mean, what do you do with all these people that are subscribed to this? Yeah, because the strategy seems a lot like what they were demanding of TikTok. Well, in a sense, I guess there's an analog there. That's a good point, Kyle. But I think the idea behind this order was to give U.S. consumers, and mostly companies, notice that you had to have some kind of change and you had to make some... I'm sorry, Alex, you froze for a second. Just repeat the last sentence. Oh. So that these consumers... I think notice was given to the consumers and the companies that were utilizing Kaspersky that they were going to have to make some kind of change with respect to their antivirus software. The way I read it, it sounded like Kaspersky notified consumers that a change would be made, and it would not be the consumers making that change. They would just have a change on their machines. I think that was the wrong way to go about it. It gives people a choice. Yeah. But if they have some kind of a deal with Ultra-AV, and that's something I think that we should look at, well, that raises all sorts of questions. Is Ultra-AV just an extension of Kaspersky? What kind of deal did they make? How is this any different for the consumer? It just seems to be causing a lot of confusion and questions. Well, I agree with you entirely. And I think that the questions and the issues that this raises are issues of commerce and trust, and I think Kaspersky made the absolute wrong moves here when it came to establishing trust with its consumers, and this is probably going to be an issue that is now not necessarily addressed with the Department of Commerce and the Bureau of Industry and Security, but possibly with the FTC, the Federal Trade Commission, because this is a problem of trust in the consumer. What can consumers trust when it comes to antivirus software and these changes of control that are happening outside of their knowledge and consumers not being even given some kind of choice to maintain or discontinue their relationship with an antivirus provider, which is a really intimate relationship when you think about it. You're giving privileged access to whoever that company is, to your machine, to your data, to scan your hard drive. That's, you know, I wouldn't trust a lot of people with that. Kyle and Rob. I just think that kind of proves your point of the kind of hesitation that they are to be the ones to determine any kind of future activity of this kind for those consumers because they themselves are associated or otherwise deemed untrustworthy. You might argue by association. Anyway, I just want to add that caveat. Go ahead, Rob. Yeah. The thing about who is Ultra AV, and the answer to that is people don't really know a lot about them. They're apparently the relatively new antivirus service by UltraVPN, which is a VPN brand owned by a group called Pango Group, which owns a bunch of different VPN services. And so this is basically a completely, I guess, relatively unknown service that people who decided on the tried and true Kaspersky brand now find themselves saddled with. It's like, you know, if you woke up one morning and your antivirus was being handled by, you know, Roy's gerbil feed store and cybersecurity outlet, it's just really unexpected. It's really just not something that anybody has that brand trust in and certainly not something that people who signed up, you know, a license agreement with Kaspersky were expecting to happen. Well, let me just ask the hacker question here. Let's say I had Kaspersky running on my system and now this has happened. How do they know I'm in the United States? And how can I prove to them that I'm not? What do you mean? You mean... I want to keep using it. I want to keep using their service and say I'm not in the United States. I want to get around these restrictions, which is what hackers like to do. So it must be a simple thing, right? Kyle, go ahead. Presumably you would have maybe had this system set up with some kind of a location setting that maintained... And depending on how far back, whatever criteria they were looking at to determine this was measuring this. But if it was maintained as something that appeared to be out of the country when it's actually there, they may not have caught it when they went ahead and discerned or made a listing through those measurements. Are they just basing it on the address you filled in on a form? Or are they basing it on where your IP is from? I'm alluding to that. If it's the latter, then you simply use a VPN and say you're somewhere else. It's the easiest thing in the world. And, you know, you don't have to tell the truth on the form either. Alex? Well, you'd have to have that VPN all the time, though. You know, and that would be somewhat problematic. But I would imagine that it would be a combination of various things. Like, you know, if you really wanted to make an accurate assessment as to where somebody was geographically located, the IP address is something that you would want to watch. You would want to determine whether or not it would change. If it changed, where would it change to? You know, what's the native IP address of this person or somebody using a VPN? What are their language settings on their computer? You know, where have they been seen to be historically? So I think there's a lot of ways that you can assess this. But I think the easiest way and I guess the most dispositive way that they would probably do it would be on the basis of the IP address. Well, it seems like, you know, there have to be simple ways around this if people really want to continue using that service. I wouldn't run any of that crap. Oh, I wouldn't either. I'm just saying that, you know, when a barrier like this emerges, the first thought is always how do you get around the barrier? Let alone the barrier might be protecting you against something evil. That's true. But I think we still should be educated and know how to deal with it. Yeah. But I think, you know, you do bring up a good point, though, Emmanuel. What are the criteria by which they make this type of assessment? That's not information that we actually have or understand. It would be interesting to know. Yeah, I mean, you're giving so much access to a company you don't know much about. So I think, you know, you should always feel free to explore, manipulate, change things, even lie to see what happens when you do. Gail, go ahead. So we're just looking at the Pango website here. And I don't know. I kind of feel like if I'm learning about a suite of security options, I would much rather know what the tools are than which venture capital firms have invested in the company. I don't know if I'm alone in this particular feeling, but it does not instill me with a lot of confidence in this particular organization to, again, know who their backers are, but not a whole lot of anything else. I would love it if it's just a giant indemnity company or something. All right. We're almost out of time, but a couple of other stories have come our way. Computer labs at Delaware libraries across the state are closed after hackers on Friday seized control of the virtual servers that run the facility's public use computers. And that's according to Delaware Division of Libraries director Annie Norman. The hackers, oh, God, the hackers now are demanding money from the state in order to relinquish control of the system. Norman said she did not know the exact amount demanded, but said she heard it was around $1 million. And if we're familiar with libraries, they always have cash just lying around. She added that she'll be directing the Division of Libraries not to pay any ransom, insisting instead that the Delaware libraries rebuild the servers that run the public's computers. And that seems like the wisest thing to do. You can also run a library without computers. There are ways of doing that. And we should all be familiar with how to run things when our computers go haywire. Norman did not immediately know when the rebuild will occur. She has to get somebody to agree to do it. Nor when the public access computers will again be available. We see a lot of stories about this around the nation. It seems to be recommended not to pay the ransom, but to rebuild. Yeah, I mean, think about it. You pay a ransom. It's not like your standard kidnapping. You know, traditional kidnapping. Okay, they take your kid. They say, please give us this amount of money. You leave it in a suitcase by the river. Kid comes back. Okay, they can't keep doing that. But with computers and data, they might still have access. They might still have the sensitive data that they're holding ransom because you can copy things. So it's very, very different. And while I would recommend paying a ransom for your kid, I would not recommend paying a ransom for your computer because there's no guarantee. Actually, there's no guarantee with traditional kidnappers either. I know that. But it's a lot less nebulous. Go ahead, Alex. I mean, I guess, although a lot of these threat actor type of entities do trade on their reputation. So, you know, it may be likely that, sadly, you can trust them when it comes to the deletion of the data or the decryption of the data that they might have otherwise compromised. So, you know, in a weird way, customer service does really factor into these types of threat actor criminal enterprises. Well, I mean, okay, why would you trust them at all? What's the rationale behind that? Well, the rationale is that if they double cross you, let's say they say they're going to delete your data and then they don't and they release it, that will get out to the rest of the community, to the cybersecurity community, to the general public at large, and then nobody will pay the ransom in the future. You know, it's almost like if you want to stop this, you do precisely that. You actually become one of these ransomware people yourself and collect money and then release the data anyway so that nobody ever trusts them again in the future and the whole industry gets shut down. And you make a lot of money in the process. But, yeah, okay, but also to counter your point, okay, let's say that you do that and everybody's happy and you pay a million dollars, you get your data back, they don't release it. Ten years, they do, okay? You don't know they're not going to do that in ten years. And when it's that far in the distance, it's not going to hurt them at all. If people don't trust them anymore, they've probably moved on to other crimes. Well, that's quite possible. Your theory of, like, doing this yourself and then kind of screwing over the reputation of these threat actors anyway is a theory I'd never heard before, which actually is quite funny. That's why you tune in to Off the Hook. You hear theories you've never heard before. Well, that's exactly right. That's why you need to support WBAI, right? Because you wouldn't otherwise never hear of such crazy outlandish theories. And, yeah, but actually have some validity to them, too. I'm not saying they're totally off the wall. Well, that's another show. All right. Well, we have to move on. Please support WBAI by going to give2wbai.org and pledging whatever you can to keep conversations like this on the air and keep all the other shows that come your way throughout the week on the air as well. Write to us, oth at 2600.com, for all the latest, what to tell us, all the latest news in the world of cybercrime and privacy and things like that. No overtime tonight. We'll be back next week. Have a good week. Good night.