You have successfully completed your test call to area code 540-829-9910. If you'd like to make a call, please hang up and try again. If you need help, stay on the line and a hacker will assist you shortly. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. We couldn't get much worse, but if they could, they would. Bon Dillibon for the best, respect the worst. I hope that's understood. Bon Dillibon! Bon Dillibon! Bon Dillibon! Bon Dillibon! Thank you. Thank you. And a very good evening to everybody. The program is Off the Hook. Emmanuel Goldstein here with you on this Wednesday evening. Joined tonight by Kyle. Yeah, right here. How are you doing? Um, hi. Uh, okay. Okay? Well, that's good to know. Um, and, um, out in Skypeland, we have Rob T. Firefly. Good evening. We have Gila. Good evening. And we have Alex. You too. Good evening. Well, um, so, uh, you're back from Thailand, I take it? I am back and extraordinarily jet lagged. Really, really tired. You know, it's a 12-hour time chain, but, uh, but here I am. Well, it's just, 12 hours is easy because, you know, it could be like morning right now. Uh, but it's not. It's the opposite. It's not like a two- or three-hour thing where, you know, it's hard to adjust. It's simple. It's half a day. So you're just half a day off. And you don't even really have to set your watch back or forwards, given the 12-hour time change. It's exactly 12 hours. Yeah, very convenient. But it was a long journey home. Long journey home. I had to stop over in, uh, Doha for about seven hours in the Doha airport, uh, with Qatar Airways. But it was very nice. Not too bad. And then a 13-hour flight back to New York. Um, and then it only took two hours from JFK to get into Manhattan. So, there you have it. Yeah, I like how, uh, ground transportation is, is, uh, comparable to air travel as far as, uh, time it takes to get places. Um, but welcome back. Welcome back. Hope you had fun over there in, in, in Thailand. And, and, and first time over there, I take it. It, it was. And I have to say, I, that city really grew on me. It was really fantastic. You know, a good friend of mine had mentioned that there are these scenes on the tops of roofs that remind you of scenes from Blade Runner. And, and it absolutely was the case. You know, being on these rooftops and seeing just how massive and expansive Thailand, um, sorry, Bangkok was. It was, it was just, uh, it really extraordinary city. Great people, really good vibes, uh, insane traffic. I took pretty much every mode of transportation, boats on the back of motorbikes, subways, skyways. It was, uh, it was really, it was, it was quite, quite an experience. Well, if you want expansive, I would suggest Beijing, uh, because, or Tokyo. You know, uh, they, they both seem to never end, uh, and it's, um, it's really quite a sight to, uh, to behold. Yeah, I haven't traveled that much in Asia, but, um, I'm hoping this is the start of, um, you know, a new leg of, uh, of my travels here. I've, um, I've, it's definitely very, very interesting. And, uh, but I'll tell you that the most terrifying way that I've traveled in Bangkok was being on the back of a motorbike. That was, you know, that was something that took some guts. First of all, why was that necessary? Why did you have to get on the back of a motorbike to get someplace? Oh, because the traffic was so insane. You'd just be snarled up in traffic for 45 minutes, 50 minutes trying to get, you know, somewhere. But these motorbikes would zip in and out of traffic and they were extraordinarily inexpensive as well. And everybody seemed to take them. And you would see, you know, like young Thai women or something sitting on the back of a motorcycle or motorbike, just with their legs hanging off, playing on their phones, not even holding on. You'd think, well, I could do that. And then you'd get on the back of this bike, you're holding on for dear life, hoping it doesn't hit a pothole. It was very, very much a big cultural differences there between, um, the locals and me riding on the back of these bikes, especially having just gotten over a broken leg, I definitely did not want to break any additional bones in 2024, especially not in Thailand. And, uh, but I did it and it was really extraordinary. At one point, my hat even flew off. I think it was coming back two or three o'clock in the morning on this busy street. Motorbike was flying down the road. My hat flew off. I said that to the bike driver. My hat flew off. So he just kind of skidded out, turned around, went on the other side of traffic, got back on the road. My hat was, was run over by about probably 20 or 30 cars, but he managed to grab it and get it. And I still have it. And it's, uh, it's still my favorite hat. So why did he get it? Why didn't you get it? I tried. I, I tried to jump off the bike and get it, but he said it was dangerous to run into the traffic and he would do it. Wow. So that's, that's, that's dedication. I got, I got to say. Yeah. Yeah. Extraordinary city. I have to say, I recommend traveling there to, uh, to all of our listeners. All right. Well, I'll keep that in mind. I haven't, I've been in that part of the world in quite a while. Um, but, um, you know, did you make use of any ride share type things? Did they have that over there? They didn't really have ride share type things. Um, I mean, you could, you could schedule a, you know, truck or something like that. Um, but I did use the, uh, the tuck tucks that, that were, or kind of, you know, almost like flatbed. And little go-kart trucks or something that you would sit on the back of, uh, and you can get around pretty quickly. And those as well, and really economical, uh, but, you know, cars were probably the worst way to get around Bangkok. Um, there were boats that would go up and down these, what, what were man-made canals. There was a subway. There was also a skyway. And of course, the subway and the skyway take different tokens. They're not interchangeable because that's, you know, just how the world works. But, uh, but it was very interesting. It was, it was neat to, to figure out the public transport. I even had one night where I was so jet lagged that I went into the Japanese area of Bangkok, had some ramen, and then just decided I was just going to walk around. And it wasn't until 7, 7.30 in the morning that I made it back to the hotel. Just kind of wandered around the streets of Bangkok. And that was the other thing, too. It felt very safe. There were areas that were very impoverished, but yet still very safe. Interesting. Okay. Well, and, um, uh, you basically made use of mass transit. You made use of, of the back of motorbikes and, and other things like that. But, um, not so much cars, if I understand correctly. Cars were kind of the worst way to get around. They were. I mean, I, I did a lot of car driving at first and then realized that that, that really was the worst way to get around. It took forever. It was, uh, it was pretty horrible to take cars everywhere back and forth in, in Bangkok. Uh, and the motorbikes were, were really the way to do it. And you would take a, a 20 or 30 minute ride on a motorbike. Right. And it would come out to maybe $2.50 or $3 in terms of, you know, U.S. dollars. It was pretty extraordinarily, uh, inexpensive. Well, and also, of course, you know, the cars add to the congestion and traffic and pollution and all that. Um, it would be a good idea, I think, if they charge those people who drove the cars an extra fee and the money for that fee went into their mass transit. You know, that would be a bright move, I think. Don't you? You think so? Yeah, I do. I do. We should try something like that. I, I, I've heard some contentious ideas, uh, that, that were floated here in, in New York for the same thing. Yeah. Uh-huh. Very funny. Oh, it's not funny. It's serious. It's, it's, it's as serious as a migraine, believe me. Uh, and it's coming. It's coming, uh, in, in two months. I would like to be in the first car to pay the toll, to be honest. That's how strongly I feel the congestion pricing is, is, uh, is something that cities should have because too many damn cars on the street, as you said, you know, congested, polluted, slow. Let's have something that benefits people more. And by, by, uh, having those folks help pay for mass transit, they might convince themselves to start using that instead. And you get less cars on, on the streets. You have a more walkable city. You have better air quality. I think it's a, it's a win-win. So that's a lesson that I get from, from your trip over to Bangkok. I mean, maybe I will, I will say though, in comparison, coming back to New York and, and being here for the last couple of days after being in Bangkok for nine to 10 days. Um, New York feels positively calm when, in terms of the traffic and the people, it's, it's really kind of funny to me that, you know, it, it almost feels like, uh, like I'm in some, some rural area now or some, some part of, uh, a city that's, that's not very populated or polluted or, you know, this, this feels like a, you know, like a small town to me now. So, well, uh, here's what I suggest tomorrow at four o'clock, uh, go down to the Holland tunnel, the entrance of the Holland tunnel and just sort of hang out there in the street and tell me how calm it is. Yeah. I've, I've been in that traffic. It's terrible. I've been sometimes leaving this city at around that time. It'll take you an hour and a half just to get down to the Holland tunnel down, down seventh Avenue. So yeah, I, I get it. I, I hear where you're going there, Emmanuel. Oh, no, I've gone there. I've gone now. I'm coming back now because in the time it takes you sitting in traffic, I've already made a round trip. Um, now, anyway, we have to, uh, this is not the traffic show. We do talk about traffic quite a bit, but, um, uh, it's not really the traffic show. It's, it's the hacker show. It's a technology show. And of course, technology plays a part in all of this. Uh, and, uh, we're always looking for the, um, uh, the, the security vulnerabilities, things that people forget about the ways to take advantage of the way that you can be taken advantage of, especially, uh, considering privacy and all that and ways you can protect yourself. Now, one of the, um, stories that I've been seeing a lot of over the past couple of weeks, this, it's, it might be a good story or it might be a silly story. And I guess that's what we're here to decide tonight. Um, this headline comes from the daily mail over in the UK. The headline reads, urgent warning, don't type these six words or your computer could be hacked and hacked is in all caps, by the way. So that underlines the seriousness of this story. All right. I'm going to read a little bit and maybe one of you who is daring can have a keyboard ready to type these words. Um, cyber security experts warn that a new hacking campaign. Don't you just love our hacking campaigns? You know, we, we're always starting hacking campaigns. It's just, it never ends. Uh, a new hacking campaign is targeting people who share an extremely specific set of interests. Uh, according to cyber security firm Sophos, and I'm sorry if I'm not pronouncing that correctly. It's spelled S O P H O S and it's all caps. Um, hackers have used a sophisticated set of tools to hijack the results of one particular Google search, one particular Google search, and the experts warn that searching for this specific six word phrase could put you at serious risk of being hacked. In fact, I'm told that even hearing these six words can put you in danger of being hacked. So if you're driving an electric car right now that has all kinds of computer gizmos hooked up to it, and you're playing this radio show over your speakers, you would be warned to, um, uh, to pull over and not be in motion when I say the six words, because it could very well jump into your car's, um, uh, computer systems and, and hack the car. And, and you could be in, in jeopardy then this is a serious story, Kyle. Do you think they should, uh, go so far as to like remove the battery and I wouldn't say that. I wouldn't say that, but just, you know, pull over for, uh, for, uh, for, for caution sake. Um, anyway, uh, to, to calm people down a little bit, you're probably not in much danger unless, unless you happen to live in Australia and you have an interest in exotic cats. And that's a fair size of the population, I think. Now, uh, Safos, that's what I'm calling them now, the Safos, they warn that hackers are targeting anyone who searches. You guys ready? Okay. These are the words. Are Bengal cats legal in Australia? Don't, don't, don't type that into Google because searching for this phrase leads unsuspecting cat enthusiasts to malicious links loaded with malware. Now, you might not know that you're an unsuspecting cat enthusiast. That's how they get you. Now, and once your computer is infected, hackers can steal your information, take control of your computer and hold your data for ransom because that's what hackers do. In a blog post revealing the attack, Safos engineers wrote, victims are often enticed into clicking on malicious adware or links disguised as legitimate marketing, or in this case, a legitimate Google search. Um, yeah, the, the, the security researchers hadn't specifically set out to protect the interest of cat loving Aussies. Rather, they were investigating the use of a particularly powerful and common piece of malware called Gootloader. Anyone ever hear of Gootloader? No? Um, this software has been around for about a decade. It was previously the signature tool of the Russian Revel ransomware gang. Am I, am I saying that correctly? R-E-V-I-L? Revel? You're nodding, Alex? It, well, R-E-V-I-L, Revel, you know, I think people pronounce it different ways. Yeah. I just want to, I want to get it right. I want to get it right. It's important to be accurate. Uh, hackers infect their target's computers with Gootloader, uh, in order to stealthily install more powerful tools capable of stealing information like bank details or locking users out of their own data. Uh, typically this is done using a technique called Search Engine Optimization Poisoning. And, uh, Search Engine Optimization, uh, is abbreviated S-E-O. And S-E-O Poisoning, uh, is an insidious technique in which criminals manipulate search engine results to push websites they control to the top of the page. This lures victims into clicking on innocent-looking pages which secretly install Gootloader onto their device. Now, normally, a hacker would want to poison a really common search term so that as many people as possible follow their malicious links. Uh, has anyone typed the words in to see what the top link is? Rob, do you dare? We, we did. We did. Uh, we, we took the leap of faith. And, uh, first we, we searched it on my default search engine, which is DuckDuckGo. We searched it on Google.com. Um, and because this is Australian, we searched it on Google.com.au, the Australian version of Google. And, uh, all the top links now appear to be news stories about this. Damn it. So, like, like the snake eating its own tail. So, the news poisoned the S-E-O Poisoning. Yes. Who poisons the poisoners? Apparently, it's the Daily Mail. Wow. Okay. Well, uh, that makes it harder for us to track down the actual site. Um, it's called, uh, malvertising, if you can believe that. That's the word that S-E-O, uh, poisoning is, is, is known as malvertising. It's a technique by which hackers use search engines to make malicious sites appear legitimate. Um, and, uh, since consumers assume that the top hits on search engines are trustworthy, many people follow these links without thinking. And, uh, not me, though. I always go to number 23 on a search result. And that's almost always something that's innocent, if not completely unrelated. So, uh, I'm safe. But, um, what are the things, I, I, I, I've never had experience with this. But, if someone clicks on a malicious link, are there warnings? Or is it just done without any sign that anything bad has happened? And if that's the case, are we ever safe? Alex? Well, it, it depends. This has been, I, I think, a vector of attack for, for threat actors for a number of years now. And, and it can take a, a number of different forms as well. So, one, one way of doing it is, like, how Sophos had, um, had identified through reverse SEO or reverse search engine optimization by essentially promoting things that are bad in such a way that when people search for these things, they're going to get the, the bad links, right? You know, and they might do that by having lots of content that relates to Bengal cats or Bengal tigers in Australia all over pages in random ways so that Google will, will index that site and put it at the top of, of the heap as opposed to at the bottom. But the, the other way of doing it, which I find is more malicious and, and also involves the third party, namely Google, in profiting from this, is for threat actors to purchase Google AdWords so that the sponsored results that appear for a certain set of search terms winds up directing people to actually malicious sites. And, uh, I can tell you, I, I had a case that was, my God, it was almost four years ago now, but this exact type of thing happened. I will, you know, uh, I, I won't go into the, the names of, of the parties and things, but I'll tell you, this is the exact type of thing that happened. And so I had, uh, a client that was, uh, an investment firm on the West coast and they had at the time transferred from Celsius, the, uh, cryptocurrency exchange over to Coinbase, uh, the amount of 50 something Bitcoins at the time in Bitcoin, I think was around the, the total value was around $12 million that was transferred from Celsius over to Coinbase. So this person who was running the investment firm and made the transfer himself goes to obviously log into his Coinbase account after he transferred over this $12 million to make sure that it got there, which I think anybody would do. So he goes to log into his Coinbase account and it turns out that, um, he got this KYC notification. It's know your customer notification telling him that there's been unusual and abnormal activity in his account. And he has to go through several steps in order to get access to his account again. So that was a normal thing to see when you've just transferred over $12 million. So he calls up Coinbase, goes through the song and dance, shows them his wallet. Uh, you know, his, uh, it proves that the wallet address belongs to him, shows them his identification, his license, et cetera. And then they mentioned to him, well, you know, that that's all well and good, but if you're using this commercially, why are you, why are you, uh, why do you have this in a prime account when you should be using a pro account? I might have that reversed, but in whatever it was, they, they said, look, you can save all these fees. We'll help you do this. So they put the money into a different prime account, shown how to log into that. Two hours later, he logs into that account. You say he called them? Yes. He called them. Yeah. In order to go through this KYC process. Yeah. So two hours later, he logs into the Coinbase account and, um, everything is gone. $12 million. Gone. That's a really bad day when you lose $12 million in the course of a couple of hours. Right. So, yeah, I guess that could be seen as a bad thing. It, so what happened is it turns out, so that this, this case kind of didn't have a happy ending, but we were able to actually track and trace and freeze about $10 million of it. And it took quite a long time to even, um, to, to get, to get that, uh, to get even a portion of that back. But, um, but so this wasn't a terrible ending for him, but when we did a forensic analysis of his computer, uh, this person kept saying, well, there were, there was an email. I got an email about this. We never found an email about this, but what we found out happened was that this person did not navigate to Coinbase.com in the browser. What this person did was search for Coinbase login in Google. And then the ad results that showed up, the first one was a malicious site that was run by some scammers over in India. And it was, uh, com-session-login.xyz or something like that. But what was interesting is that the, the domain began with com. They created a sub domain, Coinbase, so that when you looked at the URL itself, it said coinbase.com. So when anybody clicked on that particular sponsored link, a banner came up, a pop-up showed up that said, there's been unusual activity in your account. You have to call us to unfreeze your account. And they happened to get a well, somebody who just transferred over $12 million. And they used that as an opportunity to, uh, access account, access his account and, uh, basically steal all $12 million in the course of a few hours. Now, Rob, I assume you've already typed coinbase.com login into Google to see what comes up first, because, uh, that, that one might still be there and that might be a lot of people fall for. Um, so, okay. What, what should this person have done, Alex, to avoid this kind of thing? Yeah, I think for, for anybody to avoid being, um, hit by these reverse SEO scams or malvertising, uh, scams that, that you correctly identified, Emmanuel, um, I think you need to navigate directly to the website itself. We've gotten to the point now where there are so many bad things that are indexed on Google and Google has an interest in taking money through these, these, uh, AdWords and does not necessarily check all the URLs that are associated with those AdWords that you can't trust them. You can't necessarily trust those links. So, uh, navigating directly to coinbase.com would have avoided this entire incident. But if you don't know the website for Coinbase, you have to search for it, right? So how do you get out of it? If you, if you have to search for it in the first place, you just see what it says and then type that manually or, uh, you just never follow links. Well, that's a tricky thing. If you don't necessarily know the address, uh, of it, I think you would have to, you would want to examine the URL pretty closely. If you're getting a, a, a link from Google itself, you definitely want to examine that URL. Um, look at the entire thing in the browser bar, make sure you're not looking at a sub domain on top of another domain. Look at how the domain ends. Does it end in.com? Does it end in.info and does the structure of it look weird? Now that's one way of identifying that these things are scams. I mean, in short of looking up the actual age of the domain itself, which would be, you know, going quite a step, uh, it's like a big step, I think, in terms of looking at these things, which is a really effective way of looking at it. If you look at the age of a domain, if it's newly registered, it's very likely not associated with Coinbase, but that would require, you know, looking at the who is data or going into the terminal or something. But I think in the first instance, try to navigate directly to, uh, the website to which you're trying to, to, to navigate, whether it's Coinbase, whether it's Google, Gmail, et cetera. Um, and be really, really careful of those sponsored links because those sponsored links, uh, tend to have bad things associated with them. They don't take you to the, to the places where you think you're being taken. Now, isn't that kind of the opposite idea of what Google is trying to push? Sponsored links are the links that you can trust, but you're saying sponsored links are the very ones that will take you into the malware. Yeah, uh, I, I am saying that that's exactly what I'm saying. And I also think that the sponsored links have actually diluted the search results to such an extent that the sponsored links, you might as well just scroll right through them anyway. You know, let's say you're, you're searching for, I don't know, that random example, it comes into my head because one of my children keeps bugging me about going camping. But let's say you're searching for Coleman tents, something like that. Um, you, you're not, the sponsored links that are going to show up often rely on the trademarks and trade names and product names of competitors in order to, um, promote their own sponsored links. So you may be searching for a Coleman tent, but you're getting some other kind of third party tent, or you might get redirected to Timu or, you know, some other, you know, schlocky site that will sell you some substandard tent, something like that. So you can't necessarily trust them, just those sponsored links to get you where you think you're going. Wow. Okay. Well, this is a, you know, a bit of a eye opener for a lot of people. I mean, the story started off kind of silly, uh, with the six words that are guaranteed to get your computer hacked, which is not necessarily true, but there is some element of truth to it in that it gets you to sites that aren't real, uh, that are loaded with malware and, um, uh, disguise JavaScript files. That's something you should look out for that, uh, uh, contain malware that you wind up having on your system. Yeah. And, and another way that these threat actors will, will use these either sponsored links or reverse SEO poisoning is that you'll click on something, you know, the page, the title of the page will look like it's a direct hit. It's exactly the information that you're looking for, but then you get redirected to another site that tells you that you're, um, there's malware on your computer that, you know, you can't go any further until you remove this malware that has been identified on your machine. And at that point, um, you need to download some kind of software that will allow you to clean the infected malware from your machine. Anytime you see a website that tells you that you have malware on your machine, that's generally some kind of scam and it's usually an attack vector by which a threat actor is trying to get you to download and run something that is actually malware itself. And if you ever are in a situation where you need to download something, um, a program that you want, be sure to check the website, uh, look for reviews. Uh, many times there are discussions. Is this particular site legitimate and there will be people who will warn you if it's not. And, uh, there will be reviews in, in all kinds of places of how trustworthy they actually are. You have to look for, um, um, basically what people have, are, are saying because a lot of people comment on the experiences they have. And, and this is, this is the warning that you could be, um, uh, receiving. Go ahead, Rob. This is also one of those things that I think a lot of folks, uh, maybe listening to this program are like, well, I'm already technical. I know this stuff. I'm hip to this stuff, but this is one of those things that's very deceptive to people who perhaps aren't so technical. And I think most of us have people in our lives that we end up, you know, helping with computer stuff, um, you know, regularly. And this is something to take those people in your life through the importance of actually typing in the site you want, maybe using the bookmark for the site you want. So, you know, it's a, it's the legit site, maybe helping them set that sort of thing up. I, I knew someone who for years and years and years have been logging into a particular site, um, just by clicking the link in one email that they happened to have from, you know, years past. And at one point they lost that email and didn't have that link anymore and didn't know how to get to the site. This is the sort of thing that like, it's a basic, it's a basic, um, matter of, uh, digital literacy, but not everybody is that, uh, is that educated. And those are the people most vulnerable to this stuff. And, you know, Alex, uh, to speak to the case that you were involved in, I think there might actually be a cottage industry here, uh, for when you need to transfer $12 million from, from cryptocurrency. And you're not quite sure if you're doing it right, maybe there are professionals who can help with this, you know, accredited professionals, uh, who will basically, um, hold your hand through the process and make sure, uh, nothing, nothing, uh, bad happens along the way. I think it would be, it would be worth it for peace of mind for people who are doing things like that. Yeah, I, I tend to agree. And, you know, oftentimes, you know, you screw up one address and a wallet address and the money can be gone. You know, it can be, it can be lost irrevocably in, in many ways, you know, if you send it to the, to the wrong address. So yeah, I think even a tiny percentage of whatever the total transfer is could be, uh, could be worth, uh, utilizing some kind of professional. Also one, one way of, of doing this before what, one way of testing before you make a large transfer, if people are doing this with cryptocurrency, it's obviously to send a very small amount to the address to which you intend to send it, make sure that it gets there and then send a large amount later. That's, that's another trick that a lot of people use. Yeah. But if I was part of that scheme, I would make sure the small test results went through somehow and then just wait for the big one to come through. Yeah. Yeah. That's a, that's, that's a good point, but at least, you know, you, you had the right address and the money was, was actually reaching the other side. Or, uh, a man in the middle that was making sure, I don't know, there's all kinds of ways to be, there's, there's, there's a way to spoof that. Yeah. You're right. Yeah. Uh, anyway, the engineers, uh, concluded that users, uh, should still look out for search results and search advertisements that seem too good to be true on domains that are off the beaten path, uh, whether they're looking to get a Bengal cat or not. Um, and if, uh, you do end up on a suspicious site, don't follow any further links or download any files. Uh, as a general rule, you should only download files from sites you absolutely trust and never from unknown sources. Um, yeah, go ahead, uh, conclude this. Yeah. I think one other tip here for our listeners is some of these nasty sites will, will tell you to call a particular number and, and that is usually the precursor to some kind of remote access scam where they get you to download something like team viewer and then, um, click on a particular link that will then give that person remote access to your particular machine. And then they start monkeying around or, or downloading files or implanting malware on your system, something like that. But a good, a really dead giveaway for all of this is that number one, you're never really going to be asked to call a particular number to remove malware or to install a VPN or something like that. And number two, if you do have to call a number for any kind of tech company, the chances are that somebody is going to answer the phone immediately are really next to zero. And all these scammers are, are, you know, they, they have call centers where the phone is answered almost immediately. You're never put on hold. So when you're about, wait, if you get good service, you should be suspicious. Absolutely. That's exactly, that's exactly it. All right. All right. Noted. Okay. Moving on. Um, great article in today's times, uh, when I can spend much time on it, but I do want to point people to it. It's called how Google spent 15 years creating a culture of concealment. And it's written by this guy, David Streitfeld, uh, and, and, uh, basically the, um, uh, the line underneath his name says, uh, David Streitfeld has written about Google since it was a startup. So, uh, he knows a bit about the company, but basically it's talking about how, um, uh, Google has this, um, uh, environment of, um, of, of keeping things from getting on the record. Um, yeah, uh, to minimize the odds that a lawsuit could flush out comments that might be incriminating, uh, employees should refrain from speculation and sarcasm and think twice before writing one another about quote unquote hot topics. They said, don't comment before you have all the facts to their employees. Uh, the technology was also tweaked to setting for the company's instant messaging tool was changed to off the record, uh, an incautious phrase would be wiped the next day. And, and basically, uh, the memo they sent out, uh, urging people, uh, to, to exercise caution, uh, became the first salvo in a 15 year campaign by Google to make deletion the default in its internal communications. The irony is, is astounding as the internet giant stored the world's information. It created an office culture that tried to minimize its own. And it's just so much to learn from this, that, um, they're telling us to do one thing. They're doing something completely different because they recognize the danger of having too much information about your internal dealings, getting out to the public. Yes, Alex. Yeah. I don't think that this is peculiar to Google. I think most companies have things called data retention policies that sound like they're there to ensure that data is retained, but they're actually there to, to ensure that data is deleted on a timely basis. A lot of, um, a lot of email systems will have data retention policies that require emails to either be dragged into a separate folder or they're automatically deleted from your particular inbox. And the, and the problem is very much this, that in the United States and the United Kingdom, we have really wide ranging discovery obligations. If there's a lawsuit and all of these documents and records and communications, whether they're instant message communications or their email communications can be subject to discovery and, and found through some kind of subpoena or court order legal process in general, uh, that would make them, uh, available to your adversary. Yeah. And so I just want to point out anytime I hear about like content on these, on social media platforms and in any sense, uh, uh, non public, um, data to me, I, it, I, I hear evidence because that is how it's used from SMS to everything you're listing. Anyway, go on. Yeah, but that, that's exactly right. All of this, all of these communications are evidence. And it's, and, and I think that, you know, I'd say, but I think Google is right when they're cautioning their employees not to engage in speculation that could be misinterpreted if found in the hands of a, um, you know, a particularly adept plaintiff's lawyer, because all of this information can be spun in one way or another. So I, I actually tend to agree with Google in advising the employees not to engage in speculation of this nature. I mean, Alex, I think you're right. Any company would say the same thing, but the difference here is that Google has users that it does not give that advice to, that it does not encourage to, uh, uh, to, to white data as soon as you no longer need it. They encourage you to, to basically say everything, hold on to everything. I mean, how many times have we, have we, uh, seen, uh, in, in crime investigations, uh, what the perpetrator search for on, on Google? I'm not even sure if they logged into Google at the time, if it's, if they're using their IP instead, but it's, um, you know, I'm not saying, uh, criminals should, should, uh, not be caught, but everyone should be educated as to the dangers of doing certain things. And if it's good enough for Google employees, it's good enough for Google users. Yeah, I, I tend to agree there. There's, there's definitely a massive disconnect between what they want their, their customers and clients to do and what they do internally. Yeah, there's that, that's, that's a fair point. Go ahead, Rob. Yeah, there's a quote in this article I really like, uh, from someone called Agnieszka McPeak, who is a law school professor. And, um, she says, uh, Google had a top-down corporate policy of don't save anything that could possibly make us look bad. And that makes Google look bad. If they've got nothing to hide, people think, why are they acting like they do? Well, yeah, I mean, you could say that about a lot of things, you know, if there's, if there's a report that's, um, uh, set to be released, uh, investigating somebody's behavior and you insist that that report not get released doesn't speak much to you being cleared of any suspicion. I don't know, I'm just, I'm just thinking out loud here. I don't know of a specific case where that applies, but you know, I, if somebody say we're up for, I don't know, a cabinet position, uh, in, in the new administration and they had some kind of a report on them that was set to come out and they somehow were able to make it so the report didn't come out. And I just, I wonder if it makes them look innocent or guilty, you know? Yeah. And, and for people, for individuals, there's the concept of, if you're, you know, not guilty, uh, if you don't have anything to hide, then, you know, why are you worried about your privacy and so on? And that's, that's very true for individuals that, uh, privacy is an important thing and it's a right and it's a human right that we should protect. But if you're a 900 pound gorilla on the level of Google and you're accountable to not only society, but shareholders and, uh, everything else, like there, there are certain, uh, there are certain things that make you look worse and, uh, you know, maybe you should be holding onto some data. And there's, there's a difference between privacy and results of an investigation. And in case you haven't figured it out by now, I am talking about Matt Gates, uh, who is basically, um, uh, in line to become the next attorney general after having an investigation into his behavior, uh, by the, uh, the, the house of representatives. And it's the, the, the report is being, is being, um, basically squashed. Uh, it's, it's the most corrupt thing I think I've ever seen, although I'm sure that will be exceeded, uh, by, by orders of magnitude in the months and years ahead. Uh, but here's some, some, uh, what I think is, is, is fairly, um, um, positive news and unidentified hacker has gained access to a computer file shared in a secure link among lawyers whose clients have given damaging testimony related to Matt Gates, the former Florida congressman who was president-elect Donald Trump's choice to be attorney general. The file of 24 exhibits is said to include sworn testimony by a woman who said that she had sex with Mr. Gates in 2017 when she was underage, as well as corroborating testimony by a second woman who said that she witnessed the encounter. The information was downloaded by a person using the name Altum Beasley. Altum. Do we know any Altums? A-L-T-A-M? Really? You don't? Huh? Interesting. Okay. Altum Beasley, uh, 1.23 PM on Monday. So I expect us all to account for our whereabouts, 1.23 PM on Monday. Um, a lawyer connected to the case sent an email to the address associated with Altum Beasley only to be informed in an automated reply that the recipient does not exist. Uh, the material does not appear to have been made public by the hacker yet. Uh, the documents include information that is under seal with the Justice Department, which investigated Mr. Gates, but did not file charges and the House Committee on Ethics, which has completed its own inquiry into the former congressman. Um, the ethics panel's members met today to decide whether to vote to release the material that's gathered. And guess what? It was blocked by Republicans. Yeah. And the reason they, they aren't releasing it by default is because he resigned as a congressman. So they no longer have any authority over him. Like I said, it's, it's one of the most corrupt things you'll ever hear about, but you know, in a situation like this, okay, so let's say we're talking directly to this hacker who we don't know. And if we did know, we would say, we don't know. And, um, is it a good thing to have this information? Is it a good thing to release this information? Is it maybe an obligation to release this information? Or do we all just play the game of letting the corruption flow and use every legal trick in the book to ensure that certain people stay in power? I don't know. Kind of, kind of mixed feelings here. Go ahead, Alex. Well, I, I think if we're in this particular position, which I, I'm, I'm not sure that we are, others probably are, but, uh, I think first and foremost, we would have to be conscious of the fact that this person is really, who's in possession of the information is putting themselves in great danger and great jeopardy by releasing the information. And I think that we would have to, in the first instance, make sure that sources and methods are protected here. Um, and this is a great reason for people who are in the possession of this type of information to use something like secure drop, which, uh, uh, in, in order to share that information, which, which I think, um, may in fact be something that's set up with, uh, 2,600. Oh yeah. No, uh, um, uh, many news organizations, um, journalists use secure drop and it works really well for getting information like this. But I think, you know, what, what we're seeing here, this story coming out, identifying the person by name, identifying by time, maybe in a way, and I kind of hope this is true. They're sending a notice to this person, warning them to be careful because this information already is out there. And if they intend on releasing this, this is what is known so far. So cover your, cover your, your, your tracks. And, uh, maybe we have something to work with Kyle. I was just going to maybe, uh, push Alex's argument a little bit further and say like, well, in addition to the grave risk of releasing, right. Um, and there, and my, where I'm going is this is a cost benefit analysis for that person, but there's also grave risk in, um, keeping it hidden because you're still going to be pursued, uh, presume, presumably. Am I, am I wrong? So, I mean, I think for them, it's, there's almost some insurance and we've seen this with leaks in the past in providing the information to some entity that can, um, though, as you point out, there is risk, uh, they can make it public because once it is then public, it is not really a secret anymore. There may be some after the fact consequence for the transgressions, but it'd be that as it may, the information itself, uh, doesn't, um, let's say succumb to process and, and stay, uh, uh, away if, um, there is some sort of, uh, uh, altruism in, in the, uh, in the act. Would you, do you hear where I'm going with that, Alex? Yeah, I, I do. And I, and I think that's a really astute observation here too, because, you know, you're, um, that the act has been completed one way or another, right? And it doesn't really, doesn't really make a difference in terms of the, the criminal liability here, whether or not the information is going to be released to the public or not. It may be an aggravating factor, perhaps, um, if the person was caught, uh, that, that, that they released it to journalists or something, didn't keep it to themselves. But I think that the, the, the grave danger that this person puts them in themselves in, which would, which would be, um, to have violated the Computer Fraud and Abuse Act, the federal statute, which is known as the hacking statute, um, that was actually passed shortly after, um, war games came out. I mean, Congress literally created that statute in, uh, in, in direct, um, kind of, uh, response to war games, um, like 1983 or 1984. I can't remember exactly when it, when it came out, but, um, that's the, that's the danger there. Um, and, and so I think, you know, working with the right journalists, working with the right organizations to make sure that your anonymity is preserved, I think is really important. I would also say that working with, uh, whistleblower organizations could be really helpful, but I would probably shy away from the whistleblower organizations that are associated directly with the government for obvious purposes. Yeah, yeah. And I, I also think, um, your suggestions, um, are, would, um, bolster a case that an individual might be making, um, and, and, um, disassociate them from, uh, any kind of accusation that they might be attempt, their motive may be to broker this for, uh, uh, a financial windfall instead of some, as I suggested, an altruistic, uh, uh, public interest motive sort of thing. So, uh, yeah, if they just take it and run, uh, there, I think then it, I don't know, you would perhaps, uh, know what, what it would suggest legally, but, um, to my mind, it, you know, there are more unknowns than if there's, uh, a destination for, for what they're doing that, that has some, some sort of public interest angle versus brokering it and tried to, to make, to make money or extort people. Yeah. I think as soon as you, um, uh, put a price on it, you lose legitimacy in my eyes, because this is something that people deserve to know about. It's something that's being actively covered up and you could say, oh, but they're following the law. Okay. Well, the laws can be abused. It doesn't mean that people don't have the right to know the truth. And in a case like this, we certainly, uh, deserve that much. By the way, I, I, I scanned the country over the last couple of minutes, uh, uh, a surface scan was not able to find the name Altem anywhere, uh, except as a last name, uh, in the UK and in some places, uh, I did find though, that, uh, Altem stands for the advanced long-term, uh, actuarial mathematical, uh, uh, mathematical exam. So I don't know if there's a message in there somewhere, but that's, that's kind of, um, uh, where that stands. Um, Hey, um, uh, there, there's, there's been some tremendous gains. Uh, there was an article about this actually in the times, uh, the rights triumph over social media, uh, right wings taking over social media, everywhere you look, uh, parlor, true social Twitter, you name it. And, um, something named blue sky has, uh, has really come up in the last couple of weeks to the point where a million people are joining a day, it seems. Um, and, um, I just wonder if anyone out there is, um, is, is, is diving into that. Uh, personally, you know, I'm, I'm, um, um, devoting most of my time to both blue sky and Mastodon as those seem to be the two avenues available for people who still value free speech, uh, and, um, and anti-fascist type of atmosphere where right wing idiots aren't prevailing as they are in so many other places. Um, but I just wonder if, um, if, if all of us are, um, at least dipping our toe into it, Kyle, I have dipped my toe into the blue ski. Uh, I'm not sure how you pronounce it, but yeah, uh, it's, um, um, it's, it looks a lot like early Twitter. I'll say that. And it's, it's pretty simple. I don't really, I don't have the knack of it yet as far as, um, reaching out to as many people as, as, um, I know are out there. I know there are tricks. I know there's ways of, um, of, of being on lists and things like that, where you can speak to more people right now, you know, I only have a couple of hundred people following as opposed to Twitter where I had, you know, close to 10,000, but the engagement is much better with those 200 than it is with the 10,000. So think about that. Yeah. Having, uh, used Mastodon for, uh, quite a while now, I, I really feel at home there, but, um, I don't have the desire to try out blue sky because I, I think, I feel like Mastodon is already the good one. It's the decentralized one. It's the one that has no chance of being, uh, wrangled away from us by, um, people at the top, like, uh, you know, other social media that I, that I could name. It's also, uh, blue sky is also the one that, um, a few weeks ago, uh, raised a $15 million series of financing, um, led by an outfit called blockchain capital, which, uh, um, I have seen described as, uh, crypto grifters. And, uh, so, you know, it's, I think if we want to have nice things, we want to have nice things that are distributed and federated and that we could easily, uh, move from one chunk to another. If, uh, if the bit we were on went bad in some way, I just like to caution you not to prejudge or at least give it a shot and see, you know, if, if what you fear is true or becomes true with, with people aware of these concerns in a way that they weren't when Twitter began, maybe there's a way to keep that from happening while, while having another platform. I'm not saying, uh, abandoned Mastodon by any means. Uh, I've been, you know, um, uh, investing a lot of time in Mastodon as well. I just find the, the engagement seems at least for now seems to be better on blue sky, but I'd like to use them both. I really would. I'd like to use as many, um, uh, social media outlets as possible that don't drag you down into, uh, idiocy and, and, and hatred. Go ahead, Alex. Uh, on, on that note, I tell our listeners to check out Farcaster. That's another decentralized social media network that is kind of part of the world of web three and where that's going. So check that out as well. Can you give us a URL that will not lead us into malware? Oh, that's a good question. I'd have to find that maybe we can do that on, uh, overtime for those people, uh, who are, um, wondering what overtime is. That is the show that follows this show on YouTube. So you'll have to go to YouTube to, uh, to hear us on channel 2600. You've been listening to off the hook here on WBAI, uh, right to us. O th at 2600.com. We love to hear from our listeners and please keep listening to and supporting WBAI. Go to WBAI.org or, uh, buddy.wbai.org to become a BAI buddy. And, uh, we'll be back next week with, uh, more insightful conversation about technology, privacy, threats to freedom, all that kind of thing. Uh, and again, uh, we will be on overtime on YouTube channel 2600, uh, in just a few minutes. You can call us, you can, um, listen to more of us, uh, talking about various other things. We'll see you next week. Good night.